A WAPI certificate authentication method and system
By installing the root certificate of the unified organization and the certificate of the local AS in the AP and STA, using the extended certificate authentication result type value 0x04, a trusted certificate authentication chain is formed, which solves the problem of the unified organization issuing certificates, simplifies the network establishment and authentication process, and meets the management needs of large organizations.
Patent Information
- Application Number
- CN202310296168.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-24
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2043-03-24
AI Technical Summary
In organizations with multiple branches, the existing WAPI authentication protocol cannot achieve the issuance of certificates by a unified agency, resulting in complex and high cost network establishment between the local AS and the unified agency, and the certificate roaming authentication is unfriendly, increasing the authentication time for end users to switch between APs.
The extended certificate authentication result mechanism is adopted. By installing the root certificate of the unified agency and the certificate of the local AS in the AP and STA, the extended certificate authentication result type value 0x04 is identified, and it is signed and verified by the unified agency's certificate system to form a complete trusted certificate authentication chain.
It realizes the unified issuance of certificates by a unified organization, simplifies certificate management, reduces the complexity of network establishment and certification time, and meets the needs of large organizations for WAPI certificate issuance and management.
Smart Images

Figure CN116249114B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of wireless local area network communication, and specifically to a WAPI certificate authentication method and system. Background Art
[0002] WAPI (Wireless LAN Authentication and Privacy Infrastructure) is the WLAN security standard and technology specified in the Chinese national standard for wireless local area network GB15629.11. With the advancement of digitalization in infrastructure industries such as the power grid, the demand for terminal mobility is becoming increasingly prominent, and the application of WAPI is increasing.
[0003] Such as Figure 1 , WAPI uses digital certificates to identify the identities of wireless access points (APs) and wireless terminals (STAs), and conducts identity authentication on the network side (AP) and the terminal side (STA) based on a three-factor authentication system, ensuring the security of wireless access authentication. Such as Figure 1 illustrates the three-factor authentication system of WAPI. In the three-factor authentication system, both the AP and the STA do not trust each other, and they are authenticated together by a third-party authentication unit (i.e., AS) trusted by both parties through the WAPI protocol.
[0004] The process of three-factor authentication is as Figure 1 , as shown in the WAPI access authentication process. The WAPI authentication process determined in the WAPI standard includes:
[0005] (1) After the wireless terminal STA associates with the AP, the AP sends an authentication activation (ACTIVE) message to the STA, and this message includes the certificate information of the AP.
[0006] (2) After receiving the authentication activation message from the WAP, the STA sends an access authentication request message to the AP, and this message includes the certificate information of the STA.
[0007] (3) After receiving the access authentication request from the STA, the AP sends a certificate authentication request message to the AS, and this message includes the certificate information of the AP itself and the received STA certificate information.
[0008] (4) After receiving the certificate authentication request from the AP, the AS conducts certificate authentication checks, forms a certificate authentication result, and sends a certificate authentication response message to the AP; the certificate authentication response message includes the certificate authentication result, and the authentication result mainly includes the certificates of the AP and the STA and the certificate authentication result. The AS uses its own WAPI digital certificate to sign and protect the authentication result to prevent tampering;
[0009] After the AP receives the certificate authentication response message sent by the AS, it will send an access authentication response message to the STA. This message includes the certificate authentication result of the AS. The AP will reject or accept the access of the STA according to the certificate authentication result. In this process, both the AP and the STA will verify the signature of the certificate authentication result based on the AS root certificate installed on their own.
[0010] In the foregoing WAPI authentication protocol process, for the AP and the STA to verify the signature of the authentication result of the AS, the AS root certificate is required. In addition to installing the certificates of the AP and the STA, the AP and the STA will also install the AS root public key certificate. In this case, the AS root public key certificate is a self-signed certificate, and the certificates of the AP and the STA are signed by the AS with the root private key. That is to say, the certificates of the AP and the STA are issued and signed by the AS.
[0011] When an organization with multiple branches deploys a WAPI wireless network, the AS is often deployed at the center and the APs are deployed at the branches. For example, in the power industry, the AS is deployed at the local power company, and the APs and STAs are deployed at the stations (such as substations). In this way, the certificates of the APs are issued by the AS deployed at the local power company. This certificate issuance method conflicts with the management mechanism. From a management perspective, some users hope that the WAPI digital certificates are issued by a unified agency (hereinafter referred to as the unified agency) at the provincial or even national level of their organization, but the unified agency does not participate in the authentication. This practice can be described in terms of certificate issuance as follows: the certificates of the AS, the APs, and the STAs are all issued by the unified agency, and the AS, the APs, and the STAs all install the user digital certificates issued by this agency and the root public key certificate (referred to as the root certificate) of this issuing agency. In this mode, the current WAPI authentication protocol cannot implement the authentication process because the AP or the STA does not have the AS root certificate of the WAPI wireless network where it is located, and they cannot perform signature authentication on the certificate authentication result of the AS.
[0012] If the WAPI certificate is issued by a unified institution, a hierarchical certificate issuance method needs to be adopted, that is, the unified institution issues certificates to multiple ASs, and each AS then issues user certificates to the APs and STAs in its respective network. In this multi-level certificate mode, in addition to installing the certificates issued by the local AS and the root certificate of the local AS, the AP also needs to install the root certificate of the unified institution, and the AP uses the root certificate of the unified institution to check whether the root certificate of the local AS is trustworthy. For the terminal STA, there are two cases: (1) The terminal also needs to install the certificates issued by the local AS, the root certificate of the local AS, and the root certificate of the unified institution, the same as the case of the AP; (2) The terminal ST installs the certificates issued by the unified institution and the root certificate of the unified institution, but in this case, to complete the WAPI authentication, the unified institution must deploy and run the AS authentication function, that is, participate in the certificate authentication, and authenticate the terminal through the WAPI certificate roaming authentication, that is, the local AS forwards the terminal's certificate to the AS of the unified institution for authentication through the WAPI certificate roaming authentication protocol. For this purpose, the unified institution needs to establish an interconnected network between the local AS and the AS of the unified institution.
[0013] This mode is not what some industry users hope for, because the issuance of certificates to APs and STAs by multiple local ASs conflicts with their centralized issuance and management mechanism for digital certificates. These industry users hope that all certificates are issued by a unified institution and do not want the local ASs to issue certificates anymore. Running certificate roaming authentication between the local AS and the unified institution is also not desired by these industries, because establishing networks between multiple local ASs and the unified institution is complex and costly, and this certificate roaming authentication is not friendly to the handover of terminal users between APs, which will increase the authentication duration; moreover, this roaming authentication only solves the problem that the local AS does not need to issue certificates to the terminal STA, and the local AS must still issue certificates to the APs within its jurisdiction. Summary of the Invention
[0014] The purpose of the present invention is to provide a WAPI certificate authentication method and system to solve the problems that establishing networks between multiple local ASs and the unified institution is complex and costly, and this certificate roaming authentication is not friendly to the handover of terminal users between APs, which will increase the authentication duration; moreover, this roaming authentication only solves the problem that the local AS does not need to issue certificates to the terminal STA, and the local AS must still issue certificates to the APs within its jurisdiction.
[0015] To achieve the above object, the present invention provides the following technical solution: a WAPI certificate authentication method, including a first WAPI certificate discriminator AS, a first wireless access point AP, and a first wireless terminal STA. The first WAPI certificate discriminator AS, the first wireless access point AP, and the first wireless terminal STA are all installed with WAPI digital certificates and first issuer public key certificates signed and issued by a first certificate system. The first issuer public key certificate is a self-signed root certificate of the first certificate system. The WAPI authentication process includes the following two key processing processes:
[0016] First, the first WAPI certificate discriminator AS includes a first AS public key certificate. The first WAPI certificate discriminator AS uses the first issuer public key certificate to verify the signature of the WAPI certificate in the WAPI certificate authentication request. After completing the certificate verification, it puts its own WAPI certificate into the certificate discrimination result field and uses the new type value 0x04 to identify the certificate discrimination result, thereby forming an extended certificate discrimination result.
[0017] Second, after the first wireless access point AP and the first wireless terminal STA receive the certificate discrimination result, they determine whether it is an extended certificate discrimination result according to the certificate discrimination result type value. If it is an extended certificate discrimination result, they first use the locally installed first issuer public key certificate to verify the first AS public key certificate in the extended certificate discrimination result. If the first AS public key certificate is trustworthy, they use the first AS public key to verify the extended discrimination result.
[0018] Among them, the first issuer public key certificate, the first AS public key certificate, and the certificates installed on the first wireless access point AP and the first wireless terminal STA are WAPI certificates based on ECDSA192-SHA256, or national secret certificates of SM2-WITH-SM3.
[0019] A WAPI certificate authentication system, including a first WAPI certificate discriminator AS, a first wireless access point AP, and a first wireless terminal STA;
[0020] Among them, the first WAPI certificate discriminator AS can form an extended certificate discrimination result in the certificate discrimination response message. The extended certificate discrimination result includes not only the certificates of the first wireless access point AP and the first wireless terminal STA, but also the certificate of the first WAPI certificate discriminator AS itself, and uses the type value 0x04 to identify the certificate discrimination result.
[0021] Among them, the first wireless access point AP and the first wireless terminal STA can receive, identify, and analyze the extended certificate authentication result included in the WAPI protocol, can verify the AS public key certificate in the extended certificate authentication result with the issuer public key certificate installed locally, and use the AS public key certificate to verify the extended certificate authentication result after verifying the AS public key certificate in the extended certificate authentication result.
[0022] Compared with the prior art, the beneficial effects of the present invention are:
[0023] The present invention fully conducts credibility checks on the certificates and certificate authentication results in the WAPI authentication process, thereby being able to solve the problem that in some industry applications of WAPI, certificates cannot be issued by a unified certificate issuing authority (or department) in an organization, and the AP and terminal certificates must be issued by the local AS. Thus, it can achieve the purpose of unified WAPI certificate issuance by the provincial or national departments of relevant organizations in these industries, meeting the requirements of these large organizations for the WAPI certificate issuance management mode. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] Figure 1 It is a schematic diagram of the composition and process of the WAPI three - element authentication system of the present invention;
[0025] Figure 2 It is a schematic diagram of the definition of the composition of the general WAPI certificate authentication result of the present invention;
[0026] Figure 3 It is a schematic diagram of the definition of the composition of the extended WAPI certificate authentication result of the present invention;
[0027] Figure 4 It is the WAPI certificate authentication response message of the present invention;
[0028] Figure 5 It is a schematic diagram of the system of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0029] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0030] Such as Figures 1-5As shown in the figure, a WAPI certificate authentication method provided by this application includes a first WAPI certificate discriminator AS, a first wireless access point AP, and a first wireless terminal STA. The first WAPI certificate discriminator AS, the first wireless access point AP, and the first wireless terminal STA are all installed with WAPI digital certificates and first issuer public key certificates signed and issued by the first certificate system. The first issuer public key certificate is the self-signed root certificate of the first certificate system. The WAPI authentication process includes the following two key processing procedures:
[0031] First, the first WAPI certificate discriminator AS includes a first AS public key certificate. The first WAPI certificate discriminator AS uses the first issuer public key certificate to verify the signature of the WAPI certificate in the WAPI certificate authentication request. After completing the certificate verification, it puts its own WAPI certificate into the certificate discrimination result field and uses the new type value 0x04 to identify the certificate discrimination result, thereby forming an extended certificate discrimination result.
[0032] Second, after the first wireless access point AP and the first wireless terminal STA receive the certificate discrimination result, they determine whether it is an extended certificate discrimination result according to the certificate discrimination result type value. If it is an extended certificate discrimination result, they first use the locally installed first issuer public key certificate to verify the first AS public key certificate in the extended certificate discrimination result. If the first AS public key certificate is trustworthy, they use the first AS public key to verify the extended discrimination result.
[0033] Among them, the first issuer public key certificate, the first AS public key certificate, and the certificates installed on the first wireless access point AP and the first wireless terminal STA can be WAPI certificates based on ECDSA192-SHA256; they can also be national cryptography certificates based on SM2-WITH-SM3.
[0034] A WAPI certificate authentication system includes a first WAPI certificate discriminator AS, a first wireless access point AP, and a first wireless terminal STA;
[0035] Among them, the first WAPI certificate discriminator AS can form an extended certificate discrimination result in the certificate discrimination response message. The extended certificate discrimination result includes not only the certificates of the first wireless access point AP and the first wireless terminal STA, but also the certificate of the first WAPI certificate discriminator AS itself, and uses the type value 0x04 to identify the certificate discrimination result.
[0036] Among them, the first wireless access point AP and the first wireless terminal STA can receive, identify, and parse the extended certificate authentication result included in the WAPI protocol, and can verify the AS public key certificate in the extended certificate authentication result with the issuer public key certificate installed locally. After verifying the AS public key certificate in the extended certificate authentication result, the AS public key certificate is used to verify the extended certificate authentication result.
[0037] As Figure 1 shown, WAPI uses digital certificates to identify the identities of wireless access points (APs) and wireless terminals (STAs), and based on a three-factor authentication system, authenticates the identities of the network side (AP) and the terminal side (STA), ensuring the security of wireless access authentication. As Figure 1 schematically shows the three-factor authentication system of WAPI. In the three-factor authentication system, neither the AP nor the STA trusts each other, and they authenticate together through the WAPI protocol by a third-party authentication unit (i.e., AS) trusted by both parties.
[0038] As Figure 2 shown, it is the certificate authentication result defined in the current WAPI standard, which includes a type value of 0x02, a length, two random numbers, an AP certificate and an authentication result, and an STA certificate and an authentication result. Figure 4 is a schematic diagram of the WAPI certificate authentication response message replied by the AS to the AP, which includes the certificate authentication result, and both the certificate authentication result and the extended certificate authentication result will be signed by the AS with its own private key.
[0039] Generally, the public key certificate of the AS is self-signed and only the AS certificate itself is installed; when the AS receives the WAPI certificate authentication request message and verifies the WAPI certificate, it uses its own AS certificate to sign and verify the certificate to be authenticated, and then transmits the authentication result to the AP and the STA through the authentication result (identification value of 0x02), and signs and protects the authentication result with the private key of the AS; when the AP and the STA receive the authentication result, they use the AS certificate installed locally on the AP or the STA to sign and verify the authentication result.
[0040] Among them, as Figure 3As shown, it illustrates the composition of the extended WAPI certificate authentication result. Among them, the type value field 100 (whose value is 0x04) is used to indicate that this certificate authentication result is an extended certificate authentication result, which is a value not used in the current WAPI standard. The extended certificate authentication result, in addition to the certificate authentication field content stipulated in the current WAPI standard, also includes the AS certificate 400, encapsulated in the certificate field format stipulated in the WAPI protocol, that is, it includes the certificate format type (where 1 is the X509 format certificate), the certificate length, and the certificate content. This certificate format definition is the same as the formats of the AP certificate 200 and the STA certificate 300 included in the certificate authentication result defined in the WAPI standard.
[0041] Among them, as Figure 5 shown, it is the application mode disclosed in this application. The first AS public key certificate installed on the first AS 500 is not self-signed, but is signed with the private key corresponding to the first signer public key certificate (i.e., the root certificate of the first certificate system) by the first certificate system. The first AS 500 also installs the first signer certificate. In this mode, the first AS 500 forms an extended authentication result by using the first certificate issuer public key certificate to verify the signature of the certificate to be authenticated, and signs the extended signature result with the private key of the first AS 500 (paired with the public key in the first public key certificate). In this mode, in order for the first AS 500 to enable the first AP 600 or the first STA 700 to verify the signature of the extended authentication result to ensure that the authentication result is formed by the first AS 500 and has not been tampered with, the first AS 500 transmits its own certificate of the first AS 500 to the first AP 600 and the first STA 700 through the extended certificate authentication result.
[0042] Among them, when the first AP600 receives the certificate authentication response message from the first AS500, the first AP600 first checks whether the certificate authentication result field therein is a general certificate authentication result (identification value is 0x02) or an extended certificate authentication result (identification value is 0x04), and the first AP600 needs to perform a signature check on the authentication result. If the first AP600 does not have the public key certificate of the first AS500, then after receiving the extended authentication result, the first AP600 will use the AS public key certificate 400 in the extended authentication result to verify the signature of the extended authentication result; but at the same time, it is also necessary to verify the credibility of the AS public key certificate 400 in the extended certificate authentication result in order to fully verify the signature of the extended certificate authentication result; and since the AS certificate is signed by the first issuer certificate installed locally by the first AP600, the first AP600 uses the first issuer certificate installed locally to verify the AS certificate in the extended certificate authentication result; and the first issuer certificate installed locally by the first AP600 is self-signed, and the first AP600 can verify the credibility of the first issuer certificate during initialization; in this way, the entire trust chain is complete and sufficient.
[0043] Among them, after the AP600 verifies that the credibility of the certificate authentication result is okay, it will send a WAPI access authentication response message to the wireless terminal first STA700, which includes a composite certificate authentication result. The composite certificate authentication result includes the certificate authentication result (including the general certificate authentication result or the extended certificate authentication result) and the AS signature. Similar to the processing process of the first AP600, if the first STA700 recognizes that the extended certificate authentication result is included in the message, the first STA700 also uses the first issuer certificate installed locally to verify the signature of the AS certificate in the extended certificate authentication result, and then uses the AS certificate in the extended certificate authentication result to verify the signature of the extended certificate authentication result. Combining the verification of the credibility of the self-signed first issuer certificate by the first STA700 during initialization, the entire trust chain is also complete and sufficient.
[0044] In this application, 0x04 is used to identify the extended certificate authentication result. Of course, other numbers can also be used to identify the extended certificate authentication result. At the same time, in this application, the extended certificate authentication result is formed by including the public key certificate of the AS at the end of the general authentication result. Of course, the public key certificate of the AS can also be placed in other field positions of the authentication result, such as after the length field.
[0045] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A WAPI certificate authentication method, including a first WAPI certificate discriminator AS, a first wireless access point AP, and a first wireless terminal STA. The first WAPI certificate discriminator AS, the first wireless access point AP, and the first wireless terminal STA are all installed with WAPI digital certificates and first issuer public key certificates signed and issued by a first certificate system. The first issuer public key certificate is a self-signed root certificate of the first certificate system, and it is characterized in that The WAPI authentication process includes the following two key processing procedures: First, the first WAPI certificate discriminator AS includes the first AS public key certificate. The first WAPI certificate discriminator AS uses the first issuer public key certificate to verify the signature of the WAPI certificate in the WAPI certificate authentication request. After completing the certificate verification, it puts its own WAPI certificate into the certificate discrimination result field and uses the new type value 0x04 to identify the certificate discrimination result, thereby forming an extended certificate discrimination result. Among them, the first AS public key certificate is not self-signed, but is signed by the private key corresponding to the first signer public key certificate by the first certificate system; Second, after the first wireless access point AP and the first wireless terminal STA receive the certificate discrimination result, they determine whether it is an extended certificate discrimination result according to the certificate discrimination result type value. If it is an extended certificate discrimination result, they first use the first issuer public key certificate installed locally to verify the first AS public key certificate in the extended certificate discrimination result. If the first AS public key certificate is trustworthy, they use the first AS public key to verify the extended discrimination result; The first issuer public key certificate, the first AS public key certificate, and the certificates installed on the first wireless access point AP and the first wireless terminal STA are one of the WAPI certificate based on ECDSA192-SHA256 and the national cryptography certificate based on SM2-WITH-SM3.
Citation Information
Patent Citations
WAPI roaming access authentication method, system and access site (AS) server thereof
CN101668292A
WAPI certificate application method, wireless terminal and certificate identifier
CN115278676A