WO2009106003A1 - 在无线局域网中实现手机接入认证的设备及方法 - Google Patents

在无线局域网中实现手机接入认证的设备及方法 Download PDF

Info

Publication number
WO2009106003A1
WO2009106003A1 PCT/CN2009/070546 CN2009070546W WO2009106003A1 WO 2009106003 A1 WO2009106003 A1 WO 2009106003A1 CN 2009070546 W CN2009070546 W CN 2009070546W WO 2009106003 A1 WO2009106003 A1 WO 2009106003A1
Authority
WO
WIPO (PCT)
Prior art keywords
mobile phone
authentication
digital certificate
certificate
sim card
Prior art date
Application number
PCT/CN2009/070546
Other languages
English (en)
French (fr)
Inventor
崔炳荣
曹军
朱立军
张变玲
陈铭
肖雳
Original Assignee
西安西电捷通无线网络通信有限公司
中太数据通信(深圳)有限公司
***通信计量中心
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 西安西电捷通无线网络通信有限公司, 中太数据通信(深圳)有限公司, ***通信计量中心 filed Critical 西安西电捷通无线网络通信有限公司
Publication of WO2009106003A1 publication Critical patent/WO2009106003A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0823Network architectures or network communication protocols for network security for authentication of entities using certificates
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • H04W12/068Authentication using credential vaults, e.g. password manager applications or one time password [OTP] applications
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • H04W12/069Authentication using certificates or pre-shared keys
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0853Network architectures or network communication protocols for network security for authentication of entities using an additional device, e.g. smartcard, SIM or a different communication terminal

Definitions

  • the present invention relates to the field of communications technologies, and in particular, to an apparatus and method for implementing mobile phone access authentication in a wireless local area network.
  • WLANs have become more and more widely used, not only for independent Internet devices, but also more and more integrated into electronic office equipment and consumer electronic devices.
  • the integration of WLAN modules in mobile phones has become a requirement for user and market development.
  • a WLAN phone is a communication tool based on wireless local area network (WLAN) and the Internet.
  • WLAN wireless local area network
  • the security part is the WAPI security protocol
  • the WAPI security protocol adopts the certificate mechanism, which can ensure the two-way identity authentication between the terminal and the network, and the data. The security of communication.
  • the existing mobile phone access authentication generally adopts an integrated dedicated logic independent WLAN module and an authentication module in the mobile phone, and the digital certificate is directly stored in the authentication module.
  • the inventor discovered through research that in the existing access authentication scheme, when the user replaces the WLAN mobile phone, the digital certificate needs to be rewritten, which brings inconvenience to the user, and at the same time brings inconvenience to the operator for centralized management of the digital certificate and the user. , affect the security of the wireless link.
  • the mobile phone belongs to consumer electronics products, the design of the user interface must be simplified, and the management of the user must be centralized, otherwise large-scale operation and use will not be realized.
  • an object of the embodiments of the present invention is to provide a device and a method for implementing mobile phone access authentication in a wireless local area network, so as to solve the security risks in the access authentication method of the existing WLAN mobile phone.
  • Technical problems that are inconvenient for users and inconvenient for operator management.
  • the embodiment of the present invention improves the following technical solutions:
  • a device for implementing mobile phone access authentication in a wireless local area network comprising a mobile phone 1 integrated with a WLAN module 11 and a WAPI authentication module 12, and a SIM card 2 disposed in the mobile phone 1; the SIM card 2 is provided with a stored digital certificate Space.
  • the above-mentioned SIM card 2 can be provided with a digital certificate storage space reserved by a fixed address.
  • the above digital SIM card 2 can also be provided with a digital certificate storage space reserved by the file.
  • the above digital certificate may include a certificate.
  • the above digital certificate may also include a certificate and a private key.
  • a method for implementing mobile phone access authentication in a wireless local area network includes the following steps:
  • the mobile phone is associated with the access point, and the access point activates the authentication
  • the WAPI authentication module reads the digital certificate from the SIM card
  • the WAPI authentication module sends the digital certificate to the access point, and authenticates between the mobile phone and the access point; 5] the authentication is successful, and the mobile phone accesses the wireless local area network.
  • the above step 1] may be to remotely download the digital certificate through the OTA system, and store the digital certificate in the digital certificate storage space in the SIM card.
  • the digital certificate can be stored in the digital certificate storage space of the SIM card by using the local mobile phone through the SIM card (mobile phone and SIM card) interface command.
  • the above digital certificate is stored in the SIM card in the form of a file.
  • the above digital certificate can also be stored directly in the fixed address of the SIM card.
  • the solution for accessing the digital certificate through the SIM card realizes the management and authentication when the mobile phone accesses the WLAN, which greatly facilitates the management of the operator.
  • the device provided by the embodiment of the present invention is a physical terminal of the WLAN, and the WAPI protocol-based authentication scheme can greatly improve the security of the wireless link.
  • the digital certificate is remotely updated, the content of the digital certificate is encrypted by the OTA server and the CRC is calculated, and the SIM card is decrypted and verified after obtaining the complete short message packet, and the digital certificate is obtained.
  • Medium is ciphertext transmission, which makes the security of digital certificate distribution extremely Great improvement.
  • the SIM card management certificate the user can be centrally managed, which breaks through the bottleneck that the user cannot centrally manage when the mobile phone accesses the WLAN.
  • the inconvenience caused by rewriting the digital certificate is required, and the identity authentication and charging of the mobile phone user are currently implemented by the SIM card, which is compatible with the previous user experience.
  • the digital certificate is stored in the file format in the SIM card, which facilitates the over-the-air download of the digital certificate and the active update of the user.
  • FIG. 1 is a schematic structural diagram of a device according to an embodiment of the present invention.
  • FIG. 2 is a flowchart of a method provided by an embodiment of the present invention.
  • the embodiments of the present invention provide an apparatus and a method for implementing mobile phone access authentication in a wireless local area network.
  • the embodiments of the present invention are described in detail below with reference to the accompanying drawings.
  • an apparatus includes: a mobile phone 1 integrated with a WLAN module 11 and a WAPI authentication module 12, and a SIM2 card disposed in the mobile phone.
  • SIM card 2 a digital certificate storage space reserved by a fixed address or reserved by a file is set.
  • a digital certificate can include only certificates, as well as certificates and private keys.
  • a method provided by an embodiment of the present invention includes the following steps:: downloading a digital certificate remotely through an OTA system, and storing the digital certificate in a digital certificate storage space in the SIM card;
  • the digital certificate is stored in the digital certificate storage space of the SIM card by using the local mobile phone through the SIM card (mobile phone and SIM card) interface command.
  • the digital certificate is stored in the SIM card as a file or stored directly in the fixed address of the SIM card.
  • the access point sends an authentication activation to the mobile phone to initiate the entire authentication process.
  • the WAPI authentication module reads the digital certificate from the SIM card.
  • Authenticate between the mobile phone and the access point including the following steps: The mobile phone sends an access authentication request to the access point, that is, the digital certificate is sent to the access point; after receiving the access authentication request, the access point sends a certificate authentication request to the AS server, that is, the certificate of the mobile phone and the certificate of the access point are formed. The certificate authentication request packet is sent to the AS server.
  • the AS server After receiving the access point certificate authentication request, the AS server verifies the validity of the certificate of the mobile phone and the certificate of the access point;
  • the AS server sends the mobile phone certificate authentication result information and the access point certificate authentication result information and the signature of the information by the AS server to form an authentication response message to the access point; the authentication result;
  • the access point sends the mobile phone certificate authentication result information, the access point certificate authentication result information, and the access point of the access point to form an access authentication response message to the mobile phone;
  • the mobile phone determines whether to access the access point according to the authentication result.
  • the remote management of the mobile phone digital certificate can be completed by the OTA application downloading system provided by the embodiment of the present invention.
  • the workflow of the user actively launching the digital certificate download through the OTA application downloading system is as follows: 1) the user initiates a digital certificate download request through the SIM card; the OTA server receives the SIM card request; 2] the OTA server downlinks the digital certificate content of the SIM card The OTA message data format is packaged; and multiple digital certificate data packets are sent to the SIM card;
  • the SIM card receives the data packet, and after all the data packets of the digital certificate are received, the data is parsed; 4) the SIM card updates the parsed digital certificate data to the digital certificate storage space in the SIM card; 5] the SIM card sends the number The certificate is updated to the OTA server.
  • the operator actively issues a digital certificate update command; the OTA server receives the update command; 2) the OTA server packs the digital certificate content of the SIM card into the RFM message data format; And sending a plurality of digital certificate data packets to the SIM card;
  • the SIM card receives the data packet, and after all the data packets of the digital certificate are received, the data is parsed;
  • the SIM card updates the parsed digital certificate data to the digital certificate storage space in the SIM card
  • the SIM card sends a digital certificate update response to the OTA server.
  • the basic data structure is as follows:
  • the command data definition is as follows:
  • Command data Command type command length command parameter
  • the basic format of the command data is as follows:
  • the certificate information is read by specifying the offset and length by the file read command.
  • the certificate information is updated by specifying the offset and length by the file update instruction.
  • WLAN Wireless Local Area Network, Wireless LAN
  • the invention may be described in the general context of computer-executable instructions executed by a computer, such as a program module.
  • program modules include routines, programs, objects, components, data structures, and the like that perform particular tasks or implement particular abstract data types.
  • the invention may also be practiced in distributed computing environments where tasks are performed by remote processing devices that are connected through a communication network.
  • program modules can be located in both local and remote computer storage media including storage devices.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Mobile Radio Communication Systems (AREA)

Description

在无线局域网中实现手机接入认证的设备及方法 本申请要求于 2008 年 2 月 29 日提交中国专利局、 申请号为 200810017584.8、 发明名称为"在无线局域网中实现手机接入认证的设备及方 法"的中国专利申请的优先权, 其全部内容通过引用结合在本申请中。 技术领域
本发明涉及通信技术领域,, 尤其涉及在无线局域网中实现手机接入认证 的设备及方法。
背景技术
随着国际标准和 GB 15629.11系列国家标准的颁布实施,无线局域网获得 了越来越广泛的应用, 不仅用于独立的上网设备, 而且越来越多的集成到电子 办公设备和消费电子设备中。 目前手机中集成 WLAN模块已经成为用户和市 场发展的需要。
WLAN手机是一种基于无线局域网(WLAN)和 Internet的通讯工具。 当手 机通过 WLAN进行无线网连接时,需要支持 GB15629.i l系列无线局域网国家 标准, 其中***分为 WAPI安全协议, WAPI安全协议采用证书机制, 可以 保证终端和网络之间的双向身份认证, 以及数据通信的安全。
现有的手机接入认证一般是在手机中采用集成专用的逻辑独立的 WLAN 模块和认证模块, 数字证书直接存入认证模块中。
发明人通过研究发现, 现有的接入认证方案中, 当用户更换 WLAN手机 时, 需要重新写入数字证书, 给用户带来不便, 同时给运营商对数字证书和 用户进行集中管理带来不便, 影响无线链路的安全性。 此外, 由于手机属于 消费电子类产品, 用户接口的设计必须非常简化, 用户的管理也必须实现集 中化, 否则将无法实现大规模的运营使用。
发明内容
有鉴于此,本发明实施例的目的是提供一种在无线局域网中实现手机接入 认证的设备及方法,以解决现有 WLAN手机的接入认证方法中存在安全隐患, 用户使用不方便和运营商管理不方便的技术问题。
为实现上述目的, 本发明实施例提高了如下技术方案:
一种在无线局域网中实现手机接入认证的设备, 包括集成有 WLAN模块 11和 WAPI认证模块 12的手机 1以及设置在手机 1中的 SIM卡 2; 所述 SIM 卡 2中设置有存储数字证书的空间。
上述 SIM卡 2中可设置有通过固定地址保留的数字证书存储空间。
上述 SIM卡 2中也可设置有通过文件保留的数字证书存储空间。
上述数字证书可包括证书。
上述数字证书还可包括证书及私钥。
一种在无线局域网中实现手机接入认证的方法, 包括以下步骤:
1]将数字证书存入 SIM卡中的数字证书存储空间;
2]手机关联到接入点, 接入点激活认证;
3]WAPI认证模块从 SIM卡中读取数字证书;
4]WAPI认证模块把数字证书发送给接入点,手机和接入点之间进行认证; 5]认证成功, 手机接入无线局域网。
上述步骤 1]可以是通过 OTA***远程下载数字证书, 并将数字证书存入 SIM卡中的数字证书存储空间。
上述步骤 1]还可以是用本地手机通过 SIM卡的机卡 (手机和 SIM卡)接口 指令将数字证书存入 SIM卡中的数字证书存储空间。
上述数字证书是通过文件形式存储在 SIM卡中。
上述数字证书还可以直接存储在 SIM卡的固定地址中。
可见, 在本发明实施例中, 通过 SIM卡存取数字证书的方案实现了手机 接入 WLAN时的管理和认证, 极大的方便了运营商的管理。
此外, 本发明实施例所提供的设备作为 WLAN 的一种实体终端, 基于 WAPI协议的认证方案, 能够使无线链路安全性得到巨大提升。 由于远程更新 数字证书,数字证书内容通过 OTA服务器端进行加密和计算 CRC校验后才进 行发送,而 SIM卡得到完整短信包后才进行解密和校验得到数字证书内容,电子 证书在整个传输过程中是密文传输的,从而使得数字证书发放的安全性有了极 大的提高。 采用 SIM卡方式管理证书, 能够对用户进行集中管理, 突破了手 机接入 WLAN时用户无法集中管理的瓶颈。 需要重新写入数字证书带来的不便, 且目前手机用户的身份认证和计费都是 通过 SIM卡来实现的, 兼容了以前的用户体验。 同时, 在本发明实施例中, 在 SIM卡中采用文件格式存储数字证书 , 方便了数字证书的空中下载和用户 主动更新。
附图说明
图 1为本发明实施例所提供的设备的结构示意图;
图 2为本发明实施例所提供的方法的流程图。
具体实施方式
本发明实施例提供了在无线局域网中实现手机接入认证的设备和方法,下 面结合附图对本发明实施例进行伴细描述。
参照图 1所示, 本发明一实施例所提供的设备包括: 集成有 WLAN模块 11和 WAPI认证模块 12的手机 1以及设置在手机中的 SIM2卡。 SIM卡 2中 设置有通过固定地址保留或通过文件保留的数字证书存储空间。数字证书可以 只包括证书, 也可以包括证书及私钥。
参照图 2所示, 本发明一实施例所提供的的方法, 包括以下步骤: 种是通过 OTA***远程下载数字证书, 并将数字证书存入 SIM卡中的数字证 书存储空间; 另一种是用本地手机通过 SIM卡的机卡 (手机和 SIM卡)接口指 令将数字证书存入 SIM卡中的数字证书存储空间。 数字证书是通过文件形式 存储在 SIM卡中或直接存储在 SIM卡的固定地址中。
2] 当手机关联到接入点 (AP) 时, 由接入点向手机发送认证激活以启动整 个认证过程。
3]WAPI认证模块从 SIM卡中读取数字证书。
4]手机和接入点之间进行认证, 具体包括以下步骤: 手机向接入点发出接入认证请求 , 即将数字证书发往接入点; 接入点收到接入认证请求后, 向 AS服务器发出证书认证请求, 即将手机 的证书和接入点的证书构成证书认证请求报文发送给 AS服务器;
AS服务器收到接入点证书认证请求后, 验证手机的证书和接入点的证书 的合法性;
验证完毕后, AS服务器将手机证书认证结果信息和接入点证书认证结果 信息及 AS服务器对上述信息的签名构成证书认证响应报文发回给接入点; 认证结果;
接入点将手机证书认证结果信息、接入点证书认证结果信息以及接入点对 它们的签名组成接入认证响应报文回送至手机;
手机验证 AS服务器的签名后, 得到接入点证书的认证结果;
手机根据该认证结果决定是否接入该接入点。
5]至此手机与接入点之间完成了证书认证过程。 若认证成功, 则接入点允 许手机接入, 否则解除其关联。
本发明实施例提供的通过 OTA应用下载***便可完成手机数字证书的远 程管理。
用户通过 OTA应用下载***主动发起数字证书下载时的工作流程如下: 1]用户通过 SIM卡发起数字证书下载请求; OTA服务器接收 SIM卡请求; 2]OTA服务器将该 SIM卡的数字证书内容进行下行 OTA报文数据格式打 包; 并将多条数字证书数据包发送给 SIM卡;
3]SIM卡接收数据包, 待数字证书所有数据包收全以后, 进行数据解析; 4]SIM卡将解析好的数字证书数据更新到 SIM卡中的数字证书存储空间; 5]SIM卡发送数字证书更新响应给 OTA服务器。
运营商通过 OTA应用下载***主动发起数字证书更新时的工作流程如 下:
1]运营商主动下发数字证书更新指令; OTA服务器接收更新指令; 2]OTA服务器将该 SIM卡的数字证书内容进行 RFM报文数据格式打包; 并将多条数字证书数据包发送给 SIM卡;
3]SIM卡接收数据包, 待数字证书所有数据包收全以后, 进行数据解析;
4]SIM卡将解析好的数字证书数据更新到 SIM卡中的数字证书存储空间;
5]SIM卡发送数字证书更新响应给 OTA服务器。
基本数据结构如下:
1、 上行 OTA报文数据格式
Figure imgf000007_0001
命令数据定义参考如下:
a) 数字证书下载请求
Figure imgf000007_0002
2、 下行 OTA报文数据格式
数据包:
OTA下行数据包头 命令数据
命令数据: 命令类型 命令长度 命令参数
命令数据参考如下
a) 数字证书下载
Figure imgf000008_0001
3、 RFM报文格式
数据包:
RFM下行数据包头 命令数据
命令数据基本格式参考如下:
Figure imgf000008_0002
本发明实施例提供的基于 WAPI 的手机数字证书读取方法的基本工作流 程如下:
1]通过选择文件指令选择数字证书文件;
2]通过权限验证指令验证数字证书文件读取权限;
3]通过文件读取指令指定偏移和长度对证书信息进行读取。
本发明实施例所提供的基于 WAPI 的手机数字证书更新方法的基本工作 流程如下:
1]通过选择文件指令选择数字证书文件;
2]通过权限验证指令验证数字证书文件更新权限;
3]通过文件更新指令指定偏移和长度对证书信息进行更新。 本发明部分名词术语解释如下:
WLAN: Wireless Local Area Network, 无线局域网
WAPI: WLAN Authentication and Privacy Infrastructure
SIM: 用户身份识别模块 (Subscriber Identify Module)
CLA: Clase, 命令类
OTA: Over The Air, 空中下载
RFM: Remote File Management远程文件管理
本发明可以在由计算机执行的计算机可执行指令的一般上下文中描述,例 如程序模块。一般地,程序模块包括执行特定任务或实现特定抽象数据类型的 例程、 程序、 对象、 组件、 数据结构等等。 也可以在分布式计算环境中实践本 发明,在这些分布式计算环境中, 由通过通信网络而被连接的远程处理设备来 执行任务。在分布式计算环境中,程序模块可以位于包括存储设备在内的本地 和远程计算机存储介质中。
以上所述仅是本发明的优选实施方式,应当指出,对于本技术领域的普通 技术人员来说, 在不脱离本发明原理的前提下, 还可以做出若干改进和润饰, 这些改进和润饰也应视为本发明的保护范围。

Claims

权 利 要 求
1、 一种在无线局域网中实现手机接入认证的设备, 其特征在于, 包括: 集成有无线局域网 WLAN模块和无线局域网鉴别与保密^ 5出结构 WAPI 认证模块的手机以及设置在所述手机中的 SIM卡, 所述 SIM卡中设置有数字 证书存储空间。
2、根据权利要求 1所述的一种在无线局域网中实现手机接入认证的设备, 其特征在于, 数字证书通过固定地址保留在所述数字证书存储空间中。
3、根据权利要求 1所述的一种在无线局域网中实现手机接入认证的设备, 其特征在于, 数字证书通过文件形式保留在所述数字证书存储空间中。
4、 根据权利要求 1或 2或 3所述的一种在无线局域网中实现手机接入认 证的设备, 其特征在于, 所述数字证书包括证书。
5、 根据权利要求 1或 2或 3所述的一种在无线局域网中实现手机接入认 证的设备, 其特征在于, 所述数字证书包括证书及私钥。
6、 一种在无线局域网中实现手机接入认证的方法, 其特征在于: 预先将 数字证书存入 SIM卡的数字证书存储空间, 该方法包括:
手机关联到接入点, 接入点激活认证;
WAPI认证模块将从 SIM卡中读取的数字证书发送给接入点,手机和接入 点之间进行认证。
7、根据权利要求 6所述的一种在无线局域网中实现手机接入认证的方法, 其特征在于, 所述手机和接入点之间进行认证包括:
接入点收到手机发送的接入认证请求后, 向 AS服务器发送证书认证请求 报文, 该报文中包含手机的证书和接入点的证书;
接收 AS服务器根据证书认证请求后返回的证书认证响应, 所述证书认证 响应中包含手机证书认证结果信息、接入点证书认证结果信息及 AS服务器对 上述信息的签名;
对所述证书认证响应进行签名验证, 得到手机证书的认证结果;
向手机回复接入认证响应 , 所述接入认证响应包括手机证书认证结果信 息、 接入点证书认证结果信息以及接入点对它们的签名。
8、根据权利要求 6所述的一种在无线局域网中实现手机接入认证的方法, 其特征在于, 所述数字证书通过 OTA***远程下载后存入 SIM卡中的数字证 书存储空间。
9、根据权利要求 6所述的一种在无线局域网中实现手机接入认证的方法, 其特征在于, 所述数字证书由本地手机通过 SIM卡的机卡 (手机和 SIM卡)接 口指令存入 SIM卡中的数字证书存储空间。
10、根据权利要求 6〜9中任意一项所述的一种在无线局域网中实现手机接 入认证的方法, 其特征在于, 所述数字证书是通过文件形式存储在 SIM卡的 数字证书存储空间中。
11、根据权利要求 6〜9中任意一项所述的一种在无线局域网中实现手机接 入认证的设备, 其特征在于, 所述数字证书直接存储在 SIM卡的数字证书存 储空间的固定地址中。
PCT/CN2009/070546 2008-02-29 2009-02-26 在无线局域网中实现手机接入认证的设备及方法 WO2009106003A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN2008100175848A CN101252434B (zh) 2008-02-29 2008-02-29 在无线局域网中实现手机接入认证的设备及方法
CN200810017584.8 2008-02-29

Publications (1)

Publication Number Publication Date
WO2009106003A1 true WO2009106003A1 (zh) 2009-09-03

Family

ID=39955632

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2009/070546 WO2009106003A1 (zh) 2008-02-29 2009-02-26 在无线局域网中实现手机接入认证的设备及方法

Country Status (2)

Country Link
CN (1) CN101252434B (zh)
WO (1) WO2009106003A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2017031664A1 (en) * 2015-08-24 2017-03-02 Arris Enterprises, Inc. Wireless setup procedure enabling modification of wireless credentials

Families Citing this family (17)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101252434B (zh) * 2008-02-29 2011-12-21 北京中电华大电子设计有限责任公司 在无线局域网中实现手机接入认证的设备及方法
CN101741655A (zh) * 2008-11-25 2010-06-16 中国电信股份有限公司 一种wlan认证的方法、***和智能卡
CN101547444B (zh) * 2009-03-11 2010-11-03 西安西电捷通无线网络通信股份有限公司 在wlan中为不同终端提供特定接入流程的方法
US8391452B2 (en) 2009-04-30 2013-03-05 Microsoft Corporation User-based authentication for realtime communications
CN101557588B (zh) * 2009-05-08 2011-10-26 中兴通讯股份有限公司 一种用户证书的管理及使用方法及移动终端
CN101577926B (zh) * 2009-06-03 2011-05-11 中兴通讯股份有限公司 对无线接入点进行控制的方法和无线接入点控制***
CN102006589B (zh) * 2009-09-02 2013-07-03 中兴通讯股份有限公司 无线局域网鉴别保密基础结构模块连接方法、装置及***
CN101754203B (zh) * 2009-12-25 2014-04-09 宇龙计算机通信科技(深圳)有限公司 一种wapi证书获取方法、装置及网络***
CN101977377A (zh) * 2010-09-27 2011-02-16 宇龙计算机通信科技(深圳)有限公司 Sim卡内数字证书的读取方法、***及移动终端
CN102202054A (zh) * 2011-04-27 2011-09-28 宇龙计算机通信科技(深圳)有限公司 Wapi证书的生成方法、应用方法及移动终端
EP3541106A1 (en) * 2012-02-14 2019-09-18 Apple Inc. Methods and apparatus for euicc certificate management
US10887170B2 (en) 2013-03-05 2021-01-05 Nokia Technologies Oy Method and apparatus for managing devices
CN103259850A (zh) * 2013-04-18 2013-08-21 深圳市宏电技术股份有限公司 一种配置智能终端的方法及装置
CN106559784A (zh) * 2015-09-30 2017-04-05 中兴通讯股份有限公司 控制设备接入的方法、装置以及接入网络的方法
CN107454595A (zh) * 2017-09-28 2017-12-08 上海盈联电信科技有限公司 用于商业综合体无线连接的认证方法
CN111970120B (zh) * 2020-07-27 2024-03-26 山东华芯半导体有限公司 一种基于openssl的加密卡安全应用机制的实现方法
CN116419230A (zh) * 2022-01-05 2023-07-11 西安西电捷通无线网络通信股份有限公司 一种网络接入方法及装置

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1456006A (zh) * 1999-10-22 2003-11-12 艾利森电话股份有限公司 电信***中的方法和设备
CN1674497A (zh) * 2004-03-26 2005-09-28 华为技术有限公司 Wlan终端接入移动网络的认证方法
WO2006103383A1 (en) * 2005-03-31 2006-10-05 Vodafone Group Plc Facilitating and authenticating transactions
CN101252434A (zh) * 2008-02-29 2008-08-27 北京中电华大电子设计有限责任公司 在无线局域网中实现手机接入认证的设备及方法

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1265609C (zh) * 2002-02-08 2006-07-19 泰康亚洲(北京)科技有限公司 一种安全移动电子商务平台数字证书的认证方法

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1456006A (zh) * 1999-10-22 2003-11-12 艾利森电话股份有限公司 电信***中的方法和设备
CN1674497A (zh) * 2004-03-26 2005-09-28 华为技术有限公司 Wlan终端接入移动网络的认证方法
WO2006103383A1 (en) * 2005-03-31 2006-10-05 Vodafone Group Plc Facilitating and authenticating transactions
CN101252434A (zh) * 2008-02-29 2008-08-27 北京中电华大电子设计有限责任公司 在无线局域网中实现手机接入认证的设备及方法

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2017031664A1 (en) * 2015-08-24 2017-03-02 Arris Enterprises, Inc. Wireless setup procedure enabling modification of wireless credentials
US10548009B2 (en) 2015-08-24 2020-01-28 Arris Enterprises Llc Wireless setup procedure enabling modification of wireless credentials

Also Published As

Publication number Publication date
CN101252434A (zh) 2008-08-27
CN101252434B (zh) 2011-12-21

Similar Documents

Publication Publication Date Title
WO2009106003A1 (zh) 在无线局域网中实现手机接入认证的设备及方法
CN111052777B (zh) 支持无线通信***中设备间简档转移的方法和装置
US12021966B2 (en) Embedded universal integrated circuit card (eUICC) profile content management
WO2009105977A1 (zh) 利用ota***实现手机数字证书远程管理的方法
US7912224B2 (en) Wireless network system and communication method for external device to temporarily access wireless network
EP2063567B1 (en) A network access authentication and authorization method and an authorization key updating method
US20070098176A1 (en) Wireless LAN security system and method
CN107197346A (zh) 电视终端及蓝牙设备回连方法和计算机可读存储介质
CN102812662A (zh) 用于管理员驱动的简表更新的方法和设备
JP2004274193A (ja) 無線通信システム、端末、その端末における処理方法並びにその方法を端末に実行させるためのプログラム
CN108762791A (zh) 固件升级方法及装置
JP2003500923A (ja) セキュア通信をイニシャライズし、装置を排他的にペアリングする方法、コンピュータ・プログラムおよび装置
CN101926151A (zh) 建立安全关联的方法和通信网络***
JP5593575B2 (ja) 無線アクセス下で暗号化情報を取得するための方法、装置、及びシステム
KR102657876B1 (ko) Ssp 단말과 서버가 디지털 인증서를 협의하는 방법 및 장치
CN103702312B (zh) 无线信息传输方法和设备
WO2007003103A1 (en) A method for sharing data and a method for recovering the backup data
WO2021109753A1 (zh) 一种应用于极简网络的机卡验证方法和相关设备
US20140341185A1 (en) Method and device for accounting in wifi roaming based on ac and ap interworking
AU2004216606A1 (en) Layer 2 switch device with verification management table
CN111615837B (zh) 数据传输方法、相关设备以及***
CN104683296A (zh) 安全认证方法和***
WO2011082529A1 (zh) 一种组临时密钥更新方法、装置和***
JP4536051B2 (ja) 無線lan端末を認証する認証システム、認証方法、認証サーバ、無線lan端末、及びプログラム
WO2022134089A1 (zh) 一种安全上下文生成方法、装置及计算机可读存储介质

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 09713826

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 09713826

Country of ref document: EP

Kind code of ref document: A1