WAPI access identification method and system containing key fast negotiation

By performing temporary public key exchange and base key calculation in advance during the WAPI access authentication process, and integrating unicast key negotiation and multicast key announcement, the problem of long WAPI access time is solved and the roaming switching efficiency of the wireless network is improved.

CN120602931AActive Publication Date: 2025-09-05STATE GRID SICHUAN ELECTRIC POWER CORP ELECTRIC POWER RES INST
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202511092942.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-06
Publication Date
2025-09-05
Estimated Expiration
2045-08-06

AI Technical Summary

Technical Problem

In the existing WAPI access process, multiple interactions between the STA and the AP result in a long access time and cannot meet the requirements of fast roaming handover.

Method used

During the WAPI access authentication process, temporary public key exchange and calculation of the base key BK and base key identifier BKID are performed in advance, integrating the unicast key negotiation and multicast key announcement processes to reduce the number of message exchanges.

Benefits of technology

It reduces WAPI access time and improves wireless network roaming switching efficiency, making it particularly suitable for industrial control application scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602931A_ABST
    Figure CN120602931A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of wireless communication, and discloses a WAPI access authentication method and a WAPI access authentication system containing key rapid negotiation in order to solve the problem of long time of traditional WAPI access. Temporary public key exchange and calculation of a base key and a base key identifier are carried out in advance in the WAPI access authentication process of an AP and an STA; bKID exchange and confirmation for unicast key negotiation and multicast key notification are completed in the WAPI access identification process; therefore, according to the method, a unicast key negotiation process and a multicast key notification process are fused into a WAPI access authentication process, so that wireless access between the AP and the STA is realized while access authentication is completed; therefore, the message interaction times of the wireless access point and the wireless terminal in the WAPI access process are reduced, so that the access time is reduced, and a better wireless roaming switching effect can be provided for a WAPI wireless network, particularly an industrial control application scene.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of wireless communications, and in particular to a WAPI access authentication method and system including fast key negotiation. Background Art

[0002] With the development of digitalization in industrial sites (such as substations and oil and gas stations), the terminal networks in these sites have shown the characteristics of "large bandwidth, mobility, and high security". Wireless local area networks based on WAPI (Wireless LAN Authentication and Privacy Infrastructure) have been increasingly used in these scenarios. Among them, WAPI is a wireless network security standard and technology specified in the Chinese national standard GB15629.11. It uses digital certificates to identify the identities of wireless access points (APs) and wireless terminals (STAs), and authenticates the identities of APs and STAs based on a three-factor authentication system, thereby ensuring the security of wireless access authentication.

[0003] The general process of wireless terminal accessing WAPI wireless network is as follows: Figure 1 As shown in the figure, it includes three sub-processes: access authentication, unicast key negotiation, and multicast key announcement. Currently, during the WAPI access process, the AP and STA need to perform access authentication first. Only after successful access authentication will the base key (BK) and base key identifier (BKID) be generated. Then, the two parties enter the unicast key negotiation process, which is to compare the consistency of the unicast key based on the BKID and negotiate the unicast communication key (UK) and the encryption key (MEK) for multicast key announcement. Finally, after completing the unicast key negotiation, the multicast announcement process begins, in which the AP announces the multicast key to the STA. The multicast key generated by the AP is encrypted with the MEK and sent to the STA, thus completing the WAPI access.

[0004] The existing WAPI access process (including access authentication, unicast key negotiation, and multicast key announcement) involves multiple interactions between STAs and APs. This is not suitable for applications that require fast network access. For example, in patrol robots or drones in smart stations, these terminals need to quickly roam between APs while moving. Therefore, existing WAPI access cannot meet the fast roaming handover requirements. Based on this, how to provide a WAPI access authentication method with fast access time and key negotiation has become an urgent problem to be solved. Summary of the Invention

[0005] The technical problem to be solved by the present invention is the problem of wireless terminal accessing WAPI wireless network. The purpose is to provide a WAPI access authentication method and system including fast key negotiation, which solves the problem that the WAPI access process in traditional technology involves multiple interactions between STA and AP, resulting in long access time and thus unable to meet the needs of fast roaming switching.

[0006] The present invention is achieved through the following technical solutions: In a first aspect, a WAPI access authentication method including fast key negotiation is provided, comprising: The AP generates an authentication activation message and sends it to the STA, where the authentication activation message includes the AP's first temporary public key and first certificate; After receiving the authentication activation message, the STA generates a second temporary public key, generates a second base key and a second base key identifier based on the first temporary public key in the authentication activation message, and sends an authentication access request message to the AP, where the authentication access request message includes the second base key identifier, the second temporary public key, and the STA's second certificate. The AP generates a first base key and a first base key identifier based on the second temporary public key in the authentication access request message, and upon determining that the first base key identifier is the same as the second base key identifier in the authentication access request message, sends a certificate authentication request to the WAPI authenticator, wherein the certificate authentication request includes the first certificate and the second certificate; The AP receives the certificate authentication result sent by the WAPI authenticator, and if the certificate authentication result is verified, generates multicast notification information based on the first base key, and sends an authentication response message to the STA, where the authentication response message includes the multicast notification information and the first base key identifier; The STA receives the authentication response message and, when determining that the second base key identifier is the same as the first base key identifier in the authentication response message, generates a session key based on the second base key and the multicast announcement information, and sends an access confirmation message to the AP; After receiving the access confirmation message, the AP opens the STA's controlled communication port to complete access authentication with the STA.

[0007] Based on the above-disclosed content, the present invention performs temporary public key exchange, calculation of base key BK and base key identifier BKID in advance during the WAPI access authentication process, and completes BKID exchange and confirmation for unicast key negotiation, as well as multicast information notification during the WAPI access authentication process. In this way, it is equivalent to integrating the unicast key negotiation and multicast key notification processes of WAPI into the WAPI access authentication process, so that after the access authentication is completed, the wireless access of AP and STA can be completed; based on this, the present invention omits the separate unicast key negotiation and multicast key notification sub-processes in the traditional technology, reduces the number of message interactions between the wireless access point and the wireless terminal during the WAPI access process, thereby reducing the access time, and can provide better wireless roaming switching effects for WAPI wireless networks, especially industrial control application scenarios; therefore, the present invention is very suitable for large-scale application and promotion.

[0008] In one possible design, the AP generates an authentication activation message that includes: Obtain the authentication identifier and the first certificate issued by the WAPI authenticator; Generate a first temporary public key and a first temporary private key, generate a first random number, and save the first temporary private key; The authentication activation message is generated using the authentication identifier, the first random number, the first certificate, and the first temporary public key.

[0009] In one possible design, the STA generates a second temporary private key before generating the second temporary public key, and the authentication activation message further includes the first random number; The method of generating a second base key and a second base key identifier according to the first temporary public key in the authentication activation message includes: Obtain key parameters and generate a second random number; Calculating a second shared key based on the first temporary public key and the second temporary private key; Generate the second base key according to the first random number, the second random number, the key parameter and the second shared key; The second base key identifier is generated using the second base key, the first random number, the second random number, and the key parameter.

[0010] In one possible design, the authentication access request message further includes a second random number, wherein the AP generates the first base key and the first base key identifier based on the second temporary public key in the authentication access request message, including: Obtaining a first temporary private key, a first random number, and key parameters, wherein the first temporary private key is generated before generating the first temporary public key, and the first random number is obtained when generating the authentication activation message; Generate a first shared key using the first temporary private key and the second temporary public key; Generate the first base key based on the first shared key, the first random number, the second random number and the key parameter; The first base key identifier is generated according to the first base key, the first random number, the second random number and the key parameter.

[0011] In one possible design, the authentication access request message further includes a second random number, wherein generating the multicast announcement information based on the first base key includes: Obtain a first random number, a second random number, a new key parameter, and a MAC address of the STA, wherein the first random number is obtained when generating an authentication activation message, and the second random number is obtained by parsing an authentication access request message; Generate an address identifier based on the MAC address of the STA and the target address, where the target address is the MAC address of the AP; Generate first key information based on the first base key, the new key parameter, the first random number, the second random number, and the address identifier, and using the HMAC-SHA256 algorithm; Determining a multicast key protection key based on the first key information; A multicast key is obtained, and the multicast key is used to protect the key and encrypt the multicast key to obtain the multicast announcement information.

[0012] In one possible design, determining a multicast key protection key based on the first key information includes: Divide the first key information into four information segments from left to right, wherein each information segment has the same length; Using the third information segment as the multicast key protection key; The first information segment obtained by evenly dividing is used as the first unicast session key of the AP, and after receiving the access confirmation message, the AP installs the first unicast session key to open the controlled communication port of the STA after installation.

[0013] In one possible design, the STA generates a session key based on the second base key and the multicast announcement information, including: generating second key information according to the second base key; Determining a multicast key protection key and a second unicast session key based on the second key information; Decrypting the multicast announcement information using a multicast key protection key to obtain a multicast key; The second unicast session key and the multicast key are used to form the session key, and after obtaining the session key, the session key is installed.

[0014] In one possible design, before generating the authentication activation message, the method further includes: The AP sends a beacon frame to the STA, wherein the beacon frame includes a manufacturer information element, and the manufacturer information element is used to indicate that the AP supports the WAPI fast key negotiation function; The STA receives the beacon frame and, after identifying that the beacon frame includes the vendor information element, generates an association request management frame and sends it to the AP, wherein the association request management frame includes the vendor information element; The AP receives the association request management frame and, after identifying that the association request management frame contains the manufacturer information element, sends an association response management frame containing the manufacturer information element to the STA, so as to enter the WAPI access authentication process including key fast negotiation after sending.

[0015] In one possible design, the method further includes: STA obtains the message content; The STA generates second key information based on the second base key, and generates a message authentication key based on the second key information; The STA generates a message authentication code using the message authentication key and the message content, and adds the message authentication code to the access confirmation message; Accordingly, after receiving the access confirmation message, the AP opens the controlled communication port of the STA, which includes: The AP verifies the message authentication code in the access confirmation message and determines whether the message verification succeeds. If so, the AP installs a first unicast session key and opens the controlled communication port of the STA after installing the first unicast session key, wherein the first unicast session key is obtained when the AP generates multicast announcement information based on the first base key.

[0016] In a second aspect, a WAPI access authentication system including fast key negotiation is provided, including: an AP and a STA, wherein the AP represents a wireless access node and the STA represents a wireless terminal: The AP is configured to generate an authentication activation message and send it to the STA, wherein the authentication activation message includes the AP's first temporary public key and first certificate; The STA is configured to, after receiving the authentication activation message, generate a second temporary public key, generate a second base key and a second base key identifier based on the first temporary public key in the authentication activation message, and send an authentication access request message to the AP, wherein the authentication access request message includes the second base key identifier, the second temporary public key, and the STA's second certificate; The AP is configured to generate a first base key and a first base key identifier based on the second temporary public key in the authentication access request message, and send a certificate authentication request to the WAPI authenticator when it is determined that the first base key identifier is the same as the second base key identifier in the authentication access request message, wherein the certificate authentication request includes the first certificate and the second certificate; The AP is configured to receive the certificate authentication result sent by the WAPI authenticator, and when the certificate authentication result is verification passed, generate multicast notification information based on the first base key, and send an authentication response message to the STA, wherein the authentication response message includes the multicast notification information and the first base key identifier; The STA is further configured to receive the authentication response message, and upon determining that the second base key identifier is the same as the first base key identifier in the authentication response message, generate a session key based on the second base key and the multicast announcement information, and send an access confirmation message to the AP; The AP is further configured to open the controlled communication port of the STA after receiving the access confirmation message, so as to complete access authentication with the STA.

[0017] In the third aspect, a WAPI access authentication device including rapid key negotiation is provided. Taking the device as an electronic device as an example, it includes a memory, a processor and a transceiver that are communicatively connected in sequence, wherein the memory is used to store computer programs, the transceiver is used to send and receive messages, and the processor is used to read the computer program and execute the WAPI access authentication method including rapid key negotiation as described in the first aspect or any possible design of the first aspect.

[0018] In a fourth aspect, a storage medium is provided, on which instructions are stored. When the instructions are executed on a computer, the WAPI access authentication method including fast key negotiation as described in the first aspect or any possible design of the first aspect is executed.

[0019] In a fifth aspect, a computer program product comprising instructions is provided, which, when executed on a computer, causes the computer to execute the WAPI access authentication method comprising fast key negotiation as described in the first aspect or any possible design of the first aspect.

[0020] Compared with the prior art, the present invention has the following advantages and beneficial effects: The present invention performs temporary public key exchange, calculation of the base key BK and the base key identifier BKID in advance during the WAPI access authentication process, and completes the BKID exchange and confirmation for unicast key negotiation, as well as the announcement of multicast information during the WAPI access authentication process. In this way, it is equivalent to integrating the unicast key negotiation and multicast key announcement processes of WAPI into the WAPI access authentication process, so that after the access authentication is completed, the wireless access of the AP and the STA can be completed; based on this, the present invention omits the separate unicast key negotiation and multicast key announcement sub-processes in the traditional technology, reduces the number of message interactions between the AP and the STA during the WAPI access process, thereby reducing the access time, and can provide a better wireless roaming switching effect for the WAPI wireless network, especially for industrial control application scenarios; therefore, the present invention is very suitable for large-scale application and promotion. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] In order to more clearly illustrate the technical solutions of the exemplary embodiments of the present invention, the following briefly introduces the drawings required for use in the examples. It should be understood that the following drawings only illustrate certain embodiments of the present invention and should not be considered as limiting the scope. A person of ordinary skill in the art can also derive other relevant drawings based on these drawings without inventive effort. In the drawings: Figure 1 A flowchart of traditional WAPI access authentication provided by an embodiment of the present invention; Figure 2 A schematic flow chart of the steps of a WAPI access authentication method including rapid key negotiation provided by an embodiment of the present invention; Figure 3 This is a flowchart of WAPI access authentication according to an embodiment of the present invention; Figure 4 A schematic diagram of the structure of the manufacturer information element provided in an embodiment of the present invention; Figure 5 A schematic diagram of the structure of a WAPI access authentication system including fast key negotiation provided by an embodiment of the present invention; Figure 6 A schematic structural diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0022] To make the objectives, technical solutions, and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the following examples and accompanying drawings. The exemplary embodiments of the present invention and their descriptions are intended only to explain the present invention and are not intended to limit the present invention. It should be understood that although the terms "first," "second," and so on may be used herein to describe various elements, these elements should not be limited by these terms. These terms are merely used to distinguish one element from another. For example, a first element may be referred to as a second element, and similarly, a second element may be referred to as a first element without departing from the scope of the exemplary embodiments of the present invention.

[0023] Example: See also Figure 2 As shown, the WAPI access authentication method including fast key negotiation provided in this embodiment performs temporary public key exchange and calculation of the base key BK and base key identifier BKID in advance during the WAPI access authentication process between the AP and the STA. Furthermore, the BKID exchange and confirmation for unicast key negotiation and multicast key announcement are completed during the WAPI access authentication process. Thus, the method is equivalent to integrating the unicast key negotiation and multicast key announcement processes into the WAPI access authentication process, thereby enabling wireless access between the AP and the STA while access authentication is completed. Consequently, the method reduces the number of message exchanges between the wireless access point and the wireless terminal during the WAPI access process, thereby reducing access time and providing better wireless roaming and handover performance for WAPI wireless networks, particularly in industrial control application scenarios. For example, the method may be, but is not limited to, executed on the wireless access point (AP), wireless terminal (STA), and WAPI authenticator side. It should be understood that the aforementioned execution entities do not constitute a limitation on this embodiment. Accordingly, the execution steps of the method may be, but are not limited to, steps S1 to S6 as shown below.

[0024] In a specific application, before using the method provided in this embodiment to perform WAPI access authentication, the AP and the STA will first confirm whether they support the API key fast negotiation function. The specific implementation process is shown in the following steps S01 to S03.

[0025] S01. The AP sends a beacon frame to the STA, wherein the beacon frame includes a manufacturer information element, and the manufacturer information element is used to indicate that the AP supports the WAPI fast key negotiation function; in a specific implementation, the wireless access point periodically sends a beacon frame to the STA, the beacon frame includes a manufacturer information element to indicate that it supports the WAPI fast key negotiation function; wherein the structure of the manufacturer information element is as follows Figure 4 As shown ( Figure 4The numbers in the information element are in hexadecimal. For example, its OUI (Organizationally Unique Identifier) ​​uses the WAPI Alliance's OUI identifier 0x001472, defines the type of this manufacturer information element as 0x65, and the content of the information element is the version number, which is currently 0x01. In this way, the manufacturer element information can be used to confirm whether the API key fast negotiation function is supported.

[0026] After sending a beacon frame to the STA, the STA may return a corresponding request management frame based on the beacon frame, and the process is shown in the following step S02.

[0027] S02. The STA receives the beacon frame and, after identifying that the beacon frame contains the vendor information element, generates an association request management frame and sends it to the AP. The association request management frame includes the vendor information element. In this embodiment, if the STA supports WAPI fast key negotiation and detects that the beacon (i.e., the aforementioned beacon frame) contains the vendor information element, the association request management frame returned by the STA includes the vendor information element. If the STA does not support WAPI fast key negotiation or the STA does not detect the vendor information element in the beacon frame, the association request management frame sent by the STA does not include the vendor information element. Based on this, after receiving the association request management frame, the AP can determine whether to enter the access authentication process based on WAPI fast key negotiation based on whether the vendor information element is included. This process is shown in the following step S03.

[0028] S03. The AP receives the Association Request Management Frame and, after identifying that the Association Request Management Frame contains the Manufacturer Information Element, sends an Association Response Management Frame containing the Manufacturer Information Element to the STA. After sending the frame, the AP enters the WAPI access authentication process including fast key negotiation. In a specific application, upon identifying that the Association Request Management Frame returned by the STA contains the Manufacturer Information Element, the AP responds by sending an Association Response Management Frame containing the Manufacturer Information Element to the STA, thereby notifying the STA to confirm the activation of the WAPI fast key negotiation function and enter the WAPI access authentication process based on fast key negotiation. Of course, if either party does not support the WAPI fast key negotiation function, the traditional access process will be entered.

[0029] In this way, after the capabilities of the two devices are negotiated based on the aforementioned steps S01 to S03, the WAPI access authentication process based on fast key negotiation can be entered, and the process is shown in the following steps S1 to S6.

[0030] S1. The AP generates an authentication activation message and sends it to the STA. The authentication activation message includes the AP's first temporary public key and first certificate. In a specific application, this embodiment generates the first temporary public key before generating the authentication activation message. The authentication activation message generation process may be, but is not limited to, steps S11 to S13 as shown below.

[0031] S11. The AP obtains the authentication identifier and the first certificate issued by the WAPI authenticator; in a specific implementation, the authentication identifier may be, but is not limited to, a 256-bit random number, which is used to identify a WAPI access authentication process; at the same time, the first certificate is the AP's public key authentication, which is issued by the WAPI authenticator to the AP and is pre-configured during network deployment.

[0032] In this way, after obtaining the authentication identifier and the first certificate, a first temporary public-private key pair and a first random number can be generated, and the process is shown in the following step S12.

[0033] S12. Generate a first temporary public key and a first temporary private key, as well as a first random number, and save the first temporary private key. In a specific application, the first temporary private key is first generated, and then the first temporary private key is used to generate the first temporary public key. At the same time, the aforementioned first temporary private key and public key can be generated by, for example, but not limited to, an elliptic curve cryptography algorithm. Among them, the elliptic curve cryptography algorithm is a commonly used encryption algorithm, and its public and private key generation process is not further described here.

[0034] At the same time, the first temporary public key will be transmitted to the STA, and the first temporary private key will be saved so that the base key and base key identifier can be calculated based on the first temporary private key. Of course, the specific calculation process is described below.

[0035] After obtaining the aforementioned first temporary public-private key pair, the first random number, the authentication identifier, and the first certificate, an authentication activation message may be generated based on the aforementioned information, and the process is shown in the following step S13.

[0036] S13. Generate the authentication activation message using the authentication identifier, the first random number, the first certificate, and the first temporary public key.

[0037] Thus, through the aforementioned steps S11 to S13, an authentication activation message including an authentication identifier, a first random number, a first certificate, and a first temporary public key can be generated, and then the authentication activation message can be sent to the STA to realize authentication activation. The flowchart can be seen in Figure 3 At the same time, after receiving the authentication activation message sent by the AP, the STA can calculate its own base key and base key identifier, and at the same time return an authentication access request to the AP, the process is shown in step S2 below.

[0038] S2. After receiving the authentication activation message, the STA generates a second temporary public key. Based on the first temporary public key in the authentication activation message, it generates a second base key and a second base key identifier. The STA then sends an authentication access request message to the AP. The authentication access request message includes the second base key identifier, the second temporary public key, and the STA's second certificate.

[0039] In specific applications, the generation process of the second temporary public key is the same as the generation process of the first temporary public key, that is, the second temporary private key is generated first, and then the second temporary public key is generated using the second temporary private key; of course, it is also generated using the elliptic curve encryption algorithm, and the second temporary private key is used for the subsequent calculation of the second base key and the second base key identifier.

[0040] Furthermore, this embodiment calculates the second base key and its identifier based on the second temporary private key generated before obtaining the second temporary public key, and in combination with the first temporary public key and the first random number in the authentication activation message sent by the AP; wherein the aforementioned calculation process can be but is not limited to the following steps S21 to S24.

[0041] S21. The STA obtains a key parameter and generates a second random number. In this embodiment, the key parameter is a preset string that is an inherent parameter between the AP and the STA. After obtaining the key parameter and the second random number, the second shared key can be calculated, as shown in step S22 below.

[0042] S22. The STA calculates a second shared key based on the first temporary public key and the second temporary private key. In a specific implementation, the second shared key can be calculated using, for example but not limited to, the Diffie-Hellman key exchange algorithm based on elliptic curve asymmetric cryptography, i.e., the second shared key SK2 = ECDH(second temporary private key, first temporary public key), where ECDH() represents the Diffie-Hellman key exchange algorithm based on elliptic curve asymmetric cryptography.

[0043] After the second shared key is calculated, the STA's own base key may be calculated in combination with the first random number, the second random number and the key parameter, as shown in step S23 below.

[0044] S23. The STA generates the second base key based on the first random number, the second random number, the key parameters, and the second shared key. In this embodiment, the second base key BK2 is: BK2 = HMAC-SHA256(SK2, N1||N2||M1). Where N1 and N2 represent the first and second random numbers, respectively, M1 represents the key parameters, HMAC-SHA256() represents the HMAC-SHA256 algorithm, i.e., the HMAC-SHA256 hash function, and || represents a concatenation operation. The key parameter M1 can be, but is not limited to, a string in the WAPI standard, i.e., "base key expansion for key and additional nonce."

[0045] Thus, after the second base key is calculated based on the aforementioned step S23, the second base key identifier can be calculated based on the second base key, and the process is shown in the following step S24.

[0046] S24. The STA generates the second base key identifier using the second base key, the first random number, the second random number, and the key parameter. In this embodiment, the second base key identifier BKID2 = HMAC-SHA256(BK2, N1||N2||M1).

[0047] Thus, through the aforementioned steps S21 to S24, the calculation of the second base key BK2 and the second base key identifier BKID2 can be completed; then, an authentication access request message can be generated; wherein, for example, but not limited to, the authentication access request message can be generated based on the authentication identifier in the aforementioned authentication activation message, the STA's second certificate, the second random number N2, the second temporary public key, and the second base key identifier; in this way, the authentication access request message contains the aforementioned information; of course, the STA's second certificate is its corresponding public key certificate, which is also issued by the WAPI authenticator.

[0048] In addition, in this embodiment, the aforementioned authentication access request message may also include, but is not limited to, STA signature information, where the STA signature information is generated by using the private key corresponding to its own public key certificate (i.e., the private key corresponding to the second certificate, also issued by the WAPI authenticator) to perform a signature calculation on the message content of the authentication access request message excluding the signature information. In this embodiment, a WAPI protocol message (abbreviated as WAI message) includes two parts: a message header and message content. The message content includes N information fields. If the message content includes signature information, the last field, i.e., the Nth information field, is the signature information, and the portion excluding the signature information is the content of the first N-1 information fields.

[0049] After receiving the authentication access request message, it can be sent to the AP. The process can be seen in Figure 3 After receiving the authentication access request message, the AP can generate its own first base key and its identifier for subsequent identification comparison; wherein, the generation process of the first base key and its identifier, and the identification comparison process are shown in step S3 below.

[0050] S3. The AP generates a first base key and a first base key identifier based on the second temporary public key in the authentication access request message. If the AP determines that the first base key identifier is the same as the second base key identifier in the authentication access request message, the AP sends a certificate authentication request to the WAPI authenticator, where the certificate authentication request includes the first certificate and the second certificate.

[0051] In this embodiment, the authentication access request message contains the STA's signature information and authentication identifier. Therefore, upon receiving the authentication access request message, the AP uses the second certificate contained in the authentication access request message to verify the signature information. After successful verification, the AP then verifies the authentication identifier. Specifically, the signature information and authentication identifier must be verified before generating the first base key and the first base key identifier. The authentication identifier verification process involves the AP determining whether the authentication identifier in the authentication access request message sent by the STA is identical to the authentication identifier in the authentication activation message in step S1. If they are different, the AP discards the authentication access request message, terminating the access authentication process. Otherwise, the AP calculates the first base key and the first base key identifier, as shown in steps S31 to S34.

[0052] S31. The AP obtains a first temporary private key, a first random number, and key parameters. The first temporary private key is generated before generating the first temporary public key, and the first random number is obtained when generating the authentication activation message. In this embodiment, the process of generating the first temporary private key and the first random number is described in step S1 and will not be repeated here. After obtaining the aforementioned data, the first shared key can be calculated, as shown in step S32.

[0053] S32. AP uses the first temporary private key and the second temporary public key to generate a first shared key; in specific applications, the first shared key is calculated in the same manner as the second shared key, ie, the first shared key SK1 = ECDH (first temporary private key, second temporary public key).

[0054] After obtaining the first shared key, the first base key may be calculated, and the process is shown in the following step S33.

[0055] S33. The AP generates the first base key based on the first shared key, the first random number, the second random number, and the key parameters. In this embodiment, the second random number is obtained by parsing the authentication access request message, and the first base key BK1 = HMAC-SHA256 (SK1, N1||N2||M1) is used as an example.

[0056] Thus, after the first base key is calculated based on the aforementioned step S33, the first base key identifier can be calculated based on the first base key, and the process is shown in the following step S34.

[0057] S34 AP generates the first base key identifier based on the first base key, the first random number, the second random number and the key parameter; in a specific implementation, for example, the first base key identifier BKID1 = HMAC-SHA256 (BK1, N1 | | N2 | | M1).

[0058] Thus, through the aforementioned steps S31 to S34, the calculation of the first base key and the first base key identifier can be completed. Then, the base key identifier can be compared. That is, the AP determines whether the first base key identifier is the same as the second base key identifier in the authentication access request message. If not, the authentication access request message is discarded, and the access authentication process ends. Otherwise, the AP generates a certificate authentication request using its own first certificate and the second certificate in the authentication access request message. Then, the certificate authentication request is sent to the WAPI authenticator (the transmission process of which can be seen in Figure 3 ), so that the WAPI authenticator performs certificate authentication after receiving the certificate authentication request and obtains a certificate authentication result (which may be fed back to the AP in the form of, but not limited to, a certificate authentication request response message, and the AP obtains the certificate authentication result by parsing the certificate authentication request response message).

[0059] In this way, after completing the certificate authentication, the AP can determine whether to perform multicast key announcement based on the certificate authentication result, and the process is shown in the following step S4.

[0060] S4. The AP receives the certificate authentication result from the WAPI authenticator. If the certificate authentication result is verified, the AP generates multicast notification information based on the first base key and sends an authentication response message to the STA. The authentication response message includes the multicast notification information and the first base key identifier. In a specific implementation, the AP first determines whether the certificate authentication result is verified (verification means that both the first certificate and the second certificate are verified). Then, after the certificate verification is successful, the AP calculates the first unicast session key and the multicast key protection key. Then, based on the multicast key protection key, the AP generates multicast notification information. The process of generating the multicast notification information may include, but is not limited to, steps S41 to S45.

[0061] S41. The AP obtains a first random number, a second random number, new key parameters, and the STA's MAC address. The first random number is obtained when generating the authentication activation message, and the second random number is obtained by parsing the authentication access request message. In this embodiment, the STA's MAC address is sent by the STA to the AP. After obtaining the aforementioned data parameters, an address identifier is generated, which is subsequently used to calculate the first key information. The address identifier calculation process is shown in step S42 below.

[0062] S42. The AP generates an address identifier based on the STA's MAC address and the target address, where the target address is the AP's MAC address. In this embodiment, the address identifier is obtained by concatenating the STA's MAC address with the AP's MAC address. The first key information is then calculated using the first base key, the two random numbers, and the new key parameters, as shown in step S43.

[0063] S43. The AP generates first key information based on the first base key, the key parameter, the first random number, the second random number, and the address identifier using the HMAC-SHA256 algorithm. In a specific implementation, the first key information Key_buff1 = HMAC-SHA256(BK1, ADDID||N1||N2||M2), where BK1 is the first base key and ADDID is the address identifier. After calculating the first key information based on the aforementioned formula, the multicast key protection key can be determined based on the first key information, as shown in step S44. M2 represents a new key parameter, which is another string in the WAPI standard, namely, "pairwise key expansion for unicast and additional keys and nonce."

[0064] S44 AP determines the multicast key protection key based on the first key information; in specific applications, for example, but not limited to, the first key information is divided into four information segments from left to right (each information segment has the same length); then, the third information segment is used as the multicast key protection key.

[0065] At the same time, the first information segment obtained by equal distribution is used as the first unicast session key of the AP, and after receiving the access confirmation message, the AP installs the first unicast session key to open the controlled communication port of the STA after installation.

[0066] Optionally, for example, the length of each information segment is 128 bits. In this case, it is equivalent to taking the first 128 bits of the first key information as the first unicast session key; taking the second 128 bits of the first key information as the integrity verification key of the first unicast session; taking the third 128 bits of the first key information as the multicast key protection key, and taking the fourth 128 bits of the first key information as the message authentication key.

[0067] In this way, the aforementioned first unicast session key is used for subsequent unicast sessions, and the multicast key protection key can be used to generate multicast announcement information, and the process is shown in the following step S45.

[0068] S45. The AP obtains a multicast key and encrypts the multicast key using a multicast key protection key to obtain the multicast announcement information. In a specific application, the multicast announcement information primarily includes a multicast key ciphertext. For example, the AP may, but is not limited to, use the multicast key protection key obtained above to perform SM4 encryption on the multicast key to generate a multicast key ciphertext, and then use the multicast key ciphertext to compose the multicast announcement information. For example, the multicast key is a 128-bit random number generated by the AP during initialization, and the multicast key installation is completed during initialization. Thus, after obtaining the multicast key protection key, it is encrypted to obtain the multicast announcement information.

[0069] Thus, through the aforementioned steps S41 to S45, multicast announcement information can be generated, and then, based on this, an authentication response message can be generated, that is, the authentication response message is generated using the multicast announcement information, the first base key identifier, the certificate authentication result and the authentication identifier in the authentication access request message, that is, the authentication response message contains the aforementioned information.

[0070] At the same time, the authentication response message may also include, but is not limited to, the signature information of the AP, wherein the signature information of the AP is generated by the AP using the private key corresponding to its own public key certificate (i.e., the private key corresponding to the first certificate) to perform a signature calculation on the message content of the access authentication response message excluding the signature information; for the part excluding the signature information, please refer to the explanation of the aforementioned step S24.

[0071] In this way, after obtaining the authentication response message, it can be sent to the STA. The process can be seen in Figure 3 As shown; then, the STA can perform base key identification verification according to the authentication response message, and after the verification is passed, generate a session key and return an access confirmation message to the AP; wherein the aforementioned execution process can be but is not limited to as shown in the following step S5.

[0072] S5. The STA receives the authentication response message and, if it determines that the second base key identifier is the same as the first base key identifier in the authentication response message, generates a session key based on the second base key and the multicast announcement information, and sends an access confirmation message to the AP. In a specific implementation, as previously explained, the authentication response message includes the authentication identifier parsed from the authentication access request message, the AP's signature information, and the certificate authentication result. Therefore, the AP's signature authentication, authentication identifier verification, and certificate authentication result verification are first performed. The process is as follows: First, when the STA performs signature verification, it uses the AP's public key certificate contained in the authentication activation message, that is, the public key of the first certificate, to verify the AP's signature information. After the verification is successful, it determines whether the authentication identifier in the authentication response message is the same as the authentication identifier in the received authentication activation message. If they are different, the message is discarded and the access authentication process is terminated. Otherwise, the certificate authentication result can be verified, that is, whether the certificate authentication result is successful. If so, it determines whether the second base key identifier is the same as the first base key identifier in the authentication response message. If the certificate authentication result is that either the AP's or the STA's certificate fails, or both certificates fail, the association with the AP is disconnected and the access process is terminated.

[0073] At the same time, when it is determined that the second base key identifier is the same as the first base key identifier in the authentication response message, the STA can calculate the second unicast session key and the multicast key protection key in order to combine the multicast announcement information to obtain the multicast key, and combine the second unicast session key and the multicast key to form the session key.

[0074] The process of generating the session key may be, but is not limited to, steps S51 to S54 as shown below.

[0075] S51. The STA generates second key information based on the second base key. In this embodiment, the second key information is generated using the formula: Key_buff2 = HMAC-SHA256(BK2, ADDID||N1||N2||M2), where Key_buff2 represents the second key information and BK2 represents the second base key.

[0076] In this way, after the second key information is generated, the multicast key protection key and the second unicast session key can be determined, and the process is shown in the following step S52.

[0077] S52. Based on the second key information, the STA determines the multicast key protection key and the second unicast session key. In practical applications, the second key information is divided equally into four segments from left to right. The third segment serves as the multicast key protection key, while the first segment serves as the second unicast session key. The second and fourth segments derived from the second key information serve as the integrity check key and message authentication key, respectively, for the STA's unicast session. After obtaining the multicast key protection key, the multicast channel information can be decrypted, as shown in step S53.

[0078] S53. The STA uses the multicast key protection key to decrypt the multicast announcement information and obtain the multicast key. In practice, the multicast key protection key from step S52 is used to perform SM4 decryption on the multicast announcement information to obtain the multicast key. The multicast key and the second unicast session key are then used to form the session key, as shown in step S54.

[0079] S54. The STA uses the second unicast session key and the multicast key to form the session key, and after obtaining the session key, installs the session key.

[0080] Thus, after obtaining the session key through the aforementioned steps S51 to S54, the session key can be installed for subsequent use in unicast and multicast communications. Furthermore, after the session key is installed, an access confirmation message can be generated and sent to the AP. For example, but not limited to, the access confirmation message can be generated using the authentication identifier obtained by parsing the authentication response message. The STA also encrypts the authentication identifier. Specifically, the process is as follows: The STA first obtains the message content, where the message content serves as the authentication identifier. The STA then generates second key information based on the second base key, and then generates a message authentication key based on the second key information. The process of the STA generating the message authentication key can be found in step S52 above and will not be repeated here. The STA then uses the message authentication key and the message content to generate a message authentication code, and adds the message authentication code to the access confirmation message.

[0081] In a specific application, the message authentication key in step S52 is used to perform HMAC-SHA256 calculation on the authentication identifier to form a message authentication code, and then the message authentication code is added to the access confirmation message; for example, but not limited to, the message authentication code can be directly used as the access confirmation message, and then sent to the AP. The sending process can be seen in Figure 3 shown.

[0082] In this way, after receiving the confirmation message, the AP can open the controlled communication port of the STA, thereby realizing access authentication, and the process is shown in the following step S6.

[0083] S6. After receiving the access confirmation message, the AP opens the STA's controlled communication port to complete access authentication with the STA. In this embodiment, the AP first performs message authentication on the message authentication code in the access confirmation message and determines whether the message authentication passes. If so, the AP installs the first unicast session key (the first unicast session key is obtained by the AP when generating multicast announcement information based on the first base key, see steps S41 to S44 above). After installing the first unicast session key, the AP opens the STA's controlled communication port to complete access authentication with the STA.

[0084] In specific applications, the AP uses the message authentication key (i.e., the message authentication key in step S44) generated when calculating the unicast session key and multicast key protection key to decrypt the message authentication code, thereby resolving the authentication identifier in the access confirmation message; then, it determines whether the authentication identifier is the same as the authentication identifier in the authentication activation message in step S1; if they are the same, the message verification succeeds; otherwise, the message verification fails.

[0085] Furthermore, when the message verification passes, the first unicast session key obtained in step S44 is installed, and the controlled communication port of the STA is opened to achieve wireless access with the STA; if the message verification fails, the association with the AP is disconnected, and the access process ends.

[0086] In this way, after receiving the access confirmation message and determining that the message verification is successful, the AP can complete the access authentication between the AP and the STA and simultaneously realize wireless access of both.

[0087] Thus, through the WAPI access authentication method including fast key negotiation described in detail in the aforementioned steps S1 to S6, the present invention reduces the number of message interactions between the wireless access point and the wireless terminal during the WAPI access authentication process by integrating the WAPI unicast key negotiation and multicast key announcement processes into the WAPI access process, but the security and reliability are not affected. From the test, it can shorten the WAPI access process by 34 to 50 milliseconds, providing better wireless roaming switching effects for WAPI wireless networks, especially industrial control application scenarios.

[0088] like Figure 5 As shown, the second aspect of this embodiment provides a hardware system for implementing the WAPI access authentication method including fast key negotiation described in the first aspect of the embodiment, including: AP and STA, wherein AP represents a wireless access node and STA represents a wireless terminal.

[0089] The AP is configured to generate an authentication activation message and send the message to the STA, wherein the authentication activation message includes the first temporary public key and the first certificate of the AP.

[0090] The STA is configured to, after receiving the authentication activation message, generate a second temporary public key, generate a second base key and a second base key identifier based on the first temporary public key in the authentication activation message, and send an authentication access request message to the AP, wherein the authentication access request message includes the second base key identifier, the second temporary public key, and the STA's second certificate.

[0091] The AP is configured to generate a first base key and a first base key identifier based on the second temporary public key in the authentication access request message, and send a certificate authentication request to the WAPI authenticator when it is determined that the first base key identifier is the same as the second base key identifier in the authentication access request message, wherein the certificate authentication request includes the first certificate and the second certificate.

[0092] The AP is configured to receive a certificate authentication result sent by the WAPI authenticator, and when the certificate authentication result is verified to be successful, generate multicast notification information based on the first base key, and send an authentication response message to the STA, wherein the authentication response message includes the multicast notification information and the first base key identifier.

[0093] The STA is also used to receive the authentication response message, and when it is determined that the second base key identifier is the same as the first base key identifier in the authentication response message, generate a session key based on the second base key and the multicast announcement information, and send an access confirmation message to the AP.

[0094] The AP is further configured to open the controlled communication port of the STA after receiving the access confirmation message, so as to complete access authentication with the STA.

[0095] The working process, working details and technical effects of the system provided in this embodiment can be found in the first aspect of the embodiment and will not be described in detail here.

[0096] like Figure 6 As shown, the third aspect of this embodiment provides a WAPI access authentication device including rapid key negotiation. Taking the device as an electronic device as an example, it includes: a memory, a processor and a transceiver that are communicatively connected in sequence, wherein the memory is used to store computer programs, the transceiver is used to send and receive messages, and the processor is used to read the computer program and execute the WAPI access authentication method including rapid key negotiation as described in the first aspect of the embodiment.

[0097] For example, the memory may include, but is not limited to, random access memory (RAM), read-only memory (ROM), flash memory, first-in first-out memory (FIFO), and / or first-in last-out memory (FILO). Specifically, the processor may include one or more processing cores, such as a quad-core processor or an octal-core processor. The processor may be implemented in at least one of the following hardware forms: a DSP (Digital Signal Processing), an FPGA (Field-Programmable Gate Array), or a PLA (Programmable Logic Array). Furthermore, the processor may include a main processor and a coprocessor. The main processor is a processor for processing data in an awake state, also known as a CPU (Central Processing Unit); the coprocessor is a low-power processor for processing data in a standby state.

[0098] In some embodiments, the processor may be integrated with a GPU (Graphics Processing Unit), which is responsible for rendering and drawing the content required to be displayed on the display screen. For example, the processor may be, but is not limited to, a microprocessor of the STM32F105 series, a reduced instruction set computer (RISC) microprocessor, an X86 architecture processor, or a processor with an integrated embedded neural network processing unit (NPU). The transceiver may be, but is not limited to, a Wireless Fidelity (WIFI) wireless transceiver, a Bluetooth wireless transceiver, a General Packet Radio Service (GPRS) wireless transceiver, a ZigBee protocol (a low-power local area network protocol based on the IEEE802.15.4 standard, ZigBee) wireless transceiver, a 3G transceiver, a 4G transceiver, and / or a 5G transceiver. In addition, the device may also include, but is not limited to, a power module, a display screen, and other necessary components.

[0099] The working process, working details and technical effects of the electronic device provided in this embodiment can be found in the first aspect of the embodiment and will not be described in detail here.

[0100] The fourth aspect of this embodiment provides a storage medium that stores instructions for the WAPI access authentication method including rapid key negotiation as described in the first aspect of the embodiment, that is, the storage medium stores instructions, and when the instructions are run on a computer, the WAPI access authentication method including rapid key negotiation as described in the first aspect of the embodiment is executed.

[0101] The storage medium refers to a carrier for storing data, which may include but is not limited to a floppy disk, an optical disk, a hard disk, a flash memory, a USB flash drive and / or a memory stick, and the computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device.

[0102] The working process, working details and technical effects of the storage medium provided in this embodiment can be found in the first aspect of the embodiment and will not be described in detail here.

[0103] A fifth aspect of this embodiment provides a computer program product comprising instructions, which, when executed on a computer, causes the computer to execute the WAPI access authentication method including rapid key negotiation as described in the first aspect of the embodiment, wherein the computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device.

[0104] The specific implementation methods described above further illustrate the objectives, technical solutions and beneficial effects of the present invention in detail. It should be understood that the above description is only a specific implementation method of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A WAPI access authentication method including fast key negotiation, characterized in that: include: The AP generates an authentication activation message and sends it to the STA, where the authentication activation message includes the AP's first temporary public key and first certificate; After receiving the authentication activation message, the STA generates a second temporary public key, generates a second base key and a second base key identifier based on the first temporary public key in the authentication activation message, and sends an authentication access request message to the AP, where the authentication access request message includes the second base key identifier, the second temporary public key, and the STA's second certificate. The AP generates a first base key and a first base key identifier based on the second temporary public key in the authentication access request message, and upon determining that the first base key identifier is the same as the second base key identifier in the authentication access request message, sends a certificate authentication request to the WAPI authenticator, wherein the certificate authentication request includes the first certificate and the second certificate; The AP receives the certificate authentication result sent by the WAPI authenticator, and if the certificate authentication result is verified, generates multicast notification information based on the first base key, and sends an authentication response message to the STA, where the authentication response message includes the multicast notification information and the first base key identifier; The STA receives the authentication response message and, when determining that the second base key identifier is the same as the first base key identifier in the authentication response message, generates a session key based on the second base key and the multicast announcement information, and sends an access confirmation message to the AP; After receiving the access confirmation message, the AP opens the STA's controlled communication port to complete access authentication with the STA.

2. The method according to claim 1, characterized in that The AP generates an authentication activation message, which includes: Obtain the authentication identifier and the first certificate issued by the WAPI authenticator; Generate a first temporary public key and a first temporary private key, generate a first random number, and save the first temporary private key; The authentication activation message is generated using the authentication identifier, the first random number, the first certificate, and the first temporary public key.

3. The method according to claim 1, characterized in that Before generating the second temporary public key, the STA also generates a second temporary private key, and the authentication activation message also includes the first random number; The method of generating a second base key and a second base key identifier according to the first temporary public key in the authentication activation message includes: Obtain key parameters and generate a second random number; Calculating a second shared key based on the first temporary public key and the second temporary private key; Generate the second base key according to the first random number, the second random number, the key parameter and the second shared key; The second base key identifier is generated using the second base key, the first random number, the second random number, and the key parameter.

4. The method according to claim 1, wherein The authentication access request message further includes a second random number, wherein the AP generates a first base key and a first base key identifier based on the second temporary public key in the authentication access request message, including: Obtaining a first temporary private key, a first random number, and key parameters, wherein the first temporary private key is generated before generating the first temporary public key, and the first random number is obtained when generating the authentication activation message; Generate a first shared key using the first temporary private key and the second temporary public key; Generate the first base key based on the first shared key, the first random number, the second random number and the key parameter; The first base key identifier is generated according to the first base key, the first random number, the second random number and the key parameter.

5. The method according to claim 1, characterized in that The authentication access request message further includes a second random number, wherein the multicast announcement information is generated based on the first base key, including: Obtain a first random number, a second random number, a new key parameter, and a MAC address of the STA, wherein the first random number is obtained when generating an authentication activation message, and the second random number is obtained by parsing an authentication access request message; Generate an address identifier based on the MAC address of the STA and the target address, where the target address is the MAC address of the AP; Generate first key information based on the first base key, the new key parameter, the first random number, the second random number, and the address identifier, and using the HMAC-SHA256 algorithm; Determining a multicast key protection key based on the first key information; A multicast key is obtained, and the multicast key is used to protect the key and encrypt the multicast key to obtain the multicast announcement information.

6. The method according to claim 5, characterized in that Determining a multicast key protection key according to the first key information includes: Divide the first key information into four information segments from left to right, wherein each information segment has the same length; Using the third information segment as the multicast key protection key; The first information segment obtained by evenly dividing is used as the first unicast session key of the AP, and after receiving the access confirmation message, the AP installs the first unicast session key to open the controlled communication port of the STA after installation.

7. The method according to claim 1, characterized in that The STA generates a session key based on the second base key and the multicast announcement information, including: generating second key information according to the second base key; Determining a multicast key protection key and a second unicast session key based on the second key information; Decrypting the multicast announcement information using a multicast key protection key to obtain a multicast key; The second unicast session key and the multicast key are used to form the session key, and after obtaining the session key, the session key is installed.

8. The method according to claim 1, characterized in that Before generating the authentication activation message, the method further includes: The AP sends a beacon frame to the STA, wherein the beacon frame includes a manufacturer information element, and the manufacturer information element is used to indicate that the AP supports the WAPI fast key negotiation function; The STA receives the beacon frame and, after identifying that the beacon frame includes the vendor information element, generates an association request management frame and sends it to the AP, wherein the association request management frame includes the vendor information element; The AP receives the association request management frame and, after identifying that the association request management frame contains the manufacturer information element, sends an association response management frame containing the manufacturer information element to the STA, so as to enter the WAPI access authentication process including key fast negotiation after sending.

9. The method according to claim 1, characterized in that The method further comprises: STA obtains the message content; The STA generates second key information based on the second base key, and generates a message authentication key based on the second key information; The STA generates a message authentication code using the message authentication key and the message content, and adds the message authentication code to the access confirmation message; Accordingly, after receiving the access confirmation message, the AP opens the controlled communication port of the STA, which includes: The AP verifies the message authentication code in the access confirmation message and determines whether the message verification succeeds. If so, the AP installs a first unicast session key and opens the controlled communication port of the STA after installing the first unicast session key, wherein the first unicast session key is obtained when the AP generates multicast announcement information based on the first base key.

10. A WAPI access authentication system including fast key negotiation, characterized in that: include: AP and STA, where AP represents a wireless access node and STA represents a wireless terminal; The AP is configured to generate an authentication activation message and send it to the STA, wherein the authentication activation message includes the AP's first temporary public key and first certificate; The STA is configured to, after receiving the authentication activation message, generate a second temporary public key, generate a second base key and a second base key identifier based on the first temporary public key in the authentication activation message, and send an authentication access request message to the AP, wherein the authentication access request message includes the second base key identifier, the second temporary public key, and the STA's second certificate; The AP is configured to generate a first base key and a first base key identifier based on the second temporary public key in the authentication access request message, and send a certificate authentication request to the WAPI authenticator when it is determined that the first base key identifier is the same as the second base key identifier in the authentication access request message, wherein the certificate authentication request includes the first certificate and the second certificate; The AP is configured to receive the certificate authentication result sent by the WAPI authenticator, and when the certificate authentication result is verification passed, generate multicast notification information based on the first base key, and send an authentication response message to the STA, wherein the authentication response message includes the multicast notification information and the first base key identifier; The STA is further configured to receive the authentication response message, and upon determining that the second base key identifier is the same as the first base key identifier in the authentication response message, generate a session key based on the second base key and the multicast announcement information, and send an access confirmation message to the AP; The AP is further configured to open the controlled communication port of the STA after receiving the access confirmation message, so as to complete access authentication with the STA.

Citation Information

Patent Citations

  • WAPI-XG1 access and fast switch authentication method

    CN101420694A

  • Method for pre-identifying wireless local area network terminal and wireless local area network system

    CN101527908A

  • Method and system for updating base key

    CN101541001A

  • Access method and access system for cellular mobile communication network

    CN101616410A

  • Wireless local area network terminal pre-authentication method and wireless local area network system

    US20120017088A1