WO2010130121A1 - 一种第三代网络的接入方法及系统 - Google Patents

一种第三代网络的接入方法及系统 Download PDF

Info

Publication number
WO2010130121A1
WO2010130121A1 PCT/CN2009/074143 CN2009074143W WO2010130121A1 WO 2010130121 A1 WO2010130121 A1 WO 2010130121A1 CN 2009074143 W CN2009074143 W CN 2009074143W WO 2010130121 A1 WO2010130121 A1 WO 2010130121A1
Authority
WO
WIPO (PCT)
Prior art keywords
terminal
tls
message
aaa server
network
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2009/074143
Other languages
English (en)
French (fr)
Inventor
梁洁辉
施元庆
刘家兵
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
ZTE Corp
Original Assignee
ZTE Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by ZTE Corp filed Critical ZTE Corp
Priority to US13/257,913 priority Critical patent/US8769647B2/en
Priority to EP09844533.1A priority patent/EP2445143B1/en
Publication of WO2010130121A1 publication Critical patent/WO2010130121A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/46Interconnection of networks
    • H04L12/4604LAN interconnection over a backbone network, e.g. Internet, Frame Relay
    • H04L12/462LAN interconnection over a bridge based backbone
    • H04L12/4625Single bridge functionality, e.g. connection of two networks over a single bridge
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/46Interconnection of networks
    • H04L12/4633Interconnection of networks using encapsulation techniques, e.g. tunneling
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0823Network architectures or network communication protocols for network security for authentication of entities using certificates
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0892Network architectures or network communication protocols for network security for authentication of entities by using authentication-authorization-accounting [AAA] servers or protocols
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/16Implementing security features at a particular protocol layer
    • H04L63/166Implementing security features at a particular protocol layer at the transport layer
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • H04W12/043Key management, e.g. using generic bootstrapping architecture [GBA] using a trusted network node as an anchor
    • H04W12/0431Key distribution or pre-distribution; Key agreement
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W84/00Network topologies
    • H04W84/02Hierarchically pre-organised networks, e.g. paging networks, cellular networks, WLAN [Wireless Local Area Network] or WLL [Wireless Local Loop]
    • H04W84/10Small scale networks; Flat hierarchical networks
    • H04W84/12WLAN [Wireless Local Area Networks]

Definitions

  • the present invention relates to the field of communications, and in particular, to a third-generation (3G) network access method and system.
  • 3G third-generation
  • Wi-Fi Protected Access Wi-Fi Protected Access
  • WAPI Wi-Fi Protected Access Infrastructure
  • the WAPI security protocol supports certificates in two formats: GBW (National Standard Substance and X.509 v3 certificates.
  • X.509 v3 certificates support a variety of extended attributes/fields, including: key identifier, key usage, extended secret Key Usage, CRL (Certificate Revocation List) Distribution Points, Certificate Policy, Certificate Authority Policy Mapping, Certificate Body Alias, Issuer Alias, and Certificate Body Directory Properties.
  • the terminal After the WLAN terminal (referred to as the terminal) completes the access authentication, if the WLAN is connected to the Internet, the terminal can access the Internet through the WLAN; but for the 3G (3rd Generation) network, the terminal also You must pass the access authentication of the AAA (Authentication Authorization Accounting) server of the 3G network to access 3G network resources such as circuit services and packet services.
  • AAA Authentication Authorization Accounting
  • the AAA server is responsible for access authentication for terminals with IP (Internet Protocol) capabilities, and retrieving user information stored in the HSS (Home Subscriber Server) to determine whether the current user is legitimate and maintain WLAN access. Continuity, providing WLAN roaming function, generating a bill for users to access the 3G network, and reporting to the user. If 3G The network applies QoS (Quality of Service) mechanism, then the AAA server needs to implement the QoS configuration of the authorized and stored WLAN, and map it to the WLAN as the access network.
  • QoS Quality of Service
  • the AAA server of the 3G network uses EAP-SIM (Extensible Authentication Protocol-Subscriber Identification Module), and EAP-AKA (Extensible Authentication Protocol-Authentication and Key Agreement, Extensible Authentication Protocol - Authentication and Key Agreement) Access authentication for wireless LAN terminals using IEEE 802.11i as a security mechanism.
  • EAP-SIM Extensible Authentication Protocol-Subscriber Identification Module
  • EAP-AKA Extensible Authentication Protocol-Authentication and Key Agreement, Extensible Authentication Protocol - Authentication and Key Agreement
  • UICC Universal Integrated Circuit Card
  • the 3GPP (3rd Generation Partnership Project) organization has not yet proposed a technical solution for accessing 3G networks.
  • the technical problem to be solved by the present invention is to overcome the deficiencies of the prior art and provide a 3G network access method and system, so that a WLAN terminal that uses the WAPI security mechanism and does not have the ability to read the UICC can securely access the 3G network.
  • the internet The internet.
  • the present invention provides a method for accessing a third generation network, the method comprising:
  • the terminal uses the wireless LAN authentication and security infrastructure. After the WAPI protocol accesses the wireless local area network, the access point AP of the wireless local area network notifies the authentication and authorization of the third generation 3G network and audits the AAA server. The terminal is ready to access the 3G network;
  • the AAA server obtains the identity information of the terminal by using the AP, and determines that the terminal is a subscription terminal of the 3G network according to the identity information, and then performs an Extensible Authentication Protocol-Transport Layer Security EAP-TLS negotiation process by using the AP and the terminal. ;
  • the terminal accesses the 3G network.
  • the step of notifying the AAA server that the terminal is ready to access the 3G network includes: the terminal sending a start packet of the local area network scalable authentication protocol to the AP; After receiving the start packet, the AP sends an access request packet of the RADIUS protocol of the remote user to the AAA server to notify the AAA server that the terminal is ready to access the 3G network.
  • the steps of obtaining identity information of the terminal include:
  • the AAA server sends an identity request message of the scalable authentication protocol to the terminal by using the AP; after receiving the identity request message, the terminal includes the identity information in an identity response message of the scalable authentication protocol, and sends the message through the AP. Give the AAA server.
  • the identity information is recorded in the terminal certificate of the terminal: an initial session protocol account number bound to the terminal certificate of the terminal in the 3G network, or an international mobile user identification code of the terminal.
  • EAP-TLS negotiation process includes the following steps:
  • the AAA server sends an EAP request packet including the TLS start message to the terminal through the AP, to start an EAP-TLS negotiation process;
  • the terminal sends an EAP response packet that includes a TLS client hello message to the AAA server by using the AP;
  • the TLS client hello message includes capability information of the terminal;
  • the AAA server sends an EAP request packet including a TLS server hello message and a TLS server key exchange message to the terminal through the AP;
  • the TLS server hello message includes a key selected by the AAA server according to the capability information of the terminal. Kit and compression algorithm;
  • TLS server key exchange message includes key exchange parameters on the AAA server side;
  • the EAP request packet that is sent by the AAA server to the terminal and includes the TLS server hello message and the TLS server key exchange message further includes: a TLS certificate message and a TLS certificate request message; and the TLS certificate message Include an AAA server certificate; the TLS certificate request message is used to indicate that the terminal provides a terminal certificate;
  • the step of the terminal sending the EAP response packet including the TLS client key exchange message to the AAA server further includes: the terminal receiving the TLS certificate message and the TLS certificate request message, and the AAA included in the TLS certificate message
  • the server certificate is verified, and carries a TLS certificate message in the EAP response packet that it sends according to the TLS certificate request message; the TLS The certificate message contains the terminal certificate;
  • the step of performing the Extensible Authentication Protocol-Transport Layer Security EAP-TLS negotiation process after the terminal sends the EAP response packet including the TLS client key exchange message to the AAA server, further includes: the AAA server receiving the received The terminal certificate included in the TLS certificate message is verified.
  • the invention also provides an access system for a third generation network, which is used for performing access authentication of a 3G network for a wireless local area network terminal; the system comprises: an AP of a wireless local area network and an AAA server of a 3G network, wherein:
  • the AP is configured to perform the access authentication of the WLAN by using the WAPI protocol, and after the terminal accesses the WLAN, send the notification message that the terminal prepares to access the 3G network to the AAA server;
  • the AAA server is configured to acquire the identity information of the terminal by using the AP, and determine, according to the identity information, that the terminal is a subscription terminal of the 3G network, and perform an EAP-TLS negotiation process with the terminal by using the AP. And after the EAP-TLS negotiation process is completed, the terminal is allowed to access the 3G network.
  • the AP is configured to notify the AAA server that the terminal is ready to access the 3G network by:
  • the AP After receiving the start packet of the local area network extensible authentication protocol sent by the terminal, the AP sends an access request packet of the RADIUS protocol to the AAA server, to notify the AAA server that the terminal is ready to access the 3G network.
  • the terminal After receiving the identity request message, the terminal includes the identity information in an identity response message of the extensible authentication protocol, and sends the identity information to the AAA server by using the AP.
  • the identity information is recorded in the terminal certificate of the terminal: an initial session protocol account number bound to the terminal certificate of the terminal in the 3G network, or an international mobile subscriber identity of the terminal.
  • the WAPI terminal certificate is used as a credential for accessing the 3G network, so that the WLAN terminal can securely access the WLAN and the 3G network at the same time after signing the contract, which greatly facilitates the user.
  • the present invention optimizes the access authentication method on the AAA server side, that is, the AAA server first obtains the terminal identity information through the AP, and performs preliminary authentication on the terminal according to the terminal identity information (determining whether the terminal is a subscription terminal), and then EAP-TLS negotiation with the terminal avoids the initiation of EAP-TLS negotiation with the WLAN terminal not contracted in the 3G network, which reduces unnecessary message interaction, certificate verification and signature verification, and improves the efficiency of the system.
  • FIG. 1 Schematic diagram of a WLAN terminal accessing a 3G network
  • FIG. 2 is a flowchart of a method for a WLAN terminal to access a 3G network according to an embodiment of the present invention
  • FIG. 3 is a schematic structural diagram of an access system of a 3G network according to an embodiment of the present invention.
  • the core idea of the present invention is that after the terminal accesses the wireless local area network by using the WAPI protocol, the AP of the wireless local area network notifies the AAA server of the 3G network that the terminal is ready to access the 3G network; the AAA server acquires the 3G access identity information of the terminal through the AP. And determining that the terminal is a subscription terminal of the 3G network, and then initiates an EAP-TLS (Extensible Authentication Protocol-Transport Layer Security) negotiation process; the terminal and the AAA server complete the 3G network through the EAP-TLS negotiation process. Certificate authentication (ie access authentication) and key exchange, including:
  • FIG. 2 is a flowchart of a method for a WLAN terminal to access a 3G network according to an embodiment of the present invention. As shown in FIG. 2, the method includes the following steps:
  • a WLAN terminal (referred to as a terminal or a UE) associates or re-associates to an AP, the AP sends an authentication activation packet to the terminal;
  • the authentication activation packet includes: an AP certificate and an authentication server identifier trusted by the AP.
  • the terminal After receiving the authentication activation packet, the terminal saves the AP certificate, selects a terminal certificate issued by the authentication server trusted by the AP according to the authentication server identifier trusted by the AP, and generates an ECDH (Diffie-Hellman of the elliptic curve cryptosystem) Man)) the temporary key pair used by the exchange (including: temporary public key px, temporary private key sx), and sends an access authentication request packet to the AP;
  • the access authentication request packet includes parameters such as a terminal certificate, a temporary public key px of the terminal, and a signature of the terminal.
  • the AP After receiving the access authentication request packet, the AP verifies whether the signature of the terminal is correct: if the signature of the terminal is correct, sending a certificate authentication request packet to the authentication server; otherwise, discarding the access authentication request packet, the process ends;
  • the certificate authentication request packet includes: an AP certificate and a terminal certificate.
  • the authentication server After receiving the certificate authentication request packet, the authentication server verifies the AP certificate and the terminal certificate, and the certificate verification result and the signature of the authentication server are included in the certificate authentication response packet and sent to the AP.
  • the AP After receiving the certificate authentication response packet, the AP checks whether the certificate of the terminal is valid according to the certificate verification result and the signature of the authentication server. If the terminal certificate is invalid, the certificate authentication response packet is discarded, and the process ends; if the terminal certificate If it is valid, a temporary key pair (including: temporary public key py, temporary private key sy) for ECDH exchange is generated, and the ECDH operation is performed by using the temporary private key sy of the AP and the temporary public key px of the terminal to obtain the base key BK. And sending an access authentication response packet to the terminal.
  • a temporary key pair including: temporary public key py, temporary private key sy
  • the access authentication response packet includes: a certificate verification result, a signature of the authentication server, a temporary public key y of the AP, and a signature of the AP.
  • the terminal After receiving the access authentication response packet, the terminal verifies the result according to the certificate, and the authentication server The signature and the signature of the AP check whether the AP certificate is valid: If the AP certificate is invalid, the access authentication response packet is discarded, and the process ends; otherwise, the temporary private key sx of the terminal and the temporary public key py of the AP are used for ECDH operation, and the base is obtained. Key BK.
  • the AP and the base key BK generated by the terminal are the same.
  • the terminal and the AP complete the certificate authentication process, and negotiate the base key BK in the certificate authentication process.
  • the terminal and the AP will negotiate to generate a unicast session using the base key BK. Key.
  • the AP sends a unicast key negotiation request packet to the terminal.
  • the unicast key negotiation request packet includes parameters such as a random number generated by the AP.
  • the terminal After receiving the unicast key negotiation request packet, the terminal generates a random number N 2 ; uses the base key BK, the random number, and the random number N 2 to calculate a unicast session key; and sends a unicast key negotiation to the AP.
  • Response packet After receiving the unicast key negotiation request packet, the terminal generates a random number N 2 ; uses the base key BK, the random number, and the random number N 2 to calculate a unicast session key; and sends a unicast key negotiation to the AP.
  • the unicast key negotiation response packet includes parameters such as a random number N 2 .
  • the AP After receiving the unicast key negotiation response packet, the AP calculates a unicast session key by using the base key BK, the random number, and the random number N 2 , and sends a unicast key negotiation confirmation packet to the terminal, and ends the unicast.
  • the negotiation process of the key After receiving the unicast key negotiation response packet, the AP calculates a unicast session key by using the base key BK, the random number, and the random number N 2 , and sends a unicast key negotiation confirmation packet to the terminal, and ends the unicast. The negotiation process of the key.
  • the terminal and the AP complete the certificate authentication process of the WAPI protocol and the unicast session key negotiation process, and the terminal successfully accesses the WLAN.
  • the terminal accesses the 3G network by using the EAP-TLS negotiation process.
  • the terminal and the AP encapsulate the EAP-TLS message through the EAPoL protocol, and the WLAN access network and the 3G AAA pass the RADIUS (
  • the remote authentication dial-in user service, the remote user dial-in authentication system encapsulates the EAP-TLS message, and the terminal and the AP can use the unicast session key negotiated in the unicast key negotiation process to perform the link layer. Encryption.
  • the AP After receiving the EAPoL START packet sent by the terminal, the AP encapsulates the EAPoL START request packet into an AAA server of the RADIUS protocol, and sends the AAA server to the AAA server of the 3G network to notify the AAA.
  • the server has a terminal to access the 3G network.
  • the AAA server After receiving the foregoing access request packet, the AAA server sends an EAP-Request/Identity (EAP-Request/Identity) message to the terminal to obtain the identity information of the terminal.
  • EAP-Request/Identity EAP-Request/Identity
  • the terminal After receiving the EAP identity request message, the terminal includes the identity information recorded in the body alias field of the terminal certificate in the EAP-Response/Identity message, and sends the message to the AAA server through the AP.
  • the identity information recorded in the subject alias field may be a SIP (Session Initial Protocol) account or an IMSI (International Mobile Subscriber Identifier) that is bound to the terminal certificate in the 3G network.
  • SIP Session Initial Protocol
  • IMSI International Mobile Subscriber Identifier
  • the AAA server After receiving the EAP identity response message, the AAA server determines, according to the terminal identity information carried in the message, whether the terminal is subscribed (that is, whether it is a subscription terminal of the 3G network). If the subscription is not signed, the process ends. When the contract is signed, the EAP request packet including the TLS Start (TLS Start) message is sent to the terminal through the AP, and the TLS negotiation process is started.
  • TLS Start TLS Start
  • the AAA server may retrieve the terminal identity information carried in the message in the locally stored user subscription information or the user subscription information stored in the HSS, and determine whether the corresponding terminal has been contracted according to the search result.
  • the terminal starts a normal TLS handshake process, and sends an EAP response packet including a TLS client_hello message to the server.
  • the TLS client hello message contains the TLS capability information of the terminal, including: TLS version number, session identifier, initial random number, client-supported key suite, and compression algorithm.
  • the AAA server sends a TLS server hello message, a TLS certificate message, a TLS server key exchange (TLS server_key_exchange) message, a TLS certificate request (TLS certificate) to the terminal through the AP.
  • Request EAP request packet for message and TLS server hello end (TLS server - hello_ done ) message;
  • the TLS server hello message includes: The AAA server selects the key suite and compression calculation supported by the AAA server from the key suite and the compression algorithm supported by the terminal according to the capability information of the terminal. Information such as law;
  • the TLS certificate message contains the AAA server certificate
  • the TLS server key exchange message includes a key exchange parameter on the AAA server side
  • the terminal certificate is included in the TLS certificate message
  • the TLS certificate verification message includes the signature information of the terminal to prevent the unauthorized terminal from impersonating the terminal to access the 3G network.
  • the TLS Change Encryption Description message is used to inform the AAA server to start enabling the new key suite and compression algorithm
  • the AAA server After receiving the foregoing EAP response packet, the AAA server verifies the terminal certificate and the signature of the terminal included therein; if the verification fails, the packet is discarded, and the process ends; if the verification succeeds, the AP sends the TLS change to the terminal.
  • TLS change cipher spec The EAP request packet for the message and TLS finished message; where:
  • the TLS Change Encryption Description message is used to inform the terminal to start enabling the new key suite and compression algorithm
  • the TLS handshake completion message is used to indicate that the AAA server has completed the TLS handshake protocol at this stage.
  • the terminal sends an EAP response packet to the AAA server, indicating that the TLS negotiation has been completed.
  • the AAA server sends an EAP-SUCCESS message indicating that the terminal authentication (ie, access authentication) is completed and the session key is negotiated, and the terminal is allowed to access the 3G network.
  • the above embodiment may also have various transformation manners, for example:
  • the terminal and the AP can also directly derive the BK using the pre-shared key (PSK).
  • PSK pre-shared key
  • step 211 after receiving the EAPoL START packet sent by the terminal, the AP learns that the terminal is ready to access the 3G network, that is, the subsequent message interaction between the terminal and the AAA server is used for access authentication of the 3G network.
  • the AP may not perform link layer encryption on the EAP-TLS message in the subsequent EAP-TLS negotiation process, and the terminal does not need to perform link layer encryption on the EAP-TLS message.
  • the AAA server is configured to obtain the identity information of the terminal by using the AP, and determine, according to the identity information, that the terminal is a subscription terminal of the 3G network, and perform an EAP-TLS negotiation process between the AP and the terminal; and after the EAP-TLS negotiation process is completed, allow The terminal accesses the 3G network.
  • the AP can notify the AAA server terminal to prepare to access the 3G network in the following manner: Received After the start packet of the local area network extensible authentication protocol sent by the terminal, the AP sends an access request packet of the RADIUS protocol to the AAA server to notify the AAA server that the terminal is ready to access the 3G network.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Business, Economics & Management (AREA)
  • Accounting & Taxation (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Small-Scale Networks (AREA)

Abstract

本发明提供一种第三代网络的接入方法及系统,所述方法包括:终端采用无线局域网认证和保密基础结构 WAPI协议接入无线局域网,通过无线局域网的接入点 AP通知第三代3G网络的认证授权和审计 AAA服务器所述终端准备接入3G网络;所述 AAA服务器通过 AP获取所述终端的身份信息,并根据所述身份信息判定所述终端为3G网络的签约终端后,通过 AP与所述终端进行可扩展认证协议-传输层安全 EAP-TLS协商过程;所述 EAP-TLS协商过程完成后,所述终端接入3G网络。所述系统包括:无线局域网的 AP和3G网络的 AAA服务器。本发明减少了不必要的消息交互、证书验证和签名验证等处理,提高了系统的效率。

Description

一种第三代网络的接入方法及系统
技术领域
本发明涉及通信领域, 尤其涉及一种第三代(3rd Generation, 3G ) 网络 的接入方法及系统。
背景技术
为了应对无线局域网 IEEE( Institute of Electrical and Electronics Engineers , 电气和电子工程师协会) 802.11的安全机制 WEP ( Wried Equivalent Privacy , 有线等效隐私 )和 WPA ( Wi-Fi Protected Access, 无线保真保护访问 )存在 的安全隐患, 提出了 WAPI ( WLAN Authentication Privacy Infrastructure, 无 线局域网认证和保密基础结构)安全协议。 该协议实现了 ASUE (鉴别请求 实体, 设置在终端中)和 AE (鉴别器实体, 设置在接入点中) 的对等认证, 确保了无线局域网 (WLAN ) 的链路层安全。
WAPI安全协议支持两种格式的证书: GBW(国家标准物质 正书和 X.509 v3证书。 X.509 v3证书支持多种扩展属性 /字段, 包括: 密钥标识符、 密钥用 法、扩展密钥用法、 CRL ( Certificate Revocation List,证书吊销列表)分布点、 证书策略、 证书机构策略映射、 证书主体别名、 颁发者别名和证书主体目录 属性。
如图 1所示, 无线局域网终端 (简称终端) 完成接入认证后, 如果无线 局域网与因特网相连,则终端可以通过无线局域网访问因特网;但对于 3G( 3rd Generation, 第三代) 网络, 终端还必须经过 3G网络的 AAA ( Authentication Authorization Accounting, 认证授权和审计)服务器的接入认证, 才能访问电 路业务和分组业务等 3G网络资源。
AAA服务器负责对具备 IP ( Internet Protocol, 因特网协议) 能力的终端 进行接入认证, 检索存储在 HSS ( Home Subscriber Server, 归属用户服务器) 中的用户信息, 判断当前用户是否合法, 维护 WLAN接入的连续性, 提供 WLAN的漫游功能, 生成用户接入 3G网络的账单, 并报告给用户。 如果 3G 网络应用 QoS ( Quality of Service, 服务质量)机制, 那么 AAA服务器还需 实现授权和存储无线局域网的 QoS配置, 并将其映射到作为接入网的无线局 域网中。
现有技术中, 3G 网络的 AAA 服务器釆用 EAP-SIM ( Extensible Authentication Protocol-Subscriber Identification Module , 可扩展认证协议 -用户 i只另l模块 )和 EAP-AKA ( Extensible Authentication Protocol- Authentication and Key Agreement, 可扩展认证协议-认证和密钥协商 )对釆用 IEEE 802.11i作为 安全机制的无线局域网终端进行接入认证。 这两种认证机制需要终端具备读 取 UICC ( Universal Integrated Circuit Card, 通用集成电路卡) 的能力, 这就 限制了无线局域网终端用户必须使用多模终端下才能享受 3G 网络服务。 而 对于釆用 WAPI安全机制而不具备读取 UICC能力的 WLAN终端, 3GPP( 3rd Generation Partnership Project, 第三代合作伙伴计划)组织目前尚未提出如何 接入到 3G网络的技术方案。
发明内容
本发明所要解决的技术问题是, 克服现有技术的不足, 提供一种 3G 网 络的接入方法及系统, 使釆用 WAPI安全机制而不具备读取 UICC 能力的 WLAN终端可以安全地接入 3G网络。
本发明提供一种第三代网络的接入方法, 该方法包括:
终端釆用无线局域网认证和保密基础结构 WAPI协议接入无线局域网 后,通过无线局域网的接入点 AP通知第三代 3G网络的认证授权和审计 AAA 服务器该终端准备接入 3G网络;
AAA服务器通过 AP获取所述终端的身份信息, 并根据所述身份信息判 定所述终端为 3G网络的签约终端后,通过 AP与所述终端进行可扩展认证协 议 -传输层安全 EAP-TLS协商过程;
EAP-TLS协商过程完成后, 所述终端接入 3G网络。
此外, 通知 AAA服务器该终端准备接入 3G网络的所述步骤包括: 所述终端向 AP发送局域网可扩展认证协议的开始分组; 接收到所述开始分组后, AP向 AAA服务器发送远程用户拨入认证系统 RADIUS协议的接入请求分组,以通知 AAA服务器有终端准备接入 3G网络。
此外, 获取所述终端的身份信息的所述步骤包括:
AAA服务器通过 AP向所述终端发送可扩展认证协议的身份请求消息; 接收到所述身份请求消息后, 所述终端将所述身份信息包含在可扩展认 证协议的身份响应消息中, 通过 AP发送给 AAA服务器。
此外, 所述身份信息是记录在所述终端的终端证书中的: 3G网络中与所 述终端的终端证书绑定的初始会话协议帐号、 或所述终端的国际移动用户识 别码。
此外, 所述 EAP-TLS协商过程包括如下步骤:
AAA服务器通过 AP向所述终端发送包含 TLS启动消息的 EAP请求分 组, 以启动 EAP-TLS协商过程;
所述终端通过 AP向 AAA服务器发送包含 TLS客户端问候消息的 EAP 响应分组; 所述 TLS客户端问候消息中包含所述终端的能力信息;
AAA服务器通过 AP向所述终端发送包含 TLS服务器问候消息、 TLS月良 务器密钥交换消息的 EAP请求分组; 所述 TLS服务器问候消息中包含 AAA 服务器根据所述终端的能力信息选择的密钥套件和压缩算法; TLS服务器密 钥交换消息中包含 AAA服务器侧的密钥交换参数;
所述终端向 AAA服务器发送包含 TLS客户端密钥交换消息的 EAP响应 分组; 所述 TLS客户端密钥交换消息中包含终端侧的密钥交换参数。
此外, AAA服务器通过 AP向所述终端发送的、 包含 TLS服务器问候消 息和 TLS服务器密钥交换消息的所述 EAP请求分组中还包含: TLS证书消息 和 TLS证书请求消息;所述 TLS证书消息中包含 AAA服务器证书;所述 TLS 证书请求消息用于指示所述终端提供终端证书;
所述终端向 AAA服务器发送包含 TLS客户端密钥交换消息的 EAP响应 分组的所述步骤还包括: 所述终端接收到所述 TLS证书消息和 TLS证书请求 消息,对 TLS证书消息中包含的 AAA服务器证书进行验证,并根据所述 TLS 证书请求消息在其发送的所述 EAP响应分组中携带 TLS证书消息;所述 TLS 证书消息中包含终端证书;
进行可扩展认证协议 -传输层安全 EAP-TLS协商过程的所述步骤在所述 终端向 AAA服务器发送包含 TLS客户端密钥交换消息的 EAP响应分组之后 还包括: AAA服务器对接收到的所述 TLS证书消息中包含的所述终端证书进 行验证。
本发明还提供一种第三代网络的接入系统, 用于对无线局域网终端进行 3G网络的接入认证; 该系统包含: 无线局域网的 AP和 3G网络的 AAA服务 器, 其中:
所述 AP设置成釆用 WAPI协议对所述终端进行无线局域网的接入认证, 并在终端接入无线局域网之后, 向所述 AAA服务器发送所述终端准备接入 3G网络的通知消息;
所述 AAA服务器设置成通过所述 AP获取所述终端的身份信息, 并根据 所述身份信息判定所述终端是 3G网络的签约终端后,通过所述 AP与所述终 端进行 EAP-TLS协商过程; 并在 EAP-TLS协商过程完成后, 允许所述终端 接入 3G网络。
此外, 所述 AP设置成釆用如下方式通知所述 AAA服务器所述终端准备 接入 3G网络:
接收到所述终端发送的局域网可扩展认证协议的开始分组后, 所述 AP 向所述 AAA服务器发送 RADIUS协议的接入请求分组, 以通知所述 AAA服 务器有终端准备接入 3G网络。
此外, 所述 AAA服务器设置成釆用如下方式获取所述终端的身份信息: 所述 AAA服务器通过所述 AP向所述终端发送可扩展认证协议的身份请 求消息;
接收到所述身份请求消息后 , 所述终端将所述身份信息包含在可扩展认 证协议的身份响应消息中, 通过所述 AP发送给所述 AAA服务器。
此外, 所述身份信息是记录在所述终端的终端证书中的: 3G网络中与所 述终端的终端证书绑定的初始会话协议帐号、 或所述终端的国际移动用户识 别码。 综上所述, 本发明通过将 WAPI的终端证书作为接入 3G网络的凭证, 使得 WLAN终端在签约后,使用同一证书即可同时安全地接入 WLAN和 3G 网络, 极大地方便了用户。
此外, 本发明对 AAA服务器侧的接入认证方法进行了优化, 即 AAA服 务器先通过 AP获取终端身份信息, 并根据终端身份信息对终端进行初步的 鉴别 (判断终端是否是签约终端)后, 再与终端进行 EAP-TLS协商, 避免了 与没有在 3G网络中签约的 WLAN终端发起 EAP-TLS协商,减少了不必要的 消息交互、 证书验证和签名验证等处理, 提高了系统的效率。
附图概述
图 1 WLAN终端接入 3G网络示意图;
图 2是本发明实施例 WLAN终端接入 3G网络的方法流程图;
图 3是本发明实施例 3G网络的接入系统结构示意图。
本发明的较佳实施方式
本发明的核心思想是, 终端釆用 WAPI协议接入无线局域网后, 通过无 线局域网的 AP通知 3G网络的 AAA服务器该终端准备接入 3G网络; AAA 服务器通过 AP获取终端的 3G接入身份信息, 并判定该终端为 3G网络的签 约终端后发起 EAP-TLS ( Extensible Authentication Protocol-Transport Layer Security, 可扩展认证协议-传输层安全)协商过程; 终端与 AAA服务器通过 EAP-TLS协商过程完成 3G网络的证书鉴别 (即接入认证)和密钥交换, 主 要包括:
( 1 )终端和 AAA服务器之间通过 TLS客户端问候消息 /TLS服务器问候 消息的交互完成了双方能力参数(主要包括密钥套件和压缩算法) 的协商; ( 2 )终端和 AAA服务器之间通过 TLS证书消息交换双方的证书(可选);
( 3 )终端和 AAA服务器之间通过 TLS客户端密钥交换消息 /TLS服务器 密钥交换消息完成密钥参数的交换和密钥的协商。 下面将结合附图和实施例对本发明进行详细描述。
图 2是本发明实施例 WLAN终端接入 3G网络的方法流程图, 如图 2所 示, 该方法包括如下步骤:
201 : 当 WLAN终端 (简称终端或 UE ) 关联或重新关联至 AP时, AP 向终端发送鉴别激活分组;
鉴别激活分组中包含: AP证书和 AP信任的鉴别服务器标识。
202: 终端收到鉴别激活分组后, 保存 AP证书, 根据 AP信任的鉴别服 务器标识选择 AP信任的鉴别服务器所颁发的终端证书,生成 ECDH (椭圓曲 线密码体制的 Diffie-Hellman (戴菲 -赫曼 ) )交换所使用的临时密钥对(包括: 临时公钥 px、 临时私钥 sx ) , 向 AP发送接入鉴别请求分组;
接入鉴别请求分组中包含: 终端证书、 终端的临时公钥 px以及终端的签 名等参数。
203: AP收到接入鉴别请求分组后, 验证终端的签名是否正确: 如果终 端的签名正确, 则向鉴别服务器发送证书鉴别请求分组; 否则丟弃该接入鉴 别请求分组, 本流程结束;
证书鉴别请求分组中包含: AP证书和终端证书。
204: 鉴别服务器收到证书鉴别请求分组后, 对 AP证书和终端证书进行 验证, 并将证书验证结果以及鉴别服务器的签名包含在证书鉴别响应分组中 发送给 AP。
205: AP收到证书鉴别响应分组后, 根据其中包含的证书验证结果及鉴 别服务器的签名检查终端的证书是否有效, 如果终端证书无效, 则丟弃证书 鉴别响应分组, 本流程结束; 如果终端证书有效, 则生成用于 ECDH交换的 临时密钥对(包括: 临时公钥 py、 临时私钥 sy ) , 使用 AP的临时私钥 sy和 终端的临时公钥 px进行 ECDH运算, 得到基密钥 BK, 并向终端发送接入鉴 别响应分组。
接入鉴别响应分组中包含: 证书验证结果、 鉴别服务器的签名、 AP的临 时公钥 y和 AP的签名。
206: 终端收到接入鉴别响应分组后, 根据证书验证结果、 鉴别服务器的 签名以及 AP的签名检查 AP证书是否有效: 如果 AP证书无效, 则丟弃接入 鉴别响应分组, 本流程结束; 否则使用终端的临时私钥 sx和 AP的临时公钥 py进行 ECDH运算, 得到基密钥 BK。
需要注意的是, 根据 ECDH原理, AP和终端生成的基密钥 BK相同。 经过步骤 201 ~ 206的交互, 终端和 AP完成了证书鉴别过程, 并在证书 鉴别过程中协商出了基密钥 BK; 在后续步骤中, 终端和 AP将使用基密钥 BK协商生成单播会话密钥。
207: AP向终端发送单播密钥协商请求分组;
单播密钥协商请求分组中包含: AP生成的随机数 等参数。
208: 接收到单播密钥协商请求分组后, 终端生成随机数 N2; 使用基密 钥 BK、 随机数 和随机数 N2计算生成单播会话密钥; 并向 AP发送单播密 钥协商响应分组;
单播密钥协商响应分组中包含随机数 N2等参数。
209: AP接收到单播密钥协商响应分组后, 使用基密钥 BK、 随机数 和随机数 N2计算生成单播会话密钥, 并向终端发送单播密钥协商确认分组, 结束单播密钥的协商过程。
至此, 终端和 AP完成了 WAPI协议的证书鉴别过程和单播会话密钥协 商过程, 终端成功接入无线局域网。 在以下步骤中, 终端将釆用 EAP-TLS协 商过程接入 3G 网络, 在此过程中, 终端与 AP之间通过 EAPoL协议封装 EAP-TLS 消息, WLAN接入网络与 3G AAA之间通过 RADIUS ( Remote Authentication Dial-In User Service , 远程用户拨入认证系统) 协议封装 EAP-TLS消息, 并且终端与 AP之间可以使用上述单播密钥协商过程中协商 得到的单播会话密钥进行链路层的加密。
210:当终端准备接入 3G网络时 ,首先向 AP发送 EAPoL( EAP Over LAN, 局域网可扩展认证协议)的 START (开始)分组, 通知 AP该终端准备接入 3G网络。
211 : AP收到终端发送的 EAPoL START (开始)分组后, 将其封装成 RADIUS协议的接入请求分组, 发送给 3G网络的 AAA服务器, 通知 AAA 服务器有终端要接入 3G网络。
212:接收到上述接入请求分组后, AAA服务器通过 AP向终端发送 EAP ( Extensible Authentication Protocol , 可扩展认证协议 ) 身份请求 ( EAP-Request/Identity ) 消息, 以获取终端的身份信息。
213: 终端收到 EAP身份请求消息后, 将终端证书的主体别名字段中记 录的身份信息包含在 EAP身份响应 ( EAP-Response/Identity ) 消息中通过 AP 发送给 AAA服务器;
上述主体别名字段中记录的身份信息可以是在 3G 网络中与终端证书绑 定的 SIP ( Session Initial Protocol, 初始会话协议)账号或 IMSI ( International Mobile Subscriber Identifier, 国际移动用户识别码 )等信息。
214: AAA服务器收到 EAP身份响应消息后, 根据该消息中携带的终端 身份信息判断该终端是否已签约 (即是否为 3G 网络的签约终端) , 如果未 签约, 则本流程结束; 如果终端已签约, 则通过 AP向终端发送包含 TLS启 动 (TLS Start ) 消息的 EAP请求分组, 开始进行 TLS协商过程。
AAA服务器可以在本地存储的用户签约信息或存储在 HSS 中的用户签 约信息中检索上述消息中携带的终端身份信息, 并根据检索的结果判断对应 终端是否已签约。
215: 终端开始正常的 TLS握手过程, 向服务器发送包含 TLS客户端问 候( TLS client_hello ) 消息的 EAP响应分组;
TLS客户问候消息中包含终端的 TLS能力信息,具体包含: TLS版本号、 会话标识、 初始随机数、 客户端支持的密钥套件和压缩算法等参数。
216 : AAA服务器通过 AP 向终端发送包含 TLS 服务器问候 ( TLS server hello ) 消息、 TLS证书 ( TLS certificate ) 消息、 TLS服务器密钥交换 ( TLS server— key— exchange ) 消息、 TLS证书请求 ( TLS certificate— request ) 消息和 TLS服务器问候结束(TLS server— hello— done )消息的 EAP请求分组; 其中:
TLS服务器问候消息中包含: AAA服务器根据终端的能力信息, 从终端 支持的密钥套件和压缩算法中选择的 AAA服务器支持的密钥套件和压缩算 法等信息;
TLS证书消息中包含 AAA服务器证书;
TLS服务器密钥交换消息中包含 AAA服务器侧的密钥交换参数;
TLS证书请求消息用于指示终端提供证书;
TLS服务器问候结束消息用于表示本阶段的服务器握手过程结束, AAA 服务器开始等待终端的应答。
217:终端接收到上述 EAP请求分组后,验证 TLS证书消息中包含的 AAA 服务器证书, 验证通过后, 通过 AP向 AAA服务器发送包含 TLS证书 (TLS certificate )消息、 TLS客户端密钥交换( TLS client— key— exchange )消息、 TLS 证书验证 ( TLS certificate_verify ) 消息、 TLS 改变加密说明 ( TLS change— cipher— spec ) 消息和 TLS握手完成(TLS finished ) 消息的 EAP响应 分组; 其中:
TLS证书消息中包含终端证书;
TLS客户端密钥交换消息中包含终端侧的密钥交换参数;
TLS证书验证消息中包含终端的签名信息, 防止非授权终端仿冒该终端 接入 3G网络;
TLS改变加密说明消息用于通知 AAA服务器开始启用新的密钥套件和 压缩算法;
TLS握手完成消息用于表示终端已完成本阶段的 TLS握手协议。
218: 接收到上述 EAP响应分组后, AAA服务器验证其中包含的终端证 书和终端的签名; 如果验证失败, 则丟弃该分组, 本流程结束; 如果验证通 过, 则通过 AP向终端发送包含 TLS改变加密说明( TLS change cipher spec ) 消息和 TLS握手完成(TLS finished ) 消息的 EAP请求分组; 其中:
TLS 改变加密说明消息用于通知终端开始启用新的密钥套件和压缩算 法;
TLS握手完成消息用于表示 AAA服务器已完成本阶段的 TLS握手协议。 219: 终端向 AAA服务器发送 EAP响应分组, 指示已完成 TLS协商。 220: AAA服务器发送 EAP成功 ( EAP-SUCCESS ) 消息, 表明完成对 终端的证书鉴别 (即接入认证)并协商出会话密钥, 允许终端接入 3G网络。
221 : 接收到 EAP成功消息后, 终端获知接入认证成功, 因此通过 WAG ( Wireless Access Gateway, 无线接入网关) /PDG ( Packet Data Gateway, 分 组数据网关)使用 3G网络的资源, 发起音频、 视频等 3G业务。
根据本发明的基本原理, 上述实施例还可以有多种变换方式, 例如:
(一 )根据 WAPI协议, 除了在步骤 201 ~ 205所示的证书鉴别过程中进 行 BK的协商外, 终端和 AP也可以使用预共享密钥 (PSK )直接导出 BK。
(二)根据 WAPI协议, AP在接收到包含终端证书的接入鉴别请求后, 也可以在本地进行证书的验证, 因此步骤 203 ~ 204可省略; 同样, 终端也无 需使用鉴别服务器的证书验证结果, 而在本地对 AP证书进行验证。
(三)在步骤 211中, AP接收到终端发送的 EAPoL START (开始)分 组后, 获知终端准备接入 3G网络, 也就是获知终端与 AAA服务器的后续消 息交互是用于 3G 网络的接入认证和密钥协商, 因此 AP可以不对后续的 EAP-TLS 协商过程中的 EAP-TLS 消息进行链路层加密, 终端也无需对 EAP-TLS消息进行链路层加密。
图 3是本发明实施例 3G网络的接入系统结构示意图, 该系统用于对无 线局域网终端 (简称终端)进行 3G 网络的接入认证; 该系统包含: 无线局 域网的 AP、 无线局域网的鉴别服务器和 3G网络的 AAA服务器, 其中: AP和鉴别服务器用于釆用 WAPI协议对终端进行无线局域网的接入认 证, 在终端接入无线局域网之后, AP向 AAA服务器发送终端准备接入 3G 网络的通知消息;
AAA服务器用于通过 AP获取终端的身份信息, 并根据所述身份信息判 定终端是 3G网络的签约终端后, 通过 AP与终端进行 EAP-TLS协商过程; 并在 EAP-TLS协商过程完成后, 允许终端接入 3G网络。
上述身份信息是记录在终端证书中的: 3G网络中与该终端证书绑定的初 始会话协议帐号、 或该终端的国际移动用户识别码。
AP可以釆用如下方式通知 AAA服务器终端准备接入 3G网络: 接收到 终端发送的局域网可扩展认证协议的开始分组后, AP 向 AAA服务器发送 RADIUS协议的接入请求分组,以通知 AAA服务器有终端准备接入 3G网络。
AAA服务器可以釆用如下方式获取终端的身份信息: AAA服务器通过 AP向终端发送可扩展认证协议的身份请求消息; 接收到该消息后, 终端将身 份信息包含在可扩展认证协议的身份响应消息中, 通过 AP发送给 AAA服务 哭口
上述系统中包含的其它网元、 各网元的详细功能、 以及各网元间的连接 关系 (消息交互关系)详见上述对图 2所示的方法的描述部分。
工业实用性
本发明对 AAA服务器侧的接入认证方法进行了优化, 即 AAA服务器先 通过 AP获取终端身份信息,并根据终端身份信息对终端进行初步的鉴别 (判 断终端是否是签约终端)后, 再与终端进行 EAP-TLS协商, 避免了与没有在 3G网络中签约的 WLAN终端发起 EAP-TLS协商,减少了不必要的消息交互、 证书验证和签名验证等处理, 提高了系统的效率。

Claims

权 利 要 求 书
1、 一种第三代网络的接入方法, 该方法包括:
终端釆用无线局域网认证和保密基础结构 WAPI协议接入无线局域网, 通过无线局域网的接入点 AP通知第三代 3G网络的认证授权和审计 AAA服 务器所述终端准备接入 3G网络;
所述 AAA服务器通过 AP获取所述终端的身份信息, 并根据所述身份信 息判定所述终端为 3G网络的签约终端后,通过 AP与所述终端进行可扩展认 证协议 -传输层安全 EAP-TLS协商过程;
所述 EAP-TLS协商过程完成后, 所述终端接入 3G网络。
2、 如权利要求 1所述的方法, 其中, 通过无线局域网的接入点 AP通知 第三代 3G网络的认证授权和审计 AAA服务器所述终端准备接入 3G网络的 所述步骤包括:
所述终端向 AP发送局域网可扩展认证协议的开始分组;
所述 AP接收所述开始分组, 向 AAA服务器发送远程用户拨入认证系统 RADIUS协议的接入请求分组, 以通知所述 AAA服务器有终端准备接入 3G 网络。
3、 如权利要求 1或 2所述的方法, 其中, 所述 AAA服务器通过 AP获 取所述终端的身份信息的所述步骤包括:
AAA服务器通过 AP向所述终端发送可扩展认证协议的身份请求消息; 所述终端接收所述身份请求消息, 将所述身份信息包含在可扩展认证协 议的身份响应消息中, 通过 AP发送给所述 AAA服务器。
4、 如权利要求 1所述的方法, 其中,
所述身份信息是记录在所述终端的终端证书中的以下信息之一:
所述终端的国际移动用户识别码。
5、 如权利要求 1所述的方法, 其中, 进行可扩展认证协议 -传输层安全 EAP-TLS协商过程的所述步骤包括: AAA服务器通过 AP向所述终端发送包含 TLS启动消息的 EAP请求分 组, 以启动 EAP-TLS协商过程;
所述终端通过 AP向 AAA服务器发送包含 TLS客户端问候消息的 EAP 响应分组, 所述 TLS客户端问候消息中包含所述终端的能力信息;
AAA服务器通过 AP向所述终端发送包含 TLS服务器问候消息和 TLS服 务器密钥交换消息的 EAP请求分组, 所述 TLS服务器问候消息中包含 AAA 服务器根据所述终端的能力信息选择的密钥套件和压缩算法, 所述 TLS服务 器密钥交换消息中包含 AAA服务器侧的密钥交换参数; 以及
所述终端向 AAA服务器发送包含 TLS客户端密钥交换消息的 EAP响应 分组, 所述 TLS客户端密钥交换消息中包含终端侧的密钥交换参数。
6、 如权利要求 5所述的方法, 其中,
AAA服务器通过 AP向所述终端发送的、包含 TLS服务器问候消息和 TLS 服务器密钥交换消息的 EAP请求分组中还包含: TLS证书消息和 TLS证书请 求消息, 所述 TLS证书消息中包含 AAA服务器证书, 所述 TLS证书请求消 息用于指示所述终端提供终端证书;
所述终端向 AAA服务器发送包含 TLS客户端密钥交换消息的 EAP响应 分组的所述步骤还包括:
所述终端接收到所述 TLS证书消息和 TLS证书请求消息,对所接收到的 TLS证书消息中包含的 AAA服务器证书进行验证, 并根据所接收到的 TLS 证书请求消息在所发送的 EAP响应分组中携带 TLS证书消息,所携带的 TLS 证书消息中包含终端证书;
进行可扩展认证协议 -传输层安全 EAP-TLS协商过程的所述步骤在所述 终端向 AAA服务器发送包含 TLS客户端密钥交换消息的 EAP响应分组之后 还包括:
AAA服务器对接收到的 TLS证书消息中包含的终端证书进行验证。
7、 一种第三代网络的接入系统, 该系统包括: 无线局域网的 AP和 3G 网络的 AAA服务器, 其中:
所述 AP设置成釆用 WAPI协议对终端进行无线局域网的接入认证, 并 在终端接入无线局域网之后, 向所述 AAA服务器发送有终端准备接入 3G网 络的通知消息;
所述 AAA服务器设置成通过所述 AP获取终端的身份信息,根据所述身 份信息判定所述终端是 3G网络的签约终端后,通过所述 AP与所述终端进行 EAP-TLS协商过程, 并在 EAP-TLS协商过程完成后, 允许所述终端接入 3G 网络。
8、 如权利要求 7所述的系统, 其中,
所述 AP设置成釆用如下方式通知所述 AAA服务器有终端准备接入 3G 网络:
所述 AP接收终端发送的局域网可扩展认证协议的开始分组, 向所述
AAA服务器发送 RADIUS协议的接入请求分组, 以通知所述 AAA服务器有 终端准备接入 3G网络。
9、 如权利要求 7或 8所述的系统, 其中,
所述 AAA服务器设置成釆用如下方式获取终端的身份信息:
所述 AAA服务器通过所述 AP向终端发送可扩展认证协议的身份请求消 息;
所述终端接收所述身份请求消息 , 将所述身份信息包含在可扩展认证协 议的身份响应消息中, 通过所述 AP发送给所述 AAA服务器。
10、 如权利要求 9所述的系统, 其中,
所述终端的身份信息是记录在终端的终端证书中的以下信息之一:
3G网络中与终端的终端证书绑定的初始会话协议帐号; 或
终端的国际移动用户识别码。
PCT/CN2009/074143 2009-05-15 2009-09-23 一种第三代网络的接入方法及系统 Ceased WO2010130121A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
US13/257,913 US8769647B2 (en) 2009-05-15 2009-09-23 Method and system for accessing 3rd generation network
EP09844533.1A EP2445143B1 (en) 2009-05-15 2009-09-23 Method and system for accessing a 3rd generation network

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CNA2009101404459A CN101562814A (zh) 2009-05-15 2009-05-15 一种第三代网络的接入方法及系统
CN200910140445.9 2009-05-15

Publications (1)

Publication Number Publication Date
WO2010130121A1 true WO2010130121A1 (zh) 2010-11-18

Family

ID=41221391

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2009/074143 Ceased WO2010130121A1 (zh) 2009-05-15 2009-09-23 一种第三代网络的接入方法及系统

Country Status (4)

Country Link
US (1) US8769647B2 (zh)
EP (1) EP2445143B1 (zh)
CN (1) CN101562814A (zh)
WO (1) WO2010130121A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2015507445A (ja) * 2012-02-10 2015-03-05 クゥアルコム・インコーポレイテッドQualcomm Incorporated 発見されたロケーションサーバに関する認可を獲得するための安全な仕組み

Families Citing this family (34)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101754203B (zh) * 2009-12-25 2014-04-09 宇龙计算机通信科技(深圳)有限公司 一种wapi证书获取方法、装置及网络系统
CN101771722B (zh) * 2009-12-25 2014-05-28 中兴通讯股份有限公司南京分公司 一种WAPI终端访问Web应用站点的系统及方法
CN102232317B (zh) * 2010-10-26 2013-12-04 华为技术有限公司 移动交换中心池中的寻呼处理方法及装置
US9015469B2 (en) 2011-07-28 2015-04-21 Cloudflare, Inc. Supporting secure sessions in a cloud-based proxy service
CN103188676B (zh) * 2011-12-29 2017-12-26 中兴通讯股份有限公司 可扩展认证协议认证接入方法及装置
MX342702B (es) * 2012-02-14 2016-10-10 Apple Inc Metodos y aparato para distribucion a gran escala de clientes de acceso electronico.
EP2642777B1 (en) * 2012-03-20 2015-03-11 Giesecke & Devrient GmbH Methods and devices for OTA management of mobile stations
WO2013181847A1 (zh) * 2012-06-08 2013-12-12 华为技术有限公司 一种无线局域网接入鉴权方法、设备及系统
KR102098239B1 (ko) * 2012-12-04 2020-04-08 삼성전자주식회사 무선 통신 시스템에서 인터넷 프로토콜 어드레스를 설정하는 방법 및 장치
CN103973658A (zh) * 2013-02-04 2014-08-06 中兴通讯股份有限公司 静态用户终端认证处理方法及装置
US8782774B1 (en) 2013-03-07 2014-07-15 Cloudflare, Inc. Secure session capability using public-key cryptography without access to the private key
EP2852118B1 (en) * 2013-09-23 2018-12-26 Deutsche Telekom AG Method for an enhanced authentication and/or an enhanced identification of a secure element located in a communication device, especially a user equipment
CN104640111B (zh) * 2013-11-11 2019-06-11 中兴通讯股份有限公司 网络接入处理方法、装置及系统
CN103763754B (zh) * 2014-01-26 2017-07-14 华为技术有限公司 一种数据处理的方法、装置及系统
US8996873B1 (en) 2014-04-08 2015-03-31 Cloudflare, Inc. Secure session capability using public-key cryptography without access to the private key
US8966267B1 (en) 2014-04-08 2015-02-24 Cloudflare, Inc. Secure session capability using public-key cryptography without access to the private key
US9184911B2 (en) 2014-04-08 2015-11-10 Cloudflare, Inc. Secure session capability using public-key cryptography without access to the private key
FR3031211B1 (fr) * 2014-12-31 2017-02-10 Thales Sa Infrastructure d'authentification de telephones ip d'un systeme toip proprietaire par un systeme eap-tls ouvert
US9979711B2 (en) * 2015-06-26 2018-05-22 Cisco Technology, Inc. Authentication for VLAN tunnel endpoint (VTEP)
CN105578464B (zh) * 2015-07-31 2019-04-12 宇龙计算机通信科技(深圳)有限公司 一种增强的wlan证书鉴别方法、装置及系统
CN105187409B (zh) * 2015-08-18 2018-09-21 杭州古北电子科技有限公司 一种设备授权系统及其授权方法
CN106912047B (zh) * 2015-12-22 2021-04-20 中兴通讯股份有限公司 终端认证方法、装置及系统
WO2018016713A2 (ko) * 2016-07-18 2018-01-25 엘지전자(주) 무선 통신 시스템에서의 단말의 접속 식별자 보안 방법 및 이를 위한 장치
CN106973383B (zh) * 2016-08-31 2020-06-09 上海博达通信科技有限公司 一种分布式portal认证方法
EP3510803B1 (en) * 2016-09-12 2021-04-28 Telefonaktiebolaget LM Ericsson (publ) Secure link layer connection over wireless local area networks
US10433163B2 (en) * 2016-09-19 2019-10-01 Qualcomm Incorporated Techniques for deriving security keys for a cellular network based on performance of an extensible authentication protocol (EAP) procedure
CN110234112B (zh) * 2018-03-05 2020-12-04 华为技术有限公司 消息处理方法、系统及用户面功能设备
US10903990B1 (en) 2020-03-11 2021-01-26 Cloudflare, Inc. Establishing a cryptographic tunnel between a first tunnel endpoint and a second tunnel endpoint where a private key used during the tunnel establishment is remotely located from the second tunnel endpoint
CN114760029A (zh) * 2020-12-26 2022-07-15 西安西电捷通无线网络通信股份有限公司 一种身份鉴别方法和装置
CN112954679B (zh) * 2021-01-28 2022-07-01 西安电子科技大学 基于DH算法的LoRa终端安全接入方法
KR102853677B1 (ko) * 2021-05-07 2025-09-01 텔레폰악티에볼라겟엘엠에릭슨(펍) 5세대 코어 네트워크에서의 사용자 장비의 데이터 검색
CN116582554B (zh) * 2022-04-07 2025-11-25 武汉联影医疗科技有限公司 边缘节点接入处理方法、装置、移动终端和边缘节点
CN117062053A (zh) * 2022-05-06 2023-11-14 华为技术有限公司 通信方法和装置
CN116528225B (zh) * 2023-07-03 2023-09-08 广东电网有限责任公司珠海供电局 一种wapi终端接入网络的数据安全管理方法、系统及装置

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101013940A (zh) * 2006-12-22 2007-08-08 西安电子科技大学 一种兼容802.11i及WAPI的身份认证方法
CN101056177A (zh) * 2007-06-01 2007-10-17 清华大学 基于无线局域网安全标准wapi的无线网状网重认证方法
CN101079786A (zh) * 2006-05-26 2007-11-28 华为技术有限公司 互连系统、互连系统中的认证方法和终端

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20030139180A1 (en) * 2002-01-24 2003-07-24 Mcintosh Chris P. Private cellular network with a public network interface and a wireless local area network extension
US8630414B2 (en) * 2002-06-20 2014-01-14 Qualcomm Incorporated Inter-working function for a communication system
WO2006000239A1 (en) * 2004-06-24 2006-01-05 Telecom Italia S.P.A. Method and system for controlling access to communication networks, related network and computer program therefor

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101079786A (zh) * 2006-05-26 2007-11-28 华为技术有限公司 互连系统、互连系统中的认证方法和终端
CN101013940A (zh) * 2006-12-22 2007-08-08 西安电子科技大学 一种兼容802.11i及WAPI的身份认证方法
CN101056177A (zh) * 2007-06-01 2007-10-17 清华大学 基于无线局域网安全标准wapi的无线网状网重认证方法

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
"3 GPP TSG SA, Wireless Local Area Network (WLAN) interworking security (Release 8)", 3GPP TS 33.234 V8.1.0, March 2008 (2008-03-01), XP050376783 *
P. FUNK ET AL: "Extensible Authentication Protocol Tunneled Transport Layer Security Authenticated Protocol Version 0 (EAP-TTLSvO)", RFC 5281, August 2008 (2008-08-01), XP015060268 *

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2015507445A (ja) * 2012-02-10 2015-03-05 クゥアルコム・インコーポレイテッドQualcomm Incorporated 発見されたロケーションサーバに関する認可を獲得するための安全な仕組み
US9467856B2 (en) 2012-02-10 2016-10-11 Qualcomm Incorporated Secure mechanism for obtaining authorization for a discovered location server

Also Published As

Publication number Publication date
EP2445143B1 (en) 2015-08-12
EP2445143A4 (en) 2013-11-13
US8769647B2 (en) 2014-07-01
US20120131329A1 (en) 2012-05-24
CN101562814A (zh) 2009-10-21
EP2445143A1 (en) 2012-04-25

Similar Documents

Publication Publication Date Title
US8769647B2 (en) Method and system for accessing 3rd generation network
EP2168068B1 (en) Method and arrangement for certificate handling
CN101606372B (zh) 支持无uicc呼叫
CN101371550B (zh) 自动安全地向移动通信终端的用户供给在线服务的服务访问凭证的方法和系统
US20050114680A1 (en) Method and system for providing SIM-based roaming over existing WLAN public access infrastructure
US20060104234A1 (en) Method for establishment of a service tunnel in a WLAN
US20060019635A1 (en) Enhanced use of a network access identifier in wlan
CN101656956B (zh) 一种接入3gpp网络的方法、系统和网关
US20110035592A1 (en) Authentication method selection using a home enhanced node b profile
WO2009074050A1 (en) A method, system and apparatus for authenticating an access point device
WO2009152749A1 (zh) 一种绑定认证的方法、系统和装置
WO2011127774A1 (zh) 一种用户终端接入互联网方式的控制方法及装置
CN113507705A (zh) 一种基于eap-tls协议的5g二次认证方法及系统
WO2010069202A1 (zh) 认证协商方法及系统、安全网关、家庭无线接入点
Yang et al. 3G and WLAN interworking security: Current status and key issues
CN101542973A (zh) 使用eap对对等设备进行认证的方法和系统
CN101715190B (zh) 一种无线局域网下实现终端与服务器鉴别的系统及方法
CN100527668C (zh) 实现wapi协议与802.1x协议兼容的方法
CN101079786B (zh) 互连系统、互连系统中的认证方法和终端
CN102752298B (zh) 安全通信方法、终端、服务器及系统
WO2012113225A1 (zh) 安全访问wapi网络的方法、装置及系统
CN101110673B (zh) 利用一次eap过程执行多次认证的方法和装置
CN102131199B (zh) 一种wapi认证方法和接入点
WO2009086769A1 (zh) 一种网络服务的协商方法和系统
Mizikovsky et al. CDMA 1x EV-DO security

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 09844533

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 13257913

Country of ref document: US

NENP Non-entry into the national phase

Ref country code: DE

WWE Wipo information: entry into national phase

Ref document number: 2009844533

Country of ref document: EP