Wireless terminal access control method and system
By writing the SSID number into the certificate authentication request message, the problem of illegal access of wireless terminals is solved, effective control of the wireless local area network is achieved, network security is improved and the implementation process is simplified.
Patent Information
- Application Number
- CN202510667805.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-23
- Publication Date
- 2025-09-05
AI Technical Summary
Existing WAPI wireless network technologies lack an effective mechanism to restrict wireless terminals from accessing specific wireless LANs, which may result in business terminals illegally accessing other security partitions, leading to security issues such as data leakage and malicious attacks.
By writing the SSID number of the wireless access point in the certificate authentication request message, the certificate authentication server detects whether the number is in the wireless terminal's access SSID list, and then controls its access rights, avoiding parameter configuration and blacklist and whitelist configuration for a large number of wireless terminals.
It achieves effective access control of wireless terminals, improves network security, simplifies the implementation process, and reduces communication resource consumption.
Smart Images

Figure CN120602938A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of wireless communications, and in particular to a wireless terminal access control method and system. Background Art
[0002] Wireless LAN authentication and privacy infrastructure (WAPI) is a wireless network security standard and technical framework specified in my country's national standard GB15629.11. This technology uses digital certificates to accurately identify wireless access points (APs) and wireless stations (STAs). During the authentication process, STAs and APs rely on a mutually trusted authentication server (AS) to authenticate each other. Only STAs and APs that successfully pass strict authentication can establish a secure connection, thus establishing a solid security barrier for wireless access.
[0003] With the acceleration of digital and intelligent transformation in various industries, the requirements for network security and stability are becoming increasingly stringent. WAPI wireless network has been widely used in the industrial field, especially in the power industry, due to its excellent security performance. It provides reliable local network construction support for scenarios with mobility requirements and extremely high network security requirements. In typical industrial business scenarios, in order to achieve refined security management, multiple different service set identifiers (SSIDs) are usually set based on different security partitions or business types to build multiple isolated virtual wireless local area networks. From a security perspective, specific business terminals are only allowed to access pre-set specific virtual wireless local area networks. This restriction is particularly critical in scenarios with extremely high security requirements such as the power industry, which can effectively prevent the illegal flow of sensitive business data between different security partitions.
[0004] However, the current WAPI wireless network technology architecture lacks an effective mechanism to restrict WAPI wireless terminals from accessing specific wireless LANs. This creates the risk that terminals in industrial scenarios, such as power generation, could break through security partitioning restrictions and illegally access virtual wireless LANs in other security partitions. This could lead to serious security issues such as data leaks and malicious attacks, posing a significant threat to network security management in industrial scenarios. Therefore, there is an urgent need to develop a technical solution that can implement WAPI wireless terminal access control to meet the urgent need for wireless network security management in the industrial sector, particularly the power generation industry. Summary of the Invention
[0005] To address the problem that existing technologies cannot effectively restrict STAs from accessing specific wireless local area networks, the present invention provides a wireless terminal access control method and system that can effectively restrict STAs from accessing specific wireless local area networks, thereby improving network security. The specific technical solution is as follows:
[0006] In a first aspect, an embodiment of the present application provides a wireless terminal access control method, including:
[0007] Receive an access authentication request message sent by a wireless terminal STA, where the access authentication request message includes a STA certificate issued by a certificate authentication server AS for the STA; based on the access authentication request message, send a certificate authentication request message to the AS, where the certificate authentication request message includes first challenge information of the AP and the STA certificate, where the first challenge information includes a service set identifier SSID number, where the SSID number is used to indicate the SSID corresponding to the AP; receive an authentication pass message or an authentication fail message returned by the AS based on the certificate authentication request message, where the authentication pass message is used to indicate that the AS determines, based on the STA certificate, that the STA is allowed to access the wireless local area network corresponding to the SSID number, and the authentication fail message is used to indicate that the AS determines, based on the STA certificate, that the STA is not allowed to access the wireless local area network corresponding to the SSID number; based on the authentication pass message, send a first response message to the STA indicating that the authentication is passed; or, based on the authentication fail message, send a second response message to the STA indicating that the authentication is failed.
[0008] Preferably, the first challenge information further includes a magic word, and the magic word is used to indicate that the SSID number exists in the first challenge information.
[0009] Preferably, the first 32 bits of the first challenge information are the magic word, and the second 32 bits of the first challenge information are the SSID number.
[0010] Preferably, before sending a certificate authentication request message to the AS based on the access authentication request message, the method further includes: obtaining the SSID number and the magic word; generating a 256-byte random number, and performing a hash operation on the 256-byte random number to obtain a 192-bit random number; and obtaining the first challenge information based on the magic word, the SSID number and the 192-bit random number.
[0011] In a second aspect, an embodiment of the present application provides a wireless terminal access control method, which is applied to a certificate authentication server AS; the method includes:
[0012] Receive a certificate authentication request message sent by a wireless access point AP, where the certificate authentication request message includes first challenge information of the AP and the STA certificate of the wireless terminal STA, where the first challenge information includes an SSID number, where the SSID number is used to indicate the SSID corresponding to the AP; based on the STA certificate, obtain a preset access SSID list of the STA, where the access SSID list includes the SSIDs of wireless local area networks that the STA is allowed to access; if the SSID corresponding to the AP exists in the access SSID list of the STA, return an authentication pass message to the AP based on the certificate authentication request message; if the SSID corresponding to the AP does not exist in the access SSID list of the STA, return an authentication fail message to the AP based on the certificate authentication request message.
[0013] Preferably, the first challenge information further includes a magic word, and the magic word is used to indicate that the SSID number exists in the first challenge information.
[0014] Preferably, the first 32 bits of the first challenge information are the magic word, and the second 32 bits of the first challenge information are the SSID number; before obtaining the preset access SSID list of the STA based on the STA certificate, the method also includes: when the magic word is in the first 32 bits of the first challenge information, obtaining the SSID number from the second 32 bits of the first challenge information, and triggering the step of obtaining the preset access SSID list of the STA based on the STA certificate; when the magic word is not in the first 32 bits of the first challenge information, triggering the step of returning an authentication failure message to the AP.
[0015] In a third aspect, an embodiment of the present application provides a wireless terminal access control method, which is applied to a communication system including a wireless terminal STA, a wireless access point AP, and a certificate authentication server AS; the method includes:
[0016] The STA sends an access authentication request message to the AP, where the access authentication request message includes the STA certificate issued by the AS for the STA; based on the access authentication request message, the AP sends a certificate authentication request message to the AS, where the certificate authentication request message includes the first challenge information of the AP and the STA certificate, where the first challenge information includes a service set identifier SSID number, where the SSID number is used to indicate the SSID corresponding to the AP; based on the STA certificate, the AS obtains a preset access SSID list for the STA, where the access SSID list includes the wireless local area network (WLAN) that the STA is allowed to access. network SSID; when the SSID corresponding to the AP exists in the access SSID list of the STA, the AS returns an authentication pass message to the AP based on the certificate authentication request message; when the SSID corresponding to the AP does not exist in the access SSID list of the STA, the AS returns an authentication fail message to the AP based on the certificate authentication request message; the AP sends a first response message to the STA indicating that the authentication is passed based on the authentication pass message; or, based on the authentication fail message, sends a second response message to the STA indicating that the authentication is failed.
[0017] In a fourth aspect, an embodiment of the present application provides a wireless access point (AP), including:
[0018] A receiving unit, configured to receive an access authentication request message sent by a wireless terminal STA, wherein the access authentication request message includes a STA certificate issued by a certificate authentication server AS for the STA;
[0019] a sending unit, configured to send a certificate authentication request message to the AS based on the access authentication request message, wherein the certificate authentication request message includes first challenge information of the AP and the STA certificate, wherein the first challenge information includes a service set identifier SSID number, where the SSID number is used to indicate an SSID corresponding to the AP;
[0020] The receiving unit is further configured to receive an authentication pass message or an authentication fail message returned by the AS based on the certificate authentication request message, wherein the authentication pass message is used to instruct the AS to determine, based on the STA certificate, that the STA is permitted to access the wireless local area network corresponding to the SSID number; and the authentication fail message is used to instruct the AS to determine, based on the STA certificate, that the STA is not permitted to access the wireless local area network corresponding to the SSID number.
[0021] The sending unit is further configured to send a first response message indicating that authentication is successful to the STA based on the authentication successful message; or send a second response message indicating that authentication is unsuccessful to the STA based on the authentication failed message.
[0022] In a fifth aspect, an embodiment of the present application provides a certificate authentication server AS, comprising:
[0023] A receiving unit, configured to receive a certificate authentication request message sent by a wireless access point AP, wherein the certificate authentication request message includes first challenge information of the AP and a STA certificate of a wireless terminal STA, wherein the first challenge information includes an SSID number, and the SSID number is used to indicate an SSID corresponding to the AP;
[0024] an acquiring unit, configured to acquire a preset access SSID list of the STA based on the STA certificate, the access SSID list including SSIDs of wireless local area networks that the STA is permitted to access;
[0025] A sending unit, configured to return an authentication pass message to the AP based on the certificate authentication request message if the SSID corresponding to the AP exists in the allowed SSID list of the STA;
[0026] The sending unit is further configured to return an authentication failure message to the AP based on the certificate authentication request message when the SSID corresponding to the AP does not exist in the allowed SSID list of the STA.
[0027] In a sixth aspect, an embodiment of the present application provides a communication system, which includes a wireless terminal STA, a wireless access point AP, and a certificate authentication server AS;
[0028] The STA is used to send an access authentication request message to the AP, where the access authentication request message includes the STA certificate issued by the AS for the STA;
[0029] The AP is configured to send a certificate authentication request message to the AS based on the access authentication request message, where the certificate authentication request message includes first challenge information of the AP and the STA certificate, where the first challenge information includes a service set identifier (SSID) number, where the SSID number is used to indicate an SSID corresponding to the AP;
[0030] The AS is configured to obtain a preset allowed SSID list for the STA based on the STA certificate, where the allowed SSID list includes SSIDs of wireless local area networks that the STA is permitted to access. If the SSID corresponding to the AP exists in the allowed SSID list of the STA, the AS returns an authentication pass message to the AP based on the certificate authentication request message. If the SSID corresponding to the AP does not exist in the allowed SSID list of the STA, the AS returns an authentication fail message to the AP based on the certificate authentication request message.
[0031] The AP is further configured to send a first response message indicating that authentication is successful to the STA based on the authentication successful message; or send a second response message indicating that authentication is unsuccessful to the STA based on the authentication failed message.
[0032] Compared with the prior art, the present invention has the following advantages: by including the SSID number of the AP's own SSID in the first challenge information in the certificate authentication request message sent by the AP to the AS, the AS detects whether the SSID corresponding to the AP exists in the STA's access SSID list during certificate authentication, and then issues a message indicating whether the authentication is successful or not, thereby achieving the purpose of controlling wireless terminals to only access specific SSIDs. The embodiments of the present application do not require corresponding parameter configuration or blacklist and whitelist configuration for a large number of wireless terminals, and are simple and easy to implement. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following briefly describes the drawings required for the specific embodiments or the description of the prior art. Similar elements or parts are generally identified by similar reference numerals throughout the drawings. Elements or parts in the drawings are not necessarily drawn to scale.
[0034] Figure 1 A system architecture diagram of a communication system provided in an embodiment of the present application;
[0035] Figure 2 A schematic diagram of the structure of a wireless access point provided in an embodiment of the present application;
[0036] Figure 3 A schematic diagram of the structure of a certificate authentication server provided in an embodiment of the present application;
[0037] Figure 4 A flowchart of a wireless terminal access control method provided in an embodiment of the present application;
[0038] Figure 5 A schematic diagram of a flow chart of another wireless terminal access control method provided in an embodiment of the present application;
[0039] Figure 6 A schematic diagram of a flow chart of another wireless terminal access control method provided in an embodiment of the present application;
[0040] Figure 7 A schematic diagram of the structure of an access authentication request message provided in an embodiment of the present application;
[0041] Figure 8 A schematic diagram of the structure of a certificate authentication request message provided in an embodiment of the present application;
[0042] Figure 9 A schematic diagram of the structure of a first challenge message provided in an embodiment of the present application. DETAILED DESCRIPTION
[0043] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0044] It will be understood that when used in this specification and the appended claims, the terms “comprises” and “comprising” indicate the presence of described features, integers, steps, operations, elements and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof.
[0045] It should also be understood that the terms used in the present specification are only for the purpose of describing particular embodiments and are not intended to limit the present invention. As used in the present specification and the appended claims, the singular forms "a", "an", and "the" are intended to include the plural forms unless the context clearly indicates otherwise.
[0046] It should be further understood that the term "and / or" used in the present description and the appended claims refers to and includes any and all possible combinations of one or more of the associated listed items.
[0047] To solve the problem that traditional methods cannot effectively restrict STAs from accessing a specific wireless local area network, the present invention provides a wireless terminal access control method and system, which can effectively restrict STAs from accessing a specific wireless local area network and improve network security.
[0048] See also Figure 1 , Figure 1 A system architecture diagram of a communication system provided in an embodiment of the present application is shown as follows: Figure 1 As shown, the communication system includes a wireless terminal (STA) 10 , a wireless access point (AP) 20 and an authentication server (AS) 30 .
[0049] STA10 has wireless transceiver capabilities, specifically supporting the 802.11 series of protocols and communicating with AP20 or other devices. For example, STA10 is any user communication device that allows a user to communicate with AP20 and, in turn, with a wireless local area network (WLAN). For example, STA10 may be a tablet computer, desktop, laptop, notebook computer, ultra-mobile personal computer (UMPC), handheld computer, netbook, personal digital assistant (PDA), mobile phone, or other user device capable of connecting to the Internet of Things (IoT), or an IoT node in the Internet of Vehicles (IoV), or an in-vehicle communication device in the IoV. STA10 may also be a chip or processing system in any of these terminals.
[0050] AP20 is a data exchange node in a wireless network and is also the core of the wireless network. AP20 can be a communication entity such as a communication server, router, switch, or bridge. Alternatively, AP20 can include various forms of macro base stations, micro base stations, and relay stations. Of course, AP20 can also be the chip and processing system in these various forms of devices, thereby implementing the methods and functions of the embodiments of the present application.
[0051] STA10 and AP20 can also be sensor nodes in smart cities (e.g., smart water meters, smart electricity meters, smart air quality monitoring nodes), smart devices in smart homes (e.g., smart cameras, projectors, displays, TVs, speakers, refrigerators, washing machines, etc.), nodes in the Internet of Things (IoT), entertainment terminals (e.g., wearable devices such as AR and VR), smart devices in smart offices (e.g., printers, projectors, etc.), and connected car devices. It is understood that these devices can function as STA10 and / or AP20.
[0052] There is no special limitation on the specific forms of STA10 and AP20 in the embodiments of the present application, which are merely illustrative.
[0053] AS30 is a server, which can be a blade server, a high-density server, a rack server, a cabinet server, a general-purpose server, a graphics processing unit (GPU) server, a data processing unit (DPU) server, or an artificial intelligence (AI) server.
[0054] AS30 is used to authenticate STA10 and AP20. Specifically, AS30 issues certificates for STA10 and AP20. STA10 has the STA certificate issued by AS30 installed, AP20 has the AP certificate issued by AS30 installed, and both STA10 and AP20 have the AS public key certificate installed. When STA10 requests access to a wireless LAN with a service set identifier (SSID) corresponding to AP20, AP20 forwards the STA certificate in the request sent by STA10 to AS30, which verifies the validity of the STA certificate. Only if AS30 determines that the STA certificate is valid will AP20 grant STA10 access to its wireless LAN.
[0055] The AP20 converts wired network signals into wireless signals (such as Wi-Fi) and covers a specific area (such as a home, office, or public place). It transmits signals through a wireless RF module and provides a physical channel for the STA10 to connect to the network.
[0056] An SSID is a logical network name that uniquely identifies a wireless local area network (WLAN). It is essentially a string of characters up to 32 bytes long, broadcast (or hidden) by the AP20. Terminals scan this identifier to identify available WLANs. SSID technology can divide a WLAN into several subnets, each requiring different authentication levels. Each subnet requires independent authentication, and only authenticated users can access the corresponding subnet, preventing unauthorized access.
[0057] It should be understood that the SSID corresponding to AP20 mentioned in this document refers to the SSID of the wireless LAN provided by AP20 conversion.
[0058] During the WAPI authentication process, the communication message contains challenge information, which is specific data or messages used in identity authentication, security authentication, or protocol interaction.
[0059] When establishing a connection or performing sensitive operations, the authentication supplicant entity (ASUE) sends a challenge message to the authenticator entity (AE). During WAPI authentication, STA10 is the ASUE and AP20 is the AE. When AP20, acting as a client, initiates an authentication request to AS30, AP20 is the ASUE and AS30 is the AE.
[0060] In this application document, AP challenge information is also referred to as first challenge information, and STA challenge information is also referred to as second challenge information.
[0061] STA10 and AP20 generate a new random number as challenge information in each challenge. Specifically, the challenge information is a 256-bit random number. When STA10 requests to access the wireless LAN corresponding to AP20, the STA challenge information is generated by STA10. STA passes the access authentication request message (such as Figure 7 As shown) transmits the second challenge information (ie Figure 7 After receiving the access authentication request message, AP20 generates the first challenge information of AP20, and then sends a certificate authentication request message to AS (such as Figure 8 As shown), which includes the second challenge information (i.e. Figure 8 ASUE challenge in) and the first challenge information (i.e. Figure 8 AE Challenges in [1].
[0062] The purpose of the first and second challenge information is to ensure the freshness of the WAPI authentication. The authentication result generated by AS30 includes the first and second challenge information, which are derived from the certificate authentication request message. After receiving the authentication result, AP20 and STA10 verify that their respective challenge information is consistent with the challenge information they sent.
[0063] To prevent STA10 from illegally accessing the virtual wireless LAN, traditional methods use methods such as blacklists and whitelists to restrict STA10's access to AP20's SSID. However, using blacklists and whitelists requires configuring the MAC address of the terminal STA on the access controller, which presents two problems:
[0064] 1. In wireless networks, there are a large number of STA10s. For example, a municipal power WAPI network may have tens of thousands of STA10s (due to the large number of sensors). Configuring a large number of blacklists and whitelists requires a large amount of computing and storage resources.
[0065] 2. MAC addresses are easy to forge and have poor security.
[0066] Therefore, in the embodiment of the present application, based on the original multiple configurations, its own SSID number is written into the first challenge information, so that after receiving the certificate authentication request message, AS30 can obtain the SSID corresponding to the SSID number, and then compare the SSID with the set access SSID list corresponding to the STA10 to confirm whether the SSID is the SSID of the wireless LAN that the STA10 is allowed to access, and then return a message to AP20 to indicate whether the authentication is successful.
[0067] The allowed SSID list includes the SSIDs of the wireless local area networks that the corresponding STA10 is allowed to access, and the allowed SSID lists corresponding to each STA10 are pre-stored in the AS30.
[0068] Specifically, the access control process of STA10 is as follows:
[0069] STA10 is used to send an access authentication request message to AP20. The access authentication request message includes the STA certificate issued by AS30 for STA10;
[0070] The AP20 is configured to send a certificate authentication request message to the AS30 based on the access authentication request message, where the certificate authentication request message includes the first challenge information of the AP20 and the STA certificate, where the first challenge information includes an SSID number, where the SSID number is used to indicate the SSID corresponding to the AP20;
[0071] The AS30 is configured to obtain a preset list of allowed SSIDs for the ST10A based on the STA certificate; and is further configured to return an authentication pass message to the AP20 based on the certificate authentication request message if the SSID corresponding to the AP20 is in the allowed SSID list of the STA10; and return an authentication fail message to the AP20 based on the certificate authentication request message if the SSID corresponding to the AP20 is not in the allowed SSID list of the STA10;
[0072] The AP 20 is further configured to send a first response message indicating that authentication is successful to the STA based on the authentication successful message; or send a second response message indicating that authentication is unsuccessful to the STA based on the authentication failed message.
[0073] Specifically, the AP20 includes:
[0074] The receiving unit 21 is configured to receive an access authentication request message sent by the STA 10, where the access authentication request message includes the STA certificate issued by the AS 30 for the STA 10;
[0075] The sending unit 22 is configured to send a certificate authentication request message to the AS 30 based on the access authentication request message, where the certificate authentication request message includes the first challenge information of the AP 20 and the STA certificate, and the first challenge information includes the SSID number;
[0076] The receiving unit 21 is further configured to receive an authentication pass message or an authentication fail message returned by the AS30 based on the certificate authentication request message, wherein the authentication pass message is used to indicate that the AS30 has determined, based on the STA certificate, that the SSID corresponding to the AP20 exists in the preset allowed SSID list of the STA10, and the authentication fail message is used to indicate that the AS30 has determined, based on the STA certificate, that the SSID corresponding to the AP20 does not exist in the allowed SSID list of the STA10;
[0077] The sending unit 22 is further configured to send a first response message indicating that the authentication is successful to the STA based on the authentication successful message; or send a second response message indicating that the authentication is unsuccessful to the STA based on the authentication failed message.
[0078] Specifically, the AS30 includes:
[0079] The receiving unit 31 is configured to receive a certificate authentication request message sent by the AP20, wherein the certificate authentication request message includes the first challenge information of the AP20 and the STA certificate of the STA10, wherein the first challenge information includes the SSID number;
[0080] An acquiring unit 32 is configured to acquire a preset access SSID list of the STA 10 based on the STA certificate;
[0081] The sending unit 33 is configured to return an authentication pass message to the AP20 based on the certificate authentication request message if the SSID corresponding to the AP20 exists in the allowed SSID list of the STA10;
[0082] The sending unit 33 is further configured to return an authentication failure message to the AP 20 based on the certificate authentication request message if the SSID corresponding to the AP 20 does not exist in the allowed SSID list of the STA 10 .
[0083] It is understandable that the specific implementation method and technical details of the above-mentioned STA10 access control process will be described in detail in the method embodiment part below and will not be repeated here.
[0084] It is understandable that, in actual applications, the communication system, AP20 and AS30 provided in the embodiments of the present application may include more or fewer devices or components than the structures shown in the corresponding drawings. Figure 1-3 The structure shown in the figure is only an example and not a limitation, and does not constitute a specific limitation on the structures of the communication system, AP20 and AS30 provided in the embodiment of the present application.
[0085] The above describes the system part provided by the embodiment of the present application. The following describes the method part of the embodiment of the present application.
[0086] See also Figure 4 , Figure 4 A flow chart of a wireless terminal access control method provided in an embodiment of the present application, wherein the method is applied to an AP; Figure 4 As shown, the method includes the following steps:
[0087] Step 401: The AP receives an access authentication request message sent by a STA.
[0088] Among them, Figure 7 As shown, the access authentication request message includes the STA certificate issued by the AS for the STA; specifically, the AP wants to authenticate the validity of the STA's certificate as an ASUE, that is, Figure 7 The STA_ASUE certificate in the STA certificate contains the STA's public key, identity (such as user name, device ID), validity period, and other information, and is signed by a trusted AS.
[0089] Specifically, the access authentication request message does not directly contain the SSID; the AP sends the SSID parameter to each STA through periodic broadcast beacon frames or probe response frames in response to STA probe requests; after the STA determines that it wants to access the wireless LAN corresponding to the AP, it sends an access authentication request message to the corresponding AP; after authentication is completed, the STA sends an association request frame containing the SSID to the AP to request to join the wireless LAN corresponding to the specific SSID.
[0090] Step 402: The AP sends a certificate authentication request message to the AS based on the access authentication request message.
[0091] Among them, Figure 8 As shown, the certificate authentication request message includes the first challenge information of the AP ( Figure 8 The AE challenge in the example) and the STA certificate, the first challenge information includes an SSID number, and the SSID number is used to indicate the SSID corresponding to the AP.
[0092] It is understood that the SSID number is a number agreed upon by the AP and the AS. For example, the AP sends its corresponding SSID to the AS, and the AS sorts the SSIDs of each AP and sends the global index of the SSID to the corresponding AP as the SSID number.
[0093] Preferably, the first challenge information further includes a magic word, and the magic word is used to indicate that the SSID number exists in the first challenge information.
[0094] The magic word allows the AS to determine whether the SSID is present by using the magic word in the first challenge message. This approach allows information to be carried in existing message fields while maintaining protocol compatibility.
[0095] The magic word may be a preset fixed field, a periodically updated field, or a temporarily generated random field; the AS and the AP communicate or use the same generation rule so that the AS can determine the correctness of the magic word.
[0096] like Figure 9 As shown, preferably, the first 32 bits (ie, the first 32 bits) of the first challenge information are the magic word, and the second 32 bits (ie, the second 32 bits) of the first challenge information are the SSID number.
[0097] The first challenge message includes three parts: a magic word M, an SSID number, and a random number r. The magic word M is used to identify the AP by selecting a specific 4-byte integer. For example, 0xFFEEDDCC is selected as the magic word M.
[0098] Preferably, before sending the certificate authentication request message to the AS based on the access authentication request message, the AP can obtain the SSID number and the magic word; generate a 256-byte random number, and perform a hash operation on the 256-byte random number to obtain a 192-bit random number; and obtain the first challenge information based on the magic word, the target SSID and the 192-bit random number.
[0099] The SSID number is a global index issued by the AS, and the magic word is a field that is preset, obtained in advance from communication with the AS, or temporarily generated. The AP can obtain the SSID number from its memory and the magic word from its memory or temporarily generate it.
[0100] The AP may concatenate the magic word, the target SSID, and the 192-bit random number to obtain the first challenge information.
[0101] Step 403: The AP receives an authentication pass message or an authentication fail message returned by the AS based on the certificate authentication request message.
[0102] Among them, the authentication message is used to indicate that the AS determines that the SSID corresponding to the AP exists in the preset access SSID list of the STA based on the STA certificate, and the authentication failure message is used to indicate that the AS determines that the SSID corresponding to the AP does not exist in the access SSID list of the STA based on the STA certificate.
[0103] Step 404: The AP sends a first response message indicating that the authentication is successful to the STA based on the authentication success message; or sends a second response message indicating that the authentication is unsuccessful to the STA based on the authentication failure message.
[0104] After obtaining the authentication result, the AP can return a corresponding response message to the STA. If the authentication is successful, the AP returns a first authentication response message, and the subsequent steps of the SSID association phase are carried out. If the authentication is unsuccessful, the AP returns a second authentication failure response message, directly denying the STA access during the authentication phase.
[0105] In an embodiment of the present application, by writing the SSID number of the AP in the first challenge information of the certificate authentication request message, the AS can determine whether the STA is allowed to access the wireless LAN indicated by the SSID corresponding to the AP during the authentication stage, thereby restricting the STA from accessing a specific wireless LAN during the authentication stage, reducing the number of communications in the SSID association stage, and saving communication resources.
[0106] See also Figure 5 , Figure 5 The present invention provides a flow chart of another wireless terminal access control method, which is applied to AS; Figure 5 As shown, the method includes:
[0107] Step 501: The AS receives a certificate authentication request message sent by the AP.
[0108] The certificate authentication request message includes the first challenge information of the AP and the STA certificate of the STA. The first challenge information includes an SSID number, and the SSID number is used to indicate the SSID corresponding to the AP.
[0109] Preferably, the first challenge information further includes a magic word, and the magic word is used to indicate that the target SSID exists in the first challenge information.
[0110] Preferably, the first 32 bits of the first challenge information are the magic word, and the second 32 bits of the first challenge information are the SSID number; the AS can first read the first 32 bits of the first challenge information; when the magic word is in the first 32 bits of the first challenge information, the SSID number is obtained from the second 32 bits of the first challenge information, and the step of obtaining the preset access SSID list of the STA based on the STA certificate is triggered; when the magic word is not in the first 32 bits of the first challenge information, the step of returning an authentication failure message to the AP is triggered.
[0111] By using the magic word as a prerequisite for obtaining the SSID number, it is possible to avoid the situation where the AS mistakenly uses the random number as the SSID number when the first challenge information does not contain the SSID number.
[0112] Step 502: The AS obtains a preset list of allowed SSIDs for the STA based on the STA certificate.
[0113] After a STA accesses the network, the AS can generate a corresponding allowed SSID list for it based on the newly accessed STA's permissions. During subsequent communications, the AS can synchronously update this allowed SSID list based on changes in the STA's permissions. When implementing this embodiment, the allowed SSID list can be considered to be pre-set in the AS.
[0114] Step 503: If the SSID corresponding to the AP exists in the STA's allowed SSID list, the AS returns an authentication pass message to the AP based on the certificate authentication request message.
[0115] The AS may obtain the SSID number from the first challenge information, and then obtain the corresponding SSID based on the SSID number; and then determine whether the SSID exists in the allowed SSID list of the STA.
[0116] It can be understood that the SSID corresponding to the AP can be one or more; when the AP corresponds to multiple SSIDs, as long as at least one of the multiple SSIDs exists in the STA's allowed SSID list, the AS can return an authentication pass message to the AP, and then in the subsequent SSID association stage, it will be based on whether the SSID of the STA's target wireless LAN is an SSID on the allowed SSID list.
[0117] Step 504: If the SSID corresponding to the AP does not exist in the STA's allowed SSID list, the AS returns an authentication failure message to the AP based on the certificate authentication request message.
[0118] Among them, the SSID corresponding to the AP does not exist in the STA's allowed SSID list, indicating that the STA does not have the authority to access any wireless LAN of the AP. At this time, an authentication failure message can be directly returned to cause the AP to deny the STA's access.
[0119] In the embodiment of the present application, by including the SSID number of the AP's own corresponding SSID in the first challenge information in the certificate authentication request message sent by the AP to the AS, the AS detects whether the SSID corresponding to the AP exists in the STA's access SSID list during certificate authentication, and then issues a message indicating whether the authentication is successful or not, thereby achieving the purpose of controlling the wireless terminal to only access specific SSIDs. The embodiment of the present application does not require corresponding parameter configuration or blacklist and whitelist configuration for a large number of wireless terminals, and is simple and easy to implement.
[0120] See also Figure 6 , Figure 6 This is a flow chart of another wireless terminal access control method provided in an embodiment of the present application. The method is applied to a communication system including an STA, an AP, and an AS. The method includes:
[0121] Step 601: The STA sends an access authentication request message to the AP.
[0122] The access authentication request message includes the STA certificate issued by the AS to the STA.
[0123] Step 602: The AP sends a certificate authentication request message to the AS based on the access authentication request message.
[0124] The certificate authentication request message includes the first challenge information of the AP and the STA certificate. The first challenge information includes the SSID number, and the SSID number is used to indicate the SSID corresponding to the AP.
[0125] Step 603: The AS obtains a preset list of allowed SSIDs for the STA based on the STA certificate.
[0126] Step 604: If the SSID corresponding to the AP exists in the STA's allowed SSID list, the AS returns an authentication pass message to the AP based on the certificate authentication request message.
[0127] Step 605: If the SSID corresponding to the AP does not exist in the STA's allowed SSID list, the AS returns an authentication failure message to the AP based on the certificate authentication request message.
[0128] Among them, step 602 and Figure 4 The implementation of step 402 in the embodiment shown is similar, and steps 603 to 605 are similar to those in the embodiment shown. Figure 5 Steps 502 to 504 in the illustrated embodiment are similar and will not be described again here.
[0129] Step 606: The AP returns a response message to the STA based on the authentication pass message or the authentication fail message.
[0130] After obtaining the authentication result, the AP can return a corresponding response message to the STA. If the authentication is successful, the AP returns a first authentication response message, and the subsequent steps of the SSID association phase are carried out. If the authentication is unsuccessful, the AP returns a second authentication failure response message, directly denying the STA access during the authentication phase.
[0131] In the embodiment of the present application, by including the SSID number of the AP's own SSID in the first challenge information of the certificate authentication request message sent by the AP to the AS, the AS detects whether the SSID corresponding to the AP exists in the STA's access SSID list during certificate authentication, and then issues a message indicating whether the authentication is successful or not, thereby achieving the purpose of controlling the wireless terminal to only access specific SSIDs. The embodiment of the present application does not require corresponding parameter configuration or blacklist and whitelist configuration for a large number of wireless terminals, and is simple and easy to implement.
[0132] In another embodiment of the present application, a computer-readable storage medium is further provided, wherein the computer-readable storage medium includes instructions, which, when executed on a computer, causes the computer to execute the above-mentioned Figures 4 to 6 The method described in any embodiment.
[0133] Those skilled in the art will appreciate that the units of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition of each example has been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.
[0134] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0135] In the several embodiments provided in the embodiments of the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0136] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0137] In addition, the functional units in the various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0138] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, read-only memory (ROM), random access memory (RAM), mobile hard disk, magnetic disk or optical disk, and other media that can store program codes.
[0139] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the above embodiments, or make equivalent replacements for some or all of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the scope of the technical solutions of the embodiments of the present invention, and they should all be included in the scope of the claims and description of the present invention.
Claims
1. A wireless terminal access control method, characterized in that: The method is applied to a wireless access point (AP); the method includes: Receive an access authentication request message sent by a wireless terminal STA, wherein the access authentication request message includes a STA certificate issued by a certificate authentication server AS for the STA; Sending a certificate authentication request message to the AS based on the access authentication request message, where the certificate authentication request message includes first challenge information of the AP and the STA certificate, where the first challenge information includes a service set identifier (SSID) number, where the SSID number is used to indicate an SSID corresponding to the AP; receiving an authentication pass message or an authentication fail message returned by the AS based on the certificate authentication request message, wherein the authentication pass message is used to instruct the AS to determine, based on the STA certificate, that the STA is permitted to access the wireless local area network corresponding to the SSID number; and the authentication fail message is used to instruct the AS to determine, based on the STA certificate, that the STA is not permitted to access the wireless local area network corresponding to the SSID number; Based on the authentication pass message, a first response message indicating that authentication is passed is sent to the STA; or based on the authentication fail message, a second response message indicating that authentication is failed is sent to the STA.
2. The method according to claim 1, characterized in that The first challenge information further includes a magic word, where the magic word is used to indicate that the SSID number exists in the first challenge information.
3. The method according to claim 2, characterized in that The first 32 bits of the first challenge information are the magic word, and the second 32 bits of the first challenge information are the SSID number.
4. The method according to claim 2 or 3, characterized in that Before sending the certificate authentication request message to the AS based on the access authentication request message, the method further includes: Obtain the SSID number and the magic word; Generate a 256-byte random number and perform a hash operation on the 256-byte random number to obtain a 192-bit random number; The first challenge information is obtained based on the magic word, the SSID number, and the 192-bit random number.
5. A wireless terminal access control method, characterized in that: The method is applied to a certificate authentication server AS; the method comprises: Receive a certificate authentication request message sent by a wireless access point AP, where the certificate authentication request message includes first challenge information of the AP and a STA certificate of a wireless terminal STA, where the first challenge information includes an SSID number, where the SSID number is used to indicate an SSID corresponding to the AP; Based on the STA certificate, obtain a preset access SSID list of the STA, where the access SSID list includes SSIDs of wireless local area networks that the STA is allowed to access; If the SSID corresponding to the AP exists in the allowed SSID list of the STA, returning an authentication pass message to the AP based on the certificate authentication request message; In a case where the SSID corresponding to the AP does not exist in the allowed SSID list of the STA, an authentication failure message is returned to the AP based on the certificate authentication request message.
6. The method according to claim 5, characterized in that The first challenge information further includes a magic word, where the magic word is used to indicate that the SSID number exists in the first challenge information.
7. The method according to claim 6, characterized in that The first 32 bits of the first challenge information are the magic word, and the second 32 bits of the first challenge information are the SSID number; Before obtaining a preset list of STA access SSIDs based on the STA certificate, the method further includes: When the magic word is in the first 32 bits of the first challenge information, obtaining the SSID number from the second 32 bits of the first challenge information, and triggering the step of obtaining a preset access SSID list of the STA based on the STA certificate; In a case where the magic word is not in the first 32 bits of the first challenge information, the step of returning an authentication failure message to the AP is triggered.
8. A wireless terminal access control method, characterized in that: The method is applied to a communication system, which includes a wireless terminal STA, a wireless access point AP, and a certificate authentication server AS; the method includes: The STA sends an access authentication request message to the AP, where the access authentication request message includes the STA certificate issued by the AS for the STA; The AP sends a certificate authentication request message to the AS based on the access authentication request message, where the certificate authentication request message includes first challenge information of the AP and the STA certificate, where the first challenge information includes a service set identifier (SSID) number, where the SSID number is used to indicate an SSID corresponding to the AP; The AS obtains a preset access SSID list of the STA based on the STA certificate, where the access SSID list includes SSIDs of wireless local area networks that the STA is allowed to access; If the SSID corresponding to the AP exists in the allowed SSID list of the STA, the AS returns an authentication pass message to the AP based on the certificate authentication request message; If the SSID corresponding to the AP does not exist in the allowed SSID list of the STA, the AS returns an authentication failure message to the AP based on the certificate authentication request message; The AP sends a first response message indicating that authentication is successful to the STA based on the authentication successful message; or sends a second response message indicating that authentication is unsuccessful to the STA based on the authentication failed message.
9. A wireless access point AP, characterized in that: include: A receiving unit, configured to receive an access authentication request message sent by a wireless terminal STA, wherein the access authentication request message includes a STA certificate issued by a certificate authentication server AS for the STA; a sending unit, configured to send a certificate authentication request message to the AS based on the access authentication request message, wherein the certificate authentication request message includes first challenge information of the AP and the STA certificate, wherein the first challenge information includes a service set identifier (SSID) number, and the SSID number is used to indicate an SSID corresponding to the AP; The receiving unit is further configured to receive an authentication pass message or an authentication fail message returned by the AS based on the certificate authentication request message, wherein the authentication pass message is used to instruct the AS to determine, based on the STA certificate, that the STA is permitted to access the wireless local area network corresponding to the SSID number, and the authentication fail message is used to instruct the AS to determine, based on the STA certificate, that the STA is not permitted to access the wireless local area network corresponding to the SSID number; The sending unit is further configured to send a first response message indicating that authentication is successful to the STA based on the authentication successful message; or send a second response message indicating that authentication is unsuccessful to the STA based on the authentication failed message.
10. A certificate authentication server AS, characterized in that: include: A receiving unit, configured to receive a certificate authentication request message sent by a wireless access point AP, wherein the certificate authentication request message includes first challenge information of the AP and a STA certificate of a wireless terminal STA, wherein the first challenge information includes an SSID number, and the SSID number is used to indicate an SSID corresponding to the AP; an acquiring unit, configured to acquire a preset access SSID list of the STA based on the STA certificate, wherein the access SSID list includes SSIDs of wireless local area networks that the STA is allowed to access; a sending unit, configured to return an authentication pass message to the AP based on the certificate authentication request message if the SSID corresponding to the AP exists in the allowed SSID list of the STA; The sending unit is further configured to return an authentication failure message to the AP based on the certificate authentication request message when the SSID corresponding to the AP does not exist in the allowed SSID list of the STA.