A power communication network system
By combining optical transmission network units, secure access network units, 5G backup communication units, and network security units, the problems of coverage, security, and reliability of power communication network systems are solved, achieving flattened and efficient and stable operation of the communication network, making it suitable for power system communication network systems.
Patent Information
- Application Number
- CN202411609892.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-12
- Publication Date
- 2025-10-31
- Estimated Expiration
- 2044-11-12
AI Technical Summary
Existing power communication network systems are unable to meet the increasing demand for communication channels from new power systems, and cannot provide high coverage, security, latency, and reliability. This results in insufficient operation and maintenance support for communication networks, failing to meet the requirements for safe, stable, and efficient operation of large power grids.
The solution adopts a combination of optical transmission network unit, secure access network unit, 5G backup communication unit, communication network management platform and network security unit. By combining full-line optical network, 5G network and intelligent switching device and BFD intelligent host, the reliability and security of communication network are achieved. Passive optical splitter and 5G slicing private network technology are used to improve signal coverage, and hyper-converged firewall and network isolation technology are combined to ensure security.
It improves the coverage, security, and reliability of communication networks, flattens the communication network structure, reduces the total cost of ownership, ensures the stable, efficient, and secure operation of communication networks, enables rapid fault recovery, and is suitable for signal coverage in remote areas.
Smart Images

Figure CN119484396B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of power system technology, and more specifically to a power communication network system. Background Technology
[0002] As an indispensable and crucial component of the power system, the communication network system provides the foundation for specialized communication services throughout the entire process of power generation, transformation, transmission, distribution, and consumption. The power information and communication system transmits a vast amount of grid information. High-speed, real-time, and two-way information communication is essential for operations such as production automation, power marketing, dispatch automation, and office automation. It creates a fundamental environment for power system infrastructure construction, the introduction of advanced technologies, and the application of intelligent equipment, thus forging an inseparable relationship between power information and communication and grid construction.
[0003] With the development of new power systems, higher demands are placed on the information and communication technologies of the power grid. In particular, significant changes in the power production structure have led to substantial alterations in the form of power communication networks, thereby placing higher demands on the performance of power communication networks that carry important production operations. Simultaneously, the increased demand for communication channels in new power systems has also placed higher requirements on the coverage, security, latency, and reliability of communication networks. Existing communication network systems are insufficient to meet the operational and maintenance requirements of communication networks, and consequently, cannot meet the needs of safe, stable, and efficient operation of large power grids. Summary of the Invention
[0004] The purpose of this invention is to provide a power communication network system that addresses the increased demand for communication channels in new power systems and improves the coverage, security, latency, and reliability of the communication network.
[0005] To achieve the above objectives, the present invention provides a power communication network system, comprising: an optical transmission network unit, a secure access network unit, a 5G backup communication unit, a communication network management platform, and a network security unit; the communication network management platform manages the optical signal or electrical signal transmission of the optical transmission network unit; the optical transmission network unit and the secure access network unit are signal-connected, and the optical signal or electrical signal is transmitted to the user terminal through the secure access network unit; the 5G backup communication unit is signal-connected to the optical transmission network unit to ensure the reliability of network communication; the network security unit is signal-connected to the secure access network unit to ensure the security of the secure access network unit and the 5G backup communication unit.
[0006] The secure access network unit includes: an all-line optical network; the all-line optical network distributes optical signals to multiple users through passive optical splitters, including:
[0007] The optical line terminal (OLT) is signal-connected to the optical transmission network unit and performs conversion, frame processing, and transmission management on the entire optical line network.
[0008] The optical network unit on the user side converts the optical signals transmitted through the optical fiber into electrical signals and sends the electrical signals to each user.
[0009] An optical distribution network is signal-connected to both the optical line terminal and the user-side optical network unit, providing an optical transmission medium for the user-side optical network unit.
[0010] Optionally, methods for achieving communication network reliability include:
[0011] The combination of 5G network with intelligent handover device and BFD intelligent host combines the high bandwidth and low latency characteristics of 5G network with the intelligent scheduling and fault detection capabilities of intelligent handover device and bidirectional forwarding detection intelligent host to achieve intelligent scheduling of network traffic and rapid fault recovery.
[0012] 5G network and fiber optic physical isolation technology enables the 5G network and fiber optic network to carry different services and data respectively, thereby achieving physical isolation at the communication network level.
[0013] Optionally, the 5G backup communication unit includes:
[0014] 5G slicing private network is a private network channel based on 5G slicing technology. It is connected to the optical transmission network unit signal and can allocate different virtual resources on a unified communication network infrastructure for different scenario needs.
[0015] Remote stations transmit data wirelessly to 5G slicing private networks, enabling signal coverage in remote areas and providing communication services.
[0016] Optionally, the security of the secure access network unit and the 5G backup communication unit can be achieved through a trusted wireless local area network (WLAN), wherein the protection method for the trusted WLAN includes:
[0017] Encryption technology uses strong encryption algorithms to encrypt data streams in wireless local area networks;
[0018] Network isolation uses security protocols in wireless LANs to separate different users and devices into different network zones.
[0019] Regularly update and maintain the equipment, including regularly updating the firmware and software of the wireless LAN devices and performing necessary security maintenance;
[0020] An authentication mechanism ensures that authorized devices can access the network.
[0021] Optionally, the security of the secure access network unit and the 5G backup communication unit can also be achieved through a hyper-converged firewall, wherein the protection methods of the hyper-converged firewall include:
[0022] Deep packet inspection identifies and blocks potential malicious traffic through in-depth analysis of packet content;
[0023] Intelligent threat defense utilizes machine learning and artificial intelligence technologies to automatically identify and respond to emerging threats;
[0024] It integrates multiple security functions, providing users with comprehensive security protection through intrusion detection and defense systems, virtual private networks, and antivirus features.
[0025] Optionally, the network security unit includes: a wireless network security module, the wireless network security module comprising:
[0026] The application server's certificate issuance function provides WAPI certificate issuance services to issue digital identity credentials to connected wireless access points and terminal devices.
[0027] The application server's authentication function adopts an elliptic curve-based public key certificate system and uses a secure message hash algorithm to ensure message integrity.
[0028] The user isolation feature isolates different devices connected to the same wireless access point.
[0029] Optionally, the network security unit further includes:
[0030] The network security module provides a network function slicing isolation mechanism for the 5G backup communication unit and uses the IP-MAC binding function to associate IP addresses and MAC addresses together.
[0031] The distributed denial-of-service attack protection module connects to the secure access network unit signal, enabling it to expand network bandwidth and increase server resources.
[0032] The external scanning attack defense module monitors user behavior by monitoring the rate at which network users initiate connections to the target system.
[0033] Optionally, the optical transmission network unit includes:
[0034] The optical layer can use substations to convert data from electrical signals to optical signals and transmit the data through optical fibers.
[0035] The electrical layer, working in conjunction with the optical layer, receives optical signals, converts the received optical signals into electrical signals, and processes the electrical signals.
[0036] Optionally, the communication network management platform includes:
[0037] The topology centralized monitoring module is connected to the optical layer signal of the optical transmission network unit, which can monitor the operating status of all devices in real time and provide appropriate ways to configure and modify network parameters according to changes in the communication network operating environment.
[0038] The fault management module is connected to the electrical layer signal of the optical transmission network unit. It can monitor the faults and operating status of all network devices in real time, and perform statistical analysis on historical data to provide means to assist in troubleshooting.
[0039] The network performance management module is connected to the optical layer signal of the optical transmission network unit, and can provide a means of monitoring the performance of large-scale communication networks.
[0040] The northbound interface is connected to the topology centralized monitoring module, fault management module, and network performance management module, enabling the communication network management platform to perform fault, topology, and resource queries.
[0041] The report management module connects with the topology centralized monitoring module, fault management module, and network performance management module, and can provide template-based report development and web-based report generation and distribution.
[0042] The device configuration file management module provides rich configuration management capabilities for network devices and tracks device configuration changes.
[0043] Optionally, the full-line optical network further includes: the Internet of Things (IoT), which is connected to the optical transmission network via electrical layer signals, supports mobile edge computing, IoT services and 5G transmission, and can meet the unified access requirements of IoT services such as intelligent inspection, mobile operation and video surveillance.
[0044] Compared with the prior art, the technical solution of the present invention has at least the following beneficial effects:
[0045] In the passive optical local area network (PLAN) scheme of the power communication network system described in this invention, the substation constructs a backbone access network through optical line terminals, and end-user service access is achieved through optical network units on the user side for different service types. The PLAN uses passive optical fiber splitters as its aggregation layer, eliminating the need for multi-level active aggregation nodes in traditional campus networks, making the communication network more flattened. From a communication network investment perspective, it saves on the aggregation layer, as well as the associated equipment rooms, power supply, and air conditioning, thereby reducing the total cost of ownership and making the communication network more environmentally friendly. The optical distribution network structure composed of passive optical splitters is clear and suitable for different service structures. WAPI adopts a three-element security architecture, with three physical entities having independent identities, truly achieving direct bidirectional authentication between mobile terminals and wireless access points, effectively ensuring air interface security and preventing fake APs and phishing APs. Simultaneously, based on the secure and controllable combination of WAPI+POL technologies, high-speed wired and wireless network coverage is achieved within the substation. EC is introduced at the service access layer, enabling simultaneous access for IP services, IoT services, auxiliary control services, and environmental monitoring services.
[0046] The power communication network system described in this invention utilizes a dedicated communication network management platform for centralized topology monitoring. This platform enables real-time monitoring of the operational status of all devices and provides appropriate methods for configuring and modifying network parameters based on changes in the communication network operating environment, ensuring the communication network operates normally with optimal performance. Simultaneously, the fault management module provides real-time monitoring and historical statistics of faults and operational status of all network devices, along with methods to assist in troubleshooting. The communication network performance management component provides large-scale communication network performance monitoring methods, monitoring network performance from multiple levels—devices, links, paths, and services—and serving as an indicator for evaluating network operational quality.
[0047] The power communication network system described in this invention utilizes a combination of a 5G network, an intelligent switching device, and a BFD intelligent host to achieve intelligent scheduling of communication network traffic and rapid fault recovery. Simultaneously, the power communication network system achieves physical isolation between the 5G network and optical fiber, effectively preventing interference and conflicts between different services and data, thereby improving the security and reliability of the communication network. Attached Figure Description
[0048] Figure 1 This is a schematic diagram of the power communication network system of the present invention.
[0049] Figure 2 This is a schematic diagram of the structure of the optical transmission network unit in the power communication network system of the present invention.
[0050] Figure 3 This is a schematic diagram of the structure of the secure access network unit in the power communication network system of the present invention.
[0051] Figure 4 This is a schematic diagram of the structure of the 5G backup communication unit in the power communication network system of the present invention.
[0052] Figure 5 This is a schematic diagram of the structure of the communication network management platform in the power communication network system of the present invention.
[0053] Figure 6 This is a schematic diagram of the network security unit in the power communication network system of the present invention.
[0054] Figure 7 This is a schematic diagram of the architecture of the power communication network system of the present invention. Detailed Implementation
[0055] The technical solution of the present invention will now be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0056] In the description of this invention, it should be noted that the terms "upper," "lower," "left," "right," "vertical," "horizontal," "inner," and "outer," etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are used only for the convenience of describing this invention and for simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on this invention. Furthermore, the terms "first," "second," and "third" are used for descriptive purposes only and should not be construed as indicating or implying relative importance.
[0057] In the description of this invention, it should be noted that, unless otherwise explicitly specified and limited, the terms "installation," "connection," and "linking" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal communication between two components. Those skilled in the art can understand the specific meaning of the above terms in this invention based on the specific circumstances.
[0058] like Figure 1As shown, this invention provides a power communication network system, including: an optical transmission network unit, a secure access network unit, a 5G backup communication unit, a communication network management platform, and a network security unit. The communication network management platform can centrally schedule and allocate communication resources, and manage the transmission of communication signals (specifically optical or electrical signals) of the optical transmission network unit; the optical transmission network unit and the secure access network unit are signal-connected; the 5G backup communication unit is signal-connected to the optical transmission network; and the network security unit is signal-connected to the secure access network unit. The optical transmission network unit outputs communication signals, which are then transmitted to the user terminal through the secure access network unit; simultaneously, the optical transmission network unit ensures the reliability of 5G network communication through the 5G backup communication unit; and the secure access network unit ensures the security of 5G network communication through the network security unit.
[0059] like Figure 2 As shown, the optical transmission network unit is an OSU (Optical Service Unit), which has the capability of transmitting hard channels and the ability to integrate packet multiplexing, and can meet the capability requirements of power communication networks. The optical transmission network unit achieves reliability through methods including: critical link protection and 1+1 protection for critical components.
[0060] Critical link protection in fiber optic communication networks involves implementing special protection measures for critical links in the transmission path to ensure rapid communication recovery in the event of a failure, thereby guaranteeing the stability and reliability of the entire network. Specific methods of critical link protection include: redundant links and automatic protection switching mechanisms. Redundant links involve deploying redundant optical cables and transmission paths on the critical links. When the primary link fails, it can automatically or manually switch to a backup link, achieving seamless switching. The automatic protection switching mechanism can monitor the communication status of the critical links in real time; once a fault is detected, the protection mechanism is immediately triggered, switching to the backup link.
[0061] The "1+1" critical board protection mechanism is a dual-board redundancy protection mechanism implemented on the critical boards of fiber optic communication equipment. In this protection method, each critical board is equipped with a backup board. The primary and backup boards operate simultaneously but transmit only the same data stream, while the receiving end selects the path with better signal quality. When the primary board fails, the backup board immediately takes over the service, ensuring uninterrupted communication. The protection methods of the "1+1" critical board include concurrent transmission and single-end switching. Concurrent transmission involves simultaneously sending the same data stream to both the primary and backup boards. Single-end switching monitors signal quality at the receiving end; when the primary board's signal quality deteriorates or fails, it automatically switches to the backup board to receive data.
[0062] The optical transmission unit comprises an optical layer and an electrical layer. The optical layer utilizes a substation to convert data from electrical signals to optical signals and transmits the data via optical fiber. The initial bandwidth of the optical layer is 3×10G, and each bandwidth channel can exclusively occupy a 10Gbps bandwidth channel, ensuring the independence and efficiency of data transmission. Simultaneously, the optical layer can support upgrades to N×100G bandwidth configurations; where N is a variable representing the ability to upgrade to multiple 100Gbps bandwidth channels. The electrical layer works in conjunction with the optical layer, receiving optical signals, converting the received optical signals into electrical signals, and processing the electrical signals. The electrical layer supports various rates and types of interfaces, including: 64k, E1, FE, GE, 10GE, and STM-N.
[0063] The service capabilities of the optical transmission network unit include: supporting dispatch voice, supporting communication protocols, supporting dispatch data network and integrated data network services, supporting OSU (Optical Service Unit) technology, and being able to transmit voice signals, carry real-time control services of the power grid, and carry administrative office information data and management information data such as financial and marketing information data.
[0064] The communication protocols include IEC-60870-101 and IEC-60870-104. IEC-60870-101 is a protocol standard for communication between remote control equipment and systems in power systems, used for remote control, remote protection and related communication in power systems. IEC-60870-104 is a commonly used communication protocol in power automation systems, used for monitoring and controlling various devices in power systems.
[0065] The OSU technology utilizes OSU cards to support high-efficiency small-granularity services at 2M / 10M / 100M. It divides the OPUk (Optical Channel Payload Unit) payload area in the existing OTN (Optical Transport Network) architecture into multiple payload blocks, defining a PB (Payload Block) base rate of 2.6Mbps, with each PB corresponding to one tributary. When mapping and multiplexing multiple OSU flex signals to the OPUk / flex payload, a TPN (Tribute Port Number) needs to be added to each OSU flex signal to identify the correspondence between them. The TPN must ensure unique identification within the service layer to ensure the receiver can correctly distinguish the tributary port number. A PB with the same TPN corresponds to one OSU flex channel. The TPN functions similarly to the MSI (Mean Signal Indicator) function in OTN, where MSI represents a signal with a rate of approximately n×100G.
[0066] The OSU TPN is 12 bits long, and each OPUk pipe in a single-level mapping supports approximately 4k OSU connections (2). 12 =4096), but currently the chip needs to take into account the implementation complexity and the number of OSU links supported. The number of single OSUk pipeline connections supported by the current equipment manufacturers is 1k. Taking single-level mapping as an example, a single wavelength 100G can provide 1000 service connections, and a single optical fiber can realize 120,000 hard slices (120 wavelengths × 1000 = 120,000). Compared with traditional OTN (80 wavelengths × 80 = 6,400), the number of service connections can be increased by 18.75 times. While supporting smaller granular service access, it can also support more innovative applications in vertical industries.
[0067] like Figure 3 As shown, the secure access network unit adopts a combination of secure and controllable WAPI+POL network technologies to achieve high-speed wired and wireless network coverage within power facilities. Furthermore, EC is introduced at the service access layer to enable simultaneous access for IP services, IoT services, auxiliary control services, and environmental monitoring services.
[0068] The secure access network unit is signal-connected to the optical transmission network unit, including: a passive optical network (PON) and an Internet of Things (IoT). The PON is signal-connected to the optical layer of the optical transmission network unit; the PON is a broadband access network using optical fiber as the transmission medium, distributing optical signals to multiple users through a passive optical splitter, achieving sharing of a single optical fiber. The IoT is signal-connected to the electrical layer of the optical transmission network and can receive electrical signals emitted by the electrical layer; the IoT supports mobile edge computing (MEC), IoT services, and 5G transmission, and can meet the unified access requirements of IoT services such as intelligent inspection, mobile operations, and video surveillance.
[0069] like Figure 7 As shown, the full-line optical network includes: an optical line terminal (OLT), an optical network unit (ONU) on the user side, and an optical distribution network (ODN).
[0070] like Figure 7 As shown, the optical line terminal (OLT) is located in the substation and serves as the starting point of the passive optical network (PON). The OLT is connected to the optical layer signal of the optical transmission network unit (OTN) and connected to the core switch (POS) via an Ethernet cable. It is capable of performing conversion, frame processing, and transmission management across the entire optical network, and coordinating the optical network terminals (i.e.,…) Figure 7The optical network unit (ONT / OSU) is multiplexed to share uplink transmission. The user-side ONT converts the optical signals transmitted through the optical fiber into electrical signals and sends these electrical signals to each user. The optical distribution network is located in a passive optical splitter, establishing a signal connection between the optical line terminal and the user-side ONT, providing an optical transmission medium for physical connections from the user-side ONT to optical line terminals at distances of 20 kilometers and beyond.
[0071] Furthermore, the WAPI+POL network technology can be divided into WAPI (Wireless LAN Security Protocol) technology and POL (Passive Optical LAN) solutions. In the POL solution, substations construct a backbone access network through optical line terminals, and end-user service access is achieved through optical network units on the user side for different service types. The POL uses passive optical fiber splitters as its aggregation layer, eliminating the need for multi-level active aggregation nodes in traditional campus networks, making the network more flattened. From a network investment perspective, saving on the aggregation layer also saves on the corresponding equipment room, power supply, and air conditioning costs, reducing the total cost of ownership (TCO) and making the network more environmentally friendly. The optical distribution network structure composed of passive optical splitters is clear and suitable for different service structures. The wireless LAN technology adopts a three-element security architecture, with three physical entities having independent identities, truly achieving direct two-way authentication between mobile terminals and wireless access points, effectively ensuring air interface security and preventing fake and phishing APs from a security mechanism perspective.
[0072] The secure access network unit achieves security through a combination of trusted wireless local area networks (WLANs) and hyper-converged firewalls. The trusted WLAN ensures the confidentiality, integrity, and availability of data transmission, enhancing the security and reliability of the wireless network. Specific protection methods include encryption technology, network isolation, authentication mechanisms, and regular equipment updates and maintenance.
[0073] The encryption technology uses a strong encryption algorithm to encrypt the data stream of the wireless local area network, which can effectively protect the transmitted data from being eavesdropped on or tampered with; the application of encryption technology ensures the confidentiality of the data, and even if the data is intercepted during transmission, it cannot be easily decrypted.
[0074] The authentication mechanism ensures that authorized devices can access the network, reducing the risk of unauthorized devices accessing the communication network and thus improving the security of the communication network.
[0075] The network isolation can use wireless LAN technology to divide different users and devices into different network areas, reducing mutual interference and potential security threats.
[0076] The aforementioned regular update and maintenance equipment involves regularly updating the firmware and software of wireless LAN devices and performing necessary security maintenance, enabling users to promptly identify and fix potential security vulnerabilities and improve the overall security of the network.
[0077] The hyperconverged firewall provides basic access control functions and achieves higher-level security protection. It typically employs a high-performance hardware platform and software architecture, capable of handling large volumes of network traffic and offering flexible scalability to meet the security needs of networks of varying sizes, thus providing high performance and scalability. Simultaneously, it offers an intuitive management interface and a wealth of management tools, enabling users to easily configure and manage it. It also supports multiple deployment methods to adapt to different application scenarios, making the hyperconverged firewall easy to manage and deploy. The specific protection methods of the hyperconverged firewall include: deep packet inspection, multi-security function integration, and intelligent threat defense.
[0078] The deep packet inspection system identifies and blocks potential malicious traffic through in-depth analysis of packet content. The integrated multi-security functions provide users with comprehensive security protection through intrusion detection and defense systems, Virtual Private Networks (VPNs), and antivirus software. The intelligent threat defense system utilizes machine learning and artificial intelligence technologies to automatically identify and respond to emerging threats, improving the intelligence level of the defense.
[0079] The secure access network unit achieves reliability through methods including: Class C protection, Class D protection, 1+1 key board configuration, primary / backup AC backup technology, 5G backup technology, BFD intelligent host, and intelligent switching device. Class C and Class D protection correspond to different computer security levels, with Class D protection being the lowest level, indicating that no actual security measures are applied. Class C protection is further divided into two subsystems: C1 and C2. The C1 subsystem separates users and data, protecting or restricting the propagation of user privileges, while the C2 subsystem provides controlled security protection, personal account management, auditing, and resource isolation, offering a more detailed access control environment.
[0080] The key boards are configured in a 1+1 dual configuration, meaning that each key component has a primary board and a backup board. When the primary board fails, the backup board can immediately take over the work to ensure the continuous operation of the communication network system.
[0081] The primary / backup AC backup technology includes a primary AC (Access Controller) and one or more backup ACs. In a wireless communication system, the AC is a key device for managing multiple wireless access points (APs) and terminal devices (STAs). By configuring backup ACs for the wireless access points, the reliability of the system is ensured. When the primary AC fails, the backup AC can quickly take over the work, continue to manage the wireless access points and maintain normal services, thereby avoiding service interruption.
[0082] The 5G backup technology uses the 5G network as a backup transmission channel and backup access method, which can improve the reliability of the system. When the primary transmission channel and access method fail, the system can quickly switch to the 5G backup channel to continue operating, ensuring the continuity and stability of services.
[0083] The BFD intelligent host and intelligent switching equipment enable the system to monitor the status of network links in real time and quickly perform switching operations when a fault is detected in order to restore communication and services.
[0084] The secure access network unit implements service capabilities through user-side optical network units of different service types. These service capabilities include: supporting electricity consumption information collection, AGV inspection, drone inspection, IoT sensors, video surveillance, smart wearables, and wireless office.
[0085] The 5G backup communication unit is connected to the electrical layer signal of the optical transmission network unit, enabling it to receive electrical signals output from the electrical layer and simultaneously utilize the 5G network to support the reliability of the communication network. In the event of a substation outage of the optical fiber cable, the 5G backup communication unit can switch power monitoring and dispatch telephone services to the 5G network emergency bearer, rapidly restoring services and providing dual-channel protection for IP-type services within the secure access network unit (i.e., the substation), while simultaneously achieving physical isolation between the 5G network and the optical fiber communication within the substation.
[0086] like Figure 4 As shown, the 5G backup communication unit includes a 5G slicing private network and a remote station. The 5G slicing private network is a private network channel implemented based on 5G slicing technology, connected to the electrical layer signal of the optical transmission network unit. The 5G slicing private network can allocate different virtual resources according to different scenario needs, and in emergency situations, switch power services to the 5G network. The remote station enables signal coverage in remote areas and provides communication services. Data is transmitted wirelessly between the remote station and the 5G slicing private network, reducing reliance on optical cables. In remote areas where optical cable laying is difficult and costly, setting up remote stations utilizes the high bandwidth and low latency characteristics of 5G technology, enabling remote stations to efficiently transmit large amounts of data, meeting the application needs of remote monitoring and real-time control, and solving the problem of optical cable shortages and achieving unmanned operation.
[0087] The 5G backup communication unit achieves security in the same way as the secure access network unit, specifically through a trusted wireless LAN and a hyper-converged firewall. The trusted wireless LAN enhances the security and reliability of the wireless network. The hyper-converged firewall provides basic access control functions, enabling more advanced security protection.
[0088] The reliability of the 5G backup communication unit is achieved through the following methods: 1+1 key boards, primary and backup AC backup, wireless mesh network, combination of 5G network and intelligent switching device + BFD intelligent host, and physical isolation technology between 5G network and optical fiber.
[0089] The key boards are configured in a 1+1 dual configuration, meaning that each key component has a primary board and a backup board. When the primary board fails, the backup board can immediately take over the work to ensure the continuous operation of the communication network system.
[0090] The primary and backup AC backup ensures system reliability by configuring an additional backup AC for the wireless access point. When the primary AC fails, the backup AC can quickly take over the work, continue to manage the wireless access point and maintain normal services, thereby avoiding service interruption.
[0091] The wireless mesh network is a multi-node, self-organizing, and self-healing network structure. In a wireless mesh network, each node can communicate directly with other nodes, forming multiple communication paths. When a node or link fails, the network can automatically adjust its routing to ensure normal data transmission.
[0092] The combination of the 5G network and the intelligent handover device + BFD intelligent host combines the high bandwidth and low latency characteristics of the 5G network with the intelligent scheduling and fault detection capabilities of the intelligent handover device and the Bidirectional Forwarding Detection (BFD) intelligent host to achieve intelligent scheduling of network traffic and rapid fault recovery.
[0093] The 5G network and fiber optic physical isolation technology achieves physical isolation at the communication network level by having the 5G network and fiber optic network carry different services and data respectively. This isolation method can effectively prevent interference and conflicts between different services and data, improving the security and reliability of the communication network.
[0094] The 5G backup communication unit's service capabilities include: supporting electricity information collection, AGV inspection, drone inspection, IoT sensors, video surveillance, smart wearables, and wireless office.
[0095] The Network Management System (NMS) is connected to the optical transmission network unit and can perform comprehensive management of the communication network system, including providing network management functions such as topology, configuration, assets, faults, performance, events, traffic, and reports. Figure 5 As shown, the communication network management platform specifically includes: a topology centralized monitoring module, a fault management module, a network performance management module, a report management module, a device configuration file management module, and a northbound interface.
[0096] The centralized topology monitoring module is connected to the optical layer signal of the optical transmission network unit, providing a unified topology discovery function to acquire and maintain information and connection relationships of each node in the communication network, thus achieving network-wide monitoring. The centralized topology monitoring module can monitor the operating status of all devices in real time and provide appropriate methods to configure and modify network parameters according to changes in the communication network operating environment, ensuring the network operates normally with optimal performance.
[0097] The fault management module is connected to the electrical layer signal of the optical transmission network unit, enabling real-time monitoring of the faults and operating status of all network devices, while also statistically analyzing historical data to provide assistance in troubleshooting.
[0098] The network performance management module is implemented through network performance components and is connected to the optical layer signal of the optical transmission network unit. It can provide a means of monitoring the performance of large-scale communication networks, monitor the performance of communication networks from multiple levels such as devices, links, paths, and services, and use the monitoring data at the device level, link level, path level, and service level as indicators for evaluating the network operation status.
[0099] The northbound interface integrates interface definition, protocol implementation, service encapsulation, and upper-layer applications. It supports SNMP (Simple Network Management Protocol) and CORBA (Common Object Request Broker Architecture) northbound interface protocols. The northbound interface is connected to the topology centralized monitoring module, fault management module, and network performance management module, enabling the communication network management platform to perform fault, topology, and resource queries.
[0100] The device configuration file management module provides rich configuration management capabilities for network devices, tracks device configuration changes, and immediately restores the communication network devices to normal operation through historical configuration backups when a communication network failure occurs.
[0101] The report management module is connected to the topology centralized monitoring module, fault management module, and network performance management module, and can provide template-based report development and web-based report generation and distribution, as well as store and process data in the communication network.
[0102] The IoT signal connection between the network security unit and the secure access network unit provides support for the security of the secure access network unit and the 5G backup communication unit, thereby ensuring the overall security of the communication network system. Figure 6 As shown, the network security unit includes: a wireless network security module, a network-wide security module, a DDoS protection module, and an external scanning attack defense module.
[0103] The wireless network security module includes: certificate issuance function of application server (AS), identity authentication function of application server, and user isolation function.
[0104] The application server's certificate issuance function provides WAPI certificate issuance services to issue digital identity credentials to connected wireless access points and terminal devices. Simultaneously, it employs the SM4 symmetric cryptographic algorithm to encrypt and decrypt transmitted data, fully ensuring data transmission security and the integrity of user information. For dedicated smart terminal devices, it supports the integration of a built-in cryptographic module, generating keys and P10 requests within the terminal device and sending them to the application server for certificate application and issuance.
[0105] The application server's identity authentication function uses digital identity credentials as user identity credentials. During the authentication process, it adopts an elliptic curve-based public key certificate system and uses a secure message hash algorithm to ensure message integrity, making it difficult for attackers to modify or forge authentication information and improving security strength.
[0106] The user isolation function can isolate different devices connected to the same wireless access point, so that a terminal device can only access its corresponding network, effectively avoiding Layer 2 attacks such as Address Resolution Protocol (ARP) attacks, DHCP starvation attacks, and broadcast storms.
[0107] In a preferred embodiment, when a malicious intruder uses a fake wireless access point (AP) to trick users into connecting to the fake, unauthorized AP and thereby intercepting user information, the MSG smart access gateway with user isolation functionality can enable detection of the fake phishing AP. Upon detecting an unauthorized AP or impersonating a legitimate service set identifier (SSID) from a service provider, the MSG smart access gateway can promptly alert the network administrator. When the MSG smart access gateway's unauthorized AP suppression function is enabled, upon detecting a phishing AP, the MSG smart access gateway can send a forged deauthentication data packet to the unauthorized AP and the client connected to the unauthorized AP, causing them to disconnect and suppressing the unauthorized AP's access to the client.
[0108] The network-wide security module provides a network function slicing isolation mechanism for 5G slicing private networks and achieves proactive protection through hyper-converged firewall technology. The network-wide security module utilizes IP-MAC binding function to associate IP addresses and MAC addresses together, requiring users to open the IP address associated with the corresponding MAC address through the corresponding MAC address device for network communication. This achieves multi-layered protection against ARP attacks, preventing address resolution protocol spoofing (ARP-Flood) attacks that could cause communication network failures and thus threaten the security of communication networks.
[0109] The DDoS (Distributed Denial of Service) protection module is connected to the IoT signal of the secure access network unit. By expanding the network bandwidth and increasing server resources, the communication network can better share and handle the large traffic requests brought by DDoS attacks.
[0110] The external scanning attack defense module monitors user behavior by tracking the rate at which network users initiate connections to the target system. After configuring IP address scanning attack prevention parameters, the device detects incoming TCP (Transmission Control Protocol), UDP (User Datagram Protocol), and ICMP (ICMP Control Message Protocol) packets. If the abnormal frequency exceeds a predefined threshold, it is considered a scanning attack; the excess packets are discarded. This reduces the risk of exposing potential security vulnerabilities in the target system while effectively preventing scanning attacks from consuming excessive system resources, ensuring normal network operation.
[0111] In summary, the communication network system of this invention uses a passive optical fiber splitter as the aggregation layer of the passive optical local area network, thus flattening the communication network. A communication network management platform centrally monitors the topology and adjusts network parameters in real time to ensure optimal performance. Simultaneously, the combination of a 5G network, intelligent switching device, and BFD intelligent host enables intelligent scheduling of communication network traffic and rapid fault recovery, enhancing the security and reliability of the communication network system.
[0112] Although the present invention has been described in detail through the preferred embodiments above, it should be understood that the above description should not be considered as a limitation of the present invention. Various modifications and substitutions to the present invention will be apparent to those skilled in the art after reading the above description. Therefore, the scope of protection of the present invention should be defined by the appended claims.
Claims
1. A power communication network system, characterized in that, include: Optical transmission network unit, secure access network unit, 5G backup communication unit, communication network management platform, and network security unit; The communication network management platform manages the optical or electrical signal transmission of the optical transmission network unit. The optical transmission network unit and the secure access network unit are signal-connected, and the optical or electrical signals are transmitted to the user terminal through the secure access network unit. The 5G backup communication unit is signal-connected to the optical transmission network unit to ensure the reliability of network communication. The network security unit is signal-connected to the secure access network unit to ensure the security of the secure access network unit and the 5G backup communication unit; The secure access network unit includes: an all-line optical network; the all-line optical network distributes optical signals to multiple users through passive optical splitters, including: The optical line terminal (OLT) is signal-connected to the optical transmission network unit and performs conversion, frame processing, and transmission management on the entire optical line network. The optical network unit on the user side converts the optical signals transmitted through the optical fiber into electrical signals and sends the electrical signals to each user. An optical distribution network is signal-connected to both the optical line terminal and the user-side optical network unit, providing an optical transmission medium for the user-side optical network unit.
2. The power communication network system according to claim 1, characterized in that, Methods for achieving communication network reliability include: The combination of 5G network with intelligent handover device and BFD intelligent host combines the high bandwidth and low latency characteristics of 5G network with the intelligent scheduling and fault detection capabilities of intelligent handover device and bidirectional forwarding detection intelligent host to achieve intelligent scheduling of network traffic and rapid fault recovery. 5G network and fiber optic physical isolation technology enables the 5G network and fiber optic network to carry different services and data respectively, thereby achieving physical isolation at the communication network level.
3. The power communication network system according to claim 1, characterized in that, The 5G backup communication unit includes: 5G slicing private network is a private network channel based on 5G slicing technology. It is connected to the optical transmission network unit signal and can allocate different virtual resources on a unified communication network infrastructure for different scenario needs. Remote stations transmit data wirelessly to 5G slicing private networks, enabling signal coverage in remote areas and providing communication services.
4. The power communication network system according to claim 1, characterized in that, The security of the secure access network unit and the 5G backup communication unit can be achieved through a trusted wireless local area network (WLAN), and the protection methods for the trusted WLAN include: Encryption technology uses strong encryption algorithms to encrypt data streams in wireless local area networks; Network isolation uses security protocols in wireless LANs to separate different users and devices into different network zones. Regularly update and maintain the equipment, including regularly updating the firmware and software of the wireless LAN equipment and performing necessary security maintenance; An authentication mechanism ensures that authorized devices can access the network.
5. The power communication network system according to claim 4, characterized in that, The security of the secure access network unit and the 5G backup communication unit also includes: a hyper-converged firewall, wherein the protection methods of the hyper-converged firewall include: Deep packet inspection identifies and blocks potential malicious traffic through in-depth analysis of packet content; Intelligent threat defense utilizes machine learning and artificial intelligence technologies to automatically identify and respond to emerging threats; It integrates multiple security functions, providing users with comprehensive security protection through intrusion detection and defense systems, virtual private networks, and antivirus features.
6. The power communication network system according to claim 1, characterized in that, The network security unit includes: a wireless network security module, the wireless network security module including: The application server's certificate issuance function provides WAPI certificate issuance services to issue digital identity credentials to connected wireless access points and terminal devices. The application server's authentication function adopts an elliptic curve-based public key certificate system and uses a secure message hash algorithm to ensure message integrity. The user isolation feature isolates different devices connected to the same wireless access point.
7. The power communication network system according to claim 6, characterized in that, The network security unit also includes: The network security module provides a network function slicing isolation mechanism for the 5G backup communication unit and uses the IP-MAC binding function to associate IP addresses and MAC addresses together. The distributed denial-of-service attack protection module connects to the secure access network unit signal, enabling it to expand network bandwidth and increase server resources. The external scanning attack defense module monitors user behavior by monitoring the rate at which network users initiate connections to the target system.
8. The power communication network system according to claim 1, characterized in that, The optical transmission network unit includes: The optical layer can use substations to convert data from electrical signals to optical signals and transmit the data through optical fibers. The electrical layer, working in conjunction with the optical layer, receives optical signals, converts the received optical signals into electrical signals, and processes the electrical signals.
9. The power communication network system according to claim 8, characterized in that, The communication network management platform includes: The topology centralized monitoring module is connected to the optical layer signal of the optical transmission network unit, which can monitor the operating status of all devices in real time and provide appropriate ways to configure and modify network parameters according to changes in the communication network operating environment. The fault management module is connected to the electrical layer signal of the optical transmission network unit. It can monitor the faults and operating status of all network devices in real time, and perform statistical analysis on historical data to provide means to assist in troubleshooting. The network performance management module is connected to the optical layer signal of the optical transmission network unit, and can provide a means of monitoring the performance of large-scale communication networks. The northbound interface is connected to the topology centralized monitoring module, fault management module, and network performance management module, enabling the communication network management platform to perform fault, topology, and resource queries. The report management module connects with the topology centralized monitoring module, fault management module, and network performance management module, and can provide template-based report development and web-based report generation and distribution. The device configuration file management module provides rich configuration management capabilities for network devices and tracks device configuration changes.
10. The power communication network system according to claim 8, characterized in that, The full-line optical network also includes: the Internet of Things (IoT), which is connected to the optical transmission network via electrical layer signals, supports mobile edge computing, IoT services and 5G transmission, and can meet the unified access requirements of IoT services such as intelligent inspection, mobile operation and video surveillance.
Citation Information
Patent Citations
Mining passive optical network system
CN115835066A
Special 5G network communication system for coal mine
CN115915504A