WO2009106003A1 - Appareil et procédé pour mise en œuvre de l'authentification d'accès de téléphone mobile dans un réseau local radio - Google Patents
Appareil et procédé pour mise en œuvre de l'authentification d'accès de téléphone mobile dans un réseau local radio Download PDFInfo
- Publication number
- WO2009106003A1 WO2009106003A1 PCT/CN2009/070546 CN2009070546W WO2009106003A1 WO 2009106003 A1 WO2009106003 A1 WO 2009106003A1 CN 2009070546 W CN2009070546 W CN 2009070546W WO 2009106003 A1 WO2009106003 A1 WO 2009106003A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- mobile phone
- authentication
- digital certificate
- certificate
- sim card
- Prior art date
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0823—Network architectures or network communication protocols for network security for authentication of entities using certificates
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
- H04W12/068—Authentication using credential vaults, e.g. password manager applications or one time password [OTP] applications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
- H04W12/069—Authentication using certificates or pre-shared keys
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0853—Network architectures or network communication protocols for network security for authentication of entities using an additional device, e.g. smartcard, SIM or a different communication terminal
Definitions
- the present invention relates to the field of communications technologies, and in particular, to an apparatus and method for implementing mobile phone access authentication in a wireless local area network.
- WLANs have become more and more widely used, not only for independent Internet devices, but also more and more integrated into electronic office equipment and consumer electronic devices.
- the integration of WLAN modules in mobile phones has become a requirement for user and market development.
- a WLAN phone is a communication tool based on wireless local area network (WLAN) and the Internet.
- WLAN wireless local area network
- the security part is the WAPI security protocol
- the WAPI security protocol adopts the certificate mechanism, which can ensure the two-way identity authentication between the terminal and the network, and the data. The security of communication.
- the existing mobile phone access authentication generally adopts an integrated dedicated logic independent WLAN module and an authentication module in the mobile phone, and the digital certificate is directly stored in the authentication module.
- the inventor discovered through research that in the existing access authentication scheme, when the user replaces the WLAN mobile phone, the digital certificate needs to be rewritten, which brings inconvenience to the user, and at the same time brings inconvenience to the operator for centralized management of the digital certificate and the user. , affect the security of the wireless link.
- the mobile phone belongs to consumer electronics products, the design of the user interface must be simplified, and the management of the user must be centralized, otherwise large-scale operation and use will not be realized.
- an object of the embodiments of the present invention is to provide a device and a method for implementing mobile phone access authentication in a wireless local area network, so as to solve the security risks in the access authentication method of the existing WLAN mobile phone.
- Technical problems that are inconvenient for users and inconvenient for operator management.
- the embodiment of the present invention improves the following technical solutions:
- a device for implementing mobile phone access authentication in a wireless local area network comprising a mobile phone 1 integrated with a WLAN module 11 and a WAPI authentication module 12, and a SIM card 2 disposed in the mobile phone 1; the SIM card 2 is provided with a stored digital certificate Space.
- the above-mentioned SIM card 2 can be provided with a digital certificate storage space reserved by a fixed address.
- the above digital SIM card 2 can also be provided with a digital certificate storage space reserved by the file.
- the above digital certificate may include a certificate.
- the above digital certificate may also include a certificate and a private key.
- a method for implementing mobile phone access authentication in a wireless local area network includes the following steps:
- the mobile phone is associated with the access point, and the access point activates the authentication
- the WAPI authentication module reads the digital certificate from the SIM card
- the WAPI authentication module sends the digital certificate to the access point, and authenticates between the mobile phone and the access point; 5] the authentication is successful, and the mobile phone accesses the wireless local area network.
- the above step 1] may be to remotely download the digital certificate through the OTA system, and store the digital certificate in the digital certificate storage space in the SIM card.
- the digital certificate can be stored in the digital certificate storage space of the SIM card by using the local mobile phone through the SIM card (mobile phone and SIM card) interface command.
- the above digital certificate is stored in the SIM card in the form of a file.
- the above digital certificate can also be stored directly in the fixed address of the SIM card.
- the solution for accessing the digital certificate through the SIM card realizes the management and authentication when the mobile phone accesses the WLAN, which greatly facilitates the management of the operator.
- the device provided by the embodiment of the present invention is a physical terminal of the WLAN, and the WAPI protocol-based authentication scheme can greatly improve the security of the wireless link.
- the digital certificate is remotely updated, the content of the digital certificate is encrypted by the OTA server and the CRC is calculated, and the SIM card is decrypted and verified after obtaining the complete short message packet, and the digital certificate is obtained.
- Medium is ciphertext transmission, which makes the security of digital certificate distribution extremely Great improvement.
- the SIM card management certificate the user can be centrally managed, which breaks through the bottleneck that the user cannot centrally manage when the mobile phone accesses the WLAN.
- the inconvenience caused by rewriting the digital certificate is required, and the identity authentication and charging of the mobile phone user are currently implemented by the SIM card, which is compatible with the previous user experience.
- the digital certificate is stored in the file format in the SIM card, which facilitates the over-the-air download of the digital certificate and the active update of the user.
- FIG. 1 is a schematic structural diagram of a device according to an embodiment of the present invention.
- FIG. 2 is a flowchart of a method provided by an embodiment of the present invention.
- the embodiments of the present invention provide an apparatus and a method for implementing mobile phone access authentication in a wireless local area network.
- the embodiments of the present invention are described in detail below with reference to the accompanying drawings.
- an apparatus includes: a mobile phone 1 integrated with a WLAN module 11 and a WAPI authentication module 12, and a SIM2 card disposed in the mobile phone.
- SIM card 2 a digital certificate storage space reserved by a fixed address or reserved by a file is set.
- a digital certificate can include only certificates, as well as certificates and private keys.
- a method provided by an embodiment of the present invention includes the following steps:: downloading a digital certificate remotely through an OTA system, and storing the digital certificate in a digital certificate storage space in the SIM card;
- the digital certificate is stored in the digital certificate storage space of the SIM card by using the local mobile phone through the SIM card (mobile phone and SIM card) interface command.
- the digital certificate is stored in the SIM card as a file or stored directly in the fixed address of the SIM card.
- the access point sends an authentication activation to the mobile phone to initiate the entire authentication process.
- the WAPI authentication module reads the digital certificate from the SIM card.
- Authenticate between the mobile phone and the access point including the following steps: The mobile phone sends an access authentication request to the access point, that is, the digital certificate is sent to the access point; after receiving the access authentication request, the access point sends a certificate authentication request to the AS server, that is, the certificate of the mobile phone and the certificate of the access point are formed. The certificate authentication request packet is sent to the AS server.
- the AS server After receiving the access point certificate authentication request, the AS server verifies the validity of the certificate of the mobile phone and the certificate of the access point;
- the AS server sends the mobile phone certificate authentication result information and the access point certificate authentication result information and the signature of the information by the AS server to form an authentication response message to the access point; the authentication result;
- the access point sends the mobile phone certificate authentication result information, the access point certificate authentication result information, and the access point of the access point to form an access authentication response message to the mobile phone;
- the mobile phone determines whether to access the access point according to the authentication result.
- the remote management of the mobile phone digital certificate can be completed by the OTA application downloading system provided by the embodiment of the present invention.
- the workflow of the user actively launching the digital certificate download through the OTA application downloading system is as follows: 1) the user initiates a digital certificate download request through the SIM card; the OTA server receives the SIM card request; 2] the OTA server downlinks the digital certificate content of the SIM card The OTA message data format is packaged; and multiple digital certificate data packets are sent to the SIM card;
- the SIM card receives the data packet, and after all the data packets of the digital certificate are received, the data is parsed; 4) the SIM card updates the parsed digital certificate data to the digital certificate storage space in the SIM card; 5] the SIM card sends the number The certificate is updated to the OTA server.
- the operator actively issues a digital certificate update command; the OTA server receives the update command; 2) the OTA server packs the digital certificate content of the SIM card into the RFM message data format; And sending a plurality of digital certificate data packets to the SIM card;
- the SIM card receives the data packet, and after all the data packets of the digital certificate are received, the data is parsed;
- the SIM card updates the parsed digital certificate data to the digital certificate storage space in the SIM card
- the SIM card sends a digital certificate update response to the OTA server.
- the basic data structure is as follows:
- the command data definition is as follows:
- Command data Command type command length command parameter
- the basic format of the command data is as follows:
- the certificate information is read by specifying the offset and length by the file read command.
- the certificate information is updated by specifying the offset and length by the file update instruction.
- WLAN Wireless Local Area Network, Wireless LAN
- the invention may be described in the general context of computer-executable instructions executed by a computer, such as a program module.
- program modules include routines, programs, objects, components, data structures, and the like that perform particular tasks or implement particular abstract data types.
- the invention may also be practiced in distributed computing environments where tasks are performed by remote processing devices that are connected through a communication network.
- program modules can be located in both local and remote computer storage media including storage devices.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
La présente invention concerne un appareil et un procédé d'authentification d'accès de téléphone mobile dans un réseau local radio. L'invention comprend un téléphone mobile comprenant un module WLAN, un module d'authentification WAPI, et une carte SIM installée dans le téléphone mobile et comportant un espace réservé à la conservation d'un certificat numérique. Le certificat numérique étant préalablement enregistré dans la carte SIM, le téléphone mobile s'associe au point d'accès qui lance la procédure d'authentification. Le module d'authentification WAPI lit dans la carte SIM le certificat numérique et l'envoi au point d'accès. À l'achèvement de la procédure d'authentification entre le téléphone mobile et le point d'accès, le téléphone mobile accède au réseau local radio. La présente invention propose ainsi un téléphone mobile capable de se comporter en terminal d'entité de réseau local radio. La façon dont le certificat numérique est gardé en mémoire et lu dans la carte SIM, permet au téléphone mobile WAPI d'assurer la gestion et l'authentification lors de l'accès au réseau local radio par le téléphone mobile du réseau local radio accède. L'invention évite à l'utilisateur d'avoir à réécrire le certificat numérique à chaque changement d'appareil, et facilite le téléchargement du certificat numérique et les mises à jour à l'initiative de l'utilisateur.
Applications Claiming Priority (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN200810017584.8 | 2008-02-29 | ||
CN2008100175848A CN101252434B (zh) | 2008-02-29 | 2008-02-29 | 在无线局域网中实现手机接入认证的设备及方法 |
Publications (1)
Publication Number | Publication Date |
---|---|
WO2009106003A1 true WO2009106003A1 (fr) | 2009-09-03 |
Family
ID=39955632
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
PCT/CN2009/070546 WO2009106003A1 (fr) | 2008-02-29 | 2009-02-26 | Appareil et procédé pour mise en œuvre de l'authentification d'accès de téléphone mobile dans un réseau local radio |
Country Status (2)
Country | Link |
---|---|
CN (1) | CN101252434B (fr) |
WO (1) | WO2009106003A1 (fr) |
Cited By (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
WO2017031664A1 (fr) * | 2015-08-24 | 2017-03-02 | Arris Enterprises, Inc. | Procédure d'établissement sans fil permettant la modification de justificatifs d'identité sans fil |
Families Citing this family (17)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101252434B (zh) * | 2008-02-29 | 2011-12-21 | 北京中电华大电子设计有限责任公司 | 在无线局域网中实现手机接入认证的设备及方法 |
CN101741655A (zh) * | 2008-11-25 | 2010-06-16 | 中国电信股份有限公司 | 一种wlan认证的方法、系统和智能卡 |
CN101547444B (zh) * | 2009-03-11 | 2010-11-03 | 西安西电捷通无线网络通信股份有限公司 | 在wlan中为不同终端提供特定接入流程的方法 |
US8391452B2 (en) * | 2009-04-30 | 2013-03-05 | Microsoft Corporation | User-based authentication for realtime communications |
CN101557588B (zh) * | 2009-05-08 | 2011-10-26 | 中兴通讯股份有限公司 | 一种用户证书的管理及使用方法及移动终端 |
CN101577926B (zh) * | 2009-06-03 | 2011-05-11 | 中兴通讯股份有限公司 | 对无线接入点进行控制的方法和无线接入点控制系统 |
CN102006589B (zh) * | 2009-09-02 | 2013-07-03 | 中兴通讯股份有限公司 | 无线局域网鉴别保密基础结构模块连接方法、装置及系统 |
CN101754203B (zh) * | 2009-12-25 | 2014-04-09 | 宇龙计算机通信科技(深圳)有限公司 | 一种wapi证书获取方法、装置及网络系统 |
CN101977377A (zh) * | 2010-09-27 | 2011-02-16 | 宇龙计算机通信科技(深圳)有限公司 | Sim卡内数字证书的读取方法、系统及移动终端 |
CN102202054A (zh) * | 2011-04-27 | 2011-09-28 | 宇龙计算机通信科技(深圳)有限公司 | Wapi证书的生成方法、应用方法及移动终端 |
CN107332817B (zh) * | 2012-02-14 | 2020-12-25 | 苹果公司 | 支持多个访问控制客户端的移动装置和对应的方法 |
CN105122723B (zh) * | 2013-03-05 | 2019-12-13 | 诺基亚技术有限公司 | 用于管理设备的方法及装置 |
CN103259850A (zh) * | 2013-04-18 | 2013-08-21 | 深圳市宏电技术股份有限公司 | 一种配置智能终端的方法及装置 |
CN106559784A (zh) * | 2015-09-30 | 2017-04-05 | 中兴通讯股份有限公司 | 控制设备接入的方法、装置以及接入网络的方法 |
CN107454595A (zh) * | 2017-09-28 | 2017-12-08 | 上海盈联电信科技有限公司 | 用于商业综合体无线连接的认证方法 |
CN111970120B (zh) * | 2020-07-27 | 2024-03-26 | 山东华芯半导体有限公司 | 一种基于openssl的加密卡安全应用机制的实现方法 |
CN116419230A (zh) * | 2022-01-05 | 2023-07-11 | 西安西电捷通无线网络通信股份有限公司 | 一种网络接入方法及装置 |
Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN1456006A (zh) * | 1999-10-22 | 2003-11-12 | 艾利森电话股份有限公司 | 电信系统中的方法和设备 |
CN1674497A (zh) * | 2004-03-26 | 2005-09-28 | 华为技术有限公司 | Wlan终端接入移动网络的认证方法 |
WO2006103383A1 (fr) * | 2005-03-31 | 2006-10-05 | Vodafone Group Plc | Procede pour faciliter et authentifier des transactions |
CN101252434A (zh) * | 2008-02-29 | 2008-08-27 | 北京中电华大电子设计有限责任公司 | 在无线局域网中实现手机接入认证的设备及方法 |
Family Cites Families (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN1265609C (zh) * | 2002-02-08 | 2006-07-19 | 泰康亚洲(北京)科技有限公司 | 一种安全移动电子商务平台数字证书的认证方法 |
-
2008
- 2008-02-29 CN CN2008100175848A patent/CN101252434B/zh not_active Expired - Fee Related
-
2009
- 2009-02-26 WO PCT/CN2009/070546 patent/WO2009106003A1/fr active Application Filing
Patent Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN1456006A (zh) * | 1999-10-22 | 2003-11-12 | 艾利森电话股份有限公司 | 电信系统中的方法和设备 |
CN1674497A (zh) * | 2004-03-26 | 2005-09-28 | 华为技术有限公司 | Wlan终端接入移动网络的认证方法 |
WO2006103383A1 (fr) * | 2005-03-31 | 2006-10-05 | Vodafone Group Plc | Procede pour faciliter et authentifier des transactions |
CN101252434A (zh) * | 2008-02-29 | 2008-08-27 | 北京中电华大电子设计有限责任公司 | 在无线局域网中实现手机接入认证的设备及方法 |
Cited By (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
WO2017031664A1 (fr) * | 2015-08-24 | 2017-03-02 | Arris Enterprises, Inc. | Procédure d'établissement sans fil permettant la modification de justificatifs d'identité sans fil |
US10548009B2 (en) | 2015-08-24 | 2020-01-28 | Arris Enterprises Llc | Wireless setup procedure enabling modification of wireless credentials |
Also Published As
Publication number | Publication date |
---|---|
CN101252434A (zh) | 2008-08-27 |
CN101252434B (zh) | 2011-12-21 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
WO2009106003A1 (fr) | Appareil et procédé pour mise en œuvre de l'authentification d'accès de téléphone mobile dans un réseau local radio | |
US12021966B2 (en) | Embedded universal integrated circuit card (eUICC) profile content management | |
CN111052777B (zh) | 支持无线通信系统中设备间简档转移的方法和装置 | |
WO2009105977A1 (fr) | Procédé de réalisation de télégestion d'un certificat numérique de terminal en utilisant le système ota | |
US7912224B2 (en) | Wireless network system and communication method for external device to temporarily access wireless network | |
CN1245846C (zh) | 安全的通过空间管理无线移动站的系统和方法 | |
CN102812662B (zh) | 用于管理员驱动的简表更新的方法和设备 | |
WO2022111187A1 (fr) | Procédé et appareil d'authentification de terminal, dispositif informatique et support de stockage | |
US20070098176A1 (en) | Wireless LAN security system and method | |
CN107197346A (zh) | 电视终端及蓝牙设备回连方法和计算机可读存储介质 | |
JP2004274193A (ja) | 無線通信システム、端末、その端末における処理方法並びにその方法を端末に実行させるためのプログラム | |
CN102223231B (zh) | M2m终端认证系统及认证方法 | |
CN101926151A (zh) | 建立安全关联的方法和通信网络系统 | |
JP2003500923A (ja) | セキュア通信をイニシャライズし、装置を排他的にペアリングする方法、コンピュータ・プログラムおよび装置 | |
CN108762791A (zh) | 固件升级方法及装置 | |
CN103702312B (zh) | 无线信息传输方法和设备 | |
US20140341185A1 (en) | Method and device for accounting in wifi roaming based on ac and ap interworking | |
CN101420686A (zh) | 基于密钥的工业无线网络安全通信实现方法 | |
AU2004216606A1 (en) | Layer 2 switch device with verification management table | |
CN102291386A (zh) | 处理服务器授权的方法及其通信装置 | |
WO2022134089A1 (fr) | Procédé et appareil de génération de contexte de sécurite, et support de stockage lisible par ordinateur | |
CN111615837B (zh) | 数据传输方法、相关设备以及系统 | |
CN104683296A (zh) | 安全认证方法和系统 | |
CN101715190B (zh) | 一种无线局域网下实现终端与服务器鉴别的系统及方法 | |
JP4536051B2 (ja) | 無線lan端末を認証する認証システム、認証方法、認証サーバ、無線lan端末、及びプログラム |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 09713826 Country of ref document: EP Kind code of ref document: A1 |
|
NENP | Non-entry into the national phase |
Ref country code: DE |
|
122 | Ep: pct application non-entry in european phase |
Ref document number: 09713826 Country of ref document: EP Kind code of ref document: A1 |