A wapi network security enhancement method based on dynamic key management and behavior analysis
The WAPI network security enhancement method, which utilizes dynamic key management and behavioral analysis, solves the problems of vulnerability to attack and insufficient behavioral monitoring in traditional WAPI static keys. It achieves high security and reliability of the WAPI network, timely identifies abnormal behavior, and enhances the network's resistance to attacks.
Patent Information
- Application Number
- CN202510550415.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-29
- Publication Date
- 2025-12-05
- Estimated Expiration
- 2045-04-29
AI Technical Summary
Traditional WAPI security mechanisms employ static key management, which is vulnerable to attacks and lacks real-time monitoring and analysis of terminal device behavior, making it difficult to identify and prevent cybersecurity threats.
Employing a dynamic key management mechanism and behavioral analysis methods, temporary keys are generated using elliptic curve cryptography. Combined with multi-factor authentication, including identity authentication, geolocation authentication, and user password authentication, the system monitors terminal device behavior in real time, builds a normal behavior model, and identifies abnormal behavior.
It improves the security and reliability of WAPI networks, reduces false rejection rates, responds promptly to abnormal behavior, enhances anti-attack capabilities, comprehensively identifies spoofed terminal devices, and improves the security of network access.
Smart Images

Figure CN120166394B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application belongs to the technical field of wireless communication security, and specifically relates to a WAPI network security enhancement method based on dynamic key management and behavior analysis. BACKGROUND
[0002] WAPI (Wireless Authentication and Privacy Infrastructure) is a wireless local area network security standard independently developed by China, and plays an important role in the field of wireless communication. However, with the rapid development of network technology and the increasing complexity of network attack means, the traditional WAPI security mechanism gradually exposes some shortcomings. The traditional WAPI adopts a static key management mode, and the key update period is long, which makes the key in a fixed state for a long time, and it is easy for attackers to obtain the key through brute force cracking, man-in-the-middle attacks and other means, thereby threatening the network security. At the same time, its authentication mechanism is relatively single, mainly relying on digital certificate for identity verification, lacking real-time monitoring and analysis of terminal device behavior, and being difficult to effectively identify disguised terminal devices or abnormal behavior, and being unable to timely discover and prevent potential security threats. SUMMARY
[0003] The purpose of the present application is to provide a WAPI network security enhancement method based on dynamic key management and behavior analysis. The present application can comprehensively identify abnormal behavior, and improve the security and reliability of terminal device access to WAPI network.
[0004] The technical solution of the present application is a WAPI network security enhancement method based on dynamic key management and behavior analysis, specifically comprising the following steps:
[0005] Step 1: the terminal device sends an access request to the access point, and the access point receives the request;
[0006] Step 2: the access point and the terminal device perform bidirectional key negotiation based on a dynamic key management mechanism to obtain a shared key;
[0007] Step 3: the access point performs behavior analysis and multi-factor authentication on the terminal device to verify the identity of the terminal device;
[0008] Step 4: if the terminal device identity authentication result is passed, the terminal device accesses the WAPI network for data communication using the shared key.
[0009] In the foregoing WAPI network security enhancement method based on dynamic key management and behavior analysis, in step 2, the process of bidirectional key negotiation is that after the access point receives the access request, a set of temporary key parameters is generated according to the current network security situation and preset rules, and an elliptic curve encryption algorithm is used to generate a temporary public key P of the access pointAP and a temporary private key S AP , and then sends the temporary public key P AP to the terminal device; after the terminal device receives the temporary public key P AP , it generates a temporary public key P Device and a temporary private key S Device of the terminal device, and then sends P Device back to the access point, and finally calculates a shared key K through an elliptic curve encryption algorithm, with the formula being:
[0010] K = S AP × P Device = S Device × P AP .
[0011] In the aforementioned WAPI network security enhancement method based on dynamic key management and behavior analysis, the specific steps of the dynamic key management mechanism are as follows:
[0012] Step 2.1: judging the key update trigger condition; the key update trigger condition includes time trigger and security event trigger;
[0013] Step 2.2: the access point generates a new temporary public key P APnew and a temporary private key S APnew of the access point through an elliptic curve encryption algorithm;
[0014] Step 2.3: the access point sends a key update notification message containing the new temporary public key P APnew to the terminal device that has accessed;
[0015] Step 2.4: after the terminal device receives the new temporary public key P AP , it generates a new temporary public key P Devicenew and a temporary private key S Devicenew of the terminal device, and then sends P Devicenew back to the access point;
[0016] Step 2.5: the access point and the terminal device respectively use the new temporary public key of the other party and the new temporary private key of themselves to calculate a new shared key K new through an elliptic curve encryption algorithm, with the formula being K new = S APnew × P Devicenew = S Devicenew × P APnew ;
[0017] Step 2.6: the access point and the terminal device use the new shared key K new for subsequent data communication, and record the update time of the shared key and related information.
[0018] In the aforementioned WAPI network security enhancement method based on dynamic key management and behavior analysis, the time-triggered process is to set a key update period T update When the time since the last key update t exceeds T update , the key update is triggered; the security event-triggered process is to trigger key update when a security event is detected in the network; the security event includes abnormal data packet flow and man-in-the-middle attack signs.
[0019] In the aforementioned WAPI network security enhancement method based on dynamic key management and behavior analysis, in step 3, the specific steps of the behavior analysis are as follows:
[0020] Step 3.1: Collect behavior data of terminal devices in real time through network monitoring terminal devices or software, store the collected behavior data into a database and perform data preprocessing;
[0021] Step 3.2: Calculate the behavior characteristics of the behavior data after data preprocessing, analyze the correlation between different behavior characteristics, and extract the correlation characteristics;
[0022] Step 3.3: Use historical normal behavior data to construct a normal behavior model through machine learning algorithm; set a threshold T of abnormal behavior according to the normal behavior model;
[0023] Step 3.4: Compare the behavior characteristics after real-time collection and processing with the normal behavior model, calculate the similarity score S; according to the similarity score S and the preset threshold T, make a judgment on the abnormal behavior of the terminal device.
[0024] In the aforementioned WAPI network security enhancement method based on dynamic key management and behavior analysis, in step 3.1, the behavior data includes data transmission rate, access time, access frequency, data packet size and communication protocol type.
[0025] In the aforementioned WAPI network security enhancement method based on dynamic key management and behavior analysis, the data preprocessing includes data cleaning and data normalization.
[0026] In the aforementioned WAPI network security enhancement method based on dynamic key management and behavior analysis, in step 3.4, the calculation formula of the similarity score S is as follows:
[0027]
[0028] Where X represents the behavior characteristic vector of the terminal device collected in real time, and Y represents the characteristic vector of the normal behavior model.
[0029] In the aforementioned WAPI network security enhancement method based on dynamic key management and behavior analysis, the calculation formula of the data transmission rate is:
[0030]
[0031] Wherein, μ represents the mean of the data transmission rate, σ represents the standard deviation of the data transmission rate, m is the number of acquisitions, r j represents the data transmission rate acquired in the jth acquisition.
[0032] In the aforementioned WAPI network security enhancement method based on dynamic key management and behavior analysis, the multi-factor authentication includes identity authentication, geographic location authentication and user password authentication.
[0033] In the aforementioned WAPI network security enhancement method based on dynamic key management and behavior analysis, the identity authentication is performed by sending a certificate from the terminal device to the access point, and then the access point verifies the certificate of the terminal device.
[0034] In the aforementioned WAPI network security enhancement method based on dynamic key management and behavior analysis, the geographic location authentication is performed by verifying the geographic location of the terminal device through GPS positioning information and / or Wi-Fi positioning information of the terminal device.
[0035] In the aforementioned WAPI network security enhancement method based on dynamic key management and behavior analysis, the user password authentication is performed by verifying the user input password.
[0036] In the aforementioned WAPI network security enhancement method based on dynamic key management and behavior analysis, in step 4, the authentication result is fed back to the terminal device and the network administrator, the terminal device is notified to access the network, and detailed information of the authentication is provided to the administrator.
[0037] Compared with the prior art, the present application has the following beneficial effects:
[0038] The application improves the security and reliability of terminal equipment accessing the WAPI network, and reduces the false rejection rate by fusing the dynamic key management mechanism, behavior analysis and multi-factor authentication. The application can quickly respond to abnormal behavior, issue an alarm in time and limit the access permission of abnormal terminal equipment through behavior analysis, and provides more intelligent and real-time protection for WAPI network security. The application can comprehensively identify abnormal behavior, reduce the success rate of disguised terminal equipment and malicious attacks, and improve the security of WAPI network access through multi-factor authentication. In addition, the dynamic key management mechanism of the application can update the communication key in time by setting reasonable trigger conditions and standard update processes, and enhance the security and attack resistance of the WAPI network. The behavior analysis module of the application can discover abnormal behavior in time through comprehensive collection, deep processing and intelligent modeling of terminal equipment behavior data, and provide strong protection for WAPI network security. The multi-factor authentication module of the application can comprehensively and strictly authenticate terminal equipment from multiple dimensions by combining identity authentication, geographic location authentication and user password authentication, and greatly improve the security of WAPI network access. BRIEF DESCRIPTION OF DRAWINGS
[0039] Figure 1 is a flowchart of the application;
[0040] Figure 2 is a flowchart of the dynamic key management mechanism of the application;
[0041] Figure 3 is a flowchart of the behavior analysis of the application. DETAILED DESCRIPTION
[0042] The application will be further described below in combination with the drawings and examples, but it is not used as the basis for limiting the application.
[0043] Embodiment: A WAPI network security enhancement method based on dynamic key management and behavior analysis, as shown in Figure 1 specifically includes the following steps:
[0044] Step 1: The terminal equipment sends an access request to the access point, and the access point receives the request.
[0045] In this step, the request contains the basic information of the terminal equipment, such as terminal equipment identifier, supported encryption algorithm, etc.
[0046] Step 2: The access point and the terminal equipment perform bidirectional key negotiation based on the dynamic key management mechanism to obtain a shared key.
[0047] In this step, the two-way key negotiation process involves the access point, upon receiving an access request, generating a set of temporary key parameters based on the current network security status and preset rules, and then using an elliptic curve cryptography algorithm to generate the access point's temporary public key P. AP and temporary private key S AP Then, the temporary public key P AP Send to the terminal device; the terminal device receives the temporary public key P AP Then, a temporary public key P for the terminal device is generated. Device and temporary private key S Device Then P Device The data is sent back to the access point, and finally the shared key K is calculated using the elliptic curve cryptography algorithm. The calculation formula is as follows:
[0048] K = S AP ×P Device =S Device ×P AP .
[0049] In this step, such as Figure 2 As shown, the specific steps of the dynamic key management mechanism are as follows:
[0050] Step 2.1: Determine the key update trigger conditions; the key update trigger conditions include time-based triggering and security event triggering;
[0051] In this embodiment, the time-triggered process involves setting a key update period T. update When the time t since the last key update exceeds T update When a key update is triggered, the security event is triggered when a key update is detected in the network. The security event includes abnormal packet traffic and signs of man-in-the-middle attacks.
[0052] Step 2.2: The access point generates a new temporary public key P using the elliptic curve cryptography algorithm. APnew and temporary private key S APnew ;
[0053] Step 2.3: The access point sends a key update notification message to the connected terminal devices. This message contains the new temporary public key P. APnew ;
[0054] Step 2.4: The terminal device receives the new temporary public key P AP Then, a new temporary public key P is generated for the terminal device. Devicenew and temporary private key S Devicenew Then P Devicenew Send back to the access point;
[0055] Step 2.5: The access point and the terminal device respectively use each other's new temporary public key and their own new temporary private key to calculate a new shared key K using the elliptic curve cryptography algorithm. new The calculation formula is K new =S APnew ×P Devicenew =S Devicenew ×P APnew ;
[0056] Step 2.6: Access points and terminal devices use the new shared key K new Subsequent data communication is then conducted, while the update time and related information of the shared key are recorded.
[0057] Step 3: The access point performs behavioral analysis and multi-factor authentication on the terminal device to verify the identity of the terminal device; the multi-factor authentication includes identity authentication, geographical location authentication and user password authentication.
[0058] In this step, the terminal device sends a digital certificate to the access point for identity verification. This authentication involves the terminal device sending the certificate to the access point, and then the access point verifies the validity and authenticity of the certificate, including the issuing authority, validity period, and signature. If the certificate is issued by an intermediate certificate authority, the access point also needs to verify the integrity of the certificate chain to ensure its legitimacy. Geographic location authentication verifies the terminal device's geographical location using its GPS and / or Wi-Fi location information. User password authentication verifies the password entered by the user.
[0059] In this step, such as Figure 3 As shown, the specific steps of behavioral analysis are as follows:
[0060] Step 3.1: Collect real-time behavioral data from terminal devices via network monitoring terminal equipment or software. Store the collected behavioral data in a database and perform data preprocessing. The behavioral data includes data transmission rate, access time, access frequency, data packet size, and communication protocol type. Data preprocessing includes data cleaning and data normalization. Data cleaning removes noise, outliers, and duplicate data from the collected data, improving data quality. Data normalization normalizes different types of behavioral data, mapping the data to the [0,1] interval for unified analysis and comparison. For example, for data transmission rate r, the formula r = (rr) can be used. min ) / (r max -r min Normalize r, where r min and r max These are the minimum and maximum data transmission rates, respectively.
[0061] Step 3.2: Calculate the behavior features of the pre-processed behavior data, analyze the correlation between different behavior features, and extract the correlation features, such as calculating the correlation coefficient between access frequency and data transmission rate;
[0062] In this embodiment, the collected behavior data is represented by a vector , where x i represents the i-th behavior feature. The collected raw data is processed to extract behavior features such as mean, standard deviation, variance, median, etc. For example, the mean μ and standard deviation σ of the data transmission rate are calculated, and the calculation formula is as follows:
[0063]
[0064] where μ represents the mean of the data transmission rate, m is the number of collections, r j represents the data transmission rate collected at the j-th time; σ represents the standard deviation of the data transmission rate.
[0065] Step 3.3: Use historical normal behavior data to construct a normal behavior model through machine learning algorithms such as Gaussian mixture model, support vector machine, etc.; set the threshold T of abnormal behavior according to the normal behavior model;
[0066] Step 3.4: Compare the real-time collected and processed behavior features with the normal behavior model, calculate the similarity score S; according to the similarity score S and the preset threshold T, judge the abnormal behavior of the terminal device.
[0067] The calculation formula of the similarity score S is as follows:
[0068]
[0069] where, represents the real-time collected terminal device behavior feature vector, and Y represents the feature vector of the normal behavior model.
[0070] Compare the real-time collected and processed behavior features with the normal behavior model, calculate the similarity score S. According to the similarity score S and the preset threshold T, judge whether the behavior of the terminal device is abnormal. If S < T, it is determined as abnormal behavior; otherwise, it is determined as normal behavior.
[0071] In this example, the abnormal behavior processing is as follows:
[0072] 1. Alarm: When abnormal behavior is detected, the system sends an alarm message to notify the network administrator;
[0073] 2. Limit access: limit the network access rights of the terminal device with abnormal behavior, such as only allow access to specific network resources;
[0074] 3. Record logs: Detailed records of abnormal behavior-related information, including time, behavior characteristics, similarity scores, etc., for subsequent analysis and investigation.
[0075] In this embodiment, if the identity authentication, behavior analysis, geographic location authentication, and user password authentication all pass, and the similarity score S is greater than the preset threshold T, it is determined that the terminal device authentication passes, and the terminal device is allowed to access the network; if any authentication fails or the similarity score S is less than or equal to the preset threshold T, it is determined that the terminal device authentication fails, and the terminal device is denied access to the network, and abnormal information is recorded. This dynamic key update is completed. Subsequent time triggers or security event triggers, the access point initiates the dynamic key management mechanism, and the bidirectional key negotiation in step 2 is repeated to generate a new shared key to ensure the security of network communication.
[0076] Step 4: If the terminal device identity authentication result passes, the terminal device uses the shared key to access the WAPI network for data communication.
[0077] In this step, the authentication result is fed back to the terminal device and the network administrator, and the terminal device is notified to access the network, and detailed information of the authentication is provided to the administrator.
[0078] The present application improves the security and reliability of terminal device access to WAPI network by fusing dynamic key management mechanism, behavior analysis and multi-factor authentication, and reduces the false rejection rate. The present application can quickly respond to abnormal behavior through behavior analysis, and timely issue an alarm and limit the access rights of abnormal terminal devices, providing more intelligent and real-time protection for WAPI network security. The present application can comprehensively identify abnormal behavior through multi-factor authentication, reduce the success rate of disguised terminal devices and malicious attacks, and improve the security of WAPI network access. In addition, the dynamic key management mechanism of the present application can update the communication key in time by setting reasonable trigger conditions and standardized update process, and enhance the security and attack resistance of WAPI network. The behavior analysis module of the present application can discover abnormal behavior in time through comprehensive collection, deep processing and intelligent modeling of terminal device behavior data, and provide strong protection for WAPI network security. The multi-factor authentication module of the present application can comprehensively and strictly authenticate terminal devices from multiple dimensions by combining identity authentication, geographic location authentication and user password authentication, greatly improving the security of WAPI network access.
[0079] In summary, the present application can comprehensively identify abnormal behavior, improve the security and reliability of terminal device access to WAPI network.
Claims
1. A WAPI network security enhancement method based on dynamic key management and behavior analysis, characterized in that, Specifically comprising the following steps: Step 1: the terminal device sends an access request to the access point, and the access point receives the request; Step 2: the access point and the terminal device perform bidirectional key negotiation based on a dynamic key management mechanism to obtain a shared key; Step 3: the access point performs behavior analysis and multi-factor authentication on the terminal device to verify the identity of the terminal device; Step 4: if the terminal device identity authentication result is passed, the terminal device accesses the WAPI network using the shared key for data communication; In step 2, the process of the bidirectional key agreement is that, after the access point receives the access request, a set of temporary key parameters is generated according to the current network security situation and preset rules, and the temporary public key of the access point is generated using an elliptic curve encryption algorithm and the temporary private key Then, the temporary public key is sent to the terminal device; after the terminal device receives the temporary public key , the temporary public key and the temporary private key of the terminal device are generated, and then is sent back to the access point, and finally, the shared key is calculated through the elliptic curve encryption algorithm, and the calculation formula is: ; The specific steps of the dynamic key management mechanism are as follows: Step 2.1: judging the key update trigger condition; the key update trigger condition includes time trigger and security event trigger; Step 2.2: The access point generates a new ephemeral public key of the access point by an elliptic curve encryption algorithm and an ephemeral private key ; Step 2.3: The access point sends a key update notification message to the accessed terminal device, which contains the new temporary public key ; Step 2.4: The terminal device receives the new temporary public key After, the new temporary public key of the terminal device is generated and the temporary private key is then sent back to the access point; Step 2.5: The access point and the terminal device respectively use the new temporary public key of the other party and the new temporary private key of itself to calculate a new shared key through an elliptic curve encryption algorithm , the calculation formula is ; Step 2.6: Access point and terminal device use new shared key Subsequent data communications are conducted while recording the update time and related information of the shared key. The time triggered process is to set the key update period The security event triggered process is to trigger key update when detecting a security event in the network The security event includes abnormal data packet flow and man-in-the-middle attack signs The security event triggered process is to trigger key update when detecting a security event in the network 2. The WAPI network security enhancement method based on dynamic key management and behavior analysis according to claim 1, characterized in that: In step 3, the specific steps of the behavior analysis are as follows: Step 3.1: monitoring the terminal device or software through the network, collecting behavior data of the terminal device in real time, storing the collected behavior data into a database and performing data preprocessing; Step 3.2: calculating the behavior characteristics of the behavior data after data preprocessing, analyzing the correlation between different behavior characteristics, and extracting the correlation characteristics; Step 3.3: using historical normal behavior data, constructing a normal behavior model through a machine learning algorithm; Setting a threshold for abnormal behavior according to a normal behavior model ; Step 3.4: compare the behavior features after real-time acquisition and processing with the normal behavior model, calculate the similarity score ; according to the similarity score and the preset threshold , make a terminal device abnormal behavior judgment.
3. The WAPI network security enhancement method based on dynamic key management and behavior analysis according to claim 2, characterized in that: In step 3.1, the behavior data includes data transmission rate, access time, access frequency, data packet size and communication protocol type.
4. The WAPI network security enhancement method based on dynamic key management and behavior analysis according to claim 2, characterized in that: The data preprocessing includes data cleaning and data normalization.
5. The WAPI network security enhancement method based on dynamic key management and behavior analysis according to claim 2, characterized in that: In step 3.4, the similarity score is calculated as follows: ; wherein, represents a real-time collected terminal device behavior feature vector, represents a feature vector of a normal behavior model.
6. The WAPI network security enhancement method based on dynamic key management and behavior analysis according to claim 3, characterized in that: The calculation formula of the data transmission rate is: ; ; wherein, denotes the mean value of the data transfer rate, denotes the standard deviation of the data transfer rate, is the number of acquisitions, denotes the data transfer rate of the acquired data.
7. The WAPI network security enhancement method based on dynamic key management and behavior analysis according to claim 1, characterized in that: The multi-factor authentication includes identity authentication, geographic location authentication and user password authentication.
8. The WAPI network security enhancement method based on dynamic key management and behavior analysis according to claim 7, characterized in that: The identity authentication is performed by the terminal device sending a certificate to the access point, and then the access point verifies the certificate of the terminal device.
9. The WAPI network security enhancement method based on dynamic key management and behavior analysis according to claim 7, characterized in that: The geographic location authentication is performed by verifying the geographic location of the terminal device through GPS positioning information and / or Wi-Fi positioning information of the terminal device.
10. The WAPI network security enhancement method based on dynamic key management and behavior analysis according to claim 7, characterized in that: The user password authentication is performed by verifying the user input password.
11. The WAPI network security enhancement method based on dynamic key management and behavior analysis according to claim 1, characterized in that: In step 4, the authentication result is fed back to the terminal device and the network administrator, the terminal device is notified to access the network, and detailed information of the authentication is provided to the administrator.
Citation Information
Patent Citations
5G network information security authority authentication method and system based on asymmetric algorithm
CN118714568A
Method for joining communication network
CN119547383A