Five-prevention management machine authorization communication method and system based on cellular network

By adopting an authorized communication method for the five-proof management unit based on cellular networks, utilizing localized identity authentication and session key negotiation at the edge management node, and combining multi-access edge computing and network slicing isolation, the problem of quickly completing the issuance, confirmation, and execution of device commands in five-proof application scenarios is solved, achieving low-latency and highly reliable communication.

CN121013076AActive Publication Date: 2025-11-25DONGGUAN HUAFUU IND CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202511283280.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-09
Publication Date
2025-11-25
Estimated Expiration
2045-09-09

AI Technical Summary

Technical Problem

In five-proof application scenarios, existing technologies are unable to complete the issuance, confirmation and execution of equipment commands in a very short time, which increases the risk of misoperation or the spread of faults.

Method used

The five-proof management unit authorization communication method based on cellular network is adopted. By localizing identity authentication and session key negotiation at the edge management node and combining multi-access edge computing technology, the authentication latency is reduced. End-to-end network slicing isolation and dynamic slicing routing mechanism are adopted to ensure the reliability and availability of communication.

Benefits of technology

It significantly reduces authentication latency, meets the requirement of completing instruction issuance, confirmation and execution within tens of milliseconds, enhances network reliability and robustness, and reduces instruction loss or timeout issues caused by sudden network jitter or link interruption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121013076A_ABST
    Figure CN121013076A_ABST
Patent Text Reader

Abstract

The invention relates to the field of Internet security services, in particular to a five-prevention management machine authorization communication method and system based on a cellular network. According to the five-prevention management machine authorization communication method provided by the invention, when pass permits of an operation and maintenance terminal and a five-prevention management terminal are both in a valid period, the method comprises the following rules: the operation and maintenance terminal generates an operation instruction, encrypts the operation instruction based on a first secret key, and generates a first encryption instruction; the operation and maintenance terminal selects a cellular network slice and transmits the first encryption instruction to the five-prevention management terminal by using the cellular network slice; the five-prevention management terminal decrypts the first encryption instruction based on the second first key to obtain an operation instruction, and controls the equipment terminal according to the operation instruction; the five-prevention management terminal generates a first feedback instruction after the operation is completed, and encrypts the first feedback instruction based on the second first key to obtain a second encryption instruction; and the five-prevention management terminal selects a cellular network slice and transmits the second encryption instruction to the operation and maintenance terminal by using the cellular network slice.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of Internet security services, and in particular to an authorized communication method and system for a five-prevention management unit based on a cellular network. Background Technology

[0002] In five-prevention application scenarios, such as power distribution rooms, prefabricated substations, or outdoor switching stations, once an equipment abnormality is detected or maintenance personnel issue an emergency switching command, the system must complete the issuance, confirmation, and execution of the command within an extremely short time window—usually within tens of milliseconds—to effectively protect personnel safety and power grid equipment from the impact of misoperation or the spread of faults. Summary of the Invention

[0003] In a first aspect, the present invention provides an authorized communication method for a five-proof management device based on a cellular network, comprising the following steps:

[0004] An operation and maintenance terminal sends a first authentication request to a first edge management node, and the first edge management node issues a first access pass and a first key to the operation and maintenance terminal based on the first authentication request;

[0005] The five-proof management terminal sends a second authentication request to the second edge management node, and the second edge management node issues a second access pass and a second key to the five-proof management terminal based on the second authentication request;

[0006] When both the first access pass and the second access pass are valid, the operation and maintenance terminal and the five-prevention management terminal communicate according to the following rules:

[0007] The operation and maintenance terminal generates an operation command and encrypts the operation command based on the first key to generate a first encrypted command;

[0008] The operation and maintenance terminal selects a cellular network slice and uses this cellular network slice to transmit the first encryption command to the five-proof management terminal;

[0009] The five-prevention management terminal decrypts the first encrypted instruction based on the second key to obtain the operation instruction, and controls the device terminal according to the operation instruction;

[0010] After the operation is completed, the five-prevention management terminal generates a first feedback instruction and encrypts the first feedback instruction based on the second key to obtain a second encrypted instruction;

[0011] The five-prevention management terminal selects a cellular network slice and uses this cellular network slice to transmit the second encryption command to the operation and maintenance terminal.

[0012] In some examples, the cellular network-based five-prevention management device authorized communication method further includes the following steps:

[0013] The maintenance terminal periodically checks the validity period of the first short-term token. When the validity period of the first short-term token is less than a preset first validity period threshold, a handshake is triggered between the maintenance terminal and an edge management node. During the handshake process:

[0014] The operation and maintenance terminal provides the first device information to the edge management node. The edge management node verifies the first device information based on the stored first device certificate and sends the first and second short-term tokens and the first and second keys to the operation and maintenance terminal after successful verification. At the same time, it sends the second key that matches the first and second keys to the five-proof management terminal.

[0015] In some examples, the cellular network-based five-prevention management device authorized communication method further includes the following steps:

[0016] The five-proof management terminal periodically checks the validity period of the second short-term token. When the validity period of the second short-term token is less than a preset second validity period threshold, a handshake is triggered between the five-proof management terminal and an edge management node. During the handshake process:

[0017] The five-proof management terminal provides the second device information to the edge management node. The edge management node verifies the second device information based on the stored second device certificate and sends a second short-term token and a second key to the operation and maintenance terminal after successful verification. At the same time, it sends a first key that matches the second key to the operation and maintenance terminal.

[0018] In some examples, the cellular network-based five-prevention management device authorized communication method is characterized by further including the following steps:

[0019] The operation and maintenance terminal has a preset feedback time limit. If no feedback instruction is received within the feedback time limit for an operation instruction of this operation and maintenance terminal, the encrypted first instruction will be transmitted to the corresponding five-proof management machine again using the same cellular network slice.

[0020] In some examples, the cellular network-based five-prevention management device authorized communication method is characterized by further including the following steps:

[0021] The maintenance terminal has a preset number of retransmissions for a cellular network slice. If no corresponding feedback instruction is received within the preset number of retransmissions for an operation command of this maintenance terminal through the same cellular network slice, then the cellular network slice is switched.

[0022] In some examples, in the cellular network-based five-prevention management machine authorized communication method, the first key and the second key are stacked key pairs.

[0023] In some examples, the selection of cellular network slices between an operation and maintenance terminal and a five-defense management terminal in the cellular network-based authorized communication method for the five-defense management terminal includes the following steps:

[0024] The cellular network slice management module acquires candidate cellular network slices between the operation and maintenance terminal and the five-proof management terminal;

[0025] The Cellular Slice Manager obtains the communication utility of each candidate cellular network slice based on the QoS metrics of each candidate cellular network slice;

[0026] The Cellular Slice Manager binds the candidate cellular slices with the highest communication efficiency to the corresponding operation and maintenance terminal and the five-proof management terminal.

[0027] In some examples, the QoS metrics in the cellular network-based five-defense management unit authorized communication method include packet loss rate and latency.

[0028] In some examples, in the cellular network-based five-defense management machine authorized communication method, the communication utility of the cellular network slice is a weighted value of packet loss rate and latency.

[0029] Secondly, based on the cellular network-based authorized communication method for the five-proof management device provided in the first aspect, the present invention also provides a cellular network-based authorized communication system for the five-proof management device, including an operation and maintenance terminal, a five-proof management terminal, and an edge management node. The cellular network-based authorized communication system for the five-proof management device achieves communication through the cellular network-based authorized communication method for the five-proof management device provided in the first aspect.

[0030] The five-proof management machine authorization communication method and system based on cellular networks provided by this invention have benefits including, but not limited to, the following:

[0031] This invention pushes the identity authentication and session key negotiation process down to the edge management node on the link access side. Combined with localized multi-access edge computing technology, it can significantly reduce the round-trip authentication latency from tens or even hundreds of milliseconds to the order of milliseconds, fully meeting the stringent requirement of "completing command issuance, confirmation and execution within tens of milliseconds" in five-proof scenarios.

[0032] Furthermore, this invention employs an end-to-end network slice isolation and dynamic slice routing mechanism. The system can monitor QoS indicators such as latency, packet loss rate, jitter, and bandwidth of multiple slices in real time, and automatically select the optimal slice based on a weighted utility function. This not only significantly enhances the reliability and availability of the network, but also effectively reduces the problem of instruction loss or timeout caused by sudden network jitter or link interruption.

[0033] Furthermore, compared to traditional centralized authentication schemes, this invention minimizes handshake overhead by employing measures such as two-way lightweight handshake, short-term token pre-authorization caching, key double-buffered updates, and feedback timeout / retransmission management, while ensuring forward security and resistance to replay attacks. At the same time, it can automatically trigger slice switching or alarm mechanisms when retransmission fails or there is no feedback for a long time, which further enhances the robustness of the system. Attached Figure Description

[0034] Figure 1 A logical diagram illustrating the authorized communication method for a cellular network-based five-proof management device provided as an example of the present invention; and

[0035] Figure 2 The flowchart illustrates the cellular network slice selection process in the five-prevention management unit authorization communication method based on cellular networks provided as an example of the present invention. Detailed Implementation

[0036] In the following description, specific details such as particular systems, structures, and techniques are set forth for illustrative purposes rather than limiting, in order to provide a thorough understanding of the examples in this application. Those skilled in the art will understand that this application can also be implemented in other examples without these specific details.

[0037] In the description of this application, detailed descriptions of well-known systems, apparatuses, circuits, and methods have been omitted to avoid unnecessary detail from obscuring the description. Furthermore, it should be noted that terms such as "first" and "second" are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0038] With the advancement of fifth-generation cellular network technology, the widespread deployment of the Industrial Internet of Things (IIoT) in critical infrastructure sectors such as power, petrochemicals, and rail transit is becoming a trend. Especially in power substations and distribution networks, in order to prevent operational risks of "secondary equipment" such as misoperation, accidental switching, accidental closing, and accidental entry into dead zones, more and more power grid companies are building five-prevention management systems for remote monitoring and control of various switches, circuit breakers, and other terminal equipment.

[0039] In the five-prevention application scenario, once an equipment abnormality is detected or maintenance personnel issue an emergency switching command, the system must complete the issuance, confirmation and execution of the command within a very short time window to effectively protect personnel safety and power grid equipment from the impact of misoperation or the spread of faults.

[0040] Based on a five-proof application scenario, which includes an operation and maintenance terminal and a device terminal controlled by the five-proof management terminal, one example of the present invention provides, as follows: Figure 1 The authorized communication method for the five-proof management unit based on cellular networks, as shown, includes the following steps:

[0041] S01. An operation and maintenance terminal sends a first authentication request to a first edge management node. Based on the first authentication request, the first edge management node issues a first access pass and a first key to the operation and maintenance terminal.

[0042] It should be noted that the operation and maintenance terminal mentioned in this invention refers to an intelligent terminal device deployed at the power operation and maintenance site, used to send control commands to the five-prevention management terminal and receive its feedback.

[0043] Typically, the maintenance terminal described in this invention is primarily aimed at maintenance personnel and appears in the form of smartphones, tablets, or industrial portable terminals. It is responsible for receiving personnel instructions, generating and encrypting instructions, and sending them to the network. Its software focuses on human-computer interaction and feedback management.

[0044] Furthermore, the five-prevention management terminal described in this invention refers to a dedicated intelligent control device deployed at the site of power facilities, used to receive encrypted control commands issued by the operation and maintenance terminal and perform corresponding operations on the controlled equipment, while generating and returning encrypted feedback messages.

[0045] Typically, the five-prevention management terminal described in this invention is fixedly deployed in a power distribution room, prefabricated substation, or outdoor switching station. It has a built-in programmable logic controller or intelligent RTU and is directly connected to power equipment such as circuit breakers and disconnectors. It is responsible for accurately driving the decrypted control commands and generating encrypted feedback messages. Its hardware focuses on rich digital / analog input / output interfaces and secure storage modules to ensure reliable execution and status reporting of the controlled equipment.

[0046] It should also be noted that the edge management node described in this invention refers to a localized network security and management entity deployed on the cellular access network side. It is usually set up on the MEC node or micro data center on the cellular network base station side to realize functions such as secure handshake between the operation and maintenance terminal and the five-proof management terminal, issuance and updating of access tokens and session keys.

[0047] In this example, both the first edge management node and the second edge management node are the aforementioned edge management nodes, meaning their "node type" and "functional module" are the same, but the terminal roles they serve are different, and their geographical and logical locations may also be different.

[0048] Specifically, within the same geographical or logical region, if both the operation and maintenance terminal and the five-proof management terminal are connected to the same cellular network base station side multi-access edge computing (MEC) or micro data center (i.e., the edge management node described in this invention), then the first edge management node and the second edge management node can actually be the same device or logical entity. Furthermore, when the two types of terminals belong to different regions or are deployed on different edge management nodes due to load isolation or security isolation requirements, the first edge management node and the second edge management node are two edge management nodes that do not overlap physically or logically.

[0049] It is understood that the authentication request described in this invention, including the first authentication request in step S01 and the second authentication request in step S02, are both security handshake request messages initiated by the terminal (operation and maintenance terminal or five-proof management terminal). These messages do not carry any business load and are only used to complete identity verification and negotiation of credentials and session keys with the edge management node.

[0050] Specifically, when an edge management node receives such an authentication request, it performs certificate verification based on the terminal identifier and credential information carried in the message, generates a short-term pass and a session key based on the preset root key or long-term key, and then encapsulates and sends them to the requesting terminal, thereby completing an end-to-end security handshake and key negotiation process.

[0051] It should be noted that in some embodiments, the remote operation and maintenance terminal and the local five-proof management terminal establish handshakes with edge management nodes located in different geographical locations respectively; furthermore, multiple edge management nodes in different geographical locations need to form a federated authorization management cluster through a secure interconnection mechanism such as a dedicated control plane or VPN tunnel.

[0052] Specifically, when a remote maintenance terminal initiates a first authentication request to its corresponding first edge management node and completes a handshake, the short-term pass and session key generated by the first edge management node will be synchronously copied or distributed to all other edge management nodes in the cluster. Similarly, when a five-proof management terminal initiates a second authentication request to a second edge management node, the issued pass and session key will be synchronously consistent with those of the first edge management node.

[0053] Understandably, regardless of which node the maintenance terminal uses to complete the handshake, or which node the five-proof management terminal uses to complete the handshake, both parties can obtain the same pair of session keys generated by the latest handshake behavior, thereby ensuring that encryption and decryption always match.

[0054] Compared to centralizing all authentication, authorization, and session key negotiation functions in the core network or cloud data center, the local deployment of edge management nodes can significantly reduce authentication round-trip latency. At the same time, local processing greatly saves the use of core network bandwidth and computing resources, and can further enhance the security isolation and on-site controllability of the five-defense services.

[0055] S02. The five-proof management terminal sends a second authentication request to the second edge management node. Based on the second authentication request, the second edge management node issues a second access pass and a second key to the five-proof management terminal.

[0056] S03. When both the first access pass and the second access pass are valid, the maintenance terminal and the five-prevention management terminal communicate according to the following rules:

[0057] S031. The operation and maintenance terminal generates an operation instruction and encrypts the operation instruction based on the first key to generate a first encrypted instruction.

[0058] S032. The operation and maintenance terminal selects a cellular network slice and uses this cellular network slice to transmit the first encryption command to the five-proof management terminal.

[0059] S033. The five-prevention management terminal decrypts the first encryption instruction based on the second key to obtain the operation instruction, and controls the device terminal according to the operation instruction.

[0060] S034. After the operation is completed, the five-prevention management terminal generates a first feedback instruction and encrypts the first feedback instruction based on the second key to obtain a second encrypted instruction.

[0061] S035. The five-prevention management terminal selects a cellular network slice and uses this cellular network slice to transmit the second encryption command to the operation and maintenance terminal.

[0062] It should be noted that the passes issued from any edge management node to the terminal (operation and maintenance terminal or five-proof management terminal) in this invention, such as the first pass and the second pass mentioned above, are all short-term credentials; therefore, the passes of any terminal (operation and maintenance terminal or five-proof management terminal) need to be verified and updated regularly.

[0063] To achieve efficient verification, an example of this invention provides a lightweight handshake verification process between the operation and maintenance terminal and the edge management node, specifically including the following:

[0064] S011. The maintenance terminal periodically checks the validity period of the first short-term token. When the validity period of the first short-term token is less than a preset first validity period threshold, a handshake is triggered between the maintenance terminal and an edge management node. During the handshake process:

[0065] The maintenance terminal provides the first device information to the edge management node. The edge management node verifies the first device information based on the stored first device certificate and sends the first and second short-term tokens and the first and second keys to the maintenance terminal after successful verification. At the same time, it sends the second key that matches the first and second keys to the five-proof management terminal.

[0066] In this example, the first validity threshold is a key parameter used to determine when the first short-term token should be renewed in advance. It is a comparison benchmark between the remaining validity period of the first short-term token and a preset threshold. That is, when the remaining validity period of the first short-term token, obtained by subtracting the elapsed time from the total validity period since its issuance, is lower than the first validity threshold, a new round of lightweight handshake with the edge management node is triggered.

[0067] In some embodiments, the first time limit can be preset to a fixed time limit based on the maximum tolerable round-trip delay and safety margin of the five-proof scenario: for example, the threshold can be configured to 50ms for emergency switching instructions, or 200ms to 1s for regular queries.

[0068] In other embodiments, the first timeliness threshold can be based on the average round-trip time (RTT) of the most recent N token interactions at runtime. avg And latency jitter, according to formula T thr =α·(RTT) avg The +β·Jitter setting, where α is the safety factor and β is the jitter factor, can be determined according to the operation and maintenance strategy to balance the handshake success rate and immediacy.

[0069] In this example, based on the reasonable setting of the first time limit threshold, the operation and maintenance terminal can reasonably initiate the renewal before the token expires. This avoids unnecessary overhead caused by premature handshake and ensures that the key update is completed before the token expires, thus guaranteeing the continuity and security of subsequent control commands.

[0070] Similarly, to achieve efficient verification, an example of this invention provides a lightweight handshake verification process between the five-proof management terminal and the edge management node, specifically including the following:

[0071] S021. The five-proof management terminal periodically checks the validity period of the second short-term token. When the validity period of the second short-term token is less than the preset second validity period threshold, a handshake is triggered between the five-proof management terminal and an edge management node. During the handshake process:

[0072] The five-proof management terminal provides the second device information to the edge management node. The edge management node verifies the second device information based on the stored second device certificate and sends a second short-term token and a second key to the operation and maintenance terminal after successful verification. At the same time, it sends a first key that matches the second key to the operation and maintenance terminal.

[0073] The definition and setting of the second time-sensitive threshold in this example can be referred to the definition and setting of the first time-sensitive threshold in the example above, and will not be repeated here.

[0074] It should be noted that updating the pass of any terminal is accompanied by updating its key. In order to ensure that the encryption and decryption keys match, in any example, the key pair of any two communicating terminals is the latest key pair, that is, the key pair updated based on the latest handshake behavior.

[0075] Furthermore, in some embodiments, the key pairs used are symmetric key pairs, that is, the first key and the second key are stacked key pairs; the first second key and the second second key are stacked key pairs.

[0076] It should also be noted that each edge management node stores the device certificate of each operation and maintenance terminal or each five-proof management terminal in advance to support subsequent lightweight handshake verification.

[0077] To ensure the stability and efficiency of every communication between the maintenance terminal and the five-proof management terminal, the selection of cellular network slices for each maintenance terminal and the five-proof management terminal includes, for example: Figure 2 The cellular network slice selection process is shown below:

[0078] S001. The cellular network slice management module obtains candidate cellular network slices between the operation and maintenance terminal and the five-proof management terminal.

[0079] S002. The Cellular Network Slice Manager obtains the communication utility of each candidate cellular network slice based on the QoS indicators of each candidate cellular network slice.

[0080] Furthermore, in this example, the communication utility of any cellular network slice between maintenance terminal i and the five-defense management terminal j is determined by the packet loss rate and latency of this cellular network slice. In other examples, one or more other QoS indicators can be used to evaluate communication utility, such as latency jitter, available bandwidth, throughput, reliability, etc.

[0081] In one specific embodiment, the communication utility of a cellular network slice between maintenance terminal i and five-proof management terminal j is represented by the weighted value of packet loss rate and latency of this cellular network slice:

[0082] Among them, U i,j(s) represents the communication utility of cellular network slice s between maintenance terminal i and five-proof management terminal j, where ω1≥0 and ω2≥0 are weighting coefficients, and ω1+ω2=1, used to reflect the system's emphasis on "reliability" (reducing packet loss) and "timeliness" (reducing latency). This represents the packet loss rate in the direction from maintenance terminal i to the five-proof management terminal j. This represents the latency in the direction from maintenance terminal i to the five-prevention management terminal j.

[0083] Understandably, U i,j When (s) is large, it means that the communication quality of the slice between the maintenance terminal i and the five-prevention management terminal j is better; furthermore, in specific implementation scenarios, ω1 and ω2 can be dynamically adjusted according to different maintenance scenarios (for example, increase ω2 in extremely low latency scenarios and increase ω1 in high reliability scenarios to achieve the optimal decision of slice scheduling).

[0084] It is important to note that when selecting cellular network slices between any two terminals, a utility evaluation should be performed based on the QoS indicators of the communication direction between the two terminals. Specifically, for communication from terminal A to terminal B, a set of slices that meet the directional constraints should be dynamically selected based on the real-time end-to-end latency, component power, and other preset QoS requirements in the A→B direction, and the optimal slice should be determined accordingly. The same directional indicator collection and evaluation should be performed for the opposite direction, B→A, to ensure that both bidirectional communication can achieve the expected reliability and timeliness on their respective optimal slices. This avoids performance degradation caused by link asymmetry and guarantees the quality of service for peer-to-peer access and control between different terminals.

[0085] S003. The Cellular Network Slice Manager binds the candidate cellular network slice with the greatest communication efficiency to the corresponding operation and maintenance terminal and the five-proof management terminal.

[0086] Furthermore, based on the above-mentioned cellular network slice selection, in order to ensure optimal communication timeliness, the cellular network slice manager also periodically refreshes the utility evaluation results of each cellular network slice for different communication needs according to real-time sampled communication data, so as to update the optimal cellular network slice bound to different communication needs.

[0087] Based on the cellular network-based authorized communication method for the five-prevention management unit proposed in the above examples, in some embodiments, there may be situations where the feedback time is long or there is no feedback.

[0088] Based on the above, another example of the present invention provides a further communication process between the maintenance terminal and the five-proof management terminal:

[0089] The operation and maintenance terminal has a preset feedback time limit. If no feedback instruction is received within the feedback time limit for an operation instruction of this operation and maintenance terminal, the encrypted first instruction will be transmitted to the corresponding five-proof management machine again using the same cellular network slice.

[0090] Based on the above communication process, in one specific embodiment, before sending the first operation command, the operation and maintenance terminal statically configures or dynamically calculates a preset feedback time limit during system deployment or runtime, based on the maximum tolerable latency threshold of the selected cellular network slice and historical round-trip latency statistics, or according to the urgency of the command:

[0091] Furthermore, after the maintenance terminal sends the first operation command, it immediately starts the feedback timeout timer. If no verified feedback message is received from the five-prevention management terminal before the preset timeout expires, the maintenance terminal extracts the first operation command to be confirmed from the local command cache, updates the timestamp and random number in the command to prevent replay attacks, and still encrypts the updated command through the same cellular network slice as before and resends it.

[0092] Furthermore, in some embodiments, the retransmitted operation instructions still suffer from long feedback times or no feedback. In yet another example of the present invention, a further communication process between the maintenance terminal and the five-proof management terminal is provided:

[0093] The maintenance terminal has a preset number of retransmissions for a cellular network slice. If no corresponding feedback instruction is received within the preset number of retransmissions for an operation command of this maintenance terminal through the same cellular network slice, then the cellular network slice is switched.

[0094] Specifically, after sending the initial operation command, the maintenance terminal starts a feedback timeout timer. If no feedback is received each timeout, the terminal re-encrypts the command using the same slice and sends it again, while accumulating the retransmission count. If the retransmission count has not reached the preset maximum value and no feedback is received, the terminal continues to retransmit and restarts the timeout timer. When the retransmission count reaches the preset threshold and no corresponding feedback is received within the respective time limit, the maintenance terminal generates a cellular network slice switching signal, which includes the current cellular network slice identifier and necessary network quality indicators, and sends the switching signal to the cellular network slice manager.

[0095] Furthermore, after receiving the signal, the cellular network slice manager can re-select the slice candidate set based on the latest QoS monitoring results, and trigger a new cellular network slice binding or switching process through the cellular network slice selection function, so as to ensure the reliability and real-time performance of communication between the operation and maintenance terminal and the five-proof management terminal in the event of sudden changes in network conditions or long latency / no feedback scenarios.

[0096] In one example, to implement the above-mentioned five-proof management machine authorization communication method based on cellular network, a five-proof management machine authorization communication system based on cellular network is also provided.

[0097] The five-proof management terminal authorized communication system provided in this example includes the operation and maintenance terminal, the five-proof management terminal and the edge management node in the example above, as well as the cellular network communication base station that provides cellular network resources, and the cellular network slice manager that divides the cellular network resources into several logically isolated cellular network slices.

[0098] Specifically, after establishing a secure session, the operation and maintenance terminal and the five-proof management terminal establish bidirectional communication channels on the cellular communication network base station for the same slice through the slice identifier issued by the cellular network slice manager. The encrypted control command generated by the operation and maintenance terminal is transmitted to the five-proof management terminal after being carried by the cellular network slice. The encrypted feedback message generated by the five-proof management terminal is returned to the operation and maintenance terminal through the same or another cellular network slice. Thus, under the synergistic effect of local authentication and slice-based carrying, authorized communication of the five-proof management terminal with low latency, high reliability and end-to-end isolation capability is achieved.

[0099] In the examples above, the descriptions of each example have their own emphasis. For parts that are not described or recorded in detail in a certain example, please refer to the relevant descriptions in other examples.

[0100] It should be noted that the above examples can be freely combined as needed. The above are merely preferred embodiments of the present invention; it should be observed that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. A five-prevention management device authorized communication method based on cellular networks, characterized in that, Includes the following steps: An operation and maintenance terminal sends a first authentication request to a first edge management node, and the first edge management node issues a first access pass and a first key to the operation and maintenance terminal based on the first authentication request; The five-proof management terminal sends a second authentication request to the second edge management node, and the second edge management node issues a second access pass and a second key to the five-proof management terminal based on the second authentication request; When both the first access pass and the second access pass are valid, the operation and maintenance terminal and the five-prevention management terminal communicate according to the following rules: The operation and maintenance terminal generates an operation command and encrypts the operation command based on the first key to generate a first encrypted command; The operation and maintenance terminal selects a cellular network slice and uses this cellular network slice to transmit the first encryption command to the five-proof management terminal; The five-prevention management terminal decrypts the first encrypted instruction based on the second key to obtain the operation instruction, and controls the device terminal according to the operation instruction; After the operation is completed, the five-prevention management terminal generates a first feedback instruction and encrypts the first feedback instruction based on the second key to obtain a second encrypted instruction; The five-prevention management terminal selects a cellular network slice and uses this cellular network slice to transmit the second encryption command to the operation and maintenance terminal.

2. The authorized communication method for a five-prevention management device based on a cellular network according to claim 1, characterized in that, It also includes the following steps: The maintenance terminal periodically checks the validity period of the first short-term token. When the validity period of the first short-term token is less than a preset first validity period threshold, a handshake is triggered between the maintenance terminal and an edge management node. During the handshake process: The operation and maintenance terminal provides the first device information to the edge management node. The edge management node verifies the first device information based on the stored first device certificate and sends the first and second short-term tokens and the first and second keys to the operation and maintenance terminal after successful verification. At the same time, it sends the second key that matches the first and second keys to the five-proof management terminal.

3. The authorized communication method for a five-prevention management device based on a cellular network according to claim 1, characterized in that, It also includes the following steps: The five-proof management terminal periodically checks the validity period of the second short-term token. When the validity period of the second short-term token is less than a preset second validity period threshold, a handshake is triggered between the five-proof management terminal and an edge management node. During the handshake process: The five-proof management terminal provides the second device information to the edge management node. The edge management node verifies the second device information based on the stored second device certificate and sends a second short-term token and a second key to the operation and maintenance terminal after successful verification. At the same time, it sends a first key that matches the second key to the operation and maintenance terminal.

4. The authorized communication method for a five-prevention management device based on a cellular network according to claim 1, characterized in that, It also includes the following steps: The operation and maintenance terminal has a preset feedback time limit. If no feedback instruction is received within the feedback time limit for an operation instruction of this operation and maintenance terminal, the encrypted first instruction will be transmitted to the corresponding five-proof management machine again using the same cellular network slice.

5. The authorized communication method for a five-prevention management device based on a cellular network according to claim 1, characterized in that, It also includes the following steps: The maintenance terminal has a preset number of retransmissions for a cellular network slice. If no corresponding feedback instruction is received within the preset number of retransmissions for an operation command of this maintenance terminal through the same cellular network slice, then the cellular network slice is switched.

6. The authorized communication method for a five-prevention management device based on a cellular network according to any one of claims 1-5, characterized in that, The first key and the second key are stacked key pairs.

7. The authorized communication method for a five-prevention management device based on a cellular network according to any one of claims 1-5, characterized in that, The selection of cellular network slices for one maintenance terminal and one five-prevention management terminal includes the following steps: The cellular network slice management module acquires candidate cellular network slices between the operation and maintenance terminal and the five-proof management terminal; The Cellular Slice Manager obtains the communication utility of each candidate cellular network slice based on the QoS metrics of each candidate cellular network slice; The Cellular Slice Manager binds the candidate cellular slices with the highest communication efficiency to the corresponding operation and maintenance terminal and the five-proof management terminal.

8. The authorized communication method for a five-prevention management device based on a cellular network according to claim 7, characterized in that, The QoS metrics include packet loss rate and latency.

9. The authorized communication method for a five-prevention management device based on a cellular network according to claim 8, characterized in that, The communication utility of the cellular network slice is a weighted value of packet loss rate and latency.

10. A cellular network-based five-proof management terminal authorized communication system, comprising an operation and maintenance terminal, a five-proof management terminal, and an edge management node, characterized in that, Communication is achieved through the authorized communication method for the five-prevention management unit based on cellular networks as described in any one of claims 1-9.

Citation Information

Patent Citations

  • Direct communication authentication method, terminal, edge service node and network side equipment

    CN112954643A

  • End-to-end security guarantee method facing communication sensor network and edge server

    CN113630244A

  • Resource allocation method and device for network slices, storage medium and electronic equipment

    CN114666220A

  • Five-prevention management machine authorization communication method and device based on 4G cellular network

    CN115550923A