CN103123731B - The electricity-selling system that flows is carried out based on 3G communications wireless network - Google Patents

The electricity-selling system that flows is carried out based on 3G communications wireless network Download PDF

Info

Publication number
CN103123731B
CN103123731B CN201110370062.8A CN201110370062A CN103123731B CN 103123731 B CN103123731 B CN 103123731B CN 201110370062 A CN201110370062 A CN 201110370062A CN 103123731 B CN103123731 B CN 103123731B
Authority
CN
China
Prior art keywords
network
mobile electricity
wireless
power
wireless network
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN201110370062.8A
Other languages
Chinese (zh)
Other versions
CN103123731A (en
Inventor
刘世良
韩良煜
王凤
李国栋
耿科理
刘晓刚
王光辉
白莉珍
李红梅
蔺革晒
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
QINGHAI ELECTRIC POWER CO Ltd
QINGHAI ELECTRIC POWER Corp INFORMATION COMMUNICATION CORPORATION
State Grid Corp of China SGCC
Original Assignee
QINGHAI ELECTRIC POWER CO Ltd
QINGHAI ELECTRIC POWER Corp INFORMATION COMMUNICATION CORPORATION
State Grid Corp of China SGCC
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by QINGHAI ELECTRIC POWER CO Ltd, QINGHAI ELECTRIC POWER Corp INFORMATION COMMUNICATION CORPORATION, State Grid Corp of China SGCC filed Critical QINGHAI ELECTRIC POWER CO Ltd
Priority to CN201110370062.8A priority Critical patent/CN103123731B/en
Publication of CN103123731A publication Critical patent/CN103123731A/en
Application granted granted Critical
Publication of CN103123731B publication Critical patent/CN103123731B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Landscapes

  • Small-Scale Networks (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

本发明涉及通信技术和信息技术领域,具体地说是涉及一种基于3G通信无线网络进行流动售电的系统。一种基于3G通信无线网络进行流动售电的系统移动售电终端(笔记本电脑和小型打印机)通过电信公司的3G无线网络与信通公司的主站网络信息设备进行信息传输和信息交换。可随时随地快速建立起与省公司总部营销业务系统远程通信链路,传输营销业务数据等各种信息。同时解决传统的台收或银行代收缴费不便,缴费难的问题,使用此系统要能够实现只需要一台笔记本电脑和一台小型打印机就能够实现卡表售电、缴费、发票打印以及业务受理等功能,具有体积小、重量轻,便于携带、方便使用等特点。提高了电力营销售电缴费的灵活性、可靠性、便捷性。

The invention relates to the fields of communication technology and information technology, in particular to a system for mobile electricity selling based on a 3G communication wireless network. A mobile electricity selling system based on 3G communication wireless network. Mobile electricity selling terminals (laptops and small printers) carry out information transmission and information exchange with the main station network information equipment of Xintong Company through the 3G wireless network of the telecommunications company. It can quickly establish a remote communication link with the marketing business system of the provincial company headquarters anytime, anywhere, and transmit various information such as marketing business data. At the same time, it solves the problem of inconvenient and difficult payment of traditional Taiwan collection or bank collection and payment. Using this system, only a notebook computer and a small printer can be used to realize card meter electricity sales, payment, invoice printing and business acceptance. And other functions, with small size, light weight, easy to carry, easy to use and so on. Improve the flexibility, reliability and convenience of electric power sales electricity payment.

Description

基于 3G 通信无线网络进行流动售电系统Mobile electricity sales system based on 3G communication wireless network

技术领域 technical field

本发明涉及通信技术领域,具体地说是涉及一种基于 3G 通信无线网络进行流动 售电的系统。 The present invention relates to the field of communication technology, in particular to a system for mobile electricity sales based on a 3G communication wireless network.

背景技术 Background technique

青海电力传统方式下广大用户缴纳电费,基本是通过银行代收、电力营业厅进行。 但由于电费缴纳的数额比较小,银行在进行电费代缴时积极性不高 ; 电力营业厅数量比较 少、营业压力大,势必造成广大用户电费缴纳难的问题。加之青海地域广阔,人烟稀少,且分 布极为不均,在广大牧区,牧民缴费往往要跑上几十甚至上百公里,才能把电费缴纳上,极 为不方便,极大地影响了电力公司的服务品牌和服务质量。而专用于青藏高原地区特点的 基于 3G 通信无线网络进行流动售电的系统,尚未见记载。 Under the traditional method of Qinghai Electric Power, the majority of users pay electricity bills, basically through bank collection and electric power business halls. However, due to the relatively small amount of electricity bill payment, banks are not very active in paying electricity bills; the number of power business halls is relatively small, and the business pressure is high, which will inevitably cause difficulties in paying electricity bills for the majority of users. In addition, Qinghai has a vast territory, sparsely populated, and the distribution is extremely uneven. In the vast pastoral areas, herdsmen often have to run dozens or even hundreds of kilometers to pay the electricity bill, which is extremely inconvenient and greatly affects the service brand and reputation of the power company. service quality. However, there is no record of the mobile electricity sales system based on the 3G communication wireless network that is dedicated to the characteristics of the Qinghai-Tibet Plateau region.

发明内容 Contents of the invention

本发明要解决的技术问题是针对现有技术存在的不足,提供一种专用于有线信息 网络无法到达, 3G 通信无线网络能够覆盖的地区进行流动售电系统。 The technical problem to be solved by the present invention is to provide a mobile electricity selling system dedicated to the areas where the wired information network cannot reach and the 3G communication wireless network can cover.

本发明一种基于 3G 通信无线网络进行流动售电的系统,通过下述技术方案予以 实现 : 一种基于 3G 通信无线网络进行流动售电的方法包括流动售电终端、电信 3G 无线接 入路由器、 3G 无线基站、 LAC 交换路由器、电信侧 LAC AAA 安全认证服务器、 IP 专网、 LNS 汇 聚交换机、LNS AAA 安全认证服务器、电信侧边界路由器 、电力侧边界路由器、电力侧防火墙、无线售电应用服务器和数据库服务器,所述的流动售电终端模块和 3G 无线接入路由器 模块连接,再采用 IPSEC 安全加密技术与电信运维商的网络连接,电信运维商网络主要包 括 3G 无线基站连接 LAC 交换路由器并经过 LAC AAA 安全认证服务器安全认证,再通过电信 IP 专网连接 LNS 汇聚交换机经过 LNS AAA 安全认证服务器安全认证后,到达电信侧边界路由器与电力侧边界路由器连接,电力侧边界路由器与电力侧防火墙连接,电力侧防火墙分别与无线售电应用服务器和数据库服务器连接 , 完成售电数据传送。 The present invention is a system for mobile electricity sales based on 3G communication wireless network, which is realized through the following technical solutions: A method for mobile electricity sales based on 3G communication wireless network includes mobile electricity sales terminals, telecom 3G wireless access routers, 3G wireless base stations, LAC switching routers, LAC AAA security authentication servers on the telecom side, IP private networks, LNS aggregation switches, LNS AAA security authentication servers, telecom-side border routers, power-side border routers, power-side firewalls, wireless power sales application servers and The database server, the mobile electricity sales terminal module is connected with the 3G wireless access router module, and then uses IPSEC security encryption technology to connect with the network of the telecom operation and maintenance provider. The telecom operation and maintenance provider network mainly includes 3G wireless base stations connected to the LAC switch router and After passing the security authentication of the LAC AAA security authentication server, and then connecting to the LNS aggregation switch through the telecom IP private network. After passing the security authentication of the LNS AAA security authentication server, it reaches the border router on the telecom side and connects to the border router on the power side, and the border router on the power side connects to the firewall on the power side , the power side firewall is connected to the wireless power sales application server and the database server respectively to complete the power sales data transmission.

本发明一种基于 3G 通信无线网络进行流动售电的系统与现有技术相比较有如下有益效果 : 1、本发明一种基于3G通信无线网络进行流动售电的系统通过电信公司的3G无线网络 与信通公司的主站网络信息设备进行信息传输和信息交换。可随时随地快速建立起与省公 司总部营销业务系统远程通信链路,传输营销业务数据等各种信息。 Compared with the prior art, a system for mobile electricity sales based on a 3G communication wireless network of the present invention has the following beneficial effects: 1. A system for mobile electricity sales based on a 3G communication wireless network of the present invention passes through the 3G wireless network of a telecommunications company Carry out information transmission and information exchange with the main station network information equipment of Xintong Company. It can quickly establish a remote communication link with the marketing business system of the provincial company headquarters anytime, anywhere, and transmit various information such as marketing business data.

2、本发明一种基于 3G 通信无线网络进行流动售电的系统目的是解决传统的台收 或银行代收缴费不便,缴费难的问题,使用此系统要能够实现只需要一台笔记本电脑和一 台小型打印机就能够实现卡表售电、缴费、发票打印以及业务受理等功能,具有体积小、重 量轻,便于携带、方便使用等特点。提高了电力营销的灵活性、可靠性、便捷性。 2. The purpose of this invention is a system for mobile electricity sales based on 3G communication wireless network to solve the problem of inconvenient and difficult payment of traditional Taiwan collection or bank collection and payment. To use this system, only a notebook computer and a A small printer can realize the functions of card meter electricity sales, payment, invoice printing, and business acceptance. It has the characteristics of small size, light weight, easy to carry, and convenient to use. Improve the flexibility, reliability and convenience of power marketing.

3、本发明一种基于 3G 通信无线网络进行流动售电的系统通过无线通道与企业内 部网相连,因此设计首先要保证接入安全性,不容许对企业内部网安全产生任何影响,此次我们租用了中国电信的 3G VPDN 专网进行研究测试,在安全方面主要是通过专有 APN +绑 定接入认证、 L2TP私有隧道、 IPSEC安全加密技术来实现3G部署时对接入认证、端到端的私 有性、端到端安全加密的安全原则,同时在电力公司侧采用了防火墙技术。确保了电力营销 数据安全传输。 3. The present invention is based on a 3G communication wireless network for mobile electricity sales. The system is connected to the enterprise intranet through a wireless channel. Therefore, the design must first ensure access security and not allow any impact on the security of the enterprise intranet. This time we The 3G VPDN private network of China Telecom was rented for research and testing. In terms of security, access authentication and end-to-end The security principles of privacy, end-to-end security encryption, and firewall technology are adopted on the power company side. Ensure the safe transmission of power marketing data.

附图说明 Description of drawings

图 1 为本发明一种基于3G 通信无线网络进行流动售电的系统的连接状态示意 图 ; 其中 : 1、流动售电终端 ; 2、电信 3G 无线接入路由器 ; 3、 3G 无线基站 ; 4、LAC 交换路由 器 ; 5、电信侧 LAC AAA 安全认证服务器 ; 6、IP 专网 ; 7、 LNS 汇聚交换机 ; 8、 LNS AAA 安全认证服务器 ; 9、电信侧边界路由器 ; 10、电力侧边界路由器 ; 11、电力侧防火墙、 12、无线售电 应用服务器 ; 13 数据库服务器。 Figure 1 is a schematic diagram of the connection state of a system for mobile electricity sales based on the 3G communication wireless network of the present invention; wherein: 1. Mobile electricity sales terminal; 2. Telecom 3G wireless access router; 3. 3G wireless base station; 4. LAC Switch router; 5. Telecom side LAC AAA security authentication server; 6. IP private network; 7. LNS aggregation switch; 8. LNS AAA security authentication server; 9. Telecom side border router; 10. Power side border router; side firewall, 12, wireless power sales application server ; 13 database server.

具体实施方式 detailed description

下面结合附图和实施例对本发明一种基于 3G 通信无线网络进行流动售电的系统 技术方案作进一步描述。 The following will further describe the technical scheme of a mobile electricity selling system based on a 3G communication wireless network of the present invention in conjunction with the accompanying drawings and embodiments.

如图1所示,本发明一种基于3G通信无线网络进行流动售电的系统包括流动售电 终端 1、电信 3G 无线接入路由器 2、 3G 无线基站 3、 LAC 交换路由器 4、电信侧 LAC AAA 安全 认证服务器 5、 IP 专网 6、 LNS 汇聚交换机 7、 LNS AAA 安全认证服务器 8、电信侧边界路由器 9 、电力侧边界路由器10、电力侧防火墙11、无线售电应用服务器12和数据库服务器13,所述的流动售电终端 1 模块和 3G 无线接入路由器2模块连接,再采用 IPSEC 安全加密技术与 电信运维商的网络连接,电信运维商网络主要包括 3G 无线基站 3 连接 LAC 交换路由器 4 并 经过 LAC AAA 安全认证服务器 5 安全认证,再通过电信 IP 专网 6 连接 LNS 汇聚交换机 7 经 过 LNS AAA 安全认证服务器 8 安全认证后,到达电信侧边界路由器 9 与电力侧边界路由器 10 连接,电力侧边界路由器 10 与电力侧防火墙 11 连接,电力侧防火墙 11 分别与无线售电应用 服务器 12 和数据库服务器13连接 , 完成售电数据传送。 As shown in Figure 1, a system for mobile electricity sales based on a 3G communication wireless network in the present invention includes a mobile electricity sales terminal 1, a telecom 3G wireless access router 2, a 3G wireless base station 3, a LAC switching router 4, and a telecom side LAC AAA Security authentication server 5, IP private network 6, LNS aggregation switch 7, LNS AAA security authentication server 8, telecommunications side border router 9, power side border router 10, power side firewall 11, wireless power vending application server 12 and database server 13, The mobile electricity vending terminal 1 module is connected to the 3G wireless access router 2 module, and then IPSEC security encryption technology is used to connect to the network of the telecom operation and maintenance provider. The telecom operation and maintenance provider network mainly includes 3G wireless base stations 3 connected to LAC switching routers 4 And pass the security authentication of LAC AAA security authentication server 5, and then connect to the LNS aggregation switch 7 through the telecom IP private network 6. After passing the security authentication of LNS AAA security authentication server 8, it reaches the border router 9 on the telecom side and connects to the border router 10 on the power side. The border router 10 is connected to the power side firewall 11, and the power side firewall 11 is respectively connected to the wireless power sales application server 12 and the database server 13 to complete power sales data transmission.

所述的流动售电终端 1 通过电信无线网络与电力公司内部网络连接。 The mobile power selling terminal 1 is connected to the internal network of the electric power company through the telecommunications wireless network.

系统采用了 IPSEC 实现端到端的加密。 The system uses IPSEC to realize end-to-end encryption.

实施例 1。 Example 1.

3G 即第三代移动通信技术,是指支持高速数据传输的蜂窝移动通讯技术。3G 服务 能够同时传送声音及数据信息,与 2G 的主要区别是在传输声音和数据的速度上的提升,速 率一般在几百 kbps 以上。目前 3G 存在四种标准 : CDMA2000, WCDMA, TD-SCDMA, WiMAX。 3G is the third generation mobile communication technology, which refers to the cellular mobile communication technology that supports high-speed data transmission. 3G service can transmit voice and data information at the same time. The main difference from 2G is the increase in the speed of transmission of voice and data. The rate is generally above several hundred kbps. There are currently four 3G standards: CDMA2000, WCDMA, TD-SCDMA, and WiMAX.

VPDN 英文为 Virtual Private Dial - up Networks,又称为虚拟专用拨号网,是 VPN 业务的一种,是基于拨号用户的虚拟专用拨号网业务,即以拨号接入方式上网。VPDN 的 具体实现是采用隧道技术,即将企业网的数据封装在隧道中进行传输,用户通过 VPDN 可以 实现总部对分支机构的远程管理,远程监控,业务应用等多方面数据传输需求,节省了用户 的通信成本,提高了企业管理运作效率,同时也为客户业务的扩展提供了很好的保障。分支 企业使用 VPDN 专用帐号拨入企业总部,实现本地的数据到企业总部数据中心的上传,实现 信息共享,交互和相关业务应用的处理。 VPDN is Virtual Private Dial-up Networks in English, also known as virtual private dial-up network. The specific implementation of VPDN is to use tunnel technology, that is, the data of the enterprise network is encapsulated in the tunnel for transmission. Through VPDN, users can realize the remote management of branches from the headquarters, remote monitoring, business applications and other data transmission requirements, saving users' time and effort. The cost of communication improves the efficiency of enterprise management and operation, and also provides a good guarantee for the expansion of customer business. The branch enterprise uses the VPDN special account to dial into the enterprise headquarters to upload local data to the data center of the enterprise headquarters, realize information sharing, interaction and processing of related business applications.

随着 3G 网络业务的不断普及,运营商针对企业用户对“3G 移动专用网”的需求推 出了 3G 的 VPDN 业务,即 : 基于 3G 无线接入方式的虚拟专用拨号网业务,它是利用 L2TP 隧道传输协议,就可以在现有的拨号网络上构建一条虚拟的、不受外界干扰的专用通道,从而 实现类似采用有线专用网络的方式访问企业内部网资源。 With the continuous popularization of 3G network services, operators have launched 3G VPDN services in response to the needs of enterprise users for "3G mobile private networks", namely: virtual private dial-up network services based on 3G wireless access methods, which use L2TP tunnels By using a transmission protocol, a virtual private channel free from external interference can be built on the existing dial-up network, so as to access corporate intranet resources in a way similar to using a wired private network.

由以上分析可知,我们可以采用基于 3G VPDN 专网的技术来进行流动售电系统设 计。采用这种技术首先减少了人力与设备的费用,由于可以采用 ISP 提供现成的网络平台, 大大减少了人力和设备上的投入 ; 其次提高了业务处理速度, 3G 网络相比同类 GPRS 技术有较高的业务处理和传输性能, 3G VPDN 系统还可以促进管理信息服务的改进,供电局可以利 用此系统改进缴费流程,从方便用户的角度出发,提高服务品牌和服务等级 ; 3G 网络具有 随时随地接入的特点,只需一台笔记本电脑 +3G 无线网卡,就能进行流动售电,提高供电营 销人员工作效率。 From the above analysis, we can use the technology based on 3G VPDN private network to design mobile electricity sales system. The use of this technology firstly reduces the cost of manpower and equipment, because ISP can be used to provide a ready-made network platform, which greatly reduces the investment in manpower and equipment; secondly, it improves the business processing speed, and 3G network has higher The 3G VPDN system can also promote the improvement of management information services, the power supply bureau can use this system to improve the payment process, and improve the service brand and service level from the perspective of user convenience; 3G network has the ability to access anytime, anywhere It only needs a laptop + 3G wireless network card to conduct mobile electricity sales and improve the work efficiency of power supply marketers.

1、系统组网说明 : 此系统采用了 B/S 结构,流动售电终端设备采用了“无线网卡 + 笔记本 + 打印机”,通过 浏览器访问电信 3G 无线接入网络,同时在安全方面采用 VPDN 专用帐号拨入专用的认证服务器来获得认证,安全认证通过之后才能接入 VPDN 服务器获得青海营销业务系统专业地 址,得到访问企业网络的权限(如果帐号没有通过认证则不具备联网的功能)。 1. System networking description: This system adopts the B/S structure, and the mobile electricity sales terminal equipment adopts "wireless network card + notebook + printer". The account dials into a dedicated authentication server to obtain authentication. After the security authentication is passed, it can access the VPDN server to obtain the professional address of Qinghai marketing business system, and obtain the authority to access the corporate network (if the account has not passed the authentication, it will not have the function of networking).

在电力侧我们还安装了路由器和防火墙,在防火墙上作了安全策略,只容许指定 的端口访问 DMZ 区中的无线售电前置机,无线售电前置机接到指令后与营销业务系统的数 据库进行数据交互,将数据反馈到流动售电终端。 We also installed routers and firewalls on the power side, and made a security policy on the firewall to allow only designated ports to access the wireless power sales front-end processor in the DMZ area. After receiving the instruction, the wireless power sales front-end The database interacts with the data and feeds the data back to the mobile electricity vending terminal.

2. 系统安全解决措施 由于青海电力无线缴费系统通过无线通道与企业内部网相连,因此设计首先要保证接 入安全性,不容许对企业内部网安全产生任何影响,所以解决系统安全问题是 3G 无线网络流动售电系统应用的关键。 2. System security solutions Since the Qinghai Electric Power wireless payment system is connected to the enterprise intranet through a wireless channel, the design must first ensure access security and not allow any impact on the security of the enterprise intranet. Therefore, the solution to the system security problem is 3G wireless The key to the application of network mobile electricity sales system.

此次我们租用了中国电信的 3G VPDN 专网进行研究测试,在安全方面主要是通过 专有 APN +绑定接入认证、 L2TP 私有隧道、 IPSEC 安全加密技术来实现 3G 部署时对接入认 证、端到端的私有性、端到端安全加密的安全原则,具体部署方案如下 : ●专有 APN+ 绑定接入认证 在进行流动终端网点的3G无线接入部署时, 先由运营商分配的专网APN (Access Point Name)。终端网点采用 3G 路由器接入,运营商会将网点用户的 IMSI 信息(IMSI 是在运营商 网络中唯一识别一个移动用户的号码,由 15 位数字组成,存于 SIM 卡中)、终端用户的账号 和密码事先配置在运营商认证服务器上。当网点的 3G 路由器发起无线连接时,只允许绑定 信息合法的用户通过用户名、密码的 AAA 认证后接入 3G 专用网络,防止非法 SIM 卡用户拨 入用户 3G 专网。 This time we rented China Telecom's 3G VPDN private network for research and testing. In terms of security, we mainly use proprietary APN + binding access authentication, L2TP private tunnel, and IPSEC security encryption technology to realize access authentication, The security principle of end-to-end privacy and end-to-end security encryption, the specific deployment plan is as follows: Proprietary APN+ binding access authentication When deploying 3G wireless access at mobile terminal outlets, the private network APN (Access Point Name) assigned by the operator is firstly assigned. The terminal outlets are accessed by 3G routers, and the operator will store the IMSI information of the outlet users (IMSI is a number that uniquely identifies a mobile user in the operator's network, consisting of 15 digits, and stored in the SIM card), the terminal user's account number and The password is configured on the carrier authentication server in advance. When the 3G router at the outlet initiates a wireless connection, only users with legal binding information are allowed to access the 3G private network after passing the AAA authentication of the user name and password to prevent illegal SIM card users from dialing into the user's 3G private network.

此外,可进一步通过 3G 路由器设置 SIM 卡的 PIN 码保护功能,只有知道 SIM 卡的 PIN 密码才能触发 3G 拨号,防止非法用户获取到用户 SIM 卡后进行的非法操作,保证了 SIM 卡的使用安全。 In addition, the PIN code protection function of the SIM card can be further set through the 3G router. Only knowing the PIN code of the SIM card can trigger 3G dialing, preventing illegal users from illegal operations after obtaining the user’s SIM card, and ensuring the safety of the SIM card.

● L2TP + IPSEC VPN 私有隧道 ● L2TP + IPSEC VPN private tunnel

为了保证 3G 接入网点的数据业务在运营商 IP 核心网中传输的的私有性,我们向运营 商申请企业集团用户3G的VPDN业务,在现有的拨号网络上构建一条虚拟的、不受外界干扰的专用通道,从而安全访问企业内部网资源。 In order to ensure the privacy of the data services of 3G access points transmitted in the operator's IP core network, we apply to the operator for the 3G VPDN service of enterprise group users, and build a virtual network on the existing dial-up network that is not protected from the outside world. Dedicated channel for interference, so as to securely access corporate intranet resources.

运 营 商 会 提 供 L2TP 的 LAC 端 路 由 器 及 配 套 AAA(Authentication 验 证、 Authorization 授权、 Accounting 记账 ) 服务器。我们在企业一级网或二级网汇聚层采用 一台路由器作为 L2TP 的 LNS 端,并部署一台 AAA 服务器。LAC 路由器主要负责对 3G 用户 的接入认证,与该用户所属企业的专有 LNS 建立 L2TP 隧道。企业一级网或二级网汇聚的 AAA 服务器主要存放网点路由器建立连接时所需要的用户名和密码。用户名的格式为 XX@ XX.COM,其中 @ 前面的字符串可以由用户端自行定义,@后面的字符串即域名。运营商 AAA 服务器通过域名确认该用户的接入权限。运营商 AAA 服务器与企业 AAA 服务器的用户名和 密码必须一致。 Operators will provide L2TP LAC end routers and supporting AAA (Authentication verification, Authorization authorization, Accounting accounting) servers. We use a router as the LNS end of L2TP at the aggregation layer of the enterprise's primary network or secondary network, and deploy an AAA server. The LAC router is mainly responsible for the access authentication of the 3G user, and establishes an L2TP tunnel with the private LNS of the enterprise to which the user belongs. The AAA server converged on the primary network or secondary network of the enterprise mainly stores the user name and password required when the network router establishes a connection. The format of the user name is XX@XX.COM, where the string in front of @ can be defined by the client, and the string behind @ is the domain name. The carrier's AAA server confirms the user's access rights through the domain name. The user name and password of the carrier AAA server and enterprise AAA server must be the same.

对端到端的安全加密原则, 如前文所述, 3G 技术有自身的加密验证技术,但是 3G 的加密验证技术只针对无线部分,而在 IP 核心网部分,从 LAC 到 LNS 之间的 L2TP 隧道是不 加密的,数据还是明文传送。而从 LAC 到网络中间还会经过运营商的 IP 网络,为了达到端 到端的加密传输,需要在售电网点和电力总部路由器之间,采用 IPSEC 实现端到端的加密。 For the principle of end-to-end security encryption, as mentioned above, 3G technology has its own encryption verification technology, but 3G encryption verification technology is only for the wireless part, and in the IP core network part, the L2TP tunnel from LAC to LNS is Without encryption, the data is still transmitted in clear text. From the LAC to the network, the operator's IP network will also pass through. In order to achieve end-to-end encrypted transmission, IPSEC needs to be used between the point of sale and the power headquarters router to achieve end-to-end encryption.

Claims (3)

1.一种基于3G通信无线网络进行流动售电的系统,包括流动售电终端(1)、电信3G无线接入路由器(2)、3G无线基站(3)、LAC交换路由器(4)、电信侧LAC AAA安全认证服务器(5)、IP专网(6)、LNS汇聚交换机(7)、LNS AAA安全认证服务器(8)、电信侧边界路由器(9) 、电力侧边界路由器(10)、电力侧防火墙(11)、无线售电应用服务器(12)、数据库服务器(13),其特征在于:所述的流动售电终端(1)模块和3G无线接入路由器(2)模块连接,再采用IPSEC安全加密技术与电信运维商的网络连接,电信运维商网络主要包括3G无线基站(3)连接LAC交换路由器(4)并经过LAC AAA安全认证服务器(5)安全认证,再通过电信IP专网(6)连接LNS汇聚交换机(7)经过LNS AAA安全认证服务器(8)安全认证后,到达电信侧边界路由器(9)与电力侧边界路由器(10)连接,电力侧边界路由器(10)与电力侧防火墙(11)连接,电力侧防火墙(11)分别与无线售电应用服务器(12)和数据库服务器(13)连接,完成售电数据传送。 1. A mobile electricity selling system based on 3G communication wireless network, including mobile electricity selling terminal (1), telecom 3G wireless access router (2), 3G wireless base station (3), LAC switching router (4), telecom Side LAC AAA security authentication server (5), IP private network (6), LNS aggregation switch (7), LNS AAA security authentication server (8), telecommunications side border router (9), power side border router (10), power side firewall (11), wireless electricity vending application server (12), and database server (13), characterized in that: the mobile electricity vending terminal (1) module is connected to the 3G wireless access router (2) module, and then adopts IPSEC security encryption technology is connected to the network of the telecom operation and maintenance provider. The network of the telecom operation and maintenance provider mainly includes 3G wireless base stations (3) connected to the LAC switch router (4) and passed the security authentication of the LAC AAA security authentication server (5), and then passed the telecom IP The private network (6) is connected to the LNS aggregation switch (7) and after passing the security authentication of the LNS AAA security authentication server (8), it reaches the telecom side border router (9) and connects with the power side border router (10), and the power side border router (10) It is connected with the power side firewall (11), and the power side firewall (11) is respectively connected with the wireless power sales application server (12) and the database server (13) to complete the power sales data transmission. 2.根据权利要求1所述的基于3G通信无线网络进行流动售电的系统,其特征在于:所述的流动售电终端(1)通过电信无线网络与电力公司内部网络连接。 2. The system for mobile electricity sales based on 3G communication wireless network according to claim 1, characterized in that: the mobile electricity sales terminal (1) is connected to the internal network of the power company through the telecommunications wireless network. 3.根据权利要求1所述基于3G通信无线网络进行流动售电的系统,其特征在于:系统采用了IPSEC 实现端到端的加密。 3. The system for mobile electricity sales based on 3G communication wireless network according to claim 1, characterized in that: the system adopts IPSEC to realize end-to-end encryption.
CN201110370062.8A 2011-11-21 2011-11-21 The electricity-selling system that flows is carried out based on 3G communications wireless network Active CN103123731B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201110370062.8A CN103123731B (en) 2011-11-21 2011-11-21 The electricity-selling system that flows is carried out based on 3G communications wireless network

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201110370062.8A CN103123731B (en) 2011-11-21 2011-11-21 The electricity-selling system that flows is carried out based on 3G communications wireless network

Publications (2)

Publication Number Publication Date
CN103123731A CN103123731A (en) 2013-05-29
CN103123731B true CN103123731B (en) 2016-08-17

Family

ID=48454695

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201110370062.8A Active CN103123731B (en) 2011-11-21 2011-11-21 The electricity-selling system that flows is carried out based on 3G communications wireless network

Country Status (1)

Country Link
CN (1) CN103123731B (en)

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104468801A (en) * 2014-12-11 2015-03-25 上海因联企业咨询合伙企业(普通合伙) Free wireless value-added platform and service method thereof
CN105306334A (en) * 2015-10-10 2016-02-03 无锡高联信息技术有限公司 Wireless access method for intelligent transportation bus IC card recharge outlets based on TD-SCDMA technology
CN113508413B (en) * 2019-06-18 2025-09-05 维萨国际服务协会 Cross-border Quick Response (QR) payment flows for encrypted primary account number (PAN) payment flows

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1440155A (en) * 2002-02-23 2003-09-03 三星电子株式会社 Safety system and method for accessing virtual special network service in communication network
CN101482998A (en) * 2009-02-10 2009-07-15 宁夏隆基宁光仪表有限公司 Movable electricity-selling system for electronic electric energy meter
CN101540946A (en) * 2009-04-01 2009-09-23 神州数码网络(北京)有限公司 Finance website terminal wireless long range automatic on and off-line system and method

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
GB0107638D0 (en) * 2001-03-27 2001-05-16 Marconi Comm Ltd Access networks
KR100478899B1 (en) * 2003-12-29 2005-03-24 주식회사 플랜티넷 The system and service providing method for harmful site connection interception service by using tunneling protocol and packet mirroring mode

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1440155A (en) * 2002-02-23 2003-09-03 三星电子株式会社 Safety system and method for accessing virtual special network service in communication network
CN101482998A (en) * 2009-02-10 2009-07-15 宁夏隆基宁光仪表有限公司 Movable electricity-selling system for electronic electric energy meter
CN101540946A (en) * 2009-04-01 2009-09-23 神州数码网络(北京)有限公司 Finance website terminal wireless long range automatic on and off-line system and method

Also Published As

Publication number Publication date
CN103123731A (en) 2013-05-29

Similar Documents

Publication Publication Date Title
CN103619020B (en) Mobile payment security system for wireless data private network physical isolation internet
CN106385404B (en) Construction method of electric power information system based on mobile terminal
CN100395982C (en) Wireless local area network prepaid billing system and its method
CN104767621B (en) A kind of Mobile solution accesses the one-point safety authentication method of business data
CN104469045A (en) System and method for self-service payment for defaulting subscribers in telecom 3G mobile network
Yan et al. Network security protection technology for a cloud energy storage network controller
CN103227773B (en) A kind of method and system thereof of setting up VPDN connection
CN103123731B (en) The electricity-selling system that flows is carried out based on 3G communications wireless network
CN102647300A (en) Network equipment remote maintenance system and maintenance method
CN108092969A (en) The system and method for Intelligent Mobile Robot acquisition image access electric power Intranet
CN103684958A (en) Method and system for providing flexible VPN (virtual private network) service and VPN service center
CN102446398B (en) Mobile meter reading system based on wireless point-of-sale (POS) terminal
CN106790086A (en) A kind of safety access method and device of electric power VoLTE business
CN201662844U (en) Electric power payment terminal
CN101521878A (en) Method for realizing the public wireless broadband network access and wireless network access equipment
CN101990204B (en) Method and device for accessing service by using card inserted terminal
CN101511086A (en) Wireless safety networking system and method for financial grid point terminal
CN103905236A (en) Terminal positioning method, system and device
CN201662846U (en) Electricity charge management terminal
CN101540946A (en) Finance website terminal wireless long range automatic on and off-line system and method
CN202422388U (en) Wireless POS terminal-based mobile meter reading system
Janevski AAA system for PLMN-WLAN internetworking
CN109982276B (en) A broadband network connection and billing method
CN104680676B (en) The across a network VPN access billing systems and its method of a kind of self-built secure tunnel
CN101562526A (en) Method, system and equipment for data interaction

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
ASS Succession or assignment of patent right

Owner name: QINGHAI ELECTRIC POWER CORPORATION INFORMATION COM

Effective date: 20131128

Owner name: STATE ELECTRIC NET CROP.

Free format text: FORMER OWNER: INFORMATION COMMUNICATION COMPANY OF QINGDAO ELECTRIC POWER COMPANY

Effective date: 20131128

C41 Transfer of patent application or patent right or utility model
COR Change of bibliographic data

Free format text: CORRECT: ADDRESS; FROM: 810008 XINING, QINGHAI PROVINCE TO: 100031 DONGCHENG, BEIJING

TA01 Transfer of patent application right

Effective date of registration: 20131128

Address after: 100031 West Chang'an Avenue, Beijing, No. 86

Applicant after: State Grid Corporation of China

Applicant after: Qinghai Electric Power Co., Ltd.

Applicant after: Qinghai Electric Power Corporation Information Communication Corporation

Address before: 810008, 2, Jian Cheng alley, Xining, Qinghai

Applicant before: Qinghai Electric Power Corporation Information Communication Corporation

C14 Grant of patent or utility model
GR01 Patent grant