WO2008080353A1 - Procédé d'exploitation de réseau local sans fil basé sur une infrastructure d'authentification et de confidentialité de réseau wlan (wapi) - Google Patents

Procédé d'exploitation de réseau local sans fil basé sur une infrastructure d'authentification et de confidentialité de réseau wlan (wapi) Download PDF

Info

Publication number
WO2008080353A1
WO2008080353A1 PCT/CN2007/071372 CN2007071372W WO2008080353A1 WO 2008080353 A1 WO2008080353 A1 WO 2008080353A1 CN 2007071372 W CN2007071372 W CN 2007071372W WO 2008080353 A1 WO2008080353 A1 WO 2008080353A1
Authority
WO
WIPO (PCT)
Prior art keywords
authentication
mobile terminal
certificate
access point
wireless access
Prior art date
Application number
PCT/CN2007/071372
Other languages
English (en)
French (fr)
Inventor
Bianling Zhang
Jun Cao
Xiaolong Lai
Benteng Ma
Xiangchen Ma
Original Assignee
China Iwncomm Co., Ltd.
China Mobile Group Design Institute Co., Ltd.
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China Iwncomm Co., Ltd., China Mobile Group Design Institute Co., Ltd. filed Critical China Iwncomm Co., Ltd.
Publication of WO2008080353A1 publication Critical patent/WO2008080353A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3263Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0823Network architectures or network communication protocols for network security for authentication of entities using certificates
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • H04W12/069Authentication using certificates or pre-shared keys
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/80Wireless
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W84/00Network topologies
    • H04W84/02Hierarchically pre-organised networks, e.g. paging networks, cellular networks, WLAN [Wireless Local Area Network] or WLL [Wireless Local Loop]
    • H04W84/10Small scale networks; Flat hierarchical networks
    • H04W84/12WLAN [Wireless Local Area Networks]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W92/00Interfaces specially adapted for wireless communication networks
    • H04W92/04Interfaces between hierarchically different network devices
    • H04W92/10Interfaces between hierarchically different network devices between terminal device and access point, i.e. wireless air interface

Definitions

  • the present invention relates to the field of wireless local area networks, and more particularly to a method for WLAN operation based on WAPI.
  • WLAN Wireless Local Area Network
  • the standard system includes a new WLAN Authentication and Privacy Infrastructure (WAPI) security mechanism, which is defined by the WLAN Authentication Infrastructure (WAI) and the Wireless Office i or Network Privacy Infrastructure.
  • WAPI WLAN Privacy Infrastructure
  • WAPI provides certificate-based authentication and key negotiation methods. This method provides high security, ensures legitimate users access to legitimate networks, and protects data on wireless links.
  • the current authentication mechanism (such as Radius) only implements one-way authentication of the network to the user, and implements charging and other functions based on the authentication.
  • the authentication charging mode is effective when the link is relatively secure, that is, in a wired environment. The next is more suitable.
  • wireless LAN links are very insecure due to their open features. These authentication and charging methods are directly applied to wireless LANs, which may cause major security problems.
  • the present invention provides a certificate-based WAPI standard operation method that complies with national standards and supports various authentication and charging methods currently used, and can effectively solve the method for authenticating and charging of operators for wireless local area network operations in the prior art.
  • Technical issues that are incompatible with the certification methods specified in the National Standard GB 15629.11 and its Modification No. 1.
  • a WAPI-based WLAN operation method including:
  • the authentication server issues certificates for each type of mobile terminal according to the classification of the mobile terminal, and the same type of mobile terminal uses the same certificate, and the authentication server issues a certificate for each wireless access point, and the mobile terminal and the wireless access point install the authentication server to issue the certificate. Certificate
  • the mobile terminal When the mobile terminal needs to access the network, the mobile terminal associates with the wireless access point to establish a link connection; the wireless access point sends an authentication activation frame to the mobile terminal to start the authentication process; the mobile terminal and the wireless access point are in accordance with the national standard GB 15629.11 and The modification No. 1 stipulates that the certificate authentication is performed by the authentication server. If the certificate authentication is successful, the mobile terminal and the wireless access point perform session key negotiation, and the wireless access point notifies the mobile terminal of the multicast key;
  • the wireless access point allows the mobile terminal to access, and performs access control on the terminal user according to the authentication information of different certificate types
  • the access controller authenticates the account information of the mobile terminal
  • the server gives the mobile terminal authentication information according to the result of the account information authentication, and the mobile terminal exchanges information data with the network.
  • the mobile terminal and The specific steps for the wireless access point to perform certificate authentication through the access server include:
  • the wireless access point sends an authentication activation to the mobile terminal
  • the mobile terminal sends an access authentication request to the wireless access point, where the access authentication request includes a certificate of the mobile terminal;
  • the wireless access point sends a certificate authentication request to the authentication server, the certificate authentication request including a certificate of the mobile terminal and the wireless access point;
  • the authentication server verifies the certificate of the mobile terminal and the wireless access point, determines corresponding authentication information according to the terminal certificate category and the corresponding access control policy, and the authentication server returns a certificate authentication response to the wireless access point, the certificate authentication response
  • the authentication result including the mobile terminal and the wireless access point certificate
  • the wireless access point determines whether the mobile terminal is allowed to access according to the mobile terminal certificate authentication result returned by the authentication server, and sends an access authentication response to the mobile terminal;
  • the mobile terminal determines whether to access the wireless access point according to the certificate authentication result of the authentication server to the wireless access point in the access authentication response, and if yes, determines that the certificate authentication is successful.
  • the access controller authenticates the account information of the mobile terminal as follows: When the certificate authentication phase is completed, when the user browses the network, the system automatically pops up a webpage, prompting the user to input a username and password, and the server verifies the identity of the user according to the username and password. And control the access of the network according to the authentication result. If the authentication is successful, the mobile terminal can access the network.
  • the access controller authenticates the account information of the mobile terminal as follows: When the certificate authentication phase is completed, the mobile terminal uses the information in the Subscriber Identity Module (SIM) card to perform the authentication server and the wireless access point. Identity authentication and session key negotiation, and control network access according to the authentication result. If the authentication is successful, the mobile terminal can access the network.
  • SIM Subscriber Identity Module
  • the invention separates two independent processes of link level authentication and user level identity identification, so that the wireless local area network can be extended as the original operation network, and the operation management of the wireless local area network is consistent with the original operation network, wherein the link Level authentication is used to secure wireless link access, and user level identity is used for management services such as authorization and billing.
  • the invention adopts a security access technology conforming to national standards in the link level authentication process, It can realize two-way identity authentication between users and networks, and is compatible with the original authorization and billing management systems. It fully complies with the national standard GB15629.11-2003, GB 15629.11-2003/XG1-2006 and other sub-standards. , In line with national standards.
  • the invention adopts a secure access technology conforming to national standards in the link level authentication process, and utilizes a certificate mechanism based on a public key cryptosystem to truly realize mutual authentication between a mobile terminal (MT) and a wireless access point (AP). It fully satisfies the operator's requirements for secure access, so that the security of the wireless link is guaranteed; and it is equivalent to the wired link.
  • the network further authenticates the user identity of the mobile terminal during the user account information authentication phase, controls whether the mobile terminal can access the network, and controls the access network according to the result of the authentication and charges the user access network. Therefore, the present invention is highly safe.
  • the present invention can continue to use the existing user authentication and charging method, and has good flexibility. After the wireless access point sets the certificate, the AAA server in the background is not required to be set up, and the installation and networking are convenient, and can be used for large-scale hotspots. And other regional operations.
  • the present invention can also classify users according to different user application services, and issue certificates based on user types, and support a more flexible user level configuration policy on the basis of ensuring security, thereby supporting a more flexible operation mode.
  • the present invention separates two independent processes of link level authentication and user level identity authentication, so that the wireless local area network can be extended as the original operating network, and the operation management of the wireless local area network is consistent with the original operating network.
  • the present invention will be further described in detail below.
  • An embodiment of the present invention provides a method for implementing a WAPI-based WLAN operation by using a classification terminal certificate, including: a link level authentication step and an account information authentication step, where:
  • the link level authentication steps are as follows:
  • the authentication server AS (Authentication Server) issues certificates for each type of mobile terminal according to the classification of the mobile terminal MT (Mobile Terminal).
  • the mobile terminal uses the same certificate, and the authentication server issues a certificate for each access point AP (Access Point), and the mobile terminal and the wireless access point install a certificate issued by the access server; wherein, the AS provides the identity authentication service and the certificate.
  • a network entity that manages functions an MT is a terminal installed with a wireless network adapter; and an AP provides a network access service for a mobile terminal;
  • the mobile terminal When the mobile terminal needs to access the network, the mobile terminal first associates with the wireless access point to establish a link connection;
  • the wireless access point sends an authentication activation frame to the mobile terminal, and starts the authentication process
  • the mobile terminal and the wireless access point perform certificate authentication through the authentication server;
  • the wireless access point sends the authentication activation to the mobile terminal, and then the certificate authentication can be performed as follows:
  • the mobile terminal sends an access authentication request to the wireless access point, where the access authentication request includes a certificate of the mobile terminal;
  • the wireless access point sends a certificate authentication request to the authentication server, where the certificate authentication request includes a certificate of the mobile terminal and the wireless access point;
  • the authentication server verifies the certificate of the mobile terminal and the wireless access point, and determines corresponding authentication information according to the terminal certificate category and the corresponding access control policy, and then the authentication server returns a certificate authentication response to the wireless access point.
  • the certificate authentication response includes an authentication result of the mobile terminal and the wireless access point certificate;
  • the wireless access point determines whether the mobile terminal is allowed to access according to the mobile terminal certificate authentication result returned by the authentication server, and sends an access authentication response to the mobile terminal;
  • the mobile terminal determines whether to access the wireless access point according to the certificate authentication result of the authentication server to the wireless access point in the access authentication response, and if yes, proceeds to step 5), or does not end.
  • the mobile terminal and the wireless access point perform session key negotiation, and the wireless access point notifies the mobile terminal of the multicast key;
  • the wireless access point allows the mobile terminal to access, and according to different certificate types
  • the right information controls the access of the terminal user
  • the account information authentication steps are as follows:
  • the access controller AC Access Control authenticates the account information of the mobile terminal, where the AC is a network device that provides access control for the user to access the network;
  • the server gives the mobile terminal authentication information according to the result of the account information authentication, and the mobile terminal exchanges information data with the network, that is, the mobile terminal can access the network.
  • the account information of the access controller to the mobile terminal in the step 7) may be authenticated according to the following steps:
  • the certificate authentication phase when the user browses the network, the system automatically pops up a webpage, prompting the user to input the username and The password, the access server verifies the identity of the user according to the username and password, and controls the access of the network according to the authentication result. If the authentication is successful, the mobile terminal can access the network.
  • the account information of the access controller to the mobile terminal in the step 7) may also be authenticated according to the following steps:
  • the mobile terminal uses the information in the SIM card to pass the authentication server and the wireless
  • the access point performs identity authentication and session key negotiation, and controls network access according to the authentication result. If the authentication is successful, the mobile terminal can access the network.

Description

基于 WAPI的 WLAN运营的方法
本申请要求于 2006年 12 月 29 日提交中国专利局、 申请号为 200610105378.3、 发明名称为"釆用分类终端证书实现基于 WAPI 的 WLAN运营的方法"的中国专利申请的优先权, 其全部内容通过引用 结合在本申请中。
技术领域
本发明涉及无线局域网领域, 尤其是一种基于 WAPI的 WLAN 运营的方法。
背景技术
无线局域网 WLAN ( Wireless Local Area Network )以其构架的灵 活性、 快捷性及可扩展性, 近几年发展迅速, 已经广泛应用于热点地 区运营、 企业、 行业和家庭领域。
对于无线局域网来说, 安全至关重要。 2003年 5月份我国颁布 了无线局域网国家标准 GB15629.il 和 GB15629.1102, 这是我国在 无线局域网领域首批颁布的标准。 2006年, 无线局域网国家标准第 1 号修改单 GB 15629.11-2003/XG1-2006 及其他相关子项标准 GB15629.1101、 GB/T 15629.1103和 GB15629.1104也颁布实施,初步 形成了无线局域网国家标准体系。标准体系中包含了全新的无线局域 网鉴别与保密基础结构 WAPI ( WLAN Authentication and Privacy Infrastructure )安全机制, 这种安全机制由无线局域网鉴别基础结构 WAI ( WLAN Authentication Infrastructure )和无线局 i或网保密基础结 构 WPI ( WLAN Privacy Infrastructure ) 两部分组成。
WAPI提供了基于证书的认证及密钥协商方法, 该方法可以提供 很高的安全性, 保证合法的用户接入合法的网络, 保护无线链路上的 数据安全。
当 WLAN在运营环境下应用时,认证和计费有非常密切的关系。 计费是在认证的基础上进行, 目前运营商们已经有各自成熟的认证计 费方式,但这些方式不一定可以和国家标准 GB 15629.11及其第 1号 修改单中定义的证书认证融合,如何匹配这些成熟的认证计费方式和 国家标准 GB 15629.11 及其第 1 号修改单中定义的证书认证, 是 WLAN运营的关键问题之一。
目前的认证机制 (如 Radius )仅实现网络对用户的单向认证, 在 认证的基础上实现计费等功能,该认证计费方式在链路比较安全的情 况下是有效的, 即在有线环境下比较适合。但无线局域网链路由于其 开放特征而非常不安全,这些认证计费方式直接应用在无线局域网中 会出现较大的安全问题。
发明内容
本发明提供一种符合国家标准并支持目前使用的多种认证、计费 方法的基于证书的 WAPI标准运营的方法,能够有效解决现有技术中 运营商用于无线局域网运营的认证和计费的方法和国家标准 GB 15629.11及其第 1号修改单中规定的认证方法不兼容的技术问题。
本发明的技术解决方案是:
一种基于 WAPI的 WLAN运营的方法, 包括:
鉴别服务器按照移动终端的分类, 为每一类移动终端颁发证书, 同类的移动终端釆用同一个证书,鉴别服务器为每个无线接入点颁发 证书, 移动终端和无线接入点安装鉴别服务器颁发的证书;
当移动终端需要访问网络时, 移动终端关联至无线接入点, 建立 链路连接; 无线接入点向移动终端发送鉴别激活帧, 启动认证过程; 移动终端和无线接入点根据国标 GB 15629.11及其第 1号修改单 规定, 通过鉴别服务器进行证书认证, 如果证书认证成功, 移动终端 和无线接入点进行会话密钥协商,无线接入点向移动终端通告组播密 钥;
无线接入点允许移动终端接入,根据不同的证书类型的鉴权信息 对终端用户进行接入控制;
以及接入控制器对移动终端的帐户信息进行认证;
服务器根据帐户信息认证的结果给出移动终端鉴权信息,移动终 端与网络进行信息数据的交换。
所述根据国标 GB 15629.11及其第 1号修改单规定, 移动终端和 无线接入点通过接入服务器进行证书认证的具体步骤包括:
无线接入点向移动终端发送鉴别激活;
移动终端向无线接入点发送接入鉴别请求,所述接入鉴别请求包 含移动终端的证书;
无线接入点向鉴别服务器发送证书鉴别请求,所述证书鉴别请求 包含移动终端和无线接入点的证书;
鉴别服务器对移动终端和无线接入点的证书进行验证,根据终端 证书类别和对应的接入控制策略确定相应的鉴权信息,鉴别服务器向 无线接入点返回证书鉴别响应,所述证书鉴别响应包含移动终端和无 线接入点证书的鉴别结果;
无线接入点根据鉴别服务器返回的移动终端证书鉴别结果确定 是否允许所述移动终端接入, 并向移动终端发送接入鉴别响应;
移动终端根据接入鉴别响应中鉴别服务器对无线接入点的证书 鉴别结果确定是否接入所述无线接入点, 若是则确定证书认证成功。
所述接入控制器对移动终端的帐户信息按如下步骤进行认证: 当 证书认证阶段完成, 用户浏览网络时, 系统自动弹出网页, 提示用户 输入用户名和密码, 服务器根据用户名和密码验证用户的身份, 并根 据认证结果控制网络的访问,如果认证成功,移动终端可以访问网络。
所述接入控制器对移动终端的帐户信息按如下步骤进行认证: 当 证书认证阶段完成, 移动终端利用用户识别模块 SIM ( Subscriber Identity Module )卡中的信息, 通过认证服务器与无线接入点进行身 份认证和会话密钥协商, 并根据认证结果控制网络的访问, 如果认证 成功, 移动终端可以访问网络。
本发明通过分离链路级认证和用户级身份鉴别两个相互独立的 过程, 使得无线局域网可作为原来运营网络的扩展, 并且使无线局域 网的运营管理和原来的运营网络相一致, 其中, 链路级认证用于保护 无线链路接入的安全, 用户级身份鉴别用于授权以及计费等管理服 务。
本发明在链路级认证过程釆用符合国家标准的安全接入技术,既 可实现用户和网络之间双向身份鉴别, 又可与原来的授权、计费等管 理 系 统兼容 , 其 完全符合 国 标 GB15629.11-2003 、 GB 15629.11-2003/XG1-2006及其他子项标准的规定, 符合国家标准。
本发明在链路级认证过程釆用符合国家标准的安全接入技术,利 用基于公钥密码体系的证书机制, 真正实现了移动终端 (MT ) 与无 线接入点 ( AP ) 间的双向认证, 完全满足运营商对安全接入的要求, 使得无线链路的安全性得到保证; 并且其等同于有线链路, 除了保护 无线链路的安全接入和数据通信外,还可以有效地保护后续的用户帐 户认证阶段的信息, 在用户帐户信息认证阶段, 网络对移动终端的用 户身份进行进一步验证, 控制移动终端是否可以访问网络, 并根据认 证的结果控制访问网络以及对用户访问网络进行计费,因此本发明安 全性高。
本发明可以继续使用目前已有的用户认证计费方式, 灵活性好, 无线接入点设置好证书后, 无需再对后台的 AAA服务器进行设置, 安装、 组网便捷, 可用于大规模的热点等地区的运营。 本发明还可以 根据用户应用业务等的不同, 对用户进行分类, 并颁发基于用户类型 的证书, 在保证安全的基础上支持更灵活的用户等级配置策略, 从而 支持更灵活的运营方式。
具体实施方式
本发明通过分离链路级认证和用户级身份鉴别两个相互独立的 过程, 使得无线局域网可作为原来运营网络的扩展, 并且使无线局域 网的运营管理和原来的运营网络相一致。 为使本发明的目的、技术方 案及优点更加清楚明白, 下面举实施例, 对本发明进一步详细说明。
本发明实施例提供一种釆用分类终端证书实现基于 WAPI 的 WLAN运营的方法, 包括: 链路级认证步骤和帐户信息认证步骤, 其中:
链路级认证步骤如下:
1 ) 鉴别服务器 AS(Authentication Server)按照移动终端 MT ( Mobile Terminal ) 的分类, 为每一类移动终端颁发证书, 同类的移 动终端釆用同一个证书, 鉴别服务器为每个无线接入点 AP(Access Point)颁发证书,移动终端和无线接入点安装接入服务器颁发的证书; 其中, AS是提供身份鉴别服务和证书管理功能的网络实体; MT是 安装有无线网络适配器的终端; AP为移动终端提供网络接入服务的 设备;
2 ) 当移动终端需要访问网络时, 首先由移动终端关联至无线接 入点, 建立链路连接;
3 )移动终端关联至无线接入点后, 无线接入点向移动终端发送 鉴别激活帧, 启动认证过程;
4 )根据国标 GB 15629.11及其第 1号修改单规定, 移动终端和 无线接入点通过鉴别服务器进行证书认证;
所述步骤 4 ) 中无线接入点向移动终端发送鉴别激活, 然后可以 按照如下步骤进行证书认证:
4.1 )移动终端向无线接入点发送接入鉴别请求, 其中, 所述接 入鉴别请求包含移动终端的证书;
4.2 )无线接入点向鉴别服务器发送证书鉴别请求, 其中, 所述 证书鉴别请求包含移动终端和无线接入点的证书;
4.3 )鉴别服务器对移动终端和无线接入点的证书进行验证, 并 根据终端证书类别和对应的接入控制策略确定相应的鉴权信息,再由 鉴别服务器向无线接入点返回证书鉴别响应, 其中, 所述证书鉴别响 应包含移动终端和无线接入点证书的鉴别结果;
4.4 )无线接入点根据鉴别服务器返回的移动终端证书鉴别结果 确定是否允许该移动终端接入, 并向移动终端发送接入鉴别响应;
4.5 )移动终端根据接入鉴别响应中鉴别服务器对无线接入点的 证书鉴别结果确定是否接入该无线接入点, 若是则进至步骤 5 ), 否 则结束。
5 )如果证书认证成功, 移动终端和无线接入点进行会话密钥协 商, 无线接入点向移动终端通告组播密钥;
6 )无线接入点允许移动终端接入, 并根据不同的证书类型的鉴 权信息对终端用户进行接入控制;
帐户信息认证步骤如下:
7 )接入控制器 AC(Access Control)对移动终端的帐户信息进行认 证, 其中, AC是对用户访问网络提供接入控制的网络设备;
8 )服务器根据帐户信息认证的结果给出移动终端鉴权信息, 移 动终端与网络进行信息数据的交换, 即移动终端可以访问网络。
在上述实施例中, 所述步骤 7 ) 中接入控制器对移动终端的帐户 信息可以按照如下步骤进行认证: 当证书认证阶段完成, 用户浏览网 络时, 系统自动弹出网页, 提示用户输入用户名和密码, 接入服务器 根据用户名和密码验证用户的身份, 并根据认证结果控制网络的访 问, 如果认证成功, 移动终端可以访问网络。
在上述实施例中, 所述步骤 7 ) 中接入控制器对移动终端的帐户 信息还可以按照如下步骤进行认证: 当证书认证阶段完成, 移动终端 利用 SIM卡中的信息, 通过认证服务器与无线接入点进行身份认证 和会话密钥协商, 并根据认证结果控制网络的访问, 如果认证成功, 移动终端可以访问网络。

Claims

权 利 要 求
1、 一种基于 WAPI的 WLAN运营的方法, 其特征在于, 包括: 鉴别服务器按照移动终端的分类, 为每一类移动终端颁发证书, 同类的移动终端釆用同一个证书,鉴别服务器为每个无线接入点颁发 证书, 移动终端和无线接入点安装鉴别服务器颁发的证书;
当移动终端需要访问网络时, 移动终端关联至无线接入点, 建立 链路连接; 无线接入点向移动终端发送鉴别激活帧, 启动认证过程; 移动终端和无线接入点根据国标 GB 15629.11及其第 1号修改单 规定, 通过鉴别服务器进行证书认证, 如果证书认证成功, 移动终端 和无线接入点进行会话密钥协商,无线接入点向移动终端通告组播密 钥;
无线接入点允许移动终端接入,根据不同的证书类型的鉴权信息 对终端用户进行接入控制;
以及接入控制器对移动终端的帐户信息进行认证;
服务器根据帐户信息认证的结果给出移动终端鉴权信息,移动终 端与网络进行信息数据的交换。
2、根据权利要求 1所述的基于 WAPI的 WLAN运营的方法, 其 特征在于: 所述根据国标 GB 15629.11及其第 1号修改单规定, 移动 终端和无线接入点通过接入服务器进行证书认证的具体步骤包括: 无线接入点向移动终端发送鉴别激活;
移动终端向无线接入点发送接入鉴别请求,所述接入鉴别请求包 含移动终端的证书;
无线接入点向鉴别服务器发送证书鉴别请求,所述证书鉴别请求 包含移动终端和无线接入点的证书;
鉴别服务器对移动终端和无线接入点的证书进行验证,根据终端 证书类别和对应的接入控制策略确定相应的鉴权信息,鉴别服务器向 无线接入点返回证书鉴别响应,所述证书鉴别响应包含移动终端和无 线接入点证书的鉴别结果;
无线接入点根据鉴别服务器返回的移动终端证书鉴别结果确定 是否允许所述移动终端接入, 并向移动终端发送接入鉴别响应; 移动终端根据接入鉴别响应中鉴别服务器对无线接入点的证书 鉴别结果确定是否接入所述无线接入点, 若是则确定证书认证成功。
3、根据权利要求 1或 2所述的基于 WAPI的 WLAN运营的方法, 其特征在于:所述接入控制器对移动终端的帐户信息按如下步骤进行 认证:
当证书认证阶段完成, 用户浏览网络时, 系统自动弹出网页, 提 示用户输入用户名和密码, 服务器根据用户名和密码验证用户的身 份, 并根据认证结果控制网络的访问, 如果认证成功, 移动终端可以 访问网络。
4、根据权利要求 1或 2所述的基于 WAPI的 WLAN运营的方法, 其特征在于:所述接入控制器对移动终端的帐户信息按如下步骤进行 认证:
当证书认证阶段完成, 移动终端利用 SIM卡中的信息, 通过认 证服务器与无线接入点进行身份认证和会话密钥协商,并根据认证结 果控制网络的访问, 如果认证成功, 移动终端可以访问网络。
PCT/CN2007/071372 2006-12-29 2007-12-28 Procédé d'exploitation de réseau local sans fil basé sur une infrastructure d'authentification et de confidentialité de réseau wlan (wapi) WO2008080353A1 (fr)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CNB2006101053783A CN100512111C (zh) 2006-12-29 2006-12-29 采用分类终端证书实现基于wapi的wlan运营的方法
CN200610105378.3 2006-12-29

Publications (1)

Publication Number Publication Date
WO2008080353A1 true WO2008080353A1 (fr) 2008-07-10

Family

ID=38251797

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2007/071372 WO2008080353A1 (fr) 2006-12-29 2007-12-28 Procédé d'exploitation de réseau local sans fil basé sur une infrastructure d'authentification et de confidentialité de réseau wlan (wapi)

Country Status (2)

Country Link
CN (1) CN100512111C (zh)
WO (1) WO2008080353A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103596177A (zh) * 2013-11-19 2014-02-19 上海众人网络安全技术有限公司 移动终端一键接入公共WiFi的接入方法

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN100512111C (zh) * 2006-12-29 2009-07-08 西安西电捷通无线网络通信有限公司 采用分类终端证书实现基于wapi的wlan运营的方法
CN101547444B (zh) * 2009-03-11 2010-11-03 西安西电捷通无线网络通信股份有限公司 在wlan中为不同终端提供特定接入流程的方法
JP5624219B2 (ja) 2010-10-13 2014-11-12 西安西▲電▼捷通▲無▼綫▲網▼絡通信股▲分▼有限公司Chinaiwncomm Co., Ltd. ネットワークアクセス制御方法およびシステム
CN113612731A (zh) * 2021-07-06 2021-11-05 湖南方心科技股份有限公司 宽带wapi多通道数据传输与随机数据加密通信设备

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1426200A (zh) * 2002-11-06 2003-06-25 西安西电捷通无线网络通信有限公司 无线局域网移动终端的安全接入与无线链路的数据保密通信方法
CN1602108A (zh) * 2004-11-04 2005-03-30 西安西电捷通无线网络通信有限公司 全局信任的无线ip系统移动终端的漫游接入方法
US20050138355A1 (en) * 2003-12-19 2005-06-23 Lidong Chen System, method and devices for authentication in a wireless local area network (WLAN)
CN1996842A (zh) * 2006-12-29 2007-07-11 西安西电捷通无线网络通信有限公司 采用分类终端证书实现基于wapi的wlan运营的方法

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1426200A (zh) * 2002-11-06 2003-06-25 西安西电捷通无线网络通信有限公司 无线局域网移动终端的安全接入与无线链路的数据保密通信方法
US20050138355A1 (en) * 2003-12-19 2005-06-23 Lidong Chen System, method and devices for authentication in a wireless local area network (WLAN)
CN1602108A (zh) * 2004-11-04 2005-03-30 西安西电捷通无线网络通信有限公司 全局信任的无线ip系统移动终端的漫游接入方法
CN1996842A (zh) * 2006-12-29 2007-07-11 西安西电捷通无线网络通信有限公司 采用分类终端证书实现基于wapi的wlan运营的方法

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103596177A (zh) * 2013-11-19 2014-02-19 上海众人网络安全技术有限公司 移动终端一键接入公共WiFi的接入方法

Also Published As

Publication number Publication date
CN1996842A (zh) 2007-07-11
CN100512111C (zh) 2009-07-08

Similar Documents

Publication Publication Date Title
JP7035163B2 (ja) ネットワークセキュリティ管理方法および装置
WO2008080351A1 (fr) Procédé d'exploitation de réseau local sans fil basé sur une infrastructure d'authentification et de confidentialité de wlan (wapi)
JP5313200B2 (ja) 通信システムにおけるキー発生方法及び装置
TWI558253B (zh) 進行用戶認證的計算機執行方法及使用用戶識別碼得到存取目標域處服務的方法
CN101150594B (zh) 一种移动蜂窝网络和无线局域网的统一接入方法及系统
KR101068424B1 (ko) 통신시스템을 위한 상호동작 기능
WO2011144174A1 (zh) 配置接入设备的方法、装置及系统
WO2009000206A1 (fr) Procédé et système de commande d'accès de nœud initial b
WO2009135445A1 (zh) 一种基于wapi的漫游认证方法
WO2012094841A1 (zh) 网络接入方法、装置及系统
WO2010102493A1 (zh) 在wlan中为不同终端提供特定接入流程的方法
WO2014176964A1 (zh) 一种通信管理方法及通信系统
JP5187393B2 (ja) 高レートパケットデータセッションの終了方法
WO2007131426A1 (en) Aaa system and authentication method of multi-hosts network
WO2010069202A1 (zh) 认证协商方法及系统、安全网关、家庭无线接入点
WO2008101426A1 (fr) Procédé d'identification d'itinérance en fonction du certificat wapi
WO2008080353A1 (fr) Procédé d'exploitation de réseau local sans fil basé sur une infrastructure d'authentification et de confidentialité de réseau wlan (wapi)
CN103685201A (zh) 一种wlan用户固网接入的方法和系统
WO2013170814A2 (zh) 一种内置PPPoE拨号功能的移动终端及其拨号方法
WO2010102496A1 (zh) 一种实现wapi系统终端零干预计费的方法
WO2008080352A1 (fr) Procédé de chargement de réseau local sans fil basé sur une infrastructure d'authentification et de confidentialité de wlan (wapi)
TW201316792A (zh) 區域網協存取網路元件與終端設備的認證方法與裝置
CN102271125B (zh) 跨设备进行802.1x认证的方法及接入设备、接入控制设备
WO2015100874A1 (zh) 家庭网关接入管理方法和系统
CN101272297B (zh) 一种WiMAX网络用户EAP认证方法

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 07846198

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 07846198

Country of ref document: EP

Kind code of ref document: A1