WLAN Terminal 3G Network Access via WAPI and AAA Server
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
WLAN terminals using the WAPI security mechanism without UICC capability cannot access 3G networks, as there is no established technical scheme for secure access.
Innovation Solution
A method and system that enables WLAN terminals using WAPI to access 3G networks by notifying the 3G AAA server through an AP, performing EAP-TLS negotiation, and using terminal identity information to authenticate and authorize access, allowing secure access without UICC capability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If EAP-SIM or EAP-AKA authentication mechanisms are used for 3G network access, then 3G network security is ensured, but terminals must have UICC reading capability which restricts WAPI terminal users from accessing 3G networks
Solution Approach 1:
The patent introduces an intermediary conversion mechanism where the WAPI terminal's identity information (obtained through WAPI authentication) is transformed into a format compatible with 3G network authentication. The system acts as a mediator that translates between WAPI and 3G authentication protocols, enabling WAPI terminals to access 3G networks without requiring UICC reading capability while maintaining security requirements.
2Adaptability or versatility
If multiple authentication protocols are supported to ensure broad terminal compatibility, then more terminals can access 3G networks, but the authentication process complexity increases
Solution Approach 1:
The patent applies local quality by implementing different authentication mechanisms for different terminal types. WAPI terminals use a simplified authentication flow that leverages their existing WAPI credentials, while other terminals continue to use traditional EAP-SIM or EAP-AKA. This localized approach reduces overall system complexity by allowing each terminal type to use the most appropriate authentication method for its capabilities.
3Reliability
If traditional 3G authentication methods are used, then security requirements are met, but WAPI terminals without UICC capability cannot complete the authentication process
Solution Approach 1:
The patent makes the authentication system universal by enabling WAPI terminals to access 3G networks using their existing WAPI credentials. The system is modified to accept and process WAPI authentication results for 3G network access, making the authentication process convenient for WAPI terminals while maintaining security. This multi-functional approach allows the same terminal to access both WLAN and 3G networks using a single authentication mechanism.
Data Source
AI summary
A method for accessing a 3G network includes: a terminal accessing a wireless local area network by adopting a WAPI protocol, and notifying an AAA server of a 3G network through an AP of the wireless local area network that the terminal intends to access the 3G network; the AAA server obtaining identity information of the terminal through the AP, and performing an EAP-TLS negotiation process with the terminal through the AP after determining that the terminal is a subscription terminal of the 3G network according to the identity information; and the terminal accessing the 3G network after finishing the EAP-TLS negotiation process. A system for accessing a 3G network includes an AP of a wireless local area network and an AAA server of a 3G network. The present invention reduces unnecessary processes the message interacting, the certificate verification, the signature verification, and so on and improves the system efficiency.


