WAPI Roaming Authentication via Root Server Mediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing WAPI-based roaming authentication methods face challenges in establishing trust relationships and obtaining certificates, especially when a terminal lacks alternative network access, leading to failed roaming authentication.
Innovation Solution
A WAPI-based authentication method that initiates a security mechanism between a terminal and a wireless access point, involving a foreign-authentication server searching for a trusted home-authentication server or an upper central root-authentication server to verify and authenticate roaming access, ensuring seamless network access without user intervention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a terminal uses certificate-based roaming authentication in WAPI, then security is improved, but the authentication fails when the terminal cannot obtain the foreign authentication server's certificate through alternative network access
Solution Approach 1:
The patent introduces a root authentication server as an intermediary entity that mediates between the foreign authentication server and the home authentication server. When the foreign authentication server cannot directly verify the terminal's certificate, it queries the root authentication server, which in turn queries the home authentication server. This intermediary mechanism enables certificate verification even when direct trust relationships cannot be established, resolving the contradiction between maintaining security and ensuring authentication accessibility.
2Reliability
If the WAPI security mechanism requires certificate verification for roaming, then security is enhanced, but the authentication process becomes complex and may fail without pre-established trust relationships
Solution Approach 1:
The patent implements preliminary action by having the root authentication server pre-store public keys or verification credentials of home authentication servers in a cached trust relationship. This pre-establishment of trust allows the root server to quickly verify certificates without requiring complex real-time mutual authentication protocols, thereby maintaining high security while reducing system complexity and enabling seamless roaming authentication.
Data Source
AI summary
A roaming authentication method based on WAPI. The present invention includes the steps of adopting a terminal and a wireless access point to initiate a WAPI security mechanism, relating the terminal to the wireless access point, and initiating a WAPI authentication process and so on. And a highly safe and convenient roaming authentication method based on WAPI is provided, so as to solve the technical problem that how the specific method of certificate roaming authentication is realized, the certificate of external network authentication server can not be obtained to establish a trustful relationship, and the terminal perhaps can not realize roaming authentication.

