Network Isolation Method, Apparatus, Device, and Storage Medium

By identifying the device identity and dividing ports based on interface-level VLANs, network isolation between 5G and WIFI is solved, and network instability and reliability problems when 5G and WIFI are jointly deployed, improving network stability and reliability.

CN117528844BActive Publication Date: 2025-07-29CHINA MOBILE ZIJIN INNOVATION INST CO LTD +2
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202311556999.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-11-20
Publication Date
2025-07-29
Estimated Expiration
2043-11-20

AI Technical Summary

Technical Problem

When 5G and WIFI are jointly deployed, the network usage is unstable and the reliability is not high. This is mainly because the WIFI AP device is in the same broadcast domain as the RRU device and the base station, resulting in traffic not being isolated.

Method used

By identifying the identity information of the device, the base station judges and connects the ports divided by the interface level VLAN based on the base station, and forwards the device data so that the network traffic of different devices is in different broadcast domains, realizing traffic isolation.

Benefits of technology

It solves the problem of network instability when co-deployed 5G and WIFI, improves the reliability and stability of the network, maximizes the use of existing equipment, and reduces investment and construction complexity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117528844B_ABST
    Figure CN117528844B_ABST
Patent Text Reader

Abstract

The present application discloses a network isolation method, apparatus, device and storage medium, belonging to the field of wireless communication technologies. In the present application, when it is detected that a device is connected, the identity information of the device is identified, wherein the identity information is obtained based on the judgment of a base station, and then based on the identity information of the device, the corresponding port is connected, wherein the port is obtained based on the interface-level VLAN division, and finally based on the corresponding port, the data that the device needs to send is forwarded. The present application enables the network traffic of the device to be in different broadcast domains and the traffic data to be isolated, achieving stable network use and high reliability when 5G and WIFI are co-deployed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of wireless communications, and in particular to network isolation methods, devices, equipment, and storage media. Background Art

[0002] The fifth generation mobile communication technology (5G) is a new generation of broadband mobile communication technology with the characteristics of high speed, low latency and large connection. WiFi, also known as WLAN, is a wireless communication technology used in local area networks. When building wireless networks, to save investment, simplify construction and maximize the use of existing equipment, 5G and WiFi are often deployed simultaneously, which makes the network integration of 5G and WiFi particularly important.

[0003] In the existing technology, the network integration of 5G and WiFi uses a common fronthaul deployment solution. However, since the WiFi AP device, RRU (remote radio unit) and BBU (base station) in the common fronthaul deployment solution are in the same broadcast domain, and the network traffic of different devices is not isolated, the network usage is unstable and the reliability is low when 5G and WiFi are deployed together.

[0004] The above content is only used to assist in understanding the technical solution of this application and does not constitute an admission that the above content is prior art. Summary of the Invention

[0005] The main purpose of this application is to provide a network isolation method, device, equipment and storage medium, aiming to solve the technical problems of unstable network usage and low reliability when 5G and WIFI are deployed together.

[0006] To achieve the above objectives, the present application provides a network isolation method, which is applied to an expansion device. The network isolation method includes the following steps:

[0007] When a device is detected to be connected, identifying the identity information of the device, wherein the identity information is obtained based on the judgment of the base station;

[0008] Based on the identity information of the device, connecting to the corresponding port, wherein the port is obtained based on the interface-level VLAN division;

[0009] Based on the corresponding port, forward the data that the device needs to send.

[0010] Optionally, before the step of identifying the identity information of the device when detecting access of the device, wherein the identity information is obtained based on judgment by the base station, the method includes:

[0011] Connecting to base stations of the 5G fronthaul network;

[0012] Based on the ECPRI protocol, an Ethernet interface is added, where the Ethernet interface supports the access of WIFI devices to the 5G fronthaul network;

[0013] The Ethernet interface is divided into different ports using interface-level VLAN.

[0014] Optionally, the step of connecting to the corresponding port based on the identity information of the device, where the port is obtained by dividing based on interface-level VLAN, includes:

[0015] If the identity information of the device is an RRU device, use the port corresponding to the RRU device to connect to the device;

[0016] If the identity information of the device is a normal AP or an abnormal device, use the port corresponding to the normal AP or abnormal device to connect to the device.

[0017] Optionally, the step of forwarding the data that the device needs to send based on the corresponding port includes:

[0018] Receive the data that the device needs to send and monitor the type of the data;

[0019] If there is only one type of data, directly forward the data that the device needs to send based on the corresponding port;

[0020] If there are multiple types of data, place the data into the send queue and forward the data with the highest priority in the send queue through the corresponding port.

[0021] In addition, to achieve the above object, the present application also provides a network isolation method applied to a base station. The network isolation method includes the following steps:

[0022] When it is detected that a device is connected to an extended device, receive the message broadcast by the device and change the identity information of the device based on the message, where the identity information is divided into normal AP devices, abnormal devices, RRU devices, and undetermined devices;

[0023] Send the information required by the configuration device to the device with undetermined identity information and establish a connection channel with the device. If the establishment of the connection channel with the device fails, determine that the identity information of the device is an abnormal device and change the identity information of the device to an abnormal device;

[0024] Initiate identity authentication to the device with undetermined identity information and change the identity information of the device.

[0025] Optionally, when it is detected that a device is connected to the extended device, receive the message broadcast by the device, and change the identity information of the device based on the message. The step of dividing the identity information into ordinary AP devices, abnormal devices, RRU devices, and undetermined devices includes:

[0026] When it is detected that a device is connected to the extended device, prepare to receive the message broadcast by the device;

[0027] If the message sent by the device is not received within the preset time, change the identity information of the device to an ordinary AP device;

[0028] If the message sent by the device does not carry device information, change the identity information of the device to an abnormal device;

[0029] If the message sent by the device is received within the preset time and the message carries device information, change the identity information of the device to undetermined.

[0030] Optionally, the step of initiating an identity authentication to a device with undetermined identity information and changing the identity information of the device includes:

[0031] Initiate an identity authentication to a device with undetermined identity information, and determine whether the identity authentication is successful;

[0032] If the identity authentication of the device is successful, change the identity information of the device to an RRU device;

[0033] If the identity authentication of the device fails, change the identity information of the device to an abnormal device.

[0034] In addition, to achieve the above object, the present application further provides a network isolation device applied to an extended device. The device includes:

[0035] An identification module, configured to identify the identity information of a device when detecting that a device is connected. The identity information is obtained based on a base station, and based on the identity information of the device, connect to a corresponding port, where the port is obtained by dividing according to interface-level VLAN;

[0036] A forwarding module, configured to forward the data sent by the device.

[0037] In addition, to achieve the above object, the present application further provides a network isolation device. The device includes: a memory, a processor, and a network isolation program stored on the memory and executable on the processor. The network isolation program is configured to implement the steps of the network isolation method as described above.

[0038] In addition, to achieve the above-mentioned purpose, the present application also provides a storage medium, on which a network isolation program is stored. When the network isolation program is executed by a processor, the steps of the network isolation method described above are implemented.

[0039] The present application provides a network isolation method, apparatus, device and storage medium. Compared with the related art common fronthaul deployment scheme in which the WIFI AP device, RRU device and base station are in the same broadcast domain and the network traffic is not isolated, resulting in unstable network use and low reliability when 5G and WIFI are deployed together, the present application identifies the identity information of the device when a device access is detected, wherein the identity information is obtained based on the judgment of the base station, and then connects to the corresponding port based on the identity information of the device, wherein the port is obtained based on the interface-level VLAN division, and finally forwards the data that the device needs to send based on the corresponding port. It can be understood that the present application uses different ports to connect different devices, so that the network traffic of the device is in different broadcast domains, and the traffic data is isolated, which solves the problem of unstable network use and low reliability when 5G and WIFI are deployed together. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] Figure 1 It is a structural diagram of a network isolation device in a hardware operating environment involved in an embodiment of the present application;

[0041] Figure 2 This is a flow chart of the first embodiment of the present application;

[0042] Figure 3 This is a flow chart of the second embodiment of the present application;

[0043] Figure 4 This is a structural diagram of the 5G fronthaul network mode for this application;

[0044] Figure 5 This is a flow chart of the third embodiment of the present application;

[0045] Figure 6 Schematic diagram of the process of determining the device type for the base station of this application;

[0046] Figure 7 This is a structural block diagram of a network isolation device applied to the expansion device side of this application;

[0047] Figure 8 This is a structural block diagram of a network isolation device applied to a base station.

[0048] The realization of the purpose, functional features and advantages of this application will be further explained in conjunction with embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION

[0049] It should be understood that the specific embodiments described herein are only used to explain the present application and are not intended to limit the present application.

[0050] Reference Figure 1 , Figure 1 This is a schematic diagram of the network isolation device structure of the hardware operating environment involved in the embodiment of the present application.

[0051] like Figure 1 As shown, the network isolation device may include: a processor 1001, such as a central processing unit (CPU), a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. Among them, the communication bus 1002 is used to realize the connection and communication between these components. The user interface 1003 may include a display screen (Display), an input unit such as a keyboard (Keyboard), and the user interface 1003 may optionally include a standard wired interface and a wireless interface. The network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a wireless fidelity (WIreless-FIdelity, WI-FI) interface). The memory 1005 may be a high-speed random access memory (Random Access Memory, RAM) memory, or a stable non-volatile memory (Non-Volatile Memory, NVM), such as a disk memory. The memory 1005 may also be a storage device independent of the aforementioned processor 1001.

[0052] Those skilled in the art will understand that Figure 1 The structure shown in does not constitute a limitation on the network isolation device, and may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.

[0053] like Figure 1 As shown, the memory 1005 as a storage medium may include an operating system, a data storage module, a network communication module, a user interface module and a network isolation program.

[0054] exist Figure 1 In the network isolation device shown, the network interface 1004 is mainly used for data communication with other devices; the user interface 1003 is mainly used for data interaction with the user; the processor 1001 and the memory 1005 in the network isolation device of the present application can be set in the network isolation device, and the network isolation device calls the network isolation program stored in the memory 1005 through the processor 1001, and executes the network isolation method provided in the embodiment of the present application.

[0055] The first embodiment of the present application provides a network isolation method applied to an expansion device, referring to Figure 2 , the network isolation method includes:

[0056] It should be noted that the method execution subject of this embodiment is an expansion device, which can be a network device with data receiving and sending functions such as a HUB or a switch, and this application does not impose any specific restrictions.

[0057] It should be understood that, compared with the prior art co-fronthaul deployment scheme in which the WIFI AP device, RRU device and base station are in the same broadcast domain, and the network traffic is not isolated, resulting in unstable network usage and low reliability when 5G and WIFI are deployed together, the present application identifies the identity information of the device when a device access is detected, wherein the identity information is obtained based on the judgment of the base station, and then connects to the corresponding port based on the identity information of the device, wherein the port is obtained based on the interface-level VLAN division, and finally forwards the data that the device needs to send based on the corresponding port. Since the present application uses different ports to connect different devices, the network traffic of the device is in different broadcast domains, and the traffic data is isolated, which solves the problem of unstable network usage and low reliability when 5G and WIFI are deployed together.

[0058] The following description uses the HUB as the expansion device.

[0059] Step S10: When a device access is detected, the identity information of the device is identified, wherein the identity information is obtained based on the judgment of the base station.

[0060] In a specific implementation, when the extension device detects that a device has been connected, it identifies the identity information of the connected device.

[0061] It should be noted that the expansion device itself cannot identify whether a device is connected to the port. The process of detecting whether a device is connected is to detect the information sent by the base station. If the expansion device detects that the base station has changed the identity information of the access device, it is determined that a device is connected to the port.

[0062] It should be noted that the identity information of the device includes the model and type of the device, wherein the type of the device is divided into an RRU device, a common AP device or an abnormal device.

[0063] Step S20: connecting to corresponding ports based on the identity information of the device, wherein the ports are obtained based on interface-level VLAN division.

[0064] In a specific implementation, the extension device connects to the port corresponding to the identity information based on the identity information of the device.

[0065] Among them, the step of connecting to the corresponding port based on the identity information of the device, where the port is obtained by dividing according to interface-level VLAN, specifically includes:

[0066] Step S21: If the identity information of the device is an RRU device, use the port corresponding to the RRU device to connect to the device.

[0067] It can be understood that the full English name of the RRU device is Remote Radio Unit, translated as radio remote unit. Its function is to transmit the radio frequency part of a single sector in the base station to a transmitting device at a certain distance through optical fiber, so that the transmitting device can share resources with other sectors of the original base station and improve capacity.

[0068] In specific implementation, if the extended device identifies that the identity information of the device is an RRU device, the extended device uses the Trunk port corresponding to the RRU device to connect to the device.

[0069] It should be noted that the Trunk port can send multiple VLAN packets, and all of its packets need to carry VLAN Tags. Among them, the Trunk port is usually used for interconnection between network transmission devices.

[0070] It should be understood that a packet is a data unit for exchange and transmission in a network and is also a unit of network transmission. A packet contains the complete data information to be sent, and its length is inconsistent. Among them, the packet will be continuously encapsulated into groups, packets or frames for transmission during the transmission process. The encapsulation method is to add some control information to the header of the packet, and the control information is the packet header.

[0071] Step S22: If the identity information of the device is a normal AP or an abnormal device, use the port corresponding to the normal AP or the abnormal device to connect to the device.

[0072] In specific implementation, if the extended device identifies that the identity information of the device is a normal AP device or an abnormal device, the extended device uses the Access port corresponding to the normal AP device or the abnormal device to connect to the device.

[0073] It should be noted that the Access port can only send one VLAN packet at a time. Since the packets sent by the Access port do not carry VLAN Tags, the Access port is generally used to connect to user terminal devices that cannot recognize VLAN Tags. Among them, the Access port is usually used when it is not necessary to distinguish different VLAN members.

[0074] Step S30: Forward the data that the device needs to send based on the corresponding port.

[0075] In a specific implementation, the extension device forwards the data that the access device needs to send based on the corresponding port.

[0076] It should be noted that if the access device is connected to the Trunk port, the extension device transmits the data that the access device needs to send to the base station through the Trunk port; if the access device is connected to the Access port, the extension device transmits the data that the access device needs to send to the base station through the Access port.

[0077] The step of forwarding the data to be sent by the device based on the corresponding port specifically includes:

[0078] Step S31: receiving data that the device needs to send, and monitoring the type of the data.

[0079] In a specific implementation, the extension device receives data that the access device needs to transmit, and monitors the type of the data.

[0080] It should be understood that the data includes PTP traffic, IQ traffic, IR traffic and WIFI traffic. PTP traffic, IQ traffic and IR traffic are all traffic transmitted from the RRU device to the extended device, and WIFI traffic is traffic transmitted from the WIFI device to the extended device. Among them, 5G traffic includes three types of traffic: PTP traffic, IQ traffic and IR traffic.

[0081] Step S32: If there is only one type of data, the data that the device needs to send is forwarded directly based on the corresponding port.

[0082] In a specific implementation, if the extension device determines that the types of the traffic data to be forwarded are all the same, the extension device forwards the traffic data to be sent by the device based on the port corresponding to the device.

[0083] Step S33: If there are multiple types of data, the data are placed into a sending queue, and the data with the highest priority in the sending queue is forwarded through the corresponding port.

[0084] In a specific implementation, if the expansion device determines that there are several types of traffic data that need to be forwarded, the expansion device places the traffic data into a sending queue, and then forwards the traffic data with the highest priority in the sending queue based on the port corresponding to the device.

[0085] It should be understood that the priority of the traffic data should be set as PTP traffic > IQ traffic > IR traffic > WIFI traffic, wherein the priority of the traffic data can also be manually set based on business needs.

[0086] It should be noted that the priority of 5G traffic is usually higher than that of WIFI traffic. In the common fronthaul network, when WIFI traffic and 5G traffic enter the extended device or RRU device simultaneously, due to the different requirements for reliability and real-time performance of the traffic within the same extended device or RRU device, the extended device needs to distinguish different types of traffic and mark them with different priorities respectively to ensure the high availability of the 5G network.

[0087] For example, since IR traffic can be retransmitted and has high reliability, IR traffic can be set to a lower priority. Since IQ traffic is sent in real time, if IQ traffic cannot be sent in time, an error code will be generated, so IQ traffic needs to be set to a higher priority.

[0088] It should be noted that the retransmission of the IR traffic refers to that in network transmission, if the base station fails to correctly receive the IR traffic data packet sent by the extended unit, the extended unit will retransmit the uncorrectly received IR traffic data packet to ensure the correct transmission of the IR traffic data.

[0089] This application provides a network isolation method, device, system, equipment and storage medium. In this embodiment, compared with the problem in the related technology that in the common fronthaul deployment scheme, the WIFI AP device, RRU device and base station are in the same broadcast domain and the network traffic is not isolated, resulting in unstable network use and low reliability when 5G and WIFI are co-deployed. In this application, when detecting that a device is accessing, the identity information of the device is identified, where the identity information is obtained based on the judgment of the base station. Then, based on the identity information of the device, the corresponding port is connected, where the port is obtained by dividing the interface-level VLAN. Finally, based on the corresponding port, the data that the device needs to send is forwarded. Since this application uses different ports to connect different devices, the network traffic of the devices is in different broadcast domains and the traffic data is isolated, solving the problem of unstable network use and low reliability when 5G and WIFI are co-deployed.

[0090] Based on the first embodiment of this application, the second embodiment of this application is proposed. Refer to Figure 3 , before the step of identifying the identity information of the device when detecting that a device is accessing, the network isolation method includes steps A10 - A30:

[0091] It should be noted that the networking mode of this embodiment connects to the base station of the 5G fronthaul network, and then based on the ECPRI protocol, an Ethernet interface is added, where the Ethernet interface supports the access of WIFI devices to the 5G fronthaul network. Finally, the Ethernet interface is divided into different ports using the interface-level VLAN, enabling 5G and WIFI to be co-deployed in the fronthaul, maximizing the utilization of existing equipment, resulting in less investment and simpler construction.

[0092] Step A10: Connect to the base station of the 5G fronthaul network.

[0093] In a specific implementation, the extension device is connected to the base station of the 5G fronthaul network.

[0094] For example, the expansion device is connected to the base station of the 5G fronthaul network through the Trunk port and Figure 4 , forming a complete 5G fronthaul network. The full name of AC in English is Access Controller, which is translated as wireless controller; the full name of AP in English is Access Point, which is translated as wireless access point; the full name of NR in English is New Radio, which is translated as new air interface technology (5G).

[0095] In this scenario, the AP device can be hung under the RRU, or directly hung on the EU's downlink port through a switch. The EU device usually has 8 downlink ports and supports cascading. The downlink port can be connected to both the RRU device and the switch or directly to the AP, making the fronthaul network more flexible.

[0096] Step A20: Based on the ECPRI protocol, an Ethernet interface is added, wherein the Ethernet interface supports WIFI devices to access the 5G fronthaul network.

[0097] In a specific implementation, the expansion device adds an Ethernet interface based on the ECPRI protocol, wherein the Ethernet interface supports WIFI devices to access the 5G fronthaul network.

[0098] It should be noted that the full English name of ECPRI is ethernet CPRI or enhanced CPRI. Ethernet CPRI is used to indicate that the ECPRI protocol is a CPRI protocol carried on Ethernet, and enhanced CPRI is used to indicate that the ECPRI protocol is an evolution of the CPRI protocol. ECPRI and CPRI are both interface specifications between base stations and RRU devices in wireless networks.

[0099] It should be understood that the full English name of CPRI is Common Public Radio Interface, which defines the communication interface specification between radio control equipment and radio equipment in cellular wireless networks. It is widely used in LTE and 5G base station systems. Among them, the CPRI protocol is a protocol for the physical layer and data link layer.

[0100] It should be noted that the physical layer and the data link layer are the two bottommost layers in the OSI reference model. Among them, the 7 layers of the OSI reference model from low to high are the Physical Layer, Data Link Layer, Network Layer, Transport Layer, Session Layer, Presentation Layer, and Application Layer.

[0101] Step A30: Divide the Ethernet interface into different ports using interface-level VLAN.

[0102] In a specific implementation, the expansion device divides the Ethernet interface into Trunk ports and Access ports using interface-level VLAN.

[0103] It should be noted that the English full name of VLAN is Virtual Local Area Network, which is translated as Virtual Local Area Network. The VLAN technology divides a physical LAN into multiple logical VLANs. Among them, hosts in the same VLAN can communicate directly, while hosts in different VLANs cannot communicate directly, thus enhancing the security of the local area network.

[0104] It should be understood that after dividing VLANs, broadcast packets are restricted within the same VLAN, that is, each VLAN is a separate broadcast domain, effectively restricting the scope of the broadcast domain. Based on VLANs, different hosts can be divided into different workgroups. Among them, hosts in the same workgroup can be located in different physical locations, making the construction and maintenance of the network more convenient.

[0105] It can be understood that dividing VLANs based on ports is the simplest and most effective VLAN division method. After customizing VLAN members according to device ports and adding the specified ports to the specified VLAN, the ports can forward the packets of the VLAN.

[0106] For example, using interface-level VLAN division, it is stipulated that the VLAN ID of layer 2 PTP traffic is 501, the VLAN ID of IQ traffic is 502, the VLAN ID of IR traffic is 503, and the VLAN ID of WIFI data traffic is 1001. Different types of traffic form different forwarding domains. Among them, the base station belongs to VLAN 501, 502, and 503 at the same time. The traffic entering and leaving the base station must carry a VLAN TAG to ensure that 5G-related traffic and devices are in an independent forwarding domain.

[0107] It should be noted that the above VLAN IDs such as 501, 502, 503, 1001 are just examples. In actual use, the VLAN IDs for different traffic can be configured through network management. For example, when the VLAN function in ORAN Option 7-2 is supported, in order to distinguish the traffic of different cells and different antennas, VLAN IDs will also be added. At this time, it can be flexibly configured through the network to avoid the used VLAN IDs. In addition to statically configuring VLANs, dynamic VLANs can also be considered to enable extended devices to manage network resources more flexibly. Among them, dynamic VLANs are dynamically allocated based on user identities or device types, which can better meet the network security and performance requirements.

[0108] In this embodiment, the present application connects to a base station in the 5G fronthaul network, and then based on the ECPRI protocol, an Ethernet interface is added. Among them, the Ethernet interface supports WIFI devices to access the 5G fronthaul network. Finally, the Ethernet interface is divided into different ports using interface-level VLANs, enabling the integration of the 5G fronthaul network and WIFI devices.

[0109] In addition, the third embodiment of the present application provides a network isolation method applied to a base station. Referring to Figure 5 , the network isolation method includes:

[0110] It should be noted that the execution subject of the method in this embodiment is a base station, and the base station can be a network device with data transceiver and processing functions such as a switch or a router. The present application does not make specific limitations.

[0111] The following takes a switch as the base station for specific description.

[0112] Step B10: When it is detected that a device is connected to the expansion unit, receive the message broadcast by the device, and change the identity information of the device based on the message. Among them, the identity information is divided into ordinary AP devices, abnormal devices, RRU devices, and undetermined devices.

[0113] In specific implementation, when the base station detects that a device is connected to the port of the expansion unit, the base station receives the message broadcast by the device and changes the identity information of the device based on the message.

[0114] It should be noted that the base station monitors the port status of the expansion unit. When the status of the port changes from down to up, it is determined that a device is connected to the port of the expansion unit. Among them, the port has only two states, down and up. When the status of the port is down, no device is connected to the port of the expansion unit. When the status of the port is up, a device is connected to the port of the expansion unit.

[0115] It should be understood that since the online and offline status of the port may frequently switch due to some temporary reasons (such as line noise), an anti-jitter mechanism needs to be used when monitoring the status of the port. The anti-jitter mechanism is that when the base station detects a change in the online and offline status of the port, it needs to wait for a preset time and then confirm the online and offline status of the port again to prevent the base station from performing unnecessary operations due to various temporary switches of the port.

[0116] For example, when the status of the port changes from down to up, the base station waits for 5 seconds and then confirms the status of the port again. If the status of the port is still up, it is determined that there is a device accessing the port of the expansion unit. If the status of the port is down, it is determined that there is line noise interference and there is no device accessing the port of the expansion unit.

[0117] It should be noted that the message should contain verification information and device information required for connection. For example, the base station receives the DHCP message broadcast by the device, where the DHCP message includes verification information and device information required for connection such as <vender id>, <device type>, <device serial number>, etc.

[0118] Among them, the steps of receiving the message broadcast by the device and changing the identity information of the device based on the message when it is detected that there is a device accessing the expansion unit, where the identity information is divided into ordinary AP devices, abnormal devices, RRU devices, and undetermined devices, specifically include:

[0119] Step B11: When it is detected that there is a device accessing the expansion unit, prepare to receive the message broadcast by the device.

[0120] In a specific implementation, when the base station detects that there is a device accessing the port of the expansion unit, the base station prepares to receive the message broadcast by the device.

[0121] Step B12: If the message sent by the device is not received within the preset time, change the identity information of the device to an ordinary AP device.

[0122] In a specific implementation, if the base station does not receive the message sent by the device within the preset time, the base station changes the identity information of the device to an ordinary AP device.

[0123] It should be noted that the preset time should be manually set according to network requirements. For example, when the base station determines that there is a device accessing in the port of the extended device, it starts a 60 - second countdown. When the 60 - second countdown ends and the base station does not receive the DHCP packet sent by the device, it is determined that the identity information of the device is a common AP device, and the identity information of the device is changed to a common AP device.

[0124] It should be noted that since the DHCP packet sent by a common AP device does not carry a VLAN Tag, the base station will not be able to receive the DHCP packet sent by the common AP device.

[0125] Step B13: If the packet sent by the device does not carry device information, change the identity information of the device to an abnormal device.

[0126] In a specific implementation, if the base station determines that the packet sent by the device does not carry device information, the base station changes the identity information of the device to an abnormal device.

[0127] Step B14: If a packet sent by the device is received within the preset time and the packet carries device information, change the identity information of the device to undetermined.

[0128] In a specific implementation, if the base station receives a packet sent by the device within the preset time and the packet carries device information, the base station changes the identity information of the device to undetermined.

[0129] Step B20: Send the information required by the configuration device to the device with undetermined identity information and establish a connection channel with the device. If the establishment of the connection channel with the device fails, it is determined that the identity information of the device is an abnormal device, and the identity information of the device is changed to an abnormal device.

[0130] In a specific implementation, the base station sends the information required by the configuration device to the device whose identity information has not been changed and establishes a connection channel with the device. If the base station fails to establish a connection channel with the device, the base station determines that the identity information of the device is an abnormal device, and the identity information of the device is changed to an abnormal device.

[0131] It should be noted that the information required by the configuration device can be an IP address or any information required by the configuration device.

[0132] It can be understood that the connection channel established between the base station and the device is based on the SSH protocol. The full English name of SSH is Secure Shell, which is translated as the Secure Shell Protocol. It is a security protocol based on the application layer and the transport layer. Using the SSH protocol can effectively solve the problem of information leakage during data transmission.

[0133] For example, traditional network transfer protocols (FTP, PoP, and Telnet) are all insecure in nature because these protocols transmit passwords and data in plain text. External devices can easily intercept these passwords and data and impersonate the terminal to receive or send these passwords and data. By using SSH, the passwords and data transmitted in plain text can be encrypted, preventing external devices from intercepting the transmitted passwords and data and making the data transmission more secure.

[0134] Step B30: Initiate an identity authentication for a device with undetermined identity information and change the identity information of the device.

[0135] In a specific implementation, the base station initiates an identity authentication for a device with undetermined identity information and changes the identity information of the device based on the result of the identity authentication.

[0136] For example, as Figure 6 shown, the base station is used to determine the device type of the access device, and the expansion device is used to connect the determined device to the corresponding port. If the DHCP packet transmission does not time out, the DHCP packet carries device information, the connection between the base station and the access device is successfully established, and the identity authentication is successful, the base station determines that the type of the accessed device is an RRU device and connects the device using a Trunk port; otherwise, it connects the device using an Access port.

[0137] Among them, the step of initiating an identity authentication for a device with unchanged identity information and changing the identity information of the device specifically includes:

[0138] Step B31: Initiate an identity authentication for a device with undetermined identity information and determine whether the identity authentication is successful.

[0139] In a specific implementation, the base station initiates an identity authentication for a device with undetermined identity information and determines whether the identity authentication is successful based on the identity authentication message returned by the device.

[0140] It should be noted that the identity authentication procedure is issued by the base station. The base station first randomly generates a random string with a length within 64 bytes, and the instruction is <randmsg_len_64>. Then, the base station sends the string to the device that needs identity authentication for the device to calculate the hash value using the hash algorithm. The formula of the hash algorithm is hash_msg = SHA1(<vender id> + <device type> + <device serial number> + <verification code> + <randmsg_len_64>), where the verification code is recorded by both the base station and the RRU device. The verification code can be customized by the manufacturer or manually, and its length is 64 bytes. Since the key information verification code is not transmitted in the network and the base station generates a different randmsg_len_64 for each authentication, it can be ensured that even if the network packet is intercepted, the attacker still cannot disguise as an RRU device to access the network.

[0141] It should be understood that after the base station sends out the string, it needs to receive the identity authentication information hasm_msg file returned by the device that needs identity authentication, read the hash_msg information therein, and finally compare the hash_msg information returned by the device that needs identity authentication with the hash_msg information calculated locally by the base station. If they are the same, it is determined that the identity authentication is successful. Among them, only a message content with a length of 160 bits is compared, and the information in the file is not involved.

[0142] Step B32: If the identity authentication of the device is successful, change the identity information of the device to that of an RRU device.

[0143] In specific implementation, if the identity authentication of the device is successful, the base station changes the identity information of the device to that of an RRU device.

[0144] Step B33: If the identity authentication of the device fails, change the identity information of the device to that of an abnormal device.

[0145] In specific implementation, if the identity authentication of the device fails, the base station changes the identity information of the device to that of an abnormal device.

[0146] In this embodiment, when it is monitored that a device is connected to the extension unit, the message broadcast by the device is received, and the identity information of the device is changed based on the message, and then the information required to configure the device is sent to the device with undetermined identity information, wherein the identity information is divided into ordinary AP devices, abnormal devices, RRU devices and undetermined devices, and a connection channel is established with the device. If the connection channel with the device fails to be established, the identity information of the device is determined to be an abnormal device, and the identity information of the device is changed to an abnormal device. Finally, identity authentication is initiated to the device with undetermined identity information, and the identity information of the device is changed. This embodiment enables the base station to identify the identity information of the access device, so that when the access device is an ordinary AP device or an abnormal device, there is a corresponding processing mechanism to ensure the security and stability of the network.

[0147] In addition, the embodiment of the present application also proposes a network isolation device, which is applied to the expansion device, referring to Figure 7 , the network isolation device includes:

[0148] The identification module 10 is used to identify the identity information of the device when a device is detected to be connected, wherein the identity information is obtained based on the judgment of the base station;

[0149] A first connection module 20 is configured to connect to a corresponding port based on the identity information of the device, wherein the port is obtained based on interface-level VLAN division;

[0150] The forwarding module 30 is used to forward the data that the device needs to send based on the corresponding port.

[0151] Optionally, the connection module 20 includes:

[0152] A first connecting unit, configured to connect the device using a port corresponding to the RRU device if the identity information of the device is an RRU device;

[0153] The second connecting unit is configured to connect the device using a port corresponding to the common AP or the abnormal device if the identity information of the device is a common AP or an abnormal device.

[0154] Optionally, the forwarding module 30 includes:

[0155] A monitoring unit, configured to receive data to be sent by the device and monitor the type of the data;

[0156] A first forwarding unit is configured to forward the data to be sent by the device directly based on the corresponding port if there is only one type of data;

[0157] A second forwarding unit, configured to, if there are multiple types of data, place the data into a transmission queue and forward the data with the highest priority in the transmission queue through a corresponding port.

[0158] Optionally, when applied to an extended device, the network isolation device further includes:

[0159] A second connection module, configured to connect to a base station of a 5G fronthaul network;

[0160] An adding module, configured to add an Ethernet interface based on the ECPRI protocol, where the Ethernet interface supports WIFI device access to the 5G fronthaul network;

[0161] A partitioning module, configured to partition the Ethernet interface into different ports using interface-level VLAN.

[0162] The specific implementation manners of the network isolation device in this application are basically the same as those of the foregoing embodiments of the network isolation method, and will not be elaborated herein.

[0163] In addition, an embodiment of this application further provides a network isolation device, which is applied to a base station. Referring to Figure 8 , the network isolation device includes:

[0164] A receiving module 10, configured to, when detecting that a device accesses an extended device, receive a packet broadcast by the device and change the identity information of the device based on the packet, where the identity information is divided into a normal AP device, an abnormal device, an RRU device, and an undetermined device;

[0165] A sending module 20, configured to send information required by a configuration device to a device with undetermined identity information and establish a connection channel with the device. If the establishment of the connection channel with the device fails, it is determined that the identity information of the device is an abnormal device, and the identity information of the device is changed to an abnormal device;

[0166] An initiating module 30, configured to initiate an identity authentication to a device with undetermined identity information and change the identity information of the device.

[0167] Optionally, the receiving module 10 includes:

[0168] A receiving unit, configured to, when detecting that a device accesses an extended device, prepare to receive a packet broadcast by the device;

[0169] A first changing unit, configured to, if a packet sent by the device is not received within a preset time, change the identity information of the device to a normal AP device;

[0170] A second modification unit, configured to change the identity information of the device to an abnormal device if the message sent by the device does not carry device information;

[0171] A third modification unit, configured to change the identity information of the device to undetermined if a message sent by the device is received within a preset time and the message carries device information.

[0172] Optionally, the initiating module 30 includes:

[0173] A judgment unit, configured to initiate an identity authentication for a device with undetermined identity information and judge whether the identity authentication is successful;

[0174] A third modification unit, configured to change the identity information of the device to an RRU device if the identity authentication of the device is successful;

[0175] A fourth modification unit, configured to change the identity information of the device to an abnormal device if the identity authentication of the device fails.

[0176] The specific implementation manners of the network isolation device of the present application are basically the same as those of the above-mentioned network isolation method embodiments, and will not be elaborated herein.

[0177] The embodiments of the present application provide a storage medium, and the storage medium stores one or more programs, and the one or more programs can also be executed by one or more processors to implement the steps of the network isolation method described in any one of the above.

[0178] The specific implementation manners of the storage medium of the present application are basically the same as those of the above-mentioned network isolation method embodiments, and will not be elaborated herein.

[0179] It should be noted that in this article, the terms "include", "comprise" or any other variant thereof are intended to cover a non-exclusive inclusion, so that a process, method, article or system including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or system. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or system including the element.

[0180] The serial numbers of the above embodiments of the present application are only for description and do not represent the advantages and disadvantages of the embodiments.

[0181] Through the description of the above embodiments, those skilled in the art can clearly understand that the above method of the embodiment can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is a better implementation. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art can be embodied in the form of a software product. This computer software product is stored in a storage medium as described above (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions for causing a terminal device (which can be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods described in various embodiments of the present application.

[0182] The above are only the preferred embodiments of the present application, and do not limit the patent scope of the present application. Any equivalent structure or equivalent process transformation made by using the content of the specification and drawings of the present application, or directly or indirectly applied in other related technical fields, shall be equally included in the patent protection scope of the present application.

Claims

1. A network isolation method, characterized in that, Applied to an extended device, the network isolation method includes the following steps: When a device is detected to be connected, identify the identity information of the device. Among them, the identity information is based on the base station receiving the message broadcast by the device and modified based on the message. After the base station sends out a string, it needs to receive the identity authentication information hasm_msg file returned by the device that requires identity authentication, and read the hash_msg information therein. Finally, compare the hash_msg information returned by the device that requires identity authentication with the hash_msg information calculated locally by the base station. If they are the same, it is determined that the identity authentication is successful. Then, the base station sends the information required to configure the device to the device with undetermined identity information and establishes a connection channel with the device. If the establishment of the connection channel with the device fails, it is determined that the identity information of the device is an abnormal device, and the identity information of the device is changed to an abnormal device. Finally, initiate identity authentication to the device with undetermined identity information and change the identity information of the device; Based on the identity information of the device, connect to the corresponding port. Among them, the port is obtained by dividing based on interface-level VLAN. If the identity information is an RRU device, connect to the Trunk port. If it is a normal AP or an abnormal device, connect to the Access port; Forward the data that the device needs to send based on the corresponding port.

2. The network isolation method according to claim 1, wherein Before the step of when a device is detected to be connected and identifying the identity information of the device, where the identity information is obtained based on the judgment of the base station, the method includes: Connect to the base station of the 5G fronthaul network; Based on the ECPRI protocol, add an Ethernet interface, where the Ethernet interface supports WIFI devices to access the 5G fronthaul network; Use interface-level VLAN to divide the Ethernet interface into different ports.

3. The network isolation method according to claim 1, wherein The step of based on the identity information of the device, connecting to the corresponding port, where the port is obtained by dividing based on interface-level VLAN, includes: If the identity information of the device is an RRU device, use the port corresponding to the RRU device to connect to the device; If the identity information of the device is a normal AP or an abnormal device, use the port corresponding to the normal AP or abnormal device to connect to the device.

4. The network isolation method according to claim 1, wherein The step of forwarding the data that the device needs to send based on the corresponding port includes: Receive the data that the device needs to send and monitor the type of the data; If there is only one type of data, directly forward the data that the device needs to send based on the corresponding port; If there are multiple types of data, place the data into a send queue and forward the data with the highest priority in the send queue through the corresponding port.

5. A network isolation method, characterized in that, Applied to a base station, the network isolation method includes the following steps: When it is monitored that a device is connected to an extended device, receive the message broadcast by the device and modify the identity information of the device based on the message. Among them, the identity information is divided into normal AP devices, abnormal devices, RRU devices, and undetermined devices; Send the information required for configuring the device to the device with undetermined identity information, initiate an identity authentication based on the hash algorithm to the device with undetermined identity information, change the identity information of the device and establish a connection channel. Among them, after sending the string, it is necessary to receive the hasm_msg file of the identity authentication information returned by the device that requires identity authentication, read the hash_msg information therein, and finally compare the hash_msg information returned by the device that requires identity authentication with the hash_msg information calculated locally by the base station. If they are the same, it is determined that the identity authentication is successful, change the identity information of the device to RRU device and connect to the Trunk port. If the identity authentication of the device fails, it is determined that the identity information of the device is an abnormal device, and the identity information of the device is changed to an abnormal device and connected to the Access port.

6. The network isolation method according to claim 5, wherein When it is monitored that a device is connected to the extended device, receive the message broadcast by the device, and change the identity information of the device based on the message. The steps of dividing the identity information into ordinary AP device, abnormal device, RRU device and undetermined device include: When it is monitored that a device is connected to the extended device, prepare to receive the message broadcast by the device; If the message sent by the device is not received within the preset time, change the identity information of the device to an ordinary AP device; If the message sent by the device does not carry device information, change the identity information of the device to an abnormal device; If the message sent by the device is received within the preset time and the message carries device information, change the identity information of the device to undetermined.

7. The network isolation method according to claim 5, characterized in that, The steps of initiating an identity authentication based on the hash algorithm to the device with undetermined identity information and changing the identity information of the device include: Initiate an identity authentication to the device with undetermined identity information and determine whether the identity authentication is successful; If the identity authentication of the device is successful, change the identity information of the device to RRU device; If the identity authentication of the device fails, change the identity information of the device to an abnormal device.

8. A network isolation device, characterized in that, Applied to an extended device, the device includes: An identification module, configured to identify the identity information of a device when detecting that a device is connected. The identity information is based on the base station receiving a message broadcast by the device and modified based on the message. After the base station sends out a string, it needs to receive the identity authentication information hasm_msg file returned by the device that requires identity authentication, read the hash_msg information therein, and finally compare the hash_msg information returned by the device that requires identity authentication with the hash_msg information calculated locally by the base station. If they are the same, it is determined that the identity authentication is successful. Then, the base station sends the information required by the configured device to the device with undetermined identity information and establishes a connection channel with the device. If the establishment of the connection channel with the device fails, it is determined that the identity information of the device is an abnormal device, and the identity information of the device is changed to an abnormal device. Finally, an identity authentication is initiated to the device with undetermined identity information and the identity information of the device is changed; A first connection module, configured to connect to a corresponding port based on the identity information of the device. The port is obtained based on interface-level VLAN division. If the identity information is of an RRU device, it connects to a Trunk port; if it is a normal AP or an abnormal device, it connects to an Access port; A forwarding module, configured to forward the data that the device needs to send based on the corresponding port.

9. A network isolation device, characterized in that, The device includes: a memory, a processor, and a network isolation program stored on the memory and executable on the processor. The network isolation program is configured to implement the steps of the network isolation method according to any one of claims 1 to 7.

10. A storage medium, characterized in that, A network isolation program is stored on the storage medium. When the network isolation program is executed by the processor, it implements the steps of the network isolation method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Host interface expansion method and device, equipment and storage medium

    CN113965456A