Network driver, computer incorporated with the network driver and server
Abstract
Problem to be solved.To quickly access an information resource belonging to a desired VLAN. A network driver 32 set in a terminal device 30 transmits from an IP address / VLAN ID correspondence table that defines the correspondence between the IP address of each computer on the network and the VLAN ID of the VLAN to which they belong. The configuration is such that the VLAN ID to which the destination IP address of the IP packet belongs is read, the Ethernet packet with the VLAN ID added to the IP packet is created, and the Ethernet packet is sent to the network. Therefore, it is not necessary to set a dedicated program for assigning VLAN on the VLAN authentication switch 20, and the VLAN to which the destination computer belongs is assigned to the local terminal regardless of the computer that sends the IP packet. Will be. [Selection diagram] Fig. 3

Term
Projected expiry 14 May 2028.
- Priority and filed
- Published
- Today
- Projected expiry
6 claims: 2 independent, 4 dependent
- 1ネットワーク上の各端末装置にインストールされるコンピュータプログラムからなるネットワークドライバであって、 ネットワーク上のいずれかのコンピュータとの通信の際に、自端末から送信されるIPパケットの送信先IPアドレスを取得するステップと、 前記各コンピュータのIPアドレスと各コンピュータが所属するVLANのVLAN IDとの対応を規定したIPアドレス・VLAN ID対応テーブルから、前記送信先IPアドレスの所属するVLAN IDを読み込むステップと、 前記送信先IPアドレスの所属するVLAN IDを前記IPパケットに付加したイーサパケットを作成して送出するステップとを備えており、 自端末が所属するVLANを、送信先IPアドレスに応じて動的に割り当て可能であることを特徴とするネットワークドライバ。
- 2自端末に、前記IPアドレス・VLAN ID対応テーブルの一時記憶領域が形成されており、 前記VLAN IDを読み込むステップでは、前記一時記憶領域にアクセスして、送信先IPアドレスが所属するVLAN IDを読み込むことを特徴とする請求項1記載のネットワークドライバ。
- 3請求項1又は2に記載のネットワークドライバがインストールされたコンピュータから構成され、VLANに所属する端末装置として用いられることを特徴とするコンピュータ。
- 4ネットワーク上の各コンピュータのIPアドレスと各コンピュータが所属するVLANのVLAN IDとの対応を規定したIPアドレス・VLAN ID対応テーブルの一時記憶領域を備えていることを特徴とする請求項3記載のコンピュータ。
- 5前記IPアドレス・VLAN ID対応テーブルの最新情報が記憶された前記ネットワーク上の専用サーバにアクセスし、当該最新情報を読み込んで、前記一時記憶領域に当該最新情報を書き込むIPアドレス・VLAN ID更新プログラムが設定されていることを特徴とする請求項3又は4記載のコンピュータ。
- 6ネットワーク上の各コンピュータのIPアドレスと各コンピュータが所属するVLANのVLAN IDとの対応を規定したIPアドレス・VLAN ID対応テーブルが記憶部に設定されており、 前記ネットワーク上の端末装置からのアクセスにより、前記IPアドレス・VLAN ID対応テーブルの最新情報を提供可能であることを特徴とするサーバ。
Independent claims6
20 paragraphs, as filed
The present invention relates to a technique for dynamically rearranging a VLAN (Virtual LAN) to which a terminal device belongs.
Patent Document 1 discloses a technique for controlling access to a VLAN from a terminal device for each user. Specifically, a user authentication server and a device authentication server are provided, these are connected to a VLAN authentication switch, user authentication information and device authentication information transmitted from the terminal device are authenticated, and a predetermined value is determined based on the authentication result. It allows the connection of the terminal device to the VLAN of.<patcit num="1"><text>Japanese Unexamined Patent Publication No. 2002-366522</text></patcit>
<p> The VLAN authentication switch disclosed in Patent Document 1 sets the VLAN allocation for each user, refers to the information from the device authentication server and the user authentication server, and sets the user authentication information transmitted from the terminal device and the like. An authentication control program (for example, a program compatible with IEEE802.1x) that collates and determines the VLAN to which it belongs is set. Immediately after starting the terminal device, the terminal device belongs to the default VLAN, but if the user authentication is successful, the terminal device belongs to the VLAN permitted in advance by the user. As a result, the VLAN to which the terminal device belongs will shift from the default VLAN to another VLAN, but this can only belong to the VLAN specified in advance for each user, and it belongs to a certain VLAN. It is not supposed to add affiliation to another VLAN while belonging. In such a case, it is possible to add affiliation by creating another connection route in the terminal device even with the conventional method, but for example, when connecting to a large number of VLANs up to 1000, this is used. It is costly and difficult to construct realistically.</p><p> The present invention has been made in view of the above, and is a network driver capable of realizing quick access to information resources belonging to a desired VLAN easily and at low cost, a computer in which the network driver is incorporated, and an IP address / VLAN ID. The object is to provide a server in which the corresponding table is set.</p>
<p> In order to solve the above problems, the invention according to claim 1 is a network driver including a computer program installed in each terminal device on the network. When communicating with any computer on the network, the step of acquiring the destination IP address of the IP packet sent from the local terminal, and A step of reading the VLAN ID to which the destination IP address belongs from the IP address / VLAN ID correspondence table that defines the correspondence between the IP address of each computer and the VLAN ID of the VLAN to which each computer belongs. It includes a step of creating and sending an ether packet in which the VLAN ID to which the destination IP address belongs is added to the IP packet. It provides a network driver characterized in that the VLAN to which the local terminal belongs can be dynamically assigned according to the destination IP address. In the invention according to claim 2, a temporary storage area of the IP address / VLAN ID correspondence table is formed in the own terminal. The VLAN The network driver according to claim 1, wherein in the step of reading the ID, the temporary storage area is accessed and the VLAN ID to which the destination IP address belongs is read. The invention according to claim 3 is provided with a computer comprising a computer on which the network driver according to claim 1 or 2 is installed and used as a terminal device belonging to a VLAN. The invention according to claim 4 is characterized in that it includes a temporary storage area of an IP address / VLAN ID correspondence table that defines the correspondence between the IP address of each computer on the network and the VLAN ID of the VLAN to which each computer belongs. The computer according to claim 3 is provided. In the invention according to claim 5, the dedicated server on the network in which the latest information of the IP address / VLAN ID correspondence table is stored is accessed, the latest information is read, and the latest information is written in the temporary storage area. The computer according to claim 3 or 4, wherein the IP address / VLAN ID update program is set. In the invention according to claim 6, an IP address / VLAN ID correspondence table that defines the correspondence between the IP address of each computer on the network and the VLAN ID of the VLAN to which each computer belongs is set in the storage unit. Provided is a server characterized in that the latest information of the IP address / VLAN ID correspondence table can be provided by access from a terminal device on the network.</p>
<p> According to the present invention, the network driver set in the terminal device transmits from the IP address / VLAN ID correspondence table that defines the correspondence between the IP address of each computer on the network and the VLAN ID of the VLAN to which they belong. The configuration is such that the VLAN ID to which the destination IP address of the IP packet belongs is read, the Ethernet packet with the VLAN ID added to the IP packet is created, and the Ethernet packet is sent to the network. As a result, regardless of the computer that transmits the IP packet, the VLAN to which the destination computer belongs can be assigned to the own terminal each time communication is performed. According to the present invention, the above network driver and the IP address / VLAN ID correspondence table may be set in the terminal device, and it is possible to make the terminal device belong to a desired VLAN with a simple configuration and at low cost.</p>
Hereinafter, embodiments of the present invention will be described in more detail with reference to the drawings. FIG. 1 is a diagram showing an overall configuration of a VLAN network including an authentication server and a VLAN authentication switch.
As shown in FIG. 1, the VLAN network is constructed by including the authentication server 10, the VLAN authentication switch 20, and the terminal device 30 (30a, 30b, 30c). The VLAN authentication switch 20 includes a plurality of connection ports 21 and is connected to the authentication server 10 and the terminal device 30 via a LAN cable. The terminal device 30 is, for example, an arithmetic processing unit composed of an MPU (Micro Processing Unit), a main memory, or the like in the apparatus main body, a hard disk storing software for arithmetic processing, and an input / output unit for these data. It consists of a personal computer or the like equipped with input / output ports. Further, as shown in FIG. 2, the terminal device 30 includes an OS, various application programs, a supplicant 31 that transmits authentication information of the terminal device (own terminal) 30, a network driver 32, and the like as software. Is installed.
The network driver 32 of this embodiment is a computer program having a function of assigning a VLAN to which the terminal device (own terminal) 30 belongs. Specifically, an IP address that reads the IP address of the computer to which the IP packet is sent when communicating with any computer on the network, for example, a server having some information resource or another terminal device 30. A VLAN ID read step that reads the VLAN ID to which the destination IP address belongs from the IP address / VLAN ID correspondence table that defines the correspondence between the read step 321 and the IP address of each computer and the VLAN ID of the VLAN to which each computer belongs. Sending step 323 to create and send an ether packet (ether packet with the VLAN ID specified in IEEE802.1Q) added to the IP packet to be transmitted by adding 322 and the VLAN ID read in VLAN ID reading step 322 to the transmitted IP packet. And have.
The IP address / VLAN ID correspondence table is stored in the temporary storage area 33 formed in the storage unit of the terminal device 30. Therefore, the VLAN ID reading step 322 accesses the temporary storage area 33 and reads the VLAN ID to which the IP address read by the IP address reading step 321 belongs.
The IP address / VLAN ID update program 34 is set in the terminal device 30. This IP address / VLAN ID update program 34 periodically accesses a dedicated server (IP address / VLAN ID compatible server 40) on the network in which the latest information of the IP address / VLAN ID correspondence table is stored, or It is set to be accessed at the required time, reads the latest information of the IP address / VLAN ID correspondence table, and writes the latest information to the temporary storage area 33. As a result, the IP address / VLAN ID correspondence table stored in the temporary storage area 33 is maintained with the latest information updated periodically.
The IP address / VLAN ID compatible table stored in the storage unit of the IP address / VLAN ID compatible server 40 can be used together with the authentication server 10 in response to an increase or decrease in the number of computers participating in the network, a change in the VLAN ID, and the like. The administrator always keeps the latest information.
Here, the VLAN authentication switch 20 to which the terminal device 30 is connected is set to the trunk port so that the terminal device 30 can belong to a plurality of permitted VLANs by the authentication server 10.
Next, the operation of this embodiment will be described. As shown in FIG. 3, for example, when the user terminal 30a, which is one of the terminal devices 30, communicates, first, a predetermined authentication step is performed between the supplicant 31 of the user terminal 30a and the authentication server 10. Is carried out.
When communicating from the user terminal 30a to the information resource server A belonging to VLAN ID = 10 after the authentication process, the IP address reading step 321 of the network driver 32 is performed from the user terminal (own terminal) 30a. Reads the IP address of information resource server A, which is the destination of the IP packet to be sent. When this destination IP address is read, the VLAN ID reading step 322 accesses the IP address / VLAN ID compatible table stored in the temporary storage area 33 (or IP address / VLAN ID compatible server 40) of the user terminal 30a. .. Refer to the IP address / VLAN ID correspondence table and read the VLAN ID = 10 corresponding to the IP address of the information resource server A. After reading VLAN ID = 10, sending step 323 creates an ether packet with this VLAN ID = 10 added to the IP packet and sends it to the network.
Since the VLAN authentication switch 20 is connected to the trunk port, this ether packet is sent to the information resource server A belonging to VLAN ID = 10. Therefore, at this point, the user terminal 30a belongs to VLAN ID = 10.
Next, when the user terminal 30a communicates with the information resource server B belonging to VLAN ID = 20, the IP address reading step 321 is the IP packet transmitted from the user terminal (own terminal) 30a. The IP address of the information resource server B, which is the destination, is read, and the VLAN ID reading step 322 refers to the IP address / VLAN ID correspondence table and reads the VLAN ID = 20 corresponding to the IP address of the information resource server B. When VLAN ID = 20 is read, sending step 323 creates and sends an ether packet with VLAN ID = 20 added to the IP packet. As a result, this ether packet is transmitted to the information resource server B belonging to VLAN ID = 20, and at this point, the user terminal 30a belongs to VLAN ID = 20. Therefore, if the user terminal 30b, which is another terminal device 30, belongs to VLAN ID = 20 after undergoing a predetermined authentication process, the user terminal 30a is the user terminal 30b at this point. Communication with is possible.
As described above, in the present embodiment, the VLAN to which the terminal device 30 (user terminals 30a, 30b) belongs is the destination IP address by referring to the IP address / VLAN ID correspondence table each time communication is performed. Can be assigned correspondingly. Therefore, a plurality of VLANs are dynamically assigned to the terminal device 30 each time communication is performed. As a result, for example, although communication is performed as the terminal device 30 belonging to VLAN ID = 10, such as the above user terminal 30a, communication is performed as the terminal device 30 belonging to VLAN ID = 20. As a result, communication between different VLANs can be easily established.
<figref num="1">It is a figure which showed an example of the VLAN network for demonstrating one Embodiment of this invention.</figref><figref num="2">It is a figure for demonstrating the configuration of the network driver installed in the terminal apparatus.</figref><figref num="3">It is a figure for demonstrating the operation of the said embodiment.</figref>
Code description
10 Authentication device 20 VLAN authentication switch 30 Terminal device 31 supplicant 32 network driver 321 IP address read step 322 VLAN ID read step 323 Sending step 324 Memory step 33 Temporary storage 34 IP address / VLAN ID support update program 40 IP address / VLAN ID compatible server
4 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US9923733B2 | Cited by | United States of America | Applicant |
| WO2014033835A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JP2014526216A | Cited by | Japan | Examiner |
| JP2014225926A | Cited by | Japan | Examiner |
| US9503695B2 | Cited by | United States of America | Applicant |
| JP2014526216A | Cited by | Japan | Search report |
| US9413554B2 | Cited by | United States of America | Applicant |
| JP2003244185A | Cites | Japan | Search report |
| JP2005020170A | Cites | Japan | Search report |
| JP2008098937A | Cites | Japan | Examiner |
1 member in 1 office
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2008126834 | Japan | A | |
| JP20080126834 | – | – | – |
Members1
| Document | Office | Kind | |
|---|---|---|---|
| JP2009278317AThis record | Japan | A |
5 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Decision of refusalJAPANESE INTERMEDIATE CODE: A02A02 | A02 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A821A521 | A521 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 2009278317
- Publication, DOCDB
- 2009278317
- Publication, EPODOC
- JP2009278317
- Application
- 126834
- Application, DOCDB
- 2008126834
- Application, EPODOC
- JP20080126834
Titles2
- Japanese
- ネットワークドライバ、該ネットワークドライバが組み込まれたコンピュータ及びサーバ
- English
- Network driver, computer and server in which the network driver is installed
Classification
- IPC, 3
- H04L12 46
- H04L12 56
- H04L12 70