Method of ip communication
Abstract
This record has no abstract on file.
Term
Projected expiry 22 January 2027.
- Priority
- Filed
- Granted
- Today
- Projected expiry
3 claims: 1 independent, 2 dependent
- 1IP転送網は複数のアクセス制御装置及び複数のサーバを含み、前記アクセス制御装置及び前記サーバは内部通信回線により接続されており、前記複数のサーバはドメイン名サーバ、変換表サーバを含み、ICSフレームを送受する通信が可能であり、前記アクセス制御装置は複数レコードから成る変換表を含み、複数の端末はユーザ通信回線ユーザ通信回線終端の論理端子を経て前記アクセス制御装置のいずれかに接続されており、送信側の端末1が送信したICSユーザフレーム1がユーザ通信回線1、論理端子1を経て発信側のアクセス制御装置1に入力すると、前記論理端子1を識別するための論理端子識別情報1及び前記ICSユーザフレーム1内の少なくとも受信ユーザアドレスが前記アクセス制御装置1内の変換表のレコード1として登録され、前記レコード1が着信側論理端子識別情報を含んでいると、前記ICSユーザフレーム1及び前記着信側論理端子識別情報を含むICSネットワークフレーム1が形成され、前記発信側アクセス制御装置1から送出された前記ICSネットワークフレーム1は転送されて着信側のアクセス制御装置2に到達し、前記ICSネットワークフレーム1内の前記着信側論理端子識別情報を基に着信側論理端子2が決定され、前記ICSネットワークフレーム1から前記ICSユーザフレーム1が復元され、復元された前記ICSユーザフレーム1は前記着信側論理端子2及びユーザ通信回線2を経て受信側の端末2に到達可能であり、端末3がサーバ3に向けてICSユーザフレーム3を送信するとアクセス制御装置3内のレコード3内の前記サーバ3のアドレスが参照され、ICSネットワークフレーム3が形成されて前記サーバ3に到達し、前記サーバ3がICSネットワークフレーム4を形成して送信すると、前記アクセス制御装置3においてICSユーザフレーム4が復元されて前記端末3に到達可能であり、前記変換表サーバは、前記変換表のレコードを含むICSフレームを用いて前記アクセス制御装置と通信を行うことにより、前記アクセス制御装置内の変換表のレコードの更新が可能であることを特徴とするIP通信の方法。
- 2前記IP転送網は更に1以上のユーザサービスサーバ、1以上の当局サーバを含み、前記ユーザサービスサーバは少なくとも複数ユーザの利用申込み情報を保持し、前記当局サーバは少なくともユーザが用いるドメイン名やアドレスを保持し、前記IP転送網の運用者は少なくとも前記ユーザサービスサーバ、前記変換表サーバを用いて前記IP転送網の運用を行うようになっている請求項1に記載のIP通信の方法。
- 3前記アクセス制御装置3は、前記変換表内の前記レコード3内に前記端末3のICSユーザアドレスが含まれていないことを確認すると前記ICSユーザフレーム3を廃棄し、前記ICSネットワークフレーム3を前記サーバ3に送信せず、前記変換表内のレコードに未登録の端末から前記サーバ3への通信を不可能にする請求項1又は2に記載のIP通信の方法。
Independent claims3
465 paragraphs, as filed
The present invention uses ISDN as well as dedicated lines for information communication devices or information communication systems such as personal computers, LAN (Local Area Network), telephones (including mobile phones), FAX (Facsimile), CATV (Cable Television), and the Internet. (Integrated Services Digital Network), FR (Frame Relay), ATM (Asynchronous Transfer Mode), IPX (Integrated Packet Exchange), satellite, wireless, integrated information communication system connected via public lines. Here, the information communication device is assigned an address (for information communication) for distinguishing from others and communicates. The present invention particularly relates to connectionless networks (eg RFC791, RFC1883 IP (Internet). Data transfer services based on (Protocol) technology) have been integrated, and a unified address system has been adopted to improve the economic efficiency of information communication as a whole, ensuring security and enabling mutual communication between connected terminals or systems. Regarding the method of IP communication.
With the development of computers and information and communication technology, computer communication networks have become widespread in universities, research institutes, government agencies, companies, and companies in recent years. LAN is used as a computer communication network in a company, and when the area is spread nationwide, it takes the form shown in Fig. 150. In the example of FIG. 150, the LANs in each region use a common protocol and are connected by dedicated lines. Here, for example, company X uses LAN-X1, LAN-X2, and LAN-X3 as LAN, company Y uses LAN-Y1, LAN-Y2, and LAN-Y3 as LAN, and company X and Y use LAN-Y1, LAN-Y2, and LAN-Y3, respectively. Communication address system Computer communication is performed using ADX and ADY. In such a LAN network, it is necessary to lay a separate dedicated line for each company, which makes the system construction expensive, and when connecting to the LAN network of another company, the interface such as the communication address system is matched. There is a problem that it is necessary, its interconnection is very difficult, and it costs a lot of money.
On the other hand, in recent years, the Internet has become widespread as a computer communication network on a global scale. In the Internet, networks are connected using a provider's router, which is called TCP / IP (Transmission Control Protocol / Internet Protocol). When using a communication protocol and connecting remote locations, use a dedicated line or FR network, and if it is on the premises, Ethernet, which is a 10 Mbps LAN, or FDDI (Fiber Distributed Data), which is a 100 Mbps LAN. Interface) etc. is used as a communication path. FIG. 151 shows an example of a connection form of the Internet. In the Internet, routers in a provider maintain a connection between each other while exchanging routing table connection information. Each router is connected to multiple networks, and the routing table is used to determine which router is connected to which provider's network to send the received data to which router. In this way, on the Internet, the IP address of the destination attached to each IP frame (IP datagram) is seen, the router to be sent next is determined, and the router is sent to that router. When all routers perform this operation, IP frames are delivered one after another and delivered to the target computer.
FIG. 152 shows the information content of RFC791 of the IP frame used for the Internet, and is divided into a control unit and a data unit. FIG. 153 shows the same information content of RFC 1883, which is divided into a control unit and a data unit, in which () indicates the number of bits.
<p> However, since the Internet does not have a system that comprehensively manages communication routes, it is not possible to confirm whether or not the communication partner is the intended legitimate person, and there is a high risk that communication information will be eavesdropped. There is a problem in terms of security, and the IP address inside many LANs is actually decided by the LAN user independently. When connecting the LAN to the Internet, the IP address of the LAN user is selected. You need to replace it with an IP address for the Internet. In addition, communication qualities such as communication speed and communication error rate are not unified because the backbone lines that make up the Internet communication path are different for each LAN line, and for example, 10 Mbps for video conference communication. Even if you try to send the TV signal of, there is a problem that the communication speed is not achieved. In addition, there is no person in charge of maintenance such as network failure countermeasures and overall network management such as future network planning, and reliability is especially important for communications and corporate operations in countries and research institutes. , There is a problem that the Internet cannot be used with peace of mind. Moreover, in the LAN network and the Internet, the terminal is a personal computer (computer), and it is difficult to integrate and use telephones, fax machines, CATV, etc.</p><p> The present invention has been made for the above-mentioned circumstances, and an object of the present invention is to improve the economic efficiency of constructing an information communication system without using a dedicated line or the Internet, and to improve communication speed, communication quality, and communication failure. To provide an integrated integrated information communication system that can accommodate multiple VANs that transfer data / information using IP frames that ensure security and reliability in communication by centrally guaranteeing countermeasures. It is in. Furthermore, by a single information transfer that does not depend on the type of service such as voice, image (video, still image), text, etc., comprehensive communication service, analog and digital telephone line service, Internet provider service, FAX service, computer data exchange The purpose is to provide an integrated information communication system in which services that have been individually provided in the past, such as services and CATV services, are interconnected. In addition, integration that enables inter-company communication with almost no change in the address system for computer communication that is conventionally decided and used by individual companies (including universities, research institutes, government agencies, etc.) separately within each company. It also aims to provide an information communication system. An IP terminal refers to a terminal or computer having a function of transmitting and receiving IP frames.</p>
<p> The present invention relates to an integrated information communication system, and an object of the present invention is to provide an access control device for individually connecting a plurality of external computer communication networks or information communication devices, and a relay device for networking the access control device. It has a function of transferring and routing information in a unified address system, and is achieved by configuring the configuration so that the plurality of computer communication networks or information communication devices can communicate with each other. The present invention corresponds to a computer communication network based on IP technology in which the range of dedicated lines used for communication inside and between companies shown in FIG. 150 shown as a conventional example is replaced with a common communication network shown by a broken line. To do.</p><p> The above object of the present invention is to convert an ICS user frame having a unique ICS user address system ADX into an ICS network frame having an address system ADS based on the management of a conversion table in the access control device, and at least one built-in. The above VAN is transmitted according to the rules of the address system ADS, and when it reaches the target other access control device, it is converted to the ICS user address system ADX and converted to another external device based on the management of the conversion table. Achieved by reaching information and communication equipment. In addition, an ICS user frame having a unique ICS user address system ADX can be used for a user logical communication line without using the ICS user address inside the ICS user frame based on the management of the conversion table of the access control device. Converts to an ICS network frame corresponding to the incoming ICS network address registered in the conversion table, and the transfer destination of the ICS network frame is 1 or N, and follows the rules of the ICS address system ADS via at least one VAN. Achieved by transferring the ICS network frame to another access control device and returning it to the ICS user frame based on the management of the conversion table of the access control device so that it can reach other external information and communication devices. Will be done.</p>
<p> As described above, according to the present invention, it is not necessary to use an expensive dedicated line, a high-speed communication line used for video communication such as TV is not provided, or a person in charge of a communication line facility expansion plan. It is possible to construct a relatively inexpensive large-scale communication system without using the Internet, which is absent. In addition, there is an advantage that inter-company communication can be performed as well as intra-company communication with almost no change in the private address system for computer communication of individual companies (including government agencies and universities) that have been individually serviced in the past. .. Furthermore, since the network administrator has the control right of the network, the management of the failure countermeasures of the entire network becomes clear, it becomes easy to secure the reliability, and the eavesdropping prevention measures can be taken by the encrypted communication inside the ICS. Is. In addition, since the network itself can optionally add a digital signature to the ICS frame, tampering with the ICS frame can be detected and information security is significantly improved. According to the present invention, by a single information transfer (transfer of IP datagram) that does not depend on services such as voice, image, and text, services that have been conventionally provided individually such as a telephone line service and an Internet provider service are mutually provided. It is possible to realize an integrated information communication system connected to.</p>
FIG. 1 schematically shows the basic principle of the present invention, and shows the integrated information / communication of the present invention. System: (hereinafter abbreviated as "ICS") 1 has its own rules for assigning addresses as computer information / communication addresses. That is, it has a unique address system ADS, and multiple external computer communication networks and information communication devices, such as a large number of LANs (in this example, LAN-X1, LAN-X2, LAN-X3 of company X and LAN of company Y). -It has an access control device (2 to 7 in this example) that serves as an access point for connecting (Y1, LAN-Y2, LAN-Y3). LAN-X1, LAN-X2 and LAN-X3 of company X have the same address system ADX, and LAN-Y1, LAN-Y2 and LAN-Y3 of company Y have the same address system ADY. Access control devices 2, 3 and 4 have a conversion table that manages mutual conversion between the address system ADS and the address system ADX, and access control devices 5, 6 and 7 have the address system ADS and the address system ADY. It has a conversion table that manages mutual conversion and the like. The computer communication data (ICS frame) in ICS1 uses the address according to the address system ADS of ICS1 and communicates by the IP frame used on the Internet or the like.
Here, the communication operation in the case of the same company will be described. Computer communication data (ICS frame) 80 originating from LAN-X1 of company X is given an address according to the address system ADX, but the address is managed under the management of the conversion table of access control unit 2 in ICS1. It is converted to an address that follows the system ADS and becomes ICS frame 81. Then, when it is transmitted in ICS1 according to the rules of the address system ADS and reaches the target access control device 4, it is restored to the computer communication data 80 of the address system ADX under the management of the conversion table, and it is restored to the computer communication data 80 of the same company X. It is sent to LAN-X3. Here, the ICS frame sent and received inside the ICS1 is called an "ICS network frame", and the ICS frame sent and received outside the ICS1 is called an "ICS user frame". The format of the ICS user frame is, in principle, the format specified by RFC791 and RFC1883 used on the Internet, etc., but the handling of ICS frames that deviate from the principle will be described in Examples described later.
The ICS network frame 81 consists of a network control unit 81-1 and a network data unit 81-2, and inside the network control unit 81-1 is the address (address) of each ICS logical terminal inside the access control devices 2 and 4. System ADS) is stored. The ICS user frame 80 is designated as the network data section 81-2 with the data value as it is, or the data format is converted to the network data section 81-2 according to the rules defined inside the ICS1. The conversion rules for this data format include, for example, conversion to encrypted text and data compression. The access control device 2 has an encryption means, a decryption means for returning the encrypted text to the original plain text (ICS user frame), and data compression. It may have a means and a compressed data restoration means for restoring the compressed data. In the access control device 2, the operation of assigning the ICS user frame 80 to the ICS network frame 81-2 and the network control unit 81-1 to the ICS network frame 81-2 is called ICS encapsulation. Further, in the access control device 4, the operation of removing the network control unit 81-1 from the ICS network frame 81 is called "ICS decapsulation".
Similarly, the case of inter-company communication will be described. Computer communication data (ICS user frame) 82 transmitted from LAN-Y2 of company Y is given an address according to the address system ADY, but under the management of the conversion table of access control device 6 in ICS1. It is converted to an address that conforms to the address system ADS and becomes ICS frame 83. Then, when it is transmitted in ICS1 according to the rules of the address system ADS and reaches the target access control device 3, it is converted to the computer communication data 82 of the address system ADX under the management of the conversion table, and the LAN of the company X. -Sent to X2. Although 32 bits and 128 bits are used as the address lengths in the present invention, they are not restricted by these lengths. Even if the length of the address is changed to other than 32 bits or 128 bits, the essence of address translation, which is the basic idea of the present invention, does not change.
As described above, in the present invention, the centralized address management of ICS1 enables computer communication within and between enterprises. Generally used computer communication user terminals are housed in the LAN of the user's premises, housed in the VAN (Value Added Network) via the access line, and users with different data formats and address systems for each service type. The frame is transferred. For example, Internet services use IP addresses, telephone services use telephone numbers / ISDN numbers (E.164 addresses), and X.25 packet services use X.121 addresses. On the other hand, in ICS1 of the present invention, address translation (called ICS address translation) is performed in the conversion table of the access control device based on the input ICS user frame, and a single unified data of various structures is performed. Information is transferred by converting to a frame of data format and address system, that is, an ICS frame.
FIG. 2 schematically shows an example in which the ICS1 of the present invention is composed of a plurality of VANs (VAN-1, VAN-2, VAN-3), and each VAN is managed by the VAN operator, and the ICS1 The user applies for a user communication line to the VAN operator, and the VAN operator decides the user's ICS user address, ICS network address, etc., and displays these information together with the line type, etc. in the access control device as shown in Fig. 3. Register in conversion table 12 in 10. ICS1 has access control devices 10-1, 10-2, 10-3, 10-4, 10-5 as access points for external connection elements with LANs (or their terminals) of companies X and Y. Furthermore, the relay device 20-1,20-2,20-3,20-4, the ICS network server 40-1,40-2,40-3,40-4,40-5, and the ICS address management server 50- It has 1 and 50-2. The communication path inside each VAN is provided with a relay device 20 as shown in FIG. 4, and an inter-VAN gateway 30 as shown in FIG. 5 is provided as a connecting element of VAN-2 and VAN-3. LAN1-1, 1-2, 1-3, 1-4 shown in Fig. 2 have access control devices 10-1, 10-5, 10-4, 10-2 and user communication lines 36-1, 36-, respectively. It is connected via 2,36-3,36-4.
The access control device 10 (10-1,10-2,10-3,10-4,10-5) is a device that accommodates a user communication line from a user (company X, Y) to ICS1. As shown in 3, it is composed of a processing device 11 including a CPU and the like, a conversion table 12 as a database for performing address translation and the like, an input / output interface line unit 13, and a temporary conversion table 14. Further, the relay device 20 has a transfer function of an ICS network frame and a routing function of route designation, and has a processing device 21 composed of a CPU and the like and a relay table 22 as shown in FIG. 4. The relay table 22 is an ICS network. Used to determine the communication destination when the frame is transferred inside ICS1. As shown in FIG. 5, the inter-VAN gateway 30 has a processing device 31 composed of a CPU or the like and a relay table 32 for determining the destination of the ICS network frame between the VANs.
As shown in FIG. 6, the ICS network server 40 is composed of a processing device 41 and an ICS network database 42, and the ICS network database 42 has various uses. For example, user-specific data corresponding to the ICS user address (user name, address, etc.), data not corresponding to the ICS user address, for example, data indicating the communication failure status inside the VAN, or data not directly related to the VAN, for example. Data retention such as electronic library that holds and publishes digital documents, public key of public encryption method using encryption technology used for authenticating the authenticity of senders and receivers, public key certification data or private key of private key method Used for. The processing device 41 refers to the ICS network database 42, acquires the corresponding data, and transmits the corresponding data to the access control device 10. In addition to operating independently, the ICS network database 42 can communicate with other ICS network servers by sending and receiving ICS network frames based on IP communication technology, and can acquire data from other ICS network servers. The ICS network server is assigned the only ICS network address inside ICS.
In the present invention, the address that identifies the computer, terminal, etc. used in the ICS network frame is referred to as "ICS network address", and the address that identifies the computer, terminal, etc. used in the ICS user frame is referred to as "ICS user address". .. The ICS network address is used only inside the ICS and uses one or both of the 32-bit and 128-bit lengths. Similarly, the ICS user address uses one or both of the 32-bit length and the 128-bit length. An ICS network address is assigned to each of the ICS logical terminal inside the access control device 10, the relay device 20, the gateway 30 between VANs, and the ICS network server so as to be uniquely identified from the others. The ICS user address is composed of a VAN upper code and a VAN internal code. When the length of the VAN upper code is expressed in C1 bits and the length of the VAN internal code is expressed in C2 bits, C1 + C2 is 32 bits or 128 bits. Use one of.
In the present invention, the specific method of determining the VAN upper code and the VAN internal code is not specified, but when C1 + C2 = 32 bits, for example, VAN upper code = regional control code (4 bits) The country code (4 bits) The VAN code (8 bits) VAN internal code = VAN area code (4 bits) The VAN Access point code (8 bits) The User logical code (4 bits) It should be decided. Figure 7 shows an example of an ICS user address. Here, the symbol "aTheb" represents the concatenation of the data a and b, that is, the data obtained by arranging the data a and b in this order. The ICS network address can also be assigned including regional characteristics in the same way as the user network address. For example ICS network address = regional control code The country code The VAN code The VAN area code The User logical communication line code And so on. In this way, the relay device can efficiently find the destination by deciding the destination in consideration of the area. The same can be specified for C1 + C2 = 128 bits.
In the present invention, C1 + C2 = 32 bits or C1 + C2 = 128, regardless of how the internal fields of the VAN upper code and the VAN internal code are divided and the length of each division field is defined. As long as the bits are protected, the ICS frame can be configured as described below. In addition, when determining the VAN superordinate code or VAN internal code, a part of these codes may be specified uniquely to the user. That is, the user can have a user-specific address system. Address values in 32-bit representation start at address 0 (2)<sup>32</sup>-1) Up to the address, but in this address, for example, 10 × 2<sup>24</sup>From the street address (10 x 2)<sup>24</sup>+2<sup>24</sup>-1) Address or (172 x 2)<sup>24</sup>+16×2<sup>16</sup>) From the street address (172 x 2)<sup>24</sup>+32×2<sup>16</sup>-1) Up to address or (192 x 2)<sup>24</sup>+168×2<sup>16</sup>) From the street address (192 x 2)<sup>24</sup>+169×2<sup>16</sup>-1) In the section up to the address, the present invention is carried out by assigning an address unique to the user.
The physical communication line can be logically divided into a plurality of communication lines and used, which is realized as a conventional technique, for example, by a multiplex communication method of a frame relay (FR). In the present invention, the user's communication line is divided into a user physical communication line and one or more user logical communication lines. FIG. 8 shows this situation, and shows an example in which the user physical communication line 60 having a communication speed of 100 Mbps is divided into two user logical communication lines 61-1 and 61-2 having a communication speed of 50 Mbps. In addition, separate computer communication devices 62-1,62-2,62-3,62-4 are connected to their respective user logical communication lines, and the ICS user address "4123,0025,0026,4124" is assigned to each computer communication device. Examples given to 62-1 to 62-4 are shown. The user physical communication line 60 is connected to the access control device 63, and the connection point between the two is referred to as an ICS logical terminal. The ICS logical terminal is assigned the only ICS network address inside the ICS. In the example of FIG. 8, the user logical communication lines 61-1 and 61-2 are connected to the access control device 63, and the ICS network addresses 8710 and are connected to the ICS logical terminals 64-1 and 64-2 at the connection points, respectively. 8711 is given.
As described above, since the ICS network server 40 is also given a unique ICS network address, the ICS network address can identify the ICS logical terminal or the ICS network server as the only one inside the ICS. The ICS network server can exchange information by transmitting and receiving between another ICS network server and an ICS network frame to which each other's ICS network address is assigned by using IP communication technology. This communication function is called "ICS network server communication function". The access control device also has the only ICS network address inside the ICS, and can exchange information with the ICS network server by using another ICS network server communication function as the access control device server. The ICS network server communication function is realized by using, for example, the conventional technology TCP or UDP (User Datagram Protocol).
As described above, the ICS frame of the present invention includes an ICS network frame transmitted and received inside the ICS and an ICS user frame transmitted and received outside the ICS, and each frame consists of a control unit and a data unit. As shown in FIG. 9, it is used as a network control unit, a network data unit, a user control unit, and a user data unit in ICS encapsulation or ICS decapsulation. That is, when the ICS user frame enters the ICS from the access control device, the ICS user frame becomes the data part of the ICS network frame, and the control unit (network control unit) of the ICS network frame is added (ICS encapsulation). The inside of the network control unit is divided into a basic unit and an extension unit. The basic part is used for the header specified in RFC791 and RFC1883, for example, and the extended part is used for encryption and the like. If encryption or the like is not required at all, the extension is not used and does not have to exist.
An area for storing the source address and the destination address is placed in the network control unit of the ICS frame. The format of the ICS frame may be 32 bits or 128 bits. When the address length is 32 bits, for example, the frame format specified by RFC791 shown in FIG. 152 is adopted. If the ICS network address is insufficient with 32 bits, for example, when using 64 bits, write the missing 32 bits (64 bits to 32 bits) to the option part of the ICS network frame control unit according to the rules of RFC791, and write the missing 32 bits (64 bits to 32 bits) to the network address. Set the length to 64 bits and use it. Here, the address specified specifically for the user is supplemented. Many users, for example (10x2)<sup>24</sup>) From the street address (10 × 2)<sup>24</sup>+2<sup>24</sup>-1) Considering the case of having a private address (one of the ICS user addresses) in the section up to the address, the ICS network address is assigned corresponding to the ICS user address, so the length of the ICS user address is 32. In the case of bits, 32 bits is not enough for the length of the ICS network address, for example 64 bits are required. In this case, as described above, the shortage of 32 bits is written to the option part of the ICS network frame control unit, and the length of the network address is set to 64 bits.
The fact that communication between the same users (referred to as intra-company communication) is possible using the above private address will be described in the first embodiment. When the address length is 128 bits, the present invention is carried out by adopting, for example, the frame format specified in RFC 1883 shown in FIG. 153. The source address area in the network control unit and the address stored in the destination address area are ICS network addresses, and are the outgoing ICS network address and the incoming ICS network address, respectively. Further, the source address area in the user control unit and the address stored in the destination address area are ICS user addresses, and are the sender ICS user address and the receiver ICS user address, respectively.
When implementing the present invention, it is not always necessary to comply with the provisions of RFC791 and RFC1883 as the format of the ICS frame, and the frame format can be implemented as long as the address uses either 32-bit or 128-bit. Generally, in ICS, the ICS user frame specified in RFC791 or RFC1883 of the communication protocol is received from the user, but other frame formats are converted to the ICS user frame format by the conversion means (conversion unit) and ICS. It can be handled within the network.
Example-1 (ICS basics, intra-company communication and inter-company communication): A first embodiment of the present invention will be described with reference to FIGS. 10 and 11 as a basic communication for determining a transfer destination in the ICS from the recipient ICS user address based on the management of the conversion table. In the figure, 170-1,170-2,170-3,170-4 are gateways provided inside LAN100-1,100-2,100-3,100-4, respectively, and the ICS frame can pass through these gateways 170-1 to 170-4.
First, a terminal connected to LAN100-1 of company X having a unique address system ADX and having an address according to address system ADX and a terminal connected to LAN100-2 of the same company X and having an address according to address system ADX The communication with the terminal to have is described. That is, it is communication between the terminal having the ICS user address "0012" on LAN100-1 and the terminal having the ICS user address "0034" on LAN100-2. This communication is a typical communication in which terminals whose addresses are set based on a unique address system (ADX in this example) within the same company mutually perform via ICS100, and this is a corporate communication service (intra-company communication service). Or in-house communication). Next, communication between a terminal connected to LAN100-1 of company X and having an address according to the address system ADX and a terminal connected to LAN100-3 of company Y and having an address according to the address system ADY. Will be described. That is, it is communication between the terminal having the ICS user address "0012" on LAN100-1 and the terminal having the ICS user address "1156" on LAN100-3. This communication is a typical terminal mutual communication performed by terminals having different address systems between different companies using an ICS address system that can be commonly used by each other, and this is a business-to-business communication service (or business-to-business communication). Called.
<< Common preparation >> In explaining this example, the address format and the like are determined as follows, but the specific numerical values and formats shown here are all examples and are not bound by this. The ICS network address is represented by a 4-digit number, and the sender ICS user address and the receiver ICS user address are both represented by a 4-digit number. Then, among the sender ICS user address and the receiver ICS user address, the address whose upper two digits are not "00" is used as the inter-company communication address, and this inter-company communication address is the only value inside the ICS100. Of the sender ICS user address and the receiver ICS user address, the address whose upper two digits are "00" is used as the corporate communication address, but this corporate communication address is the same as the corporate communication address of another company inside ICS100. It may be duplicated. In addition, the conversion table 113-1 provided in the access control device 110-1 includes the outgoing ICS network address, the incoming IC network address, the sender ICS user address, the recipient ICS user address, the request identification, the speed classification, and the like. I'm out. The request identification registered in the conversion table 113-1 is represented by, for example, "1" for the intra-company communication service, "2" for the inter-company communication service, and "3" for the virtual leased line connection described in another embodiment. The speed classification includes the speed and throughput of the line required for communication from the ICS network address (for example, the number of ICS frames transferred within a certain time).
<< Preparation for intra-company communication >> LAN100-1 and LAN100-2 users specify terminals to VAN operators so that corporate communication between terminals connected to each LAN can be performed via VAN-1 and VAN-3. And apply. Then, the VAN operator responds to the application by displaying the above-mentioned ICS network address, ICS user address, and request identification in the conversion table of the access control devices 110-1 and 110-5 connected to LAN100-1 and LAN100-2. Etc. are also set, and they are also written and stored in the ICS address management server 150-1.
The settings related to VAN-1 are as follows. The ICS network address is determined from the ICS logical terminal of the access control device 110-1 to which LAN100-1 is connected. Here, the ICS network address of the logical terminal is set to "7711". The in-house communication address of one terminal connected to the LAN100-1 for which the application was made is set to "0012", and this is set as the sender ICS user address. The inter-company communication address used by the terminal with this address is set to "2212", and this is set as the sender ICS user address. Then, the ICS network address is determined from the ICS logical terminal of the access control device 110-5 connected to the LAN100-2 for which the application was made. Here, the ICS network address is set to "9922" and this is used as the incoming ICS network address. To do. Further, the ICS user address of one terminal connected to LAN100-2 is set to "0034", and this is set as the recipient ICS user address. The value "1" indicating the in-house communication service for which the application has been made is used as the request identification, and the above is registered in the conversion table 113-1.
The settings related to VAN-3 are as follows. Set the values required for reverse communication (communication from LAN100-2 to LAN100-1) in the conversion table of the access control device 110-5 that connects the LAN100-2 that you applied for. That is, the outgoing ICS network address and the incoming ICS network address set the opposite data, and at the same time, the sender ICS user address and the receiver ICS user address set the opposite data. Set the ICS network address of LAN100-2 to "9922" and use it as the outgoing ICS network address. Set "0034" as the in-house ICS user address of the terminal connected to LAN100-2 as the sender ICS user address, and set the ICS user address "0012" of the communication destination terminal as the receiver ICS user address. Further, the ICS network address "7711" of LAN100-1 is set as the incoming ICS network address, the value of the request identification indicating the in-house communication service is set to "1", and this is set as the request identification. Write the above in the conversion table of access control device 110-5 and register it.
<< Operation of corporate communication >> The terminal having the ICS user address 0012 sends the ICS user frame P1. The sender ICS user address "0012" is set in this ICS user frame P1, and "0034" is set in the receiver ICS user address.
Next, it will be described with reference to the flowchart of FIG.
The ICS user frame P1 is transferred to the access control device 110-1 via the user logical communication line 180-1. The access control device 110-1 obtains conversion table 113-1 from the outgoing ICS network address 7711 of LAN100-1 and the recipient ICS user address 0034 of the received ICS user frame (steps S100, S101). Refer to it and know that this communication is an intra-company communication from the request identification value 1 (step S102). The incoming ICS network address 9922 corresponding to the recipient ICS user address 0034 is acquired (step S103) and then ICS encapsulated (step S106). The above procedure is shown in the flowchart as shown in Fig. 12, and the intra-company communication is the flow of (1) in it. The sender ICS user address may be used, for example, to specify the source of the ICS frame.
The access control device 110-1 constitutes the ICS network frame P2 by ICS encapsulation and transmits the ICS network frame P2 to the relay device 120-1. Since the ICS network address of the network control unit is guaranteed to be unique inside the ICS, it does not collide with other ICS frames. The ICS network frame P2 passes through the relay devices 120-1 and 120-2 based on the incoming ICS network address, and reaches the access control device 110-5 of VAN-3. The access control device 110-5 removes the network control unit from the ICS network frame P4, decapsulates the ICS, reproduces the same ICS user frame P5 as the ICS user frame P1 from the network data unit of the ICS frame, and transfers it to LAN100-2. .. The ICS user frame is routed through LAN100-2 and transferred to the terminal with the ICS user address "0034".
<< Preparation for inter-company communication >> As an example of inter-company communication service, a terminal with an ICS user address "0012" connected to LAN100-1 according to the address system ADX and a terminal with an ICS user address "1156" connected to LAN100-3 according to the address system ADY. The communication with and is described. Users of LAN100-1 and LAN100-3 specify terminals for the connected VANs so that they can communicate via VAN-1 and VAN-2, and apply to the VAN operator. The VAN operator sets the necessary items in the conversion table of the access control device connected to LAN100-1 and LAN100-3 according to the application.
The settings related to VAN-1 are as follows. The ICS network address of LAN100-1 is set to "7711", the in-house communication address of one terminal connected to the applied LAN100-1 is set to "0012", and this is set as the sender ICS user address. The inter-company communication address assigned to the terminal of this ICS user address is set to "2212", and this is set as the sender ICS user address (inter-company). The ICS network address is determined from the ICS logical terminal of the access control device 110-4 to which the ICS network address of LAN100-3 that has been applied for is connected. Here, "8822" is used and this is used as the incoming ICS network address. Also, the ICS user address of one terminal connected to LAN100-3 is set to "1156", and this is set as the recipient ICS user address. Furthermore, the value "2" indicating the inter-company communication service for which the application has been made is used as the request identification, and the above is registered in the conversion table 113-1.
The settings related to VAN-2 are as follows. As a conversion table of the access control device 110-4 to which LAN100-3 is connected, a temporary conversion table 114-2 that retains reverse data for a certain period of time, for example, 24 hours is set. That is, regarding the ICS network address "8822" to which LAN100-3 that uses the communication service between companies is connected, the outgoing ICS network address, the sender ICS user address, the recipient ICS user address, the incoming ICS network address, the request identification, etc. Temporary conversion table 114-2 including the above is provided inside the access control device 110-4. However, the timing of setting in the temporary conversion table 114-2 will be described later. In the other embodiment described above, the temporary conversion table 114-2 is not set.
<< Operation of inter-company communication >> A terminal having an ICS user address "0012" sends an ICS user frame F1 in which "0012" is set as the sender ICS user address and "1156" is set as the receiver ICS user address. The ICS user frame F1 is transferred to the access control device 110-1 via the user logical communication line 180-1.
The access control device 110-1 refers to the conversion table 113-1 using the outgoing ICS network address 7711 and the recipient ICS user address 1156 of LAN100-1 (steps S100, S101) to identify the request. Know that is "2", that is, an inter-company communication service (step S102). Next, while knowing that the incoming ICS network address corresponding to the receiver ICS user address 1156 is 8822 (step S104), the sender ICS user address 0012 is changed to the inter-company communication address 2212. Convert (step S105). The access control device 110-1 is provided with a network control unit as an outgoing ICS network address "7711", a sender ICS user address "2212", a receiver ICS user address "1156", and an incoming ICS network address "8822". It is encapsulated in ICS and transmitted to relay device 120-1 as ICS network frame F2 (step S106). The above procedure is the flow of (2) in the flowchart of FIG.
In the above inter-company communication, when the sender ICS user address in the ICS user frame F1 is set to the inter-company communication address "2212", the sender and the receiver perform inter-company communication using the inter-company communication address ( Steps S102, S104). In this case, the access control device 110-1 does not execute the process of converting the sender ICS user address "2212" to the inter-company communication address "2212" because it is unnecessary. The above procedure is (3) in the flowchart of FIG. The sender ICS user address may be used, for example, to specify the source of the ICS frame.
The relay device 120-1 passes the ICS network frame based on the incoming ICS network address through the relay device 120-2 in VAN-1, the gateway 130 between VANs, and the relay device 120-3 in VAN-2, and then VAN. Transfer to access control device 110-4 in -2. Next, it will be described with reference to the flowchart of FIG. The access control device 110-4 receives the ICS network frame (step S110) and creates the ICS user frame F5 from the network data section (step S111 :). ICS decapsulation), determine the ICS logical terminal to be transmitted from the incoming ICS network address ((1) in step S112), and transfer to LAN100-3 (step S113). At the same time, the relationship between the outgoing ICS network address "8822", the sender ICS user address "1156", the receiver ICS user address "2212", and the incoming ICS network address "7711" is inside the access control device 110-4. If it is not registered in the conversion table, these four types of addresses are set to "2" for request identification, that is, the designation of inter-company communication is set in the temporary conversion table 114-2 ((2) in step S112). The settings in Temporary Conversion Table 114-2 are updated by performing processing such as erasing when not in use for 24 hours, for example. The ICS user frame is routed through LAN100-3 and transferred to the terminal with the ICS user address "1156". If the sender ICS user address field in conversion table 114-2 is divided into "inside the company" and "inter-company" as shown in conversion table 113-1, for example, the sender ICS user address (inside the company) In the case of a conversion table in which the value of is "0023" and the value of the sender ICS user address (between companies) is "1159", the destination address of the user control unit of the ICS user frame immediately after ICS decapsulation. When the ICS user frame whose address value is "1159" written in the column of is processed, the process of rewriting the destination address value of the user control unit of this ICS user frame to "0023" is performed in step S112 (1) described above. ) Is added to the process. To summarize the effects of the above processing, the ICS user address "0023" for intra-company communication is used inside the LAN, but for other companies outside the LAN, the ICS user address for inter-company communication. Can be claimed to be "1159". In the other examples above, it is not set in Temporary Change Table 114-2. Further in the other embodiment described above, conversion table 113-1 includes a sender ICS user address (intra-company) and a sender ICS user address (between companies). In addition, the flowchart (2) of FIG. 12, that is, step S105 is not included. Also, in step S104, the sender ICS user address is not referenced. The merit of this embodiment is that when there are many sender ICS user addresses for one receiver ICS user address, the number of registrations in the conversion table can be reduced to only one receiver ICS user address.
Example-2 (Virtual Leased Line): The operation of the virtual leased line connection according to the present invention will be described with reference to FIG. Here, the virtual leased line connection is a communication in which the ICS user frame is fixedly transferred to the incoming ICS network address registered in the conversion table regardless of the ICS user address in the user control unit of the ICS user frame. It takes the form of one-to-one or one-to-N. The components of FIG. 14 are almost the same as those of FIGS. 10 and 11 of the first embodiment, and the difference is the registered contents of the conversion table. In the conversion table of the access control device, the incoming ICS network address is fixedly determined from the outgoing ICS network address, so the sender ICS user address (inside the company), the sender ICS user address (between companies), and the receiver ICS user. The address is not registered, or even if it is registered, it is ignored.
Between company X's LAN200-1 connected to access control device 210-1 and company X's LAN200-2 connected to access control device 210-5 using a virtual leased line connection The case of communicating with is described.
<< Preparation >> The user applies to the VAN operator for a virtual leased line connection. The VAN operator determines the ICS network address 7711 of the ICS logical terminal at the connection point between the access control device 210-1 that connects LAN200-1 of company X and the user logical communication line 240-1, and similarly, company X Determine the ICS network address "9922" of the ICS logical terminal at the connection point between the access control device 210-5 that connects LAN200-2 and the user logical communication line 240-2. Next, the VAN operator sets the outgoing ICS network address 7711, the incoming ICS network address 9922, and the request type in the conversion table 213-1 of the access control device 210-1. FIG. 14 shows an example in which the request type 3 is set as a virtual leased line connection. Similarly, the outgoing ICS network address 9922, the incoming ICS network address 7711, and the request type information are set in the conversion table of the access control device 210-5.
<< Procedure >> This will be described with reference to the flowchart of FIG.
LAN200-1 of company X sends ICS user frame F10 to ICS200 through user logical communication line 240-1. The access control device 210-1 receives the ICS user frame F10 from the ICS logical terminal of the ICS network address 7711 (steps S200 and S201), and the request identification value of the outgoing ICS network address 7711 in the conversion table 213-1. Refer to 3 to recognize that it is a virtual leased line connection (step S202), and read the incoming ICS network address 9922 (step S203). Next, the access control device 210-1 creates an ICS network frame F11 by adding a network control unit in which the incoming ICS network address is set to "9922" and the outgoing ICS network address is set to "7711" to the ICS user frame F10. (Step S204: ICS encapsulation) and send it to the relay device 220-1 (step S205). The relay device 220-1 that has received the ICS network frame F11 determines the transmission destination based on the incoming ICS network address of the ICS network frame F11, and transmits the ICS network frame F12 to the relay device 220-2. The ICS network frame F12 is transferred to the access control device 210-5 via the relay device 220-4 in the VAN-3.
The access control device 210-5 removes the network control unit from the ICS network frame F13 (ICS decapsulation), and transfers the ICS user frame F14 from the ICS logical terminal of the ICS network address 9922 to the user logical communication line 240-2. Send out. Then, LAN200-2 of company X receives the ICS user frame F14. Since it is possible to transmit from LAN200-2 to LAN200-1 in the same manner as described above, mutual communication is possible. In the above explanation, it is clear that the sender and the receiver do not necessarily have to be the same company X. Therefore, the same method is used to change the LAN200-1 of the company X to the LAN200-3 of another company Y. ICS user frames can be transferred toward.
Further, in the above description, one-to-one communication has been described as an example, but one-to-N communication is also possible. For example, in the conversion table 213-1 of the access control device 210-1 in FIG. 14, a plurality of incoming ICS network addresses may be set as shown by 7712 of the outgoing ICS network address. In this example, two ICS network addresses "6611" and "8822" are set. When the access control device 210-1 receives an ICS user frame from the ICS logical terminal whose ICS network address is "7712", the access control device 210-1 is the first ICS network frame to which a network control unit in which "6611" is set for the incoming ICS network address is added. Then, a second ICS network frame with a network control unit set to the incoming ICS network address set to "8822" is created, and these are sent to the relay device 220-1. As a result, one-to-two communication is possible. Furthermore, one-to-N communication is possible by transferring individual ICS network frames in the same manner as above.
Example-3 (ICS network server): As shown in FIG. 16, the ICS network server 330 is composed of the processing device 331 and the ICS network database 332, and the data held by the ICS network database 332 is the question item, type, answer content, and network address of another ICS network server. Consists of. The ICS network server 330 analyzes the data part of the ICS frame received from the access control device 310-1, refers to the ICS network database 332 based on this, and acquires the answer contents corresponding to the question items (type " (When 1 ), the obtained answer is transmitted to the access control device 310-1. Furthermore, when the ICS network database 332 does not retain the answer content corresponding to the question item (type 2), the question item is entered using the ICS network server communication function based on the ICS network address of another ICS network server. The corresponding answer is obtained by asking another ICS network server, and the answer to the question obtained as a result is transmitted to the access control device 310-1.
More specifically, the ICS user address 2000, the ICS network address 7721, and the request identification 4 of the ICS network server 330 are registered in the conversion table 313-1 as preparation items. Here, the request identification "4" indicates that the ICS user address "2000" is a common number (referred to as an ICS special number) with other users, such as the Japanese telephone number "119". Next, write in the ICS network database 332 that the type for question Q1 is "1" and the answer content is "A1", the type for question Q2 is "2", the answer content is blank, and the other ICS network server 340. Write down the ICS network address "8844".
Next, the user with the ICS user address 0012 sends the ICS user frame F20 to the ICS user address 2000 of the ICS network database 332 (including question Q1), and the access control device 310-1 connects to the line. Receives the ICS user frame F20 from the ICS logical terminal in Part 311-1, obtains the ICS network address "7711", and then ICS-encapsulates the ICS frame F20 in the ICS network server 320, referring to conversion table 313-1. Send the ICS network frame. As shown in the flowchart of FIG. 17, the ICS network database 332 finds the answer A1 corresponding to the question Q1 included in the ICS frame F20 (steps S300 and S301), and returns the answer A1 to the access control device 310-1. The access control device 310-1 transmits an ICS frame containing the answer A1 to the ICS user address 0012.
The user with the ICS user address 0012 sends the ICS frame F21 to the ICS user address 2000 (including question Q2), and the access controller 310-1 refers to the conversion table 313-1 and ICS. When the network address "7721" is obtained, the ICS frame in which the ICS frame F21 is encapsulated in ICS is sent. The ICS network database 332 recognizes the type "2" corresponding to question Q2 of the ICS frame F21 (step S300), learns that the ICS network database 332 itself does not hold the answer (A2), and other ICSs. Based on the ICS network address "8844" of the network server 340, information is exchanged with the ICS network server 340 using the ICS network communication function (step S302), and the answer "A2" corresponding to question Q2 is obtained (step S303). , Returns answer A2 to access controller 310-1. The access control device 310-1 transmits an ICS frame containing the answer A2 to the ICS user address 0012.
Example-3A (when the ICS network server is connected to the relay device): As shown in FIG. 16, the ICS network server 330 is connected to the access control device 310-1, but is not connected to the relay device 320-1. On the other hand, in this embodiment, as shown in FIG. 18, the ICS network servers 340A-1 and 340A-2 are connected to the access control devices 310A-1 and 310A-2, respectively, but the ICS network server 340A-3 relays. Connected to device 320A-1. In addition, all ICS network servers 340A-1, 340A-2, and 340A-3 have the only ICS network address inside the ICS300A. The ICS network server 340A-3 uses the ICS network communication function to communicate with the ICS network servers 340A-1 and 340A-2 connected to the access control device inside the same VAN-300A1, and only these ICS network servers. Can collect and retain the unique information it holds. Such an ICS network server is called an ICS network server representing the VAN-300A1. As a result, the ICS network server 340A-1 communicates with the ICS network server 340A-3, which represents the VAN-300A1, and obtains the unique information possessed by the ICS network server 340A-2 connected to other access control devices. can do. In addition, the ICS network server 340A-3 representing VAN-300A1 and the ICS network server 340A-6 representing other VAN-300A2 communicate with each other using the ICS network communication function, and the unique information held by each is used. Can be exchanged. The ICS network server connected to the access control device may be made to collect the information held by all the ICS network servers inside the VAN, and may be used as the ICS network server representing the VAN.
Example-4 (ICS Address Management Server): As shown in FIG. 19, the ICS address management server 430 is connected to the access control device 410-1 via the ICS network communication line 460, and has an ICS logical terminal in the line section 411-1 of the access control device 410-1. The correspondence table 432 of the ICS network address and the corresponding ICS user address is held. For example, it holds the ICS network addresses "7711", "7711", "7712", and "7713" corresponding to the ICS user addresses "2013", "2014", "1234", and "4500", respectively. At the same time, all the information described in the conversion table and address-related information such as records related to VAN operation may be included. Further, the ICS address management server 430 holds the ICS network addresses of the plurality of other ICS address management servers and the ICS network addresses of the plurality of ICS name servers. Further, the ICS address management server communicates with the ICS name server shown in Example 5 described later by using the ICS network server communication function, and can obtain the ICS name corresponding to the ICS user address.
The processing device 412-1 of the access control device 410-1 communicates with the ICS address management server 430 using the ICS network server communication function, presents the value of the ICS network address, and asks for the corresponding ICS user address. Alternatively, the value of the ICS user address can be presented to tell the corresponding ICS network address. This will be described with reference to the flowchart of FIG. The ICS address management server 430 checks whether the ICS network address or ICS user address inquired from the access control device server 410-1 is registered in the correspondence table 432 held by itself (step S400), and includes it in the correspondence table. If yes, answer (step S401), and if not, communicate with another ICS address management server 440 using the ICS network server communication function to obtain the ICS user address or ICS network address (step S402). ), Answer this result to the access control device 410-1 from which the question was asked (step S403). With this configuration, the access control device 410-1 can request the ICS address management server 430 to acquire the other address from one of the ICS network address and the ICS user address.
Example-4A (when the ICS address management server is connected to the relay device): As shown in FIG. 19, the ICS address management server 430 is connected to the access control device 410-1, but not to the relay device 420-1. On the other hand, in this embodiment, as shown in FIG. 21, the ICS address management server 450B-3 is connected to the relay device 420B-1, and the ICS address management server 450B-3 has the only ICS network address inside the ICS400B. There is. The ICS address management server 450B-3 uses the ICS network server communication function to communicate with the ICS address management servers 450B-1 and 450B-2 connected to the access control device inside the same VAN-400B1 to communicate with these ICSs. The ICS network address, ICS user address, and ICS address-related information held by the address management server can be collected and held. Such an ICS address management server is called an ICS address management server representing the VAN-400B1. As a result, the ICS address management server 450B-1 can communicate with the ICS address management server 450B-3 representing the VAN-400B1 and obtain the ICS address-related information possessed by the ICS address management server 450B-2. In addition, the ICS address management server 450B-3 representing VAN-400B1 and the ICS address management server 450B-6 representing other VAN-400B2 communicate using the ICS network server communication function, and the ICS held by each communicates. Address related information can be exchanged. The ICS address management server connected to the access control device may be made to collect the information held by all the ICS address management servers inside the VAN, and may be used as the ICS address management server representing the VAN.
Example-5 (ICS name server): The ICS user address has the disadvantage that it is difficult to remember because it is represented by, for example, a 32-bit long binary number or a 128-bit binary number. Instead, a method of using an "ICS name" that is easy for humans to remember is used. Example-5. The term "ICS domain name" is also used instead of "ICS name". In this case, instead of the ICS name server, it is called the ICS domain name server.
First, the ICS name will be described. As shown in Fig. 7, the binary ICS address is represented by, for example, a regional management code, a country code, a VAN code, a VAN regional code, a VAN access point code, and a user logical code, and these numerical codes are arranged side by side. For example, the area management code The country code The VAN code The VAN area code The VAN access point code The user logical code. For the ICS name, for example, the regional management code that can be represented by a binary number as described above is AS (element of the ICS name meaning Asia), JP (Japan), VAN # 1 (identifies one of VAN), DIS. # 1 (identifies one of the VAN area codes that make up VAN # 1), ACS # 1 (identifies one of the VAN access point codes limited by DIS # 1), USR # 1 (identifies one of the user logical codes) (Identify one). The elements of the ICS name defined above are reversed and arranged with the dot "." In between, that is, "USR # 1.ACS # 1.DIS # 1.VAN # 1.JP.AS" is the ICS name. To be determined. In the above case, for example, the ICS name is divided into USR # 10 and COMP # 10, ACS # 1 is divided into ACS # 11 and ACS # 12, and "USR # 10.COMP #" as a whole. It may be divided into more details such as "10.ACS # 11.ACS # 12.DIS # 1.VAN # 1.JP.AS".
An ICS name server, which is a type of ICS network server, will be described. As shown in FIG. 22, the ICS name server 550 is composed of the processing device 551 and the ICS name conversion table 552, and the ICS name conversion table 552 contains, for example, the existence of the ICS name and the type (the existence of the ICS user address corresponding to the ICS name). Identification), ICS user address, etc. Type "2" indicates that the ICS network database 332 does not hold the ICS network address corresponding to the ICS name, and therefore obtains the ICS network address corresponding to the ICS name from another ICS name server. Here, for example, other ICS name servers that manage the ICS name USR # 2.ACS # 2.DIS # 2.VAN # 2.JP.AS are DIS excluding USR # 2.ACS # 2. It can be called by "# 2.VAN # 2.JP.AS". The ICS name server 550 analyzes the ICS frame data part received from the access control device 510-1, refers to the ICS name conversion table 552 based on this, acquires the ICS user address corresponding to the ICS name, and obtains the access control device. Send to 510-1. Furthermore, based on the ICS user dress, the corresponding ICS name is answered. If the corresponding ICS user address does not exist in the ICS name conversion table 552, use the ICS network server communication function to request another ICS name server that holds the ICS user address in question, and from here. The acquired ICS user address is sent to the access control device 510-1.
The terminal of the sender ICS user address "0012" connected to LAN500-1 is the ICS user address corresponding to "USR # 1.ACS # 1.DIS # 1.VAN # 1.JP.AS" of ICS name 1. The acquisition method of is explained. Here, a case where the access control device 510-1 acquires data from the ICS name server 550 and a case where the access control device 510-1 acquires data from another ICS name server 560 will be described.
First, as a preparation, the ICS network address "7741" and the request identification "4" corresponding to the ICS user address "1000" of the ICS name server 550 are registered in the conversion table 513-1 of the access control device 510-1. Here, the request type "4" represents an ICS special number common to other users, such as the ICS user address "1000" being the telephone number "119". Register the recipient ICS user address "2014" corresponding to the ICS name "USR # 1.ACS # 1.DIS # 1.VAN # 1.JP.AS" in the ICS name conversion table 552 of the ICS name server 550. Then, the terminal user of the sender ICS user address 0012 of LAN500-1 transmits the ICS user frame F40 to the access control device 510-1, and the ICS name # 1 USR # 1.ACS # 1.DIS # 1 Request conversion from .VAN # 1.JP.AS to ICS user address. The processing device 512-1 in the access control device 510-1 receives the ICS user frame F40 from the ICS logical terminal of the line section 511-1, acquires this ICS network address 7711, and then the ICS user frame F40. Refer to the conversion table 513-1 based on the recipient ICS user address, and when the corresponding request identification is "4" (connect to the ICS name server with the ICS special number), the ICS network address "7711" obtained by the above operation. Is used to encapsulate the ICS user frame F40 in ICS and send the ICS network frame containing the ICS name to the ICS name server 550.
As shown in the flowchart of FIG. 23, the ICS name server 550 analyzes the ICS name in the ICS frame received from the address control device 510-1 in the processing device 551, and refers to the ICS name conversion table 552 based on this. (Step S500). Then, if the ICS user address corresponding to the ICS name exists in the ICS name conversion table 552, it is acquired and the ICS network frame F45 including the ICS user address 2014 is transmitted to the access control device 510-1. (Step S501). If the ICS name inquired does not exist in the ICS name conversion table 552, for example, the processing device 512-1 receives the ICS user frame F41, and the ICS name # 2 described in this ICS user frame F41 (that is, that is). If USR # 2.ACS # 2.DIS # 2.VAN # 2.JP.AS) is not listed in the ICS name conversion table 552, the ICS name server 550 will have an ICS name (DIS # 2.VAN # 2. Based on JP.AS), the ICS that was asked by obtaining the ICS network address of another ICS name server from the ICS name conversion table 552 and exchanging information with the ICS name server 560 using the ICS network server communication function. The ICS user address 1130 corresponding to the name is acquired (step S502), and the acquired result is transmitted to the access control device 510-1 (step S503).
The access control device 510-1 exchanges information with the ICS address management server 570 based on the recipient ICS user address described in the ICS network frame F45 received from the ICS name server 550, and the ICS corresponding to the ICS user address. Acquire the network address and the address-related information included in the correspondence table, and write the data consisting of the obtained ICS user address, ICS network address, and address-related information to the conversion table 513-1. The access control device 510-1 transmits the ICS user address 2014 (or 1130) obtained from the ICS name server 550 to the terminal user of the sender ICS user address 0012 of LAN500-1. Here, the ICS user address 0012 is written in the ICS network frame F45. The terminal user of the sender ICS user address 0012 of LAN500-1 obtains the receiver ICS user address 2014 (or 1130) obtained from the access control device 510-1.
Example-5A (when the ICS name server is connected to the relay device): In FIG. 22, the ICS name server 550 is connected to the access control device 510-1, but not to the relay device 520-1. On the other hand, in this embodiment, as shown in FIG. 24, the ICS name server 550C-3 is connected to the relay device 520C-1, and the ICS name server 550C-3 has the only ICS network address inside the ICS500C. The ICS name server 550C-3 uses the ICS network server communication function to communicate with the ICS name servers 550C-1 and 550C-2 connected to the access control devices 510C-1 and 510-C2 inside the same VAN-500C1. Therefore, it is possible to collect and retain unique information held only by these ICS name servers. Such an ICS name server is called an ICS name server representing the VAN-500C1. As a result, the ICS name server 550C-1 can communicate with the ICS name server 550C-3 representing the VAN-500C1 and obtain the unique information possessed by the ICS name server 550C-2. In addition, the ICS name server 550C-3 representing VAN-500C1 and the ICS name server 550C-6 representing other VAN-500C2 communicate using the ICS network server communication function, and the unique information held by each is used. Can be exchanged. The ICS name server connected to the access control device may be made to collect the information held by all the ICS name servers inside the VAN, and may be used as the ICS name server representing the VAN.
Example-6 (ICS name server): In Examples 5 and -5A, the access control device 510-1 writes the obtained data such as the ICS user address and the ICS network address to the conversion table 513-1. Write to -1. In this case, the address data written in the temporary conversion table is deleted after, for example, 24 hours.
Example-7 (ICS name server): In Examples 5 and -5A, the access control device 510-1 does not call the address management server 570 and informs the terminal of the ICS user address "0012" of the obtained ICS user address "2014" (or "1130"). Only provide services.
Example-8 (Billing Server): There are two types of billing methods: the "network billing method" that counts and charges the ICS user frames that are sent and received when communication is performed, and the "information billing method" that counts and charges the information inside the transmitted and received ICS user frames. , "Flat-rate billing method" that sets a fixed charge for the period during which the ICS user address etc. is continuously registered in the conversion table of the access control device, for example, on a monthly basis, without charging for the transmitted and received ICS user frames. There are three methods. Here, in the information billing method, the user control unit of the ICS user frame is counted and charged by designating an identifier indicating information billing. In both the network billing method and the information billing method, the case where the sender of the communication bears the charge is called "outgoing billing", and the case where the receiver bears the bill is called "incoming billing". The network billing method and the information billing method are collectively called the "pay-as-you-go billing method".
<< Configuration >> The billing method in the ICS network of the present invention will be described with reference to FIGS. 25 and 26.
The billing method setting information is retained in the conversion table 813-1 in the access control device 810-1 and the flat-rate charge definition table 843 in the billing server 840, and the conversion table 813-1 shows whether network billing is performed or not. And the set value of whether to use the pay-as-you-go billing method (separate outgoing billing and incoming billing) or the flat-rate billing method (separate outgoing billing and incoming billing) are retained. .. Hereinafter, description will be made with reference to the flowchart of FIG. 27. When the access control device 810-1 receives the ICS user frame F50 (step S800), the type of billing method for each ICS frame held in the conversion table 813-1 based on the ICS user address included in the ICS user frame. Is read to check the billing conditions (step S801), and if the read type indicates a pay-as-you-go billing method, billing information is generated, and the billing information is used as the billing information frame F51, which is one of the ICS network servers. If the read type is a value that does not indicate the pay-as-you-go billing method, the billing information is not generated and the billing information is not transferred to the billing server 840 as the billing information frame F51 (step S820). ..
The billing server 840 receives the billing information frame F51 sent from each access control device, and stores the billing information included in the billing information frame. The billing server 840 contains a billing processing device 841 and a billing information database 842, and the billing processing device 841 receives the billing information frame F51 sent from the access control device 810-1 and the billing information included in the billing information frame F51. Is analyzed and stored in the billing information database 842. The billing information database 842 stores billing information as a database with the ICS network address and the ICS user address as identifiers. In addition, in the case of the pay-as-you-go billing method, the billing information database 842 stores information with a count indicating the pay-as-you-go, and an upper limit can be set for the count. If the set upper limit is exceeded, the billing server 840 Notifies the access control device 810-1 that the count exceeds the upper limit value, and stops the communication of the corresponding user in the access control device 810-1 that receives the notification. The billing server 840 can pass the stored billing information to other VANs and users by using the ICS network server communication function.
(1) Outgoing billing communication example with pay-as-you-go network billing: A case where company X and company Y perform communication between companies using the ICS800 of the present invention will be described. In this case, the billing method for communication between LAN800-1 and LAN800-3 is a case where network billing is used, the communication charge on the transmitting side is borne by LAN800-1, and information billing is not performed.
<< Preparations for communication >> Connect LAN800-1 and LAN800-3 to the respective access control devices 810-1 and 810-4.
<< Preparation for billing >> Register the billing conditions for LAN800-1 and LAN800-3 for communication in the conversion table 813-1. Subscribe to conversion table 813-1 as the record, the originating ICS network address, sender ICS user address, incoming ICS network address, and sets the to charging conditions on the basis of the recipient ICS user address. Set "1" as the value for outgoing billing in network billing. Also, set "1" as the billing unit price. Since information billing is not performed, "0" indicating non-billing is set in the billing condition in the information billing condition of conversion table 813-1. Since the charge burden is LAN800-1 in the conversion table to the access control device 810-4 that accommodates LAN800-3, a flat-rate billing method is used to prevent the access control device 810-4 from performing billing processing. Set 0 to indicate.
<< Explanation of billing operation >> The ICS user frame F50 sent by the terminal with the ICS network address 0012 connected to LAN800-1 is sent by the processing device 812-1 in the access control device 810-1 (steps S800, S801) in the ICS user frame. The billing condition field is specified from the sender ICS user address and the receiver ICS user address (step S810), and the billing condition is referred to in order to specify the billing method related to network billing from the field. In this case, since the setting value of the outgoing billing is set to "1" in the network billing, the billing unit price is referred to (step S811) and the billing information is generated (for example, the billing unit price "1" is set. Generated as one-time billing information) (step S812), and the billing information is transferred to the billing server 840 as a billing information frame F51 (step S813). In the billing processing device 841 of the billing server 840, the network billing counter of the billing information database 842 is added according to the billing information in the billing information frame F51 received from the access control device 810-1 (step S814). If the billing conditions are not any of the billing examples described later, the billing described here is performed.
(2) Flat-rate billing method Outgoing billing Communication example: A case where the company X uses the ICS800 of the present invention to perform communication within the company X will be described. In this case, the charge for communication between LAN800-1 and LAN800-2 is a flat-rate charge method, and the communication charge on the calling side is borne by LAN800-1.
<< Preparations for communication >> Connect LAN800-1 and LAN800-2 to the respective access control devices 810-1 and 810-5.
<< Preparation for billing >> Register the billing conditions for LAN800-1 and LAN800-2 that communicate with each other in the conversion table 813-1. For registration in conversion table 813-1, billing conditions are set based on the outgoing ICS network address, sender ICS user address, incoming ICS network address, and recipient ICS user address. 0 is set as the value for the flat-rate billing method, and 1 is set for the charge burden in the flat-rate charge definition table 843 to indicate the outgoing charge. Since information-related charges are not performed, "0" indicating non-charge is set in the charge conditions in the information charge conditions in conversion table 813-1. Also set "0", which indicates the flat-rate billing method, in the conversion table for the access control device 810-5 that accommodates LAN800-2.
<< Explanation of billing operation >> The ICS user frame sent by the terminal with the ICS network address "0012" connected to LAN800-1 is transmitted in the ICS user frame by the processing device 812-1 in the access control device 810-1 (steps S800, S801). The billing condition field is specified from the person ICS user address and the recipient ICS user address (step S810), and the billing condition is referred to in order to specify the billing method from the field. Since the set value in this case is 0 indicating the flat-rate billing method, billing processing such as generation of billing information is not performed (step S820). The process of billing the fee is performed with reference to the flat rate rate definition table 843. In other words, since "0" indicating outgoing charge is set in the flat rate charge definition table 843, the charge is charged to LAN800-1.
(3) Incoming billing communication example with pay-as-you-go network billing: The case where the company X and the company Y communicate with each other will be described. In this case, the billing method for communication between LAN800-1 and LAN800-3 is a case where network billing is used as a pay-as-you-go billing method, the communication charge of the called party is borne by LAN800-3, and information billing is not performed.
<< Preparations for communication >> Connect LAN800-1 and LAN800-3 to the respective access control devices 810-1 and 810-4.
<< Preparation for billing >> Register the billing conditions for LAN800-1 and LAN800-3 that communicate with each other in the conversion table 813-1. For registration in conversion table 813-1, billing conditions are set based on the outgoing ICS network address, sender ICS user address, incoming ICS network address, and recipient ICS user address. Set "2" as the value for incoming billing in network billing, and set "1" as the billing unit price. Since information billing is not performed, "0" indicating non-billing is set in the billing condition in the information billing condition of conversion table 813-1. In the conversion table to the access control device 810-4 that accommodates LAN800-3, since the charge burden is LAN800-3, set "2" as the value for making the network charge the callee charge by the pay-as-you-go method. ..
<< Explanation of billing >> The ICS user frame sent by the terminal with the ICS network address "0012" connected to LAN800-1 is transmitted in the ICS user frame by the processing device 812-1 in the access control device 810-1 (steps S800, S801). The billing condition field is specified from the person ICS user address and the recipient ICS user address (step S810), and the billing condition is referred to in order to specify the billing method related to network billing from the field. Since the set value in this case is 2, which indicates incoming call billing in network billing, the access control device 810-1 in which LAN800-1 is accommodated interrupts the billing process (step S820). When the access control device 810-4 in which LAN800-3 is housed receives the corresponding ICS frame, it refers to the conversion table. In this case, since network billing is set to "2", which is a pay-as-you-go billing method, billing information is generated (for example, billing unit price "1" is generated as two-time billing information) and billing is performed. It is sent to the billing server 840 as an information frame. The network billing counter of LAN800-3 of the billing information database 842 is added according to the billing information of the billing information frame received from the access control device 810-4 by the billing processing device 841 of the billing server 840.
(4) Incoming call billing communication example of flat-rate billing method: The case where the company X communicates within the company X will be described. In this case, the billing method for communication between LAN800-1 and LAN800-2 is a case where network billing is a flat-rate billing method, all charges are borne by the called LAN800-2, and information billing is not performed. is there.
<< Preparations for communication >> Connect LAN800-1 and LAN800-2 to the respective access control devices 810-1 and 810-5.
<< Preparation for billing >> Register the billing conditions for LAN800-1 and LAN800-2 that communicate with each other in the conversion table 813-1. For registration in conversion table 813-1, billing conditions are set based on the outgoing ICS network address, sender ICS user address, incoming ICS network address, and recipient ICS user address. 0 is set as the value indicating the flat-rate billing method, and 2 for incoming billing is set in the billing burden in the flat-rate billing definition table 843 to indicate the billing burden. Since information-related charges are not performed, "0" indicating non-charge is set in the charge conditions in the information charge conditions in conversion table 813-1. Also set "0", which indicates the flat-rate billing method, in the conversion table for the access control device 810-5 that accommodates LAN800-2.
<< Explanation of billing operation >> The ICS user frame sent by the terminal with the ICS network address "0012" connected to LAN800-1 is transmitted in the ICS user frame by the processing device 812-1 in the access control device 810-1 (steps S800, S801). The billing condition field is specified from the person ICS user address and the recipient ICS user address (step S810), and the billing condition is referred to in order to specify the billing method from the field. In this case, since "0" indicating the flat-rate billing method is set, billing processing such as billing information generation is not performed (step S820). The process of billing the fee is performed with reference to the flat rate rate definition table 843. In other words, since "2" indicating incoming call billing is set in the flat-rate charge definition table 843, the charge is charged to LAN800-2.
(5) Outgoing billing with information billing based on pay-as-you-go communication Example: The case where the company X communicates with the company Y will be described. The billing method for communication between LAN800-1 and LAN800-3 is a case where information billing is performed without billing on the network. The charge is when the caller is LAN800-1.
<< Preparations for communication >> Connect LAN800-1 and LAN800-3 to the respective access control devices 810-1 and 810-4.
<< Preparation for billing >> For the billing condition in the network billing condition, set "0" indicating non-billing in the conversion table 813-1. Since the billing itself is not performed, the billing unit price is not set. For the information billing condition, set "1" indicating caller billing by pay-as-you-go billing, and set the billing unit price to "2".
<< Explanation of billing operation >> The ICS user frame sent by the terminal with the ICS network address "0012" connected to LAN800-1 is transmitted in the ICS user frame by the processing device 812-1 in the access control device 810-1 (steps S800, S801). Identify the billing condition field from the person ICS user address and the recipient ICS user address (step S810). Refer to the billing conditions to identify the billing conditions for network communication from that field. In this case, since 0 indicating non-billing is set, the billing process related to the network is not performed (step S820). Next, in order to specify the billing conditions related to information billing, the billing conditions of the information billing conditions are referred to. In this case, since "1" indicating the pay-as-you-go billing paid by the caller is set, the pay-as-you-go billing is performed. Further, the billing unit price indicating the weighting of the pay-as-you-go billing is referred to, and the set value of the billing unit price in this case is 2. Next, based on the obtained information, billing information for each ICS user frame is generated (for example, the billing unit price "2" is generated as billing information for two times), and the billing information is used as the billing information frame F51 for the billing server. Transfer to 840. The billing processing device 841 in the billing server 840 that has received the billing information is a billing information database 842 based on the outgoing ICS network address, the sender ICS user address, the incoming ICS network address, and the recipient ICS user address from the billing information frame F51. The information storage field is specified, and the network billing counter there is added according to the billing information of the billing information frame F51.
(6) Incoming billing communication example with pay-as-you-go billing method information billing: The case where the company X communicates with the company Y will be described. The billing method for communication between LAN800-1 and LAN800-3 shows the case where information billing is performed without network billing. The charge is when the called party is LAN800-3.
<< Preparations for communication >> Connect LAN800-1 and LAN800-3 to the respective access control devices 810-1 and 810-4.
<< Preparation for billing >> For the billing condition in the network billing condition, set "0" indicating non-billing in the conversion table 813-1. Since the billing itself is not performed, the billing unit price is not set. For the information billing condition, set "2" indicating the callee billing by pay-as-you-go billing, and set the billing unit price to "2".
<< Explanation of billing operation >> The ICS user frame sent by the terminal with the ICS network address "0012" connected to LAN800-1 is transmitted in the ICS user frame by the processing device 812-1 in the access control device 810-1 (steps S800, S801). Identify the billing condition field from the person ICS user address and the recipient ICS user address (step S810). Refer to the billing conditions to identify the billing conditions for network communication from that field. In this case, since 0 indicating non-billing is set, the billing process related to the network is not performed (step S820). Next, in order to specify the billing conditions related to information billing, the billing conditions of the information billing conditions are referred to. In this case, "2" indicating the pay-as-you-go billing paid by the called party is set, so the pay-as-you-go billing is performed. .. In addition, the billing unit price indicating the weighting of the pay-as-you-go billing is referred to, and in this case, "2" is set. Next, based on the obtained information, billing information for each ICS user frame is generated (for example, the billing unit price "2" is generated as billing information for two times), and the billing information is used as the billing information frame F51 for the billing server. Transfer to 840. The billing processing device 841 in the billing server 840 that has received the billing information is a billing information database 842 based on the outgoing ICS network address, the sender ICS user address, the incoming ICS network address, and the recipient ICS user address from the billing information frame F51. The information storage field is specified, and the network billing counter there is added according to the billing information of the billing information frame.
(7) An example in which the billing conditions are not registered in the conversion table in advance in the outgoing billing communication with the information billing of the pay-as-you-go billing method: The case where the company X communicates with the company Y will be described. The billing conditions for communication between LAN800-1 and LAN800-4 are the same as above, but in this case, the value that specifies the billing conditions is the conversion table 813-1 of access control 810-1 to which LAN800-1 is connected. The difference is that it is not registered in 1.
<< Preparations for communication >> Connect LAN800-1 and LAN800-4 to the respective access control devices 810-1 and 810-2.
<< Preparation for billing >> In this case, since the billing conditions are not registered in the conversion table 813-1, no prior preparation is required for the access control device 810-1 accommodating the LAN 800-1. In the conversion table of the access control device 810-2 that accommodates LAN800-4, the billing conditions when LAN800-4 receives an incoming call are set. In the billing condition in the network billing condition, "0" indicating non-billing is set in the conversion table. Since the billing itself is not performed, the billing unit price is not set. In the information billing condition, "3" indicating caller billing is set by pay-as-you-go billing, and the billing unit price is set to "1".
<< Explanation of billing operation >> The ICS user frame sent by the terminal with the ICS network address "0012" connected to LAN800-1 is sent by the processing device 812-1 in the access control device 810-1 (step S800), and the ICS user is displayed from the conversion table 813-1. An attempt is made to identify a billing condition field using the sender ICS user address and the recipient ICS user address in the frame (step S801), but in this case there is no field indicating the applicable billing condition, so the called user Inquires to the access controller 810-4 in which the called user is accommodated based on the recipient ICS user address of (step S802). The access control device 810-4 refers to the conversion table in the access control device 810-4 for the billing conditions of the corresponding called party user, and returns the billing conditions to the access control device 810-1. The billing conditions acquired by the access control device 810-1 from the access control device 810-4 are registered in the temporary conversion table 814-1 (step S803). After that, the processing device 812-1 refers to the billing conditions in order to specify the billing conditions related to network communication from the billing conditions (step S810). In this case, since 0 indicating that the network billing is non-billing is set, the billing process related to the network is not performed (step S820).
Next, in order to specify the billing conditions related to information billing, the billing conditions of the information billing conditions are referred to. In this case, since "1" is set to indicate the pay-as-you-go billing paid by the caller, the pay-as-you-go billing is performed. Further, the billing unit price indicating the weighting of the pay-as-you-go billing is referred to, and the set value of the billing unit price in this case is "1", and the weighting of the billing is known. Based on the obtained information, billing information for each ICS user frame is generated (for example, the billing unit price "1" is generated as one-time billing information), and the billing information is transferred to the billing server 840 as the billing information frame F51. To do. The billing processing device 841 in the billing server 840 that has received the billing information identifies the information storage field of the billing information database 842 based on the outgoing ICS network address and the recipient ICS user address from the billing information frame F51, and charges the information there. The counter is added according to the billing information of the billing information frame F51.
Example-9 (ICS frame database server): 28 and 29 are examples of ICS900 including ICS frame database servers 950 and 960, which are one of the ICS network servers. The ICS frame database servers 950 and 960 are terminals that use ICS900 (hereinafter, ICS use). Data is stored based on the request timing of (called "terminal"), or the stored data is taken out and sent to the request source. The ICS frame database servers 950 and 960 are composed of processing devices 951 and 961, storage information management tables 952 and 962, and BOX 953 and 963, respectively. The processing devices 951 and 961 receive the ICS user frame from the ICS user terminal, refer to the ICS frame database server usage request explicitly indicated by the ICS user terminal, and store the ICS user frame storage instruction. Information management table 952 and This is done for 962, and information storage instructions are given to BOX 953 and 963. The stored information management tables 952 and 962 receive the instructions of the processing devices 951 and 961 and store the items to be managed such as the communication partner address and the index number of the stored information for each ICS-using terminal to be accommodated. The BOX 953 and 963 receive the instructions of the processing devices 951 and 961 and store the management number, user information, etc. of the stored information for each ICS-using terminal to be accommodated. The preparations for using the ICS frame database servers 950 and 960 and their communication examples are described below. << Preparations >> In order to enable the VAN-1 operator to store the information of the terminal with the ICS user address "0012" connected to the LAN900-1 of the company X, the information about the user (book) is stored in advance in the stored information management table 952 and BOX953. In the example, the ICS user address 0012 etc.) is registered. Similarly, the VAN-3 operator can also store the information of the terminal with the ICS user address "0034" connected to the LAN900-2 of the company X in advance in the stored information management table 962 and BOX963. Register information about the user (ICS user address "0034" etc. in this example). The ICS user sends the ICS user frame F60 as shown in FIG. 30 to the ICS900. In this ICS user frame F60, the user control unit is provided with a usage request identifier for using the ICS frame database server (an identifier that explicitly indicates that the ICS frame database server is used) and an information operation identifier (in the ICS frame database server). An identifier that explicitly indicates the operation of the stored information) is added. In this embodiment, the user realizes the user's ICS frame database server usage request by adding the usage request identifier and the information manipulation identifier to the user control unit of the ICS user frame F60. However, the ICS user data It is also possible to add a usage request identifier and an information manipulation identifier to the unit.
<< Communication example >> (1) Communication example-1 (Operation of ICS frame database server on the sending side): A terminal with an ICS user address "0012" connected to LAN900-1 of company X communicates with a terminal with an ICS user address "0034" connected to LAN900-2 of company X using an ICS frame database server. carry out. A flowchart is shown in FIG. 31, and its operation will be described.
The caller terminal is a usage request identifier that uses the ICS frame database server 950 in the user control unit (caller storage user management number: a code arbitrarily assigned by the user who uses ICS, and information stored by the ICS user. The ICS user frame F60 with the added information operation identifier (scheduled transfer time, information storage, information transfer, information deletion, information end, etc.) is sent to the ICS900. The received access control device 9101 (step S900) refers to the usage request identifier of the ICS user frame F60 in the processing device 912-1 (step S901), and the number of the usage request identifier set by the caller terminal exists. If so, the ICS user frame F60 is transferred to the processing device 951. Upon receiving the ICS user frame F60, the processing device 951 refers to the usage request identifier and the information manipulation identifier (step S910), and performs the operation indicated by the information manipulation identifier.
When information storage is indicated, the processing device 951 receives the usage request identifier (caller storage user management number) and information operation identifier (information storage) of the ICS user frame F60 sent from the caller terminal. , The receiver ICS user address and the usage request identifier are stored in the storage information management table 952 corresponding to the sender ICS user address of the corresponding frame, and the ICS user frame is stored in the BOX 953 (step S911). Since the ICS user frame to be stored is divided into a plurality of ICS user frames and sent from the caller, this operation is performed by the information manipulation identifier (end of information) shown in the ICS user frame F60. It is executed until the last frame is indicated (step S912).
When the scheduled transfer time is indicated (step S913), the processing device 951 sends the ICS user frame F60 usage request identifier (caller storage user management number) and information operation identifier (scheduled transfer time) sent from the caller terminal. ) Is stored in the storage information management table 952 (step S914), and the processing device 951 constantly monitors the scheduled transfer time. Transfer the stored information to the recipient terminal (step S915).
When information transfer is indicated, the processing device 951 receives the usage request identifier (originating side stored user management number) and information manipulation identifier (transfer request) of the ICS user frame F60 sent from the calling terminal. , Sends the information (ICS user frame) stored in BOX953 to the recipient terminal (step S916). When information erasure is indicated, the processing device 951 receives the usage request identifier and information manipulation identifier (information erasure) of the ICS user frame F60 sent from the caller terminal, thereby storing information management table 952. And delete the stored information from BOX953 (step S917).
(2) Communication example-2 (Operation of ICS frame database server on the receiving side): A terminal with an ICS user address "0034" connected to LAN900-2 of company X uses the user BOX to receive information from a terminal with an ICS user address "0012" connected to LAN900-1 of company X. To receive. A flowchart is shown in FIG. 32 to explain its operation.
The caller terminal is a code that is arbitrarily assigned by the user who uses the receiver side ICS frame database server 960 in the user control unit, and is stored in the user control unit. The ICS user frame F60 with the information manipulation identifier added (which is the index number when manipulating the information) is sent to the ICS900. The corresponding ICS user frame F60 is transferred in the ICS900 to the access control device 910-5 in which the receiver terminal is housed (step S920), and the processing device 912-5 refers to the usage request identifier of the ICS user frame F60 (step S920). In step S921), if the usage request identifier number set by the caller terminal exists, the ICS user frame F60 is transferred to the processing device 961.
Upon receiving the ICS user frame F60, the processing device 961 examines the information operation identifier (information storage, information transfer, information deletion, information termination) of the ICS user frame F60 (step S930), and if the information is stored, transmits the corresponding frame. The usage request identifier is stored in the storage information management table 962 corresponding to the person ICS user address and the recipient ICS user address, and the ICS user frame is stored in BOX963 (step S931). Since the ICS user frame to be stored is divided into a plurality of ICS user frames and sent from the caller, this operation is performed by the information manipulation identifier (information end) shown in the ICS user frame F60 of the ICS user frame to be stored. Executed until the final frame is indicated (step S932). The processing device 962 attaches the arrival side storage user management number to the receiver terminal at the timing agreed with the receiver terminal in advance (for example, at 12:00) that the information addressed to the receiver terminal exists in the ICS frame database server 960. And notify (step S933). The receiver terminal that received the notification sends the ICS user frame F60 in which the usage request identifier and the information operation identifier (information transfer) are set to the access control device 910-5, and the ICS frame database server 960 stores it in the BOX 963. A certain user information is transmitted to the recipient terminal (step S936), and the recipient terminal receives the information (ICS user frame) stored in the ICS frame database server 960. When the processing device 961 receives a frame in which the usage request identifier and the information manipulation identifier (information deletion) of the ICS user frame F60 are specified from the receiver terminal, the processing device 961 deletes the information from the stored information management table 962 and BOX963 (step S937).
(3) Communication example-3 (when the receiving side cannot receive temporarily): Recipient terminal when a terminal with an ICS user address "0012" connected to Enterprise X's LAN900-1 communicates with a terminal with an ICS user address "0034" connected to Enterprise X's LAN900-2. Alternatively, even if it is temporarily impossible to connect to LAN900-2 of company X, the information addressed to the recipient terminal is temporarily stored in the ICS frame database server 960, and communication is performed in a state where the connection is possible. The operation will be described with reference to the flowchart of FIG. 33.
The caller terminal adds an information manipulation identifier (temporarily stored) to the user control unit by temporarily storing the information in the ICS frame database server 960 even when communication with the receiver terminal is not possible. ICS user frame F60 is sent to ICS900. The corresponding ICS user frame F60 is transferred in the ICS900 to the access control device 910-5 in which the receiver terminal is housed, the access control device 910-5 receives the ICS user frame F60 (step S940), and the processing device 912- 5 checks the existence of the usage request identifier inside the ICS user frame F60 (step S941), refers to the information operation identifier (temporarily stored) of the ICS user frame F60 (step S942), and once there is a request for storage, the receiving side Determines if the terminal is in a communicable state, and if possible, sends the corresponding ICS user frame F60 to the receiving terminal (step S950), and if not, sends the corresponding ICS user frame F60 to the ICS frame database server. Transferred to the processing device 961 of the 960, and then the processing device 961 stores the sender ICS address, the receiver ICS address, and the usage request identifier of the corresponding ICS user frame F60 in the storage information management table 962, and stores the ICS user frame. Store in BOX963 (step S951).
Since the ICS user frame to be stored is divided into a plurality of ICS user frames and sent from the caller, this operation is performed by the information manipulation identifier (information end) shown in the ICS user frame F60. It is executed until the final frame of is indicated (step S952). The processing device 912-5 constantly monitors the communication status with the receiver terminal, and when the receiver terminal becomes receivable, the processing device 961 is notified that the corresponding receiver communication status is possible. Upon receiving the notification, the processing device 961 notifies the receiver terminal at the timing agreed with the receiver terminal in advance (for example, after 5 minutes) that the information addressed to the receiver terminal exists in the ICS frame database server 960 (step). S953). The receiver terminal that received the notification sends the ICS user frame F60 in which the usage request identifier (ICS storage user management number) and the information operation identifier (information transfer) are set to the access control device 910-5, and sends the ICS frame database server 960. Sends the user information stored in the BOX 963 to the recipient terminal (step S956), and the recipient terminal receives the information stored from the ICS frame database server 960.
When the processing device 961 receives a frame in which the usage request identifier and the information manipulation identifier (information deletion) of the ICS user frame F60 are specified from the receiver terminal, the processing device 961 deletes the information from the stored information management table 962 and BOX 963 (step S957).
Example-10 (X.25, FR, ATM, transmission by satellite communication and telephone line, ISDN line, CATV line, satellite line, accommodation of IPX frame): The format of data from the user in the ICS of the present invention is not limited to the ICS user frame according to the provisions of RFC791 or RFC1883, and can accommodate telephone lines, ISDN lines, CATV lines, satellite lines, and IPX. In addition, the relay network of the ICS network frame in the ICS network can also support X.25, FR, ATM, satellite communication, etc. In the present invention, the ATM switch includes a cell relay switch, and the ATM network includes a cell relay network.
FIGS. 34 to 37 show an example of interface conversion in the ICS1000 of the present invention, and are access control devices 1010-1 and 1010-2, ICS frame interface network 1050, X.25 network 1040, FR network 1041, and ATM network. 1042, satellite communication network 1043, X.25 / ICS network frame converters 1031-1 and 1031-2, FR / ICS network frame converters 1032-1 and 1032-2, ATM / ICS network frame converters 1033-1 and 1033-2, satellite / ICS network frame converters 1034-1 and 1034-2, telephone line converters 1030-1 and 1030-2, ISDN line converters 1029-1 and 1029-2, CATV line converters 1028-1 And 1028-2, satellite line conversion units 1027-1 and 27-2, and IPX conversion units 1026-1 and 1026-2.
The ICS frame interface network 1050 is a relay network that transfers ICS network frames in the same format in accordance with the provisions of RFC791 or RFC1883. The X.25 network 1040 is a relay network that transfers X.25 format frames, and is used to convert ICS network frames to X.25 format frames and reverse conversion. It has 25 / ICS network frame converters 1031-1 and 1031-2 in the input / output section. The FR network 1041 is a relay network that transfers frames in the frame relay format, and includes FR / ICS network frame converters 1032-1 and 1032-2 for converting and inverting ICS network frames into frame relay format frames. I have it in the output section. The ATM network 1042 is a relay network that transfers ATM format frames, and the ATM / ICS network frame conversion units 1033-1 and 1033-2 for converting and reversely converting ICS network frames to ATM format frames are input and output units. Have in The satellite communication network 1043 is a relay network that transfers information using satellites, and is a satellite / ICS network frame conversion unit 1034-1 and 1034-2 for converting and inversely converting an ICS network frame into an interface of a satellite communication network. Is in the input / output section. The telephone line conversion units 1030-1 and 1030-2 convert and reverse the functions corresponding to the physical layer and data link layer (first layer and second layer of the OSI communication protocol) between the telephone line and the access control device. It has a function to convert. The ISDN line conversion units 1029-1 and 1029-2 have a function of converting and inverting a function corresponding to a physical layer or a data link layer between the ISDN line and the access control device. The CATV line conversion units 1028-1 and 1028-2 have a function of converting and inverting a function corresponding to a physical layer or a data link layer between the CATV line and the access control device. The satellite line conversion units 1027-1 and 1027-2 have a function of converting and inverting a function corresponding to a physical layer or a data link layer between the satellite line and the access control device. The IPX conversion units 1026-1 and 1026-2 have a function of converting and inverting a function corresponding to a physical layer or a data link layer between the IPX and the access control device.
(1) The operation when communication is performed between the access control measure 1010-1 and the access control device 1010-2 via the X.25 network 1040 will be described.
The access controller 1010-1 sends an ICS network frame to the X.25 switch 10131-1. The X.25 / ICS network frame converter 1031-1 in the X.25 switch 10131-1 converts the ICS network frame received from the access controller 1010-1 into an X.25 format frame as shown in Fig. 38. To do. Then, the X.25 exchange 10131-1 sends an X.25 format frame into the X.25 network 1040. X.25 format frames sent from the X.25 switch 10131-1 are transferred within the X.25 network 1040 and reach the X.25 switch 10131-2. Next, the X.25 / ICS network frame converter 1031-2 in the X.25 switch 10131-2 converts the received X.25 format frame back to the ICS network frame format and accesses the access control device 1010-. Send to 2. Access controller 1010-2 receives the ICS network frame. The ICS1000 network frame sent from the access control device 1010-2 to the X.25 switchboard 10131-2 is also transferred to the access control device 1010-1 in the same manner.
(2) The operation when communication is performed between the access control measure 1010-1 and the access control device 1010-2 via the FR network 1041 will be described.
Access control device 1010-1 sends out an ICS network frame. The FR / ICS network frame conversion unit 1032-1 in the FR exchange 10132-1 converts the ICS network frame received from the access control device 1010-1 into an FR format frame as shown in FIG. 39. Then, the FR exchange 10132-1 sends the FR format frame into the FR network 1041, and the FR format frame sent from the FR exchange 10132-1 is transferred in the FR network 1041 and reaches the FR exchange 10132-2. To do. The FR / ICS network frame conversion unit 1032-2 in the FR exchange 10132-2 reversely converts the received FR format frame into the ICS network frame format and sends it to the access control device 1010-2. Access controller 1010-2 receives the ICS network frame. The ICS network frame sent from the access control device 1010-2 to the FR switch 10132-2 is also transferred to the access control device 1010-1 in the same manner.
(3) The operation when communication is performed between the access control measure 1010-1 and the access control device 1010-2 via the ATM network 1042 will be described.
The access control device 1010-1 sends an ICS network frame to the ATM switch 10133-1. The ATM / ICS network frame conversion unit 1033-1 in the ATM exchange 10133-1 converts the ICS network frame received from the access control device 1010-1 into an ATM format frame as shown in FIG. 40. The ATM exchange 10133-1 sends an ATM format frame into the ATM network 1042, and the ATM format frame sent from the ATM exchange 10133-1 is transferred in the ATM network 1042 and reaches the ATM exchange 10133-2. The ATM / ICS network frame conversion unit 1033-2 in the ATM exchange 10133-2 reversely converts the received ATM format frame into the ICS network frame format and sends it to the access control device 1010-2. Access controller 1010-2 receives the ICS network frame. The ICS network frame sent from the access control device 1010-2 to the ATM switch 10133-2 is also transferred to the access control device 1010-1 in the same manner.
(4) The operation when communication is performed between the access control measure 1010-1 and the access control device 1010-2 via the satellite communication network 1043 will be described.
The access control device 1010-1 sends an ICS network frame to the satellite transmitter / receiver 10134-1. The satellite / ICS network frame conversion unit 1034-1 in the satellite transmitter / receiver 10134-1 converts the ICS network frame received from the access control device 1010-1 into an interface in the satellite communication network 1043. Next, the satellite transmitter / receiver 10134-1 transmits the ICS network frame converted into the interface in the satellite communication network 1043 into the satellite communication network 1043, and the ICS network frame transmitted from the satellite transmitter / receiver 10134-1. Is transferred within the satellite communication network 1043 and reaches the satellite transmitter / receiver 10134-2. The satellite / ICS network frame converter 1034-2 in the satellite transmitter / receiver 10134-2 reverse-converts the ICS network frame converted to the interface in the received satellite communication network 1043 and sends it to the access control device 1010-2. To do. Access controller 1010-2 receives the ICS network frame. The ICS network frame transmitted from the access control device 1010-2 to the satellite transmitter / receiver 10134-2 is also transferred to the access control device 1010-1 in the same manner.
(5) User 1060-1 who is connected to the telephone line conversion unit 1030-1 of access control device 1010-1 makes a call and is connected to the telephone line conversion unit 1030-2 of access control device 1010-2. The operation when communicating with 2 via the telephone line interface will be explained.
User 1060-1 applies to the VAN operator for a telephone line connection. The VAN operator identifies the access control device 1010-1 to which the user 1060-1 is connected, and determines the ICS network address 7721 of the ICS logical terminal. Next, the VAN operator puts the outgoing ICS network address "7721", the sender telephone number "03-5555-1234", and the recipient telephone number "06-5555-9876" in the conversion table 1013-1 of the access control device 1010-1. , Incoming ICS network address "5521" and information such as request type are set. This example shows an example in which the request type "5" is set as a telephone line connection. Similarly, the conversion table 1013-2 of the access control device 1010-2 shows the outgoing ICS network address 5521, the sender telephone number 06-5555-9876, the recipient telephone number 03-5555-1234, and the incoming ICS. Set information such as network address "7721" and request type.
User 1060-1 sends out the telephone number "06-5555-9876". The telephone line conversion unit 1030-1 converts the received telephone number into the reading format of the processing device 1012-1 and sends it to the processing device 1012-1. The processing device 1012-1 that received the telephone number information from the telephone line conversion unit 1030-1 of the ICS network address "7721" refers to the request type of the outgoing ICS network address "7721" in the conversion table 1013-1 and makes a telephone call. Recognizes that it is a line connection and reads the incoming ICS network address "5521" from the incoming telephone number "06-5555-9876". The access control device 1010-1 has a network control unit in which the incoming ICS network address is set to "5521" and the outgoing ICS network address is set to "7721", and network data describing information for notifying that there is an incoming call. Create an ICS network frame with a part and send it to the ICS1000 network. The ICS network frame sent from the access control device 1010-1 is transferred in the network of the ICS1000 and reaches the access control device 1010-2. The access control device 1010-2 that received the ICS network frame having the network data section that describes the information for notifying that there is an incoming call is the user 1060-2 from the telephone line conversion section 1030-2 of the ICS network address "5521". To send a signal to notify the incoming call. Then, user 1060-2 sends a response signal.
When the telephone line converter 1030-2 receives the response signal, it converts it into a format that can be transferred within the ICS1000 network. The access control device 1010-2 has a network control unit in which the incoming ICS network address is set to "7721" and the outgoing ICS network address is set to "5521", and a network that describes information for notifying that the call has been answered. Create an ICS network frame with a data part and send it to the ICS network. The ICS network frame sent from the access control device 1010-2 is transferred in the ICS network and reaches the access control device 1010-1. The access control device 1010-2 that received the ICS network frame having the network data section that describes the information to convey that there was a response is the user 1060- from the telephone line conversion section 1030-1 of the ICS network address "7721". For 1, send a signal to notify the response. As a result, the user 1060-1 and the user 1060-2 start full-duplex communication using an analog signal (voice, etc.), and the user 1060-1 sends an analog signal. Upon receiving the analog signal, the telephone line converter 1030-1 converts the analog signal into an analog information format that can be transferred within the ICS network.
The access control device 1010-1 creates a network control unit in which the incoming ICS network address is set to "5521" and the outgoing ICS network address is set to "7721", and an ICS network frame having a network data unit in which analog information is described. Then send it to the ICS1000 network. The ICS network frame sent from the access control device 1010-1 is transferred within the network of the ICS1000 and reaches the access control device 1010-2. The access control device 1010-2, which received the ICS network frame having the network data unit in which the analog information was described, converted the analog information into the telephone line interface in the telephone line conversion unit 1030-2 of the ICS network address "5521". Send to user 1060-2 as an analog signal. The analog signal sent from user 1060-2 is also transferred to user 1060-1 in the same procedure.
(6) User 1061-1 connected to ISDN line conversion unit 1029-1 of access control device 1010-1 originated and connected to ISDN line conversion unit 1029-2 of access control device 1010-2. The operation when communicating with 2 via the ISDN line interface will be described.
User 1061-1 applies for an ISDN line connection to the VAN operator, and the VAN operator identifies the access control device 1010-1 to which user 1061-1 is connected and determines the ICS network address "7722" of the ICS logical terminal. Next, the VAN operator puts the outgoing ICS network address 7722, the sender ISDN number 03-5555-1111, and the receiver ISDN number 06-5555-2222 in the conversion table 1013-1 of the access controller 1010-1. , Incoming ICS network address "5522" and information such as request type are set. In this example, an example is shown in which the request type "6" is used as an ISDN line connection. Similarly, the conversion table 1013-2 of the access control device 1010-2 shows the outgoing ICS network address 5522, the sender ISDN number 06-5555-2222, the receiver ISDN number 03-5555-1111, and the incoming ICS network address. Set information such as "7722" and request type.
User 1061-1 sends the ISDN number "06-5555-2222". The ISDN line conversion unit 1029-1 converts the received ISDN number into the reading format of the processing device 1012-1 and sends it to the processing device 1012-1. The processor 1012-1 that received the ISDN number information from the ISDN line conversion unit 1029-1 of the ICS network address "7722" refers to the request type of the outgoing ICS network address "7722" in conversion table 1013-1 and ISDN. Recognizes that it is a line connection and reads the incoming ICS network address "5522" from the incoming ISDN number "06-5555-2222". The access control device 1010-1 has a network control unit with the incoming ICS network address set to "5522" and an outgoing ICS network address set to "7722", and a network data unit that describes information for notifying that there is an ISDN incoming call. Create an ICS network frame to have and send it to the ICS1000 network.
The ICS network frame sent from the access control device 1010-1 is transferred in the ICS1000 and reaches the access control device 1010-2. The access control device 1010-2 that received the ICS network frame having the network data unit that describes the information for notifying that there is an incoming call is the user 1061-2 from the ISDN line conversion unit 1029-2 of the ICS network address "5522". Sends a signal to notify the incoming call. Then, user 1061-2 sends a response signal. When the ISDN line converter 1029-2 receives the response signal, it converts it into a format that can be transferred within the ICS1000. The access control device 1010-2 describes the network control unit in which the incoming ICS network address is set to "7722" and the outgoing ICS network address is set to "5522", and information for notifying that an ISDN response has been received. Create an ICS network frame with a network data part and send it to the ICS1000 network.
The ICS network frame sent from the access control device 1010-2 is transferred in the ICS1000 and reaches the access control device 1010-1. The access control device 1010-2 that received the ICS network frame having the network data section that describes the information to convey that there was a response is the user 1061-from the ISDN line conversion section 1029-1 of the ICS network address "7722". For 1, send a signal to notify the response. As a result, the user 1061-1 and the user 1061-2 start full-duplex communication using a digital signal (voice, etc.), and the user 1061-1 sends a digital signal. Upon receiving the analog signal, the ISDN line converter 1029-1 converts the analog signal into a digital information format that can be transferred within the ICS1000.
The access control device 1010-1 creates a network control unit in which the incoming ICS network address is set to "5522" and the outgoing ICS network address is set to "7722", and an ICS network frame having a network data unit in which digital information is described. And send it to ICS1000. The ICS network frame sent from the access control device 1010-1 is transferred in the ICS1000 and reaches the access control device 1010-2. The access control device 1010-2, which received the ICS network frame having the network data unit in which the digital information was described, converted the digital information into the ISDN line interface in the ISDN line conversion unit 1029-2 of the ICS network address "5522". It is sent to user 1061-2 as a digital signal. Conversely, the digital signal sent from user 1061-2 is also transferred to user 1061-1 in the same procedure.
(7) The CATV broadcasting station 1062-1 connected to the CATV line conversion unit 1028-1 of the access control device 1010-1 and the user 1062-2 connected to the CATV line conversion unit 1028-2 of the access control device 1010-2. The operation when communicating with the CATV line interface will be described.
CATV broadcasting station 1062-1 applies to the VAN operator for a CATV line connection with user 1062-2. The VAN operator identifies the access control device 1010-2 to which the user 1062-2 is connected, and determines the ICS network address "5523" of the ICS logical terminal. Next, the VAN operator sets information such as the incoming ICS network address "5523" and the request type in the corresponding part of the outgoing ICS network address "7723" in the conversion table 1013-1 of the access control device 1010-1. This example shows an example in which the request type "7" is used as a CATV line connection. Similarly, information such as the outgoing ICS network address 5523, the incoming ICS network address 7723, and the request type is set in the conversion table 1013-2 of the access control device 1010-2.
CATV broadcasting station 1062-1 sends out a CATV analog signal. Upon receiving the CATV analog signal, the CATV line converter 1028-1 converts the CATV analog signal into an information format that can be transferred within the ICS1000. The access control device 1010-1 has a network control unit in which the incoming ICS network address is set to "5523" and an outgoing ICS network address is set to "7723", and an ICS network frame having a network data unit in which CATV information is described. Create and send to ICS1000. The ICS network frame sent from the access control device 1010-1 is transferred in the ICS1000 and reaches the access control device 1010-2. The access control device 1010-2, which receives the ICS network frame having the network data section that describes the CATV information, converts the CATV information into the CATV line interface at the CATV line conversion section 1028-2 with the ICS network address "5523". It is sent to user 1062-2 as a CATV analog signal. Conversely, the CATV analog signal sent from user 1062-2 is also transferred to the CATV broadcasting station 1062-1 in the same procedure.
(8) User 1063-1 connected to the satellite line conversion unit 1027-1 of access control device 1010-1 and user 1063-2 connected to satellite line conversion unit 1027-2 of access control device 1010-2. The operation when communicating with each other by the interface of the satellite line will be described.
Users 1063-1 and 1063-2 apply to the VAN operator for a satellite line connection between user 1063-1 and user 1063-2. The VAN operator identifies the access control device 1010-1 to which the user 1063-1 is connected, and determines the ICS network address "7724" of the ICS logical terminal. Similarly, identify the access control device 1010-2 to which the user 1063-2 is connected, and determine the ICS network address 5524 of the ICS logical terminal. Next, the VAN operator sets the incoming ICS network address 5524 and information such as the request type in the corresponding part of the outgoing ICS network address 7724 in the conversion table 1013-1 of the access control device 1010-1. In this example, the request type "8" is used as the satellite line connection. Similarly, information such as the outgoing ICS network address 5524, the incoming ICS network address 7724, and the request type is set in the conversion table 1013-2 of the access control device 1010-2.
User 1063-1 sends a satellite signal. Upon receiving the satellite signal of the satellite line interface, the satellite line conversion unit 1027-1 converts the satellite signal into an information format that can be transferred within the ICS1000. The access control device 1010-1 includes a network control unit in which the incoming ICS network address is set to "5524" and the outgoing ICS network address is set to "7724", and an ICS network frame having a network data unit in which satellite signal information is described. Is created and sent to ICS1000. The ICS network frame sent from the access control device 1010-1 is transferred in the network of the ICS1000 and reaches the access control device 1010-2. The access control device 1010-2, which has received the ICS network frame having a network data unit that describes the satellite signal information, transmits the satellite signal information to the satellite line in the satellite line conversion unit 1027-2 of the ICS network address "5524". It is sent to user 1063-2 as a satellite signal converted into an interface. On the contrary, the satellite signal of the interface of the satellite line transmitted from the user 1063-2 is also transferred to the user 1063-1 in the same procedure.
(9) The operation when communication is performed between the terminal having the IPX address "9901" of the user 1064-1 and the terminal having the IPX address "8801" of the user 1064-2 by the IPX interface will be described.
Users 1064-1 and 1064-2 apply to the VAN operator for an IPX connection between the terminal with the IPX address "9901" of the user 1064-1 and the terminal with the IPX address "8801" of the user 1064-2. I do. The VAN operator determines the ICS network address 7725 of the access control device 1010-1 and the IPX converter 1026-1 to connect the user 1064-1. Similarly, the ICS network address 5525 of the access control device 1010-2 and the IPX converter 1026-2 to which the user 1064-2 is connected is determined. Next, the VAN operator puts the sender IPX address "9901", the receiver IPX address "8801", and the incoming ICS network in the corresponding part of the outgoing ICS network address "7725" in the conversion table 1013-1 of the access control device 1010-1. Set information such as address "5525" and request type. In this example, the request type "9" is used as the IPX connection. Similarly, the sender IPX address 8801, the receiver IPX address 9901, and the incoming ICS network address 7725 correspond to the outgoing ICS network address 5525 in the conversion table 1013-2 of the access control device 1010-2. And set information such as request type.
The terminal having the IPX address "9901" of the user 1064-1 sends an IPX frame in which the sender IPX address is set to "9901" and the receiver IPX address is set to "8801". The access control device 1010-1 receives the IPX frame at the IPX conversion unit 1026-1 of the ICS network address 7725, and reads the sender IPX address 9901 and the receiver IPX address 8801 in the IPX frame. Then, the access control device 1010-1 reads the incoming network address 5525 of the receiver IPX address 8801 of the sender IPX address 9901 of the outgoing ICS network address 7725 from the conversion table 1013-1. The access control device 1010-1 includes a network control unit in which the incoming ICS network address is set to "5525" and the outgoing ICS network address is set to "7725", and an ICS network frame having a network data unit in which IPX frame information is described. Is created and sent to ICS1000.
The ICS network frame sent from the access control device 1010-1 is transferred in the ICS1000 and reaches the access control device 1010-2. The access control device 1010-2 that receives the ICS network frame having the network data section that describes the IPX frame information receives the IPX frame information of the ICS network frame in the IPX conversion section 1026-2 of the ICS network address "5525". It is sent to user 1064-2 as an IPX frame converted to an IPX interface. The terminal having the IPX address 8801 of user 1064-2 receives the IPX frame. Conversely, for IPX frames with the sender IPX address set to "8801" and the recipient IPX address set to "9901" sent from the terminal with the IPX address "8801" of user 1064-2, the user can follow the same procedure. Transferred to 1064-1.
Example-11 (X.25, FR, ATM, transmission by satellite communication and telephone line, ISDN line, CATV line, accommodation of satellite line): In the above embodiment-10, X.25 / ICS network frame conversion units 1031-1 and 1031-2, FR / ICS network frame conversion units 1032-1 and 1032-2, and ATM / ICS network frame conversion units 1033-1. And 1033-2, satellite / ICS network frame converters 1034-1 and 1034-2 are located in the relay network, that is, in the X.25 network 1040, FR network 1041, ATM network 1042, and satellite communication network 1043, respectively. There is. On the other hand, in Example-11, as shown in FIGS. 41 and 42, the X.25 / ICS network frame converters 1131-1 and 1131-2 and the FR / ICS network frame converters 1132-1 and 1132-2. , ATM / ICS network frame converters 1133-1 and 1133-2, and satellite / ICS network frame converters 1134-1 and 1134-2 are located in access control devices 1110-1 and 1110-2, respectively. That is, in Example-10, each relay network (X.25 network 1040, FR network 1041, ATM network 1042, satellite communication network 1043) converts the received ICS network frame into a format that can be transferred on each relay network side. Inverse conversion is performed, but in the present embodiment-11, conversion to a format that can be transferred by each relay network and reverse conversion are performed on the access control device side.
Example-12 (Accommodation of access control device in relay network): In the tenth embodiment, the X.25 / ICS network conversion units 1031-1 and 1031-2, the FR / ICS network conversion units 1032-1 and 1032-2, and the ATM / ICS network conversion units 1033-1 and 1033- 2. The satellite communication network / ICS network converters 1034-1 and 1034-2 are located in the relay network, that is, in the X.25 network 1040, FR network 1041, ATM network 1042, and satellite communication network 1043, respectively. Access control devices 1010-1 and 1010-2 are not installed in the X.25 network, FR network, ATM network, or satellite communication network. On the other hand, in Example-12, as shown in FIGS. 43 and 44, the access control devices 1120-1, 1120-2, 1121-1, 1121-2, 1122-1, 1122-2, 1123-1, 1123-2 is located within the relay network, that is, within the X.25 network 1240-1, FR network 1241-1, ATM network 1242-1, and satellite communication network 1243-1, respectively. That is, in the tenth embodiment, the conversion from the ICS user frame to the ICS network frame and the inverse conversion were performed based on the management of the conversion table in the access control device installed outside each relay network, but in this embodiment, the conversion is performed. Conversion from ICS user frame to ICS network frame (ICS encapsulation) and reverse conversion (ICS reverse encapsulation) performed based on the management of the conversion table are performed in each of the above relay networks, that is, inside the X.25 switch, in the FR switch. It is done inside the ATM network switch, inside the satellite transmitter / receiver.
Example-13 (relay network connected to relay device): In the tenth embodiment, the X.25 network 1040, the FR network 1041, the ATM network 1042, and the satellite communication network 1043 are all connected to the access control devices 1010-1 and 1010-2, but are connected to the relay device. Is not connected. On the other hand, in Example-13, as shown in FIG. 45, the X.25 network 202-1 is connected to the access control device 2010 and the relay device 2030, and the FR network 2021-1 is connected to the access control device 2011 and the relay device 2031. The ATM network 2022-1 is connected to the access control device 2012 and the relay device 2032, the satellite communication network 2023-1 is connected to the access control device 2013 and the relay device 2033, and the X.25 network 2020-2. Is connected to relay devices 2030, 2034, 2035, FR network 2021-2 is connected to relay devices 2031, 2035, ATM network 2022-2 is connected to relay devices 2031, 2032, 2036, and satellite communication network 2023-2. Is connected to repeaters 2033, 2036, 2037. That is, in this embodiment, the X.25 network 202-1, 2020-2, RF network 2021-1, 2021-2, ATM network 2022-1, 2022-2, satellite communication network 2023-1, 2023-2 , Both are configured to be connected to a relay device.
Example-14 (when the access control device is installed outside the ICS): FIG. 46 shows a 14th embodiment of the present invention, in which the access control device 1210-1 is placed outside the ICS1200, that is, inside the LAN-1200 of the company X. Correspondingly, the ICS address management server 1250-1 and the ICS network server 1260-1 are also placed outside the ICS1200, that is, inside the LAN1200-1, and the access control device general management server 1240 is placed inside the ICS1200. The access control device general management server 1240 has a function of communicating with the access control device 1210-1, the ICS address management server 1250-1, and the ICS network server 1260-1 by using the ICS network server communication function to exchange information. There is. When the VAN operator concludes a contract with company X and connects the user communication line to the ICS1200, the VAN operator writes the data to the internal conversion table of the access control device 1210-1 using the function of the access control device general management server 1240. In addition, the ICS address management server 1250-1 and the ICS network server 1260-1 can communicate with the ICS address management server 1250-2 and the ICS network server 1260-2 inside the ICS1200 by using their respective ICS network server communication functions. ..
Since it is configured in this way, the user terminal inside the LAN 1200 can perform intra-company communication and inter-company communication according to the same method as described in the first embodiment. Even if the ICS address management server 1250-1 and the ICS network server 1260-1 are placed in the ICS1200, it is clear that the user terminal can perform intra-company communication and inter-company communication as described above. .. The other embodiment described above replaces the ICS address management server with the ICS address name management server described in Example-24.
Example-15 (Non-ICS encapsulation of inter-company communication): Using FIGS. 47 and 48, an example of non-ICS encapsulation in business-to-business communication will be described as a method of determining a transfer destination in ICS from a recipient ICS user address based on management of a conversion table and communicating. .. This communication method is an example in which ICS encapsulation is not performed only for inter-company communication despite using a conversion table as in Example-1 above. Furthermore, despite not performing ICS encapsulation in inter-company communication, with intra-company communication (Example-1), virtual leased line connection (Example-2), and ICS network server using ICS special number address. It will be described that communication (Examples-3, 3A) can be realized in the same manner as described in Examples -1, -2, -3, -3A, respectively.
First, an example of how to determine the ICS user address (in the case of 32-bit length, the address is from address 0 to 232-1) in this embodiment will be described. ICS user addresses are classified into intra-company communication addresses, inter-company communication addresses, ICS special number addresses, and ICS operating addresses. As the in-house communication address, the above-mentioned address unique to the user is adopted. For the inter-company communication address, the range from 0 to (215-1) of the VAN internal code (16-bit: 0 to (216-1)) that does not overlap with the intra-company communication address is assigned. For the ICS special number address, the range from 215 to (215 + 214-1) of the VAN internal code (16 bits) that does not overlap with the corporate communication address is assigned. For the ICS operating address, the range from address (215 + 214) to address (216-1) of the VAN internal code (16 bits) that does not overlap with the corporate communication address is assigned. The ICS operation address is used for ICS operation (for example, it is used for communication for exchanging failure information inside VAN).
In FIGS. 47 and 48, 15170-1, 15170-2, 15170-3, 15170-4, 15170-5, and 15170-6 are LAN15100-1, 15100-2, 15100-3, 15100-4, and 15100, respectively. -5, 15100-6 are gateways provided inside, and ICS frames can pass through these gateways 15170-1 to 15170-6.
<< Common preparation >> The conversion table 15113-1 included in the access control device 15110-1 includes the outgoing ICS network address, the incoming ICS network address, the recipient ICS user address, the request identification, and the speed classification. The request identification described in the conversion table 15113-1 is represented by, for example, "1" for the corporate communication service, "3" for the virtual leased line connection, and "4" for the ICS network server connection. The speed classification includes the speed and throughput of the line required for communication from the ICS network address (for example, the number of ICS frames transferred within a certain time).
<< Preparation for inter-company communication >> The terminal that performs business-to-business communication inside LAN15100-1 of company X holds the ICS user address "7711". In this embodiment, the ICS user address for inter-company communication uses the same value as the ICS network address. The ICS address information for inter-company communication is not written in the conversion table 15113-1. Similarly, the terminal that performs inter-company communication inside LAN15100-3 of company Y holds the ICS user address "8822".
<< Preparation for intra-company communication >> LAN15100-1 and LAN15100-2 users specify terminals to VAN operators so that in-house communication between terminals connected to each LAN can be performed via VAN-1 and VAN-3. And apply. The ICS network address of the logical communication line 15180-1 connected to the ICS logical terminal of the access control device 15110-1 is set to "7711". The in-house communication addresses of the terminals connected to the LAN15100-1 for which the application was made are set to "0012" and "0025", and the in-house communication addresses of the destinations to communicate from these terminals are "0034", "0036", and "". Suppose that it is "0045" and "0046".
The terminal with the corporate communication addresses "0034" and "0036" is inside LAN15100-2, and the ICS network address assigned to the ICS logical terminal of the access control device 15110-5 is "9922". The terminal with the corporate communication addresses "0045" and "0046" is inside LAN15100-6, and the ICS network address assigned to the ICS logical terminal of the access control device 15110-4 is "8900". The value "1" indicating the in-house communication service for which the application has been made is used as the request identification, and the above is registered in the conversion table 15113-1. The access control devices 15110-4 and 15110-5 are also registered in their respective conversion tables for intra-company communication in the same manner as above. Also, write the contents of the conversion table created by the above method to the ICS address management server 15150-1.
<< Preparation for virtual leased line connection >> The principle is the same as that of the second embodiment, which will be described below. LAN15100-5 is connected to the access control device 15110-1 via the user logical communication line 15180-5, and is given the ICS network address "7712". LAN15110-4 is connected to the access control device 15110-2 via the user logical communication line 15180-4, and is given the ICS network address "6611". Since the virtual dedicated line is connected from the user logical communication line 15180-5 to the user logical communication line 15180-4, these ICS network addresses "7712" and "6611" are shown in the conversion table 15113-1 inside the access control device 15110-1. And the request identification "3" are registered. For the same purpose, these ICS network addresses "6611" and "7712" are also registered in the conversion table inside the access control device 15110-2.
<< Preparation for communication with ICS network server using ICS special number >> If the ICS user address of the ICS network server 15330-1 connected to the access control device 15110-1 is "2000" and the ICS network address is "7721", register each address and request identification "4" in the conversion table. Keep it.
Hereinafter, description will be made with reference to the flowchart of FIG. 49.
<< Business-to-business communication >> Explain inter-company communication without ICS encapsulation. In other words, it is "business-to-business communication" between the terminal having the ICS user address "7711" on LAN15100-1 and the terminal having the ICS user address "8822" on LAN15100-3.
The terminal having the address "7711" of LAN15100-1 sends out the ICS user frame F1 in which the sender ICS user address "7711" and the receiver ICS user address "8822" are set respectively. The ICS user frame F1 reaches the ICS logical terminal of the access control device 15110-1 via the user logical communication line 15180-1. The access control device 15110-1 checks whether the ICS network address 7711 assigned to the ICS logical terminal is registered as a virtual leased line connection (3) on the conversion table 15113-1. (Step S1501), since it is not registered in this case, then check whether the recipient ICS network address 8822 in the ICS user frame F1 is registered in the conversion table 15113-1 (step S1503). In this case, since it is not registered, it is next determined whether the recipient network address 8822 in the ICS user frame F1 is in the section of the inter-company communication address (step S1504).
If the ICS user frame F1 can be determined to be inter-company communication by the above procedure, processing such as billing for inter-company communication is performed (step S1505). The access control device 15110-1 transmits the ICS user frame F1 to the relay device 15120-1 without performing ICS encapsulation (step S1525). The relay device 15120-1 transfers the ICS user frame to the access control device 15110-4 of VAN-2 via the relay devices 15120-2 and 15120-3 based on the incoming ICS network address. Access control device 15110-4 transfers to LAN 15110-3. The ICS user frame is routineized in LAN15110-3 and delivered to the terminal with the ICS user address "8822".
<< Corporate communication >> Explain that in-house communication with ICS encapsulation can be realized despite non-ICS encapsulation of inter-company communication. The ICS user frame P1 is sent for communication between the terminal having the ICS user address "0012" connected to LAN15100-1 and the terminal having the ICS user address "0034" connected to LAN15100-2. In this ICS user frame P1, "0012" is set for the sender ICS user address and "0034" is set for the receiver ICS user address. The ICS user frame P1 is transmitted through the user logical communication line 15180-1 and further transferred to the access control device 15110-1. The access control device 15110-1 checks whether the ICS network address "7711" assigned to the ICS logical terminal is registered as a virtual leased line connection ("3") on the conversion table 15113-1. (Step S1501), since it is not registered in this case, then check whether the recipient network address 0034" in the ICS user frame P1 is registered in the conversion table 15113-1 (step S1503). In the case of this embodiment, "0034" is registered, and the request identification is read as "1" for intra-company communication (step S1510). Therefore, the incoming ICS network corresponding to the outgoing ICS network address "7711" from the conversion table. Acquire the address "9922" and perform processing such as billing for inter-company communication (step S1511). The above procedure is also shown in the flowchart of FIG.
The access control device 15110-1 uses the obtained outgoing ICS network address 7711 and the incoming ICS network address 9922 to add a network control unit and encapsulate it in ICS (step S1520), and ICS network frame P2. Is configured and transmitted to the relay device 15120-1 (step S1525).
<< Communication by virtual leased line >> Explain that communication by virtual leased line that performs ICS encapsulation can be realized despite non-ICS encapsulation of inter-company communication.
LAN15100-5 sends an ICS user frame to ICS15100 through the user logical communication line 15180-5. The access control device 15110-1 that received the ICS user frame from the ICS logical terminal of the ICS network address "7712" has the ICS network address "7712" assigned to the ICS logical terminal, and the request type is on the conversion table 15113-1. Check if it is registered as a virtual leased line connection (3) (step S1501). In this case, since it is registered, it can be confirmed that the incoming ICS network address is a virtual leased line connection of "6611", and processing such as billing is performed (step S1502). The access control device 15110-1 adds a network control unit in which the incoming ICS network address is set to "6611" and the outgoing ICS network address is set to "7711" to the received ICS user frame, and the ICS network frame is encapsulated in ICS. Is created (step S1520) and transmitted to the relay device 15120-1 (step S1525).
<< Communication with ICS network server using ICS special number >> Explain that it is possible to communicate with the ICS network server that performs ICS encapsulation despite the non-ICS encapsulation of inter-company communication. That is, it is explained that the terminal (address 0012) connected to the LAN 15100-1 of the company X can communicate with the ICS network server 15330-1 connected to the access control device 15110-1.
The terminal of the sender ICS user address "0012" of LAN15100-1 sends the ICS user frame G1 to the access control device 15110-1, and the receiver ICS user address is "2000" to the ICS network server 15330-1. Request communication. The access control device 15110-1 checks whether the ICS network address 7711 assigned to the ICS logical terminal is registered as a virtual leased line connection (3) on the conversion table 15113-1. (Step S1501), since it is not registered in this case, then check whether the recipient network address 2000 in the ICS user frame G1 is registered in the conversion table 15113-1 (steps S1503, S1510). In this case, the request identification in conversion table 15113-1 is read as communication with the ICS network server 15330-1 (4) (step S1512). Next, the ICS network address 7721 of the ICS network server 15330-1 is acquired from the conversion table 15113-1, and processing such as billing is performed (step S1513). Next, the ICS user frame is converted into an ICS packet (step S1520) and transmitted to the ICS network server 15330-1 (step S1525).
Example-16 (Other Examples Using ATM Network): Another embodiment in which the network inside the ICS of the present invention is configured by using the ATM network will be described. In this embodiment, (1) supplementary explanation of the prior art regarding ATM, (2) explanation of components, (3) frame flow using SVC, (4) frame flow using PVC, (5) PVC 1 to N communication or N to 1 communication using, and (6) N to N communication using PVC will be described in this order. Since the embodiment described here mainly discloses the technique of address conversion between the ICS network frame and the ATM network, the intra-company communication service and the inter-company communication service described in the first embodiment, and the embodiment This embodiment can be applied to any of the virtual leased line services described in -2.
(1) Supplementary explanation of the prior art related to ATM: First, the prior art related to ATM necessary for explaining this embodiment will be supplementarily described. In an ATM network, a plurality of non-fixed logical lines that can flexibly set the communication speed and the like can be set on the physical line, and this logical line is called a virtual channel (VC). SVC (Swiched Virtual Channel) and PVC (Permanent Virtual Channel) are defined as virtual channels depending on how they are set. SVC calls and sets a virtual channel when necessary, and is required for the required time with any ATM terminal (generally a communication device that is connected to an ATM network and communicates using the ATM network). It is possible to secure a logical line having a speed of. The call setting of the virtual channel is performed by the ATM terminal that is about to start communication, and this method is standardized as a signaling method in ITU-T. The call setting is an address that identifies the ATM terminal to which the call is set (hereinafter referred to as the "ATM address"). Is required, and the ATM address is systematized so that each ATM terminal can be identified so that it is unique in the ATM network. This address system has E.164 specified in ITU-T Recommendation Q.931. There are three types of NSAP format ATM addresses, as shown in Figure 50, according to the 164 format or the ATM Forum UNI3.1 specification. In ICS, which of the above ATM address systems is used depends on the specific configuration of the ATM network. Therefore, the term ATM address will be used in this embodiment.
PVC is a semi-fixed call setting that can be regarded as a virtual leased line when viewed from an ATM terminal. For the established virtual channel, an ID that identifies the virtual channel (hereinafter referred to as "virtual channel ID") is assigned to both SVC and PVC. Specifically, the virtual channel ID is composed of VPI (Virtual Path Identifier) and VCI (Virtual Channel Identifier) in the cell header part of the ATM cell format (53 bytes) shown in FIG. 51. To.
Since information communication within the ATM network is performed in the ATM cell format information unit shown in FIG. 51, it is necessary to convert the ICS network frame into an ATM cell in order to transfer the ICS network frame via the ATM network. This conversion is performed through a two-step process of conversion to a CPCS (Common Part Convergence Sublayer) frame shown in FIG. 52 and decomposition of the CPCS frame into an ATM cell shown in FIG. 53. When a communication frame is divided into ATM cells, it usually becomes a plurality of ATM cells. Therefore, a series of multiple ATM cells related to one communication frame is called an ATM cell series. When an ATM cell sequence is received, the conversion is inversely performed, and there are two steps: assembling the ATM cell sequence shown in Fig. 53 into a CPCS frame, and extracting and restoring the communication frame (ICS network frame) from the CPCS frame shown in Fig. 52. Processing is done. This conversion to CPCS frame and disassembly / assembly of ATM cells are known techniques and standardized techniques in accordance with ITU-T recommendations. The protocol header in the CPCS frame user information is standardized by the IETF RFC1483.
(2) Explanation of components: In FIGS. 54 and 55, focusing on the ATM network 1042 from FIG. 35 in FIGS. 34 to 36, the conversion unit 1033-1 inside the ATM exchange 10133-1 and the conversion unit 1033 inside the ATM exchange 10133-2. It corresponds to the description of the internal structure of -2 and the simplified description of the access control devices 1010-2 and 1010-1 shown in FIGS. 34 to 36. In this embodiment, the internal configuration of the access control device or the operation of the processing device in the access control device is the same as the content described in the first embodiment and the basic principle.
The access control device 1010-5 in FIG. 54 is assigned ICS network addresses 7711 and 7722 as connection points (ICS logical terminals) of companies X and A who are users of ICS905, respectively. Similarly, the access control device 1010-7 is assigned the ICS network addresses "7733" and "7744" as connection points of the companies W and C, respectively. In Fig. 55, the access control device 1010-6 is similarly assigned the ICS network addresses "9922" and "9933" as the connection points of the companies Y and B, respectively, and the access control device 1010-8 is also the company. ICS network addresses "9944" and "9955" are assigned as connection points for Z and D, respectively. Here, in the example of the ATM network, the company X, the company Y, etc. used as examples of the users may be different bases of the same company that performs intra-company communication, or different companies that perform inter-company communication. It doesn't matter.
The interface unit 1133-5 is provided in the conversion unit 1033-5 inside the ATM exchange 10133-5, and the interface unit 1133-5 is connected to the communication line connecting the access control device 1010-5 and the ATM exchange 10133-5. It is in charge of the process of aligning the interfaces (physical layer, data link layer protocol) of. In addition to the processing device 1233-5, the conversion unit 1033-5 also translates the ATM address conversion table 1533-5 for call setting by SVC and the ICS network address used for both SVC and PVC into a virtual channel. It is composed of VC address translation table 1433-5. The ATM exchange 10133-5 is an ATM address management server 1633-5 as an information processing device that stores an ATM address conversion table, and an information processing device that stores a VC address conversion table in the case of using PVC. It connects to the PVC address management server 1733-5 and processes information related to address translation. The components related to the ATM switchboard 10133-6 are the same as those described for the ATM switchboard 10133-5. In FIGS. 54 and 55, the access control device 1010-5 is connected to the ATM switch 10133-5 via the communication line 1810-5, and the access control device 1010-7 is connected to the ATM switch 10133-5 via the communication line 1810-7, respectively. The access control device 1010-6 is connected to the ATM switch 10133-6 via the communication line 1810-6, and the access control device 1010-8 is connected to the ATM switch 10133-6 via the communication line 1810-8. The ATM switchboard 10133-5 has the only ATM address "3977" in the network set in the internal conversion unit 1033-5, and the ATM switchboard 10133-6 has the network in the internal conversion unit 1033-6. The only ATM address "3999" is set. The ATM switchboard 10133-5 and the ATM switchboard 10133-6 are connected via the ATM switchboard 10133-7 in this embodiment.
(3) Frame flow using SVC: An example in which SVC is applied as a communication path in an ATM network will be described with reference to FIGS. 54 and 55, taking as an example an ICS user frame emitted from a terminal of company X to a terminal of company Y.
<< Preparation >> ATM address translation In Table 1533-5, the incoming ICS network address indicating the destination of the ICS network frame, the incoming ATM address indicating the destination for calling the virtual channel in the ATM network, and the virtual channel are requested. Register the channel performance such as the communication speed. Also, make the same registration for ATM address translation table 1533-6. As an example, the value set in the ATM address conversion table 1533-5 is the ICS network address assigned to the ICS logical terminal of the access control device 1010-6 as the incoming ICS network address and the communication address with the company Y. Set "9922" and register the only ATM address "3999" assigned in the ATM network to the conversion unit 1033-6 as the incoming ATM address. As the channel performance, a communication speed of 64 Kbps is set in this embodiment. ATM address translation The contents registered in Table 1533-5 are also written and stored in the ATM address management server 1633-5.
As the value to be set in the ATM address conversion table 1533-6, the ICS network address "7711" assigned to the ICS logical terminal of the access control device 1010-5 is set as the incoming ICS network address for communication with the company X. Then, as the incoming ATM address, the ATM address "3977" assigned only in the ATM network is registered for the conversion unit 1033-5 inside the ATM exchange 10133-5 to which the access control device 1010-5 is connected. For the channel performance, a communication speed of 64 Kbps is set in this embodiment. The contents registered in the ATM address conversion table 1533-6 are also written and stored in the ATM address management server 1633-6.
<< ICS network frame transfer from access control unit >> As described in the first embodiment, the ICS user frame emitted from the terminal of the company X to the terminal of the company Y connected to the access control device 1010-6 via the access control device 1010-5 is accessed. It is ICS-encapsulated when passing through the control device 1010-5, and becomes the ICS network frame F1 having the outgoing ICS network address "7711" and the incoming ICS network address "9922" in the ICS frame header. The ICS network frame F1 is transmitted from the access control device 1010-5 to the ATM switch 10133-5 and reaches the conversion unit 1033-5. Hereinafter, description will be made with reference to the flowchart of FIG. 56.
<< Get Virtual Channel ID >> When the converter 1033-5 receives the ICS network frame F1 (step S1601), it receives the outgoing ICS network address 7711 inside the ICS frame header in order to correctly transfer the received frame F1 to the ATM switch 10133-5. It is necessary to find the virtual channel ID of the SVC virtual channel determined by the correspondence with the ICS network address "9922". In the case of SVC-based communication, the virtual channel corresponding to this channel may or may not be established at the time of receiving the ICS network frame. The processor 1233-5 first knows if a virtual channel has been established, so the outgoing ICS network address It was searched whether the virtual channel corresponding to the pair of "7711" and the incoming ICS network address "9922" was registered in the VC address translation table 1433-5 (step S1602), and it was registered here. Know that the virtual channel you want is established. That is, from the VC address translation table 1433-5, it is acquired that the virtual channel ID corresponding to the pair of the outgoing ICS network address "7711" and the incoming ICS network address "9922" is "33", and at the same time, it is acquired. From the value "11" of the channel type to be performed, it is known that this virtual channel is communication based on SVC. If there is no registration on the VC address translation table 1433-5, establish the desired virtual channel by performing << call setting >> described later, and register it on the VC address translation table 1433-5 at that time. Obtain the virtual channel ID from the information provided (step S1603).
<< Call settings >> In the above explanation, "when the virtual channel ID corresponding to the communication path determined by the correspondence between the outgoing ICS network address and the incoming ICS network address is not registered in the VC address translation table 1433-5", that is, in this communication path. If the corresponding virtual channel has not been established yet, it is necessary to establish the virtual channel in the ATM network that constitutes ICS905 by performing the call setting described below, and an operation example of this call setting will be described.
The processing device 1233-5 of the conversion unit 1033-5 refers to the VC address conversion table 1433-5 and sets the outgoing ICS network address 7711 and the incoming ICS network address 9922 inside the header of the ICS network frame F1. When it is found that the virtual channel ID corresponding to the pair is not registered (step S1602), refer to the ATM address translation table 1533-5, and the ATM address translation table 1533-5 that matches the incoming ICS network address 9922. Incoming ICS network address registered in Find "9922" and obtain the corresponding incoming ATM address "3999" and the corresponding incoming ATM address "64K" (step S1605). The processor 1233-5 uses the acquired incoming ATM address "3999". The ATM switch 10133-5 is requested to set the call, and at this time, the channel performance such as the communication speed of the virtual channel acquired at the same time from the ATM address translation table 1533-5 is also requested. The ATM switch 10133-5 requests the call setting. When the setting request is received, a virtual channel is established in the ATM exchange network from the ATM exchange 10133-5 to the ATM exchange 10133-6 by using the signal method that is standard equipment in the ATM exchange itself (step S1606). The virtual channel ID assigned to identify the virtual channel is notified from the ATM switch to the conversion units 1033-5 and 1033-6 that are inside each, but if it is based on the provisions of the signal system of the prior art, it will be issued. The value notified from the calling ATM exchange 10133-5 (for example, 33) and the value notified from the calling ATM exchange 10133-6 (for example, 44) are not necessarily the same value. No. In the conversion unit 1033-5, the virtual channel ID 33 notified from the ATM switch 10133-5 is sent to the VC address together with the outgoing ICS network address 7711 and the incoming ICS network address 9922 of the ICS network frame F1. Registered in conversion table 1433-5 (step S1607) and retained on VC address translation table 1433-5 while this virtual channel connection is established. -5 requests the ATM switch 10133-5 to release the call of the virtual channel, and at the same time, deletes the registration corresponding to the virtual channel ID 33 from the VC address translation table 1433-5. Registration in the VC address translation table 1433-6 will be described later.
<< Send frame >> The processing device 1233-5 of the conversion unit 1033-5 illustrates the ICS network frame F1 received from the access control device 1010-5 for the virtual channel (virtual channel ID 33) established according to the explanation so far. It is converted into the CPCS frame shown in 52, further disassembled into the ATM cells shown in FIG. 53, and transferred to the relay ATM switch 10133-7 (step S1604).
<< Transfer ATM cells >> The ATM cell sequence S1 consisting of a plurality of cells obtained by converting the ICS network frame F1 by the method described above is transferred from the ATM switch 10133-5 to the relay ATM switch 10133-5, and further becomes an ATM as the ATM cell sequence S2. Transferred to exchange 10133-6. Hereinafter, description will be made with reference to the flowchart of FIG. 57.
<< Behavior after reaching the frame >> When the ATM cell series S2 reaches the ATM exchange 10133-6 (step S1610), the ATM cell series S2 is transferred from the ATM exchange 10133-6 to the conversion unit 1033-6. The conversion unit 1033-6 assembles the received ATM cell into a CPCS frame as shown in FIG. 53, and further restores the ICS network frame from the CPCS frame as shown in FIG. 52 (step S1611). In Fig. 55, the restored ICS network frame is shown as ICS network frame F2, but the frame contents are the same as ICS network frame F1. The ICS network frame F2 is transferred to the access control device identified by the incoming ICS network address "9922" in the frame header, that is, the access control device 1010-6 having an ICS logical terminal assigned the ICS network address "9922". Is done (step S1612).
At this time, in the conversion unit 1033-6, the outgoing ICS network address 7711 of the ICS network frame F2, the incoming ICS network address 9922, and the channel type 11 indicating that the SVC is known at the time of incoming call. And the virtual channel ID 44 assigned when the call of the SVC virtual channel was set are registered in the VC address conversion table 1433-6 (step S1614). At this time, the outgoing ICS of the ICS network frame F2 The network address "7711" is converted to the incoming ICS network address in VC address conversion table 1433-6, and the incoming ICS network address "9922" in ICS network frame F2 is converted to the outgoing ICS network address in table 1433-6. Write in. However, at the time of this registration, if the same content as the one to be registered is already registered in the VC address translation table 1433-6, the registration will not be performed. The address translation information registered in VC address translation table 1433-6 is used in VC address translation table 1433- while the connection of the virtual channel with the corresponding virtual channel (virtual channel ID 44 in this example) is maintained. 6 Holds on (step S1613).
<< Reverse flow of frame >> Next, the reverse flow of the ICS frame, that is, the case of flowing from the company Y to the company X, is shown in FIGS. 54 and 55 under the assumption that the virtual channel of the SVC is set as described above. It will be explained with reference to. The ICS user frame issued from company Y to company X has the outgoing ICS network address "9922" and the incoming ICS network address "7711" in the header part at the stage of passing through the access control device 1010-6. Is converted to, and processing is performed according to the flow of FIG. 56 described above by the processing device 1233-6 of the conversion unit 1033-6 inside the ATM exchange 10133-6.
In this case, the VC address translation table 1433-6 of the conversion unit 1033-6 shows the outgoing ICS network address 9922 and the incoming ICS network address 7711 as already explained in << Operation after reaching the frame >>. Since the virtual channel ID 44 corresponding to is registered as the channel type 11, that is, as an SVC, it operates according to the flow of (1) in FIG. 56, and the ICS is applied to the virtual channel ID 44. Network frame F3 in multiple ATM cells (ATM series S3) Convert to and transfer. The ATM cell series S3 is relayed and transferred to the relay ATM switch 10133-5, becomes the ATM cell series S4, reaches the ATM switch 10133-5, and has a virtual channel ID "33" in its conversion unit 1033-6. Received through and restored as an ICS network frame F4 with the same content as the ICS network frame F3. In the conversion unit 1033-5, the pair of the outgoing ICS network address 9922 and the incoming ICS network address 7711 held in the header of the ICS network frame F4 reverses the arrival and departure, and is shown in the VC address translation table 1433-5. Since it has already been registered, it is not registered in the VC address translation table, and the ICS network frame F4 is transferred to the access control device 1010-5.
<< Application example for half-duplex communication >> In the above, one SVC virtual is used when the internal network of ICS905 is configured by the ATM network and the ICS frame is transferred from company X to company Y and in the opposite direction from company Y to company X. It was explained that it is carried out using a channel. This transfer and reverse transfer are, for example, a request frame (transfer) from the client terminal of company X connecting to ICS to the server terminal of company Y connecting to ICS, and a client of company X from the server terminal of company Y to this request frame. When applied to a response frame (reverse transfer) to a terminal, only one-way communication is performed at one time, but it is an application example of half-duplex communication that realizes two-way communication by switching the communication direction for each time zone.
<< Application example for full-duplex communication >> The virtual channel itself set in the ATM network is capable of full-duplex communication, that is, bidirectional communication at the same time, according to the ATM rules. Transfer and reverse transfer using one SVC virtual channel in the ATM network, for example, request frames (transfers) from multiple client terminals of company X connecting to ICS to multiple server terminals of company Y connecting to ICS. , When applied to the response frame (reverse transfer) from the multiple server terminals of company Y to the multiple client terminals of company X for this request frame, the frames between the client terminal and the server terminal are transferred asynchronously, respectively. Therefore, bidirectional communication is simultaneously performed on one SVC virtual channel that serves as a communication path, and this is an application example of full-duplex communication.
(4) Frame flow using PVC: As shown in FIGS. 54 and 55, an example in which the internal network of ICS905 is composed of an ATM network and PVC is applied as a communication path in the ATM network is issued from the terminal of company W to the terminal of company Z. The ICS user frame will be described as an example.
<< Preparation >> VC address conversion in conversion unit 1033-5 In table 1433-5, the outgoing ICS network address, incoming ICS network address, and ATM network (pointing to the communication path between ATM switch 10133-5 and ATM switch 10133-6). ) Is fixedly set to the virtual channel ID of the PVC and the channel type indicating that the virtual channel ID is PVC is registered. Unlike the case of SVC, this registration is registered in the VC address translation table 1433-5 at the same time when the PVC virtual channel is set in the ATM switch (10133-5, 10133-7, 10133-6) that is the communication path, and communication is performed. Hold the path fixedly for the required period, i.e., until the PVC virtual channel is unconfigured. It is also registered and retained in the VC address translation table 1433-6 in the same way. The virtual channel ID of PVC is assigned to each ATM switch when the PVC is set to be fixedly connected between the ATM switches.
The value set in the VC address conversion table 1433-5 is the communication address with the company W as the outgoing ICS network address, that is, the ICS network address "7733" assigned to the ICS logical terminal of the access control device 1010-7. Is set, and the communication address with the company Z, that is, the ICS network address "9944" assigned to the ICS logical terminal of the access control device 1010-8 is set as the incoming ICS network address. Further, the PVC virtual channel ID 55 assigned to the ATM switch 10133-5 is set as the virtual channel ID, and the value 22 indicating PVC is set as the channel type. In addition, the settings registered in the VC address translation table 1433-5 are also written and saved in the PVC address management server 1733-5.
Similarly, in the VC address conversion table 1433-6 in the conversion unit 1033-6 inside the ATM exchange 10133-6, make the same settings by reversing the outgoing ICS network address and the incoming ICS network address. .. In this case, even if the same PVC is shown, the virtual channel ID may have a different value from the VC address translation table 1433-5. At this time, the settings registered in the VC address translation table 1433-6 are also written and saved in the PVC address management server 1733-6.
The value set in the VC address conversion table 1433-6 is the communication address with the company Z as the outgoing ICS network address, that is, the ICS network address "9944" assigned to the ICS logical terminal of the access controller 1010-8. Is set, and the communication address with the company W, that is, the ICS network address "7733" assigned to the ICS logical terminal of the access control device 1010-7 is set as the incoming ICS network address. Further, the virtual channel ID is set to "66", which is the ID of this PVC virtual channel assigned to the ATM exchange 10133-6, and the channel type is set to the value "22" indicating PVC.
<< ICS network frame transfer from access control unit >> The ICS user frame issued from the terminal of company W to the terminal of company Z connected to the access control device 1010-5 via the access control device 1010-7 is sent when passing through the access control device 1010-7. The ICS is encapsulated and becomes the ICS network frame F5 having the outgoing ICS network address "7733" and the incoming ICS network address "9944" in the ICS frame header. The ICS network frame F5 is transmitted from the access control device 1010-7 to the ATM switch 10133-5, and reaches the conversion unit 1033-5 via the interface unit 1133-5.
<< Get Virtual Channel ID >> The processing device 1233-5 uses the outgoing ICS network address 7733 and the incoming ICS network address 9944 in the header of the received ICS network frame F5 to refer to the VC address conversion table 1433-5, and this conversion unit. Between 1033-5 and the conversion unit 1033-6 inside the ATM switch 10133-6 to which the access control device 1010-8 whose connection point is the ICS logical terminal to which the incoming ICS network address "9944" is assigned is connected. On the other hand, the virtual channel ID that identifies the set virtual channel is acquired as "55". At the same time, it is known that this virtual channel is PVC from the acquired channel type value "22".
<< Send frame >> The processing device 1233-5 converts the ICS network frame F5 received from the access control device 1010-7 into an ATM cell series for the PVC virtual channel 55 acquired in accordance with the above, and transmits the ICS network frame F5 to the ATM switch 10133-7. The method of this ATM cell conversion is the same as that described in the SVC example. The processing procedure of the above conversion unit 1033-5 is as shown in Fig. 56, and in PVC, the flow is always (1).
<< Transfer ATM cells >> The ATM cell series S1 consisting of multiple cells obtained by converting the ICS network frame F1 is transferred from the ATM exchange 10133-5 to the relay ATM exchange 10133-7, and further transferred to the ATM exchange 10133-6 as the ATM cell series S2. It is transferred, but this behavior is similar to that for SVC.
<< Behavior after reaching the frame >> When the ATM cell series S2 reaches the ATM exchange 10133-6, the ATM cell series S2 is transferred from the ATM exchange 10133-6 to the internal conversion unit 1033-6 of the ATM exchange 10133-6. The converter 1033-6 restores the ICS network frame from the received ATM cell sequence, but this operation is the same as for SVC. The restored ICS network frame is described as ICS network frame F6 in Fig. 55, but the frame contents are the same as ICS network frame F5. The ICS network frame F6 is transferred to the access control device identified by the incoming ICS network address "9944" in the header, that is, the access control device 1010-8 having an ICS logical terminal assigned the ICS network address "9944". To. The processing procedure of the above conversion unit 1033-6 is as shown in Fig. 57, and in PVC, the flow is always (1).
<< Reverse flow of frame >> Next, the reverse flow of the ICS frame, that is, the case of flowing from the company Z to the company W will be described with reference to FIGS. 54 and 55, using the PVC virtual channel as a communication path. The ICS user frame issued from company Z to company W has the outgoing ICS network address "9944" and the incoming ICS network address "7733" in the header part at the stage of passing through the access control device 1010-8. The processing device 1233-6 of the conversion unit 1033-6, which is encapsulated in ICS and installed inside the ATM switch 10133-6, performs processing according to the flow shown in FIG. 56. In this case, since the virtual channel ID 66 corresponding to the outgoing ICS network address 9944 and the incoming ICS network address 7733 is registered in the VC address translation table 1433-6 of the conversion unit 1033-6, Converts the ICS network frame F7 to multiple ATM cell series and sends it to the virtual channel ID "66".
The ATM cell sequence transferred in the ATM network reaches the conversion unit 1033-5 of the ATM switch 10133-5, then is received from the virtual channel with the virtual channel ID "55", and has the same contents as the ICS network frame F7. Restored as ICS network frame F8 with. However, in the conversion unit 1033-5, the pair of the outgoing ICS network address "9944" and the incoming ICS network address "7733" held in the header of the ICS network frame F8 has already been reversed in the arrival and departure of the VC address conversion table 1433. Since it has been registered in -5 and the virtual channel ID "55" for this incoming / outgoing address pair is obtained as PVC from the channel type value "22", the registration process is not performed and the ICS network frame F8 is accessed by the access control device. Transfer to 1010-7.
<< Application example for half-duplex communication >> As described above, the internal network of the ICS905 is configured using the ATM network, and an example of transferring ICS frames using PVC has been described. However, PVC and the above-mentioned SVC require that the virtual channel is fixedly set. There is no difference in the operation itself of transferring frames to the set virtual channel. Therefore, for the ICS of the present invention, the application example to the half-duplex communication using the PVC virtual channel of the ATM network is equivalent to the application example to the half-duplex communication using the SVC virtual channel.
<< Application example for full-duplex communication >> For the same reason as the application example for half-duplex communication, the application example for full-duplex communication of PVC is equivalent to the application example for full-duplex communication in SVC.
(5) 1-to-N communication or N-to-1 communication using PVC: In the above description, one virtual channel of PVC is used as a communication path connecting one company (base) and one company (base), that is, a communication path connecting one ICS logical terminal and one ICS logical terminal inside ICS. Although an embodiment is shown, it is possible to share one virtual channel of PVC as a communication path between one ICS logical terminal and a plurality of ICS logical terminals. An embodiment of such 1-to-N communication or N-to-I communication will be described with reference to FIG. 58.
<< Explanation of components >> In FIG. 58, the access control device 1010-10 is connected to the ATM switch 10133-10 by the company X using the ICS logical terminal assigned the ICS network address 7711 in the access control device 1010-10 as a connection point. The other party to be connected from company X is company A to D, company A uses the ICS logical terminal assigned the ICS network address "9922" in the access control device 1010-20 as the connection point, and company B uses the access control device. The connection point is the ICS logical terminal assigned the ICS network address "9923" in 1010-20. Similarly, Company C uses the ICS logical terminal assigned the ICS network address 9944 in the access control device 1010-40 as the connection point, and Company D uses the ICS network address 9955 in the access control device 1010-40 as the connection point. The assigned ICS logical terminal is used as the connection point. The access control devices 1010-20 and 1010-40 are connected to the ATM switch 10133-20, and the ATM switch 10133-10 and the ATM switch 10133-20 are connected via a relay network.
<< Preparation >> For ATM exchanges 10133-10 and 10133-20, set one PVC virtual channel that connects the conversion unit 1033-10 inside the ATM exchange 10133-10 and the conversion unit 1033-20 inside the ATM exchange 10133-20. Then, the virtual channel ID given to the virtual channel conversion unit 1033-10 is "33", and the virtual channel ID given to the virtual channel conversion unit 1033-20 is "44". Register the VC address translation table 1433-1 in the conversion unit 1033-10 and the VC address translation table 1433-20 in the conversion unit 1033-20 as shown in Fig. 58.
<< 1-to-N communication frame flow >> The flow of frames for 1-to-N communication will be explained using frames transmitted from company X to companies A to D. For the ICS network frame having the outgoing ICS network address "7711" and the incoming ICS network address "9922" directed from the company X to the company A, refer to the VC address translation table 1433-10 in the conversion unit 1033-10. As a result, it is transmitted to the PVC virtual channel with the virtual channel ID 33. Similarly, an ICS network frame having an outgoing ICS network address 7711 directed from company X to company B and an incoming ICS network address 9933 is also transmitted to the PVC virtual channel with virtual channel ID 33. An ICS network frame with an outgoing ICS network address "7711" from company X to company C and an incoming ICS network address "9944", and an outgoing ICS network address "7711" from company X to company D. And the ICS network frame having the incoming ICS network address 9955 is also transmitted to the PVC virtual channel with the virtual channel ID 33. This indicates that 1-to-N (company X-to-company A to D) communication is performed by sharing one PVC virtual channel. The reverse flow of frames, that is, the case where frames are transferred from companies A to D to company X, will be described in the next section.
<< N to 1 communication frame flow >> The flow of frames for N-to-1 communication will be explained using frames transmitted from companies A to D to company X. For the ICS network frame having the outgoing ICS network address "9922" and the incoming ICS network address "7711" directed from the company A to the company X, refer to the VC address translation table 1433-20 at the conversion unit 1033-20. As a result, it is transmitted to the PVC virtual channel with the virtual channel ID 44. Similarly, an ICS network frame having an outgoing ICS network address 9933 directed from company B to company X and an incoming ICS network address 7711 is also transmitted to the PVC virtual channel with virtual channel ID 44. An ICS network frame with an outgoing ICS network address "9944" from company C to company X and an incoming ICS network address "7711", and an outgoing ICS network address "9955" from company D to company X. And the ICS network frame having the incoming ICS network address 7711 is also transmitted to the PVC virtual channel with the virtual channel ID 44. This indicates that N-to-1 (company A to D-to-company X) communication is performed by sharing one PVC virtual channel.
(6) N-to-N communication using PVC: By the same method as 1-to-N communication, one virtual channel of PVC can be shared as a communication path between multiple ICS logical terminals and multiple ICS logical terminals. An embodiment of N-to-N communication will be described with reference to FIG. 59.
<< Explanation of components >> Company X uses the ICS logical terminal address 7711 of access control device 1010-11 as a connection point, and company Y uses the ICS logical terminal address 7722 of access control device 1010-11 as a connection point, and access control device 1010-11. Is connected to ATM switch 10133-11. The other party to be connected from company X or company Y is company A or company C, company A uses the ICS logical terminal address "9922" of access control device 1010-21 as a connection point, and company C is access control device 1010-. The connection point is the ICS logical terminal address 9944 of 41. The access control devices 1010-21 and 1010-4 are connected to the ATM switchboard 10133-21, and the ATM switchboards 10133-11 and 10133-21 are connected via a relay network.
<< Preparation >> For ATM exchanges 10133-11 and 10133-21, set one PVC virtual channel to connect the conversion unit 1033-11 inside the ATM exchange 10133-11 and the conversion unit 1033-21 inside the ATM exchange 10133-21. Then, the virtual channel ID given to the conversion unit 1033-11 of this virtual channel is set to "33", and the virtual channel ID given to the conversion unit 1033-21 of this virtual channel is set to "44". The VC address translation table 1433-11 in the conversion unit 1033-11 and the VC address translation table 1433-21 in the conversion unit 1033-21 are registered as shown in FIG. 59.
<< N to N communication frame flow >> The flow of frames for N-to-N communication will be explained first with the frames transmitted from company X to companies A and C, respectively. For the ICS network frame having the outgoing ICS network address "7711" and the incoming ICS network address "9922" directed from the company X to the company A, refer to the VC address translation table 1433-11 in the conversion unit 1033-1. , Sent to the PVC virtual channel with virtual channel ID 33. Similarly, an ICS network frame having an outgoing ICS network address 7711 and an incoming ICS network address 9944 directed from the company X to the company C is also transmitted to the PVC virtual channel with the virtual channel ID 33. Next, the frame transmitted from company Y to companies A and C will be described. For the ICS network frame having the outgoing ICS network address "7722" and the incoming ICS network address "9922" directed from the company Y to the company A, refer to the VC address translation table 1433-11 in the conversion unit 1033-11. , Sent to the PVC virtual channel with virtual channel ID 33. Similarly, the ICS network frame having the outgoing ICS network address 7722 and the incoming ICS network address 9944 directed from the company Y to the company C is also transmitted to the PVC virtual channel with the virtual channel ID 33.
Next, the flow in the reverse direction of the frame will be described with the frames transmitted from the company A to the companies X and Y, respectively. For the ICS network address having the outgoing ICS network address "9922" and the incoming ICS network address "7711" directed from the company A to the company X, refer to the VC address translation table 1433-21 in the conversion unit 1033-2. , Sent to the PVC virtual channel with virtual channel ID 44. For the ICS network frame having the outgoing ICS network address "9922" and the incoming ICS network address "7722" directed from the company A to the company Y, refer to the VC address translation table 1433-2 in the conversion unit 1033-2. , Sent to the PVC virtual channel with virtual channel ID 44. An ICS network frame having an outgoing ICS network address 9944 and an incoming ICS network address 7711 directed from company C to company X is transmitted to the PVC virtual channel with virtual channel ID 44. An ICS network frame with an outgoing ICS network address 9944 and an incoming ICS network address 7722 directed from Company C to Company Y is also transmitted to the PVC virtual channel with virtual channel ID 44. As a result, N-to-N communication is performed by sharing one PVC virtual channel.
Example-17 (Other Examples Using FR Network): Another embodiment in which the network inside the ICS of the present invention is configured by using the FR network will be described. In this embodiment, (1) supplementary explanation of the prior art regarding FR, (2) explanation of components, (3) frame flow using SVC, (4) frame flow using PVC (5) PVC The following will be described in the order of 1-to-N communication or N-to-1 communication used, and (6) N-to-N communication using PVC. In this embodiment, it is possible to use two types of methods using SVC or PVC, or to use both methods in a mixed manner, and each case using SVC or PVC will be described. .. Further, in order to realize the intra-company communication service and the inter-company communication service described in the first embodiment and the virtual leased line service described in the second embodiment by the access control device of the present invention, the network in the network inside the ICS is used. It is not necessary to consider the communication of the leased line separately, and in this embodiment, these communication services will be integrated and described.
(1) Supplementary explanation of the prior art regarding FR: The prior art relating to FR necessary for explaining the method of constructing the inside of the ICS of the present invention using the FR network will be supplementarily described.
A frame relay uses a variable-length communication information unit called a frame for communication, and by specifying a communication path for each frame, storage and exchange of frames in the network and logical multiplexing (one physical). This is a conventional technology standardized by the ITU.TI.233 recommendations, etc., which realized (a technology that multiplexes lines into multiple logical lines). A communication service using this technology is called a Frame Mode Bearer Service (hereinafter referred to as FMBS), and FMBS is a Frame Switch Bearer Service that assumes a remote connection (SVC). : Hereafter referred to as FSBS) and Frame Relay Bearer on the premise of fixed connection (PVC) Service: Hereinafter referred to as "FRBS"). The term "frame relay" generally refers only to FRBS ("frame relay" in a narrow sense), but in the ICS of the present invention, "frame relay" refers to the entire FMBS including FSBS and FRBS. Used as a name ("frame relay" in a broad sense), especially when referring only to FSBS, it is called "frame relay using SVC", and especially when referring only to FRBS, it is called "frame relay using PVC". To do. Hereinafter, the frame relay (FMBS) in a broad sense defined above is abbreviated as FR, and the frame transferred by the FR network is particularly referred to as FR frame in order to distinguish it from the ICS frame.
In the FR network, a plurality of logical lines can be set on the physical line as described above, and this logical line is called a logical channel. In order to identify a logical channel, the identifier assigned to each FR terminal (generally a communication device connected to the FR network and communicating using the FR network) connected to both ends of the logical channel is assigned to a data link connection identifier (Data). Link Connection Identifier: Hereinafter referred to as DLCI). SVC and PVC are specified for the logical channel depending on how they are set. The SVC calls and sets the logical channel when necessary, and can take a logical line with any FR terminal for the required time and at the required speed. The call setting of the logical channel is performed by the FR terminal that is about to start communication, and this method is standardized as a signal method in ITU-T. In the call setting, the address that identifies the other party FR terminal that makes the call setting (Hereinafter referred to as "FR address") is required, and the FR address is systematized so as to be unique in the FR network so that each FR terminal can be identified. PVC has a fixed call setting for the FR exchange, and can be regarded as a virtual leased line when viewed from the FR terminal.
For the established logical channel, DLCI that identifies the logical channel is assigned to both SVC and PVC, and when forwarding FR frames, DLCI is set in the DLCI bit part of the FR frame address part shown in Fig. 60. To do. There are three types of rules for the FR frame address part format, and in Fig. 60, the 2-byte format address part is shown. The logical channel performance (channel performance) of the FR network is the committed information rate (Committed Information Rate), which is the information transfer rate guaranteed by the FR network under normal conditions (no congestion). ) Etc.
In order to transfer a communication frame such as an ICS network frame via the FR network, it is necessary to convert it into an FR frame as shown in Fig. 61. When the FR frame is received, the conversion is reversed, and as shown in Fig. 61, the communication frame (ICS network frame) is taken out from the FR frame and restored. This FR frame conversion is a standardized technology in accordance with ITU-T recommendations. In addition, the protocol header in the user data of FR frame is standardized by RFC1490 of IETF.
(2) Explanation of components: Of FIGS. 34 to 36, FIGS. 62 and 63 focus on the FR network 1041 from FIG. 35, and inside the conversion unit 1032-1 and the FR switch 10132-2 described inside the FR switch 10132-1. The internal structure of the converted unit 1032-2 described is described, and it corresponds to a simplified version of the access control devices 1010-2 and 1010-1 described in FIGS. 34 to 36. In the method of configuring the inside of the ICS using the FR network, the internal configuration of the access control device or the operation of the processing device in the access control device has the same basic principle as the content described in the first embodiment.
The access control device 1010-5 is assigned ICS network addresses "7711" and "7722" as connection points (ICS logical terminals) of companies X and A who are users of ICS925, respectively. Similarly, the access control devices 1010-7 are assigned ICS network addresses "7733" and "7744" as connection points for companies W and C, respectively. Similarly, the access control device 1010-6 is assigned the ICS network addresses "9922" and "9933" as the connection points of the companies Y and B, respectively, and the access control device 1010-8 is similarly assigned to the companies Z and D. ICS network addresses "9944" and "9955" are assigned as connection points, respectively. Here, in the examples of FIGS. 62 and 63, the company X, the company Y, etc. shown as examples of the users may be different bases of the same company that performs intra-company communication, or may be between companies. It can be a different company that communicates.
The conversion unit 1032-5 inside the FR exchange 10132-5 has an interface unit 1132-5, and the interface unit 1132-5 is a communication line 1812-5 that connects the access control device 1010-5 and the FR exchange 10132-5. Interface with communication line 1812-7 connecting access control device 1010-7 and FR switch 10132-5 (physical layer, data link layer protocol) Is in charge of the process of matching. In addition to the processing device 1232-5, the conversion unit 1032-5 also uses the FR address translation table 1532-5 for call setting by SVC and to translate the ICS network address used by both SVC and PVC into a logical channel. It is composed of DLC address translation table 1432-5 of. The FR exchange 10132-5 is an FR address management server 1632-5 as an information processing device that stores the FR address conversion table, and DLC as an information processing device that stores the DLC address conversion table in the case of using PVC. Connects to the address management server 1732-5 to perform processing related to address translation. The components related to FR exchange 10132-6 are the same as those for FR exchange 10132-5. In this embodiment, the access control device 1010-5 is connected to the FR switch 10132-5 via the communication line 1812-5, and the access control device 1010-7 is connected to the FR exchange 10132-5 via the communication line 1812-7, and the access control device 1010- 6 is connected to the FR switch 10132-6 via the communication line 1812-6, and the access control device 1010-8 is connected to the FR exchange 10132-6 via the communication line 1812-8. The FR exchange 10132-5 has the only FR address "2977" in the network set in the internal conversion unit 1032-5, and the FR exchange 10132-6 has the only FR address in the network 1032-6 in the internal conversion unit 1032-6. FR address "2999" is set. The FR exchanges 10132-5 and 10132-6 are connected via the FR relay network, but in this example, they are connected via the FR exchange 10132-7, which is a representative of the FR relay network.
(3) Frame flow using SVC: As shown in FIGS. 62 and 63, an example in which the network inside the ICS is composed of the FR network and SVC is applied as the communication path in the FR network is shown from the terminal in the company X to the terminal in the company Y. The emitted ICS user frame will be described as an example.
<< Preparation >> In the FR address conversion table 1532-5 in the conversion unit 1032-5 inside the FR exchange 10132-5, the incoming ICS network address indicating the destination of the ICS network frame to be transferred from the conversion unit 1032-5 to the FR network is displayed. , Register the incoming FR address indicating the other party to call and set the logical channel in the FR network, and the channel performance such as the authentication information speed required for the logical channel. In addition, the same registration is made for the FR address conversion table 1532-6 in the conversion unit 1032-6 inside the FR exchange 10132-6.
As an example, the values set in the FR address conversion table 1532-5 are the ICS network assigned to the ICS logical terminal of the access control device 1010-6 as the incoming ICS network address and the communication address with the company Y. The address "9922" is set, and as the incoming FR address, the FR address "only assigned in the FR network to the conversion unit 1032-6 inside the FR exchange 10132-6 to which the access control device 1010-6 is connected" 2999 is registered. For the channel performance, the certified information speed of 64 Kbps is set in this embodiment. The contents registered in the FR address conversion table 1532-5 are also written and saved in the FR address management server 1632-5.
The values set in the FR address conversion table 1532-6 are the ICS network address "7711" assigned to the ICS logical terminal of the access control device 1010-5 as the incoming ICS network address and the address for communication with the company X. Is set, and as the incoming FR address, the FR address 2977 that is uniquely assigned in the FR network to the conversion unit 1032-5 inside the FR exchange 10132-5 to which the access control device 1010-5 is connected is set. sign up. For the channel performance, the certified information speed of 64 Kbps is set in this embodiment. FR address conversion The contents registered in Table 15 32-6 are also written and saved in the FR address management server 1632-6.
<< ICS network frame transfer from access control unit >> The ICS user frame issued from the terminal of company X to the terminal of company Y connected to the access control device 1010-6 via the access control device 1010-5 is sent when passing through the access control device 1010-5. It is ICS-encapsulated and becomes the ICS network frame F1 that has the outgoing ICS network address "7711" and the incoming ICS network address "9922" inside the ICS frame header. The ICS network frame F1 is transmitted from the access control device 1010-5 to the FR switch 10132-5, and reaches the conversion unit 1032-5 via the interface unit 1132-5 that processes the electrical signal conversion / matching of the communication path. Hereinafter, description will be made with reference to the flowchart of FIG.
<< Obtaining DLCI >> When the converter 1032-5 receives the ICS network frame F1 (step S1701), the outgoing ICS network address 7711 inside the ICS frame header is used to transfer the frame to the FR switch 10132-5. It is necessary to find the DLCI of the SVC logical channel that realizes the FR network communication path inside the ICS925, which is determined by the correspondence between the and the incoming ICS network address "9922". In the case of SVC-based communication, the logical channel corresponding to this communication path may or may not be established at the time of receiving the ICS network frame. In order to know whether the logical channel is established, the processing device 1232-5 first finds the logical channel corresponding to the pair of the outgoing ICS network address 7711 and the incoming ICS network address 9922 in the DLC address translation table 1432-5. Search for registration in (step S1702), and if registration is made here, know that the desired logical channel has been established. That is, from the DLC address conversion table 1432-5, it is acquired that the DLCI corresponding to the pair of the outgoing ICS network address "7711" and the incoming ICS network address "9922" is "16", and it is also acquired at the same time. From the channel type value "10", it is known that this logical channel is communication based on SVC. If there is no registration on the DLC address translation table 1432-5, establish the desired logical channel by performing << call setting >> described later, and register it on the DLC address translation table 1432-5 at that point. Obtain the DLCI from the information provided (step S1703).
<< Call settings >> In the above, "when the DLCI corresponding to the communication path determined by the correspondence between the outgoing ICS network address and the incoming ICS network address is not registered in the DLC address translation table 1432-5", that is, the logic corresponding to the communication path. If the channel has not been established yet, it is necessary to perform the call setting described below and establish a logical channel in the FR network constituting the ICS925, and an operation example of this call setting will be described.
The processing device 1232-5 of the conversion unit 1032-5 refers to the DLC address conversion table 1432-5 and refers to the outgoing ICS network address 7711 and the incoming ICS network address 9922 inside the ICS frame header of the ICS network frame F1. When you find out that there is no DLCI registration corresponding to the pair with "", refer to FR address conversion table 1532-5, and the incoming call registered in FR address conversion table 1532-5 that matches the incoming ICS network address "9922". Find the ICS network address "9922" and get the corresponding incoming FR address "2999", the corresponding channel performance "64K", etc. (step S1705). As described in the << Preparation >> section above, the incoming FR address 2999 is connected to the access control device 1010-6 whose connection point is the ICS logical terminal to which the incoming ICS network address 9922 is assigned. This is the address set to be unique in the FR network for the conversion unit 1032-6 inside the FR exchange 10132-6 to be connected.
The processing device 1232-5 requests the FR exchange 10132-5 to set a call using the acquired incoming FR address 2999. At this time, the logical channel is certified simultaneously acquired from the FR address translation table 1532-5. It also requires channel performance such as information speed (step S1706). When the FR exchange 10132-5 receives the call setting request, it uses the signal system that is standard equipment on the FR exchange itself as standard technology, and enters the FR exchange network from the FR exchange 10132-5 to the FR exchange 10132-6. Establish a logical channel to connect the conversion unit 1032-5 and the conversion unit 1032-6. The DLCI assigned to identify the established logical channel is notified from the FR exchange to the conversion units 1032-5 and 1032-6 that are inside each, but if it is based on the provisions of the signal system of the prior art, it is emitted. The value notified from the calling FR exchange 10132-5 (for example, 16) and the value notified from the calling FR exchange 10132-6 (for example, 26) are not necessarily the same value. Absent. In the conversion unit 1032-5, the DLCI 16 notified from the FR exchange 10132-5 is sent to the DLC address conversion table 1432-5 together with the outgoing ICS network address 7711 and the incoming ICS network address 9922 of the ICS network frame F1. Register with (step S1707) and keep it on the DLC address translation table 1432-5 while the connection for this logical channel is established. When the logical channel connection is no longer required, the conversion unit 1032-5 requests the FR exchange 10132-5 to release the call of the logical channel, and at the same time, the registration corresponding to DLCI 16 is performed from the DLC address translation table 1432-5. Erase. The registration in the DLC address translation table 1432-6 in the conversion unit 1032-6 will be described later.
<< Send frame >> The processing device 1232-5 of the conversion unit 1032-5 shows the ICS network frame F1 received from the access control device 1010-5 for the logical channel (DLCI 16) established according to the above description in FIG. 61. Converted to FR frame and transferred to FR switch 10132-5 (step S1704).
<< Transfer of FR frame >> The FR frame S1 obtained by converting the ICS network frame F1 by the method described above is transferred from the FR exchange 10132-5 to the relay FR exchange 10132-5, and further from the FR exchange 10132-5 as the FR frame S2. Transferred to 10132-6. Hereinafter, description will be made with reference to the flowchart of FIG. 65.
<< Behavior after reaching the frame >> When the FR frame S2 reaches the FR switch 10132-6 (step S1710), this FR frame is transferred from the FR switch 10132-6 to the internal converter 1032-6 of the FR switch 10132-6. The conversion unit 1032-6 restores the ICS network frame from the FR frame as shown in Fig. 61 (step S1711). The restored ICS network frame is described as ICS network frame F2 in Fig. 63, but the frame contents are the same as ICS network frame F1. The ICS network frame F2 is attached to the access control device identified by the incoming ICS network address "9922" inside the ICS frame header, that is, the access control device 1010-6 having an ICS logical terminal assigned the ICS network address "9922". Transferred (step S1712).
At this time, in the conversion unit 1032-6, the outgoing ICS network address 7711 of the ICS network frame F2, the incoming ICS network address 9922, and the channel type 10 indicating that the SVC is known at the time of incoming call. And the DLCI 26 assigned when the call of the SVC logical channel was set are registered in the DLC address translation table 1432-6 (step S1714). At this time, the outgoing ICS network address 7711 of the ICS network frame F2 is converted to the incoming ICS network address in DLC address conversion table 1432-6, and the incoming ICS network address 9922 of the ICS network frame F2 is converted to the DLC address conversion table 1432-6. Write to the outgoing ICS network address in the opposite location. However, at the time of this registration, if the same content as the one to be registered is already registered in the DLC address translation table 1432-6, the registration will not be performed. The address translation information registered in the DLC address translation table 1432-6 is retained on the DLC address translation table 1432-6 while the connection of the corresponding logical channel (DLCI 26 in this example) is maintained. To.
<< Reverse flow of frame >> Next, the reverse flow of the ICS frame, that is, the case of flowing from the company Y to the company X, will be described in the same manner with reference to FIGS. 62 and 63 under the assumption that the logical channel of the SVC is set to call. To do.
The ICS user frame originating from company Y to company X is ICS-encapsulated when passing through the access control device 1010-6, and the outgoing ICS network address "9922" and the incoming ICS network address "7711" are sent to the ICS frame header. It is converted to the internal ICS network frame F3 and transferred to the conversion unit 1032-6 inside the FR switch 10132-6. The processing device 1232-6 of the conversion unit 1032-6 performs processing according to the flow shown in Fig. 64, but the DLC address conversion table 1432-6 of the conversion unit 1032-6 already states that the outgoing ICS network address is 9922. Since the DLCI 26 corresponding to the incoming ICS network address 7711 is registered as the channel type 10, that is, the SVC, it operates according to the flow of (1) in Fig. 64, and for the DLCI 26. Converts the ICS network frame F3 to an FR frame (FR frame S3) and transfers it.
The FR frame S3 is relayed and transferred through the FR network, becomes the FR frame S4, reaches the FR switch 10132-5, is received by the conversion unit 1032-5 through a logical channel having DLCI 16, and is received by the ICS network frame F3. Restored as an ICS network frame F4 with the same content as. In the conversion unit 1032-5, the pair of the outgoing ICS network address 9922 and the incoming ICS network address 7711 held inside the ICS frame header of the ICS network frame F4 reverses the arrival and departure of the DLC address conversion table 1432. Since it is already registered in -5, it is not registered in the DLC address translation table, and the ICS network frame F4 is transferred to the access control device 1010-5.
<< Application example for half-duplex communication >> As described above, there is one case where the internal network of ICS925 is configured by FR network and the ICS frame is transferred from company X to company Y, and conversely, the case where the ICS frame is transferred from company Y to company X. It was explained that the implementation is performed using the SVC logical channel. Such transfer and transfer in the opposite direction are performed from, for example, a request frame (transfer) from the client terminal of company X connecting to ICS to the server terminal of company Y connecting to ICS, and from the server terminal of company Y for this request frame. When applied to a response frame (reverse transfer) to a client terminal of company X, only one-way communication is performed at one time, but an application example of half-duplex communication that realizes two-way communication by switching the communication direction for each time zone. It becomes.
<< Application example for full-duplex communication >> The logical channel itself set in the FR network is capable of full-duplex communication, that is, bidirectional communication at the same time according to the FR rules. Request frames (transfers) for transfer using one SVC logical channel and reverse transfer in the FR network, for example, from multiple client terminals of company X connected to ICS to multiple server terminals of company Y connected to ICS. And, when applied to the response frame (reverse transfer) from the multiple server terminals of company Y to the multiple client terminals of company X for this request frame, the frames between the client terminal and the server terminal are transferred asynchronously, respectively. Therefore, bidirectional communication is simultaneously performed on one SVC logical channel that serves as a communication path, which is an application example of full-duplex communication.
(4) Frame flow using PVC: An example in which the internal network of ICS925 is composed of an FR network and PVC is applied as a communication path in the FR network will be described by taking an ICS user frame emitted from a terminal of company W to a terminal of company Z as an example. ..
<< Preparation >> DLC address conversion in the conversion unit 1032-5 inside the FR exchange 10132-5 In Table 1432-5, the outgoing ICS network address of the ICS network frame transferred from the conversion unit 1032-5 to the FR network and the incoming ICS network. As the communication path between the address and this incoming / outgoing ICS network address pair, the DLCI of PVC fixedly set to the FR network (pointing to the communication path between FR exchange 10132-5 and FR exchange 10132-6) and the logical channel. Register the channel type indicating that is PVC. Unlike the case of SVC, this registration is registered in the DLC address translation table 1432-5 at the same time when the PVC logical channel is set in the FR switch (10132-5, 10132-5 and 10132-6) that is the communication path. , The communication path is fixedly held for a required period, that is, until the PVC logical channel is deconfigured. It is also registered and retained in the DLC address translation table 1432-6 in the conversion unit 1032-6 inside the FR exchange 10132-6. The DLCI of PVC is assigned to each FR exchange when the PVC is fixedly connected between the FR exchanges.
The values set in the DLC address conversion table 1432-5 are the outgoing ICS network address, the communication address with the company W, that is, the ICS network address assigned to the ICS logical terminal of the access control device 1010-7. 7733 is set, and the communication address with the company Z, that is, the ICS network address 9944 assigned to the ICS logical terminal of the access control device 1010-8 is set as the incoming ICS network address. Furthermore, as DLCI, the ID "18" of the PVC logical channel assigned to the FR exchange 10132-5 is set, and the value "20" indicating PVC is set for the channel type. In addition, the settings registered in the DLC address translation table 1432-5 are also written and saved in the DLC address management server 1732-5. Also, in the DLC address conversion table 1432-6 in the conversion unit 1032-6 inside the FR exchange 10132-6, make the same settings by reversing the outgoing ICS network address and the incoming ICS network address. In this case, even if the same PVC is shown, the DLCI may have a different value from the DLC address translation table 1432-5.
The value set in the DLC address conversion table 1432-6 is the communication address with the company Z as the outgoing ICS network address, that is, the ICS network address "9944" assigned to the ICS logical terminal of the access controller 1010-8. Is set, and the communication address with the company W, that is, the ICS network address "7733" assigned to the ICS logical terminal of the access control device 1010-7 is set as the incoming ICS network address. Furthermore, "28" is set as the ID of the PVC logical channel assigned to the FR switch 10132-6 in DLCI, and "20" indicating PVC is set as the channel type. In addition, the settings registered in the DLC address translation table 1432-6 are also written and saved in the DLC address management server 1732-6.
<< ICS network frame transfer from access control unit >> As described in the first embodiment, the ICS user frame emitted from the terminal of the company W to the terminal of the company Z connected to the access control device 1010-8 via the access control device 1010-7 is access control. It is ICS-encapsulated when passing through the device 1010-7, and becomes an ICS network frame F5 having an outgoing ICS network address "7733" and an incoming ICS network address "9944" inside the ICS frame header. The ICS network frame F5 is transmitted from the access control device 1010-7 to the FR exchange 10132-5, and reaches the conversion unit 1032-5 via the interface unit 1132-5.
<< Obtaining DLCI >> The processing device 1232-5 refers to the DLC address conversion table 1432-5 using the outgoing ICS network address 7733 and the incoming ICS network address 9944 in the header of the received ICS network frame F5, and refers to this ICS network. Acquires that the DLCI of the logical channel set as the communication path for the address pair is "18". At the same time, it is known that this logical channel is PVC from the acquired channel type value "20".
<< Send frame >> The processing device 1232-5 converts the ICS network frame F5 received from the access control device 1010-7 into an FR frame and transmits it to the FR switch 10132-5 for the PVC logical channel 18 acquired as described above. To do. This FR frame conversion method is the same as that described in the SVC example. The above processing procedure of the conversion unit 1032-5 is shown in a flowchart as shown in FIG. 64, and PVC always follows the flow of (1).
<< Transfer of FR frame >> The FR frame S1 obtained by converting the ICS network frame F5 is transferred from the FR exchange 10132-5 to the relay FR exchange 10132-5, and further transferred from the FR exchange 10132-5 to the FR exchange 10132-6 as the FR frame S2. However, this operation is the same as for SVC.
<< Behavior after reaching the frame >> When the FR frame S2 reaches the FR exchange 10132-6, the FR frame S2 is transferred from the FR exchange 10132-6 to the conversion unit 1032-6 inside the FR exchange 10132-6. The conversion unit 1032-6 restores the ICS network frame from the received FR frame, but this operation is the same as in the case of SVC. The restored ICS network frame is described as ICS network frame F6 in Fig. 63, but the frame contents are the same as ICS network frame F5. The ICS network frame F6 is transferred to the access control device identified by the incoming ICS network address "9944" inside the ICS frame header, that is, the access control device 1010-8 having a logical terminal assigned the ICS network address "9944". Will be done. The above processing procedure of the conversion unit 1032-6 is shown in a flowchart as shown in FIG. 65, and PVC always follows the flow of (1).
<< Reverse flow of frame >> Next, the reverse flow of the ICS frame, that is, the case of flowing from the company Z to the company W will be described using the PVC logic channel as a communication path. The ICS user frame originating from company Z to company W is ICS-encapsulated when passing through the access control device 1010-8, and the outgoing ICS network address "9944" and the incoming ICS network address "7733" are ICS frames. It is converted to the ICS network frame F7 held inside the header and transferred to the conversion unit 1032-6 inside the FR switch 10132-6. The processing device 1232-6 of the conversion unit 1032-6 performs processing according to the flow shown in Fig. 64. In this case, the DLC address conversion table 1432-6 of the conversion unit 1032-6 shows the outgoing ICS network address 9944. And since DLCI "28" corresponding to the incoming ICS network address "7733" is registered, ICS network frame F7 is converted to FR frame and transmitted to DLCI "28".
The FR frame transferred in the FR network is received from the logical channel having DLCI 18 in the conversion unit 1032-5 of the FR exchange 10132-5, and is used as the ICS network frame F8 having the same contents as the ICS network frame F7. It will be restored. However, the conversion unit 1032-5 already has the DLC address conversion table 1432- in the form in which the pair of the outgoing ICS network address "9944" and the incoming ICS network address "7733" held in the header of the ICS network frame F8 reverses the arrival and departure. Since the DLCI 18 for this outgoing / incoming address pair is obtained as PVC from the channel type value 20, the registration process is not performed, and the ICS network frame F8 is accessed by the access control device 1010. Transfer to -7.
<< Application example for half-duplex communication >> As described above, the internal network of the ICS925 is configured using the FR network, and an example of transferring ICS frames using PVC has been described. However, whether the logical channels of PVC and SVC are fixedly set or not. The difference is whether the call is set when necessary, and there is no difference in the operation itself of transferring FR frames to the set logical channel. Therefore, the application example to the half-duplex communication when the ICS is configured using the FR network and the PVC logical channel is used for the FR network is the application example to the half-duplex communication using the SVC logical channel. Equivalent.
<< Application example for full-duplex communication >> For the same reason as the application example for half-duplex communication, the application example for full-duplex communication of PVC is equivalent to the application example for full-duplex communication in SVC.
(5) 1-to-N communication or N-to-1 communication using PVC: In the above description, one logical channel of PVC is used as a communication path connecting one company (base) and one company (base), that is, as a communication path connecting one ICS logical terminal and one ICS logical terminal inside ICS. Although the example to be used is shown, it is possible to share one logic channel of PVC as a communication path between one ICS logic terminal and a plurality of ICS logic terminals. An embodiment of such one-to-N communication or N-to-one communication will be described with reference to FIG. 66.
<< Explanation of components >> Company X uses the ICS logical terminal assigned the ICS network address 7711 in the access control device 1010-12 as the connection point, and the access control device 1010-12 is connected to the FR switch 10132-12. From company X The parties to be connected are companies A to D, company A uses the ICS logical terminal assigned the ICS network address "9922" in the access control device 1010-22 as the connection point, and company B uses the access control device 1010-22. The ICS logical terminal to which the ICS network address "9933" is assigned is used as the connection point. Similarly, the company C connects the ICS logical terminal to which the ICS network address "9944" is assigned in the access control device 1010-42. As a point, company D uses the ICS logical terminal assigned the ICS network address "9955" in the access control device 1010-42 as the connection point. The access control devices 1010-22 and 1010-42 are connected to the FR switch 10132-22. Connected, FR exchangers 10132-12 and 10132-42 are connected via the FR relay network.
<< Preparation >> For FR exchanges 10132-12 and 10132-22, set one PVC logical channel to connect the conversion unit 1032-12 inside the FR exchange 10132-52 and the conversion unit 1032-22 inside the FR exchange 10132-22. Then, the DLCI given to the conversion unit 1032-12 of this logical channel is set to "16", and the DLCI given to the conversion unit 1032-22 of the logical channel is set to "26". Register the DLC address translation table 1432-12 in the conversion unit 1032-12 and the DL address translation table 1432-22 in the conversion unit 1032-22 as shown in Fig. 66.
<< 1-to-N communication frame flow >> The flow of frames for 1-to-N communication will be explained using frames transmitted from company X to companies A to D. For the ICS network frame having the outgoing ICS network address "7711" and the incoming ICS network address "9922" directed from the company X to the company A, refer to the DLC address conversion table 1432-12 in the conversion unit 1032-12. , DLCI 16 is sent to the PVC logical channel. Similarly, an ICS network frame having an outgoing ICS network address 7711 and an incoming ICS network address 9933 directed from company X to company B is also transmitted to the PVC logical channel of DLCI 16. ICS network frame with outgoing ICS network address "7711" and incoming ICS network address "9944" from company X to company C, outgoing ICS network address "7711" and incoming ICS from company X to company D The ICS network frame with the network address 9955 is also transmitted to the PVC logical channel of DLCI 16. This indicates that 1-to-N (company X-to-company A to D) communication is performed by sharing one PVC logical channel. The reverse flow of the frame, that is, the case where the frame is transferred from the company A to D to the company X will be described next.
<< N to 1 communication frame flow >> The flow of frames for N-to-1 communication will be explained using frames transmitted from companies A to D to company X. For the ICS network frame having the outgoing ICS network address "9922" and the incoming ICS network address "7111" directed from the company A to the company X, refer to the DLC address conversion table 1432-22 in the conversion unit 1032-22. , Sent to the PVC logical channel of DLCI 26. An ICS network frame with an outgoing ICS network address 9933 and an incoming ICS network address 7711 directed from Company B to Company X is also transmitted to the PVC logical channel of DLCI 26. ICS network frame with outgoing ICS network address "9944" and incoming ICS network address "7711" from company C to company X, outgoing ICS network address "9955" and incoming ICS network from company D to company X The ICS network frame with the address 7711 is also sent to the PVC logical channel of DLCI 26. This means N to 1 (Companies A to D vs. Company X) Indicates that communication is being performed by sharing one PVC logical channel.
(6) N-to-N communication using PVC: By the same method as 1-to-N communication, one logical channel of PVC can be shared as a communication path between multiple ICS logical terminals and multiple ICS logical terminals. An embodiment of this N-to-N communication will be described with reference to FIG. 67.
<< Explanation of components >> Company X uses the ICS logical terminal address 7711 of access control device 1010-13 as a connection point, and company Y uses the ICS logical terminal address 7722 of access control device 1010-13 as a connection point, and access control device 1010-13. Is connected to FR switch 10132-13. The other party to connect from company X or company Y is company A or company C, company A uses the ICS logical terminal address "9922" of access control device 1010-23 as the connection point, and company C is access control device 1010-. The connection point is the ICS logical terminal address "9944" of 43. The access control devices 1010-23 and 1010-43 are connected to the FR exchange 10132-23, and the FR exchanges 10132-13 and 10132-23 are connected via the FR relay network.
<< Preparation >> For FR exchanges 10132-13 and 10132-23, set one PVC logical channel to connect the conversion unit 1032-13 inside the FR exchange 10132-13 and the conversion unit 1032-23 inside the FR exchange 10132-23. , The DLCI given to the conversion unit 1032-13 of this logical channel is "16", and the DLCI given to the conversion unit 1032-23 of the logical channel is "26". The DLC address conversion table 1432-13 in the conversion unit 1032-13 and the DLC address conversion table 1432-23 in the conversion unit 1032-23 are registered as shown in FIG. 67.
<< N to N communication frame flow >> First, the flow of frames for N-to-N communication will be described using frames transmitted from company X to companies A and C, respectively. For the ICS network frame having the outgoing ICS network address "7711" and the incoming ICS network address "9922" directed from the company X to the company A, refer to the DLC address conversion table 1432-13 in the conversion unit 1032-13. , DLCI 16 is sent to the PVC logical channel. Similarly, an ICS network frame having an outgoing ICS network address 7711 and an incoming ICS network address 9944 directed from the company X to the company C is also transmitted to the PVC logical channel of DLCI 16. Next, the frame transmitted from company Y to companies A and C will be described. For the ICS network frame having the outgoing ICS network address "7722" and the incoming ICS network address "9922" directed from the company Y to the company A, refer to the DLC address conversion table 1432-13 in the conversion unit 1032-13. , DLCI 16 is sent to the PVC logical channel. Further, the ICS network frame having the outgoing ICS network address 7722 and the incoming ICS network address 9944 directed from the company Y to the company C is also transmitted to the PVC logical channel of DLCI 16.
Next, the flow in the reverse direction of the frame will be described with the frames transmitted from the company A to the companies X and Y, respectively. For the ICS network address with the outgoing ICS network address "9922" and the incoming ICS network address "7711" directed from company A to company X, refer to DLC address translation table 1432-23 in the conversion unit 1032-23. Is sent to the PVC logical channel of DLCI 26. For the ICS network frame having the outgoing ICS network address "9922" and the incoming ICS network address "7722" directed from the company A to the company Y, refer to the DLC address conversion table 1432-23 in the conversion unit 1032-23. As a result, it is transmitted to the PVC logical channel of DLCI 26. Similarly, an ICS network frame having an outgoing ICS network address 9944 and an incoming ICS network address 7711 directed from Company C to Company X is transmitted to the PVC logical channel of DLCI 26. An ICS network frame with an outgoing ICS network address 9944 and an incoming ICS network address 7722 from Enterprise C to Enterprise Y is also transmitted to the PVC logical channel of DLCI 26. The above description shows that N-to-N communication is performed by sharing one PVC logical channel.
Example-18 (accommodation of telephone line, ISDN line, CATV line, satellite line, IPX line, mobile phone line): The connection to the access control device, which is an access point to the ICS of the present invention, is not limited to the communication line (dedicated line, etc.) to the LAN as described in Example 1 and Example 2. , Telephone line, ISDN line, CATV line, satellite line, IPX line, mobile phone line can be accommodated, and other examples different from Example-10 will be described.
FIGS. 68 to 71 show an example of a system accommodating a telephone line, an ISDN line, a CATV line, a satellite line, an IPX line, and a mobile phone line by ICS6000. , Telephone line converters 6030-1 and 6030-2, ISDN line converters 6029-1 and 6029-2, CATV line converters 6028-1 and 6028-2, Satellite line converters 6027-1 and 6027-2, IPX It is composed of conversion units 6026-1 and 6026-2 and mobile phone conversion units 6025-1 and 6025-2. The telephone line converters 6030-1 and 6030-2 are the physical layer and data link layer (OSI (Open Systems)) between the telephone lines 6160-1 and 6160-2 and the access control devices 6010-1 and 6010-2. Interconnection) It has the function of conversion and inverse conversion of the function corresponding to the first layer and the second layer of the communication protocol. In addition, the ISDN line converters 6029-1 and 6029-2 have functions corresponding to the physical layer and data link layer between the ISDN lines 6161-11 and 6161-2 and the access control devices 6010-1 and 6010-2. It has conversion and inverse conversion functions, and the CATV line converters 6028-1 and 6028-2 are the physical layers between the CATV lines 6162-1 and 6162-2 and the access control devices 6010-1 and 6010-2. It has the functions of conversion and inverse conversion of the functions corresponding to the layer and the data link layer. Further, the satellite line converters 6027-1 and 6027-2 have functions corresponding to the physical layer and data link layer between the satellite lines 6163-1 and 6163-2 and the access control device 6010-1 or 6010-2. It has conversion and inverse conversion functions, and the IPX converters 6026-1 and 6026-2 are the physical layer between the IPX lines 6164-1 and 6164-2 and the access control devices 6010-1 and 6010-2. It has the function of conversion and inverse conversion of the function corresponding to the data link layer. The mobile phone converters 6026-1 and 6026-2 have functions corresponding to the physical layer and data link layer between the mobile phone wireless lines 6165-11 and 6165-2 and the access control devices 6010-1 and 6010-2. It has conversion and inverse conversion functions.
The ICS frame interface network 6050 is the same type of network as the ICS frame interface network 1050 shown in FIG. 35, and transfers ICS network frames in accordance with the provisions of RFC791 or RFC1883 in the same format. The X.25 network 6040 is also the same type of network as the X.25 network 1040 in Fig. 35. It accepts ICS network frames, converts them to X.25 format frames and transfers them, and finally converts them to the ICS network frame format. Reverse conversion and output. The FR network 6041 is also the same type of network as the FR network 1041 in Fig. 35. It accepts ICS network frames, converts them to frame relay format frames and transfers them, and finally converts them back to the ICS network frame format and outputs them. To do. The ATM network 6042 is also the same type of network as the ATM network 1042 shown in Fig. 35. It accepts ICS network frames, converts them to ATM format frames and transfers them, and finally converts them back to the ICS network frame format and outputs them. .. The satellite communication network 6043 is the same type of network as the satellite communication network 1043 shown in Fig. 35. It accepts ICS network frames, transfers information using satellites, and finally converts back to the format of ICS network frames and outputs them. To do. In addition, the CATV network 6044 accepts ICS network frames, converts them into CATV format frames, transfers the inside thereof, and finally converts them back to the ICS network frame format and outputs them.
<< Common preparation >> The conversion table 6013-1 in the access controller 6010-1 includes the outgoing ICS network address, the sender ICS user address, the recipient ICS user address, the incoming ICS network address, and the request identification. This request identification is represented by, for example, "1" for the intra-company communication service, "2" for the inter-company communication service, "3" for the virtual leased line connection, and "4" for the ICS network server connection. In the conversion table 6013-1, the addresses registered by the same method as in Example 1 and Example 2 are described. The ICS network server 670 has an ICS user address of "2000" and an ICS network address of "7821", and is connected to the access control device 6010-1 via the ICS network communication line 6081-1. Conversion table 6013- In 1, the recipient ICS user address 2000, the incoming ICS network address 7821, and the request identification 4 of the ICS network server 670 are registered.
The operation will be described with reference to the flowchart of FIG. 72.
<< Communication from telephone line to ISDN line >> The user 6060-1 sends the ICS user frame F110 having the sender ICS user address 3400 and the receiver ICS user address 2500 to the access control device 6010-1 via the telephone line 6160-1. The access control device 6010-1 receives the ICS user frame F110 from the telephone line conversion unit 6030-1 of the ICS network address "7721" (step S1800), and the ICS network address "7721" identifies the request in the conversion table 6013-1. Checks if is registered as a virtual leased line connection 3 (step S1801). In this case, since it is not registered, the recipient ICS user address 2500 written on the ICS user frame Fll0 is registered on the conversion table 6013-1 (step S1803), and further, the request is made. Check whether the identification is registered as inter-company communication 2 (step S1804). In this case, since it is registered, the incoming ICS network address "5522" is obtained from the conversion table 6013-1, processing such as billing related to inter-company communication is performed (step S1805), and the ICS user frame F110 is encapsulated in ICS (step S1805). In step S1820), it is converted to the ICS network frame F120 and transmitted to the ICS frame transfer network 6030 via the ICS network communication line 6080-1 (step S1825). The ICS network frame F120 reaches the access control device 6010-2 via, for example, the X.25 network 6040 and the ICS network communication line 6080-2, where the ICS decapsulated and the ICS user frame F110 is restored and the recipient. Reach user 6061-2 with ICS user address "2500".
<< Communication from ISDN line to CATV line >> The user 6061-1 sends the ICS user frame Flll of the sender ICS user address 3500 and the receiver ICS user address 2600 to the access control device 6010-1 via the ISDN line 6161-1. The access control device 6010-1 receives the ICS user frame Flll from the ISDN line conversion unit 6029-1 of the ICS network address 7722 (step S1800), and the ICS network address 7722 requests it on the conversion table 6013-1. Check if the identification is registered as a virtual leased line connection 3 (step S1801). In this case, since the virtual leased line connection "3" is registered, obtain the incoming ICS network address "5523" from the conversion table 6013-1, perform processing such as billing for the leased line connection (step S1802), and ICS. The user frame Flll is encapsulated in ICS (step S1820), converted to the ICS network frame F121, and transmitted to the ICS frame transfer network 6030 via the ICS network communication line 6080-1 (step S1825).
In the virtual leased line connection, the sender ICS user address and the receiver ICS user address written inside the ICS network frame Flll do not have to be used inside the access control device. Next, the ICS network frame F121 reaches the access control device 6010-2 via, for example, the FR network 6041 and the ICS network communication line 6080-2, and the ICS reverse encapsulation is performed to restore the ICS user frame Flll, and the incoming ICS is restored. It reaches the user 6062-2 connected from the CATV line 6162-2 via the CATV line unit 6028-2 to which the network address "5523" is assigned.
<< Communication from CATV line to satellite line >> The user 6062-1 sends the ICS user frame F112 having the sender ICS user address 3600 and the receiver ICS user address 2700 to the access control device 6010-1 via the CATV line 6162-1. The access control device 6010-1 receives the ICS user frame F112 from the CATV line conversion unit 6028-1 of the ICS network address 7723 (step S1800), and this ICS network address 7723 is displayed on the conversion table 6013-1. Check whether the request identification is registered as the virtual leased line connection 3 (step S1801). In this case, since it is not registered, the recipient ICS user address 2700 written on the ICS user frame F112 is registered on the conversion table 6013-1 (step S1803), and further, the request is made. Check whether the identification is registered as inter-company communication 2 (step S1804). In this case, since the inter-company communication "2" is registered, the incoming ICS network address "5524" is acquired from the conversion table 6013-1, and processing such as billing related to the inter-company communication is performed (step S1805), and the ICS user Frame F112 is encapsulated in ICS (step S1820), converted to ICS network frame F122, and transmitted to ICS frame transfer network 630 via the ICS network communication line 6080-1 (step S1825). The ICS network frame F120 reaches the access control device 6010-2 via, for example, the ATM network 6042 and the ICS network communication line 6080-2, and is ICS decapsulated to restore the ICS user frame frame F112, and the recipient ICS user address. Reach user 6063-2 for "2700".
<< Communication from satellite line to IPX line >> The user 6063-1 sends the ICS user frame F113 having the sender ICS user address 3700 and the receiver ICS user address 2800 to the access control device 6010-1 via the telephone line 6163-1. The access control device 6010-1 receives the ICS user frame F113 from the satellite line conversion unit 6027-1 of the ICS network address 7724 (step S1800), and the ICS network address 7724 requests it on the conversion table 6013-1. Check whether the identification is registered as a virtual leased line connection 3 (step S1801). In this case, since it is not registered, the recipient ICS user address 2800 written on the ICS user frame F113 is registered on the conversion table 6013-1 (step S1803), and the request identification is further performed. Check whether it is registered as inter-company communication 2 (step S1804). In this case, since the inter-company communication "2" is registered, the incoming ICS network address "5525" is acquired from the conversion table 6013-1, and processing such as billing related to the inter-company communication is performed (step S1805), and the ICS user Frame F113 is encapsulated in ICS (step S1820), converted to ICS network frame F123, and transmitted to ICS frame transfer network 6030 via ICS network communication line 6080-1 (step S1825). The ICS network frame F123 reaches the access control device 6010-2 via, for example, the ICS frame interface network 6050 and the ICS network communication line 6080-2, and is ICS decapsulated to restore the ICS user frame F113, and the recipient ICS user. Reach user 6064-2 with address "2800".
<< Communication from IPX line to mobile phone line >> The user 6064-1 sends the ICS user frame F114 having the sender ICS user address 0012 and the receiver ICS user address 2900 to the access control device 6010-1 via the IPX line 6164-1. The access control device 6010-1 receives the ICS user frame F114 from the IPX line conversion unit 6026-1 of the ICS network address "7725" (step S1800), and the ICS network address "7725" requests it on the conversion table 6013-1. Check if the identification is registered as a virtual leased line connection 3 (step S1801). In this case, since it is not registered, the recipient ICS user address 2900 written on the ICS user frame F114 is registered on the conversion table 6013-1 (step S1803), and further, the request is made. Check whether the identification is registered as inter-company communication 2 (step S1804). In this case, since "2" is not registered, it is checked whether or not the request identification is registered as the intra-company communication "1" (step S1810). In this case, since the inter-company communication "1" is registered, the incoming ICS network address "5526" is acquired from the conversion table 6013-1, and processing such as billing related to the in-house communication is performed (step S1811), and the ICS user. Frame F114 is encapsulated in ICS (step S1820), converted to ICS network frame F124, and transmitted to ICS frame transfer network 6030 via ICS network communication line 6080-1 (step S1825). The ICS network frame F124 reaches the access control device 6010-2 via, for example, the CATV network 6044 and the ICS network communication line 6080-2, and is ICS decapsulated to restore the ICS user frame F114, and the recipient ICS user. Reach user 6065-2 with address "2900".
<< Communication from mobile phone line to phone line >> The user 6065-1 sends the ICS user frame F115 of the sender ICS user address 3800 and the receiver ICS user address 2400 to the access control device 6010-1 via the mobile phone line 6165-1. The access control device 6010-1 receives the ICS user frame F115 from the mobile phone line conversion unit 6035-1 of the ICS network address 7726 (step S1800), and the ICS network address 7726 is displayed on the conversion table 6013-1. Check whether the request identification is registered as the virtual leased line connection 3 (step S1801). In this case, since it is not registered, the recipient ICS user address 2400 written on the ICS user frame F115 is registered on the conversion table 6013-1 (step S1803), and the request identification is between companies. Check whether it is registered as communication 2 (step S1804). In this case, since the request identification is registered as inter-company communication "2", the incoming ICS network address "5521" is acquired from the conversion table 6013-1, and processing such as billing for inter-company communication is performed (step S1805). , ICS user frame F115 is encapsulated in ICS (step S1820), converted to ICS network frame F125, and transmitted to ICS frame transfer network 6030 via ICS network communication line 6080-1 (step S1825). The ICS network frame F120 reaches the access control device 6010-2 via, for example, the satellite network 6043 and the ICS network communication line 6080-2, and is ICS decapsulated to restore the ICS user frame Fll5, and the recipient ICS user address. Reach "2400" user 6060-2.
<< Communication from mobile phone line to ICS network server >> The user 6066-1 sends the ICS user frame F116 of the sender ICS user address 3980 and the receiver 1CS user address 2000 to the access control device 6010-1 via the mobile phone line 6166-1. The access control device 6010-1 receives the ICS user frame F116 from the mobile phone line conversion unit 6025-1 of the ICS network address "7726" (step S1800), and the ICS network address "7726" is displayed on the conversion table 6013-1. Check whether the request identification is registered as the virtual leased line connection 3 (step S1801). In this case, since it is not registered, the recipient ICS user address 2000 written on the ICS user frame F116 is registered on the conversion table 6013-1 (step S1803), and the request identification is between companies. Check whether it is registered as communication 2 (step S1804). In this case, since it is not registered, it is checked whether or not the request identification is registered as the intra-company communication 1 (step S1810). In this case, it is not registered, so check whether the request identification is registered as communication 4 with the ICS network server (step S1812). In this case, since it is registered, the incoming ICS network address "7821" is obtained from the conversion table 6013-1, processing such as billing related to corporate communication is performed (step S1813), and the ICS user frame F116 is encapsulated in ICS (step S1813). Step S1820), convert to an ICS network frame and send it to the ICS network server 670 (step S1825). The method by which the ICS network server 670 returns a reply to the source user 6066-1 is the same as the method described in Example-3.
In the various transmission methods of the ICS user frame described above, the transmitting side changes the receiver ICS user address written in the ICS user frame, so that the transmitting side can make a telephone line, an ISDN line, a CATV line, or a satellite line. , IPX line, mobile phone line, any of the receiving side telephone line, ISDN line, CATV line, satellite line, IPX line, and mobile phone line can be selected.
Example-19 (Dial Apple-Ta): An example using a dial apple-ta will be described with reference to FIGS. 73 to 75. LAN7400 internal user 7400-1 has an ICS user address "2500", similarly LAN7410 internal user 7410-1 has an ICS user address "3601". The person who manages the dial-up router 7110 inputs the telephone number specified for the recipient ICS user address correspondence and its priority from the router table input unit 7018-1 in the router table 7113-1 of the dial-up router 7110.
Here, the registration contents of the router table 7113-1 will be described with reference to FIG. 76. When the recipient ICS user address "3601" is specified, the first priority is the telephone number "03-1111-1111" and the second priority is the telephone number "03-2222-2222". The third place is the telephone number "03-3333-3333". Recipient ICS user addresses "3602" and "3700" are also registered in the same way. Then, as an example of communication from the sender ICS user address 2500 to the receiver ICS user address 3601, the flow chart of FIG. 77 will be referred to and described.
User 7400-1 sends the ICS user frame F200 to the dial-up router 7110 via gateway 7400-2 and user logical communication line 7204. The dial-up router 7110 operates under the control of the processor 7112-1, receives the ICS user frame F200 (step S1901), reads the recipient ICS user address "3601" contained in the ICS user frame F200, and addresses it. Search router table 7113-1 with "3601" as the search keyword (step S1902) to find the phone number with the highest priority. In this case, the telephone number with the highest priority is "03-1111-1111" as shown in the router table in Fig. 76, so the dial-up router 7110 uses the telephone network 7215-1 as the first attempt. Then make a call to the telephone number "03-1111-1111" (step S1910). As a result, a telephone communication path 7201 is established between the line section 7011-1 of the access control device 7010-1 called by the telephone number "03-1111-1111", that is, the dial-up router 7110 and the line section 7011-1. Is connected by a telephone line. If the dial-up router 7110 and the line section 7011-1 are not connected by a telephone line in the above telephone call procedure, the dial-up router 7110 is then subjected to the telephone number "03-2222", which has the second highest priority according to the router table 7113-1. Finding "-2222" and calling the telephone number "03-2222-2222" via the telephone network 7215-1 as the second attempt (step S1911). As a result, a telephone communication path 7202 is established with the line unit 7011-1 of the access control device 7010-1 called by the telephone number "03-2222-2222". If the dial-up router 7110 and the line section 7011-1 are not connected by a telephone line in the above telephone call procedure, the dial-up router 7110 is then the telephone number with the third highest priority according to the router table 7113-1. Find "03-3333-3333", No. As a third attempt, call the telephone number "03-3333-3333" via the telephone network 7215-3 (step S1912). As a result, a telephone communication path 7203 is established with the line unit 7011-3 of the access control device 7010-3 called by the telephone number "03-3333-3333". When the telephone communication path is not established from the dial-up router to the access control device even after the above multiple attempts, the dial-up router 7110 stores the received ICS frame F200 in the storage unit 7117-1 (step S1913), and after a certain period of time. Index the router table again in (step S1914) (step S1902), and try to establish the telephone communication channels 7201, 7202, 7203, etc.
Next, the operation after the dial-up router 7110 and the line unit 7011-1 are connected by a telephone line will be described. The dial-up router 7110 enters the authentication procedure for whether or not it is a legitimate user registered as a user in the access control device 701O-1 (step S1920). The authentication procedure may be any one that can achieve the purpose of authentication. For example, the dial-up router 7110 sends an ID and password for identifying the dial-up router 7110 to the line unit 7011-1 through the telephone line 7201, and the access control device. The authentication unit 7016-1 of 7010-1 checks whether the received ID and password are correct, and if they are correct, the notification data notifying that the user is correct, that is, "affirmation confirmation" is sent to the dial-up router 7110 via the telephone communication path 7201. By sending, the authentication procedure is completed. In addition, if either the received ID or password is incorrect, the communication on the telephone communication path 7201 will be interrupted.
When the dial-up router 7110 receives the affirmative confirmation notification in the user authentication from the telephone line 7201, it sends the ICS user frame F200 to the telephone channel 7201 (step S1930), and the access control device 7010-1 receives the ICS user frame F200. When the above is confirmed, the telephone communication path 7201 is released and the telephone is hung up (step S1931), and the series of processing of the dial-up router described above is completed.
When the access control device 7010-1 receives the ICS user frame F200, it performs ICS encapsulation using the conversion table 7013-1 under the control of the processing device 7012-1 to generate the ICS network frame F301, and inside the ICS7100. Send to ICS network communication line 7301. In this embodiment, the outgoing ICS network address of the ICS network frame F301 is the network address "7501" assigned to the ICS logical terminal in the line section 7011-1, and the incoming ICS network address is the access control device 7010-2. It is "8601" assigned to the ICS logical terminal. The ICS network frame F301 is transferred to the ICS7100 to reach the access controller 7010-2, where it is ICS decapsulated, passes through the user logical communication line 7601, and reaches the user 7410-1 with the ICS user address 3601. To do.
In the above description, when the telephone communication path 7202 called by the telephone number "03-2222-2222" is established between the dial-up router 7110 and the line portion 7011-1 of the access control device 7010-1, the ICS user frame. The F200 passes through the telephone communication path 7202 and is transferred from the dial-up router 7110 to the line section 7011-1. In this case as well, the access control device 7010-1 receives the ICS user frame F200, performs ICS encapsulation, generates the ICS network frame F302, and sends it to the ICS network communication line 7301 inside the ICS7100. Here, the ICS user frame F302 is the outgoing ICS user address 7502 and the incoming ICS user address 8601.
If a telephone communication path 7203 called by the telephone number "03-3333-3333" is established between the dial-up router 7110 and the line section 7011-3 of the access control device 7010-3, the ICS user frame F200 is a telephone. It passes through the communication path 7203 and is transferred from the dial-up router 7110 to the line section 7011-3. In this case, when the access control device 7010-3 receives the ICS user frame F200, it encapsulates the ICS, generates the ICS network frame F303, and sends it to the ICS network communication line 7303 inside the ICS7100. In this case, the outgoing ICS network address of the ICS network frame F303 is the network address "7800" assigned to the ICS logical terminal in the line section 7011-3, and the incoming ICS network address is the ICS of the access control device 7010-2. It is "8601" given to the logical terminal. The ICS network frame F303 is transferred to the ICS7100 to reach the access controller 7010-2, where it is ICS decapsulated, passes through the user logical communication line 7601, and reaches the user 7410-1 with the ICS user address 3601. To do.
Example-20 (speed class and priority): << Configuration >> As shown in FIGS. 78 to 80, the ICS8000-1 includes an access control device 8010-1,8010-2,801O-3,8010-4, a relay device 80200-1, an ICS address management server 802.115, and an ICS network server 8027. These devices, including -1, are connected by ICS network communication lines 8030-1,8030-2,8030-3,8030-4,8030-5,8030-6, which transfer ICS network frames. The line section 8011-1, the processing device 8012-1, and the conversion table 8013-1 are all provided inside the access control device 8010-1. ICS logical communication lines 8051-1,8051-2,8051-3,8051-4 are connected to the plurality of ICS logical terminals of the line section 8011-1, respectively, and the ICS network addresses "7721", "7723", " 7724 and 7725 are given respectively. The ICS network communication line in ICS8000-1 is given a speed class that indicates the speed at which ICS network frames are transferred. For example, the ICS network communication line 8030-1,8030-2,8030-6 has a speed class. Both are "4", the speed class of both the ICS network communication lines 8030-3 and 8030-5 is "3", and the speed class of the ICS network communication line 8030-4 is "2". The speed class is defined by the same standard as the speed class registered inside the conversion table 8013-1. The ICS address management server 802.11 is assigned the ICS network address "7811", and the ICS network server 802.11 is assigned the ICS network address "7821". It is connected to 8010-1.
The user 8400-1 as an ICS communication terminal has an ICS user address "2500" and is connected to the line section 8011-1 via the ICS logical communication line 8051-1. The user 8400-2 as an ICS communication terminal is an ICS user. It has the address "2510" and is connected to the access control device 8010-2 via the ICS logical communication line 8052-1. The user 8400-3 as an ICS communication terminal has the ICS user address "3600" and the user 8400. -4 has an ICS user address "3610" and is connected to the access control device 8010-3 via gateway 8041-1 and ICS logical communication line 8053-1, respectively.
The method of registering the ICS network address and the ICS user address in the conversion table 8013-1 is the same method as that of the above-mentioned Example-1 and Example-2, and the difference is the conversion of Example-1. The speeds registered in Table 113-1 have been deleted, and instead, as shown in Figure 80, the speed class and priority are registered, and the speed class and priority are in the address management server 8025-1. , It is stored with the corresponding ICS user address as part of the address-related information.
The speed class is expressed numerically instead of being expressed in units of speed. For example, a communication speed of 64 Kbps is expressed in speed class 1, a communication speed of 128 Kbps is expressed in speed class 2, and so on, a communication speed of 500 Mbps is expressed in speed class 7. Represent. The numerical value of the speed class is defined as the faster speed as the numerical value is larger. An example of associating the communication speed with the speed class is shown in Fig. 81. It is not necessary to set the number of communication speed classes to 7 levels from 1 to 7, for example, 20 levels in response to the progress of communication technology. It may be subdivided to some extent. In addition, the communication speed does not have to exactly match the physical communication speed of the ICS network communication line in the ICS8000-1, for example, it corresponds to 25% of the physical communication speed so that the communication speed has a margin. You may do so. The priority is represented by a numerical value, for example, in eight stages, and represents the priority when the ICS network frame is sent from the access control device or the relay device to the ICS network communication line when compared in the same speed class. The higher the priority value, the higher the priority. For example, the relay device receives two ICS network frames F510 and F511 at approximately the same time, the speed class of these two frames is the same value "3", the priority of the ICS network frame F510 is "3", and the ICS. When the priority of the network frame F511 is 5, the ICS network frame F511 having a high priority is sent out in time first.
In this embodiment, for example, the ICS network communication lines 8030-3 and 8030-4 are said to be "in the same communication path" from the relay device 8020-1 to the access control device 8010-3, and the ICS network communication line 8030. -5 and 8030-6 are said to be "in the same communication path" from the relay device 8020-1 to the access control device 8010-4. The communication route may be directed from the access control device to the relay device, or from one relay device to another relay device connected by the ICS network communication line. A plurality of ICS network communication lines of the same speed class may exist in the same communication route, and in this case, the same speed class may be in the same ICS network communication line.
<< operation >> The operation will be described with reference to the flowcharts of FIGS. 82 and 83.
User 8400-1 sends the ICS user frame F500 with the sender ICS user address 2500 and the receiver ICS user address 3600 to the ICS logical communication line 8051-1. The processing device 8012-1 of the access control device 8010-1 receives the ICS user frame F500 from the ICS logical terminal of the ICS network address "7721" of the line unit 8011-1, and acquires the ICS network address "7721" (step). S2001), check whether the address "7721" is registered as the request identification as the virtual leased line connection "3" on the conversion table 8013-1 (step S2002). In this case, since it is not registered, the recipient ICS user address 3600 written on the ICS user frame F500 is acquired next corresponding to the ICS network address 7721 (step S2004), and the address Check whether "3600" is registered in the conversion table and the request identification is registered as inter-company communication "2" (step S2005). In this case, since it is registered, the incoming ICS network address "5522" is obtained from the conversion table 8013-1 in preparation for ICS encapsulation, and the speed class "3" and priority "3" are obtained from the conversion table 8013-1. Obtain information related to billing (step S2006). Next, ICS encapsulation is performed by generating an ICS network frame F510 in which the speed class 3 and the priority 3 are written in the ICS network frame control unit (step S2020), and the ICS network communication line 8030- Send to 1 (step S2021).
In the above explanation, the ICS network frame is for inter-company communication with the request identification of "2", but for the virtual line connection with the request identification of "3", the incoming ICS is shown in the conversion table 8013-1. Acquire the network address, speed class, priority, etc., and further acquire the information related to billing (step S2003). For example, in the case of corporate communication "1", the incoming ICS network address, speed, etc. are obtained from conversion table 8013-1. Acquire the class, priority, etc., and further acquire the information related to billing (step S2011), and in the case of communication "4" to the ICS network server, acquire the incoming ICS network address, etc. from conversion table 8013-1. Then, the information related to billing is acquired (step S2013), and after ICS encapsulation, it is sent to the ICS network server 8027-1.
The ICS network frame F510 generated by the above procedure reaches the relay device 802.110 via the ICS network communication line 8030-1. At this time, it is assumed that another ICS network frame F511 arrives at the relay device 8020-1 via the ICS network communication line 8030-2 at about the same time. The ICS network frame F511 is sent from the user 8400-2 as the ICS user frame F501, reaches the access control device 8010-2 via the ICS logical communication line 8052-1, and is then ICS-encapsulated to become the ICS network frame F511. It was transmitted through the ICS network communication line 8030-2 and reached the relay device 8020-11. When the relay device 802.11 receives the ICS network frames F510 and F511 (step S2030), under the control of the processing device 802.111, the relay table 802.111 is first checked to communicate the ICS network frames F510 and F511 with the ICS network. Which line should be used, that is, find the communication route (step S2031) and divide each communication route (step S2032). In the case of this embodiment, the transmission destination of both of the two ICS network frames F510 and F511 is the communication route from the relay device 8020-1 to the access control device 8010-3, and the ICS network communication line 8030- There are 3 and 8030-4, 2 ICS network communication lines. Next, for both the ICS network frames F510 and F511, the speed class described in the control unit is read and divided for each speed class (step S2041), and thereafter, the procedure for each divided speed class is performed. In the case of this embodiment, both the speed classes of the ICS network frames F510 and F511 are 3. Next, ICS frames of the same speed class read the priority described in each control unit and are transmitted from the ICS frame having the higher priority (step S2042). If they have the same priority, either one may be sent first. As a result of the above processing, the relay device 802.11 is ICS network.
In the above procedure, if there is only an ICS network communication line whose speed is lower than the speed class described in the control unit of the ICS network frame F510, information on the decrease in communication service due to the decrease in speed, that is, the corresponding ICS network. Record the sender ICS user address, receiver user address, communication service time (year, month, day, hour, minute, second), etc. described in the frame in the relay operation file 8023-1. The recorded contents of the relay operation file are notified to the ICS8000-1 user upon request.
By the above procedure, the two ICS network frames F511 and F510 are transferred to the ICS network communication line 8030-3 and reach the access control device 8010-3, with the high-priority ICS user frame F511 leading in time. To do. The ICS network frame F511 becomes the ICS user frame F501 by being decapsulated by ICS, and reaches the user 8400-4 of the ICS user address "3610" via the ICS logical channel 8053-1. The ICS network frame F510 is ICS decapsulated to become the ICS user frame F500, and reaches the user 8400-3 with the ICS user address "3600" via the ICS logical channel 8053-1.
Next, options are shown for how to use priorities. When transferring the speed class and priority registered in the conversion table 8013-1 to the ICS network at the time of ICS encapsulation, the processing device 8012-1 controls the ICS user frame to be processed. Check the length written in the part, for example, only when the ICS user frame is less than the specified value (for example, 256 bytes), increase the priority value by "+1" and increase the ICS network. Post to kuframe. In this way, it is possible to realize a service that preferentially transfers the inside of the ICS8000-1 only to a short ICS user frame. By such a method, the ICS8000-1 operator can easily realize a communication service in which a short ICS user frame is prioritized, that is, a communication charge is increased. If the ICS user frame is short for the user, the flow will be more reliable. Whether or not to adopt the priority option is achieved by, for example, determining for each access control device.
In addition, only the speed class may be carried out, and the above method may be carried out except for the priority, that is, with the same priority. In another embodiment, conversion table 8013-1 does not include sender ICS user addresses (intra-company and inter-company). Even in this case, the flowchart in FIG. 82 does not originally refer to the sender ICS user address, so it does not change.
Example-21 (Giving a digital signature to an ICS user frame): An embodiment of electronically signing an ICS user frame to prove that the ICS user frame has passed an access control device will be described, and an embodiment of encrypting an ICS user frame when requested will be described. explain. First, the technique of electronic signature (electronic signature) used in this embodiment will be described. When using a digital signature, there are a signer who creates the digital signature and a signature verifier. The signer a simultaneously generates a pair of signing key KSa and verification key KPa of signer a, keeps the signing key KSa in secret, and discloses only the verification key KPa by some means. The signer a generates an electronic signature σ depending on the data m and the signature key KSa by using the secret signature key KSa only for the signer a. Expressed in a mathematical formula, it becomes the following number 1.
(Number 1) σ = SIGN (KSa, h (m)) Here, SIGN is a signature function representing a signature function, and the function y = h (m) is a hash function for electronic signature having a function of compressing data m into short data. Verifier b uses the published verification key KPa to (Number 2) ν = TEST (σ, KPa, h (m)) The correctness of the electronic signature σ is verified by. If ν = 1, both the electronic signature σ and the data m are correct, indicating that both the electronic signature σ and the data m have not been rewritten and tampered with after the generation of the electronic signature σ. If ν = 0, it means that either one or both of the electronic signature σ and the data m are incorrect. The verification key KPa is widely disclosed by, for example, a public key guidance service center that provides public key guidance service services, a public key guidance service center, and general advertisements by appropriate means. A technique for creating a signature function SIGN that makes it virtually impossible to calculate the signature key KSa even if the verification key KPa is disclosed is known.
Next, the procedure for assigning a digital signature to the ICS user frame will be described. Conditions related to the time and place where the electronic signature is given, that is, the time consisting of the year, month, day, hour, minute, and second when the electronic signature is given, the person in charge of operating the access control device, and the "time / place parameter" that indicates the identification code of the access control device. "P1" and "Signature function parameter P2" indicating the type of signature function SIGN and hash function h (m), the length of the signature key, etc. are also subject to digital signature. Expressed in a mathematical formula, the following number 3 is obtained.
(Number 3) σ = SIGN (KSa, h (m)) However, m = UFTheP1TheP2.
Here, UF represents the ICS user frame before ICS encapsulation or the restored ICS user frame after ICS decapsulation. The receiving user receives the ICS user frame UF, the time / place parameter P1, the signature function parameter P2, and the digital signature σ in the receiving ICS user frame as UFTheP1TheP2Theσ. This is illustrated as shown in FIG. 84. Further, there is also a method of leaving the writing area of the parameters P1 and P2 and the electronic signature σ as a free area inside the ICS user frame UF as shown in FIG. 85. In this case, when the free space of the ICS user frame UF is represented by Data, the digital signature σ is (Number 4) σ = SIGN (KSa, h (m)) However, m = Data The P1 The P2.
Generated as and signature verification (Number 5) ν = TEST (σ, KPa, h (m)) However, m = Data The P1 The P2.
Do as.
Furthermore, for example, if the length of the ICS user frame UF is 2048 bytes and the length of UFTheP1TheP2Theσ is 2448 bytes (2048 bytes + 400 bytes), inside the control unit of the ICS user frame UF. A field representing the length of a frame (eg, the total length field in Figure 152) needs to be rewritten from 2048 bytes to 2448 bytes. In this way, the ICS user frame with the length field rewritten is represented by UF ́. When adopting such an embodiment, the electronic signature σ is (Number 6) σ = SIGN (KSa, h (m)) However, m = UF ́The P1 The P2.
Generated as and signature verification (Number 7) ν = TEST (σ, KPa, h (m)) However, m = UF ́The P1 The P2.
Do as.
In this embodiment, the order in which UFs, P1 and P2 are arranged may be changed. For example, the electronic signature σ = SIGN (KSa, h (m)) is calculated as m = PlTheP2TheUF, and P1TheP2The UFTheσ may be set inside the ICS user frame on the receiving side. In this embodiment, the encryption function is represented by y = ENC (K1, x), and the decryption function is represented by x = DEC (K2, y). Here, x is plaintext data, y is ciphertext data, ENC is an encryption function, DEC is a decryption function, K1 is an encryption key, and K2 is a decryption key. The technique of electronic signature is also called digital signature. For example, W. Diffie, ME Hellman's paper "New Direction in Cryptography" IEEE, IT. Vol.IT-22, No.6, p.644-654, 1976, Shokodo, published in 1990, edited by Shigeo Tsujii, "Cryptography and Information Security," p.127-138.
<< Configuration >> As shown in FIGS. 86 and 87, the ICS9000-1 includes access control devices 9010-1, 9010-2, 9010-3 and relay device 9120-1, which are ICS network communications that transfer ICS network frames. It is connected by lines 9030-1,9030-2,9030-3. The line unit 9011-11, the processing device 9012-1, the conversion table 9013-1, and the electronic signature unit 9017-1 are all provided inside the access control device 9010-1. Inside the digital signature unit 9017-1, a signature key KSa, a verification key KPa, a program module that realizes the digital signature function SIGN and the hash function h (m), a time / place parameter P1, and a signature function parameter P2 are included. There is. Here, the signature Ken KSa is a secret value held by the access control device 9010-1, and the electronic signature part holds the secret signature key inside, so that the secret signature key is not leaked to the outside. There is a need. For example, the electronic signature unit is stored inside a physically strong box so that the signature key cannot be read from the outside. The ICS network addresses "7721", "7722", "7725", "7726", "7727", and "7728" are assigned to the plurality of ICS logical terminals of the line unit 9011-1.
The encryption / decryption means 9018-1 includes an encryption function and holds an encryption key K1 and a decryption key K2. When the ICS user frame UF1 is input, the ciphertext UF2 is generated as UF2 = ENC (K1, UF1), and when the ciphertext UF2 is input, the plaintext is calculated as UF1 = DEC (K2, UF2).
<< operation >> The operation will be described with reference to the flow chart of FIG. 88. User 9400-1 sends the ICS user frame F900 with the sender ICS user address 2500 and the receiver ICS user address 3600 to the ICS logical communication line 9051-1. The processing device 9012-1 of the access control device 9010-1 receives the ICS user frame F900 from the ICS logical terminal of the ICS network address 7721 of the line unit 9011-1, and acquires the ICS network address 7721 (step). S2001), check whether the request identification is registered as the virtual leased line connection "3" on the conversion table 9013-1 with the address "7721" (step S2002). In this case, since it is not registered, the recipient ICS user address 3600 written on the ICS user frame F900 corresponding to the ICS network address 7721 is acquired (step S2004), and this address Check whether "3600" is registered in the conversion table and whether the request identification is registered as inter-company communication "2" (step S2005). In this case, since it is registered, the incoming ICS network address "5522" is obtained from the conversion table 9013-1 in preparation for ICS encapsulation. Next, the information related to the speed class and priority billing is obtained from the conversion table 9013-1 (step S2006). Since "1" is specified in the signature field of conversion table 9013-1 and "YES" is registered in the electronic signature field at the time of transmission, the processing device 9012-1 is stored in the electronic signature unit 9017-1. Using the program module that realizes the digital signature function SIGN and the hash function h (m), the time / location parameter P1 and the signature function parameter P2, the digital signature of the ICS user frame F900 is performed by the above-mentioned digital signature technique. Generate and create a new ICS user frame (represented by UF2) (step S2019). Expressed in a mathematical formula, the following number 8 is obtained.
(Number 8) UF2 = mTheσ However, m = F900TheP1TheP2, σ = SIGN (KSa, h (m)).
In the above procedure, even if "1" is specified in the signature field of conversion table 9013-1, if "NO" is registered in the electronic signature field at the time of transmission, the electronic signature section 9017- 1 does not work and the digital signature is not given.
Next, since the encryption class is specified as "1", the ICS user frame UF2 is encrypted by the encryption / decryption means 9018-1 and the new ICS user frame UF3 (= ENC (K1)) , UF2)). If the encryption class is "0", encryption is not performed.
Next, ICS encapsulation is performed by generating an ICS network frame F901 in which the speed class, priority and encryption class are written in the ICS network frame control unit (step S2020), and the ICS network communication line 9030 inside the ICS9000-1 is performed. Send to -1 (step S2021). In the above explanation, the ICS network frame is an example of inter-company communication with a request identification of "2". For example, in the case of a virtual line connection with a request identification of "3", the incoming ICS is shown in the conversion table 9013-1. Acquire information on network address, billing, etc. (step S2003), and in the case of in-house communication with request identification of "1", obtain information on incoming ICS network address, billing, etc. from conversion table 9013-11 (step S2011). ), In the case of communication to the ICS network server whose request identification is "4", information on the incoming ICS network address, billing, etc. is acquired from the conversion table 9013-1 (step S2013).
The ICS network frame F901 generated by the above procedure reaches the access control device 9010-2 via the ICS network communication line 9030-1 and the relay device 9120-1, and is ICS decapsulated to become the ICS user frame F902. , The user 9400-2 with the ICS user address "3600" is reached via the ICS logical communication path 9051-3. Here, F902 = mTheσ, m = UF1TheP1TheP2, UF1 is the ICS user frame F900 before transmission, P1 is the time / place parameter, P2 is the electronic signature parameter, σ is the electronic signature, and σ = SIGN (KSa). , H (m)).
<< Digital signature and decryption in ICS decapsulation >> User 9400-3 sends an ICS user frame F930 having a sender ICS user address 3610 and a receiver ICS user address 2510 to the ICS logical communication line 9051-4. The access control device 9010-3 receives the ICS user frame F930, performs ICS encapsulation using the internal conversion table, generates the ICS network frame F931, and sends it to the ICS network communication line 9030-3. The ICS network frame F931 reaches the access control device 9010-1 via the central device 9120-1 and the ICS network communication line 9030-1, and is ICS decapsulated under the control of conversion table 9013-1 to be an ICS user. It becomes frame UF1. Since the encryption class is specified as "1" in the control unit of the ICS network F931, the ICS user frame (UF1) obtained by decapsulation is encrypted / decrypted by the encryption / decryption means 9018-1. Decrypt it to ICS user frame UF1 ́. If UF1 ́ = DEC (K2, UF1) and the encryption class is 0, decryption is not performed.
Next, since "1" is specified in the signature field of conversion table 9013-1 and "YES" is registered in the electronic signature field at the time of reception, the electronic signature unit 9017-11 operates here. , Parameters P1 and P2 and the electronic signature σ are added by the same method as described above, and a new ICS user frame F932 is obtained. Expressed in symbols, F932 = mTheσ, m = UF1TheP1TheP2, electronic signature σ = SIGN (KSa, h (m)), and UF1 ́ instead of UF1 when the above decoding is performed. In the above procedure, even if "1" is specified in the signature field of conversion table 9013-1, the electronic signature will not be given if "NO" is registered in the electronic signature field at the time of reception. .. The ICS user frame F932 reaches the user 9400-4 at the ICS user address 2510 via the line unit 9011-1 and the logical communication line 9051-4.
<< For signature request >> When the ICS user frame F940 with the sender ICS user address "2800" and the receiver ICS user address "3700" is input from the line section 9011-1, the request identification is "2" corresponding to the ICS network address "7728". , And "0" is registered in the signature column of the conversion table 9013-1 corresponding to the recipient ICS user address "3700", and "YES" is registered in the electronic signature column at the time of transmission. Then, since "1" is specified in the "signature request" field written at the predetermined position of the ICS user frame F940, the electronic signature unit 9017-1 operates, and the parameters P1 and P2 and the parameters P1 and P2 and the same as described above are operated. A new ICS user frame is added with the electronic signature σ.
If "0" or "1" is registered in the signature field of conversion table 9013-1 and "NO" is registered in the electronic signature field at the time of transmission, "1" is displayed in the signature request field of the ICS user frame. If specified, no digital signature is given prior to ICS encapsulation. Similarly, if "0" or "1" is registered in the signature field of conversion table 9013-1 and "NO" is registered in the digital signature field at the time of reception, "1" is registered in the signature request field of the ICS user frame. Even if is specified, the digital signature is not given after ICS decapsulation.
On the other hand, when the ICS user frame is digitally signed at the time of transmission by the transmitting side access control device and further digitally signed at the time of reception by the receiving side access control device, the electronic signature at the time of transmission and the electronic signature at the time of reception are obtained as shown in FIG. Granted. There are also other examples of including the value of the validation key KPa in the signature function parameter P2. By doing so, the recipient of the ICS user frame can save the trouble of obtaining the verification key KPa from the public key guidance service center or the like. Further, when the content of the ICS user frame is an electronic slip (order slip, receipt, etc.), an electronic signature is given to the electronic slip together with the identification name of the access control device through which the electronic slip has passed. When either the sender (creator) of the electronic slip or the recipient (receiver) of the electronic slip modifies the electronic slip, the alteration can be detected by the principle of the electronic signature. Therefore, as long as the digital signature key is a secret value, that is, as long as the operator of the access control device holding the signature key internally guarantees the signature key as a secret value, the digital signature is a public one that cannot be tampered with. Can be used as.
Example-22 (Digital Signature Server and Cryptographic Server): As shown in FIG. 86 of Example-21, the electronic signature unit 9017-1 and the encryption / decryption means 9018-1 are inside the access control device 9010-1. On the other hand, in this embodiment, as shown in FIG. 90, the access control devices 9310-1,9310-2,9310-3,9310-4 are examples in which the electronic signature unit is not included inside each of the access control devices 9310-1,9310-2,9310-3,9310-4. The digital signature server 9340-1,9340-2,9340-3,9340-4 and the ICS network communication line 9341-1,9341-2,9341-3,9341-4 are connected, respectively. Each digital signature server includes the function of the digital signature section of Example-21, and cooperates with an access control device to add a digital signature before ICS encapsulation, or a digital signature after ICS de-encapsulation. This is the same as the function of the electronic signature unit 9017-1 of Example-21, and includes a signature key, a verification key, an electronic signature function, a program module that realizes a hash function, a time / place parameter, and a signature function parameter. The electronic signature servers 9342-1 and 9342-2 are connected to the relay devices 9320-1 and 9320-2 via the ICS network communication lines 9344-1 and 9342-2, respectively. All digital signature servers have a unique ICS network address inside the ICS network, and use the ICS network server communication function to communicate with other digital signature servers and access control devices to exchange information held by each other. Has a function. The electronic signature server 9342-1 is a digital signature server that represents VAN9301-1, and is an internal electronic signature server 9340-1, of VAN9301-1. You can obtain the information held by these digital signature servers by communicating with 9340-2 using the ICS network server communication function. Further, the electronic signature server 9340-1 can obtain information (for example, a verification key) related to the electronic signature held by the electronic signature server 9340-12 via the electronic signature server 9342-1. The electronic signature server 9342-1 can communicate with another electronic signature server 9342-2 representing VAN9301-2 by using the ICS network server communication function, and can exchange information about the electronic signature held by each of them. The electronic signature server does not exchange the secret signature key held inside the electronic signature server with another electronic signature server, and strictly keeps the secret of the signature key.
Further, in this embodiment, as shown in FIG. 90, the access control devices 9310-1,9310-2,9310-3,9310-4 are examples in which the encryption / decryption means is not included inside, and instead, encryption is performed. It is connected to the server 9343-1,9343-2,9343-3,9343-4 by the ICS network communication line, respectively. Each cryptographic server includes the function of the encryption / decryption means 9018-1 and cooperates with the access control device connected to it to encrypt the ICS user frame before ICS encapsulation, or Decrypting the ICS user frame encrypted at the source after ICS de-encapsulation is the same as the encryption / decryption means 9018-1, and the encryption function and decryption function Includes a program module, encryption key, and decryption key that realizes. The cryptographic servers 9343-5 and 9343-6 are connected to the relay devices 9320-1 and 9320-2 via the ICS network communication line, respectively. Each cryptographic server has a unique ICS network address inside the ICS network, and uses the ICS network server communication function to communicate with other cryptographic servers and exchange the information held by each. Has the function of Cryptographic server 9343-5 is a cryptographic server that represents VAN9301-1, and communicates with the cryptographic servers 9343-1 and 9343-2 inside VAN9301-1 using the ICS network server communication function. However, the information held by these cryptographic servers can be obtained. In addition, the encryption server 9343-1 can obtain information about the encryption (for example, the encryption key) held by the encryption server 9343-2 via the encryption server 9342-5. Cryptographic server 9343-5 can communicate with other cryptographic servers 9343-6 representing VAN9301-2 using the ICS network server communication function, and exchange information about the cryptography held by each. it can.
Example-23 (open connection): ICS open connection, that is, the preparatory procedure performed by the user and the VAN operator in order to change the destination and perform business-to-business communication is explained.
<< User application >> The user applies for the ICS name and ICS user address to the VAN operator, and at the same time presents the ICS connection conditions, user identity and payment method (address, company name, payment bank account number, etc.). Also, if there is an ICS user address for in-house communication specified by the user, it will be presented, but if it is not, it will not be presented. The VAN operator decides the ICS name and the ICS user address according to the common rules set in advance with other VAN operators and informs the user. The items of ICS connection conditions include ICS name condition, communication band condition, billing condition, electronic signature condition, encryption condition, open area condition, dynamic change condition, etc. The contents of these conditions are as follows.
The ICS name condition is the left part of the ICS name, for example, if the ICS name is "USR # 1.ACS # 1.DIS # 1.VAN # 1.JP.AS", the user is the leftmost "USR # 1". Specify only (VAN operator decides the remaining right part). Communication band conditions are speed class and priority. The billing conditions are flat-rate charges for each fixed period, network usage charges (network charges), and charges for the contents of information sent and received by electronically signed communication (information charges), communication band conditions, electronic signature conditions, and encryption. It is set according to the conditions. The digital signature condition specifies whether or not to add a digital signature that can prove the fact that the ICS user frame has passed the access control device together with the date and time, and the encryption condition is whether to encrypt when the ICS user frame is transferred. Specify whether or not. The open condition is the inter-company communication service, that is, when the request identification "2" in the conversion table is used, the access control device rejects the reception when an ICS frame is received from an unknown sender not registered in the conversion table. It specifies whether or not, or whether or not to create a temporary conversion table and receive it. The dynamic change condition specifies a function that allows the user to change the above conditions according to the user's request through the ICS frame, and is specified by the open class. The method of specifying the value of the open area class will be described later. As for the dynamic change conditions, for example, signature conditions and encryption conditions can be changed, but important conditions for VAN operation such as ICS address and billing are not subject to change.
<< ICS Address Management Server and ICS Name Server >> Explaining with reference to FIGS. 91 and 92, in this embodiment, the access control device 11110-1,11110-2,11110-3, the relay device 11116-1, and the ICS address management server 11150- are described inside the ICS11000-1. Includes 1,11150-2, ICS name server 11160-1,11160-2, ICS conversion table server 11170-1,11170-2, user 11132-11, 11132-2. The ICS address management server 11150-2 includes the ICS network address 8210 and ICS user address 4200 of the user 11132-2 and the user's address-related information in the internal correspondence table, and the ICS name server 11160-2 is internal. ICS name conversion table of user 11132-2 includes "USR # 3.ACS # 3.DIS # 3.VAN # 3.JP.AS" of ICS name and "4200" of ICS user address. The VAN operator determines the ICS network address (7777) to be used in association with the ICS user address 3333 of user 11132-1, assigns it to the ICS logical terminal 11111-2 of the access control device 11110-1, and assigns it to the user. Connect the ICS logical communication path 11133-1, which is connected to 11132-1 via the gateway 11000-2. Since the ICS network address "7777" is a private value for the user, it is not notified to the user.
Next, the VAN operator can see the internal correspondence table 11152-1 of the ICS address management server 11150-1 with the ICS network address "7777", the ICS user address (between companies) "3333", and the user. Presented ICS user address (inside the company) "1111" and user address related information, that is, communication band condition, billing condition, electronic signature condition, encryption condition, open area condition, dynamic change condition, user identity and fee payment method , Directly write to Correspondence Table 11152-1 via Data Passage 11153-1 and Processing Device 11151-1. The VAN operator also added the ICS name USR # 1.ACS # 1.DIS # 1.VAN # 1.JP.AS specified above in the ICS name conversion table 11162-1 inside the ICS name server 11160-1. , ICS user address "3333", type "1" (ICS user address "3333" is listed inside ICS name conversion table 11162-1), data passage 11163-1 and processing device 11161-11 Write directly to the ICS name conversion table 11162-1 via. The above results are shown in Correspondence Table 11152-1 and ICS Name Conversion Table 11162-1.
When the ICS address management server 11150-1 and the ICS name server 11160-1 finish writing various information about the new user described above, they use the ICS network addresses "8910" and "8920" and the ICS network communication function, respectively. , ICS conversion table Notifies server 11170-1 that it has obtained information on the ICS address and ICS connection conditions for the new user. Here, the ICS conversion table server 11170-1 is a kind of ICS network server, and in this example, it has an ICS network address 8100 and an ICS user address 2100.
<< ICS conversion table server >> The ICS conversion table server 11170-1 reads the information described in the correspondence table 11152-1 of the ICS address management server 11150-1 using the ICS network communication function and writes it in the conversion table prototype 11172-1. That is, write "7777" in the outgoing ICS network address field, "1111" in the sender ICS user address (inside the company) field, and "3333" in the sender ICS user address (between companies) field. If there is no ICS user address for in-house communication, the sender ICS user address (inside the company) field will be blank. Request identification shall be "2", which represents inter-company communication. The communication band condition is an example of speed class "3" and priority "3", and the electronic signature condition is "1" for signature specification, "YES" for transmission signature, and reception signature. This is an example in which the specification is specified as "NO". The billing condition is "4" in the billing class, and in this example, it represents billing by a flat rate system. The encryption condition is the encryption class "1". In this example, the ICS network frame is specified to be encrypted inside the ICS. The open class of this example is 0. In this example, the dynamic change class "6" can change the signature at the time of transmission at the request of the user.
<< Using the ICS conversion table server (user) >> The user 11132-1 writes "3333" as the sender ICS user address and the ICS user address "2100" of the ICS conversion table server 11170-1 as the receiver ICS user address, and the recipient is written in the user data part of the ICS user frame. The ICS user frame F1200 in which the information (recipient ICS user address or recipient ICS name) is written is transmitted. The ICS conversion table server 11170-1 receives the ICS user frame F1200 via the access control device 11110-1, and whether the recipient information in the user data section is the recipient ICS user address or the recipient ICS name. Correspondingly, the incoming ICS network address for inter-company communication is acquired by the method described below. If the recipient ICS name is specified, the recipient ICS user address is further acquired.
(When the recipient ICS user address is specified) When the recipient information is the recipient ICS user address "3800", the ICS conversion table server 11170-1 uses the ICS network communication function for the ICS address management server 11150-1 connected to the access control device 11110-1. Inquire and obtain the ICS network address "7600" (incoming ICS network address) corresponding to the ICS user address "3800". If the recipient ICS user address is not included in the correspondence table 11152-1 (ICS network address search failure), the ICS conversion table server 11170-1 will start from the ICS address management server 11150-11 "Search for ICS network address". Receive "Failure Notification".
(When the recipient ICS name is specified) If the recipient information is the recipient ICS name "USR # 3.ACS # 3.DIS # 3.VAN # 3.JP.AS", the ICS conversion table server 11170-1 will use the same access control device 11110-. Send the ICS name "USR # 3.ACS # 3.DIS # 3.VAN # 3.JP.AS" to the ICS name server 11160-1 connected to 1 using the ICS network communication function. The ICS name server 11160-1 holds the ICS network addresses of other ICS name servers corresponding to the ICS name (the leftmost part of the ICS name excluding USR # n). In this example, ICS The name server 11160-1 searches the ICS name conversion table 11162-1 and finds the ICS network address of the ICS name server 11160-2 that manages "ACS # 3.DIS # 3.VAN # 3.JP.AS". 8930 is found, the address 8930 is inquired using the ICS network communication function, and the ICS user corresponding to the ICS name USR # 3.ACS # 3.DIS # 3.VAN # 3.JP.AS Acquire the address "4200" (recipient ICS user address) and the ICS network address "8210" (incoming ICS network address). In this procedure, the ICS name server 11160-2 inquires of the ICS address management server 11150-2 for the ICS network address of the user 11132-2 and acquires the address "8210".
(Completion of conversion table 11113-1) When the recipient ICS user address is specified, the ICS conversion table server 11170-1 adds the recipient ICS user address "3800" and the incoming ICS network address "7600" to the conversion table 11113-1, and the conversion table 11113-1 Complete the part corresponding to the receiving user. When the recipient ICS name is specified, the ICS conversion table server 11170-1 adds the recipient ICS user address "4200" and the incoming ICS network address "8210" to the conversion table 11113-1, and the conversion table 11113-1 Complete the part corresponding to the receiving user. If "Notification of ICS network address search failure" is received from ICS address management server 11150-1 or ICS name server 11160-1 in the above procedure, ICS conversion table server 11170-1 fails to add the conversion table. Is sent to the requesting user 11132-1.
<< Other uses of the ICS conversion table server (user) >> The user 11132-1 sends the user individual contents of the user individual contents to the ICS conversion table server 11170-1 by sending an ICS user frame in which a request for notifying the contents of the user individual correspondence of the conversion table 11113-1 is written to the ICS conversion table server 11170-1. Request to notify. Further, the user can request the rewriting of a part of the conversion table 11113-1 by using the dynamic change class previously agreed with the VAN operator by the above method. For example, the dynamic change class is 1,2, ..., the dynamic change class 1 is specified to increase the priority of each application user by 1, and the dynamic change class 2 is set to 1 priority. Decrease specification, dynamic change class 3 is specified to change the signature at the time of transmission to "YES" and the encryption class to "2".
<< Use of conversion table >> How to use the conversion table created in the above procedure was explained in Example-1 and the like. In Example 1, a method of creating a temporary conversion table, that is, a method of creating a temporary conversion table when the access control device receives an ICS network frame and decapsulates the ICS and there is no conversion table has been described. On the other hand, in this example, the open area class of the conversion table is used. That is, when the access control device receives the ICS network frame and decapsulates the ICS, the received "pair of the incoming ICS network address and the outgoing ICS network address included in the network control unit of the ICS network frame" is converted. If it is not registered as "a pair of outgoing ICS network address and incoming ICS network address" in the table and the open area class is specified as "2", it is set in the temporary conversion table as in the above embodiment, but it is open. If the region class is specified as "1", the temporary conversion table is not set. Furthermore, if the open class specification is "0", the temporary conversion table is not set and the received ICS network frame is discarded. In this case, the ICS user frame is not delivered to the user. That is, when the designation of the open class is "0", reception from an unknown sender not registered in the conversion table is rejected, and a so-called closed connection is realized. In the above, in the case of request identification "4", it is always treated as the designation "1" of the open area class. That is, it is not set in the temporary conversion table.
<< Cutting out a closed network using an open class >> When performing inter-company communication between companies A, B, and C, set all the IP terminal open class designations of these companies registered in the conversion table to "0". Then, all ICS user frames from unknown senders that are not registered in the conversion table are discarded by the access control device, so ICS user frames should be sent and received only between companies A, B, and C. become. In this sense, it is possible to construct a closed virtual closed network for these three companies, that is, to cut out the closed network. For one of the IP terminals of company A, if the open class of the conversion table is specified as "2", only this terminal receives the ICS user frame from an unknown sender, so the above It will be placed outside the closed network.
<< Partial change (variation) of the example >> In the above embodiment, the VAN operator inputs the ICS address, ICS connection conditions, etc. to the ICS address management server 11150-1 and the ICS name server 11160-1 using the data passage 11153-1 and the data passage 11163-1. The method was explained. The VAN operator creates a special ICS network server inside the ICS11000-1 without using these data passages, and from this special ICS network server, uses the ICS network communication function to create the ICS address management server 11150-11 and The ICS address, ICS connection conditions, etc. may be directly input to the ICS name server 11160-1 to rewrite the contents of the conversion table 11152-1 and the ICS name conversion table.
Example-24 (ICS address name management server): As shown in FIGS. 91 and 92 of Example-23, the ICS address management server and the ICS name server are independent of each other and are connected to the access control device via the ICS network communication line, respectively. On the other hand, in this embodiment, as shown in FIG. 93, the ICS address name management server 13000-1,13000-2,13000-3,13000-4 inside the ICS13000-1 is the access control device 13010-1, respectively. It is connected to 13010-2,13010-3,13010-4. The ICS address name management server 13000-1 has a processing device 130001-1, and has the same functions as those included in the ICS address management server of Example-23. Correspondence table 13002-1 and the equivalent that the ICS name server includes. It has an ICS name conversion table 13003-1 that has a function, and is given an ICS network address "9801" that can be uniquely distinguished from others inside the ICS.
Other ICS address name management servers 13000-2,13000-3,13000-4 also have the same functions as ICS address name management server 13000-1, including processing equipment, correspondence table and ICS name conversion table, respectively. They have ICS network addresses "9802", "9803", and "9804", respectively, and can communicate with each other using the ICS network communication function and exchange information held by other ICS address name management servers. The ICS address name VAN representative management server 13020-1 has an ICS network address "9805", and the other ICS address name VAN representative management server 13020-2 has an ICS network address "9806" and has an ICS network communication function. Can be used to communicate with a large number of ICS address name management servers and other ICS address name VAN representative management servers, and exchange their own information with each other. ICS address name VAN representative management server 13020-1 has processing device 13031-1 and database 13032-1, and exchanges information such as ICS address and ICS name with all ICS address name management servers inside VAN13000-1. , The collected ICS address and ICS name data are accumulated in database 13032-1, and by performing the above procedure, VAN13030-1 is represented.
The ICS address name management server includes a processing device, a correspondence table, and an ICS name conversion table. However, as another embodiment, the correspondence table and the ICS name conversion table may be combined into one table, and these may be combined. Only one of the ICS user addresses contained in both of the two types of tables needs to be used.
Example-25 (Separation of functions of access control device): As shown in FIGS. 91 and 92 of Example-23, the ICS address management server 11150-1, the ICS name server 11160-1, and the ICS conversion table server 11170-1 are connected to the access control device 11110-1, respectively. , ICS encapsulation and ICS decapsulation are performed inside the access control device 11110-1 using conversion table 11113-1. On the other hand, in this embodiment, the functions of the access control device 11110-1 are divided into the centralized access control device 14110-1 and a plurality of simple access control devices 14210-1,14210-2,14210-3. There is. That is, as shown in FIGS. 94 and 95, the access control device 11110-1 is a simple access control device 14210-1, 14210-2 via the ICS network communication lines 14190-1, 14190-2, 14190-3, respectively. , 14210-3 is connected. ICS address management server 14150-1, ICS name server 14160-1, ICS conversion table server 14170-1, ICS billing server 14180-1, electronic signature server 14181-1, encryption server 14182-1, operation management server 14183-1, The ICS network server 14184-1 is an aggregate access control device via the ICS network communication lines 14191-1, 14191-2, 14191-3, 14191-4, 14191-5, 14191-6, 14191-7, 14191-8, respectively. It is connected to 14110-1, and the conversion table 11113-1 inside the access control device 11110-1 is the aggregate conversion table 14113-1 and the simple conversion table 14213-1, 14213-2, It is divided into 14213-3. However, some of these aggregate conversion tables and simple conversion tables are duplicated. In other words, the four items of outgoing ICS network address, request identification, speed class, and priority are included in both of these conversion tables. The temporary partial conversion table 14214-1 is not essentially different from the temporary conversion table described in Example-1 and the like, but the items included in the temporary partial conversion table 14214-1 are included in the simple conversion table 14213-1. Same as the item. The line section 14211-1 inside the simple access control device 14210-1 has the same function as the line section 11111-1 inside the access control device 11110-1.
The simple access control device 14210-1 uses the simple conversion table 14213-1 to perform ICS encapsulation at the time of transmission and ICS decapsulation at the time of reception. Is used to perform processing related to electronic signatures and billing as described above. In addition, both of these plurality of simple access control devices 14210-1,14210-2,14210-3 and the centralized access control device 14110-1 function together to perform the same functions as the access control device 11110-1. User 14132-1 sends an ICS user frame F1300 having a sender ICS user address 3333 and a receiver ICS user address 4200 to the ICS logical communication line 14133-1. As shown in the flowchart of FIG. 96, the processing device 14212-1 of the simple access processing device 14210-1 receives the ICS user frame F1300 from the ICS logical terminal of the ICS network address 7777 of the line unit 14211-1 and ICS. Acquire the network address "7777" (step S2501) and check whether this address "7777" is registered as the virtual leased line connection "3" on the simple conversion table 14213-1 (step S2502). ). In this case, since it is not registered, the recipient ICS user address 4200 written on the ICS user frame F1300 corresponding to the ICS network address 7777 is acquired (step S2504), and this address 4200 is obtained. Is registered in the simple conversion table 14213-1, and further checks whether the request identification is registered as inter-company communication 2 (step S2505). In this case, since it is registered, the incoming ICS network address 8210 is obtained from the simple conversion table 14213-1 in preparation for ICS encapsulation (step S2506).
The simple access controller 14210-1 then generates an ICS network frame F1301 in which the speed class and priority are written based on the information obtained from the simple conversion table 14213-1 inside the ICS network frame. Encapsulate (step S2520) and send to the aggregate access controller (step S2521). Here, as described above, the information of the speed class 3, the priority 3, and the encryption class 0, which are the items of the simple conversion table 14213-1, is written in the extension part of the ICS network control unit.
The centralized access control device 14110-1 receives the ICS network frame F1301 from the simple access control device 14210-1, and based on the fact that this ICS network frame F1301 passes through the centralized access control device 14110-11, the billing information frame FK01 Is created and sent to the billing server 14180-1. Information such as request identification, speed class, priority, billing class, and encryption class of items registered in the aggregate conversion table 14113-1 is referred to in order to create the billing information frame FK01. The signature, the signature at the time of transmission, and the signature at the time of reception in the items of the aggregate conversion table 14113-1 are used to add the electronic signature, and as described in other embodiments, the electronic signature server 14181- Request 1 to digitally sign. Similarly, if the encryption class is specified as "1" which means encryption, it is requested to the encryption server 14182-1.
When the above processing is completed, the centralized access control device 14110-1 sends the ICS network frame F1302 to another access control device 14110-2 or the centralized access control device via the ICS network communication line 14190-4. The format of the ICS network frame F1302 changes when the electronic signature server or encryption server operates, as described above, due to the addition of the electronic signature or conversion to the ciphertext. Equivalent to ICS network frame F1301. The simple access control device 14210-1 can be realized with almost no changes to the functions of the existing router. In addition, when the number of users accommodated in the simple access control device 14210-1 is small and the users are widely distributed in the region. Has an economic advantage that the total number of ICS address management server, ICS name server, ICS conversion table server, billing server, digital signature server, and encryption server can be reduced.
The operation management server 14183-1 is assigned an ICS network address and is connected to the centralized access control device 14110-1 and the relay device. The ICS network communication function enables other operation management servers, access control devices, and ICS addresses. Exchanges information related to ICS operation such as communication status (communication congestion level, etc.) and failure information inside ICS with the management server.
By the way, the open class of the items included in the simple conversion table 14213-1 inside the simple access control device 14210-1 is the treatment of the open class registered in the conversion table inside the access control device as described above. Used for the same process. That is, when the simple access control device 14210-1 receives the ICS network frame and decapsulates the ICS, the received "pair of the incoming ICS network address and the outgoing ICS network address included in the ICS network frame control unit" is displayed. Specifying the open class when it is not registered as "pair of outgoing ICS network address and incoming ICS network address" in the simple conversion table 14213-1, that is, when the source of the received frame is not registered in the simple conversion table. If is "2", the temporary partial conversion table 14214-1 is set by the above method, but if the open area class is specified as "1", the temporary partial conversion table is not set. Furthermore, if the open class designation is "0", the temporary partial conversion table is not set and the received ICS network frame is discarded. This reconciliation does not send an ICS user frame to the user. 0 specified in the open area class rejects reception from an unknown source that is not registered in the simple conversion table, and realizes a so-called closed area connection.
As described in the above embodiment, the ICS address management server and the ICS name server may be integrated, that is, a single ICS address name management server may be realized, and the aggregate access control device is the ICS address name management server. Used by connecting to an ICS network communication line. Further, in the above embodiment, the speed class and priority items are not provided in the simple conversion table 14213-1, and at the time of ICS encapsulation, the speed class and priority 0 are set in the extension part of the ICS network control unit. It may indicate that there is no writing or designation. Similarly, an example in which the open area class is not specified in the simple conversion table 14213-1 may be used. In this case, the speed class and priority "0" are written in the extension of the ICS network control unit to indicate that there is no specification. ..
Example-26 (Access control device including server and centralized access control device): As shown in FIG. 97, the ICS15000-1 includes an access control device 15110-1,15110-2,15110-3 including a server, an aggregate access control device 15210-1,15210-2,15210-3 including a server, and a simple method. Includes access control devices 15213-1, 15213-2, 15213-3. In the examples of FIGS. 91 and 92, the ICS address management server 11150-1, the ICS name server 11160-1, and the ICS conversion table server 11170-1 are connected to the access control device 11110-1, respectively, and the examples of FIGS. 94 and 95 are shown. Then, ICS address management server 14150-1, ICS name server 14160-1, ICS conversion table server 14170-1, billing server 14180-1, electronic signature server 14181-11, and encryption server 14182-1 are aggregate access control devices 14110, respectively. It is connected to -1. On the other hand, in this embodiment, as shown in FIG. 97, the access control device 15110-1 has the ICS address management server 15115-1, the ICS name server 15115-2, and the ICS name server 15115-2 inside the same physically independent housing. Includes ICS conversion table server 15115-3, ICS frame database server 15115-4, billing server 15115-5, operation management server 15115-6, electronic signature server 15115-7, and encryption server 15115-8. However, these servers are assigned ICS network addresses "6701", "6702", "6703", "6704", "670", "6706", "6707", and "6708", respectively. -By using the communication function, information can be exchanged with the ICS network server outside the access control device 15110-1 including the server. The processing device 15112-1 can exchange information with the servers 15115-1 to 15115-8 via the data line 15117-1. Further, these servers 1515-1 to 15115-8 can exchange information with each other via the data line 15117-1.
Similarly, the centralized access control device 15210-1 including the server has the ICS address management server 15215-1, the ICS name server 15215-2, the ICS conversion table server 15215-3, inside the same physically independent chassis. Includes ICS frame database server 15215-4, billing server 15215-5, operation management server 15215-6, electronic signature server 15215-7, and encryption server 15215-8. However, these servers are assigned the ICS network addresses "7001", "7002", "7003", "7004", "7005", "7006", "7007", and "7008", respectively. With the server communication function, information can be exchanged with the ICS network server outside the centralized access control device 15210-1 including the server. The processing device 15212-1 can exchange information with the servers 15215-1 to 15215-8 via the data line 15217-1. Further, the servers 15215-1 to 15215-8 can exchange information with each other via the data line 15217-1. In the above description, the same physically independent housing means, for example, a stand-alone computer, a single electronic board, or an LSI. In the case of LSI, the centralized access device including the server is realized as a system on the LSI chip.
The ICS frame database server or other servers may be excluded from the "access control device including the server". Similarly, the ICS frame database server or other servers may be excluded from the "aggregated access control device including the server". In the case of each of these embodiments, for example, an access control device including an ICS frame database server and a server, or an aggregate access control device including a server is connected via an ICS network communication line.
Example-27 (Incoming call priority control): The control unit in the IP frame shown in FIG. 152 includes a source IP address and a destination IP address in addition to the protocol type, and inside the TCP frame shown in FIG. 98 and the UDP frame shown in FIG. 99. Is defined as a source port number and a destination port number, respectively. The 48-bit data in which the IP address (32 bits) and the port number (16 bits) are arranged is called the socket number. That is, socket number = IP address The port number. In this embodiment, it is called source socket number = source IP address The source port number, destination socket number = destination IP address The destination port number. In this embodiment, the access control device is reached from the ICS network communication line, and the ICS user frame obtained by decapsulating the access control device is used for the "protocol type" and the socket number displayed inside the ICS user frame. This is an example of controlling the priority of the order of sending to the outside of ICS.
"Constitution" As shown in FIGS. 100 and 101, the ICS17000-1 includes an access control device 17100-1,17110-1,17120-1,17130-1,17140-1,17150-1,17160-1. 17100-1 includes the line unit 17111-1, the processing device 17112-1, and the conversion table 17113-1. 17200-1,17210-1,17220-1,17230-1,17240-1,17250-1,17260-1,17270-1,17280-1 are LAΝ of each company, and their respective gateways 17201-1, It is connected to ICS17000-1 via 17211-1,17221-1,17231-1,17241-1,17251-1,17261-1,17271-1,17281-1. Each LAN contains 2 to 3 terminals that have the function of sending and receiving IP user frames, and these ICS user addresses are "2600" and "2610" inside LAN17200-1 and "1230" inside LAN17210-1. , "1240", LAN17220-1 inside is "2700", "2710" and "2720", LAN17230-1 inside is "2800" and "2810", LAN17240-1 inside is "2100" "And" 2110 ", the inside of LAN17250-1 is" 1200 "," 1210 "and" 1220 ", the inside of LAN17260-1 is" 2200 "and" 2210 ", and the inside of LAN17270-1 is" 2300 ". And "2310", and the inside of LAN17280-1 is "2400" and "2410". Furthermore, 17291-1 and 17292-1 are terminals having the function of sending and receiving IP user frames, respectively, and each has an ICS user address. It has "2500" and "1250" and is connected to ICS17000-1.
Conversion table>> The conversion table 17113-1 inside the access control device 17100-1 will be described with reference to FIG. 102. The function of the conversion table is the same as that of other examples. In this example, the part that is a component of conversion table 17113-1 named the incoming call priority symbol, protocol priority, TCP socket priority, and UDP socket priority. The feature is to control the priority using a table. If the outgoing ICS network address in the conversion table is "7821", the incoming priority symbol is defined as "pr-7821". That is, the incoming call priority is defined to be a parameter that depends on the ICS network address assigned to the ICS user logical terminal that the access control device sends after ICS decapsulation. Looking at the other subtables of conversion table 17113-1, for example, corresponding to "pr-7821", the protocol priority is "p-1", the TCP socket priority is "t-1", and the UDP socket priority. Is described as "NULL". Here, "NULL" represents no specification. The protocol priority "p-1" is defined as "TCP", "UDP", "ICMP", and "IGMP" in descending order of priority.
Looking at the other subtables, the TCP socket priority "t-1" defines the socket symbols "sk-1" and "sk-7" in descending order of priority. UDP socket priority "u-" Looking at the other sub-tables, "1" defines "sk-3" and "sk-8" in descending order of priority. Furthermore, the socket symbol "sk-" written in the other sub-tables. In the content of "1", "To" indicates that the destination socket number, the destination IP address is "2100", the destination port number is "30", and similarly, the socket symbol "sk-2". In the content of "," "From" indicates that the source socket number is "1240" and the source port number is "32".
ICS Fre separate description of over-time" The ICS network frame NF01 was sent from the terminal 17291-1 with the ICS user address "2500", and then ICS-encapsulated as the outgoing ICS network address "7200" and the incoming ICS network address "7821" by the access control device 17110-1. It is transferred inside the ICS17000-1 to reach the access control device 17100-1, where it is decapsulated to become the ICS user frame UF01, and the ICS user address via the user logical communication line 17821-1. Reach the 2100 terminal. The "protocol type" of the control unit of the user frame UF01 inside the ICS network frame NF01 is TCP, and the "destination port number" of the TCP frame is "30". Hereinafter, the ICS network frames NF02 to NF03, NF04, NF05, NF06, NF07, NFO8, NF09, NF10, and NF11 are the same as shown in FIG. 115, and will be briefly described below.
The frame NF02 is sent from the terminal with the address "2600" and is ICS-encapsulated as the outgoing ICS network address "7300" and the incoming ICS network address "7821". It becomes UF02 and reaches the terminal with ICS user address "2110" via the user logical communication line 17821-1. This is an example in which the protocol type of frame UF02 is TCP and the destination port number is 30.
The frame NF03 is sent from the terminal with the address "1230" and is ICS-encapsulated as the outgoing ICS network address "7400" and the incoming ICS network address "7822". It becomes UF03 and reaches the terminal with ICS user address "1200" via the user logical communication line 17822-1. This is an example in which the protocol type of frame UF03 is TCP and the source port number is 30.
The frame NF04 is sent from the terminal with the address "1240" and is ICS-encapsulated as the outgoing ICS network address "7400" and the incoming ICS network address "7822". It becomes UF04 and reaches the terminal with ICS user address "1210" via the user logical communication line 17822-1. This is an example in which the protocol type of frame UF04 is TCP and the source port number is 32.
The frame NF05 is sent from the terminal with the address 1250 and is ICS-encapsulated as the outgoing ICS network address 7500 and the incoming ICS network address 7822. It becomes UF05 and reaches the terminal with ICS user address "1220" via the user logical communication line 17822-2. This is an example in which the protocol type of frame UF05 is TCP and the source port number is 32.
The frame NF06 is sent from the terminal with the address "2610" and is ICS-encapsulated as the outgoing ICS network address "7300" and the incoming ICS network address "7823". It becomes UF06 and reaches the terminal with ICS user address "2200" via the user logical communication line 17823-1. The "protocol type" of frame UF06 is UDP, and the "destination port number" is "40".
The frame NF07 is sent from the terminal with the address "2700" and is ICS-encapsulated as the outgoing ICS network address "7600" and the incoming ICS network address "7823". It becomes UF07 and reaches the terminal with ICS user address "2210" via the user logical communication line 17823-1. The "protocol type" of frame UF07 is UDP, and the "destination port number" is "40".
The frame NF08 is sent from the terminal with the address "2710" and is ICS-encapsulated as the outgoing ICS network address "7600" and the incoming ICS network address "7824". It becomes UF08 and reaches the terminal with ICS user address "2300" via the user logical communication line 17824-1. The "protocol type" of frame UF08 is UDP, and the "source port number" is "40".
The frame NF09 is sent from the terminal with the address "2800" and is ICS-encapsulated as the outgoing ICS network address "7700" and the incoming ICS network address "7824". It becomes UF09 and reaches the terminal with ICS user address "2310" via the user logical communication line 17824-1. The "protocol type" of frame UF09 is UDP, and the "source port number" is "42".
The frame NF10 is sent from the terminal with the address "2720" and is ICS-encapsulated as the outgoing ICS network address "7600" and the incoming ICS network address "7825". It becomes UF10 and reaches the terminal with ICS user address "2400" via the user logical communication line 17825-1. This is an example where the "protocol type" of frame UF10 is TCP and the "destination port number" is "60".
The frame NF11 is sent from the terminal with the address "2810" and is ICS-encapsulated as the outgoing ICS network address "7700" and the incoming ICS network address "7825". It becomes UF11 and reaches the terminal with ICS user address "2410" via the user logical communication line 17825-1. The "protocol type" of frame UF11 is UDP, and the "source port number" is "70".
<< Example of priority determination 1 >> A method of determining the priority will be described with reference to the flowchart of FIG. 103. The access control device 17100-1 receives the ICS network frames NF01 and NF02 from the ICS network communication line at approximately the same time (step S1000), and reverse-encapsulates each network frame to obtain the ICS user frames UF01 and UF02 (step). S1010). From the conversion table 17113-1, it can be seen that the incoming ICS network addresses of the ICS logical terminals that transmit these ICS user frames are both 7821 and match (step S1020). The incoming priority symbol for both ICS network frames NF01 and NF02 is "pr-7821", and then the protocol priority corresponding to "pr-7821" is "p-1" according to the subtable of conversion table 17113-1. , TCP socket priority is specified as "t-1", and UDP socket priority is specified as "NULL". Further examination of the other parts of the conversion table 17113-1 reveals that the protocol priority TCP, UDP, ICMP, IGMP have the highest priority from the breakdown of "p-1", and for TCP with the highest priority, the socket symbol "sk-1", from the breakdown of TCP socket priority "t-1", The priority is higher in the order of "sk-7", and from the breakdown of the socket symbol "sk-1", it can be seen that the IP address constituting the destination socket number is "2100" and the destination port number is "30". The protocol type displayed inside the ICS network frame NF01 is "TCP", the destination IP address is "2100", and the destination port number is "30". On the other hand, the protocol type displayed inside the ICS network frame NF02 is "TCP", the destination IP address is "2110", and the destination port number is "30". In this embodiment, it can be seen that the protocol type and the destination socket number match the designation of the socket symbol sk-1 in the ICS network frame NF01.
Through the above procedure, it is determined that the ICS network frame to be sent preferentially is NF01 (step S1030). Next, this ICS network frame NF01 is sent to the user logical terminal via the ICS logical terminal (step S1040).
<< Example 2 of priority determination >> The access control device 17100-1 receives the ICS network frames NF03, NF04 and NF05 from the ICS network communication line at approximately the same time (step S1000), reverse-encapsulates each network frame, and receives the ICS user frames UF03, UF04, UF05. Get (step S1010). From the conversion table 17113-1, it can be seen that the incoming ICS network addresses of the ICS logical terminals that transmit these ICS user frames are both 7822 and match (step S1020). The incoming priority symbol for ICS network frames NF03, NF04 and NF05 is "pr-7822", the protocol priority is "P-1", the TCP socket priority is "t-2", and the UDP socket priority is "NULL" is specified. Protocol priority From the breakdown of "p-1", TCP has a high priority, from the breakdown of TCP socket priority "t-2", the priority of socket symbol "sk-2" is high, and the breakdown of socket symbol "sk-2". It can be seen from that that the IP address that constitutes the source socket number is "2100" and the source port number is "30". The protocol type displayed inside the ICS network frame NF03 is "TCP", the source IP address is "1230", and the source port number is "30". The protocol type displayed inside the ICS network frame NF04 is "TCP", the source IP address is "1240", and the source port number is "32". Furthermore, the protocol type displayed inside the ICS network frame NF05 is "TCP", the source IP address is "1250", and the source port number is "32". In this embodiment, it can be seen that the protocol type and the source socket number match the designation of the socket symbol sk-2 in the ICS network frame NF04.
By the above procedure, it is determined that the ICS network frame to be preferentially transmitted is NF04 (step S1030). Next, this ICS network frame NF04 is sent to the user logical terminal via the ICS logical terminal (step S1040).
<< Example 3 of priority determination >> The access control device 17100-1 receives the ICS network frames NF06 and NF07 from the ICS network communication line at approximately the same time (step S1000), and reverse-encapsulates each network frame to obtain the ICS user frames UF06 and UF07 (step S1010). ). From the conversion table 17113-1, it can be seen that the incoming ICS network addresses of the ICS logical terminals that transmit these ICS user frames are both 7823 and match (step S1020). .. For both ICS network frames NF06 and NF07, the incoming priority symbol is "pr-7823", the protocol priority is "p-2", the TCP socket priority is "NULL", and the UDP socket priority is "u-1". Is specified. From the breakdown of protocol priority "p-2", UDP, TCP, ICMP, IGMP have the highest priority, and for the UDP with the highest priority, the socket symbol "sk-" from the breakdown of UDP socket priority "t-1". The priority is higher in the order of "3" and "sk-8", and from the breakdown of the socket symbol "sk-3", the IP address that constitutes the destination socket number is "2200" and the destination port number is "40". I understand. The protocol type displayed inside the ICS network frame NF06 is "UDP", the destination IP address is "2200", and the destination port number is "40". On the other hand, it is displayed inside the ICS network frame NF07. The protocol type is "UDP", the destination IP address is "2110", and the destination port number is "40". In this embodiment, the protocol type and the destination socket number match the designation of the socket symbol "sk-3". It can be seen that the ICS network frame NF06 is to be used. By the above procedure, it is determined that the ICS network frame to be sent with priority is NF06 (step S1030). Next, this ICS network frame NF01 is set. Send to the user logical terminal via the ICS logical terminal (step S1040).
<< Example 4 of priority determination >> The access control device 17100-1 receives the ICS network frames NF08 and NF09 at approximately the same time (step S1000), and decapsulates each network frame to obtain the ICS user frames UF08 and UF09 (step S1010). From the conversion table 17113-1, it can be seen that the incoming ICS network addresses of the ICS logical terminals that transmit these ICS user frames are both 7824 and match (step S1020). For both ICS network frames NF08 and NF09, the incoming priority symbol is "pr-7824", the protocol priority is "p-2", the TCP socket priority is "NULL", and the UDP socket priority is "u-2". Is specified. From the breakdown of the protocol priority "p-2", the priority of the socket symbol "sk-4" is high, and from the breakdown of the socket symbol "sk-4", the IP address that constitutes the source socket number is "2710". You can see that the source port number is "40". The protocol type displayed inside the ICS network frame NF08 is "UDP", the source IP address is "2710", and the source port number is "40". On the other hand, the protocol type displayed inside the ICS network frame NF09 is "UDP", the source IP address is "2800", and the source baud number is "42". In this embodiment, it can be seen that it is the ICS network frame NF08 that the protocol type and the source socket number match the designation of the socket symbol sk-4.
Through the above procedure, it is determined that the ICS network frame to be sent preferentially is NF08 (step S1030). Next, this ICS network frame NF01 is sent to the user logical terminal via the ICS logical terminal (step S1040). << Example 5 of priority determination >> The access control device 17100-1 receives the ICS network frames NF10 and NF11 at approximately the same time (step S1000), and decapsulates each network frame to obtain the ICS user frames UF10 and UF11 (step S1010). From the conversion table 17113-1, it can be seen that the incoming ICS network addresses of the ICS logical terminals that transmit these ICS user frames are both 7825 and match (step S1020). The incoming priority symbol for both ICS network frames NF10 and NF11 is "pr-7825", the protocol priority is "p-1", the TCP socket priority is "t-3", and the UDP socket priority is "u-3". Is specified. From the breakdown of protocol priority "p-1", TCP has a higher priority than UDP. However, the protocol type displayed inside the ICS network frame NF10 is "TCP", and the protocol type displayed inside the ICS network frame NF11 is "UDP".
Through the above procedure, it is determined that the ICS network frame to be sent preferentially is NF10 (step S1030). Next, this ICS network frame NF10 is sent to the user logical terminal via the ICS logical terminal (step S1040).
Example-28 (outgoing priority control): An example will be described in which a user IP frame arriving from outside the ICS is encapsulated in the ICS by an access control device, and then the order of sending to the ICS network communication line is determined.
"Constitution" As shown in FIG. 104, the ICS17000-2 includes the access control device 17100-2,17110-2, ..., 17190-2, and the access control device 17100-2 includes the line section 17111-2 and the processing device 17112-2. , Includes conversion table 17113-2. 17240-2, ..., 17280-2 are corporate LANs, which are connected to ICS17000-2 via ICS user logical communication lines. Each LAN includes a plurality of IP terminals, and 17401-2 to 17411-2 are all IP terminals.
Conversion table>> The functions of conversion table 17113-2 shown in FIG. 105 are the same as those of other examples. In this example, conversion table 17113- named as outgoing priority symbol, protocol priority, TCP socket priority, and UDP socket priority. It is characterized by using a subtable, which is a component of 2. If the outgoing ICS network address in conversion table 17113-2 is "7821", the outgoing priority symbol is defined as "ps-7821". That is, the outgoing priority is set to be a parameter depending on the network address assigned to the ICS logical terminal that accepts the user IP frame arriving at the access control device from the user logical communication line. Looking at the other subtables of conversion table 17113-2, for example, the protocol priority is "p-21", the TCP socket priority is "t-21", and the UDP socket priority is "ps-7821". It is described as "NULL". Notations such as protocol priority, TCP socket priority, and UDP socket priority are the same as in Example 32.
<< Example 1 of priority determination >> A method of determining the priority will be described with reference to the flowchart of FIG. The access control device 17100-2 receives the ICS user frames F01 and F02 from the ICS logical terminal of the line unit 17111-2 to which the ICS network address "7821" is assigned at approximately the same time, and is assigned to the ICS logical terminal. Obtain the ICS network address that is being used (step S2700). Next, the procedure for controlling the outgoing priority is performed as follows. The outgoing priority symbol of both ICS user frames F01 and F02 is "ps-7821", and then the protocol priority corresponding to "ps-7821" is "p-21" according to the subtable of conversion table 17113-2. , TCP socket priority is specified as "t-21", and UDP socket priority is specified as "NULL". Further examination of other parts that are components of conversion table 17113-2 shows that TCP, UDP, ICMP, and IGMP have the highest priority in the order of protocol priority "p-21", and TCP has the highest priority. , TCP socket priority "t-21", socket symbols "sk-21", "sk-27" in that order, and socket symbol "sk-21" breakdown, source socket number It can be seen that the IP address that composes is "2100" and the source port number is "30". The protocol type displayed inside the ICS user frame F01 is "TCP", the source IP address is "2100", and the source port number is "30". On the other hand, the protocol type displayed inside the ICS user frame F02 is "TCP", the source IP address is "2110", and the source port number is "30". In this embodiment, it can be seen that it is the ICS user frame F01 that the protocol type and the source socket number match the designation of the socket symbol sk-21. Based on the above, it is determined that the ICS user frame that is encapsulated in ICS and sent with priority is F01 (step S2710). Next, whether or not the ICS network address 7721 assigned to the logical terminal that received the ICS user frame F01 is registered as the virtual leased line connection 3 on the conversion table 17113-2. Examine (step S2720). The following is shown in a series of steps S2730, ..., S2770 similar to those described in the other examples, and finally ICS encapsulation was performed (step S2780), and the ICS network obtained by encapsulation was performed. Priority is given to frame NF01 and transmitted into ICS17000-2 (step S2790). << Other examples of priority determination >> An example of priority determination in which the access control device 17100-2 receives ICS user frames F03, F04, and F05 at approximately the same time from the ICS logical terminal of the line section 17111-2 to which the ICS network address "7822" is assigned. For 2, the access control device 17100-2 determines the priority of receiving the ICS user frames F06 and F07 at approximately the same time from the ICS logical terminal of the line section 17111-2 to which the ICS network address "7823" is assigned. Also in Example 3, the access control device 17100-2 receives the ICS user frames F08 and F09 at approximately the same time from the ICS logical terminal of the line section 17111-2 to which the ICS network address 7824 is assigned. In Example 4 of priority determination, the access control device 17100-2 has almost the same ICS user frames F10 and Fll from the ICS logical terminal of the line section 17111-2 to which the ICS network address "7825" is assigned. Example 5 of priority determination received at time is the same as that of example 1 of priority determination, as shown in the subtable which is a component of conversion table 17113-2, and the description thereof will be omitted.
Example-29 (plural communication): This example is a new example configured by combining the above-mentioned Examples-2, -10, -18, and will be described with reference to FIGS. 102 to 109. ICS18000-1 includes access control units 18140-1,18141-1,18142-1 and 18143-1,18144-1. The conversion table inside access control unit 18140-1 is 18195-1, access control unit 18141-1. The internal conversion table is 18196-1. Conversion table 18195-1 includes the specified values 1, 2, 3, and 4 for request identification, as in conversion table 6013-1, and corresponds to intra-company communication and inter-company communication. , Virtual leased line connection and ICS network server connection can be implemented inside one access control device. Conversion table 18196-1 shows only the specified value "3" for request identification, enabling virtual leased line connection.
The ICS network server 18160-1 is connected to the access control device 18140-1 via the ICS network communication line. 18184-1 is an FR network or an ATM network, and if 18184-1 is an FR network, it corresponds to FR network 1041 shown in Fig. 35, and if 18184-1 is an ATM network, it corresponds to ATM network 1042 shown in Fig. 35. Corresponds to. The conversion units 18181-1 and 18182-1 correspond to the FR / ICS network frame conversion unit 1032-1 shown in FIG. 35 when 18184-1 is an FR network. Further, in the conversion units 18181-1 and 18182-1, 18184-1 corresponds to the ATM / ICS network frame conversion unit 1033-1 shown in FIG. 35 for the ATM network.
LAN18110-1,18130-1 are connected to access control devices 18140-1 and 18142-1 via ICS user logical communication lines, respectively. The gateways 18171-1 and 18172-1 of LAN 18120-1 are connected to the access control device 18140-1 or 18141-1 via the ICS user logical communication line, respectively. LAN18120-1 includes a plurality of IP terminals 18121-1,18122-1,18123-1. Here, the IP terminal refers to a terminal having a function of sending and receiving IP user frames. The IP terminals 18150-1 and 18151-1 are connected via the access control device 18143-1, 18144-1 and the ICS user logical communication line, respectively. The ICS network communication line 18191-1 connects the conversion unit 18181-1 and the access control device 18141-1, and the ICS network communication line 18192-1 connects the conversion unit 18182-1 and the access control device 18142-1.
When the ICS user frame transmitted from LAN18120-1 or LAN18110-1 reaches the access controller 18140-1, the request identification values 1, 2, 3, listed in the conversion table 18195-1 According to the control of "4", it is ICS-encapsulated to receive the communication service of intra-company communication, inter-company communication, virtual leased line, or ICS network server, but the details are explained in other examples. It is a street and is omitted. When the ICS user frame transmitted from the gateway 18172-1 reaches the access control device 18141-1, the communication service of the virtual dedicated line follows the control of the request identification value "3" shown in the conversion table 18196-1. It is encapsulated in ICS so that it can be received, via the ICS network communication line 18191-1, via the conversion unit 18181-1, further via the FR network or ATM network 18184-1, via the conversion unit 18182-1, and then through the ICS network. It is delivered to the access control device 18142-1 via the communication line 18192-1. Here, the FR network to the ATM network 18184-1 uses the function of the other party fixed connection (PVC), which is a known technology as the function of the FR network to the ATM network. By the procedure described above, the transfer of ICS user frames is realized.
<< Partial change of the above example: Variation >> This will be described with reference to FIG. 110. Like 8000-1800-1, the ICS18000-2 includes multiple access control devices and is connected to LAN and IP terminals through the access control devices. The FR network to ATM network 18184-1 in Fig. 107 is replaced with the FR network to ATM network 18200-2, and the access control device 18141-1, conversion unit 18181-1, and ICS network communication line 18191-1 are replaced with PVC interface conversion unit 18210-. Replaced with 2, access control device 18142-1, conversion unit 18182-1, ICS network communication line 18192-1 replaced with PVC interface conversion unit 18220-2, and gateways 18171-1 and 18172-1 replaced with new gateway 18230- It is replaced with 2. Here, when 18200-2 is an FR network, the PVC interface conversion units 18210-2 to 18220-2 are functions for converting and inversely converting the ICS user frame to the FR frame format, and this conversion and inverse conversion function. Is as explained in Figure 39. If the 18200-2 is an ATM network, the PVC interface converters 18210-2 to 18220-2 are functions for converting and inversely converting ICS user frames to the ATM frame format. As explained in FIG. 40. The transfer of ICS user frames by this variation is realized by using the function of the other party fixed connection (represented by PVC) by the FR network or ATM network.
Example-30 (Operation of integrated information communication system): This will be described with reference to FIGS. 111 and 112. ICS19000-1 is VAN19010-1, VAN19020-1, access control device 19300-1,19310-1,19320-1,19330-1, relay device 19400-1,19410-1,1942O-1,19430-1, Includes inter-VAN gateway 19490-1, server equipment 19500-1,19510-1,19520-1,19530-1,19540-1. Each server device is assigned an ICS network address, and includes a plurality of ICS network servers inside each server device. These multiple ICS network servers are distinguished by the port number used in the TCP communication protocol and the UDP communication protocol. The access control devices 19300-1, 19310-1, 19320-1, and 19330-1 are shown in the conversion tables 19301-1, 19311-1, respectively. Includes 19321-1 and 19331-1, including conversion table servers 19731-1,19732-1,19733-1,19734-1, respectively, and domain name servers 19741-1,19742-1,19743-1, respectively. 19744-1 is included, resource management servers 19751-1, 19752-1, 19753-1, 19754-1 are included, respectively, and relay device 19400-1 includes route information server 19761-1 and resource management server 19755-1. The relay device 19410-1 includes the route information server 19762-1, the relay device 19420-1 includes the route information server 19763-1, and the relay device 19430-1 includes the route information server 19764-1, and the server device 19500-1. Includes user service server 19711-1, ICS authority server 19721-1, server device 19510-1 includes centralized resource management server 19750-1, centralized route information server 19760-1, and server device 19520-1 is user service server. Including 19712-1, ICS authority server 19722-1, server device 19530-1 has ICS network server 19980-1 which has ICS user address "1200" and performs electronic library service, and ICS user address "1300". Including the ICS network server 19981-1 that provides travel guidance services, the server device 19540-1 is the centralized ICS authority server 19720-1, the centralized domain name server 19740-1, the centralized conversion table server 19730-1, and the centralized user service. Includes server 19710-1. The domain name server is a server having the same functions as the ICS address management server and the ICS name server described in the other examples, and has different functions, and the details of the functions are defined in this embodiment.
The access control device, relay device, server device, and gateway between VANs described above are connected by the ICS network communication line 19040-1,19041-1,19042-1,19043-1, etc., and are connected to each other by using the ICS network communication function. Information can be exchanged. A server device is created, for example, by giving a computer an ICS network communication function, and a program that executes the server function runs inside the server device.
19110-1 is an FR network, and conversion units 19111-1 and 19112-1 perform interface conversion between the communication line of the FR switching network and the ICS network communication line that transfers ICS network frames. It is the same as that described in the Example of. In addition, 19900-1 is an ATM network, and the conversion units 19901-1 and 19902-1 perform interface conversion between the communication line of the ATM switching network and the ICS network communication line that transfers ICS network frames. Is similar to that described in the other examples.
Outside the ICS19000-1, LAN19600-1,19601-1, 19602-1,19603-1, 19604-1,19605-1, and IP terminals 19606-1, 19607-1 that have the function of sending and receiving ICS network frames. Is an example in which is connected.
<< Hierarchical structure of ICS network server >> This will be described with reference to FIGS. 113 to 118. The centralized user service server 19710-1 is the user service server 19711-1, It has a higher control right in the sense of giving instructions to 19712-1 or making individual information reported, and the meaning of the higher control right is illustrated in a tree structure in FIG. 113. 19811-1 is a communication path for exchanging information between the centralized user service server 19710-1 and the user service server 19711-1, and consists of an ICS network communication line and a relay device. The same applies to the centralized ICS authority server 19720-1, the centralized conversion table server 19730-1, the centralized domain name server 19740-1, the centralized resource management server 19750-1, and the centralized route information server 19760-1, respectively. Shown in. In this embodiment, the tree structure of the server has two layers, but the number of access control devices, relay devices, server devices, etc. installed inside the ICS may increase to three or more layers. The route information server has a function to send and receive the route table used in the relay device and the access control device inside the ICS. The resource management server is provided with management functions such as grasping the installation status and failure information of relay devices, access control devices, and server devices.
<< Operation of ICS19000-1 by ICS operator >> The ICS operators 19960-1 and 19961-1 instruct the centralized user service server 19710-1, the centralized conversion table server 19730-1, the centralized resource management server 1950-1, and the centralized route information server 19760-1 to start operation. The operation of ICS19000-1 can be easily performed by giving or reporting individual information.
<< Management of ICS19000-1 by ICS officials >> The ICS official 19950-1 manages the addresses used in the ICS19000-1 by giving instructions such as starting operation to the central ICS authority server 19720-1 and the central domain name server 19740-1, or by having them report individual information. It can be done easily.
<< Socket number and server >> The ICS network server has an ICS user address and an ICS network address, respectively, and it is added to other embodiments that each server has a port number specified by a TCP or UDP communication protocol in addition to the ICS network address. It is a matter to be done. That is, each server is identified by a 32-bit ICS network address and a 16-bit port number, which is a total of 48 bits (this is called a socket number). Each server contains a program having a unique function that works inside the ICS19000-1, and some servers have an "operation interface" as described later. Here, the "operation interface" is a function for exchanging information with the operator via a keyboard or the like, and sending and receiving commands such as operation and operation start of each server function. Each server assigns an ICS network address to, for example, an access control device or a relay device, assigns different port numbers to a plurality of programs (that is, servers) inside these devices, and distinguishes them by socket numbers. Each server has an ICS network communication function as described in another embodiment, and can exchange information with each other using an ICS network address and a port number.
<< User registration with ICS-1: Interprocess communication and ICS network server >> This will be described with reference to FIGS. 111, 112, and 119. ICS19000-1 user applicant 19200-1 applies for ICS subscription to ICS receptionist 19940-1 (procedure P100). "Application acceptance data" is an ICS usage item excluding the ICS user address ICS network address and ICS name. For example, request identification (intra-company communication, inter-company communication, virtual leased line connection, classification of ICS network server) and speed. Communication band conditions such as class and priority, billing conditions, open connection conditions, toll payment methods, user address and name (identification data), signature conditions, encryption conditions, etc., and the meaning of these usage items is other implementation. It is explained by an example.
The ICS receptionist 19940-1 inputs the application reception data to the user service server 19711-1 via the operation interface, and stores the application reception data in the user database 19611-1 (procedure P110). Next, the user service server 19711-1 requests the ICS authority server 19721-11 for its ICS user address, ICS network address, and ICS name using the ICS network communication function (procedure P120). The ICS authority server 19721-1 holds the requested ICS address and ICS name inside the database 19621-1. ICS network address allocation record table 19622-1 (Fig. 120), ICS user address allocation. Allocation is performed using the record table 19623-1 (Fig. 121) (procedure P130), the allocation result is recorded in the allocation table, and the allocation result is returned to the user service server 19711-1 (procedure P140). The user service server 19711-11 stores the allocation result obtained from the ICS authority server 19721-1 in the user database 19611-1 (procedure P150).
Figure 135 is an example of the ICS network address allocation record table 19622-1. In the first row of this table, the ICS network address 7700 is the node identification symbol ACU-1 and the ICS logical terminal identification symbol LT- Assigned to 001, the allocation destination identification symbol is "user-1", the allocation date is an example of "April 1, 1998", and the node identification symbol ACU-1 points to the access control device 19300-1. That is predetermined. In addition, in the third row of this table, the ICS network address "9630 is assigned to the port number" 620 "of the node identification code SVU-1, the allocation destination identification code is" Sv-001 ", and the allocation date. Is an example of "February 1, 1998", and it is predetermined that the node identification symbol SVU-1 refers to the server device 19530-1.
Figure 121 is an example of the ICS user address allocation record table. In the first row name of this table, the ICS user address 4610 and the ICS name (also called the ICS domain name) ddl.ccl.bbl.aal. This is an example of assigning "jp", the value of the request identification is "2", the allocation destination identification symbol is "user-1", and the allocation date is "April 1, 1998". Furthermore, in the 4th row of this table, the ICS name "rrl.qq.pp.jp" is assigned to the ICS user address "1200", and the request identification value is "4". The identification code is "Sv-001" and the allocation date is "February 1, 1998".
The user service server 19711-1 converts the application details of the user applicant 19200-1 and the acquired ICS network address via the ICS network communication function so as to write them in the conversion table 19301-1 inside the access control device 19300-1. Provide information to the table server 19731-1 (procedure P160). The contents to be provided are registration in the conversion table described in other examples such as outgoing ICS network address, sender ICS user address, request identification, speed class, priority, signature condition, cryptographic condition, open class, etc. It is an item. The above-mentioned ICS network address and ICS user address are registered as the outgoing ICS network address and the sender ICS user address when the request identification value is "2", that is, in the case of inter-company communication. If the request identification value is "4", that is, if it is an ICS network server, it is registered as an incoming ICS network address and a recipient ICS user address. The conversion table server 19731-1 adds the above contents to the conversion table 19301-1 (procedure P170). The incoming ICS network address and the recipient ICS user address are not registered in the conversion table 19301-1 at this point, but are registered in the conversion table 19301-1 in "Registration of communication partner" described later in this embodiment.
Next, the conversion table server 19731-1 notifies the ICS domain name server 19741-1 of the ICS network address, ICS user address, and ICS name (procedure P180). The ICS domain name server 19741-1 writes and holds the received ICS network address, ICS user address, and ICS name in its internal database 19641-1 (procedure P190), and converts the completion of writing to the conversion table server 19731-1. Report to (Procedure P200). The conversion table server 19731-1 confirms this report (procedure P210), reports the end of the series of procedures to the user service server 19711-1 (procedure P220), and the user service server 19711-1 confirms this report. (Procedure P230), inform the user of the ICS user address and ICS name that are the assignment results (Procedure P240) .. Since the ICS network address is used only inside ICS, it will not be notified to the applicant. Also, in the case of an ICS network server, that is, when the request identification value is "4", the user service server 19711-1 notifies all conversion table servers inside ICS19000-1 in step P160, and all access. Request registration in the control table conversion table.
<< Management of conversion table rewriting by the integrated conversion table server >> This will be described with reference to the lower procedures P800 to 960 of FIG. 119, FIGS. 111, 112, and 115. The integrated conversion table server 19730-1 instructs the conversion table server 19731-1 to rewrite the contents of the conversion table 19301-1, such as speed class priority, outgoing ICS network address, and some or all other items in the conversion table. (Procedure P800), the conversion table server 19731-1 modifies the contents of conversion table 19301-1 according to this instruction (procedure P810). In addition, the domain name server 19741-1 is instructed to rewrite the ICS network address, etc. (procedure P820), the domain name server 19741-1 updates its internal table according to this instruction (procedure P830), and the result is converted to the conversion table server 19731. Report to -1 (procedure P840), confirmed by conversion table server 19731-1 (procedure P850), and report to general conversion table server 19730-1 (procedure P860). In addition, the integrated conversion table server 19730-1 instructs the user service server 19711-1 to rewrite the contents of the user database 19611-1 such as speed class, ICS network address, and other items (procedure P900). The user service server 19711-1 updates the contents of the user database 19611-1 according to this instruction (procedure P910). In addition, the ICS authority server 19721-1 is returned with the unnecessary ICS network address, ICS user address, and ICS name, or a new request is sent (procedure P920), and the ICS authority server 19721-1 follows this instruction to perform the ICS. Update the network address allocation record table 19622-1 and the ICS user address allocation record table 19623-1 (procedure P930), report the result to the user service server 19711-1 (procedure P940), and report the result to the user service server 19711-1. Confirms (Procedure P950) and reports to the integrated conversion table server 19730-1 (Procedure P960).
In the above description, the integrated conversion table server 19730-1 first calls the user service server 19711-1 to execute the procedures P900 to P960, and secondly calls the conversion table server 19731-1 to perform the procedure. You can also run P800-P860. Therefore, the ICS operator 19960-1 instructs the centralized conversion table server 19730-1 to rewrite the contents of the access control table, so that the conversion table inside the access control device and its accompanying conversion table are attached. By exchanging information with the domain name server and ICS authority server that manage address information, etc., it is easy to manage rewriting of consistent conversion table contents, that is, update management of all conversion tables of the access control device inside ICS19000-1. Can be done.
<< User communication partner registration >> This will be described with reference to FIG. 125. The ICS19000-1 user applicant 19200-1 applies to the ICS receptionist 19940-1 with the domain name of the communication partner to register as a communication partner (procedure P300). The ICS receptionist 19940-1 accepts the domain name of this communication partner (procedure P310) and sends it to the conversion table server 19731-1 (procedure P320). The conversion table server 19731-1 exchanges information with the domain name servers 19740-1, 19742-1, etc. (procedures P330, P331) and acquires the ICS network address and ICS user address corresponding to the domain name of the inquired communication partner. Then, update the contents of conversion table 19301-1 (procedure P340) and report the result (procedure P350, P360). The updated results are shown in Conversion Table 19301-2. The ICS network address acquired here is an incoming ICS network address, and the ICS user address is a recipient ICS user address, which are registered in the conversion table as shown in FIG. 141. In the case of the ICS network server, the fields of the incoming ICS network address and the recipient ICS user address remain blank.
<< User registration to ICS-2: Corporate communication and virtual leased line >> This will be described with reference to FIG. 127. In the case of intra-company communication, the difference from the above-mentioned inter-company communication is that the ICS user address is submitted and the ICS name cannot be used, so there is no ICS name assignment and the ICS name can be used. The point is that there is no procedure (procedure equivalent to P180, P190, P200). First, the ICS19000-1 user applicant 19200-1 applies to the ICS receptionist 19940-1 for ICS subscription (procedure P400). Application acceptance data is ICS usage items excluding ICS network addresses and ICS names. For example, ICS user addresses, such as request identification (intra-company communication, inter-company communication, virtual leased line connection, ICS network server classification), The speed class and priority are the same as those for inter-company communication. As the ICS user address, one or more sets of both the sender ICS user address and the receiver ICS user address are presented. Further, in the case of a virtual leased line connection, it is different from the case of in-house communication that the sender ICS user address and the receiver ICS user address are not presented.
The ICS receptionist 19940-1 inputs the "application reception data" to the user service server 19711-1 via the operation interface, and stores the "application reception data" in the user database 19611-1 (procedure P410). .. Next, the user service server 19711-1 requests the ICS authority server 19721-1 for its ICS user address, ICS network address, and ICS name using the ICS network communication function (procedure P420). The ICS authority server 19721-1 allocates only the ICS network address in the same manner as in the above procedure P130 (procedure P430), records the allocation result in the allocation table, and returns the assigned result to the user service server 19711-1. (Procedure P440). The user service server 19711-1 stores the allocation result obtained from the ICS authority server 19721-1 in the user database 19611-1 (procedure P450).
When the user service server 19711-1 notifies the conversion table server 19731-1 of the application contents and the acquired ICS network address (procedure P460), the conversion table server 19731-1 is registered in the conversion table 19301 (procedure P370). ), Report the completion of registration (procedures P480, P495). FIG. 128 shows an example in which in-house communication and virtual leased line are registered in conversion table 19301.
<< Domain Name Server Description >> In the description of FIG. 125, for the procedure P330 and P331 related to the domain name server, an example of four layers will be described with reference to FIG. 129. The ICS network address in Table 19600-1 inside the domain name server for the domain name "root" is "9500", and the domain names "al", "a2", "a3" ... exist under it. However, for example, it indicates that the ICS network address where the domain name server that handles the domain name "a1" is located is "9610" and the port number is "440". The ICS network address in Table 19610-1 inside the domain name server for the domain name "a1" is "9610", and the domain names "bl", "b2", "b3" ... exist under it. However, for example, it indicates that the ICS network address where the domain name server that handles the domain name "b2" is located is "9720" and the port number is "440".
The ICS network address in Table 19620-1 inside the domain name server that targets the domain name "b2" is "9720", and the domain names "c4", "c5", "c6", etc. exist below it. However, for example, the domain name "c5" does not have a domain name below it because the end point column is displayed as "YES". In this example, the ICS network address corresponding to the ICS name "c5.b2.al." Is "9720", indicating that the ICS user address is "4510". In addition, the records in the internal table 19620-1 of the domain name server, that is, a set of data including the combination of the ICS name (ICS domain name), the ICS network address, and the ICS user address "4610", is particularly the "domain name server". Called "resource record".
<< Call domain name server >> With reference to Figure 133, the conversion table server 19630-1 calls the domain name servers 19640-1, 19650-1,19660-1 and corresponds to the domain name c5.b 2.al., The ICS network address and The procedure for searching the ICS user address will be described. The conversion table server 19630-1 inputs the domain name c5.b2.al. In the resolver 19635-1 inside this conversion table. When the resolver 19635-1 uses the ICS network communication function to send an ICS frame 19641-1 containing "al" to the ICS domain name server 19640-1, the ICS network address "9610" of the ICS domain name server for "a1" An ICS frame 19642-1 containing is returned. Next, when the resolver 19635-1 sends the ICS frame 19651-1 containing "b2" to the ICS domain name server 19650-1, the ICS frame containing the ICS network address "9720" of the ICS domain name server for "b2". 19652-1 is returned.
Next, when the resolver 19635-1 sends the ICS frame 19661-1 containing "c5" to the ICS domain name server 19660-1, the ICS containing the ICS network address "9820" and the ICS user address "4520" of "c5". Frame 19662-1 is returned. Through the above procedure, the conversion table server 19630-1 acquires the ICS network address "9820" and the ICS user address "4520" corresponding to the domain name "c5.b2.al.".
<< Rewriting conversion table from IP terminal >> This will be described with reference to FIGS. 134 and 135. Send an ICS user frame containing the domain name c5.b2.al from the IP terminal 19608-1 to the conversion table server 19731-1 (procedure P500). The conversion table server 19731-1 queries the domain name server (procedure P510), and the domain name server searches for the ICS network address "9820" and ICS user address "4520" corresponding to the domain name "c5.b2.al". (Procedure P520) and reply to the conversion table server 19731-1 (Procedure P53O), the conversion table server writes to the conversion table 19301-1 (Procedure P540) and reports to the IP terminal 19608-1 (Procedure P550). .. In this procedure, the ICS network address 9820 is the incoming network address, the ICS user address 4520 is the recipient ICS user address, and the rewritten conversion table is shown in Fig. 138. Note that FIG. 123 omits the contents of the conversion table corresponding to the request identification included in FIG. 122.
Next, the IP terminal 19608-1 transmits an ICS user frame including a specification for changing the speed class to 2 for the registered contents of the conversion table 19301-1X to the conversion table server 19731-1 (procedure P600). The conversion table server 19731-1 rewrites the registered contents of the conversion table 19301-1X to the speed class 2 according to the specification (procedure P610), and reports to the IP terminal 19608-1 (procedure P620). The conversion table rewritten by this procedure is shown in 19301-Y (Fig. 124).
<< Moving terminals between access control devices >> As seen in the examples in the ICS User Address Assignment Record Table 19623-1, the first row of this table is the ICS user address 4610 with the ICS name (also called the ICS domain name) dd1.cc1.bb1. It is characterized by assigning ".aa1.jp" and holding the ICS user address and ICS name. For example, move the terminal 19608-1 (Fig. 111) having the ICS user address 4610 from the access control device 19300-1 to the access control device 19320-1 (Fig. 112), for example, to give this terminal a new ICS network address. When "7821" is assigned, the outgoing ICS network address "7821" and the sender ICS user address "4610" are registered as a pair inside the conversion table 19321-1. In this case, the ICS name "dd1.cc1.bb1.aa1.jp" is paired with the ICS user address "4610" as specified in the ICS user address allocation record table 19623-1. Will not change. The resource record including the combination of the ICS name "dd1.cc1.bb1.aa1.jp" inside the domain name server, the ICS network address "7700", and the ICS user address "4610" is the ICS name "dd1.cc1". It will be changed to ".bb1.aa1.jp", ICS network address "7821", and ICS user address "4610". In other words, the ICS network address 7700 is rewritten to another address 7821, but the ICS name dd1.cc1.bb1.aa1.
(Other Examples above: User determination of ICS user address) In the above embodiment, the user is modified to determine the ICS user address. That is, when a user (user (applicant 19200-1) applies for use to ICS19000-1, the ICS user address is added. The ICS receptionist 19940-1 newly includes the ICS user address in the application reception data. In addition, the ICS authority server 19711-1 stores the ICS user address provided by the user in the ICS user address allocation table 19623-1. By the above method, the user can determine his / her own ICS user address, and the degree of freedom is improved.
Example-31 (Calling a communication partner by telephone number): In this embodiment, by using the telephone number as the ICS domain name, it is possible to send and receive the ICS user IP frame with the communication partner, and the digitized voice is stored inside the user IP frame. Here is an example of public communication by. In this embodiment, the telephone number "81-3-1234-5678" in Tokyo, Japan will be regarded as the domain name "5678.34.12.3.81". Here, "3" represents Tokyo and "81" represents Japan.
This will be described with reference to FIG. 136. ICS20000-1 is an access control device 20010-1,20020-1,20030-1, a relay device 20080-1,20090-1, a domain name server 20110-1,20120-1,20130-1,20140-1,20150- 1 is included, and the access control device 20010-1 includes a line unit 20011-1, a processing device 20012-1, a conversion table 20013-1, and a conversion table server 20040-1. The conversion table server 20040-1 is inside the access control device 20010-1, and the ICS network address is "7800" and the port number is "600". The conversion table server 20040-1 is given an ICS user address "4600" from the outside of ICS20000-1. When a domain name is entered, it is converted to an ICS user address and returned, and the ICS network address is used as an access control device. It looks like an ICS server that has the function to register in the conversion table 20013-1 inside 20010-1.
20210-1 is a LAN, 20211-1 and 2030-1 are IP terminals that have the function of sending and receiving ICS user frames, and have ICS user addresses "4520" and "1200", respectively, and ICS user logical communication lines. It is connected to ICS20000-1 via. Since the IP terminal 20300-1 can be used as a telephone, it is called an IP telephone. The IP telephone 20300-1 includes a telephone number input unit 20310-1, an IP address storage unit 20320-1, a voice data transmission / reception unit 20330-1, an input button 20340-1, and a voice input / output unit 20350-1.
<< Acquisition of ICS user address by phone number >> Enter the telephone number "1234-5678" from the input button 20340-1 into the telephone number input section 20310-1. The telephone number input unit 20310-1 generates the ICS user frame P1201 and delivers it to the access control device 20010-1 via the ICS user logical communication line. Here, the ICS user frame P1201 is the sender ICS user address 1200 and the receiver ICS user address 4600, and the data part includes the telephone number 1234-5678 input from the input button 20340-1. Is done. The processing device 20012-1 sees the conversion table 20013-1 and sends the ICS user frame P1201 to the conversion table server 20040-1 pointed to by the ICS user address 4600. In the case of this embodiment, since the conversion table server 20040-1 is inside the access control device 20010-1, it is not necessary to use the ICS network communication function. The conversion table server 20040-1 makes inquiries to the domain name servers 20130-1,20140-1,20150-1 one after another based on the telephone number "1234-5678" included in the data part of the ICS user frame P1201 and makes a phone call. Acquires the ICS network address "7920" and ICS user address "4520" of the communication partner terminal 20211-1 when the number "1234-5678" is regarded as the domain name.
Next, the conversion table server 20040-1 creates a new conversion table item 20030-1 using the two addresses "7920" and "4520" acquired here, and for the ICS user address "4520", the ICS user frame P1202. Is generated, the ICS user address "4520" is written in it, and it is sent to the IP telephone 20300-1. The IP telephone 20300-1 holds the ICS user address "4520" included in the received ICS user frame P1202 and the telephone number "1234-5678" inquired at the beginning in the IP address storage unit 20320-1 in combination. , Will be used later when the ICS user address "4520" corresponding to the telephone number "1234-5678" is needed. The above-mentioned conversion table new item 20030-1 is the IP telephone 20300-1 having the ICS network address "7820" and the ICS user address "1200", and the destination terminal 20211-1 specified by the telephone number "1234-5678". To relate to. Conversion table new item 20030-1 is used as a new element in conversion table 20013-1.
<< Communication using ICS user address >> Voice is input from the voice input / output unit 20350-1, and the voice is converted into digital data by the voice data transmission / reception unit 20330-1, stored in the ICS user frame P1210, and specified by the telephone number "1234-5678". It is transmitted to the destination, that is, the destination terminal 20211-1 determined by the ICS user address "4520" by the same principle as described in other embodiments. After that, telephone communication is performed between the two terminals 20211-1 and 20300-1 by sending and receiving ICS user frames.
<< Detailed description of domain name server >> In the above description, a method in which the conversion table server presents the telephone number 1234-5678 to the domain name server to acquire the ICS network address 7920 and the ICS user address 4520 will be described in detail.
FIG. 137 is a diagram showing an example of a domain name tree having 6 layers based on an international telephone number. A root domain name root-tel is provided at level 1 of the tree, and a lower level thereof is provided. There is a domain name "1" ... "44" ... "81" ... "90" ... at level 2 of the tree, and then, for example, a level 3 domain name under the domain name "81". "3" "6" exists, then level 4 domain name "11", "12", "13" exists under the domain name "3", for example. Then, for example, there are level 5 domain names "33", "34", "35", ... under the domain name "12", and then level 6 under the domain name "34", for example. It shows that the domain name of "5677", "5678", "5679" ... exists.
Figure 138 shows the internal table 20131-1 of the domain name server 20130-1 that handles the domain name 3. For example, the domain server 20140-1 that handles the domain name 12 under the domain name 3. It indicates that the ICS network address is "8720" and the port number is "440". FIG. 139 shows the internal table 20141-1 of the domain name server 20140-1 that handles the domain name 12. For example, the domain server 20150-1 that handles the domain name 34 lower than the domain name 12. It indicates that the ICS network address is "8820" and the port number is "440". In addition, Fig. 140 shows the internal table 20151-1 of the domain name server 20150-1 that handles the domain name 34. For example, for the domain name 5678, the end point column of the internal table 20151-1 is displayed as Since it is "YES", the lower domain name does not exist. In this example, the ICS network address corresponding to the domain name "5678.34.12.3.18." Is "7920" and the ICS user address is "4520". It is shown that.
<< Call domain name server >> With reference to Figure 141, the translation table server 20040-1 calls the domain name servers 20130-1, 20140-1, 20150-1 and the ICS network address and ICS corresponding to the domain name 5678.34.12.3.81. The procedure for searching the user address will be described. Here, the resolver 20041-1 holds the ICS network address of the domain name server that handles the level 1 domain root-tel shown in FIG. 138. In addition, when communicating with domain name servers that handle Level 2 and Level 3 domains, the ICS network addresses of those higher-level domain name servers are stored inside Resolver 20041-1.
The conversion table server 20040-1 inputs the domain name "5678.34.12." In the internal resolver 20041-1. Resolver 20041-1 holds the ICS network address "8610" of the server in charge of the domain name "3.81." Pointing to Tokyo "3" of Japan "81", and uses the ICS network communication function to use the domain name "3.81." When the ICS frame 20135-1 including the domain name "12" under "3" is sent to the ICS domain name server 20130-1, the ICS network address "8720" of the ICS domain name server 20140-1 that handles the domain name "12" Reply ICS frame 20136-1 including. Next, when the resolver 20041-1 sends an ICS frame 20145-1 containing the domain name "34" to the ICS domain name server 20140-1, the ICS network address "8820" of the ICS domain name server that handles the domain name "34" Reply ICS frame 20146-1 including.
Next, when the resolver 20041-1 sends the ICS frame 20155-1 including the domain name 5678 to the ICS domain name server 20150-1, the ICS network address 7920 corresponding to the domain name 5678 and the ICS user Returns the ICS frame 20156-1 containing the address 4520. Through the above procedure, the conversion table server 20040-1 acquires the ICS network address "7920" and the ICS user address "4520" corresponding to the domain name "5678.34.12.3.81.".
<< Telephone line connection >> There is a telephone line conversion unit 20510-1 inside the line unit 20011-1, and the telephone 20520-1 is connected to the telephone line conversion unit 20510-1 via the telephone line 20530-1. The telephone line conversion unit 20510-1 has the same function as described in other embodiments, and converts the voice transmitted from the telephone line 20530-1 into digitized voice and stores it in the data unit. Generate an ICS user frame. In the opposite transmission direction, that is, the ICS user frame sent from within the ICS network and passing through the access control line section, the digitized voice stored in the data section is analogized in the telephone line conversion section 20510-1. It is converted to voice, or in the case of an ISDN line, it is converted to its digitized voice. Because of this, the IP terminal 20300-1 to which the ICS domain name is assigned and the telephone 20520-1 can communicate with each other by telephone voice.
(Connection to the public telephone network) Further, the telephone line conversion unit 20510-1 and the private branch exchange 20600-1 are connected by the telephone line 20530-2. Telephones 20520-2 and 20520-3 are connected from the private telephone line 20540-1 from the private branch exchange 20600-1, for example, telephone communication is possible between the telephone 20520-2 and the IP telephone 20300-1. It is possible. In addition, it can be connected to the public telephone network or the international telephone network 20680-1 from the private branch exchange 20600-1 via the telephone line 20670-1. Because of this, telephone communication is possible between the telephone 20520-4 and the IP telephone 20300-1.
Example-32 (IP terminal capable of connecting to multiple access control devices): In this embodiment, instead of fixing an IP terminal having a function of sending and receiving ICS user IP frames to a specific access control device, the use of a mobile IP terminal that can be used by connecting to another access control device, that is, Achieves roaming. Roaming is realized based on the ICS domain name given to the IP terminal. In the following description, aTheb represents data (concatenated data) obtained by arranging data a and data b side by side.
<< Password transmission technique by encryption >> In this embodiment, the procedure of encrypting the secret password PW and sending it from the sender (encryption side) to the receiver (decryption side) is included. First, the encryption function Ei and the decryption function Di are set. explain. The encryption function Ei is represented by y = Ei (k1, x), and the decryption function Di is represented by x = Di (k2, y). Here, y is a cipher, x is a plain text, kl, k2 is a cryptographic key, and i is a cryptographic number (i) that determines how to use private key cryptography or public key cryptography, including the value of the cryptographic key. = 1,2, ...). In the above, the plaintext x'is encrypted as x'= xTher (where r is a random number) instead of the plaintext x, and the random number r is discarded from the plaintext x'obtained at the time of decryption to obtain the plaintext x. Is also good. In this way, even if the same plaintext is encrypted, different ciphertexts are generated due to random numbers, and it is said that the ciphertext is resistant to decryption.
(Example of code number i = 1) << Preparation >> The sender m publishes his domain name (represented by DNm) including the recipient. The recipient calculates Km = Hash-1 (DNm) using the secret data compression function Hash-1, and hands only the encryption key Km to the sender in a secure way that is unknown to a third party. This example is an example of adopting DES encryption, and the sender holds the "encryption module DES-e" and the encryption key Km to realize the encryption function Ei. The encryption key Km is a secret value shared by the sender and the receiver. The receiver holds a "decoding module DES-d" for realizing the decoding function Di and a data compression function Hash-1. What is used as the data compression function Hash-1 is determined for each encryption number value. The data compression function is also called a hash function.
<< Sender encryption >> The sender sets the secret password PW to x = PW, encrypts it as y = DES-e (Km, x) with the encryption module DES-e and the holding encryption key Km, and ciphertext y and the domain name. Send with DNm.
<< Decryption by recipient >> The recipient receives the ciphertext y and the domain name DNm, calculates the secret encryption key Km as Km = Hash-1 (DNm) using the recipient's secret data compression function Hash-1, and then receives it. Uses the decryption module to get the plaintext x as x = DES-d (Km, y). Plaintext x is the password PW, and the recipient can obtain the secret password PW. Since the third party does not know the data shrink function Hash-1, the encryption key Km cannot be calculated, and therefore the secret password PW cannot be calculated. In the above embodiment, as a rule of the encryption number i = 3, the encryption function or the decryption function can be changed to the encryption function or the decryption function other than the DES encryption.
(Example of code number i = 2) << Preparation >> This example is an example of adopting RSA encryption, and the receiver generates an encryption function y = xemod n and a decryption function y = xdmod n. Here, e d and the key d is a secret value. The receiver passes the publicly available encryption keys e and n and the encryption module RSA-e that realizes the encryption function y = xemod n to the sender. Sender Keep these encryption keys and the encryption module RSA-e. The sender does not keep any secret cryptographic modules or secret data. On the other hand, the recipient holds n, a secret key d, and a decryption module RSA-d that implements the decryption function y = xemod n.
<< Sender encryption >> Set the secret password PW you want to send, your domain name DNm, and the date and time of transmission (year, month, day, hour, minute, second) x = PWThex1Thex2 (however, xl: domain name DNm, x2 = year, month, day, hour, minute, second) As a result, the encryption module RSA-e encrypts it as y = xemod n and sends the ciphertext y.
<< Decryption by recipient >> The receiver receives the ciphertext y and calculates x = ydmod n using the decryption module RSA-d and the decryption key held in advance. Since x = PWThex1Thex2, the data at a predetermined position from the beginning of x is used as PW. In the above encryption, xl of the domain name and x2 of the year, month, day, hour, minute, and second are used as random numbers. Since the third party does not know the secret key d, the secret password PW cannot be calculated. In the above embodiment, the values of the encryption keys e, d, and n can be changed as the specification of the encryption number i = 4. In addition, the RSA cryptographic technique can be used as another public key cryptographic technique as a rule of the encryption number i = 5.
<< Terminal authentication technique using password and random number >> The authentication technique of the terminal for checking whether the password PW used in the roaming terminal matches the password registered in the authentication server will be described. As a prerequisite, the authentication server of the authentication subject and the terminal of the authenticated person have the encryption function E (provided that y = E (k,). In x), y is the ciphertext, k is the encryption key, x is the plaintext), and a third party has a secret password PW. The specific procedure of terminal authentication will be described. The terminal to be authenticated determines the random number R by an appropriate means, calculates Y1 = F (PW, R) using the password PW and the function y = F (PW, R), and calculates both the random numbers R and Y1. Send to the certifier. The authentication subject receives the random numbers R and Y1 and calculates Y2 = F (FW, R) using the received random numbers R, the password FW held by itself, and the function F, and Y1 = Y2 is established. Check if it is. If they match, the owner of the terminal as the person to be authenticated uses the correct password PW, that is, the terminal can be authenticated. In the above technique, by limiting the random number R to a time-dependent random number (called a time random number) so that the person to be authenticated cannot freely select it, it becomes more difficult for a third party to calculate the password PW. .. Instead of the encryption function used above, the secret data compression function Hj may be used and Y1, Y2 = Hj (PW, R) may be used.
<< Overall configuration >> FIGS. 142 and 143 show an overall outline of the roaming technique according to this embodiment, and the ICS21000-1 is an access control device 21010-1,21020-1,21030-1,21040-1,21050-1,21060-. 1, Relay device 21080-1,21081-1,21082-1,21083-1, Authentication server 21100-1,21101-1,21102-1,21103-1, Domain name server 21130-1,21131-1,21132 Includes -1,21133-1, user service server 21250-1, and ICS authority server 21260-1. The access control device 21010-1 includes the conversion table 21013-1, the conversion table server 21016-1, the registration server 21017-1, and the connection server 21018-1, and the access control device 21020-1 includes the conversion table 21023-1 and the conversion table server. Includes 21026-1, registration server 21027-1, and connection server 21028-1. The ICS user address "6300" is assigned to the registration servers 21017-1 and 21027-1. The ICS user address "6310" is assigned to the connection servers 21018-1 and 21028-1, and the access control device determined according to the necessity is IP from the roaming IP terminal outside the ICS21000-1. It has a function to register or connect to a terminal.
It will be explained in another embodiment that the conversion table server 21016-1 has a function of rewriting the contents of the conversion table 21013-1 and the conversion table server 21026-1 has a function of rewriting the contents of the conversion table 21023-1. It is the same as. In addition, LAN21150-1 includes an IP terminal 21151-1, LAN21160-1 includes an IP terminal 21161-1, and 21170-1 is an IP terminal. 21200-1 is a mobile roaming terminal, according to the ICS domain name "cl.bl.al.", which is the only one given as ICS21000-1.
<< Application for roaming terminal >> The owner of the roaming terminal 21200-1 specifies the payment method of the roaming terminal 21200-1 as the ICS user 21270-1, and ICS to the ICS authority server 21260-1 via the user service server 21250-1. Apply for a domain name (same as ICS name) and ICS user address. The charge payment method is represented by the charge category "MNY". For example, when MNY = 1, the charge is the home IP terminal (that is, the IP terminal that is fixedly connected to the access control device). When paying with, and MNY = 2, specify that the fee will be paid according to the record of the authentication server. The ICS authority server 21260-1 defines the ICS domain name cl.bl.al. and the ICS user address 1200 for using the roaming terminal 21200-1. In addition, the owner of the IP terminal 21200-1 goes to the ICS authority server 21260-1 via the user service server 21250-1 to use the IP terminal 21200-1 in a fixed connection to the access control device 21010-1. Apply for an ICS network address. When the user service server 21250-11 acquires the ICS network address, it requests the conversion table server 21016-1 to set the ICS network address "8115" and the ICS user address "1200" in the conversion table 21013-1. This procedure is described in other embodiments.
The ICS receptionist 21271-1 has an ICS domain name cl.bl.al., an ICS user address 1200, and a special ICS user address for the roaming terminal (roaming) on the internal 2201-1 of the roaming terminal 21200-1. (Special number) "1000", ICS user address "6300" of registration server, ICS user address "6310" of connection server are embedded, and encryption function Ei and encryption related data RP1 are embedded in internal 21202-1 of roaming terminal 21200-1. Embed. Do not embed hash functions. Here, RP1 = Hj (domain name TheRP0) TheRP0 (where RP0 = MNYTheiThej), the domain name is cl.bl.al., and MNY is the above-mentioned billing category, i. Is the cipher number for classifying the cipher Ei, and "j" determines the type of the hash function Hj. The data compression function Hj is a secret dedicated function used only by the authentication server and user service server. Since the user does not have the data compression function Hj and does not know Hj, the cryptographic data RP1 cannot be generated.
<< Registration procedure from home IP terminal >> This will be described with reference to FIGS. 142 to 144. The roaming terminal user connects the roaming terminal 21200-1 to the position of the home IP terminal 21151-1. Next, the roaming terminal user decides the password (PW) and inputs it from the input unit 21204-1, and also uses the encryption function and sound number related data stored inside 21202-1 to input the ICS user frame PK01. Generate and send to access controller 21010-1 via ICS user logical communication line 21152-1 (procedure T10). The destination of the ICS user frame PK01 is "6300" pointing to the roaming registration server, its own ICS domain name "cl.bl.al.", cryptographic parameters RP1, ICS user address "1200", expiration date "98-12-" Includes 31 , the ciphertext y that encrypts the password, tg (however, tg = 1 to display the registration procedure), and Yes or No for the roaming connection specification. Here, the above-mentioned encryption technique is adopted as the method of generating the ciphertext y. For example, when the code number = 2, y = xemod Generate the ciphertext y as n (where x = PWThec1.bl.a1The year, month, day, hour, minute, and second). The access control device 21010-1 sees the conversion table 21013-1 and transfers the ICS user frame PK01 to the registration server 21017-1 of the destination 6300 (procedure T15). The registration server 21017-1 calls the authentication server 21100-1 using the domain name c1.b1.a1 (procedure T20). The method in which the registration server 21017-1 calls the authentication server 21100-1 using the domain name is the same as the method in which the connection server 21028-1 calls the authentication server 21100-1 using the domain name. Will be described later. The authentication server 21100-1 examines the contents of PK01 of the received ICS user frame, decrypts the ciphertext "y" by the above-mentioned technique, and calculates the password PW. For example, when the encryption number = 2, the ciphertext "y" is decrypted with x = ydmod n. Then, since x = PWThec1.bl.a1The year, month, day, hour, minute, and second, the password PW can be obtained.
Next, since the content of the cryptographic parameter PP1 is RP1 = Hj (domain name TheRPO) TheRPO (however, RPO = MNYTheiThej), the secret held by the authentication server 21100-1 itself. Calculate t = Hj (domain name TheRP0) TheRP0) using the hash function Hj and the obtained domain name cl.bl.al, and determine whether t = RP1 holds for the received RP1. Find out. If it is established, it is judged that the domain name "cl.bl.al", the billing classification MNY, and the encryption numbers "i" and "j" have not been tampered with. The authentication server 21100-1 checks whether there is any excess or deficiency in the registered contents, and if it is normal, the registration result is registered in the authentication table 21100-2, and if there is a deficiency, it is not registered.
This situation is shown in the line of control number 1 in the authentication table 21100-2, and the domain name is "cl.bl.al.", the code number is "2", and the billing category (MNY) is "1". The password PW value is "224691", the expiration date is "98-12-31", and the roaming connection is "Yes", which means that the roaming connection is accepted. When generating PK01 in step T10, the roaming connection may be specified as No with the value of tg described above being tg = 2. By applying the above-mentioned cryptographic technique, the password will not be leaked to a third party. The roaming registration report is reported to the roaming IP terminal via the registration server 21017-1 (procedure T30) and then through the access control device 21010-1 (procedure T35) (procedure T40). In addition, the ICS user frame that changes the password PW value with tg = 3 or changes the expiration date value with tg = 4 from the terminal 21200-1 via the ICS user logical communication line 21152-1 is described above. It can be sent after step T40 is complete. To change the password, a method of specifying the password used before that can also be adopted.
<< Sending and receiving user IP frames at the destination >> By connecting the roaming terminal 21200-1 to the access control device 21020-1, the domain name "cl.bl.al." of the roaming terminal 21200-1 and the domain name "c2.b2.a2." An example of inter-company communication that sends and receives IP frames between companies will be described. The user specifies the domain name "c2.b2.a2." Of the communication partner, "tg" with tg = 5 to specify the transmission / reception of IP frames, his / her own password PW, and the roaming connection period. Enter the "5" day (expressed in TTL) from the input section 21204-1. For this purpose, 21201-1 and 21202-1 inside the roaming terminal 21200-1 are used. The IP frame unit 21203-1 is used to generate and send / receive ICS user IP frames PK01, PK02, PK03, PK04 and the like.
Next, the roaming terminal 21200-1 generates the user IP frame PK02 and transmits it to the access control device 21020-1 via the ICS user logical communication line 21210-1 (procedure T50). The user IP frame PK02 includes the sender domain name cl.bl.al., the recipient domain name c2.b2.a2., The cryptographic parameter RP2, and the connection period (expressed in TTL). The cryptographic parameter RP2 is the data calculated inside the password PW and 21202-2. In other words, the year, month, day, second "yy-mm-dd-sssss" is generated to make the time random number TR (TR = yy-mm-dd-sssss), and the internal clock of 21202-2 and the cryptographic function Ei are used. RP2 = Ei (PW, TR) The TR is calculated.
The access control device 21020-1 receives the user IP frame PK02, acquires the ICS network address "7800" assigned to the ICS logical terminal, the request identification is "4" according to the conversion table 21023-1, and the user. Since the sender ICS user address written in the IP frame PK02 is "1000" (roaming special number), the ICS network address "7800" is retained, and the receiver ICS user address "6310" is retained together with the ICS user frame PK02. Deliver to the connection server 21028-1 pointed to by "(Procedure T60). The ICS network address "7800" held in this procedure will be used after the procedure T130 described later.
<< Connection server function >> Next, the connection server 21028-1 calls the authentication server 21100-1 using the domain name c1.b1.a1 and transfers the domain name cl.bl.al. and the encryption parameter RP2 to the authentication server ( Step T70). The authentication server 21100-1 reads the password PW and the value of the encryption number written in the authentication table 21100-2, selects the encryption function Ei, and reads the password PW. Next, since the cryptographic parameter RP2 is RP2 = Ei (PW, TR) TheTR, t = Ei (PW, TR) is calculated using the time random number TR in the latter half of RP2. If the value of the temporary variable t calculated here matches the received Ei (PW, T) in the first half of RP2, it can be confirmed that the password PW input to the terminal 21200-1 is correct. Since the time function TR contains the date (that is, TR = yy-mm-dd-sssss), fraud can be detected when the received date does not match the processing time.
Next, the authentication server 21100-1 reports the roaming registration, billing classification, and authentication server call information described in the authentication table 21100-2 to the connection server 21028-1 (procedure T80). In the case of this embodiment, the billing category is MNY = 1, and the authentication server call information is composed of the ICS network address 7981 of the authentication server 21100-1, the port number 710, and the management number 1 of the authentication management table. .. Connection server 21028-1 presents the domain name cl.bl.al. to the domain name server, requests the ICS user address and ICS network address associated with this domain name (procedure T90), and requests the ICS user address cl.bl.al. Obtain 1200 and ICS network address 8115 (step T100). Similarly, present the domain name c2.b2.a2. To the domain name server, request the ICS user address and ICS network address associated with this domain name (step T110), and enter the ICS user address 2500. Get the ICS network address "8200" (Procedure T120). The access to the domain name server described above is the same as that described in detail in other examples.
Next, the connection server 21028-1 has the ICS network address 7800 of the ICS logical terminal that entered the ICS user frame (held in step T60), and the ICS user address 1200 that was obtained from the domain name server immediately before. The ICS user address "2500", the ICS network address "8200", and the roaming registration, billing classification, and authentication server call information transmitted from the authentication server 21100-1 are transmitted to the conversion table server 21026-1 (procedure T130). The conversion table server 2120-6 writes the four transmitted addresses to the conversion table 21023-11. The value of request identification is "10", that is, it represents inter-company communication by roaming. When the billing category is MNY = 1, the ICS network address "8115" and the ICS user address "1200" obtained from the domain name server immediately before are posted to the billing notification destination in the conversion table 21023-1. If the billing category is MNY = 2, the authentication server call information is posted to the billing notification destination in conversion table 21013-1. Furthermore, the roaming connection period specification "5" days included in the ICS user frame PK02 is also written in the conversion table 21013-1. The conversion table server 21026-1 reports the result to the connection server 21028-1 when the writing of the conversion table 21023-1 is completed (procedure T140). This completion report is sent to the roaming terminal 21200-1 via the access control device 21020-1 (procedure T150) and the ICS user frame PK03 (procedure T160). Here, the ICS user frame PK03 is set to the ICS user address "1200" attached to the domain name "cl.bl.al." of the roaming terminal 21200-1 and the domain name "c2.b2.a2." Of the communication partner. Includes the accompanying ICS user address "2500". The operating company of the access control device uses the connection server 21028-1 described above, that is, a series of procedures from receiving the ICS user frame PK02 to returning the ICS user frame PK03, and specifying the roaming connection period. You can charge the owner of the roaming terminal 21200-1 for "5 days".
<< Use of roaming terminal >> The roaming terminal 21200-1 can perform inter-company communication in the same manner as described in other examples by using the conversion table 21023-1 created according to the procedure described above (procedures T170 to T220). Further, the conversion table server 21026-1 can delete the roaming connection written inside the conversion table 21023-1 after the roaming connection period designation "5" is passed.
<< Billing Notification >> The access control device 21020-1 notifies the billing notification destination registered in the conversion table 21023-1 of the communication charge (procedure T300 or T310).
<< How to access the authentication server >> In the above explanation, the connection server 21028-1 presents the domain name "cl.bl.al." to multiple authentication servers including the authentication server 21100-1, and the ICS network frame generated by the roaming terminal 21200-1. The method of checking whether the authentication request included in PK02 is correct, that is, whether the domain name "c1.bl.al." of the roaming terminal 21200-1 is registered in the authentication server will be described in detail.
FIG. 145 is a diagram showing an example of a domain name tree having four layers. A root domain name root is provided at level 1 of the tree, and domain names al, a2, are provided at level 2 of the tree below it. A3 ... exists, then level 3 domain names bl, b2, b3 exist under the domain name al, and then, for example, the domain name bl. It indicates that level 4 domain names cl, c2, c3, etc. exist at the lower level.
Figure 146 shows the internal table 21102-2 of the authentication server 21102-1 that handles the domain name root. For example, the domain server 21101-1 that handles the domain name al under the domain name root. It indicates that the ICS network address is "7971" and the port number is "710". In addition, FIG. 147 shows the internal table 21 101-2 of the authentication server 21101-1 that handles the domain name al. For example, the domain server 21100 that handles the domain name b1 under the domain name a1. It indicates that the ICS network address of -1 is "7981" and the port number is "710".
Figure 148 shows the internal table 21100-2 of the authentication server 21100-1 that handles the domain name bl. For example, for the domain name cl, the display of the end point column of the internal table 21100-2 is YES. Since there is no lower domain name, in this example the domain name "cl.bl.al." is registered in the authentication server, the password PW is "224691", and the expiration date is "98-12-". 31 etc. are recorded.
<< Calling the authentication server >> With reference to Figure 149, Connection Server 21028-1 calls Authentication Server 21100-1 with the domain name c1.b1.a1 and the domain name cl.bl.al. Is already registered in the authentication server. Here's how to find out if it is. Here, the connection server 21028-1 holds the ICS network address of the authentication server that handles the level 1 domain root shown in FIG. 145. Also, when communicating with authentication servers that handle Level 2 and Level 3 domains, the ICS network addresses of these authentication servers are also held.
Connection server 21028-1 inputs the domain name "c1.bl.al" to the internal resolver 21029-1. When the resolver 21029-1 uses the ICS network communication function to send the ICS frame 21335-1 containing the domain name al under the domain name root and the encryption parameter RP2 to the authentication server 21102-1, the domain name Returns the ICS frame 21336-1 including the ICS network address "7971" of the authentication server 21101-1 that handles "a1". Next, when the resolver 21029-1 sends the ICS frame 21345-1 containing the domain name bl to the authentication server 21101-1, the resolver 21029-1 includes the ICS network address 7981 of the authentication server that handles the domain name bl. Reply frame 21346-1. Next, when the resolver 21029-1 sends the ICS frame 21355-1 including the domain name cl to the authentication server 21100-1, the end point column of the domain name cl, in this case 21100-2, is Yes. Therefore, it can be determined that the authentication information is registered. As mentioned above, since the procedure is done in the order of root, a1., Bl, the authentication information for the domain name cl.bl.al. which is the reverse of these is shown in the internal table 21100-. You can see that it is registered in 2.
The authentication server 21100-1 checks the received cryptographic parameter RP2 and checks that the expiration date "98-12-31" has not passed. Next, the authentication server 21100-1 reads the password PW and the encryption number values written in the authentication table 21100-2 and selects the encryption function Ei. Since the cryptographic parameter RP2 is RR2 = Ei (PW, TR) TheTR, t = Ei (PW, TR) is calculated using the time random number TR in the latter half of RP2. If the value of the temporary variable t calculated here matches the received Ei (PW, TR) in the first half of RP2, it is confirmed that the password PW input to the terminal 21200-1 is correct. Report the above results to Connection Server 21028-1. As a result, the connection server 21028-1 knows the authentication result (pass or fail) of the roaming terminal and the billing classification MNY.
<< Other examples of roaming without a home IP terminal >> In the above embodiment, when the ICS receptionist 21271-1 does not set the home IP terminal, the above-mentioned "registration procedure from the home IP terminal" is performed via the user service server 21250-1. In this case, the billing record "120" inside the authentication table 21100-2 inside the authentication server 21100-1 and the authentication server information "7981-710-1" shown in the billing notification destination inside the conversion table 21023-1. Use.
<< Another example of roaming that includes an authentication server in a domain name server >> The domain name tree of FIG. 145, which is the target of the authentication server 21110-1, has the same structure as the domain name tree, which is the target of the domain name server, as shown in another embodiment. Therefore, each domain server can store the data of the authentication server described in this embodiment and include the function of the authentication server. That is, another method of roaming is to integrate the authentication server described in this embodiment and the domain name server described in other examples.
<< Access control device and IP terminal connected to wireless transceiver >> The wireless transceiver 21620-1 is installed inside the ICS21000-1, and the wireless transceiver 21620-1 and the wireless transceiver 21640-1 can exchange information with each other via the wireless communication path 21625-1. The terminal 21630-1 includes the wireless transceiver 21640-1, and the terminal 21200-2 has a function of inter-company communication using the ICS domain name like the above-mentioned IP terminal 21200-1. There is an information communication path 21620-1 between the access control device 21020-1 and the wireless transceiver 21620-1. The information channel 21610-1 is similar to the ICS user logical communication line in that it has a function of transmitting and receiving ICS user frames, and the difference is that the information channel 21610-1 is inside the ICS21000-1. The wireless transceiver 21620-1 and the wireless transceiver 21640-1 receive the ICS user frame, convert the internal information of the ICS user frame into the ICS user frame information in the radio wave format, and transmit it, and vice versa. It has a function of receiving ICS user frame information in radio wave format, converting it back to the ICS user frame format, and sending it out. Therefore, the ICS user frame transmitted from the IP terminal 21200-2 uses the wireless transceiver 21640-1, the wireless communication path 21625-1, the wireless transceiver 21620-1, and the information communication path 21610-1. Then, it is transmitted to the access control device 21020-1. In the opposite direction, that is, the ICS user frame transmitted from the access control device 21020-1 passes through the information communication path 21610-1, the wireless transceiver 21620-1, the wireless communication path 21625-2, and the wireless transceiver 21640-1. Delivered to IP terminal 21200-2.
<figref num="1">It is a block diagram which shows typically the basic principle of this invention.</figref><figref num="2">It is a block diagram which shows the network example which made up the ICS of this invention by a plurality of VANs.</figref><figref num="3">It is a block diagram which shows the configuration example of an access control device.</figref><figref num="4">It is a block diagram which shows the configuration example of a relay device.</figref><figref num="5">It is a block diagram which shows the configuration example of the gateway between VANs.</figref><figref num="6">It is a block diagram which shows the configuration example of an ICS network server.</figref><figref num="7">It is a sequence diagram which shows an example of the ICS user address used in this invention.</figref><figref num="8">It is a wiring diagram which shows the connection relationship between an ICS logical terminal and a user communication line.</figref><figref num="9">It is a figure which shows the relationship between the ICS user frame and the ICS network frame used in this invention.</figref><figref num="10">It is a part of the block block diagram which shows 1st Example (intra-company communication, inter-company communication) of this invention.</figref><figref num="11">It is a part of the block block diagram which shows 1st Example of this invention.</figref><figref num="12">It is a flowchart which shows the operation example of an access control device.</figref><figref num="13">It is a flowchart which shows the operation example of the access control device in inter-company communication.</figref><figref num="14">It is a block block diagram which shows the 2nd Example (virtual exclusive line) of this invention.</figref><figref num="15">It is a flowchart which shows the operation example of the access control device in virtual exclusive line connection.</figref><figref num="16">It is a block block diagram which shows 3rd Example (ICS network server) of this invention.</figref><figref num="17">It is a flowchart which shows the operation example in the access control device in the server connection in an ICS network.</figref><figref num="18">It is a block diagram for demonstrating the modification of the said 3rd Example.</figref><figref num="19">It is a block block diagram which shows 4th Example (ICS address management server) of this invention.</figref><figref num="20">It is a flowchart which shows the operation example of the ICS address management server.</figref><figref num="21">It is a block diagram for demonstrating the modification of the said 4th Example.</figref><figref num="22">It is a block block diagram which shows 5th Example (ICS name server) of this invention.</figref><figref num="23">It is a flowchart which shows the operation example of the ICS name server.</figref><figref num="24">It is a block diagram for demonstrating the modification of the said 5th Example.</figref><figref num="25">It is a part of the block block diagram which shows the 8th Example (billing server) of this invention.</figref><figref num="26">It is a part of the block block diagram which shows 8th Example of this invention.</figref><figref num="27">It is a flowchart which shows the operation example of the billing process.</figref><figref num="28">It is a part of the block block diagram which shows the 9th Example (ICS frame database server) of this invention.</figref><figref num="29">It is a part of the block block diagram which shows the 9th Example of this invention.</figref><figref num="30">ICS frame is a diagram showing an example of an ICS user frame used in a database server.</figref><figref num="31">It is a flowchart which shows the operation example of the communication example-1 of the ICS frame database server.</figref><figref num="32">It is a flowchart which shows the operation example of the communication example-2 of the ICS frame database server.</figref><figref num="33">It is a flowchart which shows the operation example of the communication example-3 of the ICS frame database server.</figref><figref num="34">It is a part of the block block diagram which shows the tenth embodiment (X.25, FR, ATM, transmission by satellite communication and telephone line, ISDN line, CATV line, satellite line, accommodation of IPX frame) of this invention.</figref><figref num="35">It is a part of the block block diagram which shows the tenth embodiment of this invention.</figref><figref num="36">It is a part of the block block diagram which shows the tenth embodiment of this invention.</figref><figref num="37">It is a part of the block block diagram which shows the tenth embodiment of this invention.</figref><figref num="38">It is a figure which shows the state of the ICS network frame and the frame conversion of the X.25 format.</figref><figref num="39">It is a figure which shows the state of the frame conversion of ICS network frame and FR format.</figref><figref num="40">It is a figure which shows the state of the frame conversion of ICS network frame and ATM format.</figref><figref num="41">It is a part of the block block diagram which shows the eleventh embodiment of the present invention (transmission by X.25, FR, ATM, satellite communication and telephone line, ISDN line, CATV line, satellite line, accommodation of IPX frame).</figref><figref num="42">It is a part of the block block diagram which shows the eleventh embodiment of this invention.</figref><figref num="43">It is a part of the block block diagram which shows the twelfth embodiment of the present invention (the access control device is housed in the X.25 network and the FR network).</figref><figref num="44">It is a part of the block block diagram which shows the twelfth embodiment of this invention.</figref><figref num="45">It is a part of the block block diagram which shows the thirteenth embodiment of this invention (the access control device is connected to a relay network).</figref><figref num="46">It is a block block diagram which shows the 14th Example of this invention (when the access control device is installed outside the ICS).</figref><figref num="47">It is a part of the block block diagram which shows 15th Example (non-ICS encapsulation of inter-company communication) of this invention.</figref><figref num="48">It is a part of the block block diagram which shows the 15th Example of this invention.</figref><figref num="49">It is a flowchart which shows the operation example of the non-ICS encapsulation of the intercompany communication.</figref><figref num="50">It is a figure which shows the format example of the NSAP format ATM address.</figref><figref num="51">It is a figure which shows the information unit of the ATM cell format.</figref><figref num="52">It is a figure for demonstrating the conversion / restoration between an ICS network frame and a CPCS frame.</figref><figref num="53">It is a figure for demonstrating the disassembly / assembly between a CPCS frame and a cell.</figref><figref num="54">It is a part of the block block diagram which shows the 16th Example (another Example using an ATM network) of this invention.</figref><figref num="55">It is a part of the block block diagram which shows the 16th Example of this invention.</figref><figref num="56">It is a flowchart which shows the flow example of a frame using SVC and PVC.</figref><figref num="57">It is a flowchart which shows the flow example of a frame using SVC and PVC.</figref><figref num="58">It is a block block diagram which shows the example of one-to-N communication or N-to-one communication using PVC.</figref><figref num="59">It is a block block diagram which shows the example of N-to-N communication using PVC.</figref><figref num="60">It is a figure which shows an example of the FR frame address part.</figref><figref num="61">It is a figure which shows the modification example between the ICS network frame and the FR frame.</figref><figref num="62">It is a part of the block block diagram which shows the 17th Example (another Example using the FR network) of this invention.</figref><figref num="63">It is a part of the block block diagram which shows the 17th Example of this invention.</figref><figref num="64">It is a flowchart which shows the flow example of a frame using SVC and PVC.</figref><figref num="65">It is a flowchart which shows the flow example of a frame using SVC and PVC.</figref><figref num="66">It is a block block diagram which shows the example of one-to-N communication or N-to-one communication using PVC.</figref><figref num="67">It is a block block diagram which shows the example of N-to-N communication using PVC.</figref><figref num="68">It is a part of the block block diagram which shows 18th Embodiment of this invention (accommodation of a telephone line, an ISDN line, a CATV line, a satellite line, an IPX line, and a mobile phone line).</figref><figref num="69">It is a part of the block block diagram which shows 18th Embodiment of this invention.</figref><figref num="70">It is a part of the block block diagram which shows 18th Embodiment of this invention.</figref><figref num="71">It is a part of the block block diagram which shows 18th Embodiment of this invention.</figref><figref num="72">It is a flowchart which shows the operation of 18th Example.</figref><figref num="73">It is a part of the block block diagram which shows the 19th Example of this invention.</figref><figref num="74">It is a part of the block block diagram which shows the 19th Example of this invention.</figref><figref num="75">It is a part of the block block diagram which shows the 19th Example of this invention.</figref><figref num="76">It is a figure which shows an example of the description contents of the router table in a dial-up router.</figref><figref num="77">It is a flowchart which shows the operation of the 19th Example.</figref><figref num="78">It is a part of the block block diagram which shows the 20th Example of this invention.</figref><figref num="79">It is a part of the block block diagram which shows the 20th Example of this invention.</figref><figref num="80">It is a part of the block block diagram which shows the 20th Example of this invention.</figref><figref num="81">It is a figure which shows an example of correspondence of a communication speed and a speed class.</figref><figref num="82">It is a flowchart which shows the operation of the 20th Example.</figref><figref num="83">It is a flowchart which shows the operation of the 20th Example.</figref><figref num="84">It is a figure which shows the ICS user frame after the electronic signature is given.</figref><figref num="85">It is a figure which shows the ICS user frame before the digital signature is given.</figref><figref num="86">It is a part of the block block diagram which shows the 21st Example (electronic signature and encryption) of this invention.</figref><figref num="87">It is a part of the block block diagram which shows the 21st Example of this invention.</figref><figref num="88">It is a flowchart which shows the operation of the 21st Example.</figref><figref num="89">It is a figure for demonstrating the electronic signature at the time of transmission and the time of reception.</figref><figref num="90">It is a block block diagram which shows the 22nd Example (electronic signature server and encryption server) of this invention.</figref><figref num="91">It is a part of the block block diagram which shows the 23rd Example (open connection) of this invention.</figref><figref num="92">It is a part of the block block diagram which shows the 23rd Example of this invention.</figref><figref num="93">It is a block block diagram which shows the 24th Example (ISC address name management server) of this invention.</figref><figref num="94">It is a part of the block block diagram which shows the 25th Example (functional separation of an access control device) of this invention.</figref><figref num="95">It is a part of the block block diagram which shows the 25th Example of this invention.</figref><figref num="96">It is a flowchart which shows the operation of the 25th Example.</figref><figref num="97">It is a block block diagram which shows the 26th Example (access control device including a server and aggregated access control device) of this invention.</figref><figref num="98">It is a figure which shows the example of the TCP frame.</figref><figref num="99">It is a figure which shows the example of the UDP frame.</figref><figref num="100">It is a part of the block block diagram which shows 27th Embodiment (incoming call priority control) of this invention.</figref><figref num="101">It is a part of the block block diagram which shows 27th Embodiment (incoming call priority control) of this invention.</figref><figref num="102">It is a figure for demonstrating the 27th Example.</figref><figref num="103">It is a flowchart which shows the operation example of priority determination.</figref><figref num="104">It is a block block diagram which shows the 28th Example (transmission priority control) of this invention.</figref><figref num="105">It is a figure which shows an example of the conversion table used in 28th Example.</figref><figref num="106">It is a flowchart which shows the operation example of priority determination in 28th Example.</figref><figref num="107">It is a block block diagram which shows the 29th Example (plural communication) of this invention.</figref><figref num="108">It is a figure which shows an example of the conversion table used in the 29th Example.</figref><figref num="109">It is a figure which shows an example of the conversion table used in the 29th Example.</figref><figref num="110">It is a block block diagram which shows the modification of 34th Example.</figref><figref num="111">It is a part of the block block diagram which shows the 30th Example (operation of integrated information communication system) of this invention.</figref><figref num="112">It is a part of the block block diagram which shows the 30th Example (operation of integrated information communication system) of this invention.</figref><figref num="113">It is a figure for demonstrating the 30th Example.</figref><figref num="114">It is a figure for demonstrating the 30th Example.</figref><figref num="115">It is a figure for demonstrating the 30th Example.</figref><figref num="116">It is a figure for demonstrating the 30th Example.</figref><figref num="117">It is a figure for demonstrating the 30th Example.</figref><figref num="118">It is a figure for demonstrating the 30th Example.</figref><figref num="119">It is a figure for demonstrating the 30th Example.</figref><figref num="120">It is a figure which shows an example of the ICS network address allocation record table used in the 30th Example.</figref><figref num="121">It is a figure which shows an example of the ICS user address allocation record table used in the 30th Example.</figref><figref num="122">It is a figure which shows an example of the conversion table used in the 30th Example.</figref><figref num="123">It is a figure which shows an example of the conversion table used in the 30th Example.</figref><figref num="124">It is a figure which shows an example of the conversion table used in the 30th Example.</figref><figref num="125">It is a procedure diagram for demonstrating the 30th Example.</figref><figref num="126">It is a figure which shows an example of the conversion table used in the 30th Example.</figref><figref num="127">It is a procedure diagram for demonstrating the 30th Example.</figref><figref num="128">It is a figure which shows an example of the conversion table used in the 30th Example.</figref><figref num="129">It is a figure for demonstrating the domain name server.</figref><figref num="130">It is a figure for demonstrating the domain name server.</figref><figref num="131">It is a figure for demonstrating the domain name server.</figref><figref num="132">It is a figure for demonstrating the domain name server.</figref><figref num="133">It is a figure for demonstrating the call of a domain name server.</figref><figref num="134">It is a figure for demonstrating the rewriting of the conversion table from an IP terminal.</figref><figref num="135">It is a figure for demonstrating the rewriting of the conversion table from an IP terminal.</figref><figref num="136">It is a block block diagram which shows the 31st Example (calling a communication partner by a telephone number) of this invention.</figref><figref num="137">It is a figure for demonstrating the 31st Example.</figref><figref num="138">It is a figure which shows an example of the internal table used in 31st Example.</figref><figref num="139">It is a figure which shows an example of the internal table used in 31st Example.</figref><figref num="140">It is a figure which shows an example of the internal table used in 31st Example.</figref><figref num="141">It is a figure for demonstrating the call of a domain name server.</figref><figref num="142">It is a part of the block block diagram which shows the 32nd Example (IP terminal which can connect to a plurality of access control devices) of this invention.</figref><figref num="143">It is a part of the block block diagram which shows the 32nd Example (IP terminal which can connect to a plurality of access control devices) of this invention.</figref><figref num="144">It is a timing chart for explaining the registration procedure from the home IP terminal.</figref><figref num="145">It is a figure for demonstrating the access method of an authentication server.</figref><figref num="146">It is a figure which shows an example of the internal table used in 32nd Example.</figref><figref num="147">It is a figure which shows an example of the internal table used in 32nd Example.</figref><figref num="148">It is a figure which shows an example of the internal table used in 32nd Example.</figref><figref num="149">It is a figure for demonstrating the call of an authentication server.</figref><figref num="150">It is a block diagram for explaining a conventional LAN network.</figref><figref num="151">It is a figure which shows the form example of the Internet.</figref><figref num="152">It is a figure which shows the IP frame specified by RFC791.</figref><figref num="153">It is a figure which shows the IP frame specified in RFC1883.</figref>
Code description
1,100 Integrated Information and Communication Systems (ICS) 2, 3, 4, 5, 10 Access control device 20 Relay device Gateway between 30 VANs 40 ICS network server 50 ICS network address management server 60 User physical communication line
Every citation, both waysCites: the store holds 3 of 4
| Document | Relation | Office |
|---|---|---|
| JP10233795A | Cites | Japan |
| JP6501826A | Cites | Japan |
| JP63280539A | Cites | Japan |
| 1996年信学総合大会 B-809 | Non-patent | – |
| NTT R&D,Vol.45 No.10,p961-970 | Non-patent | – |
| 信学技報 IN98-12 | Non-patent | – |
| 信学技報 IN98-29 | Non-patent | – |
| 1998年信学総大 SB-7-5 | Non-patent | – |
152 members in 12 offices
Priority claims17
| Document | Office | Kind | Date |
|---|---|---|---|
| 1996326736 | Japan | – | |
| 32673696 | Japan | A | |
| 32673696 | Japan | A | |
| 1997054812 | Japan | – | |
| 5481297 | Japan | A | |
| 5481297 | Japan | A | |
| 18254197 | Japan | A | |
| 18254197 | Japan | A | |
| 1997182541 | Japan | – | |
| 2007011679 | Japan | A | |
| 1996326736 | – | – | – |
| 199754812 | – | – | – |
| 1997182541 | – | – | – |
| JP19960326736 | – | – | – |
| JP19970054812 | – | – | – |
| JP19970182541 | – | – | – |
| JP20070011679 | – | – | – |
Members152
| Document | Office | Kind | |
|---|---|---|---|
| GB9722070D0 | United Kingdom | D0 | |
| CA2220559A1 | Canada | A1 | |
| CA2537966A1 | Canada | A1 | |
| CA2538190A1 | Canada | A1 | |
| CA2538673A1 | Canada | A1 | |
| CA2538990A1 | Canada | A1 | |
| CA2540793A1 | Canada | A1 | |
| DE19754073A1 | Germany | A1 | |
| GB2320167A | United Kingdom | A | |
| AU4679497A | Australia | A | |
| FR2758924A1 | France | A1 | |
| KR19980063826A | Republic of Korea | A | |
| GB9821661D0 | United Kingdom | D0 | |
| CN1201200A | China | A | |
| JPH1188438A | Japan | A | |
| CA2254045A1 | Canada | A1 | |
| AU8956998A | Australia | A | |
| GB2332837A | United Kingdom | A | |
| TW364964B | Taiwan Province of China | B | |
| JPH11239178A | Japan | A | |
| GB9920041D0 | United Kingdom | D0 | |
| GB9920042D0 | United Kingdom | D0 | |
| GB9920076D0 | United Kingdom | D0 | |
| GB9920079D0 | United Kingdom | D0 | |
| GB9920084D0 | United Kingdom | D0 | |
| GB9920086D0 | United Kingdom | D0 | |
| GB2338871A | United Kingdom | A | |
| GB2338872A | United Kingdom | A | |
| GB2338873A | United Kingdom | A | |
| GB2338874A | United Kingdom | A | |
| GB2338875A | United Kingdom | A | |
| GB2338876A | United Kingdom | A | |
| AU714668B2 | Australia | B2 | |
| JP3000051B2 | Japan | B2 | |
| GB2338871B | United Kingdom | B | |
| GB2338872B | United Kingdom | B | |
| GB2338873B | United Kingdom | B | |
| GB2338874B | United Kingdom | B | |
| GB2338875B | United Kingdom | B | |
| GB2338876B | United Kingdom | B | |
| JP3084681B2 | Japan | B2 | |
| GB0019276D0 | United Kingdom | D0 | |
| US6145011A | United States of America | A | |
| JP2000316026A | Japan | A | |
| SG79949A1 | Singapore | A1 | |
| GB2356327A | United Kingdom | A | |
| JP2001177578A | Japan | A | |
| HK1033397A1 | Hong Kong, China | A1 | |
| GB0122573D0 | United Kingdom | D0 | |
| GB0122580D0 | United Kingdom | D0 | |
| GB0122620D0 | United Kingdom | D0 | |
| GB0122622D0 | United Kingdom | D0 | |
| GB0122624D0 | United Kingdom | D0 | |
| GB2363298A | United Kingdom | A | |
| GB2363299A | United Kingdom | A | |
| GB2364490A | United Kingdom | A | |
| GB2364491A | United Kingdom | A | |
| JP3261459B2 | Japan | B2 | |
| GB2366707A | United Kingdom | A | |
| FR2758924B1 | France | B1 | |
| GB0204600D0 | United Kingdom | D0 | |
| GB0204605D0 | United Kingdom | D0 | |
| GB0204606D0 | United Kingdom | D0 | |
| GB0204609D0 | United Kingdom | D0 | |
| GB0204718D0 | United Kingdom | D0 | |
| GB0204725D0 | United Kingdom | D0 | |
| GB0204726D0 | United Kingdom | D0 | |
| GB0204942D0 | United Kingdom | D0 | |
| GB2363298B | United Kingdom | B | |
| GB2364491B | United Kingdom | B | |
| JP3283864B2 | Japan | B2 | |
| JP2002158717A | Japan | A | |
| KR100321899B1 | Republic of Korea | B1 | |
| GB2356327B | United Kingdom | B | |
| GB2332837B | United Kingdom | B | |
| GB2370734A | United Kingdom | A | |
| GB2370735A | United Kingdom | A | |
| GB2371188A | United Kingdom | A | |
| GB2371189A | United Kingdom | A | |
| GB2371958A | United Kingdom | A | |
| GB2371959A | United Kingdom | A | |
| GB2370734B | United Kingdom | B | |
| GB2370735B | United Kingdom | B | |
| GB2372182A | United Kingdom | A | |
| GB2320167B | United Kingdom | B | |
| GB2371188B | United Kingdom | B | |
| GB2371958B | United Kingdom | B | |
| GB2371959B | United Kingdom | B | |
| GB2372182B | United Kingdom | B | |
| JP2003069606A | Japan | A | |
| US2003118034A1 | United States of America | A1 | |
| US6618366B1 | United States of America | B1 | |
| US2003179758A1 | United States of America | A1 | |
| JP2004048744A | Japan | A | |
| CN1520086A | China | A | |
| CN1170398C | China | C | |
| HK1068754A1 | Hong Kong, China | A1 | |
| JP2005287067A | Japan | A | |
| JP2005341549A | Japan | A | |
| JP3756895B2 | Japan | B2 |
21 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Written notification of registration of transferJAPANESE INTERMEDIATE CODE: R350R350 | R350 | |
| Written request for registration of change of nameJAPANESE INTERMEDIATE CODE: R313533S533 | S533 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Written notification of registration of transferJAPANESE INTERMEDIATE CODE: R350R350 | R350 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Request for change of ownership or part of ownershipJAPANESE INTERMEDIATE CODE: R313117S111 | S111 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 |
Numbers
- Publication
- 4222619
- Publication, DOCDB
- 4222619
- Publication, EPODOC
- JP4222619B
- Application
- 11679
- Application, DOCDB
- 2007011679
- Application, EPODOC
- JP20070011679
Titles2
- Japanese
- IP通信の方法
- English
- IP communication method
Classification
- IPC, 4
- H04L12 56
- H04L12 46
- H04L12 70
- H04W8 26