Wapi access authentication method and system comprising key fast negotiation

By integrating unicast key negotiation and multicast key announcement during the WAPI access authentication process, the problem of multiple interactions between STA and AP is solved, enabling fast access and improving the roaming handover effect of the wireless network.

CN120602931BActive Publication Date: 2025-11-07STATE GRID SICHUAN ELECTRIC POWER CORP ELECTRIC POWER RES INST
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511092942.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-06
Publication Date
2025-11-07
Estimated Expiration
2045-08-06

AI Technical Summary

Technical Problem

In the existing WAPI access process, the multiple interactions between the STA and AP result in long access times, which cannot meet the needs of rapid roaming and switching, especially in the application of inspection robots or inspection drones in industrial sites.

Method used

By performing temporary public key exchange and calculating the base key BK and base key identifier BKID in advance during the WAPI access authentication process, the unicast key negotiation and multicast key announcement processes are integrated into the access authentication process, reducing the number of message exchanges.

Benefits of technology

It reduces WAPI access time and improves the roaming handover efficiency of wireless networks, making it suitable for industrial control applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602931B_ABST
    Figure CN120602931B_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of wireless communication, and discloses a WAPI access authentication method and system containing key fast negotiation, to solve the problem of long access time of traditional WAPI, wherein the application performs temporary public key exchange, base key and base key identification calculation in advance in the WAPI access authentication process of AP and STA, and performs BKID exchange and confirmation for unicast key negotiation and groupcast key announcement in the WAPI access authentication process; thus, the application is equivalent to integrating the unicast key negotiation and groupcast key announcement process into the WAPI access authentication process, so that wireless access of AP and STA is realized at the same time of completing the access authentication; therefore, the message interaction times of wireless access point and wireless terminal in the WAPI access process are reduced, the access time is reduced, and better wireless roaming switching effect can be provided for the WAPI wireless network, especially for the industrial control application scenario.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of wireless communication, in particular to a WAPI access authentication method and system containing key fast negotiation. BACKGROUND

[0002] With the development of industrial sites (such as substations, oil and gas stations, etc.) digitalization, the end network in the industrial site presents the characteristics of "large bandwidth, mobility, high security", and the wireless local area network based on WAPI (Wireless LAN Authentication and Privacy Infrastructure) has been more and more applied in these scenarios. WAPI is a wireless network security standard and technology specified in Chinese national standard GB15629.11, which identifies the identity of wireless access points (AP) and wireless terminals (STA) by using digital certificates, and performs identity authentication of AP and STA based on a three-element authentication system, thereby ensuring the security of wireless access authentication.

[0003] The general process of wireless terminal accessing WAPI wireless network is shown in Figure 1 It includes three sub-processes of access authentication, unicast key negotiation and multicast key announcement; at present, in the WAPI access process, AP and STA need to perform access authentication first, and after the access authentication is successful, the base key (BK) and base key identifier (BKID) are generated, and then the two parties enter the unicast key negotiation process, that is, the consistency of the unicast key is compared based on BKID, and the unicast communication key (UK) and multicast key announcement encryption key (MEK) are negotiated; finally, after completing the unicast key negotiation, the multicast announcement process is entered, that is, the AP announces the multicast key to the STA, and the multicast key generated by the AP is sent to the STA after being encrypted by MEK, thereby completing the WAPI access.

[0004] Therefore, the existing WAPI access process (including access authentication, unicast key negotiation and multicast key announcement) involves multiple interactions between STA and AP, which is not friendly to applications that need to quickly access the network. For example, in the application of inspection robots or inspection drones in intelligent sites, these terminals need to perform fast roaming switching between APs during movement, therefore, the existing WAPI access cannot meet the demand of fast roaming switching. Based on this, how to provide a WAPI access authentication method containing key fast negotiation with short access time has become a problem to be solved. SUMMARY

[0005] The technical problem to be solved by the present application is the problem of wireless terminal access to WAPI wireless network, and the purpose is to provide a WAPI access authentication method and system containing key fast negotiation, which solves the problem that the WAPI access process in the prior art involves multiple interactions between STA and AP, resulting in long access time and thus failing to meet the requirement of fast roaming switching.

[0006] The present application is realized by the following technical solutions:

[0007] In a first aspect, a WAPI access authentication method containing key fast negotiation is provided, comprising:

[0008] The AP generates an authentication activation message and sends it to the STA, wherein the authentication activation message includes a first temporary public key and a first certificate of the AP;

[0009] After receiving the authentication activation message, the STA generates a second temporary public key, generates a second base key and a second base key identifier according to the first temporary public key in the authentication activation message, and sends an authentication access request message to the AP, wherein the authentication access request message includes the second base key identifier, the second temporary public key and a second certificate of the STA;

[0010] The AP generates a first base key and a first base key identifier based on the second temporary public key in the authentication access request message, and sends a certificate authentication request to the WAPI authenticator when it is determined that the first base key identifier is the same as the second base key identifier in the authentication access request message, wherein the certificate authentication request includes the first certificate and the second certificate;

[0011] The AP receives the certificate authentication result sent by the WAPI authenticator, and generates a multicast announcement information based on the first base key when the certificate authentication result is verified, and sends an authentication response message to the STA, wherein the authentication response message includes the multicast announcement information and the first base key identifier;

[0012] The STA receives the authentication response message, and generates a session key based on the second base key and the multicast announcement information when it is determined that the second base key identifier is the same as the first base key identifier in the authentication response message, and sends an access confirmation message to the AP;

[0013] After receiving the access confirmation message, the AP opens the controlled communication port of the STA to complete the access authentication between the STA and the AP.

[0014] Based on the above disclosure, the application fuses the unicast key negotiation and the multicast key announcement process of WAPI into the WAPI access authentication process, so that the wireless access of the AP and the STA can be completed after the access authentication is completed; based on this, the application omits the separate unicast key negotiation and multicast key announcement sub-process in the conventional technology, reduces the message interaction times of the wireless access point and the wireless terminal in the WAPI access process, thereby reducing the access time, and further can provide better wireless roaming switching effect for the WAPI wireless network, especially for the industrial control application scenario; therefore, the application is very suitable for large-scale application and promotion.

[0015] In one possible design, the AP generates the authentication activation message, including:

[0016] obtaining the authentication identifier and the first certificate issued by the WAPI authenticator;

[0017] generating the first temporary public key and the first temporary private key, and generating the first random number, and saving the first temporary private key;

[0018] generating the authentication activation message by using the authentication identifier, the first random number, the first certificate and the first temporary public key.

[0019] In one possible design, the STA also generates the second temporary private key before generating the second temporary public key, and the authentication activation message further includes the first random number;

[0020] wherein, the second group key and the second group key identifier are generated according to the first temporary public key in the authentication activation message, including:

[0021] obtaining the key parameter and generating the second random number;

[0022] calculating the second shared key according to the first temporary public key and the second temporary private key;

[0023] generating the second group key according to the first random number, the second random number, the key parameter and the second shared key;

[0024] generating the second group key identifier by using the second group key, the first random number, the second random number and the key parameter.

[0025] In one possible design, the authentication access request message further includes the second random number, wherein the AP generates the first group key and the first group key identifier based on the second temporary public key in the authentication access request message, including:

[0026] obtaining a first temporary private key, a first random number and a key parameter, wherein the first temporary private key is generated before the first temporary public key is generated, and the first random number is obtained when the authentication activation message is generated;

[0027] generating a first shared key by using the first temporary private key and the second temporary public key;

[0028] generating the first base key based on the first shared key, the first random number, the second random number and the key parameter;

[0029] generating the first base key identification according to the first base key, the first random number, the second random number and the key parameter.

[0030] In one possible design, the authentication access request message further includes the second random number, and generating the multicast announcement information based on the first base key includes:

[0031] obtaining a first random number, a second random number, a new key parameter and a MAC address of the STA, wherein the first random number is obtained when the authentication activation message is generated, and the second random number is obtained by analyzing the authentication access request message;

[0032] generating an address identification according to the MAC address of the STA and a target address, wherein the target address is a MAC address of the AP;

[0033] generating first key information based on the first base key, the new key parameter, the first random number, the second random number and the address identification, and using an HMAC-SHA256 algorithm;

[0034] determining a multicast key protection key according to the first key information;

[0035] obtaining a multicast key, and encrypting the multicast key by using the multicast key protection key to obtain the multicast announcement information.

[0036] In one possible design, determining the multicast key protection key according to the first key information includes:

[0037] dividing the first key information into four information segments from left to right, wherein each information segment has the same length;

[0038] taking the third information segment as the multicast key protection key;

[0039] The first information segment obtained by the equal division is used as a first unicast session key of the AP, and the AP installs the first unicast session key after receiving the access confirmation message, so as to open a controlled communication port of the STA after the installation.

[0040] In a possible design, the STA generates a session key based on the second base key and the group announcement information, including:

[0041] generating second key information according to the second base key;

[0042] determining a group key protection key and a second unicast session key based on the second key information;

[0043] decrypting the group announcement information by using the group key protection key to obtain a group key;

[0044] composing the session key by using the second unicast session key and the group key, and installing the session key after obtaining the session key.

[0045] In a possible design, before generating the authentication activation message, the method further includes:

[0046] The AP sends a beacon frame to the STA, wherein the beacon frame contains a manufacturer information element, and the manufacturer information element is used to indicate that the AP supports the WAPI key fast negotiation function;

[0047] The STA receives the beacon frame, and generates an association request management frame containing the manufacturer information element and sends the association request management frame to the AP after identifying that the beacon frame contains the manufacturer information element;

[0048] The AP receives the association request management frame, and sends an association response management frame containing the manufacturer information element to the STA after identifying that the association request management frame contains the manufacturer information element, so as to enter a WAPI access authentication process containing the key fast negotiation after the sending.

[0049] In a possible design, the method further includes:

[0050] The STA obtains message content;

[0051] The STA generates second key information according to the second base key, and generates a message authentication key according to the second key information;

[0052] The STA generates a message authentication code by using the message authentication key and the message content, and adds the message authentication code to the access confirmation message;

[0053] Correspondingly, the AP opens the controlled communication port of the STA after receiving the access confirmation message, and the opening comprises:

[0054] The AP performs message verification on the message authentication code in the access confirmation message, and judges whether the message verification is passed.

[0055] If yes, the AP installs the first unicast session key, and opens the controlled communication port of the STA after installing the first unicast session key, wherein the first unicast session key is obtained by the AP when generating the group announcement information based on the first base key.

[0056] In a second aspect, a WAPI access authentication system comprising key fast negotiation is provided, comprising an AP and a STA, wherein the AP represents a wireless access node, and the STA represents a wireless terminal:

[0057] The AP is configured to generate an authentication activation message and send the authentication activation message to the STA, wherein the authentication activation message comprises a first temporary public key of the AP and a first certificate.

[0058] The STA is configured to generate a second temporary public key after receiving the authentication activation message, generate a second base key and a second base key identifier based on the first temporary public key in the authentication activation message, and send an authentication access request message to the AP, wherein the authentication access request message comprises the second base key identifier, the second temporary public key and a second certificate of the STA.

[0059] The AP is configured to generate a first base key and a first base key identifier based on the second temporary public key in the authentication access request message, and send a certificate authentication request to a WAPI authenticator when it is judged that the first base key identifier is the same as the second base key identifier in the authentication access request message, wherein the certificate authentication request comprises the first certificate and the second certificate.

[0060] The AP is configured to receive the certificate authentication result sent by the WAPI authenticator, and generate a group announcement information based on the first base key when the certificate authentication result is verified, and send an authentication response message to the STA, wherein the authentication response message comprises the group announcement information and the first base key identifier.

[0061] The STA is further configured to receive the authentication response message, and generate a session key based on the second base key and the group announcement information when it is judged that the second base key identifier is the same as the first base key identifier in the authentication response message, and send an access confirmation message to the AP.

[0062] The AP is further configured to open the controlled communication port of the STA after receiving the access confirmation message, so as to complete the access authentication with the STA.

[0063] In a third aspect, a WAPI access authentication device including a key fast negotiation is provided, taking an electronic device as an example, comprising a memory, a processor and a transceiver connected in sequence and in communication, wherein the memory is configured to store a computer program, the transceiver is configured to transceive messages, and the processor is configured to read the computer program and execute the WAPI access authentication method including the key fast negotiation as in the first aspect or any possible design of the first aspect.

[0064] In a fourth aspect, a storage medium is provided, and the storage medium has instructions stored thereon, and the instructions, when executed on a computer, perform the WAPI access authentication method including the key fast negotiation as in the first aspect or any possible design of the first aspect.

[0065] In a fifth aspect, a computer program product including instructions is provided, and the instructions, when executed on a computer, cause the computer to perform the WAPI access authentication method including the key fast negotiation as in the first aspect or any possible design of the first aspect.

[0066] Compared with the prior art, the present application has the following advantages and beneficial effects:

[0067] In the present application, the temporary public key exchange, the base key BK and the base key identification BKID are calculated in advance in the WAPI access authentication process, and the BKID exchange and confirmation for the unicast key negotiation and the announcement of the multicast information are completed in the WAPI access authentication process, so as to integrate the unicast key negotiation and the multicast key announcement process of the WAPI into the WAPI access authentication process, thereby completing the wireless access of the AP and the STA after the access authentication is completed; based on this, the present application omits the separate unicast key negotiation and multicast key announcement sub-process in the conventional technology, reduces the number of message interactions between the AP and the STA in the WAPI access process, thereby reducing the access time, and further being capable of providing better wireless roaming switching effect for the WAPI wireless network, especially for the industrial control application scenario; therefore, the present application is very suitable for large-scale application and promotion. BRIEF DESCRIPTION OF DRAWINGS

[0068] In order to more clearly illustrate the technical solutions of the exemplary embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be considered as a limitation to the scope, and for those skilled in the art, other related drawings can also be obtained without creative labor. In the drawings:

[0069] Figure 1 The conventional WAPI access authentication flowchart provided for the embodiments of the present application;

[0070] Figure 2 A step flowchart of the WAPI access authentication method comprising the key fast negotiation provided by the embodiment of the present application;

[0071] Figure 3 A WAPI access authentication flowchart of the embodiment of the present application;

[0072] Figure 4 A structure diagram of the manufacturer information element provided by the embodiment of the present application;

[0073] Figure 5 A structure diagram of the WAPI access authentication system comprising the key fast negotiation provided by the embodiment of the present application;

[0074] Figure 6 A structure diagram of the electronic device provided by the embodiment of the present application. DETAILED DESCRIPTION

[0075] In order to make the objectives, technical solutions and advantages of the present application clearer, further detailed description will be made to the present application with reference to the embodiments and the drawings, the illustrative embodiments of the present application and the description thereof are only used to explain the present application, and should not be regarded as a limitation to the present application; it should be understood that although the terms first, second, etc. can be used herein to describe various units, these units should not be limited by these terms. These terms are only used to distinguish one unit from another unit. For example, the first unit can be called the second unit, and similarly, the second unit can be called the first unit, without departing from the scope of the example embodiments of the present application.

[0076] Embodiment:

[0077] Reference is made to Figure 2As shown, the WAPI access authentication method provided by the embodiment comprises the following steps S1-S6.

[0078] In a specific application, before the WAPI access authentication is performed by using the method provided by the embodiment, the AP and the STA will first perform the confirmation of whether the API key fast negotiation function is supported, and the specific implementation process is shown in the following steps S01-S03.

[0079] S01. The AP sends a beacon frame to the STA, wherein the beacon frame comprises a manufacturer information element, and the manufacturer information element is used to represent that the AP supports the WAPI key fast negotiation function; in a specific implementation, the wireless access point will periodically send a beacon frame to the STA, and the beacon frame comprises a manufacturer information element to indicate that the wireless access point supports the WAPI key fast negotiation function; wherein the structure of the manufacturer information element is as shown in the following table (the numbers in the table are in hexadecimal). Figure 4 Figure 4 As an example, the OUI (Organizationally Unique Identifier) of the manufacturer information element is 0x001472 of the WAPI alliance, the type of the manufacturer information element is defined as 0x65, the content of the information element is the version number, and the current version number is 0x01; thus, the confirmation of whether the API key fast negotiation function is supported can be performed through the manufacturer element information.

[0080] After the beacon frame is sent to the STA, the STA can return a corresponding request management frame based on the beacon frame, and the process is shown in the following step S02.

[0081] ​S02. The STA receives the beacon frame and generates an association request management frame containing the manufacturer information element after identifying that the manufacturer information element is contained in the beacon frame and sends the association request management frame to the AP. In this embodiment, if the STA supports the WAPI key fast negotiation capability and the STA checks that the manufacturer information element is contained in the beacon, the association request management frame returned by the STA contains the manufacturer information element. If the STA does not support the WAPI key fast negotiation or the STA does not check the manufacturer information element in the beacon frame, the association request management frame sent by the STA does not contain the manufacturer information element. Based on this, the AP can determine whether to enter the WAPI access authentication process based on the WAPI key fast negotiation according to whether the manufacturer element information is contained in the association request management frame, and the process is shown in the following step S03.

[0082] S03. The AP receives the association request management frame and sends an association response management frame containing the manufacturer information element to the STA after identifying that the manufacturer information element is contained in the association request management frame, so as to enter the WAPI access authentication process containing the key fast negotiation after sending. In a specific application, the AP sends the association response management frame containing the manufacturer information element to the STA after identifying that the association request management frame returned by the STA contains the manufacturer information element, so as to notify the STA to confirm the WAPI key fast negotiation function to enter the WAPI access authentication process based on the key fast negotiation. Of course, if any party does not support the WAPI key fast negotiation function, the traditional access process is entered.

[0083] In this way, after the capability negotiation of the two devices based on the above steps S01-S03, the WAPI access authentication process based on the key fast negotiation is entered, and the process is shown in the following steps S1-S6.

[0084] S1. The AP generates an authentication activation message and sends it to the STA, wherein the authentication activation message includes the first temporary public key and the first certificate of the AP. In a specific application, the first temporary public key is generated before the authentication activation message is generated, and the generation process of the authentication activation message can but is not limited to the following steps S11-S13.

[0085] S11. The AP obtains the authentication identifier and the first certificate issued by the WAPI authenticator. In a specific implementation, the authentication identifier can but is not limited to a 256-bit random number, which is used to identify a WAPI access authentication process. At the same time, the first certificate is the public key certificate of the AP, which is issued by the WAPI authenticator and is pre-configured when the network is deployed.

[0086] Thus, after obtaining the authentication identifier and the first certificate, a first temporary public-private key pair and a first random number can be generated, as shown in the following step S12.

[0087] S12. A first temporary public key and a first temporary private key are generated, and a first random number is generated and the first temporary private key is saved. In specific applications, the first temporary private key is generated first, and then the first temporary public key is generated using the first temporary private key. Meanwhile, the first temporary private key and the public key can be generated by, but not limited to, an elliptic curve encryption algorithm. The elliptic curve encryption algorithm is a commonly used encryption algorithm, and its public-private key generation process is not described here.

[0088] Meanwhile, the first temporary public key is transmitted to the STA, and the first temporary private key is saved for subsequent calculation of the own base key and base key identifier based on the first temporary private key. Of course, the specific calculation process is described below.

[0089] After obtaining the first temporary public-private key pair, the first random number, the authentication identifier, and the first certificate, an authentication activation message can be generated based on the above information, as shown in the following step S13.

[0090] S13. The authentication activation message is generated using the authentication identifier, the first random number, the first certificate, and the first temporary public key.

[0091] Thus, through the above steps S11-S13, an authentication activation message containing the authentication identifier, the first random number, the first certificate, and the first temporary public key can be generated, and then the authentication activation message can be sent to the STA to achieve authentication activation. The flowchart can be seen in Figure 3 Meanwhile, after receiving the authentication activation message sent by the AP, the STA can calculate its own base key and base key identifier, and return an authentication access request to the AP, as shown in the following step S2.

[0092] S2. After receiving the authentication activation message, the STA generates a second temporary public key, generates a second base key and a second base key identifier according to the first temporary public key in the authentication activation message, and sends an authentication access request message to the AP, wherein the authentication access request message includes the second base key identifier, the second temporary public key, and the second certificate of the STA.

[0093] In specific applications, the generation process of the second temporary public key is the same as that of the first temporary public key, that is, the second temporary private key is generated first, and then the second temporary public key is generated using the second temporary private key. Of course, it is also generated by using an elliptic curve encryption algorithm, and the second temporary private key is applied to the subsequent calculation of the second base key and the second base key identifier.

[0094] Further, the embodiment is based on the second temporary private key generated before the second temporary public key is obtained, and in combination with the first temporary public key and the first random number in the authentication activation message issued by the AP, to calculate the second base key and the identification thereof; wherein the calculation process can be but not limited to the following steps S21-S24.

[0095] S21. The STA acquires the key parameter and generates a second random number; in the embodiment, the key parameter is a preset string, which belongs to the inherent parameter between the AP and the STA; thus, after the key parameter and the second random number are obtained, the calculation of the second shared key can be performed, and the process is shown in the following step S22.

[0096] S22. The STA calculates the second shared key based on the first temporary public key and the second temporary private key; in specific implementation, for example, but not limited to, the Diffie-Hellman key exchange algorithm based on the elliptic curve asymmetric cryptography system can be used to calculate the second shared key, i.e., the second shared key SK2=ECDH (second temporary private key, first temporary public key), wherein ECDH() represents the Diffie-Hellman key exchange algorithm based on the elliptic curve asymmetric cryptography system.

[0097] After the second shared key is calculated, the base key of the STA itself can be calculated in combination with the first random number, the second random number, and the key parameter, and the process is shown in the following step S23.

[0098] S23. The STA generates the second base key based on the first random number, the second random number, the key parameter, and the second shared key; in the embodiment, the second base key BK2 is: BK2=HMAC-SHA256 (SK2, N1||N2||M1); wherein N1 and N2 represent the first random number and the second random number respectively, M1 represents the key parameter, HMAC-SHA256() represents the HMAC-SHA256 algorithm, i.e., the HMAC-SHA256 hash function, and || represents the splicing operation. For the key parameter M1, it can be but not limited to the string in the WAPI standard, i.e., “base key expansion for key and additional nonce”.

[0099] Thus, after the second base key is calculated based on the foregoing step S23, the second base key identification can be calculated based on the second base key, and the process is shown in the following step S24.

[0100] S24. The STA generates the second base key identifier using the second base key, the first random number, the second random number, and the key parameter; in this embodiment, the second base key identifier BKID2 = HMAC-SHA256 (BK2, N1 || N2 || M1).

[0101] Thus, the calculation of the second base key BK2 and the second base key identifier BKID2 can be completed through the foregoing steps S21-S24; then, the authentication access request message can be generated; for example, but not limited to, the authentication access request message can be generated according to the authentication identifier in the foregoing authentication activation message, the second certificate of the STA, the second random number N2, the second temporary public key, and the second base key identifier; in this way, the authentication access request message contains the foregoing information; of course, the second certificate of the STA is the public key certificate corresponding thereto, which is also issued by the WAPI authenticator.

[0102] In addition, in this embodiment, the foregoing authentication access request message can further include, but is not limited to, the signature information of the STA, wherein the signature information of the STA is generated by the STA using the private key corresponding to the public key certificate (i.e., the private key corresponding to the second certificate, which is also issued by the WAPI authenticator) of the STA, for signature calculation on the part of the message content of the authentication access request message except the signature information; in this embodiment, the WAPI protocol message (referred to as WAI message) includes two parts, one is the message header, and the other is the message content; the message content includes N information fields; if the signature information is included, the last field, i.e., the Nth information field, is the signature information; and the part except the signature information is the content of the first N-1 information fields.

[0103] After obtaining the authentication access request message, the STA can send the authentication access request message to the AP; the process can be referred to as shown in FIG. 4. Figure 3 After obtaining the authentication access request message, the AP can generate the first base key and the identifier thereof, so as to perform the identifier comparison subsequently; the generation process of the first base key and the identifier thereof, and the identifier comparison process are shown in the following step S3.

[0104] S3. The AP generates the first base key and the first base key identifier based on the second temporary public key in the authentication access request message, and sends a certificate authentication request to the WAPI authenticator when it is judged that the first base key identifier is the same as the second base key identifier in the authentication access request message, wherein the certificate authentication request includes the first certificate and the second certificate.

[0105] In the embodiment, the signature information and the authentication identifier in the authentication access request message have been described above, thus, after receiving the authentication access request message, the AP uses the second certificate contained in the authentication access request message to verify the signature information, and after verification, the authentication identifier is verified, that is, before the first base key and the first base key identifier are generated, the signature information and the authentication identifier need to be verified first; wherein, the authentication identifier verification process is: the AP judges whether the authentication identifier in the authentication access request message sent by the STA is same as the authentication identifier in the authentication activation message in step S1; wherein, if not, the authentication access request message is discarded, and the access authentication process is ended; otherwise, the first base key and the first base key identifier are calculated, and the process is shown in the following steps S31-S34.

[0106] S31. The AP obtains the first temporary private key, the first random number and the key parameter, wherein the first temporary private key is generated before the first temporary public key is generated, and the first random number is obtained when the authentication activation message is generated; in the embodiment, the generation process of the first temporary private key and the first random number has been described in step S1, and will not be repeated here; after the above data is obtained, the first shared key can be calculated, and the process is shown in the following step S32.

[0107] S32. The AP generates the first shared key by using the first temporary private key and the second temporary public key; in specific application, the calculation method of the first shared key is same as the calculation method of the second shared key, that is, the first shared key SK1=ECDH (first temporary private key, second temporary public key).

[0108] After the first shared key is obtained, the first base key can be calculated, and the process is shown in the following step S33.

[0109] S33. The AP generates the first base key based on the first shared key, the first random number, the second random number and the key parameter; in the embodiment, the second random number is obtained by analyzing the authentication access request message, and for example, the first base key BK1=HMAC-SHA256 (SK1, N1||N2||M1).

[0110] Thus, based on the first base key calculated in the above step S33, the first base key identifier can be calculated based on the first base key, and the process is shown in the following step S34.

[0111] S34. The AP generates the first base key identifier according to the first base key, the first random number, the second random number and the key parameter; in specific implementation, for example, the first base key identifier BKID1=HMAC-SHA256 (BK1, N1||N2||M1).

[0112] Thus, by the foregoing steps S31-S34, the calculation of the first base key and the first base key identification is completed, and then the comparison of the base key identification is performed, i.e., the AP judges whether the first base key identification is the same as the second base key identification in the authentication access request message; if not, the foregoing authentication access request message is discarded, and the access authentication procedure is ended; otherwise, the certificate authentication request is generated by using the first certificate of the AP and the second certificate in the authentication access request message; then, the certificate authentication request is sent to the WAPI authenticator (the transmission process can be referred to in Figure 3 ), so that the WAPI authenticator performs the certificate authentication after receiving the certificate authentication request, and obtains the certificate authentication result (which can be but not limited to fed back to the AP in the form of a certificate authentication request response message, and the AP obtains the certificate authentication result by analyzing the certificate authentication request response message).

[0113] Thus, after the certificate authentication is completed, the AP can determine whether the multicast key announcement can be performed according to the certificate authentication result, and the process is shown in the following step S4.

[0114] S4. The AP receives the certificate authentication result sent by the WAPI authenticator, and when the certificate authentication result is verified, generates the multicast announcement information based on the first base key, and sends the authentication response message to the STA, wherein the authentication response message includes the multicast announcement information and the first base key identification; in the specific implementation, the AP first judges whether the certificate authentication result is verified, and then, when the certificate is verified, the first unicast session key and the multicast key protection key are calculated, and then the multicast announcement information is generated according to the multicast key protection key; wherein the generation process of the multicast announcement information can be but not limited to shown in the following steps S41-S45.

[0115] S41. The AP obtains the first random number, the second random number, the new key parameter and the MAC address of the STA, wherein the first random number is obtained when the authentication activation message is generated, and the second random number is obtained by analyzing the authentication access request message; in this embodiment, the MAC address of the STA is sent to the AP by the STA; and after the foregoing data parameters are obtained, the address identification can be generated, so as to calculate the first key information by using the address identification subsequently; wherein the calculation process of the address identification is shown in the following step S42.

[0116] S42. The AP generates an address identifier according to the MAC address of the STA and a target address, wherein the target address is the MAC address of the AP; in this embodiment, the MAC address of the STA is spliced with the MAC address of the AP, and the address identifier is obtained; then, the first key information is calculated in combination with the first base key, the two random numbers and the new key parameter, and the process is shown in the following step S43.

[0117] S43. The AP generates the first key information based on the first base key, the key parameter, the first random number, the second random number and the address identifier, and adopts the HMAC-SHA256 algorithm; in a specific implementation, the first key information Key_buff1= HMAC-SHA256(BK1, ADDID||N1||N2||M2); in the formula, BK1 is the first base key, and ADDID is the address identifier; in this way, after the first key information is calculated based on the foregoing formula, the multicast key protection key is determined based thereon, and the process is shown in the following step S44. M2 represents the new key parameter, which is another string in the WAPI standard, namely "pairwise key expansion for unicast and additional keys and nonce".

[0118] S44. The AP determines the multicast key protection key according to the first key information; in a specific application, for example but not limited to, the first key information is divided into four information segments (each information segment has the same length) from left to right; then, the third information segment is taken as the multicast key protection key.

[0119] At the same time, the first information segment obtained by the division is taken as the first unicast session key of the AP, and the AP installs the first unicast session key after receiving the access confirmation message, so that the controlled communication port of the STA is opened after the installation.

[0120] Optionally, for example, the length of each information segment is 128 bits, so that the first 128 bits of the first key information are taken as the first unicast session key; the second 128 bits of the first key information are taken as the integrity check key of the first unicast session; the third 128 bits of the first key information are taken as the multicast key protection key, and the fourth 128 bits of the first key information are taken as the message authentication key.

[0121] In this way, the foregoing first unicast session key is used for the subsequent unicast session, and the multicast key protection key can be used for generating the multicast announcement information, and the process is shown in the following step S45.

[0122] S45. The AP acquires the multicast key, and protects the key with the multicast key, encrypts the multicast key to obtain the multicast announcement information; in a specific application, the multicast announcement information mainly includes the multicast key ciphertext, wherein, for example, the AP can but is not limited to use the multicast key protection key obtained in the foregoing to perform SM4 encryption on the multicast key, thereby generating the multicast key ciphertext, and then uses the multicast key ciphertext to compose the multicast announcement information; at the same time, for example, the multicast key is a 128-bit random number generated by the AP at initialization, and the installation of the multicast key is completed at the initialization; in this way, after the multicast key protection key is obtained, it is encrypted to obtain the multicast announcement information.

[0123] In this way, through the foregoing steps S41-S45, the multicast announcement information can be generated, and then based on this, the authentication response message can be generated, that is, the authentication response message is generated by using the multicast announcement information, the first base key identifier, the certificate authentication result, and the authentication identifier in the authentication access request message, that is, the authentication response message contains the foregoing information.

[0124] At the same time, for example, the authentication response message can but is not limited to contain the signature information of the AP, wherein the signature information of the AP is generated by the AP using the private key corresponding to the public key certificate of the AP (that is, the private key corresponding to the first certificate) to perform signature calculation on the part of the authentication response message except the signature information; the part except the signature information can be referred to the explanation and description of the foregoing step S24.

[0125] In this way, after the authentication response message is obtained, it can be sent to the STA, and the process can be referred to Figure 3 ; then, the STA can verify the base key identifier according to the authentication response message, and generate the session key and return the access confirmation message to the AP after the verification is passed; wherein, the foregoing execution process can but is not limited to the following step S5.

[0126] S5. The STA receives the authentication response message, and when it is judged that the second base key identifier is the same as the first base key identifier in the authentication response message, generates the session key based on the second base key and the multicast announcement information, and sends the access confirmation message to the AP; in a specific implementation, as has been described in the foregoing, the authentication response message contains the authentication identifier parsed from the authentication access request message, the signature information of the AP, and the certificate authentication result, therefore, the signature authentication of the AP, the verification of the authentication identifier, and the verification of the certificate authentication result are performed first, and the process is as follows:

[0127] First, when the STA performs signature verification, the STA uses the public key certificate of the AP included in the authentication activation message, i.e., the public key of the first certificate, to verify the AP signature information, and after verification, judges whether the authentication identifier in the authentication response message is the same as the authentication identifier in the authentication activation message received by the STA. If they are different, the message is discarded, and the access authentication process is ended. Otherwise, the certificate authentication result is verified, i.e., whether the certificate authentication result is verified. If yes, the second base key identifier is judged to be the same as the first base key identifier in the authentication response message. If the certificate authentication result is that either the AP or the STA certificate is not passed, or neither of the two certificates is passed, the association with the AP is disconnected, and the access process is ended.

[0128] At the same time, when it is judged that the second base key identifier is the same as the first base key identifier in the authentication response message, the STA can calculate the second unicast session key and the group key protection key, so as to obtain the group key in combination with the group announcement information, and combine the second unicast session key and the group key to form the session key.

[0129] The generation process of the session key can be, but is not limited to, the following steps S51-S54.

[0130] S51. The STA generates second key information according to the second base key. In this embodiment, the generation formula of the second key information is: Key_buff2= HMAC-SHA256(BK2, ADDID||N1||N2||M2), where Key_buff2 represents the second key information, and BK2 represents the second base key.

[0131] After the second key information is generated, the group key protection key and the second unicast session key can be determined, and the process is as shown in the following step S52.

[0132] S52. The STA determines the group key protection key and the second unicast session key based on the second key information. In specific applications, the second key information is divided into four information segments from left to right, where the third information segment is used as the group key protection key, and the first information segment in the second key information is used as the second unicast session key. Of course, the second information segment and the fourth information segment obtained by dividing the second key information are respectively used as the integrity check key and the message authentication key of the unicast session of the STA. After the group key protection key is obtained, the group channel information can be decrypted, and the process is as shown in the following step S53.

[0133] S53. The STA decrypts the multicast announcement information using the group key protection key to obtain the group key; in a specific implementation, the group key protection key in the foregoing step S52 is used to perform SM4 decryption on the multicast announcement information, so as to obtain the group key; then, the group key and the second unicast session key are used to compose the session key, and the process is shown in the following step S54.

[0134] S54. The STA composes the session key using the second unicast session key and the group key, and installs the session key after obtaining the session key.

[0135] Therefore, after the session key is obtained through the foregoing steps S51-S54, the session key can be installed for subsequent unicast communication and multicast communication; meanwhile, after the installation of the session key is completed, an access confirmation message can be generated and sent to the AP; for example, but not limited to, the authentication identifier obtained by analyzing the authentication response message is used to generate the access confirmation message, and the authentication identifier is also encrypted by the STA; specifically, the process is as follows.

[0136] The STA first obtains message content, and the message content is the authentication identifier; then, the STA generates second key information according to the second base key, and generates a message authentication key according to the second key information; the process of generating the message authentication key by the STA can be referred to the foregoing step S52, and will not be described here; then, the STA generates a message authentication code using the message authentication key and the message content, and adds the message authentication code to the access confirmation message.

[0137] In a specific application, the message authentication code is formed by performing HMAC-SHA256 calculation on the authentication identifier using the message authentication key in step S52, and then the message authentication code is added to the access confirmation message; for example, but not limited to, the message authentication code is directly used as the access confirmation message, and then the access confirmation message is sent to the AP, and the sending process can be referred to the foregoing step S55. Figure 3

[0138] In this way, after the AP receives the access confirmation message, the controlled communication port of the STA can be opened, so as to realize access authentication, and the process is shown in the following step S6.

[0139] ​S6. After receiving the access confirmation message, the AP opens the controlled communication port of the STA to complete the access authentication between the AP and the STA; in this embodiment, the AP first performs message verification on the message authentication code in the access confirmation message, and judges whether the message verification is passed; if yes, the AP installs the first unicast session key (the first unicast session key is obtained by the AP when generating the groupcast announcement information based on the first base key, see the foregoing steps S41-S44), and opens the controlled communication port of the STA to complete the access authentication between the AP and the STA after installing the first unicast session key.

[0140] In a specific application, the AP decrypts the message authentication code by using the message authentication key generated when the AP performs unicast session key and groupcast key protection key calculation (i.e. the message authentication key in step S44), to parse the authentication identifier in the access confirmation message; and then judges whether the authentication identifier is the same as the authentication identifier in the authentication activation message of step S1; if yes, the message verification is passed, otherwise, the message verification is not passed.

[0141] Further, when the message verification is passed, the first unicast session key obtained in step S44 is installed, and the controlled communication port of the STA is opened to realize the wireless access between the AP and the STA; and if the message verification is not passed, the association with the AP is disconnected, and the access process is ended.

[0142] In this way, after receiving the access confirmation message and judging that the message verification is passed, the AP can complete the access authentication between the AP and the STA, and simultaneously realize the wireless access between the AP and the STA.

[0143] The WAPI access authentication method containing the fast key negotiation described in detail by the foregoing steps S1-S6, the WAPI unicast key negotiation and the groupcast key announcement process are fused into the WAPI access process, the number of message interactions between the wireless access point and the wireless terminal in the WAPI access authentication process is reduced, but the security and reliability are not affected, from the test, the WAPI access process can be shortened by 34-50 milliseconds, and better wireless roaming switching effect is provided for the WAPI wireless network, especially for the industrial control application scenario.

[0144] As shown in Figure 5 the second aspect of the embodiment provides a hardware system for implementing the WAPI access authentication method containing the fast key negotiation described in the first aspect of the embodiment, comprising: an AP and a STA, wherein the AP represents a wireless access node, and the STA represents a wireless terminal.

[0145] The AP is configured to generate an authentication activation message and send the authentication activation message to the STA, wherein the authentication activation message comprises a first temporary public key and a first certificate of the AP.

[0146] The STA is configured to generate a second temporary public key after receiving the authentication activation message, generate a second base key and a second base key identifier according to the first temporary public key in the authentication activation message, and send an authentication access request message to the AP, wherein the authentication access request message comprises the second base key identifier, the second temporary public key and a second certificate of the STA.

[0147] The AP is configured to generate a first base key and a first base key identifier based on the second temporary public key in the authentication access request message, and send a certificate authentication request to the WAPI authenticator when it is determined that the first base key identifier is the same as the second base key identifier in the authentication access request message, wherein the certificate authentication request comprises the first certificate and the second certificate.

[0148] The AP is configured to receive the certificate authentication result sent by the WAPI authenticator, generate multicast announcement information based on the first base key when the certificate authentication result is verified, and send an authentication response message to the STA, wherein the authentication response message comprises the multicast announcement information and the first base key identifier.

[0149] The STA is further configured to receive the authentication response message, generate a session key based on the second base key and the multicast announcement information when it is determined that the second base key identifier is the same as the first base key identifier in the authentication response message, and send an access confirmation message to the AP.

[0150] The AP is further configured to open a controlled communication port of the STA to complete the access authentication with the STA after receiving the access confirmation message.

[0151] The working process, working details and technical effects of the system provided by the embodiment can be referred to the first aspect of the embodiment, and will not be repeated here.

[0152] As shown in Figure 6 The third aspect of the embodiment provides a WAPI access authentication device comprising a key fast negotiation, which is taken as an electronic device for example, comprising: a memory, a processor and a transceiver connected in sequence, wherein the memory is configured to store a computer program, the transceiver is configured to transceive messages, and the processor is configured to read the computer program and execute the WAPI access authentication method comprising a key fast negotiation as described in the first aspect of the embodiment.

[0153] For example, the memory can include, but is not limited to, random access memory (RAM), read only memory (ROM), flash memory, first input first output (FIFO) memory, first in last out (FILO) memory, and the like; specifically, the processor can include one or more processing cores, such as a 4-core processor, an 8-core processor, and the like. The processor can be implemented in at least one of a hardware form of a DSP (Digital Signal Processing), an FPGA (Field-Programmable Gate Array), and a PLA (Programmable Logic Array), and the processor can also include a main processor and a co-processor. The main processor is a processor for processing data in an awake state, also known as a CPU (Central Processing Unit); the co-processor is a low-power processor for processing data in a standby state.

[0154] In some embodiments, the processor can be integrated with a GPU (Graphics Processing Unit) that is responsible for rendering and drawing the content required to be displayed on the display screen. For example, the processor can be, but is not limited to, a microprocessor of the STM32F105 series, a RISC (reduced instruction set computer) microprocessor, an X86 architecture processor, or a processor integrated with an embedded neural network processing unit (NPU); the transceiver can be, but is not limited to, a WIFI wireless transceiver, a Bluetooth wireless transceiver, a GPRS (General Packet Radio Service) wireless transceiver, a ZigBee wireless transceiver, a 3G transceiver, a 4G transceiver, and / or a 5G transceiver, and the like. In addition, the device can also include, but is not limited to, a power module, a display screen, and other necessary components.

[0155] The working process, working details, and technical effects of the electronic device provided in the embodiment can be referred to the first aspect of the embodiment, and will not be repeated here.

[0156] The fourth aspect of the embodiment provides a storage medium storing instructions of the WAPI access authentication method with key fast negotiation according to the first aspect of the embodiment, that is, the storage medium stores the instructions, and when the instructions run on a computer, the WAPI access authentication method with key fast negotiation according to the first aspect of the embodiment is executed.

[0157] The storage medium refers to a carrier for storing data, which can include, but is not limited to, a floppy disk, an optical disk, a hard disk, a flash memory, a USB flash disk, a Memory Stick and the like, and the computer can be a general-purpose computer, a special-purpose computer, a computer network or other programmable devices.

[0158] The working process, working details and technical effects of the storage medium provided by the embodiment can be referred to the first aspect of the embodiment, and will not be described here.

[0159] The fifth aspect of the embodiment provides a computer program product containing instructions, which, when running on a computer, causes the computer to execute the WAPI access authentication method with key fast negotiation according to the first aspect of the embodiment, wherein the computer can be a general-purpose computer, a special-purpose computer, a computer network or other programmable devices.

[0160] The above detailed description is used to further describe the purpose, technical scheme and beneficial effects of the present application, and it should be understood that the above description is only a specific embodiment of the present application and is not used to limit the protection scope of the present application. Any modification, equivalent replacement, improvement and the like within the spirit and principle of the present application should be included in the protection scope of the present application.

Claims

1. A WAPI access authentication method comprising key fast negotiation, characterized in that, Comprise: The AP generates an authentication activation message and sends it to the STA, wherein the authentication activation message comprises a first temporary public key of the AP and a first certificate; in the process of generating the authentication activation message, a first random number is generated and sent to the STA; After receiving the authentication activation message, the STA generates a second temporary public key, and generates a second base key and a second base key identifier according to the first temporary public key in the authentication activation message, and sends an authentication access request message to the AP, wherein the authentication access request message comprises the second base key identifier, the second temporary public key and a second certificate of the STA; in the process of generating the authentication access request message, a second random number is generated; The second shared key SK2 is: SK2=ECDH (second temporary private key, first temporary public key); The second base key BK2 is: BK2=HMAC-SHA256 (SK2, N1||N2||M1); The second base key identifier BKID2 is: BKID2=HMAC-SHA256 (BK2, N1||N2||M1); Wherein, N1 and N2 represent the first random number and the second random number respectively, M1 represents a key parameter, which is an inherent parameter between the AP and the STA; HMAC-SHA256() represents the HMAC-SHA256 algorithm, that is, the HMAC-SHA256 hash function, and || represents the splicing operation; ECDH() represents the Diffie-Hellman key exchange algorithm based on the elliptic curve asymmetric cryptography system; The AP generates a first base key and a first base key identifier based on the second temporary public key in the authentication access request message, and sends a certificate authentication request to the WAPI authenticator when it is judged that the first base key identifier is the same as the second base key identifier in the authentication access request message, wherein the certificate authentication request comprises the first certificate and the second certificate; The first shared key SK1 is: SK1=ECDH (first temporary private key, second temporary public key) The first base key BK1 is: BK1=HMAC-SHA256 (SK1, N1||N2||M1); The first base key identifier BKID1 is: BKID1=HMAC-SHA256 (BK1, N1||N2||M1); SK1 represents the first shared key; The AP receives the certificate authentication result sent by the WAPI authenticator, and generates a multicast announcement information based on the first base key when the certificate authentication result is verified, and sends an authentication response message to the STA, wherein the authentication response message comprises the multicast announcement information and the first base key identifier; The AP obtains the first random number, the second random number, a new key parameter and the MAC address of the STA; the AP generates an address identifier according to the MAC address of the STA and the MAC address of the AP; The AP generates first key information Key_buff1: Key_buff1= HMAC-SHA256(BK1, ADDID||N1||N2||M2); M2 represents a new key parameter; ADDID represents the address identifier; the first key information is divided into four information segments from left to right; then, the third information segment is taken as a multicast key protection key; The STA receives the authentication response message, and judges that the second base key identifier is the same as the first base key identifier in the authentication response message; based on the second base key and the multicast announcement information, the session key is generated, and the access confirmation message is sent to the AP; The AP generates first key information based on the first base key, the new key parameter, the first random number, the second random number and the address identifier, and adopts the HMAC-SHA256 algorithm; the AP determines the multicast key protection key according to the first key information; the AP obtains the multicast key, and encrypts the multicast key by using the multicast key protection key, so as to obtain the multicast announcement information; The STA generates second key information Key_buff2: Key_buff2= HMAC-SHA256(BK2, ADDID||N1||N2||M2), wherein Key_buff2 represents the second key information; the second key information is divided into four information segments from left to right, and the third information segment is taken as the multicast key protection key, and the first information segment in the second key information is taken as the second unicast session key; the second information segment and the fourth information segment obtained by dividing the second key information are respectively taken as the integrity check key and the message authentication key of the unicast session of the STA; The STA decrypts the multicast announcement information by using the multicast key protection key, so as to obtain the multicast key; the STA uses the second unicast session key and the multicast key to form the session key, and installs the session key after obtaining the session key; The AP opens the controlled communication port of the STA after receiving the access confirmation message, so as to complete the access authentication between the AP and the STA.

2. The method of claim 1, wherein, The AP generates an authentication activation message, including: Obtaining an authentication identifier and a first certificate issued by a WAPI authenticator; Generating a first temporary public key and a first temporary private key, and generating a first random number, and saving the first temporary private key; Generating the authentication activation message by using the authentication identifier, the first random number, the first certificate and the first temporary public key.

3. The method of claim 1, wherein, Determining the multicast key protection key according to the first key information, including: Dividing the first key information into four information segments from left to right, wherein the length of each information segment is the same; Taking the third information segment as the multicast key protection key; Wherein, the first information segment obtained by dividing is taken as the first unicast session key of the AP, and the AP installs the first unicast session key after receiving the access confirmation message, so as to open the controlled communication port of the STA after installation.

4. The method of claim 1, wherein, Before generating the authentication activation message, the method further includes: The AP sends a beacon frame to the STA, wherein the beacon frame contains a manufacturer information element, and the manufacturer information element is used to represent that the AP supports the WAPI key fast negotiation function; The STA receives the beacon frame, and after identifying that the beacon frame contains the manufacturer information element, generates an association request management frame and sends it to the AP, wherein the association request management frame contains the manufacturer information element; The AP receives the association request management frame, and after identifying that the association request management frame contains the manufacturer information element, sends an association response management frame containing a manufacturer information element to the STA, so as to enter a WAPI access authentication process containing a key fast negotiation after sending.

5. The method of claim 1, wherein, The method further comprises: The STA acquires message content; The STA generates second key information according to the second base key, and generates a message authentication key according to the second key information; The STA generates a message authentication code by using the message authentication key and the message content, and adds the message authentication code into the access confirmation message; Correspondingly, after receiving the access confirmation message, the AP opens the controlled communication port of the STA, which comprises: The AP performs message verification on the message authentication code in the access confirmation message, and judges whether the message verification is passed; If yes, the AP installs a first unicast session key, and opens the controlled communication port of the STA after installing the first unicast session key, wherein the first unicast session key is obtained by the AP when generating the groupcast announcement information based on the first base key.

6. A WAPI access authentication system comprising a key fast negotiation, characterized in that, The method for implementing any one of claims 1-5 comprises an AP and a STA, wherein the AP represents a wireless access node, and the STA represents a wireless terminal; The AP is configured to generate an authentication activation message and send it to the STA, wherein the authentication activation message comprises a first temporary public key of the AP and a first certificate; The STA is configured to generate a second temporary public key after receiving the authentication activation message, generate a second base key and a second base key identifier according to the first temporary public key in the authentication activation message, and send an authentication access request message to the AP, wherein the authentication access request message comprises the second base key identifier, the second temporary public key and a second certificate of the STA; The AP is configured to generate a first base key and a first base key identifier based on the second temporary public key in the authentication access request message, and when judging that the first base key identifier is the same as the second base key identifier in the authentication access request message, send a certificate authentication request to a WAPI authenticator, wherein the certificate authentication request comprises the first certificate and the second certificate; The AP is configured to receive a certificate authentication result sent by the WAPI authenticator, and when the certificate authentication result is verified, generate a groupcast announcement information based on the first base key, and send an authentication response message to the STA, wherein the authentication response message comprises the groupcast announcement information and the first base key identifier; The STA is further configured to receive the authentication response message, and when judging that the second base key identifier is the same as the first base key identifier in the authentication response message, generate a session key based on the second base key and the groupcast announcement information, and send an access confirmation message to the AP. The AP is also used for opening the controlled communication port of the STA to complete the access authentication with the STA after receiving the access confirmation message.

Citation Information

Patent Citations

  • Method for pre-identifying wireless local area network terminal and wireless local area network system

    CN101527908A

  • Method and system for updating base key

    CN101541001A