JPH1079759A - Communication network system and information management device therefor - Google Patents
Communication network system and information management device thereforInfo
- Publication number
- JPH1079759A JPH1079759A JP8235220A JP23522096A JPH1079759A JP H1079759 A JPH1079759 A JP H1079759A JP 8235220 A JP8235220 A JP 8235220A JP 23522096 A JP23522096 A JP 23522096A JP H1079759 A JPH1079759 A JP H1079759A
- Authority
- JP
- Japan
- Prior art keywords
- information
- terminal
- communication
- management device
- identification information
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Landscapes
- Computer And Data Communications (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
(57)【要約】
【課題】 端末装置とその現在の利用者との対応関係の
把握や、現在の利用者に基づく端末装置間の通信の制限
を可能とする。
【解決手段】 バインディングサーバ(200)は、各端末
装置毎にその識別情報とアドレスと現在の利用者の識別
情報を管理し、DHCPサーバ(101)やLES(103)や端末装置
(105,107)からの通知に応じて、上記情報を更新する。
アクセス制御サーバ(800)は、利用者および端末装置の
各属性情報を管理し、ATM-SW(100)やルートサーバ(104)
やIEEE802.3LAN-SW(106)からの問い合わせに対して、発
着アドレスから現在の利用者をバインディングサーバ(2
00)に照会し、照会により得た利用者または端末装置の
属性情報を基に通信の可否を判断して返答する。
(57) [Summary] [PROBLEMS] To grasp the correspondence between a terminal device and its current user and to limit communication between terminal devices based on the current user. SOLUTION: A binding server (200) manages the identification information and address of each terminal device and the identification information of the current user for each terminal device, and a DHCP server (101), a LES (103) and a terminal device.
The above information is updated in response to the notification from (105, 107).
The access control server (800) manages each attribute information of the user and the terminal device, and stores the ATM-SW (100) and the route server (104).
And the current user from the destination address in response to an inquiry from the IEEE802.3 LAN-SW (106) or the binding server (2
00) and determines whether communication is possible based on the attribute information of the user or the terminal device obtained by the inquiry, and replies.
Description
【0001】[0001]
【発明の属する技術分野】本発明は、通信ネットワーク
システムに関するものであり、特に、端末装置の接続位
置や利用者が変化する通信ネットワークシステムに好適
な情報管理装置に関するものである。BACKGROUND OF THE INVENTION 1. Field of the Invention The present invention relates to a communication network system, and more particularly to an information management device suitable for a communication network system in which the connection position of a terminal device and the user change.
【0002】[0002]
【従来の技術】コンピュータ用の通信ネットワークに接
続された端末装置の通信を管理する手法としては、P. M
ockapetriが“Domain Name System”, Internet Standa
rd 13,Nov. 1987に示したDNS(Domain Name System)があ
る。このシステムでは、端末装置とその利用者の対応関
係を固定とみなし、端末装置の名称および利用者名から
なるドメインネームと、端末装置のアドレスとを対応付
けて管理する。このシステムで端末装置は、利用者が指
定した通信相手のドメインネームから、通信相手の端末
装置のアドレスを知ることができる。2. Description of the Related Art As a method for managing communication of terminal devices connected to a communication network for computers, P.M.
ockapetri “Domain Name System”, Internet Standa
rd 13, Nov. 1987 has a DNS (Domain Name System). In this system, the correspondence between a terminal device and its user is regarded as fixed, and a domain name including the name of the terminal device and the user name is managed in association with the address of the terminal device. In this system, the terminal device can know the address of the terminal device of the communication partner from the domain name of the communication partner specified by the user.
【0003】ネットワーク上の資源(装置、アプリケー
ション、ファイルなど)を階層化して管理し、それらに
対するアクセスを制御する手法としては、ITUにより制
定されたディレクトリサービス規格であるX.500等があ
る。このディレクトリサービス規格を採用したシステム
では、ネットワークOS(Operating System)等が、各資源
を保有する利用者の管理や、各資源に対する利用者のア
クセス権の管理を行うことができる。As a method of hierarchically managing resources (devices, applications, files, and the like) on a network and controlling access to them, there is X.500, which is a directory service standard established by the ITU, and the like. In a system that adopts this directory service standard, a network OS (Operating System) or the like can manage users who own each resource and manage access rights of users to each resource.
【0004】また、移動する端末装置の通信を管理する
手法としては、C. Perkinsが“IP Mobility Support”,
Internet Draft:draft-ietf-mobileip-protocol-15, F
eb,1996に示した、移動体向けネットワークレイヤプロ
トコル(Mobile IP等)がある。このプロトコルを用い
るシステムでは、端末装置が移動した場合にも、上位の
アプリケーションから見たネットワークアドレスの変更
無しに通信を継続することができる。[0004] As a method of managing communication of a moving terminal device, C. Perkins has described "IP Mobility Support",
Internet Draft: draft-ietf-mobileip-protocol-15, F
eb, 1996, there is a network layer protocol for mobiles (such as Mobile IP). In a system using this protocol, even when a terminal device moves, communication can be continued without changing the network address as viewed from a higher-level application.
【0005】[0005]
【発明が解決しようとする課題】企業内の通信ネットワ
ークなど、特定の組織で利用されるネットワークには、
その利用者を把握したり、端末装置やその利用者毎に、
通信可能な相手を制限したいという要求がある。また、
利用者の出張などにより一時的に、端末装置の利用場所
が変更されたり、利用する端末装置自体が変わったりす
る状況でも煩雑な手続なしに通信を行いたいという要求
もある。A network used by a specific organization, such as a communication network in a company, includes:
You can grasp the users, and for each terminal device and each user,
There is a demand to limit the communicable parties. Also,
There is also a demand for performing communication without complicated procedures even in a situation where the use location of the terminal device is temporarily changed due to a business trip of the user or the terminal device used is changed.
【0006】上記従来の技術では、端末装置間の通信
(接続)をその現在の利用者を基に管理できないため、
上記の要求を満足するのは困難であった。例えば、利用
する端末装置を利用者が変更すると、その利用者に対す
る他の端末装置からの通信要求は、上記利用者に送られ
なくなる。また、その利用者に対して通信相手を制限す
る制御が正常に行われなくなることもある。In the above-mentioned conventional technology, communication (connection) between terminal devices cannot be managed based on the current user.
It was difficult to satisfy the above requirements. For example, when a user changes the terminal device to be used, a communication request for the user from another terminal device is not sent to the user. In addition, control for restricting the communication partner for the user may not be performed normally.
【0007】そこで、本発明は、通信ネットワーク上の
各種装置が端末装置とその現在の利用者との対応関係を
把握できるようにすることを目的とする。Accordingly, an object of the present invention is to enable various devices on a communication network to grasp the correspondence between a terminal device and its current user.
【0008】さらに、通信ネットワーク上の各種装置が
端末装置間の通信をその現在の利用者を基に制限できる
ようにすることを目的とする。It is another object of the present invention to enable various devices on a communication network to restrict communication between terminal devices based on their current users.
【0009】[0009]
【課題を解決するための手段】上記の課題を解決するた
めに、本発明の情報管理装置は、複数の端末装置と、当
該端末装置間の通信を管理する通信管理装置とが接続さ
れた通信ネットワークに接続される情報管理装置であっ
て、前記各端末装置を識別するための端末識別情報と、
当該端末装置に割り当てられたアドレス情報と、当該端
末装置の利用者を識別するための利用者識別情報とを対
応付けて保持する記憶手段と、前記端末装置もしくは通
信管理装置から送られた登録要求に応じて、前記記憶手
段で保持されている前記端末識別情報とアドレス情報と
利用者識別情報との対応が、現時点における通信ネット
ワークの利用状態を反映したものとなるように、前記記
憶手段で保持されている情報を更新する手段と、前記端
末装置もしくは通信管理装置から送られた端末識別情報
もしくはアドレス情報もしくは利用者識別情報に応じ
て、当該送られた情報に対応して前記記憶手段で保持さ
れている情報を前記端末装置もしくは通信管理装置に返
送する手段とを有することを特徴とする。In order to solve the above-mentioned problems, an information management apparatus according to the present invention comprises a communication apparatus in which a plurality of terminal apparatuses and a communication management apparatus for managing communication between the terminal apparatuses are connected. An information management device connected to a network, wherein terminal identification information for identifying each of the terminal devices,
Storage means for storing address information assigned to the terminal device and user identification information for identifying a user of the terminal device in association with each other; and a registration request sent from the terminal device or the communication management device. In accordance with the above, the correspondence between the terminal identification information, the address information, and the user identification information held in the storage means is stored in the storage means so as to reflect the current use state of the communication network. Means for updating the stored information and, in response to the terminal identification information or address information or user identification information sent from the terminal device or the communication management device, holding the information in the storage means in correspondence with the sent information Means for returning the received information to the terminal device or the communication management device.
【0010】この情報管理装置を用いることで、通信ネ
ットワーク上の各種装置が端末装置とその現在の利用者
との対応関係を把握できるようになる。さらに、例え
ば、利用者がネットワーク上の任意の位置で任意の端末
を使用して通信を行うことが可能となる。By using this information management device, various devices on the communication network can grasp the correspondence between the terminal device and its current user. Further, for example, a user can communicate at an arbitrary position on a network using an arbitrary terminal.
【0011】また、本発明の情報管理装置は、請求項1
に記載の情報管理装置と、複数の端末装置と、当該端末
装置間の通信を管理する通信管理装置とが接続された通
信ネットワークに接続される情報管理装置であって、前
記端末装置の利用者を識別するための利用者識別情報
と、当該利用者について設定された属性情報とを対応付
けて保持する記憶手段と、前記通信管理装置から送られ
た、通信を開始しようとする発側および着側の端末装置
の端末識別情報に応じて、当該2つの端末識別情報を請
求項1に記載の情報管理装置に送り、前記発側および着
側の端末装置の利用者の利用者識別情報を得る手段と、
当該手段により得た利用者識別情報に対応して前記第2
の記憶手段で保持されている属性情報を基に、前記通信
を開始しようとする端末装置の相互の接続の可否を決定
し、決定結果を前記通信管理装置に返送する手段とを有
することを特徴とする。[0011] Further, the information management apparatus of the present invention comprises:
An information management device, a plurality of terminal devices, and an information management device connected to a communication network connected to a communication management device that manages communication between the terminal devices, wherein a user of the terminal device Storage means for storing user identification information for identifying the user and attribute information set for the user in association with each other; The two terminal identification information is sent to the information management device according to claim 1 according to the terminal identification information of the terminal device on the side, and the user identification information of the user of the terminal device on the calling side and the terminal device on the called side is obtained. Means,
The second method corresponds to the user identification information obtained by the means.
Means for determining whether or not the terminal devices that are to start the communication can connect with each other based on the attribute information held in the storage means, and returning the determination result to the communication management device. And
【0012】この情報管理装置を用いることで、通信ネ
ットワーク上の各種装置が端末装置間の通信(接続)を
その現在の利用者を基に制限できるようになる。By using this information management device, various devices on the communication network can restrict communication (connection) between terminal devices based on their current users.
【0013】[0013]
【発明の実施の形態】図1は、本発明の実施の形態に係
るネットワークシステムの構成図である。FIG. 1 is a configuration diagram of a network system according to an embodiment of the present invention.
【0014】図1において、本ネットワークシステム
は、ATM(Asynchronous Transfer System)の交換機能を
持つATM-SW(100)と、そのATM-SW(100)に接続された複数
の端末装置(コンピュータ)を有する。また、ATM-SW(1
00)には、IEEE802.3LAN用端末装置(107)が接続されたIE
EE802.3LAN用スイッチ(106)も接続されている。ATM-SW
(100)に接続された端末装置には、複数のATM端末装置(1
05)と、端末装置間の通信を管理・制御する複数のサー
バ装置(バインディングサーバ(200)、アクセス制御サ
ーバ(800)、DHCPサーバ(101)、LECS(102)、LES/BUS(10
3)など)とが含まれる。これら端末装置の各々には、AT
M通信を行う機能が設けられている。In FIG. 1, the network system includes an ATM-SW (100) having an ATM (Asynchronous Transfer System) exchange function and a plurality of terminal devices (computers) connected to the ATM-SW (100). Have. In addition, ATM-SW (1
00), the IEEE802.3 LAN terminal device (107) is connected to the IE.
The EE802.3 LAN switch (106) is also connected. ATM-SW
The terminal connected to (100) includes a plurality of ATM terminals (1
05) and multiple server devices that manage and control communication between terminal devices (binding server (200), access control server (800), DHCP server (101), LECS (102), LES / BUS (10
3) etc.). Each of these terminals has an AT
A function for performing M communication is provided.
【0015】バインディングサーバ(200)は、ATM-SW(10
0)に接続された端末装置に割り当てられているアドレス
情報と、端末装置の利用者の情報を管理する機能を持
つ。アクセス制御サーバ(800)は、利用者や端末装置に
与えた属性の情報を管理する機能を持つ。これらの機能
は、各サーバ装置でのプログラム処理により実現され
る。The binding server (200) is connected to the ATM-SW (10
It has a function of managing address information assigned to the terminal device connected to (0) and information of the user of the terminal device. The access control server (800) has a function of managing attribute information given to users and terminal devices. These functions are realized by program processing in each server device.
【0016】また、本ネットワークシステムでATM-SW(1
00)に接続された各装置は、LANE(LAN Emulation)プロト
コルにより擬似的なLAN(Local Aria Network)通信を
行い、ネットワークレイヤのプロトコルとしてはIP(Int
ernet Protocol)を用いる。LECS(102)とLES/BUS(103)
は、このLANEプロトコルによる通信を実現するためのサ
ーバ装置である。なお、LES/BUS(103)は、LES、BUSの2
つの機能を持つサーバ装置であるが、以下の説明では、
機能を示すためにLES(103)あるいはBUS(103)と表すこと
がある。LANEプロトコルの詳細については、The ATM Fo
rumが公開および発行している“LAN Emulation over AT
M v1.0 Specification”に記述されている。Further, the ATM-SW (1
00) perform pseudo LAN (Local Aria Network) communication by LANE (LAN Emulation) protocol, and use IP (Int) as a network layer protocol.
Internet Protocol). LECS (102) and LES / BUS (103)
Is a server device for realizing communication using the LANE protocol. LES / BUS (103) is LES and BUS 2
Although the server device has two functions, in the following description,
It may be expressed as LES (103) or BUS (103) to indicate the function. For more information about the LANE protocol, see The ATM Fo
“LAN Emulation over AT” published and published by rum
M v1.0 Specification ".
【0017】本ネットワークシステムでは、ATM端末装
置(105)がネットワークに接続され稼働を開始すると、L
ANEプロトコルを用いる端末装置のアドレスを管理して
いるLES(103)は、上記ATM端末装置(105)に割り当てられ
たMACアドレスおよびATMアドレスをバインディングサー
バ(200)に登録する。DHCPサーバ(101)は、稼働を開始し
たATM端末装置(105)やIEEE802.3LAN用端末装置(107)に
対しIPアドレスを割り当て、同時に、端末装置に割り当
てたIPアドレスをバインディングサーバ(200)に登録す
る。また、バインディングサーバ(200)には、端末装置
の実際の利用者を特定可能とする情報も登録される。In this network system, when the ATM terminal device (105) is connected to the network and starts operating,
The LES (103) managing the address of the terminal device using the ANE protocol registers the MAC address and the ATM address assigned to the ATM terminal device (105) in the binding server (200). The DHCP server (101) assigns an IP address to the ATM terminal device (105) and the IEEE802.3 LAN terminal device (107) that have started operation, and simultaneously assigns the IP address assigned to the terminal device to the binding server (200). register. In the binding server (200), information for specifying an actual user of the terminal device is also registered.
【0018】ATM端末装置(105)間で通信が開始される前
には、まず、端末装置からの接続要求を受け取ったATM-
SW(100)が、発着ATMアドレスを指定してアクセス制御サ
ーバ(800)に照会を行う。アクセス制御サーバ(800)は、
指定されたATMアドレスが現在どの端末装置で使用され
ているか、または、現在誰が使用している端末装置のも
のであるかを知るために、バインディングサーバ(200)
に対して照会を行う。そして、照会により得た端末装置
または利用者について設定されている属性を基に通信の
可否を判定し、ATM-SW(100)に通知する。Before communication is started between the ATM terminal devices (105), the ATM-terminal receiving the connection request from the terminal device first receives the connection request.
The SW (100) makes an inquiry to the access control server (800) by designating the incoming / outgoing ATM address. The access control server (800)
A binding server (200) to know which terminal device is currently using the specified ATM address or who is currently using the terminal device
Make an inquiry to. Then, based on the attributes set for the terminal device or the user obtained by the inquiry, it is determined whether communication is possible or not, and the ATM-SW (100) is notified.
【0019】次に、各端末装置の具体的な構成および動
作を説明する。Next, a specific configuration and operation of each terminal device will be described.
【0020】<バインディングサーバ>図2は、バイン
ディングサーバ(200)の構成例を示すブロック図であ
る。バインディングサーバ(200)は、CPU(202)、ROM(20
4)、RAM(203)などの一般的なコンピュータシステムの構
成に加え、ATMインタフェース回路(201)を有する。<Binding Server> FIG. 2 is a block diagram showing a configuration example of the binding server (200). The binding server (200) has a CPU (202) and a ROM (20
4) In addition to the general computer system configuration such as the RAM (203), it has an ATM interface circuit (201).
【0021】RAM(203)は、本ネットワークシステムに含
まれる端末装置のアドレスや名称、利用者などを表すデ
ータが格納される情報保持テーブル部(300)と、情報保
持テーブル部(300)のデータを登録・更新するためのプ
ログラムが格納された更新処理プログラム部(600)と、
他の端末装置からの問い合わせに応じて情報保持テーブ
ル部(300)のデータの検索および送信を行うためのプロ
グラムが格納された応答処理プログラム部(700)を有す
る。CPU(202)は、他の端末装置からのアクセスに応じ
て、更新処理プログラム部(600)および応答処理プログ
ラム部(700)の各プログラムを適宜選択し実行する。The RAM (203) includes an information holding table section (300) for storing data representing addresses, names, users and the like of terminal devices included in the network system, and a data for the information holding table section (300). Update processing program part (600) in which a program for registering and updating
It has a response processing program unit (700) in which a program for searching and transmitting data of the information holding table unit (300) in response to an inquiry from another terminal device is stored. The CPU (202) appropriately selects and executes each program of the update processing program section (600) and the response processing program section (700) in response to access from another terminal device.
【0022】図3に、情報保持テーブル部(300)の構造
を示す。情報保持テーブル部(300)は、端末情報保持部
分(310)と、ネットワークアドレス情報保持部分(320)
と、利用者情報保持部分(330)からなる。FIG. 3 shows the structure of the information holding table unit (300). The information holding table section (300) has a terminal information holding section (310) and a network address information holding section (320).
And a user information holding part (330).
【0023】端末情報保持部分(310)には、端末装置の
ネットワークインタフェースに割り当てられたMACアド
レスと、端末装置名称のデータと、他の情報保持部分(3
20,330)の対応する格納領域を指し示すポインターとの
組(端末情報(314))が格納される。この端末情報(314)
は、本ネットワークシステムに接続された全ての端末装
置について登録される。なお、MACアドレスと端末装置
名称のデータ、ネットワークアドレス情報保持部分(32
0)へのポインター、利用者情報保持部分(330)へのポイ
ンターは、それぞれ端末識別情報部(311)、ポインター
部(312)、ポインター部(313)に格納される。端末装置名
称は、数十文字からなる文字列により表現され(長さは
統一しなくてもよい)、各端末装置毎に固有である。The terminal information holding portion (310) includes a MAC address assigned to the network interface of the terminal device, data of the terminal device name, and other information holding portions (3).
20, 330) and a pointer (terminal information (314)) pointing to the corresponding storage area. This terminal information (314)
Is registered for all terminal devices connected to the network system. The MAC address and terminal device name data, network address information holding part (32
The pointer to (0) and the pointer to the user information holding part (330) are stored in the terminal identification information part (311), the pointer part (312), and the pointer part (313), respectively. The terminal device name is represented by a character string composed of several tens of characters (the length does not need to be unified), and is unique to each terminal device.
【0024】ネットワークアドレス情報保持部分(320)
には、各ネットワークインタフェースに割り当てられた
ATMアドレスと、ネットワークレイヤプロトコルアドレ
スと、端末情報保持部分(310)の対応する格納領域への
ポインターとの組(アドレス情報(323))が格納され
る。複数の仮想LANに所属するネットワークインタフェ
ースについては、アドレス情報(323)も連続して複数登
録される。また、ネットワークアドレス情報保持部分(3
20)には、各ネットワークインタフェース毎のアドレス
情報(323)の区分を示す終了表示(324)も格納される。な
お、ATMアドレスおよびネットワークレイヤプロトコル
アドレス、ポインターは、それぞれアドレスデータ部(3
21)、ポインター部(322)に格納される。アドレスデータ
部(321)には、アドレス種別毎に格納場所が用意されて
おり、使用されていないアドレス種別の部分にはnull値
が設定される。Network address information holding part (320)
Assigned to each network interface
A set (address information (323)) of an ATM address, a network layer protocol address, and a pointer to a corresponding storage area of the terminal information holding part (310) is stored. For network interfaces belonging to a plurality of virtual LANs, a plurality of pieces of address information (323) are continuously registered. In addition, the network address information holding part (3
20) also stores an end display (324) indicating the division of the address information (323) for each network interface. The ATM address, the network layer protocol address, and the pointer are respectively in the address data section (3
21) is stored in the pointer section (322). In the address data section (321), a storage location is prepared for each address type, and a null value is set in an unused address type portion.
【0025】利用者情報保持部分(330)には、各ネット
ワークインタフェースを使用する利用者の利用者名称の
データと、端末情報保持部分(310)の対応する格納領域
へのポインターとの組(利用者情報(333))が格納され
る。複数の利用者により使用されるネットワークインタ
フェースについては、利用者情報(333)も連続して複数
登録される。また、利用者情報保持部分(330)には、各
ネットワークインタフェース毎の利用者情報(333)の区
分を示す終了表示(334)も格納される。なお、利用者名
称のデータ、ポインターは、それぞれ利用者データ部(3
31)、ポインター部(322)に格納される。利用者名称は、
数十文字からなる文字列により表現され(長さは統一し
なくてもよい)、利用者毎に固有である。In the user information holding part (330), a set (use) of user name data of a user using each network interface and a pointer to a corresponding storage area of the terminal information holding part (310). Information (333)) is stored. For the network interface used by a plurality of users, a plurality of pieces of user information (333) are continuously registered. The user information holding part (330) also stores an end display (334) indicating the classification of the user information (333) for each network interface. The data of the user name and the pointer are stored in the user data section (3
31) is stored in the pointer section (322). The user name is
It is represented by a character string consisting of several tens of characters (the length does not need to be unified), and is unique for each user.
【0026】次に、本ネットワークシステムの端末装置
や利用者の登録・更新に関わる装置の動作を説明する。Next, the operation of the terminal device of this network system and the device relating to the registration / update of the user will be described.
【0027】図4および図5は、ATM端末装置(105)の起
動時に本ネットワークシステムで行われる通信を示すシ
ーケンス図である。FIGS. 4 and 5 are sequence diagrams showing communication performed in the present network system when the ATM terminal device (105) is activated.
【0028】図4で、ATM端末装置(105-1)は、ネットワ
ークに接続されて電源が投入されると(または、ネット
ワークインタフェースがリセットされると)、自装置(1
05-1)のMACアドレスを、ILMIプロトコル(401)によりATM
-SW(100)に通知する。ATM-SW(100)は、通知されたMACア
ドレスを基にATMアドレスを生成してATM端末装置(105-
1)に返答する。なお、ILMIプロトコルの詳細について
は、The ATM Forumが公開し、Prentice Hall社が発行し
ている“ATM User-Network Interface (UNI) Specifica
tion Version 3.1”, ISBN No.: 0-13-393828-Xに記述
されている。In FIG. 4, when the ATM terminal device (105-1) is connected to the network and turned on (or the network interface is reset), the ATM terminal device (105-1) becomes
05-1) MAC address by the ILMI protocol (401)
-Notify SW (100). The ATM-SW (100) generates an ATM address based on the notified MAC address and
Respond to 1). The details of the ILMI protocol are published by The ATM Forum and published by Prentice Hall, Inc. “ATM User-Network Interface (UNI) Specifica
Option Version 3.1 ”, ISBN No .: 0-13-393828-X.
【0029】そして、ATM端末装置(105-1)は、LECS(10
2)と共に、LANEプロトコルの一部であるLECS接続フェー
ズ(402)およびコンフィグレーションフェーズ(403)の処
理を実施し、さらに、LES(103)と共に、LANEプロトコル
の一部である参加フェーズ(404)の処理を実施する。こ
の処理の後、ATM端末装置(105-1)がBUS(103)と共に、LA
NEプロトコルの一部であるBUS接続フェーズ(405)の処理
を開始するまでの間に、LES(103)は、ATM端末装置(105-
1)のMACアドレスおよびATMアドレスを指定して、バイン
ディングサーバ(200)にATMアドレスの登録を要求(406)
する。Then, the ATM terminal device (105-1) sets the LECS (10
2), the processing of the LECS connection phase (402) and the configuration phase (403), which are part of the LANE protocol, is performed, and together with the LES (103), the participation phase (404), which is part of the LANE protocol. Is performed. After this processing, the ATM terminal device (105-1), together with the BUS (103),
Before starting the processing of the BUS connection phase (405) which is a part of the NE protocol, the LES (103)
Specifying the MAC address and ATM address of 1) and requesting the binding server (200) to register the ATM address (406)
I do.
【0030】なお、参加フェーズ(404)以降において、A
TM端末装置(105-1)が、LANEプロトコルの一部である登
録・削除の処理により追加のMACアドレスおよびATMアド
レスをLES(103)に登録したり、逆に、追加で登録したも
のを削除した際には、LES(103)は直ちにそれをバインデ
ィングサーバ(200)に通知(406)する。Note that after the participation phase (404), A
TM terminal device (105-1) registers additional MAC address and ATM address in LES (103) by registration / deletion processing that is part of LANE protocol, or deletes additional registration When doing so, the LES (103) immediately notifies (406) it to the binding server (200).
【0031】図5で、ATM端末装置(105-1)は、図4の処
理に続き、DHCプロトコル(501)によりDHCPサーバ(101)
からIPアドレスの割当を受ける。この際、DHCPサーバ(1
01)とATM端末装置(105-1)との間にVC(Virtual Channel)
コネクションを確立するため、LANEプロトコルの一部で
あるアドレス解決プロトコル(502)およびVCセットアッ
ププロトコル(504)の処理が実施される。この時、DHCP
サーバ(101)は、IPアドレスを割り当てるATM端末装置(1
05-1)からDHCプロトコルのDHCP_REQUESTメッセージを受
け取ってから、当該ATM端末装置(105-1)にDHCプロトコ
ルのDHCP_ACKメッセージを渡す直前までの間に、当該AT
M端末装置(105-1)のMACアドレスおよびIPアドレスを指
定してバインディングサーバ(200)に対しIPアドレスの
登録を要求(503)する。次に、ATM端末装置(105-1)は、
バインディングサーバ(200)との間でVCコネクションを
確立(504)し、ATM端末装置(105-1)上のLoginプログラム
により認識した利用者名称を指定して、その登録をバイ
ンディングサーバ(200)に要求(505)する。In FIG. 5, the ATM terminal device (105-1) follows the process of FIG. 4 and the DHCP server (101) by the DHC protocol (501).
Receives an IP address assignment from. At this time, the DHCP server (1
01) and the ATM terminal device (105-1) between VC (Virtual Channel)
In order to establish a connection, processing of an address resolution protocol (502) and a VC setup protocol (504), which are part of the LANE protocol, is performed. At this time, DHCP
The server (101) allocates an IP address to the ATM terminal device (1
05-1) from receiving the DHCP_REQUEST message of the DHC protocol to immediately before passing the DHCP_ACK message of the DHC protocol to the ATM terminal device (105-1).
The MAC address and IP address of the M terminal device (105-1) are designated, and the binding server (200) is requested to register the IP address (503). Next, the ATM terminal device (105-1)
Establish a VC connection with the binding server (200) (504), specify the user name recognized by the Login program on the ATM terminal device (105-1), and register the registration to the binding server (200). Request (505).
【0032】以上の手順で、現在ネットワーク上で稼働
状態にある各端末装置のアドレスと利用者名称の登録要
求が、バインディングサーバ(200)になされる。With the above procedure, a request for registration of the address and the user name of each terminal device currently operating on the network is made to the binding server (200).
【0033】なお、VCセットアッププロトコルの詳細に
ついては、The ATM Forumが公開し、Prentice Hall社が
発行している“ATM User-Network Interface (UNI) Spe
cification Version 3.1”, ISBN No.: 0-13-393828-X
に記述されている。また、DHCプロトコルについては、T
he ATM Forumが公開し、IETFが発行している“Dynamic
Host Configuration Protocol”, RFC1541, Oct. '93に
記述されている。The details of the VC setup protocol are disclosed by The ATM Forum and published by Prentice Hall, Inc., “ATM User-Network Interface (UNI) Spe
cification Version 3.1 ”, ISBN No .: 0-13-393828-X
It is described in. For the DHC protocol, T
he “Dynamic” published by the ATM Forum and published by the IETF
Host Configuration Protocol ", RFC 1541, Oct. '93.
【0034】次に、バインディングサーバ(200)におけ
る情報保持テーブル部(300)のデータの登録・更新方法
について説明する。Next, a method of registering / updating data in the information holding table unit (300) in the binding server (200) will be described.
【0035】図6は、バインディングサーバ(200)の登
録処理を示すフローチャートである。FIG. 6 is a flowchart showing a registration process of the binding server (200).
【0036】(アドレス登録処理)まず、アドレスの登
録処理(6100)について説明する。アドレスの登録要求を
受けたバインディングサーバ(200)は、指定されたMACア
ドレスと一致するものを端末情報保持部分(310)の端末
識別情報部(311)で検索する(6110)。そして、検索したM
ACアドレスの設定された端末情報(314)のポインター部
(312)のポインターから、ネットワークアドレス情報保
持部分(320)に格納された対応するアドレス情報(323)を
特定する。このとき、上記ポインターが示す位置からア
ドレス情報終了表示(324)の位置までに格納されている
全てものが、対応するアドレス情報(323)として特定さ
れる。そして、特定したアドレス情報(323)のアドレス
データ部(321)で、該当するアドレス種別の位置にnull
値が設定されたアドレスデータ部(321)を検索し(612
0)、そこにアドレスを設定する(6130)。このとき、該当
するアドレス種別の位置にnull値が設定されたアドレス
データ部(321)が無い場合には、新たにアドレス情報(32
3)を追加する(6140)。このとき、該当するアドレス種別
を記録する部分以外はnull値を設定し、ポインター部(3
22)には、登録対象の端末装置の端末情報(314)の格納位
置を設定する。なお、登録対象としている端末装置にま
だアドレスが割り当てられていない場合には、ポインタ
ー部(312)のポインターの指定する位置にはアドレス情
報終了表示(324)しかない。この場合も上記と同様に、
新たにアドレス情報(323)を作成および追加する(614
0)。(Address Registration Processing) First, the address registration processing (6100) will be described. Upon receiving the address registration request, the binding server (200) searches the terminal identification information part (311) of the terminal information holding part (310) for a match with the specified MAC address (6110). And the searched M
Pointer part of terminal information (314) with AC address set
From the pointer of (312), the corresponding address information (323) stored in the network address information holding part (320) is specified. At this time, everything stored from the position indicated by the pointer to the position of the address information end display (324) is specified as the corresponding address information (323). Then, in the address data part (321) of the specified address information (323), null is set at the position of the corresponding address type.
The address data part (321) in which the value is set is searched for (612
0), an address is set there (6130). At this time, if there is no address data part (321) in which a null value is set at the position of the corresponding address type, address information (32
3) is added (6140). At this time, a null value is set except for the part where the corresponding address type is recorded, and the pointer part (3
In 22), the storage location of the terminal information (314) of the terminal device to be registered is set. If an address has not been assigned to the terminal device to be registered, there is only an address information end display (324) at the position specified by the pointer in the pointer section (312). In this case, as above,
Create and add new address information (323) (614
0).
【0037】(利用者登録処理)次に、利用者の登録処
理(6200)について説明する。利用者の登録要求を受けた
バインディングサーバ(200)は、指定されたMACアドレス
と一致するものを端末情報保持部分(310)の端末識別情
報部(311)で検索し(6210)、検索したMACアドレスの設定
された端末情報(314)に対応する利用者情報保持部分(33
0)の格納領域を特定する。そして、特定した領域に利用
者情報(333)を追加する(6220)。(User Registration Process) Next, the user registration process (6200) will be described. Upon receiving the user registration request, the binding server (200) searches for a match with the specified MAC address in the terminal identification information section (311) of the terminal information holding portion (310) (6210), and searches the searched MAC. The user information holding part (33) corresponding to the terminal information (314) for which the address is set
Specify the storage area of (0). Then, the user information (333) is added to the specified area (6220).
【0038】図7は、登録の削除処理を示したフローチ
ャートである。FIG. 7 is a flowchart showing a registration deletion process.
【0039】(アドレス削除処理)まず、登録されたア
ドレスの削除処理(6300)について説明する。アドレスの
削除要求を受けたバインディングサーバ(200)は、ま
ず、指定されたMACアドレスと一致するものを端末情報
保持部分(310)の端末識別情報部(311)で検索し(6310)、
検索したMACアドレスの設定された端末情報(314)に対応
するアドレス情報(323)を特定する。特定したアドレス
情報(323)のアドレスデータ部(321)で、指定されたアド
レスを検索し(6320)、検索したアドレスの格納位置にnu
ll値を設定する(6340)。そして、そのアドレスデータ部
(321)が全てnull値となったか否かを調べ(6350)、全てn
ull値ならそのアドレス情報(323)の全てのデータを削除
する(6360)。さらに、特定したアドレス情報(323)がな
くなり、アドレス情報終了表示(324)しか残っていない
かどうかを調べ(6370)、アドレス情報終了表示(324)し
か残っていない場合には、対応する利用者情報(333)の
データも全て削除する(6380)。(Address Deletion Processing) First, the deletion processing (6300) of the registered address will be described. Upon receiving the address deletion request, the binding server (200) first searches the terminal identification information part (311) of the terminal information holding part (310) for a match with the specified MAC address (6310),
The address information (323) corresponding to the terminal information (314) set with the searched MAC address is specified. In the address data section (321) of the specified address information (323), the specified address is searched (6320), and nu is stored in the storage location of the searched address.
Set the ll value (6340). And the address data part
Check whether (321) is all null values (6350), all n
If it is a ull value, all data of the address information (323) is deleted (6360). Further, it is checked whether the specified address information (323) is lost and only the address information end display (324) remains (6370), and if only the address information end display (324) remains, the corresponding user is checked. All data of the information (333) is also deleted (6380).
【0040】なお、ATMアドレスの削除要求は、LES/BUS
(103)とATM端末装置(105)との間のVCコネクションの
内、LANEプロトコルで規定されたControl Direct VCC、
ControlDistribute VCC、Multicast Send VCC、およ
び、Multicast Forward VCCのいずれかが切断された時
点で、LES(103)から送られる。また、IPアドレスの削除
要求は、DHCPサーバ(101)がATM端末装置(105)に割り当
てたIPアドレスの有効期限が切れた時点、または、割り
当てられたIPアドレスをATM端末装置(105)がDHCPサーバ
(101)に返却した時点で、DHCPサーバ(101)から送られ
る。It should be noted that the ATM address deletion request is sent to the LES / BUS
Among the VC connections between (103) and the ATM terminal device (105), Control Direct VCC specified by the LANE protocol,
Sent from the LES (103) when any one of ControlDistribute VCC, Multicast Send VCC, and Multicast Forward VCC is disconnected. Also, the IP address deletion request is issued when the IP address assigned by the DHCP server (101) to the ATM terminal device (105) expires or when the ATM terminal device (105) assigns the assigned IP address to the ATM terminal device (105). server
When it is returned to (101), it is sent from the DHCP server (101).
【0041】(利用者削除処理)次に、利用者の登録の
削除処理(6400)について説明する。利用者の登録の削除
要求を受けたバインディングサーバ(200)は、まず、削
除対象の利用者が使用する端末装置のMACアドレスと一
致するものを、端末情報保持部分(310)の端末識別情報
部(311)で検索し(6410)、検索したMACアドレスの設定さ
れた端末情報(314)に対応する利用者情報(333)を特定
し、特定した利用者情報(333)の利用者データ部(331)に
おいて、指定された削除対象の利用者名称に一致する利
用者名称が設定された利用者情報(333)を検索する(642
0)。そして、検索した利用者情報(333)のデータを削除
する(6430)。なお、利用者の登録の削除要求は、ATM端
末装置(105)のLogoutプログラムにより、ATM端末装置(1
05)から送られる。(User Deletion Process) Next, a user registration deletion process (6400) will be described. Upon receiving the request to delete the user registration, the binding server (200) first checks the terminal ID information part of the terminal information holding part (310) for the one that matches the MAC address of the terminal device used by the user to be deleted. Searched in (311) (6410), the user information (333) corresponding to the set terminal information (314) of the searched MAC address is identified, and the user data portion (333) of the identified user information (333) In (331), the user information (333) in which the user name matching the specified user name to be deleted is set is searched (642).
0). Then, the data of the searched user information (333) is deleted (6430). Note that the user registration deletion request is sent to the ATM terminal device (1) by the logout program of the ATM terminal device (105).
Sent from 05).
【0042】次に、照会要求に応じて行われるバインデ
ィングサーバ(200)の返答処理について説明する。Next, the response processing of the binding server (200) performed in response to the inquiry request will be described.
【0043】(アドレス返答処理)図8は、アドレス返
答処理を示すフローチャートである。(Address Reply Process) FIG. 8 is a flowchart showing the address reply process.
【0044】まず、指定された利用者名称からアドレス
を返答する処理(6500)について説明する。アドレスの照
会要求を受けたバインディングサーバ(200)は、指定さ
れた利用者名称を利用者データ部(331)で検索し(651
0)、その利用者名称が設定された利用者情報(333)が存
在するかどうかを判断する(6520)。そして、存在しない
場合には、未利用の旨を要求元に返答する(6570)。存在
する場合には、その利用者情報(333)に対応する端末情
報(314)を読み(6530)、その端末情報(314)に対応するア
ドレス情報(323)において、指定されたアドレス種別の
位置を検索する(6540)。そして、終了表示に達するまで
にnull以外の値があるかどうかを判断し(6550)、あった
ならその値を返答する(6560)。なければ、利用者無しの
旨を返答する(6570)。First, the process (6500) of returning an address from a designated user name will be described. Upon receiving the address inquiry request, the binding server (200) searches for the specified user name in the user data section (331) (651).
0), it is determined whether or not there is user information (333) in which the user name is set (6520). If it does not exist, a response indicating that it is not used is returned to the request source (6570). If there is, the terminal information (314) corresponding to the user information (333) is read (6530), and in the address information (323) corresponding to the terminal information (314), the position of the specified address type is determined. (6540). Then, it is determined whether there is a value other than null before reaching the end display (6550), and if so, the value is returned (6560). If not, it responds that there is no user (6570).
【0045】次に、指定された装置名称からアドレスを
返答する処理(6600)について説明する。アドレスの照会
要求を受けたバインディングサーバ(200)は、指定され
た装置名称を端末識別情報部(311)で検索(6610)し、そ
の装置名称が設定された端末情報(314)が存在するかど
うかを判断する(6620)。存在しない場合には、未利用の
旨を返答する(6660)。存在する場合にはその端末情報(3
14)に対応するアドレス情報(323)のアドレスデータ部(3
21)で、指定されたアドレス種別の位置を検索する(663
0)。終了表示に達するまでにnull以外の値があるかどう
かを判断し(6640)、あったならその値を返答する(665
0)。なければ未利用の旨を返答する(6660)。Next, the process (6600) of returning an address from a designated device name will be described. Upon receiving the address inquiry request, the binding server (200) searches for the specified device name in the terminal identification information section (311) (6610), and determines whether there is terminal information (314) in which the device name is set. It is determined whether it is (6620). If it does not exist, it responds that it is not used (6660). If it exists, its terminal information (3
The address data part (3) of the address information (323) corresponding to (14)
21), search for the position of the specified address type (663
0). It is determined whether there is a non-null value before reaching the end display (6640), and if so, the value is returned (665).
0). If not, it responds that it is not used (6660).
【0046】(利用者返答処理)図9は、指定されたア
ドレスから利用者名称を返答する処理(6700)を示すフロ
ーチャートである。利用者名称の照会要求を受けたバイ
ンディングサーバ(200)は、指定されたアドレスをアド
レスデータ部(321)で検索し(6710)、そのアドレスが設
定されたアドレス情報(323)が存在するかどうかを判断
する(6720)。存在しない場合には未登録の旨を返答する
(6780)。存在する場合には、そのアドレス情報(323)に
対応する端末情報(314)を読み込み(6730)、さらに、そ
の端末情報(314))に対応する利用者情報(333)を読み込
む(6740)。そして、終了表示以外のデータがあるかどう
かを判断し(6750)、存在する場合、読み込んだ利用者情
報(333)の全ての内容を返答する(6760)。終了表示しか
なければ、読み込んだ端末情報(314)のMACアドレスを返
答する(6770)。(User Response Process) FIG. 9 is a flow chart showing a process (6700) for replying a user name from a designated address. Upon receiving the user name inquiry request, the binding server (200) searches the specified address in the address data part (321) (6710), and determines whether there is address information (323) in which the address is set. Is determined (6720). If it does not exist, reply that it is not registered
(6780). If there is, the terminal information (314) corresponding to the address information (323) is read (6730), and the user information (333) corresponding to the terminal information (314) is read (6740). Then, it is determined whether or not there is data other than the end display (6750). If there is data, all the contents of the read user information (333) are returned (6760). If there is only an end display, the MAC address of the read terminal information (314) is replied (6770).
【0047】<アクセス制御サーバ>次に、アクセス制
御サーバ(800)について説明する。<Access Control Server> Next, the access control server (800) will be described.
【0048】図10は、アクセス制御サーバ(800)の構
成例を示すブロック図である。アクセス制御サーバ(80
0)も、CPU(202)、ROM(204)、RAM(803)などの一般的なコ
ンピュータシステムの構成に加え、ATMインタフェース
回路(201)を有する。FIG. 10 is a block diagram showing a configuration example of the access control server (800). Access control server (80
0) also has an ATM interface circuit (201) in addition to the configuration of a general computer system such as a CPU (202), a ROM (204), and a RAM (803).
【0049】RAM(803)は、本ネットワークシステムの利
用者に関する情報や、アプリケーションサーバやネット
ワークプリンタなどのネットワーク機器(端末装置の一
種)に関する情報のデータが格納される情報保持テーブ
ル部(900)と、外部からの照会要求に応じて情報保持テ
ーブル部(900)のデータの検索および返答を行うための
プログラムが格納された応答処理プログラム部(1100)を
有する。応答処理プログラム部(1100)のプログラムは、
CPU(202)により実行される。The RAM (803) includes an information holding table (900) for storing data on information on users of the network system and information on network devices (a type of terminal device) such as application servers and network printers. And a response processing program section (1100) in which a program for searching and replying to data in the information holding table section (900) in response to an external inquiry request is stored. The program of the response processing program section (1100)
It is executed by the CPU (202).
【0050】図11に、情報保持テーブル部(900)の構
造を示す。情報保持テーブル部(900)には、本ネットワ
ークシステムの利用者の番号と名称と属性情報を示すデ
ータの組(914-1)と、本ネットワークに接続されたネッ
トワーク機器のMACアドレスと属性情報を示すデータの
組(914-2)とが格納された登録済利用者・装置情報保持
部(910)が含まれる。登録されたデータの最後には、終
了表示(932)が格納される。上記のデータの内、利用者
の番号および名称とMACアドレスはデータ部(930)に格納
され、利用者や装置の属性データは属性データ保持部(9
20)に格納される。また、情報保持テーブル部(900)に
は、データ部(930)に格納されたデータの種類を特定で
きるように、利用者名称データならば“1”、MACアド
レスデータであれば“2”、終了表示であれば“0”が
それぞれ格納されるデータ種別表示部(911)も含まれ
る。FIG. 11 shows the structure of the information holding table unit (900). The information holding table unit (900) stores a data set (914-1) indicating the number, name, and attribute information of the user of the network system, and the MAC address and attribute information of the network device connected to the network. A registered user / device information holding unit (910) in which a data set (914-2) shown is stored. At the end of the registered data, an end indication (932) is stored. Among the above data, the user number, name and MAC address are stored in the data section (930), and the attribute data of the user and the device are stored in the attribute data holding section (9).
Stored in 20). The information holding table unit (900) has "1" for user name data and "2" for MAC address data so that the type of data stored in the data unit (930) can be specified. In the case of the end display, a data type display section (911) in which "0" is stored is also included.
【0051】各属性データは、本ネットワークシステム
の運用上必要となる複数種類の属性の各々を1ビットで
表すビット列からなり、各ビットには、属性を持つなら
“1”、属性を持たないなら“0”が設定される。な
お、この属性は、例えばグループを意味する場合、その
属性を持つことによりそのグループに属してることを意
味する表現となる。基本的なネットワークサービス機能
を提供するLECS(102)やLES/BUS(103)等のサーバ装置に
対しては、全ての属性を持つように属性データを設定
し、サービスを無条件に提供するようにしてもよい。Each attribute data is composed of a bit string representing each of a plurality of types of attributes required for the operation of the present network system with one bit. If each bit has an attribute, it is “1”. “0” is set. In addition, when this attribute means a group, for example, it is an expression that means that it belongs to the group by having the attribute. For server devices such as LECS (102) and LES / BUS (103) that provide basic network service functions, set attribute data to have all attributes and provide services unconditionally. It may be.
【0052】次に、アクセス制御サーバ(800)が通信に
どのように関わるかを説明する。Next, how the access control server (800) is involved in communication will be described.
【0053】図12は、本ネットワークシステムで、2
台のATM端末装置(105-1,105-2)が通信を行なう際の処理
を示すシーケンス図である。なお、この図には、2台の
ATM端末装置(105-1,105-2)がそれぞれ初期登録の動作
(図4および図5)を済ませた後のシーケンスを示して
いる。FIG. 12 shows this network system.
FIG. 8 is a sequence diagram showing a process when two ATM terminal devices (105-1, 105-2) perform communication. In this figure, two units
The sequence after the ATM terminal devices (105-1, 105-2) have completed the initial registration operation (FIGS. 4 and 5) is shown.
【0054】まず、発信側のATM端末装置(105-1)は、通
信相手のATM端末装置(105-2)のIPアドレスを知るため
に、通信相手の利用者名を指定してバインディングサー
バ(200)にIPアドレスを照会(1002)する。そして、着信
側のATM端末装置 (105-2)のMACアドレスを知るために、
ARPプロトコル(1003)によりARPリクエストをブロードキ
ャストで送信する。First, in order to know the IP address of the ATM terminal device (105-2) of the communication partner, the ATM terminal device (105-1) on the calling side specifies the user name of the communication partner and specifies the binding server (105-1). Inquire (1002) the IP address to (200). Then, in order to know the MAC address of the called ATM terminal device (105-2),
An ARP request is transmitted by broadcast using the ARP protocol (1003).
【0055】ARPリクエストを受信した着信側のATM端末
装置(105-2)は、LANEプロトコルの一部であるアドレス
解決プロトコル(502)により、要求元のATM端末装置(105
-1)のMACアドレスをLES(103)に指定してATMアドレスを
得る。そして、VCセットアッププロトコル(504)によ
り、発信側のATM端末装置(105-1)との間にVCコネクショ
ンを確立するようにATM-SW(100)に要求する。ATM-SW(10
0)は、接続対象のATM端末装置(105-1,105-2)のATMアド
レスを指定して、上記VCコネクションの確立が可能か否
かをアクセス制御サーバ(800)に問い合わせる。The receiving-side ATM terminal device (105-2) that has received the ARP request uses the address resolution protocol (502), which is a part of the LANE protocol, to send the requesting ATM terminal device (105-2).
-1) Specify the MAC address in LES (103) to get the ATM address. The VC setup protocol (504) requests the ATM-SW (100) to establish a VC connection with the ATM terminal device (105-1) on the transmitting side. ATM-SW (10
(0) specifies the ATM address of the ATM terminal device (105-1, 105-2) to be connected, and inquires of the access control server (800) whether or not the VC connection can be established.
【0056】問い合わせを受けたアクセス制御サーバ(8
00)は、指定された各ATMアドレスが割り当てられている
端末装置の現在の利用者を知るために、ATMアドレスを
指定してバインディングサーバ(200)に、利用者名称を
照会する。そして、得た利用者名称の利用者について設
定された属性データ(921-1,921-2)から通信の可否を判
断し、判断結果をATM-SW(100)に返答する。The access control server (8
00) specifies the ATM address and inquires the binding server (200) of the user name to know the current user of the terminal device to which each specified ATM address is assigned. Then, based on the attribute data (921-1,921-2) set for the user having the obtained user name, it is determined whether communication is possible or not, and the determination result is returned to the ATM-SW (100).
【0057】ATM-SW(100)は、返答された判断結果が通
信可能を示す場合、ATM端末装置(105-1,105-2)間にVC
コネクションを確立する。VCコネクションの確立後、着
信側のATM端末装置(105-2)は、ARPリクエストの応答と
して、自装置のMACアドレスをATM端末装置(105-1)に送
る。ATM端末装置(105-1)は、LANEプロトコルの一部であ
るアドレス解決プロトコル(502)により、送られたATM端
末装置(105-2)のMACアドレスをLES(103)に指定して、AT
Mアドレスを得る。そして、得たATMアドレスに対するVC
を用いて通信を開始する。When the returned determination result indicates that communication is possible, the ATM-SW (100) transmits a VC between the ATM terminal devices (105-1, 105-2).
Establish a connection. After the establishment of the VC connection, the receiving-side ATM terminal device (105-2) sends the MAC address of the own device to the ATM terminal device (105-1) as a response to the ARP request. The ATM terminal (105-1) specifies the MAC address of the ATM terminal (105-2) sent to the LES (103) by the address resolution protocol (502) which is a part of the LANE protocol, and
Get M address. Then, VC for the obtained ATM address
Start communication using.
【0058】次に、アクセス制御サーバ(800)の動作を
より詳しく説明する。Next, the operation of the access control server (800) will be described in more detail.
【0059】前述のように、ATM-SW(100)より問い合わ
せを受けたアクセス制御サーバ(800)は、発着側それぞ
れのATMアドレスを指定して、バインディングサーバ(20
0)に利用者を照会する。この照会によりバインディング
サーバ(200)は、利用者がいる装置なら利用者名称を返
答し、利用者がいない装置ならMACアドレスを返答すい
る。アクセス制御サーバ(800)は、返答されたデータを
情報保持テーブル部(図9)のデータ部(930)で検索
し、返答されたデータに対応する属性データ保持部分(9
20)の属性データ(921)を得る。そして、得た2つの属性
データ(921-1,921-2)に、全ビット“1”の属性データ
が含まれる場合は、通信の許可をATM-SW(100)に通知す
る。それ以外の場合には、2つの属性データに対して算
術的論理積演算を実施し、結果が“0”でなければ「通
信許可」の返答を行い、結果が“0”であれば「通信不
許可」の返答を行う。なお、複数の利用者名称が返答さ
れたものについては、共用装置用に設定しておく既定の
属性値を用いる。As described above, the access control server (800) receiving the inquiry from the ATM-SW (100) designates each ATM address of the caller and the caller, and specifies the ATM address of the caller / receiver.
Inquire the user at 0). In response to this inquiry, the binding server (200) returns a user name if the device has a user, and returns a MAC address if the device does not have a user. The access control server (800) searches the returned data in the data section (930) of the information holding table section (FIG. 9), and finds the attribute data holding section (9) corresponding to the returned data.
20) Attribute data (921) is obtained. If the two pieces of attribute data (921-1, 921-2) obtained include attribute data of all bits “1”, the communication permission is notified to the ATM-SW (100). In other cases, an arithmetic AND operation is performed on the two pieces of attribute data, and if the result is not "0", a reply of "communication permitted" is given. Reply "Not allowed". Note that, for those to which a plurality of user names have been replied, a predetermined attribute value set for the shared device is used.
【0060】以上で説明したように、本ネットワークシ
ステムでは、バインディングサーバ(200)の利用によ
り、各装置が、端末装置のアドレスと、その端末装置の
現在の利用者との対応を把握することができる。また、
利用者は、任意の位置で任意の端末を用いて通信を行う
ことができる。さらに、バインディングサーバ(200)と
アクセス制御サーバ(800)により、端末装置間の通信
を、端末装置の現在の利用者について設定された属性情
報を基に制限することができる。As described above, in the present network system, by using the binding server (200), each device can grasp the correspondence between the address of the terminal device and the current user of the terminal device. it can. Also,
The user can perform communication using an arbitrary terminal at an arbitrary position. Further, the communication between the terminal devices can be restricted by the binding server (200) and the access control server (800) based on the attribute information set for the current user of the terminal device.
【0061】[0061]
【発明の効果】本発明によれば、通信ネットワーク上の
各種装置が端末装置とその現在の利用者との対応関係を
把握できるようにすることができる。According to the present invention, various devices on the communication network can grasp the correspondence between the terminal device and its current user.
【0062】さらに、通信ネットワーク上の各種装置が
端末装置間の通信をその現在の利用者を基に制限できる
ようにすることができる。Further, various devices on the communication network can restrict communication between terminal devices based on the current user.
【図1】 本発明の実施形態に係るネットワークシステ
ムの全体構成を示す図である。FIG. 1 is a diagram showing an overall configuration of a network system according to an embodiment of the present invention.
【図2】 バインディングサーバの全体構成を示す図で
ある。FIG. 2 is a diagram illustrating an overall configuration of a binding server.
【図3】 バインディングサーバ内のテーブルの構造を
示す図である。FIG. 3 is a diagram showing a structure of a table in a binding server.
【図4】 バインディングサーバへのATMアドレスの登
録に関わる一連の通信を示すシーケンス図である。FIG. 4 is a sequence diagram showing a series of communications relating to registration of an ATM address in a binding server.
【図5】 IPアドレスおよび利用者名称の登録に関わる
一連の通信を示すシーケンス図である。FIG. 5 is a sequence diagram showing a series of communications relating to registration of an IP address and a user name.
【図6】 更新処理プログラム部の登録処理を示すフロ
ーチャートである。FIG. 6 is a flowchart illustrating registration processing of an update processing program unit.
【図7】 更新処理プログラム部の削除処理を示すフロ
ーチャートである。FIG. 7 is a flowchart illustrating a deletion process of an update processing program unit.
【図8】 応答処理プログラム部の端末装置への応答処
理を示すフローチャートである。FIG. 8 is a flowchart illustrating a response process performed by the response processing program unit to the terminal device.
【図9】 応答処理プログラム部のアクセス制御サーバ
への応答処理を示すフローチャートである。FIG. 9 is a flowchart showing a response process of the response processing program unit to the access control server.
【図10】 アクセス制御サーバの全体構成を示す図で
ある。FIG. 10 is a diagram illustrating an overall configuration of an access control server.
【図11】 アクセス制御サーバ内のテーブルの構造を
示す図である。FIG. 11 is a diagram showing a structure of a table in the access control server.
【図12】 端末装置間の通信の可否の判断に関わる一
連の通信を示すシーケンス図である。FIG. 12 is a sequence diagram showing a series of communications related to a determination as to whether or not communication between terminal devices is possible.
100・・・ATMスイッチ 101・・・DHCPサーバ 102・・・LECS 103・・・LES/BUS 104・・・ルートサーバ 105・・・ATM端末装置 106・・・IEEE802.3LAN用スイッチ 107・・・IEEE802.3LAN用端末装置 200・・・バインディングサーバ 800・・・アクセス制御サーバ 406・・・MAC, ATMアドレス対通知メッセージ 1001・・・アクセス可否照会シーケンス 100: ATM switch 101: DHCP server 102: LECS 103: LES / BUS 104: Route server 105: ATM terminal device 106: IEEE802.3 LAN switch 107: IEEE 802.3 LAN terminal device 200 binding server 800 access control server 406 MAC / ATM address pair notification message 1001 access permission inquiry sequence
───────────────────────────────────────────────────── フロントページの続き (72)発明者 林 謙治 神奈川県海老名市下今泉810番地 株式会 社日立製作所オフィスシステム事業部内 (72)発明者 新 善文 神奈川県海老名市下今泉810番地 株式会 社日立製作所オフィスシステム事業部内 (72)発明者 峰尾 晃 神奈川県横浜市戸塚区戸塚町5030番地 株 式会社日立製作所ソフトウェア開発本部内 ──────────────────────────────────────────────────続 き Continuing on the front page (72) Inventor Kenji Hayashi 810 Shimo-Imaizumi, Ebina-shi, Kanagawa Prefecture Inside the Office Systems Division of Hitachi, Ltd. (72) Inventor Akira Mineo 5030 Totsuka-cho, Totsuka-ku, Yokohama-shi, Kanagawa Prefecture Software Development Division, Hitachi, Ltd.
Claims (7)
を管理する通信管理装置とが接続された通信ネットワー
クに接続される情報管理装置であって、 前記各端末装置を識別するための端末識別情報と、当該
端末装置に割り当てられたアドレス情報と、当該端末装
置の利用者を識別するための利用者識別情報とを対応付
けて保持する記憶手段と、 前記端末装置もしくは通信管理装置から送られた登録要
求に応じて、前記記憶手段で保持されている前記端末識
別情報とアドレス情報と利用者識別情報との対応が、現
時点における通信ネットワークの利用状態を反映したも
のとなるように、前記記憶手段で保持されている情報を
更新する手段と、 前記端末装置もしくは通信管理装置から送られた端末識
別情報もしくはアドレス情報もしくは利用者識別情報に
応じて、当該送られた情報に対応して前記記憶手段で保
持されている情報を前記端末装置もしくは通信管理装置
に返送する手段とを有することを特徴とする情報管理装
置。An information management device connected to a communication network in which a plurality of terminal devices and a communication management device that manages communication between the terminal devices are connected, and an information management device for identifying each of the terminal devices. Storage means for holding terminal identification information, address information assigned to the terminal device, and user identification information for identifying a user of the terminal device in association with each other; In response to the sent registration request, the correspondence between the terminal identification information, the address information, and the user identification information held in the storage unit reflects the current usage state of the communication network, Means for updating the information held in the storage means, terminal identification information or address information or use sent from the terminal device or the communication management device Depending on the identification information, the information management apparatus characterized by having a means for returning information corresponding to the sent information held by the storage means to the terminal device or the communication management device.
利用者識別情報とを、前記各端末装置毎に1つ以上保持
することを特徴とする情報管理装置。2. The information management apparatus according to claim 1, wherein said storage means stores at least one of the terminal identification information, the address information, and the user identification information for each of the terminal devices. An information management device characterized by the following.
端末装置と、当該端末装置間の通信を管理する通信管理
装置とが接続された通信ネットワークに接続される情報
管理装置であって、 前記端末装置の利用者を識別するための利用者識別情報
と、当該利用者について設定された属性情報とを対応付
けて保持する記憶手段と、 前記通信管理装置から送られた、通信を開始しようとす
る発側および着側の端末装置の端末識別情報に応じて、
当該2つの端末識別情報を請求項1に記載の情報管理装
置に送り、前記発側および着側の端末装置の利用者の利
用者識別情報を得る手段と、 当該手段により得た利用者識別情報に対応して前記第2
の記憶手段で保持されている属性情報を基に、前記通信
を開始しようとする端末装置の相互の接続の可否を決定
し、決定結果を前記通信管理装置に返送する手段とを有
することを特徴とする情報管理装置。3. An information management device connected to a communication network in which the information management device according to claim 1, a plurality of terminal devices, and a communication management device for managing communication between the terminal devices are connected. Storage means for holding user identification information for identifying the user of the terminal device and attribute information set for the user in association with each other; and transmitting the communication sent from the communication management device. According to the terminal identification information of the calling and called terminal devices to be started,
Means for sending the two terminal identification information to the information management device according to claim 1, and obtaining user identification information of a user of the calling side and destination side terminal devices; and user identification information obtained by the means. Corresponding to the second
Means for determining whether or not the terminal devices that are to start the communication can connect with each other based on the attribute information held in the storage means, and returning the determination result to the communication management device. Information management device.
別情報と、当該端末装置について設定された属性情報と
を対応付けて保持することを特徴とする情報管理装置。4. The information management device according to claim 3, wherein the storage unit associates terminal identification information for identifying the terminal device with attribute information set for the terminal device. An information management device characterized by holding.
を管理する通信管理装置とが接続された通信ネットワー
クに接続される情報管理装置であって、 前記各端末装置を識別するための端末識別情報と、当該
端末装置に割り当てられたアドレス情報と、当該端末装
置の利用者を識別するための利用者識別情報とを対応付
けて保持する第1の記憶手段と、 前記端末装置もしくは通信管理装置から送られた登録要
求に応じて、前記記憶手段で保持されている前記端末識
別情報とアドレス情報と利用者識別情報との対応が、現
時点における通信ネットワークの利用状態を反映したも
のとなるように、前記記憶手段で保持されている情報を
更新する手段と、 前記端末装置もしくは通信管理装置から送られた、端末
識別情報もしくはアドレス情報もしくは利用者識別情報
に応じて、当該送られた情報に対応して前記記憶手段で
保持されている情報を前記端末装置もしくは通信管理装
置に返送する手段と、 前記端末装置の利用者を識別するための利用者識別情報
と、当該利用者について設定された属性情報とを対応付
けて保持する第2の記憶手段と、 前記通信管理装置から送られた、通信を開始しようとす
る発側および着側の端末装置の端末識別情報に応じて、
当該2つの端末識別情報に対応して前記第1の記憶手段
で保持されている利用者識別情報を得る手段と、 当該手段により得た利用者識別情報に対応して前記第2
の記憶手段で保持されている属性情報を基に、前記通信
を開始しようとする端末装置の相互の接続の可否を決定
し、決定結果を前記端末識別情報を送った通信管理装置
に返送する手段とを有することを特徴とする情報管理装
置。5. An information management device connected to a communication network in which a plurality of terminal devices and a communication management device for managing communication between the terminal devices are connected. First storage means for holding terminal identification information, address information assigned to the terminal device, and user identification information for identifying a user of the terminal device in association with each other; In response to the registration request sent from the management device, the correspondence between the terminal identification information, the address information, and the user identification information held in the storage unit reflects the current usage state of the communication network. Means for updating the information held in the storage means, and terminal identification information or address information transmitted from the terminal device or the communication management device. Means for returning information held in the storage means to the terminal device or the communication management device in accordance with the transmitted information in accordance with the user identification information, and identifying a user of the terminal device Storage means for storing user identification information for association with attribute information set for the user in association with each other, and a caller and a receiver for starting communication transmitted from the communication management device. According to the terminal identification information of the terminal device on the side,
Means for obtaining the user identification information held in the first storage means in correspondence with the two terminal identification information; and the second means in correspondence with the user identification information obtained by the means.
Means for determining whether or not mutual connection of the terminal devices which are to start the communication is possible based on the attribute information held in the storage means, and returning the determination result to the communication management apparatus which has transmitted the terminal identification information An information management device comprising:
続する通信ネットワークとを有することを特徴とする通
信ネットワークシステム。6. A plurality of terminal devices, a communication management device that manages communication between the terminal devices, an information management device according to claim 5, the terminal device, a communication management device, and an information management device. And a communication network for connecting the communication network.
ムであって、 前記通信ネットワークに接続されるATMスイッチ装置
を有し、 前記端末装置、通信管理装置、および、情報管理装置
は、前記ATMスイッチ装置を介して擬似的にLAN通
信を行う手段を有することを特徴とする通信ネットワー
クシステム。7. The communication network system according to claim 6, further comprising an ATM switch device connected to said communication network, wherein said terminal device, communication management device, and information management device are each said ATM switch. A communication network system comprising means for performing pseudo LAN communication via a device.
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP8235220A JPH1079759A (en) | 1996-09-05 | 1996-09-05 | Communication network system and information management device therefor |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP8235220A JPH1079759A (en) | 1996-09-05 | 1996-09-05 | Communication network system and information management device therefor |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| JPH1079759A true JPH1079759A (en) | 1998-03-24 |
Family
ID=16982870
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| JP8235220A Pending JPH1079759A (en) | 1996-09-05 | 1996-09-05 | Communication network system and information management device therefor |
Country Status (1)
| Country | Link |
|---|---|
| JP (1) | JPH1079759A (en) |
Cited By (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2005130157A (en) * | 2003-10-23 | 2005-05-19 | Ntt Docomo Inc | Terminal address management device, server device, terminal address management method, and terminal address management program |
| GB2408650A (en) * | 2003-11-28 | 2005-06-01 | Toshiba Kk | Updating network identification information |
| KR100714130B1 (en) | 2005-12-08 | 2007-05-02 | 한국전자통신연구원 | User Authentication System and Authentication Method Supporting Terminal Mobility between User Lines |
| WO2009069178A1 (en) * | 2007-11-29 | 2009-06-04 | Duaxes Corporation | Communication control apparatus and communication control method |
-
1996
- 1996-09-05 JP JP8235220A patent/JPH1079759A/en active Pending
Cited By (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2005130157A (en) * | 2003-10-23 | 2005-05-19 | Ntt Docomo Inc | Terminal address management device, server device, terminal address management method, and terminal address management program |
| GB2408650A (en) * | 2003-11-28 | 2005-06-01 | Toshiba Kk | Updating network identification information |
| GB2408650B (en) * | 2003-11-28 | 2006-01-04 | Toshiba Kk | Network telephone system main apparatus for the same system and connection information update method using the same system |
| KR100714130B1 (en) | 2005-12-08 | 2007-05-02 | 한국전자통신연구원 | User Authentication System and Authentication Method Supporting Terminal Mobility between User Lines |
| WO2009069178A1 (en) * | 2007-11-29 | 2009-06-04 | Duaxes Corporation | Communication control apparatus and communication control method |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US5737333A (en) | Method and apparatus for interconnecting ATM-attached hosts with telephone-network attached hosts | |
| JP3411159B2 (en) | Mobile computer support system | |
| US6507873B1 (en) | Network address assigning system | |
| JP3131137B2 (en) | Virtual network system | |
| JPH07118717B2 (en) | Multi-protocol packet network configuration method | |
| JPH1075258A (en) | LAN connection method | |
| CN106790732B (en) | Address translation method, device and system, and network identification control method and device | |
| US6625658B1 (en) | End equipment and router | |
| CN114125995B (en) | Data transmission method and device | |
| US9749201B2 (en) | Method and system for monitoring locator/identifier separation network | |
| JPH1065734A (en) | Address resolution device | |
| JP2001237879A (en) | Terminal device, relay device, communication method, and recording medium on which communication program is recorded | |
| JPH11112503A (en) | Network systems and equipment | |
| JP3696816B2 (en) | Address confidential communication method, system, and privacy gateway | |
| US8036218B2 (en) | Technique for achieving connectivity between telecommunication stations | |
| JP2001094571A (en) | Communication system and communication method | |
| US20030225910A1 (en) | Host resolution for IP networks with NAT | |
| JPH11122271A (en) | Dynamic ATM address setting method | |
| JP2743890B2 (en) | Network management method | |
| JP2000194626A (en) | Network device control apparatus and method | |
| JPH09139742A (en) | Address management system in ATM-LAN | |
| JP3082760B1 (en) | MPOA packet transfer method | |
| JP3935621B2 (en) | Data link layer path information storage method, data link layer path information search method, communication apparatus for performing the data link layer path information search method, and data link layer path information storage method and data link layer path information search method That recorded the program to execute each | |
| JPH09298554A (en) | LAN emulation method, LAN emulation system, and LAN emulation server device | |
| CN109995572A (en) | A method and device for topology hiding |