Certificate online issuing method and system based on WAPI
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- XJ ELECTRIC CO LTD
- Filing Date
- 2025-12-03
- Publication Date
- 2026-04-24
Smart Images

Figure CN121924482A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of digital certificate issuance and management, specifically relating to a method and system for online certificate issuance based on WAPI. Background Technology
[0002] In existing technologies, wireless authentication servers, acting as dedicated digital certificate issuance and management systems, provide digital certificate services to wireless access points and terminals within a province that need to access the WAPI wireless network. These services include certificate issuance, authentication, and revocation, ensuring the security and standardization of WAPI network access. However, during the deployment of this system, some deployment scenarios already have a security service platform responsible for certificate issuance. To integrate this platform into the existing environment, the existing certificate distribution and authentication processes need to be adapted.
[0003] Furthermore, the certificate application and distribution process for wireless access points (APs) and wireless access terminals suffers from significant efficiency shortcomings. Current certificate distribution methods are extremely inefficient, requiring manual login to the Authentication Server (AS) to apply for certificates. After the application is complete, traditional storage media is needed to import the certificates one by one into the wireless access points or wireless access terminals. This process is not only cumbersome and time-consuming, but also highly susceptible to human error, leading to certificate import failures or information errors.
[0004] Chinese invention patent application CN116321157A discloses a system and method for online issuance of trusted WLAN certificates. The system includes a certificate application unit, an intranet certificate server, and terminal devices. The certificate application unit is communicatively connected to both the terminal devices and the intranet certificate server. It collects device information and applicant information from the terminal devices and sends a certificate application request to the intranet certificate server based on these information. The intranet certificate server, upon receiving the certificate application request, executes the application, approves it, and issues the certificate upon successful approval. Based on this system, a method for online issuance of trusted WLAN certificates is also proposed. This solution addresses the problems existing in online application for trusted WLAN wireless private network certificates in the prior art, avoiding the frequent file copying issues between the power grid's internal and external networks during manual certificate application, and providing a secure, convenient, and efficient online means for terminal certificate application. However, the certificate application unit in this solution is a physical entity. When collecting certificate applications from a large number of terminal devices, there may be insufficient certificate application units. Furthermore, this solution requires the certificate application unit and the collecting terminal devices to be located in the same spatial position. Summary of the Invention
[0005] The purpose of this invention is to provide a WAPI-based online certificate issuance method and system to solve the problem that existing online WLAN certificate issuance schemes need to be adapted to the security service platform and may be limited by the location and number of certificate application units.
[0006] To achieve the above objectives, this invention provides a WAPI-based online certificate issuance method, comprising: After the wireless authentication server obtains and installs its own certificate from the security service platform, when the wireless access point and the wireless authentication server are connected to the network, when a certificate request operation is triggered on the wireless access point or the wireless access controller, a request is sent to the wireless authentication server; the wireless authentication server then sends a request to the security service platform and, upon successful request, transmits the certificate of the wireless access point to the wireless access point. The wireless access point has first and second wireless services enabled; the first wireless service is set to hide the SSID, authenticated by WAPI-PSK, and its VLAN permissions are limited to network communication with the wireless authentication server; the second wireless service is the SSID required by the service, authenticated by WAPI-CERT, and its VLAN permissions cover the VLANs required by the service. The wireless communication terminal generates a certificate request file and initiates an application to the wireless authentication server through the first wireless service. The wireless authentication server then applies to the security service platform and, upon successful application, transmits the certificate of the wireless communication terminal to the wireless communication terminal. The wireless communication terminal completes the certificate installation and switches to the second wireless service of the wireless access point.
[0007] Furthermore, the VLAN permissions for the second wireless service also cover the permissions required for the certificate update channel.
[0008] Furthermore, the online certificate issuance method also includes: before the certificate of the wireless communication terminal expires, under the current second wireless service, using the current certificate of the wireless communication terminal, to update the on-network certificate of the wireless communication terminal through the certificate update protocol with the wireless authentication server.
[0009] Furthermore, the methods by which the wireless access point's certificate is transmitted to the wireless access point via the wireless authentication server include: The security service platform issues certificates to the wireless access point and the wireless authentication server. The wireless authentication server stores the certificate of the wireless access point locally, obtains a certificate backup for subsequent authentication, and then transmits the certificate to the wireless access point online. The methods for transmitting the certificate of a wireless communication terminal to a wireless communication terminal through a wireless authentication server include: The security service platform issues certificates to wireless authentication servers for wireless communication terminals. The wireless authentication server stores the certificates of wireless communication terminals locally, obtains a certificate backup for subsequent authentication, and then transmits the certificate online to the wireless communication terminal.
[0010] Furthermore, the wireless authentication server obtains its own certificate from the security service platform in the following ways: When the wireless authentication server device is powered on, it first establishes a front-end routing channel with the security service platform to perform identity authentication and business data encryption. After confirming that the channel between the wireless authentication server and the security service platform is working properly, the wireless authentication server calls the security service platform interface to perform front-end initialization, requests the security service platform device certificate creation interface, and obtains its own certificate.
[0011] The technical solution described above provides a novel online certificate issuance method based on WAPI, with the following advantages: It eliminates the need for a separate certificate application unit, and through the dual-wireless service design of the wireless access point (AP), it ensures certificate update security without affecting normal business operations. The hidden SSID and limited access settings of the dedicated certificate update channel (i.e., the first wireless service) prevent interference from unauthorized external access and internal misoperations. Combined with the normal operation function of the business SSID (i.e., the second wireless service), the less secure dedicated certificate update channel and the more secure business data transmission channel do not interfere with each other, thus isolating the certificate application stage (where certificate authentication is unavailable) from the normal business stage. Furthermore, it automates the entire process of obtaining and updating certificates from the wireless authentication server (AS) certificate to the terminal and wireless access point certificates. Compared to traditional manual certificate management, it significantly saves manpower and time costs. The tedious operation of manually logging into the server to apply for certificates and importing them into devices is simplified to automatic device-triggered application and online certificate transmission, improving certificate management efficiency, reducing the probability of human error, and enhancing overall network security and stability.
[0012] The present invention also provides a WAPI-based online certificate issuance system, including a security service platform, a wireless authentication server, a wireless access controller, a wireless access point, and a wireless communication terminal; The wireless authentication server is used to obtain its own certificate from the security service platform and install it. When the network between the wireless access point and the wireless authentication server is connected, it initiates a certificate request to the wireless authentication server when a certificate request operation is triggered on the wireless access point or the wireless access controller. The wireless authentication server is also used to initiate a corresponding application to the security service platform according to the application triggered when the certificate request operation is triggered. After success, it transmits the certificate of the wireless access point to the wireless access point. The wireless access point has first and second wireless services enabled; the first wireless service is set to hide the SSID, authenticated by WAPI-PSK, and has VLAN permissions for network communication with the wireless authentication server; the second wireless service is the SSID required by the service, authenticated by WAPI-CERT, and has VLAN permissions covering the VLANs required by the service. The wireless communication terminal is used to generate a certificate request file and initiate an application to the wireless authentication server through the first wireless service; the wireless authentication server is also used to apply to the security service platform in accordance with the application initiated through the first wireless service, and after success, it transmits the certificate of the wireless communication terminal to the wireless communication terminal; the wireless communication terminal is also used to complete the installation of the certificate and switch to the second wireless service of the wireless access point.
[0013] Furthermore, the VLAN permissions for the second wireless service also cover the permissions required for the certificate update channel.
[0014] Furthermore, the wireless communication terminal is also used to update its on-network certificate under the current second wireless service, using its current certificate, through a certificate update protocol with the wireless authentication server, before its own certificate expires.
[0015] Furthermore, the wireless authentication server transmits the wireless access point's certificate to the wireless access point in the following ways: The wireless authentication server receives the certificate issued by the security service platform for the wireless access point, saves the certificate locally, obtains a certificate backup for subsequent authentication, and then transmits the certificate online to the wireless access point. The wireless authentication server transmits the certificate of the wireless communication terminal to the wireless communication terminal in the following ways: The wireless authentication server receives the certificate issued by the security service platform for the wireless communication terminal, saves the certificate locally, obtains a certificate backup for subsequent authentication, and then transmits the certificate online to the wireless communication terminal.
[0016] Furthermore, the wireless authentication server obtains its own certificate from the security service platform in the following ways: When the wireless authentication server device is powered on, it first establishes a front-end routing channel with the security service platform to perform identity authentication and business data encryption. After confirming that the channel between the wireless authentication server and the security service platform is working properly, the wireless authentication server calls the security service platform interface to perform front-end initialization, requests the security service platform device certificate creation interface, and obtains its own certificate.
[0017] The technical solution of the WAPI-based online certificate issuance system described above can achieve the same beneficial effects as the WAPI-based online certificate issuance method described above. Attached Figure Description
[0018] Figure 1 This diagram illustrates the principle of the WAPI-based online certificate issuance method in the implementation of the present invention. Detailed Implementation
[0019] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments.
[0020] Implementation of WAPI-based Online Certificate Issuance Method This implementation presents a technical solution for an online certificate issuance method based on WAPI. Under the architecture of an embedded security service platform responsible for certificate issuance, and through the dual wireless service design of the wireless access point, it not only realizes automatic certificate application and ensures the security of certificate updates, but also does not affect the normal operation of wireless access point services.
[0021] The method includes: After the wireless authentication server obtains and installs its own certificate from the security service platform, when the wireless access point and the wireless authentication server are connected to the network, when a certificate request operation is triggered on the wireless access point or the wireless access controller, a request is sent to the wireless authentication server; the wireless authentication server then sends a request to the security service platform and, upon successful request, transmits the certificate of the wireless access point to the wireless access point. The wireless access point has first and second wireless services enabled; the first wireless service is set to hide the SSID and its VLAN permissions are limited to network communication with the wireless authentication server; the second wireless service is the SSID required by the service and its VLAN permissions cover the VLANs required by the service. The wireless communication terminal generates a certificate request file and initiates an application to the wireless authentication server through the first wireless service. The wireless authentication server then applies to the security service platform and, upon successful application, transmits the certificate of the wireless communication terminal to the wireless communication terminal online. The wireless communication terminal completes the certificate installation and switches to the second wireless service of the wireless access point.
[0022] Therefore, the online certificate issuance method in this embodiment does not require a separate certificate application unit. Through the dual-wireless service design of the wireless access point (AP), the method ensures certificate update security without affecting normal business operations. The hidden SSID and limited access settings of the dedicated certificate update channel (i.e., the first wireless service) prevent interference from unauthorized external access and internal misoperations. Combined with the normal operation function of the business SSID (i.e., the second wireless service), the less secure dedicated certificate update channel and the more secure business data transmission channel do not interfere with each other. This allows for the isolation of the certificate application stage (where certificate authentication is unavailable) from the normal business stage. Furthermore, it automates the entire process from obtaining the certificate from the wireless authentication server (AS) itself to applying for and updating certificates for terminals (Stations, STAs, i.e., wireless workstations) and wireless access points (APs). Compared to traditional manual certificate management methods, this significantly saves manpower and time costs. The tedious operation of manually logging into the server to apply for certificates and importing them into devices is simplified to automatic device-triggered application and online certificate transmission, which not only improves the efficiency of certificate management but also reduces the probability of human error, enhancing the overall security and stability of the network.
[0023] In this embodiment, the VLAN permissions of the second wireless service also cover the permissions required for the certificate update channel. Based on this, the online certificate issuance method further includes: before the certificate of the wireless communication terminal expires, under the current second wireless service, using the current certificate of the wireless communication terminal, and through the certificate update protocol with the wireless authentication server, to update the on-network certificate of the wireless communication terminal.
[0024] This configuration leverages the necessary permissions for certificate update channels provided by the second wireless service to update certificates using the service SSID before expiration. This allows users to update certificates without interrupting their network operations, achieving a perfect balance between security and convenience and providing a superior network experience. In one specific embodiment, the wireless communication terminal's current certificate is used under the current second wireless service, through a certificate update protocol with the wireless authentication server, only when the STA certificate is about to expire. In other words, the wireless communication terminal's online certificate is updated only within a set timeframe before the STA certificate expires, using the certificate update protocol with the wireless authentication server.
[0025] In other implementations, before the certificate of the wireless communication terminal expires, the user can switch from the current second wireless service to the first wireless service, and then submit an application to the wireless authentication server through the first wireless service. The wireless authentication server will then submit an application to the security service platform and, upon successful submission, will transmit the certificate of the wireless communication terminal to the wireless communication terminal, thereby updating the on-network certificate of the wireless communication terminal.
[0026] Furthermore, in this embodiment, the method of transmitting the wireless access point's certificate to the wireless access point via the wireless authentication server includes: The security service platform issues certificates to the wireless access point and the wireless authentication server. The wireless authentication server stores the certificate of the wireless access point locally, obtains a certificate backup for subsequent authentication, and then transmits the certificate to the wireless access point online. The methods for transmitting the certificate of a wireless communication terminal to a wireless communication terminal through a wireless authentication server include: The security service platform issues certificates to wireless authentication servers for wireless communication terminals. The wireless authentication server stores the certificates of wireless communication terminals locally, obtains a certificate backup for subsequent authentication, and then transmits the certificate online to the wireless communication terminal.
[0027] This transmission method ensures that the wireless authentication server obtains the certificate required for its authentication function while transmitting the certificate, without the need for separate acquisition. This simplifies the workflow of the wireless authentication server and improves its efficiency.
[0028] In addition, to ensure that the wireless authentication server's boot-up and use comply with standard requirements within the embedded security service platform architecture, in this embodiment, the wireless authentication server obtains its own certificate from the security service platform in the following ways: When the wireless authentication server device is powered on, it first establishes a front-end routing channel with the security service platform to perform identity authentication and business data encryption. After confirming that the channel between the wireless authentication server and the security service platform is working properly, the wireless authentication server calls the security service platform interface to perform front-end initialization, requests the security service platform device certificate creation interface, and obtains its own certificate.
[0029] Reference Figure 1 In one specific embodiment, the architecture underlying the entire WAPI online certificate issuance method includes a security service platform, a wireless authentication server (AS), a wireless access controller (AC), a wireless access point (AP), and a wireless communication terminal (STA). Figure 1 The process of APs and STAs applying for and renewing certificates online from the security service platform is highly automated and convenient. A specific example of this process is as follows: (1) When the AS device is powered on and in use, it must first establish a front-end routing channel with the security service platform to perform identity authentication and business data encryption, so as to ensure the legality of the identity of the access business system and the security and non-repudiation of the business data transmission. After ensuring that the channel with the security service platform is working normally, the AS calls the security service platform interface to perform front-end initialization, requests the security service platform device certificate creation interface, obtains its own certificate, and completes the automatic installation of the certificate.
[0030] (2) The AP connects to the wireless authentication network via a wired connection, ensuring network connectivity between it and the AS. A certificate request can be manually triggered on the AP or AC to send a certificate request to the AS. Upon receiving the certificate request message, the AS automatically generates the corresponding certificate request file according to the security service platform standard and sends the request to the security service platform (i.e., the wireless authentication server sends a corresponding request to the security service platform). After receiving the request, the security service platform issues the AP certificate to the AS. The AS saves a copy locally and then transmits the obtained certificate online to the AP.
[0031] (3) Two wireless services are enabled on the AP. One wireless service is a dedicated certificate update channel, which uses WAPI-PSK authentication and is set to hide the SSID. Its VLAN permissions are limited to network communication with the AS and are dedicated to certificate updates. It has no service access permissions, ensuring the security and independence of the certificate update process. The other is the SSID required by the service, which uses WAPI-CERT authentication. Its VLAN permissions cover the VLANs required by the service and the permissions required by the certificate update channel.
[0032] (4) The STA accesses the AP's dedicated wireless service for certificate updates (dedicated certificate update channel). The STA automatically generates a certificate request file and submits an application to the AS. The AS then uses the certificate application interface to apply to the security service platform. Upon successful application, the AS transmits the certificate to the STA online. The STA receives the certificate, completes the automatic certificate installation, and automatically switches to the AP's service wireless service.
[0033] (5) Since STA certificates have an expiration time, when a STA certificate is about to expire, the current certificate can be used under the current business SSID to update the online certificate through the certificate update protocol with AS.
[0034] Implementation of an Online Certificate Issuance System Based on WAPI This embodiment provides a technical solution for an online certificate issuance system based on WAPI, including a security service platform, a wireless authentication server, a wireless access controller, a wireless access point, and a wireless communication terminal. The wireless authentication server is used to obtain its own certificate from the security service platform and install it. When the network between the wireless access point and the wireless authentication server is connected, it initiates a certificate request to the wireless authentication server when a certificate request operation is triggered on the wireless access point or the wireless access controller. The wireless authentication server is also used to initiate a corresponding application to the security service platform according to the application triggered when the certificate request operation is triggered. After success, it transmits the certificate of the wireless access point to the wireless access point. The wireless access point has first and second wireless services enabled; the first wireless service is set to hide the SSID, authenticated by WAPI-PSK, and has VLAN permissions for network communication with the wireless authentication server; the second wireless service is the SSID required by the service, authenticated by WAPI-CERT, and has VLAN permissions covering the VLANs required by the service. The wireless communication terminal is used to generate a certificate request file and initiate an application to the wireless authentication server through the first wireless service of the wireless access point; the wireless authentication server is also used to apply to the security service platform in accordance with the application initiated through the first wireless service, and after success, it transmits the certificate of the wireless communication terminal to the wireless communication terminal; the wireless communication terminal is also used to complete the installation of the certificate and switch to the second wireless service of the wireless access point.
[0035] Therefore, this system architecture eliminates the need for a separate certificate application unit. Through the dual-wireless service design of the wireless access point (AP) and the wireless authentication server, it ensures secure certificate updates without disrupting normal business operations. The hidden SSID and limited access settings of the dedicated certificate update channel (i.e., the first wireless service) prevent interference from unauthorized external access and internal misoperations. Combined with the normal operation of the business SSID (i.e., the second wireless service), the less secure dedicated certificate update channel and the more secure business data transmission channel remain independent, enabling isolation between the certificate application phase (when certificate authentication is unavailable) and the normal business phase. Furthermore, it automates the entire process from obtaining the certificate from the wireless authentication server (AS) itself to applying for and updating certificates for terminals (Stations, STAs, i.e., wireless workstations) and wireless access points (APs). Compared to traditional manual certificate management, this significantly reduces manpower and time costs. The tedious process of manually logging into the server to apply for certificates and importing them into devices has been simplified to automatic device-triggered application and online certificate transmission, improving certificate management efficiency, reducing the probability of human error, and enhancing overall network security and stability.
[0036] In this embodiment, the VLAN permissions of the second wireless service also include the permissions required for the certificate update channel. Based on this, the wireless communication terminal is also used to update its on-network certificate under the current second wireless service, using its current certificate and through the certificate update protocol with the wireless authentication server, before its own certificate expires.
[0037] This configuration leverages the necessary permissions for certificate update channels provided by the second wireless service to update certificates using the service SSID before expiration. This allows users to update certificates without interrupting their network operations, achieving a perfect balance between security and convenience and providing a superior network experience. In one specific embodiment, the wireless communication terminal's current certificate is used under the current second wireless service, through a certificate update protocol with the wireless authentication server, only when the STA certificate is about to expire. In other words, the wireless communication terminal's online certificate is updated only within a set timeframe before the STA certificate expires, using the certificate update protocol with the wireless authentication server.
[0038] In other implementations, the wireless authentication server can also switch from the second wireless service of the current wireless access point to the first wireless service before the certificate of the wireless communication terminal expires. The wireless communication terminal then initiates an application to the wireless authentication server through the first wireless service. The wireless authentication server then applies to the security service platform accordingly and, upon successful application, transmits the certificate of the wireless communication terminal to the wireless communication terminal, thereby realizing the online certificate update of the wireless communication terminal.
[0039] Furthermore, in this embodiment, the wireless authentication server transmits the wireless access point's certificate to the wireless access point in the following ways: The wireless authentication server receives the certificate issued by the security service platform for the wireless access point, saves the certificate locally, obtains a certificate backup for subsequent authentication, and then transmits the certificate online to the wireless access point. The wireless authentication server transmits the certificate of the wireless communication terminal to the wireless communication terminal in the following ways: The wireless authentication server receives the certificate issued by the security service platform for the wireless communication terminal, saves the certificate locally, obtains a certificate backup for subsequent authentication, and then transmits the certificate online to the wireless communication terminal.
[0040] This transmission method ensures that the wireless authentication server obtains the certificate required for its authentication function while transmitting the certificate, without the need for separate acquisition. This simplifies the workflow of the wireless authentication server and improves its efficiency.
[0041] In addition, to ensure that the wireless authentication server's boot-up and use comply with standard requirements within the embedded security service platform architecture, in this embodiment, the wireless authentication server obtains its own certificate from the security service platform in the following ways: When the wireless authentication server device is powered on, it first establishes a front-end routing channel with the security service platform to perform identity authentication and business data encryption. After confirming that the channel between the wireless authentication server and the security service platform is working properly, the wireless authentication server calls the security service platform interface to perform front-end initialization, requests the security service platform device certificate creation interface, and obtains its own certificate.
[0042] In one specific embodiment, the architecture of the entire WAPI online certificate issuance system includes a security service platform, a wireless authentication server (AS), a wireless access controller (AC), a wireless access point (AP), and wireless communication terminals (STA). Figure 1 The process for APs and STAs to apply for and renew certificates online from the security service platform is highly automated and convenient. A specific example of the system's workflow is as follows: (1) When the AS device is powered on and in use, it must first establish a front-end routing channel with the security service platform to perform identity authentication and business data encryption, so as to ensure the legality of the identity of the access business system and the security and non-repudiation of the business data transmission. After ensuring that the channel with the security service platform is working normally, the AS calls the security service platform interface to perform front-end initialization, requests the security service platform device certificate creation interface, obtains its own certificate, and completes the automatic installation of the certificate.
[0043] (2) The AP connects to the wireless authentication network via a wired connection, ensuring network connectivity between it and the AS. A certificate request can be manually triggered on the AP or AC to send a certificate request to the AS. Upon receiving the certificate request message, the AS automatically generates the corresponding certificate request file according to the security service platform standard and sends the request to the security service platform (i.e., the wireless authentication server sends a corresponding request to the security service platform). After receiving the request, the security service platform issues the AP certificate to the AS. The AS saves a copy locally and then transmits the obtained certificate online to the AP.
[0044] (3) Two wireless services are enabled on the AP. One wireless service is a dedicated certificate update channel, which uses WAPI-PSK authentication and is set to hide the SSID. Its VLAN permissions are limited to network communication with the AS and are dedicated to certificate updates. It has no service access permissions, ensuring the security and independence of the certificate update process. The other is the SSID required by the service, which uses WAPI-CERT authentication. Its VLAN permissions cover the VLANs required by the service and the permissions required by the certificate update channel.
[0045] (4) The STA accesses the AP's dedicated wireless service for certificate updates (dedicated certificate update channel). The STA automatically generates a certificate request file and submits an application to the AS. The AS then uses the certificate application interface to apply to the security service platform. Upon successful application, the AS transmits the certificate to the STA online. The STA receives the certificate, completes the automatic certificate installation, and automatically switches to the AP's service wireless service.
[0046] (5) Since STA certificates have an expiration time, when a STA certificate is about to expire, the current certificate can be used under the current business SSID to update the online certificate through the certificate update protocol with AS.
[0047] It should be understood that the above-described specific embodiments of the present invention are merely illustrative or explanatory of the principles of the present invention, and do not constitute a limitation thereof.
Claims
1. A method for online certificate issuance based on WAPI, characterized in that, include: After the wireless authentication server obtains and installs its own certificate from the security service platform, when the wireless access point and the wireless authentication server are connected to the network, when a certificate request operation is triggered on the wireless access point or the wireless access controller, a request is sent to the wireless authentication server; the wireless authentication server then sends a request to the security service platform and, upon successful request, transmits the certificate of the wireless access point to the wireless access point. The wireless access point has first and second wireless services enabled; the first wireless service is set to hide the SSID, authenticated by WAPI-PSK, and its VLAN permissions are limited to network communication with the wireless authentication server; the second wireless service is the SSID required by the service, authenticated by WAPI-CERT, and its VLAN permissions cover the VLANs required by the service. The wireless communication terminal generates a certificate request file and initiates an application to the wireless authentication server through the first wireless service. The wireless authentication server then applies to the security service platform and, upon successful application, transmits the certificate of the wireless communication terminal to the wireless communication terminal. The wireless communication terminal completes the certificate installation and switches to the second wireless service of the wireless access point.
2. The online certificate issuance method based on WAPI according to claim 1, characterized in that, The VLAN permissions for the second wireless service also cover the permissions required for the certificate update channel.
3. The online certificate issuance method based on WAPI according to claim 2, characterized in that, The online certificate issuance method further includes: before the certificate of the wireless communication terminal expires, under the current second wireless service, using the current certificate of the wireless communication terminal, and through the certificate update protocol with the wireless authentication server, to update the on-network certificate of the wireless communication terminal.
4. The online certificate issuance method based on WAPI according to any one of claims 1-3, characterized in that, The methods for transmitting a wireless access point's certificate to a wireless access point via a wireless authentication server include: The security service platform issues certificates to the wireless access point and the wireless authentication server. The wireless authentication server stores the certificate of the wireless access point locally, obtains a certificate backup for subsequent authentication, and then transmits the certificate to the wireless access point online. The methods for transmitting the certificate of a wireless communication terminal to a wireless communication terminal through a wireless authentication server include: The security service platform issues certificates to wireless authentication servers for wireless communication terminals. The wireless authentication server stores the certificates of wireless communication terminals locally, obtains a certificate backup for subsequent authentication, and then transmits the certificate online to the wireless communication terminal.
5. The online certificate issuance method based on WAPI according to any one of claims 1-3, characterized in that, The wireless authentication server obtains its own certificate from the security service platform in the following ways: When the wireless authentication server device is powered on, it first establishes a front-end routing channel with the security service platform to perform identity authentication and business data encryption. After confirming that the channel between the wireless authentication server and the security service platform is working properly, the wireless authentication server calls the security service platform interface to perform front-end initialization, requests the security service platform device certificate creation interface, and obtains its own certificate.
6. A WAPI-based online certificate issuance system, characterized in that, This includes a security service platform, a wireless authentication server, a wireless access controller, a wireless access point, and a wireless communication terminal; The wireless authentication server is used to obtain its own certificate from the security service platform and install it. When the network between the wireless access point and the wireless authentication server is connected, it initiates a certificate request to the wireless authentication server when a certificate request operation is triggered on the wireless access point or the wireless access controller. The wireless authentication server is also used to initiate a corresponding application to the security service platform according to the application triggered when the certificate request operation is triggered. After success, it transmits the certificate of the wireless access point to the wireless access point. The wireless access point has first and second wireless services enabled; the first wireless service is set to hide the SSID, authenticated by WAPI-PSK, and has VLAN permissions for network communication with the wireless authentication server; the second wireless service is the SSID required by the service, authenticated by WAPI-CERT, and has VLAN permissions covering the VLANs required by the service. The wireless communication terminal is used to generate a certificate request file and initiate an application to the wireless authentication server through the first wireless service; The wireless authentication server is also used to apply to the security service platform in response to the application initiated through the first wireless service, and after success, to transmit the certificate of the wireless communication terminal to the wireless communication terminal; the wireless communication terminal is also used to complete the installation of the certificate and switch to the second wireless service of the wireless access point.
7. The online certificate issuance system based on WAPI according to claim 6, characterized in that, The VLAN permissions for the second wireless service also cover the permissions required for the certificate update channel.
8. The online certificate issuance system based on WAPI according to claim 7, characterized in that, The wireless communication terminal is also used to update its on-network certificate under the current second wireless service before its own certificate expires, using the wireless communication terminal's current certificate and through the certificate update protocol with the wireless authentication server.
9. The WAPI-based online certificate issuance system according to any one of claims 6-8, characterized in that, The wireless authentication server transmits the wireless access point's certificate to the wireless access point in the following ways: The wireless authentication server receives the certificate issued by the security service platform for the wireless access point, saves the certificate locally, obtains a certificate backup for subsequent authentication, and then transmits the certificate online to the wireless access point. The wireless authentication server transmits the certificate of the wireless communication terminal to the wireless communication terminal in the following ways: The wireless authentication server receives the certificate of the wireless communication terminal issued by the security service platform, saves the certificate of the wireless communication terminal locally, obtains a certificate backup for subsequent authentication, and then transmits the certificate to the wireless communication terminal online.
10. The WAPI-based online certificate issuance system according to any one of claims 6-8, characterized in that, The wireless authentication server obtains its own certificate from the security service platform in the following ways: When the wireless authentication server device is powered on, it first establishes a front-end routing channel with the security service platform to perform identity authentication and business data encryption. After confirming that the channel between the wireless authentication server and the security service platform is working properly, the wireless authentication server calls the security service platform interface to perform front-end initialization, requests the security service platform device certificate creation interface, and obtains its own certificate.
Citation Information
Patent Citations
System and method for online signing and issuing of trusted WLAN (Wireless Local Area Network) certificate
CN116321157A