WO2010096996A1 - Method for realizing integration of wapi and capwap in local mac mode - Google Patents
Method for realizing integration of wapi and capwap in local mac mode Download PDFInfo
- Publication number
- WO2010096996A1 WO2010096996A1 PCT/CN2009/075537 CN2009075537W WO2010096996A1 WO 2010096996 A1 WO2010096996 A1 WO 2010096996A1 CN 2009075537 W CN2009075537 W CN 2009075537W WO 2010096996 A1 WO2010096996 A1 WO 2010096996A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- site
- capwap
- wireless terminal
- access controller
- wai
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/08—Access security
Definitions
- the present invention relates to the field of network applications, and in particular, to a method for implementing WAPI and CAPWAP fusion in a local MAC mode.
- the access point AP acts as a separate entity on the network and fully deploys and terminates the GB15629.il function, which needs to be managed independently.
- the autonomous system architecture is adopted based on the WLAN authentication and confidentiality base.
- the network working mode of the autonomous architecture has gradually become an obstacle to the development of wireless technology due to its inherent defects.
- the AP acts as an Internet Protocol (IP) addressable device and needs to be managed independently, including monitoring, configuration, and control.
- IP Internet Protocol
- the wireless transmission medium is used as a shared resource.
- each AP In order to improve the performance of the network, each AP must be monitored in real time and dynamically updated according to the current usage of the shared medium, and manually configured and wirelessly transmitted. Media-related AP parameters will consume a lot of manpower and material resources.
- the purpose of the present invention is to overcome the shortcomings of the above-mentioned autonomous WLAN network architecture, and to provide a CAPWAP (Control And Provisioning of Wireless Access Points) specification in a Medium Access Control MAC (Medium Access Control) mode.
- CAPWAP Control And Provisioning of Wireless Access Points
- MAC Medium Access Control
- WAPI WLAN Authentication and Privacy Infrastructure
- the present invention provides a method for implementing WAPI and CAPWAP fusion in a local MAC mode, which is special in that the method includes the following steps:
- Steps of constructing a local MAC mode Separating the MAC function and the WAPI function of the wireless access point from the wireless terminal point and the access controller;
- step 2.1 The specific steps of step 2.1 above are as follows:
- the station passively listens to the beacon frame of the wireless terminal point to obtain parameters of the wireless terminal point including the WAPI information element;
- the station actively sends a query request frame to the wireless terminal point, and after receiving the probe request frame of the station, the wireless terminal point sends a probe response frame to the station, and the station obtains the WAPI information element from the query response frame of the received wireless terminal point.
- the WAPI information element includes an authentication and key management suite and a cipher suite supported by the wireless terminal point;
- the station sends a link verification request frame to the wireless terminal point, requesting link verification with the wireless terminal point;
- the wireless terminal point sends a link verification response frame to the station according to the link verification request frame of the station;
- the wireless terminal After successful link verification, the wireless terminal sends an association request frame to the access controller, requesting association with the access controller, and the association request frame includes a WAPI information element to determine the authentication and key management suite for the site selection. And cipher suites;
- the access controller resolves the association request frame of the site and sends an association response frame to the site.
- step 2.2 The specific steps of step 2.2) above are as follows:
- the access controller sends a CAPWAP Site Configuration Request message to the wireless terminal.
- the message includes Add Station, GB15629.il Join Station and GB15629.il Site Session Key. (Station Session Key) message element, where A in the site session key message element is set to 1 to inform the wireless terminal to close the controlled port, and only forward WAI protocol data from the corresponding site; where A is GB15629.il One of the identifiers in the site session key message element, A is used as the flag bit. If the flag is set to 1, it is used to inform the wireless terminal to open the controlled port and forward only the WAI protocol data.
- the wireless terminal sends a CAPWAP Site Configuration Response (Station Configuration Response) message to the access controller, including the Result Code message element, The result of processing the request message to the CAPWAP site configuration request.
- CAPWAP Site Configuration Response Selection Configuration Response
- step 2.3) The specific steps of step 2.3) above are as follows:
- step 2.4 The specific steps of step 2.4) above are as follows:
- the access controller sends a CAPWAP Site Configuration Request message to the wireless terminal, the message including the joining site, the GB15629.il joining site and the GB15629.il site session key message element; a MAC address, the wireless terminal opens a controlled port corresponding to the MAC address, and forwards all data from the site, including WAI protocol data and non-WAI protocol data;
- the wireless terminal point sends a CAPWAP Site Configuration Response message to the access controller, including a result code message element, for identifying the processing result of the CAPWAP Site Configuration Request message.
- step 2.5 The specific steps of step 2.5) above are as follows:
- the wireless terminal encrypts the data from the access controller and sends it to the site;
- the wireless terminal locates and forwards the data from the site.
- Step 2.5) above also includes step 2.6) accessing the unicast key update process between the controller and the site.
- step 2.6 The specific steps of step 2.6) above are as follows:
- the access controller sends a CAPWAP Site Configuration Request message to the wireless terminal, including the joining site, GB 15629.11 joining site, GB15629.il site session key and GB15629.
- Il information element message element
- the wireless terminal point sends a CAPWAP Site Configuration Response message to the access controller, which includes a result code message element for identifying the processing result of the CAPWAP Site Configuration Request message.
- steps 2.5) or 2.6) also include step 2.7) accessing the multicast key update process between the controller and the site.
- step 2.7 The specific steps of step 2.7 above are as follows:
- GB15629.11 WLAN configuration request (GB 15629.11 WLAN Configuration Request) message, which contains GB15629.il update WLAN (GB 15629.11 Update WLAN) message element, the GB15629.il update WLAN message element includes multicast session key MSK (Multicast Session Key) Key data, MSK index, MSK update start identifier, and data packet sequence number PN (Packet Number);
- the wireless terminal sends a GB 15629.11 WLAN Configuration Response (GB15629.il WLAN Configuration Response) message to the access controller, which contains the result code message element, which is used to identify the processing result of the GB15629.il WLAN configuration request message;
- the access controller sends a point to the wireless terminal.
- GB15629.11 WLAN configuration request message which includes GB15629.il update WLAN message element, the GB15629.il update WLAN message element includes MSK index and MSK update end identifier;
- the wireless terminal sends a GB15629.il WLAN configuration response message to the access controller, which contains a result code message element for identifying the processing result of the GB15629.11 WLAN configuration request message.
- the communication interaction process separates the MAC function and the WAPI function of the AP from the wireless terminal point WTP (Wireless Terminal Point) and the access controller AC (Access Controller).
- WTP implements the interaction of the real-time information required by the GB15629.il standard with the STA (Station), including the beacon frame, the response to the interrogation request frame, etc., and implements the WPI protocol, which is implemented by the AC and the STA. Real-time interaction, including associations, WAI protocols, and more.
- the communication between AC and WTP is implemented based on the CAPWAP GB15629.il binding specification.
- the division mode of this AP function is referred to as a local MAC mode.
- the present invention has the following advantages:
- the present invention provides a method for implementing WAPI and CAPWAP fusion in a local MAC mode, and realizing centralized control of the entire network AP by dividing the MAC function and the WAPI function of the AP. And management, able to meet the deployment needs of large-scale WLAN.
- Overcoming the limitations of the current autonomous network architecture based on the WAPI protocol cannot be applied to large-scale WLAN deployment requirements.
- the WAI protocol is implemented by the AC
- the WPI protocol is implemented by the WTP
- the WAPI protocol is implemented.
- the converged WLAN architecture seamlessly integrates to ensure WLAN security.
- the invention can not only meet the large-scale deployment requirements of the WLAN, but also ensure the security of the WLAN under the convergence architecture.
- FIG. 1 is a message flow diagram of implementing WAPI and CAPWAP fusion in a local MAC mode
- FIG. 2 is a flowchart of unicast key update between an AC and a STA
- FIG. 3 is a flow chart of multicast key update between the AC and the STA. detailed description
- STA passively listens to WTP beacon frames to obtain WTP related parameters, including WAPI information elements (WTP-supported authentication and key management suite, cipher suite, etc.); Or, the STA sends an inquiry request frame to the WTP, and after receiving the inquiry request frame of the STA, the WTP sends a query response frame to the STA, and the STA obtains the WTP related parameter from the WTP inquiry response frame, including the WAPI information element.
- WAPI information elements WTP-supported authentication and key management suite, cipher suite, etc.
- the WAPI information element includes an authentication and key management suite supported by WTP, a cipher suite, and the like;
- the STA sends a link verification request to the WTP to request a link verification with the WTP;
- WTP sends a link verification response frame to the STA according to the link verification request frame of the STA;
- the STA sends an association request frame to the AC, and the request is associated with the AC.
- the association request frame includes a WAPI information element to determine the authentication and key management suite, the cipher suite, and the like selected by the STA;
- the AC resolves the association request frame of the STA, and sends an association response frame to the STA;
- the AC sends a CAPWAP Site Configuration Request message to the WTP, including the joining site (the MAC address of the STA), the GB15629. il joining the site (WLAN ID), and the GB15629.
- site session key (A is set to 1) Wait for message elements.
- the A in the site session key message element is set to 1 to inform the WTP to close the controlled port, and only forward the WAI protocol data from the corresponding STA; where A is GB15629.
- the WTP sends a CAPWAP Site Configuration Response message to the AC, which contains a Result Code message element, which is used to identify the processing result of the CAPWAP Site Configuration Request message.
- the WAI authentication process between the AC and the STA includes: WTP decapsulates the WAI authentication data encapsulated according to the CAPWAP data encapsulation format from the AC, and then forwards the WAI authentication data to the STA; and wraps the WAI authentication data from the STA according to the CAPWAP data.
- the format is encapsulated and sent to the AC;
- WAI unicast key negotiation process between the AC and the STA includes: WTP pair The WAI unicast key negotiation data encapsulated by the AC according to the CAPWAP data encapsulation format is decapsulated and then forwarded to the STA; the WAI unicast key negotiation data from the STA is encapsulated according to the CAPWAP data encapsulation format and then sent to the AC;
- the AC sends a CAPWAP Site Configuration Request message to the WTP, including the joining site (the MAC address of the STA), GB15629. il joining the site (WLAN ID), GB15629. il site session key (key data), GB15629 . il information element (WAPIIE (password algorithm is WPI-SMS4)) and other message elements.
- WAPIIE password algorithm is WPI-SMS4
- the WTP opens the controlled port of the site corresponding to the MAC address, and forwards all data from the STA, including WAI protocol data and non-WAI protocol data;
- the WTP sends a CAPWAP Site Configuration Response message to the AC, which contains a Result Code message element, which is used to identify the processing result of the CAPWAP Site Configuration Request message.
- WTP encrypts data from the AC and sends it to the STA
- WTP decrypts and forwards data from the STA.
- the process of the present invention further includes the step 2.6) a unicast key update process between the AC and the STA:
- the AC sends a CAPWAP Site Configuration Request message to the WTP, where the message includes the joining site (the MAC address of the STA),
- GB15629 il join site (WLAN ID), GB15629. il site session key (unicast session key USK (Unicast Session Key) key data), GB15629. il information element ( WAPIIE (password algorithm is WPI-SMS4)) And other message elements;
- WTP sends a CAPWAP site configuration response message to the AC, which contains the result.
- the code message element is used to identify the processing result of the C APWAP site configuration request message.
- the process of the present invention further includes the step 2.7) a multicast key update process between the AC and the STA:
- the AC When the AC needs to perform multicast key update, it first sends an IEEE 802.11 WLAN configuration request message to the WTP, which includes GB15629. il updates the WLAN message element, which contains MSK key data, MSK index, MSK. Update start identifier, data packet number PN, etc.;
- the WTP sends a GB15629.11 WLAN configuration response message to the AC, which contains a result code message element for identifying the processing result of the GB15629.il WLAN configuration request message;
- the AC sends an IEEE 802.11 WLAN configuration request message to the WTP, which includes GB15629. il updates the WLAN (MSK index, MSK update end identifier) and other message elements;
- WTP sends a GB15629.il WLAN configuration response message to the AC, which contains the result code message element, which is used to identify the processing result of the GB15629.il WLAN configuration request message.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Mobile Radio Communication Systems (AREA)
- Small-Scale Networks (AREA)
Abstract
Description
以本地 MAC模式实现 WAPI与 CAPWAP融合方法 Implementing WAPI and CAPWAP fusion method in local MAC mode
本申请要求于 2009 年 2 月 27 日提交中国专利局、 申请号为 200910021417.5、 发明名称为"一种以本地 MAC模式实现 WAPI与 CAPWAP 融合的方法"的中国专利申请的优先权,其全部内容通过引用结合在本申请中。 技术领域 This application claims priority to Chinese Patent Application No. 200910021417.5, entitled "A Method for Implementing WAPI and CAPWAP Fusion in Local MAC Mode", submitted to the Chinese Patent Office on February 27, 2009. The citations are incorporated herein by reference. Technical field
本发明涉及网络应用领域, 尤其涉及一种以本地 MAC模式实现 WAPI与 CAPWAP融合的方法。 The present invention relates to the field of network applications, and in particular, to a method for implementing WAPI and CAPWAP fusion in a local MAC mode.
背景技术 Background technique
自治式体系架构的无线局域网 WLAN ( Wireless Local Area Networks ) 中 无线接入点 AP ( Access Point )作为网络上一个单独的实体, 完全部署和端接 GB15629.il 功能, 需对其进行独立管理。 目前基于无线局域网鉴别与保密基 均采用自治式体系架构, 但随着 WLAN部署规模的扩大, 这种自治式架构的 网络工作模式因其固有的缺陷已逐渐成为制约无线技术发展的障碍。 In the wireless local area network (WLAN) of the autonomous architecture, the access point AP (Access Point) acts as a separate entity on the network and fully deploys and terminates the GB15629.il function, which needs to be managed independently. At present, the autonomous system architecture is adopted based on the WLAN authentication and confidentiality base. However, with the expansion of the WLAN deployment scale, the network working mode of the autonomous architecture has gradually become an obstacle to the development of wireless technology due to its inherent defects.
首先,自治式架构的 WLAN中, AP作为网际互联协议 IP( Internet Protocol ) 可寻址设备, 需要进行独立管理, 包括监测、 配置和控制等。 在进行大规模网 络部署时, 大量的 AP将产生巨大的管理开销, 给网络造成沉重负担。 尤其是 网内 AP的配置管理方式互不相同时, 这种现象更为明显, 势必阻碍无线技术 的发展。 First, in an autonomous architecture WLAN, the AP acts as an Internet Protocol (IP) addressable device and needs to be managed independently, including monitoring, configuration, and control. When a large-scale network is deployed, a large number of APs will incur huge management overhead and impose a heavy burden on the network. Especially when the configuration and management methods of APs in the network are different from each other, this phenomenon is more obvious and will hinder the development of wireless technologies.
其次, 自治式架构的 WLAN中, 保证所有 AP配置参数的一致性存在一 定困难。 因为 AP的配置中除静态参数外, 更多的是需要动态配置的参数。 在 大规模 WLAN中, 及时更新全网 AP的动态配置的工作量非常繁重, 甚至无 法实现。 Second, in an autonomous architecture WLAN, it is difficult to ensure the consistency of all AP configuration parameters. Because AP configuration is more than static parameters, more parameters are dynamically configured. In a large-scale WLAN, the workload of dynamically updating the dynamic configuration of the AP over the entire network is very heavy or even impossible.
第三, WLAN中, 无线传输介质作为一种共享资源, 为提高网络的性能, 必须实时监测每一个 AP并根据当前共享介质的使用情况对这些 AP的配置进 行动态更新, 而手工配置与无线传输介质相关的 AP参数将耗费大量的人力、 物力。 Third, in the WLAN, the wireless transmission medium is used as a shared resource. In order to improve the performance of the network, each AP must be monitored in real time and dynamically updated according to the current usage of the shared medium, and manually configured and wirelessly transmitted. Media-related AP parameters will consume a lot of manpower and material resources.
第四, 自治式架构的 WLAN中, 安全接入网络和阻止非法 AP的加入也 较为困难。 在通常情况下, AP 的部署位置使得难以对其加以保护, 一旦 AP 被窃将造成所加载安全信息的泄漏, 对网络安全造成威胁。 Fourth, in an autonomous architecture WLAN, it is more difficult to securely access the network and prevent the joining of illegal APs. Under normal circumstances, the AP's deployment location makes it difficult to protect it once AP Theft will cause leakage of the loaded security information, posing a threat to network security.
综上所述, 自治式架构的 WLAN中, 尤其在大规模部署的情况下, 对 AP 进行监测、 配置和控制将给网络造成沉重的管理负担。 而且, 维护 AP配置的 一致性也十分困难。 此外, 无线传输介质的共享和动态特性要求网络中 AP协 作一致以争取最大的网络性能和最小的无线干扰, 这对 AP的配置管理提出了 更高的要求。安全是设计无线网络需要考虑的重要因素之一, 大规模的部署也 将给 WLAN的安全带来巨大挑战。 由此可见, 自治式体系架构 WLAN的工作 模式已无法适用大规模网络的部署需求,亟需设计基于 WAPI的会聚式 WLAN 网络体系架构,即 WAPI瘦 AP架构。目前基于无线接入点控制与配置 CAPWAP ( Control And Provisioning of Wireless Access Points )协议 IEEE 802.11绑定规 范的 WLAN不可避免地继承了 IEEE 802.11i的安全缺陷, 所以, 需要更为安 全的替代解决方案。 In summary, in the WLAN of the autonomous architecture, especially in the case of large-scale deployment, monitoring, configuring, and controlling the AP will impose a heavy management burden on the network. Moreover, maintaining the consistency of the AP configuration is also very difficult. In addition, the sharing and dynamic characteristics of the wireless transmission medium require the AP collaboration in the network to achieve maximum network performance and minimum wireless interference, which puts higher requirements on the AP configuration management. Security is one of the important factors to consider when designing a wireless network. Large-scale deployment will also pose a huge challenge to the security of WLAN. It can be seen that the autonomous architecture WLAN working mode cannot be applied to the deployment requirements of large-scale networks. It is urgent to design a WAPI-based converged WLAN network architecture, namely the WAPI thin AP architecture. Currently, WLANs based on wireless access point control and configuration CAPWAP (Control And Provisioning of Wireless Access Points) protocol IEEE 802.11 binding specification inevitably inherit the security flaws of IEEE 802.11i, so a more secure alternative solution is needed.
发明内容 Summary of the invention
本发明的目的在于克服上述自治式 WLAN网络体系架构的缺陷, 提供一 种本地媒体访问控制 MAC ( Medium Access Control )模式的将无线接入点控 制与配置 CAPWAP ( Control And Provisioning of Wireless Access Points )规范 绑定无线局域网鉴别与保密基础结构 WAPI ( WLAN Authentication and Privacy Infrastructure )的方法, 提出一种更为安全的基于 WAPI的会聚式 WLAN体系 架构的工作流程。 The purpose of the present invention is to overcome the shortcomings of the above-mentioned autonomous WLAN network architecture, and to provide a CAPWAP (Control And Provisioning of Wireless Access Points) specification in a Medium Access Control MAC (Medium Access Control) mode. A method of binding a WLAN Authentication and Privacy Infrastructure (WAPI) to propose a workflow for a more secure WAPI-based converged WLAN architecture.
本发明的技术解决方案是: The technical solution of the present invention is:
本发明提供一种以本地 MAC模式实现 WAPI与 CAPWAP融合的方法, 其特殊之处在于: 该方法包括以下步骤: The present invention provides a method for implementing WAPI and CAPWAP fusion in a local MAC mode, which is special in that the method includes the following steps:
1 )构建本地 MAC模式的步骤: 将无线接入点的 MAC功能和 WAPI功能 分别分离到无线终端点和访问控制器上; 1) Steps of constructing a local MAC mode: Separating the MAC function and the WAPI function of the wireless access point from the wireless terminal point and the access controller;
2 )在本地 MAC模式下,进行将 CAPWAP规范的绑定 WAPI的本地 MAC 模式的步骤: 2) In the local MAC mode, perform the steps of binding the WAPI local MAC mode to the CAPWAP specification:
2.1 )站点与无线终端点以及访问控制器之间进行关联连接的过程; 2.2 )访问控制器与无线终端点之间通告无线局域网鉴别基础设施 WAI ( WLAN Authentication Infrastructure )十办议开始执行的过程; 2.3 )站点与访问控制器之间执行 WAI协议的过程; 2.1) the process of associating the site with the wireless terminal point and the access controller; 2.2) the process of informing the wireless local area network authentication infrastructure WAI (WLAN Authentication Infrastructure) between the access controller and the wireless terminal point; 2.3) The process of executing the WAI protocol between the site and the access controller;
2.4 )访问控制器与无线终端点之间通告 WAI协议执行结束的过程; 2.4) Between the access controller and the wireless terminal point to announce the end of the WAI protocol execution;
2.5 )无线终端点与站点之间利用无线局域网保密基础设施 WPI ( WLAN Privacy Infrastructure )进行保密通信的过程。 2.5) The process of secure communication between the wireless terminal point and the site using the WLAN Privacy Infrastructure (WPI).
上述步骤 2.1 ) 的具体步骤如下: The specific steps of step 2.1 above are as follows:
2.1.1 )站点被动侦听无线终端点的信标帧获得包括 WAPI信息元素的无线 终端点的参数; 2.1.1) The station passively listens to the beacon frame of the wireless terminal point to obtain parameters of the wireless terminal point including the WAPI information element;
或者, 站点主动向无线终端点发送探询请求帧, 无线终端点收到站点的探 询请求帧后, 向站点发送探询响应帧, 站点从收到无线终端点的探询响应帧中 获得包括 WAPI信息元素的无线终端点的参数;所述 WAPI信息元素包括无线 终端点支持的鉴别及密钥管理套件和密码套件; Alternatively, the station actively sends a query request frame to the wireless terminal point, and after receiving the probe request frame of the station, the wireless terminal point sends a probe response frame to the station, and the station obtains the WAPI information element from the query response frame of the received wireless terminal point. a parameter of the wireless terminal point; the WAPI information element includes an authentication and key management suite and a cipher suite supported by the wireless terminal point;
2.1.2 )站点向无线终端点发送链路验证请求帧,请求与无线终端点之间的 链路验证; 2.1.2) The station sends a link verification request frame to the wireless terminal point, requesting link verification with the wireless terminal point;
2.1.3 )无线终端点根据站点的链路验证请求帧, 向站点发送链路验证响应 帧; 2.1.3) The wireless terminal point sends a link verification response frame to the station according to the link verification request frame of the station;
2.1.4 )链路验证成功后, 无线终端点向访问控制器发送关联请求帧, 请求 与访问控制器进行关联, 关联请求帧包括 WAPI信息元素, 用以确定站点选择 的鉴别及密钥管理套件和密码套件; 2.1.4) After successful link verification, the wireless terminal sends an association request frame to the access controller, requesting association with the access controller, and the association request frame includes a WAPI information element to determine the authentication and key management suite for the site selection. And cipher suites;
2.1.5 )访问控制器解析站点的关联请求帧, 向站点发送关联响应帧。 2.1.5) The access controller resolves the association request frame of the site and sends an association response frame to the site.
上述步骤 2.2 ) 的具体步骤如下: The specific steps of step 2.2) above are as follows:
2.2.1 )访问控制器向无线终端点发送 CAPWAP 站点配置请求 (Station Configuration Request )消息, 消息中包括加入站点( Add Station ), GB15629.il 加入站点 ( Add Station )和 GB15629.il站点会话密钥 ( Station Session Key ) 消息元素, 其中, 站点会话密钥消息元素中的 A被置为 1用于告知无线终端 点关闭受控端口,仅转发来自对应站点的 WAI协议数据;其中 A为 GB15629.il 站点会话密钥消息元素中的一个标识位, A作为标识位, 若标识被设置为 1 , 用于告知无线终端点打开受控端口, 仅转发 WAI协议数据。 2.2.1) The access controller sends a CAPWAP Site Configuration Request message to the wireless terminal. The message includes Add Station, GB15629.il Join Station and GB15629.il Site Session Key. (Station Session Key) message element, where A in the site session key message element is set to 1 to inform the wireless terminal to close the controlled port, and only forward WAI protocol data from the corresponding site; where A is GB15629.il One of the identifiers in the site session key message element, A is used as the flag bit. If the flag is set to 1, it is used to inform the wireless terminal to open the controlled port and forward only the WAI protocol data.
2.2.2 ) 无线终端点向访问控制器发送 CAPWAP 站点配置响应 (Station Configuration Response ) 消息, 其中包括结果码 ( Result Code ) 消息元素, 用 于标识对 CAPWAP站点配置请求消息的处理结果。 2.2.2) The wireless terminal sends a CAPWAP Site Configuration Response (Station Configuration Response) message to the access controller, including the Result Code message element, The result of processing the request message to the CAPWAP site configuration request.
上述步骤 2.3 ) 的具体步骤如下: The specific steps of step 2.3) above are as follows:
2.3.1 )访问控制器与站点之间的 WAI鉴别过程; 包括: 无线终端点对来 自访问控制器的根据 CAPWAP数据封装格式封装的 WAI鉴别数据进行拆封后 转发给站点;对来自站点的 WAI鉴别数据根据 CAPWAP数据封装格式进行封 装后发送给访问控制器; 2.3.1) accessing the WAI authentication process between the controller and the site; comprising: the wireless terminal point unpacking the WAI authentication data encapsulated according to the CAPWAP data encapsulation format from the access controller and forwarding the data to the site; The authentication data is encapsulated according to the CAPWAP data encapsulation format and sent to the access controller;
2.3.2 )访问控制器与站点之间的 WAI单播密钥协商过程; 包括: 无线终 端点对来自访问控制器的根据 CAPWAP数据封装格式封装的 WAI单播密钥协 商数据进行拆封后转发给站点; 对来自站点的 WAI 单播密钥协商数据根据 CAPWAP数据封装格式进行封装后发送给访问控制器; 2.3.2) accessing the WAI unicast key negotiation process between the controller and the site; comprising: the wireless terminal point unpacking and forwarding the WAI unicast key negotiation data encapsulated according to the CAPWAP data encapsulation format from the access controller To the site; the WAI unicast key negotiation data from the site is encapsulated according to the CAPWAP data encapsulation format and sent to the access controller;
2.3.3 )访问控制器与站点之间的 WAI组播密钥通告过程; 包括: 无线终 端点对来自访问控制器的根据 CAPWAP数据封装格式封装的 WAI组播密钥通 告数据进行拆封后转发给站点; 对来自站点的 WAI 组播密钥通告数据根据 CAPWAP数据封装格式进行封装后发送给访问控制器。 2.3.3) accessing the WAI multicast key advertisement process between the controller and the site; comprising: the wireless terminal point unpacking and forwarding the WAI multicast key advertisement data encapsulated according to the CAPWAP data encapsulation format from the access controller To the site; WAI multicast key advertisement data from the site is encapsulated according to the CAPWAP data encapsulation format and sent to the access controller.
上述步骤 2.4 ) 的具体步骤如下: The specific steps of step 2.4) above are as follows:
2.4.1 )访问控制器向无线终端点发送 CAPWAP站点配置请求消息, 消息 中包含加入站点、 GB15629.il加入站点和 GB15629.il站点会话密钥消息元素; 才艮据加入站点消息元素中站点的 MAC地址, 无线终端点打开与所述 MAC地 址对应的受控端口,转发来自该站点的所有数据,包括 WAI协议数据和非 WAI 协议数据; 2.4.1) The access controller sends a CAPWAP Site Configuration Request message to the wireless terminal, the message including the joining site, the GB15629.il joining site and the GB15629.il site session key message element; a MAC address, the wireless terminal opens a controlled port corresponding to the MAC address, and forwards all data from the site, including WAI protocol data and non-WAI protocol data;
2.4.2 )无线终端点向访问控制器发送 CAPWAP站点配置响应消息, 其中 包括结果码消息元素, 用于标识对 CAPWAP站点配置请求消息的处理结果。 2.4.2) The wireless terminal point sends a CAPWAP Site Configuration Response message to the access controller, including a result code message element, for identifying the processing result of the CAPWAP Site Configuration Request message.
上述步骤 2.5 ) 的具体步骤如下: The specific steps of step 2.5) above are as follows:
2.5.1 )无线终端点加密来自访问控制器的数据并发送给站点; 2.5.1) The wireless terminal encrypts the data from the access controller and sends it to the site;
2.5.2 )无线终端点解密并转发来自站点的数据。 2.5.2) The wireless terminal locates and forwards the data from the site.
上述步骤 2.5 )之后还包括步骤 2.6 )访问控制器与站点之间的单播密钥更 新过程。 Step 2.5) above also includes step 2.6) accessing the unicast key update process between the controller and the site.
上述步骤 2.6 ) 的具体步骤如下: The specific steps of step 2.6) above are as follows:
2.6.1 ) 当需要进行单播密钥更新时, 访问控制器与站点之间执行 WAI单 播密钥协商过程; 2.6.1) When a unicast key update is required, the WAI is executed between the access controller and the site. Broadcast key negotiation process;
2.6.2 ) 当 WAI单播密钥协商过程完成后, 访问控制器向无线终端点发送 CAPWAP站点配置请求消息, 消息中包含加入站点、 GB 15629.11加入站点、 GB15629.il站点会话密钥和 GB15629.il信息元素消息元素; 2.6.2) After the WAI unicast key negotiation process is completed, the access controller sends a CAPWAP Site Configuration Request message to the wireless terminal, including the joining site, GB 15629.11 joining site, GB15629.il site session key and GB15629. Il information element message element;
2.6.3 )无线终端点向访问控制器发送 CAPWAP站点配置响应消息, 其中 包含结果码消息元素, 用于标识对 CAPWAP站点配置请求消息的处理结果。 2.6.3) The wireless terminal point sends a CAPWAP Site Configuration Response message to the access controller, which includes a result code message element for identifying the processing result of the CAPWAP Site Configuration Request message.
上述步骤 2.5 )或 2.6 )之后还包括步骤 2.7 )访问控制器与站点之间的组 播密钥更新过程。 The above steps 2.5) or 2.6) also include step 2.7) accessing the multicast key update process between the controller and the site.
上述步骤 2.7 ) 的具体步骤如下: The specific steps of step 2.7 above are as follows:
2.7.1 ) 当访问控制器需要进行组播密钥更新时, 首先向无线终端点发送 2.7.1) When the access controller needs to perform multicast key update, first send to the wireless terminal
GB15629.11WLAN配置请求( GB 15629.11 WLAN Configuration Request )消息, 其中包含 GB15629.il 更新 WLAN(GB 15629.11 Update WLAN)消息元素, 该 GB15629.il更新 WLAN消息元素中包括组播会话密钥 MSK( Multicast Session Key ) 密钥数据、 MSK索引、 MSK更新开始标识和数据分组序号 PN ( Packet Number ); GB15629.11 WLAN configuration request (GB 15629.11 WLAN Configuration Request) message, which contains GB15629.il update WLAN (GB 15629.11 Update WLAN) message element, the GB15629.il update WLAN message element includes multicast session key MSK (Multicast Session Key) Key data, MSK index, MSK update start identifier, and data packet sequence number PN (Packet Number);
2.7.2 ) 无线终端点向访问控制器发送 GB 15629.11 WLAN 配置响应 ( GB15629.il WLAN Configuration Response ) 消息, 其中包含结果码消息元 素, 用于标识对 GB15629.il WLAN配置请求消息的处理结果; 2.7.2) The wireless terminal sends a GB 15629.11 WLAN Configuration Response (GB15629.il WLAN Configuration Response) message to the access controller, which contains the result code message element, which is used to identify the processing result of the GB15629.il WLAN configuration request message;
2.7.3 )访问控制器与站点之间执行 WAI组播密钥通告过程; 2.7.3) Performing a WAI multicast key notification process between the access controller and the site;
2.7.4 ) 当 WAI组播密钥通告过程完成后, 访问控制器向无线终端点发送 2.7.4) When the WAI multicast key advertisement process is completed, the access controller sends a point to the wireless terminal.
GB15629.11WLAN配置请求消息, 其中包括 GB15629.il更新 WLAN消息元 素, 该 GB15629.il更新 WLAN消息元素包括 MSK索引和 MSK更新结束标 识; GB15629.11 WLAN configuration request message, which includes GB15629.il update WLAN message element, the GB15629.il update WLAN message element includes MSK index and MSK update end identifier;
2.7.5 )无线终端点向访问控制器发送 GB15629.il WLAN配置响应消息, 其中包含结果码消息元素, 用于标识对 GB15629.11WLAN配置请求消息的处 理结果。 之间的通信交互流程, 将 AP的 MAC功能和 WAPI功能分离到无线终端点 WTP ( Wireless Terminal Point )和访问控制器 AC ( Access Controller )上, 由 WTP实现与站点 STA ( Station )之间的 GB15629.il标准要求的实时性信息的 交互, 包括信标帧、 对探询请求帧的响应等, 并实现 WPI协议, 由 AC实现 与 STA之间的非实时性交互, 包括关联、 WAI 协议等。 并基于 CAPWAP GB15629.il绑定规范实现 AC与 WTP之间的通信。 将这种 AP功能的划分模 式称为本地 MAC模式。 本发明与现有技术相比具有如下优点: 本发明提出了 一种以本地 MAC模式实现 WAPI与 CAPWAP融合的方法,通过将 AP的 MAC 功能以及 WAPI功能进行划分, 实现对全网 AP的集中控制和管理, 能够满足 大规模 WLAN的部署需求。 克服了目前基于 WAPI协议的自治式网络架构无 法适用大规模 WLAN部署需求的局限性。 它采用分离 MAC功能的模式, 实 现 AC对 WTP的统一监测、 配置和控制, 从而达到对 WLAN中 WTP进行集 中管理的目的; 采用由 AC实现 WAI协议, WTP实现 WPI协议的方式, 将 WAPI协议与会聚式 WLAN体系架构无缝融合, 能够保障 WLAN的安全。 本 发明不仅能够满足 WLAN的大规模部署需求, 而且能够保证会聚式体系架构 下 WLAN的安全性。 附图说明 2.7.5) The wireless terminal sends a GB15629.il WLAN configuration response message to the access controller, which contains a result code message element for identifying the processing result of the GB15629.11 WLAN configuration request message. The communication interaction process separates the MAC function and the WAPI function of the AP from the wireless terminal point WTP (Wireless Terminal Point) and the access controller AC (Access Controller). WTP implements the interaction of the real-time information required by the GB15629.il standard with the STA (Station), including the beacon frame, the response to the interrogation request frame, etc., and implements the WPI protocol, which is implemented by the AC and the STA. Real-time interaction, including associations, WAI protocols, and more. The communication between AC and WTP is implemented based on the CAPWAP GB15629.il binding specification. The division mode of this AP function is referred to as a local MAC mode. Compared with the prior art, the present invention has the following advantages: The present invention provides a method for implementing WAPI and CAPWAP fusion in a local MAC mode, and realizing centralized control of the entire network AP by dividing the MAC function and the WAPI function of the AP. And management, able to meet the deployment needs of large-scale WLAN. Overcoming the limitations of the current autonomous network architecture based on the WAPI protocol cannot be applied to large-scale WLAN deployment requirements. It adopts the mode of separating the MAC function, realizes the unified monitoring, configuration and control of the AC to the WTP, so as to achieve the purpose of centralized management of the WTP in the WLAN. The WAI protocol is implemented by the AC, the WPI protocol is implemented by the WTP, and the WAPI protocol is implemented. The converged WLAN architecture seamlessly integrates to ensure WLAN security. The invention can not only meet the large-scale deployment requirements of the WLAN, but also ensure the security of the WLAN under the convergence architecture. DRAWINGS
图 1为以本地 MAC模式实现 WAPI与 CAPWAP融合的消息流程图; 图 2为 AC与 STA之间的单播密钥更新流程图; FIG. 1 is a message flow diagram of implementing WAPI and CAPWAP fusion in a local MAC mode; FIG. 2 is a flowchart of unicast key update between an AC and a STA;
图 3为 AC与 STA之间的组播密钥更新流程图。 具体实施方式 Figure 3 is a flow chart of multicast key update between the AC and the STA. detailed description
参见图 1 , 根据本发明的优选实施例, 其具体方法如下: Referring to Figure 1, in accordance with a preferred embodiment of the present invention, the specific method is as follows:
1 ) 构建本地 MAC模式: 将 AP的 MAC功能和 WAPI功能分离到 WTP和 AC上; 1) Build a local MAC mode: Separate the MAC function and WAPI function of the AP to WTP and AC;
2 ) 在本地 MAC模式下, 实现将 CAPWAP规范绑定 WAPI的本地 2) In the local MAC mode, implement the local binding of the CAPWAP specification to WAPI.
MAC模式; MAC mode;
2.1 ) STA与 WTP以及 AC之间的关联连接过程; 2.1) the process of association between STA and WTP and AC;
2.1.1 )STA被动侦听 WTP的信标帧获得 WTP的相关参数,包括 WAPI 信息元素 (WTP支持的鉴别及密钥管理套件、 密码套件等); 或者, STA主动向 WTP发送探询请求帧, WTP收到 STA的探询请 求帧后, 向 STA发送探询响应帧, STA从收到 WTP的探询响应帧中获 得 WTP的相关参数, 包括 WAPI信息元素; 2.1.1) STA passively listens to WTP beacon frames to obtain WTP related parameters, including WAPI information elements (WTP-supported authentication and key management suite, cipher suite, etc.); Or, the STA sends an inquiry request frame to the WTP, and after receiving the inquiry request frame of the STA, the WTP sends a query response frame to the STA, and the STA obtains the WTP related parameter from the WTP inquiry response frame, including the WAPI information element.
其中, WAPI信息元素包括 WTP支持的鉴别及密钥管理套件、 密码 套件等; The WAPI information element includes an authentication and key management suite supported by WTP, a cipher suite, and the like;
2.1.2 ) STA向 WTP发送链路验证请求, 请求与 WTP之间的链路验 证; 2.1.2) The STA sends a link verification request to the WTP to request a link verification with the WTP;
2.1.3 ) WTP根据 STA的链路验证请求帧, 向 STA发送链路验证响 应帧; 2.1.3) WTP sends a link verification response frame to the STA according to the link verification request frame of the STA;
2.1.4 )链路验证成功后, STA向 AC发送关联请求帧, 请求与 AC进 行关联, 关联请求帧包含 WAPI信息元素确定 STA选择的鉴别及密钥管 理套件、 密码套件等; 2.1.4) After the link verification succeeds, the STA sends an association request frame to the AC, and the request is associated with the AC. The association request frame includes a WAPI information element to determine the authentication and key management suite, the cipher suite, and the like selected by the STA;
2.1.5 ) AC解析 STA的关联请求帧, 向 STA发送关联响应帧; 2.1.5) The AC resolves the association request frame of the STA, and sends an association response frame to the STA;
2.2 ) AC与 WTP之间 WAI协议开始执行的通告过程; 2.2) The notification process between the AC and WTP where the WAI protocol begins to be executed;
2.2.1 ) AC向 WTP发送 CAPWAP站点配置请求消息, 消息中包含加 入站点 ( STA 的 MAC 地址)、 GB15629. il 加入站点 ( WLAN ID )、 GB15629. i l站点会话密钥 (A被置为 1 ) 等消息元素。 其中, 站点会话 密钥消息元素中的 A被置为 1用于告知 WTP关闭受控端口,仅转发来自 对应 STA的 WAI协议数据; 其中 A为 GB15629. il站点会话密钥消息元素 中的一个标识位, A作为标识位, 若标识被设置为 1 , 用于告知无线终端点打 开受控端口, 仅转发 WAI协议数据; 2.2.1) The AC sends a CAPWAP Site Configuration Request message to the WTP, including the joining site (the MAC address of the STA), the GB15629. il joining the site (WLAN ID), and the GB15629. il site session key (A is set to 1) Wait for message elements. The A in the site session key message element is set to 1 to inform the WTP to close the controlled port, and only forward the WAI protocol data from the corresponding STA; where A is GB15629. il one of the site session key message elements Bit, A as the flag bit, if the flag is set to 1, it is used to inform the wireless terminal to open the controlled port, and only forward the WAI protocol data;
2.2.2 ) WTP向 AC发送 CAPWAP站点配置响应消息, 其中包含结果 码消息元素, 用于标识对 CAPWAP站点配置请求消息的处理结果。 2.2.2) The WTP sends a CAPWAP Site Configuration Response message to the AC, which contains a Result Code message element, which is used to identify the processing result of the CAPWAP Site Configuration Request message.
2.3 ) STA与 AC之间 WAI协议的执行过程; 2.3) The execution process of the WAI protocol between the STA and the AC;
2.3.1 ) AC与 STA之间的 WAI鉴别过程; 包括: WTP对来自 AC的 根据 CAPWAP 数据封装格式封装的 WAI 鉴别数据进行拆封后转发给 STA; 对来自 STA的 WAI鉴别数据根据 CAPWAP数据封装格式进行封 装后发送给 AC; 2.3.1) The WAI authentication process between the AC and the STA; the method includes: WTP decapsulates the WAI authentication data encapsulated according to the CAPWAP data encapsulation format from the AC, and then forwards the WAI authentication data to the STA; and wraps the WAI authentication data from the STA according to the CAPWAP data. The format is encapsulated and sent to the AC;
2.3.2 ) AC与 STA之间的 WAI单播密钥协商过程; 包括: WTP对来 自 AC的根据 CAPWAP数据封装格式封装的 WAI单播密钥协商数据进行 拆封后转发给 STA;对来自 STA的 WAI单播密钥协商数据根据 CAPWAP 数据封装格式进行封装后发送给 AC; 2.3.2) WAI unicast key negotiation process between the AC and the STA; includes: WTP pair The WAI unicast key negotiation data encapsulated by the AC according to the CAPWAP data encapsulation format is decapsulated and then forwarded to the STA; the WAI unicast key negotiation data from the STA is encapsulated according to the CAPWAP data encapsulation format and then sent to the AC;
2.3.3 ) AC与 STA之间的 WAI组播密钥通告过程; 包括: WTP对来 自 AC的根据 CAPWAP数据封装格式封装的 WAI组播密钥通告数据进行 拆封后转发给 STA;对来自 STA的 WAI组播密钥通告数据根据 CAPWAP 数据封装格式进行封装后发送给 AC。 2.3.3) The WAI multicast key advertisement process between the AC and the STA; the method includes: WTP decapsulating the WAI multicast key advertisement data encapsulated according to the CAPWAP data encapsulation format from the AC, and then forwarding the data to the STA; The WAI multicast key advertisement data is encapsulated according to the CAPWAP data encapsulation format and sent to the AC.
2.4 ) AC与 WTP之间 WAI协议执行结束的通告过程; 2.4) The notification process for the end of the WAI protocol between AC and WTP;
2.4.1 ) AC向 WTP发送 CAPWAP站点配置请求消息, 消息中包含加 入站点 ( STA 的 MAC 地址)、 GB15629. il 加入站点 ( WLAN ID )、 GB15629. il站点会话密钥 (密钥数据)、 GB15629. il信息元素 (WAPIIE (密码算法为 WPI-SMS4 ) ) 等消息元素。 根据加入站点消息元素中 STA 的 MAC地址, WTP打开与该 MAC地址对应站点的受控端口, 转发来自 该 STA的所有数据, 包括 WAI协议数据和非 WAI协议数据; 2.4.1) The AC sends a CAPWAP Site Configuration Request message to the WTP, including the joining site (the MAC address of the STA), GB15629. il joining the site (WLAN ID), GB15629. il site session key (key data), GB15629 . il information element (WAPIIE (password algorithm is WPI-SMS4)) and other message elements. According to the MAC address of the STA in the joining site message element, the WTP opens the controlled port of the site corresponding to the MAC address, and forwards all data from the STA, including WAI protocol data and non-WAI protocol data;
2.4.2 ) WTP向 AC发送 CAPWAP站点配置响应消息, 其中包含结果 码消息元素, 用于标识对 CAPWAP站点配置请求消息的处理结果。 2.4.2) The WTP sends a CAPWAP Site Configuration Response message to the AC, which contains a Result Code message element, which is used to identify the processing result of the CAPWAP Site Configuration Request message.
2.5 ) WTP与 STA之间利用 WPI进行保密通信的过程; 2.5) The process of using WPI for secure communication between WTP and STA;
2.5.1 ) WTP加密来自 AC的数据并发送给 STA; 2.5.1) WTP encrypts data from the AC and sends it to the STA;
2.5.2 ) WTP解密并转发来自 STA的数据。 2.5.2) WTP decrypts and forwards data from the STA.
参见图 2, 此外, 本发明流程中还包括步骤 2.6 ) AC与 STA之间的 单播密钥更新过程: Referring to FIG. 2, in addition, the process of the present invention further includes the step 2.6) a unicast key update process between the AC and the STA:
2.6.1 ) 当需要进行单播密钥更新时, AC与 STA之间执行 WAI单播 密钥协商过程; 2.6.1) When a unicast key update is required, the WAI unicast key negotiation process is performed between the AC and the STA.
2.6.2 )当 WAI单播密钥协商过程完成后, AC向 WTP发送 CAPWAP 站点配置请求消息, 消息中包含加入站点 ( STA 的 MAC 地址)、 2.6.2) After the WAI unicast key negotiation process is completed, the AC sends a CAPWAP Site Configuration Request message to the WTP, where the message includes the joining site (the MAC address of the STA),
GB15629. il加入站点 ( WLAN ID )、 GB15629. il站点会话密钥 (单播会 话密钥 USK ( Unicast Session Key ) 密钥数据)、 GB15629. il 信息元素 ( WAPIIE (密码算法为 WPI-SMS4 ) ) 等消息元素; GB15629. il join site (WLAN ID), GB15629. il site session key (unicast session key USK (Unicast Session Key) key data), GB15629. il information element ( WAPIIE (password algorithm is WPI-SMS4)) And other message elements;
2.6.3 ) WTP向 AC发送 CAPWAP站点配置响应消息, 其中包含结果 码消息元素, 用于标识对 C APWAP站点配置请求消息的处理结果。 2.6.3) WTP sends a CAPWAP site configuration response message to the AC, which contains the result. The code message element is used to identify the processing result of the C APWAP site configuration request message.
参见图 3 , 此外, 本发明流程中还包括步骤 2.7 ) AC与 STA之间的 组播密钥更新过程: Referring to FIG. 3, in addition, the process of the present invention further includes the step 2.7) a multicast key update process between the AC and the STA:
2.7.1 )当 AC需要进行组播密钥更新时,首先向 WTP发送 IEEE 802.11 WLAN配置请求消息, 其中包含 GB15629. il更新 WLAN消息元素, 该 消息元素中包含 MSK密钥数据、 MSK索引、 MSK更新开始标识、 数据 分组序号 PN等信息; 2.7.1) When the AC needs to perform multicast key update, it first sends an IEEE 802.11 WLAN configuration request message to the WTP, which includes GB15629. il updates the WLAN message element, which contains MSK key data, MSK index, MSK. Update start identifier, data packet number PN, etc.;
2.7.2 ) WTP向 AC发送 GB15629.11WLAN配置响应消息, 其中包含 结果码消息元素 ,用于标识对 GB15629. il WLAN配置请求消息的处理结 果; 2.7.2) The WTP sends a GB15629.11 WLAN configuration response message to the AC, which contains a result code message element for identifying the processing result of the GB15629.il WLAN configuration request message;
2.7.3 ) AC与 STA之间执行 WAI组播密钥通告过程; 2.7.3) Performing the WAI multicast key notification process between the AC and the STA;
2.7.4 )当 WAI组播密钥通告过程完成后, AC向 WTP发送 IEEE 802.11 WLAN配置请求消息, 其中包含 GB15629. il更新 WLAN ( MSK索引、 MSK更新结束标识 ) 等消息元素; 2.7.4) After the WAI multicast key advertisement process is completed, the AC sends an IEEE 802.11 WLAN configuration request message to the WTP, which includes GB15629. il updates the WLAN (MSK index, MSK update end identifier) and other message elements;
2.7.5 ) WTP向 AC发送 GB15629. il WLAN配置响应消息, 其中包 含结果码消息元素,用于标识对 GB15629. il WLAN配置请求消息的处理 结果。 2.7.5) WTP sends a GB15629.il WLAN configuration response message to the AC, which contains the result code message element, which is used to identify the processing result of the GB15629.il WLAN configuration request message.
以上对本发明所提供的一种以本地 MAC模式实现 WAPI与 CAPWAP 融合的方法, 进行了详细介绍, 本文中应用了具体个例对本发明的原理 及实施方式进行了阐述, 以上实施例的说明只是用于帮助理解本发明的 方法及其核心思想; 同时, 对于本领域的一般技术人员, 依据本发明的 思想, 在具体实施方式及应用范围上均会有改变之处。 综上所述, 本说明书内 容不应理解为对本发明的限制。 The method for implementing WAPI and CAPWAP fusion in the local MAC mode is introduced in detail. The principles and implementation manners of the present invention are described in the following examples. The description of the above embodiments is only used. In order to facilitate the understanding of the method of the present invention and its core idea, at the same time, there will be changes in the specific embodiments and application scopes according to the idea of the present invention. In conclusion, the contents of this specification are not to be construed as limiting the invention.
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN2009100214175A CN101577916B (en) | 2009-02-27 | 2009-02-27 | A Method of Converging WAPI and CAPWAP in Local MAC Mode |
| CN200910021417.5 | 2009-02-27 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2010096996A1 true WO2010096996A1 (en) | 2010-09-02 |
Family
ID=41272662
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2009/075537 Ceased WO2010096996A1 (en) | 2009-02-27 | 2009-12-14 | Method for realizing integration of wapi and capwap in local mac mode |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN101577916B (en) |
| WO (1) | WO2010096996A1 (en) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| RU2572825C1 (en) * | 2012-01-18 | 2016-01-20 | Хуавей Текнолоджиз Ко., Лтд. | METHOD AND APPARATUS FOR Wi-Fi TERMINAL FOR ACCESSING DIFFERENT SERVICE DOMAINS |
Families Citing this family (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101646170B (en) * | 2009-02-27 | 2011-08-17 | 西安西电捷通无线网络通信股份有限公司 | Method for realizing integration of WAPI and CAPWAP by separation MAC mode |
| CN101577916B (en) * | 2009-02-27 | 2011-07-06 | 西安西电捷通无线网络通信股份有限公司 | A Method of Converging WAPI and CAPWAP in Local MAC Mode |
| CN102281594B (en) | 2011-09-06 | 2014-06-11 | 华为技术有限公司 | Message forwarding method, wireless access point (AP) and message forwarding system |
| CN102547850B (en) * | 2012-02-22 | 2014-04-09 | 深圳市共进电子股份有限公司 | Method for realizing CAPWAP (Control and Provisioning of Wireless Access Points) tunnel |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101013940A (en) * | 2006-12-22 | 2007-08-08 | 西安电子科技大学 | Identity authentication method compatible 802.11i with WAPI |
| US20080072047A1 (en) * | 2006-09-20 | 2008-03-20 | Futurewei Technologies, Inc. | Method and system for capwap intra-domain authentication using 802.11r |
| CN101247295A (en) * | 2007-02-13 | 2008-08-20 | 华为技术有限公司 | A method and device for obtaining access controller information in a wireless local area network |
| CN101577978A (en) * | 2009-02-27 | 2009-11-11 | 西安西电捷通无线网络通信有限公司 | Method for realizing convergence WAPI network architecture in local MAC mode |
| CN101577916A (en) * | 2009-02-27 | 2009-11-11 | 西安西电捷通无线网络通信有限公司 | Method for realizing convergence of WAPI and CAPWAP in local MAC mode |
Family Cites Families (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US7426550B2 (en) * | 2004-02-13 | 2008-09-16 | Microsoft Corporation | Extensible wireless framework |
| CN100369434C (en) * | 2006-07-31 | 2008-02-13 | 西安西电捷通无线网络通信有限公司 | Method of Realizing Virtual Local Area Network Based on WAPI System in Wireless Local Area Network |
| CN100583752C (en) * | 2006-11-30 | 2010-01-20 | 北京中电华大电子设计有限责任公司 | WAPI and CCMP coexistence method and device in 802.11 chip |
-
2009
- 2009-02-27 CN CN2009100214175A patent/CN101577916B/en not_active Expired - Fee Related
- 2009-12-14 WO PCT/CN2009/075537 patent/WO2010096996A1/en not_active Ceased
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20080072047A1 (en) * | 2006-09-20 | 2008-03-20 | Futurewei Technologies, Inc. | Method and system for capwap intra-domain authentication using 802.11r |
| CN101013940A (en) * | 2006-12-22 | 2007-08-08 | 西安电子科技大学 | Identity authentication method compatible 802.11i with WAPI |
| CN101247295A (en) * | 2007-02-13 | 2008-08-20 | 华为技术有限公司 | A method and device for obtaining access controller information in a wireless local area network |
| CN101577978A (en) * | 2009-02-27 | 2009-11-11 | 西安西电捷通无线网络通信有限公司 | Method for realizing convergence WAPI network architecture in local MAC mode |
| CN101577916A (en) * | 2009-02-27 | 2009-11-11 | 西安西电捷通无线网络通信有限公司 | Method for realizing convergence of WAPI and CAPWAP in local MAC mode |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| RU2572825C1 (en) * | 2012-01-18 | 2016-01-20 | Хуавей Текнолоджиз Ко., Лтд. | METHOD AND APPARATUS FOR Wi-Fi TERMINAL FOR ACCESSING DIFFERENT SERVICE DOMAINS |
Also Published As
| Publication number | Publication date |
|---|---|
| CN101577916A (en) | 2009-11-11 |
| CN101577916B (en) | 2011-07-06 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2010096997A1 (en) | Method for implementing a convergent wireless local area network (wlan) authentication and privacy infrastructure (wapi) network architecture in a local mac mode | |
| CN102461062B (en) | For system and the equipment of Proactive authentication | |
| CN102137395B (en) | Method, device and system for configuring access device | |
| TWI713614B (en) | Methods and apparatus for wireless communication using a security model to support multiple connectivity and service contexts | |
| CN102137401B (en) | WLAN centralization 802.1X authentication methods and device and system | |
| AU2004244634A1 (en) | Facilitating 802.11 roaming by pre-establishing session keys | |
| CN101557592A (en) | STA roaming switching method for completing WPI by AC in convergent-type WLAN and system thereof | |
| CN102823280A (en) | Authentication key generation arrangement | |
| CN101335621B (en) | 802.11i key management method | |
| CN101990202A (en) | Method for updating user policy and application server | |
| CN101562811B (en) | STA roaming switching method when WPI is finished by WTP in convergence type WLAN and system thereof | |
| WO2021031055A1 (en) | Communication method and device | |
| WO2010096995A1 (en) | Method for realizing convergent wapi network architecture with separate mac mode | |
| CN1681239B (en) | Method for supporting multiple safe mechanism in wireless local network system | |
| WO2010096996A1 (en) | Method for realizing integration of wapi and capwap in local mac mode | |
| WO2010096998A1 (en) | Method for realizing convergent wapi network architecture with split mac mode | |
| CN101288063A (en) | Wireless Device Discovery and Configuration | |
| WO2010097003A1 (en) | Method for realizing integration of wapi and capwap by split mac mode | |
| WO2010097004A1 (en) | Method for realizing integration of wapi and capwap by separated mac mode | |
| WO2025113396A1 (en) | Communication method and apparatus | |
| WO2022067827A1 (en) | Key derivation method and apparatus, and system | |
| CN101557591B (en) | STA switching method for completing WPI by WTP in convergent-type WLAN and system thereof |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 09840664 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 09840664 Country of ref document: EP Kind code of ref document: A1 |