Network system and method of acquiring vlan tag data
Abstract
FIELD: information technology. SUBSTANCE: present invention relates to a network system and, in particular, to method of obtaining VLAN tag data in OpenFlow network. This is achieved due to that switches are configured to communicate via a network to a controller configured virtually process multiple VLAN by comparing VLAN internal tag data, preset for each of packets passing through network, and descriptive data flows, indicating information recording flow corresponding to packet, moving in said network. EFFECT: high flexibility of control by providing a method of obtaining VLAN tag data in OpenFlow network. 10 cl, 3 dwg

Term
Projected expiry 21 March 2032.
- Priority
- Filed
- Granted
- Today
- Projected expiry
10 claims: 6 independent, 4 dependent
- 1Сетевая система, содержащая:контроллер;и коммутаторы, каждый из которых выполнен с возможностью осуществлять с контроллером связь через сеть, при этом контроллер сконфигурирован задавать информационную запись потока, определяющую правило и действие для единообразного управления пакетами в качестве потока, в таблице потоков каждого из упомянутых коммутаторов, при этом контроллер дополнительно сконфигурирован сопоставлять и сохранять данные тега VLAN (виртуальной локальной сети), заданные для каждого из пакетов, проходящих по упомянутой сети, и описательные данные потока, которые показывают информационную запись потока, соответствующую пакету, и виртуально обрабатывать множество VLAN.
- 2Сетевая система по п.1, в которой контроллер содержит:средство для задания описательных данных потока, которые однозначно определяют информационную запись потока, в дополнение к правилу и действию в информационной записи потока;средство для сопоставления и сохранения идентификационных данных (VLAN ID), которые однозначно определяют каждую из упомянутого множества VLAN за пределами упомянутой сети, в качестве данных тега VLAN, и описательных данных потока;и средство для задания информационной записи потока путем использования описательных данных потока и обновления действия информационной записи потока.
- 3Сетевая система по п.2, в которой контроллер содержит:средство для выполнения ToS (тип службы) в качестве одного из средств управления приоритетом в отношении поступающего потока и для обновления действия, так чтобы совместно изменять значения ToS пакетов, при задании информационной записи потока путем использования описательных данных потока и обновления действия информационной записи потока.
- 4Сетевая система по любому из пп.1-3, в которой коммутатор содержит:средство для задания данных тега VLAN в качестве данных внутреннего тега, которые показывают идентификационные данные {VLAN ID) VLAN, используемой за пределами упомянутой сети, когда упомянутый коммутатор находится на входе упомянутой сети и неизвестный пакет поступает в упомянутый коммутатор;средство для задания пакета с двойным тегом путем добавления данных внешнего тега для однозначного указания VLAN, используемой в упомянутой сети, в каждом пакете с помощью функции QinQ (туннелирование IEEE802.1q);средство для вывода пакетов из заранее определенного выходного порта на основе информационной записи потока, заданной из упомянутого контроллера;и средство для удаления данных внешнего тега из пакета с помощью использования функции QinQ, когда упомянутый коммутатор находится на выходе из упомянутой сети.
- 5Контроллер, содержащий:средство для задания информационной записи потока, определяющей правило и действие для единообразного управления пакетами в качестве потока, в таблице потоков коммутатора;и средство для сопоставления и сохранения данных тега VLAN (виртуальной локальной сети), заданных для каждого из пакетов, проходящих по сети, и описательных данных потока, которые показывают информационную запись потока, соответствующую пакету, который перемещается по упомянутой сети, и для виртуальной обработки множества VLAN.
- 6Контроллер по п.5, дополнительно содержащий:средство для задания описательных данных потока, которые однозначно определяют информационную запись потока, в дополнение к правилу и действию в упомянутой информационной записи потока;средство для сопоставления и сохранения идентификационных данных (VLAN ID), которые однозначно определяют каждую из упомянутого множества VLAN за пределами упомянутой сети, в качестве данных тега VLAN, и описательных данных потока/ и средство для задания упомянутой информационной записи потока путем использования описательных данных потока и обновления действия информационной записи потока.
- 7Контроллер по п.6, дополнительно содержащий;средство для выполнения ToS (тип службы) в качестве одного из средств управления приоритетом в отношении поступающего потока и для обновления действия, так чтобы совместно изменять значение ToS пакета, при задании информационной записи потока путем использования описательных данных потока и обновления действия информационной записи потока.
- 8Коммутатор, содержащий:средство для задания информационной записи потока, определяющей правило и действие для единообразного управления пакетами в качестве потока, в таблице потоков упомянутого коммутатора под управлением контроллера;средство для задания данных тега VLAN (виртуальной локальной сети), назначенных для пакета, проходящего по сети, в качестве данных внутреннего тега, которые показывают идентификационные данные (VLAN ID) VLAN, используемой за пределами упомянутой сети, когда упомянутый коммутатор находится на входе упомянутой сети и неизвестный пакет поступает в упомянутый коммутатор;средство для задания пакета с двойным тегом путем добавления данных внешнего тега для однозначного указания VLAN, используемой в упомянутой сети, в каждом пакете с помощью функции QinQ (туннелирование IEEE802.1q);средство для вывода пакетов из заранее определенного выходного порта на основе информационной записи потока, заданной из контроллера;и средство для удаления данных внешнего тега из пакета с помощью функции QinQ, когда упомянутый коммутатор находится на выходе упомянутой сети.
- 9Способ получения данных тега VLAN (виртуальной локальной сети), который выполняется компьютером, содержащий этапы, на которых:задают информационную запись потока, определяющую правило и действие для единообразного управления пакетами в качестве потока, в таблице потоков каждого из коммутаторов;сопоставляют и сохраняют данные тега VLAN, назначенные для каждого из пакетов, проходящих по сети, и описательные данные потока, показывающие информационную запись потока, соответствующую пакету, который перемещается по упомянутой сети, и виртуально обрабатывают множество VLAN.
- 10Носитель данных, на котором сохранена программа для предписания компьютеру выполнять:этап, на котором задают информационную запись потока, определяющую правило и действие для единообразного управления пакетами в качестве потока, в таблице потоков каждого из коммутаторов;этап, на котором сопоставляют и сохраняют данные тега VLAN (виртуальной локальной сети), назначенные для каждого из пакетов, проходящих по сети, и описательные данные потока, которые показывают информационную запись потока, соответствующую пакету, который перемещается по упомянутой сети, и виртуально обрабатывают множество VLAN.
Independent claims10
247 paragraphs in 2 sections, as filed
TECHNICAL FIELD OF THE INVENTION
2The present invention relates to a network system and, in particular, to a method for VLAN tag data network OpenFlow standard.
BACKGROUND ART
4Equipment traditional network is a black box, since it is impossible to implement a flexible control such as load balancing and simple operation from outside. Therefore, when the scale of the network becomes large, it becomes difficult to check the detection and improvement of the system, and to change the circuit structure and need a large cost value.
5As a technique for solving this problem is considered a technique in which a packet control function and the route network equipment separated. For example, network equipment performs the function of packet transmission, and a control unit which is separated from the network equipment performs the route guidance, so as to implement an easier control and a more flexible network.
6(Explanation of the network with separation type CD)
7As an example of networks in which functions are separated mentioned proposed network with separation type CD (C: control plane / D: data plane) in which the assembly unit on the side of the control plane data is controlled on the side of the control plane unit.
8As an example of a network with separation type CD shown OpenFlow network (OF-NW), using the procedure OpenFlow, wherein the controller controls the switches to implement the management network routes. Details OpenFlow technique described in Nonpatent Literature 1. It is noted that OpenFlow (OF-NW) network is merely an example.
9(Explanation of the standard network OpenFlow (OF-NW))
10The network OpenFlow (OF-NW) controller OpenFlow (OFC), which is equivalent to the control unit controls the operation OpenFlow switches (OFS) by performing operations on the tables for flow control routes OpenFlow switches (OFS), which blocks equivalent nodes.
11Herein referred to as the "controller" and OpenFlow switch (OFS) is referred to as a "switch" for certain simplifications Controller OpenFlow (OFC).
12The controller and the switch are connected via a control channel (communication channel for control), called "secure channel" which is a communication channel that is protected by a dedicated line and SSL (Secure Sockets Layer). The controller and the switch are transmitted and received OpenFlow-message as a control message that corresponds to (based on) protocol OpenFlow, on a control channel.
13OpenFlow switches in the network (OF-NW) arranged in OpenFlow (OF-NW) networks like boundary switches or basic switches under control of the controller. The flow of packets from the packet reception in the boundary switch (switch input) at the input side in OpenFlow network (OF-NW) to transmit edge switch (the switch output), the output side is called a flow. The network OpenFlow (OF-NW) is fixed as a communicating flow from end to end (E2E), and a route management, error recovery, load sharing and optimization are performed in units of streams.
14The package can be read as a frame. The difference between the pack and the frame is only a difference in the data block processed in the protocol (PDU). Package is PDU "TCP / IP" (transfer / Internet Protocol Control Protocol). On the other hand, the frame is a PDU "Ethernet network (registered trademark)."
15Table streams is a set of records information streams, each of which defines a determination condition (rule) for assigning packets as flow statistics with regards to the number of times that the packets correspond to the rule and the processing content (action) to be performed in respect of packets.
16Rule flow information recording is set based on the data patterns in the different hierarchical levels of protocol which are contained in the packet header field and are identifiable. As an example, data from different hierarchical levels are given protocol destination address, source address, destination port, source port, and so on. It should be noted that the above address comprises a MAC-address (access control address to the transmission medium) and IP-address (Internet Protocol). Moreover, the data input port (input port) may be used for rules flow information recording in addition to the above data. Furthermore, it may be set normal expression of all or part of the header field values of each of the packets as a stream, as a rule the flow of information recording, or its expression,
17The flow of information recording shows this operation as "the output to a specific port", "ignore" and "rewrite header". For example, the switch outputs the packet to a specific port if the identification data (the number of output ports, and so on) of the output port set in action the flow of information recording and the switch does not include package, if identification data output port not shown. Either switch rewrites the packet header from the data packet if the data packet is not shown in the action of the flow of information recording.
18The switch performs operation flow for recording information packet group (packet flow), the flow rule that corresponds to the information recording. Specifically, when receiving a packet, the switch looks for flow table entry for the flow of information, which is generally consistent with the header data of the received packet. When the stream correspondence information recording is determined in the search result, performs an update operation statistical data stream and the information recording operation is defined as the action of the flow of information for recording received packet. On the other hand, when the matching flow entry information found as a search result, it is determined that the received packet is the first packet. The switch transmits the received packet (or a copy thereof) to the controller in OpenFlow network (OF-NW) via a control channel, It requests the route calculation for a received packet based on the source address and destination address, and so on for the received packet. A switch receives messages for establishing a flow of information entries as a response and updates the flow table.
19It should be noted that recorded streams table entry is the default, which is generally consistent with the data header of all packets with lower priority. Information recording flow, consistent with the received packet is consistent with the others. When such a record is not found, the received packet is associated with this entry by default. The default action is to write the information "transmission request for the received packet to the controller".
20Thus, the network OpenFlow (OF-NW) switch controller controls the flow table and the flow switch performs the processing according to the transmission flow chart.
21(VLAN existing OpenFlow network)
22VLAN (Virtual LAN) can be created in the OpenFlow network (OF-NW).
23This is called VLAN-tagging (tagging), when the identification number (VLAN-ID), which corresponds to the group VLAN-, wherein the packet belongs is specified (specified VLAN tag) for a packet (MAC frame, and so on) that moves through the network, a tag header.
24Which group VLAN packet belongs can be determined by referring to these data, VLAN tag (VLAN-ID), even if the network is configured from a plurality of switches.
25It should be noted that the method of identifying traffic by adding a VLAN tag that is specific to the user for the user packet, called tag VLAN. On the other hand, it is believed that it uses the VLAN tag in the user database, and the technique of double assignment of the tag is only used on the network service provider is called a VLAN tag expansion. As one of functions that implement a VLAN extension tag, in non-patent literature 2 discloses "QinQ function" (tunneling IEEE802.1q).
26"QinQ function" is a function of user authentication package in a predetermined network. For example, when the QinQ function is set to a boundary switch, the switch sets the boundary extension tag for the package moving in the network, the QinQ function.
27It should be noted that when a double VLAN tag added to the package, the first tag of the packet header called a "data external tag" and the second tag is called "internal tag data".
28Role / target using internal tag data and external tag is the same as the VLAN tag.
29Herein, it is assumed that the expansion tag that specified equipment (boundary switch and so on) that performs QinQ function on the input side of the network OpenFlow (OF-NW), is an "external tag data", and the source tag VLAN before expansion tag which is set for the package is the "internal tag data".
30In this situation, the switch can detect only an external tag data as the first tag from the packet header. Consequently, the switch can not identify the data of the inner bag tag that moves through OpenFlow network (OF-NW).
31Consequently, in the OpenFlow network (OF-NW), where there is only one the VLAN, can not handle a lot of VLAN.
32Note that as a technique of the prior art patent literature 1 (JP 2009-177281A) and patent literature 2 (JP 2009-177282A) disclose a network system, wherein when transmitting a packet in a network in which a plurality of VLAN, packet is transmitted from using double tags.
33In addition, VLAN tunneling protocol technique disclosed in patent literature 3 (JP 2009-201142A). In this procedure, the packet is tunnelled through a path with label switching (LSP) according to the protocol MPLS (Multiprotocol Label Switching). In the second switching node to the end value of the current LSP label is replaced with the label value reserved for packet transmitted from the port associated with the VLAN. output switching node in the LSP receives the packet with the reserved label value, recognizes that VLAN information embedded in the packet, and retrieves the destination address to forward the packet to the endpoint destination.
34List of references
35[Patentnaya Literature 1] JP 2009-177281A.
36[Patentnaya Literature 2] JP 2009-177282A. [Patentnaya Literature 3] JP 2009-201142A.
37[Non-Patent Literature 1] "Specification of switching streams that are open, version" 1.0.0 "[interactive] (. December 31, 2009) (found on March 24, 2011.), The Internet (URL:<u>http://openflow-spec-vl.0.0.pdf</u>).
38[Non-Patent Literature 2] "Tunneling 802.lq (Q-in-Q)" [interactive] (found on March 24, 2011.), On the Internet //<u>www.infraexpert.com/study/vlan2.3.htm</u>).
39<b>SUMMARY OF THE iNVENTION</b>
40The object of the present invention is to provide a method for producing VLAN-tag data OpenFlow network.
41The network system according to the present invention includes a controller and the switches, each of which is configured to perform the controller communication via a network, wherein the controller is configured to set information recording stream, defines the rules and action to uniformly control packets as a flow table streams of each of said switches, wherein the controller is further configured to associate (bind) and VLAN-tag store data specific to each of the packets Passing through said network, and descriptive (cookie) data stream, which show an information flow record corresponding to the package and to handle many virtual VLAN.
42The controller according to the present invention comprises: means for setting the information recording stream,
43determines rule and an action to uniformly control packets as a stream in flow table switch; and means for comparing and preserving VLAN-tag data defined for each of the packets passing through the network, and descriptive data stream, which show information flow record corresponding to a package that is moved by said network, and a plurality of virtual VLAN processing.
44According to a preferred embodiment, the controller further comprises: means for setting the descriptive data stream that uniquely identify the information stream recording in addition to the rule and action in said flow record information; means for comparing the preservation and identification data (VLAN ID), which uniquely identifies each of said plurality of VLAN outside of said network, as a VLAN-tag data and descriptive data stream; and means for setting said stream of information recording by use of descriptive data stream and updates flow information recording actions.
45According to a preferred embodiment, the controller further comprises means for performing a ToS (type of service) as a means of priority control in respect of the incoming stream and to update actions so that together modify the value ToS packet by setting the flow of information recording by making use of descriptive data stream and updating action information recording
46The switch according to the present invention comprises: means for setting the flow of information recording, and determines rule action to uniformly control packets as a stream in the stream table of said switch under the control of the controller; means for setting VLAN-tag data assigned for a packet flowing through the network, as the internal tag data that show the identification data (VLAN ID) VLAN, used outside said network when said switch is at said network input and an unknown packet arrives to said switch; means for setting a double package tag by adding the external tag data to uniquely specified VLAN, is used in said network, each packet using QinQ function; means for outputting packets of a predetermined output port based on flow information recording given from the controller; and means for deleting data from the external tag package using QinQ function when said switch is at the output of said network.
47A process for preparing VLAN-tag data according to the present invention, which is executed by a computer, includes the steps of: setting an information flow entry defining a rule and an action to uniformly control packets as a stream in the stream table of each of the switches; correlate and store data VLAN-tag assigned to each of the packets passing through the network, and descriptive data flow showing an information flow record corresponding to a package that is moved by
48said network, and a virtual process multiple VLAN.
49A program according to the present invention is a program for causing a computer to execute the above method for producing VLAN tag data. It should be noted that the program according to the present invention may be stored in the memory and the data carrier.
50A lot of VLAN can be handled in the network OpenFlow, where there is only one VLAN.
51<b>BRIEF DESCRIPTION OF DRAWINGS</b>
52FIG. 1 is a diagram showing an example of a basic configuration of a network system according to the present invention;
53FIG. 2 is a diagram showing a configuration OpenFlow network using a network system according to the present invention; and
54FIG. 3 is a logic flow chart showing an example of processing operations in the event of a package of the present invention.
55<b>Description of exemplary embodiments</b>
56[Exemplary embodiments]
57The following describes exemplary embodiments of the present invention with reference to the accompanying drawings.
58The present invention deals with the network with the type of CD separation. This case is described OpenFlow network, which is one of the networks with separating type CD, using it as an example. However, in fact, the present invention is not limited to the OpenFlow network.
59(System Configuration)
60As shown in FIG. 1, in the network system according to the present invention there is provided a controller 10 and switches 20 (20-i, i = 1 to n: n is the number of switches).
61The controller 10 calculates a packet transmission route when detecting switch 20 (20-i, i = 1 to n) based on the topology data indicating the status of network connections, and registers the information flow table entry flow switch associated with the route.
62The controller 10 is connected to each of the switches 20 (20-i, i = 1 to n) using the secure channel 50 via a control line as a transmission path control message. Consequently, secure channels 50 exist for said number of switches 20 (20-i, i = 1 to n).
63Each of the switches 20 (20-i, i = 1 to n) transmits the received packet flow based on the information record registered in his own table streams.
64(Details of the controller)
65The controller 10 is provided OpenFlow data base 11 and the control section 12 OpenFlow.
66Base 11 contains descriptive data OpenFlow (cookie) data stream 111 and data 112 internal tag.
67Descriptive (cookie) stream data 111 is identification data for uniquely identifying flow information recording.
68These internal tag 112 are VLAN tag (VLAN-ID) to its reference packet.
69That is, the internal tag 112 is data
70identification to uniquely identify each of the plurality of VLAN, which is used OpenFlow network (OF-NW).
71In this case, the base 11 OpenFlow data stores data obtained by comparing the descriptive (cookie) 111 data stream 112 and internal data tags.
72OpenFlow control section 12 controls the data base 11 OpenFlow and control switches 20 (20-i<b>, </b>i = l for n) based on the registration database 11 data OpenFlow data section 12 OpenFlow controls the switch 20 (20-i, i = l for n) over a secure channel 50 used for the controller 10 to control the switch 20 (20 -i, i = l by n) while matching OpenFlow protocol.
73(Details of the switch)
74Each of the switches 20 (20-i, i = l for n) equipped with an input port 21, output port 22, flow table 23 and the transmission control section 24.
75Input port 21 is an interface (I / F) for a package I / O and communications port for receiving (input) packet. Input ports 21 may be set.
76The output port 22 is an interface (I / F) for input / output of packets and communication port to transmit (output) of the package. Output ports 22 may be set.
77Table 23 is a flow chart in which the recording information is recorded streams by the controller 10.
78Each entry contains information descriptive flow (cookie) data stream 231, the state 232 (generally) determining
79233 and flow action.
80Descriptive data 231 is data flow identification for uniquely identifying flow information recording. Descriptive data 231 correspond to the descriptive data stream 111 flow.
81Condition 232 (typically) flow determination rule is a flow entry information is identification data to uniquely identify a flow. For example, state 232 (typically) flow definition specifies the combination of the packet header field values. In this case, the state 232 (typically) flow definition sets a value "Dst MAC" (destination MAC address) and the value "VLAN ID" of the packet header field values to uniquely identify a flow.
82Step 233 is an operation flow of the information recording and a data processing content for the packet corresponding to the state 232 (rule) determining flow. In this case, the action 233 sets the output to a predetermined port for the switch when the received packet corresponds to the state 232 (rule) determining flow. It is noted that action 233 sets the output to the output port corresponding to the destination switch.
83The transmission control section 24 processes the packet according to the registration (entry information stream) Table 23 flows. For example, the transmission control section 24 outputs a packet that entered the input port 21 to output port 22 corresponding to a predetermined destination according to the flow information recording table 23 flows. Or
84the transmission control section 24 transmits the packet to the controller 10. Alternatively, the transmission control section 24 discards the packet.
85Furthermore, the transmission control section 24 transmits and receives the control message on a secure channel 50 via the sections 12 OpenFlow flow controller 10. The transmission control section 24 changes the information recording table 23 flow streams according to the control message from the control section 12 OpenFlow controller 10 (t. e. performs registration, updating, deletion, etc.).
86(Scheme open flow network configuration)
87FIG. 2 is a diagram showing a configuration OpenFlow network (OF-NW), employing a network system according to the present invention.
88Network OpenFlow (OF-NW) has only one "VLAN = 1" and includes a controller 10 and switches 20 (20-i, I = 1 to 3).
89In this case, the switch 20-1 is "switch 1", the switch 20-2 is the "switch 2" and the switch 20-3 is the "switch 3".
90QinQ function is set in the port of which is connected to the network equipment is OpenFlow (OF-NW), of the input ports 21 and output ports 22, which are interfaces (I / F) for input / output packet switch 1 (switch 20-1), 2 switch (switch 20-2) and the switch 3 (switch 20-3).
91It is expected that subsequent comparisons made in the database 11 of the controller 10 OpenFlow.
92Controller 10:
93{Descriptor (cookie) flow = 1001, the internal tag = 10}
94= {Descriptor stream 1002 internal tag = 20}
95Furthermore, it is assumed that the subsequent recording of information streams registered in tables 23 switch 1 (switch 20-1) flows, the switch 2 (switch 20-2) and the switch 3 (switch 20-3).
96The switch 1 (switch 20-1):
97= {Descriptor stream 1001, rule = "Dst MAC = AA", and "VLAN ID = 1" action = "output to the port 2 of the switch (switch 20-2)"}, and
98= {Descriptor stream 1002 typically = "Dst MAC = BB" and "VLAN ID = 1" action = "output to the port 2 of the switch (switch 20-2}"}.
992 switch (switch 20-2):
100= {Descriptor stream 1001, rule = "Dst MAC = AA", and "VLAN ID = 1" action = "output at the port 3 of the switch (switch 3.20)"}.
101= {Descriptor stream 1002 typically = "Dst MAC = BB" and "VLAN ID = 1" action = "output at the port 3 of the switch (switch 3.20)"}.
102Switch 3 (switch 20-3):
103{Descriptor flow = 1001, rule = "Dst MAC = AA" and "VLAN ID = 1", action = "output to port for network equipment is OpenFlow (OF-NW)"}, and
104= {Descriptor stream 1002 typically = "Dst MAC = BB" and "VLAN ID = 1" action = "output at the port for the equipment is OpenFlow network (OF-NW)"}.
105(1) Packet-IN (a message about the incoming packet)
106When receiving an unknown packet switch 1 (switch 20-1) transmits a Packet-IN (message of an incoming packet) to the controller 10 of the header data of the packet for notification of the route calculation request. Furthermore, the switch 1 (switch 20-1) temporarily stores this data packet in the buffer. In this case, it is assumed that the data packet header are {Dst MAC = MOP tag = 30}. Furthermore, it is assumed that the identification data (ID buffer) buffer in which the packet data is stored, are {Buffer ID = 001}.
107(2) FlowMod-ADD (message to change the flow of information recording)
108The controller 10 transmits FlowMod-ADD (message to change the flow of information recording) in each switch along the route obtained as a result of route calculation and registers the information stream recording. In this case, it is assumed that generally an information recording stream is common to the switches on the route (typically = "Dst MAC = MOP" and a "VLAN ID = 1"). Furthermore, it is assumed that the effect of the flow of information recording is (action = "output to the port 2 of the switch (switch 20-2)") for the switch I (20-1 switch) (action = "output at the port 3 of the switch (Switch 20-3) ") for the switch 2 (switch 20-2) and (action =" display in the port equipment is OpenFlow network (oF-NW) ") for the switch 3 (switch 20-3).
109(3) Packet-OUT (outgoing message on the package)
110The controller 10 transmits the Packet-OUT (the outgoing message
111package) to the switch (switch 20-1), having transmitted Packet-IN (message of an incoming packet) and instructs it to deduce the packet data stored in buffer {Buffer ID = 001} in the switch port 2 (the switch 20-2) .
112(Processing in the case of packet arrival)
113FIG. 3 shows the processing operation in the event of a package according to the present invention.
114(1) Step S101
115Firstly, it is assumed that an unknown packet arrives at the switch 1 (switch 20-1). That is, the switch 1 (switch 20-1) takes on an unknown package, which goes to the input port 21.
116Unknown packet:
117{Dst MAC = MOP tag = 30, the data}
118(2) Step S102
119The switch 1 (switch 20-1) adds the data of the external tag "external tag = 1" in the packet using QinQ function, when an unknown packet arrives to the input port 21. Therefore, packet becomes a packet with dual tag.
120Package with dual tag:
121{Dst MAC = MOP external tag = 1, inside nny tag = 30, the data}
122These data external tag "external tag = 1" VLAN tag equivalent (VLAN-ID) of the VLAN, which is created as the only OpenFlow network (OF-NW).
123(3) Step S101
124The switch 1 (switch 20-1) generates a search key based on the packet header field value and determines whether or not the registered entry information flow,
125corresponding to this packet (whether or not there exists a corresponding stream information recording), by searching in the table 23 for the flow streams of information recording using a search key. At this point, any appropriate information flow entry is not registered yet, because the package is an unknown package. Consequently, the switch 1 (switch 20-1) is a search result corresponding to the information that flow entry does not exist.
126(4) Step S101
127When the information stream corresponding record does not exist ( "No" at step S103), the switch 1 (switch 20-1) transmits a "Packet-IN" to the controller 10 over a secure channel 50 to route the data request. "Packet-IN" message is a message for notifying the data (header data and so on) of an unknown packet received by the switch, to the controller.
128"Packet-IN":
129{Dst MAC = MOP internal tag = 30}
130It should be noted that the switch 1 (switch 20-1) stores the packet (packet with double tag at this point) in the buffer.
131ID buffer switch 1 (switch 20-1):
132{Buffer ID = 001}
133In the present exemplary embodiment, the controller 10 generates a data stream of descriptors for the flow of information recording. In this case, the controller 10 generates a "descriptor stream = 1003" as the new descriptive data stream and assigns "1003 = descriptor stream" stream information recording.
134(5) Step S105
135Upon receiving the "Packet-IN", the controller 10 determines the corresponding route data and generates the flow information record for which the newly assigned "value descriptor stream = 1003". The controller 10 transmits "FlowMod-ADD" in each of the switch 1 (switch 20-1), switch 2 (switch 20-2) and the switch 3 (switch 20-3) on the route, so that the register information flow record. "FlowMod-ADD" is a control message which instructs to register (adding) the flow of information recording.
136In this case, the controller 10 generates a "descriptor stream = 1003" as the new descriptive data stream and assigns a "handle flow = 1003" for the flow of information recording, the newly formed on the basis of route data. The controller 10 transmits "FlowMod-ADD" for the registration of flow information record for which scheduled "value descriptor stream = -1003", the switch 1 (switch 20-1), the switch 2 (switch 20-2) and the switch 3 (switch 20 -3).
137(6) Step S106
138Each of the switch 1 (switch 20-1), the switch 2
139(Switch 20-2) and the switch 3 (switch 20-3)
140record the following information a new stream entry
141its own table 23 according to the instruction streams
142"FlowMod-ADD".
143The switch 1 (switch 20-1):
144= {Descriptor stream 1003, rule = "Dst MAC = CC" and "VLAN ID = 1" action = "output port in the switch 2 (switchboard
14520-2}"}.
1462 switch (switch 20-2):
147= {Descriptor stream 1003, rule = "Dst MAC = CC" and "VLAN ID = 1" action = "output at the port 3 of the switch (switch 3.20)"}.
148Switch 3 (switch 20-3}:
149= {Descriptor stream 1003, rule = "Dst MAC = CC" and "VLAN ID = 1" action = "output at the port for the equipment is OpenFlow network (OF-NW)"}.
150(7) Step S107
151Furthermore, at this moment, the controller 10 performs a comparison of the descriptive data stream 111 and data of the internal tag 112, and stores the subsequent new mapping (linking) in the database 11 OpenFlow data.
152Controller 10:
153= {Descriptor stream 1003, the internal tag = 30}
154(8) Step S108
155Next, the controller 10 transmits "Packet-OUT" in the switch 1 (switch 20-1) which transmitted the "Packet-IN". "Packet-OUT" is a control message which instructs the withdrawal of the package (start transmission).
156"Packet-OUT":
157{Action = "output to the port 2 of the switch (switch 2.20)"}.
158(9) Step S109
159Upon receiving the "Packet-OUT" from the controller 10, the switch 1 (switch 20-1) outputs the packet stored in the buffer {Buffer ID
160= 001} switch 1 (switch 20-1) in the port of the switch 2 (switch 20-2) in response to the action (Action) "Packet-OUT".
161Herein, the switch 1 (switch 20-1) can be added to the buffer ID "Packet-IN" and notify the controller 10. The controller 10 may be added to the buffer ID "Packet-OUT" and pass it to the switch 1 (switch 20 -1).
162It should be noted that when the information recording flow, compliance of the package is already registered ( "Yes" in step S103,), the switch 1 (switch 20-1) outputs this packet to a port on the switch 2 (switch 20-2) according to the flow of information recording when a packet arrives.
163(10) Step S110
1642 switch (switch 20-2) receives the packet transmitted from the switch 1 (switch 20-1), and searches the flow table 23 to determine whether or not the registered information corresponding flow record.
165Since the information recording stream corresponding packet registered in the table 23 at this time flows, the switch 2 (switch 20-2) outputs the packet to the port of the switch 3 (switch 20-3) according to the action (Action) stream information recording.
166(11) Step S111
167Similarly, the switch 3 (switch 20-3) outputs a packet to port equipment is OpenFlow network (OF-NW) according to the action (the Action), the flow of information recording, which is registered at this time.
168At this point, the switch 3 (switch 20-3) fixes
169(Deletes) data only external tag "external tag = 1" from the QinQ function switch, and outputs the outward OpenFlow network (OF-NW).
170Output package of OpenFlow network (OF-NW):
171{Dst MAC = MOP tag = 30, the data} (12) Step S112
172Subsequently packets {Dst MAC = CC, tag = 30}, are received in the switch 1 (switch 20-1) is transmitted on "switch 1 (switch 20.1)<maths num="1"><math display="block"><mo>→</mo></math><img file="00000001.tif" he="3" wi="5" img-format="tif" img-content="undefined" /></maths> 2 switch (switch 2.20) <maths num="2"><math display="block"><mo>→</mo></math><img file="00000002.tif" he="3" wi="5" img-format="tif" img-content="undefined" /></maths> 3 switch (switch 3.20) "according to the information recording flux, which is registered in the table 23 of each switch at this time flows.
173(Flow value changes ToS)
174The following describes the processing in which ToS (type of service) as a priority control is executed in relation to the flow, which passes into OpenFlow network (OF-NW), and the ToS value of packet (ToS value change) vary together.
175It is assumed that in this case the values ToS packets having {Dst MAC = AA, VLAN ID = 10} as header fields, vary in conjunction "ToS = 5" "ToS = 3".
176For example, the controller 10 uses the three-bit field (values 0-7), which is located in the packet header ToS field in ToS as the value and controls packet priority.
177The controller 10 stores the "descriptor stream = 1001", which corresponds to the "internal tag = 10" in the database 11 OpenFlow data.
178Consequently, the controller 10 may set the information flow record having "internal tag = 10", by assigning "descriptor stream = 1001" in the table 23, the switch streams 20 (20-i, i = l for n), and may change the action (Action ) stream information recording.
179The controller 10 transmits "FlowMod-Modify", which specifies the following operation for rewriting information stream writing "descriptor stream = 1001", the switch 2 (switch 20-2). "FlowMod-Modify" is a control message which instructs a change (update) of the flow entry.
180"FlowMod-Modify":
181= {Descriptor stream 1001, action = "overwrite ToS value is 5 and output to the port 3 of the switch (switch 3.20)"}.
1822 switch (switch 2.20) overwrites action flow information table entry 23 flows under "FlowMod-Modify". To record stream information is recorded in Table 2 flow switch 23 (the switch 20-2) is rewritten as follows.
1832 switch (switch 20-2):
184= {Descriptor stream 1001, rule = "Dst MAC = AA", and "VLAN ID = 1" action = "overwrite ToS value is 5 and output to the port 3 of the switch (switch 3.20)"}.
185The switch 1 (switch 1.20) adds a "tag = 1" from the QinQ function, when a packet {Dst MAC = AA, VLAN = 10} is supplied to the input port 21,
186The switch 1 (switch 20-1) searches the flow table 23 and in accordance with the coincidence
187the flow of information recording, moves the packet to a port on the switch 2 (switch 20-2).
1882 switch (switch 2.20) overwrites the ToS value of packet "ToS = 3" "ToS = 5" according to the operation flow of recording information registered in the table 23 at this time flows, i.e. ( "ToS = 3"<maths num="3"><math display="block"><mo>→</mo></math><img file="00000002.tif" he="3" wi="5" img-format="tif" img-content="undefined" /></maths>"ToS = 5") and outputs to the switch port 3 (the switch 20-3).
189Switch 3 (switch 20-3) transmits a packet outside the network OpenFlow (OF-NW) according to the operation flow of recording information registered in the table 23 at this time flows, and eliminates (removes) the "external tag = 1" by using QinQ function for its output.
190Consequently, the ToS value of the packet having "internal tag = 10" which extends OpenFlow network (OF-NW), can be
191перезаписано с "ToS=3" в "ToS = 5" ( "ToS=3 "<maths num="4"><math display="block"><mo>→</mo></math><img file="00000002.tif" he="3" wi="5" img-format="tif" img-content="undefined" /></maths>"ToS=5" ) .
192(Characteristic of this exemplary embodiment)
193In the present invention, the switch sends an unknown packet in the controller 10 as a "Packet-IN", and the controller 10 performs a comparison of the internal tag data and descriptive data stream, which show information flow record corresponding to a package that moves through the network OpenFlow (OF-NW).
194Thus, the internal tag data (internal tag) can be identified in OpenFlow network (OF-NW). In addition, many VLAN can be handled in the OpenFlow network (OF-NW), where there is only one VLAN.
195For example, it is assumed that there are three networks -
196the user network A (NW A), in the user network (NW B) and a network communications service provider. It describes the case of user authentication packet network communications service provider through the use of QinQ function.
197First, function checked QinQ edge switch network service provider. In this case, when a packet passes the path of "NW A<maths num="5"><math display="block"><mo>→</mo></math><img file="00000002.tif" he="3" wi="5" img-format="tif" img-content="undefined" /></maths> services provider <maths num="6"><math display="block"><mo>→</mo></math><img file="00000002.tif" he="3" wi="5" img-format="tif" img-content="undefined" /></maths> The NW "Edge Switch (NW side A) of the network service provider sets the expansion tag to the package during the transfer package" NW A <maths num="7"><math display="block"><mo>→</mo></math><img file="00000002.tif" he="3" wi="5" img-format="tif" img-content="undefined" /></maths> provider of communication services "by using QinQ function.
198Each switch (basic switch, etc.) on the network service provider identifies traffic using this expansion tag.
199When a packet is transmitted by "provider of communication services <maths num="8"><math display="block"><mo>→</mo></math><img file="00000002.tif" he="3" wi="5" img-format="tif" img-content="undefined" /></maths> NW In "Edge Switch (NW side B) the network service provider removes the tag of the expansion pack.
200No problem, even if the VLAN tag is used in the user's network is blocked, since the expansion tag is used on the network service provider.
201It should be noted that when a double VLAN tag added to the package, the first tag of the packet header is referred to as "external data tag" and the second tag is referred to as "internal tag data".
202Role / target field using the internal tag data and external tag is the same as the VLAN tag. However, an internal tag data is used only among
203user networks. In the same way, the data of the external tag is used only in the network service provider.
204Role / use VLAN tag used for binding a plurality of VLAN, the switch set.
205For example, it is assumed that the VLAN1 and VLAN2 are set to switch in and VLAN1 and VLAN2 set for switch A. Two LAN-cable is necessary to provide for the VLAN1 and VLAN2 between the switch A and switch B for the connection between VLAN1 VLAN1 Switch A and Switch B, and the relationship between VLAN2 VLAN2 switch A and the switch B. Using VLAN tag, only one LAN-cable between the switch A and the switch B. By setting the VLAN tag is 1 or 2 VLAN tag package which moves between the switch A and switch B, can identify whether the packet belongs to to the VLAN1 or VLAN2.
206(Example of hardware)
207The following describes a specific example of hardware for implementing a network system according to the present invention.
208As an example of the controller 10 are shown computers such as a PC (personal computer) application, a server for a thin client, workstation, mainframe computers, super computer. It should be noted that the controller 10 may be a relay equipment or peripheral equipment.
209As an example, the switch 20 shows a network switch, a router, a proxy server, a gateway, a firewall, a load distributor (load distribution apparatus), the channel control unit (packet formation unit),
210equipment for monitoring and security control (remote control and data acquisition, SCADA), a gateway controller, a base station, an access point (AP), communication satellite (CS) any computer that has a plurality of communication ports, and so on.
211The controller 10 and the switch 20 may be expansion cards installed in the computer or virtual machine is created on the physical machine. Furthermore, the controller 10 and the switch 20 can be installed in mobile enclosures, such as a vehicle, vessel or lethal unit.
212Although not shown, each of the controller 10 and switch 20 are configured of a processor that performs predetermined processing based on a program storage device that stores the program and various types of data, and an interface that is used to communicate via network.
213As an example given above the processor central processor (CPU), a network processor (NP), a microprocessor, a microcontroller and a semiconductor integrated circuit (LSI: LSI), which has the exclusive use of the function.
214As an example, the above memory device shows a semiconductor memory device such as random access memory (RAM), read only memory (ROM), electrically erasable and programmable read only memory (EEPROM) and flash memory, auxiliary memory, e.g.
215a hard disk drive (HDD) and solid state drive (SSD), a removable drive, such as a digital versatile disc (DVD) and the storage medium such as a SD-card (Secure Digital memory card), and so on. Moreover, the memory device may be a buffer, register, and so on. Either the memory device may be a storage device using a DAS (drive with a direct connection), FC-SAN (Fiber Channel network storage system), NAS (network attached storage), IP-SAN (IP - network storage system), and etc.
216It should be noted that the above processor and the above memory device may be combined. For example, it developed a microcomputer on a single chip in the last few years. Consequently, the possibility is the idea that in the microcomputer on a single chip, which is installed in electronic equipment, provided the above processor and the above memory.
217As an example of the above-mentioned interface are given fee corresponding communication network (motherboard and I / O card), and the crystal of the semiconductor integrated circuit, a network adapter and a similar expansion card, such as NIC (network interface card), a communication device, e.g., the antenna and communication port, for example, the connecting port (connector).
218In addition, as an example of the network, given the Internet, LAN (Local Area Network), wireless LAN, WAN (Wide Area Network), a support network, a cable television line,
219fixed telephone network, mobile phone network, WiMAX (IEEE 802.16a), 3G (third generation), leased line (leased line), the IrDA (Infrared Data Technology Association), Bluetooth (registered trademark), a serial channel transmission, data bus and so forth.
220It should be noted that each internal component of the controller 10 and the switch 20 may be a module, component device with the exclusive use of either the corresponding run program (call).
221However, the present invention is not limited to these examples.
222(Disclosure of Invention)
223As mentioned above, in the present invention, the controller compares the data of the internal tag assigned to packets moving through OpenFlow network (0F-NW), and descriptive data stream, which show information flow record corresponding to packets that travel through OpenFlow network, and stores the data.
224By setting the descriptive data stream may be processed by a plurality of VLAN in the network where there is only one VLAN (e.g., in OpenFlow network where there is only one VLAN).
225Specifically, the flow entering the OpenFlow network is transmitted from the switch to the controller. The controller detects the data "VLAN ID" at the entrance to the OpenFlow network and compares the "VLAN ID" and descriptive data stream, which show information flow entry corresponding to the packet in the OpenFlow network. Therefore
226, the controller may process a plurality of VLAN.
227In addition, the controller may control the data input into the internal tag OpenFlow network and flow moving through OpenFlow network to connect them. Thus, the controller can process a plurality of virtual VLAN (multiple VLAN), irrespective of the use of only one VLAN in OpenFlow network.
228<Update>
229Part or all of the aforementioned exemplary embodiments may be mentioned in the following further aspects. However, in fact, the present invention is not limited by the subsequent specific examples.
230(A further aspect of 1)
231The controller includes: means for setting a flow entry information specifying a rule and an action to uniformly control packets as a stream in flow table switch; means for processing the virtual plurality VLAN (virtual LAN) by comparing tag data given to packages that are moving through the network, and descriptive data stream that reveal information record stream corresponding to packets that travel through the network, to preserve them.
232(A further aspect 2)
233The controller according to a further range of 1, further comprising means for setting a flow descriptive information recording stream data that uniquely identify the information stream recording in addition to the rule and action; means for comparing and save the identification data
234(VLAN ID), which uniquely identify each of the plurality of VLAN outside the network as the data tag and descriptive data stream; and means for setting the stream information recording by use of descriptive data stream and updates flow information recording actions.
235(A further aspect 3)
236The controller according to further aspect 2, further comprising: means for performing ToS
237(Service type) as one of the elements of priority control conducted in regard to the flow and update actions so that the values change together ToS packet stream when setting the information recording by use of descriptive data stream and updates flow information recording actions.
238(A further aspect 4)
239The switch includes: means for setting a table of said switch streams flow information recording defining rule and an action to uniformly control packets as a stream according to the control from the controller; and
240a block for the virtual set of VLAN matching
241(VLANs) on the basis of the information recording tag data stream according to the comparison set for packets that travel through the network, and descriptive data stream, which show information flow record corresponding to packets that travel through said network in said controller.
242(A further aspect 5}
243Switch according to further aspect 4, further comprising: means for setting tag information assigned to the packets which move across the network as the internal tag data that show the identification data (VLAN ID) VLAN, used outside said network when said switch It is provided at the entrance and into the unknown package;
244a block for adding the external tag data that uniquely define VLAN, which is used for the packets in said network packet with dual tag using QinQ function (tunneling IEEE802.lq);
245unit to output the packet to a predetermined destination according to the recording packet defined by said controller; and
246unit for removing an external tag from the packet data from the QinQ function in the event.
247<3амечания>
248The above exemplary embodiments of the present invention are described in detail. However, actually, the present invention is not limited to the above exemplary embodiments, and they are contained in the present invention, even if there is a change in volume, which does not deviate from the viewpoint of the present invention.
249It should be noted that the present application claims Convention priority based on Patent Application № 2011-072153 (JP). Disclosure is included in the materials of the present application by reference.
Contents2
6 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| OL0X0 | Cites | OL |
| WO2010103909A1 | Cites | World Intellectual Property Organization (WIPO) |
| WO2006070197A2 | Cites | World Intellectual Property Organization (WIPO) |
| CN101110764A | Cites | China |
| RU2373655C2 | Cites | Russian Federation |
| IP8800/S3640 SOFTWARE MANUAL OPENFLOW FEATURE GUIDE (VERSION 11.1 COMPATIBLE), 2010. OPENFLOW SWITCH SPECIFICATION VERSION 1.1.0 IMPLEMENTED (WIRE PROTOC | Non-patent | – |
12 members in 7 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 2011072153 | Japan | – | |
| 2011072153 | Japan | A | |
| 2011072153 | Japan | A | |
| 2012057218 | Japan | W | |
| 2012057218 | Japan | W | |
| 2011072153 | – | – | – |
| JP2012057218 | – | – | – |
| JP20110072153 | – | – | – |
| WO2012JP57218 | – | – | – |
Members12
| Document | Office | Kind | |
|---|---|---|---|
| WO2012133060A1 | World Intellectual Property Organization (WIPO) | A1 | |
| KR20130125826A | Republic of Korea | A | |
| CN103460666A | China | A | |
| US2014016647A1 | United States of America | A1 | |
| EP2693708A1 | European Patent Office (EPO) | A1 | |
| JPWO2012133060A1 | Japan | A1 | |
| RU2013143626A | Russian Federation | A | |
| EP2693708A4 | European Patent Office (EPO) | A4 | |
| RU2589340C2This record | Russian Federation | C2 | |
| CN103460666B | China | B | |
| US9608908B2 | United States of America | B2 | |
| EP2693708B1 | European Patent Office (EPO) | B1 |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| The patent is invalid due to non-payment of feesMM4A | MM4A |
Numbers
- Publication
- 0002589340
- Publication, DOCDB
- 2589340
- Publication, EPODOC
- RU2589340
- Application
- 201314362608
- Application, DOCDB
- 2013143626
- Application, EPODOC
- RU20130143626
Titles2
- Russian
- СЕТЕВАЯ СИСТЕМА И СПОСОБ ПОЛУЧЕНИЯ ДАННЫХ ТЕГА VLAN
- English
- NETWORK SYSTEM AND METHOD OF ACQUIRING VLAN TAG DATA
Classification
- CPC, 5
- H04L12/4666
- H04L12/4641
- H04L12/465
- H04L45/38
- H04L47/10
- IPC, 3
- H04L12 70
- H04L45 42
- H04L45 50