Equipment remote operation and maintenance method and system in private network environment
By pre-installing an eSIM card on the IoT router and establishing a channel with the device management platform, the private network parameters can be remotely configured, solving the problem of IoT private networks relying on local deployment, achieving zero-contact deployment, reducing costs and improving operation and maintenance efficiency.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SHENZHEN HONGDIAN TECH CORP
- Filing Date
- 2026-01-30
- Publication Date
- 2026-05-26
AI Technical Summary
IoT private networks rely on local on-site deployment, resulting in long deployment cycles and high labor costs.
The IoT router is pre-installed with an eSIM card, which automatically connects to the public network and establishes a management channel with the device management platform. Configuration parameters are remotely distributed, and an external physical SIM card is configured to access the private network and establish a business data channel, achieving zero-contact deployment.
Shorten project cycles, reduce labor costs, adapt to changing site environments, achieve comprehensive remote control, reduce on-site maintenance frequency, and improve equipment utilization.
Smart Images

Figure CN122093789A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of Internet of Things (IoT) technology, and in particular to a method and system for remote operation and maintenance of equipment in a private network environment. Background Technology
[0002] With the popularization of the Internet of Things (IoT) and the Industrial Internet, a large number of devices are deployed in remote fields (such as factories and the field), requiring remote operation and maintenance through private networks. Private networks usually refer to dedicated networks, also called private networks or industry-specific networks. They are communication networks tailored for specific organizations, enterprises, or industries, physically or logically isolated from the public Internet, and emphasize security, controllability, low latency, and high reliability.
[0003] IoT devices are typically deployed in dispersed, remote, or harsh environments. Before powering on the device, network parameters (especially private network APN parameters) must be pre-configured to connect to the network, or the device must be debugged by technicians on site. The initial network configuration after the device is powered on is highly dependent on local technicians, making it impossible to achieve remote, zero-contact deployment, resulting in long deployment cycles and high labor costs.
[0004] In the process of realizing this invention, the inventors discovered at least the following problems in the prior art: IoT private networks rely on local on-site deployment, which has a long deployment cycle and high labor costs. Summary of the Invention
[0005] The purpose of this invention is to provide a method and system for remote operation and maintenance of devices in a private network environment, so as to solve the technical problems of existing IoT private networks relying on local on-site deployment, which results in long deployment cycles and high labor costs. The various technical effects of the preferred technical solutions provided by this invention are detailed below.
[0006] To achieve the above objectives, the present invention provides the following technical solution: This invention provides a remote operation and maintenance method for devices in a private network environment, comprising the following steps: S100: An IoT router is pre-installed with an eSIM card, and automatically accesses the public network through the eSIM card after power-on, establishing a management channel with the device management platform; S200: The device management platform remotely sends configuration parameters to the IoT router through the management channel, the configuration parameters including APN parameters for accessing the private network; S300: Based on the received APN parameters, the IoT router configures an external physical SIM card and accesses the private network, establishing a service data channel with the service data center; S400: The IoT router receives management instructions through the management channel and transmits service data of the connected devices through the service data channel.
[0007] Preferably, in step S100, after the IoT router is powered on for the first time, it automatically connects to the public network through the eSIM card and the built-in default bootloader, registers with the device management platform, and establishes an initial management channel with the device management platform.
[0008] Preferably, in step S200, the IoT router is changed from a zero-configuration state to a fully service-ready state by remotely sending configuration parameters.
[0009] Preferably, in step S200, configuration parameters are automatically sent remotely to the IoT router.
[0010] Preferably, in step S200, the configuration parameters further include firewall rules and service routing policies.
[0011] Preferably, the management channel is used for monitoring and configuration command transmission of the device management platform, and the business data channel is used for business data flow between the downstream device and the business data center.
[0012] Preferably, the management channel and the business data channel work in parallel and are physically or logically separated.
[0013] Preferably, the device management platform provides an API interface, and the business data center integrates device management functions through the API interface.
[0014] A remote equipment operation and maintenance system for a private network environment, used to run the remote equipment operation and maintenance method for a private network environment as described above, includes an IoT router, an equipment management platform, and a service data center; the IoT router is pre-installed with an eSIM card that can connect to the equipment management platform and can receive remotely issued private network APN parameters to configure the external physical SIM card function for connecting to downstream service devices and accessing the network on-site; the equipment management platform is deployed in the cloud and communicates with the IoT router through a management channel established based on the eSIM, for issuing configuration parameters to the IoT router, monitoring the status of the router and the eSIM card, and providing an application programming interface (API); the service data center receives service data from the downstream service devices through the private network service data channel established by the IoT router based on the physical SIM card and the configuration parameters, and integrates the management of the eSIM card and the IoT router by calling the application programming interface (API) provided by the equipment management platform.
[0015] Preferably, the IoT router includes a first IoT router R1, a second IoT router R2, and a third IoT router R3. The first IoT router R1, the second IoT router R2, and the third IoT router R3 all access a private network base station via a private network and a public network base station via a public network.
[0016] Implementing one of the above-described technical solutions of the present invention has the following advantages or beneficial effects: In this invention, the IoT router can be used immediately upon plugging in, requiring no on-site technical personnel, achieving zero-contact deployment, greatly shortening project cycles, reducing labor costs, and is particularly suitable for large-scale, distributed IoT deployments. The IoT router can flexibly choose between eSIM (for public network management) or physical SIM (for private network services) according to the scenario requirements, adapting to changing site environments. Through remote configuration of device parameters, real-time status monitoring, and reliable transmission of business data, comprehensive remote control is achieved, reducing on-site maintenance frequency, improving equipment utilization, and ensuring manageable, adjustable, and controllable operation and maintenance processes. Attached Figure Description
[0017] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. In the drawings: Figure 1 This is a flowchart of a remote operation and maintenance method for equipment in a private network environment according to Embodiment 1 of the present invention; Figure 2 This is a schematic diagram of the structure of a remote equipment operation and maintenance system in a private network environment according to Embodiment 2 of the present invention. Detailed Implementation
[0018] To make the objectives, technical solutions, and advantages of the present invention clearer, various exemplary embodiments described below will be referenced to the accompanying drawings, which form part of the exemplary embodiments, illustrating various exemplary embodiments that may be used to implement the present invention. Unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this disclosure. It should be understood that they are merely examples of processes, methods, and apparatuses consistent with some aspects of the present invention disclosed as detailed in the appended claims, and other embodiments may be used, or structural and functional modifications may be made to the embodiments listed herein without departing from the scope and spirit of the present invention.
[0019] In the description of this invention, it should be understood that the terms "center," "longitudinal," "lateral," etc., indicate the orientation or positional relationship based on the accompanying drawings, and are only for the convenience of describing the invention and simplifying the description, and do not indicate or imply that the referred element must have a specific orientation, or be constructed and operated in a specific orientation. The terms "first," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. The term "multiple" means two or more. The terms "connected" and "linked" should be interpreted broadly, for example, they can be fixed connections, detachable connections, integral connections, mechanical connections, electrical connections, communication connections, direct connections, indirect connections through an intermediate medium, and can be the internal connection of two elements or the interaction relationship between two elements. The term "and / or" includes any and all combinations of one or more of the related listed items. Those skilled in the art can understand the specific meaning of the above terms in this invention according to the specific circumstances.
[0020] To illustrate the technical solution described in this invention, specific embodiments are described below, showing only the parts related to the embodiments of this invention.
[0021] Example 1: like Figure 1 As shown, this invention provides a remote operation and maintenance method for devices in a private network environment, including the following steps: S100: The IoT router is pre-installed with an eSIM card, and automatically accesses the public network through the eSIM card after power-on, establishing a management channel with the device management platform; S200: The device management platform remotely sends configuration parameters to the IoT router through the management channel, including APN parameters for accessing the private network; S300: Based on the received APN parameters, the IoT router configures the external physical SIM card and accesses the private network, establishing a business data channel with the business data center; S400: The IoT router receives management instructions through the management channel and transmits business data of the connected devices through the business data channel. In this invention, the IoT router can be used immediately upon plugging in, without the need for on-site technical personnel, achieving zero-contact deployment, greatly shortening the project cycle, reducing labor costs, and is particularly suitable for large-scale, distributed IoT deployments. The IoT router can flexibly choose between eSIM (for public network management) or physical SIM (for private network services) according to the needs of the scenario, adapting to changing on-site environments. By remotely configuring equipment parameters, monitoring status in real time, and transmitting business data reliably, comprehensive remote control is achieved, reducing the number of on-site maintenance operations, improving equipment utilization, and ensuring that the operation and maintenance process is manageable, adjustable, and controllable.
[0022] As an optional implementation, in step S100, after the IoT router is powered on for the first time, it automatically connects to the public network via the eSIM card and the built-in default bootloader (which can be implemented using existing technology). Automatic connection to the public network is the basis for IoT devices to realize remote management, data upload and cloud interaction, and register with the device management platform. It can also perform continuous operations such as authentication and IP acquisition, and establish an initial management channel with the device management platform, thereby establishing a stable communication channel between the IoT device and the public network.
[0023] As an optional implementation, in step S200, configuration parameters are remotely distributed to change the IoT router from a zero-configuration state to a fully service-ready state. This reduces on-site operations, simplifies operations, and facilitates remote maintenance. By automatically distributing configuration parameters to the IoT router remotely, manual on-site configuration is eliminated, reducing configuration difficulty and improving deployment efficiency. Configuration parameters also include firewall rules (such as allowing / denying traffic from a specific source IP to a destination IP, port restrictions, filtering based on protocol (TCP / UDP / ICMP), time, and application type), and service routing policies (such as selecting links based on source IP, destination IP, application, link quality, etc., to achieve multi-egress load balancing, priority for critical services, and automatic failover). Configuring both firewall rules and service routing policies allows for more flexible and adaptable configuration of the IoT router. Other configuration types can be added as needed.
[0024] As an optional implementation, the management channel is used for monitoring and configuration command transmission on the device management platform, serving as a dedicated communication path for operation and maintenance, monitoring, configuration, alarms, and upgrades. The business data channel is used for business data flow between downstream devices and the business data center, serving as a communication path for user data transmission, application interaction, and production control commands. The management channel and business data channel operate in parallel and are physically or logically separated, meaning that "operation and maintenance management traffic" and "user / production data traffic" are physically or logically isolated. This ensures that even if the business network is congested, malfunctions, or attacked, the management channel can still function normally, allowing operation and maintenance personnel to intervene in management under any circumstances, thus guaranteeing the maintainability and emergency response capabilities of the entire system. Simultaneously, the management channel is limited to use by the device management platform, while business data is transmitted through a dedicated network, providing dual protection for data security.
[0025] As an optional implementation, the device management platform provides an API interface, through which the business data center integrates device management functions. An API interface is a pre-agreed communication contract between systems or modules, allowing different programs to communicate and invoke services, thereby enabling the business data center to effectively manage devices.
[0026] The embodiment is merely a specific example and does not indicate that this is the only way to implement the present invention.
[0027] Example 2: A remote equipment operation and maintenance system in a private network environment, such as Figure 2 As shown, a remote operation and maintenance method for devices in a private network environment, as described in Embodiment 1, includes an IoT router, a device management platform, and a business data center. The IoT router is pre-installed with an eSIM card that can connect to the device management platform and can receive remotely sent private network APN parameters to configure the external physical SIM card function, enabling on-site connection to downstream business devices and network access. The device management platform is deployed in the cloud and communicates with the IoT router through a management channel established based on the eSIM. It sends configuration parameters to the IoT router, monitors the router and eSIM card status, and provides an application programming interface (API). The business data center receives business data from downstream business devices through a private network business data channel established by the IoT router based on the physical SIM card and configuration parameters. It integrates the management of the eSIM card and IoT router by calling the API provided by the device management platform, reducing human intervention. In this invention, the IoT router is ready to use upon plugging in, requiring no on-site technical personnel, achieving zero-contact deployment, greatly shortening the project cycle, reducing labor costs, and is particularly suitable for large-scale, distributed IoT deployments. IoT routers can flexibly choose between eSIM (for public network management) or physical SIM (for private network services) depending on the scenario requirements, adapting to diverse field environments. Through remote configuration of device parameters, real-time status monitoring, and reliable transmission of business data, comprehensive remote control is achieved, reducing the number of on-site maintenance operations, improving equipment utilization, and ensuring manageable, adjustable, and controllable operation and maintenance processes.
[0028] As an optional implementation method, such as Figure 2As shown, the IoT routers include a first IoT router R1, a second IoT router R2, and a third IoT router R3. All three routers access a dedicated network base station via a dedicated network and a public network base station via a public network. Specifically, each router is configured to access the dedicated network via a dedicated network configuration and the public network via a public network configuration. Dedicated network base stations do not rely on the public core network. They are base station devices in dedicated wireless communication networks independently deployed for specific industries, enterprises, or closed scenarios (such as factories, mines, ports, power plants, and rail transit). They are isolated from public mobile communication networks (public networks, such as the 5G networks of China Mobile / China Unicom / China Telecom) and feature high security, high reliability, low latency, and customizability. Public network base stations refer to base station facilities built and operated by telecommunications operators that provide wide-area wireless communication services to public users. They are wireless access nodes for mobile communication networks (2G / 3G / 4G / 5G) and are the core infrastructure for IoT devices to connect to the internet and communication services.
[0029] The above are merely preferred embodiments of the present invention. Those skilled in the art will understand that various changes or equivalent substitutions can be made to these features and embodiments without departing from the spirit and scope of the present invention. Furthermore, under the teachings of the present invention, these features and embodiments can be modified to adapt to specific situations and materials without departing from the spirit and scope of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed herein, and all embodiments falling within the scope of the claims of this application are within the protection scope of the present invention.
Claims
1. A method for remote operation and maintenance of equipment in a private network environment, characterized in that, Includes the following steps: S100: The IoT router is pre-installed with an eSIM card. After power-on, it automatically accesses the public network through the eSIM card and establishes a management channel with the device management platform. S200: The device management platform remotely sends configuration parameters to the IoT router through the management channel. The configuration parameters include APN parameters for accessing the private network. S300: Based on the received APN parameters, the IoT router configures the external physical SIM card and connects to the private network to establish a business data channel with the business data center; S400: The IoT router receives management instructions through the management channel and transmits service data of the connected devices through the service data channel.
2. The method for remote operation and maintenance of equipment in a private network environment according to claim 1, characterized in that, In step S100, after the IoT router is powered on for the first time, it automatically connects to the public network through the eSIM card and the built-in default bootloader, registers with the device management platform, and establishes an initial management channel with the device management platform.
3. The method for remote operation and maintenance of equipment in a private network environment according to claim 1, characterized in that, In step S200, the IoT router is changed from a zero-configuration state to a fully service-ready state by remotely sending configuration parameters.
4. The method for remote operation and maintenance of equipment in a private network environment according to claim 1, characterized in that, In step S200, configuration parameters are automatically sent remotely to the IoT router.
5. The method for remote operation and maintenance of equipment in a private network environment according to claim 1, characterized in that, In step S200, the configuration parameters also include firewall rules and service routing policies.
6. The method for remote operation and maintenance of equipment in a private network environment according to claim 1, characterized in that, The management channel is used for monitoring and configuration command transmission of the device management platform, and the business data channel is used for business data flow between the downstream device and the business data center.
7. The method for remote operation and maintenance of equipment in a private network environment according to claim 6, characterized in that, The management channel and business data channel operate in parallel and are physically or logically separated.
8. The method for remote operation and maintenance of equipment in a private network environment according to claim 1, characterized in that, The device management platform provides an API interface, through which the business data center integrates device management functions.
9. A remote equipment operation and maintenance system in a private network environment, characterized in that, The method for remote operation and maintenance of equipment in a private network environment according to any one of claims 1-8 includes an IoT router, an equipment management platform, and a business data center; the IoT router is pre-installed with an eSIM card that can be connected to the equipment management platform and can receive private network APN parameters remotely to configure the external physical SIM card function for connecting to the attached business equipment on site and accessing the network. The device management platform is deployed in the cloud and communicates with the IoT router through a management channel established based on eSIM. It is used to send configuration parameters to the IoT router, monitor the status of the router and eSIM card, and provide an application programming interface (API). The service data center receives service data from the connected service devices through a private network service data channel established by the IoT router based on the physical SIM card and the configuration parameters, and integrates the management of the eSIM card and the IoT router by calling the application programming interface (API) provided by the device management platform.
10. A remote equipment operation and maintenance system in a private network environment according to claim 9, characterized in that, The IoT routers include a first IoT router R1, a second IoT router R2, and a third IoT router R3. The first IoT router R1, the second IoT router R2, and the third IoT router R3 all access a private network base station via a private network and a public network base station via a public network.