Operation and maintenance system and method of secondary authentication system

By dividing the secondary authentication system into business units and management units, remote operation and maintenance is realized, which solves the inconvenience of operators needing to go to the enterprise site for operation and maintenance in the existing technology, and improves the convenience and security of operation and maintenance.

CN118590307BActive Publication Date: 2026-01-27CHINA UNITED NETWORK COMM GRP CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410873786.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-01
Publication Date
2026-01-27
Estimated Expiration
2044-07-01

AI Technical Summary

Technical Problem

In existing technologies, the operation and maintenance of secondary authentication systems are inconvenient, requiring operators' staff to regularly visit the enterprise's site for inspection and maintenance.

Method used

The secondary authentication system is divided into a business unit and a management unit. The business unit collects fault alarm data and sends the alarm data and network identifier to the management unit. After verification by the management unit, the operation and maintenance terminal generates operation and maintenance policies and sends them to the business unit to realize remote operation and maintenance.

Benefits of technology

No staff need to go to the enterprise site for operation and maintenance, which improves the convenience and security of the secondary authentication system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118590307B_ABST
    Figure CN118590307B_ABST
Patent Text Reader

Abstract

The embodiment of the application provides a kind of secondary authentication system operation and maintenance system and method, the system includes: secondary authentication system business unit, secondary authentication system management unit and operation and maintenance terminal;Secondary authentication system business unit collects fault alarm data;Secondary authentication system business unit sends fault alarm data and first network identity to secondary authentication system management unit;Secondary authentication system management unit verifies first network identity, generates first verification information;If first verification information is verified, then secondary authentication system management unit sends alarm data to operation and maintenance terminal;Operation and maintenance terminal generates operation and maintenance strategy according to alarm data;Operation and maintenance terminal sends operation and maintenance strategy to secondary authentication system business unit, to realize the operation and maintenance of secondary authentication system business unit, improve the convenience of secondary authentication system operation and maintenance.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of 5G communication technology, and in particular to an operation and maintenance system and method for a secondary authentication system. Background Technology

[0002] 5G hybrid private networks are a solution between virtual private networks (VPNs) and standalone private networks (SPRs). After a 5G terminal passes core authentication, it cannot directly establish a connection with the enterprise's intranet business systems. Authentication must be completed through the AAA secondary authentication system before the 5G private network is allowed to establish a communication link between the user and the enterprise's intranet business systems.

[0003] In existing technologies, operators deploy secondary authentication systems within the enterprise's intranet area, physically isolated from external networks.

[0004] However, in the existing technology, operators need to regularly check the operation status of the secondary authentication system, and staff need to go to the enterprise site for operation and maintenance, which makes the operation and maintenance of the secondary authentication system inconvenient. Summary of the Invention

[0005] This application provides an operation and maintenance system and method for a secondary authentication system to solve the problem of inconvenient operation and maintenance of existing secondary authentication systems.

[0006] In a first aspect, embodiments of this application provide an operation and maintenance system for a secondary authentication system, including: a business unit of the secondary authentication system, a management unit of the secondary authentication system, and an operation and maintenance terminal;

[0007] The business units of the secondary authentication system collect fault alarm data;

[0008] The service unit of the secondary authentication system sends the fault alarm data and the first network identifier to the management unit of the secondary authentication system;

[0009] The management unit of the secondary authentication system verifies the first network identifier and generates first verification information;

[0010] If the first verification information is verified, the management unit of the secondary authentication system sends the alarm data to the operation and maintenance terminal.

[0011] The operation and maintenance terminal generates an operation and maintenance strategy based on the alarm data;

[0012] The operation and maintenance terminal sends the operation and maintenance policy to the business unit of the secondary authentication system to realize the operation and maintenance of the business unit of the secondary authentication system.

[0013] In one possible implementation, the system further includes: a user terminal; the user terminal sending a second network identifier to a service unit of the secondary authentication system; the service unit of the secondary authentication system verifying the second network identifier and generating second verification information; if the second verification information is verified successfully, the service unit of the secondary authentication system generating a communication identifier and sending the communication identifier to the user terminal; the user terminal creating a communication link with the 5G private network based on the communication identifier to achieve access to the 5G private network.

[0014] In one possible implementation, the system further includes: a management terminal; the management terminal is located outside the coverage area of ​​the 5G private network; the management terminal sends a third network identifier to the service unit of the secondary authentication system; the service unit of the secondary authentication system verifies the third network identifier and generates third verification information; if the third verification information is verified successfully, the service unit of the secondary authentication system generates a communication identifier and sends the communication identifier to the management terminal; the management terminal creates a communication link with the 5G private network based on the communication identifier to enable access to the 5G private network.

[0015] In one possible implementation, the management terminal is located within the coverage area of ​​the 5G private network: the management terminal sends a user group modification request to the service unit of the secondary authentication system; the service unit of the secondary authentication system verifies the administrator identifier in the user group modification request and generates verification information; if the verification information is successful, the service unit of the secondary authentication system modifies the user group information according to the user group modification request.

[0016] In one possible implementation, the system further includes: a dedicated UPF; the service unit of the secondary authentication system sends the fault alarm data and the first network identifier to the dedicated UPF; the dedicated UPF sends the fault alarm data and the first network identifier to the management unit of the secondary authentication system.

[0017] Secondly, embodiments of this application provide an operation and maintenance method for a secondary authentication system, applied to an operation and maintenance system for the secondary authentication system. The operation and maintenance system for the secondary authentication system includes: a business unit of the secondary authentication system, a management unit of the secondary authentication system, and an operation and maintenance terminal; the method includes:

[0018] The business units of the secondary authentication system collect fault alarm data;

[0019] The service unit of the secondary authentication system sends the fault alarm data and the first network identifier to the management unit of the secondary authentication system;

[0020] The management unit of the secondary authentication system verifies the first network identifier and generates first verification information;

[0021] If the first verification information is verified, the management unit of the secondary authentication system sends the alarm data to the operation and maintenance terminal.

[0022] The operation and maintenance terminal generates an operation and maintenance strategy based on the alarm data;

[0023] The operation and maintenance terminal sends the operation and maintenance policy to the business unit of the secondary authentication system to realize the operation and maintenance of the business unit of the secondary authentication system.

[0024] In one possible implementation, the operation and maintenance system of the secondary authentication system further includes a user terminal; before the service unit of the secondary authentication system collects fault alarm data, the system further includes: the user terminal sending a second network identifier to the service unit of the secondary authentication system; the service unit of the secondary authentication system verifying the second network identifier and generating second verification information; if the second verification information is verified successfully, the service unit of the secondary authentication system generates a communication identifier and sends the communication identifier to the user terminal; the user terminal creates a communication link with the 5G private network based on the communication identifier to achieve access to the 5G private network.

[0025] In one possible implementation, the operation and maintenance system of the secondary authentication system further includes a management terminal; the management terminal is located outside the coverage area of ​​the 5G private network; before the service unit of the secondary authentication system collects fault alarm data, the system further includes: the management terminal sending a third network identifier to the service unit of the secondary authentication system; the service unit of the secondary authentication system verifying the third network identifier and generating third verification information; if the third verification information is verified successfully, the service unit of the secondary authentication system generating a communication identifier and sending the communication identifier to the management terminal; the management terminal creating a communication link with the 5G private network based on the communication identifier to achieve access to the 5G private network.

[0026] In one possible implementation, the management terminal is located within the coverage area of ​​the 5G private network; before the service unit of the secondary authentication system collects fault alarm data, the system further includes: the management terminal sending a user group modification request to the service unit of the secondary authentication system; the service unit of the secondary authentication system verifying the administrator identifier in the user group modification request and generating verification information; if the verification information is successful, the service unit of the secondary authentication system modifies the user group information according to the user group modification request.

[0027] In one possible implementation, the operation and maintenance system of the secondary authentication system further includes a dedicated UPF; the service unit of the secondary authentication system sends the fault alarm data and the first network identifier to the management unit of the secondary authentication system, including: the service unit of the secondary authentication system sends the fault alarm data and the first network identifier to the dedicated UPF; the dedicated UPF sends the fault alarm data and the first network identifier to the management unit of the secondary authentication system.

[0028] The operation and maintenance system and method of the secondary authentication system provided in this application divide the secondary authentication system into a business unit and a management unit. The business unit collects fault alarm data and sends the alarm data and a first network identifier to the management unit of the secondary authentication system. The management unit verifies the first network identifier. If the verification is successful, the operation and maintenance terminal generates an operation and maintenance policy based on the alarm data and sends the operation and maintenance policy to the business unit of the secondary authentication system. This eliminates the need for staff to go to the enterprise site for operation and maintenance, thus improving the convenience of operation and maintenance of the secondary authentication system. Attached Figure Description

[0029] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0030] Figure 1 This is a schematic diagram of the operation and maintenance system of the secondary authentication system provided in the embodiments of this application;

[0031] Figure 2 This is a schematic diagram of the operation and maintenance method of a secondary authentication system provided in one embodiment of this application;

[0032] Figure 3 This is a schematic diagram illustrating a scenario where a user terminal accesses an enterprise intranet, as provided in one embodiment of this application.

[0033] Figure 4 This is a schematic diagram illustrating a scenario where a management terminal accesses an enterprise intranet, as provided in one embodiment of this application.

[0034] Figure 5 This is a schematic diagram illustrating a scenario where a management terminal modifies enterprise user information, as provided in one embodiment of this application.

[0035] Figure 6 This is a schematic diagram illustrating a scenario of remote operation and maintenance of a secondary authentication system provided in one embodiment of this application. Detailed Implementation

[0036] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0037] 5G hybrid private networks represent a solution between virtual private networks (VPNs) and standalone private networks (SPRs). After a 5G terminal passes core authentication, it cannot directly connect to the enterprise's intranet business systems. Authentication must be completed through the AAA (Authorized Secondary Authentication) system before the 5G private network can establish a communication link between the user and the enterprise's intranet business systems. Currently, operators deploy the secondary authentication system within the enterprise's intranet area, physically isolating it from external networks. However, this approach requires operator staff to periodically check the system's operation and perform on-site maintenance, leading to inconvenience.

[0038] To address the aforementioned technical problems, this application proposes the following technical concept: The inventors considered dividing the secondary authentication system into business units and management units. The business units of the secondary authentication system collect fault alarm data, while the management unit verifies the first network identifier sent by the business units. Upon successful verification, the alarm data is sent to the maintenance terminal. The maintenance terminal then generates maintenance policies, which are sent to the business units of the secondary authentication system. Compared to existing technologies, this eliminates the need for on-site maintenance by personnel, improving the convenience of maintenance. Detailed embodiments are described below.

[0039] First, let me explain the terms used in this application:

[0040] Two-factor authentication system: This refers to the AAA (Authentication, Authorization, and Accounting) authentication system. The AAA system is a key component used to manage user access control and service usage. The AAA system ensures that only authenticated and authorized users can access network resources and records user usage for billing purposes.

[0041] Dedicated UPF: This refers to the User Plane Function (UPF), a key component in the core network architecture. The UPF is responsible for handling user data traffic, performing functions such as packet forwarding, routing, and quality control.

[0042] Figure 1This is a schematic diagram of the operation and maintenance system of the secondary authentication system provided in the embodiments of this application, as shown in the figure. Figure 1 As shown, the operation and maintenance system of the secondary authentication system includes: the business unit 101 of the secondary authentication system, the management unit 102 of the secondary authentication system, and the operation and maintenance terminal 103.

[0043] The business units of the secondary authentication system collect fault alarm data.

[0044] In this embodiment, the business unit of the secondary authentication system is deployed in the enterprise intranet area.

[0045] In this embodiment, the functions of the business units of the secondary authentication system include, but are not limited to, adding, deleting, modifying, and querying users, adding, deleting, modifying, and querying user groups, managing runtime parameter configurations, managing logs, and managing permissions.

[0046] In this embodiment, the self-service management services provided by the business units of the secondary authentication system to enterprise managers include, but are not limited to, identity authentication management, business authorization, machine-card binding, time period control, area control, and group management.

[0047] In this embodiment, the business unit of the secondary authentication system is deployed on a server in the enterprise intranet area and interconnected with any device in the enterprise through a wired network card.

[0048] Among these, devices that can interconnect with enterprises include, but are not limited to, computers, mobile phones, and smart tablets.

[0049] The business unit of the secondary authentication system sends fault alarm data and the first network identifier to the management unit of the secondary authentication system.

[0050] In this embodiment, the first network identifier is the first DNN (Data Network Name, abbreviated as DNN). The first DNN consists of a network ID and an operator ID, and is pre-subscribed by the operator in the service unit of the secondary authentication system.

[0051] In this embodiment, the purpose of the first network identifier is to import the alarm data of the service unit of the secondary authentication system into the management unit of the secondary authentication system.

[0052] In this embodiment, the first network identifier is stored in the 5G module of the service unit of the secondary authentication system.

[0053] The management unit of the secondary authentication system verifies the first network identifier and generates the first verification information.

[0054] In this embodiment, the management unit of the secondary authentication system is deployed on the operator's cloud platform, and the operator's network maintenance personnel can access the management unit of the secondary authentication system through the operator's intranet.

[0055] Specifically, the management unit of the secondary authentication system verifies the authenticity of the first DNN. If the verification is successful, it generates the first verification message indicating successful verification.

[0056] In this embodiment, a firewall is set up for communication between the management unit and the business unit of the secondary authentication system. The management unit and the business unit of the secondary authentication system are respectively configured with port whitelists and port IPs.

[0057] In this embodiment, the functions of the management unit of the secondary authentication system include, but are not limited to, system log reporting, alarm data reporting, operation and maintenance policy distribution, and software updates.

[0058] If the first verification message is successful, the management unit of the secondary authentication system sends alarm data to the operation and maintenance terminal.

[0059] Specifically, the management unit of the secondary authentication system sends alarm data to the operation and maintenance terminal via wireless communication.

[0060] The operation and maintenance terminal generates operation and maintenance policies based on alarm data.

[0061] In this embodiment, the methods for generating operation and maintenance strategies include, but are not limited to, manually writing operation and maintenance strategies, querying the operation and maintenance strategy library to obtain operation and maintenance strategies, and generating operation and maintenance strategies through algorithm models.

[0062] The operation and maintenance terminal sends operation and maintenance policies to the business units of the secondary authentication system to realize the operation and maintenance of the business units of the secondary authentication system.

[0063] In this embodiment, the operation and maintenance terminal is deployed in the operator's intranet and transmits data with the management unit of the secondary authentication system.

[0064] In this embodiment, the API interface between the management unit and the business unit of the secondary authentication system adopts a TLS encrypted secure channel, is configured with two-way certificate authentication, and the interface data packets are encrypted and signed using AccessKey / SecretKey to prevent data tampering and replay attacks.

[0065] In this embodiment, the management unit of the secondary authentication system provides the operation and maintenance API interface to the network operation and maintenance personnel of the operator.

[0066] As can be seen from the above embodiments, by dividing the secondary authentication system into business units and management units, the business units collect fault alarm data and send the alarm data and the first network identifier to the management unit of the secondary authentication system. The management unit verifies the first network identifier. If the verification is successful, the operation and maintenance terminal generates operation and maintenance policies based on the alarm data and sends the operation and maintenance policies to the business units of the secondary authentication system. This eliminates the need for staff to go to the enterprise site for operation and maintenance, thus improving the convenience of operation and maintenance of the secondary authentication system.

[0067] In one embodiment of this application, the operation and maintenance system of the secondary authentication system further includes: a user terminal, specifically including:

[0068] The user terminal sends the second network identifier to the business unit of the secondary authentication system.

[0069] In this embodiment, the user terminal is an enterprise user terminal that has not been authenticated by the business unit through the secondary authentication system.

[0070] In this embodiment, the user terminal device includes, but is not limited to, computers, mobile phones, and smart tablets.

[0071] The business unit of the secondary authentication system verifies the second network identifier and generates second verification information.

[0072] In this embodiment, the second network identifier is the second DNN. The purpose of the second network identifier is to send the intranet connection request initiated by the user terminal to the service unit of the secondary authentication system.

[0073] In this embodiment, the second verification information is the verification information generated by the business unit of the secondary authentication system after verifying the second network identifier.

[0074] If the second verification information passes the verification, the business unit of the secondary authentication system generates a communication identifier and sends the communication identifier to the user terminal.

[0075] In this embodiment, if the second verification information is verified successfully, the business unit of the secondary authentication system allows the user terminal to access the enterprise intranet and generates a communication identifier.

[0076] User terminals establish a communication link with the 5G private network based on the communication identifier to enable access to the 5G private network.

[0077] Figure 3 This is a schematic diagram illustrating a scenario where a user terminal accesses an enterprise intranet, as provided in one embodiment of this application.

[0078] like Figure 3As shown, the user terminal transmits the intranet connection request to the dedicated UPF through the 5G base station. The dedicated UPF sends the second network identifier and the intranet connection request to the business unit of the secondary authentication system. The business unit of the secondary authentication system performs secondary authentication on the user terminal. After successful authentication, a communication identifier is generated and sent to the user terminal, enabling the user terminal to connect to and access the enterprise intranet business system.

[0079] As can be seen from the above embodiments, by sending the second network identifier to the service unit of the secondary authentication system, and using the service unit of the secondary authentication system to verify the second network identifier, a communication link for the user terminal to access the 5G private network is established after successful verification, thereby improving the security of the user terminal accessing the 5G private network.

[0080] In one embodiment of this application, the operation and maintenance system of the secondary authentication system further includes: a management terminal, which, when the management terminal is located outside the coverage area of ​​the 5G private network, specifically includes:

[0081] The management terminal sends the third network identifier to the business unit of the secondary authentication system.

[0082] In this embodiment, the management terminal is the terminal device of the enterprise intranet administrator.

[0083] In this embodiment, the devices used for managing the terminal include, but are not limited to, computers, mobile phones, and smart tablets.

[0084] In this embodiment, the third network identifier is the third DNN. The purpose of the third network identifier is to send the intranet connection request initiated by the management terminal to the business unit of the secondary authentication system.

[0085] Specifically, the management terminal sends the third network identifier to the N4 port address of the dedicated UPF, and the dedicated UPF sends the third network identifier to the service unit of the secondary authentication system.

[0086] The business unit of the secondary authentication system verifies the third network identifier and generates third verification information.

[0087] In this embodiment, the third verification information is the verification information generated by the business unit of the secondary authentication system after verifying the third network identifier.

[0088] In this embodiment, when the management terminal is outside the coverage area of ​​the enterprise intranet, the management terminal needs to undergo secondary authentication by the business unit of the secondary authentication system before it can access the enterprise intranet.

[0089] In this embodiment, after the business unit of the secondary authentication system passes the management terminal authentication, the management terminal can realize three-layer IP interconnection based on terminal mutual access at the dedicated UPF, and realize remote access to the enterprise intranet.

[0090] If the third verification information is verified, the business unit of the secondary authentication system generates a communication identifier and sends the communication identifier to the management terminal.

[0091] In this embodiment, if the third verification information is verified, the business unit of the secondary authentication system allows the management terminal to access the enterprise intranet and generates a communication identifier.

[0092] The management terminal creates a communication link with the 5G private network based on the communication identifier to enable access to the 5G private network.

[0093] Figure 4 This is a schematic diagram illustrating a scenario where a management terminal accesses an enterprise intranet, as provided in one embodiment of this application.

[0094] like Figure 4 As shown, the management terminal transmits the intranet connection request to the dedicated UPF via the 5G base station. The dedicated UPF sends the third network identifier and the intranet connection request to the 5G base station. The 5G base station sends the third network identifier and the intranet connection request to the business unit of the secondary authentication system. The business unit of the secondary authentication system performs secondary authentication on the management terminal. After successful authentication, a communication identifier is generated and sent to the management terminal, enabling the management terminal to connect to and access the enterprise intranet business system.

[0095] As can be seen from the above embodiments, by sending the third network identifier sent by the management terminal to the service unit of the secondary authentication system, and using the service unit of the secondary authentication system to verify the third network identifier, a communication link for the management terminal to access the 5G private network is established after successful verification. This enables the management terminal to remotely use the 5G private network when it is outside the coverage area of ​​the 5G private network, thus improving the convenience of the management terminal using the 5G private network when it is outside the coverage area of ​​the 5G private network.

[0096] In one embodiment of this application, when the management terminal is located within the coverage area of ​​a 5G private network, specifically including:

[0097] The management terminal sends a user group modification request to the business unit of the secondary authentication system.

[0098] In this embodiment, the internal information management requests initiated by the management terminal to the business units of the secondary authentication system include, but are not limited to, user addition, deletion, query and modification, user group addition, deletion, query and modification, operation parameter configuration management, log management and permission management.

[0099] The business unit of the secondary authentication system verifies the administrator identifier in the user group modification request and generates verification information.

[0100] In this embodiment, the form of administrator identification includes, but is not limited to, administrator name, administrator number, and administrator-customized identifier.

[0101] If the verification information is successful, the business unit of the secondary authentication system modifies the user group information according to the user group modification request.

[0102] In this embodiment, if the administrator identifier is recorded in the business unit of the secondary authentication system, the management terminal verification information that has passed the verification is generated, and the management terminal is granted permission to modify information on the enterprise intranet.

[0103] In this embodiment, the WAN port of the wired network card of the server where the business unit of the secondary authentication system is located receives the enterprise intranet IP address assigned by the management terminal, thereby realizing the routing configuration between the enterprise terminal and the enterprise intranet.

[0104] Figure 5 This is a schematic diagram illustrating a scenario where a management terminal modifies enterprise user information, as provided in one embodiment of this application.

[0105] like Figure 5 As shown, the management terminal sends a user group modification request to the business unit of the secondary authentication system. The business unit of the secondary authentication system verifies the administrator's identity and generates verification information. If the verification information passes the verification, the management terminal is allowed to modify the user group information and assign internal network IP addresses to enterprise terminals within the enterprise.

[0106] As can be seen from the above embodiments, by verifying the management identifier of the management terminal through the business unit of the secondary authentication system, if the verification is successful, the management terminal is allowed to modify the user group information. The secondary authentication system is used to perform secondary authentication on the management terminal, which improves the security of the terminal device's permission to modify intranet services.

[0107] In one embodiment of this application, the operation and maintenance system of the secondary authentication system further includes: a dedicated UPF, specifically including:

[0108] The business unit of the secondary authentication system sends fault alarm data and the first network identifier to the dedicated UPF.

[0109] In this embodiment, the service unit of the secondary authentication system sends the fault alarm data and the first network identifier to the 5G base station through the WAN port, and then transmits them to the dedicated UPF through the 5G base station.

[0110] The dedicated UPF sends fault alarm data and the first network identifier to the management unit of the secondary authentication system.

[0111] In this embodiment, the leased line UPF sends fault alarm data and the first network identifier to the management unit of the secondary authentication system through the API interface.

[0112] In this embodiment, data transmission between API interfaces uses a TLS encrypted secure channel, is configured with two-way certificate authentication, and interface data packets are encrypted and signed using AccessKey / SecretKey to prevent data tampering and replay attacks.

[0113] Figure 6 This is a schematic diagram illustrating a scenario of remote operation and maintenance of a secondary authentication system provided in one embodiment of this application.

[0114] like Figure 6 As shown, the service unit of the secondary authentication system sends the fault alarm data and the first network identifier to the 5G base station. The 5G base station then sends the fault alarm data and the first network identifier to the management unit of the secondary authentication system via a dedicated UPF. The management unit of the secondary authentication system verifies the first network identifier. If the verification is successful, the alarm data is sent to the operation and maintenance terminal. The operation and maintenance terminal generates an operation and maintenance policy and distributes it to the service unit of the secondary authentication system to achieve remote operation and maintenance.

[0115] As can be seen from the above embodiments, by sending the fault alarm data and the first network identifier to the dedicated UPF, and then using the dedicated UPF to forward the first network identifier and the fault alarm data to the management unit of the secondary authentication system, the security of data transmission is improved.

[0116] Figure 2 This is a schematic diagram of the operation and maintenance method of a secondary authentication system provided in one embodiment of this application, with reference to... Figure 1 The operation and maintenance system of this secondary authentication system includes: the business unit of the secondary authentication system, the management unit of the secondary authentication system, and the operation and maintenance terminal. The method includes:

[0117] S201: The business unit of the secondary authentication system collects fault alarm data.

[0118] S202: The business unit of the secondary authentication system sends fault alarm data and the first network identifier to the management unit of the secondary authentication system.

[0119] S203: The management unit of the secondary authentication system verifies the first network identifier and generates the first verification information.

[0120] S204: If the first verification information is verified successfully, the management unit of the secondary authentication system sends alarm data to the operation and maintenance terminal.

[0121] S205: The operation and maintenance terminal generates operation and maintenance policies based on alarm data.

[0122] S206: The operation and maintenance terminal sends the operation and maintenance policy to the business unit of the secondary authentication system to realize the operation and maintenance of the business unit of the secondary authentication system.

[0123] As can be seen from the above embodiments, by dividing the secondary authentication system into business units and management units, the business units collect fault alarm data and send the alarm data and the first network identifier to the management unit of the secondary authentication system. The management unit verifies the first network identifier. If the verification is successful, the operation and maintenance terminal generates operation and maintenance policies based on the alarm data and sends the operation and maintenance policies to the business units of the secondary authentication system. This eliminates the need for staff to go to the enterprise site for operation and maintenance, thus improving the convenience of operation and maintenance of the secondary authentication system.

[0124] In one embodiment of this application, the operation and maintenance system of the secondary authentication system further includes a management terminal, and before step S201, the following steps are also included:

[0125] S301: The user terminal sends the second network identifier to the secondary authentication system.

[0126] S302: The business unit of the secondary authentication system verifies the second network identifier and generates second verification information.

[0127] S303: If the second verification information is verified, the business unit of the secondary authentication system generates a communication identifier and sends the communication identifier to the user terminal.

[0128] S304: The user terminal establishes a communication link with the 5G private network based on the communication identifier to enable access to the 5G private network.

[0129] As can be seen from the above embodiments, by sending the second network identifier to the service unit of the secondary authentication system, and using the service unit of the secondary authentication system to verify the second network identifier, a communication link for the user terminal to access the 5G private network is established after successful verification, thereby improving the security of the user terminal accessing the 5G private network.

[0130] In one embodiment of this application, the operation and maintenance system of the secondary authentication system further includes a management terminal, and the system further includes the following steps before step S201:

[0131] S401: The management terminal sends the third network identifier to the service unit of the secondary authentication system.

[0132] S402: The business unit of the secondary authentication system verifies the third network identifier and generates third verification information.

[0133] S403: If the third verification information is verified, the business unit of the secondary authentication system generates a communication identifier and sends the communication identifier to the management terminal.

[0134] S404: The management terminal creates a communication link with the 5G private network based on the communication identifier to enable access to the 5G private network.

[0135] As can be seen from the above embodiments, by sending the third network identifier sent by the management terminal to the service unit of the secondary authentication system, and using the service unit of the secondary authentication system to verify the third network identifier, a communication link for the management terminal to access the 5G private network is established after successful verification. This enables the management terminal to remotely use the 5G private network when it is outside the coverage area of ​​the 5G private network, thus improving the convenience of the management terminal using the 5G private network when it is outside the coverage area of ​​the 5G private network.

[0136] In one embodiment of this application, when the management terminal is within the coverage area of ​​the 5G private network, the method further includes the following step before step S201:

[0137] S501: The management terminal sends a user group modification request to the business unit of the secondary authentication system.

[0138] S502: The business unit of the secondary authentication system verifies the administrator identifier in the user group modification request and generates verification information.

[0139] S503: If the verification information is successful, the business unit of the secondary authentication system modifies the user group information according to the user group modification request.

[0140] As can be seen from the above embodiments, by verifying the management identifier of the management terminal through the business unit of the secondary authentication system, if the verification is successful, the management terminal is allowed to modify the user group information. The secondary authentication system is used to perform secondary authentication on the management terminal, which improves the security of the terminal device's permission to modify intranet services.

[0141] In one embodiment of this application, the operation and maintenance system of the secondary authentication system further includes a dedicated UPF, and step S202 includes:

[0142] S2021: The business unit of the secondary authentication system sends fault alarm data and the first network identifier to the dedicated UPF.

[0143] S2022: The management unit that sends fault alarm data and the first network identifier to the secondary authentication system via the dedicated UPF.

[0144] As can be seen from the above embodiments, by sending the fault alarm data and the first network identifier to the dedicated UPF, and then using the dedicated UPF to forward the first network identifier and the fault alarm data to the management unit of the secondary authentication system, the security of data transmission is improved.

[0145] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.

Claims

1. An operation and maintenance system for a secondary authentication system, characterized in that, include: The secondary authentication system comprises a business unit, a management unit, and an operation and maintenance terminal; wherein, the secondary authentication system is an authentication, authorization, and billing system. The business units of the secondary authentication system collect fault alarm data; The service unit of the secondary authentication system sends the fault alarm data and the first network identifier to the management unit of the secondary authentication system; The management unit of the secondary authentication system verifies the first network identifier and generates first verification information; If the first verification information is verified, the management unit of the secondary authentication system sends the alarm data to the operation and maintenance terminal. The operation and maintenance terminal generates an operation and maintenance strategy based on the alarm data; The operation and maintenance terminal sends the operation and maintenance policy to the business unit of the secondary authentication system to realize the operation and maintenance of the business unit of the secondary authentication system.

2. The system according to claim 1, characterized in that, The operation and maintenance system of the secondary authentication system also includes: a user terminal; The user terminal sends a second network identifier to the service unit of the secondary authentication system; The business unit of the secondary authentication system verifies the second network identifier and generates second verification information; If the second verification information is verified, the business unit of the secondary authentication system generates a communication identifier and sends the communication identifier to the user terminal; The user terminal establishes a communication link with the 5G private network based on the communication identifier to enable access to the 5G private network.

3. The system according to claim 1, characterized in that, The operation and maintenance system of the secondary authentication system also includes: a management terminal; the management terminal is located outside the coverage area of ​​the 5G private network. The management terminal sends a third network identifier to the service unit of the secondary authentication system; The business unit of the secondary authentication system verifies the third network identifier and generates third verification information; If the third verification information is verified, the business unit of the secondary authentication system generates a communication identifier and sends the communication identifier to the management terminal; The management terminal creates a communication link with the 5G private network based on the communication identifier to enable access to the 5G private network.

4. The system according to claim 1, characterized in that, The operation and maintenance system of the secondary authentication system also includes: a management terminal; the management terminal is located within the coverage area of ​​the 5G private network. The management terminal sends a user group modification request to the business unit of the secondary authentication system; The business unit of the secondary authentication system verifies the administrator identifier in the user group modification request and generates verification information. If the verification information is successful, the business unit of the secondary authentication system modifies the user group information according to the user group modification request.

5. The system according to claim 1, characterized in that, The operation and maintenance system of the secondary authentication system also includes: a dedicated UPF; The service unit of the secondary authentication system sends the fault alarm data and the first network identifier to the dedicated UPF; The dedicated UPF sends the fault alarm data and the first network identifier to the management unit of the secondary authentication system.

6. A method for operating and maintaining a secondary authentication system, characterized in that, An operation and maintenance system for a secondary authentication system, comprising: a business unit, a management unit, and an operation and maintenance terminal; wherein the secondary authentication system is an authentication, authorization, and billing system; the method includes: The business units of the secondary authentication system collect fault alarm data; The service unit of the secondary authentication system sends the fault alarm data and the first network identifier to the management unit of the secondary authentication system; The management unit of the secondary authentication system verifies the first network identifier and generates first verification information; If the first verification information is verified, the management unit of the secondary authentication system sends the alarm data to the operation and maintenance terminal. The operation and maintenance terminal generates an operation and maintenance strategy based on the alarm data; The operation and maintenance terminal sends the operation and maintenance policy to the business unit of the secondary authentication system to realize the operation and maintenance of the business unit of the secondary authentication system.

7. The method according to claim 6, characterized in that, The operation and maintenance system of the secondary authentication system also includes a user terminal; before the business unit of the secondary authentication system collects fault alarm data, it also includes: The user terminal sends a second network identifier to the service unit of the secondary authentication system; The business unit of the secondary authentication system verifies the second network identifier and generates second verification information; If the second verification information is verified, the business unit of the secondary authentication system generates a communication identifier and sends the communication identifier to the user terminal; The user terminal establishes a communication link with the 5G private network based on the communication identifier to enable access to the 5G private network.

8. The method according to claim 6, characterized in that, The operation and maintenance system of the secondary authentication system also includes a management terminal; the management terminal is located outside the coverage area of ​​the 5G private network; before the service unit of the secondary authentication system collects fault alarm data, it also includes: The management terminal sends a third network identifier to the service unit of the secondary authentication system; The business unit of the secondary authentication system verifies the third network identifier and generates third verification information; If the third verification information is verified, the business unit of the secondary authentication system generates a communication identifier and sends the communication identifier to the management terminal; The management terminal creates a communication link with the 5G private network based on the communication identifier to enable access to the 5G private network.

9. The method according to claim 6, characterized in that, The operation and maintenance system of the secondary authentication system also includes: a management terminal; the management terminal is located within the coverage area of ​​the 5G private network; before the service unit of the secondary authentication system collects fault alarm data, it also includes: The management terminal sends a user group modification request to the business unit of the secondary authentication system; The business unit of the secondary authentication system verifies the administrator identifier in the user group modification request and generates verification information. If the verification information is successful, the business unit of the secondary authentication system modifies the user group information according to the user group modification request.

10. The method according to claim 6, characterized in that, The operation and maintenance system of the secondary authentication system also includes a dedicated UPF; the service unit of the secondary authentication system sends the fault alarm data and the first network identifier to the management unit of the secondary authentication system, including: The service unit of the secondary authentication system sends the fault alarm data and the first network identifier to the dedicated UPF; The dedicated UPF sends the fault alarm data and the first network identifier to the management unit of the secondary authentication system.

Citation Information

Patent Citations

  • Fault network element identification method, device and equipment

    CN113891374A

  • Authentication method and device, equipment and computer readable storage medium

    CN116546496A