Integrated information communication system
Abstract
This record has no abstract on file.
Term
Term ended
Expired 23 March 2020, 6.5 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
84 claims: 33 independent, 51 dependent
- 1【特許請求の範囲】 【請求項1】ユーザ通信回線の終端のICS論理端子に、ICS論理端子を識別するICSネットワークアドレスが付与され、発信側のICS論理端子識別情報、送信者ICSユーザアドレス及び受信者ICSユーザアドレスの組が定まれば、送信側のアクセス制御装置と受信側のアクセス制御装置との間にICSネットワークフレームが転送されるICS網通信回線が一意に定まり、前記ICS網通信回線を特定するためのICSネットワークフレームの転送先を定めるICSネットワークアドレスは、前記アクセス制御装置の変換表及び中継装置の中継表により規定され、固有のICSユーザアドレス体系ADXを持つ外部のICSユーザフレームが、前記ユーザ通信回線からICS論理端子を経由して前記送信側のアクセス制御装置に入力し、前記ICSユーザフレームが入力したICS論理端子を識別する情報と、前記ICSユーザフレーム内の送信者ICSユーザアドレス及び受信者ICSユーザアドレスとが共に前記アクセス制御装置の変換表のレコードに登録されていることが見出されたときに、前記ICSユーザフレームがICSネットワークアドレス体系ADSを有する内部のICSネットワークフレームに変換されるようになっており、前記ICSネットワークフレームはネットワーク制御部を含み、前記ネットワーク制御部は少なくとも前記ICS網通信回線を特定するための前記ICSネットワークアドレスを格納し、前記ICSネットワークフレームは前記ICSネットワークアドレス体系ADSのルールに従い、前記アクセス制御装置の変換表及び中継装置の中継表によりICSネットワークフレームの転送先が判定されて前記ICS網通信回線を送信され、前記ICSネットワークフレームが前記受信側のアクセス制御装置に到達したときに、前記ICSユーザフレームが前記ICSネットワークフレームから復元され、前記受信側のアクセス制御装置のICS論理端子を経て他のユーザ通信回線を転送され、外部の他の情報通信機器に到達するようになっていることを特徴とする統合情報通信システム。
- 2【請求項2】前記変換表が優先度を含んでおり、前記ICSネットワークフレームは前記変換表から取得した優先度を含み、前記ICSネットワークフレームは前記中継装置により前記ICSネットワークフレームの優先度に従って送出されるようになっている請求項1に記載の統合情報通信システム。
- 3【請求項3】前記変換表のレコードは2以上であり、前記ICS論理端子識別情報、前記送信者ICSユーザアドレス及び前記受信者ICSユーザアドレスの組に対して、前記ICS網通信回線を特定するための前記ICSネットワークアドレスの組はレコード毎に異なり、前記受信者ICSユーザアドレスを変更することにより前記ICSユーザフレームの到達先を変更できるようになっている請求項1に記載の統合情報通信システム。
- 4【請求項4】前記変換表に登録される前記送信者ICSユーザアドレス及び受信者ICSユーザアドレスが共に企業内通信用アドレス又は企業間通信用アドレスであるかに応じて、企業内通信及び企業間通信を行い得るようになっている請求項1に記載の統合情報通信システム。
- 5【請求項5】ユーザ通信回線の終端のICS論理端子に、ICS論理端子を識別するICSネットワークアドレスが付与され、ICSユーザフレームが入力するICS論理端子識別情報が定まればICSネットワークフレームが転送されるICS網通信回線が定まり、当該ICS網通信回線を特定するためのICSネットワークアドレスがアクセス制御装置の変換表のレコードとして登録されていると共に、前記レコードに要求識別が仮想専用線として登録されており、固有のICSユーザアドレス体系ADXを持つ外部のICSユーザフレームが、前記ユーザ通信回線からICS論理端子を経由して前記アクセス制御装置に入力し、前記ICS論理端子識別情報を含む前記変換表のレコードに、要求識別が仮想専用線として登録されていることが見出されたときに、前記ICSユーザフレームがICSネットワークアドレス体系ADSを有する内部のICSネットワークフレームに変換されるようになっており、前記ICSネットワークフレームはネットワーク制御部を含み、前記ネットワーク制御部は少なくとも前記ICS網通信回線を特定するための前記ICSネットワークアドレスを格納し、前記ICSネットワークフレームは前記ICSネットワークアドレス体系ADSのルールに従い、前記アクセス制御装置の変換表及び中継装置の中継表によりICSネットワークフレームの転送先が判定されて前記ICS網通信回線を送信され、前記ICSネットワークフレームが受信側のアクセス制御装置に到達したときに、前記ICSユーザフレームが前記ICSネットワークフレームから復元され、前記受信側のアクセス制御装置のICS論理端子を経て他のユーザ通信回線を転送され、外部の他の情報通信機器に到達するようになっていることを特徴とする統合情報通信システム。
- 6【請求項6】前記変換表のレコードに企業内通信/企業間通信を示す要求識別を含み、前記ICSユーザフレームが入力した前記ICS論理端子を含む前記変換表のレコードに、要求識別が仮想専用線として登録されているときは当該レコードに関する処理を行わず、次に前記要求識別が企業内通信/企業間通信であると見出されたときに、前記ICSネットワークフレームに変換されるようになっている請求項1に記載の統合情報通信システム。
- 7【請求項7】ICS論理端子の識別情報、送信者ICSユーザアドレス(企業間)及び受信者ICSユーザアドレス(企業間)の組が定まれば、ICSネットワークフレームが転送されるICS網通信回線が定まり、当該ICS網通信回線を特定するためのICSネットワークアドレスがアクセス制御装置の変換表のレコードに登録されており、前記変換表のレコード内に、送信者ICSユーザアドレス(企業内)が前記送信者ICSユーザアドレス(企業間)に1対1に対応付けて登録されており、前記変換表に企業間通信を意味する要求識別を含み、前記ICSユーザフレームが入力したICS論理端子を識別する情報と、前記ICSユーザフレーム内の送信者ICSユーザアドレス及び受信者ICSユーザアドレスの組が、共に前記変換表のレコードに、ICS論理端子を識別する情報と、送信者ICSユーザアドレス(企業内)及び受信者ICSユーザアドレス(企業間)として登録されていることが見出されたとき、前記ICSユーザフレーム内の送信者ICSユーザアドレスを、前記変換表のレコードに登録される送信者ICSユーザアドレス(企業間)に変更した後に、前記ICSユーザフレームがICSネットワークアドレス体系ADSを有する内部のICSネットワークフレームに変換され、前記ICSネットワークフレームはネットワーク制御部を含み、前記ネットワーク制御部は少なくとも前記ICS網通信回線を特定するための前記ICSネットワークアドレスを格納し、前記ICSネットワークフレームは前記ICSネットワークアドレス体系ADSのルールに従い、前記アクセス制御装置の変換表及び中継装置の中継表によりICSネットワークフレームの転送先が判定されて前記ICS網通信回線を送信され、前記ICSネットワークフレームが受信側のアクセス制御装置に到達したときに、前記ICSユーザフレームが前記ICSネットワークフレームから復元され、前記受信側のアクセス制御装置のICS論理端子を経て他のユーザ通信回線を転送され、外部の他の情報通信機器に到達するようになっていることを特徴とする統合情報通信システム。
- 8【請求項8】処理装置及びICS網データベースで成り、前記アクセス制御装置からの要求に対して自らが保持する結果を返信するか、又は前記アクセス制御装置からの質問に対する回答を保持していないとき、ICS網サーバ通信機能を用いて他のICS網サーバと通信して回答を取得し、この結果を質問元のアクセス制御装置に返信する機能のICS網サーバを有している請求項1に記載の統合情報通信システム。
- 9【請求項9】処理装置と、前記ICSユーザアドレスに対応するICSネットワークアドレスの関係を対応づける対応表を持つアドレス管理サーバを更に含んでいる請求項8に記載の統合情報通信システム。
- 10【請求項10】前記処理装置及びICSネーム変換表を含み、前記アクセス制御装置からICSネームの提示を受け、これに対するICSユーザアドレスを前記ICSネーム変換表から求め、得られた結果を前記アクセス制御装置に通知し、前記アドレス管理サーバは少なくとも前記ICSユーザアドレス及び前記ICSネットワークアドレスを前記変換表に書込むと共に、前記ICSネームに対応するICSユーザアドレスをユーザに返送する機能のICSネームサーバを有している請求項8に記載の統合情報通信システム。
- 11【請求項11】前記処理装置及びICSネーム変換表を含み、前記アクセス制御装置からICSネームの提示を受け、これに対するICSユーザアドレスを前記ICSネーム変換表から求め、得られた結果を前記アクセス制御装置に通知し、前記アドレス管理サーバは少なくとも前記ICSユーザアドレス及び前記ICSネットワークアドレスを一時変換表に書込むと共に、前記ICSネームに対応するICSユーザアドレスをユーザに返送する機能のICSネームサーバを有している請求項10に記載の統合情報通信システム。
- 12【請求項12】前記処理装置及びICSネーム変換表を含み、前記アクセス制御装置からICSネームの提示を受け、これに対するICSユーザアドレスを前記ICSネーム変換表から求め、得られた結果を前記アクセス制御装置に通知し、前記ICSネームに対応するICSユーザアドレスをユーザに返送する機能を有している請求項10に記載の統合情報通信システム。
- 13【請求項13】前記アクセス制御装置は、ICSユーザフレームを受信すると、そのICSユーザフレームに含まれるICSユーザアドレスを基に変換表に保持されているICSフレーム毎の課金方式の種別を読出し、読出した種別が従量制課金方式を示す値の場合は課金情報を生成し、その課金情報を課金情報フレームとして課金サーバに伝え、前記読出した内容が定額制課金方式を示す値の場合は、課金情報の生成やその課金情報を課金情報フレームとして課金サーバに伝えることを行わない機能を有している請求項3又は5に記載の統合情報通信システム。
- 14【請求項14】外部に少なくともアクセス制御装置を置き、内部にアクセス制御装置統括管理サーバを置くことにより企業内通信或いは企業間通信を行うようにした請求項3又は5に記載の統合情報通信システム。
- 15【請求項15】前記アクセス制御装置が暗号化手段及び復号化手段を有し、ICSカプセル化のとき、前記ICSユーザフレームを前記暗号化手段で暗号文に変換してICS内部を送信し、ICS逆カプセル化のとき、暗号文に変換されている前記ICSユーザフレームを前記復号化手段で元のICSユーザフレームに戻すようになっている請求項3又は5に記載の統合情報通信システム。
- 16【請求項16】前記アクセス制御装置を集約アクセス制御装置及び簡易アクセス制御装置に機能分離し、ユーザは前記簡易アクセス制御装置に接続され、前記変換表を前記集約アクセス制御装置内部の集約変換表及び前記簡易アクセス制御装置内部の簡易変換表に分け、ICSカプセル化及びICS逆カプセル化は前記簡易アクセス制御装置で行い、課金及び電子署名は前記集約アクセス制御装置で行うようになっている請求項3又は5に記載の統合情報通信システム。
- 17【請求項17】ユーザサービスサーバ、ICS当局サーバ、変換表サーバをそれぞれ複数有し、ICS加入の申し込みを前記ユーザサービスサーバで受付け、前記ICS当局サーバがICSユーザアドレス、ICSネットワークアドレス及びICSネームを割当て、前記変換表サーバが前記アクセス制御装置内の変換表を書き換えるようになっている請求項3又は5に記載の統合情報通信システム。
- 18【請求項18】ICS運用者が統括ユーザサービスサーバ、統括リソース管理サーバ、統括経路情報サーバに指示を与え、個別の報告をさせることにより運用するようになっている請求項3又は5に記載の統合情報通信システム。
- 19【請求項19】前記アクセス制御装置の内部の電話回線変換部から電話回線を経て電話機に接続し、電話音声による通信が可能である請求項3又は5に記載の統合情報通信システム。
- 20【請求項20】ICS受付け者がローミング端末に暗号機能及び暗号関連データを埋め込み、前記暗号機能はパラメータを変更することにより選択できるようになっている請求項3又は5に記載の統合情報通信システム。
- 21【請求項21】電話番号をICSドメイン名として通信相手先のICSユーザアドレス及びICSネットワークアドレスを取得し、前記ICSネットワークアドレスは呼び出し側のアクセス制御装置内の変換表に保持するようになっている請求項3又は5に記載の統合情報通信システム。
- 22【請求項22】前記電話番号をICSドメイン名として、通信相手先のICSユーザアドレス及びICSネットワークアドレスを取得し、ICSユーザフレームにディジタル化した音声を乗せるようになっている請求項21に記載の統合情報通信システム。
- 23【請求項23】ユーザ通信回線の終端のICS論理端子に、ICS論理端子を識別するICSネットワークアドレスが付与され、発信側のICS論理端子識別情報及び受信者ICSユーザアドレスの組が定まれば、送信側のアクセス制御装置と受信側のアクセス制御装置との間にICSネットワークフレームが転送されるICS網通信回線が一意に定まり、前記ICS網通信回線を特定するためのICSネットワークフレームの転送先を定めるICSネットワークアドレスは、前記アクセス制御装置の変換表及び中継装置の中継表により規定され、固有のICSユーザアドレス体系ADXを持つ外部のICSユーザフレームが、前記ユーザ通信回線からICS論理端子を経由して前記送信側のアクセス制御装置に入力し、前記ICSユーザフレームが入力したICS論理端子を識別する情報と、前記ICSユーザフレーム内の受信者ICSユーザアドレスとが共に前記アクセス制御装置の変換表のレコードに登録されていることが見出されたときに、前記ICSユーザフレームがICSネットワークアドレス体系ADSを有する内部のICSネットワークフレームに変換されるようになっており、前記ICSネットワークフレームはネットワーク制御部を含み、前記ネットワーク制御部は少なくとも前記ICS網通信回線を特定するための前記ICSネットワークアドレスを格納し、前記ICSネットワークフレームは前記ICSネットワークアドレス体系ADSのルールに従い、前記アクセス制御装置の変換表及び中継装置の中継表によりICSネットワークフレームの転送先が判定されて前記ICS網通信回線を送信され、前記ICSネットワークフレームが前記受信側のアクセス制御装置に到達したときに、前記ICSユーザフレームが前記ICSネットワークフレームから復元され、前記受信側のアクセス制御装置のICS論理端子を経て他のユーザ通信回線を転送され、外部の他の情報通信機器に到達するようになっており、ICSユーザアドレスの値を有しているユーザ1と、ICSユーザアドレスの他の値を有している他のユーザ2との間で、それぞれのユーザ通信回線が接続するアクセス制御装置の変換表及び中継装置の中継表にICSユーザフレームを送受可能とするICS網通信回線が設定されており、 他のユーザmと、前記ユーザ1又は2との間で、それぞれのユーザ通信回線が接続するアクセス制御装置の変換表及び中継装置の中継表にICSユーザフレームを送受可能とするICS網通信回線が設定されており、 他のユーザnと、前記ユーザ1、2又はmとの間で、それぞれのユーザ通信回線が接続するアクセス制御装置の変換表及び中継装置の中継表にICSユーザフレームを送受可能とするICS網通信回線が設定されており、 前記全てのICS網通信回線の集合として、前記ユーザ1、2、m、nとの間でのみ前記ICSユーザフレームを送受可能な閉域網をICS内部に定義し、前記閉域網を内部に含むようになっていることを特徴とする統合情報通信方法。
- 24【請求項24】ユーザ通信回線の終端のICS論理端子に、ICS論理端子を識別するICSネットワークアドレスが付与され、ICS論理端子識別情報及び受信者ICSユーザアドレスの組が定まれば、着信ICSネットワークアドレスが一意に定まるように前記変換表のレコードとして登録されており、前記ICSユーザフレームが入力したICS論理端子識別情報と、前記ICSユーザフレーム内の受信者ICSユーザアドレスとが共に前記アクセス制御装置の変換表のレコードに登録されていることが見出されたときに、前記ICSネットワークフレームに変換されるようになっており、固有のICSユーザアドレス体系ADXを持つ外部のICSユーザフレームが、ユーザ通信回線からICS論理端子を経由して、送信側のアクセス制御装置に入力すると、前記変換表の管理の基に内部のICSネットワークフレームに変換され、前記ICSネットワークフレームは前記ICSネットワークアドレス体系ADSのルールに従い内部を送信され、前記ICSネットワークフレームが受信側のアクセス制御装置に到達したときに、前記ICSユーザフレームが前記ICSネットワークフレームから復元され、前記受信側のアクセス制御装置のICS論理端子を経て他のユーザ通信回線を転送され、外部の他の情報通信機器に到達するようになっており、 ICSユーザアドレスの値を有しているユーザ1と、ICSユーザアドレスの他の値を有している他のユーザ2との間で、ユーザ1のユーザ通信回線が接続するアクセス制御装置及びユーザ2のユーザ通信回線が接続する他のアクセス制御装置の変換表それぞれにICSユーザフレームを送受可能とするレコードが設定されており、 他のユーザmと、前記ユーザ1又は2との間で、それぞれのユーザ通信回線が接続するアクセス制御装置の変換表のレコードが設定されており、これによってユーザmはユーザ1又は2との間でICSユーザフレームを送受可能とするレコードが設定されており、 他のユーザnは前記ユーザ1、2又はmとの間で、それぞれのユーザ通信回線が接続するアクセス制御装置の変換表にICSユーザフレームを送受可能とするレコードが設定されており、 前記全てのレコードの集合として前記ユーザ1,2、m、nとの間でのみ前記ICSユーザフレームを送受可能な閉域網をICS内部に定義し、前記閉域網を内部に含むようになっていることを特徴とする統合情報通信方法。
- 25【請求項25】請求項23又は24に記載の方法により閉域網X及び他の閉域網Yを定め、前記閉域網Xに属するユーザxと前記閉域網Yに属するユーザyとの間で前記ICSユーザフレームを送受できないようになっており、前記閉域網を2以上含むようになっている統合情報通信システム。
- 26【請求項26】ユーザ通信回線の終端のアクセス制御装置のICS論理端子に、ICS論理端子を識別するICSネットワークアドレスが付与され、 第1のルールとして、前記ICS論理端子の識別情報が定まれば着信ICSネットワークアドレスが一意に定まるように変換表のレコードとして登録され、かつ前記レコードに要求識別が仮想専用線として登録されており、 第2のルールとして、前記ICS論理端子の識別情報及び受信者ICSユーザアドレスの組が定まれば、着信ICSネットワークアドレスが一意に定まるように前記変換表のレコードとして登録されており、かつ前記レコードに要求識別が企業内通信として登録されており、 前記変換表のレコードは2以上であり、同一のICS論理端子識別情報に対して、前記受信者ICSユーザアドレスを変更することにより前記ICSユーザフレームの到達先を変更できるようになっており、 前記ICS論理端子からICSユーザフレームが入力し、前記ICS論理端子識別情報を含む前記変換表のレコードが見出されて要求識別が仮想専用線として登録されているときは、前記第1のルールにより得た着信ICSネットワークアドレスを用いてICSネットワークフレームに変換し、 又は前記要求識別が企業内通信として登録されているときは前記第2のルールとして、前記ICSユーザフレームが入力したICS論理端子の識別情報、前記ICSユーザフレーム内の受信者ICSユーザアドレスが共に前記変換表のレコードに登録されていることが見出されたときに、前記ICSユーザフレームがICSネットワークフレームに変換され、 次に、前記第1のルールと前記第2のルールによる手続きが共に成立しなかったとき、つまり前記ICSユーザフレームが入力したICS論理端子の識別情報、前記ICSユーザフレーム内の受信者ICSユーザアドレスの組が前記変換表のレコードとして登録されていることが見出されないときに、 前記ICSユーザフレーム内の受信者ICSユーザアドレスが企業間通信アドレスの区間であるかを判定し、企業間通信アドレスの区間である場合は前記ICSユーザフレームをそのままICSネットワークフレームとし、このとき、前記ICSネットワークフレーム内の着信ネットワークアドレスは前記ICSユーザフレーム内の受信者ICSユーザアドレスであり、 前記ICSネットワークフレームは少なくとも1以上の中継装置を経由して送信され、他のアクセス制御装置に到達すると前記ICSネットワークフレームから前記ICSユーザフレームを復元し、ICSネットワークフレーム内の着信ネットワークアドレスが、企業間通信アドレス区間である場合は、前記ICSネットワークフレームをそのまま前記ICSユーザフレームとし、前記ICSユーザフレームを外部の他の情報通信機器に転送されるようになっており、仮想専用線、企業内通信及び企業間通信を行い得るようになっているために用いるアクセス制御装置。
- 27【請求項27】ユーザ通信回線の終端のICS論理端子に、ICS論理端子を識別するICSネットワークアドレスが付与され、前記変換表のレコードに受信者ICSユーザアドレスが定まるのみで、ICS網サーバのICSネットワークアドレスが着信ICSネットワークアドレスとして一意に定まるように登録されており、前記レコードにICS特番号を意味する要求識別が登録されており、 前記ICS論理端子からICSユーザフレームが入力すると、当該ICS論理端子に付与されるICSネットワークアドレスは、発信ICSネットワークアドレスとして保持され、次に前記ICSユーザフレーム内の受信者ICSユーザアドレスと前記変換表のレコードの受信者ICSユーザアドレスとが一致するかを検出し、一致する場合は、前記保持された発信ICSネットワークアドレスと前記レコード内に登録される着信ICSネットワークアドレスを用いて前記ICSユーザフレームがICSネットワークフレームに変換され、前記ICSネットワークフレームは前記ICSネットワークアドレス体系ADSのルールに従い内部のICS網通信回線を送信され、前記ICS網サーバに到達するようになっていることを特徴とする統合情報通信システム。
- 28【請求項28】内部に2以上のアクセス制御装置、1以上の中継装置を含み、ICS網サーバを含んでよく、それらはICS網通信回線で直接又は間接的に接続され、統合情報通信システムの外部のユーザの複数のIP端末は、それぞれユーザ通信回線を経由して前記アクセス制御装置のいずれかに接続され、個々のユーザ通信回線の終端のICS論理端子を識別するために前記ICS論理端子にICSネットワークアドレスが付与され、前記中継装置及びICS網サーバを識別するためにそれぞれ前記ICSネットワークアドレスが付与され、 前記アクセス制御装置、前記中継装置、前記ICS網サーバは、それぞれの前記ICSネットワークアドレスを用いてICSネットワークフレームを送受して情報交換することができ、 ICSユーザアドレス体系ADXを持つ外部のICSユーザフレームが、前記アクセス制御装置内の変換表の管理の基に前記ICSネットワークフレームに変換され、前記ICSネットワークフレームはネットワーク制御部及びネットワークデータ部で成り、前記ネットワーク制御部は少なくとも前記ICSネットワークアドレス体系ADSに従うアドレスを含み、前記ICSネットワークフレームは少なくとも1以上の中継装置を経由して前記ICSネットワークアドレス体系のルールに従って送信され、 ICS論理端子識別情報及び受信者ICSユーザアドレスの組が定まれば、前記アクセス制御装置が変換して生成する前記ICSネットワークフレームのネットワーク制御部に格納するICSネットワークアドレスが一意に定まるように前記変換表のレコードとして登録されており、前記ICSユーザフレームが入力したICS論理端子の識別情報、前記ICSユーザフレーム内の受信者ICSユーザアドレスが共に、前記変換表のレコードに登録されていることが見出されたときに、前記ICSユーザフレームが前記ICSネットワークフレームに変換されるようになっており、 前記レコードは2以上であり、ICS論理端子識別情報に対して、前記受信者ICSユーザアドレス及び前記ネットワーク制御部に格納するICSネットワークアドレスの組が共にレコード毎に異なり、同一のICS論理端子から入力するICSユーザフレーム内の受信者ICSユーザアドレスを変更することにより、前記ICSユーザフレームの到達先を変更できるようになっており、 前記変換表のレコードとして登録されているICSユーザフレームのみ転送することにより通信料金の徴収を容易にできるようにしたことを特徴とする統合情報通信システム。
- 29【請求項29】発信側のICSネットワークアドレスが定まれば、ネットワーク制御部に格納するICSネットワークアドレスが一意に定まるように前記変換表のレコードとして登録されており、前記レコードは仮想専用線として登録されており、 前記ICSユーザフレームが入力し、発信側のICS論理端子の識別情報を含む前記変換表のレコードに仮想専用線と登録されていることが見出されたときに、前記ICSユーザフレームが前記ICSネットワークフレームに変換され、 仮想専用線として登録されていないときに、前記ICSユーザフレームが入力したICS論理端子の識別情報、前記ICSユーザフレーム内の受信者ICSユーザアドレスが共に、前記変換表のレコードに登録されていることが見出されたときに、前記ICSユーザフレームが前記ICSネットワークフレームに変換されるようになっている請求項28に記載の統合情報通信システム。
- 30【請求項30】発信側のICS論理端子と外部の送信ICSユーザフレームに付与されたICSユーザアドレスを基に、内部のICSネットワークフレームのICSネットワークアドレスを決定し、前記決定されたICSネットワークアドレスを基に、送信ICSネットワークフレームを送信すべき着信側ICS論理端子を決定することを特徴とする統合情報通信システム。
- 31【請求項31】ユーザ通信回線の終端のICS論理端子に、ICS論理端子を識別するICSネットワークアドレスが付与され、発信側のICS論理端子識別情報及び受信者ICSユーザアドレスの組が定まれば、送信側のアクセス制御装置と受信側のアクセス制御装置との間にICSネットワークフレームが転送されるICS網通信回線が定まることを特徴とする統合情報通信システム。
- 32【請求項32】固有のICSユーザアドレス体系ADXを持つ外部のICSユーザフレームが、アクセス制御装置内の変換表の管理の基に、ICSネットワークアドレス体系ADSを有する内部のICSネットワークフレームに変換され、前記ICSネットワークフレームはネットワーク制御部及びネットワークデータ部で成り、前記ネットワーク制御部は前記ICSネットワークアドレス体系ADSに従うアドレスを格納し、前記ネットワークデータ部は前記ICSユーザフレームを含み、少なくとも1以上の中継装置を経由して前記ICSネットワークアドレス体系ADSのルールに従って送信され、前記ICSユーザフレームが前記ICSネットワークフレームから復元されて外部の他の情報通信機器に転送されるようになっており、ユーザ通信回線の終端のICS論理端子に前記ICSネットワークアドレスが付与され、発信側のICS論理端子識別情報及び受信者ICSユーザアドレスの組が定まれば、着信ICSネットワークアドレスが一意に定まるように前記変換表のレコードとして登録されており、前記ICSユーザフレームが入力したICS論理端子の識別情報、前記ICSユーザフレーム内の受信者ICSユーザアドレスが共に前記変換表のレコードに登録されていることが見出されたときに、前記ICSユーザフレームが前記ICSネットワークフレームに変換されるようになっていることを特徴とする統合情報通信システム。
- 33【請求項33】前記統合情報通信システムの外部のIP電話機と他のIP電話機との間で、前記統合情報通信システムを経由して、ディジタル化した音声を格納したICSユーザフレームを送受信することにより電話通信を行う請求項30乃至32のいずれかに記載の統合情報通信システム。
- 34【請求項34】前記統合情報通信システムの外部のIP電話機と他のIP電話機との間で、前記統合情報通信システムを経由して、ディジタル化した音声を格納したICSユーザフレームを送受信することにより電話通信を行う請求項3又は5に記載の統合情報通信システム。
- 35【請求項35】変換表サーバが電話番号を基に、ドメイン名サーバに問い合わせて取得したICSネットワークアドレス及びICSユーザアドレスを含む変換表新規項目を作成するようになっている請求項3、5、30、31又は32に記載の統合情報通信システム。
- 36【請求項36】請求項23に記載の方法を用いて閉域網Xを定め、ネットワーク制御部内部に格納されたICSネットワークアドレスが、ICS網通信回線の集合としての閉域網を定める性質を用いて、ICSネットワークアドレスの値から前記閉域網Xを識別することを特徴とする統合情報通信方法。
- 37【請求項37】請求項24に記載の方法を用いて閉域網Xを定め、アクセス制御装置内部の変換表のレコードの集合としての閉域網を定める性質を用いて、前記レコードの値から前記閉域網Xを識別することを特徴とする統合情報通信方法。
- 38【請求項38】送信側の前記アクセス制御装置内の変換表が優先度を登録しており、前記ICSネットワークフレームは前記変換表から取得した優先度を含み、前記ICSネットワークフレームは中継装置により前記優先度に従って送出されるようになっている請求項31又は32に記載の統合情報通信システム。
- 39【請求項39】前記ICS網通信回線は速度クラスを付与されており、前記速度クラスを書込まれたICSネットワークフレームが前記中継装置から、前記速度クラスに対応して前記ICS網通信回線に送出されるようになっている請求項3、5、30、31又は32に記載の統合情報通信システム。
- 40【請求項40】発信ICSネットワークアドレス、送信者ICSユーザアドレス及び受信者ICSユーザアドレスの組が定まれば、着信ICSネットワークアドレスが一意に定まるように登録されたレコードを含む変換表を有し、 送信側の機能として、ICS論理端子から入力されたICSユーザフレームと、前記ICSユーザフレームが入力したICS論理端子に付与されたICSネットワークアドレスとを入力し、前記ICSネットワークアドレスと、前記ICSユーザフレームに含まれる送信者ICSユーザアドレス及び受信者ICSユーザアドレスとが共に前記変換表のレコードに登録されていることが見出されたときに、前記ICSユーザフレームをICSネットワークフレームに変換してICS網通信回線に送出する機能を有し、 受信側の機能として、前記ICSネットワークフレームから、前記ICSユーザフレームを復元して着信側のICS論理端子からユーザ通信回線へ送出する機能を有していることを特徴とするアクセス制御装置。
- 41【請求項41】発信ICSネットワークアドレス及び受信者ICSユーザアドレスの組が定まれば、着信ICSネットワークアドレスが一意に定まるように登録されたレコードを含む変換表を有し、 送信側の機能として、ICS論理端子から入力されたICSユーザフレームと、前記ICSユーザフレームが入力したICS論理端子に付与されたICSネットワークアドレスとを入力し、前記ICSネットワークアドレスと、前記ICSユーザフレームに含まれる受信者ICSユーザアドレスとが共に前記変換表のレコードに登録されていることが見出されたときに、前記ICSユーザフレームをICSネットワークフレームに変換してICS網通信回線に送出する機能を有し、 受信側の機能として、前記ICSネットワークフレームから、前記ICSユーザフレームを復元して着信側のICS論理端子からユーザ通信回線へ送出する機能を有していることを特徴とするアクセス制御装置。
- 42【請求項42】発信側のICS論理端子と外部の送信ICSユーザフレームに付与されたICSユーザアドレスとを基に、内部のICSネットワークフレームのICSネットワークアドレスを決定し、前記決定されたICSネットワークアドレスを基に、送信ICSネットワークフレームを送信すべき着信側ICS論理端子を決定するようになっていることを特徴とするアクセス制御装置。
- 43【請求項43】ユーザ通信回線の終端のICS論理端子に、ICS論理端子を識別するICSネットワークアドレスが付与され、発信側のICS論理端子識別情報及び受信者ICSユーザアドレスの組が定まれば、送信側のアクセス制御装置と受信側のアクセス制御装置との間にICSネットワークフレームが転送されるICS網通信回線が定まるようになっていることを特徴とするアクセス制御装置。
- 44【請求項44】受信側の機能として、前記ICSネットワークフレームに含まれる前記ICSネットワークアドレス及び受信者ICSユーザアドレスが共に前記変換表のレコードに登録されていることが見出されたときのみ、前記ICSネットワークフレームから前記ICSユーザフレームを復元して、着信側のICS論理端子から前記ユーザ通信回線へ送出し、他の場合には、前記ICSネットワークフレームを廃棄するようになっている請求項40に記載のアクセス制御装置。
- 45【請求項45】前記変換表に速度クラスが登録されており、前記速度クラスを前記ICSネットワークフレームに書込むようになっている請求項40乃至44のいずれかに記載のアクセス制御装置。
- 46【請求項46】前記変換表に優先度が登録されており、前記優先度を前記ICSネットワークフレームに書込むようになっている請求項40乃至44のいずれかに記載のアクセス制御装置。
- 47【請求項47】前記変換表に優先度が登録されており、前記優先度に従って、前記ICSネットワークフレームを前記ICS網通信回線に送出する順序を決めるようになっている請求項40乃至44のいずれかに記載のアクセス制御装置。
- 48【請求項48】前記変換表に優先度が登録されており、前記優先度に従って、復元した前記ICSユーザフレームをユーザ通信回線に送出する順序を制御するようになっている請求項40乃至44のいずれかに記載のアクセス制御装置。
- 49【請求項49】電子署名部を有し、送信時の動作として、前記変換表に登録された送信時署名の指定により前記ICSユーザフレームに電子署名を付与し、受信時の動作として、前記変換表に登録された受信時署名の指定により前記ICSユーザフレームに電子署名を付与する機能を有する請求項40乃至43のいずれかに記載のアクセス制御装置。
- 50【請求項50】暗号化手段及び復号化手段を有し、送信時の動作として、前記変換表に登録された暗号クラスの指定により、前記ICSユーザフレームを暗号化した後にICSネットワークフレームに変換してICS網通信回線に送出し、受信時の動作として、前記ICSネットワークフレームを復元した後、前記暗号化されたICSユーザフレームを復号化して前記ICSユーザフレームを得、着信側のICS論理端子からユーザ通信回線へ送出する機能を有する請求項40乃至43のいずれかに記載のアクセス制御装置。
- 51【請求項51】前記変換表に課金クラスが登録されている請求項40乃至43のいずれかに記載のアクセス制御装置。
- 52【請求項52】電話回線変換部を含み、送信側の機能として、電話回線からICSユーザフレームを入力して、ICSネットワークフレームに変換してICS網通信回線に送出し、受信側の機能として、ICS網通信回線から入力したICSネットワークフレームを変換して得たICSユーザフレームを、前記電話回線に送出する機能を具備している請求項40乃至43のいずれかに記載のアクセス制御装置。
- 53【請求項53】ISDN回線変換部を含み、送信側の機能として、ISDN回線からICSユーザフレームを入力し、ICSネットワークフレームに変換してICS網通信回線に送出し、受信側の機能として、前記ICS網通信回線から入力したICSネットワークフレームを変換して得たICSユーザフレームを前記ISDN回線に送出する機能を具備している請求項40乃至43のいずれかに記載のアクセス制御装置。
- 54【請求項54】CATV回線変換部を含み、送信側の機能として、CATV回線からICSユーザフレームを入力し、ICSネットワークフレームに変換してICS網通信回線に送出し、受信側の機能として、前記ICS網通信回線から入力したICSネットワークフレームを変換して得たICSユーザフレームを前記CATV回線に送出する機能を具備した請求項40乃至43のいずれかに記載のアクセス制御装置。
- 55【請求項55】衛星回線変換部を含み、送信側の機能として、衛星回線からICSユーザフレームを入力し、ICSネットワークフレームに変換してICS網通信回線に送出し、受信側の機能として、前記ICS網通信回線から入力したICSネットワークフレームを変換して得たICSユーザフレームを前記衛星回線に送出する機能を具備した請求項40乃至43のいずれかに記載のアクセス制御装置。
- 56【請求項56】携帯電話回線変換部を含み、送信側の機能として、携帯電話回線からICSユーザフレームを入力し、ICSネットワークフレームに変換してICS網通信回線に送出し、受信側の機能として、前記ICS網通信回線から入力したICSネットワークフレームを変換して得たICSユーザフレームを前記携帯電話回線に送出する機能を具備した請求項40乃至43のいずれかに記載のアクセス制御装置。
- 57【請求項57】前記変換表の内部に、前記第1のルールに従うレコードを含まず、企業内通信及び企業間通信を行い得るようになっている請求項26に記載のアクセス制御装置。
- 58【請求項58】ユーザ通信回線の終端のアクセス制御装置のICS論理端子に、ICS論理端子を識別するICSネットワークアドレスが付与され、第1のルールとして、前記ICS論理端子の識別情報が定まれば着信ICSネットワークアドレスが一意に定まるように変換表のレコードとして登録され、かつ前記レコードに要求識別が仮想専用線として登録されており、 第2のルールとして、前記ICS論理端子の識別情報及び受信者ICSユーザアドレスの組が定まれば、着信ICSネットワークアドレスが一意に定まるように前記変換表のレコードとして登録されており、かつ前記レコードに要求識別が企業内通信として登録されており、 前記変換表のレコードは2以上であり、同一のICS論理端子識別情報に対して、前記受信者ICSユーザアドレスを変更することにより前記ICSユーザフレームの到達先を変更できるようになっており、 前記ICS論理端子からICSユーザフレームが入力し、前記ICS論理端子識別情報を含む前記変換表のレコードが見出されて要求識別が仮想専用線として登録されているときは、前記第1のルールにより得た着信ICSネットワークアドレスを用いてICSネットワークフレームに変換し、 又は前記要求識別が企業内通信として登録されているときは前記第2のルールとして、前記ICSユーザフレームが入力したICS論理端子の識別情報、前記ICSユーザフレーム内の受信者ICSユーザアドレスが共に前記変換表のレコードに登録されていることが見出されたときに、前記ICSユーザフレームがICSネットワークフレームに変換され、 次に、前記第1のルールと前記第2のルールによる手続きが共に成立しなかったとき、つまり前記ICSユーザフレームが入力したICS論理端子の識別情報、前記ICSユーザフレーム内の受信者ICSユーザアドレスの組が前記変換表のレコードとして登録されていることが見出されないときに、 前記ICSユーザフレーム内の受信者ICSユーザアドレスが企業間通信アドレスの区間であるかを判定し、企業間通信アドレスの区間である場合は前記ICSユーザフレームをそのままICSネットワークフレームとし、このとき、前記ICSネットワークフレーム内の着信ネットワークアドレスは前記ICSユーザフレーム内の受信者ICSユーザアドレスであり、 前記ICSネットワークフレームは少なくとも1以上の中継装置を経由して送信され、他のアクセス制御装置に到達すると前記ICSネットワークフレームから前記ICSユーザフレームを復元し、ICSネットワークフレーム内の着信ネットワークアドレスが、企業間通信アドレス区間である場合は、前記ICSネットワークフレームをそのまま前記ICSユーザフレームとし、前記ICSユーザフレームを外部の他の情報通信機器に転送されるようになっており、仮想専用線、企業内通信及び企業間通信を行うことを特徴とする統合情報通信システム。
- 59【請求項59】前記変換表の内部に、前記第1のルールに従うレコードを含まず、企業内通信及び企業間通信を行い得るようになっている請求項58に記載の統合情報通信システム。
- 60【請求項60】ユーザ通信回線の終端のICS論理端子に、ICS論理端子を識別するICSネットワークアドレスが付与され、発信側のICS論理端子識別情報及び受信者ICSユーザアドレスの組が定まれば、送信側のアクセス制御装置と受信側のアクセス制御装置との間にICSネットワークフレームが転送されるICS網通信回線が一意に定まり、前記ICS網通信回線を特定するためのICSネットワークフレームの転送先を定めるICSネットワークアドレスは、前記アクセス制御装置の変換表及び中継装置の中継表により規定され、固有のICSユーザアドレス体系ADXを持つ外部のICSユーザフレームが、前記ユーザ通信回線からICS論理端子を経由して前記送信側のアクセス制御装置に入力し、前記ICSユーザフレームが入力したICS論理端子を識別する情報と、前記ICSユーザフレーム内の受信者ICSユーザアドレスとが共に前記アクセス制御装置の変換表のレコードに登録されていることが見出されたときに、前記ICSユーザフレームがICSネットワークアドレス体系ADSを有する内部のICSネットワークフレームに変換されるようになっており、前記ICSネットワークフレームはネットワーク制御部を含み、前記ネットワーク制御部は少なくとも前記ICS網通信回線を特定するための前記ICSネットワークアドレスを格納し、前記ICSネットワークフレームは前記ICSネットワークアドレス体系ADSのルールに従い、前記アクセス制御装置の変換表及び中継装置の中継表によりICSネットワークフレームの転送先が判定されて前記ICS網通信回線を送信され、前記ICSネットワークフレームが前記受信側のアクセス制御装置に到達したときに、前記ICSユーザフレームが前記ICSネットワークフレームから復元され、前記受信側のアクセス制御装置のICS論理端子を経て他のユーザ通信回線を転送され、外部の他の情報通信機器に到達するようになっていることを特徴とする統合情報通信システム。
- 61【請求項61】前記変換表が優先度を含んでおり、前記ICSネットワークフレームは前記変換表から取得した優先度を含み、前記ICSネットワークフレームは前記中継装置により前記ICSネットワークフレームの優先度に従って送出されるようになっている請求項60に記載の統合情報通信システム。
- 62【請求項62】前記変換表のレコードは2以上であり、前記ICS論理端子識別情報及び受信者ICSユーザアドレスの組に対して、前記ICS網通信回線を特定するための前記ICSネットワークアドレスの組はレコード毎に異なり、前記受信者ICSユーザアドレスを変更することにより前記ICSユーザフレームの到達先を変更できるようになっている請求項60に記載の統合情報通信システム。
- 63【請求項63】前記変換表に登録される前記受信者ICSユーザアドレスが企業内通信用アドレス又は企業間通信用アドレスであるかに応じて、企業内通信及び企業間通信を行い得るようになっている請求項60に記載の統合情報通信システム。
- 64【請求項64】前記変換表のレコードに企業内通信/企業間通信を示す要求識別を含み、前記ICSユーザフレームが入力した前記ICS論理端子を含む前記変換表のレコードに、要求識別が仮想専用線として登録されているときは当該レコードに関する処理を行わず、次に前記要求識別が企業内通信/企業間通信であると見出されたときに、前記ICSネットワークフレームに変換されるようになっている請求項60に記載の統合情報通信システム。
- 65【請求項65】処理装置及びICS網データベースで成り、前記アクセス制御装置からの要求に対して自らが保持する結果を返信するか、又は前記アクセス制御装置からの質問に対する回答を保持していないとき、ICS網サーバ通信機能を用いて他のICS網サーバと通信して回答を取得し、この結果を質問元のアクセス制御装置に返信する機能のICS網サーバを有している請求項60に記載の統合情報通信システム。
- 66【請求項66】前記アクセス制御装置は、ICSユーザフレームを受信すると、そのICSユーザフレームに含まれるICSユーザアドレスを基に変換表に保持されているICSフレーム毎の課金方式の種別を読出し、読出した種別が従量制課金方式を示す値の場合は課金情報を生成し、その課金情報を課金情報フレームとして課金サーバに伝え、前記読出した内容が定額制課金方式を示す値の場合は、課金情報の生成やその課金情報を課金情報フレームとして課金サーバに伝えることを行わない機能を有している請求項60に記載の統合情報通信システム。
- 67【請求項67】外部に少なくともアクセス制御装置を置き、内部にアクセス制御装置統括管理サーバを置くことにより企業内通信或いは企業間通信を行うようにした請求項60に記載の統合情報通信システム。
- 68【請求項68】前記アクセス制御装置が暗号化手段及び復号化手段を有し、ICSカプセル化のとき、前記ICSユーザフレームを前記暗号化手段で暗号文に変換してICS内部を送信し、ICS逆カプセル化のとき、暗号文に変換されている前記ICSユーザフレームを前記復号化手段で元のICSユーザフレームに戻すようになっている請求項60に記載の統合情報通信システム。
- 69【請求項69】前記アクセス制御装置を集約アクセス制御装置及び簡易アクセス制御装置に機能分離し、ユーザは前記簡易アクセス制御装置に接続され、前記変換表を前記集約アクセス制御装置内部の集約変換表及び前記簡易アクセス制御装置内部の簡易変換表に分け、ICSカプセル化及びICS逆カプセル化は前記簡易アクセス制御装置で行い、課金及び電子署名は前記集約アクセス制御装置で行うようになっている請求項60に記載の統合情報通信システム。
- 70【請求項70】ユーザサービスサーバ、ICS当局サーバ、変換表サーバをそれぞれ複数有し、ICS加入の申し込みを前記ユーザサービスサーバで受付け、前記ICS当局サーバがICSユーザアドレス、ICSネットワークアドレス及びICSネームを割当て、前記変換表サーバが前記アクセス制御装置内の変換表を書き換えるようになっている請求項60に記載の統合情報通信システム。
- 71【請求項71】ICS運用者が統括ユーザサービスサーバ、統括リソース管理サーバ、統括経路情報サーバに指示を与え、個別の報告をさせることにより運用するようになっている請求項60に記載の統合情報通信システム。
- 72【請求項72】前記アクセス制御装置の内部の電話回線変換部から電話回線を経て電話機に接続し、電話音声による通信が可能である請求項60に記載の統合情報通信システム。
- 73【請求項73】ICS受付け者がローミング端末に暗号機能及び暗号関連データを埋め込み、前記暗号機能はパラメータを変更することにより選択できるようになっている請求項60に記載の統合情報通信システム。
- 74【請求項74】電話番号をICSドメイン名として通信相手先のICSユーザアドレス及びICSネットワークアドレスを取得し、前記ICSネットワークアドレスは呼び出し側のアクセス制御装置内の変換表に保持するようになっている請求項60に記載の統合情報通信システム。
- 75【請求項75】前記統合情報通信システムの外部のIP電話機と他のIP電話機との間で、前記統合情報通信システムを経由して、ディジタル化した音声を格納したICSユーザフレームを送受信することにより電話通信を行う請求項60に記載の統合情報通信システム。
- 76【請求項76】前記送信側のアクセス制御装置の変換表の複数のレコードがそれぞれ受信者ICSユーザアドレスを含み、ICSユーザフレームに付与された受信者ICSユーザアドレスの変化に対応して前記複数のレコードのいずれかが参照され、ICSネットワークフレームが転送される前記ICS網通信回線が選択されるようになっている請求項31に記載の統合情報通信システム。
- 77【請求項77】発信側のICS論理端子情報と外部のICSユーザフレーム内の受信者ICSユーザアドレスを基に、アクセス制御装置の変換表を用いて内部のICSネットワークアドレスを決定し、前記決定されたICSネットワークアドレスを用いてICSネットワークフレームに変換し、前記ICSネットワークフレームは内部を転送されて着信側のアクセス制御装置に到達して前記外部のICSユーザフレームが復元され、前記ICSネットワークフレーム内の少なくとも着信ICSネットワークアドレスを用いて着信側ICS論理端子を決定することを特徴とする統合情報通信システム。
- 78【請求項78】発信側のICS論理端子情報と外部のICSユーザフレーム内の受信者ICSユーザアドレスを基に、アクセス制御装置の変換表を用いて内部のICSネットワークアドレスを決定し、前記決定されたICSネットワークアドレスを用いてICSネットワークフレームに変換し、前記ICSネットワークフレームは内部を転送されて着信側のアクセス制御装置に到達して前記外部のICSユーザフレームが復元され、前記ICSネットワークフレーム内の少なくとも着信ICSネットワークアドレスを用いて着信側ICS論理端子を決定するようになっている統合情報通信システムにおいて、前記外部のICSユーザフレーム内の送信者ICSユーザアドレスを用いて、送信者ICSユーザアドレスの範囲区分として閉域網を識別すると共に、発信側のICS論理端子に接続するユーザ通信回線に接続する送信元IP端末を含むLANを識別するようになっていることを特徴とする閉域網とLANの識別方法。
- 79【請求項79】発信ICSネットワークアドレス、送信者ICSユーザアドレス及び受信者ICSユーザアドレスの組が定まれば、着信ICSネットワークアドレスが一意に定まるように登録された1以上のレコードを含む変換表部を含み、送信側として、ICS論理端子から入力したICSユーザフレームと、前記ICS論理端子に付与されたICSネットワークアドレスとを入力し、前記ICSネットワークアドレスと、前記ICSユーザフレームに含まれる送信者ICSユーザアドレス及び受信者ICSユーザアドレスとが共に前記変換表部のレコードに登録されていることが見出されたときに、前記ICSユーザフレームをICSネットワークフレームに変換し、受信側として、前記ICSネットワークフレームから、前記ICSユーザフレームを復元し他のICS論理端子に送出する機能部を有していることを特徴とする通信機能回路。
- 80【請求項80】発信ICSネットワークアドレス及び受信者ICSユーザアドレスの組が定まれば、着信ICSネットワークアドレスが一意に定まるように登録された1以上のレコードを含む変換表部を含み、送信側として、ICS論理端子から入力したICSユーザフレームと、前記ICS論理端子に付与されたICSネットワークアドレスとを入力し、前記ICSネットワークアドレスと、前記ICSユーザフレームに含まれる受信者ICSユーザアドレスとが共に前記変換表部のレコードに登録されていることが見出されたときに、前記ICSユーザフレームをICSネットワークフレームに変換し、受信側として、前記ICSネットワークフレームから、前記ICSユーザフレームを復元し他のICS論理端子に送出する機能部を有していることを特徴とする通信機能回路。
- 81【請求項81】変換表サーバから取得したICSネットワークアドレス及びICSユーザアドレスを含む変換表新規項目をアクセス制御装置で使用してICSネットワークフレームを形成し送信するようになっている請求項1,5,30,31又は32に記載の統合情報通信システム。
- 82【請求項82】変換表サーバから取得したICSネットワークアドレス及びICSユーザアドレスを含む変換表新規項目を基に、ICSユーザフレームをカプセル化したICSネットワークフレームを送信するようになっている請求項1,5,30,31又は32に記載の統合情報通信システム。
- 83【請求項83】変換表サーバから取得したICSネットワークアドレス及びICSユーザアドレスを含む変換表新規項目を使用してICSネットワークフレームを形成し送信するようになっている請求項26,40乃至43のいずれかに記載のアクセス制御装置。
- 84【請求項84】変換表サーバから取得したICSネットワークアドレス及びICSユーザアドレスを含む変換表新規項目を基に、ICSユーザフレームをカプセル化したICSネットワークフレームを送信するようになっている請求項26,40乃至43のいずれかに記載のアクセス制御装置。
Independent claims84
1,235 paragraphs in 5 sections, as filed
Description: TECHNICAL FIELD [Detailed description of the invention]
【0001】
[Technical field to which the invention belongs]
The present invention provides not only dedicated lines but also ISDN for information communication devices or information communication systems such as personal computers, LAN (Local Area Network), telephones (including mobile phones), faxes (Facsimile), CATV (Cable Television), and the Internet. (Integrated Services Digital Network), FR (Frame Relay), ATM (Asynchronous Transfer Mode), IPX (Integrated Packet Exchange), satellite, wireless, integrated information communication system connected via public lines. Here, the information communication device is assigned an address (for information communication) for distinguishing from others and communicates. The present invention particularly integrates data transfer services based on connectionless networks (for example, RFC791 and RFC1883 IP (Internet Protocol) technology), and adopts a unified address system to improve the economic efficiency of information and communication as a whole. The present invention relates to an integrated information communication system that ensures security and enables mutual communication between connection terminals or systems.
【0002】
[Conventional technology]
With the development of computers and information and communication technology, computer communication networks have become widespread in universities, research institutes, government agencies, companies, and companies in recent years. LAN is used as a computer communication network in a company, and when the area is spread nationwide, it takes the form shown in Fig. 150. In the example of FIG. 150, the LANs in each region use a common protocol and are connected by dedicated lines. Here, for example, company X uses LAN-X1, LAN-X2, and LAN-X3 as LAN, company Y uses LAN-Y1, LAN-Y2, and LAN-Y3 as LAN, and company X and Y use LAN-Y1, LAN-Y2, and LAN-Y3, respectively. Communication address system Computer communication is performed using ADX and ADY. In such a LAN network, it is necessary to lay a separate dedicated line for each company, which makes the system construction expensive, and when connecting to the LAN network of another company, the interface such as the communication address system is matched. There is a problem that it is necessary, its interconnection is very difficult, and it costs a lot of money.
【0003】
On the other hand, in recent years, the Internet has become widespread as a computer communication network on a global scale. In the Internet, networks are connected using a provider's router, which is called TCP / IP (Transmission Control Protocol / Internet Protocol). When using a communication protocol and connecting remote locations, use a dedicated line or FR network, and if it is on the premises, Ethernet, which is a 10 Mbps LAN, or FDDI (Fiber Distributed Date), which is a 100 Mbps LAN. Interface) etc. is used as a communication path. FIG. 151 shows an example of a connection form of the Internet. In the Internet, routers in a provider maintain a connection between each other while exchanging routing table connection information. Each router is connected to multiple networks, and the routing table is used to determine which router is connected to which provider's network to send the received data to which router. In this way, on the Internet, the IP address of the destination attached to each IP frame (IP datagram) is seen, the router to be sent next is determined, and the router is sent to that router. When all routers perform this operation, IP frames are delivered one after another and delivered to the target computer.
【0004】
FIG. 152 shows the information content of RFC791 of the IP frame used for the Internet, and is divided into a control unit and a data unit. FIG. 153 shows the same information content of RFC 1883, which is divided into a control unit and a data unit, in which () indicates the number of bits.
【0005】
[Problems to be Solved by the Invention]
However, since the Internet does not have a system that comprehensively manages communication routes, it is not possible to confirm whether or not the communication partner is the intended legitimate person, and there is a high risk that communication information will be eavesdropped. There is a problem in terms of security, and the IP address inside many LANs is actually decided by the LAN user independently. When connecting the LAN to the Internet, the IP address of the LAN user is selected. You need to replace it with an IP address for the Internet. In addition, communication qualities such as communication speed and communication error rate are not unified because the backbone lines that make up the Internet communication path are different for each LAN line, and for example, 10 Mbps for video conference communication. Even if you try to send the TV signal of, there is a problem that the communication speed is not achieved. Furthermore, there is no manager who supervises the entire network such as maintenance and management of network failure countermeasures and future plans of the network, and it is used for communication and corporate business of countries and research institutes where reliability is particularly important. , There is a problem that the Internet cannot be used with confidence. Moreover, in the LAN network and the Internet, the terminal is a personal computer (computer), and it is difficult to integrate and use telephones, fax machines, CATV, etc.
【0006】
The present invention has been made for the above-mentioned circumstances, and an object of the present invention is to improve the economic efficiency of constructing an information communication system without using a dedicated line or the Internet, and to improve communication speed, communication quality, and communication failure. To provide an integrated integrated information communication system that can accommodate multiple VANs that transfer data / information using IP frames that ensure security and reliability in communication by centrally guaranteeing countermeasures. It is in. Furthermore, by a single information transfer that does not depend on the type of service such as voice, image (video, still image), text, etc., comprehensive communication service, analog and digital telephone line service, Internet provider service, FAX service, computer data exchange The purpose is to provide an integrated information communication system in which services that have been individually serviced in the past, such as services and CATV services, are interconnected. In addition, integration that enables inter-company communication with almost no change in the address system for computer communication that is conventionally decided and used by individual companies (including universities, research institutes, government agencies, etc.) separately within each company. It also aims to provide an information communication system. An IP terminal refers to a terminal or computer having a function of transmitting and receiving IP frames.
【0007】
[Means for solving problems]
The present invention relates to an integrated information communication system, and an object of the present invention is to provide an access control device for individually connecting a plurality of external computer communication networks or information communication devices, and a relay device for networking the access control device. It has a function of transferring and routing information in a unified address system, and is achieved by configuring the configuration so that the plurality of computer communication networks or information communication devices can communicate with each other. The present invention corresponds to a computer communication network based on IP technology in which the range of dedicated lines used for communication inside and between companies shown in FIG. 150 shown as a conventional example is replaced with a common communication network shown by a broken line. To do.
【0008】
The above object of the present invention is to convert an ICS user frame having a unique ICS user address system ADX into an ICS network frame having an address system ADS based on the management of a conversion table in the access control device, and at least one built-in. The above VAN is transmitted according to the rules of the address system ADS, and when it reaches the target other access control device, it is converted to the ICS user address system ADX and converted to another external device based on the management of the conversion table. Achieved by reaching information and communication equipment. Further, the ICS user frame having the unique ICS user address system ADX can be used for the user logical communication line without using the ICS user address inside the ICS user frame based on the management of the conversion table of the access control device. Converts to an ICS network frame corresponding to the incoming ICS network address registered in the conversion table, and the transfer destination of the ICS network frame is 1 or N, and follows the rules of the ICS address system ADS via at least one VAN. Achieved by transferring the ICS network frame to another access control device and returning it to the ICS user frame based on the management of the conversion table of the access control device so that it can reach other external information and communication devices. Will be done.
【0009】
BEST MODE FOR CARRYING OUT THE INVENTION
FIG. 1 schematically shows the basic principle of the present invention, and shows the integrated information / communication of the present invention. System: (hereinafter abbreviated as "ICS") 1 has its own rules for assigning computer information / communication addresses. That is, it has a unique address system ADS, and multiple external computer communication networks and information communication devices, such as a large number of LANs (in this example, LAN-X1, LAN-X2, LAN-X3 of company X and LAN of company Y). -It has an access control device (2 to 7 in this example) that serves as an access point for connecting (Y1, LAN-Y2, LAN-Y3). LAN-X1, LAN-X2 and LAN-X3 of company X have the same address system ADX, and LAN-Y1, LAN-Y2 and LAN-Y3 of company Y have the same address system ADY. Access control devices 2, 3 and 4 have a conversion table that manages mutual conversion between the address system ADS and the address system ADX, and access control devices 5, 6 and 7 have the address system ADS and the address system ADY. It has a conversion table that manages mutual conversion and the like. The computer communication data (ICS frame) in ICS1 uses the address according to the address system ADS of ICS1 and communicates by the IP frame used on the Internet or the like.
【0010】
Here, the communication operation in the case of the same company will be described. The computer communication data (ICS frame) 80 transmitted from LAN-X1 of company X is given an address according to the address system ADX, but the address is managed under the management of the conversion table of access control device 2 in ICS1. It is converted to an address that follows the system ADS and becomes ICS frame 81. Then, when it is transmitted in ICS1 according to the rules of the address system ADS and reaches the target access control device 4, it is restored to the computer communication data 80 of the address system ADX under the management of the conversion table, and it is restored to the computer communication data 80 of the same company X. It is sent to LAN-X3. Here, the ICS frame sent and received inside the ICS1 is called an "ICS network frame", and the ICS frame sent and received outside the ICS1 is called an "ICS user frame". As a general rule, the format of the ICS user frame is the format specified by RFC791 or RFC1883 used on the Internet or the like, but the handling of the ICS frame that deviates from the principle will be described in Examples described later.
【0011】
The ICS network frame 81 consists of a network control unit 81-1 and a network data unit 81-2, and inside the network control unit 81-1 is the address (address) of each ICS logical terminal inside the access control devices 2 and 4. System ADS) is stored. The ICS user frame 80 is designated as the network data section 81-2 with the data value as it is, or the data format is converted to the network data section 81-2 according to the rules defined inside the ICS1. The conversion rules for this data format include, for example, conversion to encrypted text and data compression. The access control device 2 has an encryption means, a decryption means for returning the encrypted text to the original plain text (ICS user frame), and data compression. It may have a means and a compressed data restoration means for restoring the compressed data. In the access control device 2, the operation of assigning the ICS user frame 80 to the ICS network frame 81-2 and the network control unit 81-1 to the ICS network frame 81-2 is called "ICS encapsulation". Further, in the access control device 4, the operation of removing the network control unit 81-1 from the ICS network frame 81 is called "ICS decapsulation".
【0012】
Similarly, the case of inter-company communication will be described. Computer communication data (ICS user frame) 82 transmitted from LAN-Y2 of company Y is given an address according to the address system ADY, but under the management of the conversion table of access control device 6 in ICS1. It is converted to an address that conforms to the address system ADS and becomes ICS frame 83. Then, when it is transmitted in ICS1 according to the rules of the address system ADS and reaches the target access control device 3, it is converted to the computer communication data 82 of the address system ADX under the management of the conversion table, and the LAN of the company X. -Sent to X2. Although 32 bits and 128 bits are used as the address lengths in the present invention, they are not restricted by these lengths. Even if the length of the address is changed to other than 32 bits or 128 bits, the essence of address translation, which is the basic idea of the present invention, does not change.
【0013】
As described above, in the present invention, the centralized address management of ICS1 enables computer communication within and between enterprises. Generally used computer communication user terminals are accommodated in the LAN of the user's premises, accommodated in the VAN (Value Added Network) via the access line, and the user has a different data format and address system for each service type. The frame is transferred. For example, Internet services use IP addresses, telephone services use telephone numbers / ISDN numbers (E.164 addresses), and X.25 packet services use X.121 addresses. On the other hand, in ICS1 of the present invention, address translation (called ICS address translation) is performed in the conversion table of the access control device based on the input ICS user frame, and a single unified data of various structures is performed. Information is transferred by converting it into a frame of data format and address system, that is, an ICS frame.
【0014】
FIG. 2 schematically shows an example in which the ICS1 of the present invention is composed of a plurality of VANs (VAN-1, VAN-2, VAN-3), and each VAN is managed by the VAN operator, and the ICS1 The user applies for a user communication line to the VAN operator, and the VAN operator decides the user's ICS user address, ICS network address, etc., and displays these information together with the line type, etc. in the access control device as shown in Fig. 3. Register in conversion table 12 in 10. ICS1 has access control devices 10-1, 10-2, 10-3, 10-4, 10-5 as access points for external connection elements with LANs (or their terminals) of companies X and Y. Furthermore, the relay device 20-1,20-2,20-3,20-4, the ICS network server 40-1,40-2,40-3,40-4,40-5, and the ICS address management server 50- It has 1 and 50-2. The communication path inside each VAN is provided with a relay device 20 as shown in FIG. 4, and an inter-VAN gateway 30 as shown in FIG. 5 is provided as a connecting element of VAN-2 and VAN-3. LAN1-1, 1-2, 1-3, 1-4 shown in Fig. 2 have access control devices 10-1, 10-5, 10-4, 10-2 and user communication lines 36-1, 36-, respectively. It is connected via 2,36-3,36-4.
【0015】
The access control device 10 (10-1,10-2,10-3,10-4,10-5) is a device that accommodates a user communication line from a user (company X, Y) to ICS1. As shown in 3, it is composed of a processing device 11 including a CPU and the like, a conversion table 12 as a database for performing address translation and the like, a line unit 13 of an input / output interface, and a temporary conversion table 14. Further, the relay device 20 has a transfer function of an ICS network frame and a routing function of route designation, and has a processing device 21 composed of a CPU and the like and a relay table 22 as shown in FIG. 4. The relay table 22 is an ICS network. Used to determine the communication destination when the frame is transferred inside ICS1. As shown in FIG. 5, the inter-VAN gateway 30 has a processing device 31 composed of a CPU or the like and a relay table 32 for determining the destination of the ICS network frame between the VANs.
【0016】
As shown in FIG. 6, the ICS network server 40 is composed of a processing device 41 and an ICS network database 42, and the ICS network database 42 has various uses. For example, user-specific data corresponding to the ICS user address (user name, address, etc.), data not corresponding to the ICS user address, for example, data indicating the communication failure status inside the VAN, or data not directly related to the VAN, for example. Data retention such as electronic library that holds and publishes digital documents, public key of public cryptography using cryptography used for authenticating the authenticity of senders and receivers, public key certification data or private key of private key method Used for. The processing device 41 refers to the ICS network database 42, acquires the corresponding data, and transmits the corresponding data to the access control device 10. In addition to operating independently, the ICS network database 42 can communicate with other ICS network servers by sending and receiving ICS network frames based on IP communication technology, and can acquire data from other ICS network servers. The ICS network server is assigned the only ICS network address inside ICS.
【0017】
In the present invention, the address that identifies the computer, terminal, etc. used in the ICS network frame is referred to as "ICS network address", and the address that identifies the computer, terminal, etc. used in the ICS user frame is referred to as "ICS user address". .. The ICS network address is used only inside the ICS and uses one or both of the 32-bit and 128-bit lengths. Similarly, the ICS user address uses one or both of the 32-bit length and the 128-bit length. An ICS network address is assigned to each of the ICS logical terminal inside the access control device 10, the relay device 20, the gateway 30 between VANs, and the ICS network server so as to be uniquely identified from the others. The ICS user address is composed of a VAN upper code and a VAN internal code. When the length of the VAN upper code is expressed in C1 bits and the length of the VAN internal code is expressed in C2 bits, C1 + C2 is 32 bits or 128 bits. Use one of.
【0018】
In the present invention, the specific method of determining the VAN upper code and the VAN internal code is not specified, but when C1 + C2 = 32 bits, for example, VAN upper code = Regional management code (4 bits) The Country code (4 bits) The VAN code (8 bits) VAN internal code = VAN area code (4 bits) The VAN access point code (8 bits) The User logical code (4 bits) It should be decided. Figure 7 shows an example of an ICS user address. Here, the symbol "aTheb" represents the concatenation of the data a and b, that is, the data obtained by arranging the data a and b in this order. The ICS network address can also be assigned including regional characteristics in the same way as the user network address. For example ICS network address = region management code The country code The VAN code The VAN region code The user logical communication line code And so on. In this way, the relay device can efficiently find the destination by deciding the destination in consideration of the area. The same can be specified for C1 + C2 = 128 bits.
【0019】
In the present invention, C1 + C2 = 32 bits or C1 + C2 = 128, regardless of how the internal fields of the VAN upper code and the VAN internal code are divided and the length of each division field is defined. As long as the bits are protected, the ICS frame can be configured as described below. In addition, when determining the VAN superordinate code or VAN internal code, a part of these codes may be specified uniquely to the user. That is, the user can have a user-specific address system. Address values in 32-bit representation start at address 0 (2)<sup>32</sup>-1) Up to the address, but in this address, for example, 10 x 2<sup>24</sup>From the street address (10 x 2)<sup>24</sup>+2<sup>24</sup>-1) Address or (172 x 2)<sup>24</sup>+16×2<sup>16</sup>) From the street address (172 x 2)<sup>24</sup>+32×2<sup>16</sup>-1) Up to address or (192 x 2)<sup>24</sup>+168×2<sup>16</sup>) From the street address (192 x 2)<sup>24</sup>+169×2<sup>16</sup>-1) In the section up to the address, the present invention is carried out by assigning an address unique to the user.
【0020】
The physical communication line can be logically divided into a plurality of communication lines and used, which is realized as a conventional technique, for example, by a multiple communication method of a frame relay (FR). In the present invention, the user's communication line is divided into a user physical communication line and one or more user logical communication lines. FIG. 8 shows this situation, and shows an example in which the user physical communication line 60 having a communication speed of 100 Mbps is divided into two user logical communication lines 61-1 and 61-2 having a communication speed of 50 Mbps. In addition, separate computer communication devices 62-1,62-2,62-3,62-4 are connected to their respective user logical communication lines, and the ICS user address "4123,0025,0026,4124" is assigned to each computer communication device. Examples given to 62-1 to 62-4 are shown. The user physical communication line 60 is connected to the access control device 63, and the connection point between the two is referred to as an ICS logical terminal. The ICS logical terminal is assigned the only ICS network address inside the ICS. In the example of FIG. 8, the user logical communication lines 61-1 and 61-2 are connected to the access control device 63, and the ICS network addresses 8710 and are connected to the ICS logical terminals 64-1 and 64-2 at the connection points, respectively. 8711 is given.
【0021】
As described above, since the ICS network server 40 is also given a unique ICS network address, the ICS network address can identify the ICS logical terminal or the ICS network server as the only one inside the ICS. The ICS network server can exchange information by transmitting and receiving between another ICS network server and an ICS network frame to which each other's ICS network addresses are assigned by using IP communication technology. This communication function is called "ICS network server communication function". The access control device also has the only ICS network address inside the ICS, and can exchange information with the ICS network server by using another ICS network server communication function as the access control device server. The ICS network server communication function is realized by using, for example, the conventional technology TCP or UDP (User Datagram Protocol).
【0022】
As described above, the ICS frame of the present invention includes an ICS network frame transmitted and received inside the ICS and an ICS user frame transmitted and received outside the ICS, and each frame consists of a control unit and a data unit. As shown in FIG. 9, it is used as a network control unit, a network data unit, a user control unit, and a user data unit in ICS encapsulation or ICS decapsulation. That is, when the ICS user frame enters the ICS from the access control device, the ICS user frame becomes the data part of the ICS network frame, and the control part (network control part) of the ICS network frame is added (ICS encapsulation). The inside of the network control unit is divided into a basic unit and an extension unit. The basic part is used for the header specified in RFC791 and RFC1833, for example, and the extended part is used for encryption and the like. If encryption or the like is not required at all, the extension is not used and does not have to exist.
【0023】
An area for storing the source address and the destination address is placed in the network control unit of the ICS frame. The format of the ICS frame may be 32 bits or 128 bits. When the address length is 32 bits, for example, the frame format specified by RFC791 shown in FIG. 152 is adopted. If the ICS network address is insufficient with 32 bits, for example, when using 64 bits, write the insufficient 32 bits (64 bits to 32 bits) to the option part of the ICS network frame control unit according to the rules of RFC791, and write the missing 32 bits (64 bits to 32 bits) to the network address. Set the length to 64 bits and use it. Here, the address specified specifically for the user is supplemented. Many users, for example (10x2)<sup>24</sup>) From the street address (10 × 2)<sup>24</sup>+2<sup>24</sup>-1) Considering the case of having a private address (one of the ICS user addresses) in the section up to the address, the ICS network address is assigned corresponding to the ICS user address, so the length of the ICS user address is 32. In the case of bits, 32 bits is not enough for the length of the ICS network address, for example 64 bits are required. In this case, as described above, the shortage of 32 bits is written to the option part of the ICS network frame control unit, and the length of the network address is set to 64 bits.
【0024】
The fact that communication between the same users (referred to as intra-company communication) is possible using the above private address will be described in the first embodiment. When the address length is 128 bits, the present invention is carried out by adopting, for example, the frame format specified in RFC 1883 shown in FIG. 153. The source address area in the network control unit and the address stored in the destination address area are ICS network addresses, and are the outgoing ICS network address and the incoming ICS network address, respectively. Further, the source address area in the user control unit and the address stored in the destination address area are ICS user addresses, and are the sender ICS user address and the receiver ICS user address, respectively.
【0025】
When implementing the present invention, it is not always necessary to comply with the provisions of RFC791 and RFC1883 as the format of the ICS frame, and the frame format can be implemented as long as the address uses either 32-bit or 128-bit. Generally, in ICS, the ICS user frame specified in RFC791 or RFC1883 of the communication protocol is received from the user, but other frame formats are converted to the ICS user frame format by the conversion means (conversion unit) and ICS. It can be handled within the network.
【0026】
Example-1 (ICS basics, intra-company communication and inter-company communication): Using FIGS. 10 and 11, the first embodiment of the present invention is expressed in ICS from the recipient ICS user address based on the management of the conversion table. The basic communication for determining the transfer destination of is described. In the figure, 170-1,170-2,170-3,170-4 are gateways provided inside LAN100-1,100-2,100-3,100-4, respectively, and the ICS frame can pass through these gateways 170-1 to 170-4.
【0027】
First, a terminal connected to LAN100-1 of company X having a unique address system ADX and having an address according to address system ADX and a terminal connected to LAN100-2 of the same company X and having an address according to address system ADX The communication with the terminal to have is described. That is, it is communication between the terminal having the ICS user address "0012" on LAN100-1 and the terminal having the ICS user address "0034" on LAN100-2. This communication is a typical communication in which terminals whose addresses are set based on a unique address system (ADX in this example) within the same company mutually perform via ICS100, and this is a corporate communication service (intra-company communication service). Or in-house communication). Next, communication between a terminal connected to LAN100-1 of company X and having an address according to the address system ADX and a terminal connected to LAN100-3 of company Y and having an address according to the address system ADY. Will be described. That is, it is communication between the terminal having the ICS user address "0012" on LAN100-1 and the terminal having the ICS user address "1156" on LAN100-3. This communication is a typical terminal mutual communication performed by terminals having different address systems between different companies using an ICS address system that can be commonly used by each other, and this is a business-to-business communication service (or business-to-business communication). Called.
【0028】
<< Common preparations >> In explaining this example, the address format etc. are decided as follows, but the specific numerical values and formats shown here are all examples and are not bound by this. The ICS network address is represented by a 4-digit number, and the sender ICS user address and the receiver ICS user address are both represented by a 4-digit number. Then, among the sender ICS user address and the receiver ICS user address, the address whose upper two digits are not "00" is used as the inter-company communication address, and this inter-company communication address is the only value inside the ICS100. Of the sender ICS user address and the receiver ICS user address, the address whose upper two digits are "00" is used as the corporate communication address, but this corporate communication address is the same as the corporate communication address of another company inside ICS100. It may be duplicated. In addition, the conversion table 113-1 provided in the access control device 110-1 includes the outgoing ICS network address, the incoming ICS network address, the sender ICS user address, the recipient ICS user address, the request identification, the speed classification, and the like. I'm out. The request identification registered in the conversion table 113-1 is represented by, for example, "1" for the intra-company communication service, "2" for the inter-company communication service, and "3" for the virtual leased line connection described in another embodiment. The speed classification includes the speed and throughput of the line required for communication from the ICS network address (for example, the number of ICS frames transferred within a certain time).
【0029】
<< Preparation for in-house communication >> For LAN100-1 and LAN100-2 users, in-house communication between terminals connected to each LAN communicates via VAN-1 and VAN-3. Specify the terminal to the VAN operator and apply so that it can be done. Then, the VAN operator responds to the application by displaying the above-mentioned ICS network address, ICS user address, and request identification in the conversion table of the access control devices 110-1 and 110-5 connected to LAN100-1 and LAN100-2. Etc. are also set, and they are also written and stored in the ICS address management server 150-1.
【0030】
The settings related to VAN-1 are as follows. The ICS network address is determined from the ICS logical terminal of the access control device 110-1 to which LAN100-1 is connected. Here, the ICS network address of the logical terminal is set to "7711". The in-house communication address of one terminal connected to the LAN100-1 for which the application was made is set to "0012", and this is set as the sender ICS user address. The inter-company communication address used by the terminal with this address is set to "2212", and this is set as the sender ICS user address. Then, the ICS network address is determined from the ICS logical terminal of the access control device 110-5 connected to the LAN100-2 for which the application was made. Here, the ICS network address is set to "9922" and this is used as the incoming ICS network address. To do. Further, the ICS user address of one terminal connected to LAN100-2 is set to "0034", and this is set as the recipient ICS user address. The value "1" indicating the in-house communication service for which the application has been made is used as the request identification, and the above is registered in the conversion table 113-1.
【0031】
The settings related to VAN-3 are as follows. Set the values required for reverse communication (communication from LAN100-2 to LAN100-1) in the conversion table of the access control device 110-5 that connects the LAN100-2 that you applied for. That is, the outgoing ICS network address and the incoming ICS network address set the opposite data, and at the same time, the sender ICS user address and the receiver ICS user address set the opposite data. Set the ICS network address of LAN100-2 to "9922" and use it as the outgoing ICS network address. Set "0034" as the in-house ICS user address of the terminal connected to LAN100-2 as the sender ICS user address, and set the ICS user address "0012" of the communication destination terminal as the receiver ICS user address. Further, the ICS network address "7711" of LAN100-1 is set as the incoming ICS network address, the value of the request identification indicating the in-house communication service is set to "1", and this is set as the request identification. Write the above in the conversion table of access control device 110-5 and register it.
【0032】
<< Operation of intra-company communication >> The terminal with the ICS user address "0012" sends the ICS user frame P1. The sender ICS user address "0012" is set in this ICS user frame P1, and "0034" is set in the receiver ICS user address.
【0033】
Next, it will be described with reference to the flowchart of FIG.
【0034】
The ICS user frame P1 is transferred to the access control device 110-1 via the user logical communication line 180-1. The access control device 110-1 obtains conversion table 113-1 from the outgoing ICS network address 7711 of LAN100-1 and the recipient ICS user address 0034 of the received ICS user frame (steps S100, S101). Refer to it and know that this communication is an intra-company communication from the request identification value 1 (step S102). The incoming ICS network address 9922 corresponding to the recipient ICS user address 0034 is acquired (step S103) and then ICS-encapsulated (step S106). The above procedure is shown in the flowchart as shown in Fig. 12, and the intra-company communication is the flow of (1) in it. The sender ICS user address may be used, for example, to specify the source of the ICS frame.
【0035】
The access control device 110-1 constitutes the ICS network frame P2 by ICS encapsulation and transmits the ICS network frame P2 to the relay device 120-1. Since the ICS network address of the network control unit is guaranteed to be unique inside the ICS, it does not collide with other ICS frames. The ICS network frame P2 passes through the relay devices 120-1 and 120-2 based on the incoming ICS network address, and reaches the access control device 110-5 of VAN-3. The access control device 110-5 removes the network control unit from the ICS network frame P4, decapsulates the ICS, reproduces the same ICS user frame P5 as the ICS user frame P1 from the network data unit of the ICS frame, and transfers it to LAN100-2. .. The ICS user frame is routineized in LAN100-2 and transferred to the terminal with the ICS user address "0034".
【0036】
<< Preparation for inter-company communication >> As an example of inter-company communication service, connect to a terminal with ICS user address "0012" connected to LAN100-1 according to address system ADX and LAN100-3 according to address system ADY. The communication with the terminal having the ICS user address "1156" will be described. Users of LAN100-1 and LAN100-3 specify terminals for the connected VANs so that they can communicate via VAN-1 and VAN-2, and apply to the VAN operator. The VAN operator sets the necessary items in the conversion table of the access control device connected to LAN100-1 and LAN100-3 according to the application.
【0037】
The settings related to VAN-1 are as follows. The ICS network address of LAN100-1 is set to "7711", the in-house communication address of one terminal connected to the applied LAN100-1 is set to "0012", and this is set as the sender ICS user address. The inter-company communication address assigned to the terminal of this ICS user address is set to "2212", and this is set as the sender ICS user address (inter-company). The ICS network address is determined from the ICS logical terminal of the access control device 110-4 to which the ICS network address of LAN100-3 that has been applied for is connected. Here, "8822" is used and this is used as the incoming ICS network address. Also, the ICS user address of one terminal connected to LAN100-3 is set to "1156", and this is set as the recipient ICS user address. Furthermore, the value "2" indicating the inter-company communication service for which the application has been made is used as the request identification, and the above is registered in the conversion table 113-1.
【0038】
The settings related to VAN-2 are as follows. As a conversion table of the access control device 110-4 to which LAN100-3 is connected, a temporary conversion table 114-2 that retains reverse data for a certain period of time, for example, 24 hours is set. That is, regarding the ICS network address "8822" to which LAN100-3 that uses the communication service between companies is connected, the outgoing ICS network address, the sender ICS user address, the recipient ICS user address, the incoming ICS network address, the request identification, etc. Temporary conversion table 114-2 including the above is provided inside the access control device 110-4. However, the timing of setting in the temporary conversion table 114-2 will be described later. In the other embodiment described above, the temporary conversion table 114-2 is not set.
【0039】
<< Operation of inter-company communication >> A terminal with an ICS user address "0012" sends an ICS user frame F1 with "0012" set as the sender ICS user address and "1156" set as the recipient ICS user address. To do. The ICS user frame F1 is transferred to the access control device 110-1 via the user logical communication line 180-1.
【0040】
The access control device 110-1 refers to the conversion table 113-1 using the outgoing ICS network address 7711 and the recipient ICS user address 1156 of LAN100-1 (steps S100, S101) to identify the request. Know that is "2", that is, an inter-company communication service (step S102). Next, while knowing that the incoming ICS network address corresponding to the receiver ICS user address 1156 is 8822 (step S104), the sender ICS user address 0012 is changed to the inter-company communication address 2212. Convert (step S105). The access control device 110-1 is provided with a network control unit as an outgoing ICS network address "7711", a sender ICS user address "2212", a receiver ICS user address "1156", and an incoming ICS network address "8822". It is encapsulated in ICS and transmitted to relay device 120-1 as ICS network frame F2 (step S106). The above procedure is the flow of (2) in the flowchart of FIG.
【0041】
In the above inter-company communication, when the sender ICS user address in the ICS user frame F1 is set to the inter-company communication address "2212", the sender and the receiver perform inter-company communication using the inter-company communication address ( Steps S102, S104). In this case, the access control device 110-1 does not execute the process of converting the sender ICS user address "2212" to the inter-company communication address "2212" because it is unnecessary. The above procedure is (3) in the flowchart of FIG. The sender ICS user address may be used, for example, to specify the source of the ICS frame.
【0042】
The relay device 120-1 passes the ICS network frame based on the incoming ICS network address through the relay device 120-2 in VAN-1, the gateway 130 between VANs, and the relay device 120-3 in VAN-2, and then VAN. Transfer to access control device 110-4 in -2. Next, it will be described with reference to the flowchart of FIG. The access control device 110-4 receives the ICS network frame (step S110) and creates the ICS user frame F5 from the network data section (step S111:). ICS decapsulation), determine the ICS logical terminal to be transmitted from the incoming ICS network address ((1) in step S112), and transfer to LAN100-3 (step S113). At the same time, the relationship between the outgoing ICS network address "8822", the sender ICS user address "1156", the receiver ICS user address "2212", and the incoming ICS network address "7711" is inside the access control device 110-4. If it is not registered in the conversion table, these four types of addresses are set to "2" for request identification, that is, the designation of inter-company communication is set in the temporary conversion table 114-2 ((2) in step S112). The settings in Temporary Conversion Table 114-2 are updated by performing processing such as deleting them when they are not used for 24 hours, for example. The ICS user frame is routinely routed through LAN100-3 and transferred to the terminal with the ICS user address "1156". If the sender ICS user address field in conversion table 114-2 is divided into "inside the company" and "between companies" as shown in conversion table 113-1, for example, the sender ICS user address (inside the company) In the case of a conversion table in which the value of is "0023" and the value of the sender ICS user address (between companies) is "1159", the destination address of the user control unit of the ICS user frame immediately after ICS decapsulation. When the ICS user frame whose address value is "1159" written in the column of is processed, the process of rewriting the destination address value of the user control unit of this ICS user frame to "0023" is performed in step S112 (1) described above. ) Is added to the process. To summarize the effects of the above processing, the ICS user address "0023" for intra-company communication is used inside the LAN, but for other companies outside the LAN, the ICS user address for inter-company communication. Can be claimed to be "1159". In the other examples above, it is not set in Temporary Change Table 114-2. Furthermore, in the other embodiment above, conversion table 113-1 does not include sender ICS user addresses (intra-company) and sender ICS user addresses (between companies). Further, the flowchart (2) of FIG. 12, that is, step S105 is not included. Also, in step S104, the sender ICS user address is not referenced. The merit of this embodiment is that when there are many sender ICS user addresses for one receiver ICS user address, the number of registrations in the conversion table can be reduced to only one receiver ICS user address.
【0043】
Example-2 (Virtual Leased Line): The operation of the virtual leased line connection according to the present invention will be described with reference to FIG. Here, the virtual leased line connection is a communication in which the ICS user frame is fixedly transferred to the incoming ICS network address registered in the conversion table regardless of the ICS user address in the user control unit of the ICS user frame. It takes the form of one-to-one or one-to-N. The components of FIG. 14 are almost the same as those of FIGS. 10 and 11 of the first embodiment, and the difference is the registered contents of the conversion table. In the conversion table of the access control device, the incoming ICS network address is fixedly determined from the outgoing ICS network address, so the sender ICS user address (inside the company), the sender ICS user address (between companies), and the receiver ICS user. The address is not registered, or even if it is registered, it is ignored.
【0044】
Between company X's LAN200-1 connected to access control device 210-1 and company X's LAN200-2 connected to access control device 210-5 using a virtual leased line connection The case of communicating with is described.
【0045】
<< Preparation >> The user applies to the VAN operator for a virtual leased line connection. The VAN operator determines the ICS network address 7711 of the ICS logical terminal at the connection point between the access control device 210-1 that connects LAN200-1 of company X and the user logical communication line 240-1, and similarly, company X Determine the ICS network address "9922" of the ICS logical terminal at the connection point between the access control device 210-5 that connects LAN200-2 and the user logical communication line 240-2. Next, the VAN operator sets the outgoing ICS network address 7711, the incoming ICS network address 9922, and the request type in the conversion table 213-1 of the access control device 210-1. FIG. 14 shows an example in which the request type 3 is set as a virtual leased line connection. Similarly, the outgoing ICS network address "9922", the incoming ICS network address "7711", and the request type information are set in the conversion table of the access control device 210-5.
【0046】
<< Procedure >> This will be described with reference to the flowchart of FIG.
【0047】
LAN200-1 of company X sends ICS user frame F10 to ICS200 through user logical communication line 240-1. The access control device 210-1 receives the ICS user frame F10 from the ICS logical terminal of the ICS network address 7711 (steps S200 and S201), and the value of the request identification of the outgoing ICS network address 7711 in the conversion table 213-1. Refer to 3 to recognize that it is a virtual leased line connection (step S202), and read the incoming ICS network address 9922 (step S203). Next, the access control device 210-1 creates an ICS network frame F11 by adding a network control unit in which the incoming ICS network address is set to "9922" and the outgoing ICS network address is set to "7711" to the ICS user frame F10. (Step S204: ICS encapsulation) and send it to the relay device 220-1 (step S205). The relay device 220-1 that has received the ICS network frame F11 determines the transmission destination based on the incoming ICS network address of the ICS network frame F11, and transmits the ICS network frame F12 to the relay device 220-2. The ICS network frame F12 is transferred to the access control device 210-5 via the relay device 220-4 in the VAN-3.
【0048】
The access control device 210-5 removes the network control unit from the ICS network frame F13 (ICS decapsulation), and transfers the ICS user frame F14 from the ICS logical terminal of the ICS network address 9922 to the user logical communication line 240-2. Send out. Then, LAN200-2 of company X receives the ICS user frame F14. Since it is possible to transmit from LAN200-2 to LAN200-1 in the same manner as described above, mutual communication is possible. In the above explanation, it is clear that the sender and the receiver do not necessarily have to be the same company X. Therefore, the same method is used to change the LAN200-1 of the company X to the LAN200-3 of another company Y. ICS user frames can be transferred toward.
【0049】
Further, in the above description, one-to-one communication has been described as an example, but one-to-N communication is also possible. For example, in the conversion table 213-1 of the access control device 210-1 in FIG. 14, a plurality of incoming ICS network addresses may be set as shown by 7712 of the outgoing ICS network address. In this example, two ICS network addresses "6611" and "8822" are set. When the access control device 210-1 receives an ICS user frame from the ICS logical terminal whose ICS network address is "7712", the access control device 210-1 is the first ICS network frame to which a network control unit in which "6611" is set for the incoming ICS network address is added. Then, a second ICS network frame with a network control unit set to the incoming ICS network address set to "8822" is created, and these are sent to the relay device 220-1. As a result, one-to-two communication is possible. Furthermore, one-to-N communication is possible by transferring individual ICS network frames in the same manner as above.
【0050】
Example-3 (ICS network server): As shown in FIG. 16, the ICS network server 330 is configured by the processing device 331 and the ICS network database 332, and the data held by the ICS network database 332 is set as a question item, type, and answer. It consists of the contents and the network address of another ICS network server. The ICS network server 330 analyzes the data part of the ICS frame received from the access control device 310-1, refers to the ICS network database 332 based on this, and acquires the answer contents corresponding to the question items (type " (When 1 ), the obtained answer is transmitted to the access control device 310-1. Furthermore, when the ICS network database 332 does not retain the answer content corresponding to the question item (type "2"), the question item is entered using the ICS network server communication function based on the ICS network address of another ICS network server. The corresponding answer is obtained by asking another ICS network server, and the answer to the question obtained as a result is transmitted to the access control device 310-1.
【0051】
More specifically, the ICS user address 2000, the ICS network address 7721, and the request identification 4 of the ICS network server 330 are registered in the conversion table 313-1 as preparation items. Here, the request identification "4" indicates that the ICS user address "2000" is a common number (referred to as an ICS special number) with other users, such as the Japanese telephone number "119". Next, write in the ICS network database 332 that the type for question Q1 is "1" and the answer content is "A1", the type for question Q2 is "2", the answer content is blank, and the other ICS network server 340. Write down the ICS network address "8844".
【0052】
Next, the user with the ICS user address 0012 sends the ICS user frame F20 to the ICS user address 2000 of the ICS network database 332 (including question Q1), and the access control device 310-1 connects to the line. Receives the ICS user frame F20 from the ICS logical terminal in Part 311-1, obtains the ICS network address "7711", and then ICS-encapsulates the ICS frame F20 in the ICS network server 320 with reference to conversion table 313-1. Send the ICS network frame. As shown in the flowchart of FIG. 17, the ICS network database 332 finds the answer A1 corresponding to the question Q1 included in the ICS frame F20 (steps S300 and S301), and returns the answer A1 to the access control device 310-1. The access control device 310-1 transmits an ICS frame containing the answer A1 to the ICS user address 0012.
【0053】
The user with the ICS user address 0012 sends the ICS frame F21 to the ICS user address 2000 (including question Q2), and the access controller 310-1 refers to the conversion table 313-1 and ICS. When the network address "7721" is obtained, the ICS frame in which the ICS frame F21 is encapsulated in ICS is sent. The ICS network database 332 recognizes the type 2 corresponding to question Q2 of the ICS frame F21 (step S300), learns that the ICS network database 332 itself does not hold the answer (A2), and other ICSs. Based on the ICS network address "8844" of the network server 340, information is exchanged with the ICS network server 340 using the ICS network communication function (step S302), and the answer "A2" corresponding to question Q2 is obtained (step S303). , Returns answer A2 to access control device 310-1. The access control device 310-1 transmits an ICS frame containing the answer A2 to the ICS user address 0012.
【0054】
Example-3A (when the ICS network server is connected to the relay device): As shown in FIG. 16, the ICS network server 330 is connected to the access control device 310-1, but the relay device 320-1 Is not connected. On the other hand, in this embodiment, as shown in FIG. 18, the ICS network servers 340A-1 and 340A-2 are connected to the access control devices 310A-1 and 310A-2, respectively, but the ICS network server 340A-3 relays. Connected to device 320A-1. In addition, all ICS network servers 340A-1, 340A-2, and 340A-3 have the only ICS network address inside the ICS300A. The ICS network server 340A-3 uses the ICS network communication function to communicate with the ICS network servers 340A-1 and 340A-2 connected to the access control device inside the same VAN-300A1, and only these ICS network servers. Can collect and retain the unique information it holds. Such an ICS network server is called an ICS network server representing the VAN-300A1. As a result, the ICS network server 340A-1 communicates with the ICS network server 340A-3, which represents the VAN-300A1, and obtains the unique information possessed by the ICS network server 340A-2 connected to other access control devices. can do. In addition, the ICS network server 340A-3 representing VAN-300A1 and the ICS network server 340A-6 representing other VAN-300A2 communicate with each other using the ICS network communication function, and the unique information held by each is used. Can be exchanged. The ICS network server connected to the access control device may be made to collect the information held by all the ICS network servers inside the VAN, and may be used as the ICS network server representing the VAN.
【0055】
Example-4 (ICS Address Management Server): As shown in FIG. 19, the ICS address management server 430 is connected to the access control device 410-1 via the ICS network communication line 460, and the access control device 410-1 is connected to the access control device 410-1. The correspondence table 432 of the ICS network address having the ICS logical terminal and the corresponding ICS user address is held in the line section 411-1. For example, it holds the ICS network addresses "7711", "7711", "7712", and "7713" corresponding to the ICS user addresses "2013", "2014", "1234", and "4500", respectively. At the same time, all the information described in the conversion table and address-related information such as records related to VAN operation may be included. Further, the ICS address management server 430 holds the ICS network addresses of the plurality of other ICS address management servers and the ICS network addresses of the plurality of ICS name servers. Further, the ICS address management server communicates with the ICS name server shown in Example 5 described later by using the ICS network server communication function, and can obtain the ICS name corresponding to the ICS user address.
【0056】
The processing device 412-1 of the access control device 410-1 communicates with the ICS address management server 430 using the ICS network server communication function, presents the value of the ICS network address, and asks for the corresponding ICS user address. Alternatively, you can present the value of the ICS user address and tell us the corresponding ICS network address. This will be described with reference to the flowchart of FIG. The ICS address management server 430 checks whether the ICS network address or ICS user address inquired from the access control device server 410-1 is registered in the correspondence table 432 held by itself (step S400), and is included in the correspondence table. If yes, answer (step S401), and if not, communicate with another ICS address management server 440 using the ICS network server communication function to obtain the ICS user address or ICS network address (step S402). ), Answer this result to the access control device 410-1 from which the question was asked (step S403). With this configuration, the access control device 410-1 can request the ICS address management server 430 to acquire the other address from one of the ICS network address and the ICS user address.
【0057】
Example-4A (when the ICS address management server is connected to the relay device): As shown in FIG. 19, the ICS address management server 430 is connected to the access control device 410-1, but the relay device 420- Not connected to 1. On the other hand, in this embodiment, as shown in FIG. 21, the ICS address management server 450B-3 is connected to the relay device 420B-1, and the ICS address management server 450B-3 has the only ICS network address inside the ICS400B. There is. The ICS address management server 450B-3 uses the ICS network server communication function to communicate with the ICS address management servers 450B-1 and 450B-2 connected to the access control device inside the same VAN-400B1 to communicate with these ICSs. The ICS network address, ICS user address, and ICS address-related information held by the address management server can be collected and held. Such an ICS address management server is called an ICS address management server representing the VAN-400B1. As a result, the ICS address management server 450B-1 can communicate with the ICS address management server 450B-3 representing the VAN-400B1 and obtain the ICS address-related information possessed by the ICS address management server 450B-2. In addition, the ICS address management server 450B-3 representing VAN-400B1 and the ICS address management server 450B-6 representing other VAN-400B2 communicate using the ICS network server communication function, and the ICS held by each communicates. Address related information can be exchanged. The ICS address management server connected to the access control device may be made to collect the information held by all the ICS address management servers inside the VAN, and may be used as the ICS address management server representing the VAN.
【0058】
Example-5 (ICS name server): The ICS user address has a drawback that it is difficult to remember because it is represented by, for example, a 32-bit long binary number or a 128-bit binary number. Instead, it is easy for a person to remember "ICS". The method of using the "name" is the fifth embodiment. The term "ICS domain name" is also used instead of "ICS name". In this case, instead of the ICS name server, it is called the ICS domain name server.
【0059】
First, the ICS name will be described. As shown in Fig. 7, the binary ICS address is represented by, for example, a regional management code, a country code, a VAN code, a VAN regional code, a VAN access point code, and a user logical code, and these numerical codes are arranged side by side. For example, the area management code The country code The VAN code The VAN area code The VAN access point code The user logical code. For the ICS name, for example, the regional management code that can be represented by a binary value as described above is AS (element of the ICS name meaning Asia), JP (Japan), VAN # 1 (identifies one of VAN), DIS. # 1 (identifies one of the VAN area codes that make up VAN # 1), ACS # 1 (identifies one of the VAN access point codes limited by DIS # 1), USR # 1 (identifies one of the user logical codes) (Identify one). The elements of the ICS name defined above are reversed and arranged with the dot "." In between, that is, "USR # 1.ACS # 1.DIS # 1.VAN # 1.JP.AS" is the ICS name. To be determined. In the above case, for example, the ICS name is divided into USR # 10 and COMP # 10, ACS # 1 is divided into ACS # 11 and ACS # 12, and "USR # 10.COMP #" as a whole. 10.ACS # 11.ACS # 12.DIS # 1.VAN # 1.JP.AS may be divided into more details.
【0060】
An ICS name server, which is a type of ICS network server, will be described. As shown in FIG. 22, the ICS name server 550 is composed of a processing device 551 and an ICS name conversion table 552, and the ICS name conversion table 552 contains, for example, an ICS name and a type (the existence of an ICS user address corresponding to the ICS name). Identification), ICS user address, etc. Type "2" indicates that the ICS network database 332 does not hold the ICS network address corresponding to the ICS name, and therefore obtains the ICS network address corresponding to the ICS name from another ICS name server. Here, for example, other ICS name servers that manage the ICS name USR # 2.ACS # 2.DIS # 2.VAN # 2.JP.AS are DIS excluding USR # 2.ACS # 2. It can be called by "# 2.VAN # 2.JP.AS". The ICS name server 550 analyzes the ICS frame data part received from the access control device 510-1, refers to the ICS name conversion table 552 based on this, acquires the ICS user address corresponding to the ICS name, and obtains the access control device. Send to 510-1. Furthermore, based on the ICS user dress, the corresponding ICS name is answered. If the corresponding ICS user address does not exist in the ICS name conversion table 552, use the ICS network server communication function to request another ICS name server that holds the ICS user address in question, and from here. The acquired ICS user address is sent to the access control device 510-1.
【0061】
The terminal with the sender ICS user address "0012" connected to LAN500-1 is the ICS user address corresponding to "USR # 1.ACS # 1.DIS # 1.VAN # 1.JP.AS" with ICS name 1. The acquisition method of is explained. Here, a case where the access control device 510-1 acquires data from the ICS name server 550 and a case where the access control device 510-1 acquires data from another ICS name server 560 will be described.
【0062】
First, as a preparation, the ICS network address "7741" and the request identification "4" corresponding to the ICS user address "1000" of the ICS name server 550 are registered in the conversion table 513-1 of the access control device 510-1. Here, the request type "4" represents an ICS special number common to other users, such as the ICS user address "1000" being the telephone number "119". Register the recipient ICS user address "2014" corresponding to the ICS name "USR # 1.ACS # 1.DIS # 1.VAN # 1.JP.AS" in the ICS name conversion table 552 of the ICS name server 550. Then, the terminal user of the sender ICS user address 0012 of LAN500-1 transmits the ICS user frame F40 to the access control device 510-1, and the ICS name # 1 USR # 1.ACS # 1.DIS # 1 Request conversion from .VAN # 1.JP.AS to ICS user address. The processing device 512-1 in the access control device 510-1 receives the ICS user frame F40 from the ICS logical terminal of the line section 511-1, acquires this ICS network address 7711, and then the ICS user frame F40. Refer to the conversion table 513-1 based on the recipient ICS user address, and when the corresponding request identification is "4" (connect to the ICS name server with the ICS special number), the ICS network address "7711" obtained by the above operation. Is used to encapsulate the ICS user frame F40 in ICS and send the ICS network frame containing the ICS name to the ICS name server 550.
【0063】
As shown in the flowchart of FIG. 23, the ICS name server 550 analyzes the ICS name in the ICS frame received from the address control device 510-1 in the processing device 551, and refers to the ICS name conversion table 552 based on this. (Step S500). Then, if the ICS user address corresponding to the ICS name exists in the ICS name conversion table 552, it is acquired and the ICS network frame F45 including the ICS user address 2014 is transmitted to the access control device 510-1. (Step S501). If the questioned ICS name does not exist in the ICS name conversion table 552, for example, the processing device 512-1 receives the ICS user frame F41, and the ICS name # 2 described in this ICS user frame F41 (that is, that is). If USR # 2.ACS # 2.DIS # 2.VAN # 2.JP.AS) is not listed in the ICS name conversion table 552, the ICS name server 550 will have an ICS name (DIS # 2.VAN # 2. Based on JP.AS), the ICS asked by obtaining the ICS network address of another ICS name server from the ICS name conversion table 552 and exchanging information with the ICS name server 560 using the ICS network server communication function. The ICS user address 1130 corresponding to the name is acquired (step S502), and the acquired result is transmitted to the access control device 510-1 (step S503).
【0064】
The access control device 510-1 exchanges information with the ICS address management server 570 based on the recipient ICS user address described in the ICS network frame F45 received from the ICS name server 550, and the ICS corresponding to the ICS user address. Acquire the address-related information included in the network address and its correspondence table, and write the data consisting of the obtained ICS user address, ICS network address, and address-related information to conversion table 513-1. The access control device 510-1 transmits the ICS user address 2014 (or 1130) obtained from the ICS name server 550 to the terminal user having the sender ICS user address 0012 of LAN500-1. Here, the ICS user address 0012 is written in the ICS network frame F45. The terminal user of the sender ICS user address 0012 of LAN500-1 obtains the receiver ICS user address 2014 (or 1130) obtained from the access control device 510-1.
【0065】
Example-5A (when the ICS name server is connected to the relay device): In FIG. 22, the ICS name server 550 is connected to the access control device 510-1, but is connected to the relay device 520-1. Absent. On the other hand, in this embodiment, as shown in FIG. 24, the ICS name server 550C-3 is connected to the relay device 520C-1, and the ICS name server 550C-3 has the only ICS network address inside the ICS500C. The ICS name server 550C-3 uses the ICS network server communication function to communicate with the ICS name servers 550C-1 and 550C-2 connected to the access control devices 510C-1 and 510-C2 inside the same VAN-500C1. Therefore, it is possible to collect and retain unique information held only by these ICS name servers. Such an ICS name server is called an ICS name server representing the VAN-500C1. As a result, the ICS name server 550C-1 can communicate with the ICS name server 550C-3 representing the VAN-500C1 and obtain the unique information possessed by the ICS name server 550C-2. In addition, the ICS name server 550C-3 representing VAN-500C1 and the ICS name server 550C-6 representing other VAN-500C2 communicate using the ICS network server communication function, and the unique information held by each is used. Can be exchanged. The ICS name server connected to the access control device may be made to collect the information held by all the ICS name servers inside the VAN, and may be used as the ICS name server representing the VAN.
【0066】
Example-6 (ICS name server): In Examples-5 and -5A, the access control device 510-1 writes the obtained data such as the ICS user address and the ICS network address to the conversion table 513-1. Write these data obtained in to Temporary Conversion Table 514-1. In this case, the address data written in the temporary conversion table is deleted after, for example, 24 hours.
【0067】
Example-7 (ICS name server): In Examples-5 and -5A, the access control device 510-1 does not call the address management server 570, but instead uses the obtained ICS user address 2014 (or 1130). Only the service to notify the terminal with the ICS user address "0012" is provided.
【0068】
Example-8 (Billing server): The billing method includes a "network billing method" that counts and charges ICS user frames transmitted and received when communication is performed, and counts information inside the transmitted and received ICS user frames. The "information billing method" that charges for the ICS user frame, and the period during which the ICS user address etc. are continuously registered in the conversion table of the access control device without charging for the transmitted and received ICS user frames, for example, a fixed charge for each month. There are three methods, the "flat-rate billing method" that sets. Here, in the information billing method, the user control unit of the ICS user frame is counted and charged by designating an identifier indicating information billing. In both the network billing method and the information billing method, the case where the sender of the communication bears the charge is called "outgoing billing", and the case where the receiver bears the bill is called "incoming billing". The network billing method and the information billing method are collectively called the "pay-as-you-go billing method".
【0069】
<< Configuration >> A billing method in the ICS network of the present invention will be described with reference to FIGS. 25 and 26.
【0070】
The billing method setting information is retained in the conversion table 813-1 in the access control device 810-1 and the flat-rate charge definition table 843 in the billing server 840, and the conversion table 813-1 shows whether network billing is performed or not. And the set value of whether to use the pay-as-you-go billing method (separate outgoing billing and incoming billing) or the flat-rate billing method (separate outgoing billing and incoming billing) are retained. .. Hereinafter, description will be made with reference to the flowchart of FIG. 27. When the access control device 810-1 receives the ICS user frame F50 (step S800), the type of billing method for each ICS frame held in the conversion table 813-1 based on the ICS user address included in the ICS user frame. Is read to check the billing conditions (step S801), and if the read type indicates a pay-as-you-go billing method, billing information is generated, and the billing information is used as the billing information frame F51, which is one of the ICS network servers. (Step S810), and only when the read content is a value indicating the flat-rate billing method, the billing information is not generated and the billing information is not transferred to the billing server 840 as the billing information frame F51 (step S820).
【0071】
The billing server 840 receives the billing information frame F51 sent from each access control device, and stores the billing information included in the billing information frame. The billing server 840 contains a billing processing device 841 and a billing information database 842, and the billing processing device 841 receives the billing information frame F51 sent from the access control device 810-1 and the billing information included in the billing information frame F51. Is analyzed and stored in the billing information database 842. The billing information database 842 stores billing information as a database with the ICS network address and the ICS user address as identifiers. In addition, in the case of the pay-as-you-go billing method, the billing information database 842 stores information with a count indicating the pay-as-you-go, and an upper limit can be set for the count. If the set upper limit is exceeded, the billing server 840 Notifies the access control device 810-1 that the count exceeds the upper limit value, and stops the communication of the corresponding user in the access control device 810-1 that receives the notification. The billing server 840 can pass the stored billing information to other VANs and users by using the ICS network server communication function.
【0072】
(1) Communication example of pay-as-you-go billing method of outgoing billing by network billing: A case where company X and company Y perform communication between companies using the ICS800 of the present invention will be described. In this case, the billing method for communication between LAN800-1 and LAN800-3 is a case where network billing is a pay-as-you-go billing method, all charges are borne by LAN800-1, and information billing is not performed.
【0073】
<< Preparations for communication >> Connect LAN800-1 and LAN800-3 to the respective access control devices 810-1 and 810-4.
【0074】
<< Preparation for billing >> Register the billing conditions for LAN800-1 and LAN800-3 for communication in the conversion table 813-1. For registration in conversion table 813-1, billing conditions are set based on the outgoing ICS network address, sender ICS user address, incoming ICS network address, and recipient ICS user address. Set "1" as the value for outgoing billing using the pay-as-you-go billing method for network billing. Also, set "1" as the billing unit price. Since information billing is not performed, "0" indicating non-billing is set in the billing condition in the information billing condition of conversion table 813-1. Since the charge burden is LAN800-1 in the conversion table to the access control device 810-4 that accommodates LAN800-3, a flat-rate billing method is used to prevent the access control device 810-4 from performing billing processing. Set 0 to indicate.
【0075】
<< Explanation of billing operation >> The ICS user frame F50 sent by the terminal with the ICS network address "0012" connected to LAN800-1 is sent by the processing device 812-1 in the access control device 810-1 (step S800, S801), specify the billing condition field from the sender ICS user address and the recipient ICS user address in the ICS user frame (step S810), and refer to the billing condition to specify the billing method related to network billing from the field. .. In this case, since the setting value of the outgoing billing is set to "1" in the pay-as-you-go billing method, the billing unit price is referred to (step S811) and the billing information is generated (for example, the billing unit price "1". Is generated as one-time billing information) (step S812), and the billing information is transferred to the billing server 840 as a billing information frame F51 (step S813). In the billing processing device 841 of the billing server 840, the network billing counter of the billing information database 842 is added according to the billing information in the billing information frame F51 received from the access control device 810-1 (step S814). If the billing conditions are not any of the billing examples described later, the billing described here is performed.
【0076】
(2) Communication example of a flat-rate billing method for outgoing billing by network billing: A case where the company X uses the ICS800 of the present invention to perform communication within the company X will be described. In this case, the billing method for communication between LAN800-1 and LAN800-2 is a case where network billing is a flat-rate billing method, all charges are borne by LAN800-1, and information billing is not performed.
【0077】
<< Preparations for communication >> Connect LAN800-1 and LAN800-2 to the respective access control devices 810-1 and 810-5.
【0078】
<< Preparation for billing >> Register the billing conditions for LAN800-1 and LAN800-2 to communicate in the conversion table 813-1. For registration in conversion table 813-1, billing conditions are set based on the outgoing ICS network address, sender ICS user address, incoming ICS network address, and recipient ICS user address. 0 is set as the value for using network billing as the flat-rate billing method, and 1 is set for the billing burden in the flat-rate billing definition table 843 to indicate the outgoing billing. Since information-related charges are not performed, "0" indicating non-charge is set in the charge conditions in the information charge conditions in conversion table 813-1. Also set "0", which indicates the flat-rate billing method, in the conversion table for the access control device 810-5 that accommodates LAN800-2.
【0079】
<< Explanation of billing operation >> The ICS user frame sent by the terminal with the ICS network address "0012" connected to LAN800-1 is sent by the processing device 812-1 in the access control device 810-1 (steps S800, S801). ), The billing condition field is specified from the sender ICS user address and the recipient ICS user address in the ICS user frame (step S810), and the billing condition is referred to in order to specify the billing method related to network billing from the field. Since the set value in this case is 0 indicating the flat-rate billing method, billing processing such as generation of billing information is not performed (step S820). The process of billing the charge is performed with reference to the flat rate charge definition table 843. In other words, since "0" indicating outgoing charge is set in the flat-rate charge definition table 843, the charge is charged to LAN800-1.
【0080】
(3) Communication example of pay-as-you-go billing method for incoming billing by network billing: A case where company X and company Y perform communication between companies will be described. In this case, the billing method for communication between LAN800-1 and LAN800-3 is a case where network billing is used as a pay-as-you-go billing method, all charges are borne by LAN800-3, and information billing is not performed.
【0081】
<< Preparations for communication >> Connect LAN800-1 and LAN800-3 to the respective access control devices 810-1 and 810-4.
【0082】
<< Preparation for billing >> Register the billing conditions for LAN800-1 and LAN800-3 to communicate in the conversion table 813-1. For registration in conversion table 813-1, billing conditions are set based on the outgoing ICS network address, sender ICS user address, incoming ICS network address, and recipient ICS user address. Set "2" as the value for incoming billing by the pay-as-you-go billing method for network billing, and set "1" as the billing unit price. Since information billing is not performed, "0" indicating non-billing is set in the billing condition in the information billing condition of conversion table 813-1. In the conversion table to the access control device 810-4 that accommodates LAN800-3, since the charge burden is LAN800-3, set "2" as the value for making the network charge the callee charge by the pay-as-you-go method. ..
【0083】
<< Explanation of billing >> The ICS user frame sent by the terminal with the ICS network address "0012" connected to LAN800-1 is sent by the processing device 812-1 in the access control device 810-1 (steps S800, S801). ), The billing condition field is specified from the sender ICS user address and the recipient ICS user address in the ICS user frame (step S810), and the billing condition is referred to in order to specify the billing method related to network billing from the field. Since the set value in this case is "2", which indicates incoming charge by the pay-as-you-go billing method, the access control device 810-1 in which LAN800-1 is accommodated interrupts the billing process (step S820). When the access control device 810-4 in which LAN800-3 is housed receives the corresponding ICS frame, it refers to the conversion table. In this case, since network billing is set to "2", which is a pay-as-you-go billing method, billing information is generated (for example, billing unit price "1" is generated as two-time billing information) and billing is performed. It is sent to the billing server 840 as an information frame. The network billing counter of LAN800-3 of the billing information database 842 is added according to the billing information of the billing information frame received from the access control device 810-4 by the billing processing device 841 of the billing server 840.
【0084】
(4) Communication example of flat-rate billing method for incoming billing by network billing: A case where company X performs communication within company X will be described. In this case, the billing method for communication between LAN800-1 and LAN800-2 is a case where network billing is a flat-rate billing method, all charges are borne by LAN800-2, and information billing is not performed.
【0085】
<< Preparations for communication >> Connect LAN800-1 and LAN800-2 to the respective access control devices 810-1 and 810-5.
【0086】
<< Preparation for billing >> Register the billing conditions for LAN800-1 and LAN800-2 to communicate in the conversion table 813-1. For registration in conversion table 813-1, billing conditions are set based on the outgoing ICS network address, sender ICS user address, incoming ICS network address, and recipient ICS user address. Set "0" as the value indicating the flat-rate billing method for network billing, and set "2" for incoming billing to the billing burden in the flat-rate billing definition table 843 to indicate the billing burden. Since information-related charges are not performed, "0" indicating non-charge is set in the charge conditions in the information charge conditions in conversion table 813-1. Also set "0", which indicates the flat-rate billing method, in the conversion table for the access control device 810-5 that accommodates LAN800-2.
【0087】
<< Explanation of billing operation >> The ICS user frame sent by the terminal with the ICS network address "0012" connected to LAN800-1 is sent by the processing device 812-1 in the access control device 810-1 (steps S800, S801). ), The billing condition field is specified from the sender ICS user address and the recipient ICS user address in the ICS user frame (step S810), and the billing condition is referred to in order to specify the billing method related to network billing from the field. In this case, since "0" indicating the flat-rate billing method is set, billing processing such as billing information generation is not performed (step S820). The process of billing the charge is performed with reference to the flat rate charge definition table 843. In other words, since "2" indicating incoming call billing is set in the flat-rate charge definition table 843, the charge is charged to LAN800-2.
【0088】
(5) Communication example of pay-as-you-go billing method of outgoing billing by information billing: A case where company X communicates with company Y will be described. The billing method for communication between LAN800-1 and LAN800-3 is a case where information billing is performed without billing on the network. The charge is when the caller is LAN800-1.
【0089】
<< Preparations for communication >> Connect LAN800-1 and LAN800-3 to the respective access control devices 810-1 and 810-4.
【0090】
<< Preparation for billing >> For the billing conditions in the network billing conditions, set "0" indicating non-billing in the conversion table 813-1. Since the billing itself is not performed, the billing unit price is not set. For the information billing condition, set "3" indicating caller billing by pay-as-you-go billing, and set the billing unit price to "2".
【0091】
<< Explanation of billing operation >> The ICS user frame sent by the terminal with the ICS network address "0012" connected to LAN800-1 is sent by the processing device 812-1 in the access control device 810-1 (steps S800, S801). ), Identify the billing condition fields from the sender ICS user address and the recipient ICS user address in the ICS user frame (step S810). Refer to the billing conditions to identify the billing conditions for network communication from that field. In this case, since 0 indicating non-billing is set, the billing process related to the network is not performed (step S820). Next, in order to specify the billing conditions related to information billing, the billing conditions of the information billing conditions are referred to. In this case, since "1" indicating the pay-as-you-go billing paid by the caller is set, the pay-as-you-go billing is performed. Further, the billing unit price indicating the weighting of the pay-as-you-go billing is referred to, and the set value of the billing unit price in this case is 2. Next, based on the obtained information, billing information for each ICS user frame is generated (for example, the billing unit price "2" is generated as billing information for two times), and the billing information is used as the billing information frame F51 for the billing server. Transfer to 840. The billing processing device 841 in the billing server 840 that has received the billing information is a billing information database 842 based on the outgoing ICS network address, the sender ICS user address, the incoming ICS network address, and the recipient ICS user address from the billing information frame F51. The information storage field is specified, and the network billing counter there is added according to the billing information of the billing information frame F51.
【0092】
(6) Communication example of pay-as-you-go billing method for incoming billing with information billing: A case where company X communicates with company Y will be described. The billing method for communication between LAN800-1 and LAN800-3 shows the case where information billing is performed without network billing. The charge is when the called party is LAN800-3.
【0093】
<< Preparations for communication >> Connect LAN800-1 and LAN800-3 to the respective access control devices 810-1 and 810-4.
【0094】
<< Preparation for billing >> For the billing conditions in the network billing conditions, set "0" indicating non-billing in the conversion table 813-1. Since the billing itself is not performed, the billing unit price is not set. For the information billing condition, set "2" indicating the callee billing by pay-as-you-go billing, and set the billing unit price to "2".
【0095】
<< Explanation of billing operation >> The ICS user frame sent by the terminal with the ICS network address "0012" connected to LAN800-1 is sent by the processing device 812-1 in the access control device 810-1 (steps S800, S801). ), Identify the billing condition fields from the sender ICS user address and the recipient ICS user address in the ICS user frame (step S810). Refer to the billing conditions to identify the billing conditions for network communication from that field. In this case, since 0 indicating non-billing is set, the billing process related to the network is not performed (step S820). Next, in order to specify the billing conditions related to information billing, the billing conditions of the information billing conditions are referred to. In this case, "2" indicating the pay-as-you-go billing paid by the called party is set, so the pay-as-you-go billing is performed. .. In addition, the billing unit price indicating the weighting of the pay-as-you-go billing is referred to, and in this case, "2" is set. Next, based on the obtained information, billing information for each ICS user frame is generated (for example, the billing unit price "2" is generated as billing information for two times), and the billing information is used as the billing information frame F51 for the billing server. Transfer to 840. The billing processing device 841 in the billing server 840 that has received the billing information is a billing information database 842 based on the outgoing ICS network address, the sender ICS user address, the incoming ICS network address, and the recipient ICS user address from the billing information frame F51. The information storage field is specified, and the network billing counter there is added according to the billing information of the billing information frame.
【0096】
(7) In the case of pay-as-you-go billing method communication of outgoing billing with information billing, the billing conditions are not registered in the conversion table in advance. Example: A case where company X communicates with company Y will be described. The billing conditions for communication between LAN800-1 and LAN800-4 are the same as above, but in this case, the value that specifies the billing conditions is the conversion table 813-1 of access control 810-1 to which LAN800-1 is connected. The difference is that it is not registered in 1.
【0097】
<< Preparations for communication >> Connect LAN800-1 and LAN800-4 to the respective access control devices 810-1 and 810-2.
【0098】
<< Preparation for billing >> In this case, there is no registration of billing conditions in conversion table 813-1, so no prior preparation is required for the access control device 810-1 that accommodates LAN800-1. In the conversion table of the access control device 810-2 that accommodates LAN800-4, the billing conditions when LAN800-4 receives an incoming call are set. In the billing condition in the network billing condition, "0" indicating non-billing is set in the conversion table. Since the billing itself is not performed, the billing unit price is not set. In the information billing condition, "3" indicating caller billing is set by pay-as-you-go billing, and the billing unit price is set to "1".
【0099】
<< Explanation of billing operation >> The ICS user frame sent by the terminal with the ICS network address "0012" connected to LAN800-1 is sent by the processing device 812-1 in the access control device 810-1 (step S800). From the conversion table 813-1, the sender ICS user address and the receiver ICS user address in the ICS user frame are used to specify the billing condition field (step S801), but in this case, the applicable billing condition is shown. Since there is no field, the access control device 810-4 in which the called user is accommodated is queried based on the recipient ICS user address of the called user (step S802). The access control device 810-4 refers to the conversion table in the access control device 810-4 for the billing conditions of the corresponding called party user, and returns the billing conditions to the access control device 810-1. The billing conditions acquired by the access control device 810-1 from the access control device 810-4 are registered in the temporary conversion table 814-1 (step S803). After that, the processing device 812-1 refers to the billing conditions in order to specify the billing conditions related to network communication from the billing conditions (step S810). In this case, since 0 indicating that the network billing is non-billing is set, the billing process related to the network is not performed (step S820).
【0100】
Next, in order to specify the billing conditions related to information billing, the billing conditions of the information billing conditions are referred to. In this case, since "1" is set to indicate the pay-as-you-go billing paid by the caller, the pay-as-you-go billing is performed. Further, the billing unit price indicating the weighting of the pay-as-you-go billing is referred to, and the set value of the billing unit price in this case is "1", and the weighting of the billing is known. Based on the obtained information, billing information for each ICS user frame is generated (for example, the billing unit price "1" is generated as one-time billing information), and the billing information is transferred to the billing server 840 as the billing information frame F51. To do. The billing processing device 841 in the billing server 840 that has received the billing information identifies the information storage field of the billing information database 842 based on the outgoing ICS network address and the recipient ICS user address from the billing information frame F51, and charges the information there. The counter is added according to the billing information of the billing information frame F51.
【0101】
Example-9 (ICS frame database server): FIGS. 28 and 29 are examples of the ICS 900 including the ICS frame database servers 950 and 960, which are one of the ICS network servers. Data is stored based on the request timing of the terminal that uses ICS900 (hereinafter referred to as "ICS-using terminal"), or the stored data is taken out and sent to the requester. The ICS frame database servers 950 and 960 are composed of processing devices 951 and 961, stored information management tables 952 and 962, and BOX 953 and 963, respectively. The processing devices 951 and 961 receive the ICS user frame from the ICS user terminal, refer to the ICS frame database server usage request explicitly indicated by the ICS user terminal, and store the ICS user frame storage instruction. Information management table 952 and This is done for 962, and information storage instructions are given to BOX 953 and 963. The stored information management tables 952 and 962 receive the instructions of the processing devices 951 and 961 and store the items to be managed such as the communication partner address and the index number of the stored information for each ICS-using terminal to be accommodated. The BOX 953 and 963 receive the instructions of the processing devices 951 and 961 and store the management number, user information, etc. of the stored information for each ICS-using terminal to be accommodated. The preparations for using the ICS frame database servers 950 and 960 and their communication examples are described below. << Preparations >> The VAN-1 operator can store the information of the terminal with the ICS user address "0012" connected to the LAN900-1 of the company X in advance, so that the stored information management table 952 and BOX953 Information about the user (ICS user address "0012" etc. in this example) is registered in. Similarly, the VAN-3 operator can also store the information of the terminal with the ICS user address "0034" connected to the LAN900-2 of the company X in advance in the stored information management table 962 and BOX963. Register information about the user (ICS user address "0034" etc. in this example). The ICS user sends the ICS user frame F60 as shown in FIG. 30 to the ICS900. In this ICS user frame F60, the user control unit is provided with a usage request identifier for using the ICS frame database server (an identifier that explicitly indicates that the ICS frame database server is used) and an information operation identifier (in the ICS frame database server). An identifier that explicitly indicates the operation of the stored information) is added. In this embodiment, the user realizes the user's ICS frame database server usage request by adding the usage request identifier and the information manipulation identifier to the user control unit of the ICS user frame F60. However, the ICS user data It is also possible to add a usage request identifier and an information manipulation identifier to the unit.
【0102】
<< Communication example >> (1) Communication example-1 (Operation of ICS frame database server on the sending side): A terminal with an ICS user address "0012" connected to LAN900-1 of company X was connected to LAN900-2 of company X. Communicate using the ICS frame database server to the terminal with the ICS user address "0034". A flowchart is shown in FIG. 31, and its operation will be described.
【0103】
The caller terminal is a usage request identifier that uses the ICS frame database server 950 in the user control unit (caller storage user management number: a code arbitrarily assigned by the user who uses ICS, and information stored by the ICS user. The ICS user frame F60 with the added information manipulation identifier (scheduled transfer time, information storage, information transfer, information deletion, information termination, etc.) is sent to the ICS900. The received access control device 9101 (step S900) refers to the usage request identifier of the ICS user frame F60 in the processing device 912-1 (step S901), and the number of the usage request identifier set by the caller terminal exists. If so, the ICS user frame F60 is transferred to the processing device 951. Upon receiving the ICS user frame F60, the processing device 951 refers to the usage request identifier and the information manipulation identifier (step S910), and performs the operation indicated by the information manipulation identifier.
【0104】
When information storage is indicated, the processing device 951 receives the usage request identifier (calling side storage user management number) and information manipulation identifier (information storage) of the ICS user frame F60 sent from the calling terminal. , The receiver ICS user address and the usage request identifier are stored in the storage information management table 952 corresponding to the sender ICS user address of the corresponding frame, and the ICS user frame is stored in the BOX 953 (step S911). Since the ICS user frame to be stored is divided into a plurality of ICS user frames and sent from the caller, this operation is performed by the information manipulation identifier (information end) shown in the ICS user frame F60 of the ICS user frame to be stored. Executed until the final frame is indicated (step S912).
【0105】
When the scheduled transfer time is indicated (step S913), the processing device 951 sends the ICS user frame F60 usage request identifier (caller storage user management number) and information manipulation identifier (scheduled transfer time) sent from the caller terminal. ) Is stored in the storage information management table 952 (step S914), and the processing device 951 constantly monitors the scheduled transfer time. Transfer the stored information to the recipient terminal (step S915).
【0106】
When information transfer is indicated, the processing device 951 receives the usage request identifier (originating side stored user management number) and information manipulation identifier (transfer request) of the ICS user frame F60 sent from the calling terminal. , Sends the information (ICS user frame) stored in BOX953 to the recipient terminal (step S916). When information erasure is indicated, the processing device 951 receives the usage request identifier and information manipulation identifier (information erasure) of the ICS user frame F60 sent from the caller terminal, thereby storing information management table 952. And delete the stored information from BOX953 (step S917).
【0107】
(2) Communication example-2 (Operation of ICS frame database server on the receiving side): A terminal with an ICS user address "0034" connected to LAN900-2 of company X is connected to LAN900-1 of company X. Receive information from the terminal with the ICS user address "0012" using the user BOX. A flowchart is shown in FIG. 32, and its operation will be described.
【0108】
The caller terminal is a code that is arbitrarily assigned by the user who uses the receiver side ICS frame database server 960 in the user control unit, and is stored in the ICS user. The ICS user frame F60 with the information manipulation identifier added (which is the index number when manipulating the information) is sent to the ICS900. The corresponding ICS user frame F60 is transferred in the ICS900 to the access control device 910-5 in which the receiver terminal is housed (step S920), and the processing device 912-5 refers to the usage request identifier of the ICS user frame F60 (step S920). In step S921), if the usage request identifier number set by the caller terminal exists, the ICS user frame F60 is transferred to the processing device 961.
【0109】
Upon receiving the ICS user frame F60, the processing device 961 examines the information operation identifier (information storage, information transfer, information deletion, information termination) of the ICS user frame F60 (step S930), and if the information is stored, transmits the corresponding frame. The usage request identifier is stored in the storage information management table 962 corresponding to the person ICS user address and the recipient ICS user address, and the ICS user frame is stored in BOX963 (step S931). Since the ICS user frame to be stored is divided into a plurality of ICS user frames and sent from the caller, this operation is performed by the information manipulation identifier (information end) shown in the ICS user frame F60 of the ICS user frame to be stored. Executed until the final frame is indicated (step S932). The processing device 962 attaches the arrival side storage user management number to the receiver terminal at the timing agreed with the receiver terminal in advance (for example, at 12:00) that the information addressed to the receiver terminal exists in the ICS frame database server 960. And notify (step S933). The receiver terminal that received the notification sends the ICS user frame F60 in which the usage request identifier and the information operation identifier (information transfer) are set to the access control device 910-5, and the ICS frame database server 960 stores it in the BOX 963. A certain user information is transmitted to the recipient terminal (step S936), and the recipient terminal receives the information (ICS user frame) stored in the ICS frame database server 960. When the processing device 961 receives a frame in which the usage request identifier and the information manipulation identifier (information deletion) of the ICS user frame F60 are specified from the receiver terminal, the processing device 961 deletes the information from the stored information management table 962 and BOX 963 (step S937).
【0110】
(3) Communication example-3 (when the receiving side cannot receive temporarily): The terminal with the ICS user address "0012" connected to LAN900-1 of company X is connected to LAN900-2 of company X. When communicating with a terminal with the user address "0034", even if it is temporarily impossible to connect to the recipient terminal or LAN900-2 of company X, the information addressed to the recipient terminal is sent to the ICS frame database server 960. Once stored, communication is performed with the connection enabled. The operation will be described with reference to the flowchart of FIG. 33.
【0111】
The caller terminal adds an information manipulation identifier (temporarily stored) to the user control unit by temporarily storing the information in the ICS frame database server 960 even when communication with the receiver terminal is not possible. ICS user frame F60 is sent to ICS900. The corresponding ICS user frame F60 is transferred in the ICS900 to the access control device 910-5 in which the receiver terminal is housed, the access control device 910-5 receives the ICS user frame F60 (step S940), and the processing device 912- 5 checks the existence of the usage request identifier inside the ICS user frame F60 (step S941), refers to the information operation identifier (temporarily stored) of the ICS user frame F60 (step S942), and once there is a request for storage, the receiving side Determines if the terminal is in a communicable state, and if possible, sends the corresponding ICS user frame F60 to the receiving terminal (step S950), and if not, sends the corresponding ICS user frame F60 to the ICS frame database server. Transferred to the processing device 961 of the 960, and then the processing device 961 stores the sender ICS address, the receiver ICS address, and the usage request identifier of the corresponding ICS user frame F60 in the storage information management table 962, and stores the ICS user frame. Store in BOX963 (step S951).
【0112】
Since the ICS user frame to be stored is divided into a plurality of ICS user frames and sent from the caller, this operation is performed by the information manipulation identifier (information end) shown in the ICS user frame F60. It is executed until the final frame of is indicated (step S952). The processing device 912-5 constantly monitors the communication status with the receiver terminal, and when the receiver terminal becomes receivable, the processing device 961 is notified that the corresponding receiver communication status is possible. Upon receiving the notification, the processing device 961 notifies the receiver terminal at the timing agreed with the receiver terminal in advance (for example, after 5 minutes) that the information addressed to the receiver terminal exists in the ICS frame database server 960 (step). S953). The receiver terminal that received the notification sends the ICS user frame F60 in which the usage request identifier (ICS storage user management number) and the information operation identifier (information transfer) are set to the access control device 910-5, and sends the ICS frame database server 960. Sends the user information stored in the BOX 963 to the recipient terminal (step S956), and the receiver terminal receives the information stored from the ICS frame database server 960.
【0113】
When the processing device 961 receives a frame in which the usage request identifier and the information manipulation identifier (information deletion) of the ICS user frame F60 are specified from the receiver terminal, the processing device 961 deletes the information from the stored information management table 962 and the BOX 963 (step S957).
【0114】
Example-10 (X.25, FR, ATM, transmission by satellite communication and telephone line, ISDN line, CATV line, satellite line, accommodation of IPX frame): The format of data from the user in the ICS of the present invention is It is not limited to ICS user frames that comply with the provisions of RFC791 or RFC1883, and can accommodate telephone lines, ISDN lines, CATV lines, satellite lines, and IPX. In addition, the relay network of the ICS network frame in the ICS network can also support X.25, FR, ATM, satellite communication, etc. In the present invention, the ATM switch includes a cell relay switch, and the ATM network includes a cell relay network.
【0115】
FIGS. 34 to 37 show an example of interface conversion in the ICS1000 of the present invention, and are access control devices 1010-1 and 1010-2, ICS frame interface network 1050, X.25 network 1040, FR network 1041, and ATM network. 1042, satellite communication network 1043, X.25 / ICS network frame converters 1031-1 and 1031-2, FR / ICS network frame converters 1032-1 and 1032-2, ATM / ICS network frame converters 1033-1 and 1033-2, satellite / ICS network frame converters 1034-1 and 1034-2, telephone line converters 1030-1 and 1030-2, ISDN line converters 1029-1 and 1029-2, CATV line converters 1028-1 And 1028-2, satellite line conversion units 1027-1 and 27-2, and IPX conversion units 1026-1 and 1026-2.
【0116】
The ICS frame interface network 1050 is a relay network that transfers ICS network frames in the same format in accordance with the provisions of RFC791 or RFC1883. The X.25 network 1040 is a relay network that transfers X.25 format frames, and is used to convert ICS network frames to X.25 format frames and reverse conversion. It has 25 / ICS network frame converters 1031-1 and 1031-2 in the input / output section. FR network 1041 is a relay network that transfers frames in frame relay format, and contains FR / ICS network frame converters 1032-1 and 1032-2 for converting ICS network frames to frame relay format frames and reverse conversion. I have it in the output section. The ATM network 1042 is a relay network that transfers ATM format frames, and the ATM / ICS network frame conversion units 1033-1 and 1033-2 for converting and reversely converting ICS network frames to ATM format frames are input and output units. Have in The satellite communication network 1043 is a relay network that transfers information using satellites, and is a satellite / ICS network frame conversion unit 1034-1 and 1034-2 for converting and inversely converting an ICS network frame into an interface of the satellite communication network. Is in the input / output section. The telephone line conversion units 1030-1 and 1030-2 convert and reverse the functions corresponding to the physical layer and data link layer (first layer and second layer of the OSI communication protocol) between the telephone line and the access control device. It has a function to convert. The ISDN line conversion units 1029-1 and 1029-2 have a function of converting and inverting a function corresponding to a physical layer or a data link layer between the ISDN line and the access control device. The CATV line conversion units 1028-1 and 1028-2 have a function of converting and inverting a function corresponding to a physical layer or a data link layer between the CATV line and the access control device. The satellite line conversion units 1027-1 and 1027-2 have a function of converting and inverting a function corresponding to a physical layer or a data link layer between the satellite line and the access control device. The IPX conversion units 1026-1 and 1026-2 have a function of converting and inverting a function corresponding to a physical layer or a data link layer between the IPX and the access control device.
【0117】
(1) The operation when communication is performed between the access control measure 1010-1 and the access control device 1010-2 via the X.25 network 1040 will be described.
【0118】
The access controller 1010-1 sends an ICS network frame to the X.25 switch 10131-1. The X.25 / ICS network frame converter 1031-1 in the X.25 switch 10131-1 converts the ICS network frame received from the access controller 1010-1 into an X.25 format frame as shown in Fig. 38. To do. Then, the X.25 exchange 10131-1 sends an X.25 format frame into the X.25 network 1040. X.25 format frames sent from the X.25 switch 10131-1 are transferred within the X.25 network 1040 and reach the X.25 switch 10131-2. Next, the X.25 / ICS network frame converter 1031-2 in the X.25 switch 10131-2 converts the received X.25 format frame back to the ICS network frame format and accesses the access control device 1010-. Send to 2. Access controller 1010-2 receives the ICS network frame. The ICS1000 network frame sent from the access control device 1010-2 to the X.25 switch 10131-2 is also transferred to the access control device 1010-1 in the same manner.
【0119】
(2) The operation when communication is performed between the access control measure 1010-1 and the access control device 1010-2 via the FR network 1041 will be described.
【0120】
Access control device 1010-1 sends out an ICS network frame. The FR / ICS network frame converter 1032-1 in the FR switch 10132-1 converts the ICS network frame received from the access control device 1010-1 into a FR format frame as shown in FIG. 39. Then, the FR exchange 10132-1 sends the FR format frame into the FR network 1041, and the FR format frame sent from the FR exchange 10132-1 is transferred in the FR network 1041 and reaches the FR exchange 10132-2. To do. The FR / ICS network frame conversion unit 1032-2 in the FR exchange 10132-2 reversely converts the received FR format frame into the ICS network frame format and sends it to the access control device 1010-2. Access controller 1010-2 receives the ICS network frame. The ICS network frame sent from the access control device 1010-2 to the FR switch 10132-2 is also transferred to the access control device 1010-1 in the same manner.
【0121】
(3) The operation when communication is performed between the access control measure 1010-1 and the access control device 1010-2 via the ATM network 1042 will be described.
【0122】
The access control device 1010-1 sends an ICS network frame to the ATM switch 10133-1. The ATM / ICS network frame converter 1033-1 in the ATM switch 10133-1 converts the ICS network frame received from the access control device 1010-1 into an ATM format frame as shown in FIG. 40. The ATM exchange 10133-1 sends an ATM format frame into the ATM network 1042, and the ATM format frame sent from the ATM exchange 10133-1 is transferred in the ATM network 1042 and reaches the ATM exchange 10133-2. The ATM / ICS network frame conversion unit 1033-2 in the ATM exchange 10133-2 reversely converts the received ATM format frame into the ICS network frame format and sends it to the access control device 1010-2. Access controller 1010-2 receives the ICS network frame. The ICS network frame sent from the access control device 1010-2 to the ATM switch 10133-2 is also transferred to the access control device 1010-1 in the same manner.
【0123】
(4) The operation when communication is performed between the access control measure 1010-1 and the access control device 1010-2 via the satellite communication network 1043 will be described.
【0124】
The access control device 1010-1 sends an ICS network frame to the satellite transmitter / receiver 10134-1. The satellite / ICS network frame conversion unit 1034-1 in the satellite transmitter / receiver 10134-1 converts the ICS network frame received from the access control device 1010-1 into an interface in the satellite communication network 1043. Next, the satellite transmitter / transmitter 10134-1 transmits the ICS network frame converted into the interface in the satellite communication network 1043 into the satellite communication network 1043, and the ICS network frame transmitted from the satellite transmitter / transmitter 10134-1. Is transferred within the satellite communication network 1043 and reaches the satellite transmitter / transmitter 10134-2. The satellite / ICS network frame converter 1034-2 in the satellite transmitter / receiver 10134-2 reverse-converts the ICS network frame converted to the interface in the received satellite communication network 1043 and sends it to the access control device 1010-2. To do. Access controller 1010-2 receives the ICS network frame. The ICS network frame transmitted from the access control device 1010-2 to the satellite transmitter / receiver 10134-2 is also transferred to the access control device 1010-1 in the same manner.
【0125】
(5) User 1060-1 who is connected to the telephone line conversion unit 1030-1 of access control device 1010-1 makes a call and is connected to the telephone line conversion unit 1030-2 of access control device 1010-2. The operation when communicating with 2 via the telephone line interface will be explained.
【0126】
User 1060-1 applies to the VAN operator for a telephone line connection. The VAN operator identifies the access control device 1010-1 to which the user 1060-1 is connected, and determines the ICS network address 7721 of the ICS logical terminal. Next, the VAN operator puts the outgoing ICS network address "7721", the sender telephone number "03-5555-1234", and the recipient telephone number "06-5555-9876" in the conversion table 1013-1 of the access control device 1010-1. , Incoming ICS network address "5521" and information such as request type are set. This example shows an example in which the request type "5" is set as a telephone line connection. Similarly, the conversion table 1013-2 of the access control device 1010-2 shows the outgoing ICS network address 5521, the sender telephone number 06-5555-9876, the recipient telephone number 03-5555-1234, and the incoming ICS. Set information such as network address "7721" and request type.
【0127】
User 1060 sends out the telephone number "06-5555-9876". The telephone line conversion unit 1030-1 converts the received telephone number into the reading format of the processing device 1012-1 and sends it to the processing device 1012-1. The processing device 1012-1 that received the telephone number information from the telephone line conversion unit 1030-1 of the ICS network address "7721" refers to the request type of the outgoing ICS network address "7721" in the conversion table 1013-1 and makes a telephone call. Recognizes that it is a line connection and reads the incoming ICS network address "5521" from the incoming telephone number "06-5555-9876". The access control device 1010-1 has a network control unit in which the incoming ICS network address is set to "5521" and the outgoing ICS network address is set to "7721", and network data describing information for notifying that there is an incoming call. Create an ICS network frame with a part and send it to the ICS1000 network. The ICS network frame sent from the access control device 1010-1 is transferred in the network of the ICS1000 and reaches the access control device 1010-2. The access control device 1010-2 that received the ICS network frame having the network data section that describes the information for notifying that there is an incoming call is the user 1060-2 from the telephone line conversion section 1030-2 of the ICS network address "5521". To send a signal to notify the incoming call. Then, user 1060-2 sends a response signal.
【0128】
When the telephone line converter 1030-2 receives the response signal, it converts it into a format that can be transferred within the ICS1000 network. The access control device 1010-2 has a network control unit in which the incoming ICS network address is set to "7721" and the outgoing ICS network address is set to "5521", and a network that describes information for notifying that the call has been answered. Create an ICS network frame with a data part and send it to the ICS network. The ICS network frame sent from the access control device 1010-2 is transferred in the ICS network and reaches the access control device 1010-1. The access control device 1010-2 that received the ICS network frame having the network data section that describes the information to convey that there was a response is the user 1060- from the telephone line conversion section 1030-1 of the ICS network address "7721". For 1, send a signal to notify the response. As a result, the user 1060-1 and the user 1060-2 start full-duplex communication using an analog signal (voice, etc.), and the user 1060-1 sends an analog signal. Upon receiving the analog signal, the telephone line converter 1030-1 converts the analog signal into an analog information format that can be transferred within the ICS network.
【0129】
The access control device 1010-1 creates a network control unit in which the incoming ICS network address is set to "5521" and the outgoing ICS network address is set to "7721", and an ICS network frame having a network data unit in which analog information is described. Then send it to the ICS1000 network. The ICS network frame sent from the access control device 1010-1 is transferred within the network of the ICS1000 and reaches the access control device 1010-2. The access control device 1010-2, which received the ICS network frame having the network data unit in which the analog information was described, converted the analog information into the telephone line interface in the telephone line conversion unit 1030-2 of the ICS network address "5521". Send to user 1060-2 as an analog signal. The analog signal sent from user 1060-2 is also transferred to user 1060-1 in the same procedure.
【0130】
(6) User 1061-1 connected to ISDN line conversion unit 1029-1 of access control device 1010-1 originated and connected to ISDN line conversion unit 1029-2 of access control device 1010-2. The operation when communicating with 2 via the ISDN line interface will be described.
【0131】
User 1061-1 applies for an ISDN line connection to the VAN operator, and the VAN operator identifies the access control device 1010-1 to which user 1061-1 is connected and determines the ICS network address "7722" of the ICS logical terminal. Next, the VAN operator puts the outgoing ICS network address 7722, the sender ISDN number 03-5555-1111, and the receiver ISDN number 06-5555-2222 in the conversion table 1013-1 of the access control device 1010-1. , Incoming ICS network address "5522" and information such as request type are set. In this example, an example is shown in which the request type "6" is used as an ISDN line connection. Similarly, the conversion table 1013-2 of the access control device 1010-2 shows the outgoing ICS network address 5522, the sender ISDN number 06-5555-2222, the receiver ISDN number 03-5555-1111, and the incoming ICS network address. Set information such as "7722" and request type.
【0132】
User 1061-1 sends the ISDN number "06-5555-2222". The ISDN line conversion unit 1029-1 converts the received ISDN number into the reading format of the processing device 1012-1 and sends it to the processing device 1012-1. Upon receiving the ISDN number information from the ISDN line conversion unit 1029-1 of the ICS network address "7722", the processor 1012-1 refers to the request type of the outgoing ICS network address "7722" in the conversion table 1013-1 and ISDN. Recognizes that it is a line connection and reads the incoming ICS network address "5522" from the incoming ISDN number "06-5555-2222". The access control device 1010-1 has a network control unit with the incoming ICS network address set to "5522" and an outgoing ICS network address set to "7722", and a network data unit that describes information for notifying that there is an ISDN incoming call. Create an ICS network frame to have and send it to the ICS1000 network.
【0133】
The ICS network frame sent from the access control device 1010-1 is transferred in the ICS1000 and reaches the access control device 1010-2. The access control device 1010-2 that received the ICS network frame having the network data unit that describes the information for notifying that there is an incoming call is the user 1061-2 from the ISDN line conversion unit 1029-2 of the ICS network address "5522". Sends a signal to notify the incoming call. Then, user 1061-2 sends a response signal. When the ISDN line converter 1029-2 receives the response signal, it converts it into a format that can be transferred within the ICS1000. The access control device 1010-2 describes the network control unit in which the incoming ICS network address is set to "7722" and the outgoing ICS network address is set to "5522", and information for notifying that an ISDN response has been received. Create an ICS network frame with a network data part and send it to the ICS1000 network.
【0134】
The ICS network frame sent from the access control device 1010-2 is transferred in the ICS1000 and reaches the access control device 1010-1. The access control device 1010-2 that received the ICS network frame having the network data section that describes the information to convey that there was a response is the user 1061-from the ISDN line conversion section 1029-1 of the ICS network address "7722". For 1, send a signal to notify the response. As a result, the user 1061-1 and the user 1061-2 start full-duplex communication using a digital signal (voice, etc.), and the user 1061-1 sends a digital signal. Upon receiving the analog signal, the ISDN line converter 1029-1 converts the analog signal into a digital information format that can be transferred within the ICS1000.
【0135】
The access control device 1010-1 creates a network control unit in which the incoming ICS network address is set to "5522" and the outgoing ICS network address is set to "7722", and an ICS network frame having a network data unit in which digital information is described. And send it to ICS1000. The ICS network frame sent from the access control device 1010-1 is transferred in the ICS1000 and reaches the access control device 1010-2. The access control device 1010-2, which received the ICS network frame having the network data unit in which the digital information was described, converted the digital information into the ISDN line interface in the ISDN line conversion unit 1029-2 of the ICS network address "5522". It is sent to user 1061-2 as a digital signal. Conversely, the digital signal sent from user 1061-2 is also transferred to user 1061-1 in the same procedure.
【0136】
(7) The CATV broadcasting station 1062-1 connected to the CATV line conversion unit 1028-1 of the access control device 1010-1 and the user 1062-2 connected to the CATV line conversion unit 1028-2 of the access control device 1010-2. The operation when communicating with the CATV line interface will be described.
【0137】
CATV broadcasting station 1062-1 applies to the VAN operator for a CATV line connection with user 1062-2. The VAN operator identifies the access control device 1010-2 to which the user 1062-2 is connected, and determines the ICS network address "5523" of the ICS logical terminal. Next, the VAN operator sets information such as the incoming ICS network address 5523 and the request type in the corresponding portion of the outgoing ICS network address 7723 in the conversion table 1013-1 of the access control device 1010-1. This example shows an example in which the request type "7" is used as a CATV line connection. Similarly, information such as the outgoing ICS network address 5523, the incoming ICS network address 7723, and the request type is set in the conversion table 1013-2 of the access control device 1010-2.
【0138】
CATV broadcasting station 1062-1 sends out a CATV analog signal. Upon receiving the CATV analog signal, the CATV line converter 1028-1 converts the CATV analog signal into an information format that can be transferred within the ICS1000. The access control device 1010-1 has a network control unit in which the incoming ICS network address is set to "5523" and an outgoing ICS network address is set to "7723", and an ICS network frame having a network data unit in which CATV information is described. Create and send to ICS1000. The ICS network frame sent from the access control device 1010-1 is transferred in the ICS1000 and reaches the access control device 1010-2. The access control device 1010-2, which receives the ICS network frame having the network data section that describes the CATV information, converts the CATV information into the CATV line interface at the CATV line conversion section 1028-2 with the ICS network address "5523". It is sent to user 1062-2 as a CATV analog signal. Conversely, the CATV analog signal sent from user 1062-2 is also transferred to the CATV broadcasting station 1062-1 in the same procedure.
【0139】
(8) User 1063-1 connected to the satellite line conversion unit 1027-1 of access control device 1010-1 and user 1063-2 connected to satellite line conversion unit 1027-2 of access control device 1010-2. The operation when communicating with each other by the interface of the satellite line will be described.
【0140】
Users 1063-1 and 1063-2 apply to the VAN operator for a satellite line connection between user 1063-1 and user 1063-2. The VAN operator identifies the access control device 1010-1 to which the user 1063-1 is connected, and determines the ICS network address "7724" of the ICS logical terminal. Similarly, identify the access control device 1010-2 to which the user 1063-2 is connected, and determine the ICS network address 5524 of the ICS logical terminal. Next, the VAN operator sets information such as the incoming ICS network address 5524 and the request type in the corresponding portion of the outgoing ICS network address 7724 in the conversion table 1013-1 of the access control device 1010-1. In this example, the request type "8" is used as the satellite line connection. Similarly, information such as the outgoing ICS network address 5524, the incoming ICS network address 7724, and the request type is set in the conversion table 1013-2 of the access control device 1010-2.
【0141】
User 1063-1 sends a satellite signal. Upon receiving the satellite signal of the satellite line interface, the satellite line conversion unit 1027-1 converts the satellite signal into an information format that can be transferred within the ICS1000. The access control device 1010-1 includes a network control unit in which the incoming ICS network address is set to "5524" and the outgoing ICS network address is set to "7724", and an ICS network frame having a network data unit in which satellite signal information is described. Is created and sent to ICS1000. The ICS network frame sent from the access control device 1010-1 is transferred in the network of the ICS1000 and reaches the access control device 1010-2. The access control device 1010-2, which has received the ICS network frame having a network data unit that describes the satellite signal information, transfers the satellite signal information to the satellite line in the satellite line conversion unit 1027-2 of the ICS network address 5524. It is sent to user 1063-2 as a satellite signal converted into an interface. On the contrary, the satellite signal of the interface of the satellite line transmitted from the user 1063-2 is also transferred to the user 1063-1 in the same procedure.
【0142】
(9) The operation when communication is performed between the terminal having the IPX address "9901" of the user 1064-1 and the terminal having the IPX address "8801" of the user 1064-2 by the IPX interface will be described.
【0143】
Users 1064-1 and 1064-2 apply to the VAN operator for an IPX connection between the terminal with the IPX address "9901" of the user 1064-1 and the terminal with the IPX address "8801" of the user 1064-2. I do. The VAN operator determines the ICS network address 7725 of the access control device 1010-1 and the IPX converter 1026-1 to connect the user 1064-1. Similarly, the ICS network address 5525 of the access control device 1010-2 and the IPX converter 1026-2 to which the user 1064-2 is connected is determined. Next, the VAN operator puts the sender IPX address "9901", the receiver IPX address "8801", and the incoming ICS network in the corresponding part of the outgoing ICS network address "7725" in the conversion table 1013-1 of the access control device 1010-1. Set information such as address "5525" and request type. In this example, the request type "9" is used as the IPX connection. Similarly, the sender IPX address "8801", the receiver IPX address "9901", and the incoming ICS network address "7725" correspond to the outgoing ICS network address "5525" in the conversion table 1013-2 of the access control device 1010-2. And set information such as request type.
【0144】
The terminal having the IPX address "9901" of the user 1064-1 sends an IPX frame in which the sender IPX address is set to "9901" and the receiver IPX address is set to "8801". The access control device 1010-1 receives the IPX frame in the IPX conversion unit 1026-1 of the ICS network address 7725, and reads the sender IPX address 9901 and the receiver IPX address 8801 in the IPX frame. Then, the access control device 1010-1 reads the incoming network address 5525 of the receiver IPX address 8801 of the sender IPX address 9901 of the outgoing ICS network address 7725 from the conversion table 1013-1. The access control device 1010-1 includes a network control unit in which the incoming ICS network address is set to "5525" and the outgoing ICS network address is set to "7725", and an ICS network frame having a network data unit in which IPX frame information is described. Is created and sent to ICS1000.
【0145】
The ICS network frame sent from the access control device 1010-1 is transferred in the ICS1000 and reaches the access control device 1010-2. Network describes information IPX frame access controller 1010-2 which receives the ICS network frame having a Kudeta section, the information of IPX Frame ICS network frames in IPX converting unit 1026-2 of the ICS network address "5525" , Sends to user 1064-2 as an IPX frame converted to an IPX interface. The terminal having the IPX address 8801 of user 1064-2 receives the IPX frame. Conversely, for IPX frames with the sender IPX address set to "8801" and the recipient IPX address set to "9901" sent from the terminal with the IPX address "8801" of user 1064-2, the user can follow the same procedure. Transferred to 1064-1.
【0146】
Example-11 (X.25, FR, ATM, transmission by satellite communication and accommodation of telephone line, ISDN line, CATV line, satellite line): In Example-10 above, X.25 / ICS network frame conversion Units 1031-1 and 1031-2, FR / ICS network frame conversion units 1032-1 and 1032-2, ATM / ICS network frame conversion units 1033-1 and 1033-2, satellite / ICS network frame conversion units 1034-1 and 1034-2 are located in the relay network, that is, in the X.25 network 1040, FR network 1041, ATM network 1042, and satellite communication network 1043, respectively. On the other hand, in Example-11, as shown in FIGS. 41 and 42, the X.25 / ICS network frame converters 1131-1 and 1131-2 and the FR / ICS network frame converters 1132-1 and 1132-2 , ATM / ICS network frame converters 1133-1 and 1133-2, and satellite / ICS network frame converters 1134-1 and 1134-2 are located in access control devices 1110-1 and 1110-2, respectively. That is, in Example-10, each relay network (X.25 network 1040, FR network 1041, ATM network 1042, satellite communication network 1043) converts the received ICS network frame into a format that can be transferred on each relay network side. Inverse conversion is performed, but in the present embodiment-11, conversion to a format that can be transferred by each relay network and reverse conversion are performed on the access control device side.
【0147】
Example-12 (Accommodation of Access Control Device in Relay Network): In Example-10, X.25 / ICS network conversion units 1031-1 and 1031-2, FR / ICS network conversion units 1032-1 and 1032. -2, ATM / ICS network converters 1033-1 and 1033-2, satellite communication network / ICS network converters 1034-1 and 1034-2 are in the relay network, that is, X.25 network 1040, FR network 1041, It is located in the ATM network 1042 and the satellite communication network 1043, and the access control devices 1010-1 and 1010-2 are not installed in the X.25 network, FR network, ATM network, and satellite communication network. On the other hand, in Example-12, as shown in FIGS. 43 and 44, the access control devices 1120-1, 1120-2, 1121-1, 1121-2, 1122-1, 1122-2, 1123-1, 1123-2 is located within the relay network, that is, within the X.25 network 1240-1, FR network 1241-1, ATM network 1242-1, and satellite communication network 1243-1, respectively. That is, in the tenth embodiment, the conversion from the ICS user frame to the ICS network frame and the inverse conversion were performed based on the management of the conversion table in the access control device installed outside each relay network, but in this embodiment, the conversion is performed. Conversion from ICS user frame to ICS network frame (ICS encapsulation) and reverse conversion (ICS reverse encapsulation) performed based on the management of the conversion table are performed in each of the above relay networks, that is, inside the X.25 switch, and in the FR switch. It is done inside the ATM network switch, inside the satellite transmitter / receiver.
【0148】
Example-13 (relay network is connected to the relay device): In the above-mentioned Example-10, the X.25 network 1040, the FR network 1041, the ATM network 1042, and the satellite communication network 1043 are all access control devices 1010-1. And 1010-2, but not connected to the repeater. On the other hand, in Example-13, as shown in FIG. 45, the X.25 network 202-1 is connected to the access control device 2010 and the relay device 2030, and the FR network 2021-1 is the access control device 2011 and the relay device 2031. The ATM network 2022-1 is connected to the access control device 2012 and the relay device 2032, the satellite communication network 2023-1 is connected to the access control device 2013 and the relay device 2033, and the X.25 network 2020-2. Is connected to relay devices 2030, 2034, 2035, FR network 2021-2 is connected to relay devices 2031, 2035, ATM network 2022-2 is connected to relay devices 2031, 2032, 2036, and satellite communication network 2023-2. Is connected to repeaters 2033, 2036, 2037. That is, in this embodiment, the X.25 network 202-1, 2020-2, RF network 2021-1, 2021-2, ATM network 2022-1, 2022-2, satellite communication network 2023-1, 2023-2 , Both are configured to be connected to a relay device.
【0149】
Example-14 (when the access control device is installed outside the ICS): FIG. 46 shows the 14th embodiment of the present invention, in which the access control device 1210-1 is placed outside the ICS1200, that is, the enterprise X. It is placed inside the LAN-1200. Correspondingly, the ICS address management server 1250-1 and the ICS network server 1260-1 are also placed outside the ICS1200, that is, inside the LAN1200-1, and the access control device general management server 1240 is placed inside the ICS1200. The access control device general management server 1240 has a function of communicating with the access control device 1210-1, the ICS address management server 1250-1, and the ICS network server 1260-1 by using the ICS network server communication function to exchange information. There is. When the VAN operator concludes a contract with company X and connects the user communication line to the ICS1200, the VAN operator writes the data to the internal conversion table of the access control device 1210-1 using the function of the access control device general management server 1240. In addition, the ICS address management server 1250-1 and the ICS network server 1260-1 can communicate with the ICS address management server 1250-2 and the ICS network server 1260-2 inside the ICS1200 by using their respective ICS network server communication functions. ..
【0150】
Since it is configured in this way, the user terminal inside the LAN 1200 can perform intra-company communication and inter-company communication according to the same method as described in the first embodiment. Even if the ICS address management server 1250-1 and the ICS network server 1260-1 are placed in the ICS1200, it is clear that the user terminal can perform intra-company communication and inter-company communication as described above. .. The other embodiment described above replaces the ICS address management server with the ICS address name management server described in Example-24.
【0151】
Example-15 (Non-ICS Encapsulation of Business-to-Business Communication): Using FIGS. 47 and 48, an example of non-ICS encapsulation in business-to-business communication is performed from the recipient ICS user address based on the management of the conversion table. Explain how to determine the transfer destination in ICS and communicate. This communication method is an example in which ICS encapsulation is not performed only for inter-company communication despite using a conversion table as in Example-1 above. Furthermore, despite not performing ICS encapsulation in inter-company communication, with intra-company communication (Example-1), virtual leased line connection (Example-2), and ICS network server using ICS special number address. It will be described that communication (Examples-3, 3A) can be realized in the same manner as described in Examples-1, 2, 3, and 3A, respectively.
【0152】
First, the ICS user address in this embodiment (in the case of 32-bit length, the address is from address 0 to 2).<sup>32</sup>An example of how to determine -1) will be explained. ICS user addresses are classified into intra-company communication addresses, inter-company communication addresses, ICS special number addresses, and ICS operating addresses. As the intra-company communication address, the above-mentioned address unique to the user is adopted. The inter-company communication address is the VAN internal code (16 bits: 0 to (2)<sup>16</sup>-1) Address 0) to (2)<sup>15</sup>-1) Allocate a range up to the address that does not overlap with the corporate communication address. The ICS special number address is 2 of the VAN internal code (16 bits).<sup>15</sup>From (2<sup>15</sup>+2<sup>14</sup>-1) Allocate a range up to the address that does not overlap with the corporate communication address. The ICS operating address is (2) of the VAN internal code (16 bits).<sup>15</sup>+2<sup>14</sup>) From the street address (2)<sup>16</sup>-1) Allocate a range up to the address that does not overlap with the corporate communication address. The ICS operation address is used for ICS operation (for example, for communication for exchanging failure information inside VAN). In FIGS. 47 and 48, 15170-1, 15170-2, 15170-3, 15170- 4, 15170-5 and 15170-6 are gateways provided inside LAN15100-1, 15100-2, 15100-3, 15100-4, 15100-5 and 15100-6, respectively, and the ICS frame is these gateways. You can pass through 15170-1 to 15170-6.
【0153】
<< Common preparations >> The conversion table 15113-1 included in the access control device 15110-1 includes the outgoing ICS network address, the incoming ICS network address, the recipient ICS user address, the request identification, and the speed classification. The request identification described in the conversion table 15113-1 is represented by, for example, "1" for the corporate communication service, "3" for the virtual leased line connection, and "4" for the ICS network server connection. The speed classification includes the speed and throughput of the line required for communication from the ICS network address (for example, the number of ICS frames transferred within a certain time).
【0154】
<< Preparation for inter-company communication >> The terminal that performs inter-company communication inside LAN15100-1 of company X holds the ICS user address "7711". In this embodiment, the ICS user address for inter-company communication uses the same value as the ICS network address. The ICS address information for inter-company communication is not written in the conversion table 15113-1. Similarly, the terminal that performs inter-company communication inside LAN15100-3 of company Y holds the ICS user address "8822".
【0155】
<< Preparation for in-house communication >> For LAN15100-1 and LAN15100-2 users, in-house communication between terminals connected to each LAN communicates via VAN-1 and VAN-3. Specify the terminal to the VAN operator and apply so that you can do. The ICS network address of the logical communication line 15180-1 connected to the ICS logical terminal of the access control device 15110-1 is set to "7711". The in-house communication addresses of the terminals connected to the LAN15100-1 for which the application was made are set to "0012" and "0025", and the in-house communication addresses of the destinations to communicate from these terminals are "0034", "0036", and "". Suppose that it is "0045" and "0046".
【0156】
The terminal with the corporate communication addresses "0034" and "0036" is inside LAN15100-2, and the ICS network address assigned to the ICS logical terminal of the access control device 15110-5 is "9922". The terminal with the corporate communication addresses "0045" and "0046" is inside LAN15100-6, and the ICS network address assigned to the ICS logical terminal of the access control device 15110-4 is "8900". The value "1" indicating the in-house communication service for which the application has been made is used as the request identification, and the above is registered in the conversion table 15113-1. The access control devices 15110-4 and 15110-5 are also registered in their respective conversion tables for intra-company communication in the same manner as above. Also, write the contents of the conversion table created by the above method to the ICS address management server 15150-1.
【0157】
<< Preparation for virtual leased line connection >> The principle is the same as that of the second embodiment, which will be described below. LAN15100-5 is connected to the access control device 15110-1 via the user logical communication line 15180-5, and is given the ICS network address "7712". LAN15110-4 is connected to the access control device 15110-2 via the user logical communication line 15180-4, and is given the ICS network address "6611". Since the virtual dedicated line is connected from the user logical communication line 15180-5 to the user logical communication line 15180-4, these ICS network addresses "7712" and "6611" are shown in the conversion table 15113-1 inside the access control device 15110-1. And the request identification "3" are registered. For the same purpose, these ICS network addresses "6611" and "7712" are also registered in the conversion table inside the access control device 15110-2.
【0158】
<< Preparation for communication with the ICS network server using the ICS special number >> The ICS user address of the ICS network server 15330-1 connected to the access control device 15110-1 is "2000" and the ICS network address is "7721". In this case, register each address and request identification "4" in the conversion table.
【0159】
Hereinafter, description will be made with reference to the flowchart of FIG. 49.
【0160】
<< Inter-company communication >> Explain inter-company communication without ICS encapsulation. In other words, it is "business-to-business communication" between the terminal having the ICS user address "7711" on LAN15100-1 and the terminal having the ICS user address "8822" on LAN15100-3.
【0161】
The terminal having the address "7711" of LAN15100-1 sends out the ICS user frame F1 in which the sender ICS user address "7711" and the receiver ICS user address "8822" are set respectively. The ICS user frame F1 reaches the ICS logical terminal of the access control device 15110-1 via the user logical communication line 15180-1. The access control device 15110-1 checks whether the ICS network address 7711 assigned to the ICS logical terminal is registered as a virtual leased line connection (3) on the conversion table 15113-1. (Step S1501), since it is not registered in this case, then check whether the recipient ICS network address 8822 in the ICS user frame F1 is registered in the conversion table 15113-1 (step S1503). In this case, since it is not registered, it is next determined whether the receiver network address 8822 in the ICS user frame F1 is in the section of the inter-company communication address (step S1504).
【0162】
If the ICS user frame F1 can be determined to be inter-company communication by the above procedure, processing such as billing for inter-company communication is performed (step S1505). The access control device 15110-1 transmits the ICS user frame F1 to the relay device 15120-1 without performing ICS encapsulation (step S1525). The relay device 15120-1 transfers the ICS user frame to the access control device 15110-4 of VAN-2 via the relay devices 15120-2 and 15120-3 based on the incoming ICS network address. Access control device 15110-4 transfers to LAN 15110-3. The ICS user frame is routinely routed through LAN15110-3 and delivered to the terminal with the ICS user address "8822".
【0163】
<< In-house communication >> Explain that in-house communication with ICS encapsulation can be realized despite non-ICS encapsulation of inter-company communication. The ICS user frame P1 is sent for communication between the terminal having the ICS user address "0012" connected to LAN15100-1 and the terminal having the ICS user address "0034" connected to LAN15100-2. In this ICS user frame P1, "0012" is set for the sender ICS user address and "0034" is set for the receiver ICS user address. The ICS user frame P1 is transmitted through the user logical communication line 15180-1 and further transferred to the access control device 15110-1. The access control device 15110-1 checks whether the ICS network address "7711" assigned to the ICS logical terminal is registered as a virtual leased line connection ("3") on the conversion table 15113-1. (Step S1501), since it is not registered in this case, then check whether the recipient network address 0034" in the ICS user frame P1 is registered in the conversion table 15113-1 (step S1503). In the case of this embodiment, "0034" is registered, and the request identification is read as "1" for intra-company communication (step S1510). Therefore, the incoming ICS network corresponding to the outgoing ICS network address "7711" from the conversion table. Acquire the address "9922" and perform processing such as billing for inter-company communication (step S1511). The above procedure is also shown in the flowchart of FIG.
【0164】
The access control device 15110-1 uses the obtained outgoing ICS network address 7711 and the incoming ICS network address 9922 to add a network control unit and encapsulate it in ICS (step S1520), and ICS network frame P2. Is configured and transmitted to the relay device 15120-1 (step S1525).
【0165】
<< Communication by virtual leased line >> Explain that communication by virtual leased line that performs ICS encapsulation can be realized despite non-ICS encapsulation of inter-company communication.
【0166】
LAN15100-5 sends an ICS user frame to ICS15100 through the user logical communication line 15180-5. The access control device 15110-1 that received the ICS user frame from the ICS logical terminal of the ICS network address "7712" has the ICS network address "7712" assigned to the ICS logical terminal, and the request type is on the conversion table 15113-1. Check if it is registered as a virtual leased line connection (3) (step S1501). In this case, since it is registered, it can be confirmed that the incoming ICS network address is a virtual leased line connection of "6611", and processing such as billing is performed (step S1502). The access control device 15110-1 ICS-encapsulated ICS network frame by adding a network control unit in which the incoming ICS network address is set to "6611" and the outgoing ICS network address is set to "7711" to the received ICS user frame. Is created (step S1520) and transmitted to the relay device 15120-1 (step S1525).
【0167】
<< Communication with ICS network server using ICS special number >> Explain that communication with ICS network server that performs ICS encapsulation is possible despite non-ICS encapsulation of inter-company communication. That is, it is explained that the terminal (address 0012) connected to the LAN 15100-1 of the company X can communicate with the ICS network server 15330-1 connected to the access control device 15110-1.
【0168】
The terminal of the sender ICS user address "0012" of LAN15100-1 sends the ICS user frame G1 to the access control device 15110-1, and the receiver ICS user address is "2000" to the ICS network server 15330-1. Request communication. The access control device 15110-1 checks whether the ICS network address 7711 assigned to the ICS logical terminal is registered as a virtual leased line connection (3) on the conversion table 15113-1. (Step S1501), since it is not registered in this case, then check whether the recipient network address 2000 in the ICS user frame G1 is registered in the conversion table 15113-1 (steps S1503, S1510). In this case, the request identification in conversion table 15113-1 is read as communication with the ICS network server 15330-1 (4) (step S1512). Next, the ICS network address 7721 of the ICS network server 15330-1 is acquired from the conversion table 15113-1, and processing such as billing is performed (step S1513). Next, the ICS user frame is converted into an ICS packet (step S1520) and transmitted to the ICS network server 15330-1 (step S1525).
【0169】
Example-16 (Other Examples Using an ATM Network): Another example in which the network inside the ICS of the present invention is configured by using an ATM network will be described. In this embodiment, (1) supplementary explanation of the prior art regarding ATM, (2) explanation of components, (3) frame flow using SVC, (4) frame flow using PVC, (5) PVC 1 to N communication or N to 1 communication using, and (6) N to N communication using PVC will be described in this order. Since the embodiment described here mainly discloses the technique of address conversion between the ICS network frame and the ATM network, the intra-company communication service and the inter-company communication service described in the first embodiment, and the embodiment This embodiment can be applied to any of the virtual leased line services described in -2.
【0170】
(1) Supplementary explanation of the prior art related to ATM: First, a supplementary explanation of the prior art related to ATM necessary for explaining this embodiment will be given. In an ATM network, a plurality of non-fixed logical lines that can flexibly set the communication speed and the like can be set on the physical line, and this logical line is called a virtual channel (VC). SVC (Swiched Virtual Channel) and PVC (Permanent Virtual Channel) are defined as virtual channels depending on how they are set. SVC calls and sets a virtual channel when necessary, and is required for the required time with any ATM terminal (generally a communication device that is connected to an ATM network and communicates using the ATM network). It is possible to secure a logical line having a speed of. The call setting of the virtual channel is performed by the ATM terminal that is about to start communication, and this method is standardized as a signal method in ITU-T. The call setting is an address that identifies the ATM terminal to which the call is set (hereinafter referred to as the "ATM address"). Is required, and the ATM address is systematized so that each ATM terminal can be identified so that it is unique in the ATM network. This address system is specified in E.2961 of ITU-T Recommendation Q.2931. There are three types of NSAP format ATM addresses, as shown in Figure 50, according to the 164 format or the ATM Forum UNI3.1 specification. In ICS, which of the above ATM address systems is used depends on the specific configuration of the ATM network. Therefore, the term ATM address will be used in this embodiment.
【0171】
PVC is a semi-fixed call setting that can be regarded as a virtual leased line when viewed from an ATM terminal. For the established virtual channel, an ID that identifies the virtual channel (hereinafter referred to as "virtual channel ID") is assigned to both SVC and PVC. Specifically, the virtual channel ID is composed of VPI (Virtual Path Identifier) and VCI (Virtual Channel Identifier) in the cell header part of the ATM cell format (53 bytes) shown in FIG. 51. To.
【0172】
Since information communication within the ATM network is performed in the ATM cell format information unit shown in FIG. 51, it is necessary to convert the ICS network frame into an ATM cell in order to transfer the ICS network frame via the ATM network. This conversion is performed through a two-step process of conversion to a CPCS (Common Part Convergence Sublayer) frame shown in FIG. 52 and decomposition of the CPCS frame into an ATM cell shown in FIG. 53. When a communication frame is divided into ATM cells, it usually becomes a plurality of ATM cells. Therefore, a series of multiple ATM cells related to one communication frame is called an ATM cell series. When an ATM cell sequence is received, the conversion is reversed, and there are two steps: assembling the ATM cell sequence shown in Fig. 53 into a CPCS frame, and taking out the communication frame (ICS network frame) from the CPCS frame shown in Fig. 52 and restoring it. Processing is done. This conversion to CPCS frame and disassembly / assembly of ATM cells are known techniques and standardized techniques in accordance with ITU-T recommendations. The protocol header in the CPCS frame user information is standardized by the IETF RFC1483.
【0173】
(2) Explanation of components: Fig. 54 and Fig. 55 focus on the ATM network 1042 from Fig. 35 in FIGS. 34 to 36, and the internal conversion unit 1033-1 and ATM exchange 10133 of the ATM exchange 10133-1. It corresponds to the description of the internal structure of the conversion unit 1033-2 inside -2 and the simplified description of the access control devices 1010-2 and 1010-1 shown in FIGS. 34 to 36. In this embodiment, the internal configuration of the access control device or the operation of the processing device in the access control device is the same as the content described in the first embodiment and the basic principle.
【0174】
The access control device 1010-5 in FIG. 54 is assigned ICS network addresses 7711 and 7722 as connection points (ICS logical terminals) of companies X and A who are users of ICS905, respectively. Similarly, the access control device 1010-7 is assigned the ICS network addresses "7733" and "7744" as connection points of the companies W and C, respectively. In Fig. 55, the access control device 1010-6 is similarly assigned the ICS network addresses "9922" and "9933" as the connection points of the companies Y and B, respectively, and the access control device 1010-8 is also the company. ICS network addresses "9944" and "9955" are assigned as connection points for Z and D, respectively. Here, in the example of the ATM network, the company X, the company Y, etc. used as examples of the users may be different bases of the same company that performs intra-company communication, or different companies that perform inter-company communication. It doesn't matter.
【0175】
The interface unit 1133-5 is provided in the conversion unit 1033-5 inside the ATM exchange 10133-5, and the interface unit 1133-5 is connected to the communication line connecting the access control device 1010-5 and the ATM exchange 10133-5. It is in charge of the process of aligning the interfaces (physical layer, data link layer protocol) of. In addition to the processing device 1233-5, the conversion unit 1033-5 also translates the ATM address conversion table 1533-5 for call setting by SVC and the ICS network address used for both SVC and PVC into a virtual channel. It is composed of VC address translation table 1433-5. The ATM exchange 10133-5 is an ATM address management server 1633-5 as an information processing device that stores an ATM address conversion table, and an information processing device that stores a VC address conversion table in the case of using PVC. It connects to the PVC address management server 1733-5 and processes information related to address translation. The components related to the ATM switchboard 10133-6 are the same as those described for the ATM switchboard 10133-5. In FIGS. 54 and 55, the access control device 1010-5 is connected to the ATM switch 10133-5 via the communication line 1810-5, and the access control device 1010-7 is connected to the ATM switch 10133-5 via the communication line 1810-7, respectively. The access control device 1010-6 is connected to the ATM switch 10133-6 via the communication line 1810-6, and the access control device 1010-8 is connected to the ATM switch 10133-6 via the communication line 1810-8. In the ATM switchboard 10133-5, the only ATM address "3977" in the network is set in the internal conversion unit 1033-5, and in the ATM switchboard 10133-6, the network is set in the internal conversion unit 1033-6. The only ATM address "3999" is set. The ATM switch 10133-5 and the ATM switch 10133-6 are connected via the ATM switch 10133-7 in this embodiment.
【0176】
(3) Frame flow using SVC: An example in which SVC is applied as a communication path in an ATM network using FIGS. 54 and 55 is ICS issued from a terminal of company X to a terminal of company Y. A user frame will be described as an example.
【0177】
<< Preparation >> In the ATM address translation table 1533-5, the incoming ICS network address indicating the destination of the ICS network frame, the incoming ATM address indicating the destination for calling the virtual channel on the ATM network, and Register the channel performance such as the communication speed required for the virtual channel. Also, make the same registration for ATM address translation table 1533-6. As an example, the value set in the ATM address conversion table 1533-5 is the ICS network address assigned to the ICS logical terminal of the access control device 1010-6 as the incoming ICS network address and the communication address with the company Y. Set "9922" and register the only ATM address "3999" assigned in the ATM network to the conversion unit 1033-6 as the incoming ATM address. As the channel performance, a communication speed of 64 Kbps is set in this embodiment. The contents registered in the ATM address conversion table 1533-5 are also written and stored in the ATM address management server 1633-5.
【0178】
As the value to be set in the ATM address conversion table 1533-6, the ICS network address 7711 assigned to the ICS logical terminal of the access control device 1010-5 is set as the incoming ICS network address and the communication address with the company X. Then, as the incoming ATM address, the ATM address "3977" assigned only in the ATM network is registered for the conversion unit 1033-5 inside the ATM exchange 10133-5 to which the access control device 1010-5 is connected. For the channel performance, a communication speed of 64 Kbps is set in this embodiment. The contents registered in the ATM address conversion table 1533-6 are also written and stored in the ATM address management server 1633-6.
【0179】
<< ICS network frame transfer from the access control device >> As described in Example-1, the company Y connected to the access control device 1010-6 from the terminal of the company X via the access control device 1010-5. The ICS user frame issued to the terminal is ICS-encapsulated when passing through the access control device 1010-5, and has the outgoing ICS network address "7711" and the incoming ICS network address "9922" in the ICS frame header. It becomes ICS network frame F1. The ICS network frame F1 is transmitted from the access control device 1010-5 to the ATM switch 10133-5 and reaches the conversion unit 1033-5. Hereinafter, description will be made with reference to the flowchart of FIG. 56.
【0180】
<< Acquisition of virtual channel ID >> When the converter 1033-5 receives the ICS network frame F1 (step S1601), it is inside the ICS frame header in order to correctly transfer the received frame F1 to the ATM switch 10133-5. It is necessary to obtain the virtual channel ID of the SVC virtual channel determined by the correspondence between the outgoing ICS network address "7711" and the incoming ICS network address "9922". In the case of SVC-based communication, this is the time when the ICS network frame is received. The virtual channel corresponding to the communication path may be established or not yet established. The processor 1233-5 first knows whether the virtual channel is established, so that the outgoing ICS network address It was searched whether the virtual channel corresponding to the pair of "7711" and the incoming ICS network address "9922" was registered in the VC address translation table 1433-5 (step S1602), and it was registered here. Know that the virtual channel you want is established. That is, from the VC address translation table 1433-5, it is acquired that the virtual channel ID corresponding to the pair of the outgoing ICS network address "7711" and the incoming ICS network address "9922" is "33", and at the same time, it is acquired. From the value "11" of the channel type to be performed, it is known that this virtual channel is communication based on SVC. If there is no registration on the VC address translation table 1433-5, establish the desired virtual channel by performing << call setting >> described later, and register it on the VC address translation table 1433-5 at that time. Obtain the virtual channel ID from the information provided (step S1603).
【0181】
<< Call settings >> "When the virtual channel ID corresponding to the communication path determined by the correspondence between the outgoing ICS network address and the incoming ICS network address is not registered in the VC address translation table 1433-5", That is, if the virtual channel corresponding to this communication path has not been established yet, it is necessary to perform the call setting described below and establish the virtual channel in the ATM network constituting the ICS905, and an operation example of this call setting. Will be explained.
【0182】
The processing device 1233-5 of the conversion unit 1033-5 refers to the VC address translation table 1433-5 and sets the outgoing ICS network address 7711 and the incoming ICS network address 9922 inside the header of the ICS network frame F1. When it is found that the virtual channel ID corresponding to the pair is not registered (step S1602), refer to the ATM address translation table 1533-5, and the ATM address translation table 1533-5 that matches the incoming ICS network address 9922. Incoming ICS network address registered in Find "9922" and obtain the corresponding incoming ATM address "3999" and the corresponding incoming ATM address "64K" (step S1605). The processor 1233-5 uses the acquired incoming ATM address "3999". The ATM switch 10133-5 is requested to set the call, and at this time, the channel performance such as the communication speed of the virtual channel acquired at the same time from the ATM address conversion table 1533-5 is also requested. The ATM switch 10133-5 requests the call setting. When a setting request is received, a virtual channel is established in the ATM exchange network from ATM exchange 10133-5 to ATM exchange 10133-6 by using the signal method that is standard equipment in the ATM exchange itself (step S1606). The virtual channel ID assigned to identify the virtual channel is notified from the ATM switch to the conversion units 1033-5 and 1033-6 that are inside each, but if it is based on the provisions of the signal system of the prior art, it will be issued. The value notified from the calling ATM exchange 10133-5 (for example, 33) and the value notified from the calling ATM exchange 10133-6 (for example, 44) are not necessarily the same value. No. In the conversion unit 1033-5, the virtual channel ID "33" notified from the ATM switch 10133-5 is sent together with the outgoing ICS network address "7711" and the incoming ICS network address "9922" of the ICS network frame F1. Register in VC address translation table 1433-5 (step S1607) and keep it on VC address translation table 1433-5 while this virtual channel connection is established. Part 1033-5 requests the ATM switch 10133-5 to release the call of the virtual channel, and at the same time, deletes the registration corresponding to the virtual channel ID "33" from the VC address conversion table 1433-5. The registration in the VC address translation table 1433-6 in the conversion unit 1033-6 will be described later.
【0183】
<< Transmission of frame >> The processing device 1233-5 of the conversion unit 1033-5 receives from the access control device 1010-5 for the virtual channel (virtual channel ID 33) established according to the explanation so far. The ICS network frame F1 is converted into the CPCS frame shown in FIG. 52, further decomposed into the ATM cells shown in FIG. 53, and transferred to the relay ATM switch 10133-7 (step S1604).
【0184】
<< Transfer of ATM cells >> The ATM cell series S1 consisting of multiple cells obtained by converting the ICS network frame F1 is transferred from the ATM switch 10133-5 to the relay ATM switch 10133-5 by the method described above. Then, it is transferred to the ATM exchange 10133-6 as the ATM cell series S2. Hereinafter, description will be made with reference to the flowchart of FIG. 57.
【0185】
<< Operation after reaching the frame >> When the ATM cell sequence S2 reaches the ATM switch 10133-6 (step S1610), this ATM cell sequence S2 is transferred from the ATM switch 10133-6 to the conversion unit 1033-6. The conversion unit 1033-6 assembles the received ATM cell into a CPCS frame as shown in FIG. 53, and further restores the ICS network frame from the CPCS frame as shown in FIG. 52 (step S1611). In Fig. 55, the restored ICS network frame is shown as ICS network frame F2, but the frame contents are the same as ICS network frame F1. The ICS network frame F2 is transferred to the access control device identified by the incoming ICS network address "9922" in the frame header, that is, the access control device 1010-6 having an ICS logical terminal assigned the ICS network address "9922". Is done (step S1612).
【0186】
At this time, in the conversion unit 1033-6, the outgoing ICS network address 7711 of the ICS network frame F2, the incoming ICS network address 9922, and the channel type 11 indicating that the SVC is known at the time of incoming call. And the virtual channel ID 44 assigned when the call of the SVC virtual channel was set are registered in the VC address translation table 1433-6 (step S1614). At this time, the outgoing ICS of the ICS network frame F2 The network address "7711" is converted to the incoming ICS network address in VC address conversion table 1433-6, and the incoming ICS network address "9922" in ICS network frame F2 is converted to the outgoing ICS network address in table 1433-6. Write in. However, at the time of this registration, if the same content as the one to be registered is already registered in the VC address translation table 1433-6, the registration will not be performed. The address translation information registered in VC address translation table 1433-6 is used in VC address translation table 1433- while the connection of the virtual channel with the corresponding virtual channel (virtual channel ID 44 in this example) is maintained. 6 Holds on (step S1613).
【0187】
<< Reverse flow of frame >> Next, the reverse flow of ICS frame, that is, the case of flow from company Y to company X, is based on the premise that the virtual channel of SVC is set by the above description. This will be described with reference to FIGS. 54 and 55. The ICS user frame issued from company Y to company X has the outgoing ICS network address "9922" and the incoming ICS network address "7711" in the header part at the stage of passing through the access control device 1010-6. Is converted to, and processing is performed according to the flow of FIG. 56 described above by the processing device 1233-6 of the conversion unit 1033-6 inside the ATM exchange 10133-6.
【0188】
In this case, the VC address translation table 1433-6 of the conversion unit 1033-6 shows the outgoing ICS network address 9922 and the incoming ICS network address 7711 as already explained in << Operation after reaching the frame >>. Since the virtual channel ID 44 corresponding to is registered as the channel type 11, that is, as an SVC, (1) in Fig. 56. ICS network frame F3 is converted to multiple ATM cells (ATM series S3) and transferred to the virtual channel ID "44". The ATM cell series S3 is relayed and transferred to the relay ATM switch 10133-5, becomes the ATM cell series S4, reaches the ATM switch 10133-5, and has a virtual channel ID "33" in its conversion unit 1033-6. Received through and restored as an ICS network frame F4 with the same content as the ICS network frame F3. In the conversion unit 1033-5, the pair of the outgoing ICS network address "9922" and the incoming ICS network address "7711" held in the header of the ICS network frame F4 reverses the arrival and departure, and is shown in the VC address translation table 1433-5. Since it has already been registered, it is not registered in the VC address translation table, and the ICS network frame F4 is transferred to the access control device 1010-5.
【0189】
<< Application example for half-duplex communication >> In the above, the internal network of ICS905 is configured with an ATM network, and the ICS frame is transferred from company X to company Y, and in the opposite direction from company Y to company X. It was explained that the case of forwarding is performed using one SVC virtual channel. This transfer and reverse transfer are, for example, a request frame (transfer) from the client terminal of company X connecting to ICS to the server terminal of company Y connecting to ICS, and a client of company X from the server terminal of company Y to this request frame. When applied to a response frame (reverse transfer) to a terminal, only one-way communication is performed at one time, but it is an application example of half-duplex communication that realizes two-way communication by switching the communication direction for each time zone.
【0190】
<< Application example to full-duplex communication >> The virtual channel itself set in the ATM network can perform full-duplex communication, that is, bidirectional communication at the same time according to the ATM rules. Transfer and reverse transfer using one SVC virtual channel in the ATM network, for example, request frames (transfers) from multiple client terminals of company X connecting to ICS to multiple server terminals of company Y connecting to ICS. , When applied to the response frame (reverse transfer) from the multiple server terminals of company Y to the multiple client terminals of company X for this request frame, the frames between the client terminal and the server terminal are transferred asynchronously, respectively. Therefore, bidirectional communication is simultaneously performed on one SVC virtual channel that serves as a communication path, and this is an application example of full-duplex communication.
【0191】
(4) Frame flow using PVC: As shown in Fig. 54 and Fig. 55, an example in which the internal network of ICS905 is composed of an ATM network and PVC is applied as a communication path in the ATM network is shown in Company W. An ICS user frame emitted from a terminal to a terminal of company Z will be described as an example.
【0192】
<< Preparation >> VC address conversion in conversion unit 1033-5 In table 1433-5, outgoing ICS network address, incoming ICS network address, ATM network (between ATM exchange 10133-5 and ATM exchange 10133-6) Register the virtual channel ID of PVC and the channel type indicating that the virtual channel ID is PVC. Unlike the case of SVC, this registration is registered in the VC address translation table 1433-5 at the same time when the PVC virtual channel is set in the ATM switch (10133-5, 10133-7, 10133-6) that is the communication path, and communication is performed. Hold the path fixedly for the required period, i.e., until the PVC virtual channel is unconfigured. It is also registered and retained in the VC address translation table 1433-6 in the same way. The virtual channel ID of PVC is assigned to each ATM switch when the PVC is set to be fixedly connected between the ATM switches.
【0193】
The values set in the VC address conversion table 1433-5 are the communication address with the company W as the outgoing ICS network address, that is, the ICS network address "7733" assigned to the ICS logical terminal of the access control device 1010-7. Is set, and the communication address with the company Z, that is, the ICS network address "9944" assigned to the ICS logical terminal of the access control device 1010-8 is set as the incoming ICS network address. Further, the PVC virtual channel ID 55 assigned to the ATM switch 10133-5 is set as the virtual channel ID, and the value 22 indicating PVC is set as the channel type. In addition, the settings registered in the VC address translation table 1433-5 are also written and saved in the PVC address management server 1733-5.
【0194】
Similarly, in the VC address conversion table 1433-6 in the conversion unit 1033-6 inside the ATM exchange 10133-6, make the same settings by reversing the outgoing ICS network address and the incoming ICS network address. .. In this case, even if the same PVC is shown, the virtual channel ID may have a different value from the VC address translation table 1433-5. At this time, the settings registered in the VC address translation table 1433-6 are also written and saved in the PVC address management server 1733-6.
【0195】
The values set in the VC address translation table 1433-6 are the outgoing ICS network address for communication with the company Z, that is, the ICS network address "9944" assigned to the ICS logical terminal of the access control unit 1010-8. Is set, and the communication address with the company W, that is, the ICS network address "7733" assigned to the ICS logical terminal of the access control device 1010-7 is set as the incoming ICS network address. Further, the virtual channel ID is set to "66", which is the ID of this PVC virtual channel assigned to the ATM exchange 10133-6, and the channel type is set to the value "22" indicating PVC.
【0196】
<< Transfer of ICS network frame from access control device >> ICS user frame issued from the terminal of company W to the terminal of company Z connected to access control device 1010-5 via access control device 1010-7. Is an ICS network frame F5 that is ICS-encapsulated and has an outgoing ICS network address "7733" and an incoming ICS network address "9944" in the ICS frame header when passing through the access control device 1010-7. The ICS network frame F5 is transmitted from the access control device 1010-7 to the ATM switch 10133-5, and reaches the conversion unit 1033-5 via the interface unit 1133-5.
【0197】
<< Acquisition of virtual channel ID >> The processing device 1233-5 uses the outgoing ICS network address "7733" and the incoming ICS network address "9944" in the header of the received ICS network frame F5 to convert the VC address to 1433. Refer to -5, and the inside of the ATM switch 10133-6 to which this conversion unit 1033-5 and the access control device 1010-8 whose connection point is the ICS logical terminal to which the incoming ICS network address "9944" is assigned are connected. Acquires that the virtual channel ID that identifies the set virtual channel is "55" with respect to the conversion unit 1033-6 of. At the same time, it is known that this virtual channel is PVC from the acquired channel type value "22".
【0198】
<< Transmission of frame >> The processing device 1233-5 converts the ICS network frame F5 received from the access control device 1010-7 into an ATM cell series for the PVC virtual channel "55" acquired according to the above, and is an ATM switch. Send to 10133-7. The method of this ATM cell conversion is the same as that described in the SVC example. The processing procedure of the above conversion unit 1033-5 is as shown in Fig. 56, and in PVC, the flow is always (1).
【0199】
<< Transfer of ATM cells >> The ATM cell series S1 consisting of multiple cells obtained by converting the ICS network frame F1 is transferred from the ATM switch 10133-5 to the relay ATM switch 10133-7, and further transferred to the ATM switch 10133. It is transferred to -6 as an ATM cell series S2, but this operation is the same as for SVC.
【0200】
<< Operation after reaching the frame >> When the ATM cell series S2 reaches the ATM switchboard 10133-6, the ATM cell series S2 is transferred from the ATM switchboard 10133-6 to the internal converter 1033-6 of the ATM switchboard 10133-6. To. The converter 1033-6 restores the ICS network frame from the received ATM cell sequence, but this operation is the same as for SVC. The restored ICS network frame is described as ICS network frame F6 in Fig. 55, but the frame contents are the same as ICS network frame F5. The ICS network frame F6 is transferred to the access control device identified by the incoming ICS network address "9944" in the header, that is, the access control device 1010-8 having an ICS logical terminal assigned the ICS network address "9944". To. The processing procedure of the above conversion unit 1033-6 is as shown in Fig. 57, and in PVC, the flow is always (1).
【0201】
<< Reverse flow of the frame >> Next, the reverse flow of the ICS frame, that is, the case of flowing from the company Z to the company W, using the PVC virtual channel as the communication path, also refer to FIGS. 54 and 55. I will explain. The ICS user frame issued from company Z to company W has the outgoing ICS network address "9944" and the incoming ICS network address "7733" in the header part at the stage of passing through the access control device 1010-8. The processing device 1233-6 of the conversion unit 1033-6, which is encapsulated in ICS and installed inside the ATM switch 10133-6, performs processing according to the flow shown in Fig. 56. In this case, the virtual channel ID 66 corresponding to the outgoing ICS network address 9944 and the incoming ICS network address 7733 is registered in the VC address translation table 1433-6 of the conversion unit 1033-6. Converts the ICS network frame F7 to multiple ATM cell series and sends it to the virtual channel ID "66".
【0202】
The ATM cell sequence transferred in the ATM network reaches the conversion unit 1033-5 of the ATM switch 10133-5, then is received from the virtual channel with the virtual channel ID "55", and has the same contents as the ICS network frame F7. Restored as ICS network frame F8 with. However, in the conversion unit 1033-5, the pair of the outgoing ICS network address "9944" and the incoming ICS network address "7733" held in the header of the ICS network frame F8 has already been reversed in the arrival and departure of the VC address conversion table 1433. Since it has been registered in -5 and the virtual channel ID "55" for this incoming / outgoing address pair is obtained as PVC from the channel type value "22", the registration process is not performed and the ICS network frame F8 is accessed by the access control device. Transfer to 1010-7.
【0203】
<< Application example for half-duplex communication >> As described above, the internal network of ICS905 is configured using an ATM network, and an example of transferring ICS frames using PVC has been described. Is the difference between whether the virtual channel is fixedly set or the call is set when necessary, and there is no difference in the operation itself of transferring frames to the set virtual channel. Therefore, for the ICS of the present invention, the application example to the half-duplex communication using the PVC virtual channel of the ATM network is equivalent to the application example to the half-duplex communication using the SVC virtual channel.
【0204】
<< Application example for full-duplex communication >> For the same reason as the application example for half-duplex communication, the application example for full-duplex communication of PVC is equivalent to the application example for full-duplex communication in SVC. is there.
【0205】
(5) One-to-N communication or N-to-one communication using PVC: In the above explanation, one virtual channel of PVC is connected to one company (base) and one company (base), that is, inside the ICS. An example of using one ICS logical terminal and one ICS logical terminal as a communication path has been shown, but one virtual channel of PVC is shared as a communication path between one ICS logical terminal and a plurality of ICS logical terminals. Is possible. An embodiment of such 1-to-N communication or N-to-I communication will be described with reference to FIG. 58.
【0206】
<< Explanation of components >> In Fig. 58, the access control device 1010-10 is an ATM switch in which the company X uses the ICS logical terminal assigned the ICS network address "7711" in the access control device 1010-10 as a connection point. Connected to 10133-10. The other party to be connected from company X is company A to D, company A uses the ICS logical terminal assigned the ICS network address "9922" in the access control device 1010-20 as the connection point, and company B uses the access control device. The connection point is the ICS logical terminal assigned the ICS network address "9923" in 1010-20. Similarly, Company C uses the ICS logical terminal assigned the ICS network address 9944 in the access control device 1010-40 as the connection point, and Company D uses the ICS network address 9955 in the access control device 1010-40 as the connection point. The assigned ICS logical terminal is used as the connection point. The access control devices 1010-20 and 1010-40 are connected to the ATM switchboard 10133-20, and the ATM switchboards 10133-10 and the ATM switchboard 10133-20 are connected via a relay network.
【0207】
<< Preparation >> One that connects the conversion unit 1033-10 inside the ATM exchange 10133-10 and the conversion unit 1033-20 inside the ATM exchange 10133-20 to the ATM exchanges 10133-10 and 10133-20. A PVC virtual channel is set, and the virtual channel ID given to the virtual channel conversion unit 1033-10 is set to "33", and the virtual channel ID given to the virtual channel conversion unit 1033-20 is set to "44". Register the VC address translation table 1433-1 in the conversion unit 1033-10 and the VC address translation table 1433-20 in the conversion unit 1033-20 as shown in Fig. 58.
【0208】
<< 1-to-N communication frame flow >> The 1-to-N communication frame flow will be explained using frames transmitted from company X to companies A to D. For the ICS network frame having the outgoing ICS network address "7711" and the incoming ICS network address "9922" directed from the company X to the company A, refer to the VC address translation table 1433-10 in the conversion unit 1033-10. As a result, it is transmitted to the PVC virtual channel with the virtual channel ID 33. Similarly, an ICS network frame having an outgoing ICS network address 7711 directed from company X to company B and an incoming ICS network address 9933 is also transmitted to the PVC virtual channel with virtual channel ID 33. An ICS network frame with an outgoing ICS network address "7711" from company X to company C and an incoming ICS network address "9944", and an outgoing ICS network address "7711" from company X to company D. And the ICS network frame having the incoming ICS network address 9955 is also transmitted to the PVC virtual channel with the virtual channel ID 33. This indicates that 1-to-N (company X-to-company A to D) communication is performed by sharing one PVC virtual channel. The reverse flow of frames, that is, the case where frames are transferred from companies A to D to company X, will be described in the next section.
【0209】
<< Flow of frames for N-to-1 communication >> The flow of frames for 1-to-N communication will be explained using frames transmitted from companies A to D to company X, respectively. For the ICS network frame having the outgoing ICS network address "9922" and the incoming ICS network address "7711" directed from the company A to the company X, refer to the VC address translation table 1433-20 at the conversion unit 1033-20. As a result, it is transmitted to the PVC virtual channel with the virtual channel ID 44. Similarly, an ICS network frame having an outgoing ICS network address 9933 directed from company B to company X and an incoming ICS network address 7711 is also transmitted to the PVC virtual channel with virtual channel ID 44. An ICS network frame with an outgoing ICS network address "9944" from company C to company X and an incoming ICS network address "7711", and an outgoing ICS network address "9955" from company D to company X. And the ICS network frame having the incoming ICS network address 7711 is also transmitted to the PVC virtual channel with the virtual channel ID 44. This indicates that N-to-1 (company A to D-to-company X) communication is performed by sharing one PVC virtual channel.
【0210】
(6) N-to-N communication using PVC: By the same method as 1-to-N communication, one virtual channel of PVC can be shared as a communication path between multiple ICS logical terminals and multiple ICS logical terminals. is there. An embodiment of N-to-N communication will be described with reference to FIG. 59.
【0211】
<< Explanation of components >> Company X uses the ICS logical terminal address 7711 of access control device 1010-11 as the connection point, and company Y uses the ICS logical terminal address 7722 of access control device 1010-11 as the connection point. Then, the access control device 1010-11 is connected to the ATM switch 10133-11. The other party to be connected from company X or company Y is company A or company C, company A uses the ICS logical terminal address "9922" of access control device 1010-21 as a connection point, and company C is access control device 1010-. The connection point is the ICS logical terminal address 9944 of 41. The access control devices 1010-21 and 1010-4 are connected to the ATM switchboard 10133-21, and the ATM switchboards 10133-11 and 10133-21 are connected via a relay network.
【0212】
<< Preparation >> One that connects the conversion unit 1033-11 inside the ATM exchange 10133-11 and the conversion unit 1033-21 inside the ATM exchange 10133-21 to the ATM exchanges 10133-11 and 10133-21. A PVC virtual channel is set, and the virtual channel ID given to the conversion unit 1033-11 of this virtual channel is set to "33", and the virtual channel ID given to the conversion unit 1033-21 of this virtual channel is set to "44". .. The VC address translation table 1433-11 in the conversion unit 1033-11 and the VC address translation table 1433-21 in the conversion unit 1033-21 are registered as shown in FIG. 59.
【0213】
<< Flow of N-to-N communication frame >> First, the flow of N-to-N communication frame will be explained with the frames transmitted from company X to companies A and C, respectively. For ICS network frames with outgoing ICS network address "7711" and incoming ICS network address "9922" directed from company X to company A, refer to VC address translation table 1433-11 in the conversion unit 1033-1. , Sent to the PVC virtual channel with virtual channel ID 33. Similarly, an ICS network frame having an outgoing ICS network address 7711 and an incoming ICS network address 9944 directed from the company X to the company C is also transmitted to the PVC virtual channel with the virtual channel ID 33. Next, the frame transmitted from company Y to companies A and C will be described. For the ICS network frame having the outgoing ICS network address "7722" and the incoming ICS network address "9922" directed from the company Y to the company A, refer to the VC address translation table 1433-11 in the conversion unit 1033-11. , Sent to the PVC virtual channel with virtual channel ID 33. Similarly, the ICS network frame having the outgoing ICS network address 7722 and the incoming ICS network address 9944 directed from the company Y to the company C is also transmitted to the PVC virtual channel with the virtual channel ID 33.
【0214】
Next, the flow in the reverse direction of the frame will be described with the frames transmitted from the company A to the companies X and Y, respectively. For the ICS network address with the outgoing ICS network address "9922" and the incoming ICS network address "7711" directed from company A to company X, refer to VC address translation table 1433-21 in the conversion unit 1033-2. , Sent to the PVC virtual channel with virtual channel ID 44. For ICS network frames with outgoing ICS network address "9922" and incoming ICS network address "7722" directed from company A to company Y, refer to VC address translation table 1433-2 in the conversion unit 1033-2. , Sent to the PVC virtual channel with virtual channel ID 44. The ICS network frame having the outgoing ICS network address 9944 and the incoming ICS network address 7711 directed from the company C to the company X is transmitted to the PVC virtual channel with the virtual channel ID 44. An ICS network frame with an outgoing ICS network address 9944 and an incoming ICS network address 7722 directed from Company C to Company Y is also transmitted to the PVC virtual channel with virtual channel ID 44. As a result, N-to-N communication is performed by sharing one PVC virtual channel.
【0215】
Example-17 (Other Examples Using FR Network): Another example in which the network inside the ICS of the present invention is configured by using the FR network will be described. In this embodiment, (1) supplementary explanation of the prior art regarding FR, (2) explanation of components, (3) frame flow using SVC, (4) frame flow using PVC (5) PVC The following will be described in the order of 1-to-N communication or N-to-1 communication used, and (6) N-to-N communication using PVC. In this embodiment, it is possible to use two types of methods using SVC or PVC, or to use both methods in a mixed manner, and each case using SVC or PVC will be described. .. Further, in order to realize the intra-company communication service and the inter-company communication service described in the first embodiment and the virtual leased line service described in the second embodiment by the access control device of the present invention, the network in the network inside the ICS It is not necessary to consider frame communication separately, and in this embodiment, these communication services will be integrated and described.
【0216】
(1) Supplementary explanation of the prior art related to FR: A supplementary explanation of the prior art related to FR necessary for explaining the method of configuring the inside of the ICS of the present invention using the FR network.
【0217】
A frame relay uses a variable-length communication information unit called a frame for communication, and by specifying a communication path for each frame, storage and exchange of frames in the network and logical multiplexing (one physical). This is a conventional technology standardized by the ITU.TI.233 recommendations, etc., which realized (a technology that multiplexes lines into multiple logical lines). A communication service using this technology is called a Frame Mode Bearer Service (hereinafter referred to as FMBS), and FMBS is a Frame Switch Bearer Service that assumes a partner selection connection (SVC). :: Hereinafter, FSBS) and Frame Relay Bearer Service (hereinafter referred to as FRBS) assuming a fixed connection (PVC) to the other party are specified. The term "frame relay" generally refers only to FRBS ("frame relay" in a narrow sense), but in the ICS of the present invention, "frame relay" refers to the entire FMBS including FSBS and FRBS. Used as a name ("frame relay" in a broad sense), especially when referring only to FSBS, it is called "frame relay using SVC", and especially when referring only to FRBS, it is called "frame relay using PVC". To do. Hereinafter, the frame relay (FMBS) in a broad sense defined above is abbreviated as FR, and the frame transferred by the FR network is particularly referred to as FR frame in order to distinguish it from the ICS frame.
【0218】
In the FR network, a plurality of logical lines can be set on the physical line as described above, and this logical line is called a logical channel. In order to identify a logical channel, the identifier assigned to each FR terminal (generally a communication device connected to the FR network and communicating using the FR network) connected to both ends of the logical channel is assigned to a data link connection identifier (Data). Link Connection Identifier: Hereinafter referred to as DLCI). SVC and PVC are specified for the logical channel depending on how they are set. The SVC calls and sets the logical channel when necessary, and can take a logical line with any FR terminal for the required time and at the required speed. The call setting of the logical channel is performed by the FR terminal that is about to start communication, and this method is standardized as a signal method in ITU-T. In the call setting, the address that identifies the other party FR terminal that makes the call setting (Hereinafter referred to as "FR address") is required, and the FR address is systematized so as to be unique in the FR network so that each FR terminal can be identified. PVC has a fixed call setting for the FR exchange, and can be regarded as a virtual leased line when viewed from the FR terminal.
【0219】
DLCI that identifies the logical channel is assigned to the established logical channel for both SVC and PVC, and when forwarding FR frames, DLCI is set in the DLCI bit part of the FR frame address part shown in Fig. 60. To do. There are three types of rules for the FR frame address part format, and in Fig. 60, the 2-byte format address part is shown. The logical channel performance (channel performance) of the FR network is the committed information rate (Committed Information Rate), which is the information transfer rate guaranteed by the FR network under normal conditions (no congestion). ) Etc.
【0220】
In order to transfer a communication frame such as an ICS network frame via the FR network, it is necessary to convert it into an FR frame as shown in Fig. 61. When the FR frame is received, the conversion is reversed, and as shown in Fig. 61, the communication frame (ICS network frame) is taken out from the FR frame and restored. This FR frame conversion is a standardized technology in accordance with ITU-T recommendations. In addition, the protocol header in the user data of FR frame is standardized by RFC1490 of IETF.
【0221】
(2) Explanation of components: Fig. 62 and Fig. 63 focus on the FR network 1041 from Fig. 35 to Fig. 36, and the conversion unit 1032-1 and the conversion unit 1032-1 described inside the FR switch 10132-1. It describes the internal structure of the conversion unit 1032-2 described inside the FR switch 10132-2, and corresponds to a simplified version of the access control devices 1010-2 and 1010-1 described in FIGS. 34 to 36. To do. In the method of configuring the inside of the ICS using the FR network, the internal configuration of the access control device or the operation of the processing device in the access control device has the same basic principle as the content described in the first embodiment.
【0222】
The access control device 1010-5 is assigned ICS network addresses "7711" and "7722" as connection points (ICS logical terminals) of companies X and A who are users of ICS925, respectively. Similarly, the access control device 1010-7 is assigned the ICS network addresses "7733" and "7744" as connection points of the companies W and C, respectively. Similarly, the access control device 1010-6 is assigned the ICS network addresses "9922" and "9933" as the connection points of the companies Y and B, respectively, and the access control device 1010-8 is similarly assigned to the companies Z and D. ICS network addresses "9944" and "9955" are assigned as connection points, respectively. Here, in the examples of FIGS. 62 and 63, the company X, the company Y, etc. shown as examples of the users may be different bases of the same company that performs intra-company communication, or may be between companies. It can be a different company that communicates.
【0223】
The conversion unit 1032-5 inside the FR exchange 10132-5 has an interface unit 1132-5, and the interface unit 1132-5 is a communication line 1812-5 that connects the access control device 1010-5 and the FR exchange 10132-5. Interface with communication line 1812-7 connecting access control device 1010-7 and FR switch 10132-5 (physical layer, data link layer protocol) Is in charge of the process of matching. In addition to the processing device 1232-5, the conversion unit 1032-5 also uses the FR address translation table 1532-5 for call setting by SVC and to translate the ICS network address used by both SVC and PVC into a logical channel. It is composed of DLC address translation table 1432-5 of. The FR exchange 10132-5 is an FR address management server 1632-5 as an information processing device that stores the FR address conversion table, and DLC as an information processing device that stores the DLC address conversion table in the case of using PVC. Connects to the address management server 1732-5 to perform processing related to address translation. The components related to FR exchange 10132-6 are the same as those for FR exchange 10132-5. In this embodiment, the access control device 1010-5 is connected to the FR exchange 10132-5 via the communication line 1812-5, and the access control device 1010-7 is connected to the FR exchange 10132-5 via the communication line 1812-7, and the access control device 1010- 6 is connected to the FR exchange 10132-6 via the communication line 1812-6, and the access control device 1010-8 is connected to the FR exchange 10132-6 via the communication line 1812-8. The FR exchange 10132-5 has the only FR address "2977" in the network set in the internal conversion unit 1032-5, and the FR exchange 10132-6 has the only FR address in the network 1032-6 in the internal conversion unit 1032-6. FR address "2999" is set. The FR exchanges 10132-5 and 10132-6 are connected via the FR relay network, but in this example, they are connected via the FR exchange 10132-7, which is a representative of the FR relay network.
【0224】
(3) Frame flow using SVC: As shown in Fig. 62 and Fig. 63, an example in which the network inside the ICS is composed of an FR network and SVC is applied as a communication path in the FR network is shown in Company X. An ICS user frame issued from the terminal of the company Y to the terminal in the company Y will be described as an example.
【0225】
<< Preparation >> FR address conversion in the conversion unit 1032-5 inside the FR exchange 1032-5 Table 1532-5 shows the destination of the ICS network frame to be transferred from the conversion unit 1032-5 to the FR network. Register the incoming ICS network address, the incoming FR address indicating the other party to call and set the logical channel in the FR network, and the channel performance such as the authentication information speed required for the logical channel. In addition, the same registration is made for the FR address conversion table 1532-6 in the conversion unit 1032-6 inside the FR exchange 10132-6.
【0226】
As an example, the values set in the FR address translation table 1532-5 include the incoming ICS network address, the communication address with the company Y, and the ICS network assigned to the ICS logical terminal of the access control device 1010-6. The address "9922" is set, and as the incoming FR address, the FR address "only assigned in the FR network to the conversion unit 1032-6 inside the FR exchange 10132-6 to which the access control device 1010-6 is connected" 2999 is registered. For the channel performance, the certified information speed of 64 Kbps is set in this embodiment. The contents registered in the FR address conversion table 1532-5 are also written and saved in the FR address management server 1632-5.
【0227】
The values set in FR address conversion table 1532-6 are the ICS network address "7711" assigned to the ICS logical terminal of the access control unit 1010-5 as the incoming ICS network address and the address for communication with company X. Is set, and as the incoming FR address, the FR address 2977 that is uniquely assigned in the FR network to the conversion unit 1032-5 inside the FR exchange 10132-5 to which the access control device 1010-5 is connected is set. sign up. For the channel performance, the certified information speed of 64 Kbps is set in this embodiment. The contents registered in the FR address conversion table 1532-6 are also written and saved in the FR address management server 1632-6.
【0228】
<< Transfer of ICS network frame from access control device >> ICS user frame issued from the terminal of company X to the terminal of company Y connected to access control device 1010-6 via access control device 1010-5. Is encapsulated in ICS when passing through the access control device 1010-5, and becomes an ICS network frame F1 having an outgoing ICS network address "7711" and an incoming ICS network address "9922" inside the ICS frame header. The ICS network frame F1 is transmitted from the access control device 1010-5 to the FR switch 10132-5, and reaches the conversion unit 1032-5 via the interface unit 1132-5 that processes electrical signal conversion / matching of the communication path. Hereinafter, description will be made with reference to the flowchart of FIG.
【0229】
<< Acquisition of DLCI >> When the converter 1032-5 receives the ICS network frame F1 (step S1701), the outgoing ICS network address inside the ICS frame header is set to transfer the frame to the FR switch 10132-5. It is necessary to find the DLCI of the SVC logical channel that realizes the FR network communication path inside the ICS925, which is determined by the correspondence between 7711 "and the incoming ICS network address" 9922 ". In the case of SVC-based communication, the logical channel corresponding to this communication path may or may not be established at the time of receiving the ICS network frame. In order to know whether the logical channel is established, the processing device 1232-5 first finds the logical channel corresponding to the pair of the outgoing ICS network address 7711 and the incoming ICS network address 9922 in the DLC address translation table 1432-5. Search for registration in (step S1702), and if registration is made here, know that the desired logical channel has been established. That is, from the DLC address translation table 1432-5, it is acquired that the DLCI corresponding to the pair of the outgoing ICS network address "7711" and the incoming ICS network address "9922" is "16", and it is also acquired at the same time. From the channel type value "10", it is known that this logical channel is communication based on SVC. If there is no registration on the DLC address translation table 1432-5, establish the desired logical channel by performing << call setting >> described later, and register it on the DLC address translation table 1432-5 at that point. Obtain the DLCI from the information provided (step S1703).
【0230】
<< Call settings >> "When the DLCI corresponding to the communication path determined by the correspondence between the outgoing ICS network address and the incoming ICS network address is not registered in the DLC address translation table 1432-5", that is, If the logical channel corresponding to the communication path has not been established yet, it is necessary to perform the call setting described below and establish the logical channel in the FR network that constitutes ICS925, and an operation example of this call setting will be described. ..
【0231】
The processing device 1232-5 of the conversion unit 1032-5 refers to the DLC address translation table 1432-5 and refers to the outgoing ICS network address 7711 and the incoming ICS network address 9922 inside the ICS frame header of the ICS network frame F1. When you find out that there is no DLCI registration corresponding to the pair with "", refer to FR address translation table 1532-5, and the incoming call registered in FR address translation table 1532-5 that matches the incoming ICS network address "9922". Find the ICS network address "9922" and get the corresponding incoming FR address "2999", the corresponding channel performance "64K", etc. (step S1705). As described in the << Preparation >> section above, the incoming FR address 2999 is connected to the access control device 1010-6 whose connection point is the ICS logical terminal to which the incoming ICS network address 9922 is assigned. This is the address set to be unique in the FR network for the conversion unit 1032-6 inside the FR switch 10132-6 to be connected.
【0232】
The processing device 1232-5 requests the FR exchange 10132-5 to set a call using the acquired incoming FR address 2999. At this time, the logical channel is certified simultaneously acquired from the FR address translation table 1532-5. It also requires channel performance such as information speed (step S1706). When the FR exchange 10132-5 receives the call setting request, the FR exchange itself uses the signal system that is standard equipment as a conventional technology to enter the FR exchange network from the FR exchange 10132-5 to the FR exchange 10132-6. Establish a logical channel to connect the conversion unit 1032-5 and the conversion unit 1032-6. The DLCI assigned to identify the established logical channel is notified from the FR exchange to the conversion units 1032-5 and 1032-6 that are inside each, but if it is based on the provisions of the signal system of the prior art, it is emitted. The value notified from the calling FR exchange 10132-5 (for example, 16) and the value notified from the calling FR exchange 10132-6 (for example, 26) are not necessarily the same value. Absent. In the conversion unit 1032-5, the DLCI 16 notified from the FR exchange 10132-5 is sent to the DLC address conversion table 1432-5 together with the outgoing ICS network address 7711 and the incoming ICS network address 9922 of the ICS network frame F1. Register with (step S1707) and keep it on the DLC address translation table 1432-5 while the connection for this logical channel is established. When the logical channel connection is no longer required, the conversion unit 1032-5 requests the FR exchange 10132-5 to release the call of the logical channel, and at the same time, the registration corresponding to DLCI 16 is performed from the DLC address translation table 1432-5. Erase. The registration in the DLC address translation table 1432-6 in the conversion unit 1032-6 will be described later.
【0233】
<< Transmission of frame >> The processing device 1232-5 of the conversion unit 1032-5 receives the ICS network received from the access control device 1010-5 for the logical channel (DLCI 16) established according to the above description. Convert frame F1 to FR frame as shown in Figure 61 and transfer to FR switch 10132-5 (step S1704).
【0234】
<< Transfer of FR frame >> The FR frame S1 obtained by converting the ICS network frame F1 by the above method is transferred from the FR exchange 10132-5 to the relay FR exchange 10132-5, and further, the FR exchange 10132- Transferred from 5 to FR exchange 10132-6 as FR frame S2. Hereinafter, description will be made with reference to the flowchart of FIG. 65.
【0235】
<< Operation after reaching the frame >> When the FR frame S2 reaches the FR exchange 10132-6 (step S1710), this FR frame is transferred from the FR exchange 10132-6 to the internal converter 1032-6 of the FR exchange 10132-6. Transferred. The conversion unit 1032-6 restores the ICS network frame from the FR frame as shown in Fig. 61 (step S1711). The restored ICS network frame is described as ICS network frame F2 in Fig. 63, but the frame contents are the same as ICS network frame F1. The ICS network frame F2 is attached to the access control device identified by the incoming ICS network address "9922" inside the ICS frame header, that is, the access control device 1010-6 having an ICS logical terminal assigned the ICS network address "9922". Transferred (step S1712).
【0236】
At this time, in the conversion unit 1032-6, the outgoing ICS network address "7711" and the incoming ICS network address "9922" of the ICS network frame F2, and the channel type indicating that the SVC is known at the time of incoming call. Register 10 and the DLCI 26 assigned when the call of the SVC logical channel was set in the DLC address translation table 1432-6 (step S1714). At this time, the outgoing ICS network address 7711 of the ICS network frame F2 is converted to the incoming ICS network address in DLC address conversion table 1432-6, and the incoming ICS network address 9922 of the ICS network frame F2 is converted to the DLC address conversion table 1432-6. Write to the outgoing ICS network address in the opposite location. However, at the time of this registration, if the same content as the one to be registered is already registered in the DLC address translation table 1432-6, the registration will not be performed. The address translation information registered in the DLC address translation table 1432-6 is retained on the DLC address translation table 1432-6 while the connection of the corresponding logical channel (DLCI 26 in this example) is maintained. To.
【0237】
<< Reverse flow of frame >> Next, the reverse flow of ICS frame, that is, the case of flowing from company Y to company X, is similarly set on the assumption that the logical channel of SVC is set. This will be described with reference to FIGS. 62 and 63.
【0238】
The ICS user frame originating from company Y to company X is ICS-encapsulated when passing through the access control device 1010-6, and the outgoing ICS network address "9922" and the incoming ICS network address "7711" are sent to the ICS frame header. It is converted to the internal ICS network frame F3 and transferred to the conversion unit 1032-6 inside the FR switch 10132-6. The processing device 1232-6 of the conversion unit 1032-6 performs processing according to the flow shown in Fig. 64, but the DLC address conversion table 1432-6 of the conversion unit 1032-6 already states that the outgoing ICS network address is "9922". Since the DLCI 26 corresponding to the incoming ICS network address 7711 is registered as the channel type 10, that is, as an SVC, it operates according to the flow of (1) in Fig. 64, and for the DLCI 26. Converts the ICS network frame F3 to an FR frame (FR frame S3) and transfers it.
【0239】
The FR frame S3 is relayed and transferred through the FR network, becomes the FR frame S4, reaches the FR switch 10132-5, is received by the conversion unit 1032-5 through a logical channel having DLCI 16, and is received by the ICS network frame F3. Restored as an ICS network frame F4 with the same content as. In the conversion unit 1032-5, the pair of the outgoing ICS network address 9922 and the incoming ICS network address 7711 held inside the ICS frame header of the ICS network frame F4 reverses the arrival and departure of the DLC address conversion table 1432. Since it is already registered in -5, it is not registered in the DLC address translation table, and the ICS network frame F4 is transferred to the access control device 1010-5.
【0240】
<< Application example for half-duplex communication >> As described above, when the internal network of ICS925 is configured with FR network and the ICS frame is transferred from company X to company Y, conversely, from company Y to company X. It was explained that the transfer to and from the network is performed using one SVC logical channel. Such transfer and transfer in the opposite direction are performed from, for example, a request frame (transfer) from the client terminal of company X connecting to ICS to the server terminal of company Y connecting to ICS, and from the server terminal of company Y for this request frame. When applied to a response frame (reverse transfer) to a client terminal of company X, only one-way communication is performed at one time, but an application example of half-duplex communication that realizes two-way communication by switching the communication direction for each time zone. It becomes.
【0241】
<< Application example to full-duplex communication >> The logical channel itself set in the FR network can perform full-duplex communication, that is, bidirectional communication at the same time according to the FR rules. Request frames (transfers) for transfer using one SVC logical channel and reverse transfer in the FR network, for example, from multiple client terminals of company X connected to ICS to multiple server terminals of company Y connected to ICS. And, when applied to the response frame (reverse transfer) from the multiple server terminals of company Y to the multiple client terminals of company X for this request frame, the frames between the client terminal and the server terminal are transferred asynchronously, respectively. Therefore, bidirectional communication is simultaneously performed on one SVC logical channel that serves as a communication path, which is an application example of full-duplex communication.
【0242】
(4) Frame flow using PVC: An example in which the internal network of ICS925 is composed of an FR network and PVC is applied as a communication path in the FR network is shown from the terminal of company W to the terminal of company Z. The emitted ICS user frame will be described as an example.
【0243】
<< Preparation >> DLC address conversion in the conversion unit 1032-5 inside the FR exchange 10132-5 In Table 1432-5, the transmission ICS network address of the ICS network frame to be transferred from the conversion unit 1032-5 to the FR network. And, as the communication path between the incoming ICS network address and this incoming / outgoing ICS network address pair, the PVC network (pointing to the communication path between FR exchange 10132-5 and FR exchange 10132-6) is fixedly set. Register the DLCI and the channel type indicating that the logical channel is PVC. Unlike the case of SVC, this registration is registered in the DLC address translation table 1432-5 at the same time when the PVC logical channel is set in the FR exchanges (10132-5, 10132-5 and 10132-6) that are the communication paths. , Hold the communication path fixedly for the required period, that is, until the PVC logical channel is deconfigured. It is also registered and retained in the DLC address translation table 1432-6 in the conversion unit 1032-6 inside the FR exchange 10132-6. The DLCI of PVC is assigned to each FR exchange when the PVC is fixedly connected between the FR exchanges.
【0244】
The values set in the DLC address translation table 1432-5 are the outgoing ICS network address, the communication address with the company W, that is, the ICS network address assigned to the ICS logical terminal of the access control device 1010-7. 7733 is set, and the communication address with the company Z, that is, the ICS network address 9944 assigned to the ICS logical terminal of the access control device 1010-8 is set as the incoming ICS network address. Furthermore, as DLCI, the ID "18" of the PVC logical channel assigned to the FR exchange 10132-5 is set, and the value "20" indicating PVC is set for the channel type. In addition, the settings registered in the DLC address translation table 1432-5 are also written and saved in the DLC address management server 1732-5. Also, in the DLC address conversion table 1432-6 in the conversion unit 1032-6 inside the FR exchange 10132-6, make the same settings by reversing the outgoing ICS network address and the incoming ICS network address. In this case, even if the same PVC is shown, the DLCI may have a different value from the DLC address translation table 1432-5.
【0245】
The value set in the DLC address translation table 1432-6 is the communication address with the company Z as the outgoing ICS network address, that is, the ICS network address "9944" assigned to the ICS logical terminal of the access control unit 1010-8. Is set, and the communication address with the company W, that is, the ICS network address "7733" assigned to the ICS logical terminal of the access control device 1010-7 is set as the incoming ICS network address. Furthermore, "28", which is the ID of the PVC logical channel assigned to the FR switch 10132-6, is set in DLCI, and "20", which indicates PVC, is set in the channel type. In addition, the settings registered in the DLC address translation table 1432-6 are also written and saved in the DLC address management server 1732-6.
【0246】
<< ICS network frame transfer from the access control device >> As described in Example-1, the terminal of company Z connected to the access control device 1010-8 from the terminal of company W via the access control device 1010-7. The ICS user frame issued toward is encapsulated in ICS when passing through the access control device 1010-7, and has the outgoing ICS network address "7733" and the incoming ICS network address "9944" inside the ICS frame header. It becomes ICS network frame F5. The ICS network frame F5 is transmitted from the access control device 1010-7 to the FR switch 10132-5, and reaches the conversion unit 1032-5 via the interface unit 1132-5.
【0247】
<< Acquisition of DLC >> The processing device 1232-5 uses the outgoing ICS network address 7733 and the incoming ICS network address 9944 in the header of the received ICS network frame F5 to convert the DLC address to Table 1432-5. To obtain that the DLCI of the logical channel set as the communication path for this ICS network address pair is "18". At the same time, it is known that this logical channel is PVC from the acquired channel type value "20".
【0248】
<< Transmission of frame >> The processing device 1232-5 converts the ICS network frame F5 received from the access control device 1010-7 into an FR frame for the PVC logical channel 18 acquired as described above. Send to FR exchange 10132-5. This FR frame conversion method is the same as that described in the SVC example. The above processing procedure of the conversion unit 1032-5 is shown in a flowchart as shown in FIG. 64, and PVC always follows the flow of (1).
【0249】
<< Transfer of FR frame >> The FR frame S1 obtained by converting the ICS network frame F5 is transferred from the FR exchange 10132-5 to the relay FR exchange 10132-5, and further from the FR exchange 10132-5 to the FR exchange 10132. It is transferred to -6 as FR frame S2, but this operation is the same as for SVC.
【0250】
<< Operation after reaching the frame >> When the FR frame S2 reaches the FR exchange 10132-6, the FR frame S2 is transferred from the FR exchange 10132-6 to the conversion unit 1032-6 inside the FR exchange 10132-6. The conversion unit 1032-6 restores the ICS network frame from the received FR frame, but this operation is the same as in the case of SVC. The restored ICS network frame is described as ICS network frame F6 in Fig. 63, but the frame contents are the same as ICS network frame F5. The ICS network frame F6 is transferred to the access control device identified by the incoming ICS network address "9944" inside the ICS frame header, that is, the access control device 1010-8 having a logical terminal assigned the ICS network address "9944". Will be done. The above processing procedure of the conversion unit 1032-6 is shown in a flowchart as shown in FIG. 65, and PVC always follows the flow of (1).
【0251】
<< Reverse flow of the frame >> Next, the reverse flow of the ICS frame, that is, the case of flowing from the company Z to the company W, will be described using the PVC logical channel as a communication path. The ICS user frame issued from company Z to company W is ICS-encapsulated when passing through the access control device 1010-8, and the outgoing ICS network address "9944" and the incoming ICS network address "7733" are ICS frames. It is converted to the ICS network frame F7 held inside the header and transferred to the conversion unit 1032-6 inside the FR switch 10132-6. The processing device 1232-6 of the conversion unit 1032-6 performs processing according to the flow shown in Fig. 64. In this case, the DLC address conversion table 1432-6 of the conversion unit 1032-6 shows the outgoing ICS network address 9944. And since the DLCI "28" corresponding to the incoming ICS network address "7733" is registered, the ICS network frame F7 is converted into an FR frame and transmitted to the DLCI "28".
【0252】
The FR frame transferred in the FR network is received from the logical channel having DLCI 18 in the conversion unit 1032-5 of the FR exchange 10132-5, and is used as the ICS network frame F8 having the same contents as the ICS network frame F7. It will be restored. However, the conversion unit 1032-5 has already reversed the arrival and departure of the pair of the outgoing ICS network address "9944" and the incoming ICS network address "7733" in the header of the ICS network frame F8. Since the DLCI 18 for this outgoing / incoming address pair is obtained as PVC from the channel type value 20, the registration process is not performed, and the ICS network frame F8 is accessed by the access control device 1010. Transfer to -7.
【0253】
<< Application example for half-duplex communication >> As described above, the internal network of ICS925 was configured using the FR network, and an example of transferring ICS frames using PVC was explained. What are PVC and SVC? , The difference is whether the logical channel is fixedly set or the call is set when necessary, and there is no difference in the operation itself of transferring FR frames to the set logical channel. Therefore, the application example to the half-duplex communication when the ICS is configured using the FR network and the PVC logical channel is used for the FR network is the application example to the half-duplex communication using the SVC logical channel. Equivalent.
【0254】
<< Application example for full-duplex communication >> For the same reason as the application example for half-duplex communication, the application example for full-duplex communication of PVC is equivalent to the application example for full-duplex communication in SVC. is there.
【0255】
(5) One-to-N communication or N-to-one communication using PVC: In the above explanation, one logical channel of PVC is connected to one company (base) and one company (base) in the communication path, that is, inside the ICS. Shown an example of using one ICS logical terminal and one ICS logical terminal as a communication path, but one PVC logical channel is shared as a communication path between one ICS logical terminal and a plurality of ICS logical terminals. It is possible. An embodiment of such one-to-N communication or N-to-one communication will be described with reference to FIG. 66.
【0256】
<< Explanation of components >> Company X uses the ICS logical terminal assigned the ICS network address "7711" in the access control device 1010-52 as the connection point, and the access control device 1010-52 is the FR switch 10132-52. The other party to connect from company X is company A to D, and company A uses the ICS logical terminal in the access control device 1010-62 with the ICS network address "9922" as the connection point. B uses the ICS logical terminal assigned the ICS network address "9923" in the access control device 1010-62 as the connection point. Similarly, the company C uses the ICS network address "9944" in the access control device 1010-82. The assigned ICS logical terminal is used as the connection point, and the company D uses the ICS logical terminal assigned the ICS network address 9955 in the access control device 1010-82 as the connection point. Access control devices 1010-62 and 1010- 82 is connected to FR switch 10132-62, and FR switch 10132-52 and 10132-62 are connected via the FR relay network.
【0257】
<< Preparation >> One unit that connects the conversion unit 1032-52 inside the FR exchange 10132-52 and the conversion unit 1032-62 inside the FR exchange 10132-62 to the FR exchanges 10132-52 and 10132-62. A PVC logical channel is set, and the DLCI given to the conversion unit 1032-52 of this logical channel is set to "16", and the DLCI given to the conversion unit 1032-62 of the logical channel is set to "26". The DLC address translation table 1432-52 in the conversion unit 1032-52 and the DL address translation table 1432-62 in the conversion unit 1032-62 are registered as shown in FIG.
【0258】
<< 1-to-N communication frame flow >> The 1-to-N communication frame flow will be explained using frames transmitted from company X to companies A to D. For ICS network frames with outgoing ICS network address "7711" and incoming ICS network address "9922" directed from company X to company A, refer to DLC address translation table 1432-52 in the conversion unit 1032-52. , Sent to the PVC logical channel of DLCI 16. Similarly, an ICS network frame having an outgoing ICS network address 7711 and an incoming ICS network address 9933 directed from company X to company B is also transmitted to the PVC logical channel of DLCI 16. ICS network frame with outgoing ICS network address "7711" and incoming ICS network address "9944" from company X to company C, outgoing ICS network address "7711" and incoming ICS from company X to company D An ICS network frame with network address 9955 is also sent to the PVC logical channel of DLCI 16. This indicates that 1-to-N (company X-to-company A to D) communication is performed by sharing one PVC logical channel. The reverse flow of the frame, that is, the case where the frame is transferred from the company A to D to the company X will be described next.
【0259】
<< Flow of N to 1 communication frame >> The flow of 1 to N communication frame will be explained using the frames transmitted from companies A to D to company X. For the ICS network frame having the outgoing ICS network address "9922" and the incoming ICS network address "7111" directed from the company A to the company X, refer to the DLC address conversion table 1432-62 in the conversion unit 1032-62. , Sent to the PVC logical channel of DLCI 26. An ICS network frame with an outgoing ICS network address 9933 and an incoming ICS network address 7711 directed from Company B to Company X is also transmitted to the PVC logical channel of DLCI 26. ICS network frame with outgoing ICS network address "9944" and incoming ICS network address "7711" from company C to company X, outgoing ICS network address "9955" and incoming ICS network from company D to company X The ICS network frame with the address 7711 is also sent to the PVC logical channel of DLCI 26. This indicates that N-to-1 (company A to D-to-company X) communication is performed by sharing one PVC logical channel.
【0260】
(6) N-to-N communication using PVC: By the same method as 1-to-N communication, one logical channel of PVC can be shared as a communication path between multiple ICS logical terminals and multiple ICS logical terminals. is there. An embodiment of this N-to-N communication will be described with reference to FIG. 67.
【0261】
<< Explanation of components >> Company X uses the ICS logical terminal address 7711 of access control device 1010-13 as the connection point, and company Y uses the ICS logical terminal address 7722 of access control device 1010-13 as the connection point. Then, the access control device 1010-13 is connected to the FR switch 10132-13. The other party to connect from company X or company Y is company A or company C, company A uses the ICS logical terminal address "9922" of access control device 1010-23 as the connection point, and company C is access control device 1010-. The connection point is the ICS logical terminal address "9944" of 43. The access control devices 1010-23 and 1010-43 are connected to the FR switchboard 10132-23, and the FR switchboards 10132-13 and 10132-23 are connected via the FR relay network.
【0262】
<< Preparation >> One PVC that connects the conversion unit 1032-13 inside the FR exchange 10132-13 and the conversion unit 1032-23 inside the FR exchange 10132-23 to the FR exchanges 10132-13 and 10132-23. A logical channel is set, and the DLCI given to the conversion unit 1032-13 of this logical channel is set to "16", and the DLCI given to the conversion unit 1032-23 of the logical channel is set to "26". Register the DLC address translation table 1432-13 in the conversion unit 1032-13 and the DLC address translation table 1432-23 in the conversion unit 1032-23 as shown in FIG. 67.
【0263】
<< Flow of N-to-N communication frame >> First, the flow of N-to-N communication frame will be described with the frames transmitted from company X to companies A and C, respectively. For the ICS network frame having the outgoing ICS network address "7711" and the incoming ICS network address "9922" directed from the company X to the company A, refer to the DLC address conversion table 1432-13 in the conversion unit 1032-13. , Sent to the PVC logical channel of DLCI 16. Similarly, an ICS network frame having an outgoing ICS network address 7711 and an incoming ICS network address 9944 directed from the enterprise X to the enterprise C is also transmitted to the PVC logical channel of DLCI 16. Next, the frame transmitted from company Y to companies A and C will be described. For the ICS network frame having the outgoing ICS network address "7722" and the incoming ICS network address "9922" directed from the company Y to the company A, refer to the DLC address conversion table 1432-13 in the conversion unit 1032-13. , Sent to the PVC logical channel of DLCI 16. Further, the ICS network frame having the outgoing ICS network address 7722 and the incoming ICS network address 9944 directed from the company Y to the company C is also transmitted to the PVC logical channel of DLCI 16.
【0264】
Next, the flow in the reverse direction of the frame will be described with the frames transmitted from the company A to the companies X and Y, respectively. For the ICS network address with the outgoing ICS network address "9922" and the incoming ICS network address "7711" directed from company A to company X, refer to DLC address conversion table 1432-23 in the conversion unit 1032-23. Is sent to the PVC logical channel of DLCI 26. For the ICS network frame having the outgoing ICS network address "9922" and the incoming ICS network address "7722" directed from the company A to the company Y, refer to the DLC address conversion table 1432-23 in the conversion unit 1032-23. As a result, it is transmitted to the PVC logical channel of DLCI 26. Similarly, an ICS network frame with an outgoing ICS network address 9944 and an incoming ICS network address 7711 directed from Company C to Company X is transmitted to the PVC logical channel of DLCI 26. An ICS network frame with an outgoing ICS network address 9944 and an incoming ICS network address 7722 from Enterprise C to Enterprise Y is also transmitted to the PVC logical channel of DLCI 26. The above description shows that N-to-N communication is performed by sharing one PVC logical channel.
【0265】
Example-18 (Accommodation of telephone line, ISDN line, CATV line, satellite line, IPX line, mobile phone line): The connection to the access control device which is the access point to the ICS of the present invention is described in Example-1 or As described in Example 2, the communication line to the LAN (dedicated line, etc.) is not limited, and a telephone line, an ISDN line, a CATV line, a satellite line, an IPX line, and a mobile phone line can be accommodated. Therefore, another embodiment different from Example-10 will be described.
【0266】
FIGS. 68 to 71 show an example of a system accommodating a telephone line, an ISDN line, a CATV line, a satellite line, an IPX line, and a mobile phone line by ICS6000. , Telephone line converters 6030-1 and 6030-2, ISDN line converters 6029-1 and 6029-2, CATV line converters 6028-1 and 6028-2, Satellite line converters 6027-1 and 6027-2, IPX It is composed of conversion units 6026-1 and 6026-2 and mobile phone conversion units 6025-1 and 6025-2. The telephone line converters 6030-1 and 6030-2 are the physical layer and data link layer (OSI (Open Systems Interconnection)) between the telephone lines 6160-1 and 6160-2 and the access control devices 6010-1 and 6010-2. It has the functions of conversion and inverse conversion of the functions corresponding to the first layer and the second layer of the communication protocol). In addition, the ISDN line converters 6029-1 and 6029-2 have functions corresponding to the physical layer and data link layer between the ISDN lines 6161-11 and 6161-2 and the access control devices 6010-1 and 6010-2. It has conversion and inverse conversion functions, and the CATV line converters 6028-1 and 6028-2 are the physical layers between the CATV lines 6162-1 and 6162-2 and the access control devices 6010-1 and 6010-2. It has the functions of conversion and inverse conversion of the functions corresponding to the layer and the data link layer. Further, the satellite line converters 6027-1 and 6027-2 have functions corresponding to the physical layer and data link layer between the satellite lines 6163-1 and 6163-2 and the access control device 6010-1 or 6010-2. It has conversion and inverse conversion functions, and the IPX converters 6026-1 and 6026-2 are the physical layer between the IPX lines 6164-1 and 6164-2 and the access control devices 6010-1 and 6010-2. It has the function of conversion and inverse conversion of the function corresponding to the data link layer. The mobile phone converters 6026-1 and 6026-2 have functions corresponding to the physical layer and data link layer between the mobile phone wireless lines 6165-11 and 6165-2 and the access control devices 6010-1 and 6010-2. It has conversion and inverse conversion functions.
【0267】
The ICS frame interface network 6050 is the same type of network as the ICS frame interface network 1050 shown in Fig. 35, and is RFC791 or RFC1883. Transfer ICS network frames according to the regulations of. The X.25 network 6040 is also the same type of network as the X.25 network 1040 in Fig. 35. It accepts ICS network frames, converts them to X.25 format frames and transfers them, and finally converts them to the ICS network frame format. Reverse conversion and output. The FR network 6041 is also the same type of network as the FR network 1041 in Fig. 35. It accepts ICS network frames, converts them to frame relay format frames and transfers them, and finally converts them back to the ICS network frame format and outputs them. To do. The ATM network 6042 is also the same type of network as the ATM network 1042 shown in Fig. 35. It accepts ICS network frames, converts them to ATM format frames and transfers them, and finally converts them back to the ICS network frame format and outputs them. .. The satellite communication network 6043 is the same type of network as the satellite communication network 1043 shown in Fig. 35. It accepts ICS network frames, transfers information using satellites, and finally converts back to the format of ICS network frames and outputs them. To do. In addition, the CATV network 6044 accepts ICS network frames, converts them into CATV format frames, transfers the inside thereof, and finally converts them back to the ICS network frame format and outputs them.
【0268】
<< Common Preparation >> The conversion table 6013-1 in the access controller 6010-1 contains the outgoing ICS network address, sender ICS user address, recipient ICS user address, incoming ICS network address, and request identification. .. This request identification is represented by, for example, "1" for the intra-company communication service, "2" for the inter-company communication service, "3" for the virtual leased line connection, and "4" for the ICS network server connection. In the conversion table 6013-1, the addresses registered by the same method as in Example 1 and Example 2 are described. The ICS network server 670 has an ICS user address of "2000" and an ICS network address of "7821", and is connected to the access control device 6010-1 via the ICS network communication line 6081-1. In 1, the receiver ICS user address 2000, the incoming ICS network address 7821, and the request identification 4 of the ICS network server 670 are registered.
【0269】
The operation will be described with reference to the flowchart of FIG. 72.
【0270】
<< Communication from the telephone line to the ISDN line >> User 6060-1 accesses the ICS user frame F110 with the sender ICS user address "3400" and the receiver ICS user address "2500" via the telephone line 6160-1. Send to controller 6010-1. The access control device 6010-1 receives the ICS user frame F110 from the telephone line conversion unit 6030-1 of the ICS network address 7721 (step S1800), and the ICS network address 7721 identifies the request in the conversion table 6013-1. Checks if is registered as a virtual leased line connection 3 (step S1801). In this case, since it is not registered, the recipient ICS user address 2500 written on the ICS user frame Fll0 is registered on the conversion table 6013-1 (step S1803), and further, the request is made. Check if the identification is registered as inter-company communication 2 (step S1804). In this case, since it is registered, the incoming ICS network address "5522" is obtained from the conversion table 6013-1, processing such as billing related to inter-company communication is performed (step S1805), and the ICS user frame F110 is encapsulated in ICS (step S1805). Step S1820), convert to ICS network frame F120, and transmit to ICS frame transfer network 6030 via ICS network communication line 6080-1 (step S1825). The ICS network frame F120 reaches the access control device 6010-2 via, for example, the X.25 network 6040 and the ICS network communication line 6080-2, where the ICS decapsulated and the ICS user frame F110 is restored and the recipient. Reach user 6061-2 with ICS user address "2500".
【0271】
<< Communication from ISDN line to CATV line >> User 6061-1 accesses the ICS user frame Flll with sender ICS user address "3500" and recipient ICS user address "2600" via ISDN line 6161-1. Send to controller 6010-1. The access control device 6010-1 receives the ICS user frame Flll from the ISDN line conversion unit 6029-1 of the ICS network address 7722 (step S1800), and the ICS network address 7722 requests it on the conversion table 6013-1. Check whether the identification is registered as a virtual leased line connection 3 (step S1801). In this case, since the virtual leased line connection "3" is registered, obtain the incoming ICS network address "5523" from the conversion table 6013-1, perform processing such as billing for the leased line connection (step S1802), and ICS. The user frame Flll is encapsulated in ICS (step S1820), converted to the ICS network frame F121, and transmitted to the ICS frame transfer network 6030 via the ICS network communication line 6080-1 (step S1825).
【0272】
In the virtual leased line connection, the sender ICS user address and the receiver ICS user address written inside the ICS network frame Flll do not have to be used inside the access control device. Next, the ICS network frame F121 reaches the access control device 6010-2 via, for example, the FR network 6041 and the ICS network communication line 6080-2, and the ICS reverse encapsulation is performed to restore the ICS user frame Flll, and the incoming ICS is restored. The user 6062-2 connected from the CATV line 6162-2 is reached via the CATV line unit 6028-2 to which the network address "5523" is assigned.
【0273】
<< Communication from CATV line to satellite line >> User 6062-1 accesses ICS user frame F112 with sender ICS user address "3600" and receiver ICS user address "2700" via CATV line 6162-1. Send to controller 6010-1. The access control device 6010-1 receives the ICS user frame F112 from the CATV line conversion unit 6028-1 of the ICS network address 7723 (step S1800), and this ICS network address 7723 is displayed on the conversion table 6013-1. Check whether the request identification is registered as the virtual leased line connection 3 (step S1801). In this case, since it is not registered, the recipient ICS user address 2700 written on the ICS user frame F112 is registered on the conversion table 6013-1 (step S1803), and further, the request is made. Check if the identification is registered as inter-company communication 2 (step S1804). In this case, since the inter-company communication "2" is registered, the incoming ICS network address "5524" is acquired from the conversion table 6013-1, and processing such as billing related to the inter-company communication is performed (step S1805), and the ICS user Frame F112 is encapsulated in ICS (step S1820), converted to ICS network frame F122, and transmitted to ICS frame transfer network 630 via the ICS network communication line 6080-1 (step S1825). The ICS network frame F120 reaches the access control device 6010-2 via, for example, the ATM network 6042 and the ICS network communication line 6080-2, and is ICS decapsulated to restore the ICS user frame frame F112, and the recipient ICS user address. Reach user 6063-2 for "2700".
【0274】
<< Communication from satellite line to IPX line >> User 6063-1 accesses ICS user frame F113 with sender ICS user address "3700" and receiver ICS user address "2800" via telephone line 6163-1. Send to controller 6010-1. The access control device 6010-1 receives the ICS user frame F113 from the satellite line conversion unit 6027-1 of the ICS network address 7724 (step S1800), and the ICS network address 7724 requests it on the conversion table 6013-1. Check whether the identification is registered as a virtual leased line connection 3 (step S1801). In this case, since it is not registered, the recipient ICS user address 2800 written on the ICS user frame F113 is registered on the conversion table 6013-1 (step S1803), and the request identification is further performed. Check whether it is registered as inter-company communication 2 (step S1804). In this case, since the inter-company communication "2" is registered, the incoming ICS network address "5525" is acquired from the conversion table 6013-1, and processing such as billing related to the inter-company communication is performed (step S1805), and the ICS user Frame F113 is encapsulated in ICS (step S1820), converted to ICS network frame F123, and transmitted to ICS frame transfer network 6030 via ICS network communication line 6080-1 (step S1825). The ICS network frame F123 reaches the access control device 6010-2 via, for example, the ICS frame interface network 6050 and the ICS network communication line 6080-2, and is ICS decapsulated to restore the ICS user frame F113, and the recipient ICS user. Reach user 6064-2 at address "2800".
【0275】
<< Communication from IPX line to mobile phone line >> User 6064-1 uses ICS user frame F114 with sender ICS user address "0012" and recipient ICS user address "2900" via IPX line 6164-1. Send to access control device 6010-1. The access control device 6010-1 receives the ICS user frame F114 from the IPX line conversion unit 6026-1 of the ICS network address "7725" (step S1800), and the ICS network address "7725" requests it on the conversion table 6013-1. Check whether the identification is registered as a virtual leased line connection 3 (step S1801). In this case, since it is not registered, the recipient ICS user address 2900 written on the ICS user frame F114 is registered on the conversion table 6013-1 (step S1803), and further, the request is made. Check if the identification is registered as inter-company communication 2 (step S1804). In this case, since "2" is not registered, it is checked whether or not the request identification is registered as the intra-company communication "1" (step S1810). In this case, since the inter-company communication "1" is registered, the incoming ICS network address "5526" is acquired from the conversion table 6013-1, and processing such as billing related to the in-house communication is performed (step S1811), and the ICS user. Frame F114 is encapsulated in ICS (step S1820), converted to ICS network frame F124, and transmitted to ICS frame transfer network 6030 via ICS network communication line 6080-1 (step S1825). The ICS network frame F124 reaches the access control device 6010-2 via, for example, the CATV network 6044 and the ICS network communication line 6080-2, and is ICS decapsulated to restore the ICS user frame F114, and the recipient ICS user. Reach user 6065-2 with address "2900".
【0276】
<< Communication from mobile phone line to telephone line >> User 6065-1 passes the ICS user frame F115 with sender ICS user address "3800" and recipient ICS user address "2400" via mobile phone line 6165-1. Is sent to the access control device 6010-1. The access control device 6010-1 receives the ICS user frame F115 from the mobile phone line conversion unit 6035-1 of the ICS network address "7726" (step S1800), and the ICS network address "7726" is displayed on the conversion table 6013-1. Check whether the request identification is registered as the virtual leased line connection 3 (step S1801). In this case, since it is not registered, the recipient ICS user address 2400 written on the ICS user frame F115 is registered on the conversion table 6013-1 (step S1803), and the request identification is between companies. Check if it is registered as communication 2 (step S1804). In this case, since the request identification is registered as inter-company communication "2", the incoming ICS network address "5521" is acquired from the conversion table 6013-1, and processing such as billing for inter-company communication is performed (step S1805). , ICS user frame F115 is encapsulated in ICS (step S1820), converted to ICS network frame F125, and transmitted to ICS frame transfer network 6030 via ICS network communication line 6080-1 (step S1825). The ICS network frame F120 reaches the access control device 6010-2 via, for example, the satellite network 6043 and the ICS network communication line 6080-2, and is ICS decapsulated to restore the ICS user frame Fll5, and the recipient ICS user address. Reach "2400" user 6060-2.
【0277】
<< Communication from the mobile phone line to the ICS network server >> User 6066-1 sets the ICS user frame F116 with the sender ICS user address "3980" and the receiver 1CS user address "2000" to the mobile phone line 6166-1. It is sent to the access control device 6010-1 via. The access control device 6010-1 receives the ICS user frame F116 from the mobile phone line conversion unit 6025-1 of the ICS network address "7726" (step S1800), and the ICS network address "7726" is displayed on the conversion table 6013-1. Check whether the request identification is registered as the virtual leased line connection 3 (step S1801). In this case, since it is not registered, the recipient ICS user address 2000 written on the ICS user frame F116 is registered on the conversion table 6013-1 (step S1803), and the request identification is between companies. Check if it is registered as communication 2 (step S1804). In this case, since it is not registered, it is checked whether or not the request identification is registered as the intra-company communication 1 (step S1810). In this case, it is not registered, so check whether the request identification is registered as communication 4 with the ICS network server (step S1812). In this case, since it is registered, the incoming ICS network address "7821" is obtained from the conversion table 6013-1, processing such as billing related to corporate communication is performed (step S1813), and the ICS user frame F116 is encapsulated in ICS (step S1813). Step S1820), convert to an ICS network frame and send it to the ICS network server 670 (step S1825). The method by which the ICS network server 670 returns a reply to the source user 6066-1 is the same as the method described in Example-3.
【0278】
In the various transmission methods of the ICS user frame described above, the transmitting side changes the receiver ICS user address written in the ICS user frame, so that the transmitting side can make a telephone line, an ISDN line, a CATV line, or a satellite line. , IPX line, mobile phone line, any of the receiving side telephone line, ISDN line, CATV line, satellite line, IPX line, and mobile phone line can be selected.
【0279】
Example-19 (Dial Apple-Ta): An example using the dial apple-ta will be described with reference to FIGS. 73 to 75. LAN7400 internal user 7400-1 has an ICS user address "2500", similarly LAN7410 internal user 7410-1 has an ICS user address "3601". The person who manages the dial-up router 7110 inputs the telephone number specified for the recipient ICS user address correspondence and its priority from the router table input unit 7018-1 in the router table 7113-1 of the dial-up router 7110.
【0280】
Here, the registration contents of the router table 7113-1 will be described with reference to FIG. 76. When the recipient ICS user address "3601" is specified, the first priority is the telephone number "03-1111-1111" and the second priority is the telephone number "03-2222-2222". The third place is the telephone number "03-3333-3333". Recipient ICS user addresses "3602" and "3700" are also registered in the same way. Then, as an example of communication from the sender ICS user address 2500 to the receiver ICS user address 3601, the flow chart of FIG. 77 will be referred to and described.
【0281】
User 7400-1 sends the ICS user frame F200 to the dial-up router 7110 via gateway 7400-2 and user logical communication line 7204. The dial-up router 7110 operates under the control of the processor 7112-1, receives the ICS user frame F200 (step S1901), reads the recipient ICS user address "3601" contained in the ICS user frame F200, and addresses it. Search router table 7113-1 with "3601" as the search keyword (step S1902) to find the phone number with the highest priority. In this case, the telephone number with the highest priority is "03-1111-1111" as shown in the router table in Fig. 76, so the dial-up router 7110 uses the telephone network 7215-1 as the first attempt. Then make a call to the telephone number "03-1111-1111" (step S1910). As a result, a telephone communication path 7201 is established between the line section 7011-1 of the access control device 7010-1 called by the telephone number "03-1111-1111", that is, the dial-up router 7110 and the line section 7011-1. Is connected by a telephone line. If the dial-up router 7110 and the line section 7011-1 are not connected by a telephone line in the above telephone call procedure, the dial-up router 7110 is then subjected to the telephone number "03-2222", which has the second highest priority according to the router table 7113-1. Finding "-2222" and calling the telephone number "03-2222-2222" via the telephone network 7215-1 as the second attempt (step S1911). As a result, a telephone communication path 7202 is established with the line portion 7011-1 of the access control device 7010-1 called by the telephone number "03-2222-2222". If the dial-up router 7110 and the line section 7011-1 are not connected by a telephone line in the above telephone call procedure, the dial-up router 7110 is then the telephone number with the third highest priority according to the router table 7113-1. Find "03-3333-3333", No. As a third attempt, call the telephone number "03-3333-3333" via the telephone network 7215-3 (step S1912). As a result, a telephone communication path 7203 is established with the line unit 7011-3 of the access control device 7010-3 called by the telephone number "03-3333-3333". When the telephone communication path is not established from the dial-up router to the access control device even after the above multiple attempts, the dial-up router 7110 stores the received ICS frame F200 in the storage unit 7117-1 (step S1913), and after a certain period of time. Index the router table again in (step S1914) (step S1902) and try to establish the telephone communication paths 7201, 7202, 7203, etc.
【0282】
Next, the operation after the dial-up router 7110 and the line unit 7011-1 are connected by a telephone line will be described. The dial-up router 7110 enters the authentication procedure for whether or not it is a legitimate user registered as a user in the access control device 701O-1 (step S1920). The authentication procedure may be any one that can achieve the purpose of authentication. For example, the dial-up router 7110 sends an ID and password for identifying the dial-up router 7110 to the line unit 7011-1 through the telephone line 7201, and the access control device. The authentication unit 7016-1 of 7010-1 checks whether the received ID and password are correct, and if they are correct, the notification data notifying that the user is correct, that is, "affirmation confirmation" is sent to the dial-up router 7110 via the telephone communication path 7201. By sending, the authentication procedure is completed. In addition, if either the received ID or password is incorrect, the communication on the telephone communication path 7201 will be interrupted.
【0283】
When the dial-up router 7110 receives the affirmative confirmation notification in the user authentication from the telephone line 7201, it sends the ICS user frame F200 to the telephone communication path 7201 (step S1930), and the access control device 7010-1 receives the ICS user frame F200. When the above is confirmed, the telephone communication path 7201 is released and the telephone is hung up (step S1931), and the series of processing of the dial-up router described above is completed.
【0284】
When the access control device 7010-1 receives the ICS user frame F200, it performs ICS encapsulation using the conversion table 7013-1 under the control of the processing device 7012-1 to generate the ICS network frame F301, and inside the ICS7100. Send to ICS network communication line 7301. In this embodiment, the outgoing ICS network address of the ICS network frame F301 is the network address "7501" assigned to the ICS logical terminal in the line section 7011-1, and the incoming ICS network address is the access control device 7010-2. It is "8601" assigned to the ICS logical terminal. The ICS network frame F301 is transferred to the ICS7100 to reach the access controller 7010-2, where it is ICS decapsulated, passes through the user logical communication line 7601, and reaches the user 7410-1 with the ICS user address 3601. To do.
【0285】
In the above description, when the telephone communication path 7202 called by the telephone number "03-2222-2222" is established between the dial-up router 7110 and the line portion 7011-1 of the access control device 7010-1, the ICS user frame F200 Passes through the telephone communication path 7202 and is transferred from the dial-up router 7110 to the line section 7011-1. Also in this case, similar to the above, the access control unit 7010-1 is ICS capsule receives the ICS user frame F200 performs cell conversion, and sends the ICS network communication line 7301 the internal ICS7100 generates the ICS network frame F302. Here, the ICS user frame F302 is the outgoing ICS user address 7502 and the incoming ICS user address 8601.
【0286】
If a telephone communication path 7203 called by the telephone number "03-3333-3333" is established between the dial-up router 7110 and the line section 7011-3 of the access control device 7010-3, the ICS user frame F200 is a telephone. It passes through the communication path 7203 and is transferred from the dial-up router 7110 to the line section 7011-3. In this case, when the access control device 7010-3 receives the ICS user frame F200, it encapsulates the ICS, generates the ICS network frame F303, and sends it to the ICS network communication line 7303 inside the ICS7100. In this case, the outgoing ICS network address of the ICS network frame F303 is the network address "7800" assigned to the ICS logical terminal in the line section 7011-3, and the incoming ICS network address is the ICS of the access control device 7010-2. It is "8601" given to the logical terminal. The ICS network frame F303 is transferred to the ICS7100 to reach the access controller 7010-2, where it is ICS decapsulated, passes through the user logical communication line 7601, and reaches the user 7410-1 with the ICS user address 3601. To do.
【0287】
Example-20 (speed class and priority): << Configuration >> As shown in Fig. 78 to Fig. 80, the ICS8000-1 is an access control device 8010-1,8010-2,801O-3,8010-4, a relay device 8020-1, and an ICS address management server 802.115-1. , ICS network server 8027-1, these devices are connected by ICS network communication line 8030-1,8030-2,8030-3,8030-4,8030-5,8030-6 to transfer ICS network frames. ing. The line section 8011-1, the processing device 8012-1, and the conversion table 8013-1 are all provided inside the access control device 8010-1. ICS logical communication lines 8051-1,8051-2,8051-3,8051-4 are connected to the plurality of ICS logical terminals of the line section 8011-1, respectively, and the ICS network addresses "7721", "7723", " 7724 and 7725 are given respectively. The ICS network communication line in ICS8000-1 is given a speed class that indicates the speed at which ICS network frames are transferred. For example, the ICS network communication line 8030-1,8030-2,8030-6 has a speed class. Both are "4", the speed class of both the ICS network communication lines 8030-3 and 8030-5 is "3", and the speed class of the ICS network communication line 8030-4 is "2". The speed class is defined by the same standard as the speed class registered inside the conversion table 8013-1. The ICS address management server 802.11 is assigned the ICS network address "7811", and the ICS network server 802.11 is assigned the ICS network address "7821". It is connected to 8010-1.
【0288】
The user 8400-1 as an ICS communication terminal has an ICS user address "2500" and is connected to the line section 8011-1 via the ICS logical communication line 8051-1. The user 8400-2 as an ICS communication terminal is an ICS user. It has the address "2510" and is connected to the access control device 8010-2 via the ICS logical communication line 8052-1. The user 8400-3 as an ICS communication terminal has the ICS user address "3600" and the user 8400. -4 has an ICS user address "3610" and is connected to the access control device 8010-3 via gateway 8041-1 and ICS logical communication line 8053-1, respectively.
【0289】
The method of registering the ICS network address and the ICS user address in the conversion table 8013-1 is the same method as that of the above-mentioned Example-1 and Example-2, and the difference is the conversion of Example-1. The speeds registered in Table 113-1 have been deleted, and instead, as shown in Figure 80, the speed class and priority are registered, and the speed class and priority are in the address management server 8025-1. , It is stored with the corresponding ICS user address as part of the address-related information.
【0290】
The speed class is expressed numerically instead of being expressed in units of speed. For example, a communication speed of 64 Kbps is expressed in speed class 1, a communication speed of 128 Kbps is expressed in speed class 2, and so on, a communication speed of 500 Mbps is expressed in speed class 7. Represent. The numerical value of the speed class is defined as the faster speed as the numerical value is larger. An example of associating the communication speed with the speed class is shown in Fig. 81. It is not necessary to set the number of communication speed classes to 7 levels from 1 to 7, for example, 20 levels in response to the progress of communication technology. It may be subdivided to some extent. In addition, the communication speed does not have to exactly match the physical communication speed of the ICS network communication line in the ICS8000-1, for example, it corresponds to 25% of the physical communication speed so that the communication speed has a margin. You may do so. The priority is represented by a numerical value, for example, in eight stages, and represents the priority when the ICS network frame is sent from the access control device or the relay device to the ICS network communication line when compared in the same speed class. The higher the priority value, the higher the priority. For example, the relay device receives two ICS network frames F510 and F511 at approximately the same time, the speed class of these two frames is the same value "3", the priority of the ICS network frame F510 is "3", and the ICS. When the priority of the network frame F511 is 5, the ICS network frame F511 having a high priority is sent out in time.
【0291】
In this embodiment, for example, the ICS network communication lines 8030-3 and 8030-4 are said to be "in the same communication path" from the relay device 8020-1 to the access control device 8010-3, and the ICS network communication line 8030. -5 and 8030-6 are said to be "in the same communication path" from the relay device 8020-1 to the access control device 8010-4. The communication route may be directed from the access control device to the relay device, or from one relay device to another relay device connected by the ICS network communication line. A plurality of ICS network communication lines of the same speed class may exist in the same communication route, and in this case, the same speed class may be in the same ICS network communication line.
【0292】
<< Operation >> The operation will be described with reference to the flowcharts of FIGS. 82 and 83.
【0293】
User 8400-1 sends the ICS user frame F500 with the sender ICS user address 2500 and the receiver ICS user address 3600 to the ICS logical communication line 8051-1. The processing device 8012-1 of the access control device 8010-1 receives the ICS user frame F500 from the ICS logical terminal of the ICS network address "7721" of the line unit 8011-1, and acquires the ICS network address "7721" (step). S2001), check whether the address "7721" is registered as the request identification as the virtual leased line connection "3" on the conversion table 8013-1 (step S2002). In this case, since it is not registered, the recipient ICS user address 3600 written on the ICS user frame F500 is acquired next corresponding to the ICS network address 7721 (step S2004), and the address Check whether "3600" is registered in the conversion table and the request identification is registered as inter-company communication "2" (step S2005). In this case, since it is registered, the incoming ICS network address "5522" is obtained from the conversion table 8013-1 in preparation for ICS encapsulation, and the speed class "3" and priority "3" are obtained from the conversion table 8013-1. Obtain information related to billing (step S2006). Next, ICS encapsulation is performed by generating an ICS network frame F510 in which the speed class 3 and the priority 3 are written in the ICS network frame control unit (step S2020), and the ICS network communication line 8030- Send to 1 (step S2021).
【0294】
In the above explanation, the ICS network frame is for inter-company communication with the request identification of "2", but for the virtual line connection with the request identification of "3", the incoming ICS is shown in the conversion table 8013-1. Acquire the network address, speed class, priority, etc., and further acquire the information related to billing (step S2003). For example, in the case of corporate communication "1", the incoming ICS network address, speed, etc. are obtained from conversion table 8013-1. Acquire the class, priority, etc., and further acquire the information related to billing (step S2011), and in the case of communication "4" to the ICS network server, acquire the incoming ICS network address, etc. from conversion table 8013-1. Then, the information related to billing is acquired (step S2013), and after ICS encapsulation, it is sent to the ICS network server 8027-1.
【0295】
The ICS network frame F510 generated by the above procedure reaches the relay device 802.110 via the ICS network communication line 8030-1. At this time, it is assumed that another ICS network frame F511 arrives at the relay device 8020-1 via the ICS network communication line 8030-2 at about the same time. The ICS network frame F511 is sent from the user 8400-2 as the ICS user frame F501, reaches the access control device 8010-2 via the ICS logical communication line 8052-1, and is then ICS-encapsulated to become the ICS network frame F511. It was transmitted through the ICS network communication line 8030-2 and reached the relay device 8020-11. When the relay device 802.11 receives the ICS network frames F510 and F511 (step S2030), under the control of the processing device 802.111, the relay table 802.111 is first checked to communicate the ICS network frames F510 and F511 with the ICS network. Which line should be used, that is, find the communication route (step S2031) and divide each communication route (step S2032). In the case of this embodiment, the transmission destination of both of the two ICS network frames F510 and F511 is the communication route from the relay device 8020-1 to the access control device 8010-3, and the ICS network communication line 8030- There are 3 and 8030-4, 2 ICS network communication lines. Next, for both the ICS network frames F510 and F511, the speed class described in the control unit is read and divided for each speed class (step S2041), and thereafter, the procedure for each divided speed class is performed. In the case of this embodiment, both the speed classes of the ICS network frames F510 and F511 are 3. Next, ICS frames of the same speed class read the priority described in each control unit and are transmitted from the ICS frame having the higher priority (step S2042). If they have the same priority, either one may be sent first. As a result of the above processing, the relay device 802.11 is ICS network.
【0296】
In the above procedure, if there is only an ICS network communication line whose speed is lower than the speed class described in the control unit of the ICS network frame F510, information on the decrease in communication service due to the decrease in speed, that is, the corresponding ICS network. Record the sender ICS user address, receiver user address, communication service time (year, month, day, hour, minute, second), etc. described in the frame in the relay operation file 8023-1. The recorded contents of the relay operation file are notified to the ICS8000-1 user upon request.
【0297】
By the above procedure, the two ICS network frames F511 and F510 are transferred to the ICS network communication line 8030-3 and reach the access control device 8010-3, with the high-priority ICS user frame F511 leading in time. To do. The ICS network frame F511 becomes the ICS user frame F501 by being decapsulated by ICS, and reaches the user 8400-4 of the ICS user address "3610" via the ICS logical communication path 8053-1. The ICS network frame F510 is ICS decapsulated to become the ICS user frame F500, and reaches the user 8400-3 with the ICS user address "3600" via the ICS logical communication path 8053-1.
【0298】
Next, options are shown for how to use priorities. When transferring the speed class and priority registered in the conversion table 8013-1 to the ICS network at the time of ICS encapsulation, the processing device 8012-1 controls the ICS user frame to be processed. Check the length written in the part, for example, only when the ICS user frame is less than the specified value (for example, 256 bytes), the value obtained by increasing the priority value by +1 is added to the ICS network frame. Post to Mu. In this way, it is possible to realize a service that preferentially transfers the inside of the ICS8000-1 only to a short ICS user frame. By such a method, the ICS8000-1 operator can easily realize a communication service in which a short ICS user frame is prioritized, that is, a communication charge is increased. If the ICS user frame is short for the user, the flow will be more reliable. Whether or not to adopt the priority option is achieved by, for example, determining for each access control device.
【0299】
In addition, only the speed class may be carried out, and the above method may be carried out except for the priority, that is, with the same priority. In another embodiment, conversion table 8013-1 does not include sender ICS user addresses (intra-company and inter-company). Even in this case, the flowchart in FIG. 82 does not originally refer to the sender ICS user address, so it does not change.
【0300】
Example-21 (Granting an Electronic Signature to an ICS User Frame): An embodiment of electronically signing an ICS user frame to prove that the ICS user frame has passed an access control device is described, and a request is made. An example of encrypting the ICS user frame at one time will be described. First, the technique of electronic signature (electronic signature) used in this embodiment will be described. When using a digital signature, there are a signer who creates the digital signature and a signature verifier. The signer a simultaneously generates a pair of signing key KSa and verification key KPa of signer a, keeps the signing key KSa in secret, and discloses only the verification key KPa by some means. The signer a generates an electronic signature σ depending on the data m and the signature key KSa by using the secret signature key KSa only for the signer a. Expressed in a mathematical formula, it becomes the following number 1.
【0301】
[Number 1]
σ = SIGN (KSa, h (m)) Here, SIGN is a signature function representing a signature function, and the function y = h (m) is a hash function for electronic signature having a function of compressing data m into short data. The verifier b uses the published verification key KPa to [Number 2]
ν = TEST (σ, KPa, h (m)) The correctness of the electronic signature σ is verified by. If ν = 1, both the electronic signature σ and the data m are correct, indicating that both the electronic signature σ and the data m have not been rewritten and tampered with after the generation of the electronic signature σ. If ν = 0, it means that either one or both of the electronic signature σ and the data m are incorrect. The verification key KPa is widely disclosed by an appropriate means, for example, in a public key guidance service center that provides guidance services for public keys and public keys, and in general advertisements. A technique for creating a signature function SIGN that makes it virtually impossible to calculate the signature key KSa even if the verification key KPa is disclosed is known.
【0302】
Next, the procedure for assigning a digital signature to the ICS user frame will be described. Conditions related to the time and place where the electronic signature is given, that is, the time consisting of the year, month, day, hour, minute, and second when the electronic signature is given, the person in charge of operating the access control device, and the "time / place parameter" that indicates the identification code of the access control device. "P1" and "Signature function parameter P2" indicating the type of signature function SIGN and hash function h (m), the length of the signature key, etc. are also subject to digital signature. Expressed in a mathematical formula, the following number 3 is obtained.
【0303】
[Number 3]
σ = SIGN (KSa, h (m)) However, m = UFTheP1TheP2.
【0304】
Here, UF represents the ICS user frame before ICS encapsulation or the restored ICS user frame after ICS decapsulation. The receiving user receives the ICS user frame UF, the time / place parameter P1, the signature function parameter P2, and the digital signature σ in the receiving ICS user frame as UFTheP1TheP2Theσ. This is illustrated as shown in FIG. 84. Further, there is also a method of leaving the writing area of the parameters P1 and P2 and the electronic signature σ as a free area inside the ICS user frame UF as shown in FIG. 85. In this case, when the free space of the ICS user frame UF is represented by Data, the digital signature σ is [Number 4]
σ = SIGN (KSa, h (m)) However, m = Data The P1 The P2.
【0305】
Generated as and signature verification [Number 5]
ν = TEST (σ, KPa, h (m)) However, m = Data The P1 The P2.
【0306】
Do as.
【0307】
Furthermore, for example, if the length of the ICS user frame UF is 2048 bytes and the length of UFTheP1TheP2Theσ is 2448 bytes (2048 bytes + 400 bytes), inside the control unit of the ICS user frame UF. It is necessary to rewrite the field representing the length of a frame (for example, the total length field in FIG. 100) from 2048 bytes to 2448 bytes. In this way, the ICS user frame with the length field rewritten is represented by UF ́. When adopting such an embodiment, the electronic signature σ is [Number 6]
σ = SIGN (KSa, h (m)) However, m = UF ́The P1 The P2.
【0308】
Generated as and signature verification [Number 7]
ν = TEST (σ, KPa, h (m)) However, m = UF ́The P1 The P2.
【0309】
Do as.
【0310】
In this embodiment, the order in which UFs, P1 and P2 are arranged may be changed. For example, the electronic signature σ = SIGN (KSa, h (m)) is calculated as m = PlTheP2TheUF, and P1TheP2The UFTheσ may be set inside the ICS user frame on the receiving side. In this embodiment, the encryption function is represented by y = ENC (K1, x), and the decryption function is represented by x = DEC (K2, y). Here, x is plaintext data, y is ciphertext data, ENC is an encryption function, DEC is a decryption function, K1 is an encryption key, and K2 is a decryption key. The technique of electronic signature is also called digital signature. For example, W. Diffie, ME Hellman's paper "New Direction in Cryptography" IEEE, IT. Vol.IT-22, No.6, p.644-654, 1976, Shokodo, published in 1990, edited by Shigeo Tsujii, "Cryptography and Information Security," p.127-138.
【0311】
<< Configuration >> As shown in Fig. 86 and Fig. 87, ICS9000-1 includes access control devices 9010-1, 9010-2, 9010-3 and relay device 9120-1, which are ICS network frames. It is connected by the ICS network communication line 9030-1,9030-2,9030-3 to be transferred. The line unit 9011-11, the processing device 9012-1, the conversion table 9013-1, and the electronic signature unit 9017-1 are all provided inside the access control device 9010-1. Inside the digital signature unit 9017-1, a signature key KSa, a verification key KPa, a program module that realizes the digital signature function SIGN and the hash function h (m), a time / place parameter P1, and a signature function parameter P2 are included. There is. Here, the signature Ken KSa is a secret value held by the access control device 9010-1, and the electronic signature part holds the secret signature key inside, so that the secret signature key is not leaked to the outside. There is a need. For example, the electronic signature unit is stored inside a physically strong box so that the signature key cannot be read from the outside. The ICS network addresses "7721", "7722", "7725", "7726", "7727", and "7728" are assigned to the plurality of ICS logical terminals of the line unit 9011-1.
【0312】
The encryption / decryption means 9018-1 includes an encryption function and holds an encryption key K1 and a decryption key K2. When the ICS user frame UF1 is input, the ciphertext UF2 is generated as UF2 = ENC (K1, UF1), and when the ciphertext UF2 is input, the plaintext is calculated as UF1 = DEC (K2, UF2).
【0313】
<< Operation >> The operation will be described with reference to the float chart in FIG. 88. User 9400-1 sends the ICS user frame F900 with the sender ICS user address 2500 and the receiver ICS user address 3600 to the ICS logical communication line 9051-1. The processing device 9012-1 of the access control device 9010-1 receives the ICS user frame F900 from the ICS logical terminal of the ICS network address 7721 of the line unit 9011-1, and acquires the ICS network address 7721 (step). S2001), check whether the address "7721" is registered as the virtual leased line connection "3" on the conversion table 9013-1 (step S2002). In this case, since it is not registered, the recipient ICS user address 3600 written on the ICS user frame F900 corresponding to the ICS network address 7721 is acquired (step S2004), and this address Check whether "3600" is registered in the conversion table and whether the request identification is registered as inter-company communication "2" (step S2005). In this case, since it is registered, the incoming ICS network address "5522" is obtained from the conversion table 9013-1 in preparation for ICS encapsulation. Next, the information related to the speed class and priority billing is obtained from the conversion table 9013-1 (step S2006). Since "1" is specified in the signature field of conversion table 9013-1 and "YES" is registered in the electronic signature field at the time of transmission, the processing device 9012-1 is stored in the electronic signature section 9017-1. Using the program module that realizes the digital signature function SIGN and the hash function h (m), the time / location parameter P1 and the signature function parameter P2, the digital signature of the ICS user frame F900 is performed by the above-mentioned digital signature technique. Generate and create a new ICS user frame (represented by UF2) (step S2019). Expressed in a mathematical formula, the following number 8 is obtained.
【0314】
[Number 8]
UF2 = mTheσ However, m = F900TheP1TheP2, σ = SIGN (KSa, h (m)).
【0315】
In the above procedure, even if "1" is specified in the signature field of conversion table 9013-1, if "NO" is registered in the electronic signature field at the time of transmission, the electronic signature section 9017- 1 does not work and the digital signature is not given.
【0316】
Next, since the encryption class is specified as "1", the ICS user frame UF2 is encrypted by the encryption / decryption means 9018-1 and the new ICS user frame UF3 (= ENC (K1)) , UF2)). If the encryption class is "0", encryption is not performed.
【0317】
Next, ICS encapsulation is performed by generating an ICS network frame F901 in which the speed class, priority and encryption class are written in the ICS network frame control unit (step S2020), and the ICS network communication line 9030 inside the ICS9000-1 is performed. Send to -1 (step S2021). In the above explanation, the ICS network frame is an example of inter-company communication with a request identification of "2", but for example, in the case of a virtual line connection with a request identification of "3", the incoming ICS is shown in the conversion table 9013-1. Obtain information on network address, billing, etc. (step S2003), and in the case of in-house communication with request identification of "1", obtain information on incoming ICS network address, billing, etc. from conversion table 9013-11 (step S2011). ), In the case of communication to the ICS network server whose request identification is "4", information on the incoming ICS network address, billing, etc. is acquired from the conversion table 9013-1 (step S2013).
【0318】
The ICS network frame F901 generated by the above procedure reaches the access control device 9010-2 via the ICS network communication line 9030-1 and the relay device 9120-1, and is ICS decapsulated to become the ICS user frame F902. , The user 9400-2 with the ICS user address "3600" is reached via the ICS logical communication path 9051-3. Here, F902 = mTheσ, m = UF1TheP1TheP2, UF1 is the ICS user frame F900 before transmission, P1 is the time / place parameter, P2 is the electronic signature parameter, σ is the electronic signature, and σ = SIGN (KSa). , H (m)).
【0319】
<< Digital signature and decryption in ICS decapsulation >> User 9400-3 uses the ICS user frame F930 with the sender ICS user address "3610" and the receiver ICS user address "2510" on the ICS logical communication line 9051-4. Send to. The access control device 9010-3 receives the ICS user frame F930, performs ICS encapsulation using the internal conversion table, generates the ICS network frame F931, and sends it to the ICS network communication line 9030-3. The ICS network frame F931 reaches the access control device 9010-1 via the central device 9120-1 and the ICS network communication line 9030-1, and is ICS decapsulated under the control of conversion table 9013-1 to be an ICS user. It becomes frame UF1. Since the encryption class is specified as "1" in the control unit of the ICS network F931, the ICS user frame (UF1) obtained by decapsulation is encrypted / decrypted by the encryption / decryption means 9018-1. Decrypt it to ICS user frame UF1 ́. If UF1 ́ = DEC (K2, UF1) and the encryption class is 0, decryption is not performed.
【0320】
Next, since "1" is specified in the signature field of conversion table 9013-1 and "YES" is registered in the electronic signature field at the time of reception, the electronic signature unit 9017-11 operates here. , Parameters P1 and P2 and the electronic signature σ are added by the same method as described above, and a new ICS user frame F932 is obtained. Expressed in symbols, F932 = mTheσ, m = UF1TheP1TheP2, electronic signature σ = SIGN (KSa, h (m)), and UF1 ́ instead of UF1 when the above decoding is performed. In the above procedure, even if "1" is specified in the signature field of conversion table 9013-1, the electronic signature will not be given if "NO" is registered in the electronic signature field at the time of reception. .. The ICS user frame F932 reaches the user 9400-4 at the ICS user address 2510 via the line unit 9011-1 and the logical communication line 9051-4.
【0321】
<< For signature request >> When the ICS user frame F940 with the sender ICS user address "2800" and the receiver ICS user address "3700" is input from the line section 9011-1, it corresponds to the ICS network address "7728". Then, the request identification is "2", "0" is entered in the signature column of the conversion table 9013-1 corresponding to the recipient ICS user address "3700", and "YES" is entered in the electronic signature column at the time of transmission. It is registered. Then, since "1" is specified in the "signature request" field written at the predetermined position of the ICS user frame F940, the electronic signature unit 9017-1 operates, and the parameters P1 and P2 and the parameters P1 and P2 and the same as described above A new ICS user frame is added with the electronic signature σ.
【0322】
If "0" or "1" is registered in the signature field of conversion table 9013-1 and "NO" is registered in the electronic signature field at the time of transmission, "1" is displayed in the signature request field of the ICS user frame. If specified, no digital signature is given prior to ICS encapsulation. Similarly, if "0" or "1" is registered in the signature field of conversion table 9013-1 and "NO" is registered in the electronic signature field at the time of reception, "1" is registered in the signature request field of the ICS user frame. Even if is specified, the digital signature is not given after ICS decapsulation.
【0323】
On the other hand, when the ICS user frame is digitally signed at the time of transmission by the transmitting side access control device and further digitally signed at the time of reception by the receiving side access control device, the electronic signature at the time of transmission and the electronic signature at the time of reception are obtained as shown in FIG. Granted. There are also other examples of including the value of the validation key KPa in the signature function parameter P2. By doing so, the recipient of the ICS user frame can save the trouble of obtaining the verification key KPa from the public key guidance service center or the like. Further, when the content of the ICS user frame is an electronic slip (order slip, receipt, etc.), an electronic signature is given to the electronic slip together with the identification name of the access control device through which the electronic slip has passed. When either the sender (creator) of the electronic slip or the recipient (receiver) of the electronic slip modifies the electronic slip, the alteration can be detected by the principle of the electronic signature. Therefore, as long as the digital signature key is a secret value, that is, as long as the operator of the access control device holding the signature key internally guarantees the signature key as a secret value, the digital signature is a public one that cannot be tampered with. Can be used as.
【0324】
Example-22 (Electronic Signature Server and Cryptographic Server): As shown in FIG. 86 of Example-21, the electronic signature unit 9017-1 and the encryption / decryption means 9018-1 are access control devices 9010-1. Is inside. On the other hand, in this embodiment, as shown in FIG. 90, the access control devices 9310-1,9310-2,9310-3,9310-4 are examples in which the electronic signature unit is not included inside each of the access control devices 9310-1,9310-2,9310-3,9310-4. The digital signature server 9340-1,9340-2,9340-3,9340-4 and the ICS network communication line 9341-1,9341-2,9341-3,9341-4 are connected, respectively. Each digital signature server includes the function of the digital signature section of Example-21, and cooperates with an access control device to add a digital signature before ICS encapsulation, or a digital signature after ICS de-encapsulation. This is the same as the function of the electronic signature unit 9017-1 of Example-21, and includes a signature key, a verification key, an electronic signature function, a program module that realizes a hash function, a time / place parameter, and a signature function parameter. The electronic signature servers 9342-1 and 9342-2 are connected to the relay devices 9320-1 and 9320-2 via the ICS network communication lines 9344-1 and 9342-2, respectively. All digital signature servers have a unique ICS network address inside the ICS network, and use the ICS network server communication function to communicate with other digital signature servers and access control devices to exchange information held by each other. Has a function. The electronic signature server 9342-1 is a digital signature server that represents VAN9301-1, and is an internal electronic signature server 9340-1, of VAN9301-1. You can obtain the information held by these digital signature servers by communicating with 9340-2 using the ICS network server communication function. Further, the electronic signature server 9340-1 can obtain information (for example, a verification key) related to the electronic signature held by the electronic signature server 9340-12 via the electronic signature server 9342-1. The electronic signature server 9342-1 can communicate with another electronic signature server 9342-2 representing VAN9301-2 by using the ICS network server communication function, and can exchange information about the electronic signature held by each of them. The electronic signature server does not exchange the secret signature key held inside the electronic signature server with another electronic signature server, and strictly keeps the secret of the signature key.
【0325】
Further, in this embodiment, as shown in FIG. 90, the access control devices 9310-1,9310-2,9310-3,9310-4 are examples in which the encryption / decryption means is not included inside, and instead, encryption is performed. It is connected to the server 9343-1,9343-2,9343-3,9343-4 by the ICS network communication line, respectively. Each cryptographic server includes the function of the encryption / decryption means 9018-1 and cooperates with the access control device connected to it to encrypt the ICS user frame before ICS encapsulation, or Decrypting the ICS user frame encrypted at the source after ICS decapsulation is the same as the encryption / decryption means 9018-1, and the encryption function and decryption function Includes a program module, encryption key, and decryption key that realizes. The cryptographic servers 9343-5 and 9343-6 are connected to the relay devices 9320-1 and 9320-2 via the ICS network communication line, respectively. Each cryptographic server has a unique ICS network address inside the ICS network, and uses the ICS network server communication function to communicate with other cryptographic servers and exchange the information held by each. Has the function of Cryptographic server 9343-5 is a cryptographic server that represents VAN9301-1, and communicates with Cryptographic servers 9343-1 and 9343-2 inside VAN9301-1 using the ICS network server communication function. However, the information held by these cryptographic servers can be obtained. In addition, the encryption server 9343-1 can obtain information about the encryption (for example, the encryption key) held by the encryption server 9343-2 via the encryption server 9342-5. Cryptographic server 9343-5 can communicate with other cryptographic servers 9343-6 representing VAN9301-2 using the ICS network server communication function, and exchange information about the cryptography held by each. it can.
【0326】
Example-23 (Open Connection): Explains the ICS open connection, that is, the preparatory procedure performed by the user and the VAN operator in order to change the destination and perform business-to-business communication.
【0327】
<< User application >> The user applies for the ICS name and ICS user address to the VAN operator, and at the same time presents the ICS connection conditions, user identity and fee payment method (address, company name, payment bank account number, etc.). Also, if there is an ICS user address for in-house communication specified by the user, it will be presented, but if it is not, it will not be presented. The VAN operator decides the ICS name and the ICS user address according to the common rules set in advance with other VAN operators and informs the user. The items of ICS connection conditions include ICS name condition, communication band condition, billing condition, electronic signature condition, encryption condition, open area condition, dynamic change condition, etc. The contents of these conditions are as follows.
【0328】
The ICS name condition is the left part of the ICS name, for example, if the ICS name is "USR # 1.ACS # 1.DIS # 1.VAN # 1.JP.AS", the user is "USR # 1" on the far left. Specify only (VAN operator decides the remaining right part). Communication band conditions are speed class and priority. Billing conditions are flat-rate charges for regular periods, network usage charges (network charges), and charges for the content of information sent and received by digitally signed communications (information charges), communication band conditions, electronic signature conditions, and encryption. It is set according to the conditions. The digital signature condition specifies whether or not to give a digital signature that can prove the fact that the ICS user frame has passed the access control device together with the date and time, and the encryption condition is whether to encrypt when the ICS user frame is transferred. Specify whether or not. The open condition is the inter-company communication service, that is, when the request identification "2" in the conversion table is used, the access control device rejects the reception when an ICS frame is received from an unknown sender not registered in the conversion table. It specifies whether or not to do so, or whether to create a temporary conversion table and receive it. The dynamic change condition specifies a function that allows the user to change the above conditions according to the user's request through the ICS frame, and is specified by the open class. The method of specifying the value of the open area class will be described later. As for the dynamic change conditions, for example, signature conditions and encryption conditions can be changed, but important conditions for VAN operation such as ICS address and billing are not subject to change.
【0329】
<< ICS Address Management Server and ICS Name Server >> Explaining with reference to FIGS. 91 and 92, this embodiment has an access control device 11110-1,11110-2,11110-3, inside the ICS11000-1. Relay device 11116-1, ICS address management server 11150-1,11150-2, ICS name server 11160-1,11160-2, ICS conversion table server 11170-1,11170-2, user 11132-11, 11132-2 Including. The ICS address management server 11150-2 includes the ICS network address 8210 and ICS user address 4200 of the user 11132-2 and the user's address-related information in the internal correspondence table, and the ICS name server 11160-2 is internal. ICS name conversion table of user 11132-2 includes "USR # 3.ACS # 3.DIS # 3.VAN # 3.JP.AS" of ICS name and "4200" of ICS user address. The VAN operator determines the ICS network address (7777) to be used in association with the ICS user address 3333 of user 11132-1, assigns it to the ICS logical terminal 11111-2 of the access control device 11110-1, and assigns it to the user. Connect the ICS logical communication path 11133-1, which is connected to 11132-1 via the gateway 11000-2. Since the ICS network address "7777" is a private value for the user, it is not notified to the user.
【0330】
Next, the VAN operator can see the internal correspondence table 11152-1 of the ICS address management server 11150-1 with the ICS network address "7777", the ICS user address (between companies) "3333", and the user. Presented ICS user address (inside the company) "1111" and user address related information, that is, communication band condition, billing condition, electronic signature condition, encryption condition, open area condition, dynamic change condition, user identity and fee payment method , Directly write to conversion table 11152-1 via data passage 11153-1 and processing device 11151-1. The VAN operator also added the ICS name USR # 1.ACS # 1.DIS # 1.VAN # 1.JP.AS specified above in the ICS name conversion table 11162-1 inside the ICS name server 11160-1. , ICS user address "3333", type "1" (ICS user address "3333" is listed inside ICS name conversion table 11162-1), data passage 11163-1 and processing device 11161-11 Write directly to the ICS name conversion table 11162-1 via. The above results are shown in Correspondence Table 11152-1 and ICS Name Conversion Table 11162-1.
【0331】
When the ICS address management server 11150-1 and the ICS name server 11160-1 finish writing various information about the new user described above, they use the ICS network addresses "8910" and "8920" and the ICS network communication function, respectively. , ICS conversion table Notifies server 11170-1 that the ICS address and ICS connection condition information for the new user have been obtained. Here, the ICS conversion table server 11170-1 is a kind of ICS network server, and in this example, it has an ICS network address 8100 and an ICS user address 2100.
【0332】
<< ICS conversion table server >> The ICS conversion table server 11170-1 reads the information described in the correspondence table 11152-1 of the ICS address management server 11150-1 using the ICS network communication function, and the conversion table prototype 11172- Write in 1. That is, write "7777" in the outgoing ICS network address field, "1111" in the sender ICS user address (inside the company) field, and "3333" in the sender ICS user address (between companies) field. If there is no ICS user address for in-house communication, the sender ICS user address (inside the company) field will be blank. Request identification shall be "2", which represents inter-company communication. The communication band condition is an example of speed class "3" and priority "3", and the electronic signature condition is "1" for signature specification, "YES" for transmission signature, and reception signature. This is an example in which the specification is specified as "NO". The billing condition is "4" in the billing class, and in this example, it represents billing by a flat rate system. The encryption condition is the encryption class "1". In this example, the ICS network frame is specified to be encrypted inside the ICS. The open class of this example is 0. In this example, the dynamic change class "6" can change the signature at the time of transmission at the request of the user.
【0333】
<< Use of ICS conversion table server (user) >> User 11132-1 uses "3333" as the sender ICS user address and "2100" as the recipient ICS user address of the ICS conversion table server 11170-1. Is written, and the ICS user frame F1200 in which the receiver information (recipient ICS user address or recipient ICS name) is written in the user data part of the ICS user frame is transmitted. The ICS conversion table server 11170-1 receives the ICS user frame F1200 via the access control device 11110-1, and whether the recipient information in the user data section is the recipient ICS user address or the recipient ICS name. Correspondingly, the incoming ICS network address for inter-company communication is acquired by the method described below. If the recipient ICS name is specified, the recipient ICS user address is further acquired.
【0334】
(When the recipient ICS user address is specified) When the recipient information is the recipient ICS user address "3800", the ICS conversion table server 11170-1 is the ICS address management server connected to the access control device 11110-1. Inquire 11150-1 using the ICS network communication function, and inquire and obtain the ICS network address "7600" (incoming ICS network address) corresponding to the ICS user address "3800". If the recipient ICS user address is not included in the correspondence table 11152-1 (ICS network address search failure), the ICS conversion table server 11170-1 will start from the ICS address management server 11150-11 "Search for ICS network address". Receive "Failure Notification".
【0335】
(When the recipient ICS name is specified) If the recipient information is the recipient ICS name "USR # 3.ACS # 3.DIS # 3.VAN # 3.JP.AS", the ICS conversion table server 11170- 1 uses the ICS network communication function to connect to the ICS name server 11160-1 connected to the same access control device 11110-1, with the ICS name "USR # 3.ACS # 3.DIS # 3.VAN # 3.JP. .AS is sent. The ICS name server 11160-1 holds the ICS network addresses of other ICS name servers corresponding to the ICS name (the leftmost part of the ICS name excluding USR # n). In this example, ICS The name server 11160-1 searches the ICS name conversion table 11162-1 and finds the ICS network address of the ICS name server 11160-2 that manages "ACS # 3.DIS # 3.VAN # 3.JP.AS". 8930 is found, the address 8930 is inquired using the ICS network communication function, and the ICS user corresponding to the ICS name USR # 3.ACS # 3.DIS # 3.VAN # 3.JP.AS Acquire the address "4200" (recipient ICS user address) and the ICS network address "8210" (incoming ICS network address). In this procedure, the ICS name server 11160-2 inquires of the ICS address management server 11150-2 for the ICS network address of the user 11132-2 and acquires the address "8210".
【0336】
(Completion of conversion table 11113-1) When the recipient ICS user address is specified, the ICS conversion table server 11170-1 converts the recipient ICS user address "3800" and the incoming ICS network address "7600" into conversion table 11113-1. Add and complete the receiving user-corresponding part of conversion table 11113-1. When the recipient ICS name is specified, the ICS conversion table server 11170-1 adds the recipient ICS user address "4200" and the incoming ICS network address "8210" to the conversion table 11113-1, and the conversion table 11113-1 Complete the part corresponding to the receiving user. If "Notification of ICS network address search failure" is received from ICS address management server 11150-1 or ICS name server 11160-1 in the above procedure, ICS conversion table server 11170-1 fails to add the conversion table. Is sent to the requesting user 11132-1.
【0337】
<< Other uses of the ICS conversion table server (user) >> User 11132-1 writes the ICS user frame in which the request notifying the contents of the individual user correspondence of the conversion table 11113-1 is written. By transmitting to 1, the user is requested to notify the individual contents of the user. Further, the user can request the rewriting of a part of the conversion table 11113-1 by using the dynamic change class previously agreed with the VAN operator by the above method. For example, the dynamic change class is 1,2, ..., the dynamic change class 1 is specified to increase the priority of each application user by 1, and the dynamic change class 2 is set to 1 priority. Decrease specification, dynamic change class 3 is specified to change the signature at the time of transmission to "YES" and the encryption class to "2".
【0338】
<< Use of conversion table >> How to use the conversion table created in the above procedure was explained in Example-1 and the like. In Example 1, a method of creating a temporary conversion table, that is, a method of creating a temporary conversion table when the access control device receives an ICS network frame and decapsulates the ICS and there is no conversion table has been described. On the other hand, in this example, the open area class of the conversion table is used. That is, when the access control device receives the ICS network frame and decapsulates the ICS, the received "pair of the incoming ICS network address and the outgoing ICS network address included in the network control unit of the ICS network frame" is converted. If it is not registered as "a pair of outgoing ICS network address and incoming ICS network address" in the table and the open area class is specified as "2", it is set in the temporary conversion table as in the above embodiment, but it is open. If the region class specification is "1", the temporary conversion table is not set. Furthermore, if the open class specification is "0", the temporary conversion table is not set and the received ICS network frame is discarded. In this case, the ICS user frame is not delivered to the user. That is, when the designation of the open class is "0", reception from an unknown sender not registered in the conversion table is rejected, and a so-called closed connection is realized. In the above, in the case of request identification "4", it is always treated as the designation "1" of the open area class. That is, it is not set in the temporary conversion table.
【0339】
<< Cutting out a closed network using an open class >> When communicating between companies A, B, and C, specify the open class of the IP terminals of these companies to be registered in the conversion table. Set all to "0". Then, all ICS user frames from unknown senders that are not registered in the conversion table are discarded by the access control device, so ICS user frames should be sent and received only between companies A, B, and C. become. In this sense, it is possible to construct a closed virtual closed network for these three companies, that is, to cut out the closed network. For one of the IP terminals of company A, if the open class of the conversion table is specified as "2", only this terminal receives the ICS user frame from an unknown sender, so the above It will be placed outside the closed network.
【0340】
<< Partial change (variation) of the embodiment >> In the above embodiment, the VAN operator uses the data passage 11153-1 and the data passage 11163-1 to use the ICS address management server 11150-1 and the ICS name server 11160. Explained how to enter the ICS address and ICS connection conditions in -1. The VAN operator creates a special ICS network server inside the ICS11000-1 without using these data paths, and from this special ICS network server, uses the ICS network communication function to create the ICS address management server 11150-11 and The ICS address, ICS connection conditions, etc. may be directly input to the ICS name server 11160-1 to rewrite the contents of the conversion table 11152-1 and the ICS name conversion table.
【0341】
Example-24 (ICS address name management server): As shown in FIGS. 91 and 92 of Example-23, the ICS address management server and the ICS name server are independent of each other, and each via an ICS network communication line. Is connected to the access control device. On the other hand, in this embodiment, as shown in FIG. 93, the ICS address name management server 13000-1,13000-2,13000-3,13000-4 inside the ICS13000-1 is the access control device 13010-1, respectively. It is connected to 13010-2,13010-3,13010-4. The ICS address name management server 13000-1 has a processing device 130001-1, and has the same functions as those included in the ICS address management server of Example-23. Correspondence table 13002-1 and the equivalent that the ICS name server includes. It has an ICS name conversion table 13003-1 that has a function, and is given an ICS network address "9801" that can be uniquely distinguished from others inside the ICS.
【0342】
Other ICS address name management servers 13000-2,13000-3,13000-4 also have the same functions as ICS address name management server 13000-1, including processing equipment, correspondence table and ICS name conversion table, respectively. They have ICS network addresses "9802", "9803", and "9804", respectively, and can communicate with each other using the ICS network communication function and exchange information held by other ICS address name management servers. The ICS address name VAN representative management server 13020-1 has an ICS network address "9805", and the other ICS address name VAN representative management server 13020-2 has an ICS network address "9806" and has an ICS network communication function. Can be used to communicate with a large number of ICS address name management servers and other ICS address name VAN representative management servers, and exchange their own information with each other. ICS address name VAN representative management server 13020-1 has processing device 13031-1 and database 13032-1, and exchanges information such as ICS address and ICS name with all ICS address name management servers inside VAN13000-1. , The collected ICS address and ICS name data are accumulated in database 13032-1, and VAN13030-1 is represented by performing the above procedure.
【0343】
The ICS address name management server includes a processing device, a correspondence table, and an ICS name conversion table. However, as another embodiment, the correspondence table and the ICS name conversion table may be combined into one table, and these may be combined. Only one of the ICS user addresses contained in both of the two types of tables needs to be used.
【0344】
Example-25 (Separation of functions of access control device): As shown in FIGS. 91 and 92 of Example-23, ICS address management server 11150-1, ICS name server 11160-1, and ICS conversion table server 11170-1. Are each connected to access control device 11110-1, and ICS encapsulation and ICS decapsulation are performed inside access control device 11110-1 using conversion table 11113-1. On the other hand, in this embodiment, the functions of the access control device 11110-1 are divided into the centralized access control device 14110-1 and a plurality of simple access control devices 14210-1,14210-2,14210-3. There is. That is, as shown in FIGS. 94 and 95, the access control device 11110-1 is a simple access control device 14210-1, 14210-2 via the ICS network communication lines 14190-1, 14190-2, 14190-3, respectively. , 14210-3 is connected. ICS address management server 14150-1, ICS name server 14160-1, ICS conversion table server 14170-1, ICS billing server 14180-1, electronic signature server 14181-1, encryption server 14182-1, operation management server 14183-1, The ICS network server 14184-1 is an aggregate access control device via the ICS network communication lines 14191-1, 14191-2, 14191-3, 14191-4, 14191-5, 14191-6, 14191-7, 14191-8, respectively. It is connected to 14110-1, and the conversion table 11113-1 inside the access control device 11110-1 is the aggregate conversion table 14113-1 and the simple conversion table 14213-1, 14213-2, It is divided into 14213-3. However, some of these aggregate conversion tables and simple conversion tables are duplicated. In other words, the four items of outgoing ICS network address, request identification, speed class, and priority are included in both of these conversion tables. The temporary partial conversion table 14214-1 is not essentially different from the temporary conversion table described in Example-1 and the like, but the items included in the temporary partial conversion table 14214-1 are included in the simple conversion table 14213-1. Same as the item. The line section 14211-1 inside the simple access control device 14210-1 has the same function as the line section 11111-1 inside the access control device 11110-1.
【0345】
The simple access control device 14210-1 uses the simple conversion table 14213-1 to perform ICS encapsulation at the time of transmission and ICS decapsulation at the time of reception. Is used to perform processing related to electronic signatures and billing as described above. In addition, both of these plurality of simple access control devices 14210-1,14210-2,14210-3 and the centralized access control device 14110-1 function together to perform the same functions as the access control device 11110-1. The user 14132-1 sends the ICS user frame F1300 having the sender ICS user address 3333 and the receiver ICS user address 4200 to the ICS logical communication line 14133-1. As shown in the flowchart of FIG. 96, the processing device 14212-1 of the simple access processing device 14210-1 receives the ICS user frame F1300 from the ICS logical terminal of the ICS network address 7777 of the line unit 14211-1 and ICS. Acquire the network address "7777" (step S2501) and check whether this address "7777" is registered as the virtual leased line connection "3" on the simple conversion table 14213-1 (step S2502). ). In this case, since it is not registered, the recipient ICS user address 4200 written on the ICS user frame F1300 corresponding to the ICS network address 7777 is acquired (step S2504), and this address 4200 is obtained. Is registered in the simplified conversion table 14213-1, and further checks whether the request identification is registered as inter-company communication 2 (step S2505). In this case, since it is registered, the incoming ICS network address 8210 is obtained from the simple conversion table 14213-1 in preparation for ICS encapsulation (step S2506).
【0346】
The simple access controller 14210-1 then generates an ICS network frame F1301 in which the speed class and priority are written based on the information obtained from the simple conversion table 14213-1 inside the ICS network frame. Encapsulate (step S2520) and send to the aggregate access controller (step S2521). Here, as described above, the information of the speed class 3, the priority 3, and the encryption class 0, which are the items of the simple conversion table 14213-1, is written in the extension part of the ICS network control unit.
【0347】
The centralized access control device 14110-1 receives the ICS network frame F1301 from the simple access control device 14210-1, and based on the fact that this ICS network frame F1301 passes through the centralized access control device 14110-11, the billing information frame FK01 Is created and sent to the billing server 14180-1. Information such as request identification, speed class, priority, billing class, and encryption class of the items registered in the aggregate conversion table 14113-1 is referred to in order to create the billing information frame FK01. The signature, the signature at the time of transmission, and the signature at the time of reception in the items of the aggregate conversion table 14113-1 are used to add the electronic signature, and as described in other embodiments, the electronic signature server 14181- Request 1 to digitally sign. Similarly, if the encryption class is specified as "1" which means encryption, it is requested to the encryption server 14182-1. When the above processing is completed, the centralized access control device 14110-1 sends the ICS network frame F1302 to another access control device 14110-2 or the centralized access control device via the ICS network communication line 14190-4. The format of the ICS network frame F1302 changes when the electronic signature server or encryption server operates, as described above, due to the addition of the electronic signature or conversion to the ciphertext. Equivalent to ICS network frame F1301. The simple access control device 14210-1 can be realized with almost no changes to the functions of the existing router. In addition, when the number of users accommodated in the simple access control device 14210-1 is small and the users are widely distributed in the region. Has an economic advantage that the total number of ICS address management server, ICS name server, ICS conversion table server, billing server, digital signature server, and encryption server can be reduced.
【0348】
The operation management server 14183-1 is assigned an ICS network address and is connected to the centralized access control device 14110-1 and the relay device. The ICS network communication function enables other operation management servers, access control devices, and ICS addresses. Exchanges information related to ICS operation such as communication status (communication congestion level, etc.) and failure information inside ICS with the management server.
【0349】
By the way, the open class of the items included in the simple conversion table 14213-1 inside the simple access control device 14210-1 is the treatment of the open class registered in the conversion table inside the access control device as described above. Used for the same process. That is, when the simple access control device 14210-1 receives the ICS network frame and decapsulates the ICS, the received "pair of the incoming ICS network address and the outgoing ICS network address included in the ICS network frame control unit" is displayed. In the encapsulation that is not registered as "pair of outgoing ICS network address and incoming ICS network address" in the simple conversion table 14213-1, that is, when the source of the received frame is not registered in the simple conversion table, the open class If the designation is "2", the temporary partial conversion table 14214-1 is set by the above method, but if the designation of the open area class is "1", the temporary partial conversion table is not set. Further, if the designation of the open class is "0", the temporary partial conversion table is not set and the received ICS network frame is discarded. This reconciliation does not send an ICS user frame to the user. 0 specified in the open area class rejects reception from an unknown source that is not registered in the simple conversion table, and realizes a so-called closed area connection.
【0350】
As described in the above embodiment, the ICS address management server and the ICS name server may be integrated, that is, a single ICS address name management server may be realized, and the aggregate access control device is the ICS address name management server. Used by connecting to an ICS network communication line. Further, in the above embodiment, the speed class and priority items are not provided in the simple conversion table 14213-1, and at the time of ICS encapsulation, the speed class and priority 0 are set in the extension part of the ICS network control unit. It may indicate that there is no writing or designation. Similarly, an example in which the open area class is not specified in the simple conversion table 14213-1 may be used. In this case, the speed class and priority 0 are written in the extension of the ICS network control unit to indicate that there is no specification. ..
【0351】
Example-26 (Access control device including server and centralized access control device): As shown in FIG. 97, ICS15000-1 is an access control device including a server 15110-1,15110-2,15110-3, a server. Includes Aggregate access control device 15210-1,15210-2,15210-3, Simple access control device 15213-1,15213-2,15213-3. In the examples of FIGS. 91 and 92, the ICS address management server 11150-1, the ICS name server 11160-1, and the ICS conversion table server 11170-1 are connected to the access control device 11110-1, respectively, and the examples of FIGS. 94 and 95 are shown. Then, ICS address management server 14150-1, ICS name server 14160-1, ICS conversion table server 1417O-1, billing server 14180-1, electronic signature server 14181-11, and encryption server 14182-1 are aggregate access control devices 14110, respectively. It is connected to -1. On the other hand, in this embodiment, as shown in FIG. 97, the access control device 15110-1 has the ICS address management server 15115-1, the ICS name server 15115-2, and the ICS name server 15115-2 inside the same physically independent housing. Includes ICS conversion table server 15115-3, ICS frame database server 15115-4, billing server 15115-5, operation management server 15115-6, electronic signature server 15115-7, and encryption server 15115-8. However, these servers are assigned ICS network addresses "6701", "6702", "6703", "6704", "670", "6706", "6707", and "6708", respectively. -By using the communication function, information can be exchanged with the ICS network server outside the access control device 15110-1 including the server. The processing device 15112-1 can exchange information with the servers 15115-1 to 15115-8 via the data line 15117-1. Further, these servers 1515-1 to 15115-8 can exchange information with each other via the data line 15117-1.
【0352】
Similarly, the centralized access control device 15210-1 including the server has an ICS address management server 15215-1, an ICS name server 15215-2, and an ICS conversion table server 15215-3 inside the same physically special chassis. , ICS frame database server 15215-4, billing server 15215-5, operation management server 15215-6, electronic signature server 15215-7, encryption server 15215-8. However, these servers are assigned the ICS network addresses "7001", "7002", "7003", "7004", "7005", "7006", "7007", and "7008", respectively. With the server communication function, information can be exchanged with the ICS network server outside the centralized access control device 15210-1 including the server. The processing device 15212-1 can exchange information with the servers 15215-1 to 15215-8 via the data line 15217-1. Further, the servers 15215-1 to 15215-8 can exchange information with each other via the data line 15217-1. In the above description, the same physically independent housing means, for example, a stand-alone computer, a single electronic board, or an LSI. In the case of LSI, the centralized access device including the server is realized as a system on the LSI chip.
【0353】
The ICS frame database server or other servers may be excluded from the "access control device including the server". Similarly, the ICS frame database server or other servers may be excluded from the "aggregated access control device including the server". In the case of each of these embodiments, for example, an access control device including an ICS frame database server and a server, or an aggregate access control device including a server is connected via an ICS network communication line.
【0354】
Example-27 (Incoming priority control): The control unit in the IP frame shown in FIG. 152 includes a source IP address and a destination IP address in addition to the protocol type, and TCP shown in FIG. 98. A source port number and a destination port number are defined inside the frame and the UDP frame shown in FIG. 99, respectively. The 48-bit data in which the IP address (32 bits) and the port number (16 bits) are arranged is called the socket number. That is, socket number = IP address The port number. In this embodiment, it is called source socket number = source IP address The source port number, destination socket number = destination IP address The destination port number. In this embodiment, the access control device is reached from the ICS network communication line, and the ICS user frame obtained by decapsulating the access control device is used for the "protocol type" and the socket number displayed inside the ICS user frame. This is an example of controlling the priority of the order of sending to the outside of ICS.
【0355】
<< Configuration >> As shown in FIGS. 100 and 101, the ICS17000-1 includes an access control device 17100-1,17110-1,17120-1,17130-1,17140-1,17150-1,17160-1. The access control device 17100-1 includes a line unit 17111-1, a processing device 17112-1, and a conversion table 17113-1. 17200-1,17210-1,17220-1,17230-1,17240-1,17250-1,17260-1,17270-1,17280-1 are LAΝ of each company, and their respective gateways 17201-1, It is connected to ICS17000-1 via 17211-1,17221-1,17231-1,17241-1,17251-1,17261-1,17271-1,17281-1. Each LAN contains 2 to 3 terminals that have the function of sending and receiving IP user frames, and these ICS user addresses are "2600" and "2610" inside LAN17200-1 and "1230" inside LAN17210-1. , "1240", LAN17220-1 inside is "2700", "2710" and "2720", LAN17230-1 inside is "2800" and "2810", LAN17240-1 inside is "2100" "And" 2110 ", the inside of LAN17250-1 is" 1200 "," 121O "and" 1220 ", the inside of LAN1726O-1 is" 2200 "and" 2210 ", and the inside of LAN17270-1 is" 2300 ". And "2310", and the inside of LAN17280-1 is "2400" and "2410". Furthermore, 17291-1 and 17292-1 are terminals that have the function of sending and receiving IP user frames, respectively, and each has an ICS user address. It has "2500" and "1250" and is connected to ICS17000-1.
【0356】
<< Conversion Table >> The conversion table 17113-1 inside the access control device 17100-1 will be described with reference to FIG. 102. The function of the conversion table is the same as that of other examples. In this example, the parts that are the components of conversion table 17113-1 named the incoming call priority symbol, protocol priority, TCP socket priority, and UDP socket priority. The feature is to control the priority using a table. If the outgoing ICS network address in the conversion table is "7821", the incoming priority symbol is defined as "pr-7821". That is, the incoming call priority is defined to be a parameter that depends on the ICS network address assigned to the ICS user logical terminal that the access control device sends after ICS decapsulation. Looking at the other subtables of conversion table 17113-1, for example, corresponding to "pr-7821", the protocol priority is "p-1", the TCP socket priority is "t-1", and the UDP socket priority. Is described as "NULL". Here, "NULL" represents no specification. The protocol priority "p-1" is defined as "TCP", "UDP", "ICMP", and "IGMP" in descending order of priority.
【0357】
Looking at the other subtables, the TCP socket priority "t-1" defines the socket symbols "sk-1" and "sk-7" in descending order of priority. UDP socket priority "u-" Looking at the other sub-tables, "1" defines "sk-3" and "sk-8" in descending order of priority. Furthermore, the socket symbol "sk-" written in the other sub-tables. In the content of "1", "To" indicates that the destination socket number, the destination IP address is "2100", the destination port number is "30", and similarly, the socket symbol "sk-2". In the content of "," "From" indicates that the source socket number is "1240" and the source port number is "32".
【0358】
<< Individual explanation of ICS frame >> After the ICS network frame NF01 is sent from the terminal 17291-1 with the ICS user address "2500", the access control device 17110-1 sends the outgoing ICS network address "7200" and the incoming ICS network address "7821". It is ICS-encapsulated as ", and is transferred inside the ICS17000-1 to reach the access control device 17100-1, where it is ICS de-encapsulated to become the ICS user frame UF01, and the user logical communication line 17821-1. Reach the terminal with ICS user address "2100" via. The "protocol type" of the control unit of the user frame UF01 inside the ICS network frame NF01 is TCP, and the "destination port number" of the TCP frame is an example of "30". NF03, NF04, NF05, NF06, NF07, NFO8, NF09, NF10, NF11 are the same as shown in Fig. 115, and will be briefly described below.
【0359】
The frame NF02 is sent from the terminal with the address "2600" and is ICS-encapsulated as the outgoing ICS network address "7300" and the incoming ICS network address "7821". It becomes UF02 and reaches the terminal with ICS user address "2110" via the user logical communication line 17821-1. This is an example where the "protocol type" of frame UF02 is TCP and the "destination port number" is "30".
【0360】
The frame NF03 is sent from the terminal with the address "1230" and is ICS-encapsulated as the outgoing ICS network address "7400" and the incoming ICS network address "7822". It becomes UF03 and reaches the terminal with ICS user address "1200" via the user logical communication line 17822-1. This is an example in which the protocol type of frame UF03 is TCP and the source port number is 30.
【0361】
The frame NF04 is sent from the terminal with the address "1240" and is ICS-encapsulated as the outgoing ICS network address "7400" and the incoming ICS network address "7822". It becomes UF04 and reaches the terminal with ICS user address "1210" via the user logical communication line 17822-1. This is an example in which the protocol type of frame UF04 is TCP and the source port number is 32.
【0362】
The frame NF05 is sent from the terminal with the address 1250 and is ICS-encapsulated as the outgoing ICS network address 7500 and the incoming ICS network address 7822. It becomes UF05 and reaches the terminal with ICS user address "1220" via the user logical communication line 17822-2. This is an example where the protocol type of frame UF05 is TCP and the source port number is 32.
【0363】
The frame NF06 is sent from the terminal with the address "2610" and is ICS-encapsulated as the outgoing ICS network address "7300" and the incoming ICS network address "7823". It becomes UF06 and reaches the terminal with ICS user address "2200" via the user logical communication line 17823-1. The "protocol type" of frame UF06 is UDP, and the "destination port number" is "40".
【0364】
The frame NF07 is sent from the terminal with the address "2700" and is ICS-encapsulated as the outgoing ICS network address "7600" and the incoming ICS network address "7823". It becomes UF07 and reaches the terminal with ICS user address "2210" via the user logical communication line 17823-1. The "protocol type" of frame UF07 is UDP, and the "destination boat number" is "40".
【0365】
The frame NF08 is sent from the terminal with the address "2710" and is ICS-encapsulated as the outgoing ICS network address "7600" and the incoming ICS network address "7824". It becomes UF08 and reaches the terminal with ICS user address "2300" via the user logical communication line 17824-1. The "protocol type" of frame UF08 is UDP, and the "source port number" is "40".
【0366】
The frame NF09 is sent from the terminal with the address "2800" and is ICS-encapsulated as the outgoing ICS network address "7700" and the incoming ICS network address "7824". It becomes UF09 and reaches the terminal with ICS user address "2310" via the user logical communication line 17824-1. The "protocol type" of frame UF09 is UDP, and the "source port number" is "42".
【0367】
The frame NF10 is sent from the terminal with the address "2720" and is ICS-encapsulated as the outgoing ICS network address "7600" and the incoming ICS network address "7825". It becomes UF10 and reaches the terminal with ICS user address "2400" via the user logical communication line 17825-1. This is an example where the protocol type of frame UF10 is TCP and the destination port number is 60.
【0368】
The frame NF11 is sent from the terminal with the address "2810" and is ICS-encapsulated as the outgoing ICS network address "7700" and the incoming ICS network address "7825". It becomes UF11 and reaches the terminal with ICS user address "2410" via the user logical communication line 17825-1. The "protocol type" of frame UF11 is UDP, and the "source port number" is "70".
【0369】
<< Example of Priority Determination >> The method of determining the priority will be described with reference to the flowchart of FIG. 103. The access control device 17100-1 receives the ICS network frames NF01 and NF02 from the ICS network communication line at approximately the same time (step S1000), and reverse-encapsulates each network frame to obtain the ICS user frames UF01 and UF02 (step). S1010). From the conversion table 17113-1, it can be seen that the incoming ICS network addresses of the ICS logical terminals that transmit these ICS user frames are both 7821 and match (step S1020). The incoming priority symbol for both ICS network frames NF01 and NF02 is "pr-7821", and then the protocol priority corresponding to "pr-7821" is "p-1" according to the subtable of conversion table 17113-1. , TCP socket priority is specified as "t-1", and UDP socket priority is specified as "NULL". Further examination of the other parts of the conversion table 17113-1 reveals that the protocol priority TCP, UDP, ICMP, IGMP have the highest priority from the breakdown of "p-1", and for TCP with the highest priority, the socket symbol "sk-1", from the breakdown of TCP socket priority "t-1", The priority is higher in the order of "sk-7", and from the breakdown of the socket symbol "sk-1", it can be seen that the IP address constituting the destination socket number is "2100" and the destination port number is "30". The protocol type displayed inside the ICS network frame NF01 is "TCP", the destination IP address is "2100", and the destination port number is "30". On the other hand, the protocol type displayed inside the ICS network frame NF02 is "TCP", the destination IP address is "2110", and the destination port number is "30". In this embodiment, it can be seen that it is the ICS network frame NF01 that the protocol type and the destination socket number match the designation of the socket symbol sk-1 described above. Through the above procedure, it is determined that the ICS network frame to be sent preferentially is NF01 (step S1030). Next, this ICS network frame NF01 is sent to the user logical terminal via the ICS logical terminal (step S1040).
【0370】
<< Example 2 of priority determination >> The access control device 17100-1 receives ICS network frames NF03, NF04, and NF05 from the ICS network communication line at approximately the same time (step S1000), and decapsulates each network frame. Obtain the ICS user frames UF03, UF04, UF05 (step S1010). From the conversion table 17113-1, it can be seen that the incoming ICS network addresses of the ICS logical terminals that transmit these ICS user frames are both 7822 and match (step S1020). The incoming priority symbol for ICS network frames NF03, NF04 and NF05 is "pr-7822", the protocol priority is "P-1", the TCP socket priority is "t-2", and the UDP socket priority is "NULL" is specified. Protocol priority From the breakdown of "p-1", TCP has a high priority, from the breakdown of TCP socket priority "t-2", the priority of socket symbol "sk-2" is high, and the breakdown of socket symbol "sk-2". It can be seen from that that the IP address that constitutes the source socket number is "2100" and the source port number is "30". The protocol type displayed inside the ICS network frame NF03 is "TCP", the source IP address is "1230", and the source port number is "30". The protocol type displayed inside the ICS network frame NF04 is "TCP", the source IP address is "1240", and the source port number is "32". Furthermore, the protocol type displayed inside the ICS network frame NF05 is "TCP", the source IP address is "1250", and the source port number is "32". In this embodiment, it can be seen that the protocol type and the source socket number match the designation of the socket symbol sk-2 in the ICS network frame NF04. By the above procedure, it is determined that the ICS network frame to be preferentially transmitted is NF04 (step S1030). Next, this ICS network frame NF04 is sent to the user logical terminal via the ICS logical terminal (step S1040).
【0371】
<< Example 3 of priority determination >> The access control device 17100-1 receives the ICS network frames NF06 and NF07 from the ICS network communication line at approximately the same time (step S1000), and decapsulates each network frame to the ICS user. Obtain frames UF06 and UF07 (step S1010). From the conversion table 17113-1, it can be seen that the incoming ICS network addresses of the ICS logical terminals that transmit these ICS user frames are both 7823 and match (step S1020). .. For both ICS network frames NF06 and NF07, the incoming priority symbol is "pr-7823", the protocol priority is "p-2", the TCP socket priority is "NULL", and the UDP socket priority is "u-1". Is specified. From the breakdown of protocol priority "p-2", UDP, TCP, ICMP, IGMP have the highest priority, and for the UDP with the highest priority, the socket symbol "sk-" from the breakdown of UDP socket priority "t-1". The priority is higher in the order of "3" and "sk-8", and from the breakdown of the socket symbol "sk-3", the IP address that constitutes the destination socket number is "2200" and the destination port number is "40". I understand. The protocol type displayed inside the ICS network frame NF06 is "UDP", the destination IP address is "2200", and the destination port number is "40". On the other hand, it is displayed inside the ICS network frame NF07. The protocol type is "UDP", the destination IP address is "2110", and the destination port number is "40". In this embodiment, the protocol type and the destination socket number match the designation of the socket symbol "sk-3". It can be seen that the ICS network frame NF06 is to be used. By the above procedure, it is determined that the ICS network frame to be sent with priority is NF06 (step S1030). Next, this ICS network frame NF01 is set. Send to the user logical terminal via the ICS logical terminal (step S1040).
【0372】
<< Example 4 of Priority Determination >> The access control device 17100-1 receives the ICS network frames NF08 and NF09 at approximately the same time (step S1000), and reverse-encapsulates each network frame to ICS user frames UF08 and UF09. (Step S1010). From the conversion table 17113-1, it can be seen that the incoming ICS network addresses of the ICS logical terminals that transmit these ICS user frames are both 7824 and match (step S1020). For both ICS network frames NF08 and NF09, the incoming priority symbol is "pr-7824", the protocol priority is "p-2", the TCP socket priority is "NULL", and the UDP socket priority is "u-2". Is specified. From the breakdown of the protocol priority "p-2", the priority of the socket symbol "sk-4" is high, and from the breakdown of the socket symbol "sk-4", the IP address that constitutes the source socket number is "2710". You can see that the source port number is "40". The protocol type displayed inside the ICS network frame NF08 is "UDP", the source IP address is "2710", and the source port number is "40". On the other hand, the protocol type displayed inside the ICS network frame NF09 is "UDP", the source IP address is "2800", and the source baud number is "42". In this embodiment, it can be seen that it is the ICS network frame NF08 that the protocol type and the source socket number match the designation of the socket symbol sk-4. Through the above procedure, it is determined that the ICS network frame to be sent preferentially is NF08 (step S1030). Next, this ICS network frame NF01 is sent to the user logical terminal via the ICS logical terminal (step S1040). << Example 5 of priority determination >> The access control device 17100-1 receives the ICS network frames NF10 and NF11 at approximately the same time (step S1000), and reverse-encapsulates each network frame to receive the ICS user frames UF10 and UF11. Get (step S1010). From the conversion table 17113-1, it can be seen that the incoming ICS network addresses of the ICS logical terminals that transmit these ICS user frames are both 7825 and match (step S1020). The incoming priority symbol for both ICS network frames NF10 and NF11 is "pr-7825", the protocol priority is "p-1", the TCP socket priority is "t-3", and the UDP socket priority is "u-3". Is specified. From the breakdown of protocol priority "p-1", TCP has a higher priority than UDP. However, the protocol type displayed inside the ICS network frame NF10 is "TCP", and the protocol type displayed inside the ICS network frame NF11 is "UDP". Through the above procedure, it is determined that the ICS network frame to be sent preferentially is NF10 (step S1030). Next, this ICS network frame NF10 is sent to the user logical terminal via the ICS logical terminal (step S1040).
【0373】
Example-28 (Outgoing priority control): An example in which a user IP frame arriving from outside the ICS is encapsulated in the ICS by an access control device and then the order of sending to the ICS network communication line is determined will be described.
【0374】
<< Configuration >> As shown in Fig. 104, the ICS17000-2 includes the access control device 17100-2,17110-2, ..., 17190-2, and the access control device 17100-2 includes the line section 17111-2 and the processing device. 17112-2, including conversion table 17113-2. 17240-2, ..., 17280-2 are corporate LANs, which are connected to ICS17000-2 via ICS user logical communication lines. Each LAN includes a plurality of IP terminals, and 17401-2 to 17411-2 are all IP terminals.
【0375】
<< Conversion table >> The functions of conversion table 17113-2 shown in Fig. 105 are the same as those of other examples. In this example, they are named outgoing priority symbol, protocol priority, TCP socket priority, and UDP socket priority. It is characterized by using the subtable which is a component of the conversion table 17113-2. If the outgoing ICS network address in conversion table 17113-2 is "7821", the outgoing priority symbol is defined as "ps-7821". That is, the outgoing priority is set to be a parameter depending on the network address assigned to the ICS logical terminal that accepts the user IP frame arriving at the access control device from the user logical communication line. Looking at the other subtables of conversion table 17113-2, for example, the protocol priority is "p-21", the TCP socket priority is "t-21", and the UDP socket priority is "ps-7821". It is described as "NULL". Notations such as protocol priority, TCP socket priority, and UDP socket priority are the same as in Example 32.
【0376】
<< Example 1 of Priority Determination >> A method of determining the priority will be described with reference to the flowchart of FIG. The access control device 17100-2 receives the ICS user frames F01 and F02 from the ICS logical terminal of the line unit 17111-2 to which the ICS network address "7821" is assigned at approximately the same time, and is assigned to the ICS logical terminal. Obtain the ICS network address (step S2700). Next, the procedure for controlling the outgoing priority is performed as follows. The outgoing priority symbol for both ICS user frames F01 and F02 is "ps-7821", and then the protocol priority corresponding to "ps-7821" is "p-21" according to the subtable of conversion table 17113-2. , TCP socket priority is specified as "t-21", and UDP socket priority is specified as "NULL". Further examination of other parts that are components of conversion table 17113-2 shows that TCP, UDP, ICMP, and IGMP have the highest priority in the order of protocol priority "p-21", and TCP has the highest priority. From the breakdown of TCP socket priority "t-21", the priority is higher in the order of socket symbols "sk-21" and "sk-27", and from the breakdown of socket symbol "sk-21", the source socket number It can be seen that the IP address that composes is "2100" and the source port number is "30". The protocol type displayed inside the ICS user frame F01 is "TCP", the source IP address is "2100", and the source port number is "30". On the other hand, the protocol type displayed inside the ICS user frame F02 is "TCP", the source IP address is "2110", and the source port number is "30". In this embodiment, it can be seen that it is the ICS user frame F01 that the protocol type and the source socket number match the designation of the socket symbol sk-21. Based on the above, it is determined that the ICS user frame to be encapsulated in ICS and sent with priority is F01 (step S2710). Next, whether or not the ICS network address 7721 assigned to the logical terminal that received the ICS user frame F01 is registered as the virtual leased line connection 3 on the conversion table 17113-2. Examine (step S2720). The following is shown in a series of steps S2730, ..., S2770 similar to those described in the other examples, and finally ICS encapsulation was performed (step S2780), and the ICS network obtained by encapsulation. Priority is given to frame NF01 and transmitted into ICS17000-2 (step S2790). << Another example of priority determination >> The access control device 17100-2 has almost the same ICS user frames F03, F04, and F05 from the ICS logical terminal of the line section 17111-2 to which the ICS network address "7822" is assigned. For example 2 of priority determination received at the time, the access control device 17100-2 sends ICS user frames F06 and F07 from the ICS logical terminal of the line section 17111-2 to which the ICS network address "7823" is assigned. Regarding Example 3 of priority determination received at approximately the same time, the access control device 17100-2 also receives an ICS user frame from the ICS logical terminal of the line section 17111-2 to which the ICS network address 7824 is assigned. For example 4 of priority determination in which F08 and F09 are received at approximately the same time, the access control device 17100-2 is further subjected to the ICS logical terminal of the line section 17111-2 to which the ICS network address 7825 is assigned. Example 5 of priority determination, which receives ICS user frames F10 and Fll at approximately the same time, is the same as example 1 of priority determination, as shown in the subtable which is a component of conversion table 17113-2. , The description is omitted.
【0377】
Example-29 (plural communication): This example is a new example configured by combining the above-mentioned Examples-2, -10, -18, and will be described with reference to FIGS. 102 to 109. ICS18000-1 includes access control unit 18140-1,18141-1,18142-1, 18143-1,18144-1 and the conversion table inside access control unit 18140-1 is 18195-1, access control unit 18141-1. The internal conversion table is 18196-1. Conversion table 18195-1 includes the specified values 1, 2, 3, and 4 for request identification, as in conversion table 6013-1, and corresponds to intra-company communication and inter-company communication. , Virtual leased line connection and ICS network server connection can be implemented inside one access control device. Conversion table 18196-1 shows only the specified value "3" for request identification, enabling virtual leased line connection.
【0378】
The ICS network server 18160-1 is connected to the access control device 18140-1 via the ICS network communication line. 18184-1 is an FR network or an ATM network, which corresponds to the FR network 1041 shown in Fig. 35 when 18184-1 is an FR network, and the ATM network shown in Fig. 35 when 18184-1 is an ATM network. Corresponds to 1042. The conversion units 18181-1 and 18182-1 correspond to the FR / ICS network frame conversion unit 1032-1 shown in FIG. 35 when 18184-1 is an FR network. Further, in the conversion units 18181-1 and 18182-1, 18184-1 corresponds to the ATM / ICS network frame conversion unit 1033-1 shown in FIG. 35 for the ATM network.
【0379】
LAN18110-1,18130-1 are connected to access control devices 18140-1 and 18142-1 via ICS user logical communication lines, respectively. The gateways 18171-1 and 18172-1 of LAN 18120-1 are connected to the access control device 18140-1 or 18141-1 via the ICS user logical communication line, respectively. LAN18120-1 includes a plurality of IP terminals 18121-1,18122-1,18123-1. Here, the IP terminal refers to a terminal having a function of sending and receiving IP user frames. The IP terminals 18150-1 and 18151-1 are connected via the access control device 18143-1, 18144-1 and the ICS user logical communication line, respectively. The ICS network communication line 18191-1 connects the conversion unit 18181-1 and the access control device 18141-1, and the ICS network communication line 18192-1 connects the conversion unit 18182-1 and the access control device 18142-1.
【0380】
When the ICS user frame transmitted from LAN18120-1 or LAN18110-1 reaches the access controller 18140-1, the request identification values 1, 2, 3, listed in the conversion table 18195-1 According to the control of "4", it is ICS-encapsulated to receive the communication service of intra-company communication, inter-company communication, virtual leased line, or ICS network server, but the details are explained in other examples. It is a street and is omitted. When the ICS user frame transmitted from the gateway 18172-1 reaches the access control device 18141-1, the communication service of the virtual dedicated line follows the control of the request identification value "3" shown in the conversion table 18196-1. It is encapsulated in ICS so that it can be received, via the ICS network communication line 18191-1, via the conversion unit 18181-1, further via the FR network or ATM network 18184-1, via the conversion unit 18182-1, and then through the ICS network. It is delivered to the access control device 18142-1 via the communication line 18192-1. Here, the FR network to the ATM network 18184-1 uses the function of the partner fixed connection (PVC), which is a known technology as the function of the FR network to the ATM network. By the procedure described above, transfer of ICS user frame is realized.
【0381】
<< Partial modification of the above embodiment: Variation >> This will be described with reference to FIG. 110. Like 8000-1800-1, the ICS18000-2 includes multiple access control devices and is connected to LAN and IP terminals through the access control devices. The FR network to ATM network 18184-1 in Fig. 107 is replaced with the FR network to ATM network 18200-2, and the access control device 18141-1, conversion unit 18181-1, ICS network communication line 18191-1 is replaced with the PVC interface conversion unit 18210-. Replaced with 2, access control device 18142-1, conversion unit 18182-1, ICS network communication line 18192-1 replaced with PVC interface conversion unit 18220-2, and gateways 18171-1 and 18172-1 were replaced with new gateway 18230- It is replaced with 2. Here, when 18200-2 is an FR network, the PVC interface conversion units 18210-2 to 18220-2 are functions for converting and inversely converting the ICS user frame to the FR frame format, and this conversion and inverse conversion function. Is as explained in Figure 39. If 18200-2 is an ATM network, the PVC interface converters 18210-2 to 18220-2 are functions that convert and reverse ICS user frames to the ATM frame format, and this conversion and reverse conversion function is available. As explained in FIG. 40. The transfer of ICS user frames by this variation is realized by using the function of the partner fixed connection (represented by PVC) by the FR network or the ATM network.
【0382】
Example-30 (Operation of Integrated Information and Communication System): This will be described with reference to FIGS. 111 and 112. ICS19000-1 is VAN19010-1, VAN19020-1, access control device 19300-1,19310-1, 19320-1,19330-1, relay device 19400-1,19410-1,1942O-1,19430-1, Includes inter-VAN gateway 19490-1, server equipment 19500-1,19510-1,19520-1,19530-1,19540-1. Each server device is assigned an ICS network address, and includes a plurality of ICS network servers inside each server device. These multiple ICS network servers are distinguished by the port number used in the TCP communication protocol and UDP communication protocol. The access control devices 19300-1, 19310-1, 19320-1, and 19330-1 are shown in the conversion tables 19301-1, 19311-1, respectively. Includes 19321-1 and 19331-1, including conversion table servers 19731-1,19732-1,19733-1,19734-1, respectively, and domain name servers 19741-1,19742-1,19743-1, respectively. 19744-1 is included, resource management servers 19751-1, 19752-1, 19753-1, 19754-1 are included, respectively, and relay device 19400-1 includes route information server 19761-1 and resource management server 19755-1. The relay device 19410-1 includes the route information server 19762-1, the relay device 19420-1 includes the route information server 19763-1, and the relay device 19430-1 includes the route information server 19764-1, and the server device 19500-1. Includes user service server 19711-1, ICS authority server 19721-1, server device 19510-1 includes centralized resource management server 19750-1, centralized route information server 19760-1, and server device 19520-1 is user service server. Including 19712-1, ICS authority server 19722-1, server device 19530-1 has ICS network server 19980-1 which has ICS user address "1200" and performs electronic library service, and ICS user address "1300". Including the ICS network server 19981-1 that provides travel guidance services, the server device 19540-1 is the centralized ICS authority server 19720-1, the centralized domain name server 19740-1, the centralized conversion table server 19730-1, and the centralized user service. Includes server 19710-1. The domain name server is a server having the same functions as the ICS address management server and the ICS name server described in the other examples, and has different functions, and the details of the functions are defined in this embodiment.
【0383】
The access control device, relay device, server device, and gateway between VANs described above are connected by the ICS network communication line 19040-1,19041-1,19042-1,19043-1, etc., and are connected to each other by using the ICS network communication function. Information can be exchanged. A server device is created, for example, by giving a computer an ICS network communication function, and a program that executes the server function runs inside the server device.
【0384】
19110-1 is an FR network, and conversion units 19111-1 and 19112-1 perform interface conversion between the communication line of the FR switching network and the ICS network communication line that transfers ICS network frames. It is the same as that described in the Example of. In addition, 19900-1 is an ATM network, and the conversion units 19901-1 and 19902-1 perform interface conversion between the communication line of the ATM switching network and the ICS network communication line that transfers ICS network frames. Is similar to that described in the other examples.
【0385】
Outside the ICS19000-1, LAN19600-1,19601-1, 19602-1,19603-1, 19604-1,19605-1, and IP terminals 19606-1, 19607-1 that have the function of sending and receiving ICS network frames. Is an example in which is connected.
【0386】
<< Hierarchical structure of ICS network server >> This will be described with reference to FIGS. 113 to 118. The centralized user service server 19710-1 is the user service server 19711-1, It has a higher control right in the sense of giving instructions to 19712-1 or making individual information reported, and the meaning of the higher control right is illustrated in a tree structure in FIG. 113. 19811-1 is a communication path for exchanging information between the centralized user service server 19710-1 and the user service server 19711-1, and consists of an ICS network communication line and a relay device. The same applies to the centralized ICS authority server 19720-1, the centralized conversion table server 19730-1, the centralized domain name server 19740-1, the centralized resource management server 19750-1, and the centralized route information server 19760-1, respectively. Shown in. In this embodiment, the tree structure of the server has two layers, but the number of access control devices, relay devices, server devices, etc. installed inside the ICS can be increased to three or more layers. The route information server has a function of transmitting and receiving the route table used in the relay device and the access control device inside the ICS. The resource management server is provided with management functions such as grasping the installation status and failure information of relay devices, access control devices, and server devices.
【0387】
<< Operation of ICS19000-1 by ICS operator >> ICS operators 19960-1 and 19961-1 are the centralized user service server 19710-1, the centralized conversion table server 19730-1, the centralized resource management server 1950-1, and the generalized. The operation of ICS19000-1 can be easily performed by giving an instruction such as starting operation to the route information server 19760-1 or making it report individual information.
【0388】
<< Management of ICS19000-1 by ICS officials >> ICS officials 19950-1 give instructions such as the start of operation to the central ICS authority server 19720-1 and the central domain name server 19740-1, or report individual information. It is possible to easily manage the address etc. used in ICS19000-1 by making it.
【0389】
<< Socket number and server >> The ICS network server has an ICS user address and an ICS network address, respectively, and each server has a port number specified by TCP or UDP communication protocol in addition to the ICS network address. Is an addition to the other embodiments. That is, each server is identified by a 32-bit ICS network address and a 16-bit port number, which is a total of 48 bits (this is called a socket number). Each server contains a program having a unique function that works inside the ICS19000-1, and some servers have an "operation interface" as described later. Here, the "operation interface" is a function for exchanging information with the operator via a keyboard or the like, and sending and receiving commands such as operation and operation start of each server function. Each server assigns an ICS network address to, for example, an access control device or a relay device, assigns different port numbers to a plurality of programs (that is, servers) inside these devices, and distinguishes them by socket numbers. Each server has an ICS network communication function as described in another embodiment, and can exchange information with each other using an ICS network address and a port number.
【0390】
<< Registration of user to ICS-1: Inter-company communication and ICS network server >> This will be explained with reference to FIGS. 111, 112, and 119. ICS19000-1 user applicant 19200-1 applies for ICS subscription to ICS receptionist 19940-1 (procedure P100). "Application acceptance data" is an ICS usage item excluding the ICS user address ICS network address and ICS name. For example, request identification (intra-company communication, inter-company communication, virtual leased line connection, classification of ICS network server) and speed. Communication band conditions such as class and priority, billing conditions, open connection conditions, fee payment methods, user address and name (identification card), signature conditions, encryption conditions, etc., and the meaning of these usage items is other implementation. It is explained by an example.
【0391】
The ICS receptionist 19940-1 inputs the application reception data to the user service server 19711-1 via the operation interface, and stores the application reception data in the user database 19611-1 (procedure P110). Next, the user service server 19711-1 requests the ICS authority server 19721-11 for its ICS user address, ICS network address, and ICS name using the ICS network communication function (procedure P120). The ICS authority server 19721-1 holds the requested ICS address and ICS name inside the database 19621-1. ICS network address allocation record table 19622-1 (Fig. 120), ICS user address allocation. Allocation is performed using the record table 19623-1 (Fig. 121) (procedure P130), the allocation result is recorded in the allocation table, and the allocation result is returned to the user service server 19711-1 (procedure P140). The user service server 19711-11 stores the allocation result obtained from the ICS authority server 19721-1 in the user database 19611-1 (procedure P150).
【0392】
Figure 135 is an example of the ICS network address allocation record table 19622-1. In the first row of this table, the ICS network address 7700 is specified as the node identification symbol ACU-1 ICS logical terminal identification symbol LT-. Assigned to 001, the allocation destination identification symbol is user-1, the allocation date is an example of April 1, 1998, and it is predetermined that the node identification symbol ACU-1 points to the access control device 19300-1. There is. In the third row of this table, the ICS network address "9630 is assigned to the port number" 620 "of the node identification code SVU-1, the allocation destination identification code is Sv-001, and the allocation date is 98. This is an example of February 1, 2014, and it is predetermined that the node identification symbol SVU-1 refers to the server device 19530-1.
【0393】
Figure 121 is an example of the ICS user address allocation record table. In the first row name of this table, the ICS user address 4610 and the ICS name (also called the ICS domain name) ddl.ccl.bbl.aal. The assignment of "jp", the value of the request identification is "2", the allocation destination identification symbol is user-1, and the allocation date is April 1, 1998. Furthermore, in the 4th row of this table, the ICS name "rrl.qq.pp.jp" was assigned to the ICS user address "1200", and the request identification value is "4". The identification code is Sv-001, and the allocation date is February 1, 1998.
【0394】
The user service server 19711-1 converts the application details of the user applicant 19200-1 and the acquired ICS network address via the ICS network communication function so as to write them in the conversion table 19301-1 inside the access control device 19300-1. Provide information to the table server 19731-1 (procedure P160). The contents to be provided are registration in the conversion table described in other examples such as outgoing ICS network address, sender ICS user address, request identification, speed class, priority, signature condition, cryptographic condition, open class, etc. It is an item. The above-mentioned ICS network address and ICS user address are registered as the outgoing ICS network address and the sender ICS user address when the request identification value is "2", that is, in the case of inter-company communication. If the request identification value is "4", that is, if it is an ICS network server, it is registered as an incoming ICS network address and a recipient ICS user address. The conversion table server 19731-1 adds the above contents to the conversion table 19301-1 (procedure P170). The incoming ICS network address and the recipient ICS user address are not registered in the conversion table 19301-1 at this point, but are registered in the conversion table 19301-1 in "Registration of communication partner" described later in this embodiment.
【0395】
Next, the conversion table server 19731-1 notifies the ICS domain name server 19641-1 of the ICS network address, ICS user address, and ICS name (procedure P180). The ICS domain name server 19741-1 writes and holds the received ICS network address, ICS user address, and ICS name in its internal database 19641-1 (procedure P190), and notifies the conversion table server 19731-1 of the completion of writing. Report (Procedure P200). The conversion table server 19731-1 confirms this report (procedure P210), reports the end of the series of procedures to the user service server 19711-1 (procedure P220), and the user service server 19711-1 confirms this report. (Procedure P230), inform the user of the ICS user address and ICS name that are the assignment results (Procedure P240) .. Since the ICS network address is used only inside ICS, it will not be notified to the applicant. Also, in the case of an ICS network server, that is, when the request identification value is "4", the user service server 19711-1 notifies all conversion table servers inside ICS19000-1 in step P160, and all access. Request registration in the conversion table of the controller.
【0396】
<< Management of conversion table rewriting by the integrated conversion table server >> This will be described with reference to the lower procedures P800 to 960, Fig. 111, Fig. 112, and Fig. 115 in Fig. 119. The centralized conversion table server 19730-1 instructs the conversion table server 19731-1 to rewrite the contents of the conversion table 19301-1, such as speed class priority, outgoing ICS network address, and some or all other items in the conversion table. (Procedure P800), the conversion table server 19731-1 modifies the contents of conversion table 19301-1 according to this instruction (procedure P810). In addition, the domain name server 19741-1 is instructed to rewrite the ICS network address, etc. (procedure P820), the domain name server 19741-1 updates its internal table according to this instruction (procedure P830), and the result is converted to the conversion table server 19731. Report to -1 (procedure P840), confirmed by conversion table server 19731-1 (procedure P850), and report to general conversion table server 19730-1 (procedure P860). In addition, the integrated conversion table server 19730-1 instructs the user service server 19711-1 to rewrite the contents of the user database 19611-1 such as speed class, ICS network address, and other items (procedure P900). The user service server 19711-1 updates the contents of the user database 19611-1 according to this instruction (procedure P910). In addition, the ICS authority server 19721-1 is returned with the unnecessary ICS network address, ICS user address, and ICS name, or a new request is sent (procedure P920), and the ICS authority server 19721-1 follows this instruction to perform the ICS. Update the network address allocation record table 19622-1 and the ICS user address allocation record table 19623-1 (procedure P930), report the result to the user service server 19711-1 (procedure P940), and report the result to the user service server 19711-1. Confirms (Procedure P950) and reports to the integrated conversion table server 19730-1 (Procedure P960).
【0397】
In the above description, the integrated conversion table server 19730-1 first calls the user service server 19711-1 to execute the procedures P900 to P960, and secondly calls the conversion table server 19731-1 to perform the procedure. You can also run P800 to P860. Therefore, the ICS operator 19960-1 instructs the centralized conversion table server 19730-1 to rewrite the contents of the access control table, so that the conversion table inside the access control device and its accompanying conversion table are attached. By exchanging information with the domain name server and ICS authority server that manage address information, etc., it is easy to manage rewriting of consistent conversion table contents, that is, update management of all conversion tables of the access control device inside ICS19000-1. Can be done.
【0398】
<< User communication partner registration >> This will be described with reference to FIG. 125. The ICS19000-1 user applicant 19200-1 applies to the ICS receptionist 19940-1 with the domain name of the communication partner to register as a communication partner (procedure P300). The ICS receptionist 19940-1 accepts the domain name of this communication partner (procedure P310) and sends it to the conversion table server 19731-1 (procedure P320). The conversion table server 19731-1 exchanges information with the domain name servers 19740-1, 19742-1, etc. (procedures P330, P331), and exchanges the ICS network address and ICS user address corresponding to the domain name of the inquired communication partner. Obtain it, update the contents of conversion table 19301-1 (procedure P340), and report the result (procedure P350, P360). The updated results are shown in Conversion Table 19301-2. The ICS network address acquired here is an incoming ICS network address, and the ICS user address is a recipient ICS user address, which are registered in the conversion table as shown in FIG. 141. The fields for the ICS network server, the incoming ICS network address, and the recipient ICS user address remain blank.
【0399】
<< Registration of user to ICS-2: In-house communication and virtual leased line >> This is explained with reference to Fig. 127. The difference between intra-company communication and the above-mentioned inter-company communication is that you cannot submit an ICS user address and you cannot use an ICS name, so there is no ICS name assigned and you use an ICS name. The point is that the procedure (procedure equivalent to P180, P190, P200) does not exist. First, the ICS19000-1 user applicant 19200-1 applies to the ICS receptionist 19940-1 to join ICS (procedure P400). The application acceptance data is ICS usage items excluding the ICS network address and ICS name. For example, ICS user address, for example, request identification (intra-company communication, inter-company communication, virtual leased line connection, classification of ICS network server), The speed class and priority are the same as those for inter-company communication. As the ICS user address, one or more sets of both the sender ICS user address and the receiver ICS user address are presented. Further, in the case of a virtual leased line connection, it is different from the case of in-house communication that the sender ICS user address and the receiver ICS user address are not presented.
【0400】
The ICS receptionist 19940-1 inputs the "application reception data" to the user service server 19711-1 via the operation interface, and stores the "application reception data" in the user database 19611-1 (procedure P410). .. Next, the user service server 19711-1 requests the ICS authority server 19721-1 for its ICS user address, ICS network address, and ICS name using the ICS network communication function (procedure P420). The ICS authority server 19721-1 allocates only the ICS network address in the same manner as in the above procedure P130 (procedure P430), records the allocation result in the allocation table, and returns the assigned result to the user service server 19711-1. (Procedure P440). The user service server 19711-1 stores the allocation result obtained from the ICS authority server 19721-1 in the user database 19611-1 (procedure P450).
【0401】
When the user service server 19711-1 notifies the conversion table server 19731-1 of the application contents and the acquired ICS network address (procedure P460), the conversion table server 19731-1 is registered in the conversion table 19301 (procedure P370). ), Report the completion of registration (procedures P480, P495). FIG. 128 shows an example in which in-house communication and virtual leased line are registered in conversion table 19301.
【0402】
<< Explanation of domain name server >> In the explanation of Fig. 125, the procedure for the domain name server P330 and P331 will be described with reference to Fig. 129 as an example of four layers. The ICS network address in Table 19600-1 inside the domain name server for the domain name "root" is "9500", and the domain names "al", "a2", "a3" ... exist under it. However, for example, it indicates that the ICS network address where the domain name server that handles the domain name "a1" is located is "9610" and the port number is "440". The ICS network address in Table 19610-1 inside the domain name server for the domain name "a1" is "9610", and the domain names "bl", "b2", "b3" ... exist under it. However, for example, it indicates that the ICS network address where the domain name server that handles the domain name "b2" is located is "9720" and the port number is "440".
【0403】
The ICS network address in Table 19620-1 inside the domain name server for the domain name "b2" is "9720", and the domain names "c4", "c5", "c6" ... exist under it. However, for example, the domain name "c5" does not have a domain name below it because the end point column is displayed as "YES". In this example, the ICS network address corresponding to the ICS name "c5.b2.al." Is "9720", indicating that the ICS user address is "4510". In addition, the records in the internal table 19620-1 of the domain name server, that is, a set of data including the combination of the ICS name (ICS domain name), the ICS network address, and the ICS user address "4610", is particularly the "domain name server". Called "resource record".
【0404】
<< Calling the domain name server >> Refer to Figure 133, the conversion table server 19630-1 calls the domain name servers 19640-1, 19650-1,19660-1 and the domain name c5.b2.al. The procedure for searching the ICS network address and the ICS user address corresponding to the above will be described. The conversion table server 19630-1 inputs the domain name c5.b2.al. In the resolver 19635-1 inside this conversion table. When the resolver 19635-1 uses the ICS network communication function to send an ICS frame 19641-1 containing "al" to the ICS domain name server 19640-1, the ICS network address "9610" of the ICS domain name server for "a1" An ICS frame 19642-1 containing is returned. Next, when the resolver 19635-1 sends the ICS frame 19651-1 containing "b2" to the ICS domain name server 19650-1, the ICS frame containing the ICS network address "9720" of the ICS domain name server for "b2". 19652-1 is returned.
【0405】
Next, when the resolver 19635-1 sends an ICS frame 19661-1 containing "c5" to the ICS domain name server 19660-1, the ICS containing the ICS network address "9820" and the ICS user address "4520" of "c5". Frame 19662-1 is returned. Through the above procedure, the conversion table server 19630-1 acquires the ICS network address "9820" and the ICS user address "4520" corresponding to the domain name "c5.b2.al.".
【0406】
<< Rewriting the conversion table from the IP terminal >> This will be explained with reference to FIGS. 134 and 135. Send an ICS user frame containing the domain name c5.b2.al from the IP terminal 19608-1 to the conversion table server 19731-1 (procedure P500). The conversion table server 19731-1 queries the domain name server (procedure P510), and the domain name server searches for the ICS network address "9820" and the ICS user address "4520" corresponding to the domain name "c5.b2.al". (Procedure P520) and reply to the conversion table server 19731-1 (Procedure P53O), the conversion table server writes to the conversion table 19301-1 (Procedure P540) and reports to the IP terminal 19608-1 (Procedure P550). ). In this procedure, the ICS network address "9820" is the incoming network address, the ICS user address "4520" is the recipient ICS user address, and the rewritten conversion table is shown in FIG. 138. Note that FIG. 123 omits the contents of the conversion table corresponding to the request identification included in FIG. 122.
【0407】
Next, the IP terminal 19608-1 transmits an ICS user frame including a specification for changing the speed class to 2 for the registered contents of the conversion table 19301-1X to the conversion table server 19731-1 (procedure P600). The conversion table server 19731-1 rewrites the registered contents of the conversion table 19301-1X to the speed class "2" (procedure P610) and reports it to the IP terminal 19608-1 (procedure P620). It is rewritten by this procedure. The conversion table is shown in 19301-Y (Fig. 124).
【0408】
<< Movement of terminals between access control devices >> ICS user address allocation record As seen in the example of Table 19623-1, the first row of this table is the ICS name (ICS) in the ICS user address "4610". It is characterized by assigning "dd1.cc1.bb1.aa1.jp" (also called a domain name) and holding the ICS user address and ICS name. For example, move the terminal 19608-1 (Fig. 111) having the ICS user address 4610 from the access control device 19300-1 to the access control device 19320-1 (Fig. 112), for example, to give this terminal a new ICS network address. When "7821" is assigned, the outgoing ICS network address "7821" and the sender ICS user address "4610" are registered as a pair inside the conversion table 19321-1. In this case, the ICS name "dd1.cc1.bb1.aa1.jp" is paired with the ICS user address "4610" as specified in the ICS user address allocation record table 19623-1, and the ICS name. Will not change. The resource record including the combination of the ICS name "dd1.cc1.bb1.aa1.jp" inside the domain name server, the ICS network address "7700", and the ICS user address "4610" is the ICS name "dd1.cc1". It will be changed to ".bb1.aa1.jp", ICS network address "7821", and ICS user address "4610". In other words, the ICS network address 7700 is rewritten to another address 7821, but the ICS name dd1.cc1.bb1.aa1.
【0409】
(Other Examples: Determination of ICS User Address by User) In the above embodiment, the user is modified to determine the ICS user address. That is, when a user (user (applicant 19200-1) applies for use to ICS19000-1, the ICS user address is added. The ICS receptionist 19940-1 newly includes the ICS user address in the application reception data. In addition, the ICS authority server 19711-1 stores the ICS user address provided by the user in the ICS user address allocation table 19623-1. By the above method, the user can determine his / her own ICS user address, and the degree of freedom is improved.
【0410】
Example-31 (Calling a communication partner by telephone number): In this embodiment, by using a telephone number as an ICS domain name, it is possible to send and receive an ICS user IP frame with the communication partner, and inside the user IP frame. An example is shown in which digitized voice is stored, which enables public communication by telephone. In this embodiment, the telephone number "81-3-1234-5678" in Tokyo, Japan will be regarded as the domain name "5678.34.12.3.81". Here, "3" represents Tokyo and "81" represents Japan.
【0411】
This will be described with reference to FIG. 136. ICS20000-1 is an access control device 20010-1,20020-1,20030-1, a relay device 20080-1,20090-1, domain name server 20110-1, 20120-1, 20130-1, 20140-1, 20150- 1 is included, and the access control device 20010-1 includes a line unit 20011-1, a processing device 20012-1, a conversion table 20013-1, and a conversion table server 20040-1. The conversion table server 20040-1 is inside the access control device 20010-1, and the ICS network address is "7800" and the port number is "600". The conversion table server 20040-1 is given an ICS user address "4600" from the outside of ICS20000-1. When a domain name is entered, it is converted to an ICS user address and returned, and the ICS network address is used as an access control device. It looks like an ICS server that has the function to register in the conversion table 20013-1 inside 20010-1.
【0412】
20210-1 is a LAN, 20211-1 and 2030-1 are IP terminals that have the function of sending and receiving ICS user frames, and have ICS user user addresses "4520" and "1200", respectively, and ICS user logical communication. It is connected to ICS20000-1 via a line. Since the IP terminal 20300-1 can be used as a telephone, it is called an IP telephone. The IP telephone 20300-1 includes a telephone number input unit 20310-1, an IP address storage unit 20320-1, a voice data transmission / reception unit 20330-1, an input button 20340-1, and a voice input / output unit 20350-1.
【0413】
<< Acquisition of ICS user address by telephone number >> Enter the telephone number "1234-5678" from the input button 20340-1 to the telephone number input section 20310-1. The telephone number input unit 20310-1 generates the ICS user frame P1201 and delivers it to the access control device 20010-1 via the ICS user logical communication line. Here, the ICS user frame P1201 is the sender ICS user address 1200 and the receiver ICS user address 4600, and the data part includes the telephone number 1234-5678 input from the input button 20340-1. Is done. The processing device 20010-1 sees the conversion table 20013-1 and sends the ICS user frame P1201 to the conversion table server 20040-1 pointed to by the ICS user address 4600. In the case of this embodiment, since the conversion table server 20040-1 is inside the access control device 20010-1, it is not necessary to use the ICS network communication function. The conversion table server 20040-1 makes inquiries to the domain name servers 20130-1,20140-1,20150-1 one after another based on the telephone number "1234-5678" included in the data part of the ICS user frame P1201 and makes a phone call. Acquires the ICS network address "7920" and ICS user address "4520" of the communication partner terminal 20211-1 when the number "1234-5678" is regarded as the domain name.
【0414】
Next, the conversion table server 20040-1 creates a new conversion table item 20030-1 using the two addresses "7920" and "4520" acquired here, and for the ICS user address "4520", the ICS user frame P1202. Is generated, the ICS user address "4520" is written in it, and it is sent to the IP telephone 20300-1. The IP telephone 20300-1 is stored in the IP address storage unit 20320-1 by combining the ICS user address 4520 included in the received ICS user frame P1202 and the telephone number 1234-5678 inquired at the beginning. It will be retained and used at a later date when the ICS user address "4520" corresponding to the telephone number "1234-5678" is needed. The above-mentioned conversion table new item 20030-1 is the IP telephone 20300-1 having the ICS network address "7820" and the ICS user address "1200", and the destination terminal 20211-1 specified by the telephone number "1234-5678". To relate to. Conversion table new item 20030-1 is used as a new element in conversion table 20013-1.
【0415】
<< Communication using ICS user address >> Voice is input from the voice input / output unit 20350-1, the voice is converted into digital data by the voice data transmission / reception unit 20330-1, and stored in the ICS user frame P1210. It is transmitted to the destination specified by the telephone number "1234-5678", that is, to the terminal 20211-1 of the destination determined by the ICS user address "4520" by the same principle as described in other embodiments. After that, telephone communication is performed between the two terminals 20211-1 and 20211-1 by sending and receiving ICS user frames.
【0416】
<< Detailed explanation of domain name server >> In the above explanation, the conversion table server presents the telephone number "1234-5678" to the domain name server and acquires the ICS network address "7920" and the ICS user address "4520". I will explain in detail how to do it.
【0417】
FIG. 137 is a diagram showing an example of a domain name tree having 6 layers based on an international telephone number. A root domain name root-tel is provided at level 1 of the tree, and a lower level thereof is provided. There is a domain name "1" ... "44" ... "81" ... "90" ... at level 2 of the tree, and then, for example, a level 3 domain name under the domain name "81".3" "6 exists, then, for example, a level 4 domain name under the domain name 3" "11, 12, 13 exists Then, for example, there are level 5 domain names "33", "34", "35", ... under the domain name "12", and then under the domain name "34", for example. It indicates that level 6 domain names ... "5677", "5678", "5679" ... exist.
【0418】
Figure 138 shows the internal table 20131-1 of the domain name server 20130-1 that handles the domain name 3. For example, the domain server 20140-1 that handles the domain name 12 under the domain name 3. It indicates that the ICS network address is "8720" and the port number is "440". FIG. 139 shows the internal table 20141-1 of the domain name server 20140-1 that handles the domain name 12. For example, the domain server 20150-1 that handles the domain name 34 lower than the domain name 12. It indicates that the ICS network address is "8820" and the port number is "440". In addition, Fig. 140 shows the internal table 20151-1 of the domain name server 20150-1 that handles the domain name 34. For example, for the domain name 5678, the end point column of the internal table 20151-1 is displayed as Since it is "YES", the lower domain name does not exist. In this example, the ICS network address corresponding to the domain name "5678.34.12.3.18." Is "8920" and the ICS user address is "4520". It is shown that.
【0419】
<< Calling the Domain Name Server >> See Figure 141, where the translation table server 20040-1 calls the domain name servers 20130-1, 20140-1, 20150-1 and the domain name 5678.34.12.3.81. The procedure for searching the ICS network address and ICS user address corresponding to "" will be described. Here, the resolver 20041-1 holds the ICS network address of the domain name server that handles the level 1 domain root-tel shown in FIG. 138. In addition, when communicating with domain name servers that handle Level 2 and Level 3 domains, the ICS network address of the domain name server on the upper side is stored inside Resolver 20041-1.
【0420】
The conversion table server 20040-1 inputs the domain name "5678.34.12." In the internal resolver 20041-1. Resolver 20041-1 holds the ICS network address "8610" of the server in charge of the domain name "3.81." Pointing to Tokyo "3" of Japan "81", and uses the ICS network communication function to use the domain name "3.81." When the ICS frame 20135-1 including the domain name "12" under "3" is sent to the ICS domain name server 20130-1, the ICS network address "8720" of the ICS domain name server 20140-1 that handles the domain name "12" Reply ICS frame 20136-1 including. Next, when the resolver 20041-1 sends an ICS frame 20145-1 containing the domain name 34 to the ICS domain name server 20140-1, the ICS network address 8820 of the ICS domain name server that handles the domain name 34 Reply ICS frame 20146-1 including.
【0421】
Next, when the resolver 20041-1 sends the ICS frame 20155-1 including the domain name 5678 to the ICS domain name server 20150-1, the ICS network address 7920 corresponding to the domain name 5678 and the ICS user Returns the ICS frame 20156-1 containing the address 4520. Through the above procedure, the conversion table server 20040-1 acquires the ICS network address "7920" and the ICS user address "4520" corresponding to the domain name "5678.34.12.3.81.".
【0422】
<< Telephone line connection >> There is a telephone line conversion unit 20510-1 inside the line unit 200011-1, and the telephone 20520-1 is connected to the telephone line conversion unit 20510-1 via the telephone line 20530-1. The telephone line conversion unit 20510-1 has the same function as described in other embodiments, and converts the voice transmitted from the telephone line 20530-1 into digitized voice and stores it in the data unit. Generate an ICS user frame. In the opposite transmission direction, that is, the ICS user frame sent from within the ICS network and passing through the access control line section, the digitized voice stored in the data section is analogized in the telephone line conversion section 20510-1. It is converted to voice, or in the case of an ISDN line, it is converted to its digitized voice. Because of this, the IP terminal 20300-1 to which the ICS domain name is assigned and the telephone 20520-1 can communicate with each other by telephone voice.
【0423】
(Connection to the public telephone network) Furthermore, the telephone line conversion unit 20510-1 and the private branch exchange 20600-1 are connected by the telephone line 20530-2. Telephones 20520-2 and 20520-3 are connected from the private telephone line 20540-1 from the private branch exchange 20600-1, for example, telephone communication is possible between the telephone 20520-2 and the IP telephone 20300-1. It is possible. In addition, it can be connected to the public telephone network or the international telephone network 20680-1 from the private branch exchange 20600-1 via the telephone line 20670-1. Because of this, telephone communication is possible between the telephone 20520-4 and the IP telephone 20300-1.
【0424】
Example-32 (IP terminal capable of connecting to multiple access control devices): In this example, an IP terminal having a function of sending and receiving ICS user IP frames is not fixed to a specific access control device, but other access. It realizes the use of mobile IP terminals that can be used by connecting to control devices, that is, roaming. Roaming is realized based on the ICS domain name given to the IP terminal. In the following description, aTheb represents data (concatenated data) obtained by arranging data a and data b side by side.
【0425】
<< Password transmission technique by encryption >> In this embodiment, the procedure of encrypting the secret password PW and transmitting it from the sender (encryption side) to the recipient (decryption side) is included, and the beginning. The encryption function Ei and the decryption function Di will be explained in. The encryption function Ei is represented by y = Ei (k1, x), and the decryption function Di is represented by x = Di (k2, y). Here, y is the ciphertext, x is the plaintext, kl, k2 is the encryption key, and i is the encryption number (i) that determines how to use the private key cryptography or public key cryptography, including the value of the encryption key. = 1,2, ...). In the above, the plaintext x'is encrypted as x'= xTher (where r is a random number) instead of the plaintext x, and the random number r is discarded from the plaintext x'obtained at the time of decryption to obtain the plaintext x. Is also good. In this way, even if the same plaintext is encrypted, different ciphertexts are generated due to random numbers, and it is said that the ciphertext is resistant to decryption.
【0426】
(Example of code number i = 1) << Preparation >> Sender m publishes his domain name (represented by DNm) including the recipient. The recipient calculates Km = Hash-1 (DNm) using the secret data compression function Hash-1, and hands only the encryption key Km to the sender in a secure way that is unknown to a third party. This example is an example of adopting DES encryption, and the sender holds the "encryption module DES-e" and the encryption key Km to realize the encryption function Ei. The encryption key Km is a secret value shared by the sender and the receiver. The receiver holds a "decoding module DES-d" for realizing the decoding function Di and a data compression function Hash-1. What is used as the data compression function Hash-1 is determined for each encryption number value. The data compression function is also called a hash function.
【0427】
<< Encryption by sender >> The sender sets the secret password PW as x = PW, and sets y = DES-e (Km, x) by the encryption module DES-e and the holding encryption key Km. Encrypt and send the ciphertext y and the domain name DNm.
【0428】
<< Decryption by recipient >> The recipient receives the ciphertext y and the domain name DNm, and uses the recipient's secret data compression function Hash-1 to set Km = Hash-1 (DNm) as the secret cipher. The key Km is calculated, and then the receiver uses the decryption module to get the plaintext x as x = DES-d (Km, y). Plaintext x is the password PW, and the recipient can obtain the secret password PW. Since the third party does not know the data reduction function Hash-1, the encryption key Km cannot be calculated, and therefore the secret password PW cannot be calculated. In the above embodiment, as a rule of the encryption number i = 3, the encryption function or the decryption function can be changed to the encryption function or the decryption function other than the DES encryption.
【0429】
(Example of code number i = 2) << Preparation >> This example is an example of adopting RSA encryption, and the recipient is the encryption function y = x.<sup>e</sup>modn and decryption function y = x<sup>d</sup>Generate mod n. Here, e d and the key d is a secret value. The recipient can publish the encryption keys e and n, and the encryption function y = x.<sup>e</sup>Pass the encryption module RSA-e that realizes modn to the sender. Sender Keep these encryption keys and the encryption module RSA-e. The sender does not keep any secret cryptographic modules or secret data. On the other hand, the recipient has n and the secret key d, and the decryption function y = x.<sup>e</sup>It holds the decryption module RSA-d that realizes mod n.
【0430】
<< Encryption by sender >> Set the secret password PW you want to send, your domain name DNm, and the date and time of transmission (year, month, day, hour, minute, second) x = PWThex1Thex2 (where xl: domain name DNm) , X2 = year, month, day, hour, minute, second) by the encryption module RSA-e, y = x<sup>e</sup>Encrypt as mod n and send the ciphertext y.
【0431】
<< Decryption by recipient >> The recipient receives the ciphertext y and uses the decryption module RSA-d and the decryption key that it holds in advance to x = y.<sup>d</sup>Calculate mod n. Since x = PWThex1Thex2, the data at a predetermined position from the beginning of x is used as PW. In the above encryption, xl of the domain name and x2 of the year, month, day, hour, minute, and second are used as random numbers. Since the third party does not know the secret key d, the secret password PW cannot be calculated. In the above embodiment, the values of the encryption keys e, d, and n can be changed as the specification of the encryption number i = 4. In addition, the RSA cryptographic technique can be used as another public key cryptographic technique as a rule of the encryption number i = 5.
【0432】
<< Terminal authentication technique using password and random number >> This section describes the terminal authentication technique for checking whether the password PW used in the roaming terminal matches the password registered in the authentication server. As a prerequisite, the authentication server of the authentication subject and the terminal of the authenticated person have the encryption function E (provided that y = E (k,). In x), y is the ciphertext, k is the encryption key, x is the plaintext), and a third party has a secret password PW. The specific procedure of terminal authentication will be described. The terminal to be authenticated determines the random number R by an appropriate means, calculates Y1 = F (PW, R) using the password PW and the function y = F (PW, R), and calculates both the random numbers R and Y1. Send to the certifier. The authentication subject receives the random numbers R and Y1 and calculates Y2 = F (FW, R) using the received random numbers R, the password FW held by itself, and the function F, and Y1 = Y2 is established. Check if it is. If they match, the owner of the terminal as the person to be authenticated uses the correct password PW, that is, the terminal can be authenticated. In the above technique, by limiting the random number R to a time-dependent random number (called a time random number) so that the person to be authenticated cannot freely select it, it becomes more difficult for a third party to calculate the password PW. .. Instead of the encryption function used above, the secret data compression function Hj may be used and Y1, Y2 = Hj (PW, R) may be used.
【0433】
<< Overall configuration >> Figures 142 and 143 outline the roaming technique according to this example, and ICS21000-1 is the access control device 21010-1, 21020-1, 21030-1, 21040-1. , 21050-1, 21060-1, relay device 21080-1, 2108I-1, 21082-1, 21083-1, authentication server 21100-1, 21101-1, 21102-1, 21103-1, domain name server 21130- Includes 1, 21131-1, 21132-1, 21133-1, User Service Server 21250-1, and ICS Authority Server 21260-1. The access control device 21010-1 includes the conversion table 21013-1, the conversion table server 21016-1, the registration server 21017-1, and the connection server 21018-1, and the access control device 210720-1 includes the conversion table 21023-1 and the conversion table server. Includes 21026-1, registration server 21027-1, and connection server 21028-1. The ICS user address "6300" is assigned to the registration servers 21017-1 and 21027-1. The connection server 21018-1 and 21028-1 are given the ICS user address "6310", and the access control device determined according to the need is IP from the roaming IP terminal outside the ICS21000-1. It has a function to register or connect to a terminal.
【0434】
It will be explained in another embodiment that the conversion table server 21016-1 has a function of rewriting the contents of the conversion table 21013-1 and the conversion table server 21026-1 has a function of rewriting the contents of the conversion table 21023-1. It is the same as. In addition, LAN21150-1 includes an IP terminal 21151-1, LAN21160-1 includes an IP terminal 21161-1, and 21170-1 is an IP terminal. 21200-1 is a mobile roaming terminal and is identified by the ICS domain name "cl.bl.al.", which is the only one given as ICS21000-1.
【0435】
<< Application for use of roaming terminal >> The owner of roaming terminal 21200-1 specifies the payment method for roaming terminal 21200-1 as ICS application applicant 21270-1, and goes through the user service server 21250-1. Apply for the ICS domain name (same as the ICS name) and ICS user address to the ICS authority server 21260-1. The charge payment method is represented by the charge category "MNY". For example, when MNY = 1, the charge is the home IP terminal (that is, the IP terminal that is fixedly connected to the access control device). When paying with, and MNY = 2, specify that the fee will be paid according to the record of the authentication server. The ICS authority server 21260-1 defines the ICS domain name cl.bl.al. and the ICS user address 1200 for using the roaming terminal 21200-1. In addition, the owner of the IP terminal 21200-1 goes to the ICS authority server 21260-1 via the user service server 21250-1 to use the IP terminal 21200-1 in a fixed connection to the access control device 21010-1. Apply for an ICS network address. When the user service server 21250-11 acquires the ICS network address, it requests the conversion table server 21016-1 to set the ICS network address "8115" and the ICS user address "1200" in the conversion table 21013-1. This procedure is described in other embodiments.
【0436】
The ICS receptionist 21271-1 has an ICS domain name cl.bl.al., an ICS user address 1200, and a special ICS user address for the roaming terminal (roaming) on the internal 2201-1 of the roaming terminal 21200-1. (Special number) "1000", ICS user address "6300" of registration server, ICS user address "6310" of connection server are embedded, and encryption function Ei and encryption related data RP1 are embedded in internal 21202-1 of roaming terminal 21200-1. Embed. Do not embed hash functions. Here, RP1 = Hj (domain name TheRP0) TheRP0 (where RP0 = MNYTheiThej), the domain name is cl.bl.al., and MNY is the above-mentioned billing category, i. Is the cipher number for classifying the cipher Ei, and "j" determines the type of the hash function Hj. The data compression function Hj is a secret dedicated function used only by the authentication server and user service server. Since the user does not have the data compression function Hj and does not know Hj, the cryptographic data RP1 cannot be generated.
【0437】
<< Registration procedure from home IP terminal >> This will be explained with reference to Fig. 159. The roaming terminal user connects the roaming terminal 21200-1 to the position of the home IP terminal 21151-1. Next, the roaming terminal user decides the password (PW) and inputs it from the input unit 21204-1, and also uses the encryption function and sound number related data stored inside 21202-1 to input the ICS user frame PK01. Generate and send to access controller 21010-1 via ICS user logical communication line 21152-1 (procedure T10). The destination of the ICS user frame PK01 is "6300" pointing to the roaming registration server, its own ICS domain name "cl.bl.al.", cryptographic parameters RP1, ICS user address "1200", expiration date "98-12-" Includes 31 , the ciphertext y that encrypts the password, tg (however, tg = 1 to display the registration procedure), and Yes or No for the roaming connection specification. Here, the above-mentioned encryption technique is adopted as the method of generating the ciphertext y. For example, when the code number = 2, y = x<sup>e</sup>Generate the ciphertext y as mod n (where x = PWThec1.bl.a1The year, month, day, hour, minute, and second). The access control device 21010-1 sees the conversion table 21013-1 and transfers the ICS user frame PK01 to the registration server 21017-1 of the destination 6300 (procedure T15). The registration server 21017-1 calls the authentication server 21100-1 using the domain name c1.b1.a1 (procedure T20). The method in which the registration server 21017-1 calls the authentication server 21100-1 using the domain name is the same as the method in which the connection server 21028-1 calls the authentication server 21100-1 using the domain name. Will be described later. The authentication server 21100-1 examines the contents of PK01 of the received ICS user frame, decrypts the ciphertext "y" by the above-mentioned technique, and calculates the password PW. For example, when the code number = 2, x = y<sup>d</sup>Decrypt the ciphertext "y" as mod n. Then, since x = PWThec1.bl.a1The year, month, day, hour, minute, and second, the password PW can be obtained.
【0438】
Next, since the content of the cryptographic parameter PP1 is RP1 = Hj (domain name TheRPO) TheRPO (however, RPO = MNYTheiThej), the secret held by the authentication server 21100-1 itself. Calculate t = Hj (domain name TheRP0) TheRP0) using the hash function Hj and the obtained domain name cl.bl.al, and determine whether t = RP1 holds for the received RP1. Find out. If it is established, it is judged that the domain name "cl.bl.al", the billing category MNY, and the encryption numbers "i" and "j" have not been tampered with. The authentication server 21100-1 checks whether there is any excess or deficiency in the registered contents, and if it is normal, registers the registration result in the authentication table 21100-2, and does not register the deficiency.
【0439】
This situation is shown in the line of control number 1 in the authentication table 21100-2, and the domain name is "cl.bl.al.", the encryption number is "2", and the billing classification (MNY) is "1". The password PW value is "224691", the expiration date is "98-12-31", and the roaming connection is "Yes", which means that the roaming connection is accepted. When generating PK01 in step T10, the roaming connection may be specified as No with the value of tg described above being tg = 2. By applying the above-mentioned cryptographic technique, the password will not be leaked to a third party. The roaming registration report is reported to the roaming IP terminal via the registration server 21017-1 (procedure T30) and then through the access control device 21010-1 (procedure T35) (procedure T40). In addition, the ICS user frame that changes the password PW value with tg = 3 or changes the expiration date value with tg = 4 from the terminal 21200-1 via the ICS user logical communication line 21152-1 is described above. It can be sent after step T40 is complete. To change the password, a method of specifying the password used before that can also be adopted.
【0440】
<< User IP frame transmission / reception at the destination >> Connect the roaming terminal 21200-1 to the access control device 21020-1, and connect the roaming terminal 21200-1 with the domain name "cl.bl.al." An example of inter-company communication that sends and receives IP frames to and from the domain name c2.b2.a2. Will be described. The user specifies the domain name "c2.b2.a2." Of the communication partner, "tg" with tg = 5 to specify the transmission / reception of IP frames, his / her own password PW, and the roaming connection period. Enter the 5 day (represented by TTL) from the input section 21204-1. For this purpose, 21201-1 and 21202-1 inside the roaming terminal 21200-1 are used. The IP frame unit 21203-1 is used to generate and send / receive ICS user IP frames PK01, PK02, PK03, PK04, and the like.
【0441】
Next, the roaming terminal 21200-1 generates the user IP frame PK02 and sends it to the access controller 21020-1 via the ICS user logical communication line 21210-1 (procedure T50). The user IP frame PK02 includes the sender domain name cl.bl.al., the recipient domain name c2.b2.a2., The cryptographic parameter RP2, and the connection period (expressed in TTL). The cryptographic parameter RP2 is the data calculated inside the password PW and 21202-2. In other words, the year, month, day, second "yy-mm-dd-sssss" is generated to make the time random number TR (TR = yy-mm-dd-sssss), and the internal clock of 21202-2 and the cryptographic function Ei are used. RP2 = Ei (PW, TR) The TR is calculated.
【0442】
The access control device 21020-1 receives the user IP frame PK02, acquires the ICS network address "7800" assigned to the ICS logical terminal, the request identification is "4" according to the conversion table 21023-1, and the user. Since the sender ICS user address written in the IP frame PK02 is "1000" (that is, the roaming special number), the ICS network address "7800" is retained, and the receiver ICS user address is retained together with the ICS user frame PK02. Deliver to the connection server 21028-1 pointed to by 6310 (step T60). The ICS network address "7800" held in this procedure will be used after the procedure T130 described later.
【0443】
<< Function of Connection Server >> Next, Connection Server 21028-1 calls the authentication server 21100-1 using the domain name c1.b1.a1, and the domain name cl.bl.al. and the encryption parameters. Transfer RP2 to the authentication server (step T70). The authentication server 21100-1 reads the password PW and the value of the encryption number written in the authentication table 21100-2, selects the encryption function Ei, and reads the password PW. Next, since the cryptographic parameter RP2 is RP2 = Ei (PW, TR) TheTR, t = Ei (PW, TR) is calculated using the time random number TR in the latter half of RP2. If the value of the temporary variable t calculated here matches the received Ei (PW, T) in the first half of RP2, it can be confirmed that the password PW input to the terminal 21200-1 is correct. Since the time function TR contains the date (that is, TR = yy-mm-dd-sssss), fraud can be detected when the received date does not match the processing time.
【0444】
Next, the authentication server 21100-1 reports the roaming registration, billing classification, and authentication server call information described in the authentication table 21100-2 to the connection server 21028-1 (procedure T80). In the case of this embodiment, the billing category is MNY = 1, and the authentication server call information consists of the ICS network address "7981" of the authentication server 21100-1, the port number "710", and the management number "1" of the authentication management table. .. Connection server 21028-1 presents the domain name cl.bl.al. to the domain name server and requests the ICS user address and ICS network address associated with this domain name (step T90), and the ICS user address Obtain 1200 and ICS network address 8115 (step T100). Similarly, present the domain name c2.b2.a2. To the domain name server, request the ICS user address and ICS network address associated with this domain name (step T110), and enter the ICS user address 2500. Get the ICS network address "8200" (Procedure T120). The access to the domain name server described above is the same as that described in detail in other examples.
【0445】
Next, the connection server 21028-1 has the ICS network address 7800 of the ICS logical terminal that entered the ICS user frame (held in step T60), the ICS user address 1200 obtained from the domain name server immediately before, and ICS. User address "2500", ICS network address "8200", and more The roaming registration, billing classification, and authentication server call information transmitted from the certificate server 21100-1 are transmitted to the conversion table server 21026-1 (procedure T130). The conversion table server 2120-6 writes the four transmitted addresses to the conversion table 21023-11. The value of request identification is "10", that is, it represents inter-company communication by roaming. When the billing category is MNY = 1, the ICS network address "8115" and the ICS user address "1200" obtained from the domain name server immediately before are posted to the billing notification destination in the conversion table 21023-1. If the billing category is MNY = 2, the authentication server call information is posted to the billing notification destination in conversion table 21013-1. Furthermore, the roaming connection period specification "5" days included in the ICS user frame PK02 is also written in the conversion table 21013-1. The conversion table server 21026-1 reports the result to the connection server 21028-1 when the writing of the conversion table 21023-1 is completed (procedure T140). This completion report is sent to the roaming terminal 21200-1 via the access control device 21020-1 (procedure T150) and the ICS user frame PK03. (Procedure T160). Here, the ICS user frame PK03 is set to the ICS user address "1200" attached to the domain name "cl.bl.al." of the roaming terminal 21200-1 and the domain name "c2.b2.a2." Of the communication partner. Includes the accompanying ICS user address "2500". The operating company of the access control device uses the connection server 21028-1 described above, that is, a series of procedures from receiving the ICS user frame PK02 to returning the ICS user frame PK03, and specifying the roaming connection period. The usage fee can be charged to the owner of roaming terminal 21200-1 for 5 "days.
【0446】
<< Use of roaming terminal >> The roaming terminal 21200-1 can perform inter-company communication as described in other examples by using the conversion table 21023-1 created according to the above procedure. Yes (procedures T170-T220). Further, the conversion table server 21026-1 can delete the roaming connection written inside the conversion table 21023-1 after the roaming connection period designation "5" is passed.
【0447】
<< Notification of billing >> The access control device 21020-1 notifies the billing notification destination registered in the conversion table 21023-1 (procedure T300 or T310).
【0448】
<< How to access the authentication server >> In the above explanation, the connection server 21028-1 presents the domain name "cl.bl.al." to multiple authentication servers including the authentication server 21100-1 and roams. Whether the authentication request included in the ICS network frame PK02 generated by terminal 21200-1 is correct, that is, whether the domain name "c1.bl.al." of roaming terminal 21200-1 is registered in the authentication server. I will explain in detail how to check.
【0449】
FIG. 160 is a diagram showing an example of a domain name tree having four layers. A root domain name root is provided at level 1 of the tree, and domain names al, a2, are provided at level 2 of the tree below it. A3 ... exists, then level 3 domain names bl, b2, b3 exist under the domain name al, and then, for example, the domain name bl. It indicates that level 4 domain names cl, c2, c3, etc. exist at the lower level.
【0450】
Figure 146 shows the internal table 21102-2 of the authentication server 21102-1 that handles the domain name root. For example, the domain server 21101-1 that handles the domain name al under the domain name root. It indicates that the ICS network address is "7971" and the port number is "710". In addition, FIG. 146 shows the internal table 21101-2 of the authentication server 21101-1 that handles the domain name al. For example, the domain server 21100- that handles the domain name b1 under the domain name a1. It indicates that the ICS network address of 1 is "7981" and the port number is "710".
【0451】
Figure 148 shows the internal table 21100-2 of the authentication server 21100-1 that handles the domain name bl. For example, for the domain name cl, the display of the end point column of the internal table 21100-2 is YES. Since there is no lower domain name, in this example the domain name "cl.bl.al." is registered in the authentication server, the password PW is "224691", and the expiration date is "98-12-". 31 etc. are recorded.
【0452】
<< Calling the Authentication Server >> See Figure 149, where Connection Server 21028-1 calls Authentication Server 21100-1 with the domain name c1.b1.a1 and the domain name cl.bl.al. Describes how to check whether "." Is registered in the authentication server. Here, the connection server 21028-1 holds the ICS network address of the authentication server that handles the level 1 domain root shown in FIG. 160 inside. Also, when communicating with authentication servers that handle Level 2 and Level 3 domains, the ICS network addresses of these authentication servers are also held.
【0453】
Connection server 21028-1 inputs the domain name "c1.bl.al" to the internal resolver 21029-1. When the resolver 21029-1 uses the ICS network communication function to send the ICS frame 21335-1 containing the domain name al under the domain name root and the encryption parameter RP2 to the authentication server 21102-1, the domain name Returns the ICS frame 21336-1 including the ICS network address "7971" of the authentication server 21101-1 that handles "a1". Next, when the resolver 21029-1 sends the ICS frame 21345-1 containing the domain name bl to the authentication server 21101-1, the resolver 21029-1 includes the ICS network address 7981 of the authentication server that handles the domain name bl. Reply frame 21346-1. Next, when the resolver 21029-1 sends the ICS frame 21355-1 containing the domain name cl to the authentication server 21100-1, the end point column of the domain name cl, in this case 21100-2, is Yes. Therefore, it can be determined that the authentication information is registered. As mentioned above, since the procedure is done in the order of root, a1., Bl, the authentication information for the domain name cl.bl.al. which is the reverse of these is shown in the internal table 21100-. You can see that it is registered in 2.
【0454】
The authentication server 21100-1 checks the received cryptographic parameter RP2 and checks that the expiration date "98-12-31" has not passed. Next, the authentication server 21100-1 reads the password PW and the value of the encryption number written in the authentication table 21100-2, and selects the encryption function Ei. Since the cryptographic parameter RP2 is RR2 = Ei (PW, TR) TheTR, t = Ei (PW, TR) is calculated using the time random number TR in the latter half of RP2. If the value of the temporary variable t calculated here matches the received Ei (PW, TR) in the first half of RP2, it is confirmed that the password PW input to the terminal 21200-1 is correct. Report the above results to Connection Server 21028-1. As a result, the connection server 21028-1 knows the authentication result (pass or fail) of the roaming terminal and the billing classification MNY.
【0455】
<< Other examples of roaming without a home IP terminal >> In the above examples, if the ICS receptionist 21271-1 does not set a home IP terminal, the above-mentioned "Registration procedure from a home 1 P terminal" is performed by the user. Performed via service server 21250-1. This reconciliation includes the billing record "120" inside the authentication table 21100-2 inside the authentication server 21100-1 and the authentication server information "7981-710-1" shown in the billing notification destination inside the conversion table 21023-1. Is used.
【0456】
<< Another example of roaming that includes the authentication server in the domain name server >> The domain name tree in Fig. 145, which is the target of the authentication server 21110-1, is the domain that is the target of the domain name server as shown in other examples. It has the same structure as the name tree. Therefore, each domain server can store the data of the authentication server described in this embodiment and include the function of the authentication server. That is, another method of roaming is to integrate the authentication server described in this embodiment and the domain name server described in other examples.
【0457】
<< Access control device and IP terminal connected to wireless transmitter / receiver >> The wireless transmitter / receiver 21620-1 is installed inside the ICS21000-1, and the wireless transmitter / receiver 21620-1 and the wireless transmitter / receiver 21640-1 are wireless. Information can be exchanged with each other via the communication path 21625-1. The terminal 21630-1 includes a wireless transmitter / receiver 21640-1, and the terminal 21200-2 has a function of inter-company communication using an ICS domain name like the above-mentioned IP terminal 21200-1. There is an information communication path 21620-1 between the access control device 21020-1 and the wireless transmitter / receiver 21620-1. The information communication path 21610-1 is similar to the ICS user logical communication line in that it has a function of transmitting and receiving IC user frames, and the difference is that the information communication path 21610-1 is inside the ICS21000-1. The wireless transmitter / receiver 21620-1 and the wireless transmitter / receiver 21640-2 receive the ICS user frame, convert the internal information of the ICS user frame into the ICS user frame information in the radio wave format, and transmit it, and vice versa. It has a function of receiving ICS user frame information in radio wave format, converting it back to the ICS user frame format, and sending it out. Therefore, the ICS user frame transmitted from the IP terminal 21200-2 uses the wireless transmitter / receiver 21640-1, the wireless communication path 21625-1, the wireless transmitter / receiver 21620-1, and the information communication path 21610-1. Then, it is transmitted to the access control device 21020-1. In the opposite direction, that is, the ICS user frame transmitted from the access control device 21020-1 passes through the information communication path 21610-1, the wireless transmitter / receiver 21620-1, the wireless communication path 21625-2, and the wireless transmitter / receiver 21640-1. Delivered to IP terminal 21200-2.
【0458】
[Effect of the invention]
As described above, according to the present invention, it is not necessary to use an expensive dedicated line, a high-speed communication line used for moving image communication such as a TV is not provided, or a person in charge of a communication line facility expansion plan. It is possible to construct a relatively inexpensive large-scale communication system without using the Internet, which is absent. In addition, there is an advantage that inter-company communication can be performed as well as intra-company communication with almost no change in the private address system for computer communication of individual companies (including government agencies and universities) that have been individually serviced in the past. .. Furthermore, since the network administrator has the control right of the network, the management of the failure countermeasures of the entire network becomes clear, it becomes easy to secure the reliability, and the eavesdropping prevention measures can be taken by the encrypted communication inside the ICS. Is. In addition, since the network itself can optionally add a digital signature to the ICS frame, tampering with the ICS frame can be detected and information security is significantly improved. According to the present invention, by a single information transfer (transfer of IP datagram) that does not depend on services such as voice, image, and text, services that have been conventionally provided individually such as a telephone line service and an Internet provider service are mutually provided. It is possible to realize an integrated information communication system connected to.
[Simple explanation of drawings]
[Figure 1]
It is a block diagram which shows typically the basic principle of this invention.
[Figure 2]
It is a block diagram which shows the network example which made up the ICS of this invention by a plurality of VANs.
[Fig. 3]
It is a block diagram which shows the configuration example of an access control device.
[Fig. 4]
It is a block diagram which shows the configuration example of a relay device.
[Fig. 5]
It is a block diagram which shows the configuration example of the gateway between VANs.
[Fig. 6]
It is a block diagram which shows the configuration example of an ICS network server.
[Fig. 7]
It is a sequence diagram which shows an example of the ICS user address used in this invention.
[Fig. 8]
It is a wiring diagram which shows the connection relationship between an ICS logical terminal and a user communication line.
[Fig. 9]
It is a figure which shows the relationship between the ICS user frame and the ICS network frame used in this invention.
[Fig. 10]
It is a part of the block block diagram which shows 1st Example (intra-company communication, inter-company communication) of this invention.
[Fig. 11]
It is a part of the block block diagram which shows 1st Example of this invention.
[Fig. 12]
It is a flowchart which shows the operation example of an access control device.
[Fig. 13]
It is a flowchart which shows the operation example of the access control device in inter-company communication.
[Fig. 14]
It is a block block diagram which shows the 2nd Example (virtual exclusive line) of this invention.
[Fig. 15]
It is a flowchart which shows the operation example of the access control device in virtual exclusive line connection.
[Fig. 16]
It is a block block diagram which shows 3rd Example (ICS network server) of this invention.
[Fig. 17]
It is a flowchart which shows the operation example in the access control device in the server connection in an ICS network.
[Fig. 18]
It is a block diagram for demonstrating the modification of the said 3rd Example.
[Fig. 19]
It is a block block diagram which shows 4th Example (ICS address management server) of this invention.
[Fig. 20]
It is a flowchart which shows the operation example of the ICS address management server.
[Fig. 21]
It is a block diagram for demonstrating the modification of the said 4th Example.
[Fig. 22]
It is a block block diagram which shows 5th Example (ICS name server) of this invention.
[Fig. 23]
It is a flowchart which shows the operation example of the ICS name server.
[Fig. 24]
It is a block diagram for demonstrating the modification of the said 5th Example.
[Fig. 25]
It is a part of the block block diagram which shows 8th Embodiment (billing server) of this invention.
[Fig. 26]
It is a part of the block block diagram which shows 8th Example of this invention.
[Fig. 27]
It is a flowchart which shows the operation example of the billing process.
[Fig. 28]
It is a part of the block block diagram which shows the 9th Example (ICS frame database server) of this invention.
[Fig. 29]
It is a part of the block block diagram which shows the 9th Example of this invention.
[Fig. 30]
ICS frame is a diagram showing an example of an ICS user frame used in a database server.
[Fig. 31]
It is a flowchart which shows the operation example of the communication example-1 of the ICS frame database server.
[Fig. 32]
It is a flowchart which shows the operation example of the communication example-2 of the ICS frame database server.
[Fig. 33]
It is a flowchart which shows the operation example of the communication example-3 of the ICS frame database server.
[Fig. 34]
It is a part of the block block diagram which shows the tenth embodiment (X.25, FR, ATM, transmission by satellite communication and telephone line, ISDN line, CATV line, satellite line, accommodation of IPX frame) of this invention.
[Fig. 35]
It is a part of the block block diagram which shows the tenth embodiment of this invention.
[Fig. 36]
It is a part of the block block diagram which shows the tenth embodiment of this invention.
[Fig. 37]
It is a part of the block block diagram which shows the tenth embodiment of this invention.
[Fig. 38]
It is a figure which shows the state of the ICS network frame and the frame conversion of the X.25 format.
[Fig. 39]
It is a figure which shows the state of the frame conversion of ICS network frame and FR format.
[Fig. 40]
It is a figure which shows the state of the frame conversion of ICS network frame and ATM format.
[Fig. 41]
It is a part of the block block diagram which shows the eleventh embodiment of the present invention (transmission by X.25, FR, ATM, satellite communication and telephone line, ISDN line, CATV line, satellite line, accommodation of IPX frame).
[Fig. 42]
It is a part of the block block diagram which shows the eleventh embodiment of this invention.
[Fig. 43]
It is a part of the block block diagram which shows the twelfth embodiment of this invention (the access control device is housed in an X.25 network, an FR network).
[Fig. 44]
It is a part of the block block diagram which shows the twelfth embodiment of this invention.
[Fig. 45]
It is a part of the block block diagram which shows the thirteenth embodiment of this invention (the access control device is connected to a relay network).
[Fig. 46]
It is a block block diagram which shows the 14th Example of this invention (when the access control device is installed outside the ICS).
[Fig. 47]
It is a part of the block block diagram which shows 15th Example (non-ICS encapsulation of inter-company communication) of this invention.
[Fig. 48]
It is a part of the block block diagram which shows the 15th Example of this invention.
[Fig. 49]
It is a flowchart which shows the operation example of the non-ICS encapsulation of the intercompany communication.
[Fig. 50]
It is a figure which shows the format example of the NSAP format ATM address.
[Fig. 51]
It is a figure which shows the information unit of the ATM cell format.
[Fig. 52]
It is a figure for demonstrating the conversion / restoration between an ICS network frame and a CPCS frame.
[Fig. 53]
It is a figure for demonstrating the disassembly / assembly between a CPCS frame and a cell.
[Fig. 54]
It is a part of the block block diagram which shows the 16th Example (another Example using an ATM network) of this invention.
[Fig. 55]
It is a part of the block block diagram which shows the 16th Example of this invention.
[Fig. 56]
It is a flowchart which shows the flow example of a frame using SVC and PVC.
[Fig. 57]
It is a flowchart which shows the flow example of a frame using SVC and PVC.
[Fig. 58]
It is a block block diagram which shows the example of one-to-N communication or N-to-one communication using PVC.
[Fig. 59]
It is a block block diagram which shows the example of N-to-N communication using PVC.
[Fig. 60]
It is a figure which shows an example of the FR frame address part.
[Fig. 61]
It is a figure which shows the modification example between the ICS network frame and the FR frame.
[Fig. 62]
It is a part of the block block diagram which shows the 17th Example (another Example using the FR network) of this invention.
[Fig. 63]
It is a part of the block block diagram which shows the 17th Example of this invention.
[Fig. 64]
It is a flowchart which shows the flow example of a frame using SVC and PVC.
[Fig. 65]
It is a flowchart which shows the flow example of a frame using SVC and PVC.
[Fig. 66]
It is a block block diagram which shows the example of one-to-N communication or N-to-one communication using PVC.
[Fig. 67]
It is a block block diagram which shows the example of N-to-N communication using PVC.
[Fig. 68]
It is a part of the block block diagram which shows the 18th Example of this invention (accommodation of a telephone line, an ISDN line, a CATV line, a satellite line, an IPX line, and a mobile phone line).
[Fig. 69]
It is a part of the block block diagram which shows 18th Embodiment of this invention.
[Fig. 70]
It is a part of the block block diagram which shows 18th Embodiment of this invention.
[Fig. 71]
It is a part of the block block diagram which shows 18th Embodiment of this invention.
[Fig. 72]
It is a flowchart which shows the operation of 18th Example.
FIG. 73.
It is a part of the block block diagram which shows the 19th Example of this invention.
[Fig. 74]
It is a part of the block block diagram which shows the 19th Example of this invention.
[Fig. 75]
It is a part of the block block diagram which shows the 19th Example of this invention.
[Fig. 76]
It is a figure which shows an example of the description contents of the router table in a dial-up router.
[Fig. 77]
It is a flowchart which shows the operation of the 19th Example.
[Fig. 78]
It is a part of the block block diagram which shows the 20th Example of this invention.
[Fig. 79]
It is a part of the block block diagram which shows the 20th Example of this invention.
FIG. 80
It is a part of the block block diagram which shows the 20th Example of this invention.
[Fig. 81]
It is a figure which shows an example of correspondence of a communication speed and a speed class.
[Fig. 82]
It is a flowchart which shows the operation of the 20th Example.
[Fig. 83]
It is a flowchart which shows the operation of the 20th Example.
[Fig. 84]
It is a figure which shows the ICS user frame after the electronic signature is given.
[Fig. 85]
It is a figure which shows the ICS user frame before the digital signature is given.
[Fig. 86]
It is a part of the block block diagram which shows the 21st Example (electronic signature and encryption) of this invention.
[Fig. 87]
It is a part of the block block diagram which shows the 21st Example of this invention.
[Fig. 88]
It is a flowchart which shows the operation of the 21st Example.
[Fig. 89]
It is a figure for demonstrating the electronic signature at the time of transmission and the time of reception.
[Fig. 90]
It is a block block diagram which shows the 22nd Example (electronic signature server and encryption server) of this invention.
[Fig. 91]
It is a part of the block block diagram which shows the 23rd Example (open connection) of this invention.
[Fig. 92]
It is a part of the block block diagram which shows the 23rd Example of this invention.
[Fig. 93]
It is a block block diagram which shows the 24th Example (ISC address name management server) of this invention.
[Fig. 94]
It is a part of the block block diagram which shows the 25th Example (functional separation of an access control device) of this invention.
[Fig. 95]
It is a part of the block block diagram which shows the 25th Example of this invention.
[Fig. 96]
It is a flowchart which shows the operation of the 25th Example.
[Fig. 97]
It is a block block diagram which shows the 26th Example (access control device including a server and aggregated access control device) of this invention.
[Fig. 98]
It is a figure which shows the example of the TCP frame.
FIG. 99.
It is a figure which shows the example of the UDP frame.
FIG. 100
It is a part of the block block diagram which shows 27th Embodiment (incoming call priority control) of this invention.
FIG. 101.
It is a part of the block block diagram which shows 27th Embodiment (incoming call priority control) of this invention.
FIG. 102.
It is a figure for demonstrating the 27th Example.
FIG. 103.
It is a flowchart which shows the operation example of priority determination.
FIG. 104.
It is a block block diagram which shows the 28th Example (transmission priority control) of this invention.
FIG. 105.
It is a figure which shows an example of the conversion table used in 28th Example.
FIG. 106
It is a flowchart which shows the operation example of priority determination in 28th Example.
FIG. 107.
It is a block block diagram which shows the 29th Example (plural communication) of this invention.
[Fig. 108]
It is a figure which shows an example of the conversion table used in the 29th Example.
FIG. 109.
It is a figure which shows an example of the conversion table used in the 29th Example.
FIG. 110.
It is a block block diagram which shows the modification of 34th Example.
FIG. 111.
It is a part of the block block diagram which shows the 30th Example (operation of the integrated information communication system) of this invention.
[Fig. 112]
It is a part of the block block diagram which shows the 30th Example (operation of the integrated information communication system) of this invention.
FIG. 113.
It is a figure for demonstrating the 30th Example.
[Fig. 114]
It is a figure for demonstrating the 30th Example.
[Fig. 115]
It is a figure for demonstrating the 30th Example.
[Fig. 116]
It is a figure for demonstrating the 30th Example.
[Fig. 117]
It is a figure for demonstrating the 30th Example.
[Fig. 118]
It is a figure for demonstrating the 30th Example.
FIG. 119.
It is a figure for demonstrating the 30th Example.
[Fig. 120]
It is a figure which shows an example of the ICS network address allocation record table used in the 30th Example.
FIG. 121.
It is a figure which shows an example of the ICS user address allocation record table used in the 30th Example.
[Fig. 122]
It is a figure which shows an example of the conversion table used in the 30th Example.
[Fig. 123]
It is a figure which shows an example of the conversion table used in the 30th Example.
[Fig. 124]
It is a figure which shows an example of the conversion table used in the 30th Example.
[Fig. 125]
It is a procedure diagram for demonstrating the 30th Example.
[Fig. 126]
It is a figure which shows an example of the conversion table used in the 30th Example.
[Fig. 127]
It is a procedure diagram for demonstrating the 30th Example.
[Fig. 128]
It is a figure which shows an example of the conversion table used in the 30th Example.
[Fig. 129]
It is a figure for demonstrating the domain name server.
[Fig. 130]
It is a figure for demonstrating the domain name server.
FIG. 131.
It is a figure for demonstrating the domain name server.
[Fig. 132]
It is a figure for demonstrating the domain name server.
[Fig. 133]
It is a figure for demonstrating the call of a domain name server.
FIG. 134.
It is a figure for demonstrating the rewriting of the conversion table from an IP terminal.
[Fig. 135]
It is a figure for demonstrating the rewriting of the conversion table from an IP terminal.
[Fig. 136]
It is a block block diagram which shows the 31st Example (calling a communication partner by a telephone number) of this invention.
[Fig. 137]
It is a figure for demonstrating the 31st Example.
[Fig. 138]
It is a figure which shows an example of the internal table used in 31st Example.
[Fig. 139]
It is a figure which shows an example of the internal table used in 31st Example.
[Fig. 140]
It is a figure which shows an example of the internal table used in 31st Example.
FIG. 141.
It is a figure for demonstrating the call of a domain name server.
FIG. 142.
It is a part of the block block diagram which shows the 32nd Example (IP terminal which can connect to a plurality of access control devices) of this invention.
[Fig. 143]
It is a part of the block block diagram which shows the 32nd Example (IP terminal which can connect to a plurality of access control devices) of this invention.
FIG. 144
It is a timing chart for explaining the registration procedure from the home IP terminal.
[Fig. 145]
It is a figure for demonstrating the access method of an authentication server.
[Fig. 146]
It is a figure which shows an example of the internal table used in 32nd Example.
FIG. 147.
It is a figure which shows an example of the internal table used in 32nd Example.
[Fig. 148]
It is a figure which shows an example of the internal table used in 32nd Example.
[Fig. 149]
It is a figure for demonstrating the call of an authentication server.
[Fig. 150]
It is a block diagram for explaining a conventional LAN network.
[Fig. 151]
It is a figure which shows the form example of the Internet.
[Fig. 152]
It is a figure which shows the IP frame specified by RFC791.
[Fig. 153]
It is a figure which shows the IP frame specified in RFC1883.
[Explanation of symbols]
1,100 Integrated Information and Communication Systems (ICS) 2, 3, 4, 5, 10 Access control device 20 Relay device Gateway between 30 VANs 40 ICS network server 50 ICS network address management server 60 User physical communication line
Contents5
Every citation, both waysCites: the store holds 8 of 9
| Document | Relation | Office |
|---|---|---|
| JP6423646A | Cites | Japan |
| JP9266509A | Cites | Japan |
| JP575726A | Cites | Japan |
| JP9247210A | Cites | Japan |
| JP6205137A | Cites | Japan |
| JP5227165A | Cites | Japan |
| 9812 | Cites | – |
| 98113 | Cites | – |
| 【文献】高尾光一他,「C&Cインターネットサービスmesh」,NEC技報,第49巻,第7号,p.74~81,NECクリエイティブ,1996年7月30日 | Non-patent | – |
152 members in 12 offices
Priority claims17
| Document | Office | Kind | Date |
|---|---|---|---|
| 32673696 | Japan | A | |
| 32673696 | Japan | A | |
| 8326736 | Japan | – | |
| 5481297 | Japan | A | |
| 5481297 | Japan | A | |
| 954812 | Japan | – | |
| 18254197 | Japan | A | |
| 18254197 | Japan | A | |
| 9182541 | Japan | – | |
| 2000081416 | Japan | A | |
| 1996326736 | – | – | – |
| 199754812 | – | – | – |
| 1997182541 | – | – | – |
| JP19960326736 | – | – | – |
| JP19970054812 | – | – | – |
| JP19970182541 | – | – | – |
| JP20000081416 | – | – | – |
Members152
| Document | Office | Kind | |
|---|---|---|---|
| GB9722070D0 | United Kingdom | D0 | |
| CA2220559A1 | Canada | A1 | |
| CA2537966A1 | Canada | A1 | |
| CA2538190A1 | Canada | A1 | |
| CA2538673A1 | Canada | A1 | |
| CA2538990A1 | Canada | A1 | |
| CA2540793A1 | Canada | A1 | |
| DE19754073A1 | Germany | A1 | |
| GB2320167A | United Kingdom | A | |
| AU4679497A | Australia | A | |
| FR2758924A1 | France | A1 | |
| KR19980063826A | Republic of Korea | A | |
| GB9821661D0 | United Kingdom | D0 | |
| CN1201200A | China | A | |
| JPH1188438A | Japan | A | |
| CA2254045A1 | Canada | A1 | |
| AU8956998A | Australia | A | |
| GB2332837A | United Kingdom | A | |
| TW364964B | Taiwan Province of China | B | |
| JPH11239178A | Japan | A | |
| GB9920041D0 | United Kingdom | D0 | |
| GB9920042D0 | United Kingdom | D0 | |
| GB9920076D0 | United Kingdom | D0 | |
| GB9920079D0 | United Kingdom | D0 | |
| GB9920084D0 | United Kingdom | D0 | |
| GB9920086D0 | United Kingdom | D0 | |
| GB2338871A | United Kingdom | A | |
| GB2338872A | United Kingdom | A | |
| GB2338873A | United Kingdom | A | |
| GB2338874A | United Kingdom | A | |
| GB2338875A | United Kingdom | A | |
| GB2338876A | United Kingdom | A | |
| AU714668B2 | Australia | B2 | |
| JP3000051B2 | Japan | B2 | |
| GB2338871B | United Kingdom | B | |
| GB2338872B | United Kingdom | B | |
| GB2338873B | United Kingdom | B | |
| GB2338874B | United Kingdom | B | |
| GB2338875B | United Kingdom | B | |
| GB2338876B | United Kingdom | B | |
| JP3084681B2 | Japan | B2 | |
| GB0019276D0 | United Kingdom | D0 | |
| US6145011A | United States of America | A | |
| JP2000316026A | Japan | A | |
| SG79949A1 | Singapore | A1 | |
| GB2356327A | United Kingdom | A | |
| JP2001177578A | Japan | A | |
| HK1033397A1 | Hong Kong, China | A1 | |
| GB0122573D0 | United Kingdom | D0 | |
| GB0122580D0 | United Kingdom | D0 | |
| GB0122620D0 | United Kingdom | D0 | |
| GB0122622D0 | United Kingdom | D0 | |
| GB0122624D0 | United Kingdom | D0 | |
| GB2363298A | United Kingdom | A | |
| GB2363299A | United Kingdom | A | |
| GB2364490A | United Kingdom | A | |
| GB2364491A | United Kingdom | A | |
| JP3261459B2This record | Japan | B2 | |
| GB2366707A | United Kingdom | A | |
| FR2758924B1 | France | B1 | |
| GB0204600D0 | United Kingdom | D0 | |
| GB0204605D0 | United Kingdom | D0 | |
| GB0204606D0 | United Kingdom | D0 | |
| GB0204609D0 | United Kingdom | D0 | |
| GB0204718D0 | United Kingdom | D0 | |
| GB0204725D0 | United Kingdom | D0 | |
| GB0204726D0 | United Kingdom | D0 | |
| GB0204942D0 | United Kingdom | D0 | |
| GB2363298B | United Kingdom | B | |
| GB2364491B | United Kingdom | B | |
| JP3283864B2 | Japan | B2 | |
| JP2002158717A | Japan | A | |
| KR100321899B1 | Republic of Korea | B1 | |
| GB2356327B | United Kingdom | B | |
| GB2332837B | United Kingdom | B | |
| GB2370734A | United Kingdom | A | |
| GB2370735A | United Kingdom | A | |
| GB2371188A | United Kingdom | A | |
| GB2371189A | United Kingdom | A | |
| GB2371958A | United Kingdom | A | |
| GB2371959A | United Kingdom | A | |
| GB2370734B | United Kingdom | B | |
| GB2370735B | United Kingdom | B | |
| GB2372182A | United Kingdom | A | |
| GB2320167B | United Kingdom | B | |
| GB2371188B | United Kingdom | B | |
| GB2371958B | United Kingdom | B | |
| GB2371959B | United Kingdom | B | |
| GB2372182B | United Kingdom | B | |
| JP2003069606A | Japan | A | |
| US2003118034A1 | United States of America | A1 | |
| US6618366B1 | United States of America | B1 | |
| US2003179758A1 | United States of America | A1 | |
| JP2004048744A | Japan | A | |
| CN1520086A | China | A | |
| CN1170398C | China | C | |
| HK1068754A1 | Hong Kong, China | A1 | |
| JP2005287067A | Japan | A | |
| JP2005341549A | Japan | A | |
| JP3756895B2 | Japan | B2 |
21 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Written notification of registration of transferJAPANESE INTERMEDIATE CODE: R350R350 | R350 | |
| Written request for registration of change of nameJAPANESE INTERMEDIATE CODE: R313533S533 | S533 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Written notification of registration of transferJAPANESE INTERMEDIATE CODE: R350R350 | R350 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Request for change of ownership or part of ownershipJAPANESE INTERMEDIATE CODE: R313117S111 | S111 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 |
Numbers
- Publication
- 3261459
- Publication, DOCDB
- 3261459
- Publication, EPODOC
- JP3261459B
- Application
- 2000081416
- Application, DOCDB
- 2000081416
- Application, EPODOC
- JP20000081416
Titles2
- Japanese
- 【発明の名称】統合情報通信システム
- English
- [Title of Invention] Integrated Information Communication System
Classification
- IPC, 6
- H04L12 28
- H04L12 46
- H04L12 66
- H04L45 741
- H04M3 00
- H04W8 26