5GMEC deployment platform based on power business characteristics

Through the 5GMEC deployment platform based on the characteristics of power business, the problems of architectural rigidity, resource fragmentation and weak security of power MEC deployment solutions have been solved, achieving high matching and flexible deployment with power grid business, and improving the security and efficiency of power data diversion and application.

CN120659068APending Publication Date: 2025-09-16STATE GRID HENAN INFORMATION & TELECOMM CO
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510566543.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-30
Publication Date
2025-09-16

AI Technical Summary

Technical Problem

Existing power MEC deployment solutions have problems such as rigid architecture, fragmented resources, and weak security. They are unable to adapt to the layered and graded characteristics of power services and have a low degree of match with grid business needs.

Method used

The 5GMEC deployment platform based on the characteristics of power business is adopted, including the MEC three-level cloud-edge collaborative architecture, UPF collaboration mechanism, power facility integration module, security protection system and business diversion strategy. Through layered and graded processing, optimal resource allocation, multi-dimensional threat coverage and business priority scheduling, flexible deployment and high security are achieved.

Benefits of technology

It achieves a high degree of matching with the business needs of the power grid and autonomous and controllable security management, enhances the security of business transmission and deployment flexibility, and improves the level of power data diversion and application lightweighting.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120659068A_ABST
    Figure CN120659068A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of 5GMEC deployment, and relates to a 5GMEC deployment platform based on power business characteristics. The deployment platform comprises an MEC three-level cloud edge collaboration architecture, a UPF collaboration mechanism, an electric power facility fusion module, a safety protection system and a service distribution strategy. The MEC three-level cloud edge collaborative architecture is a layered architecture composed of an access layer, an edge layer and a center layer. The UPF collaboration mechanism realizes priority scheduling of three types of services through network slice identifiers; the electric power facility fusion module physically fuses the MEC node and the electric power infrastructure; the security protection system adopts a layered defense mechanism to perform multi-dimensional threat coverage; according to the service distribution strategy, classification processing is carried out on power services based on 5G network slices, and local traffic unloading and non-local traffic return are realized. According to the invention, flexible deployment and configuration can be carried out according to power business requirements, and the matching degree with power grid business requirements is high; management is autonomous and controllable, a security management strategy is customized, illegal access is prevented, and service transmission security is enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of 5GMEC deployment, and in particular relates to a 5GMEC deployment platform based on power business characteristics. Background Art

[0002] With the acceleration of the construction of new power systems, power services are showing strong real-time, high concurrency, and multimodal characteristics. The traditional centralized cloud computing architecture has excessive instruction delays due to the large number of transmission hops and the circuitous core network. Although MEC technology optimizes business processing efficiency through cloud-edge collaboration, the existing power MEC deployment still has significant defects: the architecture is rigid, and most solutions use a single-layer MEC deployment (such as only campus-level UPF), which cannot adapt to the hierarchical and hierarchical management and control characteristics of power services (local processing of control, regional aggregation of video, and global coordination of collection); resources are fragmented, and the UPF functions of each level of DC (access / edge / center) are redundantly configured, lacking a dedicated UPF and shared UPF collaboration mechanism; security is weak, cross-security domain interaction, reliance on general firewalls, and no layered dynamic encryption system is built for industrial protocols (video streams, collected data), making it difficult to defend against APT attacks and data leakage risks.

[0003] Therefore, whether a 5GMEC deployment platform based on power business characteristics can be provided that can be flexibly deployed and configured according to power business needs and has a high degree of matching with grid business needs is a technical problem that needs to be solved urgently in the present invention. Summary of the Invention

[0004] In view of this, the present invention proposes a 5GMEC deployment platform based on power business characteristics.

[0005] In order to solve the above technical problems, the technical solution adopted by the present invention is:

[0006] A 5GMEC deployment platform based on power business characteristics, comprising a MEC three-level cloud-edge collaborative architecture, a UPF collaborative mechanism, a power facility integration module, a security protection system, and a business diversion strategy;

[0007] The MEC three-level cloud-edge collaborative architecture is a layered architecture consisting of an access layer, an edge layer, and a central layer. Each layer is connected through an access ring, an aggregation ring, and a backbone ring. Differentiated UPF functions are deployed on each layer to achieve hierarchical processing and optimal resource allocation for power services.

[0008] The UPF collaboration mechanism uses network slice identification to implement priority scheduling of three types of services. The access layer and edge layer use dedicated UPFs, which are independently deployed in park substations and municipal computer rooms to support local business flow offloading and ultra-low latency processing. The central layer uses shared UPFs, which are deployed in provincial computer rooms through NFV virtualization to centrally process non-real-time data.

[0009] The power facility integration module physically integrates MEC nodes with the power infrastructure, utilizing its spare space and power capacity to deploy cabinets.

[0010] The security protection system adopts a layered defense mechanism to provide multi-dimensional threat coverage, build in-depth defense, and accurately manage risks. In the security protection system, the access layer implements industrial protocol deep filtering and uRLLC slice encryption, the edge layer uses AI video stream encryption and dynamic bandwidth isolation, and the center layer deploys zero-trust gateways and cross-domain traffic auditing.

[0011] The business diversion strategy classifies and processes power services based on 5G network slicing, and centrally schedules UPF diversion rules through SMF to achieve local traffic offloading and non-local traffic backhaul.

[0012] Furthermore, the access layer is deployed at the campus-level node and includes a dedicated UPF, a security management module, a dedicated SMF, and an AUSF. It is connected to the edge layer via an access ring and is used to process real-time services such as distribution network protection and load control.

[0013] The edge layer is deployed in the city-level computer room and includes a dedicated UPF, shared SMF, MEP, and security management module. It is connected to the central layer through a convergence ring and is used to handle high-bandwidth services such as mobile inspection and video surveillance.

[0014] The central layer is deployed in the provincial operator's computer room and includes shared UPF, shared AMF / SMF / PCF, which is connected to the 5G core network through a backbone ring for periodic data backhaul and global status monitoring.

[0015] Control services, video services and data collection services are all transmitted to the access layer through the 5G wireless access network.

[0016] Furthermore, the service scheduling layer implements priority scheduling of three types of services through network slice identification, including: allocating the highest priority slice to control services; allocating guaranteed bandwidth slice to video services; and allocating large connection slice to acquisition services.

[0017] Furthermore, the deployment of the dedicated UPF meets the following conditions: the access layer UPF supports dual-fiber ring network redundancy with reliability ≥ 99.999%, and is used for distribution network differential protection and load control; the edge layer UPF integrates the SRv6 protocol to dynamically adapt to the bandwidth, supporting 4K video stream transmission with a bandwidth fluctuation range of ≤ 10%; the dedicated UPF and the shared UPF are isolated by FlexE hard slicing.

[0018] Furthermore, the specific configuration of the power facility integration module includes:

[0019] 10-20 cabinets are reserved for MEC nodes in substations, and hyper-converged servers and GPU acceleration modules are deployed to support real-time processing of distribution network PMU data. 2-3 cabinets are configured for MEC nodes in switch stations, and edge AI inference engines are integrated for real-time analysis of mobile inspection video streams. A lightweight container platform is deployed on MEC nodes in distribution rooms, which are directly connected to local business systems through the N6 interface, with a latency of ≤5ms.

[0020] Furthermore, the security protection system further includes: the access layer UPF has built-in Modbus / TCP protocol deep packet inspection to block illegal control instructions; the edge layer UPF adopts dynamic key sharding technology to update the video stream encryption key every 10 minutes; the center layer UPF deploys a blockchain audit chain to record cross-domain traffic operation logs and store them on the chain.

[0021] Furthermore, the service offload strategy is implemented as follows: control services are allocated eMBB+uRLLC hybrid slices, with a priority of 6Gbps bandwidth + 1ms latency guarantee; video services use dynamic bandwidth reservation slices, with a minimum guaranteed bandwidth of 4Gbps and a peak bandwidth of 8Gbps; collection services use mMTC slices, supporting concurrent access of ≥100,000 terminals per square kilometer.

[0022] Furthermore, the network transmission configuration of the layered architecture is as follows: the access ring adopts CPRI fronthaul + optical bypass protection, and the single-link failure switching time is ≤50ms; the aggregation ring supports SRv6+Segment Routing, and the path optimization algorithm convergence time is ≤1s; the backbone ring deploys 400G FlexE interface, and the hard slice granularity is ≤5Gbps.

[0023] Furthermore, the data protection method of the security protection system includes: sensitive data is processed using homomorphic encryption, and the edge nodes only transmit ciphertext to the central layer for decryption; video stream data is desensitized by regional mosaic, and sensitive areas are dynamically blurred based on GIS coordinates; and equipment monitoring data is added with a timestamp watermark.

[0024] Compared with the prior art, the present invention has the following beneficial effects:

[0025] It can be flexibly deployed and configured according to the needs of power business, and has a high degree of matching with the business needs of the power grid; it has autonomous and controllable management, customized security management policies, prevents illegal access, enhances business transmission security, and ensures the protection of physical facilities; it has better performance in power data diversion, lightweight power applications, and intelligent services; and it can be flexibly deployed in combination with the deployment of the power business application system.

[0026] In summary, self-built MEC platforms offer significant advantages in security management, service optimization, and deployment flexibility, making them more suitable for large-scale 5G deployment in smart grids. The MEC platform integrates 5G networks (primarily UPF) with business applications. To meet the needs of large-scale 5G applications in smart grids, the recommended deployment solution is to build a self-built MEC platform that includes UPF.

[0027] From a technical perspective, if operators continue to lease UPFs and only build their own edge computing platforms, the shortcomings in construction planning, security management, and network performance of leasing operator MEC services listed in the table will remain difficult to address. From a network slicing perspective, the smallest slice unit of 5G network slicing on the core network side is the UPF. In the future, operators will primarily provide 5G network services to the power grid through slice leasing. Self-built MEC platforms that include UPFs can effectively improve the security of 5G power grid slices and the flexibility of service deployment. Self-built MEC platforms connect to the transmission network, SMF, and other UPFs externally through interfaces such as N3, N4, and N9, enabling service interoperability. Internally, service data is sent to the service processing portion of the MEC platform through the N6 interface, enabling service distribution, data aggregation, and control policy generation. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] The present invention will be described in further detail below with reference to the accompanying drawings.

[0029] Figure 1 This is the physical deployment architecture diagram of the MEC platform including UPF of the present invention. DETAILED DESCRIPTION

[0030] In order to better understand the present invention, the content of the present invention is further clearly described below in conjunction with the examples and drawings, but the protection content of the present invention is not limited to the following examples. In the following description, a large number of specific details are given in order to provide a more thorough understanding of the present invention. However, it is obvious to those skilled in the art that the present invention can be implemented without one or more of these details.

[0031] Example 1: See Figure 1 This embodiment discloses a 5GMEC deployment platform based on the characteristics of power services. The deployment platform includes a three-level MEC cloud-edge collaborative architecture, a UPF collaborative mechanism, a power facility integration module, a security protection system, and a business diversion strategy.

[0032] The MEC three-level cloud-edge collaborative architecture is a layered architecture consisting of an access layer, an edge layer, and a center layer. Each layer is connected through an access ring, an aggregation ring, and a backbone ring, and each layer deploys differentiated UPF functions to achieve hierarchical processing of power services and optimal resource allocation.

[0033] The access layer is deployed at the campus-level node and includes a dedicated UPF, security management module, dedicated SMF, and AUSF. It is connected to the edge layer through an access ring and is used to process real-time services such as distribution network protection and load control.

[0034] The edge layer is deployed in the city-level computer room and includes a dedicated UPF, shared SMF, MEP, and security management module. It is connected to the central layer through a convergence ring and is used to handle high-bandwidth services such as mobile inspection and video surveillance.

[0035] The central layer is deployed in the provincial operator's computer room and includes shared UPF, shared AMF / SMF / PCF, which is connected to the 5G core network through a backbone ring for periodic data backhaul and global status monitoring.

[0036] Control services, video services and data collection services are all transmitted to the access layer through the 5G wireless access network.

[0037] In this embodiment, the steps of the access layer UPF processing control services include: receiving distribution network differential protection instructions through 5G RAN and parsing the Modbus / TCP protocol; the industrial protocol firewall verifies the legitimacy of register operations; and the dedicated UPF forwards the instructions to the local execution terminal within ≤10ms.

[0038] The edge layer UPF processes video services in the following steps: dynamically blurring sensitive areas based on GIS coordinates; using the Shamir algorithm to shard encryption keys, which are updated every 10 minutes; and dynamically adapting to bandwidth fluctuations (4Gbps→8Gbps) through the SRv6 protocol.

[0039] The network transmission configuration of the layered architecture is as follows: the access ring uses CPRI fronthaul + optical bypass protection, and the single-link failure switching time is ≤50ms; the aggregation ring supports SRv6 + Segment Routing, and the path optimization algorithm convergence time is ≤1s; the backbone ring deploys 400G FlexE interfaces, and the hard slice granularity is ≤5Gbps.

[0040] The UPF collaboration mechanism uses network slice identifiers to prioritize three types of services. The access and edge layers utilize dedicated UPFs, independently deployed in campus substations and prefecture-level computer rooms, supporting local service flow offloading and ultra-low latency processing. The central layer utilizes a shared UPF, deployed in provincial computer rooms via NFV virtualization, to centrally process non-real-time data. The service scheduling layer prioritizes three types of services using network slice identifiers: control services are assigned the highest priority slices; video services are assigned guaranteed bandwidth slices; and data collection services are assigned large connection slices.

[0041] The deployment of dedicated UPF meets the following conditions: the access layer UPF supports dual-fiber ring network redundancy with a reliability of ≥99.999%, and is used for distribution network differential protection and load control; the edge layer UPF integrates the SRv6 protocol to dynamically adapt to bandwidth, supporting 4K video streaming transmission with a bandwidth fluctuation range of ≤10%; the dedicated UPF and shared UPF are isolated by FlexE hard slicing.

[0042] The power facility integration module physically integrates MEC nodes with power infrastructure, leveraging its spare space and power capacity to deploy cabinets. The specific configuration of the power facility integration module includes: 10-20 cabinets are reserved for MEC nodes in substations, deployed with hyperconverged servers and GPU acceleration modules to support real-time processing of distribution network PMU data; 2-3 cabinets are configured for MEC nodes in switch stations, integrating an edge AI inference engine for real-time analysis of mobile inspection video streams; and a lightweight container platform is deployed in MEC nodes in distribution rooms, directly connecting to local business systems via the N6 interface with a latency of ≤5ms.

[0043] The security protection system employs a layered defense mechanism to provide multi-dimensional threat coverage, build defense-in-depth, and precisely manage risks. Within this system, the access layer implements deep filtering of industrial protocols and uRLLC slicing encryption, the edge layer employs AI video stream encryption and dynamic bandwidth isolation, and the central layer deploys a zero-trust gateway and cross-domain traffic auditing. The security protection system further includes: The access layer UPF incorporates built-in Modbus / TCP protocol deep packet inspection to block illegal control commands; the edge layer UPF utilizes dynamic key sharding technology to update video stream encryption keys every 10 minutes; and the central layer UPF deploys a blockchain audit chain to record cross-domain traffic operation logs and store them on-chain.

[0044] The business diversion strategy classifies and processes power services based on 5G network slicing, and centrally schedules UPF diversion rules through SMF to achieve local traffic offloading and non-local traffic backhaul.

[0045] The service offload strategy is implemented as follows: control services are allocated eMBB+uRLLC hybrid slices, with a priority of 6Gbps bandwidth + 1ms latency guarantee; video services use dynamic bandwidth reservation slices, with a minimum guaranteed bandwidth of 4Gbps and a peak bandwidth of 8Gbps; collection services use mMTC slices, supporting concurrent access of ≥100,000 terminals per square kilometer.

[0046] The data protection method of the security protection system includes the following steps.

[0047] Sensitive data is processed using homomorphic encryption, with edge nodes transmitting only ciphertext to the central layer for decryption. Video stream data is desensitized using regional mosaics, dynamically blurring sensitive areas based on GIS coordinates. Device monitoring data is timestamped.

[0048] In this embodiment, homomorphic encryption primarily refers to the use of additive homomorphic encryption in this application, allowing direct addition operations on ciphertext to meet the privacy computing requirements of power monitoring data (such as current and voltage superposition analysis). Edge node encryption refers to the access DC to collect sensitive data such as distribution network differential protection instructions and load control parameters, and immediately encrypts them after they are generated. The ciphertext is then transmitted to the edge / central DC via the access ring.

[0049] Finally, it should be noted that the above embodiments are only used to illustrate the technical solution of the present invention and are not limiting. Other modifications or equivalent substitutions made to the technical solution of the present invention by ordinary technicians in this field should be included in the scope of the claims of the present invention as long as they do not depart from the spirit and scope of the technical solution of the present invention.

Claims

1. A 5GMEC deployment platform based on power business characteristics, characterized by: The deployment platform includes a three-level MEC cloud-edge collaborative architecture, a UPF collaborative mechanism, a power facility integration module, a security protection system, and a business diversion strategy; The MEC three-level cloud-edge collaborative architecture is a layered architecture consisting of an access layer, an edge layer, and a central layer. Each layer is connected through an access ring, an aggregation ring, and a backbone ring. Differentiated UPF functions are deployed on each layer to achieve hierarchical processing and optimal resource allocation for power services. The UPF collaboration mechanism uses network slice identification to implement priority scheduling of three types of services. The access layer and edge layer use dedicated UPFs, which are independently deployed in park substations and municipal computer rooms to support local business flow offloading and ultra-low latency processing. The central layer uses shared UPFs, which are deployed in provincial computer rooms through NFV virtualization to centrally process non-real-time data. The power facility integration module physically integrates MEC nodes with the power infrastructure, utilizing its spare space and power capacity to deploy cabinets. The security protection system adopts a layered defense mechanism to provide multi-dimensional threat coverage, build in-depth defense, and accurately manage risks. In the security protection system, the access layer implements industrial protocol deep filtering and uRLLC slice encryption, the edge layer uses AI video stream encryption and dynamic bandwidth isolation, and the center layer deploys zero-trust gateways and cross-domain traffic auditing. The business diversion strategy classifies and processes power services based on 5G network slicing, and centrally schedules UPF diversion rules through SMF to achieve local traffic offloading and non-local traffic backhaul.

2. A 5GMEC deployment platform based on power business characteristics according to claim 1, characterized in that: The access layer is deployed at the campus-level node and includes a dedicated UPF, security management module, dedicated SMF, and AUSF. It is connected to the edge layer through an access ring and is used to process real-time services such as distribution network protection and load control. The edge layer is deployed in the city-level computer room and includes a dedicated UPF, shared SMF, MEP, and security management module. It is connected to the central layer through a convergence ring and is used to handle high-bandwidth services such as mobile inspection and video surveillance. The central layer is deployed in the provincial operator's computer room and includes shared UPF, shared AMF / SMF / PCF, which is connected to the 5G core network through a backbone ring for periodic data backhaul and global status monitoring. Control services, video services and data collection services are all transmitted to the access layer through the 5G wireless access network.

3. A 5GMEC deployment platform based on power business characteristics according to claim 2, characterized in that: The service scheduling layer implements priority scheduling of three types of services through network slice identification, including: allocating the highest priority slice to control services; allocating guaranteed bandwidth slice to video services; and allocating large connection slice to acquisition services.

4. A 5GMEC deployment platform based on power business characteristics according to claim 3, characterized in that: The deployment of the dedicated UPF meets the following conditions: the access layer UPF supports dual-fiber ring network redundancy with a reliability of ≥99.999%, and is used for distribution network differential protection and load control; the edge layer UPF integrates the SRv6 protocol to dynamically adapt to the bandwidth and supports 4K video stream transmission with a bandwidth fluctuation range of ≤10%; the dedicated UPF and the shared UPF are isolated by FlexE hard slicing.

5. A 5GMEC deployment platform based on power business characteristics according to claim 4, characterized in that: The specific configuration of the power facility integration module includes: 10-20 cabinets are reserved for MEC nodes in substations, and hyper-converged servers and GPU acceleration modules are deployed to support real-time processing of distribution network PMU data. 2-3 cabinets are configured for MEC nodes in switch stations, and edge AI inference engines are integrated for real-time analysis of mobile inspection video streams. A lightweight container platform is deployed on MEC nodes in distribution rooms, which are directly connected to local business systems through the N6 interface, with a latency of ≤5ms.

6. A 5GMEC deployment platform based on power business characteristics according to claim 5, characterized in that: The security protection system further includes: the access layer UPF has built-in Modbus / TCP protocol deep packet inspection to block illegal control instructions; the edge layer UPF adopts dynamic key sharding technology to update the video stream encryption key every 10 minutes; the center layer UPF deploys a blockchain audit chain to record cross-domain traffic operation logs and store them on the chain.

7. A 5GMEC deployment platform based on power business characteristics according to claim 6, characterized in that: The service offload strategy is implemented as follows: control services are allocated eMBB+uRLLC hybrid slices, with a priority of 6Gbps bandwidth + 1ms latency guarantee; video services use dynamic bandwidth reservation slices, with a minimum guaranteed bandwidth of 4Gbps and a peak bandwidth of 8Gbps; collection services use mMTC slices, supporting concurrent access of ≥100,000 terminals per square kilometer.

8. A 5GMEC deployment platform based on power business characteristics according to claim 7, characterized in that: The network transmission configuration of the layered architecture is as follows: the access ring adopts CPRI fronthaul + optical bypass protection, and the single-link failure switching time is ≤50ms; the aggregation ring supports SRv6 + Segment Routing, and the path optimization algorithm convergence time is ≤1s; the backbone ring deploys 400GFlexE interfaces, and the hard slice granularity is ≤5Gbps.

9. A 5GMEC deployment platform based on power business characteristics according to claim 8, characterized in that: The data protection method of the security protection system includes: sensitive data is processed using homomorphic encryption, and the edge nodes only transmit ciphertext to the central layer for decryption; video stream data is desensitized using regional mosaics, and sensitive areas are dynamically blurred based on GIS coordinates; and equipment monitoring data is added with a timestamp watermark.

Citation Information

Cited By

  • Edge computing node deployment method and system suitable for 5G industrial private network

    CN121968142A