Single device power MEC terminal to prevent cyber intrusion

By configuring multiple physical network ports and virtual networks on a single power MEC terminal, the problem that general MEC devices cannot meet the requirements of security partitioning and network isolation is solved. This enables data forwarding, encryption authentication, and protocol conversion, reducing the risk of single point of failure and the space occupied by the device.

CN116455641BActive Publication Date: 2026-05-12SHANGHAI ELECTRIC POWER DESIGN INST
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SHANGHAI ELECTRIC POWER DESIGN INST
Filing Date
2023-04-21
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

Existing general-purpose MEC equipment cannot meet the National Energy Administration's requirements for security zoning, dedicated networks, horizontal isolation, and vertical encryption in 5G operator private networks, and it also has the problems of single point of failure risk and large equipment space occupation.

Method used

Multiple physical network ports and virtual networks are configured on a single power MEC terminal. Virtualization technology is used to create independent communication channels to achieve vertical encryption authentication and protocol conversion of data, simplifying equipment networking.

Benefits of technology

It enables data forwarding, encryption authentication, and protocol conversion to be completed on a single device, reducing the risk of single point of failure, reducing the space occupied by the device, and meeting the requirements of security partitioning and network isolation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116455641B_ABST
    Figure CN116455641B_ABST
Patent Text Reader

Abstract

The application discloses a single-device power MEC terminal for preventing network intrusion, wherein a first physical network port is connected with a 5G core network control plane SMF device; a second physical network port is connected with a 5G base station; a third physical network port is connected with an enterprise intranet switch; a fourth physical network port is connected with an operator wide area network router; a first virtual network is a transmission channel between an encryption authentication application and a UPF network element; a second virtual network is a transmission channel between the encryption authentication application and a protocol conversion application; a third virtual network is a transmission channel between other power applications and the protocol conversion application and the encryption authentication application; and a fourth virtual network is a transmission channel of the UPF network element and the fourth physical network port, serving as a virtual network segment of park management type services connected with non-power services, and improving the terminal park scene adaptability. The application simplifies the network intrusion problem in the prior art, which can be solved by combining a general MEC device with an encryption authentication device and a network switch device for multi-device networking.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power MEC terminal manufacturing technology, and in particular to a single-device power MEC terminal for preventing network intrusion. Background Technology

[0002] In scenarios where 5G operators need to deploy MEC devices with UPF network element functions in user-side campuses, the general MEC devices in operator networks do not have multiple network ports or have not established multiple independent virtual networks. All data is forwarded through a unified network according to the routing table. This networking method cannot meet the requirements of the National Energy Administration for "security zoning, dedicated network, horizontal isolation, and vertical encryption". In addition, the general MEC devices do not have power encryption authentication functions, requiring the addition of dedicated encryption authentication equipment and network switches. The cooperation of multiple devices poses a risk of single point of failure and occupies a large space.

[0003] Therefore, how to implement basic functions such as 5G network UPF data forwarding, encryption authentication, and protocol conversion on a single power MEC terminal, and how to support the expansion of power-related application functions, has become a technical problem that urgently needs to be solved by those skilled in the art. Summary of the Invention

[0004] In view of the above-mentioned deficiencies of the prior art, the present invention provides a single-device power MEC terminal for preventing network intrusion. The purpose of this invention is to simplify the network intrusion problem that the existing general MEC devices need to be combined with multiple devices such as encryption authentication devices and network switch devices to solve.

[0005] To achieve the above objectives, the present invention discloses a single-device power MEC terminal for preventing network intrusion, including a server as a power MEC terminal device.

[0006] The server includes multiple physical network ports, each configured with a corresponding IP address, subnet mask, and gateway address, as well as multiple virtual networks created using virtualization technology.

[0007] The first physical network port is connected to the 5G core network control plane SMF device to test the control plane interface function between the 5G core network control plane SMF device and the UPF network element in the server.

[0008] The second physical network port is connected to the 5G base station and is used to receive data from ordinary user terminals and power terminals.

[0009] The third physical network port is connected to the enterprise's internal network switch;

[0010] The fourth physical network port is connected to the operator's WAN router;

[0011] The first virtual network is a transmission channel between the encryption authentication application and the UPF network element, used to configure the IP address, subnet mask and gateway address for communication in the UPF network element and the encryption authentication application;

[0012] The encryption authentication application and the UPF network element use different IP addresses, but communicate using the same network segment corresponding to the first virtual network.

[0013] The second virtual network is a transmission channel between the encryption authentication application and the protocol conversion application, used to configure IP addresses, subnet masks and gateway addresses for communication in the encryption authentication application and the protocol conversion application;

[0014] The encryption authentication application and the protocol conversion application use different IP addresses, but communicate using the same network segment corresponding to the second virtual network.

[0015] The third virtual network is a transmission channel between other power applications and the protocol conversion application and the encryption authentication application, and is used to configure IP addresses, subnet masks and gateway addresses that can be used for communication in the encryption authentication application, the protocol conversion application and the other power applications;

[0016] Among them, any of the other power applications, the protocol conversion application and the encryption authentication application use different IP addresses, but communicate using the same network segment corresponding to the third virtual network;

[0017] The fourth virtual network serves as the transmission channel between the UPF network element and the fourth physical network port, and as a virtual network segment connecting non-power services for park management, thereby improving the terminal's adaptability to park scenarios.

[0018] Preferably, the virtualization technology is Docker software.

[0019] Preferably, the first, second, third, and fourth physical network ports are all connected to the corresponding 5G core network control plane (SMF) device, the corresponding 5G base station, the corresponding enterprise intranet switch, or the corresponding operator WAN router via network cable or optical fiber.

[0020] Preferably, the other power applications include network security monitoring applications, electricity consumption information collection applications, and / or web applications.

[0021] Preferably, the ordinary user terminal is a smartphone, tablet computer, or personal computer;

[0022] The data transmitted by the ordinary user terminal includes voice.

[0023] Preferably, the power terminal is a gateway device.

[0024] Preferably, the data sent by the ordinary user terminal is processed according to the following process:

[0025] The data is encapsulated according to the 5G air interface protocol using SDAP, PDAP, RLC and MAC, and then the data stream is sent to the 5G base station by the physical layer.

[0026] After parsing the data, the 5G base station performs GTPU, UDP, IP and MAC encapsulation according to the N3 interface protocol between the 5G base station and the UPF network element in the server, and sends it to the UPF network element in the server through the second physical network port.

[0027] After receiving the data, the UPF network element in the server forwards the data to the fourth virtual network according to the forwarding rules defined by SMF and the requirements of the N6 interface protocol.

[0028] The fourth virtual network forwards the data to the operator's wide area network via the fourth physical network port according to the network mapping and forwarding settings.

[0029] Preferably, the data transmitted by the power terminal is processed according to the following procedure:

[0030] The data is encapsulated according to the 5G air interface protocol using SDAP, PDAP, RLC and MAC, and then the data stream is sent to the 5G base station by the physical layer.

[0031] After parsing the data, the 5G base station performs GTPU, UDP, IP and MAC encapsulation according to the N3 interface protocol between the 5G base station and the UPF network element in the server, and sends it to the UPF network element in the server through the second physical network port.

[0032] After receiving the data, the UPF network element in the server forwards the data to the first virtual network according to the forwarding rules defined by SMF and the requirements of the N6 interface protocol.

[0033] The encryption authentication application forwards the data to the second or third virtual network according to the instructions of the first virtual network and the routing table;

[0034] The protocol conversion application performs protocol parsing and conversion on the data according to the instructions of the second virtual network, and then forwards it to the third virtual network;

[0035] The third virtual network sends the data to the other power applications according to the routing table, or sends the data to the power intranet through the enterprise intranet switch via the third physical network port.

[0036] The beneficial effects of this invention are:

[0037] The application of this invention simplifies the network intrusion problem that requires existing technologies to combine general MEC devices with multiple devices such as encryption and authentication devices and network switch devices to solve.

[0038] The following will further explain the concept, specific structure, and technical effects of the present invention in conjunction with the accompanying drawings, so as to fully understand the purpose, features, and effects of the present invention. Attached Figure Description

[0039] Figure 1 A schematic diagram of a network structure according to an embodiment of the present invention is shown.

[0040] Figure 2 This illustrates the data flow process sent by a regular user terminal in one embodiment of the present invention.

[0041] Figure 3 This illustrates the data flow process sent by a power terminal in one embodiment of the present invention. Detailed Implementation

[0042] Example: Figure 1 As shown, a single-device power MEC terminal for preventing network intrusion includes a server that serves as the power MEC terminal device.

[0043] The server includes multiple physical network ports, each configured with a corresponding IP address, subnet mask, and gateway address, as well as multiple virtual networks created using virtualization technology.

[0044] The first physical network port is connected to the 5G core network control plane SMF device and is used to test the control plane interface function between the 5G core network control plane SMF device and the UPF network element in the server.

[0045] The second physical network port is connected to the 5G base station and is used to receive data from ordinary user terminals and power terminals.

[0046] The third physical network port connects to the enterprise's internal network switch;

[0047] The fourth physical network port connects to the ISP's WAN router;

[0048] The first virtual network is the transmission channel between the encryption authentication application and the UPF network element, used to configure the IP address, subnet mask and gateway address for communication in the UPF network element and the encryption authentication application;

[0049] The encryption authentication application and the UPF network element use different IP addresses, but communicate using the same network segment corresponding to the first virtual network.

[0050] The second virtual network is a transmission channel between the encryption authentication application and the protocol conversion application, used to configure the IP address, subnet mask and gateway address for communication in the encryption authentication application and the protocol conversion application;

[0051] The encryption authentication application and the protocol conversion application use different IP addresses, but communicate using the same network segment corresponding to the second virtual network.

[0052] The third virtual network is a transmission channel between other power applications and protocol conversion applications and encryption authentication applications. It is used to configure IP addresses, subnet masks and gateway addresses that can be used for communication in encryption authentication applications, protocol conversion applications and other power applications.

[0053] Among them, any other power application, protocol conversion application and encryption authentication application use different IP addresses, but communicate using the same network segment corresponding to the third virtual network;

[0054] The fourth virtual network serves as the transmission channel between the UPF network element and the fourth physical network port, and as a virtual network segment connecting non-power business park management services, thereby improving the terminal's adaptability to park scenarios.

[0055] The principle of this invention is as follows:

[0056] This invention makes the four physical network ports of the server serving as the power MEC terminal device independent of each other. At the same time, four virtual networks created using virtualization technology are used to separately transfer the data input and output of the four physical network ports. This enables a single power MEC terminal device to have vertical encryption authentication and protocol conversion functions during mutual communication. This simplifies the network intrusion problem that the existing general MEC devices need to be networked with multiple devices such as encryption authentication devices and network switches to solve.

[0057] In some embodiments, the virtualization technology is Docker software.

[0058] In some embodiments, the first physical network port, the second physical network port, the third physical network port, and the fourth physical network port are all connected to the corresponding 5G core network control plane SMF equipment, the corresponding 5G base station, the corresponding enterprise intranet switch, or the corresponding operator WAN router via network cable or optical fiber.

[0059] In some embodiments, other power applications include cybersecurity monitoring applications, electricity consumption information collection applications, and / or web applications.

[0060] In some embodiments, the common user terminal is a smartphone, tablet computer, or personal computer;

[0061] Data transmitted from ordinary user terminals includes voice.

[0062] In some embodiments, the power terminal is a gateway device.

[0063] like Figure 2 As shown, in some embodiments, data sent by a regular user terminal flows according to the following process:

[0064] After being encapsulated in accordance with 5G air interface protocols using SDAP, PDAP, RLC, and MAC, the data stream is sent to the 5G base station by the physical layer.

[0065] After the 5G base station parses the data, it encapsulates it into GTPU, UDP, IP and MAC according to the N3 interface protocol between the 5G base station and the UPF network element in the server, and sends it to the UPF network element in the server through the second physical network port.

[0066] After receiving the data, the UPF network element in the server forwards the data to the fourth virtual network in accordance with the forwarding rules defined by SMF and the requirements of the N6 interface protocol.

[0067] The fourth virtual network forwards data to the operator's wide area network via the fourth physical network port according to the network mapping and forwarding settings.

[0068] During normal operation, data is sent from the UPF network element to the protocol conversion application. The flow starts from the UPF network element, passes through the first virtual network, the encryption and authentication application, and the second virtual network before reaching the protocol conversion application.

[0069] When reverse traffic occurs, it is sent from the protocol conversion application to the UPF network element. The flow starts from the protocol conversion application, passes through the second virtual network, the encryption and authentication application, the first virtual network, and finally to the UPF network element.

[0070] like Figure 3 As shown, in some embodiments, the data sent by the power terminal flows according to the following process:

[0071] After being encapsulated in accordance with 5G air interface protocols using SDAP, PDAP, RLC, and MAC, the data stream is sent to the 5G base station by the physical layer.

[0072] After the 5G base station parses the data, it encapsulates it into GTPU, UDP, IP and MAC according to the N3 interface protocol between the 5G base station and the UPF network element in the server, and sends it to the UPF network element in the server through the second physical network port.

[0073] After receiving the data, the UPF network element in the server forwards the data to the first virtual network according to the forwarding rules defined by SMF and the requirements of the N6 interface protocol.

[0074] Among them, the forwarding rules defined by SMF are the core network elements for making data forwarding strategies. They function similarly to subway signposts, allowing people going to different low points to reach different exits.

[0075] N6 is a standardized interface between 5G UPF and TCP / IP networks.

[0076] The encryption authentication application forwards data to the second or third virtual network according to the instructions of the first virtual network and the routing table;

[0077] The protocol conversion application performs protocol parsing and conversion on the data according to the instructions of the second virtual network and then forwards it to the third virtual network;

[0078] The third virtual network sends data to other power applications according to the routing table, or sends data to the power intranet through the enterprise intranet switch via the third physical network port.

[0079] The preferred embodiments of the present invention have been described in detail above. It should be understood that those skilled in the art can make numerous modifications and variations based on the concept of the present invention without creative effort. Therefore, all technical solutions that can be obtained by those skilled in the art based on the concept of the present invention through logical analysis, reasoning, or limited experimentation on the basis of existing technology should be within the scope of protection defined by the claims.

Claims

1. A single-device power MEC terminal for preventing network intrusion, including a server serving as the power MEC terminal device; characterized in that, The server includes multiple physical network ports, each configured with a corresponding IP address, subnet mask, and gateway address, as well as multiple virtual networks created using virtualization technology; The first physical network port is connected to the 5G core network control plane SMF device to test the control plane interface function between the 5G core network control plane SMF device and the UPF network element in the server. The second physical network port is connected to the 5G base station and is used to receive data from ordinary user terminals and power terminals. The third physical network port is connected to the enterprise's internal network switch; The fourth physical network port is connected to the operator's WAN router; The first virtual network is a transmission channel between the encryption authentication application and the UPF network element, used to configure the IP address, subnet mask and gateway address for communication in the UPF network element and the encryption authentication application; The encryption authentication application and the UPF network element use different IP addresses, but communicate using the same network segment corresponding to the first virtual network. The second virtual network is a transmission channel between the encryption authentication application and the protocol conversion application, used to configure IP addresses, subnet masks and gateway addresses for communication in the encryption authentication application and the protocol conversion application; The encryption authentication application and the protocol conversion application use different IP addresses, but communicate using the same network segment corresponding to the second virtual network. The third virtual network is a transmission channel between other power applications and the protocol conversion application and the encryption authentication application, and is used to configure IP addresses, subnet masks and gateway addresses that can be used for communication in the encryption authentication application, the protocol conversion application and the other power applications; Among them, any of the other power applications, the protocol conversion application and the encryption authentication application use different IP addresses, but communicate using the same network segment corresponding to the third virtual network; The fourth virtual network serves as the transmission channel between the UPF network element and the fourth physical network port, and as a virtual network segment connecting non-power services for park management, thereby improving the terminal's adaptability to park scenarios.

2. The single-device power MEC terminal for preventing network intrusion according to claim 1, characterized in that, The virtualization technology mentioned is Docker software.

3. The single-device power MEC terminal for preventing network intrusion according to claim 1, characterized in that, The first, second, third, and fourth physical network ports are all connected to the corresponding 5G core network control plane (SMF) equipment, the corresponding 5G base station, the corresponding enterprise intranet switch, or the corresponding operator WAN router via network cable or optical fiber.

4. The single-device power MEC terminal for preventing network intrusion according to claim 1, characterized in that, Other power applications include network security monitoring applications, electricity consumption information collection applications, and / or web applications.

5. The single-device power MEC terminal for preventing network intrusion according to claim 1, characterized in that, The common user terminal is a smartphone, tablet computer, or personal computer; The data transmitted by the ordinary user terminal includes voice.

6. The single-device power MEC terminal for preventing network intrusion according to claim 1, characterized in that, The power terminal is a gateway device.

7. The single-device power MEC terminal for preventing network intrusion according to claim 1, characterized in that, The data sent by the ordinary user terminal flows according to the following process: The data is encapsulated according to the 5G air interface protocol using SDAP, PDAP, RLC and MAC, and then the data stream is sent to the 5G base station by the physical layer. After parsing the data, the 5G base station performs GTPU, UDP, IP and MAC encapsulation according to the N3 interface protocol between the 5G base station and the UPF network element in the server, and sends it to the UPF network element in the server through the second physical network port. After receiving the data, the UPF network element in the server forwards the data to the fourth virtual network according to the forwarding rules defined by SMF and the requirements of the N6 interface protocol. The fourth virtual network forwards the data to the operator's wide area network via the fourth physical network port according to the network mapping and forwarding settings.

8. The single-device power MEC terminal for preventing network intrusion according to claim 1, characterized in that, The data transmitted by the power terminal is processed according to the following procedure: The data is encapsulated according to the 5G air interface protocol using SDAP, PDAP, RLC and MAC, and then the data stream is sent to the 5G base station by the physical layer. After parsing the data, the 5G base station performs GTPU, UDP, IP and MAC encapsulation according to the N3 interface protocol between the 5G base station and the UPF network element in the server, and sends it to the UPF network element in the server through the second physical network port. After receiving the data, the UPF network element in the server forwards the data to the first virtual network according to the forwarding rules defined by SMF and the requirements of the N6 interface protocol. The encryption authentication application forwards the data to the second or third virtual network according to the instructions of the first virtual network and the routing table; The protocol conversion application performs protocol parsing and conversion on the data according to the instructions of the second virtual network, and then forwards it to the third virtual network; The third virtual network sends the data to the other power applications according to the routing table, or sends the data to the power intranet through the enterprise intranet switch via the third physical network port.