Mobile device communication system and communication method
Abstract
This record has no abstract on file.
Term
Term ended
Expired 10 July 2022, 4.2 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
13 claims: 10 independent, 3 dependent
- 1複数のサービス提供サーバを備え、移動可能端末が通信を行うための移動機通信システムにおいて、 前記移動可能端末が接続され、前記サービス提供サーバ側への複数の入出力点を有する第1のネットワーク手段と、 該複数の入出力点のそれぞれに接続される複数の第1の通信振り分け手段と、 該第1の通信振り分け手段が接続される第2のネットワーク手段と、 前記複数のサービス提供サーバが接続される第3のネットワーク手段と、 該第2のネットワーク手段と第3のネットワーク手段との間に接続され、前記移動可能端末とサービス提供サーバとの間の一連の通信を、前記複数のサービス提供サーバのいずれかに振り分ける複数の第2の通信振り分け手段とを備え、 前記第1の通信振り分け手段が、前記移動可能端末とサービス提供サーバとの間での一連の通信を前記第2のネットワーク手段を介して前記複数の第2の通信振り分け手段のいずれかに振り分けるように構成されることを特徴とする移動機通信システムであって、 前記複数の第1の通信振り分け手段が、前記移動可能端末とサービス提供サーバとの間の一連の通信としてのセションの識別子に対応して、該一連の通信を振り分けるべき前記複数の第2の通信振り分け手段のいずれかを記憶する、同一記憶内容の振り分け先記憶手段をそれぞれ備えることを特徴とする移動機通信システム。
- 2前記複数のサービス提供サーバがそれぞれ同一のサービスを提供するサーバによって構成される複数のグループを構成し、 前記移動可能端末が該複数の各グループに対する代表アドレスを指定してサービス提供サーバとの間の通信を行い、 前記第2の通信振り分け手段が、該代表アドレスによって指定されるグループのうちいずれかのサービス提供サーバに、前記一連の通信を振り分けることを特徴とする請求項1記載の移動機通信システム。
- 3前記移動可能端末が前記一連の通信の中で受けるべきサービスの変更のために前記代表アドレスを変更する時、 前記第2の通信振り分け手段が、該変更後の代表アドレスによって指定されるグループのうちのいずれかのサービス提供サーバに前記一連の通信内のその後の通信を振り分けて、該一連の通信を続行することを特徴とする請求項 2 記載の移動機通信システム。
- 4前記移動機通信システムにおいて、 前記第2の通信振り分け手段が前記一連の通信を複数のサービス提供サービスのいずれかに振り分けるにあたり、前記移動可能端末の利用者が該サービス提供サーバによって提供されるサービスを受ける資格があるか否かを認証するサービス認証手段を更に備えることを特徴とする請求項1記載の移動機通信システム。
- 5前記移動機通信システムにおいて、 前記第2の通信振り分け手段が前記複数のサービス提供サーバのみでなく、前記移動機通信システム外のサーバにも前記一連の通信を振り分けることができ、 前記移動可能端末が前記サービス提供サーバ、または移動機通信システム外のサーバから受けるサービスに対する課金の情報を作成する課金情報作成手段を更に備えることを特徴とする請求項1記載の移動機通信システム。
- 6前記移動機通信システムにおいて、 前記移動可能端末とサービス提供サーバとの間の一連の通信としてのセションに対して識別子を割り当て、該識別子を管理するセション管理手段を更に備えることを特徴とする請求項1記載の移動機通信システム。
- 7前記第2の通信振り分け手段が、通信の階層構造において、前記セション管理手段によって管理されるセションに対応する層より上位の層における一連の通信としてのユーザセションに対して識別子を割り当て、該識別子に対応して前記移動可能端末とサービス提供サーバとの間の該ユーザセション内の通信を前記複数のサービス提供サーバのいずれかに振り分けることを特徴とする請求項 6 記載の移動機通信システム。
- 8前記ユーザセションのタイプとして複数のタイプが存在し、前記第2の通信振り分け手段が該ユーザセションのタイプに対応して前記ユーザセション内の通信の振り分けを行うことを特徴とする請求項 7 記載の移動機通信システム。
- 9複数のサービス提供サーバを備え、移動可能端末が通信を行うための移動機通信システムにおいて、 前記移動可能端末が接続され、前記サービス提供サーバ側への複数の入出力点を有する第1のネットワーク手段と、 該複数の入出力点のそれぞれに接続される複数の第1の通信振り分け手段と、 該第1の通信振り分け手段が接続される第2のネットワーク手段と、 前記複数のサービス提供サーバが接続される第3のネットワーク手段と、 該第2のネットワーク手段と第3のネットワーク手段との間に接続され、前記移動可能端末とサービス提供サーバとの間の一連の通信を、前記複数のサービス提供サーバのいずれかに振り分ける複数の第2の通信振り分け手段とを備え、 前記第1の通信振り分け手段が、前記移動可能端末とサービス提供サーバとの間での一連の通信を前記第2のネットワーク手段を介して前記複数の第2の通信振り分け手段のいずれかに振り分けるように構成されることを特徴とする移動機通信システムであって、 前記移動可能端末とサービス提供サーバとの間の一連の通信としてのセションに対して識別子を割り当て、該識別子を管理するセション管理手段を更に備え、 前記第2の通信振り分け手段が、通信の階層構造において、前記セション管理手段によって管理されるセションに対応する層より上位の層における一連の通信としてのユーザセションに対して識別子を割り当て、該識別子に対応して前記移動可能端末とサービス提供サーバとの間の該ユーザセション内の通信を前記複数のサービス提供サーバのいずれかに振り分けることを特徴とする移動機通信システム。
- 10前記ユーザセションのタイプとして複数のタイプが存在し、前記第2の通信振り分け手段が該ユーザセションのタイプに対応して前記ユーザセション内の通信の振り分けを行うことを特徴とする請求項 9 記載の移動機通信システム。
- 11複数のサービス提供サーバを備え、移動可能端末が通信を行うための移動機通信方法において、 前記移動可能端末が、 前記複数のサービス提供サーバのうちのいずれかを指定して、一連の通信におけるパケットを送信し、 該パケットを受け取った負荷分散装置が、該一連の通信に対する識別子に対応して該パケットを複数のパケットゲートウェイ装置のいずれかに振り分け、 該パケットを振り分けられたパケットゲートウェイ装置が、前記移動可能端末が指定したサービス提供サーバと同一のサービスを実行する複数のサービス提供サーバのいずれかに該パケットを振り分けることを特徴とする移動機通信方法。
- 12前記一連の通信がセション管理装置によって管理されるセションであり、 前記パケットゲートウェイ装置が、通信の階層構造において該セションに対応する層より上位の層における一連の通信としてのユーザセションに対応してパケットを振り分けることを特徴とする請求項 11 記載の移動機通信方法。
- 13複数のサービス提供サーバを備え、移動可能端末が通信を行うための移動機通信システムにおいて、 前記移動可能端末が接続され、前記サービス提供サーバ側への複数の入出力点を有するネットワーク手段と、 該複数の入出力点のそれぞれに接続される複数の第1の通信振り分け手段と、 該複数の第1の通信振り分け手段と前記複数のサービス提供サーバとの間に接続され、前記移動可能端末とサービス提供サーバとの間の一連の通信を、前記複数のサービス提供サーバのいずれかに振り分ける複数の第2の通信振り分け手段とを備え、 前記一連の通信の開始から終了までの間に、前記移動可能端末とサービス提供サーバ側との通信が前記ネットワーク手段の複数の入出力点のいずれを介して行われる場合にも、前記複数の第1の通信振り分け手段のいずれかが前記複数の第2の通信振り分け手段のうちで常に同一の第2の通信振り分け手段に該一連の通信を振り分けることを特徴とする移動機通信システム。
Independent claims13
198 paragraphs, as filed
The present invention relates to a communication system using a network and a communication method, and more particularly to a mobile communication system having a plurality of service providing servers and performing communication using a mobile terminal, and a communication method.
FIG. 42 is a system configuration block diagram of a first conventional example of a mobile communication system, for example, a mobile packet network. In the figure, the user of the system, that is, the client, uses mobile devices (MS) 100a, 100b, ..., For example, a mobile phone to communicate with each other or with a plurality of service providing servers. Do.
In FIG. 42, the mobile packet network performs processing corresponding to the access when, for example, a mobile IP (Internet protocol) network 101, each mobile (MS) 100a, 100b, ... Accesses the network 101. Network access device (NAS) or forein agent (FA) 102a, 102b, ..., Routers (R) 103a, 103b, 103c connected to the entrance and exit on the service providing server side of network 101, to these routers, respectively. The connected user authentication device 104, the load balancer (load balancer, LB) 105a, 105b, 105c connected to each router, the local area network for connecting these load balancers to multiple service providers, or It has a wide area network (LAN / WAN) 106 and a home agent (HA) 107 on a mobile IP network.
A plurality of service providing servers form a group composed of a plurality of servers each providing the same service. For example, service providing servers 110a, 110b, 110c, ..., Each provide the same service as a group. It consists of servers that can be provided. Therefore, for example, the server of the group composed of the service providing servers 111a, 111b, 111c, ... And the server of the group composed of the service providing servers 112a, 112b, 112c, ... Provide different services. ..
In the mobile packet network of FIG. 42, communication is performed between the mobile device, for example, the mobile phone and the service providing server, as described above. At this time, since the servers capable of providing the service requested from the client side form one group as described above, a load distribution device is installed in front of the service providing server in response to the input of the packet from the client. Distributing input packets to each service providing server based on a distribution policy that equalizes the load of each server that provides the same service by arranging them is called load distribution.
In the general load distribution method, representative address information is assigned to the grouped service providing servers, and the client sends a packet with the representative address information as the destination, based on the distribution policy of the load distribution device. Packets are distributed to one of the service providing servers in the group.
The distribution policy includes policies such as round robin, weighted round robin, priority, minimum number of connections, fastest response time, and CPU load, and the load distribution device is provided with a distribution policy information table representing such distribution policy.
For example, in a mobile packet network operated by a telecommunications carrier that provides a telecommunications service called a carrier, the number of users is generally very large, so in order to disperse the users, the service of the mobile IP network 101 in FIG. 42 A plurality of routers 103a, 103b, 103c and load distribution devices 105a, 105b, 105c are installed at the entrance and exit on the service providing server side to distribute the load to a large number of service providing servers.
However, in such a configuration, when the mobile device, for example, the mobile phone 100a moves during communication, the entrance / exit to the network 101 to the service providing server side changes dynamically. For example, even if communication is first performed via the router 103a and the load distribution device 105a, a situation occurs in which communication is performed via the router 103c and the load distribution device 105c at the next time.
In such a case, for example, when three load distribution devices 105a, 105b, and 105c perform load distribution based on independent distribution policies, packets may be distributed to different service providing servers even within the same group. In such a case, there is a problem that a TCP (Transmission Control Protocol) connection, that is, a connection for receiving a specific service cannot be maintained.
In such a case, for example, even if the load distribution devices 105a and 105c distribute the packets to the same service providing server in the group, for example, the mobile device 100a sends the upstream packet, that is, to the service providing server side. If a packet is sent and traveled while receiving a downlink packet, that is, a packet from the service providing server, and the upstream packet after the movement passes through a different load distribution device, the packet is sent between the network 101 and the service providing server. They will not follow the same route.
As a technology for distributing packets to the same service providing server even when the entrance / exit to the network to the service providing server side changes dynamically due to the movement of the mobile device during communication in this way, the user session There is a prior art that uses a layer 7 switch to maintain. A user statement is defined in, for example, UDP (User Datagram Protocol).
Unlike TCP, UDP is a connectionless protocol and there is no concept of connection, but in the upper layer protocol of UDP, such as Domain Name System (DNS) as a standard name resolution mechanism used in the Internet etc. , The concept of cessation exists, and one process is completed by processing a series of multiple UDP packets by the same server. Communication by a series of multiple UDP packets for completing this process is called a user session on UDP.
User sessions are defined not only for UDP, but also for TCP. In the case of TCP as well, there is a concept of user session in the upper layer protocol, for example, Hypertext Transfer Protocol (HTTP), and by establishing a series of multiple TCP connections, transferring data, and releasing data. One process is completed. Communication by a series of multiple TCP connections to complete this process is called a user session on TCP.
Even for user sessions on UDP and TCP, packets cannot be distributed to the same service providing server due to the dynamic change of the entrance and exit to the network due to the movement of the mobile device during communication, so the user session can be used. The problem of not being able to maintain occurs as well, but the prior art for maintaining this user session will be described with reference to FIG. 43.
FIG. 43 is a conventional example of a mobile communication system using a layer 7 switch. In this conventional example, between the plurality of load distribution devices and the service providing server side in FIG. 42, a plurality of transparent proxy (TP) devices 120a, 120b, 120c and a plurality of layer 7 switch (L7SW) devices 121a, 121b , 121c, and network 122 are provided, and static load distribution is performed by using the user identification information in the layer 7 protocol such as HTTP as a key by the layer 7 switch, so that the user session on TCP and UDP is continuing. It is possible to distribute the communication to the same service providing server.
As described above, since the packet does not follow the same route between the network 101 in FIG. 42 and the service providing server, the following five problems occur. The first problem is that it takes time to switch services. One TCP connection corresponding to one service and user session management must be performed on the service providing server side, and it is necessary to reconnect the TCP connection every time the service used is changed from the viewpoint of the mobile device. It will take time to switch services.
The second problem is that it is not possible to distribute the risk when the service providing server goes down. If the TCP connection or the service providing server that manages the user session goes down, the connection cannot be switched to the server that provides the same service, and the service cannot be received until the downed service providing server is restored.
The third problem is that it is not possible to create billing information for proxy billing. That is, only by the TCP connection or the service providing server that manages the user session, the authentication of the contracted service unit for the service use on the client side can be performed, and the billing information for the paid contents can be created on behalf of the user. ..
The fourth problem is that the protocol conversion of the transport layer between the wireless network and the wired network cannot be performed. There is a difference in delay time between the wireless network and the wired network. Therefore, in order to optimize the standard Internet service for wireless communication, it is necessary to convert the window size (the amount of data that can be transmitted at one time), that is, the protocol conversion of the transport layer between the wireless network and the wired network. Become. If the packets do not pass through the same route, it becomes impossible to install a relay device that performs protocol conversion in the transport layer.
The fifth problem is that the gateway function between the Internet Protocol version (IPV) 4 network and the IPV6 network cannot be installed. With the rapid increase in the number of mobile phones in recent years, it is necessary to significantly expand the IP address, and IPV6 is planned to be introduced. When IPV6 is introduced, a gateway function between the current IPV4 network and IPV6 network is required, but if packets do not follow the same route, that gateway function cannot be installed.
Further, as described with reference to FIG. 43, there are the following problems when the user session is maintained by using the layer 7 switch. The first problem is that packets corresponding to requests from clients with the same user identification information are always distributed to the same service providing server, so in some cases the load is concentrated on a specific service providing server. Is.
The second problem is that each time a service is added, additional processing of the layer 7 switch, that is, analysis of the additional service (Layer 7 protocol) and additional processing such as session identification processing are required, and the service is added quickly. There is a problem that it cannot be done. Especially in the case of a telecommunications carrier called a carrier, this problem becomes serious because services are added frequently.
The third problem is that the performance of packet distribution processing is low. Since the processing by the layer 7 switch is usually implemented as software, there is a problem that the performance of packet distribution processing is inferior to that when it is implemented as hardware (firmware).
<p> In view of the above problems, the subject of the present invention is to provide a plurality of entrances and exits on the service providing server side of the IP network, and even when a load distribution device is connected to each entrance and exit, for example, the same TCP connection or user session. By making the route through which the packets constituting the above are the same, it is possible to maintain the TCP connection even if the mobile device moves and communicates. Another issue is that by providing a gateway function on the route, it is possible to eliminate the time required for service switching, distribute the risk when the service providing server goes down, create billing information on behalf of the user, and convert the transport layer protocol. , To realize the gateway function between the IPV4 network and the IPV6 network.</p>
<p> FIG. 1 is a block diagram of the principle configuration of the mobile communication system of the present invention. The figure is a block diagram of the principle configuration of a communication system in which a plurality of service providing servers 7a, 7b, ..., 8a, 8b, ... Are provided and mobile terminals 1a, ..., 1n communicate with each other. Is.</p><p> In FIG. 1, the first network means 2 is a network to which mobile terminals 1a, ..., 1n are connected and has a plurality of input / output points to the service providing server side, for example, a mobile IP network.</p><p> The plurality of first communication distribution means 3a, 3b, ... Are, for example, load distribution devices, which are connected to each of the above-mentioned plurality of input / output points of the first network means 2. The second network means 4 is a network to which the first communication distribution means 3a, 3b, ... Are connected, for example, a local area network or a wide area network.</p><p> The third network means 5 is a network to which a plurality of service providing servers 7a, 7b, ..., 8a, 8b, ... Are connected, for example, a local area network or a wide area network.</p><p> The plurality of second communication distribution means 6a, 6b, ... Are connected between the second network means 4 and the third network means 5, and a series of communications between the mobile terminal and the service providing server. Is distributed to any of a plurality of service providing servers, for example, a packet gateway device.</p><p> Then, the first communication distribution means 3a, 3b, ... Performs a series of communications between the mobile terminal and the service providing server via the second network means 4, and a plurality of second communication distribution means. It is configured to be distributed to any of 6.</p><p> In the embodiment of the present invention, a session management means for assigning an identifier to a session as a series of communication between the mobile terminal and the service providing server and managing the identifier is further provided. A plurality of first communication distribution means 3a, 3b, ... Should distribute the series of communications corresponding to the identifier of the session as a series of communications between the mobile terminal and the service providing server. Each of the second communication distribution means 6a, 6b, ... Is further provided with a distribution destination storage means having the same stored contents.</p><p> In this case, the second communication distribution means assigns an identifier to a user session as a series of communications in a layer higher than the layer corresponding to the session managed by the session management means in the communication hierarchical structure, and said that Communication within the user session between the mobile terminal and the service providing server can be distributed to any of the plurality of service providing servers according to the identifier, and there are a plurality of types of user sessions. However, the second communication distribution means can also distribute the communication within the user session according to the type of the user session.</p><p> In the embodiment, a plurality of service providing servers form a plurality of groups composed of servers each providing the same service, and a mobile terminal specifies a representative address for each of the plurality of groups to form a service providing server. It is also possible for the second communication distribution means 6a, 6b, ... To distribute a series of communications to one of the service providing servers in the group specified by the representative address. When the mobile terminal changes the representative address to change the service to be received in a series of communications, the second communication distribution means 6a, 6b, ... Of the group specified by the changed representative address. Subsequent communications within a series of communications can be distributed to one of the service providing servers, and the series of communications can be continued.</p><p> Further, in the embodiment, when the second communication distribution means 6a, 6b, ... Distributes a series of communications to one of a plurality of service providing servers, the user of the mobile terminal provides the service by the service providing server. Further, a service authentication means for certifying whether or not the user is eligible to receive the service to be provided can be provided.</p><p> Further, in the embodiment, the second communication distribution means 6a, 6b, ... Can distribute a series of communications not only to a plurality of service providing servers but also to a server outside the mobile communication system, and can be moved. It is also possible to further provide a billing information creating means for creating billing information for a service received by the terminal from a service providing server or a server outside the mobile communication system.</p><p> Next, as the mobile communication method of the present invention, a mobile terminal specifies one of a plurality of service providing servers, transmits a packet in a series of communications, and a load distribution device that receives the packet is a series of the packets. Multiple packets are distributed to one of a plurality of packet gateway devices according to an identifier for communication, and the packet gateway device to which the packets are distributed executes the same service as the service providing server specified by the mobile terminal. The packet can also be distributed to one of the service providing servers. The load distribution device corresponds to the above-mentioned first communication distribution means, and the packet gateway device corresponds to the second communication distribution means.</p><p> In this method, the packet (downlink packet) in a series of communications from the service providing server to the mobile terminal is a packet gateway that first distributes the packet (uplink packet) from the service providing server to the mobile terminal to the service providing server. It is sent to the device, sent from the packet gateway device to the load distribution device that distributes the uplink packets, and finally sent to the mobile terminal.</p><p> Next, in the present invention, as a storage medium used by the computer constituting the packet gateway device, the destination address and the source address of the packet received from the load distribution device are stored using a unique source port number as a key. A step, a step of setting the unique source port number as a source port number of the packet header, and a plurality of services capable of providing the service requested from the mobile terminal side among the plurality of service providing servers. A step of selecting one of the providing servers to distribute the load of the service providing server, setting the address of the selected service providing server as the destination address, and setting the address of the own device as the source address, A computer-readable portable storage medium containing a program for causing the computer to execute a step of transmitting a packet to the service providing server is used. Also, when the mobile terminal moves and the network access device to notify is switched, the PPP (point-to-point protocol) link is temporarily disconnected on the mobile terminal side, but the PPP protocol stack is TCP. By not notifying the protocol stack of this, the TCP connection will not be disconnected.</p><p> Further, in this case, as the above-mentioned unique source port number, as a series of communications in a layer higher than the layer corresponding to the session as a series of communications between the mobile terminal and the service providing server in the communication hierarchy. You can also use the identifier for the user session of.</p><p> The storage medium used by the computer constituting the packet gateway device includes a step of searching for mobile device identification information for a mobile terminal as a source of a packet received from the load distribution device, and a transmission destination of the received packet. A computer determines whether or not the service provided by the service providing server of the destination address can be provided to the user of the mobile terminal based on the step of extracting the address and the mobile device identification information and the destination address. A computer-readable portable storage medium that stores a program to be executed is also used.</p><p> Further, as a storage medium used by the computers constituting the packet gateway device, the destination address of the packet from the packet received from the load distribution device at the start of a series of communication between the mobile terminal and the service providing server. And the step of extracting the source address and setting it in the billing record, causing the computer to execute the step of incrementing the number of packets of the billing record each time a packet is received from the load distribution device until the end of the series of communications. A computer is made to execute a step of extracting a packet length from the received packet and adding the packet length to the packet length of the billing record, and at the end of a series of communications, the source address in the billing record can be moved to a movable terminal. A computer-readable portable storage medium that stores a program for causing the computer to execute the step of resetting the user identification information and the destination address in the information of the service providing server is also used.</p><p> Next, as a program used by the computers constituting the packet gateway device, a procedure for storing the destination address and the source address of the packet received from the load distribution device using a unique source port number as a key, and the unique method. A means of setting a different source port number as a source port number of a packet header, and among multiple service providing servers, a plurality of service providing servers capable of providing the service requested from the mobile terminal side. A procedure for selecting one to distribute the load of the service providing server, setting the address of the selected service providing server as the destination address and the address of the own device as the source address, and setting the packet as the packet. A program is used to make the computer execute the procedure to be sent to the service providing server.</p><p> In this case, as the above-mentioned unique source port number, as a series of communications in a layer higher than the layer corresponding to the session as a series of communications between the mobile terminal and the service providing server in the communication hierarchy. An identifier for the user session can also be used.</p><p> The programs used by the computers that make up the gateway device include a procedure for searching mobile device identification information for a mobile terminal as a source of packets received from a load distribution device, and a destination address for the received packets. The computer executes a procedure for extracting the packet and a procedure for determining whether or not the service provided by the service providing server at the destination address can be provided to the user of the mobile terminal based on the mobile device identification information and the destination address. A program to make it happen is also used.</p><p> Further, as a program used by the computer constituting the packet gateway device, the destination of the packet from the packet received from the load distribution device at the start of a series of communication between the mobile terminal and the service providing server. A procedure of having a computer execute a procedure of extracting an address and a source address and setting them in a billing record, and incrementing the number of packets of the billing record each time a packet is received from the load distribution device until the end of the series of communications. , Extract the packet length from the received packet, have the computer execute the procedure of adding the packet length to the packet length of the billing record, and move the source address in the billing record at the end of the series of communications. A program for causing the computer to execute the procedure of resetting the user identification information and the destination address of the possible terminal to the information of the service providing server is also used.</p><p> As described above, in the present invention, a plurality of packet gateway devices are installed between a load distribution device provided at a plurality of entrances and exits of a network to which a mobile device is connected and a plurality of service providing servers, and one movement is performed. A series of packet transmission / reception with the service providing server side by the machine is always executed via the same packet gateway device.</p>
<p> According to the present invention, even if the network access device changes due to the movement of the mobile device and the load distribution device through which the packet passes dynamically changes, the packet gateway device can distribute the packet to the same service providing server. It becomes possible, the session and the user session can be maintained, and effective load distribution becomes possible. Even when adding / changing network access devices, it is possible to add / change without changing the definition on the mobile packet network side.</p><p> In addition, the same packet gateway device passes not only the uplink packet as a packet for the service providing server and the downlink packet as a packet for the mobile device, but also the next uplink packet, so the following five are on the same route. The gateway function becomes feasible.</p><p> The first function is a centralized management function for sessions and user sessions. The packet gateway device enables centralized management of sessions and user sessions, and even if the service used from the viewpoint of the mobile device is changed, the service does not require reconnection of the session or user session with the service providing server. The time for switching can be eliminated.</p><p> The second function is the risk distribution function when the service providing server goes down. Since the packet gateway device can switch the session and the user session to an alternative server that provides the same service and continue the session, it is possible to avoid the risk that the service cannot be continued.</p><p> The third function is the proxy billing function. Since the packet gateway device can centrally manage the session, it is possible to perform authentication for each contracted service by referring to the authentication contract information regarding the use of the service, and to create the billing information for the paid content on behalf of the user.</p><p> The fourth function is the protocol conversion function of the transport layer between the wireless network and the wired network. In order to use the standard Internet service for wireless communication, it becomes possible for the packet gateway device to realize protocol conversion of the transport layer between the wireless network and the wired network such as window size.</p><p> The fifth function is the gateway function between the IP version 4 network and the IP version 6 network. Even when the Internet Protocol version 6 is introduced, the gateway function to and from the current version 4 network can be realized.</p><p> Further, according to the present invention, by using the multi-window display on the mobile device side, the service providing server that provides the service for each window is fixed, and it is possible to receive a plurality of services from login to logout. It greatly contributes to improving the performance of communication systems.</p>
FIG. 2 is a system configuration block diagram of the mobile packet network according to the first embodiment of the present invention. In this system, a mobile device (MS), for example, a mobile phone 20a, 20b, ... Is a network access device (NAS) or a forein agent (FA) 22a, 22b, ... To the mobile IP network 21, for example. It is connected wirelessly or by wire.
On the service providing server side of this network 21, there are multiple entrances and exits, for example, three entrances and exits, and routers (R) 23a, 23b, ..., And load balancer (load balancer, LB) 25a, 25b at each entrance and exit. , ... are connected as shown in the figure, and the load balancer (LB) is connected to the local area network or the wide area network (LAN / WAN) 26.
In this first embodiment, communication between the mobile device and the service providing server is generally managed in the form of a session composed of one or more TCP connections, as will be described later.
For the entire system, session management for managing a user authentication device 24 for managing users and a session for sending and receiving a series of packets until, for example, one mobile device accesses network 21 and terminates necessary communication. A device 27 is provided. It is assumed that the user authentication device 24 is connected to, for example, routers 23a, 23b, ... At the entrance / exit on the service providing server side of the network 21, and is also connected to the session management device 27.
A session management device 27 and a plurality of packet gateway (GW) devices 28a, 28b, ... Are connected to the network 26 to which the load distribution devices (LB) 25a, 25b, ... Are connected. These packet gateway devices play the most important role in the embodiments of the present invention, as will be described below.
Each packet gateway device is connected to a large number of service providing servers by LAN / WAN29. A large number of service providing servers shall belong to several groups, for example, service providing servers 30a, 30b, ... Form one group, and each server in this group can provide the same service. As will be described later, the mobile device side shall communicate using the representative address of this group. For example, the service providing servers 31a, 31b, ... Perform services different from those of the servers in the group of, for example, the service providing services 32a, 32b, ....
FIG. 3 is an explanatory diagram of an inter-device processing sequence at the start of session in the system of FIG. The figure shows a processing sequence between the mobile device 20, the network access device 22, the load distribution device 25, the user authentication device 24, the session management device 27, the packet gateway device 28, and the service providing server device 30.
The packet format and packet sequence of packet communication between the mobile device 20, the network access device 22, and the user authentication device 24 shall follow the protocol proposed by the Internet Draft Diameter Mobile IP Extensions, which is detailed here. The explanation is omitted.
On the other hand, the packet sequence and packet format between the user authentication device 24, the session management device 27, and the packet gateway device 28 are irrelevant to this convention and are peculiar to the present embodiment.
In FIG. 3, first, when accessing the network 21 from the mobile device 20, the network access device 22 sends an access request specified by the above protocol to the user authentication device 24.
FIG. 4 is a block diagram of a user authentication device. The user authentication device is composed of a LAN driver unit or WAN driver unit 41, a TCP / IP protocol handler unit 42, a communication control unit 43, a user management unit 44, and a server monitoring unit 45, and further includes a user management unit 44 and a server monitoring unit 45. The address information table 46 managed by the user information table 46 and the user information table 47 managed by the user management unit 44 are provided. Here, the LAN or WAN connected to the LAN driver unit or the WAN driver unit 41 is connected via the network 26 connected via the session management device 27 in FIG. 2 or the routers 23a, 23b, ... Corresponds to mobile IP network 21.
The TCP / IP protocol handler unit 42 includes the User Datagram Protocol (UDP) and all other TCP / IP protocol sets. FIG. 5 is a flowchart of the address allocation process in the user authentication device. In this process, an IP address is assigned to a session that has been started or has already been started in response to an access request received from the network access device 22, or a search process is performed.
When the process is started in FIG. 5, the access request packet from the network access device 22 is first received in step S1, and in step S2, the user management unit 44 makes a session to the session management device 27 as shown in FIG. The information retrieval packet is transmitted, and the session information retrieval response packet from the session management device 27 is received in step S3.
FIG. 6 shows the packet formats of the session information search packet, the session information search response packet, and the packet that needs to be described later. In the session information search packet, the session information search type is stored as the packet type next to the TCP / IP header, and the mobile device identification information is stored at the end. This mobile device identification information corresponds to an identifier that identifies each mobile device, which is generally different from a telephone number, and this identification information is assumed to be extracted from, for example, an access request packet.
The session information search response packet includes the session information search response as the packet type, the mobile identification information (identifier), and the session information table inside the session management device 27, which will be described later, next to the TCP / IP header. A search result indicating whether or not there is a session record corresponding to the mobile identifier, and if there is a record, the IP address assigned corresponding to the session is stored.
Returning to FIG. 5, it is determined in step S4 whether or not the connection is new. In the new connection, the session record corresponding to the mobile device identifier is not stored in the session information table described above, and in this case, the address to be assigned in step S5 is determined.
In this decision, the details are shown in steps S10 to S16 on the right side, but in order to distribute the load, the record corresponding to the address range with the smallest number of addresses already allocated in the address information table 46 is searched. The address to be assigned is determined, and an access accept packet is sent to the network access device 22 in step S6 to end the process.
If the connection is not new in step S4, that is, if the session corresponding to the mobile device identifier is already registered in the session information table, the IP address corresponding to that session is used as it is in step S7 and accessed in step S6. An accept packet is sent and processing ends.
As described above, the session means a series of packet transmission / reception until the user logs out by the mobile device using the IP address assigned by the user authentication device 24. Therefore, when a user receives different services in one session, the session includes a plurality of TCP connections corresponding to each service.
Figure 7 is an example of the stored data in the address information table 46. In the figure, the allocation range of the IP address assigned to the mobile device basically corresponding to the session is stored in consideration of the load sharing of the packet gateway devices 28a, 28b, ... In FIG. For example, when the load is evenly distributed, the allocation range is determined so that the number of addresses in the allocation range is equal.
In the address information table 46, therefore, the IP address allocation range, the number of IP addresses already assigned in the range, and each packet gateway device are in operation corresponding to each packet gateway device. The address of the user information table is stored as a pointer to the user information table 47 that stores the operating status of whether or not the packet gateway device and the IP address already assigned corresponding to each packet gateway device.
FIG. 8 is an example of the stored data in the user information table 47. In the figure, the user identifier, password, mobile device identification information, and telephone number correspond to the four IP addresses already assigned in the IP address allocation range for the packet gateway device Pgw2 in FIG. 7, respectively. It is stored as identification information.
Returning to FIG. 5, the details of the process of step S5, that is, the process of steps S10 to S16 will be described. When the processing is started, the next steps S11 and S12 are checked for each record in the address information table in step S10.
In step S11, it is determined whether or not the number of address information already allocated is the minimum, and after the minimum number is found, the operating state of the packet gateway device corresponding to the record is normal in step S12, that is, Whether or not it is in operation is determined, and if it is in operation, the process proceeds to step S13, and if it is not in operation, the processes after step S10 are repeated.
That is, it is determined whether or not the packet gateway device corresponding to the record having the next smallest number of IP addresses already assigned is operating, and if it is operating, the process proceeds to step S13 and subsequent steps. ..
In step S13, the address in the user information table corresponding to the address allocation range of the searched record, that is, the IP address already assigned by the pointer is searched, and the address not yet assigned in the allocation range is fetched in step S14. Then, the record corresponding to the IP address is added to the user information table in step S15, and the number of assigned IP addresses of the packet gateway device record corresponding to the IP address added in the address information table in step S16 is incremented. And end the process.
FIG. 9 is a block diagram of the session management device 27 of FIG. In the figure, the session management device is composed of a LAN driver unit or WAN driver unit 51, a TCP / IP protocol handler unit 52, a communication control unit 53, and a session management unit 54, and a session information table managed by the session management unit 54. It has 55.
FIG. 10 is an example of the stored data in the session information table 55. In the figure, the session information table 55 shows the session identifier, the mobile device identifier, the assigned IP address, the session status, and here, the session is in progress, corresponding to each session that has already been started. "Act" is stored.
As described in FIG. 3, the session management unit 54 of the session management device searches the session information table using the mobile device identification information as a key when receiving the session information search packet from the user authentication device 24, and obtains the result. It is returned to the user authentication device 24 as the session information search response packet described in FIG.
The user management unit 44 of the user authentication device sets a new IP address or an already assigned IP address as the access accept based on the response as described above, and transmits the new IP address to the network access device 22.
The user authentication device 24 assigns an IP address by processing the flowchart of FIG. 5 each time it receives an access request in order to distribute the load of the packet gateway device in operation as described above. Whether or not the packet gateway device is operating is monitored by the server monitoring unit 45 of the user authentication device as a health check, for example, at regular time intervals, and the monitored state is stored in the address information table.
After the IP address is assigned, the user authentication device 24 that receives the account start from the network access device 22 sends a session information registration packet from the user management unit 44 to the session management device 27, and corresponds to the assigned IP address. A session start notification packet is transmitted to the packet gateway device 28.
The packet formats of the session information registration packet and the session start notification packet are shown in FIG. In FIG. 6, in the session information registration packet, data is stored in the order of the header, the session information registration as the packet type, the mobile device identification information, and then the IP address, and the session start notification packet. In addition to the header, a session start notification as a packet type, mobile device identification information, and an IP address are stored in.
When a new session is started, the session management unit 54 of the session management device of FIG. 9 registers a record corresponding to the session in the session information table 55 and sets the session state to Act. A session information table is also provided in the packet gateway device, which will be described later, and its contents are exactly the same as those in FIG. The session management unit in the packet gateway device also registers the record corresponding to the new session in the same manner.
The session management device 27 manages the session status by the session management unit 54 from the reception of the session information registration packet from the user authentication device 24 to the reception of the status change (close) described later. In this session state management, the state of the session is managed as one of four states. The status is "None", which indicates that the session is unregistered, "Act", which indicates that the session is in progress, "Dormant", which indicates that the session is in progress but there is no communication for a certain period of time, and the state in which the session has ended. There are four "Close" indicating.
FIG. 11 is an explanatory diagram of the state transition of the session state managed by the session management device. In the figure, when the session is started in response to the session information registration from the user authentication device 24, the session information becomes an act as shown in 1). In this state, the dormant timer, which will be described later, times out, and when the status change (stop) from the user authentication device 24 shown in 2) is received, the session state transitions to dormant.
Or, as will be described later, for example, when the user terminates the communication, that is, when the status change (closed) from the user authentication device 24 is received in response to the user logout, the session state transitions to closed as shown in 3). ..
Although not directly related to the present invention, the mobile packet network constantly monitors whether or not communication with the mobile is possible, and this is called Interim monitoring. If communication with the mobile device is possible, the network access device 22 in FIG. 2 is notified that communication is possible at a relatively long interval such as an interval of 30 minutes. This is notified from the user authentication device 24 to the session management device 27 as a status change (interim), and while this notification is given, the act is maintained as a session state as shown in 6). If the interim monitoring timer times out before this status change (interim) is input from the user authentication device 24, the session state transitions from act to closed as shown in 8).
When the session state becomes dormant, the session timer is activated as described later. If a packet sent from the user to the service providing server side is input to the network before the session timer times out, a status change (start) is input as shown in user authentication devices 24 to 5), and the session state is entered. Moves to act again.
If the session timer times out when the session state is dormant, the session state transitions from dormant to closed as shown in 7). Further, as described above, for example, when the user terminates the communication, the status change (closed) from the user authentication device 24 is input as shown in 3), and the session state transitions to closed.
When the session state is closed and the session log showing the data of that session is output, the session state transitions from closed to nan as shown in 4). In this session log output, the corresponding record in the session information table that has transitioned to closed is output to the log file, and the entry is deleted.
Next, the operation of the load distribution device (LB) 25 shown in FIG. 2 will be described. FIG. 12 is a configuration block diagram of this load distribution device. In the figure, the load distribution device is composed of a LAN driver unit or WAN driver unit 61, an address translation unit 62, a load distribution control unit 63, a server monitoring unit 64, and a load distribution policy management unit 65, and is also a load distribution policy management unit. It has a distributed policy information table 66 managed by 65.
As described in FIG. 2, the load distribution device (LB) transmits the data packet sent from the mobile device side to any of a plurality of packet gateway devices 28a, 28b, ... Via LAN / WAN26. The load is distributed to the packet gateway device by deciding whether to distribute the packet, rewriting the address portion of the packet, and transferring the packet.
The load distribution device analyzes the communication protocol of the passing packet, and in the case of a connection-oriented protocol (TCP protocol), changes the state of the TCP connection, that is, the state of connected, unconnected, waiting for connection, etc. For example, TCP connection management is performed by changing from unconnected to connected.
When the connection is opened, the packet gateway device as the packet distribution destination is determined based on the contents of the distribution policy information table 66. The contents of this distribution policy information table 66 are the same for all of the plurality of load distribution devices (LB) 25a, 25b, ... In FIG.
As described with reference to FIG. 3, the network access device 22 starts packet communication for transmitting the user data packet from the mobile device 20 to the service providing server after receiving the access accept from the user authentication device 24. The load distribution device existing on the route between the network access device 22 and the service providing server receives the user data packet and executes load distribution to distribute the packet to one of a plurality of packet gateway devices.
FIG. 13 is a processing flowchart in the load distribution device. When the process is started in the figure, the packet is first received by the address translation unit 62 in FIG. 12 in step S21, and the source IP of the received packet is received for each record in the distribution policy information table 66 in steps S22 and S23. The process of searching for records whose addresses are within the address allocation range is executed.
Figure 14 shows an example of the stored data in the distributed policy information table. In the figure, the destination MAC address, the destination status, the alternative destination MAC address 1, and the destination correspond to the allocation range of the IP address uniquely assigned to the session identification information and the mobile device identification information as described above. The state is stored.
Here, the destination MAC address is the address of one of the packet gateways of the plurality of packet gateway devices 28a, 28b, ... In FIG. 2, and the destination state is whether or not the packet gateway is operating normally. Is shown.
In addition, the alternative destination MAC address 1 should distribute the data packet having the IP address within the IP address allocation range of the record as the source address when the packet gateway specified by the destination MAC address in the record goes down. Indicates the address of the alternative packet gateway device.
Although not shown in FIG. 14, if the packet gateway specified by the alternative destination MAC address 1 also goes down, it is possible to further store the address of the packet gateway to be substituted.
Returning to FIG. 13, when a record whose source IP address is within the address allocation range is searched in the processing of steps S22 and S23, the state of the packet gateway specified by the destination MAC address in that record is normal in step S24. That is, it is determined whether or not it is operating, and if it is normal, the destination MAC address of the received packet is rewritten to the destination MAC address of the record in step S25, and it has the rewritten MAC address in step S26. A packet is sent to the packet gateway device to end the process. The storage position of the MAC address in the packet will be described later.
If the state of the packet gateway device specified by the destination MAC address is not normal in step S24, is the state of the packet gateway specified by the alternate destination MAC address 1 for that record in step S27 normal? If it is normal, the destination MAC address is rewritten to the alternative destination MAC address 1 in step S28 as in S25, and the packet is sent to the gateway device in step S26 to end the process. ..
Further, if the state of the packet gateway device as the alternative destination is not normal in step S27, the received packet is rejected in step S29, and the process ends. As a result, in the case of a TCP connection, the packet is retransmitted, but if one of the packet gateway devices of the destination or the alternative destination returns normally, the retransmitted packet is sent to the returned packet gateway, and thereafter. Normal processing is performed. If the packet gateway device remains abnormal, the retransmitted packets will continue to be rejected and eventually the TCP connection will be disconnected.
Figure 15 shows an example of the data format of TCP / IP packets. In the figure, the part corresponding to the Ethernet frame, the IP header, and the TCP header are stored before the user data. The source IP address determined in step S23 of FIG. 13 is stored in the IP header part, and the destination MAC address rewritten in step S25 or S28 is stored in the part corresponding to the Ethernet frame. It should be noted that such a data format is based on the following documents.
Reference) Internet Standard Quick Reference, by Masami Nosaka, O'Reilly Japan Figure 16 is a block diagram of a packet gateway device. As described above, in the system of FIG. 2, the data packets sent and received between the mobile device and the service providing server in one session are always the same in the plurality of packet gateway devices 28a, 28b, ... It is transmitted and received via the packet gateway device, and the packet gateway device distributes the load to the service providing server and executes various processes such as service authentication and billing process as the most important device in the present embodiment.
In FIG. 16, the packet gateway device includes a LAN driver unit or WAN driver unit 71, an address translation unit 72, a TCP / IP protocol handler unit 73, a load distribution unit 74, a gateway control unit 75, a server monitoring unit 76, and a distribution policy management unit 77. , Packet information collection unit 78 that collects information necessary for billing, Billing attribute notification unit 79 that extracts attributes necessary for billing from data packets, Service authentication unit 80 that determines whether services for mobile devices are possible, For example, when a service is not authenticated, it is composed of a proxy response unit 81 that notifies the mobile device side, a billing log editing unit 82 that edits the billing log, and a session management unit 83, and is managed by the distributed policy management unit 77. Policy information table 84, address information storage table 85 that stores addresses required for address translation of address translation unit 72, packet information table 86 managed by session management unit 83, service order information table 87 that is referenced for service authentication, etc. , And the same service can be provided corresponding to the service provision server information table 88, the billing log database (DB) 89 that stores the billing log created by the billing log editorial unit 82, and the TCP connection with the mobile device side. Among the service providing servers, the distribution information table 90 that stores the servers that should actually distribute the packets is provided.
Note that this distribution information table is used, for example, to sequentially distribute packets from the server with the lowest CPU usage rate among each service providing server, and periodically checks the CPU usage rate and stores the result. Packets are sorted.
The content of the session information table 86 in FIG. 16 is the same as that of the session information table 55 in the session management device described with reference to FIG. The distribution policy information table 84 has the same name as the distribution policy information table 66 in the load distribution device, but its contents correspond to each type of service and determine which of the plurality of service providing servers each packet should be distributed to. It stores the distribution policy, and an example of the data will be described later, but it is different from the contents of the table in FIG.
Further, in FIG. 16, the TCP / IP protocol handler unit 73 and the gateway control unit 75 are directly connected to each other, and the gateway control unit 75 and the server monitoring unit 76, and the server monitoring unit 76 and the distributed policy management unit 77 are also directly connected to each other. It is connected.
17 to 21 are flowcharts of packet distribution processing by the packet gateway device, FIGS. 17 to 19 are processing for packets from the mobile device to the service providing server, that is, uplink packets, and FIGS. 20 and 21 are the service providing server. This is an explanation of the processing for the downlink packet from the mobile device to the mobile device. These processing flowcharts will be described with reference to FIGS. 22 and 23.
FIG. 22 is an explanatory diagram of an example of stored data in the address information storage table 85 in the packet gateway device, and FIG. 23 is an explanatory diagram of the stored data in the distribution policy information table 84. Before explaining the processing of the flowcharts of FIGS. 17 to 21, the stored contents of these tables will be described.
The address information storage table in FIG. 22 contains unique key information used to store the source address and the like stored in the packet when the packet gateway device rewrites the packet destination address and the like as described later. The source IP address, source port number, destination IP address, and destination port number are stored as storage address information corresponding to each of the above.
In the distributed policy information table of FIG. 23, each group of service providing servers, that is, the representative IP address of the group, the number of real servers, and the IP address of the real servers, respectively, according to the type of service provided. The IP addresses of the real server 1 and the real server 2 are stored as the addresses of the two service providing servers of the group corresponding to the service type of, for example, mail and chat, and indicate whether or not each server is in operation. As the server status, "normal" indicating that it is operating is stored. Then, as a distribution policy, two real servers are used alternately, for example, and packets are distributed.
17 to 19 are flowcharts of uplink packets by the packet gateway device, that is, packet distribution processing (load distribution processing for the service connection server) sent from the mobile device to the service providing server.
This packet gateway device also operates as a transparent proxy. As a mechanism of TCP / IP, a device on the network, for example, a proxy, notifies the upper application only of the MAC address addressed to its own device on the Ethernet layer, and sends the other device to the network. Furthermore, in general, among the MAC addresses of the own device, the processing of the packet whose destination IP address is the address of the own device is notified to the application one level higher, but the transparent proxy is when the IP address is not addressed to the own device. Also, the IP address is rewritten to notify the higher-level application of packet reception. In this case, the original IP address is stored, for example, in a table.
When the process is started in FIG. 17, a packet is first received by the address translation unit 72 in step S31, and in step S32 it is determined whether or not the packet is a connection packet for a new TCP connection, that is, a connection opening packet. In the case of an open (connect) packet, the destination address of the received packet and the source address information are stored in the address information storage table 85 of FIG. 16 using the unique source port number as a key in step S33. Will be done.
Subsequently, in step S34, the destination address is set to the address for the own device, the source port number is set to the above-mentioned unique key number, and the packet is passed to the gateway control unit 75 via the TCP / IP protocol handler unit 73. , TCP / IP protocol processing is performed in step S35, and it is determined in step S36 whether or not the packet is a connection establishment (connection) packet.
In the case of an open packet, the gateway control unit 75 retrieves the destination address information from the address information storage table 85 using the packet source port number as a key in step S37, and the destination address is obtained in step S38 in FIG. Based on this, the TCP / IP protocol handler unit 73 is requested to perform normal TCP connection connection processing to the service providing server.
TCP / IP protocol processing is performed in step S39, the distribution policy information table 84 is referenced by the load distribution unit 74 in step S40, and the representative address for multiple service providing servers that provide the same service as the destination address in step S41. It is determined whether or not there is a representative address, and if it is a representative address, it is determined in step S42 whether or not it is a connection establishment (connection) packet, and if it is an open packet, it is serviced according to a distribution policy such as round robin in step S43. The providing server is selected and its real address information is set as the destination address of the packet.
Subsequently, in step S44 of FIG. 19, the real address of the server selected by using the source port number as a key is saved in the distribution information table 90, and in step S45, the disconnection response (disconnection response) which is a normal disconnection request of the TCP connection to the server. It is determined whether or not an attempt is being made to send either a fin ack) or an abnormal disconnection request (reset). Since the packet is a connection establishment packet here, the source address is the address of the packet gateway device in step S46. Is set, the packet is sent to the service providing server, and the process ends. Since the address of the packet gateway device is set as the source address here, the downlink packet from the service providing server to the mobile device side is transmitted to the packet gateway device that transmitted the uplink packet. Since S45 and S57 are executed for TCP connection disconnection processing, TCP connection disconnection response (fin ack) and abnormal disconnection request (fin ack) and abnormal disconnection request (fin ack) and abnormal disconnection request (fin ack) as TCP / IP protocol processing in step S111 of FIG. 21 for the downlink packet described later. This is because reset) may be sent to the mobile device side.
If the received packet is not a connection opening (connection) packet in step S32 of FIG. 17, it is determined in step S47 whether or not the received packet is a data packet in the middle of the connection from the connection to the disconnection. After the address information of the packet destination and the source is searched from the address information storage table 85 using the unique source port number as a key in step S48, the processing of steps S34 and S35 is the same as for the connection packet of the connection. Is executed.
Then, in step S36, it is determined that the connection packet is not the connection packet, and in step S49, it is determined that the data packet is in the middle. In step S50, the destination address information is extracted for the connection packet in the same manner as in step S37, and FIG. In step S51, the TCP connection is identified based on this destination address information, and the data transmission process is requested to the TCP / IP protocol handler unit 73.
The processing of steps S39 to S41 is performed in the same manner as for the connection packet, in step S42 it is determined that it is not a connection packet, in step S52 it is determined that it is an intermediate data packet, and in step S53 of FIG. Using the original port number as a key, the real address of the server to which this data packet should be sent is extracted from the distribution information table 90, and it is determined in step S45 that it is not the case to send a disconnection response or an abnormal disconnection request packet, and step S46. The packet is sent at and the process ends.
If it is determined in step S47 of FIG. 17 that the received packet is not an intermediate data packet, the received packet is a TCP connection abnormal disconnection request (reset) or a disconnection response (fin ack) corresponding to the normal disconnection request. Therefore, after the address information of the packet destination and the source is searched in step S54 as in step S48, the processes of steps S34 to S36 are performed, and then the data packet in the middle of step S49 is also performed. It is determined that the TCP connection is disconnected, the destination address information is retrieved from the address information storage table 85 in step S55, and the TCP connection disconnection process on the mobile device side is sent to the TCP / IP protocol handler unit 73 in step S56 in FIG. At the same time as making a request, the TCP connection on the server side is identified based on the destination address retrieved in step S55, and the TCP / IP protocol handler unit 73 is requested to perform the disconnection process.
Then, after the processing of steps S39 to S42, it is determined in step S52 that it is not an intermediate data packet, and in step S45 of FIG. 19, it is determined that a disconnection response or an abnormal disconnection request packet is transmitted to the server. After the corresponding record in the address information storage table 85 is deleted by the address translation unit 72 in step S57, a connection disconnection response or abnormal disconnection request packet is sent to the service providing server in step S46 to end the process.
As described above, since the user authentication device 24 assigns an IP address to the mobile device and one packet until the user logs out can generally include a plurality of TCP connections, the TCP connection can be included. The open (connect) packet is not always the first packet in the session, and the TCP normal disconnect (response) packet or TCP reset (abnormal disconnect request) packet is not necessarily the last packet in the session.
If the destination address is not the representative address in step S41 of FIG. 18, the process immediately proceeds to the process of step S45 of FIG. Then, in the case of a connection packet of the connection or a data packet in the middle, the packet is transmitted to the service providing server as the destination in step S46, and the process ends. If the packet is a connection disconnection response or an abnormal disconnection request packet, the processing of steps S57 and S46 is performed to end the processing.
When the destination address is not the representative address in step S41, one service is sent in advance instead of transmitting the packet by specifying the representative addresses of multiple service providing servers that provide the same service from the mobile device side. Corresponding to the case where the real address of the providing server is specified and the packet is sent, the representative address is not found in the distribution policy information table 84, and the load is not distributed by the packet gateway device.
20 and 21 are flowcharts of downlink packets, that is, packets transmitted from the service providing server side to the mobile device by the packet gateway device. When the process is started in the figure, the packet sent from the service providing server side is first received by the address translation unit 72 in step S101, and the distribution policy information table 84 is referred to in step S102 as the packet source. It is determined whether or not the corresponding record including the real address of the service providing server of is found in step S103, and if it is found, a plurality of source addresses providing the same service from the real address of the service providing server in step S104. It is translated into the representative address for the server of, and it is determined in step S105 whether or not the packet is an abnormal disconnection request (reset) packet of the TCP connection.
If normal communication is performed in the TCP connection, it is determined that it is not a reset packet, the packet is passed to the gateway control unit 75 via the TCP / IP protocol handler unit 73 in step S106, and TCP in step S107. / IP protocol processing is performed.
In step S108 of FIG. 21, the gateway control unit 75 reads the address of the mobile device stored from the address information storage table 85, that is, the source IP address, using the TCP port number as the destination address information of the packet as a key. Then, in step S109, it is determined whether or not the packet is a data packet in the middle of the TCP connection.
If it is a data packet in the middle, the socket is set by the gateway control unit 75 in step S110 based on the IP address of the source (which should be the destination here) read out and the port number used as the key. The specified data transmission, that is, the issue of the send function is performed via the TCP / IP protocol handler unit 73.
TCP / IP protocol processing is performed in step S111, and the representative address of the service providing server saved from the address information storage table 85, that is, saved by the address conversion unit 72 in step S112, using the destination port number as a key. Whether the destination IP address and port number and the port number of the mobile device, that is, the stored port number, are set in the packet, and either a disconnect response or an abnormal disconnection request is sent to the mobile device in step S113. Whether or not it is determined, and if not, in step S114, a packet is transmitted from the address conversion unit 72 to the mobile device to end the process. Since S113 and 117 are executed because the TCP connection is disconnected, the TCP / IP protocol handler part performs the TCP connection disconnection response (fin ack) and abnormal disconnection as TCP / IP protocol processing as shown in step S35 in FIG. This is because the request (reset) may be sent to the mobile device side.
In step S103 of FIG. 20, when the source address of the received packet, that is, the record indicating the representative address corresponding to the real address of the service providing server is not found in the distributed policy information table 84, that is, the destination of the upstream packet from the mobile device. If the representative address is not specified as the address, the processing of steps S105 to S114 is performed and the packet is transmitted to the mobile device without performing the processing of step S104, but the service is provided in step S112. The packet is transmitted in step S114 without setting the representative address of the server.
If the received packet is an abnormal disconnection request for the TCP connection from the server in step S105 of FIG. 20, that is, a reset packet, the address conversion unit 72 deletes the corresponding record in the distribution information table 90 in step S115, and then the step. The processing of S106 to S108 is performed.
Then, in step S109, it is determined that the packet is not in the middle, and in step S116, the gateway control unit 75 identifies the socket based on the destination IP address read in step S108 and the port number as a key. The TCP connection between the server side and the mobile device side is disconnected, that is, the close function is issued via the TCP / IP protocol handler unit 73.
Then, after the processing of steps S111 and S112, it is determined in step S113 that the connection disconnection packet is transmitted, and in step S117, the address conversion unit 72 deletes the corresponding record in the address information storage table 85, and then in step S114. A packet is sent to end the process.
The TCP / IP protocol handler unit 73 of the packet gateway device corresponds to the IP address of the received packet when the uplink packet is received, and sets the source MAC address of the packet, that is, the MAC address of the load distribution device as the packet source. Save to a cache table (not shown). Then, when the downlink packet is received, this table is searched, the MAC address of the load distribution device that transmitted the uplink packet is set as the destination MAC address, and the downlink packet is transmitted to the load distribution device.
The address translation in the packet gateway device as described above will be further described with reference to FIG. 24. In the figure, the source address as the address information of the TCP / IP packet is entered in the format of "source network section.host section", and the destination address is entered in the format of "destination network section.host section". And.
Therefore, for the uplink packet NetA.GrA.1 NetE.1 sent from the mobile device to the representative address NetE.1 of the service providing server, the packet gateway device converts the source address to the real address NetE.5 of its own device. , Also, convert the destination address to the real address NetE.7 of the service providing server and send it as NetE.5 NetE.7.
The service providing server that receives this uplink packet sends the downlink packet to the gateway device as NetE.7 NetE.5, and the packet gateway device sends the saved mobile address to the destination address and the source. The address is converted back to the representative address of the service providing server, and the downlink packet is sent to the mobile device side.
Next, service authentication by the packet gateway device will be described. This determines whether or not the service requested by the mobile device, that is, the service provided by the corresponding service providing server, is available to the user of the mobile device.
As described above, in the conventional mobile packet network described with reference to FIG. 33, the TCP connection is managed by the service providing server itself, so that the TCP connection is reconnected every time the service used is changed from the viewpoint of the mobile, for example. There is a problem that it takes time to switch services including service authentication.
FIG. 25 is a flowchart of the service authentication process by the packet gateway device, and this process is basically executed by the service authentication unit 80 of FIG. FIG. 26 is an example of the stored data of the service order information table 87, and FIG. 27 is an example of the stored data of the service providing server information table 88.
When the processing is started in FIG. 25, the gateway control unit 75 first receives the first service request (connection start) packet transmitted from the mobile device in step S61, and the source IP address is changed from the packet in step S62. It is taken out and given to the service authentication unit 80.
The source IP address corresponds to the assigned IP address in the session information table 86 of FIG. 10, and the corresponding mobile device identification information is searched from this table in step S63. Then, in step S64, the destination IP address is extracted from the received packet. This destination IP address is a representative IP address of a group of service providing servers that provide the same service, and the service type corresponding to the representative IP address is determined from FIG. 27.
In the service order information table of FIG. 26, whether or not various services such as e-mail and chat are available (OK) corresponding to the mobile device identification information is stored, and the mobile device identification information and the mobile device identification information are stored in step S65. The content of FIG. 26 is searched according to the service type determined in step S64, and it is determined in step S66 whether or not the corresponding service can be used.
If possible, the received packet is passed to the gateway control unit 75 in step S67, and the packet is subsequently transmitted to the service providing server. If the use of the service is not permitted in step S66, the proxy response unit 81 sends a TCP reset packet to the mobile device side, disconnects the connection, and ends the process.
FIG. 28 is a flowchart of the billing information creation process by the packet gateway device. The figure will be described with reference to the data of the billing record shown in FIG. 29. In the conventional system described with reference to FIG. 33, only each service providing server authenticates the contracted service unit, and a billing record for collecting charges for paid contents is also created for each service providing server. , It was not possible to charge them collectively, or to charge the service fee on behalf of the server connected externally to the system.
In the present embodiment, the packet information collecting unit 78 of FIG. 16 collects the number of packets and the total packet length for each combination of the address information of the mobile device and the address information of the service providing server in order to create the billing log. Then, the result is notified to the billing log editorial department 82. Further, when there is billing attribute information to be interpolated for specifying the billing destination, the billing attribute notification unit 79 collects the information from the data packet from the user, and the result is notified to the billing log editing unit 82.
The billing log editing unit 82 edits the billing log based on the information notified from the packet information collecting unit 78 and the billing attribute notification unit 79, and stores the result in the billing log DB 89. The contents of this billing log are the source specified from the session information based on the address information of the mobile device, the destination as the IP address of the service providing server according to the notification from the packet information collection unit 78, and the billing attribute. It contains the billing attribute information notified from the notification unit 79.
When the process is started in FIG. 28, first, in step S70, the packet information collecting unit 78 receives the received packet via the address translation unit 72, and in step S71, the packet is a packet that opens a TCP connection, that is, a TCP syn packet. It is determined whether or not there is.
In the case of a packet to be opened, a new billing record is generated in step S72, the destination IP address and the destination IP address are extracted from the received packet by the packet information collecting unit 78, and the destination IP address and the destination IP address are set in the billing record. If the packet is not to be opened, the process immediately proceeds to step S73.
In step S73, it is determined whether or not the received packet contains the billing attribute information, for example, the URL of the connection server in the case of an external connection as shown in FIG. 29, and if so, the billing attribute information in step S74. Is set in the billing record, and if it does not exist, the process immediately proceeds to step S75.
In step S75, the number of packets in the billing record is incremented by one, the packet length taken out from the received packet in step S76 is added to the total packet length of the billing record, and in step S77 whether or not the TCP connection is disconnected, that is, Whether or not the received packet is a TCP fin ack packet is determined, and if not, the processing of step S70 and subsequent steps is repeated.
If the TCP connection is disconnected, the packet information collection unit 78 passes the billing record to the billing log editing unit 82 in step S78, and the billing record is edited in step S79, that is, the mobile device identification information is obtained from the source IP address. Also, the service type and representative IP address of the service providing server are set from the destination address, and the result is written to the billing log DB89 as a billing log in step S80, and the process ends. Note that FIG. 29 shows the storage result in the billing log DB89, and the contents collected by the packet information collecting unit 78, for example, the destination IP address is converted into the mobile device identification information and stored as the billing log. ..
FIG. 30 is an explanatory diagram of the inter-device processing sequence at the end of the session. This figure corresponds to the inter-device processing sequence at the start of the session in FIG. 3, and shows the sequence at the time of user logout when the mobile device 20 ends communication.
At the time of user logout in FIG. 30, an account stop is sent from the network access device 22 to the user authentication device 24, and the user authentication device 24 that receives this sends a status change (close) to the session management device 27, and also a packet gateway device. Send a session end notification packet to 28. The packet format of these packets is shown in Figure 6.
The session management unit 54 of the session management device deletes the corresponding record in the session information table 55, and the session management unit 83 of the packet gateway device also deletes the corresponding record in the session information table 86.
FIG. 31 shows a processing sequence at the time of dormant, that is, when the TCP connection is continued but communication with the mobile device is not performed for a certain period of time. Generally, the network access device 22 sends an account start to the user authentication device 24 when starting a TCP connection, and at the same time, starts monitoring by a dormant timer. The session information registration from the user authentication device 24 to the session management device 27 and the session start notification to the packet gateway device 28 are performed in the same manner as in FIG.
However, if the dormant timer times out before the data packet from the user is sent from the mobile device 20 to the network access device 22, the network access device 22 sends an account stop to the user authentication device 24.
Upon receiving this, the user authentication device 24 sends a status change (stop) to the session management device 27, and the session management unit 54 of the session management device changes the session state of the corresponding record in the session information table 55 to a dormant. .. The session management unit 83 of the packet gateway device 28 also changes the session state of the corresponding record in the session information table 86 to dormant.
The network access device 22 starts monitoring the session timer after the timeout of the dormant timer occurs. Although not shown in FIG. 31, when the session timer times out, an account stop is sent to the user authentication device 24.
Upon receiving this, the user authentication device 24 sends a session end notification to the session management device 27 and the packet gateway device 28 to change the status (close). The session management unit 54 of the session management device and the session management unit 83 of the packet gateway device each change the session state of the corresponding record in the session information table to closed.
On the other hand, if the user data packet is received again from the mobile device 20 as shown in FIG. 31 before the session timer times out, the network access device 22 sends the account start to the user authentication device 24 again. , The data packet is transmitted to the route on the load distribution device side.
The user authentication device 24 that has received the account start sends a status change (start) to the session management device 27. The session management unit 54 of the session management device and the session management unit 83 of the packet gateway device change the session state of the corresponding record in the session information table to act, respectively. The transmission and reception of data packets beyond the load distribution device 25 is the same as at the start of the session in FIG.
Next, processing when the packet gateway device that plays the most important role in the present embodiment goes down will be described. As described above, the server monitoring unit 45 of the user authentication device performs a health check that collects the operating status of the packet gateway device 28 at regular intervals. Then, when the packet gateway device goes down, it is notified to the load distribution device 25 and the session management device 27.
The existing session between the packet gateway device 28 and the service providing server 30 is disconnected, and the downlink packet of the existing session is discarded by the packet gateway device 28 or the service providing server 30.
The user management unit 44 of the user authentication device 24 provides new address information other than the range assigned to the downed packet gateway device based on the address information table so that new sessions are not distributed to the downed packet gateway device. Assign to session.
When the packet gateway device 28 goes down in multiplex, the packet is distributed to the packet gateway device as an alternative distribution destination set in multiplex. When the packet gateway device 28 is restored, the server monitoring unit 45 of the user authentication device notifies the load distribution device 25 and the session management device 27 of the recovery. The user management unit 44 of the user authentication device 24 resumes the allocation of address information to the recovered packet gateway device 28, and the load distribution device 25 resumes the distribution of packets to the recovered packet gateway device 28.
In the above, the first embodiment of the present invention relating to the communication method between the mobile communication terminal and the service providing server, which is managed in the form of a session composed of one or more TCP connections, has been described in detail. Subsequently, a second embodiment of the present invention will be described.
In the second embodiment, the present invention shall be applied to communication by UDP (User Datagram Protocol) in addition to TCP, and communication by TCP connection and UDP packet shall be handled in a unified manner.
The session managed by the session management device described in FIG. 9 indicates the communication status between the mobile device and the network access device in PPP (Point-to-Point Protocol) as a lower layer of TCP / IP. is there. On the other hand, the user session is related to the communication state between the mobile device and the service providing server in the application protocol, such as HTTP, which is a higher layer for TCP / IP, and the user session is described later. It is managed by the packet gateway device.
The processing sequence between the devices described in FIG. 3 and the address allocation process by the user authentication device described in FIG. 5 can be directly applied to the second embodiment, and FIG. 5 shows the address allocation by the PPP protocol. The flow chart of the process at the time is shown.
As will be described later, in the second embodiment, since the user session is managed by the packet gateway device, the operation of the packet gateway device is different from that of the first embodiment. Therefore, the operation will be described below.
The management of the user session by the packet gateway device, that is, the management of the start and end of the user session is basically performed by using the address information storage table. Therefore, the content of the address information storage table is different from that of FIG. 22 in the first embodiment. FIG. 32 is an example of the stored contents of the address information storage table in the second embodiment.
In FIG. 32, the user session identifier is an identifier uniquely assigned to the user session, and the protocol identification indicates the protocol identification of the transport layer, that is, the protocol type such as TCP or UDP.
The contents of the stored address information are basically the same as in FIG. 22, and the source IP address and the source port number indicate the IP address and port number of the mobile device, and the destination IP address and the destination port number. Shows the representative IP address and port number of the service providing server, and the real server IP address, which is not stored in Figure 22, shows the IP address of the real server in one group assigned as a result of load distribution. ..
Next, the type of user session will be described. One of the four units of login, service, packet, and connection is used as the type of user session managed by the packet gateway device. The user session is managed by the packet gateway device according to the type. That is, in order to perform load distribution when the user session starts, the service providing server of the destination to which the packet is transmitted is determined, and the determination is canceled at the end of the user session.
In the first login unit of the user session type, the user session is defined as the period from the notification of the start of the session to the notification of the end of the session from the user authentication device. During that time, the packets sent from the mobile device side to the packet gateway device are distributed to the same server for each service.
In the login unit, when the mobile device uses a different service without logging out, the distribution information table stores the IP address information of the real server determined by the round robin method at the start of the user session. The record of is left as it is without being deleted, and when the service is used again, the packet is distributed by referring to the record.
In the second type of service unit, the same service is treated as one user session while using the same service. During that time, the packets sent from the mobile device side to the packet gateway device are distributed to the same service providing server. In the case of this type, when using a different service without logging out on the mobile device side, the record of the distribution information table that stores the IP address of the real server determined by the method such as round robin is Will be deleted. Then, when the user of the mobile device uses the service again, the actual server of the distribution destination is determined again by a method such as round robin, and the packet is distributed.
The packet unit as the third type is intended for the case of UDP, one UDP uplink packet is sent from the mobile device to the service providing server, and the corresponding downlink packet is transmitted from the service providing server to the mobile device side. Is treated as one user session. That is, load distribution is performed for each UDP packet sent to the packet gateway device, and each time the packet gateway device receives a UDP packet from the mobile device side, the service of the distribution destination is provided using a method such as round robin. Determine the server and distribute the packets.
The fourth type is on a connection-by-connection basis and is intended for TCP. In this connection unit, load distribution is performed in units of the connection executed between the mobile device and the service providing server in the first embodiment described above, and the method is the same as in the first embodiment.
FIG. 33 is an explanatory diagram of the timing from record generation to record deletion of the address information storage table corresponding to the type of user session. As shown in the figure, common to the four user session types, the record corresponding to each user session is generated when the user authentication device notifies the start of the session, and the record is deleted from the user authentication device. It will be done when the end is notified.
On the other hand, the timing at which the address information is actually saved, particularly the timing at which the destination address information is set in the record, differs depending on the type of user session. First, in the login unit, the destination address information is set in the record when the destination address information is not set in the record when the uplink packet from the mobile device to the service providing server is received, or it is set. Is also the case where the destination address information stored in the received packet and the destination address information in the record of the address information storage table are different, and in this case, the record in which the destination address information is already stored. In addition, a new record in which the destination address information stored in the packet is set is added.
In the login unit, when a user uses a different service without logging out, a record is added corresponding to the different service, and the record is already sent as in the case of the record in the distribution information table described above. The record in which the destination address information is set is not deleted and is retained in the address information storage table in case the user uses the corresponding service again.
In the service unit, as in the login unit, if the destination address information is not set in the record when the uplink packet is received, the destination address information is set in the record, but the destination address is already set in the record. If the information is set and the address information is different from the address information stored in the received packet, the destination address information is overwritten. By performing this overwriting, the destination address information that has already been set before overwriting becomes invalid, and it is assumed that the corresponding user session for each service has already been substantially terminated.
In the third type of packet unit, the destination address information is set in the record of the address information storage table when the uplink packet from the mobile device is received and the destination address information of the record is cleared. Is the time when the downlink packet is transmitted to the mobile device.
Further, in the fourth type of connection unit, as described in the first embodiment, the destination address information is set at the time when the connection establishment request (TCP syn packet) is received from the mobile device, and the destination address information. The time to clear is the time when the connection disconnection response (fin ack packet) is sent to the mobile device.
FIG. 34 is a configuration block diagram of the packet gateway device according to the second embodiment. In the figure, compared with FIG. 16 in the first embodiment, the point that the user session type identification information table 97 is added is basically different. Further, the content of the address information storage table 85 is different from that of the first embodiment as described above.
The user session type is generally defined by the user according to the IP address and port number of the service representative server and the protocol type. FIG. 35 is an example of the stored contents of the user session type identification information table for identifying this user session type. The contents of this table are defined before the user starts the packet gateway device as described above, and the load distribution unit 74 in the gateway control unit refers to the contents to identify the user session type.
Only one user session type can be defined for the service provided on the service providing server side. For example, it is possible to set both login unit and service unit as user session type for one service. Can not.
The processing by the packet gateway device will be described below. First, as the processing at the time of login and logout of the mobile device, the processing of creating and deleting the record in the address information storage table 85 is performed.
That is, when the session start packet is received from the user authentication device, the session management unit 83 generates a record in which the IP address information of the mobile device, that is, the source IP address and the source port number, is set in the address information storage table 85. Will be done. In that case, a unique key used as a user session identifier is set.
When the session end packet from the user authentication device is received, the session management unit 83 searches the contents of the table using the IP address information of the mobile device as a key, and deletes the record in which the source IP address and the like are set.
36 to 40 are flowcharts of processing by the packet gateway device at the time of receiving a packet. 36 to 38 are flowcharts of processing when an uplink packet is received from the mobile device to the service providing server, and FIGS. 39 and 40 are flowcharts of processing when a downlink packet is received from the service providing server to the mobile device.
When the process is started in FIG. 36, first, in step S121, the packet is received by the address conversion unit 72 as in step S31 of FIG. 17, and the source IP address stored in the received packet in step S122 is used as a key. The source IP address in the address information storage table is searched as, and it is determined in step S123 whether or not the address is found. If not, for example, the session start packet from the user authentication device has not been received. In step S124, the packet is rejected and the process ends.
If the source IP address is found in step S123, it is determined in step S125 whether the IP address and port number as the destination IP address information are set in the record, and if not, the user in step S126. It is determined whether the session type is in packet units or in connection units and the received packet is a syn packet indicating a connection establishment request. If neither is the case, immediately, and in either case, step S127. After the destination IP address information and the source port number are set in the record in step 2, the process proceeds to step S128 in FIG. 37. This is because if the user session type is packet unit, it is necessary to set the destination IP address etc. in the record every time a packet is received, and even if it is a connection unit and a connection establishment request. ..
In step S128 of FIG. 37, the destination address of the packet is set to the address for the local server, and the source port number is set to a unique number used for the user session identifier, and the packet is sent via the protocol handler unit 73. It is sent to the gateway control unit 75, and protocol processing is performed by the protocol handler unit 73 in step S129.
In step S130, the gateway control unit 75 retrieves the destination address information stored in the address information storage table 85 by the address translation unit 72 using the source port number as a key, and in step S131, the gateway control unit 75 obtains a unique key. It is set in the source port number, and the protocol handler unit is requested to perform normal packet transmission processing for the service providing server based on the destination address information, and the protocol processing is performed by the protocol handler unit 73 in step S132.
Subsequently, in step S133 of FIG. 38, the source port number is used as a key to search the distribution information table, and in step S134, it is determined whether or not the IP address of the real server is set in the distribution information table. In this case, the service providing server is selected from the distributed policy information table according to a method such as round robin in step S135, the address information of the real server is acquired and saved in the distribution information table, and the address of the real server is the packet in step S136. It is set to the destination address, the address of the packet gateway device is set as the source address in step S137, the packet is sent to the service providing server, and the process ends.
If the destination IP address information is set in the record in step S125, the user session type table is searched using the protocol type and destination IP address information as keys in step S140, and the user session type is the login unit in step S141. In that case, it is determined in step S142 whether or not the destination IP address information is different from the information stored in the received packet.
If there is no difference, a record is immediately added to the address information storage table using the same user session identifier if there is a difference, and if there is a difference, the source address information and the destination address information are set. Later, the processing after step S128 is performed. Here, the process of step S143 is performed as a process of adding a record when the user uses a different service in the case of a login unit as described above.
If it is determined in step S141 that the user session type is not a login unit, it is determined in step S144 whether the user session type is a service unit, and if it is a service unit, the destination IP in the record is determined in step S145. Whether or not the address information differs from the information stored in the received packet is determined, and if they do not differ, immediately, and if they do, the destination address information is overwritten in step S146, and then step S128 or later. Is processed. This is because, in the case of a service unit, it is determined that the user session type corresponding to the previous service providing server has ended when the user tries to receive a different service.
If it is determined in step S144 that the user acknowledgment type is not in service units, in step S147 it is determined whether the user acknowledgment type is in connection units, and if so, the packet type is checked in step S148. If the packet is the last fin ack packet of the connection, the processing after step S128 is performed after the destination address information of the corresponding record in the address information storage table is cleared.
If the IP address of the real server is set in the distribution information table in step S134, the process after step S136 is performed after the IP address of the real server is retrieved using the source port number as a key in step S149. Will be.
When the processing at the time of receiving the downlink packet is started in FIG. 39, the same processing as in steps S101 to S104 of FIG. 20 is first performed in steps S151 to S154, and the source address information is represented from the address of the real server. It is converted into address information, a packet is sent from the address translation unit 72 to the gateway control unit 75 via the protocol handler unit 73 in step S155, and protocol processing is performed in step S156.
Subsequently, in step S157 of FIG. 40, the gateway control unit 75 reads out the address information of the mobile device stored in the address information storage table using the packet destination port number as a key, and that information is used as the packet destination IP. A packet in which the port number set as the address and the port number used as the key is set as the destination port number is sent to the address conversion unit 72 via the protocol handler unit 73, the protocol processing is performed in step S158, and the step In S159, the address conversion unit 72 searches the address information storage table for the representative IP address information of the service providing server and the port number of the mobile device using the destination port number as a unique key, and sets them in the packet. The process is executed.
Subsequently, in step S160, the user session type table is searched using the representative IP address of the service providing server, and in step S161, the user session type is in packet units, or in connection units and the packet is the final final ack packet. In step S162, after the destination address information in the corresponding record of the address information storage table is cleared in step S162, if neither is the case, the address conversion unit 72 immediately in step S163. A packet is sent to the mobile device to end the process.
Although the second embodiment of the present invention has been described in detail above, in the second embodiment, by designating a login type as a user session type for a plurality of groups of service providing servers, a plurality of services are provided at the same time. It is possible to execute a series of communications with the service provision server of the group, and it is possible to receive the service provision using the multi-window screen on the mobile device side.
FIG. 41 is an explanatory diagram of a multi-window screen used for such a purpose. On the mobile side, by specifying the login type as the user session type as follows, from the same real server from login to logout in the group that provides service A and the group that provides service B, respectively. It will be possible to receive the service of.
TCP login type Aa TCP login type Bb where A and B indicate the IP address of the server corresponding to each of the above services, and a and b indicate the port number.
As described above, in the second embodiment, the service providing server that provides the service for each window is fixed by using the multi-window display, and it is possible to receive the service from login to logout.
Finally, loading of the program into the computer in this embodiment will be described. The packet gateway device 28, the session management device 27, the user authentication device 24, and the load distribution device 25, which play important roles in the present embodiment, each include a computer as an important component thereof. FIG. 44 is a typical block diagram of such a computer system.
In FIG. 44, the computer 91 is composed of a main body 92 and a memory 93. As the memory 93, various types of storage devices such as a random access memory (RAM), a hard disk, and a magnetic disk can be used, and such a memory 93 is used in FIGS. 5, 13, 17, 17 to 21, FIGS. 25, the program shown in the flowcharts of FIGS. 28 and 36 to 40, the program of claims 12 to 19 in the claims of the present invention, and the like are stored and executed by the main body 92 in the session. It is possible to realize gateway functions including centralized management of connections, sessions, and user sessions.
Such a program can be loaded into the computer 91 from the program provider side via the network 94, or stored in a commercially available and distributed portable storage medium 95 and loaded into the computer 91. Is also feasible. As the portable storage medium 95, storage media of various formats such as a CD-ROM, a flexible disk, an optical disk, and a magneto-optical disk can be used, and by setting such a storage medium in the computer 91, a setting, It is also possible to maintain user settings and realize gateway functions.
In the above description, the embodiment of the present invention has been described by taking as an example a mobile packet network to which a mobile phone as a mobile phone is connected, but the object of the present invention is limited to such a mobile packet network. It can be applied to any form of communication system as long as it is a communication system that uses a network in which communication terminals are connected and a plurality of entrances and exits on the side of a plurality of service providing servers exist.
The present invention can be used in wireless and wired communication systems. In particular, it is operated by a business operator that provides a communication service, such as a carrier, and can be used in a communication system that uses a large-scale network having a plurality of entrances and exits on the service providing server side.
<figref num="1">It is a principle block diagram of the mobile communication system of this invention.</figref><figref num="2">It is a system configuration block diagram of the mobile packet network in the 1st Embodiment of this invention.</figref><figref num="3">It is a figure which shows the inter-device processing sequence at the start of a session.</figref><figref num="4">It is a block diagram which shows the structure of the user authentication apparatus.</figref><figref num="5">This is an example of a flowchart of the address allocation process by the user authentication device.</figref><figref num="6">It is a figure which shows the packet format in this embodiment.</figref><figref num="7">It is a figure which shows the data example of the address information table in a user authentication apparatus.</figref><figref num="8">It is a figure which shows the data example of the user information table in a user authentication apparatus.</figref><figref num="9">It is a block diagram which shows the structure of a session management apparatus.</figref><figref num="10">It is a figure which shows the example of the data of a session information table.</figref><figref num="11">It is a figure explaining the state transition of a session state.</figref><figref num="12">It is a block diagram which shows the structure of the load distribution apparatus.</figref><figref num="13">This is an example of a flowchart of load distribution processing by the load distribution device.</figref><figref num="14">It is a figure which shows the data example of the distribution policy information table in a load distribution apparatus.</figref><figref num="15">It is a figure which shows the data format example of a packet header.</figref><figref num="16">It is a figure which shows the structure of the packet gateway apparatus.</figref><figref num="17">It is a flowchart of the upstream packet distribution processing by a packet gateway device.</figref><figref num="18">It is a flowchart (continuation) of the upstream packet distribution processing by a packet gateway device.</figref><figref num="19">It is a flowchart (continuation continuation) of the upstream packet distribution processing by a packet gateway device.</figref><figref num="20">It is a flowchart of the downlink packet distribution processing by a packet gateway device.</figref><figref num="21">It is a flowchart (continuation) of the downlink packet distribution processing by a packet gateway device.</figref><figref num="22">It is a figure which shows the data example of the address information storage table in a packet gateway apparatus.</figref><figref num="23">It is a figure which shows the data example of the distribution policy information table in a packet gateway apparatus.</figref><figref num="24">It is a figure explaining the address translation by a packet gateway apparatus.</figref><figref num="25">It is a flowchart of a service authentication process by a packet gateway device.</figref><figref num="26">It is a figure which shows the data example of the service order information table in a packet gateway apparatus.</figref><figref num="27">It is a figure which shows the data example of the service providing server information table in a packet gateway apparatus.</figref><figref num="28">It is a flowchart of the proxy charge information processing by the packet gateway device.</figref><figref num="29">It is a figure which shows the example of the data of the billing record created by a packet gateway apparatus.</figref><figref num="30">It is a figure which shows the inter-device processing sequence by user logout at the end of a session.</figref><figref num="31">It is a figure which shows the processing sequence between devices at the time of a dormant.</figref><figref num="32">This is an example of the stored contents of the address information storage table in the second embodiment of the present invention.</figref><figref num="33">It is explanatory drawing of the timing from the record generation to the record deletion of the address information storage table.</figref><figref num="34">It is a block diagram which shows the structure of the packet gateway apparatus in 2nd Embodiment.</figref><figref num="35">This is an example of the stored contents of the user session type identification information table.</figref><figref num="36">This is a flowchart of processing when an uplink packet is received from a mobile device (No. 1).</figref><figref num="37">This is a flowchart of processing when an uplink packet is received from a mobile device (Part 2).</figref><figref num="38">This is a flowchart of processing when an uplink packet is received from a mobile device (No. 3).</figref><figref num="39">It is a flowchart of processing when a downlink packet is received from a service providing server (No. 1).</figref><figref num="40">This is a flowchart of processing when a downlink packet is received from the service providing server (Part 2).</figref><figref num="41">It is explanatory drawing of the communication method using a multi-window screen.</figref><figref num="42">It is a block diagram which shows the structure of the 1st conventional example of a mobile packet network.</figref><figref num="43">It is a block diagram which shows the structure of the 2nd conventional example of a mobile packet network.</figref><figref num="44">It is a figure explaining the loading of the program for realizing this invention into a computer.</figref>
Every citation, both waysCites: the store holds 2 of 3
| Document | Relation | Office |
|---|---|---|
| JP10084385A | Cites | Japan |
| JP2000078129A | Cites | Japan |
| 崎田 寧史,ECサイトの基盤要素 7,日経コミュニケーション,日経BP社,2001年 7月 2日,第345号,pp.194-195 | Non-patent | – |
| 負荷分散装置・ECサイト急増でSIの必須商材に,テレコミュニケーション,株式会社リックテレコム,2000年 6月25日,第17巻/第7号,pp.92-99 | Non-patent | – |
7 members in 3 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 0105977 | Japan | W | |
| 0105977 | Japan | W | |
| PCTJP0105977 | Japan | – | |
| 0207012 | Japan | W | |
| 0207012 | Japan | W | |
| 2001JP200105977 | – | – | – |
| 2002007012 | – | – | – |
| WO2001JP05977 | – | – | – |
| WO2002JP07012 | – | – | – |
Members7
| Document | Office | Kind | |
|---|---|---|---|
| WO03007160A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO03009539A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US2004152439A1 | United States of America | A1 | |
| JPWO2003007160A1 | Japan | A1 | |
| JP2007312434A | Japan | A | |
| JP4113115B2This record | Japan | B2 | |
| US7554992B2 | United States of America | B2 |
13 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 4113115
- Publication, DOCDB
- 4113115
- Publication, EPODOC
- JP4113115B
- Application
- 2003512854
- Application, DOCDB
- 2003512854
- Application, EPODOC
- JP20030512854
Titles2
- Japanese
- 移動機通信システムおよび通信方法
- English
- Mobile communication system and communication method
Classification
- CPC, 8
- H04L69/16
- H04W40/00
- H04L67/14
- H04L67/146
- H04L67/142
- H04L69/165
- H04L61/5061
- H04L67/1001
- IPC, 18
- G06F13 00
- H04L12 56
- G06F9 50
- H04L12 70
- H04L12 701
- H04L12 803
- H04L29 06
- H04L29 08
- H04W4 24
- H04W8 26
- H04W12 08
- H04W24 02
- H04W28 08
- H04W40 00
- H04W40 34
- H04W80 04
- H04W80 10
- H04W88 16