Packet communication system and node constituting the same and edge device
Abstract
[Task] There is a processing load due to decapsulation and encapsulation at the node.
Solution.In the node 10, information in which the IP addresses of the edge devices 3a and 3b and the MAC addresses of the computer terminals 1a to 1d accommodated by each edge device are associated with each other is collected and registered in advance, and the computer terminals 1a are registered. If there is an inquiry about the MAC address of the other party's terminal by the ARP request packet, when returning the ARP response packet, the IP address of the edge device 3b accommodating the other party's terminal is also notified together with the MAC address of the other party's terminal. , In the edge device 3a, the MAC address and the IP address are associated and registered. For subsequent received packets, the edge device 3a refers to the registered contents, extracts the IP address of the edge device 3b that accommodates the destination terminal, encapsulates the IP address in the destination IP packet, and nodes the node. Send to. This allows node 10 to simply route IP packets.

Term
Term ended
Projected expiry passed 17 December 2018, 7.8 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
7 claims: 4 independent, 3 dependent
- 1【特許請求の範囲】 【請求項1】 ユーザ端末から受信したデータリンク層の第1パケットをIPパケットaにカプセル化し、ネットワークを介してPPPにより送出するエッジ装置(エッジ装置A)と、該エッジ装置Aから上記IPパケットaをPPPによりネットワークを介して受信し、該IPパケットaをデータリンク層の第2パケットにカプセル化してLANに送出するRASサーバと、該RASサーバから上記LANを介して上記第2パケットを受信し、該第2パケットで送られてきた上記IPパケットaをデカプセル化して上記第1パケットを取り出し、該第1パケットの宛先の端末を収容して該宛先の端末に上記第1パケットを配信するエッジ装置(エッジ装置B)を、予め登録された情報を参照して判別し、判別したエッジ装置B宛のIPパケットbに上記第1パケットをカプセル化し、該IPパケットbを上記RASサーバ宛のデータリンク層の第3パケットにカプセル化して上記LANに送出するノードとからなり、上記RASサーバは、上記IPパケットbをPPPにより上記エッジ装置Bに送信し、該エッジ装置Bは、受信したIPパケットbをデカプセル化して上記第1パケットを取り出し上記宛先の端末に配信するパケット通信システムであって、上記ノードは、上記エッジ装置AでIPパケットにカプセル化した上記ユーザ端末からのデータリンク層のパケットが、上記ユーザ端末からの相手先端末のアドレスを問い合わせるARP要求パケットであることを判別する手段と、上記予め登録された情報を参照して、上記相手先端末のMACアドレスと該相手先端末を収容するエッジ装置(エッジ装置C)のIPアドレスを抽出する手段と、上記ARP要求パケットに対応するARP応答パケットを、上記抽出した相手先端末のMACアドレスを送信元、上記ユーザ端末を宛先とするデータリンク層のパケットとして作成する手段と、上記ARP応答パケットを、上記エッジ装置Cを送信元、上記エッジ装置Aを宛先とするIPパケットcにカプセル化する手段とを有して、上記IPパケットcを上記RASサーバ宛のデータリンク層のパケットにカプセル化して上記LANに送出し、上記エッジ装置Aは、上記RASサーバから受信した上記IPパケットcの送信元アドレスと該IPパケットcにカプセル化された上記ARP応答パケットの送信先アドレスから、上記相手先端末が上記エッジ装置Cに収容されていることを判別する手段と、該手段の判別結果に基づき、上記相手先端末のMACアドレスと上記エッジ装置CのIPアドレスとを対応付けて登録する手段と、上記ユーザ端末から上記相手先端末への上記データリンク層のパケットの上記IPパケットへのカプセル化時、上記登録した対応付け情報があれば、上記エッジ装置CのIPアドレスを宛先とするIPパケットdにカプセル化する手段とを有し、上記ノードでは、上記IPパケットdに対しては、該IPパケットdに設定されたIPアドレスに基づくルーティングのみを行なうことを特徴とするパケット通信システム。
- 2【請求項2】 ユーザ端末から受信したデータリンク層のEパケットをIPパケットaにカプセル化してネットワークに送出するエッジ装置(エッジ装置A)と、上記IPパケットaを受信して、該IPパケットaをデカプセル化して上記Eパケットを取り出し、該Eパケットの宛先の端末を収容して該宛先の端末に上記Eパケットを配信するエッジ装置(エッジ装置B)を予め登録された情報を参照して判別し、判別したエッジ装置B宛のIPパケットbに上記Eパケットをカプセル化して上記ネットワークに送出するノードとからなり、上記ユーザ端末からのデータリンク層のパケットをIPパケットにカプセル化して転送するパケット通信システムであって、上記ノードは、上記エッジ装置AでIPパケットにカプセル化した上記ユーザ端末からのデータリンク層のパケットが、上記ユーザ端末からの相手先端末のアドレスを問い合わせるARP要求パケットであることを判別する手段と、上記予め登録された情報を参照して、上記相手先端末のMACアドレスと該相手先端末を収容するエッジ装置(エッジ装置C)のIPアドレスを抽出する手段と、上記ARP要求パケットに対応するARP応答パケットを、上記抽出した上記相手先端末のMACアドレスを送信元、上記ユーザ端末を宛先とするデータリンク層のパケットとして作成する手段と、上記ARP応答パケットを、上記エッジ装置Cを送信元、上記エッジ装置Aを宛先とするIPパケットcにカプセル化する手段とを有して、上記IPパケットcを上記ネットワークに送出し、上記エッジ装置Aは、上記ネットワークを介して受信した上記IPパケットcの送信元アドレスと該IPパケットcにカプセル化された上記ARP応答パケットの送信先アドレスから、上記相手先端末が上記エッジ装置Cに収容されていることを判別する手段と、該手段の判別結果に基づき、上記相手先端末のMACアドレスと上記エッジ装置CのIPアドレスとを対応付けて登録する手段と、上記ユーザ端末から上記相手先端末への上記データリンク層のパケットの上記IPパケットへのカプセル化時、上記登録した対応付け情報があれば、上記エッジ装置CのIPアドレスを宛先とするIPパケットdにカプセル化する手段とを有し、上記ノードでは、上記IPパケットdに対しては、該IPパケットdに設定されたIPアドレスに基づくルーティングのみを行なうことを特徴とするパケット通信システム。
- 3【請求項3】 ユーザ端末から受信したデータリンク層の第1パケットをIPパケットaにカプセル化しネットワークを介してPPPにより送出するエッジ装置(エッジ装置A)から上記IPパケットaを受信し、該IPパケットaをデータリンク層の第2パケットにカプセル化してLANに送出するRASサーバに接続され、上記RASサーバからの上記第2パケットを受信して、該第2パケットで送られてきた上記IPパケットaをデカプセル化して上記第1パケットを取り出し、該第1パケットの宛先の端末を収容して該宛先の端末に上記第1パケットを配信するエッジ装置(エッジ装置B)を予め登録された情報を参照して判別し、判別したエッジ装置B宛のIPパケットbに上記第1パケットをカプセル化し、該IPパケットbを上記RASサーバ宛のデータリンク層の第3パケットにカプセル化して上記LANに送出することにより、上記RASサーバから上記エッジ装置Bへ、該エッジ装置Bから上記宛先の端末へ上記IPパケットbにカプセル化した上記第1パケットを配信するノードであって、上記エッジ装置AでIPパケットにカプセル化した上記ユーザ端末からのデータリンク層のパケットが、上記ユーザ端末からの相手先端末のアドレスを問い合わせるARP要求パケットであることを判別する手段と、上記予め登録された情報を参照して、上記相手先端末のMACアドレスと該相手先端末を収容するエッジ装置(エッジ装置C)のIPアドレスを抽出する手段と、上記ARP要求パケットに対応するARP応答パケットを、上記抽出した相手先端末のMACアドレスを送信元、上記ユーザ端末を宛先とするデータリンク層のパケットとして作成する手段と、上記ARP応答パケットを、上記エッジ装置Cを送信元、上記エッジ装置Aを宛先とするIPパケットcにカプセル化する手段とを有し、上記IPパケットcを上記RASサーバを介して上記エッジ装置Aに送出し、上記ユーザ端末に上記相手先端末のMACアドレスを通知すると共に、上記エッジ装置Aに上記相手先端末のMACアドレスと該相手先端末を収容する上記エッジ装置CのIPアドレスを通知することを特徴とするノード。
- 4【請求項4】 ユーザ端末から受信したデータリンク層のEパケットをIPパケットaにカプセル化してネットワークに送出するエッジ装置(エッジ装置A)に接続され、該エッジ装置Aからの上記IPパケットaを受信して、該IPパケットaをデカプセル化して上記Eパケットを取り出し、該Eパケットの宛先の端末を収容して該宛先の端末に上記Eパケットを配信するエッジ装置(エッジ装置B)を予め登録された情報を参照して判別し、判別したエッジ装置B宛のIPパケットbに上記Eパケットをカプセル化して上記ネットワークに送出することにより、上記エッジ装置Bから上記宛先の端末へ上記IPパケットbにカプセル化した上記第1パケットを配信するノードであって、上記エッジ装置AでIPパケットにカプセル化した上記ユーザ端末からのデータリンク層のパケットが、上記ユーザ端末からの相手先端末のアドレスを問い合わせるARP要求パケットであることを判別する手段と、上記予め登録された情報を参照して、上記相手先端末のMACアドレスと該相手先端末を収容するエッジ装置(エッジ装置C)のIPアドレスを抽出する手段と、上記ARP要求パケットに対応するARP応答パケットを、上記抽出した上記相手先端末のMACアドレスを送信元、上記ユーザ端末を宛先とするデータリンク層のパケットとして作成する手段と、上記ARP応答パケットを、上記エッジ装置Cを送信元、上記エッジ装置Aを宛先とするIPパケットcにカプセル化する手段とを有し、上記IPパケットcを上記ネットワークを介して上記エッジ装置Aに送出し、上記ユーザ端末に上記相手先端末のMACアドレスを通知すると共に、上記エッジ装置Aに上記相手先端末のMACアドレスと該相手先端末を収容する上記エッジ装置CのIPアドレスを通知することを特徴とするノード。
- 5【請求項5】 請求項3、もしくは、請求項4のいずれかに記載のエッジ装置であって、上記ノードが送出した上記IPパケットcの送信元アドレスと、上記IPパケットcにカプセル化された上記ARP応答パケットの送信先アドレスとから、上記相手先端末が上記エッジ装置Cに収容されていることを判別する手段と、該手段の判別結果に基づき、上記相手先端末のMACアドレスと上記エッジ装置CのIPアドレスとを対応付けて登録する手段と、上記ユーザ端末から上記相手先端末への上記データリンク層のパケットの上記IPパケットへのカプセル化時、上記登録した対応付け情報があれば、上記相手先端末に対応付けられたエッジ装置(エッジ装置D)のIPアドレスを宛先とするIPパケットdにカプセル化する手段とを有し、上記IPパケットdを上記ノードに送出し、該ノードでの、上記IPパケットdに設定されたIPアドレスに基づくルーティングにより、上記IPパケットdを上記エッジ装置Dに転送することを特徴とするエッジ装置。
- 6【請求項6】 請求項1から請求項5のいずれかに記載のエッジ装置であって、上記IPパケットaのカプセル化の際、該IPパケットaのIPヘッダに、自装置が属するグループの識別情報(グループID)を付与する手段と、受信した上記ノードでカプセル化されたIPパケットbのIPヘッダに付与されたグループIDが自装置の属するグループIDと一致するか否かを判別する手段とを有し、一致した場合に上記IPパケットbをデカプセル化してデータリンク層のパケットを取り出し宛先に送出することを特徴とするエッジ装置。
- 7【請求項7】 請求項1から請求項6のいずれかに記載のノードであって、受信した上記IPパケットaから取り出したデータリンク層のパケットの送信先のグループIDを、予め登録された情報に基づき判別する手段と、該手段で判別したグループIDが、上記IPパケットaのIPヘッダに付与されたグループIDと一致するか否かを判別する手段とを有し、該手段での照合結果が一致であれば、上記IPパケットaから取り出したデータリンク層のパケットの送信制御を行なうことを特徴とするノード。
Independent claims7
273 paragraphs in 1 section, as filed
Description: TECHNICAL FIELD [Detailed description of the invention]
【0001】
[Technical field to which the invention belongs]
The present invention relates to a computer communication technique for transmitting packets between computer terminals via a network, and in particular, a packet communication system suitable for efficient packet transfer by PPP (Point-to-Point Protocol) and a packet communication system thereof. It relates to the constituent nodes and edge devices.
【0002】
[Conventional technology]
Conventionally, as a computer communication system for home users, a technique of packetizing data between computers and transmitting it by PPP using a dial-up communication line and a modem has been widely used.
【0003】
In this PPP, IP packets (packets handled by the Internet Protocol) are mapped to HDLC (High Level Data Link Control Procedure) frames and transmitted. That is, the packet is mapped between the start flag and the end flag and transmitted on the communication line. Then, when communication is started, processing such as call connection and user authentication is performed.
【0004】
FIG. 16 shows an example of a conventional technique for transmitting data between computers by PPP using such a dial-up line and a modem. FIG. 16 is a block diagram showing a configuration example of a computer communication system using conventional PPP.
【0005】
In FIG. 16, 160 and 161 are computer terminals, 162 is a modem, 163 is an interface between a modem 162 and a computer terminal 160 (usually a standard interface such as RS232C is used), and 164 is a subscriber system (subscriber network / public line). , 165 is a RAS (Remote Access Service) server with a modem and PPP function (indicated as "RAS" in the figure), 166 is a LAN (Local Area Network), 167 is a router, and 168 is an application server (in the figure, "Server"). ").
【0006】
The computer terminals 160, 161, the modem 162, and the interface 163 make up the user-side system, and the RAS server 165, the LAN 166, the router 167, and the application server 168 make up the center-side system. The operation will be described below.
【0007】
When making a call, the computer terminal 160 makes a call connection with the RAS server 165 on the center side via the modem 162 by PPP. That is, the RAS server 165 is called by the telephone number, the information such as the default router address is received from the RAS server 165 through the necessary authentication procedures such as PAP (Password authentication Protocol) and CHAP (Challenge Handshake Authentication Protocol), and then the link is performed. To establish.
【0008】
After the link is established, IP packets can be transmitted between the computer terminal 160 and the RAS server 165. As a result, communication between the computer terminal 160 and the server 168 of the center side system or between the computer terminals 160 and 161 becomes possible via the router 167 connected to the LAN 166. Regarding the technology for transmitting IP packets using such PPP, for example, see pages 171 to 173 of "Technology for Easy-to-Understand Communication Protocols" by Nobutaka Maruyama (published by Ohmsha, 1998). Are listed.
【0009】
Next, the frame structure in PPP will be described with reference to FIG. FIG. 17 is an explanatory diagram showing an example of a PPP frame structure. In FIG. 17, 171 is an IP packet from a computer terminal, and 172 is a PPP frame.
【0010】
In computer communication in a general Ethernet LAN, various protocol data are placed on an Ethernet frame and the terminal (computer) is identified by the Ethernet address (MAC (Media Access Control) address) in the header. Then, as shown in FIG. 17, only the IP packet portion is transmitted as a PPP frame by mapping between the start flag and the header and the FCS (Frame Check Sequence) and the end flag. FCS is an error correction code.
【0011】
Regarding this PPP, the details of the procedure and format have already been standardized by the IETF (Internet Engineering Task Force), and it is widely used in the computer communication field. I will not explain. Further, in FIG. 16, the case where the modem 162 is used assuming an analog line has been described, but in the case of a digital line, the digital connection is made via the terminal uggter (TA) instead of the modem 162. In this case, the same applies to the opposite RAS server 165 side.
【0012】
As described above, in PPP communication technology using a dial-up line and a modem, computer communication is possible via a modem through a public line, but usually the communication protocol between terminals is single (IP). In addition, ensuring security depends on the user, and the MAC address information of the terminal is lost. Therefore, in PPP communication, communication between a plurality of computers belonging to a predetermined group (group communication) cannot be performed by an arbitrary protocol and at a high security level.
【0013】
A technique for solving such a problem is described in Japanese Patent Application No. 10-341329 filed by the inventor of the present invention. Hereinafter, the technique will be described with reference to FIG. FIG. 18 is a block diagram showing a configuration example of a communication device that performs group communication at a high security level by PPP and a communication system using the communication device.
【0014】
In FIG. 18, 1a to 1d are computer terminals, 2 is an Ethernet interface, 3a'and 3b' are edge devices that perform PPP communication, 4 is an RS232C interface, 5 is a modem, 6 is a network, and 7 is a RAS server (in the figure, (Described as "RAS"), 8 is a LAN via Ethernet, 9 is a management device, 10 is a node, and 11 is a server.
【0015】
The user side system is configured by computer terminals 1a to 1d, Ethernet interface 2, edge devices 3a', 3b', RS232C interface 4, and modem 5, and the subscriber system is configured by network 6 consisting of public lines and the like, and RAS. The center side system is composed of server 7, LAN 8, management device 9, node 10, and server 11.
【0016】
In the user-side system, each of the edge devices 3a'and 3b', as shown by the edge device 3a', is a terminal accommodating unit 3c, an address information collection processing unit 3d, an information notification processing unit 3e, a packet conversion processing unit 3f, and PPP. It has a communication processing unit 3g, and accommodates one or more computer terminals 1a to 1d by the terminal accommodating unit 3c. The edge devices 3a'and 3b'and the computer terminals 1a to 1d are connected by the Ethernet interface 2 and communicated by Ethernet packets.
【0017】
In addition, the edge devices 3a'and 3b' control the modem 5 via the RS232C interface 4 by the PPP communication processing unit 3g, and communicate with the RAS server 7 of the center side system through the network 6 (subscriber system). Communicates IP packets by PPP. The telephone number and the like of the RAS server 7 of the center side system called by this PPP are set / registered in advance in the edge devices 3a and 3b. Also, specify the address of node 10 as the default router.
【0018】
The RAS server 7 of the center side system communicates IP packets by PPP with the edge devices 3a'and 3b' of the user side system via the network 6, and the management device 9 via LAN8 in the center side system. , Node 10 and server 11 communicate with each other in Ethernet packets.
【0019】
With such a configuration, in this communication system, the edge devices 3a'and 3b' create IP packets in which data link layer packets (Ethernet packets) sent from a plurality of accommodated computer terminals are used as IP data. It is transmitted by PPP, and Ethernet packets are extracted from the IP packets received by PPP and distributed based on the Ethernet address (MAC address). This makes it possible to perform broadcast distribution or the like using an Ethernet address (MAC address) using PPP.
【0020】
Further, the edge devices 3a'and 3b' are transmitted by PPP by adding the identifier (group ID) of the group to which the own device belongs to the header of the IP packet including the Ethernet packet, and the IP packet received by PPP. Only when the group ID assigned to the header is the same as the group ID to which the own device belongs, the Ethernet packet is extracted from the received IP packet and distributed based on the Ethernet address. Since the distribution of received IP packets (Ethernet packets) is controlled based on the group ID set in the edge devices 3a'and 3b' in this way, the distribution of broadcast packets to an illegally connected computer terminal is particularly distributed. Can be prevented.
【0021】
Further, the management device 9 is based on the notification from the edge devices 3a', 3b', the group ID to which each edge device 3a', 3b' belongs, the identification information of each edge device 3a', 3b', and each edge device 3a'. Registered in association with the identification information of each computer terminal 1a to 1d accommodated in, 3b', and node 10'transmits and receives IP packets with each edge device 3a', 3b' via the RAS server 7. Based on the group ID given to the received IP packet and the address information of the data link layer packet (Ethernet packet) in this IP packet, and the registered contents of the management device 9, the received IP packet By performing transfer control, communication within the group specified by the group ID given to the IP packet is performed by PPP.
【0022】
In particular, as the transfer control of the IP packet, the node 10'sets the registration contents of the registration device 9 when, for example, the destination of the Ethernet packet sent by unicast from the edge devices 3a', 3b' is not in the own LAN. Refer to it to determine whether the group IDs of the destination terminal and the source terminal (the group IDs of the edge devices 3a'and 3b' that accommodate each computer terminal) and the group IDs given to the IP packets match. , If they match, create an IP packet with the address of the edge device 3a', 3b' accommodating the destination computer terminal as the IP header (with a group ID) and the Ethernet packet as IP data, and create an IP packet with the RAS server. It is sent to the edge devices 3a'and 3b' by PPP via 7. As a result, the security in unicast communication can be efficiently controlled on the center side.
【0023】
For example, regarding the Ethernet packet sent by broadcast from the edge devices 3a'and 3b', the node 10'does not collate and determine the group ID, and the IP address for broadcasting (for example, "for example," " 255.255.255.255 ") is set and sent to each edge device 3a', 3b'via the RAS server 7, and each edge device 3a', 3b' collates and discriminates the group ID, and the same group ID. Deliver to computer terminals 1a to 1d belonging to.
【0024】
However, in such a communication system, in the node 10', as the transfer control of the IP packet, the address of the edge devices 3a', 3b' accommodating the destination computer terminal is the IP header, and the Ethernet packet is the IP data. Packets must be created, processing time is required, and throughput is reduced.
【0025】
[Problems to be Solved by the Invention]
The problem to be solved is that it takes time to create an IP packet on the node side when communicating with a high security level by any protocol by PPP. An object of the present invention is a packet communication system that solves these problems of the prior art and enables efficient communication at a high security level by any protocol by PPP, and the nodes and edges constituting the packet communication system. To provide the device.
【0026】
[Means for solving problems]
In order to achieve the above object, in the packet communication system of the present invention and the nodes and edge devices constituting the packet communication system, the IP address of each edge device and the MAC address of each terminal accommodated by each edge device are previously set in the node. Collect and register the corresponding information. Then, if the user terminal inquires about the MAC address of the destination terminal by means of an Ethernet packet (ARP request packet), the node returns the ARP response packet corresponding to the inquiry to the edge device (edge device A). , The IP address of the edge device (edge device B) accommodating the other party terminal is also notified together with the MAC address of the other party terminal, and in the edge device (edge device A) accommodating the user terminal, the MAC address of the other party terminal is also notified. Register the IP address of edge device B in association with it.
【0027】
After that, when the Ethernet packet from the user terminal to the destination terminal is received, the edge device A refers to the registered contents and extracts the IP address of the edge device (edge device C) accommodating the destination terminal. Then, the IP address is encapsulated in the destination IP packet and sent to the node. As a result, the node only needs to perform routing based on the address information of the IP packet, decapsulates the received IP packet, searches for the IP address of the edge device C accommodating the destination terminal, and goes to the IP packet. Encapsulation is not required and the throughput is improved.
【0028】
BEST MODE FOR CARRYING OUT THE INVENTION
Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings. FIG. 1 is a block diagram showing a first embodiment of the configuration of the packet communication system of the present invention and the nodes and edge devices constituting the packet communication system according to the present invention. The packet communication system of this example performs communication by PPP, and will be described below as a PPP communication system.
【0029】
In FIG. 1, 1a to 1d are computer terminals, 2 is an Ethernet interface, 3a and 3b are edge devices, 4 is an RS232C interface, 5 is a modem, 6 is a network, and 7 is a RAS server (in the figure, "RAS" is described. ), 8 is an Ethernet LAN, 9 is a management device, 10 is a node, and 11 is a server.
【0030】
The user side system is configured by computer terminals 1a to 1d, Ethernet interface 2, edge devices 3a, 3b, RS232C interface 4, and modem 5, the subscriber system is configured by network 6 consisting of public lines, etc., and the RAS server 7 The center side system is composed of LAN8, management device 9, node 10, and server 11.
【0031】
In the user-side system, each of the edge devices 3a and 3b is a terminal accommodating unit 3c, an address information collection processing unit 3d, an information notification processing unit 3e, a packet conversion processing unit 3f, and a PPP communication processing unit, as shown by the edge device 3a. It has 3g, an ARP processing unit 3h, a table management unit 3i, and a second packet creation processing unit 3j, and the terminal accommodating unit 3c accommodates one or more computer terminals 1a to 1d. The edge devices 3a and 3b and the computer terminals 1a to 1d are connected by the Ethernet interface 2 and communicated by Ethernet packets.
【0032】
Further, the edge devices 3a and 3b control the modem 5 via the RS232C interface 4 by the PPP communication processing unit 3g, and are connected to the RAS server 7 of the center side system through the network 6 (subscriber system) by PPP. Communicates IP packets. The telephone number and the like of the RAS server 7 of the center side system called by this PPP are set / registered in advance in the edge devices 3a and 3b. Also, specify the address of node 10 as the default router.
【0033】
The RAS server 7 of the center side system communicates IP packets with the edge devices 3a and 3b of the user side system via the network 6 by PPP, and in the center side system, the management device 9 and the node via LAN8. Communication of Ethernet packets with each of 10 and server 11.
【0034】
Hereinafter, the operation of the PPP communication system by the terminal accommodating unit 3c, the address information collection processing unit 3d, the information notification processing unit 3e, the packet conversion processing unit 3f, and the PPP communication processing unit 3g in the edge device 3a will be described.
【0035】
The edge device 3a collects the address information (MAC address) of the subordinate computer terminals 1a and 1b connected by the Ethernet interface 2 by the address information collection processing unit 3d, and the information notification processing unit 3e collects the SNMP (Simple Network Management). Notify the management device 9 of the center side system using a communication protocol such as Protocol). The timing of this notification includes when the power of the edge device 3a is turned on, or when a packet is received from the computer terminals 1a and 1b.
【0036】
In this way, the edge devices 3a and 3b automatically notify the management device 9 of the address information of the computer terminal, so that the user of the computer terminals 1a and 1b centers the address when adding or changing the computer terminal. There is no need to apply to the side system. In addition, even if the computer terminal moves between users, even if the edge device at the move destination notifies the management device 9 as a new computer terminal, the management device 9 confirms that the movement is performed by an address duplication check. By updating the information, it is possible to support the movement of terminals.
【0037】
Further, in the management device 9, based on the group registration information specified in advance by the user, the edge devices 3a and 3b and the computer terminals 1a to 1d under each are linked in the group to create the group information. In addition to registering in the management table 90 as shown in FIG. 9, the group registration information is notified to the node 10 and the edge devices 3a and 3b as the group identification IP by the SNMP protocol or the like.
【0038】
FIG. 9 is an explanatory diagram showing a configuration example of a management table registered in the management device in FIG. The management table 90 consists of each item column of group ID, edge device ID, and subordinate terminal ID, and each group (A, B, ...) in the group ID has an identifier (LEC (1), ... 2), (3), (4), (5) ...) are registered in the edge device ID column, and a MAC address is registered as an identifier of the subordinate terminal for each edge device. .. Here, the identifier of each edge device (LEC (1), (2), (3), (4), (5) ...) is the IP address of each edge device.
【0039】
In FIG. 1, the edge device 3a further creates an IP packet using the Ethernet packets sent from the accommodated computer terminals 1a and 1b as IP data by the packet creation processing unit 3f, and the PPP communication processing unit 3g uses the PPP communication processing unit 3g. From the IP packet sent from RAS server 7 by PPP and received from RAS server 7 by PPP in PPP communication processing unit 3g, Ethernet packet is extracted by packet creation processing unit 3f and corresponds to the Ethernet address (MAC address). Deliver to computer terminals 1a and 1b. In this way, in this example, PPP can be used to deliver packets using an Ethernet address (MAC address).
【0040】
Further, the packet creation processing unit 3f of the edge device 3a assigns the identifier (group ID) of the group to which the own edge device 3a belongs to the header (IP header) of the IP packet when the IP packet is created from the Ethernet packet. .. Then, only when the group ID assigned to the header of the IP packet received by PPP from the RAS server 7 is the same as the group ID to which the own device belongs, the Ethernet packet is extracted from the received IP packet and used as the Ethernet address. Based on this, it is delivered to each computer terminal 1a, 1b. In this way, by controlling the delivery of the received IP packet (Ethernet packet) in the edge device 3a based on the group ID, it is possible to prevent the delivery of the broadcast packet to the illegally connected computer terminal. Can be done.
【0041】
In addition, the packet creation processing unit (described as "packet creation unit" in the figure) 10a is also provided in the node 10 of the center side system, for example, by PPP from the edge device 3a via the RAS server 7. When receiving a unicast packet, whether or not the destination (destination) of the Ethernet address of the received packet and the computer terminal of the source belong to the same group based on the group information registered in the management device 9. Only in the case of the same group, an edge device accommodating the destination computer terminal is set as the destination in the IP header, an IP packet using the received Ethernet packet as IP data is created, and PPP is performed via the RAS server 7. Is sent by. As a result, it is possible to prevent erroneous delivery to computer terminals outside the group on the center side.
【0042】
Next, the packets used for PPP communication from the edge devices 3a and 3b will be described with reference to FIGS. 2 to 4. FIG. 2 is an explanatory diagram showing a configuration example of a packet used in the edge device in FIG. In FIG. 2, 21 is an Ethernet packet, 22 is an IP packet, and 23 is a PPP frame.
【0043】
In the edge devices 3a and 3b of FIG. 1, the Ethernet packets 21 from the computer terminals 1a to 1d are placed on the data area of the IP packet 22, and the IP packet 22 is further mapped to the PPP frame 23 (HDLC frame). By doing so, while the conventional PPP supports only a single protocol (usually the IP protocol), the PPP of this example can use the Ethernet protocol or an arbitrary protocol.
【0044】
FIG. 3 is an explanatory diagram showing a detailed example of the frame configuration of the Ethernet packet in FIG. As shown in FIG. 3, in the edge devices 3a and 3b of FIG. 1, among the frame configurations of the original Ethernet packets 21a transmitted from the computer terminals 1a to 1d, the preamble and the CRC (Cyclic Redundancy Check; "Cyclic Redundancy Check;" "Check", excluding the FCS (Frame Check Sequence) part that is the calculation result, that is, the Ethernet packet 21 consisting of the destination MAC address, the source MAC address, the protocol type, and the data part. , Encapsulate on the data area of the IP packet.
【0045】
FIG. 4 is an explanatory diagram showing a detailed example of the frame configuration of the IP packet in FIG. As shown in FIG. 4, in the edge devices 3a and 3b of FIG. 1, a group ID (IDentifier / IDentification) is assigned to the option portion 22c in the header 22a of the IP packet 22.
【0046】
Next, the configuration of the edge device 3a in FIG. 1 will be described with reference to FIG. FIG. 5 is a block diagram showing a configuration example of the edge device in FIG. In FIG. 5, 51 is a processor unit equipped with a CPU (Central Processing Unit) that encapsulates Ethernet packets into IP packets and performs PPP processing (referred to as CPU in the figure), and 52 is data RAM (in the figure). Among them, "RAM" is described), 53 is a program memory for storing the processing program of the processor section 51 (described as "P-memory" in the figure), and 54 is an Ethernet interface (described as "EI / F" in the figure). ), 55 is the modem interface (indicated as "MI / F" in the figure), and 56 is the bus.
【0047】
By the processing of the processor unit 51 based on the processing program stored in the program memory 53, the terminal accommodating unit 3c in the edge device 3a of FIG. 1, the address information collection processing unit 3d, the information notification processing unit 3e, the packet creation processing unit 3f, The PPP communication processing unit 3g, the ARP processing unit 3h, the table management unit 3i, and the second packet creation processing unit 3j are configured.
【0048】
That is, the edge device 3a takes in the Ethernet packets from the computer terminals 1a and 1b into the data RAM 52 from the Ethernet interface 54 via the bus 56, and uses the data RAM 52 as a buffer to perform IP packetization processing and PPP processing in the processor section 51. Then, the data is transferred from the modem Internet section 55 to the network 6 side via the modem 5.
【0049】
Further, the IP packet from the network 6 sent via the modem 5 is taken into the data RAM 52 from the modem interface 55 via the bus 6, and the data RAM 52 is used as a buffer and processed by the processor section 51. As an Ethernet packet, it is transmitted to each computer terminal 1a and 1b via the Ethernet interface 54.
【0050】
Next, the configuration of the node 10 in FIG. 1 will be described with reference to FIG. FIG. 6 is a block diagram showing a configuration example of the node in FIG. In FIG. 6, 61 is a processor unit that performs encapsulation processing (indicated as CPU in the figure), 62 is a data RAM (indicated as RAM in the figure), and 63 is a processing program of the processor unit 61. The program memory to be stored (indicated as "P-memory" in the figure), 64 is the Ethernet interface (indicated as "EI / F" in the figure), and 65 is the bus.
【0051】
By the processing of the processor unit 61 based on the processing program stored in the program memory 63, the packet creation processing unit 10a at the node 10 in FIG. 1, the ARP discrimination unit 10c, the address extraction unit 10d, the ARP response packet creation unit 10e, and the IP An ARP response unit 10b or the like composed of an encapsulation unit 10f is configured.
【0052】
Then, the node 10 transmits the packets from the edge devices 3a and 3b (computer terminals 1a to 1d) of FIG. 1 sent via the RAS server 7 and the LAN 8 from the Ethernet interface 64 via the bus 65. It is taken into RAM 62, and this data RAM 62 is used as a buffer, filtered and encapsulated in the processor unit 61, and transferred to the Ethernet interface 64 again.
【0053】
The packet transmission operation in the PPP communication system of FIG. 1 provided with the edge device 3a of FIG. 5 and the node 10 of FIG. 6 will be described with reference to FIGS. 7 and 8.
【0054】
FIG. 7 is an explanatory diagram showing an example of a transmission format of a unicast packet between computer terminals in FIG. 1, and FIG. 8 is a sequence diagram showing an operation example of the PPP communication system of FIG. 1 related to unicast transmission in FIG. is there.
【0055】
The transmission format shown in FIG. 7 shows only the address information part of the header information of the Ethernet packet, and the description of other header information (protocol type, etc.) is omitted. The IP address in the IP header of the IP packet (indicated as "H" in the figure) is an address corresponding to the IP address of the edge device or node.
【0056】
Hereinafter, transmission of a unicast packet between computer terminals (PCs) in FIG. 7 will be described. In FIG. 7, the unicast Ethernet packet 71 (PC-B is the destination Ethernet address (MAC address), PC-A is the source Ethernet address) from the computer terminal (denoted as "PC-A" in the figure) 1a. In the edge device 3a, the MAC address)) is encapsulated in an IP packet whose source is the edge device 3a and whose destination is node 10. At this time, the edge device 3a adds the group ID to the option area of the header.
【0057】
Then, the edge device 3a sends the IP packet created in this way to the connection destination RAS server 7 as a PPP frame 72 by PPP. In PPP frame 72, "FLAG" consists of 1-byte data "7E", "H" consists of the IP address of the destination node 10 and the IP address of the source edge device 3a, and "ID" is. It consists of a group ID, and the next "PC-B", "PC-A", etc. consist of Ethernet packet 71.
【0058】
Upon receiving the PPP frame 72 from the edge device 3a, the RAS server 7 attaches a header to the PPP frame 72 with the node 10 as the destination (RSN) and the RAS server 7 as the source (RAS), and sends the Ethernet packet 73. Generate it, send it to LAN8 in Figure 1, and deliver it to node 10.
【0059】
The node 10 that has received the Ethernet packet 73 searches for the group information managed by the management device 9 in FIG. 1 based on the Ethernet address (PC-B, PC-A) of the Ethernet packet 73. If the Ethernet addresses ("PC-B" and "PC-A") are in the same group, the edge device 3b that accommodates the computer terminal 1d with "PC-B" as the Ethernet address is the destination, and node 10 is the destination. Creates (encapsulates) an IP packet consisting of the IP header as the source and the IP data consisting of the received Ethernet packet, and generates an Ethernet packet 74 with this IP packet as the data part and the destination as the RAS server 7. And send it to LAN8.
【0060】
In this way, when checking the address on the node 10, it is only necessary to search for the terminal addresses under the edge device belonging to the same group using the group ID as a key, so that the address search processing time can be reduced. The RAS server 7 creates a PPP frame 75 based on the received Ethernet packet 74, and transmits the PPP frame 75 to the edge device 3b specified as the destination in the header of the IP packet by PPP.
【0061】
Upon receiving the PPP frame 75, the edge device 3b extracts the Ethernet packet 76 encapsulated in the IP packet from the PPP frame 75 and transfers it to the computer terminal 1d under the control specified by the Ethernet packet 76 as the destination.
【0062】
The transmission processing operation of each of the above packets will be described with reference to FIG. When the edge device 3a receives an Ethernet packet (EP) from the accommodating computer terminal (step 801), the edge device 3a creates an IP packet (IP) consisting of the Ethernet packet as IP data and an IP header destined for the node 10. That is, it is encapsulated (step 802) and transmitted by PPP to RAS server 7 (step 803).
【0063】
The RAS server 7 creates an Ethernet packet (ep) having the IP packet as a data part based on the destination information of the IP packet in the PPP frame received from the edge device 3a, and forwards it to the node 10 (step 804). ). Upon receiving the Ethernet packet (ep) from the RAS server 7, the node 10 determines the destination specified in the header of the Ethernet packet (EP) in the IP packet (IP) in the data part (step 805).
【0064】
Then, the groups to which the destination computer terminal and the source computer terminal belong are determined based on the group information managed by the management device 9 in FIG. 1 (step 806). The group information managed by the management device 9 may be imported into the node 10 in advance. If it does not belong to the same group (step 807), the Ethernet packet (EP) is discarded (step 808), and if it belongs to the same group, it is determined whether or not the determined destination is in LAN8 (step). 809).
【0065】
If it is in the LAN, the Ethernet packet (EP) that was considered to be the IP data in the IP packet (IP) is delivered to the LAN8 (step 810), and if it is not in the LAN8, the received Ethernet packet (EP) is IP. Encapsulate in packet (IP) (step 811). In this case, the destination of the IP packet is the edge device 3b, and the source is the node 10. Then, it is sent to the RAS server 7 as an Ethernet packet (ep) (step 812).
【0066】
The RAS server 7 forwards the IP packet (IP) received as the Ethernet packet (ep) to the edge device 3b, which is the destination, by PPP (step 813). Then, the edge device 3b reads the destination address information (destination) from the Ethernet packet (EP) encapsulated in the received IP packet (IP) (step 814), and sends the Ethernet packet (to the destination computer terminal 1d) to the Ethernet packet (destination). Transfer the EP) (step 815).
【0067】
As described above, in the PPP communication system of this example, in the edge devices 3a and 3b, the Ethernet packets from the computer terminals 1a to 1d are placed on the data area as IP packets from the edge devices 3a and 3b, and the IP header section is used. The group ID is added to, and this IP packet is placed on the PPP frame and sent to node 10 on the center side via the RAS server 7, and for the received packet from node 10, the IP packet is sent from the PPP frame. Is taken out, the group ID is checked, and the Ethernet packet in the IP data area is transferred to the computer terminals 1a to 1d only when they are in the same group.
【0068】
In addition, node 10 checks the address of the Ethernet packet encapsulated from the received IP packet, and if the computer terminal of the destination address is accommodated in the edge devices 3a and 3b, it is addressed to the edge devices 3a and 3b. This Ethernet packet is encapsulated in an IP packet and forwarded, and when the terminal of the destination address is on LAN8, the Ethernet packet is forwarded to LAN8. This makes it possible to perform group communication, which communicates only between computer terminals connected to the edge device of the registered member, via a dial-up line by using PPP.
【0069】
In this way, by encapsulating Ethernet packets as IP packet data in PPP frames and transmitting them, a protocol-free communication environment can be provided, and further, a group ID is assigned and the check is performed to improve communication security between members. Can be planned. That is, it is possible to perform communication with a high security level by an arbitrary protocol only between computers registered as the same group member. Further, when checking the group ID, it is only necessary to search only the terminal addresses under the edge device belonging to the same group using the group ID as a key, so that the address search process / time can be significantly reduced.
【0070】
The processing operations described above are performed in the terminal accommodating unit 3c, the address information collecting processing unit 3d, the information notification processing unit 3e, the packet conversion processing unit 3f, the PPP communication processing unit 3g, and the node 10 in the edge device 3a of FIG. This is a processing operation using the packet creation unit 10a.
【0071】
In such processing, as the transfer control of the IP packet at the node 10, an IP packet is created (encapsulated) in which the addresses of the edge devices 3a and 3b are used as the IP header and the Ethernet packet is used as the IP data. Therefore, processing time is required and the throughput is lowered.
【0072】
As shown in the edge device 3a, the edge devices 3a and 3b of this example in FIG. 1 are further provided with an ARP processing unit 3h, a table management unit 3i, and a second packet creation processing unit 3j, and also a node. The ARP response unit 10b including an ARP discrimination unit 10c, an address extraction unit 10d, an ARP response packet creation unit 10e, and an IP encapsulation unit 10f is provided in 10.
【0073】
With such a configuration, in the PPP communication system shown in FIG. 1, the time required for encapsulation into an IP packet on the node side is unnecessary, and the throughput can be improved. The processing operation will be described below. In the edge device 3a, the ARP request packet inquiring about the address of the computer terminal 1d from the computer terminal 1a is encapsulated in an IP packet addressed to the node 10 and transmitted. This processing operation is normal.
【0074】
Node 10 receives the IP packet from the edge device 3a addressed to itself, decapsulates it, and the encapsulated Ethernet packet is an ARP (Address Resolution Protocol) request packet for inquiring the MAC address of the destination terminal. When the ARP determination unit 10c determines that there is, the address extraction unit 10d refers to the registered contents of the management device 9, and first, as a normal process, the MAC address of the computer terminal 1d requested by the ARP request packet. Is extracted, and then the IP address of the edge device 3b associated with the MAC address is extracted.
【0075】
Then, the node 10 uses the ARP response packet creation unit 10e to create an ARP response packet corresponding to the ARP request packet with the MAC address of the computer terminal 1d extracted in this way as the source and the computer terminal 1a as the destination, and further. , The IP encapsulation unit 10f encapsulates this ARP response packet into an IP packet whose source is the IP address of the edge device 3b and whose destination is the IP address of the edge device 3a, and then becomes an Ethernet packet addressed to the RAS server 7. Encapsulate and send to LAN8.
【0076】
In the edge device 3a, when an IP packet in which an ARP response packet is encapsulated by PPP is received from the RAS server 7, the ARP processing unit 3h encapsulates the source address of the received IP packet and the IP packet c. From the source address of the ARP response packet, it is determined that the computer terminal 1d is housed in the edge device 3b, and based on the result, the MAC address of the computer terminal 1d and the IP address of the edge device 3b are associated with each other. Register by the table management unit 3i.
【0077】
After performing such registration, in the edge device 3a, if there is the correspondence information registered by the table management unit 3i at the time of encapsulating the normal Ethernet packet into the IP packet from the computer terminal 1a to the computer terminal 1d. The second packet creation processing unit 3j encapsulates this Ethernet packet into an IP packet destined for the IP address of the edge device 3b, and transmits it to the RAS server 7 by PPP.
【0078】
For such an IP packet, the node 10 only performs routing based on the IP address set in this IP packet, so that the IP packet decapsulation process described above into the Ethernet packet and the new IP packet are newly performed. It eliminates the need for encapsulation of IP packets by address, reduces processing time, and improves throughput.
【0079】
Hereinafter, the processing operation of the PPP communication system in FIG. 1 will be described in more detail with reference to FIGS. 10 to 14. FIG. 10 is a sequence diagram showing a processing operation example according to the present invention of the PPP communication system in FIG.
【0080】
This example shows an operation example based on the ARP request packet, and the MAC address of the computer terminal (described as "PC-1" in the figure) 1a to the computer terminal (described as "PC-2" in the figure) 1d. When an ARP request packet (destination is BCm = broadcast MAC address, source is P-1m = MAC address of computer terminal 1a) is sent to edge device 3a (described as "RTU-1" in the figure), In the edge device 3a, the ARP request packet is sent to the IP address (N-1i) of the node 10 (denoted as "RSN" in the figure) and the IP address (E-1i) of the edge device 3a as the source. It is encapsulated in an IP packet and transmitted to RAS server 7 (denoted as "RAS" in the figure) by PPP.
【0081】
In RAS server 7, the received IP packet is encapsulated in an Ethernet packet whose destination is the MAC address (N-1m) of node 10 and whose source is the MAC address (A-1m) of RAS server 7, and LAN8 in FIG. Send to node 10 via.
【0082】
In node 10, if the received ARP request packet is in the same group (not shown in FIG. 10, but it is assumed that a group ID is assigned as in the IP packet in FIG. 7). ), The MAC address of the computer terminal 1d and the IP address of the edge device 3b to which the computer terminal 1d is connected are notified by the proxy response.
【0083】
That is, the node 10 analyzes the received ARP request packet, determines the MAC address of the computer terminal 1d based on the inquiry content, and determines the MAC address of the computer terminal 1d based on the information from the management device 9 in FIG. Create an ARP response packet with the MAC address (P-1m) and the source as the MAC address of the computer terminal 1d, and send the ARP response packet to the IP address (E-1i) of the edge device 3a and the source. Is encapsulated in an IP packet with the IP address (E-2i) of the edge device 3b, and the IP packet is further addressed to the MAC address of the RAS server 7 (A-1m) and the source to the MAC address of node 10 (the MAC address of node 10). It is encapsulated in an Ethernet packet of N-1m) and sent to the RAS server 7.
【0084】
The RAS server 7 transmits an IP packet from the node 10 to the edge device 3a by PPP based on its destination address (E-1i). In the edge device 3a, the computer terminal 1d is edged based on the source address (E-2i) of the received IP packet and the source address (P-2m) in the ARP response packet encapsulated in the IP packet. Recognizing that it is stored under the device 3b, the correspondence is registered in the table, and the ARP packet is passed to the computer terminal 1a.
【0085】
When the computer terminal 1a that receives the ARP response packet creates an Ethernet packet addressed to the computer terminal 1d using the MAC address of the destination computer terminal 1d notified by this ARP response packet and sends it to the edge device 3a, The edge device 3a extracts the IP address (E-2i) of the edge device 3b accommodating the computer terminal 1d by referring to the registered contents of the table, and addresses this IP address (E-2i) to the edge device 3a. The Ethernet packet from the computer terminal 1a is encapsulated in the IP packet whose source is the IP address (E-1i) of 3a, and is transmitted to the RAS server 7 by PPP.
【0086】
In the RAS server 7, the received IP packet is destined for an unmanaged IP address, so an Ethernet packet destined for the MAC address of node 10 as the default router is used as the destination, and the IP packet is sent to LAN8. To do. As a result, all the IP packets from the edge device 3a are delivered to the node 10 via the RAS server 7.
【0087】
The node 10 that has received this IP packet performs routing based on the address information of the IP packet. That is, the received IP packet is returned to the RAS server 7 as it is. The RAS server 7 transmits an IP packet by PPP to the edge device 3b, which is the destination of the IP packet.
【0088】
The edge device 3b decapsulates the received IP packet and sends it to the computer terminal 1d of the destination of the Ethernet packet, and also from the address information of the IP packet from the RAS server 7 and the address information of the Ethernet packet encapsulated therein. , The MAC address (P-1m) of the source computer terminal 1a and the IP address (E-1i) of the edge device 3a are determined, associated with each other, and registered in the table.
【0089】
As a result, when sending an Ethernet packet from the computer terminal 1d to the computer terminal 1a, the edge device 3b can identify the IP address of the edge device 3a accommodating the computer terminal 1a by referring to the table, and the edge device 3b can identify the IP address of the edge device 3a accommodating the computer terminal 1a. An IP packet destined for the IP address of device 3a can be created and routed to node 10.
【0090】
In this way, by registering the IP address of each edge device and the MAC address of the computer terminal accommodated in each edge device 3a and 3b in association with each other, the processing at the node 10 is only the routing operation, and the node 10 Decapsulation of IP packets into Ethernet packets and encapsulation of Ethernet packets into IP packets is no longer required, and the routing is improved.
【0091】
In this way, examples of processing operations of the PPP communication system after registering the IP address of each edge device and the MAC address of the computer terminal accommodated in each edge device 3a and 3b in association with each other are shown in FIGS. 11 to 11 to 11. This will be described with reference to FIG.
【0092】
FIG. 11 is an explanatory diagram showing an example of a transmission format of a unicast packet between computer terminals in the PPP communication system in FIG. 1, and FIG. 12 is an example of a broadcast packet transmission format between computer terminals in the PPP communication system in FIG. FIG. 13 is an explanatory diagram showing an example of a transmission format of a unicast packet between an edge device and a management device in the PPP communication system in FIG. 1, and FIG. 14 is an explanatory diagram showing an example of a transmission format of a unicast packet in the PPP communication system in FIG. It is explanatory drawing which shows the transmission format example of the broadcast packet between and a management device.
【0093】
In FIGS. 11 to 14, the transmission format shows only the address information portion of the Heg information of the Ethernet packet. Other heg information (protocol type, etc.) is omitted. PC-A and PC-B are computer terminals 1a ,, 1d, RTU-1, -2 are edge devices 3a, 3b, RAS-1 is RAS server 7, RMS is management device 9, and RSN-1 is node 10. Represents.
【0094】
In FIG. 11, the unicast Ethernet packet from the computer terminal 1a (PC-A) for which the ARP processing has been completed has the source IP address of the edge device 3a (E-1i) in the edge device 3a (RTU-1). The destination IP address is the remote edge device 3b (E-2i), which is carried on the IP packet with the group ID (ID-k) added and transferred to the center side via RAS node 7 by PPP. Upon receiving this, the node 10 transfers it to the edge device 3b (RTU-2) side via the RAS server 7 by the routing process and delivers it to the computer terminal 1d (PC-B).
【0095】
In FIG. 12, the broadcast packet from the computer terminal 1a (PC-A) is put on the IP packet in the edge device 3a, the source is the edge device 3a (E-1i), and the destination is the node 10 (N-1i). It is transferred as an IP packet (unicast) to the center side via the RAS server 7 by PPP.
【0096】
Upon receiving this, the node 10 forwards it as a broadcast IP packet (destination is BCi: broadcast IP address) to the user side such as the edge device 3b (RTU-2) via the RAS server 7. In the edge device 3b, the packet and the group ID are extracted from the IP data, the group ID is checked, and if they are in the same group, they are transferred to the subordinate computer terminal 3b (PC-B) via the Ethernet interface. If it does not belong, discard it.
【0097】
FIG. 13 shows an example of unicast communication from the edge device 3a (RTU-1) itself to the management device 9, and is used as communication for management. That is, the unicast packet from the edge device 3a (RTU-1) is encapsulated in the edge device 3a itself and transferred to the center side as an IP packet destined for the node 10 (N-1i).
【0098】
On the node 10 that receives this, the packet is taken out, the transmission / reception address information is collated with the group information, the same group is collated, and the destination is LAN8 on the center side as an Ethernet packet of the MAC address (Sm) of the management device 9. Transfer to. Since the management device 9 assumes a general-purpose workstation and is directly connected to LAN8, it transfers without encapsulation (processing to put it on an IP packet).
【0099】
The unicast communication from the management device 9 to the edge device 3a is transferred in the reverse procedure. Further, the edge device 3a and the management device 9 are registered in advance as the same group (management group).
【0100】
FIG. 14 shows an example of broadcast communication from the edge device 3a (RTU-1) to the management device 9. The broadcast packet from the edge device 3a is encapsulated by the edge device 3a itself and forwarded to the center side as an IP packet destined for the node 10 (N-ii).
【0101】
Upon receiving this, node 10 (RSN-1) takes out the packet, checks that it is the communication of the management group from the group ID, and forwards it as an Ethernet packet to LAN8 to which the management device 9 is connected. On the other hand, the broadcast packet from the management device 9 is encapsulated in the IP packet at the node 10, the group ID is added, and the broadcast packet is forwarded to the edge device 3a (RTU-1) via the RAS server 7 (RAS-1). .. Upon receiving this, the edge device 3a extracts the Ethernet packet and the group ID, checks the group ID, and the edge device 3a itself receives the Ethernet packet and the group ID.
【0102】
As described above, in this example, by connecting the edge devices 3a and 3b to the management device 9 and the node 10 via the RAS server 7, the convenience and security are easily high by PPP using the dial-up line. A group communication system can be constructed, and throughput can be improved by devising ARP processing.
【0103】
The present invention is not limited to the PPP communication system, and examples thereof will be described below. FIG. 15 is a sequence diagram showing a processing operation example according to the present invention of the packet communication system of the present invention.
【0104】
In this example, in the communication system of FIG. 1, the edge devices 3a and 3b are directly connected by IP between the nodes 10 via the Internet without using the RAS server 7, that is, without using PPP. , An operation example based on the ARP request packet is shown. ARP inquiring the MAC address of the computer terminal (described as "PC-1" in the figure) 1a to the computer terminal (described as "PC-2" in the figure) 1d. When a request packet (destination is BCm = broadcast MAC address, source is P-1m = MAC address of computer terminal 1a) is sent to edge device 3a (described as "RTU-1" in the figure), edge device 3a Then, the ARP request packet is sent to an IP packet whose destination is the IP address (N-1i) of node 10 (indicated as "RSN" in the figure) and whose source is the IP address (E-1i) of edge device 3a. Encapsulate and send to LAN8.
【0105】
Node 10 receives this IP packet, analyzes the ARP request packet encapsulated in it, and based on the inquiry content, converts the MAC address of the computer terminal 1d into the information from the management device 9 in FIG. Based on this, an ARP response packet is created with the destination as the MAC address of the computer terminal 1a (P-1m) and the source as the MAC address of the computer terminal 1d, and the ARP response packet is used as the destination of the edge device 3a. It is encapsulated in an IP packet whose IP address (E-1i) and source are the IP address (E-2i) of the edge device 3b and transmitted to the edge device 3a.
【0106】
In the edge device 3a, the computer terminal 1d is edged based on the source address (E-2i) of the received IP packet and the source address (P-2m) in the ARP response packet encapsulated in the IP packet. Recognizing that it is stored under the device 3b, the correspondence is registered in the table, and the ARP packet is passed to the computer terminal 1a.
【0107】
When the computer terminal 1a that receives the ARP response packet creates an Ethernet packet addressed to the computer terminal 1d using the MAC address of the destination computer terminal 1d notified by this ARP response packet and sends it to the edge device 3a, The edge device 3a extracts the IP address (E-2i) of the edge device 3b accommodating the computer terminal 1d by referring to the registered contents of the table, and addresses this IP address (E-2i) to the edge device. The Ethernet packet from the computer terminal 1a is encapsulated in the IP packet whose source is the IP address (E-1i) of 3a and sent.
【0108】
Node 10 is the default router, receives the IP packet, and performs routing based on the address information of the IP packet. That is, the received IP packet is forwarded as it is to the destination edge device 3b.
【0109】
The edge device 3b decapsulates the received IP packet and sends it to the computer terminal 1d of the destination of the Ethernet packet, and from the address information of the IP packet and the address information of the Ethernet packet encapsulated therein, the source The MAC address (P-1m) of the computer terminal 1a and the IP address (E-1i) of the edge device 3a are determined, associated with each other, and registered in the table.
【0110】
As a result, when sending an Ethernet packet from the computer terminal 1d to the computer terminal 1a, the edge device 3b can identify the IP address of the edge device 3a accommodating the computer terminal 1a by referring to the table, and the edge device 3b can identify the IP address of the edge device 3a accommodating the computer terminal 1a. An IP packet destined for the IP address of device 3a can be created and routed to node 10.
【0111】
As described above with reference to FIGS. 1 to 15, in the packet communication system of this example and the nodes and edge devices constituting the packet communication system, the computer terminals 1a connected to the edge devices 3a and 3b of the registered members. In group communication that communicates only between ~ 1d, group communication via a guile-up line by using PPP is possible, and Ethernet packets are encapsulated in PPP frames as IP packet data and transmitted, which is protocol-free. Communication environment can be provided, and communication security between members can be improved by checking the newly added group ID.
【0112】
Furthermore, in this example, by devising ARP processing, packets between computer terminals 1a to 1d can be directly IP-transferred between edge devices 3a and 3b, encapsulation processing at node 10 is omitted, and only routing processing is used. As a result, the processing load on node 10 can be reduced and the throughput can be improved. Further, when checking the group ID, it is only necessary to search only the terminal addresses under the edge device belonging to the same group using the group ID as a key, so that the address search process / time can be significantly reduced.
【0113】
The present invention is not limited to the examples described with reference to FIGS. 1 to 15, and various modifications can be made without departing from the gist thereof. For example, in this example, the case where an analog line is assumed and a modem is used has been described, but in the case of a digital line, the digital connection is made via the terminal agupta (TA) instead of the modem. In this case, the same applies to the opposite RAS server side. It is also possible to place the server used by the user on the center side (in LAN8) and keep the server running at all times.
【0114】
[Effect of the invention]
According to the present invention, in a communication system in which computer terminals that communicate with each other are accommodated in a plurality of edge devices and communication is performed between the computer terminals via a node on the center side, packets are encapsulated and decapsulated at the nodes. It is possible to eliminate the process of computerization, shorten the data transfer processing time, improve the throughput, and efficiently perform communication at a high security level with any protocol by PPP. ..
[Simple explanation of drawings]
[Figure 1]
It is a block diagram which shows the 1st Example of the structure which concerns on this invention of the packet communication system of this invention and the node and edge apparatus which comprises the packet communication system.
[Figure 2]
It is explanatory drawing which shows the configuration example of the packet used in the edge apparatus in FIG.
[Fig. 3]
It is explanatory drawing which shows the detailed example of the frame structure of the Ethernet packet in FIG.
[Fig. 4]
It is explanatory drawing which shows the detailed example of the frame structure of the IP packet in FIG.
[Fig. 5]
It is a block diagram which shows the structural example of the edge apparatus in FIG.
[Fig. 6]
It is a block diagram which shows the configuration example of a node in FIG.
[Fig. 7]
It is explanatory drawing which shows the transmission format example of the unicast packet between computer terminals in FIG.
[Fig. 8]
It is a sequence diagram which shows the operation example of the PPP communication system of FIG. 1 relating to the transmission of unicast in FIG.
[Fig. 9]
It is explanatory drawing which shows the structural example of the management table registered in the management apparatus in FIG.
[Fig. 10]
It is a sequence diagram which shows the processing operation example which concerns on this invention of the PPP communication system in FIG.
[Fig. 11]
It is explanatory drawing which shows the transmission format example of the unicast packet between computer terminals in the PPP communication system in FIG.
[Fig. 12]
It is explanatory drawing which shows the transmission format example of the broadcast packet between computer terminals in the PPP communication system in FIG.
[Fig. 13]
FIG. 5 is an explanatory diagram showing an example of a transmission format of a unicast packet between an edge device and a management device in a PPP communication system in FIG.
[Fig. 14]
It is explanatory drawing which shows the transmission format example of the broadcast packet between the edge device and the management device in the PPP communication system in FIG.
[Fig. 15]
It is a sequence diagram which shows the processing operation example which concerns on this invention of the packet communication system of this invention.
[Fig. 16]
It is a block diagram which shows the configuration example of the computer communication system using the conventional PPP.
[Fig. 17]
It is explanatory drawing which shows the frame structure example of PPP.
[Fig. 18]
It is a block diagram which shows the configuration example of the communication device which performs group communication with a high security level by PPP and the communication system using it.
[Explanation of symbols]
1a ~ 1d: Computer terminal, 2: Ethernet interface, 3a, 3b, 3a', 3b': Edge device, 3c: Terminal storage unit, 3d: Address information collection processing unit, 3e: Information notification processing unit, 3f: Packet creation Processing unit, 3g: PPP communication processing unit, 3h: ARP processing unit, 3i: table management unit, 3j: second packet creation processing unit, 4: interface (RS232C), 5: modem, 6: subscriber system (subscriber) Network / public line), 7: RAS server, 8: LAN, 9: Management device, 10,10': Node, 10a: Packet creation processing unit, 10b: ARP response unit, 10c: ARP discrimination unit, 10d: Address extraction Part, 10e: ARP response packet creation part, 10f: IP encapsulation part, 11: server, 21,21a: Ethernet packet, 22: IP packet, 22a: IP header, 22b: IP data, 22c: option (group ID) , 23: PPP frame, 51: Processor part, 52: Data RAM (RAM), 53: Program memory (P-memory), 54: Ethernet interface (EI / F), 55: Modem interface (MI / F), 56 : Bus, 61: Processor section, 62: Data RAM (RAM), 63: Program memory (P memory), 64: Ethernet interface (EI / F), 65: Bus, 71,73,74,76: Ethernet packet, 72,75: PPP frame, 90: management table, 160,161: computer terminal, 162: modem, 163: interface (RS232C, etc.), 164: subscriber system (subscriber network / public line), 165: RAS (Remote Access Service) ) Server, 166: LAN (Local Area Network), 167: Router, 168: Application Server, 171: IP Packet, 172: PPP Frame.
19 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| KR101399002B1 | Cited by | Republic of Korea | Search report |
| WO03043276A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US8661525B2 | Cited by | United States of America | Applicant |
| US12160431B2 | Cited by | United States of America | Applicant |
| JP2009219127A | Cited by | Japan | Examiner |
| US7856648B2 | Cited by | United States of America | Applicant |
| JP2008258688A | Cited by | Japan | Examiner |
| US8588133B2 | Cited by | United States of America | Applicant |
| JP2022525205A | Cited by | Japan | Search report |
| JP2010178313A | Cited by | Japan | Appeal |
| JP2013504959A | Cited by | Japan | Examiner |
| JP2022525205A | Cited by | Japan | Search report |
| JP2009219127A | Cited by | Japan | Search report |
| JP2010074554A | Cited by | Japan | Examiner |
| CN108009061A | Cited by | China | Search report |
| US7796595B2 | Cited by | United States of America | Applicant |
| JP2013504960A | Cited by | Japan | Examiner |
| JP2013255245A | Cited by | Japan | Search report |
| WO03043276A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 35875298 | Japan | A | |
| JP19980358752 | – | – | – |
Numbers
- Publication
- 2000-183968
- Publication, DOCDB
- 2000183968
- Publication, EPODOC
- JP2000183968
- Application
- 10358752
- Application, DOCDB
- 35875298
- Application, EPODOC
- JP19980358752
Titles2
- Japanese
- パケット通信システムおよびそれを構成するノードとエッジ装置
- English
- [Title of the Invention] A packet communication system and a node and an edge device constituting the packet communication system.
Classification
- IPC, 4
- H04L12 28
- H04L12 46
- H04L12 66
- H04L12 70