Optimization framework and design method of wireless converged network system for new power system

By designing an optimization framework for a wireless converged network system of a new power system including access authentication, terminal management, resource management and service flow modules, the problem that the prior art is difficult to provide a secure and service environment that facilitates service flow is solved, and the demand for multiple communication access and service support for new power system services is realized.

CN117998359BActive Publication Date: 2025-05-16INFORMATION & COMMUNICATION BRANCH STATE GRID JIBEI ELECTRIC POWER CO LTD +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202311830532.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-12-28
Publication Date
2025-05-16
Estimated Expiration
2043-12-28

AI Technical Summary

Technical Problem

It is difficult to design a wireless converged network system that provides a new power system that is secure and facilitates traffic flow, especially in the face of the needs of multiple communication access and service support.

Method used

An optimization framework for a new type of wireless converged network system for power systems is designed, including access authentication module, terminal management module, resource management module and service flow module. This framework provides two-way security authentication and access control through wireless authentication protocol management submodule and authentication management service submodule, and supports cascading to adapt to wireless networks of different sizes.

Benefits of technology

It realizes the need for a variety of communication access and service support for new power system services, provides a safer and more conducive service environment, and meets the needs of network end coverage extension in new power systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117998359B_ABST
    Figure CN117998359B_ABST
Patent Text Reader

Abstract

The present application discloses an optimization framework and design method for a wireless converged network system of a new type of power system, and relates to the technical field of new power systems. The main technical scheme of the present application is: the optimization framework includes: an access authentication module, a terminal management module, a resource management module and a business flow swing module, and the access authentication module includes: a wireless authentication protocol management submodule and an authentication management service submodule; and the access authentication module includes: a wireless authentication protocol management submodule and an authentication management service submodule, thereby using the wireless authentication protocol management submodule to manage the client, the agent and the server to achieve security control, and using the authentication management service submodule to provide registration management, centralized authentication, access decision and authentication audit and other functional services, supporting cascading to cope with wireless networks of different scales; and the present application also uses the terminal management module, the resource management module and the business flow swing module to achieve auxiliary business flow swing services.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of novel power systems, and in particular to an optimization framework and design method for a wireless converged network system of a novel power system. Background Art

[0002] With the continuous development of new power systems, new power system services integrating perception, edge, network and cloud are constantly emerging. Therefore, it is necessary to deploy a large number of IoT terminals, edge gateways, etc. to ensure the security and stability of control business connections and reliable message interaction, and to support the orderly, healthy and stable operation of the "source, grid, load and storage" energy Internet system, which makes the network terminal coverage continue to extend.

[0003] Now, in order to cope with the needs of various communication access and business support for new power system services, it is a technical problem that needs to be solved urgently to study how to design and improve a wireless converged network system for a new power system to provide a secure service environment that facilitates business flow. Summary of the invention

[0004] The present application provides an optimization framework and design method for a wireless converged network system of a new power system. The main purpose is to provide a more secure and business-friendly service environment by improving the wireless converged network system framework of the new power system to include: an access authentication module, a terminal management module, a resource management module and a business flow module.

[0005] In order to achieve the above objectives, this application mainly provides the following technical solutions:

[0006] In a first aspect, the present application provides an optimization framework for a wireless converged network system of a novel power system, the framework comprising: an access authentication module, a terminal management module, a resource management module and a service flow swing module;

[0007] The access authentication module is used for terminal access authentication and management; the access authentication module includes: a wireless authentication protocol management submodule and an authentication management service submodule;

[0008] The wireless authentication protocol management submodule is used to manage the client, the agent, and the server; wherein, on the client, it is used to manage each wireless terminal; on the agent, it is used to manage each wireless access control point; on the server, it is used to manage the authentication management server to cope with wireless channels of different bandwidths and support two-way security authentication and access control between each wireless terminal and the authentication management server;

[0009] The functions provided by the authentication management service submodule include at least: registration management, centralized authentication, admission decision and authentication audit, and support cascading to cope with wireless networks of different scales;

[0010] The terminal management module is used to maintain and manage multiple types of devices connected to the same wireless terminal;

[0011] The resource management module manages system resource allocation including at least: computing resource, storage resource and communication resource allocation;

[0012] The business flow swing module manages the data information of various business flow swings in the management system, including at least: definition data, configuration data and monitoring data of various business flows.

[0013] A second aspect of the present application provides a design method for an optimization framework of a wireless converged network system of a novel power system, which is applied to the optimization framework of the wireless converged network system of the novel power system as described above, and the method comprises:

[0014] Provide application services for access authentication of wireless terminals, so as to be applied to terminal access authentication and management; the application services include: wireless authentication protocol management and authentication management services;

[0015] The wireless authentication protocol management includes: on the client, it is applied to manage each wireless terminal; on the proxy, it is applied to manage each wireless access control point; on the server, it is applied to manage the authentication management server to cope with wireless channels of different bandwidths and support two-way security authentication and access control between each wireless terminal and the authentication management server;

[0016] The authentication management service includes registration management, centralized authentication, access decision and authentication audit, and supports cascading to cope with wireless networks of different scales.

[0017] Providing maintenance and management of multiple types of equipment connected to the same wireless terminal;

[0018] Providing management system resource allocation includes at least: computing resource, storage resource and communication resource allocation;

[0019] The data information provided for various types of business flows in the management system includes at least: definition data, configuration data and monitoring data of various types of business flows.

[0020] A third aspect of the present application provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, a design method for an optimization framework of a wireless converged network system of a novel power system as described above is implemented.

[0021] The fourth aspect of the present application provides an electronic device, including: a memory, a processor, and a computer program stored in the memory and executable on the processor. When the computer program is executed by the processor, a design method for an optimization framework of a wireless converged network system of a new type of power system as described above is implemented.

[0022] By means of the above technical solution, the technical solution provided by this application has at least the following advantages:

[0023] The present application provides an optimization framework and design method for a wireless converged network system of a new type of power system. The optimization framework includes: an access authentication module, a terminal management module, a resource management module and a business flow swing module, and the access authentication module includes: a wireless authentication protocol management submodule and an authentication management service submodule. Therefore, the present application uses the wireless authentication protocol management submodule to manage the client, the agent and the server, respectively implemented on the client, applied to manage each wireless terminal, and on the agent, applied to manage each wireless access control point; and on the server, applied to manage the authentication management server to cope with wireless channels of different bandwidths, and support two-way security authentication and access control between each wireless terminal and the authentication management server. And the authentication management service submodule is used to provide registration management, centralized authentication, access judgment and authentication audit and other functional services, support cascading, to cope with wireless networks of different scales, and the present application uses the access authentication module to provide a more secure service environment. In addition, the present application also uses the terminal management module, the resource management module and the business flow swing module to realize auxiliary business flow swing services. Based on this, the optimization framework provided in this application responds to the needs of various communication access and business support for new power system services and provides a better solution.

[0024] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] Various other advantages and benefits will become apparent to those of ordinary skill in the art by reading the detailed description of the preferred embodiments below. The accompanying drawings are only for the purpose of illustrating the preferred embodiments and are not to be considered as limiting the present application. Also, the same reference symbols are used throughout the accompanying drawings to represent the same components. In the accompanying drawings:

[0026] Figure 1 A block diagram of the optimization framework of a wireless converged network system of a novel power system provided in an embodiment of the present application;

[0027] Figure 2A schematic diagram of the composition architecture of the wireless authentication protocol software provided in the embodiment of the present application;

[0028] Figure 3 A schematic diagram of the composition architecture of the authentication management service software provided in the embodiment of the present application;

[0029] Figure 4a A schematic diagram of a wireless access authentication system using wireless authentication protocol software and authentication management service software provided in an embodiment of the present application;

[0030] Figure 4b A schematic diagram of the AAA framework provided in an embodiment of the present application;

[0031] Figure 5 A functional structure diagram of a terminal management module provided in an embodiment of the present application;

[0032] Figure 6 A schematic diagram of the gateway management process provided in the embodiment of the present application;

[0033] Figure 7 A schematic diagram of the functional application provided by the resource management module provided in the embodiment of the present application;

[0034] Figure 8 A schematic diagram of the functional application provided by the business flow swing module provided in an embodiment of the present application;

[0035] Fig. 9 A flowchart of a method for designing an optimization framework of a wireless converged network system for a novel power system provided in an embodiment of the present application. DETAILED DESCRIPTION

[0036] The exemplary embodiments of the present application will be described in more detail below with reference to the accompanying drawings. Although the exemplary embodiments of the present application are shown in the accompanying drawings, it should be understood that the present application can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided in order to enable a more thorough understanding of the present application and to fully convey the scope of the present application to those skilled in the art.

[0037] Now, the new wireless converged networking of the power system combines 5G with multiple local communication networks and customized power 5G terminals / modules, and organically integrates the "access-edge-core network" system and the distributed edge core network resources therein, so that the development of the new power system business is no longer restricted by wireless access communication network technology.

[0038] In order to cope with various communication access solutions and business support for new power system services, the embodiment of the present application designs an optimized framework for a wireless converged network system of a new power system to provide a more secure service environment that facilitates business flow. Figure 1 As shown, the optimization framework provided by the embodiment of the present application includes: an access authentication module 1, a terminal management module 2, a resource management module 3 and a business flow module 4.

[0039] The access authentication module 1 is used for terminal access authentication and management; the access authentication module 1 includes: a wireless authentication protocol management submodule 11 and an authentication management service submodule 12.

[0040] The wireless authentication protocol management submodule 11 is used to manage the client, agent and server; on the client, it is used to manage each wireless terminal; on the agent, it is used to manage each wireless access control point; on the server, it is used to manage the authentication management server to cope with wireless channels of different bandwidths and support two-way security authentication and access control between each wireless terminal and the authentication management server.

[0041] The functions provided by the authentication management service submodule 12 at least include: registration management, centralized authentication, admission decision and authentication audit, and support cascading to cope with wireless networks of different sizes.

[0042] Based on the wireless authentication protocol management submodule 11 and the authentication management service submodule 12, the embodiment of the present application utilizes the access authentication module to provide a more secure service environment.

[0043] The terminal management module 2 is used to maintain and manage multiple types of devices connected to the same wireless terminal; the resource management module 3 manages the system resource allocation including at least: computing resources, storage resources and communication resource allocation; the business flow module 4 manages the data information of various business flows in the system including at least: definition data, configuration data and monitoring data of various business flows.

[0044] The present application also utilizes the terminal management module 2, the resource management module 3 and the business flow swing module 4 to implement auxiliary business flow swing services.

[0045] As described above, the optimization framework provided in this application provides a better solution to meet the needs of various communication access and business support for new power system services.

[0046] In some modified embodiments, the wireless authentication protocol management submodule 11 applies the wireless authentication protocol software, and the wireless authentication protocol software is correspondingly designed to include: a protocol adaptation layer 111, a protocol processing layer 112, a credential adaptation layer 113, an extension adaptation layer 114 and a presentation layer 115, such as Figure 2 The composition architecture of the wireless authentication protocol software is shown.

[0047] Among them, the protocol adaptation layer 111 is used to provide a protocol bearer abstract interface. Exemplarily, the protocol adaptation layer provides underlying protocol bearer interfaces such as TCP / IP, Diameter protocol, Transport Layer Security (TLS), wireless link layer protocol or wireless networking protocol, so that the wireless authentication protocol family can adapt to different wireless network protocols. Through the abstract interface, the protocol processing layer can be independent of the specific bearer protocol of the lower layer, so that the wireless authentication protocol software has good portability.

[0048] The protocol processing layer 112 is used to provide a wireless channel adaptation and authentication management protocol framework. Exemplarily, the protocol processing layer provides a wireless channel adaptation and authentication management protocol framework, on which a wireless authentication protocol family consisting of an online registration protocol and a wireless channel authentication protocol is implemented. The wireless authentication protocol family implements authentication protocol processing in different wireless channel environments.

[0049] Among them, the credential adaptation layer 113 is used to provide an abstract interface for identity credential devices. Exemplarily, the credential adaptation layer provides support for identity credential devices in the form of usernames and passwords, USB-KEYs, and security cards. Through the abstract interface, the protocol processing layer can be independent of specific identity credential devices and their drivers, so that the wireless authentication protocol software has good usability.

[0050] Among them, the extended adaptation layer 114 is used to provide the interface of the security baseline verification module and the transmission encryption module. Exemplarily, the extended adaptation layer provides support for external extended function modules such as the security baseline verification module and the transmission encryption module. Through the abstract interface, the protocol processing layer can notify the authentication server of the security baseline verification results through the authentication protocol, and extend the support for the access decision function based on the security baseline verification results; it can also notify the transmission encryption module of the session key negotiated during the two-way authentication process, and extend the support for the transmission encryption one-time password function, so that the wireless authentication protocol software has good scalability.

[0051] The presentation layer 115 is used to provide the wireless authentication protocol software with an external presentation form. Exemplarily, the presentation layer provides the wireless authentication protocol software with an external presentation form, including an authentication agent software that provides authentication client / server functions, an authentication management tool that provides online registration management client functions, and secondary development interfaces in the form of dynamic libraries and static libraries.

[0052] In some modified embodiments, the authentication management service submodule 12 applies authentication management service software, which is correspondingly designed to include: a bottom layer protocol processing unit 121, a high concurrency processing unit 122, a Web Service unit 123, an authentication and management agent unit 124, an operation management unit 125, an authentication service unit 126, and a security peripheral management unit 127. Figure 3 The composition architecture of the authentication management service software is shown.

[0053] The application provided by the underlying protocol processing unit 121 is exemplarily explained as follows:

[0054] The HTTP protocol is responsible for implementing the underlying protocol bearer for B / S operation management; the SSL protocol implements the protection function of remote management transmission data, which can prevent attacks such as data replay, tampering and eavesdropping; IPv4 / v6 provides IP dual stack support; the DIAMETER protocol is responsible for the underlying bearer of wireless channel adaptation authentication and management protocol.

[0055] The application provided by the high-concurrency processing unit 122 is exemplarily explained as follows:

[0056] The authentication management server is connected to the wireless access control point, operation management host, etc. through a 100 / 1000Mbps adaptive Ethernet electrical port. This module is responsible for the concurrent processing of more than 1000 authentication service or management configuration requests per second.

[0057] The application provided by the Web Service unit 123 is exemplarily explained as follows:

[0058] Web Service unit 123 uses Tomcat Web server software. Tomcat is a Servlet-supporting engine with a JSP environment. Servlet is a Web Server-side program written in Java, which is independent of the protocol and platform. Java Servlet can dynamically expand the capabilities of the Server and provide Web services in a request-response mode. The main function of this module is to interactively browse and modify data and generate dynamic Web content.

[0059] The application provided by the authentication and management agent unit 124 is exemplarily explained as follows:

[0060] The authentication and management agent unit 124 completes the authentication entity registration and wireless bidirectional authentication functions between the authentication management server and the wireless authentication protocol software client by performing interface interaction with the server of the wireless authentication protocol software.

[0061] The application provided by the operation management unit 125 is exemplarily explained as follows:

[0062] The operation management unit 125 completes the following functional authentication: parameter management, access policy management, policy import and export, blacklist and whitelist control, authentication log management, local status management, configuration parameter management, operator authority configuration, operator access control, operator behavior audit

[0063] The application provided by the authentication service unit 126 is exemplarily explained as follows:

[0064] The authentication service unit 126 performs the following functions: authentication audit, access decision, wireless authentication protocol software

[0065] Among them, the application provided by the security peripheral management unit 127 is exemplarily explained as: the security peripheral management unit provides functions including: local secure storage, security card management and other application services.

[0066] Further, in some modified embodiments, the access authentication module 1 uses the wireless authentication protocol software applied on the wireless authentication protocol management submodule 11 and the authentication management service software applied on the authentication management service submodule 12 to adopt the security mechanism of the AAA management framework. Figure 4a As shown, a wireless access authentication system is formed by using wireless authentication protocol software and authentication management service software.

[0067] The wireless authentication protocol software is divided into client, agent and server, which run in wireless terminals, wireless access control points and authentication management servers respectively. It can adapt to wireless channels of different bandwidths and realize two-way security authentication and access control between wireless terminals and authentication management servers. The authentication management server provides functions such as registration management, centralized authentication, admission judgment and authentication audit, supports cascading, and can be applied to wireless networks of different scales. The standard Diameter or TLS protocol is used between the wireless access control point and the authentication management server, which can prevent the wireless access control point from being counterfeited while ensuring the compatibility of the protocol.

[0068] Among them, the embodiment of the present application provides a schematic diagram of the AAA framework, such as Figure 4b As shown in the figure, the AAA (Authentication, Authorization, Accounting) framework is an architecture for terminal access management, which provides three security functions: authentication, authorization and auditing. The wireless access authentication system is oriented to the needs of new power system services and provides wireless protocol suites and wireless access authentication services for wireless users and terminal devices to access the network.

[0069] When a user wants to establish a connection with a network access server (NAS) through a certain network to obtain the right to access other networks or obtain certain network resources, NAS plays the role of verifying the user or the corresponding connection. NAS is responsible for forwarding the user's authentication, authorization and billing information to the AAA server. This management framework provides a security mechanism that authorizes some entities to access specific resources and can record the operation behavior of these entities. It is widely used because of its good scalability and easy centralized management of user information. Common authentication protocols between user hosts and network access servers are:

[0070] ① EAPoL used in the wired LAN 802.1x system supports authentication protocols such as EAP-TLS and EAP-MD5;

[0071] ② WPA, WPA2 and other protocols defined in the wireless LAN 802.11i standard and TEPA and other protocols used in the WAPI standard;

[0072] ③ 3GPP-AKA and other authentication protocols used by terrestrial cellular mobile communication systems;

[0073] ④ Kerberos, TLS, IKE and other authentication protocols used in other wired networks.

[0074] Below, the terminal management module 2, the resource management module 3 and the service flow swing module 4 in the optimization framework provided in the embodiment of the present application are explained as follows:

[0075] In some modified embodiments, for the terminal management module 2, such as Figure 5 The functional structure diagram of the terminal management module 2 is shown.

[0076] Among them, for the gateway management function, the terminal management module 2 includes: a gateway update submodule, a gateway application management submodule, and a gateway access terminal management submodule; the gateway update submodule is used to perform at least: display, add, delete, edit and send configuration operations on the gateway connected to the same wireless terminal; the gateway application management submodule is used to perform at least: start, deactivate, install and uninstall operations on the gateway application; the gateway access terminal management submodule is used to perform at least: speed limit, blacklist and whitelist configuration and access restriction operations on the wireless terminal connected to the gateway. Figure 6 A schematic diagram of the gateway management process is shown.

[0077] And, in response to the gateway alarm management function, the terminal management module 2 includes: a gateway alarm submodule, which cooperates with the preset alarm rules to monitor the alarm information, based on which the alarm information can be displayed in a list, confirmed, and the alarm can be cleared after confirming safety.

[0078] For example, you can create alarm rules through some built-in indicators of the system, and list the existing effective rules, the alarm level generated, the time required to generate an alarm, the description of the alarm rule, etc. The system has some basic built-in alarm rules, which cannot be edited or deleted.

[0079] In some modified embodiments, Figure 7 The resource management module 3 provides functional applications. The resource management module 3 provides management functions such as allocation and viewing of computing resources, storage resources and communication resources of the system.

[0080] Computing resource management provides functions such as viewing, allocating, and reclaiming system computing resources, as well as allocation strategies. Administrators use this module to manage computing resources for computing services at each terminal. Storage resources provide functions such as viewing, allocating, and reclaiming system storage resources, as well as allocation strategies. Administrators use this module to manage and configure storage according to established strategies, monitor important storage, and issue alarms based on strategies when hardware or storage problems occur. Communication resources provide functions such as policy configuration and adjustment of network communication resources, communication selection, and status monitoring. This module focuses on statistics on the allocation and utilization of communication resources, monitoring faulty lines, etc., and improves communication resource utilization and ensures stable and efficient data transmission by dynamically adjusting communication resource allocation.

[0081] In some modified embodiments, the business flow module 4 includes: a business definition unit, a business configuration unit and a business monitoring unit; it is used to configure the specified business using the business configuration unit after the business unit defines the specified business, and to monitor the execution status of the specified business using the business monitoring unit.

[0082] For example, Figure 8 The functional applications provided by the business flow swing module 4 shown include: business flow monitoring, business flow definition, business flow configuration and component management. The business flow swing module 4 can be used to create and maintain various business processes, and control and monitor the processes during user business use, and quote users to complete business functions and data flows through the correct process, which involves data access and authority control for each functional link. Business rules are formed in a configured manner, and new rules are formed by plugging and unplugging certain components.

[0083] As the above Figures 1 to 8 The implementation of the schematic diagrams shown in each of the embodiments of the present application provides a design method for an optimization framework of a wireless converged network system of a new type of power system. The method embodiment corresponds to the aforementioned device embodiment. For ease of reading, the method embodiment will no longer repeat the details of the aforementioned device embodiment one by one, but it should be clear that the method in this embodiment can correspond to all the contents of the aforementioned device embodiment. Fig. 9 As shown, the method comprises the following steps:

[0084] Step 101: Provide application services for access authentication of wireless terminals, so as to be applied to terminal access authentication and management; the application services include: wireless authentication protocol management and authentication management services;

[0085] Among them, wireless authentication protocol management includes: on the client side, it is used to manage each wireless terminal; on the agent side, it is used to manage each wireless access control point; on the server side, it is used to manage the authentication management server to cope with wireless channels of different bandwidths and support two-way security authentication and access control between each wireless terminal and the authentication management server;

[0086] Among them, the authentication management service includes: registration management, centralized authentication, access decision and authentication audit, and supports cascading to cope with wireless networks of different sizes.

[0087] Step 102: Provide maintenance and management of multiple types of devices connected to the same wireless terminal.

[0088] Step 103: Providing management system resource allocation includes at least: computing resource, storage resource and communication resource allocation.

[0089] Step 104: Provide data information of various types of business flows in the management system, including at least: definition data, configuration data and monitoring data of various types of business flows.

[0090] It should be noted that, according to the convenience of the specific operation of building the framework, steps 101-104 may be executed in sequence, or, the above steps 101-104 may be executed in parallel without any sequence.

[0091] Furthermore, in some modified embodiments, the wireless authentication protocol software is correspondingly designed to include: a protocol adaptation layer, a protocol processing layer, a credential adaptation layer, an extension adaptation layer and a presentation layer.

[0092] The protocol adaptation layer is used to provide a protocol bearer abstract interface;

[0093] The protocol processing layer is used to provide a wireless channel adaptation and authentication management protocol framework;

[0094] The credential adaptation layer is used to provide an abstract interface for identity credential devices;

[0095] The extended adaptation layer is used to provide a security baseline verification module interface and a transmission encryption module interface;

[0096] The presentation layer is used to provide the wireless authentication protocol software with an external presentation format.

[0097] Furthermore, in some modified embodiments, the authentication management service software is correspondingly designed to include: an underlying protocol processing unit, a high concurrency processing unit, a Web Service unit, an authentication and management agent unit, an operation management unit, an authentication service unit and a security peripheral management unit.

[0098] Furthermore, in some modified embodiments, the embodiments of the present application adopt the security mechanism of the AAA management framework by utilizing the wireless authentication protocol software and the authentication management service software.

[0099] Furthermore, in some variation embodiments, maintenance and management of multiple types of devices connected to the same wireless terminal are provided, including a gateway management function, which exemplarily includes: being applied to a gateway connected to the same wireless terminal to perform at least the following operations: display, add, delete, edit and issue configurations; performing at least the following operations on gateway applications: start, deactivate, install and uninstall; performing at least the following operations on the wireless terminal connected to the gateway: speed limiting, black and white list configuration and access restriction.

[0100] Furthermore, a gateway alarm service is provided, which exemplarily includes: cooperating with preset alarm rules to monitor alarm information.

[0101] Furthermore, in some modified embodiments, providing data information of various business flows in the management system also includes: after defining the specified business, configuring the specified business, and monitoring the execution status of the specified business.

[0102] The optimization framework of the wireless converged network system of the new power system includes a processor and a memory. The above-mentioned access authentication module 1, terminal management module 2, resource management module 3 and business flow swing module 4 are all stored in the memory as program units, and the processor executes the above-mentioned program units stored in the memory to realize the corresponding functions.

[0103] The processor includes a kernel, which retrieves the corresponding program unit from the memory. One or more kernels can be set, and the wireless converged network system framework of the new power system is improved by adjusting the kernel parameters to include: access authentication module, terminal management module, resource management module and business flow module to provide a more secure and conducive service environment for business flow.

[0104] An embodiment of the present application provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the method for designing an optimization framework of a wireless converged network system of a novel power system as described above is implemented.

[0105] An embodiment of the present application provides an electronic device, including: a memory, a processor, and a computer program stored in the memory and executable on the processor. When the computer program is executed by the processor, the design method of the optimization framework of the wireless converged network system of the new power system as described above is implemented.

[0106] The embodiment of the present application also provides a computer program product, which, when executed on a data processing device, is suitable for executing the program steps of the design method for initializing the optimization framework of the wireless converged network system of the new power system.

[0107] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0108] In a typical configuration, the device includes one or more processors (CPU), memory and bus. The device may also include input / output interface, network interface and the like.

[0109] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip. The memory is an example of a computer-readable medium.

[0110] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.

[0111] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.

[0112] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0113] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included within the scope of the claims of the present application.

Claims

1. An optimization device for a wireless converged network system applied to a new power system, characterized in that: The device comprises: an access authentication module, a terminal management module, a resource management module and a service flow swing module; The access authentication module is used for terminal access authentication and management; the access authentication module includes: a wireless authentication protocol management submodule and an authentication management service submodule; The wireless authentication protocol management submodule is used to manage the client, the agent, and the server; wherein, on the client, it is used to manage each wireless terminal; on the agent, it is used to manage each wireless access control point; on the server, it is used to manage the authentication management server to cope with wireless channels of different bandwidths and support two-way security authentication and access control between each wireless terminal and the authentication management server; Wherein, the wireless authentication protocol management submodule applies the wireless authentication protocol software, and the wireless authentication protocol software is correspondingly designed to include: a protocol adaptation layer, a protocol processing layer, a credential adaptation layer, an extension adaptation layer and a presentation layer; The protocol adaptation layer is used to provide a protocol bearer abstract interface; The protocol processing layer is used to provide a wireless channel adaptation and authentication management protocol framework; The credential adaptation layer is used to provide an abstract interface for identity credential devices; The extended adaptation layer is used to provide a security baseline verification module interface and a transmission encryption module interface; The presentation layer is used to provide the wireless authentication protocol software with an external presentation format; The functions provided by the authentication management service submodule include at least: registration management, centralized authentication, admission decision and authentication audit, and support cascading to cope with wireless networks of different scales; Wherein, the authentication management service submodule applies authentication management service software, and the authentication management service software is correspondingly designed to include: an underlying protocol processing unit, a high concurrency processing unit, a Web Service unit, an authentication and management agent unit, an operation management unit, an authentication service unit and a security peripheral management unit; The terminal management module is used to maintain and manage multiple types of devices connected to the same wireless terminal; The resource management module manages system resource allocation including at least: computing resource, storage resource and communication resource allocation; The business flow swing module manages the data information of various business flow swings in the management system, including at least: definition data, configuration data and monitoring data of various business flows; Wherein, the access authentication module uses the security mechanism of the AAA management framework by using the wireless authentication protocol software applied on the wireless authentication protocol management submodule and the authentication management service software applied on the authentication management service submodule; The terminal management module includes: a gateway update submodule, a gateway application management submodule, and a gateway access terminal management submodule; The gateway update submodule is used to perform at least the following configuration operations on the gateway connected to the same wireless terminal: display, add, delete, edit and issue configuration; The gateway application management submodule is used to perform at least the following operations on the gateway application: starting, stopping, installing and uninstalling; The terminal management submodule accessed by the gateway is used to perform at least the following operations on the wireless terminals connected to the gateway: speed limiting, blacklist and whitelist configuration, and access restriction; The terminal management module includes: a gateway alarm submodule, which cooperates with preset alarm rules to monitor alarm information; Among them, the business flow module includes: a business definition unit, a business configuration unit and a business monitoring unit; it is used to configure the specified business using the business configuration unit after the business definition unit defines the specified business, and to monitor the execution status of the specified business using the business monitoring unit.

2. A design method for an optimization device of a wireless converged network system applied to a new power system, characterized in that: The optimization device for the wireless converged network system applied to the new power system as claimed in claim 1, wherein the method comprises: Provide application services for access authentication of wireless terminals, so as to be applied to terminal access authentication and management; the application services include: wireless authentication protocol management and authentication management services; The wireless authentication protocol management includes: on the client, it is applied to manage each wireless terminal; on the proxy, it is applied to manage each wireless access control point; on the server, it is applied to manage the authentication management server to cope with wireless channels of different bandwidths and support two-way security authentication and access control between each wireless terminal and the authentication management server; Wherein, wireless authentication protocol software is applied to the wireless authentication protocol management, and the wireless authentication protocol software is correspondingly designed to include: a protocol adaptation layer, a protocol processing layer, a credential adaptation layer, an extension adaptation layer and a presentation layer; The protocol adaptation layer is used to provide a protocol bearer abstract interface; The protocol processing layer is used to provide a wireless channel adaptation and authentication management protocol framework; The credential adaptation layer is used to provide an abstract interface for identity credential devices; The extended adaptation layer is used to provide a security baseline verification module interface and a transmission encryption module interface; The presentation layer is used to provide the wireless authentication protocol software with an external presentation format; The authentication management service includes registration management, centralized authentication, access decision and authentication audit, and supports cascading to cope with wireless networks of different scales. Wherein, the authentication management service submodule applies authentication management service software, and the authentication management service software is correspondingly designed to include: an underlying protocol processing unit, a high concurrency processing unit, a Web Service unit, an authentication and management agent unit, an operation management unit, an authentication service unit and a security peripheral management unit; Providing maintenance and management of multiple types of equipment connected to the same wireless terminal; Providing management system resource allocation includes at least: computing resource, storage resource and communication resource allocation; The data information of various business flows in the management system includes at least: definition data, configuration data and monitoring data of various business flows; Wherein, the access authentication module uses the security mechanism of the AAA management framework by using the wireless authentication protocol software applied on the wireless authentication protocol management submodule and the authentication management service software applied on the authentication management service submodule; The terminal management module includes: a gateway update submodule, a gateway application management submodule, and a gateway access terminal management submodule; The gateway update submodule is used to perform at least the following configuration operations on the gateway connected to the same wireless terminal: display, add, delete, edit and issue configuration; The gateway application management submodule is used to perform at least the following operations on the gateway application: starting, stopping, installing and uninstalling; The terminal management submodule accessed by the gateway is used to perform at least the following operations on the wireless terminals connected to the gateway: speed limiting, blacklist and whitelist configuration, and access restriction; The terminal management module includes: a gateway alarm submodule, which cooperates with preset alarm rules to monitor alarm information; Among them, the business flow module includes: a business definition unit, a business configuration unit and a business monitoring unit; it is used to configure the specified business using the business configuration unit after the business definition unit defines the specified business, and to monitor the execution status of the specified business using the business monitoring unit.

3. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by the processor, the design method of the optimization device for the wireless converged network system applied to the new power system as claimed in claim 2 is implemented.

4. An electronic device, characterized in that: include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the computer program is executed by the processor, the design method for an optimization device for a wireless converged network system applied to a new power system as claimed in claim 2 is implemented.

Citation Information

Patent Citations

  • 5G-based power regulation and control service security communication method

    CN114302402A