Virtual network group management method of industrial Ethernet equipment

By automating base station configuration and UDM subscription data updates, the problem of complex manual configuration of industrial Ethernet devices has been solved, achieving efficient and stable VLAN group management and improving device access efficiency and production stability.

CN121001107APending Publication Date: 2025-11-21SHENZHEN AI LINK CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511199284.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-26
Publication Date
2025-11-21

AI Technical Summary

Technical Problem

In existing technologies, the division and configuration of VLAN groups for industrial Ethernet devices rely on manual operation, which leads to cumbersome device access, high costs, and a high risk of errors. Furthermore, the response efficiency is low when business needs change, affecting production stability.

Method used

By receiving data records and configuration information from terminal devices, the system automatically completes base station configuration and UDM subscription data updates, enabling virtual network group management for terminal devices, simplifying configuration operations and reducing the risk of human error.

Benefits of technology

It enables automated access and management of industrial Ethernet devices, reduces the risk of human error, improves configuration efficiency and compatibility, and supports flexible access and stable communication of multi-VLAN devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121001107A_ABST
    Figure CN121001107A_ABST
Patent Text Reader

Abstract

The invention provides a virtual network group management method of industrial Ethernet equipment, and relates to the technical field of communication. The method comprises the following steps: receiving a data record reported by terminal equipment and a subscription permanent identifier (SUPI) of the terminal equipment; determining a target network identifier supported by the terminal equipment according to the source IP address; determining a target base station corresponding to the terminal equipment according to the identity label of the current access network cell; performing virtual network configuration on the target base station to enable the target base station to support the target network identifier; and if the target base station is successfully configured, sending a subscription data updating request to a user data management unit UDM through a network open function NEF network element according to the SUPI of the terminal device. According to the method and the device, the configuration operation when a large number of devices are accessed is simplified, the risk of human errors is reduced, and the problems of high configuration complexity and insufficient compatibility in a large-scale and multi-VLAN (Virtual Local Area Network) access scene of industrial Ethernet devices in the prior art are solved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of communication, in particular to a virtual network group management method of an industrial Ethernet device. BACKGROUND

[0002] In an industrial communication network, virtual local area network (VLAN) technology is widely used in communication management of industrial Ethernet devices as a key means to realize network segmentation and isolation. By dividing different industrial Ethernet devices into a specific VLAN, the security and stability of communication between devices can be effectively guaranteed, meeting the fine management needs of enterprises for industrial control networks.

[0003] Currently, the division and related configuration of VLAN groups in an industrial scenario are mainly realized by manual operation mode. Specifically, a user needs to input related user subscription data one by one in a user data management (UDM) system through manual input, complete the basic division of VLAN groups, and at the same time, must strictly add configuration to a 5G terminal on site according to the opening information, to ensure that the industrial Ethernet device connected by the 5G terminal can accurately access the VLAN specified by the enterprise, and realize the expected communication function.

[0004] However, this traditional manual configuration method has significant defects in actual application: when the number of industrial Ethernet devices to be accessed on site is large, the user needs to repeatedly and complexly input and debug the VLAN parameters, 5G terminal configuration information and the like corresponding to each device by hand, the operation process is tedious, greatly increasing the labor cost and time cost; more importantly, when the subsequent business needs change (such as device addition or reduction, VLAN division strategy adjustment, etc.), manual modification and adaptation of related configurations are still needed, not only the response efficiency is low, but also configuration errors are easily caused by human errors in a large number of repetitive operations, thereby causing network communication failure and affecting the continuity and stability of industrial production. SUMMARY

[0005] In view of the deficiencies in the prior art, the present application provides a virtual network group management method of an industrial Ethernet device, in order to solve the problems in the prior art.

[0006] The technical solution adopted by the embodiments of the present application is as follows: In a first aspect, the embodiments of the present application provide a virtual network group management method of an industrial Ethernet device, applied to a network management server in an industrial network, and the method comprises: receiving a data record reported by a terminal device and a subscription permanent identifier SUPI of the terminal device, wherein the data record comprises a source IP address and an identity of a current access network cell of the terminal device, and the source IP address is an IP address of an industrial Ethernet device connected to the terminal device in a downlink direction; determining a target network identifier supported by the terminal device according to the source IP address, wherein the target network identifier is used to indicate an identity of a data network corresponding to a virtual network group identifier where the terminal device is located; determining a target base station corresponding to the terminal device according to the identity of the current access network cell; performing virtual network configuration on the target base station, so that the target base station supports the target network identifier; if the target base station is configured successfully, sending, according to the SUPI of the terminal device, a subscription data update request to a user data management unit UDM through a network exposure function NEF network element, so that the UDM adds the SUPI to a target virtual network group corresponding to the virtual network group identifier where the terminal device is located.

[0007] In an embodiment, the determining of the target network identifier supported by the terminal device according to the source IP address comprises: indexing the source IP address to search a local data record to obtain a first target data record matched with the source IP address, wherein the target data record further comprises the virtual network group identifier and the target network identifier; obtaining the target network identifier from the first target data record.

[0008] In an embodiment, before the indexing of the source IP address to search the local data record to obtain the first target data record matched with the source IP address, the method further comprises: receiving input network configuration information of the industrial Ethernet device, wherein the network configuration information comprises an IP address of the industrial Ethernet device and the virtual network group identifier; generating the first target data record according to the network configuration information and an identity of a data network corresponding to the virtual network group identifier.

[0009] In an embodiment, the determining of the target base station corresponding to the terminal device according to the identity of the current access network cell comprises: indexing the identity of the current access network cell to search a local data record to obtain a second target data record matched with the identity, wherein the second target data record comprises a base station identifier corresponding to the identity; determining a base station corresponding to the base station identifier as the target base station.

[0010] In an embodiment, before the retrieving the local data record indexed by the identity of the current access network cell, and obtaining the second target data record matching the identity, the method further comprises: receiving input base station configuration information, the base station configuration information comprising: the base station identifier and an identifier of a network cell covered by a base station corresponding to the base station identifier; generating the second target data record according to the base station configuration information.

[0011] In an embodiment, the method further comprises: after receiving the subscription data update success confirmation information fed back from the NEF network element, sending a data notification to the terminal device, the data notification comprising: the source IP address and the target network identifier, the data notification being used to instruct the terminal device to initiate a session creation request according to an identifier of a public land mobile network (PLMN) of a base station currently accessed by the terminal device and the target network identifier.

[0012] In a second aspect, the embodiments of the present application further provide a virtual network group management method of an industrial Ethernet device, applied to a terminal device in an industrial network, the method comprising: listening to a data packet from a lower-connected industrial Ethernet device; updating a local packet classifier according to a source IP address and a source MAC address in the data packet; wherein the data record comprises: a source IP address, and an identity of a current access network cell of the terminal device; the source IP address is used as an IP address of the industrial Ethernet device; reporting a data record and a subscription permanent identifier (SUPI) of the terminal device to a network management server, so that the network management server determines a target network identifier supported by the terminal device according to the source IP address, and determines a target base station corresponding to the terminal device according to the identity of the current access network cell, configures the target base station with a virtual network, so that the target base station supports the target network identifier, and after the target base station configuration succeeds, sends a subscription data update request to a user data management unit (UDM) through a network exposure function (NEF) network element according to the SUPI of the terminal device, so that the UDM adds the SUPI to a target virtual network group corresponding to a virtual network group identifier in which the terminal device is located; wherein the target network identifier is used to indicate an identifier of a data network corresponding to the virtual network group identifier.

[0013] In an embodiment, the method further comprises: receiving a data notification sent by the network management server, the data notification being a notification message sent by the network management server after receiving the subscription data update success confirmation information fed back from the NEF, the data notification comprising: the source IP address and the target network identifier; initiating a session creation request according to an identifier of a public land mobile network (PLMN) currently accessed by the terminal device and the target network identifier, to create a session for the data network corresponding to the virtual network group.

[0014] In an embodiment, the method further comprises: updating the local packet classifier according to the identifier of the created session and the source IP address, to update the session identifier in the local packet classifier to the identifier of the created session.

[0015] In an embodiment, the method further comprises: receiving a target data packet sent by the industrial Ethernet device; reading the source MAC address from the target data packet; retrieving the local packet classifier by taking the source MAC address as an index, obtaining the target session identifier, and sending the target data packet by using the target session identifier.

[0016] The application provides an industrial Ethernet device virtual network group management method, which can automatically complete base station configuration, UDM subscription data update and other processes without manual intervention of a user, significantly simplifies configuration operations when a large number of devices are accessed, reduces human error risks, and solves the problems of high configuration complexity and insufficient compatibility of the prior art in the large-scale and multi-VLAN access scenario of industrial Ethernet devices. BRIEF DESCRIPTION OF DRAWINGS

[0017] In order to more clearly illustrate the technical solutions of the embodiments of the application, the following will briefly introduce the drawings needed to be used in the embodiments. It should be understood that the following drawings only show some of the embodiments of the application, and therefore should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can also be obtained without creative labor on the basis of these drawings.

[0018] Figure 1 An industrial Ethernet architecture schematic diagram provided for the embodiments of the application; Figure 2 A flowchart of an industrial Ethernet device virtual network group management method provided for the embodiments of the application; Figure 3Flowchart II of a virtual network group management method of an industrial Ethernet device according to an embodiment of the present application; Figure 4 Flowchart III of a virtual network group management method of an industrial Ethernet device according to an embodiment of the present application; Figure 5 Flowchart IV of a virtual network group management method of an industrial Ethernet device according to an embodiment of the present application; Figure 6 Flowchart V of a virtual network group management method of an industrial Ethernet device according to an embodiment of the present application; Figure 7 Flowchart VI of a virtual network group management method of an industrial Ethernet device according to an embodiment of the present application; Figure 8 Flowchart VII of a virtual network group management method of an industrial Ethernet device according to an embodiment of the present application; Figure 9 Flowchart VIII of a virtual network group management method of an industrial Ethernet device according to an embodiment of the present application; Figure 10 Structure diagram I of a virtual network group management device of an industrial Ethernet device according to an embodiment of the present application; Figure 11 Structure diagram II of a virtual network group management device of an industrial Ethernet device according to an embodiment of the present application; Figure 12 A network management server according to an embodiment of the present application. DETAILED DESCRIPTION

[0019] In order to make the objectives, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some but not all of the embodiments of the present application.

[0020] Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the claimed present application, but only represents selected embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work are within the scope of protection of the present application.

[0021] Moreover, the terms "first", "second", and the like, in the description and in the claims of the present application and the above figures are used for distinguishing between similar objects and not necessarily for describing a specific sequential or chronological order. It is to be understood that the use of data "first", "second", etc., significantly does not limit the order in which the steps are to be performed and the described steps can be performed in any order, unless this order is given by the description or by the context-suitable technical terminology. Also, the terms "comprises", "comprising", "having" and the like, are to be construed as in the sense of "including and not limiting to" many terms refer to, for example, a process, method, object, or apparatus that comprises a list of steps or units, and does not necessarily correspond to all the steps or units thereof unless the context clearly indicates otherwise. Furthermore, the term "couple" or "coupled" is intended to mean either an indirect or direct electrical association or physical contact between the items named and any combinations thereof.

[0022] It should be noted that the features of the embodiments of the present application can be combined if not in conflict.

[0023] Figure 1 An architecture diagram of an industrial Ethernet provided by an embodiment of the present application is shown in FIG. 1. As shown in FIG. 1, the industrial Ethernet can be based on the architecture of a 5G network, but is not limited thereto. For example, the industrial Ethernet can include the following network elements: Figure 1 1. User Equipment (UE): also referred to as a user device, a terminal, an access terminal, a user unit, a user station, a mobile station, a mobile station, a remote station, a remote terminal, a mobile device, a user terminal, a wireless communication device, a user agent, or a user apparatus.

[0024] 2. Industrial Ethernet device: an industrial Ethernet device connected to a terminal device. These devices are connected to terminals through an Ethernet protocol and rely on a 5G network to realize data communication, and belong to a communication member of a virtual network group (VN group).

[0025] 3. Access Network (AN): provides network access functions for authorized users in a specific area, and can use transmission tunnels of different qualities according to the level of users, the needs of services, etc. An access network that realizes the function of an access network based on wireless communication technology can be referred to as a Radio Access Network (RAN). The radio access network can manage wireless resources and provide access services for terminals, thereby completing the forwarding of control signals and user data between terminals and core networks.

[0026] 4. Network Exposure Function (NEF) entity: used to safely open services and capabilities provided by 3GPP network functions to the outside.

[0027] ​5. Session Management Function (SMF) entity: mainly used for session management, IP address allocation and management of UE, selection of manageable user plane function, termination of policy control or charging function interface, and downlink data notification, etc. In the embodiments of the present application, the function of the session management network element can be implemented.

[0028] 6. Policy Control Function (PCF) entity: a unified policy framework for guiding network behavior, providing policy rule information for control plane function network elements (such as AMF, SMF network elements, etc.), etc.

[0029] 7. User Plane Function (UPF) entity: that is, a data plane gateway. It can be used for packet routing and forwarding, or quality of service (QoS) processing of user plane data, etc. User data can access a data network (DN) through the network element. In the embodiments of the present application, the forwarding of message data can be implemented.

[0030] 8. Unified Data Management (UDM) entity, that is, a local data table, storing static subscription information and registered dynamic information of a user, such as the current access AMF of the user, the authentication state or the registration state of the user, etc.

[0031] 9. Access and Mobility Management Function (AMF) entity, a termination point of RAN signaling interface (N2), a termination point of MM message interface (N1) of non-access stratum (NAS) signaling, and the main functions include: encryption and integrity protection of NAS messages, responsible for registration, access, mobility management, authentication, short message, etc.

[0032] 10. The Network Function (NF) repository function (NRF) entity's main functions include: supporting service discovery, which means receiving service discovery requests (NF-Discovery-Request) from network elements and providing the discovered network element information to the requester; maintaining the characteristics of available network element instances and their supported service capabilities. Among these, the main characteristic parameters of a network element include: the network element instance identity document (ID), network element type, PLMN, network slice related IDs such as Single Network Slice Selection Assistance Information (S-NSSAI), Network Slice Instance IDentifier (NSIID), network element IP or domain name, network element capability information, and supported service capability names, etc.

[0033] 11. The Network Slice Selection Function (NSSF) is responsible for determining the network slice instances that the UE is allowed to access based on the UE's slice selection assistance information and subscription information.

[0034] It should be noted that, Figure 1 The AMF, SMF, UPF, NEF, PCF, UDM, and NRF entities shown can be understood as network elements in the core network used to implement different functions. These core network elements can be independent devices or integrated into the same device to implement different functions. This application does not limit this.

[0035] The following examples, in conjunction with the accompanying drawings, illustrate the method provided in this application. This application provides a virtual network group management method for industrial Ethernet devices, which is applied to a network management server in an industrial network. Figure 2 This is one of the flowcharts illustrating the virtual network group management method for industrial Ethernet devices provided in this application embodiment, such as... Figure 2 As shown, the method includes: S101, Receive the data records reported by the terminal device and the terminal device's subscription permanent identifier SUPI.

[0036] The terminal device locally creates a packet classifier, which is represented as <PDU Session ID, MAC, IP>. The PDU Session ID is a PDU session identifier, the MAC is a source MAC address of a data packet from the industrial Ethernet device connected to the terminal device, and the IP is a source IP address of the industrial Ethernet device connected to the terminal device. The initial values of the PDU Session ID, the MAC, and the IP are Null.

[0037] After the terminal device completes the local packet classifier update, the terminal device reports relevant data records to the network management server. The reported data records are represented as <IP, NR-CI>, where the IP is a source IP address, and the NR-CI is an identity of a current access network cell of the terminal device. In addition, the terminal device reports a SUPI of the terminal device to the network management server, so that the network management server can subsequently perform a user subscription data update operation.

[0038] S102, determining a target network identifier supported by the terminal device according to the source IP address.

[0039] Figure 3 As shown in FIG. 2, the method for managing a virtual network group of an industrial Ethernet device according to an embodiment of the present application includes the following steps. Figure 3 S102, determining a target network identifier supported by the terminal device according to the source IP address. S201, searching a local data record by taking the source IP address as an index to obtain a first target data record matched with the source IP address.

[0040] The target data record further includes a virtual network group identifier and a target network identifier.

[0041] The network management server pre-stores network configuration information of the industrial Ethernet device. The records are in the form of <IP, VLAN ID, NID>, where the VLAN ID is an identifier of a virtual network group VLAN to which the industrial Ethernet device belongs, and the NID is a network identifier.

[0042] The network management server performs a matching search in the local stored data records by using the source IP address, and finds a record completely matched with the source IP address, that is, a first target data record.

[0043] S202, obtaining the target network identifier from the first target data record.

[0044] After obtaining the first target data record, the NID is extracted from the record, and the NID is the target network identifier supported by the terminal device, which is used to indicate the identifier of the data network corresponding to the virtual network group identifier where the terminal device is located. Through this step, the network identifier corresponding to the terminal device is determined, which provides key information for subsequent network configuration and session creation operations.

[0045] S103, determine the target base station corresponding to the terminal device according to the identity of the current access network cell.

[0046] The network management server also stores the configuration information of the base station in the form of <gNB ID, NR-CI>, where gNB ID is the base station identifier, and NR-CI is the cell identifier covered by the base station. Using the identity of the current access network cell (NR-CI) of the terminal device, the corresponding base station identifier (gNB ID) is found in the above-mentioned base station configuration information, and the base station corresponding to the identifier is determined as the target base station.

[0047] S104, configure the target base station with virtual network, so that the target base station supports the target network identifier.

[0048] The network management server issues a configuration requirement to the target base station according to the target base station determined in step S103, requiring the target base station to support the target network identifier (NID) determined in step S102. This step ensures that the base station can correctly identify and process network communication related to the target network identifier.

[0049] S105, if the target base station configuration is successful, send a subscription data update request to the user data management unit (UDM) through the network exposure function (NEF) network element according to the SUPI of the terminal device.

[0050] When the network management server receives the NID configuration success confirmation information from the target base station, it means that the base station has made relevant preparations. At this time, the network management server initiates a user subscription data update request to the UDM through the NEF network element, using the SUPI of the terminal device as the index, and requests to add the terminal device to the VN group (i.e. the target virtual network group) identified by the VLAN ID in the matching record. Through this operation, the UDM can add the SUPI to the target virtual network group corresponding to the virtual network group identifier where the terminal device is located, and the terminal device can join the corresponding virtual network group to realize communication within the group.

[0051] In summary, the embodiment provides a virtual network group management method of an industrial Ethernet device, which can automatically complete base station configuration, UDM subscription data update and other processes without manual intervention of a user, significantly simplifies configuration operations when a large number of devices are accessed, reduces the risk of human error, and solves the problems of high configuration complexity and insufficient compatibility of the prior art in the large-scale and multi-VLAN access scenario of industrial Ethernet devices. Moreover, the industrial Ethernet devices of different VLANs can be accessed by a same terminal, and the industrial Ethernet devices of different VLANs belong to different virtual network groups, which solves the limitation that the industrial Ethernet devices of different VLANs cannot be accessed by a same terminal to access different virtual network groups in the prior art.

[0052] Figure 4 As shown in a third flowchart of the virtual network group management method of the industrial Ethernet device provided by the embodiment of the present application, Figure 4 Before S201 is performed, the method of the present application further includes: S301, receiving input network configuration information of the industrial Ethernet device.

[0053] The user inputs the network configuration information of the industrial Ethernet device into the network management server, and the network configuration information includes the IP address of the industrial Ethernet device and the virtual network group identifier. These information are the basis for subsequent data retrieval and matching. The IP address is used to uniquely identify the industrial Ethernet device, and the virtual network group identifier (such as VLAN ID) indicates the virtual network group to which the device belongs.

[0054] S302, generating a first target data record according to the network configuration information and the identifier of the data network corresponding to the virtual network group identifier.

[0055] After the network management server receives the above network configuration information, it generates a first target data record in the form of <IP, VLAN ID, NID> in combination with the network identifier (NID) corresponding to the virtual network group identifier (VLAN ID), and stores it locally. In this way, when the source IP address reported by the terminal device is received subsequently, the corresponding record can be quickly and accurately retrieved.

[0056] Figure 5 As shown in a fourth flowchart of the virtual network group management method of the industrial Ethernet device provided by the embodiment of the present application, Figure 5 S103 can include: S401, using the identity of the currently accessed network cell as an index to search the local data record to obtain a second target data record matched with the identity.

[0057] The network management server stores the configuration information of the base station in the local data record in the form of <gNB ID, NR-CI>, wherein the NR-CI is the identity of the cell covered by the base station (i.e. the identity of the currently accessed network cell), and the gNB ID is the identity of the base station. The identity of the currently accessed network cell (NR-CI) received in step S101 is used as an index to search the local base station configuration information data record, and a matching record, i.e. the second target data record, is found.

[0058] S402, determine the base station corresponding to the base station identifier as the target base station.

[0059] The base station identifier (gNB ID) is extracted from the second target data record obtained in step S401, and the base station corresponding to the identifier is the target base station currently accessed by the terminal device. After the target base station is determined, subsequent virtual network configuration operations can be performed on it.

[0060] Figure 6 The flowchart of the virtual network group management method of the industrial Ethernet device provided by the embodiment of the present application is shown in Figure 5. Figure 6 As shown in Figure 5, before step S103, the method of the present application can further include: S501, receiving input base station configuration information.

[0061] The base station configuration information includes the base station identifier and the identity of the network cell covered by the base station corresponding to the base station identifier.

[0062] S502, generating a second target data record according to the base station configuration information.

[0063] The network management server generates a second target data record in the form of <gNB ID, NR-CI> according to the received base station configuration information, and stores it locally. This provides data support for subsequent retrieval of the corresponding base station according to the identity of the network cell currently accessed by the terminal device.

[0064] In another embodiment, after receiving the subscription data update success confirmation information fed back from the NEF network element, a data notification can be sent to the terminal device, and the data notification includes a source IP address and a target network identifier. The data notification is used to instruct the terminal device to initiate a session creation request according to the identity of the public land mobile network (PLMN) of the terminal device currently accessed base station and the target network identifier.

[0065] When the network management server receives the subscription data update success confirmation information fed back by the NEF network element, it indicates that the terminal device has successfully joined the target virtual network group. At this time, the network management server sends a data notification to the terminal device, and the notification contains the source IP address and the target network identifier (NID). After receiving the data notification, the terminal device initiates a PDU session creation request by taking the PLMN ID of the currently accessed base station and the target network identifier (NID) as the DNN. Through the creation of the session, the terminal device can perform data transmission by means of the corresponding PDU session, thereby realizing communication with other devices in the virtual network group.

[0066] After the terminal device creates the PDU session, it updates the local packet classifier by taking the IP obtained in the step as an index, wherein the PDU Session ID in the packet classifier is the identifier of the created PDU session. When the terminal device receives a data packet from the lower-layer industrial Ethernet device, it reads the source MAC address in the data packet and searches the local packet classifier by taking the source MAC address as an index. If there is a matching record, the terminal device sends the received data packet by means of the corresponding PDU Session ID in the matching record, thereby ensuring accurate transmission of data.

[0067] The application further provides a virtual network group management method of an industrial Ethernet device, applied to a terminal device in an industrial network, Figure 7 A flowchart of the virtual network group management method of the industrial Ethernet device provided by the embodiment of the application is shown in Figure 6, Figure 7 as shown in the figure, the method comprises the following steps. S601, listening to data packets from a lower-layer industrial Ethernet device.

[0068] The terminal device monitors data packets sent by the lower-layer industrial Ethernet device in real time. The data packets contain communication information of the industrial Ethernet device and are the basis for the terminal device to obtain the network identifier of the device. For example, service data frames sent by industrial PLCs, sensors and other devices to the terminal device are all captured by the listening module of the terminal device.

[0069] S602, updating a local packet classifier according to a source IP address and a source MAC address in the data packet.

[0070] The terminal device extracts the source IP address (IP address of the industrial Ethernet device) and the source MAC address (physical address of the industrial Ethernet device) from the captured data packet, and updates the corresponding record in the local packet classifier by using the extracted source IP address and source MAC address, thereby ensuring that the packet classifier can accurately associate the network address of the device with the subsequent session identifier. The data record comprises: the source IP address and the identity identifier of the current access network cell of the terminal device; the source IP address is used for the IP address of the industrial Ethernet device.

[0071] S603, report the data record and the subscription permanent identifier SUPI of the terminal device to the network management server.

[0072] Finally, the data record and the subscription permanent identifier SUPI of the terminal device are reported to the network management server, so that the network management server determines the target network identifier supported by the terminal device according to the source IP address, and determines the target base station corresponding to the terminal device according to the identity of the current access network cell, configures the target base station with a virtual network, so that the target base station supports the target network identifier, and after the target base station configuration is successful, sends a subscription data update request to the user data management unit UDM through the network exposure function NEF network element according to the SUPI of the terminal device, so that the UDM adds the SUPI to the target virtual network group corresponding to the virtual network group identifier where the terminal device is located. The target network identifier is used to indicate the identifier of the data network corresponding to the virtual network group identifier.

[0073] Figure 8 The seventh flowchart of the virtual network group management method of the industrial Ethernet device provided by the embodiment of the application is shown in FIG. 7. Figure 8 As shown in the figure, the method of the application further comprises: S701, receiving a data notification sent by the network management server.

[0074] The data notification is a notification message sent by the network management server after receiving the subscription data update success confirmation information fed back from the NEF. The data notification is a notification message sent by the network management server after receiving the subscription data update success confirmation information fed back from the NEF, which is in the form of <IP, NID>, wherein IP is the source IP address of the industrial Ethernet device, and NID is the target network identifier. The data notification is an instruction sent by the network management server after confirming that the terminal device has successfully joined the target virtual network group, and contains the key network identifier information required for the terminal device to create a session.

[0075] S702, according to the identifier of the public land mobile network PLMN of the terminal device currently accessing the base station and the target network identifier, initiating a session creation request to create a session for the data network corresponding to the virtual network group.

[0076] The terminal device extracts the PLMN ID (public land mobile network identifier) of the currently accessed base station, and combines the NID in the data notification to form a DNN (Data Network Name), i.e. PLMN ID+NID. With the DNN as a parameter, a PDU session creation request is initiated to establish a communication link between the terminal device and the data network corresponding to the target virtual network group, supporting data flow transmission of the industrial Ethernet device in the group.

[0077] After successfully creating the PDU session, the terminal device obtains the identifier PDU Session ID of the session, takes the source IP address as an index, finds the corresponding record in the local packet classifier, updates the PDU Session ID in the record to the newly created session identifier, updates the session identifier in the local packet classifier to the identifier of the created session, realizes the binding of the industrial Ethernet device and the session, and ensures that subsequent data can be transmitted through the correct session.

[0078] Figure 9 As shown in the eighth flowchart of the virtual network group management method of the industrial Ethernet device provided by the embodiments of the present application, Figure 9 the method further includes: S801, receiving a target data packet sent by an industrial Ethernet device.

[0079] The terminal device continuously receives service data sent by the associated industrial Ethernet device, and the data packets may be industrial control instructions, sensor collected data, etc., which need to be transmitted through the corresponding virtual network group.

[0080] S802, reading a source MAC address from the target data packet.

[0081] The source MAC address is the unique physical identifier of the industrial Ethernet device, and the terminal device can locate the corresponding transmission session by extracting the address.

[0082] S803, taking the source MAC address as an index, searching the local packet classifier to obtain a target session identifier, and sending the target data packet using the target session identifier.

[0083] The terminal device searches the local packet classifier for a record matching the source MAC address, obtains the corresponding PDU Session ID (target session identifier) from the record, sends the target data packet to other devices or industrial servers in the target virtual network group through the session corresponding to the PDU Session ID, realizes direct data interaction among the devices in the group, and ensures that devices in different VLANs are isolated from each other through their respective sessions.

[0084] The above-mentioned method embodiments on the terminal device side realize the automatic management of the access of industrial Ethernet devices to virtual network groups through the steps of listening to device data, dynamically updating the packet classifier, reporting key information, responding to session creation instructions, and accurately forwarding data, in cooperation with the collaborative operation of the network management server. In particular, the problems of single terminal unable to support multiple VLAN device access and manual configuration being complicated in the prior art are solved, and the flexibility and deployment efficiency of the industrial network are improved.

[0085] The device, the equipment and the storage medium for implementing the virtual network group management method of the industrial Ethernet device are explained as follows, and the specific implementation process and the technical effects are the same as those of the corresponding method embodiments. For brief description, the parts not mentioned in the following embodiments can be referred to the corresponding contents in the method embodiments.

[0086] Figure 10 The device for managing the virtual network group of the industrial Ethernet device provided by the embodiments of the present application is applied to a network management server in an industrial network, and the device comprises: The receiving module 10 is configured to receive a data record reported by a terminal device and a subscription permanent identifier (SUPI) of the terminal device, wherein the data record comprises a source IP address and an identity of a current access network cell of the terminal device, and the source IP address is an IP address of an industrial Ethernet device connected to the terminal device.

[0087] The first determining module 20 is configured to determine a target network identifier supported by the terminal device according to the source IP address, wherein the target network identifier is used to indicate an identity of a data network corresponding to a virtual network group identifier where the terminal device is located.

[0088] The second determining module 30 is configured to determine a target base station corresponding to the terminal device according to the identity of the current access network cell.

[0089] The configuration module 40 is configured to perform virtual network configuration on the target base station, so that the target base station supports the target network identifier.

[0090] The sending module 50 is configured to, if the target base station is configured successfully, send a subscription data update request to a user data management unit (UDM) through a network exposure function (NEF) network element according to the SUPI of the terminal device, so that the UDM adds the SUPI to a target virtual network group corresponding to a virtual network group identifier where the terminal device is located.

[0091] Figure 11 The device for managing the virtual network group of the industrial Ethernet device provided by the embodiments of the present application is applied to a network management server in an industrial network, and the device comprises: The listening module 60 is configured to listen to a data packet from an industrial Ethernet device connected below.

[0092] The updating module 70 is configured to update a local packet classifier according to a source IP address and a source MAC address in the data packet; wherein the data record comprises a source IP address and an identity of a current access network cell of the terminal device, and the source IP address is used as an IP address of the industrial Ethernet device.

[0093] The reporting module 80 is configured to report the data record and a subscription permanent identifier SUPI of the terminal device to a network management server, so that the network management server determines a target network identifier supported by the terminal device according to the source IP address, determines a target base station corresponding to the terminal device according to an identity of the current access network cell, performs virtual network configuration on the target base station, so that the target base station supports the target network identifier, and after successful configuration of the target base station, sends a subscription data update request to a user data management unit UDM through a network exposure function NEF network element according to the SUPI of the terminal device, so that the UDM adds the SUPI to a target virtual network group corresponding to a virtual network group identity where the terminal device is located. The target network identifier is used to indicate an identity of a data network corresponding to the virtual network group identity.

[0094] The apparatus is configured to perform the method provided by the foregoing embodiments, and has similar implementation principles and technical effects, which will not be described here.

[0095] The above modules can be one or more integrated circuits configured to implement the above method, for example, one or more application specific integrated circuits (ASICs), or one or more microprocessors, or one or more field programmable gate arrays (FPGAs), etc. For another example, when a certain module above is implemented in the form of a processing element scheduling program code, the processing element can be a general-purpose processor, for example, a central processing unit (CPU) or other processor that can invoke program code. For another example, the modules can be integrated together to be implemented in the form of a system on a chip (SOC).

[0096] Figure 12 A schematic diagram of a network management server provided by an embodiment of the present application is shown in FIG. 1. As shown in the figure, the network management server includes a processor 100, a storage medium 200, and a bus 300. Figure 11

[0097] The storage medium 200 stores a computer program executable by the processor 100. When the server is running, the processor 100 and the storage medium 200 communicate through the bus 300, and the processor 100 executes the computer program to perform the steps of the above method embodiments. The specific implementation manners and technical effects are similar, which will not be described here.

[0098] ​Optionally, the present application also provides a storage medium, and the storage medium stores the computer program, and the computer program is run by the processor to execute the steps of the method embodiments. The specific implementation and technical effects are similar, and will not be repeated here.

[0099] In several embodiments provided in the present application, it should be understood that the disclosed apparatus and method can be implemented in other manners. For example, the described apparatus embodiments are merely schematic. The division of the units is merely a logical function division. There can be another division manner for the actual implementation, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections can be indirect couplings or communication connections through some interfaces, devices or units, and can be electrical, mechanical or other forms.

[0100] The units described as separate components can or can not be physically separate, and the components displayed as units can or can not be physical units, that is, can be located in one place, or can be distributed on multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the embodiment scheme.

[0101] In addition, each functional unit in the various embodiments of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware, or in the form of hardware plus software functional units.

[0102] The integrated unit realized in the form of software functional units can be stored in a computer readable storage medium. The software functional units stored in the storage medium include a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor (English: processor) to execute part of the steps of the method described in the various embodiments of the present application. The foregoing storage medium includes a U disk, a mobile hard disk, a read-only memory (English: Read-Only Memory, abbreviated as: ROM), a random access memory (English: Random Access Memory, abbreviated as: RAM), a magnetic disk or an optical disk, and various program code storage media.

[0103] The above merely provides the specific implementation of the present application, but the protection scope of the present application is not limited to this. Any person skilled in the art can easily think of the changes or replacements within the technical range disclosed by the present application, which should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method for managing virtual network groups in an industrial Ethernet device, characterized in that, The method, applied to a network management server in an industrial network, includes: The terminal device receives data records reported by the terminal device and the terminal device's subscription permanent identifier (SUPI), wherein the data records include: the source IP address and the identity identifier of the current access network cell of the terminal device; the source IP address is the IP address of the industrial Ethernet device connected to the terminal device. Based on the source IP address, the target network identifier supported by the terminal device is determined, wherein the target network identifier is used to indicate the identifier of the data network corresponding to the virtual network group identifier in which the terminal device is located; Based on the identity identifier of the currently accessed network cell, the target base station corresponding to the terminal device is determined; The target base station is configured with a virtual network so that it supports the target network identifier; If the target base station is successfully configured, based on the SUPI of the terminal device, a subscription data update request is sent to the User Data Management Unit (UDM) through the Network Open Function (NEF) network element, so that the UDM adds the SUPI to the target virtual network group corresponding to the virtual network group identifier where the terminal device is located.

2. The method according to claim 1, characterized in that, The step of determining the target network identifier supported by the terminal device based on the source IP address includes: Using the source IP address as an index, a search is performed in the local data records to obtain a first target data record that matches the source IP address; wherein, the target data record further includes: the virtual network group identifier and the target network identifier; Obtain the target network identifier from the first target data record.

3. The method according to claim 2, characterized in that, Before retrieving the first target data record matching the source IP address by using the source IP address as an index in the local data records, the method further includes: The system receives network configuration information from the industrial Ethernet device, which includes the IP address of the industrial Ethernet device and the virtual network group identifier. The first target data record is generated based on the network configuration information and the identifier of the data network corresponding to the virtual network group identifier.

4. The method according to claim 1, characterized in that, The step of determining the target base station corresponding to the terminal device based on the identity identifier of the currently accessed network cell includes: Using the identity identifier of the currently accessed network cell as an index, local data records are retrieved to obtain a second target data record that matches the identity identifier; the second target data record includes: the base station identifier corresponding to the identity identifier; The base station corresponding to the base station identifier is identified as the target base station.

5. The method according to claim 4, characterized in that, Before retrieving local data records using the identity identifier of the currently accessed network cell as an index to obtain a second target data record matching the identity identifier, the method further includes: The system receives input base station configuration information, which includes: the base station identifier and the identifier of the network cell covered by the base station corresponding to the base station identifier; The second target data record is generated based on the base station configuration information.

6. The method according to claim 1, characterized in that, The method further includes: After receiving the confirmation information of successful subscription data update from the NEF network element, a data notification is sent to the terminal device. The data notification includes the source IP address and the target network identifier. The data notification is used to instruct the terminal device to initiate a session creation request based on the identifier of the Public Land Mobile Network (PLMN) of the base station currently accessed by the terminal device and the target network identifier.

7. A method for managing virtual network groups in an industrial Ethernet device, characterized in that, The method, applied to terminal devices in industrial networks, includes: Listen for data packets from downstream industrial Ethernet devices; The local packet classifier is updated based on the source IP address and source MAC address in the data packet; The terminal device reports data records and its Subscription Permanent Identifier (SUPI) to the network management server. This allows the network management server to determine the target network identifier supported by the terminal device based on the source IP address, and to determine the target base station corresponding to the terminal device based on the identity identifier of the currently accessed network cell. The server then performs virtual network configuration on the target base station to ensure it supports the target network identifier. After successful configuration, the terminal device sends a subscription data update request to the User Data Management Unit (UDM) via the Network Open Function (NEF) element, based on the SUPI. This causes the UDM to add the SUPI to the target virtual network group corresponding to the virtual network group identifier of the terminal device. The target network identifier indicates the identifier of the data network corresponding to the virtual network group identifier. The data record includes the source IP address and the identity identifier of the currently accessed network cell of the terminal device. The source IP address is the IP address of the industrial Ethernet device.

8. The method according to claim 7, characterized in that, The method further includes: The network management server receives a data notification, which is a notification message sent by the network management server after receiving confirmation information of successful subscription data update from the NEF. The data notification includes the source IP address and the target network identifier. Based on the identifier of the Public Land Mobile Network (PLMN) of the base station currently accessed by the terminal device and the identifier of the target network, a session creation request is initiated to create a session for the data network corresponding to the virtual network group.

9. The method according to claim 8, characterized in that, The method further includes: The local packet classifier is updated based on the identifier of the created session and the source IP address, so that the session identifier in the local packet classifier is updated to the identifier of the created session.

10. The method according to claim 9, characterized in that, The method further includes: Receive the target data packet sent from the industrial Ethernet device; Read the source MAC address from the target data packet; Using the source MAC address as an index, the local packet classifier is retrieved to obtain the target session identifier, and the target data packet is sent using the target session identifier.