Data processing method, device and storage medium for 5G cloud-based private network

By deploying DU proxy instances in the cloud to manage address information and data forwarding between DU and CU, the problem of easy cracking of authentication methods after 5G base station softwareization is solved, and secure and reliable data transmission and authentication are achieved.

CN115967512BActive Publication Date: 2025-09-19CHINA MOBILE GROUP DESIGN INST +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111189743.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-10-12
Publication Date
2025-09-19
Estimated Expiration
2041-10-12

AI Technical Summary

Technical Problem

After 5G base stations are software-based, the existing authentication methods are at risk of being decompiled and cracked, leading to security issues.

Method used

By deploying a distributed processing unit DU proxy instance in the cloud, creating and managing address information between the DU proxy instance and the centralized processing unit CU, data forwarding is achieved, avoiding direct transmission of sensitive information of the cloud core business, and using the DU proxy instance for client authentication and firewall functions.

Benefits of technology

It improves the security of 5G cloud-based private networks and the reliability of data transmission without relying on encryption hardware devices, prevents illegal data transmission, and protects core business information from being leaked.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115967512B_ABST
    Figure CN115967512B_ABST
Patent Text Reader

Abstract

The present application discloses a data processing method, device and storage medium for a 5G cloud-based private network. The data processing method for the 5G cloud-based private network includes: upon receiving a login request forwarded by a cloud-based authentication server, creating a distributed processing unit DU proxy instance; when the DU proxy instance is created, sending a creation completion message to the cloud-based authentication server, wherein upon receiving the creation completion message, the cloud-based authentication server requests the centralized processing unit CU pool to send the address information of the CU to be connected to the proxy pool; receiving the address information of the CU to be connected, so that when the DU proxy instance receives the interaction data sent by the client DU, it forwards the interaction data to the CU to be connected according to the address information. The present application implements client authentication by deploying a DU proxy instance in the cloud and then forwarding data between the DU and the CU based on the DU proxy instance.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of mobile communication technologies, and in particular to a data processing method, device, and storage medium for a 5G cloud-based private network. Background Art

[0002] With growing demand and technological advancements, modern mobile communications are experiencing a gradual increase in functionality, broader coverage, and increasingly complex business processes. The recent proliferation of 5G deployments has been particularly significant. Because 5G's single-site coverage is smaller than 4G's, achieving the same coverage requires several times as many base stations as 4G, making operations and maintenance increasingly challenging. Furthermore, due to 5G's higher transmission rates, greater bandwidth, and more complex functionality, the cost of base station equipment is higher than that of 4G. Therefore, to reduce the costs of building, deploying, and maintaining 5G communications, the trend in 5G deployments is to make 5G base stations software-based and cloud-based.

[0003] After the base station is software-based, soft encryption methods such as entering passwords and registration codes can be used to protect the software from being stolen, but these encryption and authentication methods are at risk of being decompiled and cracked. Summary of the Invention

[0004] The embodiments of the present application aim to solve the security problem of authentication method after the base station is software-based by providing a data processing method, device and storage medium for a 5G cloud-based private network.

[0005] To achieve the above objectives, the present application provides, on one hand, a 5G cloud-based private network data processing method, which is applied to a proxy pool, and includes:

[0006] Upon receiving a login request forwarded by the cloud authentication server, a distributed processing unit DU agent instance is created;

[0007] When the DU proxy instance is created, a creation completion message is sent to the cloud authentication server, wherein upon receiving the creation completion message, the cloud authentication server requests the centralized processing unit CU pool to send the address information of the CU to be connected to the proxy pool;

[0008] Receive the address information of the CU to be connected, so that when the DU agent instance receives the interactive data sent by the client DU, it forwards the interactive data to the CU to be connected according to the address information.

[0009] Optionally, after the step of receiving the address information of the CU to be connected, the following steps are included:

[0010] Upon receiving the offline request forwarded by the cloud authentication server, destroying the DU agent instance;

[0011] When the DU agent instance is destroyed, a destruction completion message is sent to the cloud authentication server. When the cloud authentication server receives the destruction completion message, it notifies the CU to be connected to go offline.

[0012] In addition, to achieve the above objectives, the present application also provides a data processing method for a 5G cloud-based private network, which is applied to a cloud authentication server, and the method includes:

[0013] Upon receiving the login request forwarded by the cloud authentication server, obtain the number of DUs currently connected to the client DU;

[0014] When the number of DUs is less than a preset number, forwarding the login request to the proxy pool, wherein upon receiving the login request, the proxy pool creates a DU proxy instance and sends a creation completion message of the DU proxy instance to the cloud authentication server;

[0015] Upon receiving the creation completion information of the DU agent instance, the CU pool is requested to send the address information of the CU to be connected to the agent pool.

[0016] Optionally, after the step of requesting the CU pool to send the address information of the CU to be connected to the proxy pool, the following steps are included:

[0017] Upon receiving the offline request forwarded by the cloud authentication server, updating the number of DUs currently connected to the client DU according to the offline request;

[0018] Forwarding the offline request to the proxy pool, wherein upon receiving the offline request, the proxy pool destroys the DU proxy instance and sends a destruction completion message of the DU proxy instance to the cloud authentication server;

[0019] When the destruction completion information of the DU agent instance is received, the offline request is forwarded to the CU pool to notify the CU to be connected to go offline.

[0020] In addition, to achieve the above objectives, the present application also provides a 5G cloud-based private network data processing method, which is applied to the CU pool, and the method includes:

[0021] Receive a CU application request sent by a cloud authentication server, and determine a CU to be connected based on the CU application request;

[0022] When the CU to be connected exists, the address information of the CU to be connected is sent to the proxy pool;

[0023] When the CU to be connected does not exist, the CU to be connected is created, and the address information of the CU to be connected is sent to the proxy pool.

[0024] In addition, to achieve the above objectives, the present application also provides a 5G cloud-based private network data processing method, which is applied to a client DU, and the method includes:

[0025] Sending a login request to a cloud authentication server, wherein the cloud authentication service verifies the login request upon receipt and, upon successful verification, forwards the login request to the cloud authentication server;

[0026] Receive the address information of the DU proxy instance sent by the proxy pool;

[0027] The interactive data is sent to the DU agent instance according to the address information of the DU agent instance, so that the DU agent instance forwards the interactive data to the CU to be connected.

[0028] Optionally, after the step of sending the interaction data to the DU proxy instance according to the address information of the DU proxy instance, the method further includes:

[0029] Sending a logoff request to the cloud authentication server, wherein the cloud authentication server verifies the logoff request upon receiving the logoff request, and forwards the logoff request to the cloud authentication server after successful verification;

[0030] Receive offline completion information of the CU to be connected sent by the cloud authentication server.

[0031] In addition, to achieve the above-mentioned objectives, the present application further provides a data processing device for a 5G cloud-based private network. The data processing device for the 5G cloud-based private network includes a creation module, a first sending module, and a first receiving module, wherein:

[0032] The creation module is used to create a distributed processing unit DU agent instance when receiving a login request forwarded by the cloud authentication server;

[0033] The first sending module is configured to send a creation completion message to the cloud authentication server when the DU proxy instance is created, wherein upon receiving the creation completion message, the cloud authentication server requests the centralized processing unit CU pool to send the address information of the CU to be connected to the proxy pool;

[0034] The first receiving module is configured to receive the address information of the CU to be connected, so that when the DU agent instance receives the interactive data sent by the client DU, it forwards the interactive data to the CU to be connected according to the address information;

[0035] The data processing device of the 5G cloud-based private network further includes an acquisition module, a forwarding module, and a request module, wherein:

[0036] The acquisition module is used to obtain the number of DUs currently connected to the client DU when receiving the login request forwarded by the cloud authentication server;

[0037] The forwarding module is configured to forward the login request to the proxy pool when the number of DUs is less than a preset number, wherein the proxy pool creates a DU proxy instance upon receiving the login request and sends a creation completion message of the DU proxy instance to the cloud authentication server;

[0038] The request module is configured to request the CU pool to send the address information of the CU to be connected to the proxy pool upon receiving the creation completion information of the DU proxy instance;

[0039] The data processing device of the 5G cloud-based private network further includes a second receiving module, a second sending module and a third sending module, wherein:

[0040] The second receiving module is configured to receive a CU application request sent by a cloud authentication server, and determine a CU to be connected according to the CU application request;

[0041] The second sending module is configured to send the address information of the CU to be connected to the proxy pool when the CU to be connected exists;

[0042] The third sending module is configured to create the CU to be connected if the CU to be connected does not exist, and send the address information of the CU to be connected to the proxy pool;

[0043] The data processing device of the 5G cloud-based private network further includes a fourth sending module, a third receiving module and a fifth sending module, wherein:

[0044] The fourth sending module is configured to send a login request to the cloud authentication server, wherein the cloud authentication service verifies the login request upon receiving the login request and forwards the login request to the cloud authentication server after successful verification;

[0045] The third receiving module is used to receive the address information of the DU proxy instance sent by the proxy pool;

[0046] The fifth sending module is configured to send interaction data to the DU agent instance according to the address information of the DU agent instance, so that the DU agent instance forwards the interaction data to the CU to be connected.

[0047] In addition, to achieve the above-mentioned purpose, the present application also provides a data processing device for a 5G cloud-based private network. The data processing device for the 5G cloud-based private network includes a memory, a processor, and a data processing program for the 5G cloud-based private network stored in the memory and running on the processor. When the processor executes the data processing program for the 5G cloud-based private network, the steps of the data processing method for the 5G cloud-based private network as described above are implemented.

[0048] In addition, to achieve the above-mentioned purpose, the present application also provides a storage medium on the other hand, which stores a data processing program for a 5G cloud-based private network. When the data processing program for the 5G cloud-based private network is executed by the processor, the steps of the data processing method for the 5G cloud-based private network as described above are implemented.

[0049] This application proposes a data processing method for a 5G cloud-based private network, which creates a distributed processing unit DU proxy instance upon receiving a login request forwarded by a cloud-based authentication server; when the DU proxy instance is created, it sends a creation completion message to the cloud-based authentication server, wherein upon receiving the creation completion message, the cloud-based authentication server requests the centralized processing unit CU pool to send the address information of the CU to be connected to the proxy pool; and receives the address information of the CU to be connected, so that when the DU proxy instance receives the interaction data sent by the client DU, it forwards the interaction data to the CU to be connected according to the address information. This application implements client authentication by deploying a DU proxy instance in the cloud and then forwarding data between the DU and the CU based on the DU proxy instance. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] Figure 1 This is a schematic diagram of the terminal structure of the hardware operating environment involved in the embodiment of the present application;

[0051] Figure 2 This is a flowchart of the first embodiment of the data processing method for the 5G cloud-based private network of this application;

[0052] Figure 3 This is a flowchart of the second embodiment of the data processing method for the 5G cloud-based private network of this application;

[0053] Figure 4 This is a flowchart of the third embodiment of the data processing method for the 5G cloud-based private network of the present application;

[0054] Figure 5 This is a flowchart of the fourth embodiment of the data processing method for the 5G cloud-based private network of the present application;

[0055] Figure 6 This is a diagram of the authentication process for logging into the 5G cloud-based private network.

[0056] Figure 7This is a schematic diagram of the offline process of the client DU of this application;

[0057] Figure 8 This is a schematic diagram of the system architecture of the 5G cloud-based private network of this application;

[0058] Figure 9 This is a schematic diagram of the topological relationship between DU and CU in this application;

[0059] Figure 10 This is a module diagram of the data processing device for the 5G cloud-based private network of this application;

[0060] Figure 11 Another schematic diagram of the module of the data processing device of the 5G cloud-based private network of this application;

[0061] Figure 12 This is another schematic diagram of the module of the data processing device of the 5G cloud-based private network of this application;

[0062] Figure 13 This is another schematic diagram of the module of the data processing device of the 5G cloud-based private network of this application.

[0063] The realization of the objectives, functional features and advantages of this application will be further explained in conjunction with embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION

[0064] It should be understood that the specific embodiments described herein are only used to explain the present application and are not intended to limit the present application.

[0065] The softwareization and cloudification of 5G base stations are the trends in 5G construction. After the base stations are softwareized, soft encryption methods such as entering passwords and registration codes can be used to protect the software from being stolen, but these encryption and authentication methods are at risk of being decompiled and cracked.

[0066] However, upon receiving a login request forwarded by a cloud-based authentication server, this application creates a distributed processing unit DU proxy instance; upon completion of the DU proxy instance creation, it sends a creation completion message to the cloud-based authentication server, wherein upon receiving the creation completion message, the cloud-based authentication server requests the centralized processing unit CU pool to send the address information of the CU to be connected to the proxy pool; upon receiving the address information of the CU to be connected, the DU proxy instance forwards the interaction data to the CU to be connected based on the address information when receiving the interaction data sent by the client DU. This application implements client authentication by deploying a DU proxy instance in the cloud and then forwarding data between the DU and the CU based on the DU proxy instance.

[0067] like Figure 1 As shown, Figure 1 This is a schematic diagram of the terminal device structure of the hardware operating environment involved in the embodiment of the present application.

[0068] like Figure 1 As shown, the terminal device may include: a processor 1001, such as a CPU, a network interface 1004, a user interface 1003, a memory 1005, and a communication bus 1002. Among them, the communication bus 1002 is used to realize the connection and communication between these components. The user interface 1003 may include a display screen (Display), an input unit such as a keyboard (Keyboard), and the user interface 1003 may also include a standard wired interface and a wireless interface. The network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface). The memory 1005 may be a high-speed RAM memory, or a stable memory (non-volatile memory), such as a disk memory. The memory 1005 may optionally be a storage device independent of the aforementioned processor 1001.

[0069] Those skilled in the art will understand that Figure 1 The terminal device structure shown in the figure does not constitute a limitation on the terminal device, and may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.

[0070] like Figure 1 As shown, the memory 1005 as a computer-readable storage medium may include a data processing program for the 5G cloud-based private network.

[0071] exist Figure 1 In the terminal device shown, the network interface 1004 is mainly used for data communication with the backend server; the user interface 1003 is mainly used for data communication with the client (user end); when the terminal is a proxy pool, the processor 1001 can be used to call the data processing program of the 5G cloud private network in the memory 1005 and perform the following operations:

[0072] Upon receiving a login request forwarded by the cloud authentication server, a distributed processing unit DU agent instance is created;

[0073] When the DU proxy instance is created, a creation completion message is sent to the cloud authentication server, wherein upon receiving the creation completion message, the cloud authentication server requests the centralized processing unit CU pool to send the address information of the CU to be connected to the proxy pool;

[0074] Receive the address information of the CU to be connected, so that when the DU agent instance receives the interactive data sent by the client DU, it forwards the interactive data to the CU to be connected according to the address information.

[0075] When the terminal is a cloud authentication server, the processor 1001 can be used to call the data processing program of the 5G cloud private network in the memory 1005 and perform the following operations:

[0076] Upon receiving the login request forwarded by the cloud authentication server, obtain the number of DUs currently connected to the client DU;

[0077] When the number of DUs is less than a preset number, forwarding the login request to the proxy pool, wherein upon receiving the login request, the proxy pool creates a DU proxy instance and sends a creation completion message of the DU proxy instance to the cloud authentication server;

[0078] Upon receiving the creation completion information of the DU agent instance, the CU pool is requested to send the address information of the CU to be connected to the agent pool.

[0079] When the terminal is a CU pool, the processor 1001 may be configured to call the data processing program of the 5G cloud-based private network in the memory 1005 and perform the following operations:

[0080] Receive a CU application request sent by a cloud authentication server, and determine a CU to be connected based on the CU application request;

[0081] When the CU to be connected exists, the address information of the CU to be connected is sent to the proxy pool;

[0082] When the CU to be connected does not exist, the CU to be connected is created, and the address information of the CU to be connected is sent to the proxy pool.

[0083] When the terminal is a client DU, the processor 1001 may be configured to call the data processing program of the 5G cloud-based private network in the memory 1005 and perform the following operations:

[0084] Sending a login request to a cloud authentication server, wherein the cloud authentication service verifies the login request upon receipt and, upon successful verification, forwards the login request to the cloud authentication server;

[0085] Receive the address information of the DU proxy instance sent by the proxy pool;

[0086] The interactive data is sent to the DU agent instance according to the address information of the DU agent instance, so that the DU agent instance forwards the interactive data to the CU to be connected.

[0087] refer to Figure 2 , Figure 2 This is a flow chart of the first embodiment of the data processing method for the 5G cloud-based private network of this application.

[0088] An embodiment of the present application provides a data processing method for a 5G cloud-based private network. It should be noted that although the logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in an order different from that here.

[0089] The data processing method for the 5G cloud-based private network of this embodiment is applied to a proxy pool, and includes the following steps:

[0090] Step S10: upon receiving the login request forwarded by the cloud authentication server, creating a distributed processing unit DU agent instance;

[0091] It should be noted that the 5G access network is divided into DU (Distributed Unit) and CU (Centralized Unit). Among them, DU is mainly responsible for 5G underlying signal processing and scheduling services with high real-time requirements, and is generally deployed in areas close to the terminal; while CU is mainly responsible for some upper-layer services with lower real-time requirements and can be deployed in a centralized cloud.

[0092] 5G private networks are dedicated 5G networks. Unlike the public 5G network, these networks are designed specifically for users in specific organizations, such as industrial parks, railways, and mines. In cloud-based private networks, the DU (Durative Use Unit) with higher real-time requirements is typically deployed on the client side, while the CU (Consumer Use Unit) with lower real-time requirements is deployed on the cloud side.

[0093] refer to Figure 8 , Figure 8 This is a schematic diagram of the system structure of the 5G cloud-based private network of this application. The system structure of the 5G cloud-based private network includes the cloud side and the client side. The cloud is deployed in the operator's computer room to provide cloud-based 5G CU services and 5G private network services for different customers. Among them, on the cloud side, the core business is CU. In addition, there are other management services. At the same time, the cloud is deployed with authentication services, authorization services, DU agent pools, and CU pools. The client is deployed on the client side and runs the 5G DU service. Among them, all services are software running on a general server and do not contain any encryption peripherals. In addition, the authentication of the client is completed through the authentication service and authorization service of the cloud.

[0094] refer to Figure 8 The proxy pool of this embodiment refers to a DU proxy pool, wherein the DU proxy pool is deployed on the cloud side and consists of multiple DU proxy instances (ie, DU proxies) and a DU proxy pool management service.

[0095] In this embodiment, when the DU proxy pool receives a login request forwarded by the cloud authentication server, it automatically creates a distributed processing unit DU proxy instance, wherein the DU proxy instance is responsible for communicating with the client DU. The DU proxy instance and the client DU have a one-to-one relationship and are time-sensitive: it is valid only when the client DU is working, and the DU proxy pool management service will destroy the corresponding DU proxy instance when the client DU goes offline. In addition, the DU proxy instance stores the IP address of the corresponding client DU, and all other client DU data that are not from this IP will be filtered. At the same time, the DU proxy instance also stores the route to the CU for data forwarding. The functions of the DU proxy instance include: acting as a proxy for the client DU to interact with the CU on the cloud side, without having to directly transmit sensitive information of the core business CU of the cloud (such as IP address, etc.) to the client, so the CU information can be hidden in the cloud; detecting the data sent by the client DU on the DU proxy side, discarding illegal data from non-target client DUs, and achieving the purpose of client authentication and firewall.

[0096] Step S20: When the DU proxy instance is created, a creation completion message is sent to the cloud authentication server. Upon receiving the creation completion message, the cloud authentication server requests the centralized processing unit CU pool to send the address information of the CU to be connected to the proxy pool.

[0097] In this embodiment, upon completing the creation of a DU proxy instance, the DU proxy pool sends a creation completion message to the cloud authentication server. Upon receiving the creation completion message, the cloud authentication server requests the centralized processing unit (CU) pool to send the address information of the CU to be connected to the DU proxy pool. For example, upon receiving the creation completion message, the cloud authentication server sends a CU application request to the CU pool. The CU pool determines the CU to be connected based on the CU application request and then sends the IP information of the CU to be connected to the DU proxy pool.

[0098] Step S30 : receiving the address information of the CU to be connected, so that when the DU agent instance receives the interactive data sent by the client DU, it forwards the interactive data to the CU to be connected according to the address information.

[0099] In this embodiment, upon receiving the address information of the CU to be connected from the CU pool, the DU proxy pool sets a route for the DU proxy instance based on the address information of the CU to be connected. This allows the DU proxy instance to forward the interactive data received from the client DU to the CU to be connected based on the address information. Since the interactive data between the client DU and the CU to be connected is forwarded through the DU proxy instance, sensitive information (such as the IP address, etc.) of the core service CU in the cloud is prevented from being transmitted to the client, and the CU information can be hidden in the cloud. At the same time, the DU proxy instance discards illegal data from non-target client DUs, achieving the purpose of client authentication and firewall.

[0100] In one embodiment, when the DU proxy pool receives a logoff request forwarded by the cloud authentication server, it destroys the DU proxy instance corresponding to the client DU. Then, when the destruction of the DU proxy instance is completed, it sends a destruction completion message to the cloud authentication server. When the cloud authentication server receives the destruction completion message, it notifies the CU to be connected to log off.

[0101] Upon receiving a login request forwarded by a cloud-based authentication server, this embodiment creates a distributed processing unit (DU) proxy instance. Upon completion of the DU proxy instance creation, it sends a creation completion message to the cloud-based authentication server. Upon receiving the creation completion message, the cloud-based authentication server requests the centralized processing unit (CU) pool to send the proxy pool the address information of the CU to be connected. Upon receiving the address information of the CU to be connected, the DU proxy instance forwards the interaction data sent by the client (DU) to the CU based on the address information. This embodiment implements client authentication by deploying the DU proxy instance in the cloud and then forwarding data between the DU and CU based on the DU proxy instance.

[0102] Further, refer to Figure 3 , a second example of the data processing method for the 5G cloud-based private network of this application is proposed.

[0103] The data processing method of the 5G cloud-based private network of this embodiment is applied to a cloud authentication server, and includes the following steps:

[0104] Step S40: upon receiving the login request forwarded by the cloud authentication server, obtaining the number of DUs currently connected to the client DU;

[0105] It should be noted that the cloud-based authentication server includes an authentication service and an authentication database. The authentication database stores the user ID, the maximum number of DUs the user is allowed to access, and the number of DUs the user is currently connected to. The authentication service is responsible for monitoring login requests from client DUs forwarded by the cloud-based authentication server and determining whether the login is successful based on the maximum number of DUs the user is allowed to access.

[0106] The cloud-based authentication server includes an authentication service and an authentication database. The authentication database stores the ID and password information of all registered users. The authentication service is responsible for monitoring login requests from client DUs, which include the user ID, password, and the CU-ID to which the client DU wishes to connect. When the authentication service monitors a login request from a client DU, it verifies the client's account and password. If verified, it forwards the user ID and desired CU-ID to the cloud-based authentication server, which then proceeds with authentication.

[0107] In this embodiment, when the authentication service of the cloud authentication server monitors the login request of the client DU forwarded by the cloud authentication server, the number of DUs currently accessed by the user is obtained from the authentication database to determine whether the client DU can log in successfully.

[0108] Step S50: When the number of DUs is less than a preset number, forwarding the login request to the proxy pool, wherein upon receiving the login request, the proxy pool creates a DU proxy instance and sends a creation completion message of the DU proxy instance to the cloud authentication server;

[0109] In this embodiment, after obtaining the number of DUs currently accessed by the user, the end authentication server compares the number of DUs with the maximum number of DUs allowed to be accessed by the user (i.e., the preset number). Assuming that the number of DUs currently accessed is greater than or equal to the maximum number of DUs allowed to be accessed by the user, it means that there are no remaining available DUs. At this time, a login failure message is sent to the client DU; assuming that the number of DUs currently accessed is less than the maximum number of DUs allowed to be accessed by the user, it means that the number of accessed DUs is not full. At this time, the login request of the client DU is forwarded to the DU proxy pool to notify the DU proxy pool to create a DU proxy instance in the cloud for this client DU.

[0110] Step S60: Upon receiving the creation completion information of the DU proxy instance, the CU pool is requested to send the address information of the CU to be connected to the proxy pool.

[0111] In this embodiment, when the cloud-based authentication server receives the creation completion information of the DU proxy instance sent by the DU proxy pool, it updates the number of DUs accessed by the user in the authentication database, and at the same time, requests the CU pool to send the address information of the CU to be connected to the proxy pool. For example, the cloud-based authentication server sends a CU application request to the CU pool, so that the CU pool determines the CU to be connected based on the CU application request, and then sends the IP information of the CU to be connected to the DU proxy pool.

[0112] In one embodiment, when the cloud authentication server receives the offline request forwarded by the cloud authentication server, it updates the number of DUs currently connected to the client DU according to the offline request; then, the cloud authentication server forwards the offline request to the DU proxy pool, wherein the DU proxy pool destroys the DU proxy instance when receiving the offline request and sends the destruction completion information of the DU proxy instance to the cloud authentication server; when the cloud authentication server receives the destruction completion information of the DU proxy instance, it forwards the offline request to the CU pool to notify the CU to be connected to go offline.

[0113] Upon receiving a login request forwarded by a cloud authentication server, this embodiment obtains the number of DUs currently connected to the client DU; when the number of DUs is less than a preset number, the login request is forwarded to the proxy pool. Upon receiving the login request, the proxy pool creates a DU proxy instance and sends a message indicating the completion of the DU proxy instance creation to the cloud authentication server; upon receiving the message indicating the completion of the DU proxy instance creation, the proxy pool requests the CU pool to send the address information of the CU to be connected to the proxy pool. This embodiment authenticates the login request of the client DU through the cloud authentication server. After successful authentication, the login request is forwarded to the DU proxy pool, which creates a DU proxy instance and forwards the client DU's interaction data to the CU to be connected based on the DU proxy instance, thereby achieving client authentication.

[0114] Further, refer to Figure 4 , a third embodiment of the data processing method for the 5G cloud-based private network of this application is proposed.

[0115] The data processing method for the 5G cloud-based private network of this embodiment is applied to the CU pool, and includes the following steps:

[0116] Step S70: receiving a CU application request sent by a cloud authentication server, and determining a CU to be connected based on the CU application request;

[0117] It should be noted that the CU pool consists of multiple CU instances, a CU pool management service, and a CU pool database. The CU instances running in the CU pool are the core cloud services. The CU pool runs multiple CU instances, providing access network services to all customers. CU instances are responsible for data exchange with cloud-based DU agent instances. The CU pool database stores the IP addresses of all running CUs, the user IDs to which the CUs belong, the CU-IDs assigned by the user, and the number of DU agent instances currently connected to the CU. The CU pool management service manages the creation and shutdown of CUs and monitors requests from the cloud-based authentication server.

[0118] In this embodiment, when the CU management service monitors a CU application request from the cloud authentication server, the CU management service obtains the user ID and the CU-ID specified by the user based on the CU application request, and determines the CU to be connected based on the CU-ID.

[0119] Step S80: When the CU to be connected exists, the address information of the CU to be connected is sent to the proxy pool;

[0120] In this embodiment, after the CU pool management service determines the CU to be connected based on the CU-ID, it queries the CU pool database whether there is a running instance numbered CU-ID under the user ID. If so, the IP corresponding to the CU (that is, the address information of the CU to be connected) is sent to the DU agent pool, and the number of DU agent instances connected to the CU in the CU pool database is updated.

[0121] Step S90: When the CU to be connected does not exist, create the CU to be connected, and send the address information of the CU to be connected to the proxy pool.

[0122] In this embodiment, after the CU pool management service determines the CU to be connected based on the CU-ID, it queries the CU pool database whether there is a running instance numbered CU-ID under the user ID. If not, a new CU instance is created (i.e., the CU to be connected). At the same time, the IP address of the newly created CU instance, user ID, and user-specified CU-ID are recorded in the CU pool database, and the IP address of the CU to be connected is sent to the DU agent pool.

[0123] In one embodiment, when the CU management service monitors the offline request forwarded from the cloud authentication server, it checks whether the CU-ID specified by the user is connected to the DU agent instance. If not, the CU to be connected is destroyed. After the destruction is completed, the information record of the CU in the CU pool is updated, and the destruction completion information is sent to the cloud authentication server.

[0124] This embodiment receives a CU application request from a cloud authentication server, obtains the user ID and user-specified CU-ID based on the CU application request, and queries the CU pool database to see if there is a running instance numbered CU-ID under the user ID. If so, the corresponding IP address is sent to the DU proxy pool, and the number of DU proxies connected to the CU in the CU pool database is updated. If not, a new CU instance is created, and the IP address, user ID, and user-specified CU-ID of the newly created CU instance are recorded in the CU pool database. The IP address of the CU is then sent to the DU proxy pool, binding the DU proxy instance to a CU instance in the CU pool.

[0125] Further, refer to Figure 5, a fourth embodiment of the data processing method for the 5G cloud-based private network of this application is proposed.

[0126] The data processing method of the 5G cloud-based private network of this embodiment is applied to the client DU, and includes the following steps:

[0127] Step S100, sending a login request to a cloud authentication server, wherein the cloud authentication server verifies the login request upon receiving the login request, and forwards the login request to the cloud authentication server after successful verification;

[0128] It should be noted that when the DU service is run on the client, the DU stores the IP address of the cloud authentication service. When the DU service is started, the DU sends the user name, password and other information to the cloud. If the authentication is passed, the IP address of the DU proxy instance can be obtained. Then, when the client is running, it interacts with the cloud through the DU proxy instance.

[0129] The client DU also needs to configure CU-ID, which is a user-defined CU number, indicating that the client DU expects to connect to the CU numbered CU-ID. This number can be set arbitrarily by the user and is used to indicate the topological relationship between the DU and the CU. For example, refer to Figure 9 , Figure 9 As shown in the topological relationship diagram of the DU and CU in this application, there are four DU instances on the client, namely DU1, DU2, DU3, and DU4, and their corresponding CU-IDs are id1, id1, cu2, and x3, respectively, which means that DU1 and DU2 are connected to the same CU, while DU3 and DU4 are each connected to another CU.

[0130] In this embodiment, the client DU sends a login request to the cloud authentication server. Upon receiving the login request, the cloud authentication service verifies the login request and, if successful, forwards the login request to the cloud authentication server. For example, when the authentication service intercepts the login request from the client DU, it verifies the client's account and password. If successful, it forwards the user ID and expected CU-ID to the cloud authentication server. This forwards the client DU's login request to the cloud authentication server, which then proceeds with authentication.

[0131] Step S110: receiving the address information of the DU proxy instance sent by the proxy pool;

[0132] In this embodiment, the client DU receives the address information of the DU proxy instance sent by the DU proxy pool.

[0133] Step S120: sending interaction data to the DU agent instance according to the address information of the DU agent instance, so that the DU agent instance forwards the interaction data to the CU to be connected.

[0134] In this embodiment, the client DU sends interaction data to the DU proxy instance according to the address information of the DU proxy instance, so that the DU proxy instance forwards the interaction data to the CU to be connected. That is, the client DU sends the interaction data to the cloud-side DU proxy instance, and the DU proxy instance forwards the interaction data to the CU to be connected, thereby realizing communication between the client DU and the CU to be connected.

[0135] In one embodiment, the client DU sends a logout request to the cloud authentication server. Upon receiving the logout request, the cloud authentication server verifies the logout request and, if successful, forwards the logout request to the cloud authentication server, which notifies the CU to be connected to log out. The client DU logs out by receiving a logout completion message from the cloud authentication server indicating the CU to be connected.

[0136] This embodiment sends a login request to a cloud authentication server. Upon receiving the login request, the cloud authentication service verifies the login request and, upon successful verification, forwards the login request to the cloud authentication server. The client receives the address information of the DU proxy instance from the proxy pool. Based on the address information of the DU proxy instance, the client sends interaction data to the DU proxy instance, so that the DU proxy instance forwards the interaction data to the CU to be connected. This embodiment enables communication between the client DU and the CU to be connected by forwarding the interaction data to the DU proxy instance, which then forwards the interaction data to the CU to be connected based on the DU proxy instance.

[0137] As an example to better illustrate the data processing method of the 5G cloud private network of this application, refer to Figure 6 , Figure 6 This is a diagram of the authentication process for logging into the 5G cloud-based private network.

[0138] It should be noted that when base stations are software-based, soft encryption methods such as passwords and registration codes can be used to protect the software from being misused. However, all software-based methods carry the risk of being decompiled and cracked. Higher-level authentication typically uses encryption hardware peripherals. The software can only run when the encryption peripheral is connected. However, the production, logistics, transportation, and maintenance of encryption equipment require additional costs. Moreover, encryption hardware is tied to the computer and cannot be dynamically transferred between computers, causing inconvenience to both operators and customers.

[0139] In this embodiment, the client DU sends a login request to the cloud authentication server (ie, cloud authentication service), where the login request includes a user ID, a password, and a preset CU-ID.

[0140] After receiving the login request from the client DU, the cloud authentication service verifies the user ID and password. If the verification fails, it returns a login failure message to the client DU; if the verification passes, it forwards the login request to the cloud authentication server (i.e., the cloud authentication service).

[0141] After receiving the login request forwarded by the cloud authentication service, the cloud authentication service queries the authentication database to verify whether the number of available DU connections of the user exceeds the limit. If so, it returns a DU login failure to the client; if not, it forwards the login request to the cloud DU proxy pool.

[0142] After receiving the login request forwarded by the cloud authentication service, the cloud DU proxy pool creates a DU proxy instance (i.e., DU proxy) and sends a creation completion message of the DU proxy instance to the cloud authentication service;

[0143] Upon receiving the DU proxy instance creation completion message, the cloud authentication service updates the DU connection count in the authentication database. Simultaneously, it requests a CU from the cloud CU pool and forwards the user ID and user-specified CU-ID to the cloud CU pool.

[0144] When the cloud CU pool receives the request information from the cloud authentication service, it checks the CU pool database. If a running instance with the same CU ID already exists for the user, there is no need to create a new CU instance. If not, a new CU instance is created. After creating the new CU instance, the corresponding CU information in the CU pool database is updated. At the same time, the CU IP address is sent to the cloud DU proxy pool.

[0145] After receiving the CU IP, the cloud-based DU proxy pool sets its forwarding route according to the CU IP. After that, the DU proxy instance will forward all data sent by the client DU to the CU corresponding to this IP, and the data sent by this CU will also be forwarded to the client DU through the DU proxy instance.

[0146] After the setting is completed, the IP of the DU agent is further returned to the client DU. After that, the client DU interacts with the CU via the DU agent instance in the cloud.

[0147] The authentication method of the 5G cloud-based private network of this embodiment does not rely on any encryption hardware equipment. At the same time, by deploying the DU software on the client side and the CU on the cloud, data is forwarded between the client DU and the cloud CU through the cloud DU proxy instance. In this way, there is no need to directly transmit the sensitive information of the core business CU on the cloud (such as IP address, etc.) to the client DU, and the CU information can be hidden in the cloud; at the same time, the data sent by the client DU is detected on the DU proxy side, and illegal data from non-target client DUs is discarded, thereby achieving the purpose of client authentication and firewall. Therefore, even if the DU-side software is cracked, it will not affect the entire private network system.

[0148] As an example to better illustrate the data processing method of the 5G cloud private network of this application, refer to Figure 7 , Figure 7 This is a schematic diagram of the offline process of the client DU of this application.

[0149] In this embodiment, the client DU sends a logout notification to the cloud authentication server (ie, cloud authentication service). The logout request includes a user ID, a password, and a preset CU-ID.

[0150] The cloud authentication service verifies the offline request received. If the verification fails, it returns a message to the client DU indicating that the offline request failed. If the verification passes, it forwards the offline notification to the cloud authentication server (i.e., the cloud authentication service).

[0151] After receiving the offline notification forwarded by the cloud authentication service, the cloud authentication service updates the DU connection number information of the user in the authentication database and then forwards the offline notification to the cloud DU proxy pool.

[0152] After receiving the offline notification forwarded by the cloud authentication service, the cloud DU proxy pool destroys the DU proxy instance and sends the DU proxy instance destruction completion information to the cloud authentication service;

[0153] When the cloud authentication service receives the destruction completion information of the DU agent instance, it forwards the offline notification to the cloud CU pool.

[0154] After receiving the offline notification forwarded by the cloud authentication service, the cloud CU pool checks in the CU pool database whether the CU-ID specified by the user is still connected to a DU. If not, the corresponding CU is destroyed and the information record of the CU in the CU pool is updated after completion.

[0155] After the cloud CU pool cleanup operation is completed, the CU cleanup completion information is sent to the cloud authentication service;

[0156] After receiving the CU cleanup completion information, the cloud authentication service sends a logout completion information to the client DU. At this point, the client DU's logout request is completed.

[0157] In this embodiment, after sending the offline notification to the cloud, the cloud authentication service verifies the offline request. After the verification is passed, the corresponding DU proxy instance and the CU without DU connection are destroyed, and the corresponding CU and DU information are updated to realize the offline of the client DU.

[0158] In addition, the present application also provides a data processing device for a 5G cloud-based private network, which includes a memory, a processor, and a data processing program for the 5G cloud-based private network stored in the memory and running on the processor.

[0159] Further, refer to Figure 10 , Figure 10 This is a module diagram of the data processing device for the 5G cloud-based private network of this application;

[0160] The data processing device 100 of the 5G cloud-based private network includes a creation module 10, a first sending module 20, and a first receiving module 30, wherein:

[0161] The creation module 10 is used to create a distributed processing unit DU agent instance when receiving a login request forwarded by the cloud authentication server;

[0162] The first sending module 20 is configured to send a creation completion message to the cloud authentication server when the DU proxy instance is created. Upon receiving the creation completion message, the cloud authentication server requests the centralized processing unit CU pool to send the address information of the CU to be connected to the proxy pool.

[0163] The first receiving module 30 is configured to receive the address information of the CU to be connected, so that when the DU agent instance receives the interactive data sent by the client DU, it forwards the interactive data to the CU to be connected according to the address information;

[0164] Furthermore, the first receiving module 30 includes a destroying unit and a first sending unit;

[0165] The destroying unit is configured to destroy the DU agent instance upon receiving a logoff request forwarded by the cloud authentication server;

[0166] The first sending unit is configured to send a destruction completion message to the cloud authentication server when the destruction of the DU agent instance is completed, wherein the cloud authentication server notifies the CU to be connected to go offline when receiving the destruction completion message.

[0167] refer to Figure 11 The data processing device 100 of the 5G cloud-based private network further includes an acquisition module 40, a forwarding module 50, and a request module 60, wherein:

[0168] The acquisition module 40 is used to obtain the number of DUs currently connected to the client DU when receiving the login request forwarded by the cloud authentication server;

[0169] The forwarding module 50 is configured to forward the login request to the proxy pool when the number of DUs is less than a preset number, wherein the proxy pool creates a DU proxy instance upon receiving the login request and sends a creation completion message of the DU proxy instance to the cloud authentication server;

[0170] The request module 60 is configured to request the CU pool to send the address information of the CU to be connected to the proxy pool upon receiving the creation completion information of the DU proxy instance;

[0171] Furthermore, the request module 60 includes an updating unit and a forwarding unit;

[0172] The updating unit is configured to update the number of DUs currently connected to the client DU according to the offline request when receiving the offline request forwarded by the cloud authentication server;

[0173] The forwarding unit is configured to forward the offline request to the proxy pool, wherein upon receiving the offline request, the proxy pool destroys the DU proxy instance and sends a destruction completion message of the DU proxy instance to the cloud authentication server;

[0174] The forwarding unit is further configured to forward the offline request to the CU pool upon receiving the destruction completion information of the DU agent instance, so as to notify the CU to be connected to go offline.

[0175] refer to Figure 12 The data processing device 100 of the 5G cloud-based private network further includes a second receiving module 70, a second sending module 80 and a third sending module 90, wherein:

[0176] The second receiving module 70 is configured to receive a CU application request sent by a cloud authentication server and determine a CU to be connected based on the CU application request;

[0177] The second sending module 80 is configured to send the address information of the CU to be connected to the proxy pool when the CU to be connected exists;

[0178] The third sending module 90 is configured to create the CU to be connected if the CU to be connected does not exist, and send the address information of the CU to be connected to the proxy pool;

[0179] refer to Figure 13The data processing device 100 of the 5G cloud-based private network further includes a fourth sending module 110, a third receiving module 110 and a fifth sending module 120, wherein:

[0180] The fourth sending module 100 is used to send a login request to the cloud authentication server, wherein the cloud authentication service verifies the login request when receiving the login request, and forwards the login request to the cloud authentication server after successful verification;

[0181] The third receiving module 110 is configured to receive address information of the DU proxy instance sent by the proxy pool;

[0182] The fifth sending module 120 is configured to send interaction data to the DU agent instance according to the address information of the DU agent instance, so that the DU agent instance forwards the interaction data to the CU to be connected.

[0183] Furthermore, the fifth sending module 120 includes a fifth sending unit;

[0184] The fifth sending unit is configured to send a logoff request to the cloud authentication server, wherein the cloud authentication server verifies the logoff request upon receiving the logoff request and forwards the logoff request to the cloud authentication server after successful verification;

[0185] The fifth sending unit is further configured to receive offline completion information of the CU to be connected sent by the cloud authentication server.

[0186] The implementation of the functions of each module of the data processing device of the above-mentioned 5G cloud-based private network is similar to the process in the above-mentioned method embodiment, and will not be repeated here.

[0187] In addition, the present application also provides a storage medium, which stores a data processing method program for a 5G cloud-based private network. When the data processing method program for a 5G cloud-based private network is executed by a processor, the steps of the above-mentioned data processing method for a 5G cloud-based private network are implemented.

[0188] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0189] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0190] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0191] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0192] It should be noted that in the claims, any reference signs placed between brackets shall not be construed as limiting the claims. The word "comprising" does not exclude the presence of components or steps not listed in the claim. The word "a" or "an" preceding a component does not exclude the presence of a plurality of such components. The present application may be implemented by means of hardware comprising several different components and by means of a suitably programmed computer. In a unit claim enumerating several means, several of these means may be embodied by one and the same item of hardware. The use of the words first, second, and third etc. does not indicate any order. These words may be interpreted as names.

[0193] Although the optional embodiments of the present application have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the optional embodiments and all changes and modifications that fall within the scope of the present application.

[0194] Obviously, those skilled in the art may make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalents, this application is intended to include these modifications and variations.

Claims

1. A data processing method for a 5G cloud-based private network, characterized in that: Applied to a proxy pool, the method includes: Upon receiving a login request forwarded by a cloud authentication server, a distributed processing unit DU proxy instance is created, wherein the client DU sends a login request to the cloud authentication server, and upon receiving the login request, the cloud authentication service verifies the login request and, after successful verification, forwards the login request to the cloud authentication server; upon receiving the login request forwarded by the cloud authentication server, the cloud authentication server obtains the number of DUs currently connected to the client DU; and when the number of DUs is less than a preset number, the login request is forwarded to the proxy pool; When the DU proxy instance is created, a creation completion message is sent to the cloud authentication server, wherein upon receiving the creation completion message, the cloud authentication server requests the centralized processing unit CU pool to send the address information of the CU to be connected to the proxy pool; Receive the address information of the CU to be connected, so that when the DU agent instance receives the interactive data sent by the client DU, it forwards the interactive data to the CU to be connected according to the address information.

2. The data processing method for a 5G cloud-based private network according to claim 1, wherein: After the step of receiving the address information of the CU to be connected, the method further includes: Upon receiving the offline request forwarded by the cloud authentication server, destroying the DU agent instance; When the DU agent instance is destroyed, a destruction completion message is sent to the cloud authentication server. When the cloud authentication server receives the destruction completion message, it notifies the CU to be connected to go offline.

3. A data processing method for a 5G cloud-based private network, characterized in that: Applied to a cloud authentication server, the method includes: Upon receiving a login request forwarded by a cloud authentication server, obtaining the number of DUs currently connected to the client DU, wherein the client DU sends a login request to the cloud authentication server, and the cloud authentication server verifies the login request upon receiving the login request, and forwards the login request to the cloud authentication server after successful verification; When the number of DUs is less than a preset number, forwarding the login request to the proxy pool, wherein upon receiving the login request, the proxy pool creates a DU proxy instance and sends a creation completion message of the DU proxy instance to the cloud authentication server; Upon receiving the creation completion information of the DU agent instance, the CU pool is requested to send the address information of the CU to be connected to the agent pool, wherein the agent pool receives the address information of the CU to be connected, so that when the DU agent instance receives the interaction data sent by the client DU, it forwards the interaction data to the CU to be connected according to the address information.

4. The data processing method for a 5G cloud-based private network according to claim 3, wherein: After the step of requesting the CU pool to send the address information of the CU to be connected to the proxy pool, the method further includes: Upon receiving the offline request forwarded by the cloud authentication server, updating the number of DUs currently connected to the client DU according to the offline request; forwarding the offline request to the proxy pool, wherein upon receiving the offline request, the proxy pool destroys the DU proxy instance and sends a destruction completion message of the DU proxy instance to the cloud authentication server; When the destruction completion information of the DU agent instance is received, the offline request is forwarded to the CU pool to notify the CU to be connected to go offline.

5. A data processing method for a 5G cloud-based private network, characterized in that: Applied to a CU pool, the method includes: Receive a CU application request sent by a cloud authentication server, and determine the CU to be connected based on the CU application request, wherein the client DU sends a login request to the cloud authentication server; when the cloud authentication service receives the login request, it verifies the login request, and after successful verification, forwards the login request to the cloud authentication server; when the cloud authentication server receives the login request forwarded by the cloud authentication server, it obtains the number of DUs currently connected to the client DU; when the number of DUs is less than a preset number, it forwards the login request to the proxy pool; when the proxy pool receives the login request, it creates a DU proxy instance and sends a creation completion message of the DU proxy instance to the cloud authentication server; when the cloud authentication server receives the creation completion message of the DU proxy instance, it requests the CU pool to send the address information of the CU to be connected to the proxy pool; When the CU to be connected exists, the address information of the CU to be connected is sent to the proxy pool; When the CU to be connected does not exist, creating the CU to be connected, and sending the address information of the CU to be connected to the proxy pool; The proxy pool receives the address information of the CU to be connected, so that when the DU proxy instance receives the interactive data sent by the client DU, it forwards the interactive data to the CU to be connected according to the address information.

6. A data processing method for a 5G cloud-based private network, characterized in that: Applied to a client DU, the method includes: Send a login request to the cloud authentication server, wherein the cloud authentication service verifies the login request upon receiving the login request and, after successful verification, forwards the login request to the cloud authentication server; upon receiving the login request forwarded by the cloud authentication server, the cloud authentication server obtains the number of DUs currently connected to the client DU; when the number of DUs is less than a preset number, the login request is forwarded to the proxy pool; upon receiving the login request forwarded by the cloud authentication server, the proxy pool creates a distributed processing unit DU proxy instance, and when the creation of the DU proxy instance is completed, sends a creation completion message to the cloud authentication server; upon receiving the creation completion message, the cloud authentication server requests the centralized processing unit CU pool to send the address information of the CU to be connected to the proxy pool; Receive the address information of the DU proxy instance sent by the proxy pool; The interactive data is sent to the DU agent instance according to the address information of the DU agent instance, so that the DU agent instance forwards the interactive data to the CU to be connected.

7. The data processing method for a 5G cloud-based private network according to claim 6, wherein: After the step of sending the interaction data to the DU proxy instance according to the address information of the DU proxy instance, the method further includes: Sending a logoff request to the cloud authentication server, wherein the cloud authentication server verifies the logoff request upon receiving the logoff request, and forwards the logoff request to the cloud authentication server after successful verification; Receive offline completion information of the CU to be connected sent by the cloud authentication server.

8. A data processing device for a 5G cloud-based private network, characterized in that: The data processing device of the 5G cloud-based private network includes a creation module, a first sending module and a first receiving module, wherein: The creation module is used to create a distributed processing unit DU agent instance when receiving a login request forwarded by the cloud authentication server; The first sending module is configured to send a creation completion message to the cloud authentication server when the DU proxy instance is created, wherein upon receiving the creation completion message, the cloud authentication server requests the centralized processing unit CU pool to send the address information of the CU to be connected to the proxy pool; The first receiving module is configured to receive the address information of the CU to be connected, so that when the DU agent instance receives the interactive data sent by the client DU, it forwards the interactive data to the CU to be connected according to the address information; The data processing device of the 5G cloud-based private network further includes an acquisition module, a forwarding module, and a request module, wherein: The acquisition module is used to obtain the number of DUs currently connected to the client DU when receiving the login request forwarded by the cloud authentication server; The forwarding module is configured to forward the login request to the proxy pool when the number of DUs is less than a preset number, wherein the proxy pool creates a DU proxy instance upon receiving the login request and sends a creation completion message of the DU proxy instance to the cloud authentication server; The request module is configured to request the CU pool to send the address information of the CU to be connected to the proxy pool upon receiving the creation completion information of the DU proxy instance; The data processing device of the 5G cloud-based private network further includes a second receiving module, a second sending module and a third sending module, wherein: The second receiving module is configured to receive a CU application request sent by a cloud authentication server, and determine a CU to be connected according to the CU application request; The second sending module is configured to send the address information of the CU to be connected to the proxy pool when the CU to be connected exists; The third sending module is configured to create the CU to be connected if the CU to be connected does not exist, and send the address information of the CU to be connected to the proxy pool; The data processing device of the 5G cloud-based private network further includes a fourth sending module, a third receiving module and a fifth sending module, wherein: The fourth sending module is configured to send a login request to the cloud authentication server, wherein the cloud authentication service verifies the login request upon receiving the login request and forwards the login request to the cloud authentication server after successful verification; The third receiving module is used to receive the address information of the DU proxy instance sent by the proxy pool; The fifth sending module is configured to send interaction data to the DU agent instance according to the address information of the DU agent instance, so that the DU agent instance forwards the interaction data to the CU to be connected.

9. A data processing device for a 5G cloud-based private network, characterized in that: The data processing device of the 5G cloud-based private network includes a memory, a processor, and a data processing program for the 5G cloud-based private network stored in the memory and running on the processor. When the processor executes the data processing program for the 5G cloud-based private network, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A storage medium, characterized in that: The storage medium stores a data processing program for a 5G cloud-based private network, and when the data processing program for the 5G cloud-based private network is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • NFS secure transmission device and method based on proxy forwarding

    CN112751870A

  • Method and apparatus for authentication of integrated access and backhaul (IAB) node in wireless network

    US20210105622A1