CN101227277A - Method and system for implementing safety of end to end based on WAP1.2 gateway - Google Patents

Method and system for implementing safety of end to end based on WAP1.2 gateway Download PDF

Info

Publication number
CN101227277A
CN101227277A CNA2007100009383A CN200710000938A CN101227277A CN 101227277 A CN101227277 A CN 101227277A CN A2007100009383 A CNA2007100009383 A CN A2007100009383A CN 200710000938 A CN200710000938 A CN 200710000938A CN 101227277 A CN101227277 A CN 101227277A
Authority
CN
China
Prior art keywords
gateway
application server
wap
mobile phone
phone terminal
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CNA2007100009383A
Other languages
Chinese (zh)
Other versions
CN101227277B (en
Inventor
李凤军
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
ZTE Corp
Original Assignee
ZTE Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by ZTE Corp filed Critical ZTE Corp
Priority to CN2007100009383A priority Critical patent/CN101227277B/en
Publication of CN101227277A publication Critical patent/CN101227277A/en
Application granted granted Critical
Publication of CN101227277B publication Critical patent/CN101227277B/en
Expired - Fee Related legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Landscapes

  • Mobile Radio Communication Systems (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

The invention relates to a system and a method for realizing the safety from end to end on the basis of a WAP1.2 network gateway, which comprises: sending a request address chaining to a master network gateway by a terminal, transferring the address chaining to an application server, judging if the address chaining is the address chaining which is provided with safety protection contents, producing redirection message to the master network gateway if the address chaining is provided with the safety protection contents, effectively analyzing the redirection message after the master network gateway receives the redirection message, sending navigation manuals in the redirection message to the terminal by the master network gateway if regulated strategies in the message are coincident with the strategies in the master network gateway, obtaining slave network gateway information by the terminal through analyzing the navigation manuals, building a secure link with the slave network gateway, sending the request address chaining to the slave network gateway by the terminal, building the secure link by the slave network gateway and a security application server, sending the address chaining to the security application server, and returning data contents which are protected safely to the slave network gateway by the security application server, wherein safe transmission between end and end can be realized through the slave network gateway. The invention solves the problem for realizing the safety from end to end on the basis of a WAP1.2 network gateway.

Description

A kind of based on the realization of WAP1.2 gateway safe end to end system and method thereof
Technical field
The present invention relates to the WAP gateway problem, relate in particular to a kind of based on the realization of WAP1.2 gateway safe end to end system and method thereof.
Background technology
The professional common cooperation by following several respects equipment of WAP realizes: WAP terminal, wireless-transmission network (GSM CSD/GPRS), WAP gateway equipment, WAP application server, Service Provisioning Administration Core Environment, fire compartment wall etc.
WAP gateway equipment can be divided into plurality of function modules: WAP Pull agency, WAP Push agency, WTA server, WAP back-level server, operation and maintenance platform (O﹠amp; M) etc.
WAP gateway is the key equipment that the Internet is combined with mobile phone terminal, just on the mobile network, use as far back as last century Mo, WAP gateway is acted on behalf of as surfing Internet with cell phone, and any online request of mobile phone at first sends to WAP gateway, is sent to the web station system of the Internet again by WAP gateway; The info web that the while web station system returns to mobile phone terminal also is at first to pass through WAP gateway, is sent to mobile phone terminal again.Since the disposal ability of mobile phone terminal a little less than, and the air bandwidth of wireless network is smaller, WAP gateway need convert web page contents to the revealable content of mobile phone terminal, for example: picture diminishes, the complexity reduction of picture etc., thereby and content is compressed transmission reduce air bandwidth and take.As seen WAP gateway plays functions such as format conversion, content compression aspect surfing Internet with cell phone.
Widespread usage along with the WAP browse service, particularly be applied to the higher field of some safety requirements, for example: industries such as bank, public security, because the WAP gateway of WAP1.2 version need carry out format conversion and compression with content, cause WAP gateway can not realize End-to-End Security, so-called End-to-End Security is meant between the website on mobile phone terminal and the Internet can not realize safe the connection, because the insecurity of WAP gateway equipment has been destroyed the formation of End-to-End Security.
Specifically, during Data transmission, must carry out the format conversion and the compression of data between the web station system of WAP gateway on mobile phone and the Internet, cause fail safe end to end to be difficult to reach.Particularly use at existing network, what the user at first inserted is the WAP gateway of operator's construction and maintenance, and the industry user very strong to end-to-end demand for security, for example: bank, public security etc. can not trust fully to the WAP gateway that operator safeguards, and operator also dare not promise to undertake Secure Application end to end to this type of industry user on the WAP1.2 gateway.In addition, there are some also to propose between mobile phone terminal and WAP gateway, to adopt wireless transport layer security (Wireless Transport LayerSecurity, WTLS) mode is encrypted, between gateway and web station system, adopt SSL (SecureSockets Layer) to encrypt, WAP gateway carries out WTSL to the conversion between the SSL, and obviously this method does not still solve the problem that WAP gateway is brought by operator's management maintenance.Because WTLS is the security module of WAP, it provides encryption, discriminating and data integrity sex service for WAP uses, and provides the safe transmission service interface as a level of wap protocol stack to the upper strata.WTLS is that base growth comes with the TLS standard, and carried out necessary transformation at characteristics such as the connected mode in the wireless network environment, computing capability, bandwidth constraints, and have support datagram service, support the grouping size of optimizing and shake hands, characteristics such as dynamic key renewal.According to the WTLS standard, and adopt procotol realize in some mechanism commonly used, as queuing model etc., the incident of the WTLS of WAP gateway side is handled according to the event and state translation table that defines in the standard.For the safe handling that relates in handling,, when realizing, adopt relevant open DLL (dynamic link library) as the authentication scheme of cipher key change, encrypting and decrypting, integrity checking and certificate etc.WTLS is the preliminary trial that WAP provides safe end-to-end connection.The algorithm of supporting is combined by suitable method, can guarantee certain fail safe, thereby solve safety problem in most cases.But it is impossible that the safety function that only relying on WTLS is simultaneously provided will reach absolute safety.
Summary of the invention
Technical problem to be solved by this invention is to provide a kind of and realizes the system and the method thereof of safety end to end based on the WAP1.2 gateway, realizes the problem of safety end to end to solve based on the WAP1.2 gateway.
In order to address the above problem, the invention provides a kind of based on the safe end to end method of WAP1.2 gateway realization, make data content pass through WAP mobile phone terminal, primary gateway, from the application of gateway, application server and security application server, realize the safety between end and the end, it is characterized in that, may further comprise the steps:
(1) request of sending of described WAP mobile phone terminal needs the address of secure data transmission to link to described primary gateway, and described primary gateway sends this address link to described application server;
(2) described application server judges whether it is the address link with safeguard protection content to this address link, gives described primary gateway if having then produce HTTP redirection message, a wherein subsidiary navigation document;
(3) after described primary gateway is received this HTTP redirection message, it is carried out efficiency analysis, tactful consistent with described primary gateway whether with the strategy determining to stipulate in this message is unanimity if export the result, and the then described primary gateway document that will effectively navigate is dealt on the described WAP mobile phone terminal;
(4) described WAP mobile phone terminal is by analyzing effective navigation document, obtain being associated with security application server from gateway information, and set up and from the safety chain of gateway;
(5) described WAP mobile phone terminal needs the address link of secure data transmission to the request that sends from gateway, simultaneously describedly set up secure link from gateway and security application server, the described address chain that needs secure data to transmit this request from gateway switches through issues described security application server, and described security application server returns by the data content of safeguard protection from gateway to described;
(6) after this WAP mobile phone terminal and security application server directly transmit by the data content of safety between realizing from gateway.
Method of the present invention, wherein, generation HTTP redirection message in the described step (2) is given described primary gateway, a wherein subsidiary navigation document, comprise: producing with conditional code is that 300 HTTP redirection message is given described primary gateway, wherein the navigation document of a subsidiary extend markup language (XML) form.
Method of the present invention, wherein, the described navigation document in the step (2) comprises: from the IP address of gateway and the address link information of safeguard protection content.
Method of the present invention, wherein, described HTTP redirection message in the step (3) is carried out efficiency analysis, comprising: analyze the navigation document content format, analyze redirect message the source, check described whether whether correct and described WAP mobile phone terminal has access rights from gateway information;
Described effective navigation document in the step (3), comprising: the application server that described primary gateway need dispose has the ability that is redirected to from gateway, and described be that primary gateway is defined from gateway.
Method of the present invention, wherein, described step comprises in (4): described WAP mobile phone terminal is by analyzing effective navigation document, the IP address that obtains being associated from gateway with security application server, and set up and from the safety chain of the wireless transport layer security of gateway.
Method of the present invention, wherein, described WAP mobile phone terminal, for support the WAP1.2 version, have secondary WAP agent functionality, and can carry out the WAP mobile phone terminal that simple XML format file is analyzed;
Described primary gateway is for supporting the WAP gateway WAP1.2 version, that safeguarded by operator;
Described from gateway, for supporting the WAP gateway WAP1.2 version, that safeguard by the industry user.
Method of the present invention wherein, in the described step (2), further comprises: if not then described application server does not need to carry out the End-to-End Security protection, the requirement of safeguard protection is by its content request;
In the described step (3), further comprise: if export inconsistently, then described primary gateway abandons this redirect message, does not carry out safeguard protection end to end, for the WAP mobile phone terminal, is that the browsing pages of failure shows.
In order to address the above problem, the present invention also provides a kind of and has realized the system of safety end to end based on the WAP1.2 gateway, it is characterized in that, comprising: WAP mobile phone terminal, primary gateway, from gateway, application server and security application server; Wherein,
Described WAP mobile phone terminal, the address that being used to the request of sending needs secure data to transmit links to described primary gateway; And analyze by the effective navigation document that described primary gateway is sent, obtain being associated with security application server from gateway information, set up and described safety chain from gateway; And to the described address link that needs secure data to transmit from gateway transmission request;
Described primary gateway is used for sending the link of described address to described application server; And the HTTP redirection message from described application server carried out efficiency analysis, tactful consistent with described primary gateway whether with the strategy determining to stipulate in this message, if the output result is consistent, the document that will effectively navigate is dealt on the described WAP mobile phone terminal;
Described from gateway, be used to receive and send the address link that request needs secure data to transmit from the WAP mobile phone terminal, simultaneously set up secure link, need the address chain of secure data transmission to switch through this request and issue described security application server with security application server; And data content of safety transmitted between described WAP mobile phone terminal and security application server were directly realized by it;
Described application server is used for this address link is judged whether it is the address link with safeguard protection content, gives described primary gateway if having then produce HTTP redirection message, a wherein subsidiary navigation document;
Described security application server is used for and set up secure link from gateway, receives the address link that needs secure data to transmit from described request from gateway; And return by the data content of safeguard protection from gateway to described.
System of the present invention, wherein, produce HTTP redirection message in the described application server and give described primary gateway, a wherein subsidiary navigation document, comprise: producing with conditional code is that 300 HTTP redirection message is given described primary gateway, wherein the navigation document of a subsidiary extend markup language (XML) form.
System of the present invention, wherein, described navigation document comprises: from the IP address of gateway and the address link information of safeguard protection content.
System of the present invention, wherein, described primary gateway is carried out efficiency analysis to the HTTP redirection message from described application server, comprising: analyze the navigation document content format, analyze redirect message the source, check described whether whether correct and described WAP mobile phone terminal has access rights from gateway information;
Described effective navigation document, comprising: the application server that described primary gateway need dispose has the ability that is redirected to from gateway, and described be that primary gateway is defined from gateway.
System of the present invention, wherein, passing through in the described WAP mobile phone terminal analyzed the effective navigation document that described primary gateway is sent, obtain being associated with security application server from gateway information, set up and described safety chain from gateway, comprise: analyze by the effective navigation document that described primary gateway is sent, the IP address that obtains being associated from gateway with security application server, and set up and from the safety chain of the wireless transport layer security of gateway.
System of the present invention, wherein, described WAP mobile phone terminal further comprises: be used to support the WAP1.2 version, have secondary WAP agent functionality, and can carry out the analysis of simple XML format file;
Described primary gateway further comprises: be used to support the WAP gateway WAP1.2 version, that safeguarded by operator;
Described from gateway, further comprise: be used to support the WAP gateway WAP1.2 version, that safeguard by the industry user.
System of the present invention, wherein, described application server further comprises: if not then do not need to carry out the End-to-End Security protection, the requirement of safeguard protection is by its content request;
Described primary gateway further comprises: if export inconsistently, then abandoning this redirect message, do not carry out safeguard protection end to end, for the WAP mobile phone terminal, is that the browsing pages of failure shows.
Therefore, of the present inventionly realize the system and the method thereof of safety end to end, solved WAP gateway, guaranteed to realize safety end to end based on the WAP1.2 gateway by the problem that operator's management maintenance is brought based on the WAP1.2 gateway.
Description of drawings
Fig. 1 is the described concrete structure figure that realizes safe end to end system based on the WAP1.2 gateway of the embodiment of the invention;
Fig. 2 is the described particular flow sheet of realizing safe end to end method based on the WAP1.2 gateway of the embodiment of the invention.
Embodiment
The present invention is in order to solve the drawback that conventional solution exists, further set forth of the present invention a kind of based on the realization of WAP1.2 gateway safe end to end system and method thereof by following specific embodiment, below embodiment is described in detail, but not as a limitation of the invention.
The described system of the embodiment of the invention, as shown in Figure 1, the WAP mobile phone terminal possesses a plurality of proxy server functions of support, there is the branch of primary and secondary in these acting servers, this WAP mobile phone terminal support the WAP1.2 version, have secondary WAP agent functionality, and can carry out the analysis of simple XML format file;
Mobile phone links to each other with master proxy server usually, also can link to each other with inferior acting server under the situation of needs, and WAP gateway is exactly the acting server of mobile phone terminal;
Wherein, main WAP gateway is for supporting the WAP gateway WAP1.2 version, that safeguarded by operator; Main WAP gateway is meant the WAP gateway that user's general case is used, and does not have security feature, but has configuration and manage other functions from WAP gateway.
From WAP gateway, for supporting the WAP gateway WAP1.2 version, that safeguard by the industry user; From WAP gateway is a WAP gateway with security feature in the present embodiment, and management maintenance is safeguarded by the Safety Industry personnel.
Whether application server is meant not possess security requirement or the not high application server of security requirement, is common website application system, can be secure link according to the hyperlink request of certain rule judgment WAP mobile phone terminal.
Security application server is meant the application server very high to safety requirements, and wherein the application of Bu Shuing belongs to the web station system of high Secure Application, for example: the account number cipher information of banking, the secret document of public security industry etc.
System of the present invention, wherein, the WAP mobile phone terminal, the address that being used to the request of sending needs secure data to transmit links to main WAP gateway; And analyze by the effective navigation document that described main WAP gateway is sent, obtain being associated with security application server from WAP gateway information, set up safety chain with described wireless transport layer security (WTLS) from WAP gateway; And to the described address link that needs secure data to transmit from WAP gateway transmission request;
Main WAP gateway is used for sending the link of described address to described application server; And to carry out from the HTTP redirection message of described application server efficiency analysis (comprising: analyze the navigation document content format, analyze redirect message the source, check described whether whether correct and described WAP mobile phone terminal has access rights etc. from gateway information), tactful consistent with described primary gateway whether with the strategy determining to stipulate in this message, if the output result is consistent, the document that will effectively navigate is dealt on the described WAP mobile phone terminal; If export inconsistently, then abandon this redirect message, do not carry out safeguard protection end to end;
From WAP gateway, be used to receive and send the address link that request needs secure data to transmit from the WAP mobile phone terminal, simultaneously set up secure link, need the address chain of secure data transmission to switch through this request and issue described security application server with security application server; And data content of safety transmitted between described WAP mobile phone terminal and security application server were directly realized by it;
Described application server, be used for the address link is judged whether it is the address link with safeguard protection content, if having then producing with conditional code is that 300 HTTP redirection message is given described main WAP gateway, wherein the navigation document (comprising: from the IP address of gateway and the address link information of safeguard protection content etc.) of a subsidiary XML form; If not then do not need to carry out the End-to-End Security protection;
Described security application server is used for and set up secure link from WAP gateway, receives the address link that needs secure data to transmit from described request from WAP gateway; And return by the data content of safeguard protection from WAP gateway to described.
The embodiment of the invention is described to realize the method flow of safety end to end based on the WAP1.2 gateway, and as shown in Figure 2, the respective embodiments process description is as follows:
Step 201, WAP mobile phone terminal are clicked one of them content address link URL with safeguard protection (Uniform Resource Locator, URL(uniform resource locator)) by main WAP gateway browsed web content;
Step 202, main WAP gateway send to application server after converting this linking request to the HTTP redirection document;
Step 203, application server is judged this address link, find whether to have the content address link of safeguard protection, if have, then application server generates the navigation document of an XML form, wherein comprise IP address from WAP gateway, and the address information of secure link etc., and HTTP condition of information sign indicating number is 300;
Step 204, whether main WAP gateway is analyzed the HTTP redirection document of receiving, check from WAP gateway correctly, and whether the WAP mobile phone terminal has access rights etc., after checking correctly, main WAP gateway is transmitted to the WAP mobile phone terminal with the navigation document in the HTTP redirection document; If incorrect, then to return and browse failure page to the WAP mobile phone terminal, prompting user link does not exist;
Step 205, the WAP mobile phone terminal is analyzed the navigation document of receiving, determine need with set up safety chain from WAP gateway after, the WAP mobile phone terminal with set up the WTLS safety chain from WAP gateway, guarantee the fail safe of airlink;
Step 206, WAP mobile phone terminal continue to the content that sends the link of request secure address from WAP gateway;
Step 207 is set up the SSL safety chain from WAP gateway and security application server, and will ask the content of secure address link to be transmitted to security application server;
Step 208, security application server returns by the safeguard protection data content to the WAP mobile phone terminal, is at first sent to from WAP gateway by security application server, adopts SSL safety chain mode, again from send to the WAP mobile phone terminal from WAP gateway;
After step 209, WAP mobile phone terminal were finished the safeguard protection data and obtained, the cellphone subscriber clicked the address link of a non-safeguard protection, and the WAP mobile phone terminal sends to solicited message from WAP gateway;
Step 210 is transmitted to security application server from WAP gateway with request message, and security application server is analyzed this address link, generate the corresponding navigation document that is redirected, document format is the XML form, wherein comprises main WAP gateway address information, and the link of the address after being redirected;
Step 211, the security application server document that will navigate sends to from WAP gateway, and wherein the http response conditional code of document is 300;
Step 212 is analyzed the navigation document of receiving from WAP gateway, confirms whether main WAP gateway address information correct, finish affirmation after, the navigation document that will receive from WAP gateway is transmitted to the WAP mobile phone terminal; If incorrect,, and this navigation document is transmitted to the WAP mobile phone terminal then by generating default navigation document from gateway to primary gateway;
After step 213, WAP mobile phone terminal receive this navigation document, this navigation document is analyzed, and connected with main WAP gateway, the WAP mobile phone terminal is got back to the residing state of step 201.
Certainly; the present invention also can have other various embodiments; under the situation that does not deviate from spirit of the present invention and essence thereof; those of ordinary skill in the art can make various corresponding changes and distortion according to the present invention, but these corresponding changes and distortion all should belong to the protection range of the appended claim of the present invention.

Claims (14)

1. realize the method for safety end to end based on the WAP1.2 gateway for one kind, make data content pass through WAP mobile phone terminal, primary gateway, from the application of gateway, application server and security application server, realize the safety between end and the end, it is characterized in that, may further comprise the steps:
(1) request of sending of described WAP mobile phone terminal needs the address of secure data transmission to link to described primary gateway, and described primary gateway sends this address link to described application server;
(2) described application server judges whether it is the address link with safeguard protection content to this address link, gives described primary gateway if having then produce HTTP redirection message, a wherein subsidiary navigation document;
(3) after described primary gateway is received this HTTP redirection message, it is carried out efficiency analysis, tactful consistent with described primary gateway whether with the strategy determining to stipulate in this message is unanimity if export the result, and the then described primary gateway document that will effectively navigate is dealt on the described WAP mobile phone terminal;
(4) described WAP mobile phone terminal is by analyzing effective navigation document, obtain being associated with security application server from gateway information, and set up and from the safety chain of gateway;
(5) described WAP mobile phone terminal needs the address link of secure data transmission to the request that sends from gateway, simultaneously describedly set up secure link from gateway and security application server, the described address chain that needs secure data to transmit this request from gateway switches through issues described security application server, and described security application server returns by the data content of safeguard protection from gateway to described;
(6) after this WAP mobile phone terminal and security application server directly transmit by the data content of safety between realizing from gateway.
2. the method for claim 1, it is characterized in that, generation HTTP redirection message in the described step (2) is given described primary gateway, a wherein subsidiary navigation document, comprise: producing with conditional code is that 300 HTTP redirection message is given described primary gateway, wherein the navigation document of a subsidiary XML form.
3. the method for claim 1 is characterized in that, the described navigation document in the step (2) comprises: from the IP address of gateway and the address link information of safeguard protection content.
4. the method for claim 1, it is characterized in that, described HTTP redirection message in the step (3) is carried out efficiency analysis, comprising: analyze the navigation document content format, analyze redirect message the source, check described whether whether correct and described WAP mobile phone terminal has access rights from gateway information;
Described effective navigation document in the step (3), comprising: the application server that described primary gateway need dispose has the ability that is redirected to from gateway, and described be that primary gateway is defined from gateway.
5. the method for claim 1, it is characterized in that, described step comprises in (4): described WAP mobile phone terminal is by analyzing effective navigation document, the IP address that obtains being associated from gateway with security application server, and set up and from the safety chain of the wireless transport layer security of gateway.
6. the method for claim 1 is characterized in that, described WAP mobile phone terminal, for support the WAP1.2 version, have secondary WAP agent functionality, and can carry out the WAP mobile phone terminal that simple XML format file is analyzed;
Described primary gateway is for supporting the WAP gateway WAP1.2 version, that safeguarded by operator;
Described from gateway, for supporting the WAP gateway WAP1.2 version, that safeguard by the industry user.
7. the method for claim 1 is characterized in that, in the described step (2), further comprises: if not then described application server does not need to carry out the End-to-End Security protection;
In the described step (3), further comprise: if export inconsistently, then described primary gateway abandons this redirect message, does not carry out safeguard protection end to end.
8. realize the system of safety end to end based on the WAP1.2 gateway for one kind, it is characterized in that, comprising: WAP mobile phone terminal, primary gateway, from gateway, application server and security application server; Wherein,
Described WAP mobile phone terminal, the address that being used to the request of sending needs secure data to transmit links to described primary gateway; And analyze by the effective navigation document that described primary gateway is sent, obtain being associated with security application server from gateway information, set up and described safety chain from gateway; And to the described address link that needs secure data to transmit from gateway transmission request;
Described primary gateway is used for sending the link of described address to described application server; And the HTTP redirection message from described application server carried out efficiency analysis, tactful consistent with described primary gateway whether with the strategy determining to stipulate in this message, if the output result is consistent, the document that will effectively navigate is dealt on the described WAP mobile phone terminal;
Described from gateway, be used to receive and send the address link that request needs secure data to transmit from the WAP mobile phone terminal, simultaneously set up secure link, need the address chain of secure data transmission to switch through this request and issue described security application server with security application server; And data content of safety transmitted between described WAP mobile phone terminal and security application server were directly realized by it;
Described application server is used for the address link is judged whether it is the address link with safeguard protection content, gives described primary gateway if having then produce HTTP redirection message, a wherein subsidiary navigation document;
Described security application server is used for and set up secure link from gateway, receives the address link that needs secure data to transmit from described request from gateway; And return by the data content of safeguard protection from gateway to described.
9. system as claimed in claim 8, it is characterized in that, produce HTTP redirection message in the described application server and give described primary gateway, a wherein subsidiary navigation document, comprise: producing with conditional code is that 300 HTTP redirection message is given described primary gateway, wherein the navigation document of a subsidiary XML form.
10. system as claimed in claim 8 is characterized in that, described navigation document comprises: from the IP address of gateway and the address link information of safeguard protection content.
11. system as claimed in claim 8, it is characterized in that, described primary gateway is carried out efficiency analysis to the HTTP redirection message from described application server, comprising: analyze the navigation document content format, analyze redirect message the source, check described whether whether correct and described WAP mobile phone terminal has access rights from gateway information;
Described effective navigation document, comprising: the application server that described primary gateway need dispose has the ability that is redirected to from gateway, and described be that primary gateway is defined from gateway.
12. system as claimed in claim 8, it is characterized in that, passing through in the described WAP mobile phone terminal analyzed the effective navigation document that described primary gateway is sent, obtain being associated with security application server from gateway information, set up and described safety chain from gateway, comprise: analyze by the effective navigation document that described primary gateway is sent, the IP address that obtains being associated from gateway with security application server, and set up and from the safety chain of the wireless transport layer security of gateway.
13. system as claimed in claim 8 is characterized in that, described WAP mobile phone terminal further comprises: be used to support the WAP1.2 version, have secondary WAP agent functionality, and can carry out the analysis of simple XML format file;
Described primary gateway further comprises: be used to support the WAP gateway WAP1.2 version, that safeguarded by operator;
Described from gateway, further comprise: be used to support the WAP gateway WAP1.2 version, that safeguard by the industry user.
14. system as claimed in claim 8 is characterized in that, described application server further comprises: if not then do not need to carry out the End-to-End Security protection;
Described primary gateway further comprises: if export inconsistently, then abandon this redirect message, do not carry out safeguard protection end to end.
CN2007100009383A 2007-01-15 2007-01-15 Method and system for implementing safety of end to end based on WAP1.2 gateway Expired - Fee Related CN101227277B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN2007100009383A CN101227277B (en) 2007-01-15 2007-01-15 Method and system for implementing safety of end to end based on WAP1.2 gateway

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN2007100009383A CN101227277B (en) 2007-01-15 2007-01-15 Method and system for implementing safety of end to end based on WAP1.2 gateway

Publications (2)

Publication Number Publication Date
CN101227277A true CN101227277A (en) 2008-07-23
CN101227277B CN101227277B (en) 2010-09-29

Family

ID=39859050

Family Applications (1)

Application Number Title Priority Date Filing Date
CN2007100009383A Expired - Fee Related CN101227277B (en) 2007-01-15 2007-01-15 Method and system for implementing safety of end to end based on WAP1.2 gateway

Country Status (1)

Country Link
CN (1) CN101227277B (en)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102752267A (en) * 2011-04-20 2012-10-24 阿里巴巴集团控股有限公司 Method and device for providing website information
CN103368983A (en) * 2012-03-27 2013-10-23 中兴通讯股份有限公司 Security demand query method, security demand feedback method and security demand query device
WO2016150169A1 (en) * 2015-03-25 2016-09-29 中兴通讯股份有限公司 Secure communication method, gateway, network side server and system
CN113630333A (en) * 2020-05-08 2021-11-09 中国移动通信集团终端有限公司 Distributed networking system and method based on multi-gateway access

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1567957A (en) * 2003-06-26 2005-01-19 江苏省气象台 Professional weather service system for handset WPA network station

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102752267A (en) * 2011-04-20 2012-10-24 阿里巴巴集团控股有限公司 Method and device for providing website information
CN102752267B (en) * 2011-04-20 2016-08-03 阿里巴巴集团控股有限公司 Website information provides method and device
CN103368983A (en) * 2012-03-27 2013-10-23 中兴通讯股份有限公司 Security demand query method, security demand feedback method and security demand query device
WO2016150169A1 (en) * 2015-03-25 2016-09-29 中兴通讯股份有限公司 Secure communication method, gateway, network side server and system
CN113630333A (en) * 2020-05-08 2021-11-09 中国移动通信集团终端有限公司 Distributed networking system and method based on multi-gateway access

Also Published As

Publication number Publication date
CN101227277B (en) 2010-09-29

Similar Documents

Publication Publication Date Title
CN100410927C (en) Certificate management and transfer system and method
CN103220292B (en) Cross-safe-area data transmission and system
CN103188207B (en) A kind of cross-domain single sign-on realization method and system
CN103535004B (en) Method for promoting anonymity audio and video communication and system based on web
CN106941491B (en) Safety application data link layer equipment of electricity utilization information acquisition system and communication method
CN1197297C (en) A platform information switch
CN101304310B (en) Method for reinforcing network SSL service
CN105530254A (en) Data communication method between internal and external networks
CN103108037B (en) A kind of communication means, Web server and Web communication system
CN101227470B (en) System and method of business management
CN106992908A (en) A kind of intelligent household management system and its management method
CN102938770A (en) Method for realizing uniform interface for multi-protocol messages and related device and system
CN102724322A (en) Remote control method and device
CN101227277B (en) Method and system for implementing safety of end to end based on WAP1.2 gateway
CN102025727B (en) Integrated pushing system and method for collecting and accessing multiple application systems
CN104022857A (en) Server engine frame design method based on multiple working modes
CN101202965B (en) Method for transmitting safe point-to-point short message facing to connectionless
CN104994107B (en) A kind of MMS message off-line analysis methods based on IEC62351
CN109831404A (en) A kind of instant communicating system and method for compatible multiple terminals
CN102857482A (en) Method and system for transmitting data on basis of multiple servers
CN101783806A (en) Portal certificate authentication method and device
CN101695169B (en) Remote-end maintaining method of operation support system data as well as system and remote-end account opening proxy
CN111581673B (en) SAP electronic signature method and system
CN103595722B (en) Data postback method and device in network safety
CN113766007A (en) Authentication front-end system and authentication method based on multi-source heterogeneous data analysis protocol

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant
CF01 Termination of patent right due to non-payment of annual fee
CF01 Termination of patent right due to non-payment of annual fee

Granted publication date: 20100929

Termination date: 20170115