Method for establishing WAPI certificate application network channel

By generating self-signed certificates and importing databases before wireless terminals are connected to WAPI wireless network, the problem of wireless terminal certificate application in the industry with high security requirements is solved, secure access and online certificate application are realized, and certificate installation efficiency is improved.

CN120200755APending Publication Date: 2025-06-24SHENZHEN ZHIKAI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510321891.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-18
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

The prior art is unable to effectively solve the problem of certificate application when wireless terminals are used in multiple networks in industries with high security requirements, resulting in inefficient certificate installation.

Method used

Before the wireless terminal connects to the WAPI wireless network, generate a self-signed WAPI digital certificate and import the terminal information into the database of the certificate authenticator. Online application and authentication of certificates are realized through self-signed certificates and serial number checks.

Benefits of technology

It realizes that wireless terminals can access WAPI wireless networks securely and trustworthyly in a network with high security requirements, and solves the problem of online certificate application and improves the efficiency of certificate installation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200755A_ABST
    Figure CN120200755A_ABST
Patent Text Reader

Abstract

The invention discloses a WAPI certificate application network channel establishment method, which comprises the following steps: before an STA accesses a WAPI wireless network, terminal information containing an STA public key is exported from the STA, and the terminal information is imported into a terminal database of an AS; when the STA accesses the WAPI wireless service network, the STA performs WAPI authentication based on the self-signed digital certificate, the AS judges the credibility of the STA through self-signature verification of the STA certificate, terminal information searching and certificate serial number checking, and on the basis, the STA accesses the WAPI wireless service network to establish a certificate online application data channel. By means of the method, the WAPI wireless terminal without the digital certificate can establish a network channel with the WAPI wireless service network to be accessed, good AP compatibility is achieved, and therefore online application of the WAPI digital certificate can be achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technologies, and particularly to a method for establishing a network channel for WAPI certificate application. Background Art

[0002] WAPI (Wireless LAN Authentication and Privacy Infrastructure) is a wireless network security standard and technology stipulated in the Chinese national standard GB15629.11. WAPI uses digital certificates to identify the identities of wireless access points (APs) and wireless terminals (STAs), and conducts identity authentication of APs and STAs based on a three-factor authentication system, ensuring the security of wireless access authentication.

[0003] During the authentication process of an STA accessing the network, it first establishes a wireless association with the AP, and then conducts WAPI access authentication. Only when the authentication is successful can the STA access the wireless network for service communication. During the WAPI access authentication process, the STA includes the WAPI digital certificate of the terminal in the access authentication request message. The AP transmits the WAPI digital certificate of the STA and the WAPI digital certificate of the AP to the authentication server (AS) through the certificate authentication request message. The AS authenticates the digital certificates of the STA and the AP and sends a certificate authentication response. The AP determines whether the STA is trustworthy based on the authentication result in the certificate authentication response message. Only when the STA is trustworthy will the corresponding communication port be opened for the STA, otherwise the access of the STA will be rejected. The STA receives the access authentication response message from the AP, which also includes the authentication result. The STA determines whether the AP is trustworthy based on the authentication result and establishes a WAPI wireless connection with the AP when the AP is trustworthy, otherwise it will disconnect the wireless association with the AP.

[0004] Generally, the WAPI digital certificate of a terminal is issued by the WAPI authentication server in its place of origin, which means that the issuer of the digital certificate of the WAPI wireless terminal is the WAPI authentication server in its place of origin, and the digital certificate of the WAPI wireless terminal is not self-signed.

[0005] According to the basic principle of WAPI access authentication, if a WAPI wireless terminal does not have a digital certificate, it cannot access the wireless network. If online application of a WAPI digital certificate is to be realized based on the network, the network is indispensable. In some industries with high security requirements such as the power grid, due to security management regulations not allowing "one device on two networks", that is, not allowing a network device to be used in multiple networks, the wireless terminal cannot connect to other networks to obtain a WAPI digital certificate. Currently, the certificate installation of the terminal is achieved by manually copying the WAPI digital certificate, which affects the efficiency of certificate installation.

[0006] The patent applications of the present applicant, namely, "A Method for Applying for a WAPI Certificate, a Wireless Terminal, and Certificate Authentication" (Patent Application No. 202210920349.1) and "A Method for a Wireless Terminal to Automatically Access a WAPI Network" (Patent Application No. 202510161749.2), both include a basic solution: the STA generates a self-signed WAPI digital certificate and conducts WAPI authentication based on the WAPI wireless network to be accessed. During the WAPI authentication process, the application information is carried in the extension item of the self-signed certificate generated by the STA, and the certificate issued for the STA is carried in the extension item of the self-signed certificate generated by the certificate discriminator or the certificate issuing server, thus realizing online certificate issuance. In this solution, during the WAPI wireless access authentication process for applying for a certificate, it is a WAPI authentication where the authentication result of the STA certificate fails, that is, after the certificate application is completed during the WAPI authentication process, the STA and the AP do not establish a wireless link. It can also be shown from the description in the relevant specification that the authentication result of the STA certificate is not 0. This method can solve the online application of the STA certificate, but there are the following deficiencies: (1) The STA certificate in the access authentication request message is inconsistent with the STA certificate included in the authentication result in the certificate authentication response message. If the AP device checks this, the WAPI authentication process will terminate due to this abnormality, and thus the certificate application cannot be achieved; (2) The extension item of the self-signed certificate generated by the certificate discriminator or the certificate issuing server included in the authentication result generated by the AS contains the certificate issued to the STA, the root certificate of the AS, and other information. Since both the certificate authentication response message sent by the AS and the access authentication response message sent by the AP contain the authentication result, this causes the certificate authentication response message and the access authentication response message to be too large, and there may be compatibility problems for the AP. Summary of the Invention

[0007] Based on the technical problems existing in the background art, the present invention proposes a method for establishing a network channel for WAPI certificate application.

[0008] A method for establishing a network channel for WAPI certificate application proposed by the present invention includes:

[0009] Before the STA accesses the WAPI wireless network, it generates a first public-private key pair of the STA (including a first public key and a first private key) and first STA information, where the first STA information includes the first public key, and exports the first STA information;

[0010] Before the STA accesses the WAPI wireless network, it imports the first STA information into the first terminal database of the AS;

[0011] After the STA associates with the AP in the WAPI wireless network to be accessed, it first generates a self-signed first WAPI digital certificate based on the first public-private key pair, and then sends an access authentication request message to the WAPI wireless access point. The access authentication request message contains the first WAPI digital certificate;

[0012] After the AS receives the WAPI certificate authentication request sent by the AP associated with the STA, when authenticating the STA certificate in the WAPI certificate authentication request, it first checks whether the STA certificate is a self-signed certificate. If not, it goes through the general WAPI certificate authentication process. If so, then: (a) Look up the STA record in the first terminal database according to the public key information of the STA certificate. If not found, it goes through the general WAPI certificate authentication process; (b) If found, perform a self-signature verification on the STA certificate. If the verification passes, it is determined that the STA certificate authentication passes; otherwise, it is determined that the authentication fails;

[0013] After the STA receives the WAPI access authentication response message from the associated AP, it analyzes the authentication result in the access authentication response message. If the verification results of the certificates of the associated AP and the STA itself in the authentication result are both passed, it trusts the associated AP and further performs key negotiation in the WAPI authentication protocol process, thereby establishing a wireless link with the associated AP and forming a network channel between the STA and the WAPI wireless network.

[0014] Preferably, a method for establishing a WAPI certificate application network channel in the present application further has the following characteristics:

[0015] Before each access authentication request message is sent, the STA generates a self-signed first WAPI digital certificate based on the first public-private key pair, that is, the first WAPI digital certificates included in each access authentication request message are different;

[0016] A preferred method is that when the STA generates a self-signed first WAPI digital certificate based on the first public-private key pair, it generates a strictly monotonically increasing certificate serial number each time;

[0017] Preferably, a method for establishing a WAPI certificate application network channel in the present application further has the following characteristics:

[0018] When the AS authenticates the STA certificate in the WAPI certificate authentication request, after completing the self-signature check of the STA certificate, it also checks the serial number of the STA certificate. If the serial number of the STA certificate is less than or equal to the serial number of the corresponding STA recorded in the current first terminal database, the STA certificate is regarded as failing the authentication;

[0019] To implement this check for the monotonically increasing sequence number, when the STA certificate is considered authenticated, the AS records the sequence number of the STA certificate in the first terminal database.

[0020] In a second aspect, a method for establishing a WAPI certificate application network channel, applied to a WAPI wireless terminal (STA), has the following features:

[0021] It can generate a WAPI public-private key pair, generate STA information, and be able to export the STA information, where the STA information includes the public key information of the WAPI public-private key pair;

[0022] It can generate a self-signed WAPI certificate based on the WAPI public-private key pair and include the self-signed WAPI certificate in the WAPI access authentication request, where the sequence number of the self-signed WAPI certificate in each WAPI access authentication request is strictly monotonically increasing.

[0023] In a third aspect, a method for establishing a WAPI certificate application network channel, applied to a WAPI certificate authenticator (AS), has the following features:

[0024] It has a terminal database to record the information of the wireless terminal for the certificate to be applied, and can import the information of the wireless terminal for the WAPI certificate to be applied, where the wireless terminal information includes the public key information of the wireless terminal;

[0025] When authenticating the STA certificate in the WAPI certificate authentication request, first check whether the STA certificate is a self-signed certificate. If not, go through the general WAPI certificate authentication process. If it is, then:

[0026] Search for the STA record in the first terminal database according to the public key information of the STA certificate. If not found, go through the general WAPI certificate authentication process;

[0027] If found, perform a self-signature verification on the STA certificate. If the verification fails, it is determined that the STA certificate authentication fails;

[0028] If the verification passes, perform a strict monotonically increasing check on the sequence number of the STA certificate. If the strict monotonically increasing check of the sequence number passes, it is determined that the authentication passes; otherwise, it is determined that the authentication fails.

[0029] The beneficial effects in the present invention are:

[0030] 1. Before a WAPI wireless terminal connects to a WAPI wireless network to apply for a digital certificate, the terminal information containing the public key information of the wireless terminal is exported from the wireless terminal and imported into the terminal database of the WAPI certificate discriminator. When the wireless terminal accesses the WAPI wireless network for WAPI authentication, it generates a self-signed WAPI digital certificate and includes this self-signed terminal certificate in the WAPI access authentication request message. The AP extracts the terminal certificate from the access authentication request message and includes the terminal certificate and the AP certificate in the certificate discrimination request message. The WAPI certificate discriminator in the WAPI wireless network obtains the terminal certificate from the certificate discrimination request message. When authenticating the terminal certificate, if it is checked that the terminal certificate is a self-signed certificate, the terminal information is searched in the terminal database based on the public key information of the terminal certificate. If the corresponding terminal information is found, the self-signature verification of the terminal certificate is performed. If the self-signature verification passes, it is determined that the terminal certificate passes the authentication. If both the wireless certificate and the digital certificate of the wireless access point pass the authentication, the wireless terminal and the associated wireless access point trust each other and establish a wireless link. Under this solution, a wireless terminal without a WAPI certificate issued by the WAPI discriminator can securely and credibly access the intended WAPI wireless service network, so that the WAPI wireless terminal can establish data communication with the WAPI wireless network and perform an online certificate application operation, thus solving the problem of applying for WAPI wireless terminal certificates in some high-security scenarios where only the WAPI wireless service network is available, and this method has good compatibility with the AP. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] Figure 1 It is an application environment diagram of the present invention;

[0032] Figure 2 It is a content diagram of the WAPI digital certificate format of the present invention;

[0033] Figure 3 It is the content of the P10 file format of the present invention;

[0034] Figure 4 It is a processing flow chart for the AS to authenticate the wireless terminal of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0035] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0036] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.

[0037] A method for establishing a WAPI certificate application network channel provided by an embodiment of this application can be applied to an application environment as Figure 1 shown. Among them, the wireless access point 102 (also known as AP 102) and the certificate authenticator 103 (also known as AS 103) constitute a WAPI wireless network. The wireless terminal 101 (also known as STA 101) accesses the WAPI wireless network by establishing a wireless link with the wireless access point 102. If the wireless terminal 101 has a WAPI digital certificate, then the wireless terminal 101 can perform WAPI access authentication with the AP to achieve secure access to the WAPI wireless network.

[0038] The WAPI digital certificate, its composition content is as Figure 2 shown. Among them, the issuer name indicates the signing entity of the certificate, and the subject name of the digital certificate is the owner name of the certificate. Both the issuer name and the owner name are identified by multiple DNs (Domain Names). In the WAPI wireless network, the issuer of the WAPI digital certificate of the wireless terminal is the certificate authenticator. For example, Figure 1 in the digital certificate of the wireless terminal 101 in is signed by the certificate authenticator 103. In this way, the subject name and the issuer name of the WAPI digital certificate of the wireless terminal 101 are not the same, and the WAPI digital certificate of the wireless terminal 101 is signed by the certificate authenticator 103.

[0039] The problem to be solved in this embodiment is how the wireless terminal 101 can securely and informationally establish a network connection with the WAPI wireless network to form a network channel and how to perform an online digital certificate application based on this network channel without the certificate signed by the certificate authenticator 103, which is not within the scope described in this application.

[0040] To solve this problem, the approach in this embodiment is that the STA 101 performs the following two preparatory operations before accessing the WAPI wireless network:

[0041] Generate the first public-private key pair (including the first public key and the first private key) of the STA 101 and the first STA information, where the first STA information includes the first public key information, and export the first STA information;

[0042] Import the first information of the STA 101 into the first terminal database of the AS.

[0043] For the first STA information, in one embodiment, the P10 file format is adopted. As Figure 3 shown, the P10 file (abbreviation of the standard PKCS#10) includes the subject name of the terminal device, public key information, etc., but does not include private key information, and also includes the P10 signature information generated by the producer using its private key.

[0044] To import the information of STA 101 into the first terminal database of the AS, in one embodiment, the P10 file is parsed, and the key information is stored in the first terminal database of the AS, where one of the key information is the public key information of the terminal.

[0045] For the operation of exporting terminal information, if such a wireless terminal has an external wired network interface, this operation can be carried out in the office of the deployment unit before the deployment of the terminal device, or in the production process; if such a wireless terminal does not have an external wired network interface, such as some sensor products, this operation is usually carried out in the production process.

[0046] On the basis of the above two preparations, after STA 101 is powered on and associated with AP 102 in the WAPI wireless network, the following steps will be used to securely and trustworthily establish a network channel with the WAPI wireless network:

[0047] S1: STA 101 first generates a self-signed first WAPI digital certificate based on the first public-private key pair, and then sends an access authentication request message to the WAPI wireless access point AP 102. The access authentication request message includes the first WAPI digital certificate;

[0048] S2: After receiving the WAPI certificate authentication request sent by AP 101, when authenticating the STA certificate in the WAPI certificate authentication request, as Figure 3 shown, first check whether the STA certificate is a self-signed certificate. If not, the general WAPI certificate authentication process is followed. If so: (a) Look up the STA record in the first terminal database according to the public key information of the STA certificate. If not found, the general WAPI certificate authentication process is followed; (b) If found, perform a self-signature verification on the STA certificate. If the verification passes, it is determined that the STA certificate authentication passes; otherwise, it fails.

[0049] S3: After STA 101 receives the WAPI access authentication and authentication response message from AP 102, it analyzes the authentication result in the access authentication and authentication response message. If the verification results of the certificates of AP 102 and STA 101 in the authentication result are both passed, then trust AP 101, and further complete the key negotiation of the WAPI authentication protocol process to establish a wireless link with AP 102, thereby establishing a data channel with the WAPI wireless network.

[0050] In this process, the processing process of AP 102 is the standard WAPI message processing process, that is, after AP 102 receives the access authentication request message of STA 101, AP 102 obtains the digital certificate of STA 101 from the access authentication request message. AP 102 does not perform authentication checks on the digital certificate of STA 101. AP 102 sends the digital certificate of STA 101 and the digital certificate of AP 102 to the certificate authenticator AS 103 through the certificate authentication request message for certificate authentication, and AS 103 authenticates the digital certificates of STA 101 and AP 102 and sends a certificate authentication response. AP 102 determines whether STA 101 is trustworthy according to the authentication result in the certificate authentication response message. Only when STA 101 is trustworthy will AP 102 open the communication port for STA 101, otherwise it will reject the access of STA 101. STA 101 receives the access authentication response message from AP 102, which also includes the authentication result. STA 101 determines whether AP 102 is trustworthy according to the authentication result. When AP 102 is trustworthy, it establishes a WAPI wireless connection with AP 102, otherwise it will disconnect the wireless association with AP 102.

[0051] It should be noted that when STA 101 generates a self-signed digital certificate, the issuer name and owner name of the certificate are the same, both are the information of STA 101 itself. According to the convention of the WAPI digital certificate, in addition to the fixed mandatory field ("WAPI") and country field ("CN"), it also includes an administrative domain, a network domain, and a device domain. An exemplary implementation is that the administrative domain and network domain can be set to "UNKNOWN", and the device domain can be set to the MAC address of the device. Since the digital certificate generated by STA 101 is a self-signed digital certificate, the issuer name and owner name of the certificate are the same.

[0052] The solution of this application precisely determines the particularity of the wireless terminal by taking advantage of the fact that the terminal certificate is a self-signed certificate, that is, this wireless terminal does not yet have a digital certificate issued by the WAPI certificate authenticator. The AS looks up the terminal record in the AS's terminal database based on the public key information of the terminal certificate. If found, it indicates that this wireless terminal is a wireless terminal that has been pre-filed and allowed to apply for a WAPI digital certificate online in the WAPI wireless network. Further, verifying the signature of the self-signed certificate (i.e., signature verification) can determine whether the terminal certificate is generated by the wireless terminal. Verifying the signature of the self-signed certificate is to extract the public key information from the digital certificate and verify the signature value of the digital certificate with the extracted public key.

[0053] As a preferred embodiment solution, a method for establishing a WAPI certificate application network channel in the present invention further includes the following processing:

[0054] (1) Before each access authentication request message is sent, STA 101 generates a self-signed first WAPI digital certificate based on the first public-private key pair, that is, the first WAPI digital certificate included in each access authentication request message is different;

[0055] To achieve this, in one embodiment, when the wireless terminal generates a self-signed first WAPI digital certificate based on the first public-private key pair, a strictly monotonically increasing certificate serial number is generated each time, so that the self-signed certificate generated each time is a different digital certificate;

[0056] (2) When AS103 authenticates the STA certificate in the WAPI certificate authentication request, after the self-signature check of the STA certificate, the serial number of the STA certificate is also checked. If the serial number of the STA certificate is less than or equal to the serial number of the corresponding STA recorded in the current first terminal database, the STA certificate is determined to fail the authentication;

[0057] To implement this serial number monotonically increasing check, when the STA certificate authentication of AS103 passes, the serial number of the STA certificate is recorded in the first terminal database.

[0058] Through the above mechanism, replay attack resistance is achieved. Even if an attacker obtains the self-signed certificate generated by the wireless terminal from the air interface or other channels, the attacker cannot successfully connect to the WAPI wireless network with this certificate. The WAPI authentication passes during access authentication because the AS can identify the counterfeiting behavior of certificate reuse when checking the serial number of the certificate. If the attacker modifies the serial number in the digital certificate, the AS can also identify the counterfeiting behavior of certificate tampering when verifying the signature of the digital certificate.

[0059] It should be further noted that in this embodiment, since the first private key of the first public-private key pair generated by the wireless terminal does not leave the device (how to protect the private key data is not within the scope of this application), even if the public key data exported from the wireless terminal is made public or leaked, it does not affect the security of this embodiment, which is guaranteed by the principle of asymmetric cryptography. The self-signed certificate generated by the wireless terminal during the WAPI access authentication process is exactly generated by using the first private key for the signature value, and it has the characteristic of being non-forgeable. The AS performs self-signature verification during the terminal certificate authentication, so as to determine the authenticity of the digital certificate of the wireless terminal.

[0060] The above is only a preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, according to the technical solution and inventive concept of the present invention, makes equivalent replacements or changes, and should be covered by the protection scope of the present invention.

Claims

1. A method for establishing a WAPI certificate application network channel, characterized in that: Applied to a WAPI wireless terminal and a WAPI certificate authenticator, the method includes: Before accessing the WAPI wireless network, the STA generates a first public-private pair and first STA information of the STA, wherein the first public-private pair includes a first public key and a first private key, the first STA information includes the first public key, and the first STA information is derived; Before accessing the WAPI wireless network, the STA imports the first STA information into the first terminal database of the AS; After the STA associates with the AP in the WAPI wireless network to be accessed, it first generates a self-signed first WAPI digital certificate based on the first public-private key pair, and then sends an access authentication request message to the WAPI wireless access point, where the access authentication request message includes the first WAPI digital certificate; After the AS receives the WAPI certificate authentication request sent by the AP associated with the STA, when authenticating the STA certificate in the WAPI certificate authentication request, it first checks whether the STA certificate is a self-signed certificate. If not, it follows the general WAPI certificate authentication process. If it is, it: (a) searches for the STA record in the first terminal database according to the public key information of the STA certificate. If not, it follows the general WAPI certificate authentication process; (b) if it is found, it performs self-signature verification on the STA certificate. If the verification passes, it is determined that the STA certificate authentication passes. Otherwise, it is determined that the authentication fails. After the STA receives the WAPI access authentication response message from the associated AP, it analyzes the authentication result in the access authentication response message. If the verification results of the associated AP's certificate and the STA's own certificate in the authentication result are both passed, the associated AP is trusted, and the key negotiation of the WAPI authentication protocol process is further performed, thereby establishing a wireless link with the associated AP, forming a network channel between the STA and the WAPI wireless network.

2. The method for establishing a WAPI certificate application network channel according to claim 1, applied to a WAPI wireless terminal, is characterized in that: The STA generates the first self-signed WAPI digital certificate based on the first public-private key pair before sending an access authentication request message each time, that is, the first WAPI digital certificate included in each access authentication request message is different; When the STA generates a self-signed first WAPI digital certificate based on the first public-private key pair, it generates a strictly monotonically increasing certificate serial number each time.

3. The method for establishing a WAPI certificate application network channel according to claim 1, applied to a WAPI certificate authenticator, characterized in that: When the AS authenticates the STA certificate in the WAPI certificate authentication request, after completing the self-signature check of the STA certificate, it also checks the serial number of the STA certificate. If the serial number of the STA certificate is less than or equal to the serial number of the corresponding STA currently recorded in the first terminal database, the STA certificate is deemed to have failed authentication; In order to implement such a monotonically increasing check of the serial number, the AS records the serial number of the STA certificate in the first terminal database when the STA certificate is deemed to have passed authentication.

4. The method for establishing a WAPI certificate application network channel according to claim 2, applied to a WAPI wireless terminal, is characterized in that: Capable of generating a WAPI public-private pair, and generating STA information and capable of exporting the STA information, wherein the STA information includes public key information of the WAPI public-private pair; A self-signed WAPI certificate can be generated based on the WAPI public-private pair, and included in a WAPI access authentication request, wherein the serial number of the self-signed WAPI certificate in each WAPI access authentication request is strictly monotonically increased.

5. The method for establishing a WAPI certificate application network channel according to claim 3, applied to a WAPI certificate authenticator, is characterized in that: A terminal database is provided to record the wireless terminal information to be applied for a certificate, and is capable of importing the wireless terminal information to be applied for a WAPI certificate, wherein the wireless terminal information includes the public key information of the wireless terminal; When authenticating the STA certificate in the WAPI certificate authentication request, first check whether the STA certificate is a self-signed certificate. If not, follow the general WAPI certificate authentication process. If yes, then: Searching for STA records in the first terminal database according to the public key information of the STA certificate, and if not found, going through the general WAPI certificate authentication process; If found, the STA certificate will be self-signed and verified. If the verification fails, the STA certificate authentication will be considered failed. If the signature verification is successful, a strict monotonically increasing check is performed on the serial number of the STA certificate. If the strict monotonically increasing check of the serial number is successful, it is determined that the authentication is successful; otherwise, it is determined that the authentication is unsuccessful.

Citation Information

Patent Citations

  • WAPI certificate application method, wireless terminal and certificate identifier

    CN115278676A

  • Method for automatically accessing wireless terminal to wireless authentication and privacy infrastructure (WAPI) network

    CN119946636A