A WAPI terminal security certificate system implementation method
By introducing the interaction between the security chip and the main chip in WAPI communication, the security and deployment convenience issues of WAPI certificates are solved, enabling secure and rapid deployment of WAPI communication, ensuring that certificate private keys are not stolen, and improving the management and application efficiency of WAPI networks.
Patent Information
- Application Number
- CN202310180638.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-28
- Publication Date
- 2025-12-05
- Estimated Expiration
- 2043-02-28
AI Technical Summary
The security and ease of deployment of certificates in existing WAPI communication are insufficient, especially the security of certificate private keys is difficult to guarantee, which affects the security and deployment efficiency of WAPI communication.
The system utilizes the interaction between a security chip and the terminal's main chip to issue and authenticate WAPI certificates. Leveraging the uniqueness and difficulty in theft of the security chip, it generates and manages WAPI certificates, ensuring certificate security and providing management and device binding capabilities during deployment.
It improves the security and deployment efficiency of WAPI communication, ensures that certificates and private keys are not stolen, and enables rapid deployment and management of WAPI networks, facilitating batch applications.
Smart Images

Figure CN116347446B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application is a kind of WAPI terminal security certificate system implementation method, using system can combine security chip technology and WAPI communication, solve WAPI certificate import, private key storage and other problems, make WAPI communication is safe and reliable, and solve the convenience problem of WAPI use in deployment solution. BACKGROUND
[0002] WAPI is a kind of security protocol, WAPI adopts two-way authentication encryption technology, and adopts the elliptic curve cipher algorithm of public key system and the group cipher algorithm of secret key system approved by the office of the State Cryptography Administration, realizes the identity authentication of equipment, link verification, access control and encryption protection of user information in the state of wireless transmission, so the technology can well solve the problems of secure access and secure communication.
[0003] WAPI communication is based on certificate verification communication, and the use and security of WAPI certificate is very important, the present application combines the use of security chip, solves the security problem of WAPI certificate, and provides a solution for fast deployment and convenient operation of equipment.
[0004] CN200910021418.X relates to a method for realizing convergent WAPI network architecture in local MAC mode, which comprises the following steps: 1) constructing local MAC mode; separating the MAC function and WAPI function of a wireless access point to a wireless terminal point and an access controller respectively; 2) realizing the fusion of WAPI protocol and convergent WLAN network architecture in local MAC mode; 2.1) the association connection process between a station and the wireless terminal point and the access controller; 2.2) the announcement process of the start of WAI protocol execution between the access controller and the wireless terminal point; 2.3) the execution process of WAI protocol between the station and the access controller; 2.4) the announcement process of the end of WAI protocol execution between the access controller and the wireless terminal point; 2.5) the process of using WPI for secure communication between the wireless terminal point and the station. The present application not only can meet the large-scale deployment demand of WLAN, but also can guarantee the security of WLAN under convergent architecture.
[0005] CN200710019092.8 relates to a WAPI unicast key negotiation method. The method steps are as follows: 1. The authenticator entity adds a message integrity code on the unicast key negotiation request packet, and sends it to the authentication requester entity; 2. The authentication requester entity receives the unicast key negotiation request packet, and verifies it. If the verification is incorrect, the packet is directly discarded; if the verification is correct, other verifications are performed. If the verification is successful, the authentication requester entity sends a unicast key negotiation response packet to the authenticator entity; 3. The authenticator entity receives the unicast key negotiation response packet, and verifies it. If the verification is successful, the authenticator entity sends a unicast key negotiation confirmation packet to the authentication requester entity; 4. The authentication requester entity receives the unicast key negotiation confirmation packet, and verifies it. If the verification is successful, a consistent unicast session key is negotiated. The present application solves the DOS attack problem existing in the unicast key management protocol in the current WAPI security mechanism.
[0006] CN200910000198.2 discloses a WAPI terminal access IMS network security management method and system. The method comprises the following steps: in the case that the access point and the WAPI terminal are verified by the ASU, the ASU sends a security information request message to the HSS, wherein the security information request message carries the IMS (IP Multimedia Subsystem) account information of the WAPI terminal; after receiving the security information request message of the ASU, the HSS sets the security information corresponding to the IMS account information of the WAPI terminal as access layer security; the P-CSCF receives the IMS registration request message from the WAPI terminal, queries the security information of the WAPI terminal through the HSS, and allows the WAPI terminal to execute the IMS service process in the case that the security information of the WAPI terminal is access layer security. The present application can reduce the power consumption of the WAPI terminal and improve the user experience under the premise of ensuring the security of the IMS system. SUMMARY
[0007] The present application aims at providing a WAPI terminal security certificate system implementation method, which protects the key data certificate of WAPI communication, and the WAPI certificate private key cannot be derived and used.
[0008] The technical scheme of the present application is: a WAPI terminal security certificate system implementation method, which is composed of a terminal (STA), an access terminal (AP) and an authentication server (AS), wherein the AP is a standard device without any modification; a security chip is added to the terminal (STA), the security chip runs an on-chip operating system (COS) program and interacts with the terminal main chip, a corresponding WAPI certificate management program and a WAPI connection program are run on the terminal, the management, authentication and establishment of the WAPI certificate are realized through the interaction of the program and the authentication server, and finally the WAPI communication is realized; 1) the terminal comprises a main chip, a security chip connected and controlled by the main chip and a radio frequency chip; 2) the security chip generates a hardware random number, provides a unique identification code, generates a key pair required by the WAPI protocol, saves a private key and a WAPI related certificate, and completes the private key related calculation of the WAPI protocol; the main chip controls the security chip to complete the key generation, the public key / hardware random number / unique serial number acquisition, the certificate writing / acquisition and the signature calculation;
[0009] 3) In the certificate issuance process of the WAPI communication, the main chip is responsible for the certificate issuance process; the ECC key generation is completed by the security chip when the certificate is issued, the unique serial number of the security chip is used as an identifier for the certificate application, and the private key related operations in the certificate issuance process are completed in the security chip;
[0010] 4) The AS completes the certificate issuance together with the terminal certificate issuance process, completes the certificate authentication in the WAPI communication, and manages the terminal through the chip serial number;
[0011] 5) In the certificate authentication process of the WAPI communication, the main chip controls the WAPI authentication process, and the security chip is responsible for providing related certificates, generating hardware random numbers, and performing signature calculation to configure the authentication process. The certificates required by the authentication process are provided by the security chip, the private key calculation is completed in the security chip, and other calculations and verifications are completed by the main chip.
[0012] Advantages: through the interaction of the security chip and the terminal main chip, the issuance and authentication of the WAPI certificate are realized, the security chip data is difficult to steal, the security of the WAPI certificate is ensured, the management and deployment are improved by using the uniqueness of the security chip, the security and confidentiality of data communication are improved, and the application prospect is good. The present application protects the key data certificate of the WAPI communication by using the characteristics that the content of the security chip is difficult to obtain, the WAPI certificate private key is not exported for use, the security of the WAPI communication is improved, the certificate is applied for by using the unique serial number of the security chip in the issuance process, the AS can bind the device and manage the device, the independence of the security chip is utilized, the certificate can be issued in batches and applied to the device, and the WAPI authentication process is directly used to improve the rapid deployment ability of the WAPI network. BRIEF DESCRIPTION OF DRAWINGS
[0013] Figure 1 is the terminal WAPI certificate issuing flow chart in the present application.
[0014] Figure 2 is the terminal WAPI certificate authentication flow chart in the present application. DETAILED DESCRIPTION
[0015] The present application is further explained in connection with the accompanying drawings and implementation examples.
[0016] The main chip completes the processes of certificate request, request signature, request encryption, certificate issuing, certificate installation and the like in the WAPI certificate issuing process through the interaction with the security chip, thereby ensuring the security of the certificate from the issuing process;
[0017] The main chip completes the processes of certificate acquisition, access authentication request data generation and signature, certificate verification and signature verification, key exchange and the like in the WAPI authentication process through the interaction with the security chip, thereby ensuring the security of the certificate in the authentication process.
[0018] Reference is made to the terminal WAPI certificate issuing flow chart and the terminal WAPI certificate authentication flow chart used in the present application.
[0019] The present application describes a WAPI terminal security certificate system implementation method, which comprises the following steps:
[0020] Firstly, the terminal system described in the present application comprises a main chip (CPU or embedded microprocessor), a security chip and a radio frequency chip; the main chip and the security chip are connected using a communication interface such as I2C / SDIO / USB / RS232; the main chip is responsible for the WAPI certificate management process, WAPI connection control and WAPI communication; and the security chip is responsible for the storage and operation related to the certificate.
[0021] Secondly, the terminal WAPI certificate issuing flow chart is shown in the accompanying Figure 1The process is (1) downloading the root certificate from the AS, transmitting to the secure chip through the main chip and storing; (2) the main chip (generally ARM / RISC-V / MIPS embedded application processor) sends a command to the secure chip (generally a microcontroller such as Cortex-M0) through the communication interface, and the secure chip generates a 192-bit ECC key pair, and the parameter OID is 1.2.156.11235.1.1.2.1 used by the WAPI protocol; (3) the main chip sends the public key data and the unique serial number of the secure chip to obtain the command, and generates a certificate request file in ASN1 format; (4) the main chip calculates the SHA256 hash data of the request file; (5) the hash data is sent to the secure chip by the main chip, and the secure chip uses the private key of the ECC key pair to perform signature operation using the ECC algorithm to obtain the signature result, and sends the signature result to the main chip; (6) the main chip receives the signature data and merges it with the previous request file to form an unencrypted certificate request file, which contains the public key part of the ECC key generated by the secure chip and the signature data; then an encrypted request file is generated by using the AS root certificate public key encryption calculation; (7) the request file is sent to the AS, and the AS uses its own private key to decrypt and check the signature of the request data to ensure the validity of the signature, and then generates a certificate file and records the serial number of the certificate; (8) after downloading the certificate file, the main chip transmits it to the secure chip and stores it.
[0022] Third, the terminal WAPI certificate authentication process is shown in the accompanying Figure 2 The process is (1) the main chip sends an association request through the radio frequency module; (2) the AP initiates authentication activation data after receiving the request; (3) the main chip obtains the ASUE certificate from the secure chip and the hardware random number generated by the secure chip; (4) the main chip generates a non-signed access authentication request data according to the requirements of the WAPI protocol using the ASUE certificate and the hardware random number generated by the secure chip; then calculates the SHA256 hash of the request data; (5) the calculated hash data is sent to the secure chip to run the ECC192 signature calculation, and the result of the signature calculation is returned to the main chip; (6) the main chip generates a complete access authentication request by combining the previously generated non-signed WAPI access authentication request data with the signature data returned by the secure chip, and then sends it to the AP through the terminal radio frequency module; (7) the AP sends a certificate authentication request to the AS, and the AS returns a certificate authentication result, which is authenticated by the AP and then sent to the terminal main chip; (8) the main chip obtains the AS certificate from the secure chip and completes the certificate verification and signature verification; (9) continue the key exchange and other processes of the WAPI authentication.
[0023] The above merely preferred embodiments of the present application, for those skilled in the art, without departing from the principles of the present application, can also be made several modifications and refinements, these improvements and refinements should also be considered as the protection scope of the present application.
Claims
1. A method for implementing a WAPI terminal security certificate system, characterized in that, It consists of a terminal STA, an access point AP, and an authentication server AS. The AP is a standard device. The terminal STA is equipped with a security chip. The security chip runs an on-chip operating system (COS) and interacts with the main terminal chip. The main chip and the security chip are connected using I2C / SDIO / USB / RS232 communication interfaces. The main chip is responsible for the WAPI certificate management process, WAPI connection control, and WAPI communication. The security chip is responsible for storing and operating certificate-related data; Run the corresponding WAPI certificate management program and WAPI connection program on the terminal. Through the interaction between the program and the authentication server, the WAPI certificate is managed, authenticated, and a WAPI connection is established, ultimately enabling WAPI communication. Specifically: 1) The terminal includes a main chip and a security chip and radio frequency chip connected and controlled by the main control chip; 2) The security chip generates hardware random numbers, provides a unique identification code, generates the key pair required by the WAPI protocol, stores the private key and WAPI-related certificates, and completes the private key related calculations of the WAPI protocol; The main chip controls the security chip to complete key generation, public key / hardware random number / unique serial number acquisition, certificate writing / acquisition, and signature calculation; 3) In the certificate issuance process of WAPI communication, the main chip is responsible for the certificate issuance process; When issuing a certificate, the ECC key is generated by the security chip. The certificate application is identified by the unique serial number of the security chip. All private key-related operations during the certificate issuance process are completed by the security chip. 4) AS works with the terminal certificate issuance process to complete certificate issuance, performs certificate authentication in WAPI communication, and manages the terminal through the chip serial number; 5) During the certificate authentication process of WAPI communication, the main chip controls the WAPI authentication process, while the security chip is responsible for providing relevant certificates, hardware random number generation, and signature calculation configuration for the authentication process. The certificates required for the authentication process are provided by the security chip, and the calculation of the private key is completed by the security chip.
2. The method according to claim 1, characterized in that, The main chip is responsible for the WAPI certificate management process, WAPI connection control, and WAPI communication; The security chip is responsible for storing and operating certificate-related data; Terminal WAPI certificate issuance process: (1) Download the root certificate from AS, transmit it to the security chip through the main chip and store it; (2) The main chip is an ARM / RISC-V / MIPS embedded application processor that sends a command to the security chip Cortex-M0 microcontroller through the communication interface. The security chip generates a 192-bit ECC key pair with the parameter OID being 1.2.156.11235.1.1.2.1 used by the WAPI protocol; (3) The main chip sends an acquisition command to the security chip to obtain the public key data and the security chip's unique serial number, and generates a certificate request file using the ASN1 format; (4) The main chip calculates the SHA256 hash data of the request file; (5) The hash data is sent from the main chip to the security chip. The security chip uses the private key of the ECC key pair to perform a signature operation using the ECC algorithm to obtain the signature result, and sends the signature result to the main chip; (6) The main chip receives the signature data and merges it with the previous request file to form an unencrypted certificate request file. This request file contains the public key part of the ECC key generated by the security chip and the signature data. Then, the AS root certificate public key is used to encrypt and calculate to generate an encrypted request file; (7) The request file is sent to the AS, which decrypts it using its own private key and checks the request data using the device public key data in the request. After ensuring that the signature is valid, a certificate file is generated and the certificate serial number is recorded; (8) After the certificate file is downloaded, it is transmitted to the security chip through the main chip and stored.
3. The method according to claim 1, characterized in that, The terminal WAPI certificate authentication process is as follows: (1) The main chip sends an association request through the radio frequency module; (2) After receiving the request, the AP initiates authentication activation data; (3) The main chip obtains the ASUE certificate and random number from the security chip; (4) Generates unsigned access authentication request data and generates SHA256 hash data; (5) The hash data is sent to the security chip for signature calculation and the signature result is obtained; (6) Merge the signatures to generate a complete access authentication request, and then send it to the AP via the radio frequency module; (7) The AP sends a certificate authentication request to the AS, the AS returns the certificate authentication result, and the AP sends an access authentication response to the terminal main chip after authentication. (8) The main chip obtains the AS certificate from the security chip and completes certificate verification and signature verification; (9) Continue the key exchange process for WAPI authentication.
Citation Information
Patent Citations
WAPI single broadcasting key negotiation method
CN101159543A
Security management method and system for IMS network access by WAPI terminal
CN101478753B
Method for realizing convergence WAPI network architecture in local MAC mode
CN101577978A
Wireless router based on WAPI hardware encryption chip
CN101754198A
Authentication accelerator and high-speed authentication method based on wireless LAN authentication and privacy infrastructure (WAPI)
CN102014380A