Method for automatically accessing wireless terminal to wireless authentication and privacy infrastructure (WAPI) network
By importing CIS information in the WAPI wireless terminal and configuring SSID in the certificate issuer database, the trustworthiness check between the wireless terminal and the certificate issuer is solved, and the problem that the WAPI wireless terminal cannot automatically connect to the WAPI wireless network is improved, and the deployment efficiency is improved.
Patent Information
- Application Number
- CN202510161749.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-13
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-02-13
AI Technical Summary
In the prior art, WAPI wireless terminals cannot automatically connect to WAPI wireless networks, and cannot achieve plug-and-play, resulting in low deployment efficiency.
By importing the first CIS information in the wireless terminal and configuring the service SSID of the wireless terminal in the database of the WAPI certificate issuer, the trustworthiness check between the wireless terminal and the WAPI certificate issuer is realized, and the WAPI digital certificate and SSID configuration are automatically obtained.
It realizes the automatic connection of wireless terminals to WAPI wireless network, improves the deployment efficiency of WAPI wireless terminals, and solves the problem of not being able to automatically apply for WAPI digital certificates online.
Smart Images

Figure CN119946636A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network communication technology, and in particular to a method for a wireless terminal to automatically access a WAPI network. Background Art
[0002] WAPI (Wireless LAN Authentication and Privacy Infrastructure) is a WLAN wireless security standard and technology. It uses digital certificates to identify the identities of wireless access points (APs), wireless terminals (STAs), and WAPI certificate authenticators (ASs). It performs identity authentication of wireless access points and wireless terminals based on a three-factor authentication system, thus ensuring the security of wireless access authentication. In a wireless LAN that uses WAPI digital certificate authentication, both wireless access points and wireless terminals need to install WAPI digital certificates to perform three-factor authentication, and the terminals can access the wireless network.
[0003] However, there is a method in the related art for online application of a WAPI digital certificate based on the WAPI authentication process interaction through the WAPI wireless network to be accessed, but this method has the following defects: (1) The specific authentication information and authentication method are not published or prompted, that is, the authorization authentication information contained in the first certificate and the authorization check method corresponding to the WAPI certificate identifier are not disclosed or prompted. (2) The wireless terminal cannot check the credibility of the certificate issuer, that is, the WAPI certificate identifier sends the wireless terminal's certificate and the WAPI certificate identifier's certificate to the wireless terminal based on the authentication result, but the wireless terminal has no information to check the credibility of the WAPI certificate identifier. (3) After obtaining the WAPI certificate, the wireless terminal still cannot automatically connect to the wireless network because the wireless terminal has no SSID (Service Set Identifier) configuration.
[0004] Based on the above problems, WAPI wireless terminals still cannot automatically connect to the WAPI wireless network, and a large number of wireless sensors cannot be plug-and-play, which ultimately leads to low deployment efficiency of WAPI wireless terminals. Summary of the invention
[0005] The purpose of this application is to provide a method for automatically accessing a WAPI network by a wireless terminal, which can enable a WAPI wireless terminal to automatically connect to a WAPI wireless network, realize plug-and-play, and improve the deployment efficiency of the WAPI wireless terminal.
[0006] To achieve the above objectives, this application provides the following solutions:
[0007] The present application provides a method for automatically accessing a WAPI network by a wireless terminal, including a wireless terminal, a wireless access point, a WAPI certificate identifier and a WAPI certificate issuer, wherein the WAPI certificate identifier has its own public key certificate, namely, a first AS certificate, and the WAPI certificate issuer has a first CIS key pair and first CIS information, and also stores the first AS certificate, wherein the first CIS information includes the CIS information and the CIS public key of the WAPI certificate issuer, and the CIS public key is the public key of the first CIS key pair;
[0008] The method for automatically accessing a WAPI network by a wireless terminal includes:
[0009] S1: In a stage before starting service communication, especially in a production stage, the first CIS information is imported into the wireless terminal, the wireless terminal generates a first STA key pair and first STA information, and the first STA information is derived from the wireless terminal, wherein the first STA information includes identification information of the wireless terminal and a STA public key, and the STA public key is a public key of the first STA key pair;
[0010] S2: before starting service communication, importing the first STA information into the first database of the WAPI certificate issuer to form a wireless terminal table entry, and configuring the service SSID corresponding to the wireless terminal in the wireless terminal table entry;
[0011] S3: In the post-power-on stage in the business environment, the wireless terminal connects to any SSID of the WAPI-CERT authentication mode in the business environment, and performs a WAPI authentication with the wireless access point. During this WAPI authentication process, the application intention and application information are carried through the extended attributes of the first STA certificate in the access certificate authentication request message, and the issuance result generated by the WAPI certificate issuer when issuing and the business SSID configuration information are carried through the authentication result field in the certificate authentication response message; the application intention refers to the certificate extension item of the STA digital certificate including a specific OID, and thereby indicating to the WAPI certificate authenticator that the intention of the current WAPI access authentication request is to apply for a digital certificate for the wireless terminal; the The application information includes the first STA information, the certificate application file and the signature information, wherein the signature information is generated by the wireless terminal using the private key of the first STA key pair to perform a signature calculation on the content including the first STA information and the certificate application file; the issuance result includes an issuance processing result value and a second STA certificate, wherein the issuance processing result value is used to indicate whether the issuance is successful or unsuccessful, the second STA certificate is a self-signed digital certificate generated by the WAPI certificate issuer based on the first CIS key pair, the second STA certificate includes the issuance processing result value, a third STA certificate and the first AS certificate, and the third STA certificate is a WAPI digital certificate issued by the WAPI certificate issuer to the wireless terminal;
[0012] S4: the WAPI certificate issuer searches the first database for the wireless terminal entry according to the application information, and checks the credibility of the wireless terminal according to the STA public key recorded in the wireless terminal entry;
[0013] S5: The wireless terminal checks the credibility of the WAPI certificate issuer according to the CIS public key in the first CIS information stored locally.
[0014] Preferably, the process of the wireless terminal automatically obtaining the WAPI digital certificate from the WAPI certificate issuer specifically includes:
[0015] After the wireless terminal is powered on in the service environment, it scans and associates the SSID of the WAPI-CERT authentication mode, and performs WAPI authentication with the connected wireless access point;
[0016] The wireless terminal generates a first STA certificate during the WAPI authentication process, wherein the first STA certificate includes an application intention extension item and an application information extension item;
[0017] The WAPI certificate identifier authenticates the first STA certificate, identifies the application intention of the wireless terminal, and sends a certificate issuance application to the WAPI certificate issuer, where the certificate issuance application includes the first STA certificate;
[0018] After receiving the certificate issuance application, the WAPI certificate issuer performs issuance processing on the first STA certificate and generates an issuance result;
[0019] After receiving the issuance result, the WAPI certificate identifier generates an authentication result, the verification result of the ASUE certificate in the authentication result is equal to the issuance processing result value, and the ASUE certificate is the second STA certificate;
[0020] The wireless access point sends an access authentication response message to the wireless terminal according to a standard process, wherein the access authentication response message includes the authentication result;
[0021] After the wireless terminal receives the access authentication response message, it obtains the issuance processing result value according to the verification result of the ASUE certificate in the authentication result, and when the issuance processing result value is successful issuance, it parses the ASUE certificate in the authentication result to obtain the second STA certificate, and obtains the third STA certificate, the first AS certificate and the service SSID configuration information from the extension information in the second STA certificate, wherein the third STA certificate is the WAPI certificate of the wireless terminal.
[0022] Preferably, the process of the wireless terminal generating the first STA certificate specifically includes:
[0023] The wireless terminal generates a second STA key pair;
[0024] The wireless terminal generates a certificate application file, namely a P10 file, according to the second STA key pair;
[0025] The wireless terminal generates a self-signed first STA certificate according to the first STA key pair; the first STA certificate includes an application intention extension item and an application information extension item, wherein the application information extension item includes the content of the first STA information, the information content of the P10 file and signature information, and the signature information is signed by using the private key of the first STA key pair for the content including the first STA information and the P10 file;
[0026] Based on the first STA certificate, the wireless terminal sends a certificate authentication request for WAPI authentication to the wireless access point.
[0027] Preferably, the process of the WAPI certificate issuer issuing a WAPI digital certificate specifically includes:
[0028] The WAPI certificate issuer parses the application information from the first STA certificate;
[0029] The WAPI certificate issuer searches for the corresponding wireless terminal table entry in the first database according to the first STA information. When the corresponding wireless terminal table entry is found, the STA public key recorded in the wireless terminal table entry is used to verify the signature in the application information; if the verification is successful, the wireless terminal generates a WAPI digital certificate, namely the third STA certificate; finally, a issuance result is formed, and the issuance result includes an issuance processing result value, the third STA certificate and the first AS certificate, wherein the issuance processing result value is used to indicate successful issuance or unsuccessful issuance. When the issuance is successful, the issuance result value is 100, otherwise a value greater than 100 is used to indicate other unsuccessful reasons, including failure to find the corresponding wireless terminal table entry, failure to pass the signature verification and failure to generate the WAPI digital certificate of the wireless terminal;
[0030] The WAPI certificate issuer generates a self-signed digital certificate, namely the second STA certificate, based on the first CIS key pair, which includes an issuance processing result extension item and a service SSID configuration extension item, wherein the issuance processing result extension item includes the issuance processing result, and the service SSID configuration extension item includes the service SSID configuration information recorded in the wireless terminal table item;
[0031] The WAPI certificate issuer replies the issuance result to the WAPI certificate authenticator.
[0032] Preferably, the process of the wireless terminal processing the issuance result specifically includes:
[0033] After receiving the access authentication response message, the wireless terminal checks the authentication result value in the authentication result;
[0034] When the authentication result value indicates that the issuance is successful, the wireless terminal parses the second STA certificate from the authentication result, and uses the CIS public key in the first CIS information stored locally to perform signature verification on the second STA certificate. When the signature verification passes, the third STA certificate, the first AS certificate and the service SSID configuration information are extracted from the extension item of the second STA certificate;
[0035] When the authentication result value indicates that the issuance is unsuccessful or the signature verification fails, it is processed as a failure to obtain the WAPI certificate.
[0036] Preferably, after the wireless terminal receives the issuance result, the method for the wireless terminal to automatically access the WAPI network further includes:
[0037] After the wireless terminal obtains the third STA certificate, the first AS certificate and the service SSID configuration information from the issuance result, it installs the third STA certificate and the first AS certificate, and configures the service SSID according to the service SSID configuration information. After the installation and configuration is completed, the wireless terminal automatically connects to the service SSID and accesses the WAPI wireless network.
[0038] According to the specific embodiments provided in this application, this application discloses the following technical effects:
[0039] The present application provides a method for a wireless terminal to automatically access a WAPI network. The method involves information interaction and data transmission between a wireless terminal, a wireless access point, a WAPI certificate authenticator, and a WAPI certificate issuer. First, before starting a business communication, first CIS information is imported into the wireless terminal, and a first STA key pair and first STA information are generated. The first STA information is imported into a first database of the WAPI certificate issuer to form a wireless terminal table entry, and a business SSID of the wireless terminal is configured in the wireless terminal table entry; then, in a post-power-on stage in a business environment, the wireless terminal is connected to any SSID in a WAPI-CERT authentication mode, and a WAPI authentication is performed with the wireless access point; then, the WAPI certificate issuer and the wireless terminal check each other's credibility. This application is based on automatically obtaining a WAPI certificate online when accessing the WAPI network. In the relevant process, mutual credibility checks are implemented between the certificate acquirer (wireless terminal) and the certificate issuer (WAPI certificate issuer). Overall, the wireless terminal is automatically connected to the WAPI wireless network, which is plug-and-play. The workload of on-site certificate installation and SSID configuration of the WAPI terminal is avoided, and the problem that the WAPI wireless terminal cannot automatically apply for a WAPI digital certificate online and cannot achieve plug-and-play is solved, thereby improving the deployment efficiency of the WAPI wireless terminal. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0041] Figure 1 A flowchart of a method for automatically accessing a WAPI network by a wireless terminal is provided in one embodiment of the present application.
[0042] Figure 2 A schematic diagram of a first STA certificate provided in an embodiment of the present application.
[0043] Figure 3 A schematic diagram of a second STA certificate provided in an embodiment of the present application.
[0044] Figure 4 A schematic diagram of a process in which a wireless terminal automatically applies for a certificate and connects to a service SSID according to an embodiment of the present application.
[0045] Figure 5 A schematic diagram of certificate authentication results provided in one embodiment of the present application. DETAILED DESCRIPTION
[0046] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0047] Due to the high security of WAPI wireless networks, WAPI wireless networks are increasingly used in industrial scenarios such as power, including many types of WAPI wireless sensors. In order to access the WAPI wireless network, these wireless sensor terminals need to manually install WAPI digital certificates and configure the wireless network SSID to be connected, which involves heavy manual work. For some sensor terminals, due to their small size and the fact that the entire machine has no external physical interface in order to be waterproof, such wireless sensors have certain difficulties in installing digital certificates and configuring SSID. However, the industry's security rules do not allow wireless terminals without digital certificates to connect to other networks and install digital certificates online. For example, the terminals required by the power industry security regulations do not allow "one machine, multiple networks" connection, that is, these terminals can only connect to the WAPI wireless network to be connected, but because the terminals do not have WAPI digital certificates installed, these terminals cannot connect to the WAPI wireless network. On the other hand, in order to reduce network implementation work, WAPI network users also hope to avoid manually applying for and installing digital certificates for a large number of wireless terminals and configuring the SSIDs that need to be connected. To enable WAPI wireless terminals to automatically access WAPI wireless networks, the following three issues need to be addressed: (1) Apply for and install WAPI digital certificates online through the WAPI wireless network to be connected. (2) During the online application for digital certificates, the certificate issuer must be able to authenticate the credibility of the wireless terminal and the wireless terminal must be able to authenticate the credibility of the certificate issuer. (3) The wireless terminal can automatically obtain the SSID to be connected. However, currently WAPI wireless terminals cannot automatically connect to WAPI wireless networks, and cannot achieve plug-and-play for a large number of wireless sensors. WAPI digital certificates and configurations still need to be installed manually, which ultimately leads to low deployment efficiency of WAPI wireless terminals.
[0048] The purpose of this embodiment is to provide a method for automatically accessing a WAPI network by a wireless terminal, so that after the WAPI wireless terminal is deployed, it can automatically connect to the WAPI wireless network corresponding to the service, and the WAPI wireless terminal can automatically apply for a WAPI digital certificate online, perform two-way credibility verification with the certificate issuer, and obtain SSID configuration online by the terminal to achieve plug-and-play, thereby improving the production efficiency of the WAPI wireless terminal, and in particular, can solve the problem that WAPI sensor-type wireless terminals that do not have external configuration ports in field applications have difficulty connecting to the WAPI network.
[0049] In order to make the above-mentioned objects, features and advantages of the present application more obvious and easy to understand, the present application is further described in detail below in conjunction with the accompanying drawings and specific implementation methods.
[0050] like Figure 1As shown, this embodiment provides a method for a wireless terminal to automatically access a WAPI network, including a wireless terminal, a wireless access point, a WAPI certificate identifier and a WAPI certificate issuer, the WAPI certificate identifier having its own public key certificate, namely, a first AS certificate, the WAPI certificate issuer having a first CIS key pair and a first CIS information, and also storing the first AS certificate, the first CIS information including the CIS information and the CIS public key of the WAPI certificate issuer, and the CIS public key being the public key of the first CIS key pair.
[0051] The method for automatically accessing a WAPI network by a wireless terminal in this embodiment specifically includes the following steps:
[0052] S1: In the stage before starting business communication, especially in the production stage, the first CIS information is imported into the wireless terminal, the wireless terminal generates a first STA key pair and first STA information, and the first STA information is exported from the wireless terminal, wherein the first STA information includes the identification information of the wireless terminal and the STA public key, and the STA public key is the public key of the first STA key pair.
[0053] S2: In the stage before starting business communication, especially in the pre-power-on stage in the business environment, the first STA information is imported into the first database of the WAPI certificate issuer to form a wireless terminal table entry, and the business SSID corresponding to the wireless terminal is configured in the wireless terminal table entry.
[0054] S3: In the post-power-on stage in the business environment, the wireless terminal connects to any SSID of the WAPI-CERT authentication mode in the business environment, and performs a WAPI authentication with the wireless access point. During this WAPI authentication process, the application intention and application information are carried through the extended attributes of the first STA certificate in the access certificate authentication request message, and the issuance result generated by the WAPI certificate issuer when issuing and the business SSID configuration information are carried through the authentication result field in the certificate authentication response message; the application intention refers to the certificate extension item of the STA digital certificate including a specific OID, and thereby indicating to the WAPI certificate authenticator that the intention of the current WAPI access authentication request is to apply for a digital certificate for the wireless terminal; the The application information includes the first STA information, the certificate application file and the signature information, wherein the signature information is generated by the wireless terminal using the private key of the first STA key pair to perform a signature calculation on the content including the first STA information and the certificate application file; the issuance result includes an issuance processing result value and a second STA certificate, wherein the issuance processing result value is used to indicate whether the issuance is successful or unsuccessful, and the second STA certificate is a self-signed digital certificate generated by the WAPI certificate issuer based on the first CIS key pair, and the second STA certificate includes the issuance processing result value, a third STA certificate and the first AS certificate, and the third STA certificate is a WAPI digital certificate issued to the wireless terminal by the WAPI certificate issuer.
[0055] S4: The WAPI certificate issuer searches the first database for the wireless terminal entry according to the application information, and checks the credibility of the wireless terminal according to the STA public key recorded in the wireless terminal entry.
[0056] S5: The wireless terminal checks the credibility of the WAPI certificate issuer according to the CIS public key in the first CIS information stored locally.
[0057] In this embodiment, the process of the wireless terminal automatically obtaining the WAPI digital certificate from the WAPI certificate issuer specifically includes the following steps:
[0058] After the wireless terminal is powered on in the service environment, it scans and associates the SSID of the WAPI-CERT authentication mode, and performs WAPI authentication with the connected wireless access point.
[0059] The wireless terminal generates a first STA certificate during the WAPI authentication process, and the first STA certificate includes an application intention extension item and an application information extension item.
[0060] The WAPI certificate identifier authenticates the first STA certificate, identifies the application intention of the wireless terminal, and sends a certificate issuance application to the WAPI certificate issuer, where the certificate issuance application includes the first STA certificate.
[0061] After receiving the certificate issuance application, the WAPI certificate issuer performs issuance processing on the first STA certificate and generates an issuance result, wherein the issuance result includes an issuance processing result value and a second STA certificate, wherein the second STA certificate is a self-signed digital certificate generated by the WAPI certificate issuer based on the first CIS key pair, and includes an issuance processing result extension item and a third STA certificate extension item, wherein the issuance processing result extension item includes the issuance processing result value, and the third STA certificate extension item includes a third STA certificate, and the third STA certificate is a WAPI digital certificate issued by the WAPI certificate issuer to the wireless terminal.
[0062] After receiving the issuance result, the WAPI certificate authenticator generates an authentication result, in which the verification result of the ASUE certificate in the authentication result is equal to the issuance processing result value, and the ASUE certificate is the second STA certificate.
[0063] The wireless access point sends an access authentication response message to the wireless terminal according to a standard procedure, and the access authentication response message includes the authentication result.
[0064] After the wireless terminal receives the access authentication response message, it obtains the issuance processing result value according to the verification result of the ASUE certificate in the authentication result, and when the issuance processing result value is successful issuance, it parses the ASUE certificate in the authentication result to obtain the second STA certificate, and obtains the third STA certificate, the first AS certificate and the service SSID configuration information from the extension information in the second STA certificate, wherein the third STA certificate is the WAPI certificate of the wireless terminal.
[0065] In this embodiment, the process of the wireless terminal generating the first STA certificate specifically includes the following steps:
[0066] The wireless terminal generates a second STA key pair.
[0067] The wireless terminal generates a certificate application file, namely, a P10 file, according to the second STA key pair.
[0068] The wireless terminal generates a self-signed first STA certificate based on the first STA key pair; the first STA certificate includes an application intention extension item and an application information extension item, wherein the application information extension item includes the content of the first STA information, the information content of the P10 file and signature information, and the signature information is signed using the private key of the first STA key pair for the content including the first STA information and the P10 file.
[0069] Based on the first STA certificate, the wireless terminal sends a certificate authentication request for WAPI authentication to the wireless access point.
[0070] In this embodiment, the process of the WAPI certificate issuer issuing a WAPI digital certificate specifically includes the following steps:
[0071] The WAPI certificate issuer parses the application information from the first STA certificate.
[0072] The WAPI certificate issuer searches for the corresponding wireless terminal table entry in the first database according to the first STA information. When the corresponding wireless terminal table entry is found, the STA public key recorded in the wireless terminal table entry is used to verify the signature in the application information; if the verification is successful, the wireless terminal generates a WAPI digital certificate, namely the third STA certificate; finally, a issuance result is formed, and the issuance result includes an issuance processing result value, the third STA certificate and the first AS certificate, wherein the issuance processing result value is used to indicate successful issuance or unsuccessful issuance. When the issuance is successful (certificate generation is successful), the issuance result value is 100, otherwise a value greater than 100 is used to indicate other unsuccessful reasons, including failure to find the corresponding wireless terminal table entry, failure to pass the signature verification and failure to generate the WAPI digital certificate of the wireless terminal.
[0073] The WAPI certificate issuer generates a self-signed digital certificate, namely the second STA certificate, based on the first CIS key pair, which includes an issuance processing result extension item and a service SSID configuration extension item. The issuance processing result extension item includes the issuance processing result, and the service SSID configuration extension item includes the service SSID configuration information recorded in the wireless terminal table item.
[0074] The WAPI certificate issuer replies the issuance result to the WAPI certificate authenticator.
[0075] In this embodiment, the process of the wireless terminal processing the issuance result specifically includes the following steps:
[0076] After receiving the access authentication response message, the wireless terminal checks the authentication result value in the authentication result.
[0077] When the authentication result value indicates that the issuance is successful, the wireless terminal parses the second STA certificate from the authentication result, and uses the CIS public key in the first CIS information stored locally to perform signature verification on the second STA certificate. When the signature verification passes, the third STA certificate, the first AS certificate and the service SSID configuration information are extracted from the extension item of the second STA certificate.
[0078] When the authentication result value indicates that the issuance is unsuccessful or the signature verification fails, it is processed as a failure to obtain the WAPI certificate.
[0079] In this embodiment, after the wireless terminal receives the issuance result, the method for automatically accessing the WAPI network by the wireless terminal further includes the following steps:
[0080] After the wireless terminal obtains the third STA certificate, the first AS certificate and the service SSID configuration information from the issuance result, it installs the third STA certificate and the first AS certificate, and configures the service SSID according to the service SSID configuration information. After the installation and configuration is completed, the wireless terminal automatically connects to the service SSID and accesses the WAPI wireless network.
[0081] In this embodiment, the wireless terminal generates a self-signed first STA certificate based on the first STA key pair, such as Figure 2 As shown, the first STA certificate includes a certificate body, a certificate signature algorithm identifier, and a certificate signature value, etc., wherein the certificate body includes the certificate version number, serial number, signature algorithm, issuer name, validity period, certificate subject name, certificate public key, and extended attributes, and the extended attributes include the following extensions: application intent extension, including WAPI certificate application intent; STA application information extension, including the first STA information, P10 file extension, and signature information. The signature information is generated by the wireless terminal using the private key of the first STA key pair to perform signature calculation on the content including the first STA information and the certificate application file.
[0082] like Figure 3As shown, the second STA certificate in this embodiment includes a certificate body, a certificate signature algorithm identifier and a certificate signature value, wherein the certificate body includes the certificate version number, serial number, signature algorithm, issuer name, validity period, certificate body name, certificate public key and extended attributes, and the extended attributes include the following extension items: issuance result extension item and service SSID extension item. The issuance result extension item includes the issuance processing result value, the third STA certificate and the first AS certificate, wherein the third STA certificate is the WAPI digital certificate issued by the WAPI certificate issuer to the wireless terminal. When the issuance result value is failed, the values of the third STA certificate and the first AS certificate are empty. The service SSID extension item includes service SSID configuration information.
[0083] In the existing WAPI wireless network, STA certificates are installed manually, including the WAPI digital certificate and AS certificate of the wireless terminal, and the service SSID to be connected is configured on the wireless terminal. Figure 4 In steps 2, 3, 4, 7, and 8, the wireless terminal will send the digital certificate of the wireless terminal to the wireless access point in the access authentication request, and the wireless access point will send the digital certificates of the wireless terminal and the wireless access point in the certificate authentication request. The WAPI certificate authenticator will perform authentication checks on the digital certificates of the wireless terminal and the wireless access point. Regardless of whether the certificate authentication check passes or not, it will reply a certificate authentication response to the wireless access point, including the certificate authentication result. At the same time, after receiving the certificate authentication response, the wireless access point will reply an access authentication response to the wireless access point, including the same certificate authentication result, regardless of whether the certificate authentication check passes or not. The certificate authentication result is as follows: Figure 5 As shown, it includes the STA certificate and AS certificate submitted by the wireless access point to the WAPI certificate authenticator. Figure 5 The units in brackets are the number of octets.
[0084] In this embodiment, the digital certificate adopts the X509 V3 format, and the X509 certificate can include multiple extended attributes. The extended attributes are encapsulated using the Context type, and its value domain content is the first SEQUENCE. The value domain of this first SEQUENCE includes two data items: (1) OID (Object Idenfier), which identifies the meaning expressed by the extended attribute, and its type is Object Idenfier; (2) the second SEQUENCE, whose value domain is one or more information items of the extended attributes, where the second SEQUENCE may not be present. The extension items of the first STA certificate in this embodiment are defined as follows:
[0085] (1) Application intention:
[0086] OID: 1.2.156.11235.3002.1;
[0087] There is no second sequence.
[0088] (2) Application information:
[0089] OID: 1.2.156.11235.3002.2;
[0090] The contents of the second SEQUENCE include:
[0091] (a) First STA information: PrintableString type, storing the first STA information content;
[0092] (b) P10 file extension: PrintableString type, storing PEM format content of P10;
[0093] (c) Signature information: BIT STRING type, storing the signature value.
[0094] The extension items of the second STA certificate involved in this embodiment are defined as follows:
[0095] (1) Certificate issuance results:
[0096] OID: 1.2.156.11235.3003.1;
[0097] The contents of the second SEQUENCE include:
[0098] (a) Issuance processing result value: INTEGER type, its value is an integer value, which is the issuance processing result value of the WAPI certificate issuance processor;
[0099] (b) STA certificate: PrintableString type, stores the PEM format content of the WAPI certificate issued by the WAPI certificate issuance processor to the wireless terminal; when the issuance processing result value is unsuccessful, this item is a PrintableString type value with a length of 0.
[0100] (c) AS certificate: PrintableString type, which stores the PEM format content of the WAPI certificate of the WAPI certificate identifier.
[0101] When the issuance processing result value is unsuccessful, the STA certificate and the AS certificate are both PrintableString type values with a length of 0.
[0102] This embodiment exports the first STA information of the wireless terminal and imports the first CIS information before powering on in the production process or business environment of the wireless terminal; and performs mutual authentication based on the wireless terminal and CIS public key information exchanged in the subsequent WAPI authentication process for the purpose of WAPI certificate application, thereby realizing mutual credibility check between the certificate acquirer (wireless terminal) and the certificate issuer (WAPI certificate issuer), and having better security. For sensors with sealed external structures, in a factory production environment, the control or debugging port of the circuit board connected to the inside can be extracted before the structure is sealed to obtain relevant information, which is practical and feasible.
[0103] In this embodiment, the wireless terminal distinguishes between the public and private keys required for the certificate application process and the public and private keys required for the WAPI authentication process, which is clearer in terms of the scope of use and more in line with the general security principle. In this embodiment, the public and private keys required for the application process are generated before production or online power-on, that is, the first STA key pair, and the public and private keys involved in the WAPI certificate are generated at the time of application, that is, the second STA key pair; and the digital certificate used by the wireless terminal in the WAPI authentication process for the purpose of certificate application is the STA key pair.
[0104] In this embodiment, the application information of the wireless terminal uses a certificate application file, namely a P10 file, which is more in line with the practice of existing certificate systems and can be used to implement certificate generation using common software codes such as openssl.
[0105] This embodiment configures the service SSID for the wireless terminal in advance in the first database of the WAPI certificate issuer, and sends it to the certificate acquirer, i.e. the wireless terminal, during the certificate application process, so that the wireless terminal can automatically connect to the service SSID immediately after obtaining the WAPI digital certificate. If there are other configurations that need to be sent to the wireless terminal, they can also be implemented by referring to the method of sending the SSID, thereby completely solving the problem that the wireless terminal does not need to be configured in the service environment, and is more convenient and quick to use.
[0106] This embodiment introduces a WAPI certificate issuer, which has better adaptability in practical applications. For example, in the power network, the current practice of power companies in various provinces to build WAPI wireless private networks is to deploy WAPI certificate authenticators in cities and wireless access points in substations. Under this deployment architecture, a set of WAPI certificate issuer systems can be deployed in the provincial power company throughout the province; in this way, for the WAPI wireless terminals of a certain province, the first CIS information can be uniformly imported for the wireless terminals of power customers in the province during production, without distinguishing between cities.
[0107] This embodiment can apply for a WAPI certificate online based on the WAPI network to be accessed, automatically implement online application for a WAPI digital certificate, implement mutual credibility checks between the wireless terminal and the certificate issuer, i.e., the WAPI certificate issuer, during the application process, and automatically obtain the SSID to be connected, so that the wireless terminal can automatically connect to the WAPI wireless network as a whole, and plug and play, avoiding the work of on-site installation of certificates and configuration of SSIDs for WAPI terminals, and solving the problem that the WAPI wireless terminal cannot automatically apply for a WAPI digital certificate online to achieve plug and play, and has good security and convenience.
[0108] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0109] This article uses specific examples to illustrate the principles and implementation methods of this application. The description of the above embodiments is only used to help understand the method and core ideas of this application. At the same time, for those skilled in the art, according to the ideas of this application, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as limiting this application.
Claims
1. A method for automatically accessing a WAPI network by a wireless terminal, characterized in that: It includes a wireless terminal, a wireless access point, a WAPI certificate identifier and a WAPI certificate issuer, wherein the WAPI certificate identifier has its own public key certificate, namely, a first AS certificate, and the WAPI certificate issuer has a first CIS key pair and first CIS information, and also stores the first AS certificate, wherein the first CIS information includes the CIS information and the CIS public key of the WAPI certificate issuer, and the CIS public key is the public key of the first CIS key pair; The method for automatically accessing a WAPI network by a wireless terminal includes: S1: before starting service communication, importing the first CIS information into the wireless terminal, the wireless terminal generating a first STA key pair and first STA information, and exporting the first STA information from the wireless terminal, wherein the first STA information includes identification information of the wireless terminal and a STA public key, and the STA public key is a public key of the first STA key pair; S2: before starting service communication, importing the first STA information into the first database of the WAPI certificate issuer to form a wireless terminal table entry, and configuring the service SSID corresponding to the wireless terminal in the wireless terminal table entry; S3: In the post-power-on stage in the business environment, the wireless terminal connects to any SSID of the WAPI-CERT authentication mode in the business environment, and performs a WAPI authentication with the wireless access point. During this WAPI authentication process, the application intention and application information are carried through the extended attributes of the first STA certificate in the access certificate authentication request message, and the issuance result generated by the WAPI certificate issuer when issuing and the business SSID configuration information are carried through the authentication result field in the certificate authentication response message; the application intention refers to the certificate extension item of the STA digital certificate including a specific OID, and thereby indicating to the WAPI certificate authenticator that the intention of the current WAPI access authentication request is to apply for a digital certificate for the wireless terminal; the The application information includes the first STA information, the certificate application file and the signature information, wherein the signature information is generated by the wireless terminal using the private key of the first STA key pair to perform a signature calculation on the content including the first STA information and the certificate application file; the issuance result includes an issuance processing result value and a second STA certificate, wherein the issuance processing result value is used to indicate whether the issuance is successful or unsuccessful, the second STA certificate is a self-signed digital certificate generated by the WAPI certificate issuer based on the first CIS key pair, the second STA certificate includes the issuance processing result value, a third STA certificate and the first AS certificate, and the third STA certificate is a WAPI digital certificate issued by the WAPI certificate issuer to the wireless terminal; S4: the WAPI certificate issuer searches the first database for the wireless terminal entry according to the application information, and checks the credibility of the wireless terminal according to the STA public key recorded in the wireless terminal entry; S5: The wireless terminal checks the credibility of the WAPI certificate issuer according to the CIS public key in the first CIS information stored locally.
2. The method for automatically accessing a WAPI network by a wireless terminal according to claim 1, characterized in that: The process of the wireless terminal automatically obtaining the WAPI digital certificate from the WAPI certificate issuer specifically includes: After the wireless terminal is powered on in the service environment, it scans and associates the SSID of the WAPI-CERT authentication mode, and performs WAPI authentication with the connected wireless access point; The wireless terminal generates a first STA certificate during the WAPI authentication process, wherein the first STA certificate includes an application intention extension item and an application information extension item; The WAPI certificate identifier authenticates the first STA certificate, identifies the application intention of the wireless terminal, and sends a certificate issuance application to the WAPI certificate issuer, where the certificate issuance application includes the first STA certificate; After receiving the certificate issuance application, the WAPI certificate issuer performs issuance processing on the first STA certificate and generates an issuance result; After receiving the issuance result, the WAPI certificate identifier generates an authentication result, the verification result of the ASUE certificate in the authentication result is equal to the issuance processing result value, and the ASUE certificate is the second STA certificate; The wireless access point sends an access authentication response message to the wireless terminal according to a standard process, wherein the access authentication response message includes the authentication result; After the wireless terminal receives the access authentication response message, it obtains the issuance processing result value according to the verification result of the ASUE certificate in the authentication result, and when the issuance processing result value is successful issuance, it parses the ASUE certificate in the authentication result to obtain the second STA certificate, and obtains the third STA certificate, the first AS certificate and the service SSID configuration information from the extension information in the second STA certificate, wherein the third STA certificate is the WAPI certificate of the wireless terminal.
3. The method for automatically accessing a WAPI network by a wireless terminal according to claim 2, characterized in that: The process of generating the first STA certificate by the wireless terminal specifically includes: The wireless terminal generates a second STA key pair; The wireless terminal generates a certificate application file, namely a P10 file, according to the second STA key pair; The wireless terminal generates a self-signed first STA certificate according to the first STA key pair; the first STA certificate includes an application intention extension item and an application information extension item, wherein the application information extension item includes the content of the first STA information, the information content of the P10 file and signature information, and the signature information is signed by using the private key of the first STA key pair for the content including the first STA information and the P10 file; Based on the first STA certificate, the wireless terminal sends a certificate authentication request for WAPI authentication to the wireless access point.
4. The method for automatically accessing a WAPI network by a wireless terminal according to claim 3, characterized in that: The process of the WAPI certificate issuer issuing a WAPI digital certificate specifically includes: The WAPI certificate issuer parses the application information from the first STA certificate; The WAPI certificate issuer searches for the corresponding wireless terminal table entry in the first database according to the first STA information. When the corresponding wireless terminal table entry is found, the STA public key recorded in the wireless terminal table entry is used to verify the signature in the application information; if the verification is successful, the wireless terminal generates a WAPI digital certificate, namely the third STA certificate; finally, a issuance result is formed, and the issuance result includes an issuance processing result value, the third STA certificate and the first AS certificate, wherein the issuance processing result value is used to indicate successful issuance or unsuccessful issuance. When the issuance is successful, the issuance result value is 100, otherwise a value greater than 100 is used to indicate other unsuccessful reasons, including failure to find the corresponding wireless terminal table entry, failure to pass the signature verification and failure to generate the WAPI digital certificate of the wireless terminal; The WAPI certificate issuer generates a self-signed digital certificate, namely the second STA certificate, based on the first CIS key pair, which includes an issuance processing result extension item and a service SSID configuration extension item, wherein the issuance processing result extension item includes the issuance processing result, and the service SSID configuration extension item includes the service SSID configuration information recorded in the wireless terminal table item; The WAPI certificate issuer replies the issuance result to the WAPI certificate authenticator.
5. The method for automatically accessing a WAPI network by a wireless terminal according to claim 4, characterized in that: The process of the wireless terminal processing the issuance result specifically includes: After receiving the access authentication response message, the wireless terminal checks the authentication result value in the authentication result; When the authentication result value indicates that the issuance is successful, the wireless terminal parses the second STA certificate from the authentication result, and uses the CIS public key in the first CIS information stored locally to perform signature verification on the second STA certificate. When the signature verification passes, the third STA certificate, the first AS certificate and the service SSID configuration information are extracted from the extension item of the second STA certificate; When the authentication result value indicates that the issuance is unsuccessful or the signature verification fails, it is processed as a failure to obtain the WAPI certificate.
6. The method for automatically accessing a WAPI network by a wireless terminal according to claim 5, characterized in that: After the wireless terminal receives the issuance result, the method for automatically accessing the WAPI network by the wireless terminal further includes: After the wireless terminal obtains the third STA certificate, the first AS certificate and the service SSID configuration information from the issuance result, it installs the third STA certificate and the first AS certificate, and configures the service SSID according to the service SSID configuration information. After the installation and configuration is completed, the wireless terminal automatically connects to the service SSID and accesses the WAPI wireless network.
Citation Information
Patent Citations
Authentication method based on WAPI ( wireless LAN authentication and privacy infrastructure), access point and mobile terminal
CN102026196A
WAPI wireless private network certificate issuing method and system
CN115085938A
WAPI certificate application method, wireless terminal and certificate identifier
CN115278676A
WAPI certificate authentication method and system
CN116249114A
WAPI access identification method and system, AS and medium
CN117544953A
Cited By
Method for establishing WAPI certificate application network channel
CN120200755A