Method for wireless terminal to automatically access WAPI network

By importing CIS information and generating STA key pairs during the wireless terminal production stage, online acquisition and trustworthiness checks of WAPI certificates are achieved, solving the problem of WAPI wireless terminals being unable to connect automatically and improving deployment efficiency, especially suitable for sensor terminals without external interfaces.

CN119946636BActive Publication Date: 2026-03-27SHENZHEN ZHIKAI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-13
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

In existing technologies, WAPI wireless terminals cannot automatically connect to WAPI wireless networks and cannot achieve plug-and-play functionality, resulting in low deployment efficiency. In particular, wireless sensor terminals face difficulties in installing WAPI digital certificates and configuring SSIDs.

Method used

During the wireless terminal production stage, CIS information is imported and STA key pairs are generated. WAPI certificates are obtained online through the WAPI authentication process to realize the trustworthiness check of the certificate issuer and the terminal. SSID configuration is automatically obtained to ensure that the wireless terminal automatically connects to the WAPI network after power-on.

Benefits of technology

It enables automatic connection and plug-and-play functionality for WAPI wireless terminals, reducing the workload of on-site certificate installation and SSID configuration, and improving deployment efficiency, especially suitable for sensor terminals without external physical interfaces.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119946636B_ABST
    Figure CN119946636B_ABST
Patent Text Reader

Abstract

The application discloses a method for automatically accessing a WAPI network by a wireless terminal, and relates to the technical field of network communication, which comprises the following steps: introducing first CIS information to the wireless terminal and generating a first STA key pair and first STA information in a stage before starting service communication; introducing the first STA information to a first database of a WAPI certificate issuer to form a wireless terminal table item, and configuring a service SSID of the wireless terminal; then in a power-on stage in a service environment, the wireless terminal is connected to an SSID of any WAPI-CERT authentication mode, and performs WAPI authentication with a wireless access point; then the WAPI certificate issuer and the wireless terminal check the trustworthiness of each other. The application can automatically connect the WAPI wireless terminal to the WAPI wireless network, realizes plug and play, and improves the deployment efficiency of the WAPI wireless terminal.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network communication technology, and in particular to a method for a wireless terminal to automatically access a WAPI network. Background Technology

[0002] WAPI (Wireless LAN Authentication and Privacy Infrastructure) is a WLAN wireless security standard and technology. It uses digital certificates to identify the wireless access point (AP), wireless terminal (STA), and WAPI certificate authenticator (AS), employing a three-factor authentication system to ensure the security of wireless access authentication. In a wireless LAN using WAPI digital certificate authentication, both the wireless access point and the wireless terminal need to install a WAPI digital certificate to perform three-factor authentication and allow the terminal to access the wireless network.

[0003] However, one related technology involves an online application method for a WAPI digital certificate based on the WAPI authentication process interaction with the intended WAPI wireless network. However, this method has the following drawbacks: (1) It does not disclose or provide specific authentication information and methods, meaning the authorization authentication information contained in the first certificate and the authorization check method corresponding to the WAPI certificate authenticator are not publicly disclosed or indicated. (2) The wireless terminal cannot check the trustworthiness of the certificate issuer. The WAPI certificate authenticator sends the wireless terminal's certificate and the WAPI certificate authenticator's certificate to the wireless terminal based on the authentication result, but the wireless terminal has no information to check the trustworthiness of the WAPI certificate authenticator. (3) After obtaining the WAPI certificate, the wireless terminal still cannot automatically connect to the wireless network because the wireless terminal does not have an SSID (Service Set Identifier) ​​configuration.

[0004] Due to the aforementioned issues, WAPI wireless terminals still cannot automatically connect to the WAPI wireless network, nor can they achieve plug-and-play functionality for a large number of wireless sensors, ultimately resulting in low deployment efficiency for WAPI wireless terminals. Summary of the Invention

[0005] The purpose of this application is to provide a method for wireless terminals to automatically access WAPI networks, which enables WAPI wireless terminals to automatically connect to WAPI wireless networks, achieve plug-and-play functionality, and improve the deployment efficiency of WAPI wireless terminals.

[0006] To achieve the above objectives, this application provides the following solution:

[0007] This application provides a method for a wireless terminal to automatically access a WAPI network, including a wireless terminal, a wireless access point, a WAPI certificate authenticator, and a WAPI certificate issuer. The WAPI certificate authenticator has its own public key certificate, namely a first AS certificate. The WAPI certificate issuer has a first CIS key pair and first CIS information, and also stores the first AS certificate. The first CIS information includes the CIS information of the WAPI certificate issuer and the CIS public key, and the CIS public key is the public key of the first CIS key pair.

[0008] The method for the wireless terminal to automatically access the WAPI network includes:

[0009] S1: In the stage before the start of business communication, especially in the production stage, the first CIS information is imported into the wireless terminal, the wireless terminal generates a first STA key pair and first STA information, and the first STA information is exported from the wireless terminal, wherein the first STA information includes the identification information of the wireless terminal and the STA public key, and the STA public key is the public key of the first STA key pair.

[0010] S2: In the stage before starting service communication, the first STA information is imported into the first database of the WAPI certificate issuer to form a wireless terminal entry, and the service SSID corresponding to the wireless terminal is configured in the wireless terminal entry.

[0011] S3: During the power-on phase in the service environment, the wireless terminal connects to any SSID of the WAPI-CERT authentication mode in the service environment and performs a WAPI authentication with the wireless access point. During this WAPI authentication process, the application intent and application information are carried through the extended attributes of the first STA certificate in the access certificate authentication request message, and the issuance result generated by the WAPI certificate issuer and the service SSID configuration information are carried through the authentication result field in the certificate authentication response message. The application intent refers to the inclusion of a specific OID in the certificate extension of the STA digital certificate, which indicates to the WAPI certificate authenticator that the intent of the current WAPI access authentication request is to apply for the digital certificate of the wireless terminal. The application information includes the first STA information, a certificate application file, and signature information. The signature information is generated by the wireless terminal using the private key of the first STA key pair to sign the content including the first STA information and the certificate application file. The issuance result includes an issuance processing result value and a second STA certificate. The issuance processing result value indicates whether the issuance was successful or unsuccessful. The second STA certificate is a self-signed digital certificate generated by the WAPI certificate issuer based on the first CIS key pair. The second STA certificate includes the issuance processing result value, a third STA certificate, and the first AS certificate. The third STA certificate is a WAPI digital certificate issued by the WAPI certificate issuer to the wireless terminal.

[0012] S4: The WAPI certificate issuer searches for the wireless terminal entry in the first database based on the application information, and checks the trustworthiness of the wireless terminal based on the STA public key recorded in the wireless terminal entry;

[0013] S5: The wireless terminal checks the trustworthiness of the WAPI certificate issuer based on the CIS public key in the first CIS information stored locally.

[0014] Preferably, the process by which the wireless terminal automatically obtains the WAPI digital certificate from the WAPI certificate issuer specifically includes:

[0015] After the wireless terminal is powered on in the service environment, it scans and associates the SSID of the WAPI-CERT authentication mode, and performs WAPI authentication with the connected wireless access point.

[0016] The wireless terminal generates a first STA certificate during the WAPI authentication process. The first STA certificate includes an application intent extension and an application information extension.

[0017] The WAPI certificate authenticator authenticates the first STA certificate, identifies the application intent of the wireless terminal, and sends a certificate issuance application to the WAPI certificate issuer, the certificate issuance application including the first STA certificate;

[0018] After receiving the certificate issuance application, the WAPI certificate issuer processes the first STA certificate for issuance and generates an issuance result.

[0019] After receiving the issuance result, the WAPI certificate authenticator generates an authentication result. The verification result of the ASUE certificate in the authentication result is equal to the issuance processing result value, and the ASUE certificate is the second STA certificate.

[0020] The wireless access point sends an access authentication response message to the wireless terminal according to a standard procedure, and the access authentication response message includes the authentication result.

[0021] After receiving the access authentication response message, the wireless terminal obtains the issuance processing result value based on the verification result of the ASUE certificate in the authentication result. If the issuance processing result value is successful, it parses the ASUE certificate in the authentication result to obtain the second STA certificate, and obtains the third STA certificate, the first AS certificate, and the service SSID configuration information from the extension information in the second STA certificate. The third STA certificate is the WAPI certificate of the wireless terminal.

[0022] Preferably, the process by which the wireless terminal generates the first STA certificate specifically includes:

[0023] The wireless terminal generates a second STA key pair;

[0024] The wireless terminal generates a certificate application file, namely the P10 file, based on the second STA key pair.

[0025] The wireless terminal generates a self-signed first STA certificate based on the first STA key pair. The first STA certificate includes an application intent extension and an application information extension. The application information extension includes the content of the first STA information, the information content of the P10 file, and signature information. The signature information is generated by signing the content including the first STA information and the P10 file using the private key of the first STA key pair.

[0026] Based on the first STA certificate, the wireless terminal sends a WAPI authentication certificate authentication request to the wireless access point.

[0027] Preferably, the process of the WAPI certificate issuer issuing WAPI digital certificates specifically includes:

[0028] The WAPI certificate issuer parses the application information from the first STA certificate;

[0029] The WAPI certificate issuer searches for the corresponding wireless terminal entry in the first database based on the first STA information. When the corresponding wireless terminal entry is found, the STA public key recorded in the wireless terminal entry is used to verify the signature in the application information. If the verification is successful, the wireless terminal generates a WAPI digital certificate, i.e., the third STA certificate. Finally, an issuance result is formed, which includes an issuance processing result value, the third STA certificate, and the first AS certificate. The issuance processing result value is used to indicate whether the issuance was successful or unsuccessful. When the issuance is successful, the issuance result value is 100. Otherwise, a value greater than 100 indicates other reasons for failure, including not finding the corresponding wireless terminal entry, signature verification failure, and failure to generate the WAPI digital certificate for the wireless terminal.

[0030] The WAPI certificate issuer generates a self-signed digital certificate, namely the second STA certificate, based on the first CIS key pair. The certificate includes an issuance processing result extension item and a service SSID configuration extension item. The issuance processing result extension item includes the issuance processing result, and the service SSID configuration extension item includes the service SSID configuration information recorded in the wireless terminal table.

[0031] The WAPI certificate issuer replies the issuance result to the WAPI certificate authenticator.

[0032] Preferably, the process of the wireless terminal processing the issuance result specifically includes:

[0033] After receiving the access authentication response message, the wireless terminal checks the authentication result value in the authentication result.

[0034] When the authentication result value indicates successful issuance, the wireless terminal parses the second STA certificate from the authentication result and performs signature verification on the second STA certificate using the CIS public key in the first CIS information stored locally. When the signature verification is successful, the third STA certificate, the first AS certificate, and the service SSID configuration information are extracted from the extension items of the second STA certificate.

[0035] If the authentication result value indicates that the issuance was unsuccessful or the signature verification failed, then the process of obtaining the WAPI certificate will fail.

[0036] Preferably, after the step of the wireless terminal receiving the issuance result, the method for the wireless terminal to automatically access the WAPI network further includes:

[0037] After obtaining the third STA certificate, the first AS certificate, and the service SSID configuration information from the issuance result, the wireless terminal installs the third STA certificate and the first AS certificate, and configures the service SSID according to the service SSID configuration information. After the installation and configuration are completed, the wireless terminal automatically connects to the service SSID and accesses the WAPI wireless network.

[0038] According to the specific embodiments provided in this application, the following technical effects are disclosed:

[0039] This application provides a method for automatic access to a WAPI network by a wireless terminal. This method involves information interaction and data transmission between the wireless terminal, a wireless access point, a WAPI certificate authenticator, and a WAPI certificate issuer. First, before service communication begins, first CIS information is imported into the wireless terminal, and a first STA key pair and first STA information are generated. The first STA information is then imported into the first database of the WAPI certificate issuer to form a wireless terminal entry, and the service SSID of the wireless terminal is configured in the wireless terminal entry. Then, after power-on in the service environment, the wireless terminal connects to any SSID in the WAPI-CERT authentication mode and performs WAPI authentication with the wireless access point. Finally, the WAPI certificate issuer and the wireless terminal mutually verify each other's trustworthiness. This application enables automatic online acquisition of WAPI certificates based on the intended access to the WAPI network. During the process, mutual trust checks are performed between the certificate acquirer (wireless terminal) and the certificate issuer (WAPI certificate issuer). Overall, the wireless terminal automatically connects to the WAPI wireless network, enabling plug-and-play functionality. This avoids the workload of on-site certificate installation and SSID configuration for WAPI terminals, solves the problem that WAPI wireless terminals cannot automatically apply for WAPI digital certificates online and thus cannot achieve plug-and-play functionality, thereby improving the deployment efficiency of WAPI wireless terminals. Attached Figure Description

[0040] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0041] Figure 1 This is a flowchart illustrating a method for an automatic wireless terminal to access a WAPI network, provided as an embodiment of this application.

[0042] Figure 2 A schematic diagram of a first STA certificate provided for an embodiment of this application.

[0043] Figure 3 A schematic diagram of a second STA certificate provided in an embodiment of this application.

[0044] Figure 4 This is a schematic diagram illustrating the process of a wireless terminal automatically applying for a certificate and connecting to a service SSID, as provided in an embodiment of this application.

[0045] Figure 5 This is a schematic diagram of the certificate authentication result provided in an embodiment of this application. Detailed Implementation

[0046] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0047] Due to the high security of WAPI wireless networks, they are increasingly used in industrial scenarios such as the power industry, including various types of WAPI wireless sensors. To access these wireless sensor terminals, manual installation of WAPI digital certificates and configuration of the intended wireless network SSID are required, resulting in a heavy workload. For some sensor terminals, due to their small size and waterproofing, the structure lacks external physical interfaces, making digital certificate installation and SSID configuration more difficult. However, industry security regulations do not allow wireless terminals without digital certificates to connect to other networks and install them online. For example, power industry security regulations prohibit terminals from connecting to multiple networks simultaneously; these terminals can only connect to the intended WAPI wireless network, but without a WAPI digital certificate, they cannot connect. On the other hand, to reduce network implementation work, WAPI network users also hope to avoid manually applying for and installing digital certificates and configuring SSIDs for a large number of wireless terminals. To enable WAPI wireless terminals to automatically access the WAPI wireless network, the following three issues need to be addressed: (1) Applying for and installing WAPI digital certificates online through the WAPI wireless network to be connected. (2) During the online application for digital certificates, the certificate issuer must be able to verify the trustworthiness of the wireless terminal, and the wireless terminal must be able to verify the trustworthiness of the certificate issuer. (3) The wireless terminal must be able to automatically obtain the SSID to be connected. However, currently, WAPI wireless terminals cannot automatically connect to the WAPI wireless network, and cannot achieve plug-and-play functionality for a large number of wireless sensors. Manual installation and configuration of WAPI digital certificates are still required, ultimately resulting in low deployment efficiency for WAPI wireless terminals.

[0048] The purpose of this embodiment is to provide a method for wireless terminals to automatically access WAPI networks. This method enables WAPI wireless terminals to automatically connect to the corresponding WAPI wireless network after deployment, automatically apply for WAPI digital certificates online, conduct two-way trust verification with the certificate issuer, and obtain SSID configuration online, achieving plug-and-play functionality. This improves the deployment efficiency of WAPI wireless terminals, and in particular, solves the problem of difficulty in connecting WAPI sensor-type wireless terminals without external configuration ports in field applications.

[0049] To make the above-mentioned objectives, features and advantages of this application more apparent and understandable, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0050] like Figure 1As shown, this embodiment provides a method for a wireless terminal to automatically access a WAPI network, including a wireless terminal, a wireless access point, a WAPI certificate authenticator, and a WAPI certificate issuer. The WAPI certificate authenticator has its own public key certificate, namely a first AS certificate. The WAPI certificate issuer has a first CIS key pair and first CIS information, and also stores the first AS certificate. The first CIS information includes the CIS information of the WAPI certificate issuer and the CIS public key, and the CIS public key is the public key of the first CIS key pair.

[0051] The method for automatic access to the WAPI network by a wireless terminal in this embodiment specifically includes the following steps:

[0052] S1: In the stage before the start of business communication, especially in the production stage, the first CIS information is imported into the wireless terminal, the wireless terminal generates a first STA key pair and first STA information, and the first STA information is exported from the wireless terminal, wherein the first STA information includes the identification information of the wireless terminal and the STA public key, and the STA public key is the public key of the first STA key pair.

[0053] S2: In the stage before starting service communication, especially in the stage before powering on in the service environment, the first STA information is imported into the first database of the WAPI certificate issuer to form a wireless terminal entry, and the service SSID corresponding to the wireless terminal is configured in the wireless terminal entry.

[0054] S3: During the power-on phase in the service environment, the wireless terminal connects to any SSID of the WAPI-CERT authentication mode in the service environment and performs a WAPI authentication with the wireless access point. During this WAPI authentication process, the application intent and application information are carried through the extended attributes of the first STA certificate in the access certificate authentication request message, and the issuance result generated by the WAPI certificate issuer and the service SSID configuration information are carried through the authentication result field in the certificate authentication response message. The application intent refers to the inclusion of a specific OID in the certificate extension of the STA digital certificate, which indicates to the WAPI certificate authenticator that the intent of the current WAPI access authentication request is to apply for the digital certificate of the wireless terminal. The application information includes the first STA information, a certificate application file, and signature information. The signature information is generated by the wireless terminal using the private key of the first STA key pair to sign the content including the first STA information and the certificate application file. The issuance result includes an issuance processing result value and a second STA certificate. The issuance processing result value indicates whether the issuance was successful or unsuccessful. The second STA certificate is a self-signed digital certificate generated by the WAPI certificate issuer based on the first CIS key pair. The second STA certificate includes the issuance processing result value, a third STA certificate, and the first AS certificate. The third STA certificate is a WAPI digital certificate issued by the WAPI certificate issuer to the wireless terminal.

[0055] S4: The WAPI certificate issuer searches for the wireless terminal entry in the first database based on the application information, and checks the trustworthiness of the wireless terminal based on the STA public key recorded in the wireless terminal entry.

[0056] S5: The wireless terminal checks the trustworthiness of the WAPI certificate issuer based on the CIS public key in the first CIS information stored locally.

[0057] In this embodiment, the process by which the wireless terminal automatically obtains the WAPI digital certificate from the WAPI certificate issuer specifically includes the following steps:

[0058] After the wireless terminal is powered on in the service environment, it scans and associates the SSID of the WAPI-CERT authentication mode, and performs WAPI authentication with the connected wireless access point.

[0059] The wireless terminal generates a first STA certificate during the WAPI authentication process. The first STA certificate includes an application intent extension and an application information extension.

[0060] The WAPI certificate authenticator authenticates the first STA certificate, identifies the application intent of the wireless terminal, and sends a certificate issuance application to the WAPI certificate issuer, the certificate issuance application including the first STA certificate.

[0061] After receiving the certificate issuance application, the WAPI certificate issuer processes the first STA certificate and generates an issuance result. The issuance result includes an issuance processing result value and a second STA certificate. The second STA certificate is a self-signed digital certificate generated by the WAPI certificate issuer based on the first CIS key pair. It includes an issuance processing result extension and a third STA certificate extension. The issuance processing result extension includes the issuance processing result value, and the third STA certificate extension includes a third STA certificate. The third STA certificate is a WAPI digital certificate issued by the WAPI certificate issuer to the wireless terminal.

[0062] After receiving the issuance result, the WAPI certificate authenticator generates an authentication result. The verification result of the ASUE certificate in the authentication result is equal to the issuance processing result value, and the ASUE certificate is the second STA certificate.

[0063] The wireless access point sends an access authentication response message to the wireless terminal according to a standard procedure, and the access authentication response message includes the authentication result.

[0064] After receiving the access authentication response message, the wireless terminal obtains the issuance processing result value based on the verification result of the ASUE certificate in the authentication result. If the issuance processing result value is successful, it parses the ASUE certificate in the authentication result to obtain the second STA certificate, and obtains the third STA certificate, the first AS certificate, and the service SSID configuration information from the extension information in the second STA certificate. The third STA certificate is the WAPI certificate of the wireless terminal.

[0065] In this embodiment, the process of the wireless terminal generating the first STA certificate specifically includes the following steps:

[0066] The wireless terminal generates a second STA key pair.

[0067] The wireless terminal generates a certificate application file, namely the P10 file, based on the second STA key pair.

[0068] The wireless terminal generates a self-signed first STA certificate based on the first STA key pair. The first STA certificate includes an application intent extension and an application information extension. The application information extension includes the content of the first STA information, the information content of the P10 file, and signature information. The signature information is generated by signing the content including the first STA information and the P10 file using the private key of the first STA key pair.

[0069] Based on the first STA certificate, the wireless terminal sends a WAPI authentication certificate authentication request to the wireless access point.

[0070] In this embodiment, the process of the WAPI certificate issuer issuing WAPI digital certificates specifically includes the following steps:

[0071] The WAPI certificate issuer parses the application information from the first STA certificate.

[0072] The WAPI certificate issuer searches for the corresponding wireless terminal entry in the first database based on the first STA information. When the corresponding wireless terminal entry is found, the STA public key recorded in the wireless terminal entry is used to verify the signature in the application information. If the verification is successful, the wireless terminal generates a WAPI digital certificate, i.e., the third STA certificate. Finally, an issuance result is formed, which includes an issuance processing result value, the third STA certificate, and the first AS certificate. The issuance processing result value is used to indicate whether the issuance was successful or unsuccessful. When the issuance is successful (certificate generation is successful), the issuance result value is 100. Otherwise, a value greater than 100 indicates other reasons for failure, including not finding the corresponding wireless terminal entry, signature verification failure, and failure to generate the WAPI digital certificate for the wireless terminal.

[0073] The WAPI certificate issuer generates a self-signed digital certificate, namely the second STA certificate, based on the first CIS key pair. The certificate includes an issuance processing result extension item and a service SSID configuration extension item. The issuance processing result extension item includes the issuance processing result, and the service SSID configuration extension item includes the service SSID configuration information recorded in the wireless terminal table.

[0074] The WAPI certificate issuer replies the issuance result to the WAPI certificate authenticator.

[0075] In this embodiment, the process of the wireless terminal processing the issuance result specifically includes the following steps:

[0076] After receiving the access authentication response message, the wireless terminal checks the authentication result value in the authentication result.

[0077] When the authentication result value indicates successful issuance, the wireless terminal parses the second STA certificate from the authentication result and performs signature verification on the second STA certificate using the CIS public key in the first CIS information stored locally. When the signature verification is successful, the third STA certificate, the first AS certificate, and the service SSID configuration information are extracted from the extension items of the second STA certificate.

[0078] If the authentication result value indicates that the issuance was unsuccessful or the signature verification failed, then the process of obtaining the WAPI certificate will fail.

[0079] In this embodiment, after the wireless terminal receives the issuance result, the method for the wireless terminal to automatically access the WAPI network further includes the following steps:

[0080] After obtaining the third STA certificate, the first AS certificate, and the service SSID configuration information from the issuance result, the wireless terminal installs the third STA certificate and the first AS certificate, and configures the service SSID according to the service SSID configuration information. After the installation and configuration are completed, the wireless terminal automatically connects to the service SSID and accesses the WAPI wireless network.

[0081] In this embodiment, the wireless terminal generates a self-signed first STA certificate based on the first STA key pair, such as... Figure 2 As shown, the first STA certificate includes a certificate body, a certificate signing algorithm identifier, and a certificate signature value. The certificate body includes the certificate version number, serial number, signing algorithm, issuer name, validity period, certificate body name, certificate public key, and extended attributes. The extended attributes include the following: an application intent extension, including the WAPI certificate application intent; and STA application information extensions, including first STA information, P10 file extensions, and signature information. The signature information is generated by the wireless terminal using the private key of the first STA key pair to sign the content including the first STA information and the certificate application file.

[0082] like Figure 3As shown, the second STA certificate in this embodiment includes a certificate body, a certificate signature algorithm identifier, and a certificate signature value. The certificate body includes the certificate version number, serial number, signature algorithm, issuer name, validity period, certificate body name, certificate public key, and extended attributes. The extended attributes include the following extended items: issuance result extended item and service SSID extended item. The issuance result extended item contains the issuance processing result value, the third STA certificate, and the first AS certificate, where the third STA certificate is the WAPI digital certificate issued to the wireless terminal by the WAPI certificate issuer. When the issuance result value is "failed," the values ​​of the third STA certificate and the first AS certificate are empty. The service SSID extended item includes service SSID configuration information.

[0083] In existing WAPI wireless networks, STA certificates are installed manually, including the WAPI digital certificate and AS certificate for the wireless terminal, as well as configuring the SSID of the service to be connected on the wireless terminal. During the WAPI authentication process, such as... Figure 4 In steps 2, 3, 4, 7, and 8, the wireless terminal sends its digital certificate to the wireless access point in the access authentication request. The wireless access point sends the digital certificates of both the wireless terminal and the wireless access point in the certificate authentication request. The WAPI certificate authenticator performs authentication checks on the digital certificates of the wireless terminal and the wireless access point. Regardless of whether the certificate authentication check passes, it replies to the wireless access point with a certificate authentication response, which includes the certificate authentication result. Simultaneously, upon receiving the certificate authentication response, the wireless access point, regardless of whether the certificate authentication check passes, replies to the wireless access point with an access authentication response, which includes the same certificate authentication result. The certificate authentication result is as follows: Figure 5 As shown, it includes the STA certificate and AS certificate submitted by the wireless access point to the WAPI certificate authenticator. Figure 5 The unit in parentheses is an octet.

[0084] In this embodiment, the digital certificate adopts the X.509 V3 format. The X.509 certificate may include multiple extended attributes. The extended attributes are encapsulated using the Context type, and their value field is the first SEQUENCE. The value field of this first SEQUENCE includes two data items: (1) OID (Object Identifier), which identifies the meaning expressed by the extended attribute and is of type Object Identifier; (2) the second SEQUENCE, whose value field is one or more information items of the extended attributes, wherein the second SEQUENCE may be absent. The extended items of the first STA certificate in this embodiment are defined as follows:

[0085] (1) Intent to apply:

[0086] OID: 1.2.156.11235.3002.1;

[0087] There is no second SEQUENCE.

[0088] (2) Application information:

[0089] OID: 1.2.156.11235.3002.2;

[0090] The contents of the second SEQUENCE include:

[0091] (a) First STA information: PrintableString type, storing the content of the first STA information;

[0092] (b) P10 file extension: PrintableString type, storing the P10 PEM format content;

[0093] (c) Signature information: BIT STRING type, which stores the signature value.

[0094] The extended items of the second STA certificate involved in this embodiment are defined as follows:

[0095] (1) Certificate issuance result:

[0096] OID: 1.2.156.11235.3003.1;

[0097] The contents of the second SEQUENCE include:

[0098] (a) Issuance processing result value: INTEGER type, its value is an integer value, which is the issuance processing result value of the WAPI certificate issuance processor;

[0099] (b) STA Certificate: PrintableString type, storing the PEM format content of the WAPI certificate issued to the wireless terminal by the WAPI certificate issuing processor; when the issuing result value is unsuccessful, this item is a PrintableString type value with a length of 0.

[0100] (c)AS Certificate: PrintableString type, which stores the PEM format content of the WAPI certificate of the WAPI certificate authenticator.

[0101] When the issuance processing result is "issuance unsuccessful", both STA and AS certificates are PrintableString type values ​​with a length of 0.

[0102] This embodiment exports the first STA information of the wireless terminal and imports the first CIS information before powering on during the production process or business environment of the wireless terminal. Based on the public key information of the wireless terminal and CIS exchanged during the subsequent WAPI authentication process for the purpose of applying for a WAPI certificate, mutual authentication is performed, achieving mutual trust checks between the certificate obtainr (wireless terminal) and the certificate issuer (WAPI certificate issuer), resulting in better security. For sensors with externally sealed structures, in a factory production environment, relevant information can be obtained by extracting the control or debugging ports of the internal circuit board before the structure is sealed, which is practically feasible.

[0103] In this embodiment, the wireless terminal distinguishes between the public and private keys required for the certificate application process and the public and private keys required for the WAPI authentication process. This makes the scope of use clearer and more in line with general security principles. In this embodiment, the public and private keys required for the application process are generated before production or power-on, i.e., the first STA key pair, while the public and private keys involved in the WAPI certificate are generated only at the time of application, i.e., the second STA key pair. Moreover, in the WAPI authentication process for the purpose of certificate application, the digital certificate used by the wireless terminal is the STA key pair.

[0104] In this embodiment, the application information for the wireless terminal uses a certificate application file, namely the P10 file, which is more in line with the conventions of existing certificate systems and allows for certificate generation using common software code such as OpenSSL.

[0105] This embodiment pre-configures the service SSID for the wireless terminal in the first database of the WAPI certificate issuer and distributes it to the certificate holder, i.e., the wireless terminal, during the certificate application process. This allows the wireless terminal to automatically connect to the service SSID immediately after obtaining the WAPI digital certificate. If other configurations need to be distributed to the wireless terminal, they can be implemented by referring to the SSID distribution method. This completely solves the problem that the wireless terminal does not need to be configured in the service environment, making it more convenient and faster to use.

[0106] This embodiment introduces a WAPI certificate issuer, which has better adaptability in practical applications. For example, in power networks, the current practice of provincial power companies building WAPI wireless private networks is to deploy WAPI certificate authentication devices in cities and prefectures, and wireless access points in substations. Under this deployment architecture, a single WAPI certificate issuer system can be used for the entire province by the provincial power company. In this way, for WAPI wireless terminals in a certain province, the first CIS information can be uniformly imported for the wireless terminals of power customers in that province during production, without needing to distinguish between cities and prefectures.

[0107] This embodiment enables online application for WAPI certificates based on the intended WAPI network access, automatically realizing the online application of WAPI digital certificates. During the application process, the trustworthiness of the wireless terminal and the certificate issuer (WAPI certificate issuer) is mutually checked, and the required SSID can be automatically obtained. Overall, the wireless terminal automatically connects to the WAPI wireless network, achieving plug-and-play functionality and avoiding the need for on-site certificate installation and SSID configuration on the WAPI terminal. This solves the problem that WAPI wireless terminals cannot automatically apply for WAPI digital certificates online to achieve plug-and-play functionality, providing good security and convenience.

[0108] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0109] This document uses specific examples to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the methods and core ideas of this application. Furthermore, those skilled in the art will recognize that, based on the ideas of this application, there will be changes in the specific implementation methods and application scope. Therefore, the content of this specification should not be construed as a limitation of this application.

Claims

1. A method for wireless terminal automatic access to WAPI network, characterized in that, The WAPI certificate authenticator has a first AS certificate, and the WAPI certificate issuer has a first CIS key pair and a first CIS information, and also stores the first AS certificate, wherein the first CIS information includes CIS information and a CIS public key of the WAPI certificate issuer, and the CIS public key is a public key of the first CIS key pair. The method for the wireless terminal to automatically access the WAPI network includes: S1: in the stage before starting the service communication, the first CIS information is imported into the wireless terminal, the wireless terminal generates a first STA key pair and a first STA information, and the first STA information is exported from the wireless terminal, wherein the first STA information includes identification information and a STA public key of the wireless terminal, and the STA public key is a public key of the first STA key pair; S2: in the stage before starting the service communication, the first STA information is imported into a first database of the WAPI certificate issuer to form a wireless terminal table item, and a service SSID corresponding to the wireless terminal is configured in the wireless terminal table item; S3: in the stage after the power-on in the service environment, the wireless terminal is connected to any SSID in a WAPI-CERT authentication mode in the service environment, and performs a WAPI authentication with the wireless access point, wherein in the WAPI authentication process, an application intention and application information are carried in an extension attribute of a first STA certificate in an access certificate authentication request message, and a signing result generated when the WAPI certificate issuer signs and service SSID configuration information are carried in an authentication result field in a certificate authentication response message; the application intention means that a specific OID is included in a certificate extension item of a STA digital certificate, and the WAPI certificate authenticator is indicated that the intention of the current WAPI access authentication request is to apply for the digital certificate of the wireless terminal; the application information includes the first STA information, a certificate application file and signature information, the signature information is generated by signing and calculating the content including the first STA information and the certificate application file by using a private key of the first STA key pair; the signing result includes a signing processing result value and a second STA certificate, wherein the signing processing result value is used to indicate the success or failure of the signing, and the second STA certificate is a self-signed digital certificate generated by the WAPI certificate issuer based on the first CIS key pair, and the second STA certificate includes the signing processing result value, a third STA certificate and the first AS certificate, and the third STA certificate is a WAPI digital certificate signed by the WAPI certificate issuer for the wireless terminal; S4: the WAPI certificate issuer searches the wireless terminal table item in the first database according to the application information, and checks the credibility of the wireless terminal according to the STA public key recorded in the wireless terminal table item. S5: The wireless terminal checks the credibility of the WAPI certificate issuer according to the CIS public key in the first CIS information stored locally.

2. The method for wireless terminal to automatically access WAPI network according to claim 1, characterized in that, The process that the wireless terminal automatically acquires the WAPI digital certificate from the WAPI certificate issuer specifically includes: After the wireless terminal is powered on in a service environment, the wireless terminal scans and associates with the SSID of the WAPI-CERT authentication mode, and performs WAPI authentication with the connected wireless access point; The wireless terminal generates a first STA certificate in the WAPI authentication process, and the first STA certificate includes an application intention extension item and an application information extension item; The WAPI certificate authenticator authenticates the first STA certificate, identifies the application intention of the wireless terminal, and sends a certificate issuance application to the WAPI certificate issuer, and the certificate issuance application includes the first STA certificate; After receiving the certificate issuance application, the WAPI certificate issuer performs issuance processing on the first STA certificate to generate an issuance result; After receiving the issuance result, the WAPI certificate authenticator generates an authentication result, and the verification result of the ASUE certificate in the authentication result is equal to the issuance processing result value, and the ASUE certificate is the second STA certificate; The wireless access point sends an access authentication response message to the wireless terminal according to a standard process, and the access authentication response message includes the authentication result; After receiving the access authentication response message, the wireless terminal obtains the issuance processing result value according to the verification result of the ASUE certificate in the authentication result, parses the ASUE certificate in the authentication result to obtain the second STA certificate in the case of successful issuance, and obtains the third STA certificate, the first AS certificate and the service SSID configuration information from the extension item information in the second STA certificate, wherein the third STA certificate is the WAPI certificate of the wireless terminal.

3. The method for wireless terminal to automatically access WAPI network according to claim 2, characterized in that, The process that the wireless terminal generates the first STA certificate specifically includes: The wireless terminal generates a second STA key pair; The wireless terminal generates a certificate application file, i.e. a P10 file, according to the second STA key pair; The wireless terminal generates a self-signed first STA certificate according to the first STA key pair; the first STA certificate includes an application intention extension item and an application information extension item, wherein the application information extension item includes the content of the first STA information, the information content of the P10 file and signature information, and the signature information is generated by signing the content including the first STA information and the P10 file using the private key of the first STA key pair; Based on the first STA certificate, the wireless terminal sends a certificate authentication request for WAPI authentication to the wireless access point.

4. The method for wireless terminal to automatically access WAPI network according to claim 3, characterized in that, The process that the WAPI certificate issuer performs the WAPI digital certificate issuance processing specifically includes: The WAPI certificate issuer parses the application information from the first STA certificate; The WAPI certificate issuer finds the corresponding wireless terminal table item in the first database according to the first STA information, and when the corresponding wireless terminal table item is found, the signature in the application information is verified using the STA public key recorded in the wireless terminal table item; if the verification is passed, the wireless terminal generates a WAPI digital certificate, i.e., the third STA certificate; finally, an issuing result is formed, which includes an issuing processing result value, the third STA certificate and the first AS certificate, wherein the issuing processing result value is used to indicate whether the issuing is successful or not, and when the issuing is successful, the issuing result value is 100, otherwise, a value greater than 100 is used to indicate other unsuccessful reasons, including that the corresponding wireless terminal table item is not found, the signature verification is not passed, and the generation of the WAPI digital certificate of the wireless terminal is not successful; The WAPI certificate issuer generates a self-signed digital certificate, i.e., the second STA certificate, based on the first CIS key, wherein the second STA certificate includes an issuing processing result extension item and a service SSID configuration extension item, the issuing processing result extension item includes the issuing processing result, and the service SSID configuration extension item includes the service SSID configuration information recorded in the wireless terminal table item; The WAPI certificate issuer returns the issuing result to the WAPI certificate authenticator.

5. The method for wireless terminal to automatically access WAPI network according to claim 4, characterized in that, The process of the wireless terminal processing the issuing result specifically includes: After receiving the access authentication response message, the wireless terminal checks the authentication result value in the authentication result; When the authentication result value indicates that the issuing is successful, the wireless terminal parses the second STA certificate from the authentication result, and performs signature verification on the second STA certificate using the CIS public key in the locally stored first CIS information, when the signature verification is passed, the third STA certificate, the first AS certificate and the service SSID configuration information are extracted from the extension item of the second STA certificate; When the authentication result value indicates that the issuing is not successful, or the signature verification is not passed, the wireless terminal performs processing of WAPI certificate acquisition failure.

6. The method for wireless terminal to automatically access WAPI network according to claim 5, characterized in that, After the wireless terminal receives the issuing result, the method of the wireless terminal automatically accessing the WAPI network further includes: After the wireless terminal obtains the third STA certificate, the first AS certificate and the service SSID configuration information from the issuing result, the wireless terminal installs the third STA certificate and the first AS certificate, and configures the service SSID according to the service SSID configuration information, and after the installation and configuration are completed, the wireless terminal automatically connects the service SSID and accesses the WAPI wireless network.

Citation Information

Patent Citations

  • Authentication method based on WAPI ( wireless LAN authentication and privacy infrastructure), access point and mobile terminal

    CN102026196A

  • WAPI wireless private network certificate issuing method and system

    CN115085938A