Research on the Network Architecture of Secure Power Wireless Local Area Network Based on WAPI and SDN
Abstract
In smart-grid WLANs, a terminal is not fully secured once it has merely passed wireless access authentication. The more difficult part is how the authentication result is carried forward into service isolation, forwarding control, bandwidth allocation, and security operation. In many conventional WLAN deployments, these functions are configured in separate systems, so terminals for distribution automation, electricity information collection, inspection robots, and other power services may still depend on similar access and management policies. This separation also makes burst traffic and O&M fault tracing harder to handle. To deal with this coupling problem, this study designs a secure power WLAN architecture that combines Wireless Local Area Network Authentication and Privacy Infrastructure (WAPI) with Software-Defined Networking (SDN). WAPI provides public-key-based two-way authentication, while SDN supplies centralized control through control-forwarding separation. In the architecture, the SDN controller manages WAPI servers, AP rules, and network resources together. Security domains and service domains are isolated by VLANs, and OpenFlow-supported WAPI-APs are used in the data layer to keep authenticated access, encrypted transmission, and flexible forwarding under the same control logic. A security-resource linkage module maps WAPI authentication results to SDN resource policies, so trusted power terminals can obtain service-specific access permissions and bandwidth guarantees. For typical power scenarios, differentiated WAPI policies and a “detection-alarm-disposal” monitoring loop are also introduced. The experimental results show end-to-end latency below 5 ms, throughput above 93%, and packet loss below 7%; unauthorized access alarms are reduced by 94.8% after WAPI-based protection is enabled. These results suggest that using WAPI authentication semantics as an input to SDN policy control can improve both access security and operational manageability in power WLANs.