Integrated information communication system
Abstract
Integrated information communication system, the integrated information communication system includes a communication network (ICS 100) having a first access control device (110-1) and a second access control device (110-5), wherein the first and second access control device in each case, a conversion table with multiple entries and logical connections included for coupling a logical transmission line, wherein a first terminal is associated with a first user address (0012), a second terminal a second user address (0034) is associated with a first logical port of the first access control device, a first network address (7711) is allocated and a second logical port of the second access control device, a second network address (9922) is assigned, wherein an entry in a line of the conversion table (113-1) is the first access control device present, each of the first user address as a sender user address and the first network address as a sending network address and the second user address as a recipient user address and the second network address receiving as a includes network address, wherein the transmitting network address address of origin and the receiving network address a ...

Term
Term ended
Expired 5 December 2017, 8.8 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
10 claims: 8 independent, 2 dependent
- 1Integrated information communication system, the integrated information communication system includes a communication network (ICS 100) having a first access control device ( 110-1 ) And a second access control device ( 110-5 ), Wherein the first and second access control means each contain a conversion table with multiple entries and logical connectors for coupling of a logical transmission line, wherein a first terminal is associated with a first user address (0012), a second terminal a second user address (0034) is associated with a first logical port of the first access control device, a first network address (7711) is allocated and a second logical port of the second access control device, a second network address (9922) is assigned, wherein an entry in a line of the conversion table ( 113-1 ) Of the first access control device is present which contains both the first user address as a sender user address and the first network address as a sending network address and the second user address as a recipient user address and the second network address as a receiving network address, wherein the sending network address is a source address, and the receiving network address is a destination address of a network frame (P2), which is transmitted by the first access control device, the first terminal a user frame (P-1), which contains the first user address as the sender user address and the second user address as the recipient user address, sends the user frame is input to the first access control device of the first logical connection via a logical transmission line, the first access control device the basis of information that identifies the first logical connection to which the user context is entered, and the recipient user address of the user frame in the conversion table for the entry searches, including the first network address and the second user address, and the first access control device receives the second network address . wherein the first access control device the user context converts to a network frame (P2), the network frame contains the user context and the second network address as a destination address, and the network sends frame, and wherein the network frame is transmitted in the communication network, and reaches the second access control device, the second access control device restores the user frame (P5) from the network frame and the restored user frames sent to the second logical connection which is characterized by the second network address included in the network frame, and the user context reaches the second terminal via the second logical connection and a logical transmission line.
- 2Integrated information communication system, the integrated information communication system includes a communication network (ICS 100), the two or more logical ports and a conversion table ( 113-1 ) Having a plurality of entries, each of the entries includes a network address for identifying one of the logical connections and each of the entries in a row contains both an origin user address and a sending network address and a destination user address and a receiving network address, wherein a first logical connection is assigned a first network address (7711) and a second logic connection a second network address (9922) is assigned, wherein a first terminal, which is associated with a first user address (0012), is connected to the first logical connection via a first transmission line and a second terminal, which is associated with a second user address (0034), with the second logical connection via a second transmission line connected is, wherein a first entry in the conversion table provided to communicate from the first terminal to the second terminal, and the first entry in a line contains the first network address, the first user address, the second user address and second network address, wherein the first terminal transmits a user frame (P-1) to the second terminal, whose origin user address the first user address and the destination user address is the second user address, and the user frame is input to the communication network of the first logical connection, wherein the communication network checks on the basis of information indicative of the first logical connection to which the user frame is inputted, and the target user address of the user frame if an entry in the conversion table exists or not, the first network address for identifying the first logical port and contains the second user address, wherein the communication network the first entry is used as an entry that satisfies the test condition, and replaced by that contained in the first entry second network address, and wherein the communication network comprises a network frame (P2) which contains the user context and the second network address, the network frame is transmitted to the second logical connection by referring to the second network address, the user frame (P5) is recovered from the network frame and the restored user frame to the second terminal is sent from the second logical connection which is characterized by the second network address.
- 4Integrated information communication system, the integrated information communication system includes a communication network with two or more access control devices, each of said access control means has logical connections and contains a conversion table, and wherein a plurality of terminals connected to the logical connections of any access control devices via a logical transmission line, wherein a first terminal, which is associated with a first user address, is associated with a first logical connection to a first access control device via a first logical transmission line and a second Termina l, which is associated with a second user address with a second logical connection to a second access control device via a second logical transmission line is connected and a third terminal, which is assigned to a third user address is connected to a third terminal of the first logical access control device via a third logical transmission line, wherein the first logical port is associated with a first network address, the second logical connection is associated with a second network address and the third logical port is associated with a third network address, wherein the first access control device comprises a first conversion table having entries, each of the entries contains a network address for identifying one of the logical connectors and a destination user address, wherein a first entry in the first conversion table provided to communicate from the first terminal to the second terminal, and the first entry in a line contains the first user address, the first network address, the second user address and the second network address, wherein the first terminal to the second terminal sends a first user frame, the destination user address is the second address and the user is input from the first logical connection, wherein the first access control device checks on the basis of information that identifies the first logical connection to which the first user frame is entered, and the target user address of the first user frame if an entry in the first conversion table exists or not, both the first network address for identifying the first logic terminal from which the user first frame is entered, as also contains the second user address, wherein the first access control device the first entry is used as an entry that satisfies the test condition, and replaced by that contained in the first entry second network address, wherein the first access control device forms a network frame containing the first user frame and the second network address, the network frame is transmitted to the second access control device with reference to the second network address, the second access control device restores the first user frames from the network frame and the retrieved first user frame to the second terminal is sent from the second logical connection which is characterized by the second network address, wherein the third terminal to the second terminal sends a second user frame whose origin user address is the third user address and the destination user address is the second user address, and the second user frame is input to the first access control device of the third logical connection, wherein the first access control device checks on the basis of information that identifies the third logical port on which the second user frame is entered, and the target user address of the second user frame, whether in the first conversion table is an entry or not, both the third network address to includes identifying the third logical port and the second user address, the second user context is discarded when no entry is found which satisfies the test condition.
- 6integrated information communication system (ICS), the integrated information communication system includes a communication network (ICS 100), wherein the communication network includes a plurality of entries, wherein a first terminal having a first ICS user address ( 0012 ) With the communication network by a first logical ICS port is connected via a first logical transmission line and a second terminal having a second ICS user address ( 0034 ) Is connected to the communication network through a second logic ICS port via a second logical transmission line, wherein the first logical ICS port a first ICS network address ( 7711 ) And the second logic ICS port a second ICS network address ( 9922 ) assigned, wherein an entry in a line contains the first ICS user address, the second ICS user address, the first ICS network address and the second ICS network address, wherein an ICS user frame (P-1), whose destination address is the second ICS user address, is transmitted on the first logical transmission line and is entered into the communication network of the first logical ICS connection, the second ICS network address based on information that identifies the first logical ICS connector, the target ICS user address of the ICS user frame and the entry is found and an ICS network frame (P2) containing the ICS user frame and whose destination address is the second ICS network address is formed and is transmitted in the communication network, and wherein the recovered from the ICS network frame ICS user frame (P5) is transmitted on the second logical transmission line of the second logical ICS connection, which is characterized by the second ICS network address.
- 7Integrated information communication system (ICS), the integrated information communication system includes a communication network (ICS 100) and the communication network, a first access control device ( 110-1 ) And a second access control device ( 110-5 ) Which wherein the first access control device and the second access control means each contain a plurality of entries, wherein the first access control device includes a first logical ICS connection and the second access control device includes a second logic ICS connector, wherein a first terminal having a first ICS User Address (0012) is connected to the first access control device through the first logical ICS connection via a first logical transmission line and a second terminal with a second ICS user address (0034) to the second access control device through the second logical ICS terminal is connected via a second logical transmission line, wherein the first logical connection a first ICS network address (7711) and the second logical connection is associated with a second ICS network address (9922), wherein an entry in a line contains the first ICS user address, the second ICS user address, the first ICS network address and the second ICS network address, wherein an ICS user frame (P-1), whose destination address is the second ICS user address, is transferred to the first logical transmission line and is entered in the first Zugiffssteuervorrichtung from the first logic ICS connector, wherein an ICS network communication line on which an ICS network frame is transmitted between the first access control device and the second access control device on the basis of information that identifies the first logical ICS port on which the ICS user frame is entered, the target ICS user address of the ICS user frame and the entry will be established and in which case an ICS network frame (P2), containing the ICS user frame and its destination address is the second ICS network address that is associated with the second logical connection, is formed and transferred to the ICS network communication line, and said recovered from the ICS network frame ICS user frame (P5) is transmitted to the second logical transmission line from the second logic ICS port.
- 8Access control device ( 110-1 ), Comprising the following features:the access control device has a conversion table ( 113-1 ) With multiple entries, logical connections and one or more internal connection points, each of the logical connections is associated with a network address and each of the entries contains one line a sending network address, a transmitter user address, a recipient user address and a receiving network address, a logical user transmission line for transmitting / receiving a user frame is able to be connected to one of the logical ports, a network communication line to send / receive a network frame is able to be connected to one of the internal connection points, the user frame includes a control panel, the transmitter user address a and including a receiving user address, and a data field, and the network frame includes a control field containing a receiving network address, and a data field, a first user frame (P-1) which contains a first transmitter user address (0012) and a first receiver user address (0034) as the destination address is input in the access control device via a first logical connection which is characterized by a first network address (7711), on the basis of information that identifies the first logical connection to which the first user frame is entered, and the destination address of the first user frame a first entry in the conversion table is found, and the access control device receives a first receiving network address (9922) of the first entry, and the access control device forms a first network frame (P2), wherein the control field of the first network frame contains the first receiving network address as a destination address and the data field of the first network frame contains the first user frame, and the access control device sends the first network frame formed on a first network communication line connected to is connected to a first internal node.
- 9Access control apparatus comprising logical connections that are associated with logical transmission lines, one or more associated with internal communication lines internal connection points and a conversion table with multiple entries, each of the entries contains one line both a sending network address that identifies a logical connection, and a transmitter user address and a recipient address user and a receiving network address, wherein a first entry in the conversion table is provided so that a third terminal can communicate as a third target user address, and the first entry in a row including a first network address, a first user address, a third user address and a third network address, a second entry in the conversion table is provided so that a fourth terminal can communicate as a fourth target user address, and the second entry in a row contains a second network address, a second user address, a fourth user address and a fourth network address, wherein a first user frame whose origin user address the first user address and the destination user address is the third user address, is entered by a first logical connection, wherein the access control device checks on the basis of information that identifies the first logical connection to which the first user frame is entered, and the target user address of the first user frame if an entry in the conversion table exists or not, both the first network address that the first logic terminal features, as also contains the third user address, wherein the access control device to the first entry is used as an entry that satisfies the test condition, and receives the third network address contained in the first entry, wherein said access control device forms a first network frame that contains the first user frames, and the third network address, and the first network frame is sent to a first internal node which is connected to a first internal communication line, a second user frame whose origin user address the second user address and the destination user address is the fourth user address, is entered by a second logical connection, wherein said access control device checks on the basis of information identifying the second logical connection to which the second user frame is inputted, and the target user address of the second user frame if an entry in the conversion table exists or not, both the second network address, the second logical connection features, as also contains the fourth user address, wherein the access control device to the second entry is used as an entry that satisfies the test condition, and replaced by the fourth network address contained in the second entry, wherein said access control device forms a second network frame that contains the second user frame and the fourth network address, and the second network frame of the first internal node which is connected to the first internal communication line, or to a second internal node, connected to a second internal communication line is connected, is sent.
- 10Access control device ( 110-1 ), Wherein said access control device comprises the following features:the access controller has logical connections, which network addresses are assigned and one or more internal connection points, as well as a conversion table ( 113-1 ) With multiple entries, and each of the entries contains one line a station user address, a recipient user address, a sending network address and a receiving network address, when a first user frames (P-1), whose destination address is a first receiver user address (0034) is input from a first logical connection, a first entry in the conversion table on the basis of information indicative of the first logical connection is, on the the user first frame is entered, and found the target address of the first user frame, which entry includes a first transmitting network address (7711), featuring the first logical connection, and the first recipient user address included in the first user context is, and the first entry includes a first receiving network address (9922), the access control device forms a first network frame (P2), including the first user frames, and the first receiving network address as its destination address, and sends the first network frame on a first network communication line which is connected to a first internal node.
Independent claims8
421 paragraphs in 3 sections, as filed
The invention relates to an integrated telecommunications system, which telecommunication systems or telecommunication systems, such as for or with a personal computer, a LAN. (Local Area Network; local area network), telephone (including portable phones), fax (facsimile), CATV (cable TV) Internet and the like integrally interconnects, not only via dedicated lines, but also via the ISDN (Integrated Services Digital network; Integrated Services Digital network), FR (frame Relay; frame transfer), ATM (asynchronous transfer Mode; asynchronous transfer mode), IPX ( integrated packet Exchange; integrated data packet exchange), satellite, wireless links and public networks. The integrated telecommunication system handles communication, which is equipped with an address (for the information or message) to distinguish the integrated telecommunication systems of other plants. Specifically, the present invention relates to an integrated telecommunications system which integrates data transmission services that are based on connectionless networks (z. B. IP technology (Internet Protocol), which is used for the system RFC791 or RFC1883), and the overall economy the telecommunications system improved by using a unified address system and ensuring security in the realization of an interactive message exchange between connected terminals or systems.
THE STATE OF THE ART
With the development of computer and telecommunications technology computer communication networks have been used increasingly in recent years in various fields such as universities, research institutes, government organizations, and institutions within societies and between different societies. The LANs (local networks) serving as exposure to each company belonging networks. Do these networks, for example, a geographical expansion on a national basis, so as to form a structure as in<figref idrefs="S143">1</figref> is shown. In the in<figref idrefs="S143">1</figref> Illustrated example uses each LAN a common protocol, said LANs connected with each other through dedicated lines (dedicated lines). In the present example, the company X owns the networks LAN-X1, X2-LAN and LAN-X3 as local area networks, the company Y owns the local networks LAN Y1, Y2 and LAN-LAN-Y3. The two companies X and Y using communication systems address ADX and ADY for computer communications. Since each company with such a LAN network has embarrassed separate dedicated lines, the system architecture is costly. If a connection can be established to a LAN of another company, so the interface must be set up such that the address systems coincide, so that this interconnection is very difficult and costly to implement.
As computer communications network on a global scale, the Internet has been established. When Internet networks are connected using a router of a provider or provider, it is a communication protocol called TCP (Transmission Control Protocol) / IP (Internet Protocol) used for connecting remote areas either leased lines or FR networks are used, and (fiber distributed data interface fiber distributed data interface) in the form of 100 mbps LANs used as trunk routes within the structures are Ethernets in the form of 10-mbps LANs or FDDIs.<figref idrefs="S144">2</figref> shows an example of an Internet connection, in which the router in the providers connect to one another maintained by that route link table information is kept ready. Each router is connected to multiple networks, and it is done based on the routing table, a decision to which router connected to the network of a provider, the received data is to go next. The Internet so that at each IP frames (IP datagram) appended IP address is checked, a decision is made, to be sent to which router the IP frame, and the IP frame is sent accordingly. In this way, the IP frames are successively forwarded by all routers running the above-mentioned operation, and finally delivered to a target computer.
<figref idrefs="S145">3</figref> shows the information content of the RFC791 of the IP frame used by the Internet, divided into a control field and a data field. <figref idrefs="S145">4</figref> shows the information content of a similar RFC1883, also divided into a control field and a data field. In both figures, the number of bits is shown between the parentheses.
<patcit><text>EP 0269978</text></patcit> discloses a network adapter to connect a backbone network to a LAN that consists of a plurality of nodes, the network adapter has a table memory. The table memory contains pairs of node addresses and LAN addresses, the respective LAN address the LAN referred to which the node belongs to the respective node address.
However, since the Internet, the system is constructed so that the message transmission is not managed in an integrated manner, can be not say whether the partner with whom a message exchange takes place, is really authorized partners. Consequently, there are safety problems as possible information is intercepted. In practice, also IP addresses are specified separately from the LAN users within multiple LANs, so that there is a need of the LAN user's IP address to be replaced by the Internet IP address when the LAN connected to the Internet becomes. In addition, the transmission quality and said transfer error rate for the Internet transmission forming pipelines from line to line for each LAN is different and practically not uniform. For example, there are problems in trying to send a 10 Mbps TV signal for a video conference, if not the required transmission speed is achieved. Therefore, the Internet can not be disturbed for the communication of a country, use the special security requiring communication of research institutes or the business communications of a company. There is no administrative body, responsible for maintenance of the network, for example, in case of failure by integrating the entire network for further network planning and related tasks. at the LANs and the Internet, the terminals also telephones, fax machines, CATV addition are usually personal computer (PC), and it is difficult to integrate use.
The present invention is based on the above situation and is intended to solve the object to provide an integrated telecommunication system which is able to include a plurality of LANs connected to a data / information transfer using an IP frame ensuring security and reliability of communications ensuring, where not necessarily dedicated lines or the Internet are used. In this way, an economical operation of the telecommunications architecture is to be achieved as well as a unified guarantee of transmission speeds, transmission quality and countermeasures for transmission difficulties. The invention is also intended to provide an integrated telecommunications system which operates using a single information transfer that is not dependent on the type of service, for example, sound or image (moving or still image), text, etc., to connect in this way services among themselves, which were previously handled separately, for example, total intelligence services, analog / digital telephone line services, Internet provider services, fax services, services for computer data exchange, CATV services and the like. Also to be provided by the present invention, an integrated telecommunications system that enables the exchange of messages between different companies with only a slight change in the computer communication address systems that were created independently and separately within each society (for example, in individual universities, research institutes, government agencies, etc. ).
The present invention provides an integrated telecommunications system, the above objects of the invention are achieved as follows: There is provided an access control device that enables multiple computer communication networks or information communication systems are connected with a relay device, ie a retransmission device networking for the access control device takes over. The system has features for routing (routing), by which information is transferred by means of a unified address system. The system is configured such that the mentioned multiple computer communication networks or information communication systems can make an interactive message exchange.
In <figref idrefs="S143">1</figref>Illustrating an example of a conventional arrangement, the field of leased lines for message transmissions within individual societies and between societies is indicated by solid lines. According to the invention this arrangement is replaced by the equivalent of a computer communication network according to the IP technology as a common telecommunications network or communication network, which is indicated by dashed lines.
The above objects of the invention are achieved by a integrated information communication system according to claims 1, 2, 4, 6 and 7, and by an access control apparatus according to claims 8, 9 and 10. FIG.
Specifically disclosed is an ICS user frame (ICS = integrated telecommunications system or integrated communication system), which has a unique ICS user address system ADX, the ICS user frame is converted into an ICS network frame having an address system ADS, based on the management of a conversion table which is provided within an access control device. The system is designed such that in the case of transmission via at least one contained therein VAN according to rules of the above-mentioned address system ADS and when reaching the on-destination access control apparatus, a conversion to the above-mentioned ICS user address system ADX based on the administration by the aforesaid conversion table takes place and thus another externalCommunication device is achieved. Also disclosed is an ICS user frame with a unique ICS user address system ADX, which is converted into an ICS network frame, according to a receiving ICS network address, which was set up in advance in accordance with a logical user messages route in the conversion table, instead of an ICS user address within the above-mentioned ICS user frame is used based on the administration by a conversion table inside the access control device, wherein the system is designed such that in case of a transmission of the above-mentioned ICS network frame to another access control device via at least one VAN, obey the rules that the ICS address system ADS, the transfer destination address of the mentioned ICS network frame either 1 or N, and based on the administration by a present in the aforementioned access control device conversion table a reconversion to the aforementioned ICS network Setting takes place and a further external communica Sion device is achieved.
BRIEF DESCRIPTION OF THE DRAWINGS
In the following the invention with reference to the embodiment will be explained referring to the drawings in more detail. Show it:
<figref idrefs="S143">1</figref> is a block diagram for describing a conventional LAN system;
<figref idrefs="S144">2</figref> a diagram of an example of the form of the Internet;
<figref idrefs="S145">3</figref> a diagram illustrating an IP frame in accordance with RFC791 arrangements;
<figref idrefs="S145">4</figref> a diagram illustrating an IP frame in accordance with the RF C1883 arrangements;
<figref idrefs="S146">5</figref> a block diagram representing schematically the basic principle of the present invention;
<figref idrefs="S147">6</figref> a block diagram of an example of a network in which an inventive ICS (integrated telecommunications or communication system) is built up from several VAN;
<figref idrefs="S148">7</figref> a block diagram of an example of the configuration of the access control device;
<figref idrefs="S149">8th</figref> a block diagram of an example of the configuration of the relaying apparatus;
<figref idrefs="S150">9</figref> a block diagram of an example of the configuration of an intermediate-VAN gateways;
<figref idrefs="S151">10</figref> a block diagram of an example of a configuration of the ICS network server;
<figref idrefs="S152">11</figref> a field diagram illustrating an example of the ICS user address, as used according to the invention;
<figref idrefs="S153">12</figref> a wiring diagram of connection between the logical ICS terminals and the user transmission lines;
<figref idrefs="S154">13</figref> a diagram of the relationship between the ICS user frame and the ICS network frame to be used in the invention;
<figref idrefs="S155">14</figref> a section of a constitutional block diagram of a first embodiment of the invention (company internal communication, communication between different companies);
<figref idrefs="S156">15</figref> a section of a constitutional block diagram of a first embodiment of the invention (communication within a company, communication between different companies);
<figref idrefs="S157">16</figref> a diagram of an example of the conversion table in the access control device;
<figref idrefs="S158">17</figref> a diagram of an example of the intermediate conversion table in the access control device;
<figref idrefs="S159">18</figref> a flow chart of an example of the operation of the access control device;
<figref idrefs="S160">19</figref> a flow chart of an example of the operation of the access control device in the communication between different companies;
<figref idrefs="S161">20</figref> a constitutional block diagram of a second embodiment of the invention (virtual dedicated circuit);
<figref idrefs="S162">21</figref> a diagram of an example of the conversion table in the access control device;
<figref idrefs="S163">22</figref> a flow chart of an example of the operation of the access control device with a virtual leased line connection;
<figref idrefs="S164">23</figref> a constitutional block diagram of a third embodiment of the invention (ICS network server);
<figref idrefs="S165">24</figref> a diagram of an example of the conversion table in the access control device;
<figref idrefs="S166">25</figref> a diagram of an example of the table in the ICS network database;
<figref idrefs="S167">26</figref> a flowchart of an example of the operation within the access control device in a virtual ICS network server connection;
<figref idrefs="S168">27</figref> a constitutional block diagram of a fourth embodiment of the invention (ICS address management server);
<figref idrefs="S169">28</figref> a diagram of an example of the conversion table in the access control device;
<figref idrefs="S170">29</figref> a diagram of an example of a table contained in the ICS address management server;
<figref idrefs="S171">30</figref> a flow chart of an example of the operation of the ICS address management server;
<figref idrefs="S172">31</figref> a constitutional block diagram showing a fifth embodiment of the invention (ICS Name Server);
<figref idrefs="S173">32</figref> a diagram of an example of the conversion table in the access control device;
<figref idrefs="S174">33</figref> a diagram of an example of ICS-name conversion table in the ICS name server;
<figref idrefs="S175">34</figref> a flow chart of an example of the operation of the ICS-name server;
<figref idrefs="S176">35</figref> a section of a constitutional block diagram of an eighth embodiment of the invention (accounting server);
<figref idrefs="S177">36</figref> a section of a constitutional block diagram of an eighth embodiment (accounting server) according to the invention;
<figref idrefs="S178">37</figref> a diagram of an example of the conversion table in the access control device;
<figref idrefs="S179">38</figref> a diagram of an example of the fixed costs Definition Table in the accounting server;
<figref idrefs="S180">39</figref> a diagram of an example of the accounting information database in the billing server;
<figref idrefs="S181">40</figref> a flow chart of an example of the operation of the billing process;
<figref idrefs="S182">41</figref> a detail of a constitutional block diagram of a ninth Ausfhrungsform the invention (ICS frame database server);
<figref idrefs="S183">42</figref> a detail of a constitutional block diagram of a ninth embodiment of the invention (ICS frame database server);
<figref idrefs="S184">43</figref> a diagram of an example of the stored information management table and the box in the ICS frame database server;
<figref idrefs="S185">44</figref> a diagram of an example of the stored information management table and the box in the ICS frame database server;
<figref idrefs="S186">45</figref> a diagram of an example of an ICS user frame, which is used in the ICS frame database server;
<figref idrefs="S187">46</figref> a flow chart of an example of the operation of the communication Example 1 of the ICS frame database server;
<figref idrefs="S188">47</figref> a flow chart of an example of the operation of the communication Example 2 of the ICS frame database server;
<figref idrefs="S189">48</figref> a flow chart of an example of the operation of the communication Example 3 of the ICS frame database server;
<figref idrefs="S190">49</figref> a detail of a constitutional block diagram of a tenth embodiment of the invention (transfer through X.25, FR, ATM, satellite link, a telephone line share, an ISDN line, a CATV cable, a satellite link, IPX frame);
<figref idrefs="S191">50</figref> a detail of a constitutional block diagram of a tenth embodiment of the invention;
<figref idrefs="S192">51</figref> a detail of a constitutional block diagram of a tenth embodiment of the invention;
<figref idrefs="S193">52</figref> a diagram of an example of the conversion table in the access control device;
<figref idrefs="S194">53</figref> a diagram for illustrating the manner of implementation of the frame ICS network of the X.25 and frame format;
<figref idrefs="S195">54</figref> a diagram which illustrates the manner in which the frame is carried out conversion of the ICS network-frame and FR-format;
<figref idrefs="S196">55</figref> a diagram illustrating the manner in which the frame is carried out conversion of the ICS network frame and the ATM format;
<figref idrefs="S197">56</figref> a detail of a constitutional block diagram of an eleventh embodiment of the invention (transfer through X.25, FR, ATM, satellite communications and content of telephone line, ISDN line, CATV line, satellite line, IPX frame);
<figref idrefs="S198">57</figref> a detail of a constitutional block diagram of an eleventh embodiment of the invention;
<figref idrefs="S199">58</figref> a detail of a constitutional block diagram of a twelfth embodiment of the invention (percentage of access control device within the X.25 network and the FR network);
<figref idrefs="S200">59</figref> a detail of a building-block diagram illustrating a twelfth embodiment of the invention;
<figref idrefs="S201">60</figref> a detail of a building-block diagram illustrating a thirteenth embodiment of the invention (the access control device is connected to the further end network);
<figref idrefs="S202">61</figref> a detail of a building-block diagram illustrating a fourteenth embodiment of the invention (provision of access control devices outside the ICS);
<figref idrefs="S203">62</figref> a detail of a constitutional block diagram of a fifteenth embodiment of the invention;
<figref idrefs="S204">63</figref> a detail of a constitutional block diagram of a fifteenth embodiment of the invention;
<figref idrefs="S205">64</figref> a detail of a constitutional block diagram of a fifteenth embodiment of the invention;
<figref idrefs="S206">65</figref> a diagram of an example of the conversion table in the access control device;
<figref idrefs="S207">66</figref> a diagram of an example of the table for defining the relationship between the communication speed and the speed category;
<figref idrefs="S208">67</figref> a flow chart of an example of the operation of the fifteenth embodiment;
<figref idrefs="S209">68</figref> a flow chart of an example of the operation of the fifteenth embodiment;
<figref idrefs="S210">69</figref> a diagram illustrating the ICS user frame according to the allocation of an electronic Sigantur;
<figref idrefs="S211">70</figref> is a diagram showing the ICS user frame before the assignment of an electronic Sigantur;
<figref idrefs="S212">71</figref> a constitutional block diagram of a sixteenth embodiment of the invention;
<figref idrefs="S213">72</figref> a diagram of an example of the conversion table in the access control device;
<figref idrefs="S214">73</figref> a flow chart illustrating an example of the operation of the sixteenth embodiment;
<figref idrefs="S215">74</figref> a diagram for explaining the electronic signature in transmission and reception;
<figref idrefs="S216">75</figref> a constitutional block diagram of a seventeenth embodiment of the invention;
<figref idrefs="S217">76</figref> a constitutional block diagram of an eighteenth embodiment of the invention;
<figref idrefs="S218">77</figref> a diagram of an example of the conversion table in the access control device;
<figref idrefs="S219">78</figref> a diagram of an example of the original conversion table in the ICS conversion table server;
<figref idrefs="S220">79</figref> a diagram of an example of a table contained in the ICS address management server;
<figref idrefs="S221">80</figref> a diagram of an example of ICS-name conversion table in the ICS name server;
<figref idrefs="S222">81</figref> a constitutional block diagram of a nineteenth embodiment of the invention;
<figref idrefs="S223">82</figref> a diagram of an example of the intensive conversion table in the intensive-access controller;
<figref idrefs="S224">83</figref> a diagram of an example of the simple conversion table in the simple access control device; and
<figref idrefs="S225">84</figref> a flowchart of the operation of the nineteenth embodiment.
DESCRIPTION OF THE PREFERRED EMBODIMENTS
<figref idrefs="S146">5</figref> systematically shows the basic principle of the present invention. An integrated information communication system or information communication system (hereinafter "ICS" hereinafter)<figref>1</figref> according to the invention has its own address generation rules for a Rechnerinformation- / communication address, ie, the system has its own, unique address system ADS. Moreover, the system access control devices includes (in this example, 2 to 7), which represent as access points to connect several computers communication networks or information communication equipment, in the present example in the form of a large number of LANs (in this example, belong to the organization X the networks LAN-X1, X2-LAN, LAN-X3 to the organization Y include the networks LANY-Y1, Y2-LAN, LAN-Y3). The networks LAN-X1, X2-LAN and LAN-X3 of the Company X have one and the same address system ADX, and the networks LANY-Y1, Y2 and LAN-LAN Y3 have their own address system ADY. The access control devices<figref>2</figref>. <figref>3</figref> and <figref>4</figref> contain conversion tables to handle the mutual conversion between the address system ADS and the address system ADX. The access control devices<figref>5</figref>. <figref>6</figref> and <figref>7</figref> own conversion tables for the settlement of the mutual conversion between the address system ADS and the address system ADY. The computer-communication data (ICS-frame) inside the ICS<figref>1</figref> use addresses according to the address system ADS of ICS <figref>1</figref>Wherein the message transmission is subject to the IP frames used on the Internet.
The operation for the case is described that a message transmission takes place within a single society. The computer communication data (ICS framework)<figref>80</figref>Which are transmitted from the LAN-X1 in company X, are provided with an address that matches the address system ADX, but are under the administration of the conversion table of the access control device within the ICS <figref>1</figref> subjected to address conversion in accordance with the address ADS system and thus to a frame ICS <figref>81</figref>, This is then within the ICS<figref>1</figref> transmitted according to the rules of the address system ADS until the target access control device <figref>4</figref> reached where it under the administration of the conversion table of the access control device in the computer communication data <figref>80</figref> the address system ADX is converted back to be then sent to the network LAN X3 within society X. In the present context, the inside of the ICS<figref>1</figref> sent and received ICS framework as "ICS network frame", and the outside of the ICS <figref>1</figref> sent and received ICS-frame is referred to as "ICS user frames". The shape of the ICS user frame as agreed a shape that is defined by the RFC791 or RFC1883 as used on the Internet generally, however, the work is described with ICS framework based further below Illustrated embodiments that do not meet the above rule ,
The ICS network frame <figref>81</figref> comprises a network control field <figref>81-1</figref> and a network data field <figref>81-2</figref>Of which the network control field <figref>81-1</figref> the addresses (address system ADS) of the access control devices <figref>2</figref> and <figref>4</figref> stores. The ICS user frame is either a network data field<figref>81-2</figref> or change its data value used or is a data format conversion subjected in accordance with the agreements, which are defined within the ICS, and is a network data field <figref>81-2</figref> used. An example of the arrangements relating to the data format conversion could be the conversion into ciphertext or the data compression, and the access control device<figref>2</figref> could contain reconverting the compressed data to the original data encryption device, a decryption device for reconverting the ciphertext into the original plaintext (ICS user frame), a data compression device, a data-Entkompressionseinrichtung. Within the access control device<figref>2</figref> is the ICS user frame <figref>40</figref> as an ICS network frame <figref>81-2</figref> used, and the process of adding the network control field <figref>81-1</figref> to the ICS network frames <figref>81-2</figref> is called "ICS-encapsulation". In addition, within the access control device<figref>4</figref> the process of eliminating the network control field <figref>81-1</figref> from the ICS network frames <figref>81</figref> called "ICS decapsulation".
Next, the operation for the case of communication between different organizations will be explained. The computer communication data (ICS user frame)<figref>82</figref>That are sent from the LAN-Y2 of the organization Y, are equipped with an addressing system according to the address ADY, but are the address conversion according to the address system ADS in accordance with the management by the conversion table of the access control device <figref>6</figref> within the ICS <figref>1</figref> undergo and an ICS frame <figref>83</figref>, Then this is within the ICS<figref>1</figref> according to the rules of the address system ADS sent, and after reaching the target access control device <figref>3</figref> it is converted in the computer communication data <figref>82</figref> the address ADX system, under the management of the conversion table to be transmitted within the organization to the X-X2 LAN. As address lengths are within the scope of the invention<figref>32</figref> Bits and 128 bits are used, but the invention is in no way limited thereto. Even if the length of the address is changed to values other than 32 bits or 128 bits, this does not change the principle of address conversion, which is the basic idea of the present invention.
According to both computer communications within an organization as well as those between different organizations are made possible by the unified address management by the ICS <figref>1</figref>, Within the LAN inside the user's structure commonly used user terminals for computer communications are involved, and they will be shipped within the VAN (value added network; Value Added Network) they are included on access lines, and it will be sent user data frames, the different data formats and another address system have each service type. For example, an IP address for Internet services, a phone / ISDN number (E.164 address) for telephone services and an X.121 address for X.25 packet services is used. ACCORDING TO the ICS<figref>1</figref> of the present invention, however, is carried out an address conversion (herein referred to as "ICS-address conversion") by using the conversion table of the access control device based on the input ICS user frames, to thereby enable the transmission of information data frames of varying structures which under a single data format and address system are unified, that are converted to ICS framework.
<figref idrefs="S147">6</figref> schematically shows an example in which the ICS <figref>1</figref> according to the invention of a plurality of VAN (van 1, van 2, VAN-3), each of which is managed by a VAN VAN operator. The ICS-1 user logs in to the VAN operator with respect to a user communication line, and the VAN-operator makes a decision on an ICS address, an ICS network address and the like for the user, and registers this information with a circuit type in a conversion table<figref>12</figref> inside the access control device <figref>10</figref>, as in <figref idrefs="S148">7</figref> is shown. The ICS<figref>1</figref> has as access points, which as external connection members to the LANs (or their connections) are used to organizations X and Y, the access control devices <figref>10-1</figref>. <figref>10-2</figref>. <figref>10-3</figref>. <figref>10-4</figref> and <figref>10-5</figref> and also has relay devices <figref>20-1</figref>. <figref>20-2</figref>. <figref>20-3</figref> and <figref>20-4</figref>, Also ICS network server <figref>40-1</figref>. <figref>40-2</figref>. <figref>40-3</figref>. <figref>40-4</figref> and <figref>40-5</figref> and ICS address management server <figref>50-1</figref> and <figref>50-2</figref>, A relay device<figref>20</figref>, As in <figref idrefs="S149">8th</figref> is shown, the communication channel is assigned within each of the vans, and as a connecting element of the VAN-2 and VAN-3 is an intermediate gateway VAN <figref>30</figref> present, as in <figref idrefs="S150">9</figref> is shown. The LANs-<figref>1-1</figref>. <figref>1-2</figref>. <figref>1-3</figref> and <figref>1-4</figref> according to <figref idrefs="S147">6</figref> are connected to the access control devices <figref>10-1</figref>. <figref>10-5</figref>. <figref>10-4</figref> and <figref>10-2</figref> via the user communication lines <figref>36-1</figref>. <figref>36-2</figref>. <figref>36-3</figref> and <figref>36-4</figref> connected.
The access control devices <figref>10</figref> (<figref>10-1</figref>. <figref>10-2</figref>. <figref>10-3</figref>. <figref>10-4</figref> and <figref>10-5</figref>) Are devices which the user communication lines from the user (organizations X and Y) to the ICS <figref>1</figref> at least and according <figref idrefs="S148">7</figref> from a processing device <figref>11</figref> with a CPU and the like, wherein a conversion table <figref>12</figref> as a database for performing address conversion and the like is used. In addition, the access control device includes<figref>10</figref> a line section <figref>13</figref> an input / output interface and an intermediate conversion table <figref>14</figref>, Additionally, it has relay device<figref>20</figref> a transfer function of an ICS network frame and a routing function of Wegfestlegung, and as in <figref idrefs="S149">8th</figref> As shown, it has a processing means <figref>21</figref>Consisting of a CPU and the like, and a forwarding table <figref>22</figref>, The forwarding table or relay box<figref>22</figref> used to determine the communication destination when the ICS network frame within the ICS <figref>1</figref> is transferred. The Inter-VAN Gateway<figref>30</figref> has a processing device <figref>31</figref> of a CPU and the like, and a forwarding table or relay table <figref>32</figref>To define where the ICS network frame to be transmitted between VANs, as in <figref idrefs="S150">9</figref> is shown.
As in <figref idrefs="S151">10</figref> can be seen, is the ICS network server <figref>40</figref> from a processing device <figref>41</figref> and an ICS network database <figref>42</figref>Wherein the use of the database <figref>42</figref> is different. Examples for use include: user-specific data (. Eg name or address of the user) according to the ICS user address, data that do not meet the ICS user address, for example, data on the state of communication difficulties within the VAN or data that is not itself relate directly to the VAN, for example, an electronic library, which kept digital documents and disclosed, for example, public keys for a public encryption system that uses an encryption technology, in which the authenticity of the sender and the recipient is verified. In addition, the electronic library data such. B. included backup data for public key or secret key for a secret encryption system. The processing device<figref>41</figref> accesses the ICS network database <figref>42</figref> to and receives data corresponding to the data to the access control device <figref>10</figref> to send. In addition, the ICS network database works<figref>42</figref> not in isolation, but can interact with other ICS network servers and take of this information. This is done by transmitting and receiving the ICS network frame based on the IP communication technology. Inside the ICS ICS is the network server is the only component, which is equipped with a single ICS network address.
According to the invention for identifying computers, terminals and the like in Inside the address ICS-network frame used as "ICS-network address", and the designated for identifying computers, terminals and the like inside the address ICS user frame used as "ICS user address". The ICS network address is used only within the ICS, one or both are used of two possible types: one with a length of 32 bits and / or with a length of 128 bits. In addition, the ICS user address used one or both of the two types, namely with a length of 32 bits and / or with a length of 128 bits. The logical ICS terminals inside the access control device<figref>10</figref>, The relay apparatus <figref>20</figref>, The Inter-VAN Gateway <figref>30</figref> and the ICS network servers are configured so that each is equipped with an ICS network address to be uniquely identified. In addition, the ICS user address is formed by a VAN upper code and a VAN-Intercode. While the length of the upper VAN codes represented by bits C1 and the length of the internal VAN codes by C2 bits, the ICS user address is such that the total amount of C1 + C2 is either 32 bits or 128 bits corresponds.
According to the invention, no special procedures concerning the decision of the upper VAN codes and internal codes VAN agreed, however, in the case of C1 + C2 = 32 bits, the following example of decision-making procedures are specified: <maths><formula-text>VAN upper code = District Administrative Code (4 bits) || Country code (4 bits) || VAN Code (8 bits)</formula-text></maths><maths><formula-text>VAN-Intercode = VAN district code (4 bits) || VAN access point code (8 bits) || logical user code (4 bits)</formula-text></maths>
<figref idrefs="S152">11</figref> shows such example of an ICS user address. The symbol from "as used herein means the combination of data" a "and" b ", that is data obtained by arranging the data" are formed a "and" b "in this order. The ICS network address can be provided by a similar arrangement in the user network address, namely:<maths><formula-text>ICS network address = District Administrative Code || country code || VAN Code || VAN district code || logical user communication line code</formula-text></maths>
This is the Realisvorrichtung able efficiently locate the transfer target in that it specifies the transfer destination, taking into account the district. The address can be in the same way for the case C1 + C2 = 128 bits set. In the context of the invention, the ICS-frame can be constructed in the manner described below, as long as the relationship C1 + C2 = 32 bits, or C1 + C2 = is obtained 128 bits, regardless of how the box sections for the VAN-top code and the VAN-intercode be designed, or what is the length of each of the sections. In addition, can be designed in deciding the VAN upper code and the VAN-Intercode parts of these codes that they are uniform for the user. That is, the user can create a customized address system. The address values of a comprehensive expression 32 bits ranging from the address 0 up to address (2<sup>32</sup>-1). The present invention is carried out, that an address is formed, which is clearly defined for the user within the range of address 10 × 2<sup>24</sup> to address (10 × 2<sup>24</sup> + 2<sup>24</sup> - 1), or from address (172 × 2<sup>24</sup> + 16 × 2<sup>16</sup>) To address (172 × 2<sup>24</sup> + 32 × 2<sup>16-1</sup>) Or from address (192 × 2<sup>24</sup> + 168 × 2<sup>16</sup>) To address (192 × 2<sup>24</sup> + 169 × 2<sup>16</sup> - 1).
A real or structural transmission path can be separated into several transmission lines or transmission lines and use them accordingly, as in the prior art using the multiplexing method by frame by frame transmission or forwarding (FR = Frame Relay) is realized. According to the user's transmission path is separated in a physical user-transmission path and one or more logical user-transmission links.<figref idrefs="S153">12</figref> shows an example of this aspect, in which a physical user-transmission line (= route) <figref>60</figref> into two logical user-transmission lines <figref>61-1</figref> and <figref>61-2</figref> is separated. In addition to the respective logical user-transmission lines are separate computer communication devices<figref>62-1</figref>. <figref>62-2</figref>. <figref>62-3</figref> and <figref>62-4</figref> connected, and this computer-communication devices <figref>62-1</figref> to <figref>62-4</figref> the ICS user address "4123, 0025, 0026, 4124" assigned. The physical user-transmission line<figref>60</figref> is connected to the access control device <figref>63</figref> connected, and the contact point between the two is called "ICS logical connection". The logical ICS terminal is equipped with only an ICS network address within the ICS. In the example of<figref idrefs="S153">12</figref> are the logical user communication lines <figref>61-1</figref> and <figref>61-2</figref> the access control device <figref>63</figref> , wherein the logical ICS connections <figref>64-1</figref> and <figref>64-2</figref> the contact points are assigned to "8711", the ICS network address "8710" respectively.
As stated above, the ICS network server <figref>40</figref> also equipped with a unique ICS network address, so that the ICS network address may determine that the logical connection ICS or ICS network server is the only of the ICS is. The ICS network server is capable of information with other ICS network servers characterizedexchange that equipped with the corresponding ICS network addresses ICS network frames are sent and received using the IP communications technology. This feature is called "ICS network server communication function". The access controller is also equipped with a unique ICS network address within the ICS and is able to exchange information with other ICS servers via a communication function of the ICS network server. The ICS network server communication function via TCP or UDP (User Datagram Protocol) conventional technology can be realized.
There are two types of ICS-frame according to the present invention, as has been explained above, once the ICS network imitate that is sent or received within the ICS, on the other hand the ICS user frame which is transmitted and received from outside the ICS. Each ICS network frame consists of a control box and a network data field (ICS user frame), and as in<figref idrefs="S154">13</figref> is shown, the network control field from a base field and a field extension. The network data field consists of a user control panel and a user data field, to make use of the ICS can encapsulant or the ICS-de-encapsulation. That is, if the ICS user frames from the access control device forth passes in the ICS, the ICS user frame is a data field of the ICS network frame, and this is the control field (network control field) of the ICS network frame added (ICS-encapsulation). The extension field (EXT) in the network control panel is used for encryption or the like. If no encryption, the extension field is not used.
Inside the network control field of the ICS network frame there is an area for storing the countries address and the intended recipient's address. There are two types of ICS-frame, those with an address length of 32 bits, and those having an address length of 128 bits. A frame format with an address length of 32 bits is according to the RFC791 agreements in accordance<figref idrefs="S145">3</figref> used. In the event that the 32 bits are insufficient for the ICS network address, for example, if a 64 bit full address to be used, according to the RFC791 agreements the missing 32 bits (64 bits - 32 bits) in an Option or extension field inscribed within the network control field of the ICS network frame control field, so that the network address of 64 bits is handled. The following is a narrative description of the user-specific directory mentioned above will be given. In the event that a large number of users a private address (a type of ICS user address) in the range between an address (10 × 2<sup>24</sup>) And an address (10 × 2<sup>24</sup> + 2<sup>24</sup> - 1) has and the length of the ICS user address is 32 bits, the 32 bits are for the ICS network address therefore not sufficient because the ICS network address is assigned according to the ICS user address and for example 64 bits requires. In this case, as set forth above, the missing portion of 32 bits written into the radio button of the ICS network frame control field, so that the network address of 64 bits is usable. The fact that the communication between the same users (called "intra-organization communication") using a private address is possible is described in connection with the first embodiment. Also in the case that the address length is 128 bits, the first embodiment is in accordance with a frame format according to RFC1883 agreements<figref idrefs="S145">4</figref> realized. The source address field inside the network control panel and stored in the destination area address are made to ICS network addresses to match the transmitting ICS network address and the receiving ICS network address. In addition, the source address area is made within the user control panel and stored in the destination address field to address ICS user addresses to match the transmitting ICS user address and the receiver ICS user address.
In the embodiment of the present invention there is no need to follow the recommendations of the RFC791 or RFC1883 for the ICS-frame format. The present invention can run as long as the frame format is such that it uses the address of 32 bits or 128 bits in length. Generally, the ICS receives the ICS user frame as agreed by the RFC791 or RFC1863, but other frame formats within the ICS network can be handled by being with a conversion device (or a change in part) in the ICS user frame converted will.
EMBODIMENT 1 (Base-ICS, intra-organizational communication and inter-organizational communication)
Based on <figref idrefs="S155">14</figref> and <figref idrefs="S156">15</figref> will first be described a first embodiment of the invention, wherein a basic communication will be considered in which the Tranfer target within the ICS is set to the management determined from the receiver-ICS-user based address by a conversion table. throughout the figures<figref>170-1</figref>. <figref>170-2</figref>. <figref>170-3</figref> and <figref>170-4</figref> gateways within the LANs <figref>100-1</figref>. <figref>100-2</figref>. <figref>100-3</figref> and <figref>100-4</figref>And the ICS framework can these gateways <figref>170-1</figref> to <figref>170-4</figref> happen. <figref idrefs="S157">16</figref> shows an example of a conversion table <figref>113-1</figref> in the access control device <figref>111-1</figref>and <figref idrefs="S158">17</figref> shows an intermediate conversion table <figref>114-2</figref> in the access control device <figref>110-4</figref>,
First to the description on the communication between a Anchluss, a LAN <figref>100-1</figref> one working with a private address system ADX organization X and one to a LAN <figref>100-2</figref> the same organization X relate connected port. That is, it is here to establish communication between a terminal of an ICS user address "0012" in the LAN<figref>100-1</figref> has, and a terminal of an ICS user address "0034" in the LAN <figref>100-2</figref> Has. This communication is a typical communication between terminals, the established addresses based on a private address system within a single organization have (ADX in the present example), the communication via the ICS<figref>100</figref> takes place in an interactive manner. This type of communication is referred to as intra-organizational communication service (or simply as an intra-organizational communication) referred. The following description refers to the communications between a terminal connected to a LAN<figref>100-1</figref> the organization X is connected with its own address system ADX, and a port, the LAN <figref>100-3</figref> the organization X is connected with its own address system ADY. It involves communication between a terminal of an ICS user address "0012" in the LAN<figref>100-1</figref> has, and a connection with an ICS user address "1156" in the LAN <figref>100-3</figref>, This communication is typical of a communication between terminals having different address systems in different organizations, wherein the communication is performed using a ICS address system, which can be shared between the two. This type of communication is called Inter-organizational communication service (or inter-organizational communication) referred.
<< Common Common Preparations >>
In describing the present embodiment, the address format and the like are determined in the manner described below, however, the respective specific numerical values and formats are but one example, the present invention is not limited thereto. The ICS network address is represented by a four-digit number, and the sender ICS user address and the receiver ICS user address are both represented by a four-digit number. From the sender ICS user address and the receiver ICS user address are addresses whose upper two digits of "00" are different, used as inter-organizational communication address, and this address is only one value within the ICS<figref>100</figref>, From the sender ICS user address and the receiver ICS user address are addresses whose upper two digits "00" are used as intra-organization communication address, and that address may be a duplicate of another intra-organization communication Dresse inside the ICS<figref>100</figref> be. The conversion table<figref>113-1</figref> in <figref idrefs="S157">16</figref>That in the access control device <figref>110-1</figref> exists, contains the following elements: transmitting ICS network addresses, receiving ICS network addresses, sender ICS user addresses, receiver ICS user address request identifier (ID), speed segments, and the like. The request identifier in the conversion table<figref>113-1</figref> is registered, is such that z. B. a "1" the intra-organizational communications services represents a "2" an inter-organizational communication service represented and a "3" a virtual leased line connection represents (the described later becomes). The speed segment is a link speed, requesting the communication of the ICS network address, including throughput (z. B. the number of ICS frames that are sent within a predetermined time).
<< Preparation of the intra-organization communication >>
The user of the LAN <figref>100-1</figref> and the LAN <figref>100-2</figref> specify the connections and make a report at the VAN operator, so that the intra-organization communication of coupled to the LAN connections can be made via the VAN-1 and VAN. 3 The VAN operator responds to the message and provides the aforementioned ICS network address, the ICS user address, requested identification etc. in the conversion tables of the access control device<figref>110-1</figref> and <figref>110-5</figref>That to the LAN <figref>100-1</figref> and LAN <figref>100-2</figref> are connected, and he also writes the information in the ICS address management server <figref>150-1</figref> on.
The discontinuing of the VAN-1 sizes are as follows: The ICS network address of the logical ICS port of Zugriffsteuervorrichung <figref>110-1</figref> decided on the LAN <figref>100-1</figref> is connected, the ICS network address of the logical ICS port is set in this case, "7711". The intra-organization communication address to the LAN<figref>100-1</figref> connected terminals, the message was carried out from which is set to "0012", and this is used as a transmitter-ICS-user address. As used by the connection with the above addressIntra-organizational communication address is set to "22112", and it is set, and it is used as the sender ICS user address. Next, the intra-organization communication address to the LAN<figref>100-2</figref> connected terminals from which the application was filed, from the logical ICS terminal access controller <figref>110-5</figref> decided on the LAN <figref>100-2</figref> is connected, in this case, the ICS network address is set to "9922" and is used as a receiving ICS network address. Furthermore, from the to the LAN, the ICS user address,<figref>100-2</figref> connected terminal is used, set to "0034", and it is used as a receiver ICS user address.
The number "1" is set as the request identifier, which indicates that an intra-organization communication service has been registered, and there is a registration of the above values in the conversion table <figref>113-1</figref> in <figref idrefs="S157">16</figref>,
The discontinuing of the VAN-3 sizes are the following: Values for the opposite-direction communication (communication from the LAN <figref>100-2</figref> to the LAN-1) are required to be in the conversion table of the access control device <figref>110-5</figref> set the to the LAN <figref>100-2</figref> coupled from which the application was filed. That is, data is set reverse to the transmitting ICS network address and the receiving ICS network address, and the same data is set reverse to the sender ICS user address and the receiver ICS user address. The ICS network address of the LAN<figref>100-2</figref> is set to "9922", and this address is used as the transmitting ICS network address. The address "0034" is set as the sender ICS user address for intra-organizational ICS user address to the LAN<figref>100-2</figref> connected terminal set, and the ICS user address "0012" of the terminal of the other party is used as the receiver ICS user address. In addition, the ICS user address "7711" of the LAN<figref>100-1</figref> used as the receiving ICS network address, and the value "1" as a request identifier (Request-IT) set to indicate that it is intra-organization communication services. The above figures are in the conversion table within the access control device<figref>110-5</figref> enrolled and registered.
<< Operation at the intra-organizational communication >>
The terminal with the ICS user address "0012" sends an ICS user frame P1 to the receiver "0034". This ICS user frame P1 has a tuned station-ICS user address "0012", while the receiver ICS user address "0034" reads.
The process is in connection with <figref idrefs="S159">18</figref> explained. The ICS user frame P1 is added to the access control device<figref>110-1</figref> about the logical Kommunkationsstrecke <figref>180-1</figref> Posted. The access control device<figref>110-1</figref> refers to the conversion table <figref>113-1</figref> in <figref idrefs="S157">16</figref> according to the transmitting ICS network address "7711" (steps S100 and S101) and the receiver ICS user address "0034" of the received ICS user frame, and they know the basis of the value "1" of the request identifier that it is communication to a intra-organizational communication is (step S102). The access control device<figref>110-1</figref> learn that the receiver ICS user address "0034" corresponding receiving ICS network address "9922" is to then be subjected to an ICS encapsulation (step S106). The above-mentioned and in the flow chart<figref idrefs="S159">18</figref> procedures illustrated correspond to the sequence (<figref>1</figref>) At the intra-organizational communication. The sender ICS user address can be used to specify the original being sent the ICS framework.
The access control device <figref>110-1</figref> sends the ICS network frame P2 after the ICS encapsulation to Weiterleitvorrichtung or relay device <figref>120-1</figref>, Since the network address of the network control field within the ICS is fixed by the uniqueness, there is no conflict with other ICS framework. The ICS network frame P2 passes through the Weiterleitvorrichtungen<figref>120-1</figref> and <figref>120-2</figref> due to the receiving ICS network address, to the access control device <figref>110-5</figref> of about VAN-3 reach. The access control device<figref>110-5</figref> Located at the network control field of the ICS network frame P4 and performs ICS decapsulation by to again form an ICS user frame P5, which is the same as the ICS user frame P1, namely the restoration will be based on network data field of the ICS Frame. The access control device then transmits the frame to the LAN<figref>100-2</figref>, The ICS user frame is through the LAN<figref>100-2</figref> directed and transferred to the terminal, which "0034" has the ICS user address.
<< Preparation for Inter-organizational communication >>
As an example of the implementation of an inter-organizational communication which the LAN is a communication between a terminal with an ICS user address "0012", <figref>100-1</figref> is connected with the system address ADX and explains a terminal having the ICS Benutzteradresse "1156" and to a LAN <figref>100-3</figref> is connected with the address system ADY. TheUsers of LAN <figref>100-1</figref> and the LAN <figref>100-3</figref> specify the connection to the VAN, to which they are coupled in order to handle communication through the VAN-1 and VAN-2 can, and they make a registration with the VAN operator. The VAN-operator sets the required values in the conversion table of the access control device, which to the local networks<figref>100-1</figref> and <figref>100-3</figref> is connected, according to the application.
The discontinuing of the VAN-1 values are as follows: The ICS network address of the LAN <figref>100-1</figref> is "7711", the intra-organization communication address from the LAN to the <figref>100-1</figref>Of which was carried out from the application, connected port is maintained, is set to "0012", and this is the transmitter-ICS-user address. The Inter-organization communication address which is supplied to the terminal of the above ICS user address is "2212", and this will be the sender ICS user address (for inter-organization communication). The ICS-network address from the logical ICS-terminal of the access control device<figref>110-4</figref> determined on the ICS network address of the LAN <figref>100-3</figref> is connected, the application was filed from which, with the ICS network address here "8822" is. This is then the receiving ICS network address. In addition, the ICS user address is one of the LAN<figref>100-3</figref> terminal coupled to "1156" is set, and this is then the receiver ICS user address. Outside is set as the request identifier or request ID, the number "2, which means that an inter-organization communication service has been registered and this value is in the conversion table<figref>113-1</figref> registered.
The adjusted with respect to the VAN-2 values are as follows: As a conversion table for the access control device <figref>110-4</figref>To which the LAN <figref>100-3</figref> is connected, an intermediate conversion table <figref>114-2</figref> set up which holds the return data for a certain time, for. example, for 24 hours. That is, with respect to the ICS network address "8822" to which the LAN<figref>100-3</figref> is connected, which uses the inter-organizational communication service, the following values in the access control device <figref>110-4</figref> provided an intermediate conversion table <figref>114-2</figref>Who like a transmitting ICS network address, a sender ICS user address, a receiver ICS user address, a receiving ICS network address, a request identifier and. Setting the intermediate conversion table will be explained in more detail below.
<< Operation at the Inter-organizational communication >>
are the terminal with the ICS user address "0012" sends the ICS user frame F1 in which the sender ICS user address "0012" and the receiver ICS user address "1156" is set. The ICS user frame F1 is the logical user communication path<figref>180-1</figref> to the access control device <figref>110-1</figref> transfer.
The access control device <figref>110-1</figref> takes from the sending ICS network address "7711" (steps S100 and S101) and the receiver ICS user address "1156" to the table <figref>113-1</figref> and learns from the fact that the request ID "2", ie, that it is an inter-organization-Used, ie to establish communication between different organizations is (step S102).
Next, determine the access control device <figref>110-1</figref>That the receiving ICS network address that corresponds to the recipient-user address "1156", the value "8822" (step S104), and then converts the sender ICS user address "0012" to the corresponding inter-organizational user address "2212" (step S105). The access control device<figref>110-1</figref> performs the ICS encapsulation, by adding a network control field as the transmitting ICS network address "7711", the sender ICS user address "2212" and the receiving ICS network address "8822" to the receiver ICS user address "1156", then as an ICS network frame F2 to the so extended data of the relaying device <figref>120-1</figref> sending (S106). The procedures described above bear in the flow chart<figref idrefs="S159">18</figref> the label (2) according to the Inter-organizational communication.
In the above inter-organization communication lead when the sender ICS user address is made within the ICS user frame F1 to the inter-organization address "2212", the transmitter and the receiver, this takes place between different organizations Kommunkation using a Inter-organizational communication address (steps S102 and S104). In this case, the access control apparatus performs<figref>110-1</figref> not the conversion of the sender ICS user address "2212" in the inter-organizational communication address "2212" through, as this is not necessary. The above procedures are in the flow chart of<figref idrefs="S159">18</figref> as Inter-Organization-communication flow (3). The sender ICS user address can be used to specify the original broadcast of the ICS framework.
The referencing means <figref>120-1</figref> transfers the ICS user frame to the access control device <figref>110-4</figref> within the VAN-2 on relay means <figref>120-2</figref> within the VAN-1, the intermediate-VAN Gateway (GW) <figref>130</figref> and the relay means (RT) <figref>120-3</figref> within the VAN-2 based on the receiving ICS network address. This is in conjunction with<figref idrefs="S160">19</figref> elaborated. The access control device<figref>110-4</figref> receives the ICS network frame (step S110), forms from the network data field an ICS user frame F5 (step S111: ICS decapsulation), decides from the receiving ICS network address the logical ICS port for sending ((1) in step S112 ) and sends it to the LAN <figref>100-3</figref> (Step S113). At the same time, in the case that the relation among the transmitting ICS network address "7711", the transmitter-ICS user address "2212", the receiver ICS user address "1156" and the receiving ICS network address "8822" is not in the conversion table within the access control device<figref>110-4</figref> is stored, an intermediate conversion table <figref>114-2</figref> collected ((2) in the step S112). The registration contents of the intermediate conversion table<figref>114-2</figref> according to a process updated so that the content will be deleted if they are not used within 24 hours. The ICS user frame is passed through the LAN 3, and transferred to the terminal, which is "1156" has the ICS user address.
In this embodiment, no adjustment is made in the intermediate conversion table <figref>114-2</figref>, In another embodiment, the conversion table<figref>113-1</figref> not the sender ICS user address (intra-organization) and the sender ICS user address (inter-organization), and it also does not contain the flow (2) in <figref idrefs="S159">18</figref>, Ie the step S105. An advantage of this embodiment is that the number of registers for the conversion table can be reduced to one for the sender ICS user address, if there is the sender ICS user address for the receiver ICS user addresses.
Embodiment 2 (Virtual Leased Line):
Based on <figref idrefs="S161">20</figref> will now be described the operation of a virtual leased line (fixed-switched transmission link) according to the invention. The virtual leased line connection refers to the communication in which the ICS user frame is transmitted in a fixed manner to a receiving ICS network address that is already registered in the conversion table, regardless of the ICS user address within the user control field of the ICS user frame in which the format 1 - to - 1 or 1 - to - N. While the components in accordance with<figref idrefs="S161">20</figref> are the same as in the embodiment 1 in the <figref idrefs="S155">14</figref> and <figref idrefs="S156">15</figref>, There are differences in the in by the contents of registrations <figref idrefs="S162">21</figref> shown conversion table are well founded. In the conversion table of the access control device, the receiving ICS network address is determined from the transmitting ICS network address of dedicated manner, so that the sender ICS user address (intra-organization), the sender ICS user address (inter-organization) and the receiver ICS user address are either not registered or, if registered, are ignored.
The following description relates to the case that the organization X makes use of a virtual link, the communication between the LAN <figref>200-1</figref> the organization X, attached to the access control device <figref>210-1</figref> is connected and the LAN <figref>200-2</figref> the organization X is carried out, which of the access control device <figref>210-5</figref> connected.
<< Preparation >>
The user logs in the VAN-operator to the virtual leased line connection. The VAN-operator determines the ICS network address "7711" of the logical ICS-terminal to the connection point between the access control device<figref>210-1</figref> for coupling the LAN <figref>200-1</figref> the organization X and the logical user communication path <figref>240-1</figref>And detects in a similar manner, the ICS network address "9922" of the logical ICS-terminal to the connection point between the access control device <figref>210-5</figref> for coupling the LAN <figref>200-2</figref> the organization X and the logical user communication line <figref>240-2</figref>, Next, the VAN operator performs a means of conversion table<figref>213-1</figref> the access control device <figref>210-1</figref> follow through: The transmitting ICS network address "7711", the receiving ICS network address "9922" and the request identifier. The example of<figref idrefs="S162">21</figref> shows a request identifier (Request ID) with a value of "3", which is a virtual leased line connection means. Similarly, the VAN operator performs the setting of the conversion table of the access control device<figref>210-5</figref> follow through: The sending ICS net-work address "9922", the receiving ICS network address "7711" and the request identifier.
<< Procedures >>
The operation is in conjunction with <figref idrefs="S163">22</figref> explained. The LAN<figref>200-1</figref> the organization or company X sends an ICS user frame F10 via the logical user communication path <figref>240-1</figref> to the ICS <figref>200</figref>, The access control device<figref>210-1</figref> receives the ICS user frame F10 of the logic ICS port of ICS network address "7711" (step S200 and S201), refers to the request identifier "3" of the originating ICS network address "7711" in the conversion table <figref>213-1</figref>, This is interpreted as a virtual leased line connection (step S202) and reads the receiving ICS network address "9922" (step S203). Next, add the access control device<figref>210-1</figref> a network control field to the ICS user frame F10 in which the receiving ICS network address to "9922" and the transmitting ICS network address is set to "7711" to form an ICS network frame F11 (step S204; ICS encapsulation) , and transmits the frame F11 to the relaying device or relay device <figref>200-1</figref> (Step S205). The relay device<figref>220-1</figref>Which receives the ICS network frame F10, determined by the receiving ICS network address of the ICS network frame F11, the destination address and sends an ICS network frame F12 to the relay device <figref>220-2</figref>, The ICS network frame F12 on the relay device<figref>220-4</figref> within the VAN-3 to the access control device <figref>210-5</figref> transfer.
The access control device <figref>210-5</figref> Located at the network control field of the ICS network frame F13 (ICS decapsulation) and sends the ICS network frame F14 of the logic ICS port of ICS network address "9922" to the logical user communication line <figref>240-2</figref>, Then accept the LAN<figref>200-2</figref> X the ICS user frame F14 of the Company. The transmission may in the same manner from the LAN<figref>200-2</figref> to the LAN <figref>200-1</figref> take place, so that an interactive communication is possible. As is clear that the transmitter and receiver need not necessarily belong to the same organization X, if one uses this method, the ICS user frames from the LAN can also<figref>200-1</figref> the organization X for example, a LAN <figref>200-3</figref> another organization Y are transmitted.
The above description refers to a one-to-one communication, but also a one-to-N communication is possible. For example, multiple ICS network addresses in the conversion table<figref>213-1</figref> the access control device <figref>210-1</figref> be set up, as in <figref idrefs="S161">20</figref> can be seen in conjunction with the transmitting ICS network address "7712". In the present example, two ICS network address "6611" and "8822" is set. The access control device<figref>210-1</figref> forms after receiving the ICS user frame of the logic ICS connection with the ICS network address "7712" a first ICS network frame in which an ICS network control field set to "6611" is added to the receiving ICS network address, and forming a second ICS network frame, in which a network control field is added, in which "8822" is set for the receiving ICS network address, and this network frames to the relay device <figref>220-1</figref> Posted. Accordingly, there will be a one-to-two-communication. Furthermore, it can generally characterized execute that each ICS network frame is transmitted in the manner described above, a one-to-N communication.
Embodiment 3 (ICS network server):
As in <figref idrefs="S164">23</figref> As shown, there is an ICS Network Server <figref>330</figref> from a processing device <figref>331</figref> and an ICS network database <figref>332</figref>, Said of the ICS network database <figref>332</figref> held data include: a question a query expression, a type, response content and network addresses of other ICS network server. The ICS network server<figref>330</figref> analyzing the data portion of the access control device <figref>310-1</figref> received ICS framework, accesses the ICS network database <figref>332</figref> accordingly, receives response contents in accordance with the request expressions (for the case that the flag is "1"), and sends the response received to the access control device <figref>310-1</figref>, In the event that the ICS network database<figref>332</figref> contains no answer contents corresponding to the question expressions (for the case that the flag is "2"), the server asks other ICS network server, and receives from those of the responses corresponding to the requests using the ICS network server communication function and based on the ICS network address of another ICS network server to the response thus obtained finally to the access control device <figref>310-1</figref> to send.
In detail: The following is in the conversion table <figref>313-1</figref> according to <figref idrefs="S165">24</figref> registered as preparation values: the ICS user address "2000" of the ICS network server <figref>330</figref>, The ICS network address "7721" and the request identifier (Request ID) "4". The request identifier "4" means that the ICS user address "2000" a common, used by other users number is (referred to herein as "ICS special number"), similar to the telephone number "119" in Japan. Next, in the ICS network database<figref>332</figref> enrolled in that type of request Q1 is "1", and that the response content "A1" is that the type of query Q2 "2" is that the answer field remains free, and that the ICS network address for further ICS network Server <figref>340</figref> "8844" reads.
Next, the user of the ICS user address "0012" sends an ICS frame F20 (of the question Q1 contains) to the ICS user address "2000" of the ICS network database <figref>332</figref>, The access control device<figref>310-1</figref> empfingt the ICS user frame F20 of the logical ICS terminal of the power section <figref>311-1</figref>, Receives the ICS network address "7711" refers to the conversion table <figref>313-1</figref> and sends an ICS network frame is subjected to encapsulation ICS, the ICS Network Server <figref>320</figref>As determined by the flow in <figref idrefs="S167">26</figref> is shown. The ICS network database<figref>332</figref> finds the answer A1 according to the request Q1, which is part of the ICS frame F20 (steps S300 and S301), and they are the answer A1 to the access control device <figref>310-1</figref> back. The access control device<figref>310-1</figref> sends a reply containing A1 ICS framework of the ICS user address "0012".
The user of the ICS user address "0012" sends an ICS frame F21 (the request contains Q2) to the ICS user address "2000". Access control<figref>310-1</figref> refers to the conversion table <figref>313-1</figref> Respect, and after receiving the ICS network address "7721" sends an ICS frame which is formed by the ICS-encapsulated frame F21. The ICS network database<figref>232</figref> recognizes the type "2", corresponding to the request Q2, in the ICS frame F21 (step S300) and knows that the ICS network database <figref>332</figref> even the answer (A2) has not. Therefore, the ICS network database leads<figref>232</figref> exchange information with another ICS network server <figref>340</figref> including the ICS network communication functions are used, based on the ICS network address "8844" of the ICS network server by, <figref>340</figref> (Step S302) to access controller the answer A2 to the <figref>310-1</figref> surrendered. The access control device<figref>310-1</figref> ICS sends a frame, which contains the answer A2, the ICS user address "0012".
Embodiment 4 (ICS address administration server):
As in <figref idrefs="S168">27</figref> As shown, the ICS address management server is connected to the access control device <figref>410-1</figref> on the ICS network connecting line <figref>460</figref> connected, and he holds a correspondence table <figref>432</figref> with respect to an ICS network address to a logical ICS connection to the line section <figref>411-1</figref> the access control device <figref>410-1</figref> has, and corresponding thereto ICS user address. Examples of the conversion table<figref>413-1</figref> and the correlation table <figref>432</figref> are in the <figref idrefs="S169">28</figref> or. <figref idrefs="S170">29</figref> shown. That is, the ICS address administration server<figref>430</figref> stores the ICS user address "2013", "2014", "1234" and "4500" and the corresponding thereto ICS network address "7711" "7711", "7712" and "7713". Simultaneously, all the information that is to be described in the conversion table, also be information on addresses, for example, records that are associated with the VAN mode included. Moreover, holding the ICS address administration server<figref>430</figref> ICS network addresses several other ICS address administration server, and also the ICS network addresses several ICS name server. In addition, the ICS address administration server<figref>430</figref> capable of communicating using the described in connection with the embodiment 5 ICS name server and the ICS network server communication function and to obtain in this way ICS name corresponding to the ICS user addresses.
The processing device <figref>412-1</figref> the access control device <figref>410-1</figref> can communicate with the ICS address administration server <figref>430</figref> perform using the ICS network server communication function and disclose the value of the ICS network address and obtain the corresponding ICS user address, or can reveal the value of the ICS user address and obtain the corresponding ICS network address. The operation is in conjunction with<figref idrefs="S171">30</figref> explained in more detail. The ICS address administration server<figref>430</figref> checks whether the ICS network address or the ICS user address that part of the access control device <figref>410-1</figref> was asked, in his correspondence table <figref>432</figref> is registered or not (step S400), and then returns a response, if the address is registered (step <figref>401</figref>). If the ICS network address or the ICS user address is not registered in the correspondence table, communicates the ICS address administration server<figref>430</figref> with another ICS address administration server <figref>440</figref> using the ICS network server communication function in order to obtain in this way the ICS user address or the ICS-network address (step S402), and the results of this request in response to the access controller <figref>410-1</figref> go (step S430). According to such a configuration, the access control device<figref>410-1</figref> capable of a request to the ICS address administration server <figref>430</figref> to judge and to obtain either the ICS network address or the ICS user address depends on the other address.
Embodiment 5 (ICS name server):
The ICS user address is problematic in that it is a comprehensive 32 bits binary expression or to a comprehensive 128-bit binary expression that, if anything, can be as difficult to memorize. Accordingly, a method is used, in which an easy to remember "ICS-name" is used.
First, the ICS name is illustrated. The expressed in binary form ICS address includes under<figref idrefs="S152">11</figref> For example, a district administrative code, a country code, a VAN-Code, a VAN-district code, a VAN access point code and a logical user code, these numerical values are arranged in the form of a field to form an expression, for example, in form district administrative code || || country code VAN code || VAN district code || VAN access point code || logical user code. In the ICS nameis the district administrative code, which can be expressed in binary form in the manner described above, for example, expressed as follows: AS (an ICS name component that represents Asia), JP (Japan), VAN # 1 (identification of a VAN), DIS # 1 (identification of a VAN-district codes of the VAN # 1 contains), ACS # 1 (identification of a VAN access point codes, restricted by DIS # 1), USR # 1 (identifier of the logical user code). The components of such agreed ICS names are reversed and points separated to form the ICS name in this way ".": "USR # 1.ACS # 1.DIS # 1.VAN # 1.JP.AS ". In the example case described above, this ICS name be further subdivided so that USR is # 1 divided into USR # 10 and COMP # 10, and ACS is # 1 divided into ACS # 11 and ACS # 12, so that the total ICS name results as follows: USR # 10 COMP # 10. - ACS # 11.ACS # 12.DIS # 1. VAN # 1.JP.AS ".
The ICS name server to which it is a type of ICS network server, will be explained below. As in<figref idrefs="S172">31</figref> can be seen, the ICS name server <figref>550</figref> formed by a processing device <figref>551</figref> and an ICS name conversion table <figref>552</figref>, Said ICS name conversion table <figref>552</figref> for example, includes: the ICS name, type (labeling concerning the existence of an ICS user address that corresponds to the ICS-name), the ICS user address and the like. The type "2" indicates that the ICS network database<figref>232</figref> not corresponding to the ICS name ICS network address contains and consequently the ICS network address must be obtained according to the ICS name from another ICS name server. An example of the conversion table<figref>513-1</figref> is in <figref idrefs="S173">32</figref> shown. Here, another ICS name server that the ICS name "USR # 2.ACS # 2.DIS # 2.VAN # 2. JP.AS "are managed, called with" are removed DIS # 2.VAN # 2.JP.AS "where" USR # 2 "and" ACS # 2 ". The ICS name server<figref>550</figref> analyzes of the access control device <figref>510-1</figref> ICS received frame data field, refers to the ICS-name conversion table <figref>522</figref> the basis of this analysis, is replaced by an ICS user address corresponding to the ICS name and sends it to the access control device <figref>510-1</figref>, Furthermore, based on the ICS user address, a response is made in view of the user address corresponding ICS name. In the event that an ICS user address corresponding to the ICS ICS names in a name conversion table<figref>552</figref> is available, the ICS network communication function is used to obtain the requested ICS user address from another ICS name server that has the ICS user address, so that the resultant of that ICS user address to the access control device <figref>510-1</figref> is sent.
The following describes the procedure by which the connection of the sender ICS user address "0012", the to the LAN <figref>500-1</figref> is connected, an ICS user address is replaced according to the ICS name # 1 "USR # 1.ACS # 1.DIS # 1.VAN # 1.JP.AS". There are two cases here described: In one case, the access control device receives<figref>510-1</figref> Data from the ICS name server <figref>550</figref>In the other case is replaced by the access control device <figref>510-1</figref> Data from another ICS name server <figref>560</figref>,
First, preliminarily an ICS network address "7741" according to the ICS user address "1000" of the ICS name server <figref>550</figref> and a request identifier "4" in the conversion table <figref>513-1</figref> the access control device <figref>510-1</figref> registered. The request number "4" means that the ICS user address "1000" phone number "119" is, when it comes to a specific ICS number that is shared by other users. The receiver ICS user address "2414" according to the ICS name "USR # 1.ACS # 1.DIS # 1.VAN # 1.JP.AS" is in the ICS name conversion table<figref>552</figref> the ICS name server <figref>550</figref> registered. Then, the terminal user sends the sender ICS user address "0012" of the LAN<figref>500-1</figref> an ICS user frame F40 to the access control device <figref>510-1</figref> and requests a transformation of the ICS name # 1 "USR # 1.ACS # 1.DIS # 1.VAN # 1.JP.AS" in an ICS user address. The processing device<figref>512-1</figref> inside the access control device <figref>510-1</figref> receives the ICS user frame F40 of the logic ICS connection in the power section <figref>511-1</figref>, Receives the ICS network address "7711" and then refers to the conversion table <figref>513-1</figref> based on the receiver ICS user address of the ICS-Use Nahmens F40 reference. If the corresponding request identifier "4" is (a connection ICS name server ICS special number), performs the processing device<figref>512-1</figref> ICS encapsulation of the ICS user frame F40 using the obtained ICS network address "7711" and sends a containing an ICS name ICS network frame to the ICS name server <figref>550</figref>,
As in <figref idrefs="S175">34</figref> is shown analyisiert the ICS name server <figref>550</figref> ICS name within the access control device <figref>510-1</figref> received ICS-frame to the processing device <figref>551</figref> and refers to the ICS-name conversion table <figref>552</figref> Reference (step S500). In the event that, within the ICS-name conversion table<figref>552</figref> corresponding to the ICS name ICS user address exists, it is taken, and the ICS network frame F45 with the ICS user address "2014" is applied to the access control device <figref>510-1</figref> transmitted (step S501). In the event that thequeried ICS name is not in the ICS name conversion table <figref>552</figref> located, receives the access control device <figref>512-1</figref> For example, an ICS user frame F41, and in the event that the ICS name # 2 (ie "USR # 2.ACS # 2.DIS # 2.VAN # 2.JP.AS"), which in the ICS user frame F41 is described, not in the ICS-name conversion table <figref>552</figref> is described, receives the ICS name server <figref>550</figref> ICS network address of another ICS name server from the ICS name conversion table <figref>552</figref> using the ICS name (ie based on "DIS # 2.VAN # 2.JP.AS"), and then to get the ICS user address "1130" in accordance with the requested ICS name in that an exchange of information using the ICS -Namenservers <figref>560</figref> and the ICS network server communication function takes place (step S502). The obtained result is the access control device<figref>510-1</figref> transmitted (step S530). The access control device<figref>510-1</figref> exchanges information with the ICS address administration server <figref>570</figref> based on the receiver from ICS user address of the ICS name server <figref>550</figref> has been received and is described in the ICS network frame F54, it receives the ICS network address corresponding to the ICS user address and the address on information that is contained in a table, and writes the data on the resulting ICS user address, the ICS network address and the related information to the addresses in the conversion table <figref>513-1</figref> on. The access control device<figref>510-1</figref> sends the ICS user address "2014" or "1130" of the ICS name server <figref>550</figref> was obtained at a terminal user of the sender ICS user address "0012" of the LAN <figref>500-1</figref>, The ICS user address "0012" is written in the ICS network frame F45. The terminal user with the sender ICS user address "0012" of the LAN<figref>500-1</figref> receives Empfäner-ICS user address "2014" (or "1130"), by the access control device <figref>510-1</figref> was obtained.
Embodiment 6 (ICS name server):
In the embodiment 5, the access control device writes <figref>510-1</figref> no data as that obtained ICS user address, the ICS network address and the like in the conversion table <figref>513-1</figref> a, but writes the data thus obtained to an intermediate conversion table <figref>514-1</figref> on. In this case written in this intermediate conversion table address is deleted after, say, 24 hours.
Embodiment 7 (ICS name server):
In the embodiment 5, the access control device calls <figref>510-1</figref> not the address management server <figref>570</figref> on, but only performs the service of sharing the resulting ICS user address "2014" (or "1130") to the terminal of the ICS user address "0012" from.
Embodiment 8 (booking server):
There are three types of billing systems: The "network billing system" in which the load thus occurs with the fees that the ICS user will be counted and to be sent or received in a communication, the "Information billing system" in which which are charged in that the information transmitted within the ICS user frame is counted, and the "fixed system", in which no load in accordance with the transmitted ICS user frame is done, but rather a constant amount for a certain period (month, year etc. ) will be charged, while the will be registered ICS user address or the like permanently in the conversion table of the access control device. The information-billing system counts and burdened by assignment of the information charges characterizing identifier to the user panel of the user frame. The network billing system and the information billing system steep a "transmitter settlement" is when the transmitter of communication shall bear the fees, the recipient shall bear the fees, so it is a "receiver-billing". are both the network and the information-billing system as a "sales quantities fees system".
<< Configuration >>
The billing system in the ICS network is based on the invention <figref idrefs="S176">35</figref> and <figref idrefs="S177">36</figref> explained. The<figref idrefs="S178">37</figref>. <figref idrefs="S179">38</figref> and <figref idrefs="S180">39</figref> each show an example of the conversion table <figref>813-1</figref>, The definition table for fixed charges <figref>843</figref> and the billing information database <figref>842</figref>,
The setting information for the billing system in the conversion table <figref>813-1</figref> within the access control device <figref>810-1</figref> maintained, and the definition table for fixed charges <figref>843</figref> is in the accounting server <figref>840</figref> held, and in the conversion table <figref>813-1</figref> are included: A setting that displays the network charging or the information-charging, and a set value of the sales amounts-fee system indicating (specifying the sender billing and the receiver-billing), or the fixed Gebührenystem features (stating transmitter and receiver payroll accounting). The sequence is based on the<figref idrefs="S181">40</figref> explained. The access control device<figref>810-1</figref> receives the ICS user frame F50 (Step S800) and reads the type of charging system for everyone in the conversion table <figref>813-1</figref> held ICS framework based on the ICS user address contained in the ICS user frame F50, and it checks the billing condition ( <figref>801</figref>). The access control device<figref>810-1</figref> forms the accounting information in the event that the read type corresponds to the sales volumes fees system, and transmits the accounting information in the form of a billing information frame F51 to the billing server <figref>840</figref>Which one of the ICS network server (step S810). In the event, however, that it is the read type is the fixed fee system, no formation of accounting information and no transfer of billing information in the form of a billing information frame F51 is performed to the billing server<figref>840</figref> (Step <figref>820</figref>).
The accounting server <figref>840</figref> receives the transmitted from each of the access control devices billing information frame F51 and stores the accounting information contained therein. There is a payroll processing device<figref>841</figref> and a billing information database <figref>842</figref> within the accounting server <figref>840</figref>Of which the settlement processing means <figref>841</figref> the billing information frame F51 of the access control device <figref>810-1</figref> receives the accounting information contained in the frame F51 analyzed, and the information in the accounting information database <figref>842</figref> stores. The billing information database<figref>842</figref> uses the ICS network address and the ICS user address as identifiers and stores the accounting information in the form of a database. In addition, stores in the event that the billing system is a sales quantity charge system, the accounting information database<figref>842</figref> the information on the sales amount in the form of a count, which for this count, an upper limit can be set, so that when the count exceeds the set limit, the accounting server <figref>840</figref> the access control device <figref>810-1</figref> indicates that the upper limit is exceeded, so that this message receiving access controller <figref>810-1</figref> terminates that user access. The accounting server<figref>840</figref> is able to pass the stored billing information to other VANs and user using the ICS network server communication function.
(1) Example of the configuration of the network billing, the transmitter-load and the turnover amounts-fee system:
A case will be explained below, in which the organization, the organization X and Y is an intermediate-organization communication (inter-organization communication) using the ICS according to the invention <figref>800</figref> phase out. In this case, the billing system for LANs<figref>800-1</figref> and <figref>800-3</figref> the sales quantities-charge system for network billing, the entire bill of the LAN <figref>800-1</figref> is paid and no information charges debited.
<< Preparations for communication >>
The LANs <figref>800-1</figref>- and <figref>800-3</figref> are respectively connected to the associated access control devices <figref>810-1</figref> or. <figref>810-4</figref> connected.
<< Preparations for charging fees >>
The fees stress condition for the LANs <figref>800-1</figref> and <figref>800-3</figref>Who want to handle the communication, is in the conversion table <figref>813-1</figref> registered. The fees stress conditions for registration in the conversion table<figref>813-1</figref> set based on the transmitting ICS network address, the receiver ICS user address, the receiving ICS network address and the receiver ICS user address. A set value "1" indicates that a network billing is carried out by sales quantity charging with load of the transmitter. Moreover, for the stress by the unit price, a value "1". Since the information fee charging does not take place, is in the relevant column of the conversion table<figref>813-1</figref> a value "0" is set, which means that such a fee-charging does not occur. In the conversion table of the access control device<figref>810-4</figref> the LAN <figref>800-3</figref> A "0" is set for the fixed price system to the access control device <figref>810-4</figref> discourage a payroll processing, since the LAN <figref>800-1</figref> be debited with the charges.
<< Description of accounting operation >>
With respect to the ICS from the terminal of the network address "0012" on the LAN <figref>800-1</figref> transmitted ICS user frame F50 are the billing condition fields of the sender ICS user address and Empfäner-ICS user address in the ICS user frame to the processing device <figref>812-1</figref> within the access control device <figref>810-1</figref> specified (steps S800 and S801) and it is made to the settlement conditions relating to specify the billing system with respect to the network billing from the field (step S810). Since a "1" is set, which means that the billing system is the sales quantity charging system and that a sender debited, reference is made to the accounting unit price reference (step S811), the accounting information is formed (z. B. is the accounting unit price "1" as a unit forthe accounting information is formed) (step S812), and this accounting information is transmitted to the billing server <figref>840</figref> sent in the form of a billing information frame F51 (step S813). In the settlement processing means<figref>841</figref> within the accounting server <figref>840</figref> is the billing counter in the billing information database <figref>842</figref> increased according to the accounting information frame F51 of the access control device <figref>810-1</figref> Accounting information contained (step S814). In the event that the settlement conditions do not correspond to the examples described below, the accounting is done in the manner described herein.
(2) Example of communication with network billing, transmitter load and fixed system:
The following description relates to a case in which the Company X intra-organization communication using the ICS invention <figref>800</figref> performs. In this case, it is in the charging system for the LANs<figref>800-1</figref> and <figref>800-2</figref> a fixed system for network billing, the total calculation amount of the LAN <figref>800-1</figref> is supported and no information about fees billed.
<< Preparations for communication >>
The LANs <figref>800-1</figref> and <figref>800-2</figref> are the associated access control devices <figref>810-1</figref> and <figref>810-5</figref> connected.
<< Preparation to implement the billing >>
The billing condition for LANs <figref>800-1</figref> and <figref>800-2</figref>Which perform communication, is in the conversion table <figref>813-1</figref> registered. The settlement terms are to be registered in the conversion table<figref>813-1</figref> set based on the transmitting ICS network address, the sender ICS user address, the receiving ICS network address and the receiver ICS user address. A value "0" is set to indicate that the network billing is carried out according to the fixed system, and further, a value "1" the transmitter load, according to the billing in accordance with the definition table for fixed costs<figref>843</figref> carried a burden of the charges carrying subscriber. Since the information-billing is not performed, under the heading Information Fees condition of the conversion table<figref>810-13</figref> a value "0" is entered, which non-load means, since no information-billing takes place. A value "0" for application of the fixed system is in the conversion table of the access control device<figref>810-5</figref> the LAN <figref>800-2</figref> registered.
<< Description of the billing process >>
In the ICS user frame is transmitted from the terminal to the ICS network address "0012", the to the LAN <figref>800-1</figref> is connected, the fees condition fields of the sender ICS user address and the receiver ICS user address and the ICS user frame in the processing device <figref>812-1</figref> within the access control device <figref>810-1</figref> specified (steps S800 and S801), and reference is made to the fees and conditions to specify the billing system for network billing in the field (step S810). Since the registered "0" indicating that the billing system is the fixed system, no billing processing occurs in the formation of charge information (step S820). The processing for the purpose of invoicing is done with reference to the definition table for fixed charges<figref>843</figref>, Invoicing is therefore at the expense of LAN<figref>800-1</figref>Because the value "0" according to the transmitter-billing in the definition table for fixed charges <figref>843</figref> is set.
(3) Example of the commun ication with a network billing, receiver load and sales volumes Charge System:
It describes the case that the organization X and Organization Y perform Inter-Orgrnisations communication. In this case, the billing system for LANs<figref>800-1</figref> and <figref>800-3</figref> the sales quantities-charge system for network billing, the whole sum of the LAN <figref>800-3</figref> is accepted and no information charges debited.
<< Preparations for communication >>
The LANs <figref>800-1</figref> and <figref>800-3</figref> are supplied to the corresponding access control devices <figref>810-1</figref> and <figref>810-4</figref> connected.
<< Preparations for the execution of the settlement >>
The Gebübrenbedingung for LANs <figref>800-1</figref> and <figref>800-3</figref>That communicate with each other, in the conversion table <figref>813-1</figref> registered. Charging conditions are set for registration in the conversion table<figref>813-1</figref> with reference to the transmitting ICS network address, the sender ICS user address, the receiving ICS network address and the receiver ICS user address. A value "2" is set to indicate that a network billing is based on the sales quantity charging system, also is to be debited unit price a value "1". Since the information fee charging is not performed, a corresponding value "0" in the category information fees condition of the conversion table<figref>813-1</figref> set. A value of "2", featuring the sales quantity charging system and the recipient strain, is in the conversion table of the access control device<figref>810-4</figref> the LAN <figref>800-3</figref> set as the LAN <figref>800-3</figref> is charged with the invoice.
<< Description of the load operation >>
In the ICS user frame from the terminal of the LAN <figref>800-1</figref> connected ICS network address "0012" is sent, the fee condition fields of the sender ICS user address and the receiver ICS user address in the ICS user frame in the processing device <figref>812-1</figref> within the access control device <figref>810-1</figref> specified (steps S800 and S801), and it is accessed the billing and fees conditions to specify the billing system for network billing from the field (step S810). Since this is a "2" is, which means that the billing system is the sales quantity charging system and a receiver-load occurs, the load information is formed (z. B. formed a price "1" for the load information as load unit ), and the appropriate billing information to the billing server frame<figref>840</figref> Posted. In the settlement processing means<figref>841</figref> within the accounting server <figref>840</figref> is the network billing counter for the LAN <figref>800-3</figref> the billing information database <figref>842</figref> increased according to the accounting information within the accounting information framework provided by the access control device <figref>810-4</figref> was received.
(4) Example of communication with network billing, receiver load and fixed system:
The following description relates to a case in which the organization X performs an intra-organization communication. In this case, the billing system for LANs<figref>800-1</figref> and <figref>800-2</figref> the fixed system or fixed fee system for network billing, the whole sum of the LAN <figref>800-2</figref> taken and no information-billing is performed.
<< Preparations for communication >>
The LANs <figref>800-1</figref> and <figref>800-2</figref> are respectively applied to the associated access control devices <figref>810-1</figref> or. <figref>810-5</figref> connected.
<< Preparations for charging >>
Fees condition for LANs <figref>800-1</figref> and <figref>800-2</figref>Which kommnnizieren with each other, in the conversion table <figref>813-1</figref> registered. Charging conditions are to be registered in the conversion table<figref>813-1</figref> set based on the transmitting ICS network address, the receiver ICS user address, the receiving ICS network address and the Empfäner-ICS user address. It is a value "0" to indicate that the network fee calculation is made on the basis of fixed costs system, also an a receiver-load value indicative of "2" for the bill support in the definition table for fixed charges is set by which the fees provide supporting participants. Since the information fee charging does not take place, is under the heading of information fees condition of the conversion table<figref>813-1</figref> a value "0" indicating that no such stress occurs. In the conversion table of the access control device<figref>810-5</figref> the LAN <figref>800-2</figref> is a fixed cost, the system value indicative of "0".
<< Description of the operation from the calculation >>
As regards the ICS user frame from the terminal of the ICS network address "0012" on the LAN <figref>800-1</figref> is sent, the fee condition fields of the sender ICS user address and the receiver ICS user address in the ICS user frame to the processing device <figref>812-1</figref> within the access control device <figref>810-1</figref> specified (steps S800 and S801), and reference is made to the fees and conditions to specify the billing system for network billing from the field (step S810). Since it is a "0", which means that the fixed system is applied, no payroll processing such. As, the formation of an information-billing (step S820). There is the processing for billing with reference to the definition table for fixed charges<figref>843</figref>, That is, it is invoicing done at the expense of the LAN<figref>800-2</figref>Because the value "2" in accordance with the invoice for the receiver in the definition table for fixed charges <figref>843</figref> is set.
(5) Example of communication with information-billing, transmitter load and sales volumes Charge System:
In the following a case is described in which the X organization, and the organization Y communicate. In this case, the charging system for the LANs<figref>800-1</figref> and <figref>800-3</figref> the information-billing system, no network fee calculation is performed. The whole bill is from the LAN<figref>800-1</figref> carried.
<< Preparations for communication >>
The LANs <figref>800-1</figref> and <figref>800-3</figref> are to the access control devices in question <figref>810-1</figref> and <figref>810-4</figref> connected.
<< Preparations for billing >>
For the charges and conditions for network charges, a value "0" in the conversion table <figref>813-1</figref> set, indicating a no-load, and since accordingly nothing is settled, nothing is entered for the unit price. A value "3" is set to identify the information-billing in line with sales volumes-fee system and the transmitter load. Also, a value "2 is set to be debited Unit Price.
<< Description of billing >>
For from the LAN <figref>800-1</figref> are connected terminal with the ICS Netzwerkadrese "0012" transmitted ICS user frame the charges condition fields of the sender ICS user address and the receiver ICS user address in the ICS user frame to the processing device <figref>812-1</figref> in the access control device <figref>810-1</figref> specified (steps S800 and S801). Reference is made to the fees and conditions to specify the fee system for network communications from the field (step S810). Since this condition is "0", which means that "no fees" so no load is fixed, there is no network fee calculation (step S820). Next, access the billing or charges and conditions of the information charges conditions to specify the conditions for the settlement of Information fee charging. In this case, a value "1", which means that sales volumes fees calculated that at the expense of the consignor. In addition, reference is made to the Exercise Price unit, which performs the weighting of these revenues amount fee, in this case the value "2" is set. Based on the information thus obtained, the accounting information or charge information for each ICS user frames together (z. B. is the stress Unit Price "2" formed by two units of the fee information), and this accounting information is in the form of a billing information frame F51 to the billing server<figref>840</figref> transfer. The settlement processing means<figref>841</figref> in the accounting server <figref>840</figref>Which has received the billing information specifying the information storage field of accounting information database <figref>842</figref> with reference to the transmitting ICS network address, the sender ICS user address, the receiving ICS network address and the receiver ICS user address from the billing information frame F51, and the network billing counter is incremented according to the load information in the billing information frame F51.
(6) Example of communication with billing information, load the receiver and sales quantity charging system:
The case will be described as an inter-organization communication between the organization X and Y takes place. In this case, the charging system for the LANs<figref>800-1</figref> and <figref>800-3</figref> the sales quantities-charge system for billing information, and there is no network billing. The whole bill is from the LAN<figref>800-3</figref> worn, representing the recipient.
<< Preparations for communication >>
The LANs <figref>800-1</figref> and <figref>800-3</figref> are connected to the respective access control devices <figref>810-1</figref> and <figref>810-4</figref> connected.
<< Preparations for charging >>
As fees conditions for network billing, a value "0" in the conversion table <figref>813-1</figref> set, which means that no network load occurs, and because this burden is not carried out, there is no adjustment of the accounting unit price. It is set to indicate that the information charges billed according to the volume of sales fee system and the load of the sender, a value "2" for the information charges conditions. Also, a value "2" for the accounting unit price is set.
<< Description of charging >>
In view of the ICS user frame from the LAN <figref>800-1</figref> terminal connected to the ICS network address "0012" is sent, the fee condition fields from the be Sender ICS user address and the receiver ICS user address and the ICS user frame to the processing device <figref>812-1</figref> in the access control device <figref>810-1</figref> specified (steps S800 and S801), and reference is made to the fees and conditions to specify the billing system for network communications from the field (step S810). As a non-load is adjusted by a "0", no settled using the network fee system (step S820). Reference is made to the fees and conditions for the information charges conditions to specify the conditions for the settlement with respect to the information billing Next. In this case, a value "2" indicates that settled on the sales volumes-fee system and the billing is carried by the receiver, so that a burden to the sales quantity charge system takes place. In addition, the Unit Price, featuring the Wichung sales quantity billing, read, in this case is the value of "2". Next, the accounting information or charge information for each ICS user frame is made based on the information thus obtained (z. B. is the accounting unit price "2" formed by two units of accounting information), and the accounting information is in the form of a billing information frame F51 to the billing server<figref>840</figref> Posted. The settlement processing means<figref>841</figref> in the accounting server <figref>840</figref>Which has received the billing information specifying the information storage field of accounting information database <figref>842</figref> with reference to the transmitting ICS Netzwerkadrese, the sender ICS user address, the receiving ICS network address and the Empfäner-ICS user address from the billing information frame F51, and the network billing counter is incremented according to the charging information in the charging information frame F51.
(7) Example of communication with billing information, load the transmitter and sales amount fee system, the charges and conditions were not pre-registered in a conversion table:
The case will be explained in which a company X and company Y communicate. Charging conditions for communication between the LANs<figref>800-1</figref> and <figref>800-3</figref> are the same as those described above, but there is a difference with the case so far as the values relating to the agreement on the fees and conditions not in the conversion table <figref>813-1</figref> of the LAN <figref>800-1</figref> coupled access controller <figref>810-1</figref> are registered.
<< Preparations for communication >>
The LANs <figref>800-1</figref> and <figref>800-4</figref> are connected to the respective access control devices <figref>810-1</figref> and <figref>810-2</figref> connected.
<< Preparations for charging >>
In this case, in the conversion table <figref>813-1</figref> no fees registered conditions, so that there is no need, a preparation in the access control device <figref>810-1</figref> according to the LAN <figref>800-1</figref> hold true. In the to the LAN<figref>800-4</figref> associated access controller <figref>810-2</figref> be the receiver setup fees conditions for the LAN <figref>800-4</figref> set in the conversion table. In the conversion table<figref>813-1</figref> a value "0" in the information charges condition is set, which is a non-load means. Since no load is applied, there is no adjustment of the charging unit price. A value "3" is set in the information charges conditions, to indicate that an information-billing is done in accordance with the sales quantities-charge system, the load is at the expense of the transmitter. Moreover, for the charging unit price, a value "1".
<< Description of billing >>
In the ICS user frame of the Anchluss the LAN <figref>800-1</figref> with the ICS network address "0012" is, the attempt of a specification of the fees condition fields is done using the sender ICS user address and Empfäner-ICS user address in the ICS user frame using the conversion table <figref>813-1</figref> in the processing device <figref>812-1</figref> the access control device <figref>810-1</figref> (Steps S800 and S801). There are, however, in this case, none of the fields that specify the relevant fees and conditions, is contact with the access control device<figref>810-2</figref> wanted that contains the receiving user, based on the Empfäner-ICS user address of the receiving user (step S802). The access control device<figref>810-2</figref> makes a request to the Charging conditions of the receiving user with the aid of the conversion table in the access control device <figref>810-2</figref>And they are the fees and conditions of the access control device <figref>810-1</figref>, Charging conditions, access control devices, the<figref>810-1</figref> from the access control device <figref>810-2</figref> assumed to be in an intermediate conversion table <figref>814-1</figref> be registered (step S803). Subsequently, in the processing device<figref>812-1</figref> Referring to the fees and conditions to specify the charges and conditions for network communications. Since, however, a "0" is encountered, indicating a non-calculation, there is no networkBilling (step S820). Reference is made to the fees and conditions for the charging information to specify the conditions for settlement in accordance with the information charging Next. In this case, a value "1", which means that a sales quantity billing is supported by the transmitter, and accordingly there is a sales quantity billing. Reference is also made to the charging unit price, which specifies the weighting of sales quantity charging, which in this case, the value "1", so that the weighting of the load is known. Next, the charging information for each ICS user frame is made based on the information thus obtained (z. B. is a charge unit price "1" formed as a unit of the fee information), and this charge information to the billing server<figref>840</figref> sent in the form of a billing information frame F51. The settlement processing means<figref>841</figref> within the accounting server <figref>840</figref>Which has received the charge information, specifies the information storage field in the accounting information database <figref>842</figref> with reference to the transmitting ICS network address and the receiver ICS user address from the billing information frame F51, and the network billing counter is incremented in accordance with the accounting information in the accounting information frame F51.
Embodiment 9 (ICS frame database server)
<figref idrefs="S182">41</figref> and <figref idrefs="S183">42</figref> show an example of ICS <figref>900</figref>Which ICS frame database server <figref>950</figref> and <figref>960</figref> includes corresponding type forth the ICS network servers. The ICS frame database server<figref>950</figref> and <figref>960</figref> storing data based on a requested time basis on the part of the terminals (hereinafter referred to as "ICS-use terminals" hereinafter) using the ICS <figref>900</figref>, Or remove the stored data and send the data to the requester. The ICS frame database server<figref>950</figref> and <figref>960</figref> each consisting of processing devices <figref>951</figref>. <figref>961</figref> Storage information management tables <figref>952</figref>. <figref>962</figref> and boxing <figref>953</figref>. <figref>963</figref>, Examples of the storage information management table<figref>952</figref> and the box <figref>953</figref> and the memory information management table <figref>962</figref> and the box <figref>963</figref> are in the <figref idrefs="S184">43</figref> or. <figref idrefs="S185">44</figref> shown.
Processing Facilities <figref>951</figref> and <figref>961</figref> received by the ICS-use terminal ICS user frames, refer to the usage requirements of the ICS frame database server, which is explicitly specified by the ICS-use terminal, perform a storage instruction of the ICS user frame for the memory information management table <figref>952</figref> and <figref>962</figref> , and (its a store instruction for the information in the boxes <figref>953</figref> and <figref>963</figref> out. The memory information management table<figref>952</figref> and <figref>962</figref> store receipt. appropriate instructions from the processing means<figref>951</figref> and <figref>961</figref> Expressions relating to the management, which is required for each separate ICS-use terminal, for example, the index number of the stored information. The boxes<figref>953</figref> and <figref>963</figref> Save after receiving the command from the processing means <figref>951</figref> and <figref>961</figref> Management numbers stored information for each separate ICS-use terminal, user information, etc. In the following the preparation terms for use of the ICS frame database server <figref>950</figref> and <figref>960</figref> and examples of the communication described with them.
<< Preparation Details >>
The operator of VAN-1 registers the information (in the present embodiment, the ICS user address "0012", etc.) about the user in the storage information management table <figref>952</figref> and the box <figref>953</figref> advance so that the storage of information for a terminal with the ICS user address "0012", which to the local network LAN <figref>900-1</figref> the organization X is connected, can be performed. of the VAN 3 Operator registered in the same manner, the information (in the present embodiment, the ICS user address "0034", etc.) about the user in the storage information management table<figref>962</figref> and the box <figref>963</figref> in advance so that the information storage can be carried out for a terminal, which has the ICS user address "0034" and to the LAN <figref>900-2</figref> the organization X is connected. The ICS uses end user sends an ICS user frame F60 according<figref idrefs="S186">45</figref> to the ICS <figref>900</figref>, This ICS user frame F60 is equipped with the following information in their user control panel: a usage request identifier (an identifier (Identifier), which explicitly use the ICS frame database server indicates) for use of the ICS frame database server, and an information -Operationsbezeichner (an identifier that explicitly specifies the operation to be performed with the information stored in the ICS frame database server). Although the description of the present embodiment is described in such a way that the user of the usage request identifier and the information-operation ID to the user control field of the ICS user frame F60 adds to this way to the usage request of the ICS frame database server by the user reach, such a usage request identifier and the information-operation ID could instead be also attached to the ICS user data field.
<< Examples of communication >>
(1) Communication Example 1 (operation of the ICS frame database server on the sending side):
A to the LAN <figref>900-1</figref> X terminal connected with an ICS user address "0012" of the company shall send a message to a terminal that the LAN <figref>900-2</figref> Company X is connected and the ICS user address "0034", said the ICS frame database server is used. This in<figref idrefs="S187">46</figref> Flowchart shown describes the sequence.
The transmitting terminal transmits a ICS user frame F60 to use the ICS frame database server <figref>950</figref> to the ICS <figref>900</figref>, The ICS user frame F60 is provided on the user control panel with a usage request identifier (transmitting storage user management number, a code that the user of the ICS provides optional, and is used as a search index for the case, the ICS user information stored processed), and an information operation ID (scheduled transfer time, information storage, information transfer, Informationslöschung- or disposal, information completion, etc.). The access control device<figref>900-1</figref>Receiving that user frame (step S900) accesses the usage request identifier of the ICS user frame F60 to the processing means <figref>912-1</figref> (step S901), and for the case that the connection specified by the sending terminal number of the usage request identifier exists, the ICS user frame F60 is supplied to the processing device <figref>951</figref> transfer. The processing unit<figref>951</figref>That has received the ICS user frame F60, refers to the usage request identifier and the information operation ID (step S910) and executes that operation, which is indicated by the information-operation ID.
If the information storage is specified, receives the processing device <figref>951</figref> the usage request identifier (the transmitting storage user management number) and information operation ID (information storage) of the ICS user frame F60, soft was sent by the transmitting terminal to accordingly the receiver ICS user address and the usage request identifier in those Speicherinformations- management table <figref>952</figref> to store that corresponds to the transmitter-ICS-user address of the frame and then to the ICS user data frames in the box <figref>953</figref> save (step S911). Because of to save user frame is sent from the transmitter in a form in which the information is divided into a plurality of ICS user frame, this process takes so long, until the last to be stored under the ICS user frame is displayed, what with Support of information operation identifier (information completion) happens, that is specified in the ICS user frame F60 (step S912).
In the event that the scheduled transfer time is specified (step S913), receives the processing device <figref>951</figref> the usage request identifier (the transmitting storage user management section) and information-operation ID (scheduled transfer time) of the ICS user frame F60, which was sent from the transmitting terminal to accordingly the specified time in the storage information management table <figref>952</figref> write (step S914), and also transmits the processing device <figref>951</figref> in the Box <figref>953</figref> information stored at a predetermined time to the receiver terminal, in which they scheduled transfer time constant monitored (step S915).
In the event that the information transfer is given, receives the processing means <figref>951</figref> the usage request identifier (the administrative number of the sending storage user) and the information-operation ID (the transfer request) of sent from the transmitting terminal ICS user frame F60 to accordingly the information (the ICS user frames) in the box <figref>953</figref> is stored, to the receiving terminal to send (step S916). In addition, when the removal or deletion of information is given, receives the processing device<figref>951</figref> the usage request identifier and the information operation ID (Information eliminate) the skillful of the transmitting terminal ICS user frame F60 to accordingly in the storage information management table <figref>952</figref> and in the box <figref>953</figref> delete stored information (step S917).
(2) communication example 2 (operation of the ICS frame database server on the receiving side):
A terminal that the LAN <figref>900-2</figref> Company X is connected and an ICS user address "0034" has, receives a message from a terminal connected to the LAN <figref>901</figref> Company X is connected and an ICS user address "0012" has what the user box is used. The flowchart in<figref idrefs="S188">47</figref> describes the sequence.
The transmitting terminal transmits a ICS user frame F60 to use the receiver side ICS frame database server <figref>960</figref> to the ICS <figref>900</figref>, The ICS user frame F60 equipped in their user control panel with a usage request identifier (administration number of the receiving storage user: a code of the ICS-use user uses optional, used as an index for the case that the ICS user, the stored information edited) and the information-Operationbezeichner. The ICS user frame F60 by the ICS<figref>900</figref> passing to the access control device <figref>910-5</figref> sent to the receiving terminal is connected (step S920). The processing device<figref>912-5</figref> refers to the usage request identifier of the ICS user frame F60 (step S921), and if the number of the usage request identifier, which was set by the transmitting terminal, exists, it transfers the ICS user frame F60 to the processing device <figref>961</figref>,
The processing device <figref>961</figref>Which has received the ICS user frame F60, checks the information-Bearbeitungsbezeichner (information storage, information transfer, information deletion, information completion, etc.) of the ICS user frame F60 (step S930), stores the public information store the usage request identifier in the storage information management table <figref>962</figref> then according to the sender ICS user address and the receiver ICS user address of the frame, and stores the ICS user frame in the box <figref>963</figref> (Step S931). The want to save ICS user frame is transmitted from the transmitter in the form of a split in several ICS user frame information, so that in this embodiment, the process lasts just as long until the last to be stored under the ICS user frame appears, which with the help of information operation identifier (information completion) occurs that is specified in the ICS user frame F60 (step S932). The processing device<figref>962</figref> notifies the terminal of the receiver, that at the receiving terminal in the ICS frame database server <figref>960</figref> Information is addressed by appending the management number of the receiving storage user, which at one time (z. B. noon) happens, which was agreed upon in advance with the receiving terminal (step S933). The receiving terminal, which has received the message, sends an ICS user frame F60 in which the usage request identifier and the information operation ID (information transfer) are set to the access control device<figref>910-5</figref>, The ICS frame database server <figref>960</figref> sends in the Box <figref>963</figref> stored information to the receiving terminal (step S936), and then the receiving terminal receives in the ICS frame database server <figref>960</figref> stored information (the ICS user frame).
Upon receipt of a frame explicitly the user request identifier and the information-operation ID (information elimination) of the ICS user frame F60 indicates deletes the processing device <figref>961</figref> in the storage information management table <figref>962</figref> and in the box <figref>963</figref> stored information (step S937).
(3) Communication Example 3 (The receiving side may become temporarily unavailable):
For the case that a to the LAN <figref>900-1</figref> the company wants X terminal connected with an ICS user address "0012" to send a message to a terminal, which to the LAN <figref>900-2</figref> Company X is connected and an ICS user address "0034" has, so stores even when the connection between the transmitting terminal and the LAN <figref>900-2</figref> Company X is temporarily unable to come about, the ICS frame database server <figref>960</figref> temporarily addressed to the reception terminal information, and then perform the message transmission if the connection is possible. <figref idrefs="S189">48</figref> shows in flow chart form the corresponding sequence.
The transmitting terminal transmits a ICS user frame F60 to the ICS <figref>900</figref>, And the ICS user frame F60 is equipped in their user control panel with an information operation ID (caching), by means of which information also can be spread when the communication link with the receiving terminal is not possible, for which purpose the information temporarily in the ICS framework database server <figref>960</figref> are cached. The ICS user frame F60 by the ICS<figref>900</figref> to the corresponding to the receiving terminal access controller <figref>910-5</figref> sent this access control device <figref>910-5</figref> receives the ICS user frame F60 (step S940), and the processing means <figref>912-5</figref> checks whether the usage request identifier is present in the ICS user frame F60 or not (step S941), and it refers to the information-operation ID (caching) of the ICS user frame F60 (step S942). If there is a request for a temporary storage, a decision is made whether the reception side terminal is in a state in which a transmission is possible. Once the connection is available, the ICS user frame F60 to the receiving terminal transmitted (step S950), the connection is not possible, the ICS user frame F60 to theprocessing means <figref>961</figref> the ICS frame database server <figref>960</figref> transfer.
The processing device <figref>961</figref> stores the sender ICS user address, receiver ICS user address and the usage request identifier of the ICS user frame F60 in the storage information management table <figref>962</figref>To then the ICS user frame in the box <figref>963</figref> save (step S951). The want to save ICS user frame is transmitted from the transmitter in the form of a plurality of ICS user frame, so that in this embodiment, the process lasts just as long until the last to be stored under the ICS user frame is displayed, which by means of the Information- operation identifier (information completion) happens, that is specified in the ICS user frame F60 (step S952). The processing device<figref>912-5</figref> monitors the communication status of the receiving terminal constantly, and when the reception terminal is ready to receive data, it notifies to the processing unit <figref>961</figref>That the connection is available to the receiver. Upon receipt of the message processing device logs<figref>961</figref> the receiving terminal that information for the recipient in the ICS frame database server <figref>960</figref> standing, and at a time (for example, after 5 minutes), which was previously agreed with the receiving terminal (step S952). The receiving terminal, the message is received, sends an ICS user frame F60 in which the user request identifier (ICS storage user management number) and information-Operationbezeichner (information transfer) are set to the access control device<figref>910-5</figref>, The ICS frame database server <figref>960</figref> sends in the Box <figref>963</figref> stored information to the receiving terminal (step S956), and the receiving terminal receives the stored information of the ICS frame database server <figref>960</figref> (Step S945).
If the processing device <figref>961</figref> receives a frame, indicating explicitly the usage request identifier and the information operation ID (information-elimination) of transmitted from the receiving terminal ICS user frame F60, it erases the memory in the information management table <figref>962</figref> and the box <figref>963</figref> stored information (step S957).
Embodiment 10 (transfer over X.25, ATM, satellite connection and integration of the telephone network, ISDN line, CATV line, satellite link):
The data format by the user is not limited to erfingungsgemäßen ICS ICS user frames to the protocol of RFC <figref>991</figref> or RFC <figref>1883</figref> comply, but can also be applied to the inclusion of the telephone network, the ISDN line, CATV line, the satellite link, IPX. In addition, the relay network of the ICS network frame within the ICS network X.25, FR, ATM, satellite communications etc. handle. As part of the invention, the ATM cells exchanger relay equipment, the ATM network includes cell relay networks.
<figref idrefs="S190">49</figref> to <figref idrefs="S192">51</figref> show an example of the interface conversion in an ICS <figref>1000</figref> according to the invention, consisting of access control devices <figref>1010-1</figref> and <figref>1010-2</figref>, ICS-frame-interface network <figref>1050</figref>, X.25 network <figref>1040</figref>, FR network <figref>1041</figref>, ATM network <figref>1042</figref>, Satellite communication network <figref>1043</figref>, X.25 / ICS network frame converting units <figref>1031-1</figref> and <figref>1031-2</figref>, FR / ICS network frame converting units <figref>1032-1</figref> and <figref>1032-2</figref>, ATM / ICS network frame converting units <figref>1033-1</figref> and <figref>1033-2</figref>, Satellite ICS network frame converting units <figref>1034-1</figref> and <figref>1034-2</figref>, Telephone line conversion units <figref>1030-1</figref> and <figref>1030-2</figref>, ISDN-line conversion units <figref>1029-1</figref> and <figref>1029-2</figref>, CATV line conversion units <figref>1028-1</figref> and <figref>1028-2</figref>, Satellite links Conversion units <figref>1027-1</figref> and <figref>1027-2</figref> and IPX conversion units <figref>1026-1</figref> and <figref>1026-2</figref>, An example of the conversion table<figref>1013-1</figref> in the access control device <figref>1010-1</figref> is in <figref idrefs="S193">52</figref> shown.
The ICS-frame-interface network <figref>1050</figref> is a relay network, which the ICS network frame according to the protocol of RFC <figref>791</figref> or RFC <figref>1883</figref> transfers in the format in which it is located. The X.25 network<figref>1040</figref> is a relay network for Trans vacation of part of a X.25 format, and it has as input / output range X.25 / ICS network frame converting units <figref>1031-1</figref> and <figref>1031-2</figref> for converting ICS network frame in the context of an X.25 format and to perform the reverse transformation. The FR network<figref>1041</figref> is a relay network for transferring part of a frameRelay format, and it has, as input / output part FR / ICS-network frame conversion units <figref>1032-1</figref> and <figref>1032-2</figref> for converting ICS network frame in the context of a FR-format and to perform the reverse transformation. The ATM network<figref>1042</figref> is a relay network for transferring frames of an ATM format, it has as input / output part ATM-I-CS-network frame conversion units <figref>1033-1</figref> and <figref>1033-2</figref> for converting ICS network frames in the context of an ATM format, and for carrying out the reverse transformation. The satellite communication network<figref>1043</figref> is a relay network for transferring the context of a satellite communications format, and it has, as input / output part Satellite / ICS-network frame conversion units <figref>1034-1</figref> and <figref>1034-2</figref> for converting ICS network frame in satellite communication network format and to perform the reverse transformation. The telephone network conversion units<figref>1030-1</figref> and <figref>1030-2</figref> have the function of converting a function equivalent to the physical layer or data link layer (first and second layers of the OSI communication protocol) between the telephone network and the access controller as well as to carry out the reverse transformation. The ISDN line conversion units<figref>1029-1</figref> and <figref>1029-2</figref> have the function of converting a function equivalent to the physical layer or data link layer between the ISDN line and the access control device, and for carrying out the reverse transformation. The CATV line conversion units<figref>1028-1</figref> and <figref>1028-2</figref> have the function of converting a functional equivalent of the physical layer or data link layer between the CATV line and the access controller as well as to carry out the reverse transformation. The satellite-distance conversion units<figref>1027-1</figref> and <figref>1027-2</figref> have the function of converting a function equivalent to the physical layer or data link layer between the satellite link and the access control device, as well as for carrying out the reverse transformation. The IPX line conversion units<figref>1026-1</figref> and <figref>1026</figref> have the function of converting a functional equivalent of the physical layer or data link layer between the IPX line and the access control device, as well as for carrying out the reverse transformation.
(1)
In the following, the case is described that a communication between the access control device <figref>1010-1</figref> and the access control device <figref>1010-2</figref> over the X.25 network <figref>1040</figref> takes place.
The access control device <figref>1010-1</figref> sends the ICS network frame to the X.25 exchanger <figref>10131-1</figref>, The X.25 / ICS network frame converting unit<figref>1031-2</figref> inside the X.25 exchanger <figref>10131-1</figref> converts the access from the control device <figref>1010-1</figref> receiving ICS network frame to appropriate in an X.25 frame format, as in <figref idrefs="S194">53</figref> is shown. Then sends the X.25 exchanger<figref>10131-1</figref> the X.25 format frames in the X.25 network <figref>1040</figref>, The of the X.25 exchanger<figref>10131-1</figref> Sent X.25 format frame is the X.25 network <figref>1040</figref> transmitted and reaches the X.25 exchanger <figref>10131-2</figref>, Next, the X.25 / ICS network frame converter<figref>1031-2</figref> inside the X.25 exchanger <figref>10131-2</figref> the re-conversion of the received X.25 format frame in the ICS Network frame format, and outputs it to the access control device <figref>1010-2</figref> out. The access control device<figref>1010-2</figref> receives the ICS network frame. Network under the ICS<figref>1000</figref>Which by the access control device <figref>1010-2</figref> the X.25 exchanger <figref>10131-2</figref> be transmitted are in the same manner to the access control device <figref>1010-1</figref> transfer.
(2)
There will be described a case in which a communication between the access control device <figref>1010-1</figref> and the access control device <figref>1010-2</figref> over the FR network <figref>1041</figref> takes place.
The access control device <figref>1010-1</figref> sends the ICS network frame. The FR-ICS network frame converting unit<figref>1032-1</figref> inside the FR-exchanger <figref>10131-1</figref> converts the access from the control device <figref>1010-1</figref> received ICS network frame around according to an FR format frame <figref idrefs="S195">54</figref>, Then sends the FR-exchanger<figref>10131-1</figref> the X.25 format frame in the FR network <figref>1041</figref>, The of the FR-exchanger<figref>10132-1</figref> Sent FR format frame is the FR network <figref>1041</figref> passed and reaches the FR-exchanger <figref>10132-2</figref>, The FR / ICS network frame converting unit<figref>1032-2</figref> within the FR exchanger <figref>10132-2</figref> performs a reconversion of the received FR format frame in the format of the ICS network frame, and outputs it to the access control device <figref>1010-2</figref> out. The access control device<figref>1010-2</figref> empfingt the ICS network frame. From the access control device<figref>1010-2</figref> to the FR-exchanger <figref>10132-2</figref> ICS transmitted network frames are in the same manner to the access control device <figref>1010-1</figref> transfer.
(3)
The following describes how a communication between the access control device <figref>1010-1</figref> and the access control device <figref>1010-2</figref> via the ATM network <figref>1042</figref> takes place.
The access control device <figref>1010-1</figref> sends the ICS network frames to the ATM exchanger <figref>10133-1</figref>, The ATM / ICS network frame converting unit<figref>1033-1</figref> within the ATM exchanger <figref>10133-1</figref> converts the access from the control device <figref>1010-1</figref> received ICS network frame in a in <figref idrefs="S196">55</figref> shown ATM format frame. Then sends the ATM exchanger<figref>10133-1</figref> the ATM format frame in the ATM network <figref>1042</figref>, The ATM of the exchanger<figref>10133-1</figref> sent ATM format frame is through the ATM network <figref>1042</figref> passed and reaches the ATM exchanger <figref>10133-2</figref>, Next, the ATM / ICS network frame converter<figref>1033-2</figref> in the ATMexchangers <figref>10133-2</figref> reconversion of the received ATM format frame in the ICS Network frame format, and outputs the data to the access control device <figref>1010-2</figref>, The access control device<figref>1010-2</figref> receives the ICS network frame. The of the access controller<figref>1010-2</figref> to the ATM exchanger <figref>10133-2</figref> ICS transmitted network frames are in the same manner to the access control device <figref>1010-1</figref> transfer.
(4)
In the following, the case is described that transmission between the access control device <figref>1010-1</figref> to the access control device <figref>1010-2</figref> via the satellite communication network <figref>1043</figref> takes place.
The access control device <figref>1010-1</figref> sends the ICS network frame to the satellite transceiver <figref>10134-1</figref>, The satellite / ICS network frame converting unit<figref>1034-1</figref> inside the satellite transceiver <figref>10134-1</figref> converts the access from the control device <figref>1010-1</figref> obtained ICS network frame around in a port within the satellite communications network <figref>1043</figref>, Then sends the satellite transceiver<figref>10134-1</figref> the in a port within the satellite communications network <figref>1043</figref> converted ICS network frame in the satellite communication network <figref>1043</figref>, The in a port within the satellite communications network<figref>1043</figref> converted ICS network frame of the satellite transceiver <figref>10134-1</figref> is sent, by the satellite communication network <figref>1043</figref> passed and reach the satellite transceiver <figref>10134-2</figref>, The satellite / ICS network frame converting unit<figref>1034-2</figref> within the satellite receiver end <figref>10134-2</figref> performs a re-conversion of the received interface within the satellite communications network <figref>1043</figref> in the format of the ICS network frame, and outputs the data to the access control device <figref>1010-2</figref>, The access control device<figref>1010-2</figref> receives the ICS network frame. From the access control device<figref>1010-2</figref> to the satellite transceiver <figref>10134-2</figref> Sent ICS network frames are in the same manner to the access control device <figref>1010-1</figref> transfer.
(5)
In the following a case is described in which a communication with an interface of a telephone line between a user <figref>1060-1</figref>Coupled to a telephone line conversion circuit <figref>1030-1</figref> an access control device <figref>1010-1</figref> is connected, and a user <figref>1060-2</figref> takes place, the telephone line to a converter unit <figref>1030-2</figref> an access control device <figref>1010-2</figref> is connected, wherein the first user causes the call.
The user <figref>1060-1</figref> reports to a telephone line connection at the VAN operator. The VAN operator specifies the access control device<figref>1010-1</figref> for the connection with the user <figref>1060-1</figref> and chooses the logical ICS connection an ICS network address "7721". Next, the VAN-operator information in the conversion table<figref>1013-1</figref> the access control device <figref>1010-1</figref> in a manner that the transmitting ICS network address "7721", the receiving phone number 06-555-9876 ", the receiving ICS network address" 5521 ", the request identifier, etc. are fixed. In the present embodiment, a request identifier "5" means a phone line connection. In the same way, the VAN-operator information in the conversion table<figref>1013-2</figref> the access control device <figref>1010-2</figref> in a that the transmitting ICS network address "5521", the receiving telephone number "03-5555-1234", the receiving ICS network address "7721", the request identifier and the like are determined manner.
The user <figref>1060</figref> sends the telephone number "06-5555-9876" from. The telephone line converter unit<figref>1030-1</figref> converts this received telephone number into a format of the processing device <figref>1012-1</figref> can be read, and sends it to the processing means <figref>1012-1</figref>, The processing device<figref>1012-1</figref>That the telephone number information from the telephone line converter unit <figref>1030-1</figref> has received the ICS network address "7721" refers to the request identifier of the transmitting ICS network address "7721" of the conversion table <figref>1013-1</figref>, This identifies as a telephone line connection and reads the receiving ICS network address "5521" using the telephone number "06-5555-9876". The access control device<figref>1010-1</figref> forms an ICS network frame having a network control field in which the receiving ICS network address "5521" and the transmitting ICS network address is set to "7721", as well as with a network data field containing information for reporting a phone call reception, and sends them information in a network of ICS <figref>1000</figref>, The of the access control device<figref>1010-1</figref> Sent ICS network frame is the network of the ICS <figref>1000</figref> transmitted and reaches the access control device <figref>1010-2</figref>, The access control device<figref>1010-2</figref>That has received the ICS network frame with which the information containing network data field for reporting the telephone call reception, are over the telephone line converter unit <figref>1030-2</figref> a signal with the ICS network address "5521" to the subscriber <figref>1060-2</figref>To report the receipt. Of the participants<figref>1060-2</figref> then sends a response signal.
Upon receipt of the response signal, the telephone line converter unit converts <figref>1030-2</figref> the signal into a format which is obtained by the network of the ICS <figref>1000</figref> can be transferred. The access control device<figref>1010-2</figref> forms an ICS network frame having a network control field in which the receiving ICS network address is set to "7721" is set, and in which the transmitting ICS network address is set to "5521" is set. The ICS network frame also includes a network data field, which contains information, is reported with that a response from the called phone is present, and the network frame is transmitted in the network of the ICS. The of the access control device<figref>1010-2</figref> sent ICS-network frame is passed through the network of the ICS and reaches the access control device <figref>1010-1</figref>, The access control device<figref>1010-2</figref>That has received the ICS network frame with the described network data field for a reply message, are over the telephone line converter unit <figref>1030-1</figref> with the ICS network address "7721" to the subscriber <figref>1060-1</figref> a signal to report the response. Thus, participants can<figref>1060-1</figref> and <figref>1060-2</figref> a full duplex analog signal transmission start (language, etc.), the user <figref>1060-1</figref> Analog signals sends. The telephone line-converter circuit<figref>1030-1</figref>Which receives the analog signals, converts them into an analog information format which can be transmitted through the ICS network. The access control device<figref>1010-1</figref> forms an ICS network frame having a network control field in which the transmitting ICS network address to "7721" and the receiving ICS network address is set to "5521", which is in the network data field analog information, and sends this information to the network the ICS <figref>1000</figref>, The of the access control device<figref>1010-1</figref> Sent ICS network frame is the network of the ICS <figref>1000</figref> transmitted and reaches the access control device <figref>1010-2</figref>, The access control device<figref>1010-2</figref>That has received the ICS network frames to the network the data field containing analog information, outputs the analog information from the analog signal converted for a telephone line interface of the telephone line converter unit <figref>1030-2</figref> with the ICS network address "5521" for the participants <figref>1060-2</figref>, The participants of the<figref>1060-2</figref> transmitted analog signals in accordance with the same procedure to the subscriber <figref>1060-1</figref> Posted.
(6)
In the following a case is described in which a communication with an interface of an ISDN line between a subscriber <figref>1061-1</figref>Coupled to an ISDN-line converter unit <figref>1029-1</figref> an access control device <figref>1010-1</figref> is connected, and a subscriber <figref>1061-2</figref> occurs, the ISDN line to a transducer unit <figref>1029-2</figref> an access control device <figref>1010-2</figref> is connected, the first participant of the call initiating participant.
Of the participants <figref>1061-1</figref> report to the VAN operator to an ISDN line connection. The VAN operator specifies to the subscriber<figref>1061-1</figref> connected access controller <figref>1010-1</figref> and will decide on an ICS network address "7722" for the logical ICS connection. Next, the VAN-operator information in the conversion table<figref>1013-1</figref> the access control device <figref>1010-1</figref> one, especially the transmitting ICS network address "7722", the received ISDN number 06-5555-2222 ", the receiving ICS network address" 5522 ", the request identifier and so on. In the present embodiment, the request identifier "6" means an ISDN line connection. In the same way, the VAN-operator in the conversion table<figref>1013-2</figref> the access control device <figref>1010-2</figref> Information such as the transmitting ICS network address "5522" a, also the receiving ISDN number "06-5555-1111", the receiving ICS network address "7722", the request identifier and the like.
Of the participants <figref>1061-1</figref> sends the ISDN number "06-5555-2222". The ISDN line converting unit<figref>1029-1</figref> converts the received ISDN number into a format of the processing device <figref>1012-1</figref> can be read, and sends this information to the processing means <figref>1012-1</figref>, The processing device<figref>1012-1</figref>That the ISDN number information from the ISDN line converting unit <figref>1029-1</figref> with the ICS network address "7722" has received, referring to the request identifier of the transmitting ICS network address "7722" of the conversion table<figref>1013-1</figref>It recognizes as an ISDN line connection and reads the receiving ICS network address of the receiving ISDN number "06-5555-2222". The access control device<figref>1010-1</figref> forms an ICS network frame having a network control field in which the receiving ICS network address to "5522" and the transmitting ICS network address is set to "7722", the network data field of the network frame contains information to report that to get an ISDN is receiving, and the access controller sends this information in a network of the ICS <figref>1000</figref>,
The of the access control device <figref>1010-1</figref> Sent ICS network frame is the network of the ICS <figref>1000</figref> transmitted and reaches the access control device <figref>1010-2</figref>, This access control device<figref>1010-2</figref>That the ICS network frame with the inscribed in the network data field information for reporting a reception has received, over the ISDN line converting unit <figref>1029-2</figref> a signal having an ICS network address "5522" to the subscriber <figref>1061-2</figref>To report the receipt. Thereafter, the subscriber sends<figref>1061-2</figref> a response signal. Following receipt of the response signal, the ISDN line converter unit converts<figref>1029-2</figref> this signal into a format over the network of the ICS <figref>1000</figref> can be transferred. The access control device<figref>1010-2</figref> forms an ICS network frame having a network control field in which the received ICS network address to "7722" and the transmitting ICS network address is set to "5522", and in which a network data field contains information that is reported by that there is an answer are the ISDN, and the access controller sends this information in a network of the ICS <figref>1000</figref>,
The of the access control device <figref>1010-2</figref> Sent ICS network frame is the network of the ICS <figref>1000</figref> transmitted and reaches the access control device <figref>1010-1</figref>, The access control device<figref>1010-2</figref>Which has the received the ICS network frame information for reporting a network data field containing response, are over the ISDN line converting unit <figref>1029-1</figref> with the ICS network address "7722" is a signal to the subscriber <figref>1061-1</figref> from which signals the response. Thus, participants can<figref>1061-1</figref> and <figref>1061-2</figref> (Voice data, etc.) to start a full-duplex transmission using digital signals, the participants <figref>1061-1</figref> sends the digital signals. The ISDN line converting unit<figref>1029-1</figref>Which has received the analog signals, converts them into a digital information format, which extends over the ICS <figref>1000</figref> can be transferred.
The access control device <figref>1010-1</figref> forms an ICS network frame having a network control field in which the receiving ICS network address to "5522" and the transmitting ICS network address is set to "7722", the network data field of the frame contains digital information, and this frame is in the network of ICS <figref>1000</figref> Posted. The of the access control device<figref>1010-1</figref> Sent ICS network frame is the network of the ICS <figref>1000</figref> transmitted and reaches the access control device <figref>1010-2</figref>, This receives the ICS network frame with the network data field containing the digital information and outputs the digital information in the form of digital signals that are of the ISDN line converting unit<figref>1029-2</figref> with the ICS network address "5522" were converted into an ISDN line interface to the subscriber <figref>1061-2</figref>, The digital signals from the subscriber<figref>1061-2</figref> are sent, are using the same procedure to the subscriber <figref>1061-1</figref> transfer.
(7)
In the following a case is described in which a communication with an interface to a CATV line between a CATV broadcasting station <figref>1062-1</figref>, Connected to a CATV line converter unit <figref>1028-1</figref> an access control device <figref>1010-1</figref> is connected, and a subscriber <figref>1062-2</figref> takes place, which at a CATV line converter unit <figref>1028-2</figref> an access control device <figref>1010-2</figref> connected.
The CATV broadcasting station <figref>1062-1</figref> reports a CATV line connecting with the participants at the VAN operator <figref>1062-2</figref> at. The VAN operator specifies the access control device<figref>1010-2</figref>To which the user <figref>1062-2</figref> is connected and determines with respect to an ICS network address "5523" for the logical ICS connection. Next, the VAN-operator information in a portion of the conversion table<figref>1013-1</figref> the access control device <figref>1010-1</figref> according to the transmitting ICS network address "7723" a, such. as the receiving ICS network address "5523", the request identifier and the like. In the present embodiment, the request identifier "7" means a CATV line connection. In the same way, the VAN-operator in the conversion table<figref>1013-2</figref> the access control device <figref>1010-2</figref> Information, such. As the transmitting ICS network address "5523", the receiving ICS network address "7723", the request identifier and the like.
The CATV broadcasting station <figref>1062-1</figref> sends CATV analog signals. The CATV line converting unit<figref>1028-1</figref> converts the received CATV analog signals into a format, which extends over the ICS <figref>1000</figref> can be transferred. The access control device<figref>1010-1</figref> forms an ICS network frame having a network control field in which the receiving ICS network address to "5523" and the transmitting ICS network address is set to "7723", as well as with a network data field representing the CATV information, and the device transmits the frame in a network of ICS <figref>1000</figref>, The of the access control device<figref>1010-1</figref> Sent ICS network frame is the ICS <figref>1000</figref> transmitted and reaches the access control device <figref>1010-2</figref>, This is after receipt of the ICS network frame with the CATV information forming network data field the CATV information about the CATV line converting unit<figref>1028-2</figref> with an ICS network address "5523" to the user <figref>1062-2</figref> in the form of CATV analog signals, which are converted to a CATV line interface. The CATV analog signals from the subscriber<figref>1062-1</figref> be issued, according to the procedures enstprechenden CATV broadcasting station <figref>1062-1</figref> transfer.
(8th)
Here will be described how a communication with an interface of a satellite link between a user <figref>1063-1</figref>, The distances to a satellite converter unit <figref>1027-1</figref> the access control device <figref>1010-1</figref> is connected, and a subscriber <figref>1063-2</figref> is unwound, the route to a satellite converter unit <figref>1027-2</figref> an access control device <figref>1010-2</figref> connected.
Of the participants <figref>1063-1</figref> and the participants <figref>1063-2</figref> log on to the VAN operator a satellite link between the participants <figref>1063-1</figref> and <figref>1063-2</figref> at. The VAN operator specifies to the user<figref>1063-1</figref> connected access controller <figref>1010-1</figref> and makes a decision as an ICS network address "7724" for the logical ICS connection. In the same manner the VAN operator specifies the access control device<figref>1010-2</figref>That the user <figref>1063-2</figref> is connected and makes a decision on an ICS network address "5524" for the logical ICS connection. Next, the VAN-operator information for a part of the conversion table<figref>1013-1</figref> the access control device <figref>1010-1</figref> according to the transmitting ICS network address "7724" a, for example, the receiving ICS network address "5524", a request identifier and the like. In the present embodiment, the request identifier "8" means a satellite link connection. In the same way, the VAN-operator information in the conversion table<figref>1013-2</figref> the access control device <figref>1010-2</figref> a, for example, the transmitting ICS network address "5524", the receiving network address "7724", the request identifier and the like.
The user <figref>1063-1</figref> transmits satellite signals. The satellite links converter unit<figref>1027-1</figref>Which receives the satellite signals of the satellite link, converts satellite signals into an information format, which extends over the ICS <figref>1000</figref> can be transferred. The access control device<figref>1010-1</figref> forms an ICS network frames to a network control field in which the receiving ICS network address is "5524" is set, while the output ICS network address is set to "7724", the frame also includes a network data field, which includes the satellite signal information and this frame is in the network of the ICS <figref>1000</figref> fed. The ICS network frame from the access control device<figref>1010-1</figref> is sent, is through the ICS network <figref>1000</figref> transmitted and reaches the access control device <figref>1010-2</figref>, This is after receipt of the ICS network frame having included in its data field satellite information, the satellite signal information about the satellite transmission converter unit<figref>1027-2</figref> with the ICS network address "5524" as in suitable for a satellite link interface satellite signals to the user <figref>1063-2</figref>, The satellite-distance signals of the user<figref>1063-2</figref> be issued, according to the same procedures to the subscriber <figref>1063-1</figref> transfer.
(9)
It now will be described the case that a communication with an IPX interface between a terminal with an IPX address 9901 "of a user <figref>1064-1</figref> and a connection with an IPX address "8801" of a user <figref>1064-2</figref> is unwound.
The participants <figref>1064-1</figref> and <figref>1064-2</figref> Report an IPX connection between the terminal with the IPX address "9901" of the user <figref>1064-1</figref> and a terminal with the IPX address "8801" of the user <figref>1064-2</figref> wherein at VAN operator. This specifies the access control device<figref>1010-1</figref>Associated with the subscriber <figref>1064-1</figref> is coupled, and the IPX converter unit <figref>1026-1</figref> with an ICS network address "7725". In the same manner the VAN operator specifies the access control device<figref>1010-2</figref>To which the user <figref>1064-2</figref> is connected, and the IPX converter unit <figref>1026-2</figref> with an ICS network address "5525". Next, the VAN-operator information in a portion of the conversion table<figref>1013-1</figref> the access control device <figref>1010-1</figref> according to the transmitting ICS network address "7725" a, such. as the sender IPX address "9901", the receiver IPX address "8801", the receiving ICS network address "5525", the request identifier and . like In the present embodiment, the request identifier "9" means an IPX connection. In the same way, the VAN-operator information in an area of the conversion table<figref>1013-2</figref> the access control device <figref>1010-2</figref> according to the transmitting ICS network address "5525" a, such. as the sender IPX address "8801", the receiver IPX address "9901", the receiving ICS network address "7725", the request identifier and . like
The terminal with the IPX address "9901" of the user <figref>1064-1</figref> sends an IPX frame with the transmitter-IPX address that is set to "9901", and with the receiver IPX address that is set to "8801". The IPX converting unit<figref>1026-1</figref> the access controller receives the IPX frame and reads the sender IPX address "9901" and the receiver IPX address "8801", and then reads the receiving network address "5525" of the receiver IPX address "8801" and for the sender IPX address "9901", the transmitting ICS network address "7725" from the conversion table <figref>1013-1</figref>, The access control device<figref>1010-1</figref> forms an ICS network frame with a is network control panel, in which the transmitting ICS network address to "5525" and the receiving ICS network address to "7725" is set, the network data field of the frame includes the IPX frame information. The frame is in the network of the ICS<figref>1000</figref> Posted.
The of the access control device <figref>1010-1</figref> Sent ICS network frame over the network of the ICS <figref>1000</figref> transmitted and reaches the access control device <figref>1010-2</figref>, This is after receiving the ICS network frame to the network data field ICS information containing the IPX frame information about the IPX converting unit<figref>1024-2</figref> with the ICS network address "5525" to the subscriber <figref>1064-2</figref> in a converted according to the IPX interface form from. The connection with the IPX address "8801" of the participant<figref>1064-2</figref> receives the IPX frame. On the other hand, according to the same procedures of IPX Frame which is set in the transmitter IPX address "8801" and the receiver IPX address "9901", from the terminal with the IPX address "8801" of the subscriber<figref>1064-2</figref> to the subscriber <figref>1064-1</figref> Posted.
Embodiment 11 (Transfer by X.25, FR, ATM, satellite communications, including the telephone network, the ISDN line, the CATV cable and the satellite link):
In the above embodiment 10 are the X.25 / ICS network frame converting units <figref>1031-1</figref> and <figref>1031-2</figref>, The FR / ICS network frame converting unit <figref>1032-1</figref> and <figref>1032-2</figref>, The ATM / ICS network frame converting units <figref>1033-1</figref> and <figref>1033-2</figref>, The satellite / ICS network frame converting units <figref>1034-1</figref> and <figref>1034-2</figref> each within relay networks, ie within the X.25 network <figref>1040</figref>, The FR network <figref>1041</figref>, The ATM network <figref>1042</figref> and the satellite network <figref>1043</figref>, however, as in the<figref idrefs="S197">56</figref> and <figref idrefs="S198">57</figref> As shown for the embodiment 11, there are the X.25 / ICS network frame converting units <figref>1131-1</figref> and <figref>1131-2</figref>, The FR / ICS network frame converting unit <figref>1132-1</figref> and <figref>1132-2</figref>, The ATM / ICS network frame converting units <figref>1133-1</figref> and <figref>1133-2</figref>, The satellite / ICS network frame converting units <figref>1134-1</figref> and <figref>1134-2</figref> respectively in access control devices <figref>1110-1</figref> and <figref>1110-2</figref>, That is, while in the embodiment 10, the ICS received network frames have been converted and reconverted into formats that on the side of each of the relay networks (X.25 network<figref>1040</figref>, FR network <figref>1041</figref>, ATM network <figref>1042</figref> and satellite network <figref>1043</figref>can be transferred), the conversion is performed by the relay networks in the embodiment 11, the conversion and the reconversion into formats that can be transmitted in each of the relay networks, on the side of the access control devices.
Embodiment 12 (Inclusion of access control devices in relay networks):
In the above embodiment 10 are the X.25 / ICS network frame converting units <figref>1031-1</figref> and <figref>1031-2</figref>, The FR / ICS network frame converting units <figref>1032-1</figref> and <figref>1032-2</figref>, The ATM / ICS network frame converting units <figref>1033-1</figref> and <figref>1033-2</figref>, The satellite / ICS network frame converting units <figref>1034-1</figref> and <figref>1034-2</figref> in each case in the interior of the relay networks, ie inside the X.25 network <figref>1040</figref>, The FR network <figref>1041</figref>, The ATM network <figref>1042</figref> and the satellite network <figref>1043</figref>Wherein the access control devices <figref>1010-1</figref> and <figref>1010-2</figref> are not disposed within the X.25 network, the FR network, the ATM network and the satellite network. however, as in<figref idrefs="S199">58</figref> and <figref idrefs="S200">59</figref> is shown located in the embodiment 12, the access control devices <figref>1120-1</figref>. <figref>1120-2</figref>. <figref>1121-1</figref>. <figref>1121-2</figref>. <figref>1122-1</figref>. <figref>1122-2</figref> and <figref>1123-1</figref> as <figref>1123-2</figref> within each of the relay networks, ie within the X.25 network <figref>1240-1</figref>, The FR network <figref>1241-2</figref>, The ATM network <figref>1242-1</figref> and the satellite network <figref>1243-1</figref>, That is, while in the embodiment 10 is a conversion of the ICS user frames in the ICS network frame and the corresponding re-conversion took place based on the administration by the conversion table within the access control devices outside each relay network, in the present example there is a conversion of the ICS user frames in the ICS network frame (ICS encapsulation) and the corresponding reconversion (ICS decapsulation) due to the management by the conversion table in the interior of each of the aforementioned networks, ie within the X.25 network<figref>1040</figref>, Within the FR network <figref>1041</figref>, Within the ATM network <figref>1042</figref> and within the satellite network <figref>1043</figref>,
Embodiment 13 (connection of the relay network to the relay device):
In the above embodiment 10, the X.25 network <figref>1040</figref>, The FR network <figref>1041</figref>, The ATM network <figref>1042</figref> and the satellite network <figref>1043</figref> each with access control devices <figref>1010-1</figref> and <figref>1010-2</figref> connected, but not with the relay devices. however, as in<figref idrefs="S201">60</figref> is shown in the embodiment 13, the X.25 network <figref>2020-1</figref> to the access control device <figref>2010</figref> and to the relay device (RP) P) <figref>2030</figref> connected. In addition, the FR network<figref>2021-1</figref> to the access control device <figref>2011</figref> and the relay apparatus <figref>2031</figref> connected to the ATM network <figref>2022-2</figref> is on the access control device <figref>2012</figref> and the relay apparatus <figref>2032</figref> connected and the satellite network <figref>2023-1</figref> is on the access control device <figref>2013</figref> and the relay apparatus <figref>2033</figref> connected. It should alsothe X.25 network <figref>2020-2</figref> to the relay devices <figref>2030</figref> and <figref>2034</figref> connected. The FR network<figref>2021-2</figref> is to the relay devices <figref>2031</figref> and <figref>2035</figref> connected. The ATM network<figref>2022-2</figref> is to the relay devices <figref>2032</figref> and <figref>2036</figref> connected and the satellite network <figref>2023-2</figref> is to the relay devices <figref>2033</figref> and <figref>2037</figref> connected. That is, in the present embodiment, the access control devices are arranged such that the X.25 networks<figref>2020-1</figref> and <figref>2020-2</figref>, The FR networks <figref>2021-1</figref> and <figref>2021-2</figref>That ATM networks <figref>2022-1</figref> and <figref>2022-2</figref> and satellite networks <figref>2023-1</figref> and <figref>2023-2</figref> are connected respectively to relay devices.
Embodiment 14 (access control device outside the ICS):
<figref idrefs="S202">61</figref> 14 shows an embodiment of the invention in which the access control device <figref>1210-1</figref> outside the ICS <figref>1200</figref> is provided, ie LAN within the local network<figref>1200</figref> organizing X. Accordingly are also the ICS address administration server <figref>1250-1</figref> and the ICS network server <figref>1260-2</figref> outside the ICS <figref>1200</figref>, Ie within the LAN <figref>1200-1</figref>, The integrated access control device management server<figref>1240</figref> is located in the interior of the ICS <figref>1200</figref>, The integrated access control device management server<figref>1240</figref> has communication functions and the task information to the access control device <figref>1210-1</figref>, The ICS network management server <figref>1250-1</figref> and the ICS network server <figref>1260-1</figref> exchange using the ICS network communication function. comes into contact with the organization X for the time at which the VAN operator and the user-link the ICS<figref>1200</figref> couples, serve the functions of integrated access control device management server <figref>1240</figref> for writing data in the conversion table within the access control device <figref>1210-4</figref>, In addition, the ICS address administration server<figref>1250-1</figref> and the ICS network server <figref>1260-1</figref> each using the appropriate ICS network server communication function to the ICS address administration server <figref>1250-2</figref> and the ICS network server <figref>1260-2</figref> inside the ICS <figref>1200</figref> to communicate. Since the present invention is configured in this manner, a user terminal within the LAN<figref>1200-1</figref> an intra-organization communication and inter-organizational communications run, as explained above in connection with the embodiment. 1 It is also clear that the Intra-organizational communication can be handled by means of the user terminal in the manner described above, even if the ICS address administration server<figref>1250-1</figref> and the ICS network server <figref>1260-1</figref> inside the ICS <figref>1200</figref> . are
Embodiment 15 (speed class and priority level):
<< Configuration >>
As in the <figref idrefs="S203">62</figref> to <figref idrefs="S205">64</figref> is illustrated, the ICS <figref>800-1</figref> Access control devices <figref>8010-1</figref>. <figref>8010-2</figref>. <figref>8010-3</figref> and <figref>8010-4</figref>, A relay device <figref>8020-1</figref>, An ICS address administration server <figref>8025-1</figref> and an ICS network server <figref>8027-1</figref>, These devices via ICS-network communication lines <figref>8030-1</figref>. <figref>8030-2</figref>. <figref>8030-3</figref>. <figref>8030-4</figref>. <figref>8030-5</figref> and <figref>8030-6</figref> are connected, which transmit ICS network frame. The line unit<figref>8011-1</figref>, The processing means <figref>8012-1</figref> and the conversion table <figref>8013-1</figref> are all within the access control device <figref>8010-1</figref> provided. Connected to the multiple logical connections ICS in the management unit<figref>8011-1</figref> are logical ICS connection cables <figref>8051-1</figref>. <figref>8051-2</figref>. <figref>8051-3</figref> and <figref>8051-4</figref>, Where the ICS network address "7721", "7723", "7724" or are "7725" assigned. The ICS communication lines inside the ICS<figref>8000-1</figref> associated speed classes, which characterize the transmission speed for the ICS network frame. For example, the speed classes of ICS connection cables<figref>8030-1</figref>. <figref>8030-2</figref> and <figref>8030-6</figref> all "4", the speed class of the ICS communication lines <figref>8030-3</figref> and <figref>8030-5</figref> reads each "3", and the speed class of the cable <figref>8030-4</figref> is "2". <figref idrefs="S206">65</figref> shows an example of the conversion table <figref>8013-1</figref>, The speed rating is determined by a standard which is the same as that in the conversion table<figref>8013-1</figref> registered speed class. An ICS network address "7811" is the ICS address administration server<figref>8025-1</figref> assigned, the ICS address administration server <figref>8027-1</figref> is an ICS network address assigned to "7821", the server on the ICS network lines <figref>8054-1</figref> and <figref>8054-2</figref> to the access control device <figref>8010-1</figref> are connected.
Of the participants <figref>8400-1</figref>In which it is an ICS communication terminal has an ICS user address "2500" and is connected to the line unit <figref>8011-1</figref> about the logical ICS communication line <figref>8051-1</figref> connected. Of the participants<figref>8400-2</figref>In which it is an ICS communication terminal has an ICS user address "2510" and is by the logical communication line ICS <figref>8052-1</figref> to the line unit <figref>8010-2</figref> connected. Of the participants<figref>8400-3</figref>In which it is an ICS Kommunikatinsterminal, has an ICS user address "3600", and the participants <figref>8400-4</figref>In which it is an ICS communication terminal has an ICS user address "3610", these participants are the management unit <figref>8010-3</figref> via the gateway <figref>8041-1</figref> or. the logical ICS communication line <figref>8053-1</figref> connected.
The procedure for registering the ICS network address and the ICS user address in the conversion table <figref>8013-1</figref> is the same as in the above-discussed embodiments 1 and 2, only the following points are different: in the conversion table <figref>113-1</figref> registered speed is omitted and instead a speed class and a priority level are registered. In addition, the speed class and the priority level in the address management server are<figref>8025-1</figref> together with the associated ICS user address is saved as part of the address-related information.
The speed class is a system in which the transmission or communication speed is represented by numerical values or the like, however not with speed information. For example, the transmission rate of 64 Kbps is class 1, the transmission speed of 128 kbps corresponds to class 2 and so on, the transmission speed of 500 Mbps finally corresponds to Class 7. The higher the number of speed class, the greater the transfer rate.<figref idrefs="S207">66</figref> shows an example of the relationship between the transmission speed and the speed class, although there is no requirement, "7" make the class system to a siebenklassigen system of "1" up to. One can introduce z. B. a finely divided 20-tier system, depending on the progress of technology. Moreover, there is no requirement that the transmission speed exactly with the physical transfer speed of the ICS network lines within the ICS<figref>8004</figref> matches. Rather, the system can be designed such that it accounts for 25% of the physical transmission rate so that the transmission rate has a certain latitude. The priority level is represented by numeric values, here in an 8-stage system, which represents the order of priority in terms of a single speed class when it comes to ICS network frame of the access control device or the relay device to send to the ICS network line , The higher the numerical value for the degree of priority, the better or greater is the priority. In the event, for example, that the relay device two ICS network frame F510 and F511 almost simultaneously receives and thereby the speed class of the frame the same value "3", the priority level of the frame F510 "3", the priority level of the frame F511, however "5 "is, the system sends the ICS network frame F511, which has the higher priority first.
In the embodiment 15, z. B. are the ICS network communication lines <figref>8030-3</figref> and <figref>8030-4</figref> "Within the same communication channel" of the relay device <figref>8020-1</figref> to the access control device <figref>8010-3</figref>And the ICS network communication lines <figref>8030-5</figref> and <figref>8030-6</figref> are "in the same communication channel" of the relay device <figref>8020-1</figref> to the access control device <figref>8010-4</figref>, The communication line may be directed, starting from the access control device to the relay apparatus, or may extend from one relay device to another relay device which is connected to the ICS network communication line. It can within the same channel multiple ICS network communication lines at the same speed class be established, and in this case, in the same ICS network communication line the same speed class be given.
<< Operation >>
In the following, with reference to the <figref idrefs="S208">67</figref> and <figref idrefs="S209">68</figref> the operation based on flow charts explained.
Of the participants <figref>8400-1</figref> sends the ICS user frame F500 with the sender ICS user address "2500" and the receiver ICS user address "3600" to the logical ICS transmission line <figref>8051-1</figref>, The processing device<figref>8012-1</figref> the access control device <figref>8010-1</figref> receives the ICS user frame F500 at the logical ICS connection with the ICS network address "7721" of the line unit <figref>8011-1</figref>, And the same time receive the ICS network address "7721" (step S2001), and it checks whether the ICS network address "7721" their request identifier (ID) in the conversion table <figref>8013-1</figref> registered as "3" has (virtual leased line) or not (step S2002). In this case, no registration of this kind was carried out so that next obtained in the ICS user frame F500 Enrolled receiver ICS network address "3600" according to the ICS network address "7721" (step S2004), and it is checked, whether the ICS network address "3600" has a request ID of "2" is registered in the conversion table (intermediate-organizational communication) or not (step<figref>2005</figref>). In this case there is such a registration, so that the next from the conversion table<figref>8013-1</figref> the receiving ICS network address "5522" is obtained as a preparation for the ICS encapsulation, and from the conversion table <figref>8013-1</figref> drawing a payroll-relevant information (in step S2006), namely "speed class" 3 "and priority level" 3 ". Next, the ICS encapsulation is done by generating an ICS network frame F510, enrolled in the "Speed Class 3" and "priority level 3" (step S2020), and onICS network communication line <figref>8030-1</figref> is added (step S2021).
Although the above explanation relates to the case of an inter-organization communication, wherein the request identifier of the ICS network frame is set to "2" (inter-organization communication), for the case that the request identifier "3" is (virtual leased line), the receiving ICS network address, the speed class and the priority level and the like from the conversion table <figref>8013-1</figref> receive, and also is relevant to billing information (step S2003). In the event that the request identifier is "1" (intra-organization communication) are selected from the conversion table<figref>8013-1</figref> the receiving ICS network address, the speed class, the priority level and brought the like, also payroll-relevant information (step S2011). In the event that the request identifier "4" is (ICS communication with a network server) are selected from the conversion table<figref>8013-1</figref> the receiving ICS network address and brought the like, also is used for billing benotigte information (step S2013), then after encapsulation of the frame to the ICS network server <figref>8027-1</figref> is sent.
The thus-formed ICS network frame F510 reaches the relay means <figref>8020-1</figref> on the ICS network line <figref>8030-1</figref>, It is now assumed, another ICS network frames reach the relay device F511<figref>8020-1</figref> on the ICS network line <figref>8030-2</figref> virtually at the same time. This ICS network frame F511 has been of the participants<figref>8400-2</figref> sent as ICS user frame F501, was the logical ICS-line <figref>8052-1</figref> at the access control device <figref>8010-2</figref> has arrived, and is subjected at the point of an ICS Ankapselung to become an ICS network frame F511, and the relay means have <figref>8020-1</figref> by transmission via the ICS network line <figref>8030-2</figref> reached. After arrival of the ICS network frame F510 and the ICS network frame F511 (step S2030) checks the device relay<figref>8020-1</figref> under the management by the processing device <figref>8021-1</figref> first the relay table <figref>8022-1</figref>To decide which network cable must be used for the ICS network frame F510 and F511, which means it takes delivery channels (step S2031) and receives a channel separation in (step S2033). In the present embodiment 15 have both ICS network frames F510 and F511 a destination address of the transmission channel from the relay device<figref>8020-1</figref> to the control device <figref>8010-3</figref>, And there are two ICS network lines, namely the ICS network lines <figref>8030-3</figref> and <figref>8030-4</figref>, Next, read the relay means<figref>8020-1</figref> in the control field of the ICS network frame F510 and F520 registered speed class and separates the ICS network frame according to the respective speed class (step S2041). Subsequently, the procedures are performed separately for each separate rate class.
In the case of the present embodiment 15, the speed class is each of the two ICS network frame F510 and F511 "3". Next, same speed class, the priority level is for each of the ICS network frame read, inscribed in the control part of the ICS network frame, and that ICS-frame which has a higher priority, will be the first sent (step S2042). If the priority level is equal, then some of the context of the first. As a result of the above process sends the relay means<figref>8020-1</figref> the ICS network frame F511 as the first on the ICS network line <figref>8030-3</figref> and then sends the ICS network frame F510 through the line <figref>8030-3</figref>,
If it appears from the above procedures that only ICS network lines are available, the transmission rate is lower than that corresponding to the registered in the control field of the ICS network frame F510 speed class, are in the relay Workfile <figref>8023-1</figref> Information relating to the slower operation enrolled because slower transmission speeds, ie sender ICS user address and the receiver ICS user address that are specified in the relevant ICS network frame, the time of communication processing (year, month, day, hour, minute, second etc.). The recorded contents of the relay work file<figref>8023-1</figref> are the participants at the request of the ICS <figref>8000-1</figref> notified.
According to the above procedures F511 and F510 the ICS network frame F511 is of the two ICS network frame brought forward with the higher priority and reaches the access control device <figref>8010-3</figref>After being on the ICS network communication line <figref>8030-2</figref> was transferred. The ICS network frame F511 is an ICS decapsulation subjected, will the ICS network frame F501 and reaches the participants<figref>8400-4</figref> with the ICS user address "3610" of the logic ICS communication <figref>8053-1</figref>, The ICS network frame F510 is an ICS decapsulation subjected, will the ICS network frame F500 and reaches the user<figref>8400-3</figref> with the ICS user address "3600" of the logic ICS communication <figref>8053-1</figref>,
Next options regarding the operation of the priority level will be explained. In the event that the speed class and theDegree of priority in the conversion table <figref>8013-1</figref> are recorded, are copied to the ICS network frames in the course of ICS-encapsulation, checks the processing means <figref>8012-1</figref> the inscribed in the ICS user frame control field, to be processed in length, and only in the case that the ICS user frame is the same length or shorter than a predetermined value (eg., 256 bytes), a the priority level corresponding value is to "1" increases and copied into the ICS network frame. Thus, in the limited circumstances short ICS user frame this within the ICS<figref>8000-1</figref> are transmitted with priority. This allows the ICS-8000-1 operator to easily realize a service in which the priority short ICS user frame is increased, ie the communication service can also be offered with elevated charges. As for the user, so they will be increased by short ICS user frame throughput. Whether use is made of this option or not, for example, is determined separately for each access control device.
One can make use of a method, in which only the speed class is implemented using the above method without the priority level is performed, ie all ICS user frames have the same priority level. In other embodiments, the conversion table contains<figref>8013-1</figref> not the sender ICS user address (intra-organizational and inter-organizational). Also in these cases there is no change, since the flow chart of<figref idrefs="S208">67</figref> in no way related to the sender ICS user address.
Embodiment 16 (assigning an electronic signature to the ICS user frame):
Hereinafter, an embodiment will be described, are electronically signed with the ICS user frame, it is certain that an ICS user frame has passed through an access control device. In addition, the ICS user frames are encrypted if desired in the embodiment now described. First, we will explain which technology of the electronic signature in this embodiment passes used. To make use of an electronic signature m, there is a signer for the formation of the electronic signature and a verifier for verifying the electronic signature. The signer also forms a pair of keys, a signature key and a verification key KPa KSa. The signer retains the signature key KSa secret and disclosed the verification key KPa in one way or another. The signer "a" using the secret signature key KSa held only by the signer "a" to form an electronic signature σ which depends on data m and the signature key KSa. This can be by the following expression (1) describe:<maths><formula-text>σ = SING (KSa, h (m)) (1)</formula-text></maths>
Now "SIGN" a signature function representing the function of the signature, the function y = h (m) is a control function for the electronic signature, which has the task to compress the data m in short data. The verifier "b" makes use of the disclosed verification key KPa and verifies the authenticity of the electronic signature σ by the following relationship:<maths><formula-text>ν = TEST (σ, kPa, h (m)) (2)</formula-text></maths>
In the event that ν = 1, this means that the electronic signature σ and the data m both are correct, that the electronic signature σ and the data m to generate the electronic signature σ not been rewritten, and that no non-authorized tampering attempt has occurred. In the event that ν = 0, this means that either the electronic signature σ, the data m, or both, are not correct. The verification key KPa is made extensively publicized by a public key information service. The service performs operation reports for publication of keys by or published by the key public displays. The peculiarity of the signature function SIGN, which makes the calculation of the signature key KSa even with regard to the verification key KPa practically impossible, is generally known.
Next, the procedure of assigning an electronic signature to the ICS user frame shall be explained. Objects of the electronic signature are the following: a "time / location parameter P1" representing conditions which relate to the time and place of formation of the electronic signature, ie year / month / day / hour / minute / second of the electronic signature, the operator of the access control device or the identification code of the access control device, and the "signature function parameter P2", which represents the signature function SIGN, also the type of control function h (m) or the length of the signature key. In a numerical representation of this by the following equation (3) is expressed:<maths><formula-text>σ = SIGN (KSa, h (m) (3)</formula-text></maths>where m = UF || P1 || P2.
UF represents the ICS user frame before the ICS encapsulation or the ICS user frame, after it again in the original Form was sent by ICS decapsulation. The participants on the receiving end receives the ICS user frame UF, the time / location parameter P1, the signature function parameter P2 and the electronic signature σ to the ICS user frame on the receiving side as UF || P1 || 2 || σ. This is in<figref idrefs="S210">69</figref> shown. Furthermore, there is a method in which the area for writing the parameters P1 and P2 and the electronic signature σ in the ICS user frame UF is released, as in<figref idrefs="S211">70</figref> is shown. In this case, the electronic signature σ generated such that it appears as follows, where the open area is designated in the ICS user frame UF by "data":<maths><formula-text>σ = SIGN (KSa, h (m)) (4)</formula-text></maths>where m = data || P1 || P2.
The verification of the signature is as follows: <maths><formula-text>ν = TEST (σ, kPa, h (m)) (5)</formula-text></maths>where m = data || P1 || P2.
In the event that the ICS user frame UF a length of 2048 bytes has (for example) and the length of UF || Pa || P2 || σ2448 bytes is (2048 bytes + 400 bytes), it is therefore necessary that the frame length in the control field of the ICS user frame UF representing field (z. B. the field according to the total length. <figref idrefs="S145">3</figref>) Of 2048 bytes to rewrite 2448 bytes. This raises the rewritten ICS user frame UF '. For the case that making use of such an embodiment. there is the electronic signature σ follows:<maths><formula-text>σ = SIGN (KSa, h (m)) (6)</formula-text></maths>where m = UF '|| P1 || P2.
The verification of the signature is as follows: <maths><formula-text>ν = TEST (σ, kPa, h (m)) (7)</formula-text></maths>where m = UF '|| P1 || P2.
In the present embodiment 16 of the order can UF, P1 and P2 relative to be reorganized to σ example the electronic signature = SIGN (KSa, h (m)) to be calculated as m = P1 || P2 || UF and P1 || P2 || || σ UF in the ICS user frame the receiving side adjust. In the present embodiment, the encryption function is represented by y = ENC (K1x), the decryption function is represented in the form x = DEC (K2y). Where "x" means plain text data, "y" means encrypted data ENC represents an encryption function, DEC represents a decryption function, K1 represents a key to encrypt, and K2 is a key for decrypting. The electronic signature is also called a digital signature. A description can be found for. B. New Direction in Cryptography (a paper by W. Diffie and ME Hellman, IEEE IT. Vo.1. IT-22 No. 6, pp. 644-654, 1976) and "Encryption and Information Security (Shigeo Tsujii, 1990 Shokodo, pages 127-138).
<< Configuration >>
As in <figref idrefs="S212">71</figref> is shown, the ICS <figref>9000-1</figref> Access control devices <figref>9010-1</figref>. <figref>9010-2</figref> and <figref>9010-3</figref> and a relay device <figref>9120-1</figref>, And these devices are by ICS network communication lines <figref>9030-1</figref>. <figref>9030-2</figref> and <figref>9030-3</figref> connected that transmit ICS network frame. The line unit<figref>9011-1</figref>, The processing means <figref>9012-1</figref>, The conversion table <figref>9030-1</figref> and the electronic signature unit <figref>9017-1</figref> are all within the access control device <figref>9010-1</figref> educated. Within the electronic signature unit<figref>9017-1</figref> are: program modules for realizing the signature key KSa, the verification key KPa, the electronic signature function SIGN and the control function H (m), the time / location parameter P1 and the signature function parameter P2. The signature key KSa is a secret value stored in the access control device<figref>9010-1</figref> is stored, and is located within the electronic signature unit the secret signature key so that it must be ensured that a removal of the secret key is prevented from outside. For example, you can save the electronic key unit inside a structurally strong box. This is then so constructed that the signature key can not be read from outside. The more logical ICS ports of line unit<figref>9011-1</figref> are connected to the ICS network address "7721", "7722", "7725", "7726", "7727" and "7728" feature. An example of the conversion table<figref>9013-1</figref> is in <figref idrefs="S213">72</figref> shown.
The encryption / decryption means <figref>9018-1</figref> includes encryption features and contains the key K1 for encrypting and decrypting the key K2 for. If an ICS user frame UF1 entered the passphrase UF2 in the form = ENC (K1, UF1) is generated, and if the encrypted text UF2 is entered, one obtains the corresponding plaintext through UF1 = DEC (K2, UF2).
<< Operation >>
The operation will be in connection with the in <figref idrefs="S214">73</figref> flowchart shown explained. The user<figref>9400-1</figref> sends the ICS user frame F900 with the receiver ICS user address "3600" to the logical ICS communication line <figref>9051-1</figref>, The processing device<figref>9012-1</figref> in the access control device <figref>9010-1</figref> receives the ICS user frame F900 at the logical ICS connection with the ICS network address "7721" of the power unit <figref>9011-1</figref>, And at the same time it brings the ICS network address "7721" (step S2001) and checks whether the ICS network address <figref>"7721"</figref> the request identifier (ID) in the conversion table <figref>9013-1</figref> registered as "3" has (virtual leased line connection) or not (step S2002). In this case such registration is not available, so that as in most written in the ICS user frame F900 receiver ICS user address "3600" is retrieved according to the ICS network address "7721" (step S2004) and it is checked whether the ICS network address "3600" registered with their request idea as "2" in the conversion table (according to the Inter-organizational communication) or not (step S2005). In this case there is such a registration, so that next the receiving ICS network address "5522" from the conversion table<figref>9030-1</figref> brought in preparation for the ICS encapsulation.
Next, from the conversion table <figref>9013-1</figref> Information on the settlement of the speed class and the priority level (step S2006). The value "1" in the signature column of the conversion table<figref>9013-1</figref> registered, and also recorded in the column for the electronic signature transmission "YES" so that the processing device <figref>9012-1</figref> the program modules for implementing the electronic signature function SIGN and the control function h (m), the time / location parameter P1 and the signature function parameter P2 used in the electronic signature unit <figref>9017-1</figref> stored, and from the above-mentioned electronic signature method makes use to generate an electronic signature for the ICS user frame F900 and the new ICS user frame (designated UF2) to form (step S2019). Shown is this by the expression (8):<maths><formula-text>UF2 = m || σ (8)</formula-text></maths>with m = F900 || P1 || P2, σ = SIGN (KSa, h (m)).
If the above procedures "1" in the column signature of the conversion table <figref>9013-1</figref> is registered and located in the column for the electronic signature transmission "NO", the electronic signature unit operates <figref>9017-1</figref> not, and it does not create an electronic signature.
Since the encryption class is specified at "1", the ICS user frames UF2 of the encryption / decryption means <figref>9018-1</figref> to form a new user frame UF3 (= ENC (K1, UF2)) encrypted. In the event that the encryption class "0", then no encryption will take place.
ICS-encapsulation is carried out by an ICS network frame is generated F901, in which the speed class, the priority level and the encryption class are registered (step S2020) Next. The frame is sent to the ICS network line<figref>9030-1</figref> within the ICS <figref>900-1</figref> transmitted (step S2021). Although the above discussion on the inter-organization communication relates, in which the request identifier of the ICS network frame is set to "2" (Inter-organizational communication), be the case that the request identifier "3 "Do (virtual leased line), the receiving ICS network address, payroll-relevant information and the like from the conversion table<figref>9013-2</figref> removed (step S2003). In the event that the request identifier is "1" (intra-organizational communication), the receiving ICS network address, payroll-relevant information and the like from the conversion table<figref>9013-1</figref> fetched (step S2011), and if the request identifier "4" is (communication with an ICS network server), the receiving ICS network address, payroll-relevant information and the like from the conversion table <figref>9013-1</figref> fetched (step S2013). The thus produced by the above procedures ICS-network frame F901 reaches the access control device<figref>9010-2</figref> on the ICS network line <figref>9013-1</figref> and the relay device <figref>9020-1</figref>, The ICS decapsulation is subjected is transferred to the ICS network frames F902 and finally reaches the user <figref>9400-4</figref>, The "3600" has the ICS user address, via the logical ICS communication <figref>9051-3</figref>, Here, F902 = m || σ, m = UF1 || P1 || P2, UF1 the ICS user frame F900 represents before sending, wherein P1 time / spatial parameters P2 of electronic signature parameter and σ are the electronic signature, where σ = SIGN (KSa, h (m)) is.
<< Electronic signature and decryption at the ICS decapsulation >>
Of the participants <figref>9400-3</figref> sends an ICS user frame F930 with a sender ICS user address "3610" and a receiver ICS user address "2510" to the logical ICS communication line <figref>90514</figref>, The access control device<figref>9010-3</figref> receives the ICS user frame F930, performs using the internal conversion table a ICS encapsulation by, generates an ICS network frame F931 and sends it to the ICS network line <figref>9030-3</figref>, The ICS network frame F931 reaches the access control device<figref>9010-1</figref> on the ICS network line <figref>9030-1</figref> and Relaieinrichtung <figref>9120-1</figref>, Is an ICS decapsulation under the administration of the conversion table <figref>9030-1</figref> subjected and to the ICS user frame UF1. Since the value "1" in the encryption column classes of the conversion table<figref>9013-1</figref> is entered, the obtained by the decapsulation ICS ICS user frame (UF1) using the encryption / decryption device <figref>9018-1</figref> decrypted. This an ICS user frame UF1 'condition. It is UF '= DEC (K2, UF1). In the event that the encryption class is "0", no encryption.
As in the signature column of the conversion table <figref>9013-1</figref> the value "1" is registered and is also entered in the column for transmitting electronic signature "YES", the electronic signature unit operates <figref>9017-1</figref> and supplies the ICS user frame with the parameter P1 and P2 as well as the electronic signature σ to form a new ICS user frame F932. Shown is the following:<maths><formula-text>F932 = m || σ, m = UF1 || P1 || P2 electronic signature σ = SIGN (KSa, h (m)) (9)</formula-text></maths>
In the event that the above-mentioned encryption is done, will be held UF1 course UF1 'used. Even if in the above procedures, the value "1" in the signature column in the conversion table<figref>9013-1</figref> and is registered in the column for transmitting electronic signature "NO", performed no electronic signature. The ICS user frame F932 reaches the participants<figref>9400-4</figref> with the ICS user address "2510" through the line unit <figref>9011-1</figref> and the logical ICS communication <figref>9051-4</figref>,
<< Case the signature requirement >>
In the event that an ICS user frame F940 with a sender ICS user address "2800" and a receiver ICS user address "3700" through the line unit <figref>9011-1</figref> is entered, and thereby the request identifier is set according to the ICS network address "7728" to "2", the value "0" in the signature column in said transformation table <figref>9013-1</figref> specified according to the receiver ICS user address "3700", and the same is in the space for the electronic signature transmission "YES" is entered. As in the signature request space of the ICS user frame F940, the value "1" is specified, the electronic signature unit operates<figref>9017-1</figref> and forms a new ICS user frame with the parameters P1 and P2 as well as the electronic signature σ.
If the signature space in the conversion table between <figref>9013-1</figref> either "0" or "1" and is entered in the space for the transmission of the electronic signature is "NO", takes an electronic signature before the ICS encapsulation does not occur, even not when the value "1" in the signature request space the ICS user frame F940 is specified. Similarly, if the signature request space in the Encrypt transmission table<figref>9013-1</figref> the value "0" or "1", however in the space for receiving the electronic signature of the ICS user frame "NO" is entered, an electronic signature is not performed by the ICS decapsulation, even not if the value in the signature area of the conversion table <figref>9013-1 "</figref>1 "is.
Otherwise, if the ICS user frame to receive the electronic signature when sending in the transmitter-side access control device, and also the electronic signature is to be received in the receiver-side access control device, so be referred <figref idrefs="S215">74</figref> assigned both a sending electronic signature as well as a receiving electronic signature. There are other examples in which the value of the verification key KPa is included in the signature function parameter P2. In this way, the difficulties can be avoided, which possibly has the ICS user frame receiver, when referring to the verification key KPa from the public key information center or the like. In the event that the contents of the ICS user frame representing an electronic invoice (or an assignment document, a receipt, etc.) is attached to the electronic account of an electronic signature, together with the identification code of the access control device, through which the electronic invoice run is. If either the sender (writer) of the electronic invoice the consignee (addressee) makes counterfeiting of the electronic invoice, such a forgery can discover using the electronic signature principle. As long as the electronic signature key a secret value, ie, as long as the operator of the access control device, in which the signature key is, ensuring that the signature key can be kept as a secret value, the electronic signature can be used as a tamper-proof public system.
Embodiment 17 (Server for electronic signature and encryption server).
As in <figref idrefs="S212">71</figref> is shown by the embodiment 16, are the electronic signature unit <figref>9017-1</figref> and the encryption / decryption device <figref>9018-1</figref> inside the access control device <figref>9010-1</figref>, In the present embodiment, however, according to contain<figref idrefs="S216">75</figref> the access control devices <figref>9310-1</figref>. <figref>9310-2</figref>. <figref>9310-3</figref> and <figref>9310-4</figref> in its interior no electronic signature unit. Instead, electronic signature server<figref>9340-1</figref>. <figref>9340-2</figref>. <figref>9340-3</figref> and <figref>9340-4</figref> and ICS network lines <figref>9341-1</figref>. <figref>9341-2</figref>. <figref>9341-3</figref> and <figref>9341-4</figref> connected. Each electronic signature server contains the functions of the electronic signature unit described for the embodiment 16, and the procedure for creating an electronic signature before the ICS encapsulation or by the ICS-de-encapsulation in cooperation with the access control device is the same as the function of the electronic signature unit<figref>9070-1</figref>, As described for the embodiment 16, wherein the signature key, the verification key, the electronic signature function, the program module for realizing the control function. the time / spatial parameters and the signature function parameters are used. The electronic signature server<figref>9342-2</figref> and <figref>9342-2</figref> are connected to the relay means <figref>9320-1</figref> and <figref>9320-2</figref> on the ICS network lines <figref>9344-1</figref> or. <figref>9344-2</figref> connected. The electronic signature server has a unique throughout the ICS network ICS network address and has the communication function with other electronic signature servers or access control devices using the ICS network server communication function, so that a mutual exchange of information is possible. The electronic signature server<figref>9342-1</figref> is a server that the VAN <figref>9301-1</figref> represents that the electronic signature servers <figref>9340-1</figref> and <figref>9340-2</figref> within the VAN <figref>9301-1</figref> communicates using the ICS network server communication function, and is able to obtain information that is held by the electronic signature servers. In addition, the electronic signature server<figref>9340-1</figref> able to obtain information relating to the electronic signature by the electronic signature server <figref>9340-2</figref> is held (z. B. a verification key), the communication via the electronic signature server <figref>9342-1</figref> takes place. The electronic signature server<figref>9342-1</figref> is able, with the electronic signature server <figref>9342-2</figref> to communicate which another VAN <figref>9301-2</figref> represented by the ICS network server communication function is used to enable a mutual exchange of each electronic signature. Replacing the electronic signature server no information about the secret signature key, which is stored in them, they protect the secrecy of the signature key strictly.
In the present invention according to containing <figref idrefs="S216">75</figref> the access control devices <figref>9310-1</figref>. <figref>9310-2</figref>. <figref>9310-3</figref> and <figref>9310-4</figref> no encryption / decryption device. Instead, there is a connection with the encryption servers<figref>9343-1</figref>. <figref>9343-2</figref>. <figref>9343-3</figref> and <figref>9343-4</figref> on the respective ICS network lines. Each encryption server has the functions of the above encryption / decryption means<figref>9018-1</figref>, And the flow when encrypting the ICS user frames prior to the ICS encapsulation or in decrypting the encrypted ICS user frames according to the ICS decapsulation in cooperation with the access control device is the same as the operation of the encryption / decryption means <figref>9018-1</figref> decrypt using the program module for realizing the encryption function and the decryption, the encryption key and the key mm. Encryption Server<figref>9343-5</figref> and <figref>9343-3</figref> are connected to the relay devices <figref>9320-1</figref> and <figref>9320-2</figref> connected via the ICS network lines. Each encryption server has a unique throughout the ICS network ICS network address and has the communication function with other encryption servers or access control devices using the ICS network server communication function, so that a mutual exchange of information is possible. The encryption server<figref>9343-5</figref> is the VAN <figref>9301-1</figref> representing encryption server connected to the encryption servers <figref>9343-1</figref> and <figref>9343-2</figref> in the VAN <figref>9301-1</figref> communicates via the ICS network server communication function and is able to bring the held of the encryption servers information. In addition, the encryption server<figref>9343-1</figref> in a position to pick up the information about the encryption of the encryption server <figref>9343-2</figref> is held, (z. B. a serving for encryption key). What about the encryption server<figref>9342-5</figref> expires. The encryption server<figref>9343-5</figref> can communicate with the another VAN <figref>9301-2</figref> representing Encryption Server <figref>9343-6</figref>What the ICS network server communication function is used, so that a mutual exchange of information is possible.
Embodiment 18 (open connection):
In the following an open ICS connection is to be explained, namely preparatory procedures that are performed by the participants and made by the VAN operator to switch to other participants and to perform an inter-organizational communication.
<< User Login >>
The user logs in to the VAN operator an ICS name and an ICS user address, and simultaneously ICS connection conditions, a user ID and a payment to (address, name of organization, debiting bank account etc.). Is there the ICS user address for intra-organization communications that the user specified, this will also be shown, a representation is not, however, if there is not the address. The VAN operator operates according to common rules that have been pre-arranged with other VAN operators, makes a decision with respect to the ICS name and the ICS user address and informs the user about this. The information for the ICS connection conditions include ICS name, communication band, billing terms, electronic signature conditions encryption conditions, open zone conditions and dynamic conditions. The contents and meanings of these terms are explained below.
The ICS-name-conditions specify only the left part of the ICS name. For example, if the ICS name "USR # 1.ACS # 1.DIS # 1.VAN # 1.JP.AS", then the user specifies only the leftmost "USR # 1" (the VAN operator makes decisions over the remaining right pane). The communication band conditions are speed class and Prioritätssgrad. the billing terms are defined according to charges for a fixed amount for a certain period of time, fees for network use (network billing) or charges for the information content that is sent and received via electronic communication is (Informations-billing), based on the communication band bananas, signature conditions encryption conditions, etc .. the electronic signature conditions specify whether an electronic signature is made or not, which can back up the fact about the date and time that the ICS user frame has passed through the access control device. Specify the encryption conditions, whether the transfer of the ICS user frame takes place encryption or not. Specify the open zone conditions, whether from an unknown, unregistered in the conversion table transmitter swift ICS frame at the access control device will be rejected or not, or whether an intermediate conversion table is created and the reception takes place and the like. The dynamic change conditions specify the functions which can be changed on demand from the user of ICS-frame with respect to the conditions described above. The dynamic change conditions are adjusted so that the signature conditions or the encryption conditions are changeable, but can for the VAN mode important factors not be changed, such as ICS addresses or billing information.
<< ICS address administration server and ICS name server >>
<figref idrefs="S217">76</figref> and <figref idrefs="S218">77</figref> show a conversion table <figref>11113-1</figref>. <figref idrefs="S219">78</figref> shows the conversion table template, <figref idrefs="S220">79</figref> shows the correlation table, and <figref idrefs="S221">80</figref> ICS shows the name server according to the present embodiment, which is located inside the ICS <figref>11000-1</figref> is. This includes access control devices<figref>11110-1</figref>. <figref>111110-2</figref> and <figref>11110-3</figref>, A relay device <figref>11116-1</figref>ICS address administration server <figref>11150-1</figref> and <figref>11150-2</figref>ICS name server <figref>11160-1</figref> and <figref>11160-2</figref>ICS conversion table server <figref>11170-1</figref> and <figref>11170-2</figref> and user <figref>11132-1</figref> and <figref>11132-2</figref>, The ICS address administration server<figref>11150-2</figref> contains the correlation table within it the ICS network address "8210", the ICS user address "4200" and the user's user addresses relevant information <figref>11132-2</figref>, The ICS name server<figref>11160-2</figref> contains in its ICS name conversion table the ICS name "USR # 3.ACS # 3.DIS # 3.VAN # 3.JP.AS" and the ICS user address "4200" of the user <figref>11132-2</figref>, The VAN operator makes a decision to use the ICS user address "3333" of the user<figref>11132-1</figref> on an ICS network address "7777", it supplies the logical ICS-terminal <figref>11111-2</figref> of the. Access control device<figref>11110-1</figref> and connects the logical ICS communication <figref>11133-1</figref>Which the user <figref>11132-1</figref> via the gateway <figref>11000-2</figref> connects. The ICS network address "7777" is an undisclosed value, so that the user is about failing to inform.
Next, the VAN operator directly writes the following expressions in the correlation table <figref>11152-1</figref> inside the ICS address administration server <figref>11150-1</figref> a, also via the data path <figref>11153-1</figref> and the processing means <figref>11151-1</figref> in the conversion table <figref>11152-1</figref>: ICS network address "7777", which was established by the method explained above, the ICS user address (inter-organization) "3333", the ICS user address that has been specified by the user (intra-organization), namely " 1111 ", and user address relevant information, namely conditions concerning the communication band, the billing, electronic signature, encryption, open zone, dynamic changes, user ID, payment etc. the VAN operator continues to write over the data path <figref>11163-1</figref> and the processing means <figref>11161-2</figref> following in the ICS name conversion table <figref>11162-1</figref> within the ICS name server <figref>11160-1</figref>: ICS name "USR # 1.ACS # 1.DIS # 1.VAN # 1.JP.AS" which was set in the manner described above, the ICS user address 11,333,311 and type "1" (indicating that the ICS user address "3333" in the ICS name conversion table <figref>11162-1</figref> is registered). The above results are as shown in the correlation table<figref>11152-1</figref> and in the ICS name conversion table <figref>11162-1</figref> are shown.
is completed at the point at which the above writing of various types of information to the new subscriber, use the ICS address administration server <figref>11150-1</figref> and the ICS name server <figref>11160-1</figref>, The ICS network communication functions for communication with the respective network addresses "8910" and "8920" to the ICS Conversion Server <figref>11170-1</figref> communicate that information about the ICS address and the ICS connection conditions of a new participant was obtained. Now is the ICS conversion table server<figref>11170-1</figref> a type of the ICS network server, and the present embodiment, it has an ICS network address "8100" and an ICS user address 11,210,011th
<< ICS conversion table server >>
The ICS conversion table server <figref>11170-1</figref> read in the correlation table <figref>11152-1</figref> the ICS address administration server <figref>11150-1</figref> described information using the ICS network communication functions and writes it to the conversion table Schablose <figref>11172-1</figref>, That is, in the space for the transmitting ICS network address (intra) is "7777" inscribed in the space for the sender ICS user address (intra) is "1111" inscribed and in the space for the sender ICS user address (Inter) is "3333" inscribed. In the event that there is no ICS user address for intra-organizational communication, the space for the sender ICS network address (intra) is released. The request identifier (ID) is set to "2", which corresponds to the inter-organizational communication, so the communication between different organizations. The remaining settings in this embodiment are the following: the communication band conditions are adjusted to the speed category "3" and the priority level "3" that electronic signature conditions are set to "1", the condition for sending the signature is "YES" set, and the receiving signature specification is "NO", the billing terms in accordance with the Abrechnungsklass4 "4" in the present example, this means a fixed fee system. The encryption conditions in accordance with the encryption class "1", which in this embodiment means that the encryption of the ICS network frames is performed within the ICS. The open zones class in the present embodiment is "0". The dynamic modification class "6" in the present embodiment is used to change the section "Sending Signature" on request by the user.
<< Using the ICS conversion table server (user) >>
Of the participants <figref>11132-1</figref> writes as a sender ICS user address "3333" and the ICS user address "2100" of the ICS conversion table server <figref>11170-1</figref> as the receiver ICS user address, and sends the ICS user frame F1200 with the inscribed addressee information (receiver ICS user address or receiver ICS name) in a user data part of the ICS user frame. The ICS conversion table server<figref>11170-1</figref> receives the ICS user frame F1200 on the access control device <figref>11110-1</figref> and receives the receiving ICS network address for inter-organization communication depending on whether the recipient information is a receiver ICS user address of a receiver ICS name in the user data part, by making use of the bottom Erlau failed process. In the event that the receiver-ICS-name has been specified and the receiver ICS user address is obtained.
(In the event that there is a specification of the receiver ICS user address):
If the aforementioned receiver information, the receiver ICS user address "3800" is, asks the ICS conversion table Nerver <figref>11170-1</figref> using the ICS network Kommuniktionsfunktion the ICS address administration server <figref>11150-1</figref>, Of the access control device <figref>11110-1</figref> is connected, and receives the ICS network address "7600" (the receiving ICS network address), which corresponds to the ICS user address "3800". If the receiver ICS user address is not in the correlation table<figref>11152-1</figref> place (not finding the ICS network address), receives the ICS conversion table Nerver <figref>11170-1</figref> of the ICS address administration server <figref>11150-1</figref> a "message of non-locating the ICS network address".
(The receiver ICS name is specified):
In this case, namely, that the above information receiver the receiver ICS name "USR # 3.ACS # 3.DIS # 3.VAN # 3.JP.AS" is, sends the ICS conversion table Nerver <figref>11170-1</figref> using the ICS network communication function to the ICS name "USR # 3.ACS # 3.DIS # 3.VAN # 3.JP.AS" to the ICS name server <figref>11160-1</figref>Which at the same access control device <figref>11110-1</figref> connected.
The ICS name server <figref>11160-1</figref> maintains the ICS network address other ICS-name server in a form corresponding to the ICS name (the part of the ICS name after removing the leftmost part "USR # n"), and studied in the present embodiment, the ICS name server <figref>11160-1</figref> in the ICS name conversion table <figref>11162-1</figref>, Finds the ICS network address "8930" of the ICS name server <figref>11160-2</figref>, The "ACS # 3.DIS # 3.VAN # 3.JP.AS" managed, and makes an inquiry with respect to the address "8930" using the ICS network communication capabilities to the ICS user address "4200" (the (to obtain receiver ICS user address) and the ICS network address "8210", the receiving ICS network address) which the aforementioned ICS name "USR # 3.ACS # 3.DIS # 3.VAN # 3.JP.AS "corresponds. In the above-mentioned procedures, the ICS name server<figref>11160-2</figref> the ICS address administration server <figref>11150-2</figref> with respect to the ICS network address of the user <figref>11132-2</figref> contacted and get the address "8210".
(Completion of the conversion table <figref>11113-1</figref>):
In the event that the receiver ICS user address is specified, adds the ICS conversion table server <figref>11170-1</figref> the receiver ICS user address "3800" and the receiving ICS network address "7600" of the conversion table <figref>11113-1</figref> added, thereby completing the portion of the conversion table <figref>11113-1</figref>Corresponding to the receiving subscriber. In the event that the receiver-ICS-name is specified, adds the ICS conversion table server<figref>11170-1</figref> the receiver ICS user address "4200" and the receiving ICS network address "8210" of the conversion table <figref>11113-1</figref> added, thereby completing the appropriate portion of the receiving subscriber conversion table <figref>11113-1</figref>, Even in the event that of the ICS address administration server<figref>11150-1</figref> or the ICS name server <figref>11160-1</figref> a "message of non-finding of the ICS network address" is received, sends the ICS conversion table server <figref>11170-1</figref> a non-Auffindenden indicating frame to add one to the conversion table to the requesting subscriber <figref>11132-1</figref>,
<< Other using the ICS conversion table server (participants) >>
Of the participants <figref>11132-1</figref> Calls for a message of user-specific information to the user characterized in that it sends an ICS user frame which is written with a request for notifying the contents of the user-specific information from the conversion table <figref>11113-1</figref> to the ICS conversion table server <figref>11170-1</figref>, The user can also use a dynamic modification class that was previously agreed with the VAN operator to a portion of the conversion table<figref>11113-1</figref> to rewrite. The dynamic modification class is set to 1, 2 ..., the content is as follows: The dynamic change class 1 is a specification for increasing the user-specified priority level to "1", the dynamic change of class 2 is a determination to reduce the user-specified priority level to " 1 ", and the dynamic change in class 3 is the option" send the signature "to" YES ", and specifies the same time a change of the encryption class to" 2 ".
<< Using the conversion table >>
In the embodiment 1, and so the method of using the conversion table has been described which has been prepared according to the procedures described above. Although in Embodiment 1, a description of the process is carried out, according to which a generated intermediate conversion table, when there is no conversion table at the time of reception of the ICS network frame by the access control device and is to be the ICS decapsulation of the received ICS-network frame so is the open zone class of the conversion table used in the present embodiment.
That is, to the time at which the access controller receives the ICS network frame and its ICS decapsulation is to perform, in the case that the received "pair of receiving ICS network address and transmitting ICS network address in the network control field of the ICS network frame "is be registered, an intermediate conversion table in the same manner as is usual for the above embodiment, in the case where the open-zone class to" "not in the conversion table as a" pair of the transmitting ICS network address and the receiving ICS network address 2 is set ". In the case, however, that the open zones class is set to "1", no intermediate conversion table is set up. In addition, when the open zones class is set to "0", an intermediate conversion table is not only not set, but it is also the received ICS network frames ignored. In this case, the ICS user frame is not delivered to the subscriber. That is, when the open zones class is set to "0", the reception of an unknown transmitter, which is not registered in the conversion table, rejected, thereby realizing a so-called "closed connection". If in the above-mentionedContext, the request identifier "4", then the open zones class will be treated as if it is set to "1", ie it is not established between conversion table.
<< Modifications of the embodiment >>
In the above explained embodiment, the method has been explained with the aid of the VAN-operator data path <figref>11153-1</figref> and the data path <figref>11163-1</figref> to use the ICS addresses that ICS connection conditions and the like in the ICS address administration server <figref>11150-1</figref> and in the ICS name server <figref>11160-1</figref> enter. Instead, one can also provide for an arrangement with the VAN operator these data paths do not need, but rather a special ICS network server within the ICS<figref>11000-1</figref> forms to it in a direct way the ICS addresses that ICS connection conditions and the like in the ICS address administration server <figref>11150-1</figref> and in the ICS name server <figref>11160-1</figref> enter, by making use of the ICS network communication function to the contents of the conversion table <figref>11152-1</figref> rewrite and the ICS name conversion table.
Embodiment 19 (Segregation of duties of access controller):
As in <figref idrefs="S217">76</figref> As shown for the embodiment 18, the ICS address administration server <figref>11150-1</figref>, The ICS name server <figref>11160-1</figref> and the ICS conversion table server <figref>11170-1</figref> respectively to the access control device <figref>11110-1</figref> connected, the ICS encapsulation and de-encapsulation ICS within the access control device <figref>11110-1</figref> using the conversion table <figref>11113-1</figref> be executed. In the present embodiment, however, the functions of the access control device<figref>11110-1</figref> separated into an aggregation access controller <figref>14110-1</figref> and more simplified access control devices <figref>14210-1</figref>. <figref>14210-2</figref> and <figref>14210-3</figref>, As in<figref idrefs="S222">81</figref> is shown, the access control device <figref>11110-1</figref> the simplified access control devices <figref>14210-1</figref>. <figref>14210-2</figref> and <figref>14210-3</figref> on the respective ICS network routing <figref>14190-1</figref>. <figref>14190-2</figref> and <figref>14190-3</figref> connected. The ICS address administration server<figref>14150-1</figref>, The ICS name server <figref>14160-1</figref>, The ICS conversion table server <figref>14170-1</figref>, The ICS-Billing Server <figref>14180-1</figref>, The electronic signature server <figref>14181-1</figref>, The encryption server <figref>14182-1</figref>, The operation management server <figref>114183-1</figref> and the ICS network server <figref>14184-1</figref> are the aggregation access controller <figref>14110-1</figref> via associated ICS network lines <figref>14191-1</figref>. <figref>14191-2</figref>. <figref>14191-3</figref>. <figref>141911-4</figref>. <figref>14191-5</figref>. <figref>14191-6</figref>. <figref>14191-7</figref>and <figref>14191-8</figref> connected. Furthermore, the conversion table<figref>11113-1</figref> within the access control device <figref>11110-1</figref> divided into an aggregation conversion table <figref>14113-1</figref> and more simplified conversion tables <figref>14213-1</figref>. <figref>14213-2</figref> and <figref>14213-3</figref>, An example of the aggregation conversion table<figref>14113-1</figref> is in <figref idrefs="S223">82</figref> shown, <figref idrefs="S224">83</figref> shows an example of the simplified conversion table <figref>14213-1</figref>,
A part of the aggregation conversion table and the simplified conversion tables overlap one another. That is, the following four expressions contained in the two conversion tables: the transmitting ICS network address, the request identifier, the speed class and the degree of priority. There is no fundamental difference between the intermediate unit conversion table<figref>14214-1</figref> and the intermediate conversion table which has been described in connection with the embodiment 1 and other embodiments, the terms in the intermediate part conversion table <figref>14214-1</figref> are the same as the expressions in the simplified conversion table <figref>14213-1</figref>, The line unit<figref>14211-1</figref> within the simplified access control device <figref>14210-1</figref> has the same function as the lead unit <figref>11111-1</figref> within the access control device <figref>11110-1</figref>,
The simplified access control device <figref>14210-1</figref> uses the simplified conversion table <figref>14213-1</figref>In order to then carry out the ICS encapsulation when sending, and around the ICS decapsulation executed when received, and the aggregation access controller <figref>14110-1</figref> uses the aggregation conversion table <figref>14113-1</figref> to perform the processing on the electronic signature and billing, as explained above. With the help of several simplified access control devices<figref>14210-1</figref>. <figref>14210-2</figref> and <figref>14210-3</figref> in association with the aggregation-access controller <figref>14110-1</figref> are the combined function the same as the access control device dr <figref>11110-1</figref>, The user<figref>14132-1</figref> sends an ICS user frame F1300 with a sender ICS user address "3333" and a receiver ICS user address "4200" to the logical ICS communication line <figref>14133-1</figref>, As shown in the flowchart in<figref idrefs="S225">84</figref> shown, receives the processing device <figref>14212-1</figref> simplified access controller <figref>14210-1</figref>, The ICS user frame F1300 from the logical ICS connection within the ICS network address "7777" of the line unit <figref>14211-1</figref>, And simultaneously receives the ICS network address "7777" (step S2501) and checks whether the address "7777" in the simplified conversion table <figref>14213-1</figref> is registered with a Anfordrungs identifier of "3", indicating a virtual leased line connection or not (step S2502). In this case, no registration was done so that the receiver ICS user address "4200", which is written in the ICS user frame F1300is, according to the ICS network address "7777" (step S2504) and will continue to check whether the address "4200" in the simplified conversion table <figref>14213-1</figref> is registered with a request identifier "2" indicating an inter-organizational communication or not (step S2505). In this case, registration was performed so that in preparation of the ICS encapsulation the receiving ICS network address "8210" from the conversion table simplified<figref>14213-1</figref> is fetched (step S2506).
Next, leads the simplified access controller <figref>14210-1</figref> ICS encapsulation by using a ICS network frame is generated F1301 within the ICS network frame in which the speed class and the priority level are entered, consisting of simplified conversion table <figref>14213-1</figref> were obtained (Step S2520), and the frame is sent to the aggregation access control device (step S2521). As explained above, the speed category "3", the priority level "3" and the encryption class "0" which are to expressions of simplified conversion table are now registered in the extension part of the ICS network controller,<figref>14213-1</figref> concerns.
The aggregation access controller <figref>14110-1</figref> receives the ICS network frame F1301 from simplified access controller <figref>14210-1</figref>And due to the fact that the ICS network frame F1301 by the aggregation access controller <figref>14110-1</figref> has passed, a billing information frame FK01 is formed and to the billing server <figref>14180-1</figref> Posted. The information such. As the request identifier, the speed class, the priority level, the settlement class and the encryption class that the aggregation conversion table<figref>14113-1</figref> are registered are called in the order to form the billing information frame FK01. The signature, sending the signature, receiving the signature from the aggregation conversion table<figref>14113-1</figref> are used for forming the electronic signature in the manner as described for the other embodiments, the electronic signature is effected in that the electronic signature in the electronic signature server <figref>14181-1</figref> is requested. In the same manner, when the encryption class is "1", that is to take place encryption, run the encryption in that in the encryption server<figref>14182-1</figref> encryption is logged. If the above processing steps are completed, sends the aggregation access controller<figref>14110-1</figref> the ICS network frame F1302 to another access controller <figref>14110-1</figref> and further aggregation access control devices, via the ICS network line <figref>14190-4</figref>, The format of the ICS network frame F1302 changes to its content, if the electronic signature servers or encryption server to act when you add the electronic signatures or in converting the ciphertext as described above, however, if neither the electronic signature server nor the encryption server have acted , the ICS network frame F1302 the same as the ICS network frame F1301. The simplified access control device<figref>14210-1</figref> can not only be realized with virtually no changes to the existing router, but there are also other economic advantages in that the number of subscribers for a simplified access control device <figref>14210-1</figref> is not large, and if the participants are spread over a large geographical area, the total number of ICS address administration server, the ICS name servers, the ICS conversion table server, the accounting server, the electronic signature server and the encryption server can be reduced.
The operation management server <figref>14183-1</figref> ICS is equipped with a network address, is connected to the aggregation access controller <figref>14110-1</figref> and connected to the relay devices and performs an exchange with other operating management servers, access control devices, ICS address administration servers etc. with respect to the information on the conditions of communication with the ICS (communication density, etc.) of, or with respect to difficulties, made by use of the ICS network communication functions becomes.
Now, in the simplified conversion table <figref>14213-1</figref> simplified access controller <figref>14210-1</figref> contained open zones class for the same processing used as the open zones class in the conversion table of the access control device described above. That is, at the time at which the simplified access controller<figref>14210-1</figref> the ICS network frame receives and those of ICS decapsulation subjects, when the "pair of receiving ICS network address and transmitting ICS network address corresponding to the network control field of the ICS network frame" not in the simplified conversion table <figref>14213-1</figref> as a "pair of transmitting ICS network address and receiving ICS network address" is stored, an intermediate unit conversion table <figref>14214-1</figref> in the manner described above established when the open zones class is set to "2", however, this is set to "1", no intermediate part conversion table is set up. In addition, when the open zones class is set to "0", so not only an intermediate part of the conversion table is notfurnishings, but it also ignores the receiving ICS network frame. In this case, the ICS user frame is not delivered to the user. In this embodiment, "0" means that the reception of an unknown sender, who is not registered in the conversion table, dismissed, whereby a so-called "closed connection" is realized.
As explained for the above-described embodiment, the ICS address administration server and the ICS name server can be integrated into a single directory name management server, the aggregation access control device is used, the to the ICS address name management server and ICS network cable is connected. You can also by an arrangement under the embodiment above exercise, in which the speed class and the priority level is not in the simplified conversion table<figref>14213-1</figref> are present, being registered at the relevant point of the ICS encapsulation in the extension part of the ICS network control field for the speed class as well as for the degree of priority "0", which means that no specification exists. Similarly, one can of an arrangement making use, in which the specification of the open zones class is not in the simplified conversion table<figref>14213-1</figref> is, wherein in the extension part of the ICS network controller for the speed class as well as for the degree of priority is a "0" is written, which means that no specification is provided.
The invention thus provides the management of information communication is carried out with a unified address system, and there can be provided various services without dedicated lines or the internet is used. So it is the development of a comprehensive wholesale communication system with high reliability and relatively low cost allows. leaves The communication from one organization to another (inter-organizational communication) between individual organizations (incl. government agencies, universities and the like) run, which are usually a question of separate services, where virtually no change of address system for computer communications took place. In addition, since the network administrator holds the taxing authority for the network, the overall management of the network can be seen, and in this way to ensure the reliability simplified with significantly increased security.
According to a further embodiment of a integrated information communication system (ICS) includes the following features: an ICS user frame with a unique user address ICS system (ADX) is under the management of a control device in an access (<figref>110-1</figref>) Conversion table contained (<figref>113-1</figref>) Converted to a an address system ADS corresponding ICS network frame (F2); and if the transmission of at least one network VAN done that in the ICS (ICS<figref>100</figref>) Is contained and operates according to the rules of the address ADS system, and another target access control (<figref>110-4</figref>) Obtained occurs under management of the conversion table (<figref>114-2</figref>) Conversion to the ICS user address system (ADX, ADY) before forwarding the information to an external communication device (z. B. <figref>100-3</figref>) Takes place.
Preference is given for the case where an ICS user frame corresponding to the ICS system user address ADX to a network with a different system address (ADY) is transmitted, the conversion table (<figref>113-1</figref>) Arranged such that it includes a service identifier to distinguish between intra-organizational communication, which is a communication within a single organization and inter-organizational communication, which is communication between different organizations, the implementation of the address system by transfer under management of access control device (<figref>110-1</figref>) Is carried out, thereby enabling a selection of the format conversion per user frames (F1, P1).
In yet another embodiment, an integrated information communication system (ICS) includes the following features: an ICS user frame according to a unique ICS user address system ADX is reacted in an ICS-network frame according to a pre-registered in a conversion table in accordance with a logical user-communication line pre receiving ICS network address, instead of using an ICS user address within the ICS user frame that is based on the administration of a conversion table contained in an access control device; and if the transfer of the ICS network frame is carried to a different access control device via at least one network VAN, which operates according to the rules of ICS address system ADS, wherein a transmission destination of the ICS network frame is either 1 or N, the ICS network frame under the management of a conversion table contained in the access control device in the ICS user frame is converted back, and this is routed to an external communication device.
In one embodiment, the integrated information communication system processing means (<figref>331</figref>) And an .icsNetwork database (<figref>332</figref>), Wherein the system includes features that help the system answers the results contained in a response to a request from the access control device, or, if not, the system must respond to a request from the access controller, the system responds with text Support of communication with another ICS network server receives using an ICS network server communication function and a requesting access controller communicates the results.
Furthermore, the integrated information communication system can include an address management server with a relation table corresponding to the relationship between the processing means and the ICS network address.
Also the integrated information communication system, a processor and an ICS name conversion table include which receives proposals for an ICS name from the access control device, a corresponding named ICS user address from the ICS name conversion table requests, the access control device notifies the results obtained, and the access management server least inscribes the mentioned ICS user address and the ICS network address in the conversion table and also performs functions for the return to the user an ICS user address corresponding to the ICS name.
It is also possible that the ICS is provided with a processing device and an ICS name conversion table that receives a proposal for an ICS name of the access control device, requesting a corresponding named ICS user address from the ICS name conversion table, the access control device, the results obtained notifies and wherein the access management server temporarily at least the ICS user address and the ICS network address enters in the conversion table and also processes functions to return to the user an ICS user address corresponding to the ICS name.
The ICS may also comprise a processing means and an ICS name conversion table that receives a proposal of an ICS name of the access control device, a corresponding ICS user address from the ICS-name conversion table is requesting the access control device communicates the results obtained, and functions performs to be surrendered to the user corresponding to the ICS name ICS user address.
The integrated information communication system can be designed so that in the event that the access control device receives an ICS user frames, the access control device reads out the type of billing system for each ICS-frame, which is included in the conversion table based on the ICS user address contained in the ICS user frame, billing information for the case, in that the determined by reading type corresponds to a conversion-amount fee system, the accounting server, the accounting information notifies in the form of accounting information framework, but does not form a billing information, even the billing server accounting information in the form of accounting information framework the case notifies that the determined by reading type corresponds to a fixed cost accounting system.
In one embodiment, the integrated information communication system includes an ICS frame database server for storing a user data field contained in the ICS user frame for receiving a message by using the user control panel or a user data field within the ICS user frame by the user, with the ICS frames database server is able to delete the stored user data field to send and receive.
Here, the ICS frame database server may temporarily store the user data field in the ICS user frame according to the message on the use of the ICS user frame on the side of the sending station, and transmits the stored user data field to the subscriber on the receiving side at a time, the was indicated by the transmitter-side participants using an ICS user frame.
In the ICS can relay or Weiterleitnetzwerk a FR network is present which contains, as input / output part, a FR / ICS-network frame conversion unit for converting the ICS network framework in a relay frame format and for the reverse transformation.
The ICS may also include an ATM network as a relay or Weiterleitnetzwerk whose input / output field is formed by an ATM / ICS network frame converting unit to implement the ICS network frame into an ATM format frame, and for reconversion ,
According to a Ausfürhungsform the ICS includes a satellite route network as a relay or Weiterleitnetzwerk whose input / output portion of a satellite / ICS network frame converting unit for converting the ICS network frame in a Satellite network interface as well as having to reconversion.
Further, in the ICS, the access control apparatus, a telephone line converter unit or a mobile phone routes converter unit with functions for converting a telephone line interface or a mobile phone link interface in an ICS-network frame that is suitable for transmission in a ICS network comprise, the converter unit also for the reconversion is suitable.
Also, in the ICS, the access control device may comprise an ISDN line converter unit with functions for converting an ISDN line interface in an ICS network frames for transmission in an ICS network, as well as the reverse transformation.
Also, in the ICS, the access control device having a CATV line converter unit with functions to implement a CATV line interface in an ICS network frames for transmission in an ICS network, and reverse transformation.
In one embodiment, the integrated information communication system is configured such that the access control device, a satellite transmission converter unit with functions for converting a satellite transmission interface in an ICS network frames for transmission in an ICS network, as well as the reverse transformation comprises.
The ICS can be provided with a relay network input / output portion within the access control device, in which a FR / ICS network frame converting unit is that is suitable for converting the ICS network frame into a frame-Weiterleitformat well as the reconversion ,
In the ICS, in the access control device are an ATM ICS network frame converting unit for converting the ICS network frame into an ATM format frame and conversion back at the relay network input / output part.
The ICS can also be designed so that at the relay network input / output portion of the inside of the access control device, a satellite / -ICS network frame converting unit for converting the ICS network frame in a Satellitenkommunkations format frame and to reconversion is.
The integrated information communication system can also be designed so that the access control device is in a FR-exchanger or in an ATM exchanger or in a satellite transceiver or one of the following networks: an X.25 network, a FR network, an ATM network or a satellite communication network.
According to a further embodiment of an inventive ICS further comprising: at least one externally provided access control apparatus; and an externally provided access control device management server; whereby an intra-organizational communication (intra-organizational communication) or communication between different organizations, ie an inter-organizational communication is feasible.
It is possible that having the access control apparatus an encryption and decryption means, the ICS user frames is converted by the encryption means in an encrypted text and transmitted within an ICS, which is effected in particular as part of a ICS-encapsulation, and the encrypted into a text converted ICS user frame is decrypted at the time of ICS decapsulation in the original ICS user frame.
In addition, a speed class and a priority level can be registered in the conversion table, wherein communication is carried out in accordance with the speed class and the priority degree.
The ICS may further be configured such that the access control device comprises an electronic signature unit, wherein the ICS user frames an electronic signature is assigned, if the ICS user frames passed the access control device.
In another embodiment, an integrated information communication system (IOS) includes the following features: an ICS user frame with an address of a unique ICS user address system ADX is converted into an ICS network frame according to an address system ADS, based on the administration by a conversion table that is included in an access control apparatus; and for the case that the transmission over a contained in the ICS ATM Austauschernetzwerk according to the rules of the address system ADS is performed, and a destination address is reached, which is different from the access control device, a reaction is carried out in the ICS user address system ADX on the basis of the management by the conversion table, and then the information reaches another external information communication apparatus.
In this case, the ATM exchanger that forms the ATM Austauschernetzwerk, an ATM address conversion table and a PVC-address conversion table included. Further, the ATM-exchange can also be connected to an ATM address management server and a PVC-address management server.
It is also conceivable that a communication path of the ATM-SVC or a Austauschernetzwerks is a PVC.
Furthermore, a communication path may be a PVC and a communication of the type 1: 1 or done N.:1: N, N.
In another embodiment, an integrated information communication system (ICS) includes the following features: an ICS user frame with an address of a unique ICS user address system ADX is converted into an ICS network frame according to an address system ADS, based on the administration by a conversion table that is included in an access control apparatus; and for the case that the transmission over a contained in the ICS FR-Austauschernetzwerk according to the rules of the address system ADS is performed, and a destination address is reached, which is different from the access control device, a reaction is carried out in the ICS user address system ADX on the basis of the management by the conversion table, and then the information reaches another external information communication apparatus.
In this case, each of the FR-exchange network forming FR-exchanger having a FR-address conversion table and a DLC address conversion table. Furthermore, the FR-exchanger may additionally be connected to an FR-address management server and a DLC address management server.
In one embodiment, the integrated information communication system is configured such that the access control device or a relay device, an electronic signature server is connected, and the exchange of information is carried out mutually by means of an ICS network server communication function.
Furthermore, an encryption server can be connected and the exchange of information are carried out mutually by an ICS network server communication function to the access control device or a relay device.
In addition, a conversion table server know a part of the conversion table to users or rewrite a portion of the conversion table on request from the user back.
In one embodiment, the integrated information communication system is configured such that when a registered in a network control field of the received ICS-network frame address is not registered in the conversion table, it is possible to select an open zones compound or a closed-zone connection, depending on the reception or the absence of an open zones class indicating ICS network frame.
The ICS may also be designed so that the access control device is separated into an aggregation access control apparatus and a simplified access control device in a function, wherein the simplified access control device, a subscriber is connected, the conversion table divided into a aggregation conversion table within the aggregation access control device, and a simplified conversion table within the simplified access control device, an ICS encapsulation and an ICS decapsulation are performed within the simplified access control device, and billing and the electronic signature are performed in the aggregation access controller.
The access control device may include a network server, for example, an address management server or a name server, if it is structurally formed independently.
Contents3
84 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28 Sheet 29 Sheet 30 Sheet 31 Sheet 32 Sheet 33 Sheet 34 Sheet 35 Sheet 36 Sheet 37 Sheet 38 Sheet 39 Sheet 40 Sheet 41 Sheet 42 Sheet 43 Sheet 44 Sheet 45 Sheet 46 Sheet 47 Sheet 48 Sheet 49 Sheet 50 Sheet 51 Sheet 52 Sheet 53 Sheet 54 Sheet 55 Sheet 56 Sheet 57 Sheet 58 Sheet 59 Sheet 60 Sheet 61 Sheet 62 Sheet 63 Sheet 64 Sheet 65 Sheet 66 Sheet 67 Sheet 68 Sheet 69 Sheet 70 Sheet 71 Sheet 72 Sheet 73 Sheet 74 Sheet 75 Sheet 76 Sheet 77 Sheet 78 Sheet 79 Sheet 80 Sheet 81 Sheet 82 Sheet 83 Sheet 84
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| EP0269978A2 | Cites | European Patent Office (EPO) | Search report |
152 members in 12 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 32673696 | Japan | – | |
| 32673696 | Japan | A | |
| 32673696 | – | – | – |
| JP19960326736 | – | – | – |
Members152
| Document | Office | Kind | |
|---|---|---|---|
| GB9722070D0 | United Kingdom | D0 | |
| CA2220559A1 | Canada | A1 | |
| CA2537966A1 | Canada | A1 | |
| CA2538190A1 | Canada | A1 | |
| CA2538673A1 | Canada | A1 | |
| CA2538990A1 | Canada | A1 | |
| CA2540793A1 | Canada | A1 | |
| DE19754073A1 | Germany | A1 | |
| GB2320167A | United Kingdom | A | |
| AU4679497A | Australia | A | |
| FR2758924A1 | France | A1 | |
| KR19980063826A | Republic of Korea | A | |
| GB9821661D0 | United Kingdom | D0 | |
| CN1201200A | China | A | |
| JPH1188438A | Japan | A | |
| CA2254045A1 | Canada | A1 | |
| AU8956998A | Australia | A | |
| GB2332837A | United Kingdom | A | |
| TW364964B | Taiwan Province of China | B | |
| JPH11239178A | Japan | A | |
| GB9920041D0 | United Kingdom | D0 | |
| GB9920042D0 | United Kingdom | D0 | |
| GB9920076D0 | United Kingdom | D0 | |
| GB9920079D0 | United Kingdom | D0 | |
| GB9920084D0 | United Kingdom | D0 | |
| GB9920086D0 | United Kingdom | D0 | |
| GB2338871A | United Kingdom | A | |
| GB2338872A | United Kingdom | A | |
| GB2338873A | United Kingdom | A | |
| GB2338874A | United Kingdom | A | |
| GB2338875A | United Kingdom | A | |
| GB2338876A | United Kingdom | A | |
| AU714668B2 | Australia | B2 | |
| JP3000051B2 | Japan | B2 | |
| GB2338871B | United Kingdom | B | |
| GB2338872B | United Kingdom | B | |
| GB2338873B | United Kingdom | B | |
| GB2338874B | United Kingdom | B | |
| GB2338875B | United Kingdom | B | |
| GB2338876B | United Kingdom | B | |
| JP3084681B2 | Japan | B2 | |
| GB0019276D0 | United Kingdom | D0 | |
| US6145011A | United States of America | A | |
| JP2000316026A | Japan | A | |
| SG79949A1 | Singapore | A1 | |
| GB2356327A | United Kingdom | A | |
| JP2001177578A | Japan | A | |
| HK1033397A1 | Hong Kong, China | A1 | |
| GB0122573D0 | United Kingdom | D0 | |
| GB0122580D0 | United Kingdom | D0 | |
| GB0122620D0 | United Kingdom | D0 | |
| GB0122622D0 | United Kingdom | D0 | |
| GB0122624D0 | United Kingdom | D0 | |
| GB2363298A | United Kingdom | A | |
| GB2363299A | United Kingdom | A | |
| GB2364490A | United Kingdom | A | |
| GB2364491A | United Kingdom | A | |
| JP3261459B2 | Japan | B2 | |
| GB2366707A | United Kingdom | A | |
| FR2758924B1 | France | B1 | |
| GB0204600D0 | United Kingdom | D0 | |
| GB0204605D0 | United Kingdom | D0 | |
| GB0204606D0 | United Kingdom | D0 | |
| GB0204609D0 | United Kingdom | D0 | |
| GB0204718D0 | United Kingdom | D0 | |
| GB0204725D0 | United Kingdom | D0 | |
| GB0204726D0 | United Kingdom | D0 | |
| GB0204942D0 | United Kingdom | D0 | |
| GB2363298B | United Kingdom | B | |
| GB2364491B | United Kingdom | B | |
| JP3283864B2 | Japan | B2 | |
| JP2002158717A | Japan | A | |
| KR100321899B1 | Republic of Korea | B1 | |
| GB2356327B | United Kingdom | B | |
| GB2332837B | United Kingdom | B | |
| GB2370734A | United Kingdom | A | |
| GB2370735A | United Kingdom | A | |
| GB2371188A | United Kingdom | A | |
| GB2371189A | United Kingdom | A | |
| GB2371958A | United Kingdom | A | |
| GB2371959A | United Kingdom | A | |
| GB2370734B | United Kingdom | B | |
| GB2370735B | United Kingdom | B | |
| GB2372182A | United Kingdom | A | |
| GB2320167B | United Kingdom | B | |
| GB2371188B | United Kingdom | B | |
| GB2371958B | United Kingdom | B | |
| GB2371959B | United Kingdom | B | |
| GB2372182B | United Kingdom | B | |
| JP2003069606A | Japan | A | |
| US2003118034A1 | United States of America | A1 | |
| US6618366B1 | United States of America | B1 | |
| US2003179758A1 | United States of America | A1 | |
| JP2004048744A | Japan | A | |
| CN1520086A | China | A | |
| CN1170398C | China | C | |
| HK1068754A1 | Hong Kong, China | A1 | |
| JP2005287067A | Japan | A | |
| JP2005341549A | Japan | A | |
| JP3756895B2 | Japan | B2 |
8 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Application deemed withdrawn, or ip right lapsed, due to non-payment of renewal feeWithdrawnR119 | R119 | |
| Change of applicant/patenteeR081 | R081 | |
| Change of representativeR082 | R082 | |
| Patent grant now finalGrantedR020 | R020 | |
| Grant decision by examination section/examining divisionR018 | R018 | |
| Response to examination communicationR016 | R016 | |
| Request for examination paragraph 448110 | 8110 | |
| Divided out of (supplement):Q172 | Q172 |
Numbers
- Publication
- 19758970
- Publication, DOCDB
- 19758970
- Publication, EPODOC
- DE19758970
- Application
- 19758970
- Application, DOCDB
- 19758970
- Application, EPODOC
- DE19971058970
Titles2
- English
- Integrated Telecommunication System
- German
- Integriertes Fernmeldesystem
Classification
- CPC, 11
- H04L63/0272
- H04L29/12009
- H04L29/12367
- H04L29/12424
- H04L29/12801
- H04L61/2514
- H04L61/2535
- H04L61/6004
- H04L63/10
- H04L63/12
- Y04S40/20
- IPC, 4
- H04L12 66
- H04L29 10
- H04L29 06
- H04L29 12