论文部分内容阅读
文章主要研究了无线局域网国家标准GB15629.11中的安全接入技术,并介绍了其中的一种重要的鉴别协议——证书鉴别。该标准包含全新的WAPI(WLANAuthenticationandPrivacyInfrastructure)安全机制,这种安全机制由WAI(WLANAuthenticationInfras-tructure)和WPI(WLANPrivacyInfrastructure)两部分组成。WAI和WPI分别实现用户身份的鉴别和传输数据的加密。WAI的证书鉴别过程,实现了BSS中的STA与AP的双向鉴别,对于采用“假”AP的攻击方式具有很强的抵御能力。WPI中的会话密钥没有在信道上进行传输,而且在通信一段时间或者交换一定数量的数据之后,STA和AP之间可以重新协商会话密钥。从而验证了WAPI能为用户的WLAN系统提供全面的安全保护。
This paper mainly studies the security access technology in the national standard of wireless LAN GB15629.11, and introduces one of the important authentication protocols - certificate authentication. The standard includes a new WAPI (WLANAuthenticationandPrivacyInfrastructure) security mechanism, this security mechanism by the WAI (WLANAuthenticationInfras-tructure) and WPI (WLANPrivacyInfrastructure) in two parts. WAI and WPI, respectively, to achieve the identity of the user authentication and transmission of data encryption. WAI certificate authentication process, to achieve the BSS in the two-way identification of APs and APs, with “false” AP attack has a strong resistance. The session key in the WPI is not transmitted on the channel, and the session key can be renegotiated between the STA and the AP after some time of communication or exchange of a certain amount of data. This verifies that WAPI provides comprehensive security protection for users’ WLAN systems.