JPH0595372A - Access check circuit - Google Patents
Access check circuitInfo
- Publication number
- JPH0595372A JPH0595372A JP3253288A JP25328891A JPH0595372A JP H0595372 A JPH0595372 A JP H0595372A JP 3253288 A JP3253288 A JP 3253288A JP 25328891 A JP25328891 A JP 25328891A JP H0595372 A JPH0595372 A JP H0595372A
- Authority
- JP
- Japan
- Prior art keywords
- packet
- address
- circuit
- destination address
- permitted
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
- 238000004891 communication Methods 0.000 claims description 29
- 230000005540 biological transmission Effects 0.000 abstract description 4
- 238000000605 extraction Methods 0.000 abstract description 4
- 239000000284 extract Substances 0.000 abstract description 3
- 238000010586 diagram Methods 0.000 description 7
- 238000011144 upstream manufacturing Methods 0.000 description 6
- 239000000470 constituent Substances 0.000 description 1
- 238000000034 method Methods 0.000 description 1
Landscapes
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
【0001】[0001]
【産業上の利用分野】本発明はパケットデータ通信網に
おいてユーザから網に対するアクセスが許可されたもの
であるか否かをチェックするアクセスチェック回路に関
する。BACKGROUND OF THE INVENTION 1. Field of the Invention The present invention relates to an access check circuit for checking whether or not a user has permitted access to a packet data communication network.
【0002】[0002]
【従来の技術】図3は従来のアクセスチェック回路の一
例を示すブロック図である。本従来例のアクセスチェッ
ク回路は通信回線1に接続される転送制御回路20と、
パケットを一時的に蓄積するメモリ回路21と、メモリ
回路21上のパケットに対してアドレスチェックを行う
プロセッサ22とから構成される。2. Description of the Related Art FIG. 3 is a block diagram showing an example of a conventional access check circuit. The access check circuit of this conventional example includes a transfer control circuit 20 connected to the communication line 1,
The memory circuit 21 temporarily stores packets, and the processor 22 that performs an address check on the packets on the memory circuit 21.
【0003】図3において、上り通信回線1から入力し
たパケットは転送制御回路20によりメモリ回路21上
に転送される。転送されたパケットはプロセッサ22に
よりパケット内部の宛先アドレスが妥当であるか否かの
チェックが行われ、アクセスを許可された宛先アドレス
を有するパケットであれば、転送制御回路20はメモリ
回路21からパケットを読み出してパケットスイッチ7
への入力である入力線6へと出力される。パケットスイ
ッチ7は入力するパケットに対して、宛先アドスに対応
してパケットのスイッチングを行って出力線8へパケッ
トを出力する。In FIG. 3, the packet input from the upstream communication line 1 is transferred to the memory circuit 21 by the transfer control circuit 20. The transferred packet is checked by the processor 22 whether the destination address inside the packet is valid, and if the packet has a destination address to which access is permitted, the transfer control circuit 20 causes the memory circuit 21 to send the packet. Read the packet switch 7
Is output to the input line 6 which is an input to the. The packet switch 7 performs packet switching on the input packet in accordance with the destination address and outputs the packet to the output line 8.
【0004】[0004]
【発明が解決しようとする課題】上述した従来のアクセ
スチェック回路では、パケットの有する宛先アドレスが
許可されたものであるか否かのチェックをプロセッサの
ソフトウェア処理により行っているので、通信回線のパ
ケット転送速度が高速となると、プロセッサによるソフ
トウェア処理が追いつかず、アクセスチェックが不可能
となる欠点がある。また、宛先アドレスのみについてア
クセスの許可か否かをチェックするので、パケット交換
機に対してパケットの送出を許可されないユーザから送
られたパケットについてアクセス違反を検出できないと
いう欠点があった。In the above-mentioned conventional access check circuit, since it is checked by the software processing of the processor whether or not the destination address of the packet is permitted, the packet of the communication line is not checked. When the transfer speed becomes high, there is a disadvantage that the software processing by the processor cannot catch up with the access check. Further, since it is checked whether or not the access is permitted only to the destination address, there is a drawback that the access violation cannot be detected for the packet sent from the user who is not permitted to send the packet to the packet switch.
【0005】[0005]
【課題を解決するための手段】本発明のアクセスチェッ
ク回路は、宛先アドレスと送信元アドレスを含むパケッ
トが転送される複数の通信回線を収容して前記宛先アド
レスに対応してパケット毎の交換を行うパケット交換機
の前記通信回線上の前記パケットの前記アドレスが許可
されているか否かをチェックするアクセスチェック回路
であって、前記通信回線から入力する前記パケットに対
して許可された送信元アドレスおよび前記宛先アドレス
のそれぞれをあらかじめ記憶する第1の連想メモリ回路
と、前記第1の連想メモリ回路に前記通信回線を通過す
る前記パケットから前記送信元アドレスと宛先アドレス
とを抽出して与え前記連想メモリ回路による比較の結果
が許可された送信元アドレスおよび宛先アドレスの双方
で一致が得られた場合のみ前記パケットをパケットスイ
ッチへ出力する第1の制御手段とを備えている。The access check circuit of the present invention accommodates a plurality of communication lines to which a packet including a destination address and a source address is transferred, and exchanges each packet corresponding to the destination address. An access check circuit for checking whether the address of the packet on the communication line of the packet switch is permitted, the source address being permitted for the packet input from the communication line, and the A first associative memory circuit that stores each of the destination addresses in advance, and the associative memory circuit that extracts and gives the source address and the destination address from the packet that passes through the communication line to the first associative memory circuit. The result of the comparison by the above shows that a match is obtained in both the source address and the destination address that are permitted. If only and a first control means for outputting the packet to the packet switch.
【0006】また、上記のアクセスチェック回路に加え
て、前記パケットスイッチから出力されて前記通信回線
に出力されるべきパケットに対して出力を許可する送信
元アドレスおよび宛先アドレスを記憶する第2の連想メ
モリ回路と、前記パケットスイッチから出力された前記
パケットから前記送信元アドレスと宛先アドレスとを抽
出して前記第2の連想メモリ回路に与えて比較を行い前
記送信元アドレスおよび宛先アドレスの双方で一致が得
られた場合のみ前記パケットを前記通信回線へ出力する
第2の制御手段とを備えている。In addition to the above access check circuit, a second associative memory which stores a source address and a destination address which permit output of a packet output from the packet switch and output to the communication line The source address and the destination address are extracted from the memory circuit and the packet output from the packet switch and given to the second associative memory circuit for comparison, and both source address and destination address match. And second control means for outputting the packet to the communication line only when
【0007】[0007]
【実施例】次に、本発明について図面を参照して説明す
る。図1は本発明のアクセスチェック回路の一実施例を
示すブロック図、図2は図1におけるアクセスチェック
動作を示す図で、(A)はブロック図,(B)は同図
(A)の信号のタイムチャートである。DESCRIPTION OF THE PREFERRED EMBODIMENTS Next, the present invention will be described with reference to the drawings. 1 is a block diagram showing an embodiment of the access check circuit of the present invention, FIG. 2 is a diagram showing the access check operation in FIG. 1, (A) is a block diagram, and (B) is a signal of FIG. Is a time chart of.
【0008】本実施例のアクセスチェック回路は、上り
通信回線1に対しては、アドレス抽出回路2,比較制御
回路3,連想メモリ回路4,ゲート回路5から構成され
る。また、下り通信回線14に対しても同一番号を付与
した同一の構成要素からなるアクセスチェック回路があ
る。The access check circuit of this embodiment is composed of an address extraction circuit 2, a comparison control circuit 3, an associative memory circuit 4, and a gate circuit 5 for the upstream communication line 1. Further, there is an access check circuit including the same constituent elements to which the same number is assigned to the downlink communication line 14.
【0009】データの送り先を示す宛先アドレスと、デ
ータの送り元を示す送信元アドレスとをその内部に含む
パケットが上り通信回線1から流入する。アドレス抽出
回路2はパケット内の宛先アドレスと送信元アドレスを
識別して抽出し、比較制御回路3に接続されたパケット
アドレス信号9に順次出力する。送信元アドレスおよび
宛先アドレスを受信した比較制御回路3はアドレスの識
別子15をそれぞれ付与した形式で連想メモリ回路4に
接続された比較信号10に出力する。連想メモリ回路4
にはパケット転送に対して許可することのできる送信元
アドレスおよび宛先アドレスがあらかじめ内部に設定さ
れており、入力した比較信号10と内部に設定されたア
ドレス群との比較照合動作を行い、一致の有無を示す一
致信号11を比較結果として出力する。ここで連想メモ
リ回路4は順序回路とメモリの組み合わせにより構成さ
れ、少なくとも1つの有限個の記号列を書き込み登録す
ることが可能で、外部から逐次記号列単位で入力される
記号列と登録したすべての登録済み記号列とを比較照合
し、登録された記号列のうちのどれか1つ以上と一致が
とれた場合には、一致を表示する一致信号11を出力す
る。上り通信回線1から入力したパケットが許可された
送信元からのパケットであり、更に許可された宛先に対
するパケットであれば、送信元アドレス,宛先アドレス
の双方の比較において一致が得られて一致信号11に出
力される。比較制御回路3は一致信号11が一致である
ことを示す値をとっている場合には、ゲート回路5に対
して許可信号12を許可を示す値として出力する。ゲー
ト回路5は許可信号12が許可を示す値であれば、入力
したパケットをそのままパケットスイッチ7の入力線6
に出力し、不許可を示す値であれば出力しない。A packet including therein a destination address indicating the destination of data and a source address indicating the source of data flows from the upstream communication line 1. The address extraction circuit 2 identifies and extracts the destination address and the source address in the packet, and sequentially outputs them to the packet address signal 9 connected to the comparison control circuit 3. The comparison control circuit 3 that has received the source address and the destination address outputs the comparison signal 10 connected to the associative memory circuit 4 in a format in which the address identifier 15 is added. Associative memory circuit 4
The source and destination addresses that can be permitted for packet transfer are set internally in advance, and the comparison and collation operation of the input comparison signal 10 and the internally set address group is performed to determine the match. The coincidence signal 11 indicating the presence or absence is output as the comparison result. Here, the associative memory circuit 4 is composed of a combination of a sequential circuit and a memory, and at least one finite number of symbol strings can be written and registered. The registered symbol string is compared and collated, and if any one or more of the registered symbol strings are matched, a match signal 11 indicating the match is output. If the packet input from the upstream communication line 1 is a packet from a permitted transmission source and is a packet to a permitted destination, a match is obtained by comparing both the source address and the destination address, and a match signal 11 Is output to. The comparison control circuit 3 outputs the permission signal 12 to the gate circuit 5 as a value indicating permission when the coincidence signal 11 has a value indicating the coincidence. If the permission signal 12 has a value indicating permission, the gate circuit 5 accepts the input packet as it is from the input line 6 of the packet switch 7.
Is output to, and is not output if the value indicates disapproval.
【0010】パケットスイッチ7に入力されたパケット
は、パケットの有する宛先アドレスに対応するユーザに
転送されるようスイッチングを行う。パケットのスイッ
チングの実行後にパケットスイッチ7の出力線8から出
力されたパケットは、下り通信回線14に対して設けら
れたアクセスチェック回路により再び送信元および宛先
アドレスのチェックが行われ、許可されたアドレスを有
するパケットであれば、ゲート回路5を経由して下り通
信回線14に出力される。図1に示すようにアクセスチ
ェックのための回路は上り通信回線1に備えられた回路
と同様の動作を行う。The packet input to the packet switch 7 is switched so as to be transferred to the user corresponding to the destination address of the packet. The packet output from the output line 8 of the packet switch 7 after the packet switching is executed, the source and destination addresses are checked again by the access check circuit provided for the downlink communication line 14, and the permitted address If the packet has the following, it is output to the downlink communication line 14 via the gate circuit 5. As shown in FIG. 1, the circuit for access check performs the same operation as the circuit provided in the upstream communication line 1.
【0011】次に、図2において、連想メモリ回路4の
内部には、それが設けられた通信回線上で転送が許可さ
れるパケットのアドレスが格納される。すなわち、通信
回線へのパケットの送出を許される複数のユーザのアド
レスが許可送信元アドレス群16として設定される。個
々のアドレスは1ワードに1アドレスが設定され、その
アドレスが送信元アドレスであることを示す識別子15
aがワード方向のあらかじめ決められたビット位置に付
加されて設定されている。同様にその通信回線からの送
出を許可された宛先アドレスが宛先アドレスを示す値の
識別子15bを付加されて、許可宛先アドレス群17と
して設定されている。ここで、宛先アドレスは1つのユ
ーザのみを示す個別の宛先アドレスのみならず、複数の
ユーザからなるグループを1つのアドレスで表現したグ
ループアドレスであっても良い。パケット内にグループ
アドレスを付与して送出する場合は、パケットスイッチ
7内で複数のユーザに対応してパケットが複数になるよ
う複製されて出力されるのが前提である。Next, in FIG. 2, the address of the packet permitted to be transferred on the communication line in which the associative memory circuit 4 is provided is stored in the associative memory circuit 4. That is, addresses of a plurality of users who are allowed to send packets to the communication line are set as the permitted transmission source address group 16. For each address, one address is set in one word, and an identifier 15 indicating that the address is a source address
a is added and set at a predetermined bit position in the word direction. Similarly, a destination address permitted to be sent out from the communication line is set as a permitted destination address group 17 by adding an identifier 15b having a value indicating the destination address. Here, the destination address is not limited to an individual destination address indicating only one user, but may be a group address in which a group of a plurality of users is expressed by one address. When a packet is given a group address and then transmitted, it is premised that the packet switch 7 duplicates and outputs a plurality of packets corresponding to a plurality of users.
【0012】比較制御回路3は図2(B)のタイムチャ
ートに示すように、比較信号10上に送信元アドレスと
宛先アドレスを順次出力する。このとき送信元アドレス
と宛先アドレスの判別を可能とするために、比較信号1
0上に識別子を付加して出力する。識別子の値は連想メ
モリ回路4内に設定された識別子15a,bの値と対応
するように出力する。識別子の値が異なれば、それに続
くアドレスが同一の値であっても一致は得られないか
ら、この識別子により送信元アドレスは許可送信元アド
レス群16の中で照合が行われ、宛先アドレスは許可宛
先アドレス群17の中で照合が行われることになる。As shown in the time chart of FIG. 2B, the comparison control circuit 3 sequentially outputs the source address and the destination address on the comparison signal 10. At this time, in order to enable discrimination between the source address and the destination address, the comparison signal 1
An identifier is added to 0 and output. The value of the identifier is output so as to correspond to the value of the identifiers 15a and 15b set in the associative memory circuit 4. If the value of the identifier is different, a match cannot be obtained even if the following addresses have the same value. Therefore, the source address is verified by this identifier in the source address group 16 and the destination address is permitted. The collation is performed in the destination address group 17.
【0013】連想メモリ回路4は送信元アドレス,宛先
アドレスのそれぞれについて照合動作を行い、その結果
を一致信号11に出力する。送信元アドレス,宛先アド
レス共に許可されたアドレスであれば、それぞれで一致
が得られるからそれを判別できる。逆に不許可であれ
ば、一致が得られないから結果として図1に示したゲー
ト回路5に対する許可信号12が出力されず、パケット
はパケットスイッチ7に入力されない。The associative memory circuit 4 performs a collating operation for each of the source address and the destination address, and outputs the result to the coincidence signal 11. If both the source address and the destination address are permitted addresses, a match can be obtained for each, so that it can be determined. On the other hand, if the packet is not permitted, no match is obtained and, as a result, the permission signal 12 to the gate circuit 5 shown in FIG. 1 is not output and the packet is not input to the packet switch 7.
【0014】[0014]
【発明の効果】以上説明したように本発明のアクセスチ
ェック回路は、連想メモリ回路を利用することにより、
送信元アドレスと宛先アドレスの両方に対してアクセス
が許可されているかどうかをチェックすることができ
る。またアクセスのチェックがすべてハードウェア動作
により実現されているので、通信回線上を高速で流れる
パケットに対してチェックを行なうことが可能となる。
従って、ソフトウェアによりアクセスチェックを宛先ア
ドレスについてのみ行っていた従来のアクセスチェック
方法に比較して、より高速の回線に対してのチェックを
可能とし、更に不許可のアドレスを有するユーザのパケ
ット網へのアクセスを防止することができるという効果
を有する。As described above, the access check circuit of the present invention uses the associative memory circuit,
It is possible to check whether access is permitted to both the source address and the destination address. Further, since access checking is entirely realized by hardware operation, it is possible to check packets flowing on the communication line at high speed.
Therefore, as compared with the conventional access check method in which the access check is performed only by the destination address by software, it is possible to check the line at a higher speed and further to the packet network of the user having the unauthorized address. It has an effect that access can be prevented.
【図1】本発明のアクセスチェック回路の一実施例を示
すブロック図である。FIG. 1 is a block diagram showing an embodiment of an access check circuit of the present invention.
【図2】図1におけるアクセスチェック動作を示す図で
ある。FIG. 2 is a diagram showing an access check operation in FIG.
【図3】従来のアクセスチェック回路の一例を示すブロ
ック図である。FIG. 3 is a block diagram showing an example of a conventional access check circuit.
【符号の説明】 1 上り通信回線 2 アドレス抽出回路 3 比較制御回路 4 連想メモリ回路 5 ゲート回路 6 入力線 7 パケットスイッチ 8 出力線 9 パケットアドレス信号 10 比較信号 11 一致信号 12 許可信号 13 プロセッサインタフェース 14 下り通信回線 15a,15b 識別子 16 許可送信元アドレス群 17 許可宛先アドレス群 20 転送制御回路 21 メモリ回路 22 プロセッサ[Explanation of Codes] 1 upstream communication line 2 address extraction circuit 3 comparison control circuit 4 associative memory circuit 5 gate circuit 6 input line 7 packet switch 8 output line 9 packet address signal 10 comparison signal 11 match signal 12 enable signal 13 processor interface 14 Downlink communication lines 15a, 15b Identifier 16 Allowed source address group 17 Allowed destination address group 20 Transfer control circuit 21 Memory circuit 22 Processor
Claims (2)
ケットが転送される複数の通信回線を収容して前記宛先
アドレスに対応してパケット毎の交換を行うパケット交
換機の前記通信回線上の前記パケットの前記アドレスが
許可されているか否かをチェックするアクセスチェック
回路であって、前記通信回線から入力する前記パケット
に対して許可された送信元アドレスおよび前記宛先アド
レスのそれぞれをあらかじめ記憶する第1の連想メモリ
回路と、前記第1の連想メモリ回路に前記通信回線を通
過する前記パケットから前記送信元アドレスと宛先アド
レスとを抽出して与え前記連想メモリ回路による比較の
結果が許可された送信元アドレスおよび宛先アドレスの
双方で一致が得られた場合のみ前記パケットをパケット
スイッチへ出力する第1の制御手段とを備えることを特
徴とするアクセスチェック回路。1. A packet switch on a communication line of a packet switch for accommodating a plurality of communication lines to which a packet including a destination address and a source address is transferred, and performing switching for each packet corresponding to the destination address. An access check circuit for checking whether or not the address is permitted, the first association in which each of a source address and a destination address permitted for the packet input from the communication line is stored in advance. A memory circuit and a source address for which the result of the comparison by the associative memory circuit is permitted, which is obtained by extracting the source address and the destination address from the packet passing through the communication line to the first associative memory circuit; Outputs the packet to the packet switch only when both destination addresses match. An access check circuit comprising: first control means.
記通信回線に出力されるべきパケットに対して出力を許
可する送信元アドレスおよび宛先アドレスを記憶する第
2の連想メモリ回路と、前記パケットスイッチから出力
された前記パケットから前記送信元アドレスと宛先アド
レスとを抽出して前記第2の連想メモリ回路に与えて比
較を行い前記送信元アドレスおよび宛先アドレスの双方
で一致が得られた場合のみ前記パケットを前記通信回線
へ出力する第2の制御手段とを備えることを特徴とする
請求項1記載のアクセスチェック回路。2. A second associative memory circuit for storing a source address and a destination address for permitting output of a packet output from the packet switch and output to the communication line, and output from the packet switch. The source address and the destination address are extracted from the stored packet and are given to the second associative memory circuit for comparison. Only when the source address and the destination address are coincident with each other, the packet is extracted. The access check circuit according to claim 1, further comprising second control means for outputting to the communication line.
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP3253288A JPH0595372A (en) | 1991-10-01 | 1991-10-01 | Access check circuit |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP3253288A JPH0595372A (en) | 1991-10-01 | 1991-10-01 | Access check circuit |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| JPH0595372A true JPH0595372A (en) | 1993-04-16 |
Family
ID=17249202
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| JP3253288A Pending JPH0595372A (en) | 1991-10-01 | 1991-10-01 | Access check circuit |
Country Status (1)
| Country | Link |
|---|---|
| JP (1) | JPH0595372A (en) |
-
1991
- 1991-10-01 JP JP3253288A patent/JPH0595372A/en active Pending
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US6701432B1 (en) | Firewall including local bus | |
| US5161192A (en) | Repeaters for secure local area networks | |
| US7823195B1 (en) | Method, apparatus and computer program product for a network firewall | |
| KR100216857B1 (en) | Content Address Memory Device | |
| US20140324900A1 (en) | Intelligent Graph Walking | |
| US5881242A (en) | Method and system of parsing frame headers for routing data frames within a computer network | |
| KR100670084B1 (en) | Hardware-Enhanced Loop Level Hard Zoning in Fiber Channel Switch Fabrics | |
| US8543528B2 (en) | Exploitation of transition rule sharing based on short state tags to improve the storage efficiency | |
| USRE42135E1 (en) | Multi-protocol data classification using on-chip cam | |
| CN106341338B (en) | A kind of retransmission method and device of message | |
| US7697526B2 (en) | Packet filtering based on port bit map | |
| US20050248970A1 (en) | Distributed content addressable memory | |
| US5654985A (en) | Address tracking over repeater based networks | |
| US7117301B1 (en) | Packet based communication for content addressable memory (CAM) devices and systems | |
| JPS6248424B2 (en) | ||
| EP0493892A2 (en) | Intrusion detection apparatus for local area network | |
| CN114389844A (en) | Message processing method and device, electronic equipment and computer readable storage medium | |
| JPH04273735A (en) | Local area network bridge device | |
| EP0668680B1 (en) | Address tracking over repeater based networks | |
| US7277437B1 (en) | Packet classification method | |
| US20100251355A1 (en) | Method for obtaining data for intrusion detection | |
| JPH07170279A (en) | User group setting method in LAN bridge system | |
| JP2728113B2 (en) | Facsimile mail device | |
| JPS626324A (en) | Data detector | |
| JP2000022730A (en) | Switching hub |