An access authentication system based on the WAPI protocol
By using authentication and secondary authentication methods of the access initiating unit and generating a verified account key using account key time information, the defects of user authentication in the WAPI protocol access authentication system are resolved, and the legitimacy of user identity and the security of data interaction are realized.
Patent Information
- Application Number
- CN202310467754.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-04-27
- Publication Date
- 2025-11-14
- Estimated Expiration
- 2043-04-27
AI Technical Summary
Existing technologies in access authentication systems based on the WAPI protocol lack effective verification of user identity, especially in cases where devices are lost or stolen, failing to ensure the legitimacy of user identities.
Authentication is performed by accessing the initiating unit. The time information of the account key is used for deletion to generate a verified account key. Combined with two-factor authentication, including displaying numerical combinations and time interval requirements, the user's identity is confirmed.
It effectively avoids data interaction in case of key theft, ensures device legitimacy, prevents data interaction by impersonation, and achieves simple and easy-to-use user authentication.
Smart Images

Figure CN116347442B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of access authentication technology, specifically an access authentication system based on the WAPI protocol. Background Technology
[0002] Patent CN102487506A discloses an access authentication method, system, and RADIUS server based on the WAPI protocol. The method includes a wireless access device encapsulating a certificate authentication request packet in a RADIUS request message and sending it to a RADIUS server; the RADIUS server receives and parses the RADIUS request message containing the certificate authentication request packet, performs certificate verification, constructs an authentication response packet based on the verification result, and encapsulates the authentication response packet in a RADIUS challenge message and sends it to the wireless access device. Through the WAPI access authentication method and system of this invention, only one RADIUS server needs to be deployed, which can perform certificate authentication, user authorization, and billing. User deployment is simple, and it achieves a good combination of WAPI authentication and RADIUS authentication.
[0003] This patent presents an access authentication system based on certificate verification, which provides a reasonable verification method from the hardware level. However, it lacks a reasonable solution for verifying the user in cases of device loss or other theft. Therefore, this patent offers a solution. Summary of the Invention
[0004] This invention aims to solve at least one of the technical problems existing in the prior art;
[0005] Therefore, this invention proposes an access authentication system based on the WAPI protocol, comprising:
[0006] The access initiation unit is used to initiate an access request to the target receiving end. When initiating an access request, the access initiation unit needs to perform identity verification. By determining the method of deleting the account key based on the time when the user enters the account and account key, the final verified account key is obtained.
[0007] After obtaining the verified account key, the access initiation unit will transmit the account with the time of account key entry and the verified account key to the authentication unit;
[0008] When the authentication unit receives the account, verified account key and entered account key transmitted by the access initiation unit, it will first retrieve the standard account key set for the corresponding account from the database, and process the standard account key in the same way as the time of the entered account key. The processed account key will be compared with the transmitted verified account key. If they match, an initial connection signal will be generated.
[0009] After generating the initial signal, the authentication unit will connect to the target receiver through the verification unit and access the target receiver, which is the corresponding device that needs to be accessed.
[0010] Furthermore, the specific methods for identity verification are as follows:
[0011] After initiating an access request, the user needs to enter their account and its corresponding account key;
[0012] After the user enters the account key, the account key will be processed automatically. First, the account key will be obtained, and then the time when the user entered the account key will be obtained automatically.
[0013] The time is obtained by taking the time as the time, and then the number representing each time is obtained by taking the first number to the last number to get the time representative value Ti, i = 1, ..., 8; T1 to T8 represent the numbers of the corresponding time.
[0014] Then, the time representation value Ti is obtained, summed, and the sum is marked as the time sum value;
[0015] When the sum is odd, characters with odd-numbered sequential values in the account key will be automatically deleted, and the remaining characters will be marked as the verified account key. The sequential value is the sequential number obtained by simply arranging the account key in order. When the sum is not odd, the other characters will be deleted to obtain the verified account key.
[0016] Furthermore, the specific authentication method exists only on the access initiation unit designated by the administrator; unauthorized devices do not have this authentication method.
[0017] Furthermore, when the verification unit connects to the target receiving end, it only accesses a virtual target receiving end, which is a virtual port forged by the administrator.
[0018] Furthermore, it also includes an access unit, which is used to connect the authentication unit and the target receiver.
[0019] Furthermore, after the verification unit connects to the virtual target receiver, it returns a secondary verification signal to the authentication unit. At this point, the authentication unit and the verification unit perform joint verification. The specific method of joint verification is as follows:
[0020] S1: First, obtain the hour and the value, mark the value of the units digit as the interval index value, and mark the value of the tens digit as the repetition index value;
[0021] S2: If a duplicate value is found, mark it as X1 if it is less than or equal to X1; otherwise, do nothing.
[0022] S3: Obtain the new interval direction value and repetition direction value, combine the two in the order of repetition direction value first and interval direction value last, and display them to the user of the access initiating unit for observation;
[0023] S4: And return the combination of the repeating value and the interval pointer value to the authentication unit;
[0024] S5: When a user observes a combination of repeated direction value and interval direction value, the user needs to mark it as the first information after initiating the first request information after access. The first information is the content information entered by the user when accessing the target receiving end through the access initiation unit.
[0025] S6: After sending the initial information, the user needs to use the access initiation unit to retransmit the initial information to the authentication unit after the corresponding interval value time has elapsed, until the number of times the initial information is sent is consistent with the repeated value after removing the first initial information. The time here is in seconds.
[0026] S7: When the authentication unit detects the process of step S6 and satisfies the repeatability value and the interval indicator value, it generates an allow signal;
[0027] After a permission signal is generated, the authentication unit will connect with the target receiver through the access unit to conduct real access; before a permission signal is generated, the authentication unit can only access the virtual target receiver through the authentication unit and cannot obtain real information or conduct data exchange.
[0028] Furthermore, X1 in step S2 is a preset value.
[0029] Furthermore, it also includes a management unit, which is connected to the verification unit and is used to input all preset values.
[0030] Compared with the prior art, the beneficial effects of the present invention are:
[0031] This invention performs identity verification when the access initiation unit initiates an access request. By determining the method of deleting the account key based on the time when the user enters the account and account key, the final verified account key is obtained. The verification method is set according to the specified device to determine that the device used by the user is a legitimate device.
[0032] Then, through secondary verification, a two-digit command is sent to the user who understands the information. The user needs to perform the operation according to the command to confirm the user's identity. This prevents the data interaction with the target receiving end in the event that the key is stolen. At the same time, it can also prevent other users from impersonating others to interact with the data after obtaining legitimate devices in some unreasonable way. This invention is simple, effective and easy to use. Attached Figure Description
[0033] Figure 1 This is a system block diagram of the present invention. Detailed Implementation
[0034] The technical solution of the present invention will be clearly and completely described below with reference to the embodiments. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0035] Please see Figure 1 This application provides an access authentication system based on the WAPI protocol;
[0036] As an embodiment of the present invention, it specifically includes an access initiation unit, an authentication unit, a verification unit, and a target receiving end;
[0037] The access initiating unit is used to initiate an access request to the target receiving end. The two are connected based on the WAPI protocol and are located in the same wireless local area network. When initiating the access request, the access initiating unit needs to perform authentication. The specific authentication method is as follows:
[0038] After initiating an access request, the user needs to enter their account and its corresponding account key;
[0039] After the user enters the account key, the account key will be processed automatically. First, the account key will be obtained, and then the time when the user entered the account key will be obtained automatically.
[0040] The time is obtained by retrieving the time representation value based on the month, day, hour, and minute. Then, the numbers representing each time are obtained, and the first number is sequentially assigned to the last number to obtain the time representation value Ti, i = 1, ..., 8. T1 to T8 represent the numbers corresponding to the time. For example, if the time is 15:36 on December 28, then T1 to T8 are represented as the numbers 1, 2, 2, 8, 1, 5, 3, and 6 respectively.
[0041] Then, the time representation value Ti is obtained, summed, and the sum is marked as the time sum value;
[0042] When the sum is odd, characters with odd-numbered sequential values in the account key will be automatically deleted, and the remaining characters will be marked as the verified account key. The sequential value is the sequential number obtained by simply arranging the account key in order. When the sum is not odd, the other characters will be deleted to obtain the verified account key.
[0043] After obtaining the verified account key, the access initiation unit will transmit the account with the time of account key entry and the verified account key to the authentication unit;
[0044] The specific authentication method exists only on the access initiation unit specified by the administrator; other devices do not have this type of authentication method.
[0045] When the authentication unit receives the account, verified account key and entered account key transmitted by the access initiation unit, it will first retrieve the standard account key set for the corresponding account from the database, and process the standard account key in the same way as the time of the entered account key. The processed account key will be compared with the transmitted verified account key. If they match, an initial connection signal will be generated.
[0046] After generating the initial signal, the authentication unit will connect to the target receiver through the verification unit and access the target receiver, which is the corresponding device that needs to be accessed.
[0047] Of course, as a second embodiment of the present invention, based on the first embodiment, this application also includes an access unit. The access unit is used to connect the authentication unit and the target receiving end. When the access unit is present, the authentication unit only accesses the virtual target receiving end when connecting to the target receiving end. The target receiving end is a virtual port forged by the administrator.
[0048] At this point, the verification unit will return a secondary verification signal to the authentication unit. The authentication unit and the verification unit will then perform joint verification, which will be conducted as follows:
[0049] S1: First, obtain the hour and the value, mark the value of the units digit as the interval index value, and mark the value of the tens digit as the repetition index value;
[0050] S2: Obtain duplicate values. If each value is less than or equal to X1, mark it as X1. Here, X1 is a preset value, usually 2. Otherwise, do not process it.
[0051] S3: Obtain the new interval direction value and repetition direction value, combine the two in the order of repetition direction value first and interval direction value last, and display them to the user of the access initiating unit for observation;
[0052] S4: And return the combination of the repeating value and the interval pointer value to the authentication unit;
[0053] S5: When a user observes a combination of repeated direction value and interval direction value, the user needs to mark it as the first information after initiating the first request information after access. The first information is the content information entered by the user when accessing the target receiving end through the access initiation unit.
[0054] S6: After sending the initial information, the user needs to use the access initiation unit to retransmit the initial information to the authentication unit after the corresponding interval value time has elapsed, until the number of times the initial information is sent is consistent with the repeated value after removing the first initial information. The time here is in seconds.
[0055] S7: When the authentication unit detects the process of step S6 and satisfies the repeatability value and the interval indicator value, it generates an allow signal;
[0056] After a permission signal is generated, the authentication unit will connect with the target receiver through the access unit to perform real access; before a permission signal is generated, the authentication unit can only access the virtual target receiver through the authentication unit and cannot obtain real information or perform data exchange.
[0057] It should be noted that Embodiment 2 is implemented based on Embodiment 1.
[0058] It also includes a management unit, which is connected to the verification unit and is used to input all preset values.
[0059] The data in the above formula are all calculated by removing the dimensions and taking the numerical values. The formula is the closest to the real situation obtained by software simulation of a large amount of collected data. The preset parameters and preset thresholds in the formula are set by those skilled in the art according to the actual situation or obtained through simulation of a large amount of data.
[0060] The above embodiments are only used to illustrate the technical methods of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical methods of the present invention without departing from the spirit and scope of the technical methods of the present invention.
Claims
1. An access authentication system based on the WAPI protocol, characterized in that, include: The access initiation unit is used to initiate an access request to the target receiving end. When initiating an access request, the access initiation unit needs to perform identity verification. After determining the method of deleting the account key based on the time when the user enters the account and account key, the final processed and verified account key is obtained. After obtaining the verified account key, the access initiation unit will transmit the account with the time of account key entry and the verified account key to the authentication unit; When the authentication unit receives the account, verified account key and entered account key transmitted by the access initiation unit, it will first retrieve the standard account key set for the corresponding account from the database, and process the standard account key in the same way as the authentication based on the time of the entered account key. The processed result is compared with the transmitted verified account key. If they match, an initial connection signal is generated. After generating the initial connection signal, the authentication unit connects to the target receiver via the verification unit, which is the corresponding device that needs to be connected. After connecting to the virtual target receiver, the verification unit returns a secondary verification signal to the authentication unit. At this time, the authentication unit and the verification unit perform joint verification. The specific method of joint verification is as follows: S1: First, obtain the hour and the sum value, mark the value of the units digit as the interval index value, and mark the value of the tens digit as the repetition index value; S2: If a duplicate value is found, mark it as X1 if it is less than or equal to X1; otherwise, do nothing. S3: Obtain the new interval direction value and repetition direction value, combine the two in the order of repetition direction value first and interval direction value last, and display them to the user of the access initiating unit for observation; S4: And return the combination of the repeating value and the interval pointer value to the authentication unit; S5: When a user observes a combination of repeated direction value and interval direction value, the user needs to mark it as the first information after initiating the first request information after access. The first information is the content information entered by the user when accessing the target receiving end through the access initiation unit. S6: After sending the initial information, the user needs to use the access initiation unit to retransmit the initial information to the authentication unit after the corresponding interval value time has elapsed, until the number of times the initial information is sent is consistent with the repeated value after removing the first initial information. The time here is in seconds. S7: When the authentication unit detects the process of step S6 and satisfies the repeatability value and the interval indicator value, it generates an allow signal.
2. The access authentication system based on the WAPI protocol according to claim 1, characterized in that, The specific methods for identity verification are as follows: After initiating an access request, the user needs to enter their account and its corresponding account key; After the user enters the account key, the account key will be processed automatically. First, the account key will be obtained, and then the time when the user entered the account key will be obtained automatically. The time is obtained by retrieving the time representation value based on the month, day, hour, and minute. Then, the number representing each time is obtained, and the first number is sequentially assigned to the last number to obtain the time representation value Ti, i=1, ..., 8; T1 to T8 represent the corresponding numbers of the time. Then, the time representation value Ti is obtained, summed, and the sum is marked as the time sum value; When the sum is odd, characters with odd-numbered sequential values in the account key will be automatically deleted, and the remaining characters will be marked as the verified account key. The sequential value is the sequential value obtained by simply arranging the account key in order. When the sum is not odd, the other characters will be deleted to obtain the verified account key.
3. The access authentication system based on the WAPI protocol according to claim 2, characterized in that, The specific authentication method exists only on the access initiation unit designated by the administrator; unauthorized devices do not have this authentication method.
4. The access authentication system based on the WAPI protocol according to claim 1, characterized in that, When the verification unit connects to the target receiving end, it only accesses a virtual target receiving end, which is a virtual port forged by the administrator.
5. The access authentication system based on the WAPI protocol according to claim 4, characterized in that, It also includes an access unit, which is used to connect the authentication unit and the target receiver.
6. The access authentication system based on the WAPI protocol according to claim 5, characterized in that, After generating the permission signal, the authentication unit will connect with the target receiver through the access unit to perform real access; Before a permission signal is generated, access to the virtual target receiver can only be made through the verification unit, and real information cannot be obtained or data exchange can be carried out.
7. The access authentication system based on the WAPI protocol according to claim 6, characterized in that, In step S2, X1 is a preset value.
8. The access authentication system based on the WAPI protocol according to claim 7, characterized in that, It also includes a management unit, which is connected to the verification unit and is used to input all preset values.
Citation Information
Patent Citations
Access authentication method, system and server based on WAPI (wireless local access network authentication and privacy infrastructure) protocol
CN102487506A
Intelligent encryption transmission system for computer information data
CN111800387A