WO2014194606A1 - 接入网络的认证方法、装置与终端设备 - Google Patents

接入网络的认证方法、装置与终端设备 Download PDF

Info

Publication number
WO2014194606A1
WO2014194606A1 PCT/CN2013/086984 CN2013086984W WO2014194606A1 WO 2014194606 A1 WO2014194606 A1 WO 2014194606A1 CN 2013086984 W CN2013086984 W CN 2013086984W WO 2014194606 A1 WO2014194606 A1 WO 2014194606A1
Authority
WO
WIPO (PCT)
Prior art keywords
authentication
information
authentication information
module
server
Prior art date
Application number
PCT/CN2013/086984
Other languages
English (en)
French (fr)
Inventor
周新建
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Publication of WO2014194606A1 publication Critical patent/WO2014194606A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W84/00Network topologies
    • H04W84/02Hierarchically pre-organised networks, e.g. paging networks, cellular networks, WLAN [Wireless Local Area Network] or WLL [Wireless Local Loop]
    • H04W84/10Small scale networks; Flat hierarchical networks
    • H04W84/12WLAN [Wireless Local Area Networks]

Definitions

  • the present invention relates to the field of communications technologies, and more specifically, to an authentication method, device, and terminal device for accessing a network. Background technique
  • WIFI modules are built into almost all notebooks. Operators hope that when there is a WIFI hotspot, users can switch to the WIFI networking mode at any time to improve the user's Internet speed.
  • the PC-side software of the drive-free since the SIM-Reader driver is not installed on the PC side, the PC-side software cannot complete the EAP-SIM authentication of the WIFI, and the EAP-SIM encrypted AP cannot be connected.
  • the embodiment of the invention discloses an authentication method, a device and a terminal device for accessing a network, which are used to solve the problem that the WIFI device cannot pass the EAP-SIM authentication in the free drive mode in the prior art.
  • An authentication method for accessing a network which is used for a terminal device with PC side software; comprising: obtaining, by the AT server of the terminal, information exchange with the network card side to obtain first authentication information; and the first authentication information and the WIFI device information
  • the second authentication information is generated by encrypting together;
  • the third authentication information is obtained by performing information interaction with the target AP according to the second authentication information; and the third authentication information is parsed and the analysis result is compared with the local authentication information to obtain the authentication result.
  • the method further includes:
  • the information about the first authentication information obtained by the AT server of the terminal and the network card side to obtain the first authentication information includes:
  • the AT command is configured to be sent to the AT server according to the preset protocol; the AT command is parsed by the AT server to obtain the AT command, and the AT command is sent to the network card side;
  • the encrypting the first authentication information together with the WIFI device information to generate the second authentication information includes:
  • the address information is encrypted together to generate the second authentication information.
  • the obtaining, by the information exchange with the target AP according to the second authentication information, the third authentication information includes:
  • the terminal device with the PC side software includes: a first acquiring module configured to obtain first authentication information by performing information interaction between the AT server of the terminal and the network card side;
  • a first generating module configured to encrypt the first authentication information together with the WIFI device information to generate second authentication information
  • a second acquiring module configured to perform third-party authentication information by performing information interaction with the target AP according to the second authentication information
  • the third obtaining module is configured to parse the third authentication information and compare the parsing result with the local authentication information to obtain the authentication result.
  • the fourth obtaining module is configured to acquire information of the target AP as the local information.
  • the first acquiring module includes:
  • the component module is configured to compose the received AT command according to a preset protocol and send the message to the AT server;
  • a first parsing module configured to parse the packet by the AT server to obtain the AT command, and send the AT command to the network card side;
  • the receiving module is configured to receive, by the AT server, the first authentication information that is generated by the network card side and is generated according to the AT command.
  • the block comprises:
  • the second parsing module is configured to parse the second authentication information by using the target AP, and obtain an analysis result;
  • the second generation module is configured to perform information interaction with the target AP according to the parsing result to generate the third authentication information.
  • a terminal device comprising the authentication device according to any one of claims 6 to 9.
  • the terminal device has PC side software.
  • the technical solution of the embodiment of the present invention is used to transmit the related AT information required for EAP-SIM authentication through the AT server, to assist in completing the authentication process of the WIFI module and the AP, to implement WIFI access, and to implement the WIFI device in the PC-side software in a drive-free manner.
  • EAP-SIM authentication between the AP and the AP is solved.
  • FIG. 1 is a flowchart of an authentication method of an access network according to an embodiment of the present invention
  • FIG. 2 is a system architecture diagram of an authentication method for an access network according to an embodiment of the invention
  • FIG. 3 is a PC side software interaction diagram of an authentication method for an access network according to an embodiment of the invention
  • Wireless network card control module interaction diagram of network authentication method
  • FIG. 5 is a flowchart of the authentication between the WIFI module and the AP according to the embodiment of the present invention
  • FIG. 6 is a schematic structural diagram of the authentication device of the access network according to the embodiment of the invention. detailed description
  • FIG. 1 is a flowchart of an authentication method of an access network according to an embodiment of the invention.
  • the authentication method for accessing the network includes:
  • S101 The first authentication letter is obtained by performing information exchange between the AT server of the terminal and the network card side.
  • S103 Encrypt the first authentication information together with the WIFI device information to generate a second authentication signal S105, and perform information interaction with the target AP according to the second authentication information to obtain third authentication information.
  • S107 Parse the third authentication information and compare the parsing result with the local authentication information to obtain an authentication result.
  • S101 to S107 in FIG. 1 are respectively executed by the following modules: PC side software 201, which is responsible for loading and unloading the wireless network card control module, and initiates networking, scanning, and network disconnection operations. .
  • the PC side software 201 is also responsible for the synchronous action in the EAP authentication process. If the wireless network card control module needs to read real-time information from the board side, the PC side software 201 needs to be internally synchronized to ensure wireless.
  • the network card control module can obtain the necessary authentication information in time when performing authentication; the wireless network card control module 203 (such as the WIFI control module) invokes a system function to operate the WIFI device on the PC to implement specific networking, network disconnection, WEP authentication, WPA/WPA2 certification and more.
  • the wireless network card control module encapsulates the wpa-supplicant process, which is used for authentication and authentication.
  • the wireless network card control module initiates the action of reading the AT information to the PC side software.
  • the WIFI device 205 is a WIFI device on the PC;
  • the AT server 207 is configured to receive protocol packets from the PC side software, parse and access a modem (Modem) device, and implement a user interface (User Interface, UI) ) and the function of the bridge between the board side; Modem209, to achieve specific SMS, dial-up Internet, PIN code and so on.
  • Modem Modem
  • UI User Interface
  • the function of the PC side software 201 is as shown in FIG. 3, and the software needs to have a thread specifically for authentication.
  • the calling request of the wireless network card control module 203 is suspended. Then, the request is sent to the AT server. After the AT server reads the result from the board side, the result is sent to the WIFI module, and the WIFI module continues to perform authentication.
  • the wireless network card control module consists of two parts: wpa-supplicant and system interface control module. wpa-supplicant is used to read IMSI, AKA, SIM, and authentication mode from the PC side. It will initiate EAP- The process of Request, EAP-Identify, etc.
  • the system interface control module first registers the callback interface with the PC software side, and at the same time calls the function encapsulated by the operating system to send the WIFI device to the network, disconnect the network, scan and obtain the scan result.
  • the wap_supplicant authentication requires the MAC address and the operation of calculating the key (Key), it cooperates with the wpa-supplicant to complete the response.
  • communication between the PC side software and the wireless terminal device is implemented by a message, and the specific communication carrier is AT.
  • the specific communication carrier is AT.
  • information of the target AP is obtained as local information.
  • the wireless terminal is powered on, the built-in AT server is started, and then the software on the Modem side is called.
  • the AT command is packaged into a protocol format (such as the http protocol or a user-defined protocol) and sent to the AT.
  • the AT server obtains the AT command and sends it to the network card side; the network card side returns the first authentication information to the AT server.
  • the first authentication information is encrypted together with the MAC address information of the WIFI device according to a preset encryption algorithm to generate second authentication information.
  • the second authentication information is parsed by the target AP, and an analysis result is obtained, and the analysis result is compared with the target AP to generate third authentication information.
  • the third authentication information is parsed and the analysis result is compared with the local authentication information to obtain an authentication result, and the authentication process is completed.
  • the PC side software opens the WIFI device through the WIFI module
  • the wireless network card control module is a set of library files, which can control the functions of WIFI devices of different manufacturers by calling the system interface.
  • the WIFI module is initialized, and the WIFI device is opened through the interface of the WIFI module.
  • the PC side software sets the information of the target AP to the WIFI module, and when the WIFI device is connected to the network, the information is used to initiate the network authentication;
  • the PC side software needs to set the encryption mode of the target AP, the authentication mode to the WIFI device through the WIFI module interface, and then start the networking process.
  • the WIFI module reads the card type, IMSI, SIM/AKA authentication from the PC side software;
  • the WIFI module needs to know the card type and IMSI information on the wireless terminal side.
  • the WIFI module is exported by the PC side software, and the AT information that needs to be read is sent to the PC side software. And the authentication process is temporarily waiting.
  • the PC side software After receiving the AT command of the WIFI module, the PC side software will form a protocol message according to the protocol, send it to the AT server and wait for the AT server to return the result.
  • the AT server After receiving the packet, the AT server parses the AT command and sends the AT command to the board. After the board side processing is completed, it returns to the AT server. The AT server sends the packet to the PC side software in the protocol packet format.
  • the WIFI module performs encryption and decryption internally according to the protocol of the AP;
  • the WIFI module After the WIFI module obtains the information of the PC side software, it encrypts with the MAC address of the WIFI device through the encryption algorithm, and then sends the encrypted information to the AP. After the AP obtains the encrypted information, it parses it according to the algorithm and returns the parsing result to the WIFI device.
  • the WIFI module uses this information to authenticate with the AP;
  • the parsed information is compared with the local information. The result of the authentication is obtained.
  • the WIFI module returns the result of the authentication to the PC side software. Complete the entire certification process.
  • the technical solution of the embodiment of the present invention is used to transmit the related AT information required for EAP-SIM authentication through the AT server in the drive-free mode, and assist the WIFI module to complete the authentication method.
  • the PC-side software cannot complete the EAP-SIM authentication problem through the SIM-Reader port, and successfully implements the WIFI connection EAP-SIM hotspot, which improves the user's online experience.
  • FIG. 6 is a schematic structural diagram of an authentication device for accessing a network according to an embodiment of the invention.
  • the authentication device of the access network includes: a first acquiring module 601, configured to obtain first authentication information by performing information exchange with the network card side of the AT server of the terminal; and the first generating module 603 is configured to The first authentication information is encrypted together with the WIFI device information to generate the second authentication information.
  • the second obtaining module 605 is configured to perform the information exchange with the target AP according to the second authentication information to obtain the third authentication information.
  • the third obtaining module 607 The method is configured to parse the third authentication information and compare the parsing result with the local authentication information to obtain an authentication result.
  • the authentication device of the access network further includes: a fourth ear module (not shown) configured to acquire information of the target AP as the local information.
  • the first obtaining module 601 includes: a component module (not shown) configured to configure the received AT command to form a packet according to a preset protocol, and send the packet to the AT server; Not shown in the figure, configured to parse the message by the AT server to obtain the AT command and send the AT command to the network card side; a receiving module (not shown) configured to pass the The AT server receives the first authentication information generated according to the AT command returned by the network card side.
  • the second obtaining module 605 includes: a second parsing module (not shown) configured to parse the second authentication information by using the target AP, and obtain an parsing result;
  • the generating module (not shown) is configured to generate the third authentication information by performing information interaction with the target AP according to the parsing result.
  • the wireless terminal side software controls the WIFI module to initiate wireless authentication, and in the authentication process, the corresponding authentication information is read from the terminal through the AT server on the terminal according to the needs of the WIFI module. Passed to the WIFI module to assist in the completion of the WIFI module and AP authentication process, to achieve WIFI Internet access. Successfully realized the PC side software is free of drive The EAP-SIM authentication between the WIFI device and the AP is completed in the mode.
  • the above wireless network card control module may be a CPU or a chip provided with a CPU, a single chip microcomputer, etc.;
  • the above WIFI module may be a wireless module commonly used at present, and may include a wireless transceiver;
  • the above system interface control module It may be an interface controller, and may include a CPU or a chip provided with a CPU, a single chip microcomputer, etc.;
  • the receiving module, the first ear module, the second acquiring module, the third acquiring module, and the fourth acquiring module may be receivers.
  • the like may include a CPU or a chip provided with a CPU, a single chip microcomputer, etc.; the above component module, the first analysis module, and the second analysis module may be a CPU or a chip provided with a CPU, a single chip microcomputer, etc.; the first generation module, the first generation module The second generation module may be a CPU or a chip provided with a CPU, a single chip microcomputer, or the like.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本发明公开一种接入网络的认证方法、装置与终端设备,该接入网络的认证方法,用于带有PC侧软件的终端设备,包括:通过终端的AT-Server与网卡侧进行信息交互获取第一认证信息(S101);将所述第一认证信息与WIFI设备信息一起加密生成第二认证信息(S103);根据所述第二认证信息与目标AP进行信息交互获取第三认证信息(S105);以及解析所述第三认证信息并将解析结果与本地认证信息进行比对后获取认证结果(S107)。采用本发明的技术方案,可以实现PC侧软件在免驱的方式下WIFI设备和AP之间的EAP-SIM认证,从而方便快捷地接入网络。

Description

接入网络的认证方法、 装置与终端设备 技术领域
本发明涉及通讯技术领域, 更具体的, 涉及一种接入网络的认证方法、 装置与终端设备。 背景技术
目前, 随着计算机的普及和通讯技术业务的高速发展, 计算机和通讯 已经广泛应用在人们生活中的方方面面,通过在 PC上应用无线终端设备会 带来极大的方便,有着 PC侧软件的无线终端设备,也逐渐进入人们的生活, 越来越多的运营商给客户提供他们定制的 PC侧软件和无线终端设备,而运 营商在出售产品的同时, 进行了各种形式的补贴, 希望用户使用他们的产 品就可以实现 3G上网。
随着 WIFI设备的普遍应用, 几乎所有的笔记本上都会内置有 WIFI模 块, 运营商希望在有 WIFI热点的时候, 用户可以随时切换到 WIFI联网的 方式下, 提高用户的上网速度。
目前大多数的终端软件已经可以实现这一功能, 在联网的时候由用户 自由选择 3G还是 WIFI 联网, 但由于运营商的 WIFI 热点一般是采用 EAP-SIM加密,所以终端软件在第一次使用前需要安装 SIM-Reader的驱动, 在做 WIFI认证的时候, WIFI模块会通过 SIM-Reader完成和接入点( Access Point, AP ) 的认证过程。
但是对于免驱的 PC侧软件,因为不会向 PC侧安装 SIM-Reader驱动所 以 PC侧软件无法完成 WIFI的 EAP-SIM认证, 也就无法连接 EAP-SIM加 密的 AP。
因此, 现有技术中存在免驱模式下, WIFI设备无法通过 EAP-SIM认 证的问题。 发明内容
本发明实施例公开一种接入网络的认证方法、 装置与终端设备, 用于 解决现有技术中存在免驱模式下, WIFI设备无法通过 EAP-SIM认证的问 题。
为实现上述目的, 本发明实施例的技术方案是这样实现的:
一种接入网络的认证方法, 用于带有 PC侧软件的终端设备; 包括: 通过终端的 AT服务器与网卡侧进行信息交互获取第一认证信息; 将所述第一认证信息与 WIFI设备信息一起加密生成第二认证信息; 根据所述第二认证信息与目标 AP进行信息交互获取第三认证信息; 解析所述第三认证信息并将解析结果与本地认证信息进行比对后获取 认证结果。
其中,在所述通过终端的 AT服务器与网卡侧进行信息交互获取第一认 证信息之前, 还包括:
获取所述目标 AP的信息作为所述本地信息。
其中,所述通过终端的 AT服务器与网卡侧进行信息交互获取第一认证 信息包括:
将接收到的 AT命令按照预设协议组成报文并发送至所述 AT服务器; 通过所述 AT服务器解析所述报文后得到所述 AT命令并将所述 AT命 令发送至所述网卡侧;
通过所述 AT服务器接收所述网卡侧返回的根据所述 AT命令生成的所 述第一认证信息。
其中,所述将所述第一认证信息与 WIFI设备信息一起加密生成第二认 证信息包括:
按照预设的加密算法将所述第一认证信息与所述 WIFI设备的 MAC地 址信息一起加密生成所述第二认证信息。
其中,所述根据所述第二认证信息与目标 AP进行信息交互获取第三认 证信息包括:
通过所述目标 AP解析所述第二认证信息, 并得到一解析结果; 根据所述解析结果与所述目标 AP进行信息交互生成所述第三认证信 一种接入网络的认证装置, 用于带有 PC侧软件的终端设备; 包括: 第一获取模块,配置为通过终端的 AT服务器与网卡侧进行信息交互获 取第一认证信息;
第一生成模块,配置为将所述第一认证信息与 WIFI设备信息一起加密 生成第二认证信息;
第二获取模块,配置为根据所述第二认证信息与目标 AP进行信息交互 获取第三认证信息;
第三获取模块, 配置为解析所述第三认证信息并将解析结果与本地认 证信息进行比对后获取认证结果。
其中, 还包括:
第四获取模块, 配置为获取所述目标 AP的信息作为所述本地信息。 其中, 所述第一获取模块包括:
组成模块,配置为将接收到的 AT命令按照预设协议组成报文并发送至 所述 AT服务器;
第一解析模块, 配置为通过所述 AT服务器解析所述报文后得到所述 AT命令并将所述 AT命令发送至所述网卡侧;
接收模块,配置为通过所述 AT服务器接收所述网卡侧返回的根据所述 AT命令生成的所述第一认证信息。
其中, 所述根据所述第二获耳 4莫块包括: 第二解析模块, 配置为通过所述目标 AP解析所述第二认证信息, 并得 到一解析结果;
第二生成模块,配置为根据所述解析结果与所述目标 AP进行信息交互 生成所述第三认证信息。
一种终端设备, 包括权利要求 6至 9任一项所述的认证装置。
其中 , 所述终端设备带有 PC侧软件。
采用本发明实施例的技术方案, 通过 AT服务器传输 EAP-SIM认证需 要的相关 AT信息,协助完成 WIFI模块和 AP的认证过程,实现 WIFI上网, 实现 PC侧软件在免驱的方式下完成 WIFI设备和 AP之间的 EAP-SIM认证。 解决了现有技术中在免驱模式下, WIFI无法连接 EAP-SIM热点的问题。 附图说明
图 1表示发明实施例所述的接入网络的认证方法流程图;
图 2表示发明实施例所述接入网络的认证方法的系统架构图; 图 3表示发明实施例所述接入网络的认证方法的 PC侧软件交互图; 图 4表示发明实施例所述接入网络的认证方法的无线网卡控制模块交 互图;
图 5表示发明实施例所述的 WIFI模块和 AP之间认证的流程图; 图 6表示发明实施例所述的接入网络的认证装置结构示意图。 具体实施方式
以下结合附图对本发明实施例的实施例进行详细说明, 但是本发明实 施例可以由权利要求限定和覆盖的多种不同方式实施。
图 1表示发明实施例所述的接入网络的认证方法流程图。
参见图 1所示, 接入网络的认证方法包括:
S101 : 通过终端的 AT服务器与网卡侧进行信息交互获取第一认证信 S103:将所述第一认证信息与 WIFI设备信息一起加密生成第二认证信 S105:根据所述第二认证信息与目标 AP进行信息交互获取第三认证信 息;
S 107: 解析所述第三认证信息并将解析结果与本地认证信息进行比对 后获取认证结果。 本实施例中, 参见图 2所示, 图 1中的 S101至 S107分 别由以下几个模块执行: PC侧软件 201, 负责加载和卸载无线网卡控制模 块, 并发起联网、扫描、 断网的动作。 和现有技术不同的是, PC侧软件 201 还要负责 EAP认证过程中的同步动作, 如果无线网卡控制模块需要从板侧 读取实时信息, PC侧软件 201需要在内部实现同步, 以保证无线网卡控制 模块在进行认证时能及时得到必要的认证信息; 无线网卡控制模块 203 (如 WIFI控制模块), 调用系统函数, 来操作 PC上的 WIFI设备, 实现具体的 联网、 断网、 WEP认证、 WPA/WPA2认证等等。 无线网卡控制模块内部会 封装 wpa-supplicant进程, 专门来做鉴权、认证的动作, 同时在做 EAP-SIM 认证的时候, 无线网卡控制模块会向 PC侧软件发起读取 AT信息的动作, 以进行后续的鉴权; WIFI设备 205,是 PC上的 WIFI设备; AT服务器 207, 配置为实现从 PC侧软件接收协议报文, 解析、 访问调制解调器(Modem ) 设备,实现用户界面( User Interface, UI )和板侧之间桥梁的功能; Modem209, 实现具体的短信、 拨号上网、 PIN码等等功能。
其中, PC侧软件 201的功能如图 3所示, 该软件需要专门有一个线程 做认证, 在收到无线网卡控制模块 203 的认证请求后, 让无线网卡控制模 块 203的调用请求处于挂起状态, 然后将请求发给 AT服务器, 待 AT服务 器从板侧读取到结果之后, 再将结果送给 WIFI模块, WIFI模块继续做认 证。 无线网卡控制模块如图 4所示, 由两部分组成: wpa-supplicant和系统 接口控制模块, wpa-supplicant专门用来从 PC侧读取 IMSI、 AKA、 SIM, 鉴权方式, 它会发起 EAP-Request、 EAP-Identify等等过程, 执行认证阶段 的加密解密的动作, 对网络侧返回的鉴权参数进行有效性检查。 系统接口 控制模块, 首先向 PC软件侧注册回调接口, 同时会调用操作系统封装的函 数, 来向 WIFI 设备下发联网、 断网、 扫描和获取扫描结果等动作。 在 wap_supplicant认证需要 MAC地址、 计算密钥 (Key ) 的动作的时候, 来 配合 wpa-supplicant完成响应的功能。
在本发明实施例中, PC侧软件和无线终端设备之间通讯都通过消息实 现, 具体的通讯载体为 AT。 在 S101 中, 获取第一认证信息之前, 首先要 获取目标 AP的信息作为本地信息。无线终端侧在上电的时候, 启动内置的 AT服务器, 然后调用 Modem侧的软件, 软件运行起来后, 通过将 AT命令 打包成协议格式(如 http协议或者用户自定义的协议),发送给 AT服务器, AT服务器解析报文后得到 AT命令并将其发送至网卡侧; 网卡侧返回给 AT 服务器第一认证信息。 在 S103中, 按照预设的加密算法将第一认证信息与 WIFI设备的 MAC地址信息一起加密生成第二认证信息。在 S105中, 通过 目标 AP解析第二认证信息, 得到一个解析结果, 将此解析结果与目标 AP 进行信息交互生成第三认证信息。 在 S107中, 解析第三认证信息并将解析 结果与本地认证信息进行比对后得到认证结果, 完成了本次认证过程。
更具体地, WIFI模块和 AP之间认证的流程可以通过图 5来进行详细 说明, 参见图 5所示,
PC侧软件通过 WIFI模块打开 WIFI设备;
在此步驟中, 无线网卡控制模块是一组库文件, 能够通过调用系统接 口来实现控制不同厂家 WIFI设备的功能。 PC侧软件在初始化的过程中, 初始化 WIFI模块, 通过 WIFI模块的接口打开 WIFI设备。 PC侧软件将目标 AP的信息设置给 WIFI模块, WIFI设备在联网的时 候, 会使用这些信息发起联网的认证;
在此步驟中, 在连接 AP之前, PC侧软件需要将目标 AP的加密方式, 认证方式通过 WIFI模块接口设置给 WIFI设备, 然后启动联网过程。
WIFI模块从 PC侧软件读取卡类型、 IMSI、 SIM/AKA认证;
在此步驟中, 在做 EAP-SIM认证的时候, WIFI模块需要知道无线终 端侧的卡类型、 IMSI的信息。 WIFI模块通过 PC侧软件导出, 将需要读取 的 AT信息发送给 PC侧软件。 并使得认证过程暂时等待。
PC侧软件收到 WIFI模块的 AT命令之后,将其按照协议组成协议报文, 发送给 AT服务器并等待 AT服务器返回结果。
AT服务器在收到报文后解析, 然后将 AT命令发送给板侧, 板侧处理 完成后返回给 AT服务器, AT服务器再以协议报文格式, 发送给 PC侧软 件。
WIFI模块在内部按照 AP的协议方式进行加密解密;
在此步驟中, WIFI模块得到 PC侧软件的信息后,通过加密算法和 WIFI 设备的 MAC地址一起做加密, 然后将加密信息发送给 AP。 AP得到加密信 息后, 按照算法解析, 并将解析结果返回给 WIFI设备。
WIFI模块利用这些信息和 AP之间做认证;
在此步驟中, WIFI设备解析后, 将解析得到的信息和本地信息对比。 得出鉴权结果。
认证完成, 将认证结果上报给 PC侧软件。
在此步驟中, WIFI模块将鉴权的结果, 返回给 PC侧软件。 完成整个 认证过程。
采用本发明实施例的技术方案, 在免驱模式下, 通过 AT服务器传输 EAP-SIM认证需要的相关 AT信息, 协助 WIFI模块完成认证的方法, 解决 了 PC侧软件无法通过 SIM-Reader口完成 EAP-SIM认证的问题,成功实现 了 WIFI连接 EAP - SIM热点, 提高了用户的上网体验。
图 6表示发明实施例所述的接入网络的认证装置结构示意图。
参见图 6所示, 接入网络的认证装置, 包括: 第一获取模块 601 , 配置 为通过终端的 AT服务器与网卡侧进行信息交互获取第一认证信息;第一生 成模块 603, 配置为将所述第一认证信息与 WIFI设备信息一起加密生成第 二认证信息; 第二获取模块 605 , 配置为根据所述第二认证信息与目标 AP 进行信息交互获取第三认证信息; 第三获取模块 607, 配置为解析所述第三 认证信息并将解析结果与本地认证信息进行比对后获取认证结果。
进一步地,接入网络的认证装置, 还包括: 第四获耳 4莫块(图中未示), 配置为获取所述目标 AP的信息作为所述本地信息。
可选地, 所述第一获取模块 601包括: 组成模块(图中未示), 配置为 将接收到的 AT命令按照预设协议组成报文并发送至所述 AT服务器; 第一 解析模块(图中未示), 配置为通过所述 AT服务器解析所述报文后得到所 述 AT命令并将所述 AT命令发送至所述网卡侧; 接收模块(图中未示), 配置为通过所述 AT服务器接收所述网卡侧返回的根据所述 AT命令生成的 所述第一认证信息。
可选地, 所述根据所述第二获取模块 605 包括: 第二解析模块(图中 未示), 配置为通过所述目标 AP解析所述第二认证信息, 并得到一解析结 果; 第二生成模块(图中未示), 配置为根据所述解析结果与所述目标 AP 进行信息交互生成所述第三认证信息。
相比较现有的技术方案,本发明实施例中无线终端侧软件控制 WIFI模 块启动无线认证, 并且在认证过程中根据 WIFI模块的需要通过终端上的 AT服务器从终端上读取对应的鉴权信息传递给 WIFI模块, 协助完成 WIFI 模块和 AP的认证过程, 实现 WIFI上网。 成功实现了 PC侧软件在免驱的 方式下完成 WIFI设备和 AP之间的 EAP-SIM认证。
需要说明的是, 上述的无线网卡控制模块可以是 CPU或设置有 CPU 的芯片、 单片机等; 上述的 WIFI模块可以是目前所常用的无线模块等, 可 以包括无线收发器; 上述的系统接口控制模块可以是接口控制器, 可以包 括 CPU或设置有 CPU的芯片、单片机等;上述的接收模块、第一获耳 4莫块、 第二获取模块、 第三获取模块、 第四获取模块可以是接收机等, 可以包括 CPU或设置有 CPU的芯片、 单片机等; 上述的组成模块、 第一解析模块、 第二解析模块可以是 CPU或设置有 CPU的芯片、单片机等;上述的第一生 成模块、 第二生成模块可以是 CPU或设置有 CPU的芯片、 单片机等。
以上所述, 仅为本发明的较佳实施例而已, 并非用于限定本发明的保 护范围。

Claims

权利要求书
1. 一种接入网络的认证方法, 用于带有 PC侧软件的终端设备; 包括: 通过终端的 AT服务器与网卡侧进行信息交互获取第一认证信息; 将所述第一认证信息与 WIFI设备信息一起加密生成第二认证信息; 根据所述第二认证信息与目标 AP进行信息交互获取第三认证信息; 解析所述第三认证信息并将解析结果与本地认证信息进行比对后获取 认证结果。
2. 如权利要求 1所述的认证方法, 其中, 在所述通过终端的 AT服务 器与网卡侧进行信息交互获取第一认证信息之前, 还包括:
获取所述目标 AP的信息作为所述本地信息。
3. 如权利要求 1所述的认证方法, 其中, 所述通过终端的 AT服务器 与网卡侧进行信息交互获取第一认证信息包括:
将接收到的 AT命令按照预设协议组成报文并发送至所述 AT服务器; 通过所述 AT服务器解析所述报文后得到所述 AT命令并将所述 AT命 令发送至所述网卡侧;
通过所述 AT服务器接收所述网卡侧返回的根据所述 AT命令生成的所 述第一认证信息。
4. 如权利要求 1所述的认证方法, 其中, 所述将所述第一认证信息与 WIFI设备信息一起加密生成第二认证信息包括:
按照预设的加密算法将所述第一认证信息与所述 WIFI设备的 MAC地 址信息一起加密生成所述第二认证信息。
5. 如权利要求 1所述的认证方法, 其中, 所述根据所述第二认证信息 与目标 AP进行信息交互获取第三认证信息包括:
通过所述目标 AP解析所述第二认证信息, 并得到一解析结果; 根据所述解析结果与所述目标 AP进行信息交互生成所述第三认证信
6. 一种接入网络的认证装置, 用于带有 PC侧软件的终端设备; 包括: 第一获取模块,配置为通过终端的 AT服务器与网卡侧进行信息交互获 取第一认证信息;
第一生成模块,配置为将所述第一认证信息与 WIFI设备信息一起加密 生成第二认证信息;
第二获取模块,配置为根据所述第二认证信息与目标 AP进行信息交互 获取第三认证信息;
第三获取模块, 配置为解析所述第三认证信息并将解析结果与本地认 证信息进行比对后获取认证结果。
7. 如权利要求 6所述的认证装置, 其中, 还包括:
第四获取模块, 配置为获取所述目标 AP的信息作为所述本地信息。
8. 如权利要求 6所述的认证装置, 其中, 所述第一获取模块包括: 组成模块,配置为将接收到的 AT命令按照预设协议组成报文并发送至 所述 AT服务器;
第一解析模块, 配置为通过所述 AT服务器解析所述报文后得到所述 AT命令并将所述 AT命令发送至所述网卡侧;
接收模块,配置为通过所述 AT服务器接收所述网卡侧返回的根据所述 AT命令生成的所述第一认证信息。
9. 如权利要求 6所述的认证装置, 其中, 所述根据所述第二获取模块 包括:
第二解析模块, 配置为通过所述目标 AP解析所述第二认证信息, 并得 到一解析结果;
第二生成模块,配置为根据所述解析结果与所述目标 AP进行信息交互 生成所述第三认证信息。
10.一种终端设备, 包括权利要求 6至 9任一项所述的认证装置。
11. 如权利要求 10所述的终端设备, 其中, 所述终端设备带有 PC侧 软件。
PCT/CN2013/086984 2013-06-08 2013-11-12 接入网络的认证方法、装置与终端设备 WO2014194606A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201310227575.2 2013-06-08
CN201310227575.2A CN104244241B (zh) 2013-06-08 2013-06-08 接入网络的认证方法、装置与终端设备

Publications (1)

Publication Number Publication Date
WO2014194606A1 true WO2014194606A1 (zh) 2014-12-11

Family

ID=52007474

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2013/086984 WO2014194606A1 (zh) 2013-06-08 2013-11-12 接入网络的认证方法、装置与终端设备

Country Status (2)

Country Link
CN (1) CN104244241B (zh)
WO (1) WO2014194606A1 (zh)

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104540136B (zh) * 2015-01-30 2018-09-11 中国联合网络通信集团有限公司 一种登录无线局域网的方法和系统
CN106162635A (zh) * 2015-04-01 2016-11-23 北京佰才邦技术有限公司 用户设备的认证方法和装置

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101031121A (zh) * 2007-03-14 2007-09-05 中兴通讯股份有限公司 移动终端及其读取sim卡的方法
CN101141354A (zh) * 2007-10-11 2008-03-12 中兴通讯股份有限公司 选择接入移动网络或者无线局域网的终端
CN101741655A (zh) * 2008-11-25 2010-06-16 中国电信股份有限公司 一种wlan认证的方法、系统和智能卡
CN101990204A (zh) * 2009-08-07 2011-03-23 中国移动通信集团公司 一种插卡终端业务访问的方法及装置
CN103024735A (zh) * 2011-09-26 2013-04-03 中国移动通信集团公司 无卡终端的业务访问方法及设备
US20130121197A1 (en) * 2008-01-16 2013-05-16 Huawei Technologies Co., Ltd. Mobile WLAN Gateway

Family Cites Families (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8312267B2 (en) * 2004-07-20 2012-11-13 Time Warner Cable Inc. Technique for securely communicating programming content
TW200622744A (en) * 2004-12-20 2006-07-01 Inst Information Industry Public wireless local area network roaming identity recognition method
WO2008052310A1 (en) * 2006-10-04 2008-05-08 Pgmx Inc Method and system of securing accounts
CN101212296B (zh) * 2006-12-28 2010-05-26 中国移动通信集团公司 基于证书及sim的wlan接入认证方法及系统
CN101277231B (zh) * 2008-04-29 2011-04-27 北京星网锐捷网络技术有限公司 无线接入点的检测方法和检测系统、交换机以及客户端
CN101626405A (zh) * 2009-03-02 2010-01-13 卓望数码技术(深圳)有限公司 一种无线上网卡及其身份认证方法和系统
CN101655823B (zh) * 2009-06-12 2012-12-19 中兴通讯股份有限公司 免安装数据卡驱动的实现方法、操作方法及系统
CN101945322A (zh) * 2010-09-19 2011-01-12 中兴通讯股份有限公司 使用数据卡与无线网络通信的方法、系统及数据卡
CN102932968B (zh) * 2011-02-12 2015-09-30 华为终端有限公司 数据卡及数据卡连网的方法

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101031121A (zh) * 2007-03-14 2007-09-05 中兴通讯股份有限公司 移动终端及其读取sim卡的方法
CN101141354A (zh) * 2007-10-11 2008-03-12 中兴通讯股份有限公司 选择接入移动网络或者无线局域网的终端
US20130121197A1 (en) * 2008-01-16 2013-05-16 Huawei Technologies Co., Ltd. Mobile WLAN Gateway
CN101741655A (zh) * 2008-11-25 2010-06-16 中国电信股份有限公司 一种wlan认证的方法、系统和智能卡
CN101990204A (zh) * 2009-08-07 2011-03-23 中国移动通信集团公司 一种插卡终端业务访问的方法及装置
CN103024735A (zh) * 2011-09-26 2013-04-03 中国移动通信集团公司 无卡终端的业务访问方法及设备

Also Published As

Publication number Publication date
CN104244241B (zh) 2019-03-12
CN104244241A (zh) 2014-12-24

Similar Documents

Publication Publication Date Title
JP6707717B2 (ja) デバイスプロビジョニングプロトコル(dpp)のためのコンフィギュレータ鍵パッケージ
TWI388180B (zh) 通信系統中之金鑰產生
US20180199265A1 (en) Sending and acquiring wifi networking information
US8769257B2 (en) Method and apparatus for extending transport layer security protocol for power-efficient wireless security processing
WO2017128756A1 (en) Method and apparatus for network access
US11902781B2 (en) Methods and systems of wireless sensor authentication
KR20100100641A (ko) 듀얼 모뎀 디바이스
US20160119143A1 (en) User identity authenticating method, terminal, and server
WO2006020329A2 (en) Method and apparatus for determining authentication capabilities
WO2006085169A1 (en) Method and apparatus for using generic authentication architecture procedures in personal computers
WO2021073300A1 (zh) 一种蓝牙设备及其工作方法
JP2011141877A (ja) 通信システムにおける認証
JP2018532325A (ja) ユーザ機器ueのアクセス方法、アクセスデバイス、およびアクセスシステム
WO2023280194A1 (zh) 网络连接管理方法、装置、可读介质、程序产品及电子设备
WO2018233726A1 (zh) 网络切片的认证方法及相应装置、系统和介质
US20210251019A1 (en) Systems and methods for provisioning wi-fi devices
WO2021109963A1 (zh) 初始安全配置方法、安全模块及终端
WO2016003311A1 (en) Device bootstrap to wireless network
WO2020029754A1 (zh) 一种签约信息配置方法及通信设备
WO2014161277A1 (zh) 便携式wlan热点的连接方法及系统
WO2023279897A1 (zh) 安全绑定方法及系统、存储介质、电子装置
JP6269025B2 (ja) 無線接続装置、無線通信に関する設定情報を複製する方法、および、ネットワークシステム
EP2866404B1 (en) Mobile terminal with built-in pppoe dialing function and dialing method thereof
TW552779B (en) A method and an apparatus for granting use of a session of a packet data transmission standard designated by an identifier
WO2014194606A1 (zh) 接入网络的认证方法、装置与终端设备

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 13886444

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 13886444

Country of ref document: EP

Kind code of ref document: A1