WAPI Roaming Authentication via Root Server Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing WAPI-based roaming authentication methods face challenges in establishing trust relationships and obtaining certificates, especially when a terminal lacks alternative network access, leading to failed roaming authentication.

Innovation Solution

A WAPI-based authentication method that initiates a security mechanism between a terminal and a wireless access point, involving a foreign-authentication server searching for a trusted home-authentication server or an upper central root-authentication server to verify and authenticate roaming access, ensuring seamless network access without user intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a terminal uses certificate-based roaming authentication in WAPI, then security is improved, but the authentication fails when the terminal cannot obtain the foreign authentication server's certificate through alternative network access

Engineering Contradiction:
Improveroaming authentication reliabilityVSAvoidauthentication accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a root authentication server as an intermediary entity that mediates between the foreign authentication server and the home authentication server. When the foreign authentication server cannot directly verify the terminal's certificate, it queries the root authentication server, which in turn queries the home authentication server. This intermediary mechanism enables certificate verification even when direct trust relationships cannot be established, resolving the contradiction between maintaining security and ensuring authentication accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the WAPI security mechanism requires certificate verification for roaming, then security is enhanced, but the authentication process becomes complex and may fail without pre-established trust relationships

Engineering Contradiction:
Improvecertificate verification securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by having the root authentication server pre-store public keys or verification credentials of home authentication servers in a cached trust relationship. This pre-establishment of trust allows the root server to quickly verify certificates without requiring complex real-time mutual authentication protocols, thereby maintaining high security while reducing system complexity and enabling seamless roaming authentication.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8417951B2Roaming authentication method based on WAPI
Publication Date: 2013.04.09 CHINA IWNCOMM
  • US8417951B2 patent drawing
  • US8417951B2 patent drawing

AI summary

A roaming authentication method based on WAPI. The present invention includes the steps of adopting a terminal and a wireless access point to initiate a WAPI security mechanism, relating the terminal to the wireless access point, and initiating a WAPI authentication process and so on. And a highly safe and convenient roaming authentication method based on WAPI is provided, so as to solve the technical problem that how the specific method of certificate roaming authentication is realized, the certificate of external network authentication server can not be obtained to establish a trustful relationship, and the terminal perhaps can not realize roaming authentication.