Router, Communication Method, and Program

By incorporating a request port conversion unit within a NAPT router, the router can select and register available ports for P2P communication in environments with port limitations, effectively addressing the challenge of enabling UPnP-based P2P communication in MAP-E mode.

JP7697699B2Active Publication Date: 2025-06-24NEC PLATFROMS LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023003738
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-01-13
Publication Date
2025-06-24
Estimated Expiration
2043-01-13

AI Technical Summary

Technical Problem

In environments with limitations on available ports, such as those using MAP-E mode, conventional routers struggle to enable P2P communication via UPnP due to port restrictions, leading to complex configurations and increased costs.

Method used

A router with a NAPT function, equipped with a request port conversion unit, a UPnP processing unit, and a port forwarding setting unit, manages available ports using an available port table to select and register a suitable port for P2P communication, even when the requested port is not available.

Benefits of technology

This solution enhances the possibility of realizing P2P communication without restrictions in environments with port limitations, reducing the need for additional configurations or hardware, and improving communication quality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007697699000001
    Figure 0007697699000001
  • Figure 0007697699000002
    Figure 0007697699000002
  • Figure 0007697699000003
    Figure 0007697699000003
Patent Text Reader

Abstract

To improve a possibility that a P2P communication is implemented without restriction under an environment, where available ports are restricted, without adding a new configuration.SOLUTION: A router connecting the Internet and a local area network and including a NAPT (Network Address Port Translation) function comprises: a request port translation section by which, when an open request is received from a first device connected to the local area network, a port selected from among available ports of the router is defined as an open port; a UPnP (Universal Plug and Play) processing section for opening the open port; and a port forwarding section for setting a transfer route using the open port that is opened.SELECTED DRAWING: Figure 7
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a router, a communication method, and a program.

Background Art

[0002] For example, when requesting the opening of an external port by UPnP IGD (Universal Plug and Play internet gateway device) for a NAPT (Network Address Port Translation) router operating in a mode with restrictions on available ports, such as MAP-E (Mapping of Address and Port Encapsulation), the opening may not be possible, and P2P (Peer-to-Peer) communication may not be available. Note that MAP-E is a technology that enables IPv4 packets to pass through an IPv6-only network by encapsulating them inside IPv6 packets.

[0003] Therefore, for example, vendors severely restrict or disable the use of UPnP on NAPT routers operating in MAP-E mode. However, as MAP-E becomes more popular, there are voices expressing the desire to use UPnP even when operating in MAP-E mode. Since the communication quality is also improved with MAP-E, where the in-path is IPv6 network communication, compared to a congested IPv4 network, the merit of being able to use MAP-E and UPnP simultaneously is significant.

[0004] For example, to properly set up port forwarding using UPnP and communicate normally with other computers, set up UPnP-based port forwarding on the router corresponding to a first port number used by the router and a second port number different from a predetermined number. When sending STUN (Session Traversal Utilities for NAT) packets to the server using the set-up port forwarding and receiving STUN packets from the server, there is a technique of performing P2P communication with other user terminals using the UPnP-based port forwarding corresponding to the second port number (see, for example, Patent Document 1).

Prior Art Documents

Patent Documents

[0005]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0006] The following analysis is provided by the present invention.

[0007] In the technology described in Patent Document 1, a new STUN server is required as network-side equipment. Therefore, the configuration becomes more complex and the cost also increases accordingly.

[0008] The present invention has been made in view of the above circumstances, and aims to increase the possibility of realizing P2P communication without restrictions in an environment with limitations on available ports without adding a new configuration.

Means for Solving the Problems

[0009] According to a first aspect of the present invention,[[]] a router that connects between the Internet and a local area network and has a NAPT (Network Address Port Translation) function, When receiving a release request from a first device connected to a local area network, a request port conversion unit that designates a port selected from among the available ports of the router as a release port, a UPnP (Universal Plug and Play) processing unit that releases the release port, and a port forwarding setting unit that sets a transfer path using the released release port are provided in a router. Furthermore, the router manages the available ports in the requested port conversion unit using the available port table, and the available port table stores unallocated information, which is information indicating that the port having the port number is available because it is either assigned to a target or unassigned, associated with the port number. When receiving the release request, the requested port conversion unit selects the port number stored in association with the unallocated information in the available port table, designates the port specified by the port number as the release port, and registers the IP address and port number of the first device in association with the selected port number. 。

[0010] According to a second aspect of the present invention, a communication method executed by a computer that configures a router having a NAPT (Network Address Port Translation) function and connects between the Internet and a local area network, when receiving a release request from a first device connected to a local area network, a request port conversion step of designating a port selected from among the available ports of the router as a release port, a UPnP (Universal Plug and Play) processing step of releasing the release port, and a port forwarding step of setting a transfer path using the released release port are provided. The communication method further includes, in the requested port conversion step, the computer manages the available ports using the available port table, and the available port table stores unallocated information, which is information indicating that the port having the port number is either assigned to a target or available because it is unassigned, associated with the port number. The computer, when receiving the release request, selects the port number stored in association with the unallocated information in the available port table, designates the port specified by the port number as the release port, and registers the IP address and port number of the first device in association with the selected port number. 。

[0011] According to a third aspect of the present invention, to a computer that configures a router having a NAPT (Network Address Port Translation) function and connects between the Internet and a local area network, When receiving a release request from a first device connected to a local area network, a request port conversion procedure that designates a port selected from the available ports of the router as a release port, and a UPnP (Universal Plug and Play) processing procedure for releasing the release port, and a port forwarding procedure for setting up a transfer path using the released release port are provided as a program to be executed.

[0012] Note that these programs can be recorded on a computer-readable storage medium. The storage medium can be non-transient ones such as semiconductor memories, hard disks, magnetic recording media, and optical recording media. The present invention can also be embodied as a computer program product.

Advantages of the Invention

[0013] According to the present invention, without adding a new configuration, the possibility of realizing P2P communication without restrictions in an environment with limitations on available ports is increased.

Brief Description of the Drawings

[0014]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Mode for Carrying Out the Invention

[0015] Hereinafter, an outline of an embodiment of the present invention (hereinafter referred to as this embodiment) will be described with reference to the drawings. Note that the attached reference numerals in the drawings are for convenience attached to each element as an example for helping understanding, and are not intended to limit the present invention to the illustrated embodiments. Also, the connection lines between blocks in the drawings and the like referred to in the following description include both bidirectional and unidirectional ones. Regarding the one-way arrow, it schematically shows the flow of the main signal (data) and does not exclude bidirectionality.

[0016] Also, although there are ports and interfaces at the input / output connection points of each block in the figure, illustration thereof is omitted. Also, in the following description, "A and / or B" is used to mean A or B, or A and B.

[0017] First, an outline of the communication system 100 of this embodiment will be described. As shown in FIG. 1, the user terminal 200 is connected to the server 400 on the Internet 900 via the NAPT router 300. In this embodiment, the user terminal 200 is assigned an IPv4 address, and the user terminal 200 outputs packets compliant with IPv4 (hereinafter referred to as IPv4 packets).

[0018] The NAPT router 300 has a NAPT function, a MAP-E function, and a UPnP function, encapsulates the IPv4 packets received from the user terminal 200 into packets compliant with IPv6 (hereinafter referred to as IPv6 packets), and outputs them to the server 400. Here, the user terminal 200 is connected to a LAN (Local Area Network), and the server 400 is connected via a wide area network such as the Internet 900. That is, the NAPT router 300 connects between the Internet and the local area network. Details of the NAPT function, MAP-E function, and UPnP function will be described later.

[0019] Note that when the server 400 on the Internet 900 is IPv4-compatible, a Border Relay 500 is provided in between and is converted (decapsulated) to an IPv4 address.

[0020] Prior to the detailed description of this embodiment, each of the above functions (NAPT function, MAP-E function, and UPnP function) will be described in a communication system 101 having a conventional NAPT router 301.

[0021] As described above, NAPT is an abbreviation of Network Address Port Translation, and this function is a function of converting the IP address and port number included in a TCP (UDP) / IP packet into another IP address and port number. The NAPT function is standardly provided in a general home router.

[0022] Here, as shown in FIG. 2, it is assumed that the user terminal 200 communicates with the server 400 in the Internet 900 via the NAPT router 301.

[0023] Generally, a private address (local address) is assigned to the source IP address and port number 201 of the user terminal 200 under the NAPT router 301. In the example of this figure, "xxx.xxx.xxx.xxx" is assigned as the source IP address and "1111" is assigned as the port number. Hereinafter, these are collectively described as "xxx.xxx.xxx.xxx:1111". That is, the source IP address and port number 201 of the communication packet transmitted from the user terminal 200 are "xxx.xxx.xxx.xxx:1111".

[0024] In order to communicate with a device on the Internet 900 (here, the server 400), it is necessary to convert this private address into a global address. This address conversion function is called the NAT (Network Address Translation) function, and when the port number is also converted, it is called the NAPT function.

[0025] The communication packet from the user terminal 200 is sent to the NAPT router 301 (S1101). Then, in the NAPT router 301, the source IP address of the private address is converted into a global address. Also, the port number is converted into an available port on the wide area network side of the NAPT router 301 (hereinafter also referred to as the external port). Here, it is converted into the global address "yyy.yyy.yyy.yyy", and the port number is converted into "2222". Then, the communication packet with the source IP address and port number 302 of "yyy.yyy.yyy.yyy:2222" is transferred from the NAPT router 301 to the server 400 within the Internet 900 that is the destination (S1102).

[0026] The NAPT router 301 associates the local address and port number used for this conversion with the global address and port number, and manages them as an address conversion table. The communication packet returning from the Internet 900 is referred to this NAPT management table by the NAPT router 301, and the destination IP is converted from the global address to the private address.

[0027] Next, the MAP-E function will be described. As described above, MAP-E is an abbreviation for Mapping of Address and Port Encapsulation, and is a coexistence technology between IPv6 and IPv4. It enables connection to an IPv4 network via an IPv6-only access network. It is a technology developed in view of the fact that although one wants to migrate to IPv6 in order to solve the problem of IPv4 address exhaustion, there are still few servers compatible with IPv6oE (over Ethernet).

[0028] Such technologies are collectively referred to as IPv6 migration technologies. In MAP-E, the shared IPv4 address method is adopted, and the same IPv4 global address is used by multiple routers. Therefore, since there would be a conflict as it is, each router restricts the available ports. The IPv4 global address and available ports used in MAP-E are calculated within each router according to the rules provided by the MAP-E distribution server of the VNE (Virtual Network Enabler) operator.

[0029] The outline of the MAP-E function will be described with reference to FIG. 3. Even for the NAPT router 301 having the MAP-E function, the NAPT of the IP address and port number is basically the same as the conventional mechanism. That is, the NAPT router 301 converts the source IP address and port number 201 of the private address of the communication packet transmitted from the user terminal 200 into those of the global address.

[0030] During this conversion, in the NAPT router 301 with the MAP-E function, the ports available for use as the converted port are limited. In the case of IPv4oE, basically, all ports except the system ports (port numbers: 0 to 1023) (the same 1024 to 65535) are available ports. However, in the NAPT router 301 with the MAP-E function, as described above, the available ports are limited, and only several hundred to about one thousand ports are applicable. Note that the number of ports available for one router varies depending on each MAP-E service. The specific values are determined in advance respectively.

[0031] For example, in the example shown in FIG. 3, the port numbers of the available port 303 are six numbers: 10001, 10002, 10003, 20001, 20002, and 20003. When performing NAP conversion, the NAPT router 301 selects one port from these six ports as the destination port for conversion. FIG. 3 shows an example when the port number 10001 is selected. That is, 10001 is given as the source IP address of the global address after conversion and the port number of the port 304.

[0032] In addition, the MAP-E function includes a function realized in a set with the Border Relay 500. This function is a function of encapsulating communication packets between the NAPT router 301 and the Border Relay 500 with an IPv6 address. Encapsulation is a technology that uses almost the same information of the IPv4 packet and generates a communication packet with an IPv6 header attached.

[0033] When an IPv4 packet is transmitted from the user terminal 200 to the server 400 in the Internet 900, the NAPT router 301 equipped with the MAP-E function encapsulates the original IPv4 packet into an IPv6 packet and transmits it to the Border Relay 500 as IPv6 communication (S1103). Then, the Border Relay 500 decapsulates it, returns it to an IPv4 packet, and then transmits it to the server 400.

[0034] In the case of reverse communication from the server 400 to the user terminal 200, the roles of encapsulation / decapsulation are also reversed. That is, the IPv6 packet is encapsulated into an IPv6 packet at the Border Relay 500, decapsulated by the NAPT router 301 with the MAP-E function, and returned to the IPv4 packet.

[0035] Next, the UPnP function will be described. As described above, UPnP is an abbreviation for Universal Plug and Play, and it is a protocol that allows a device to immediately communicate with other devices and utilize their functions without complicated configuration work when connecting to a communication network.

[0036] The collection of services or the nested device side is called a UPnP Device, and the side that controls the UPnP Device is called a UPnP Control Point. In the example of this embodiment, the user terminal 200 functions as a UPnP Control Point, and the NAPT router 301 functions as a UPnP Device.

[0037] There are various Device Control Protocols in UPnP, and the specifications are determined for each device category. The NAPT router 301 uses the IGD among them. As described above, IGD is an abbreviation for Internal Gateway Device.

[0038] The usage mode of the UPnP IGD in the NAPT router 301 will be described with reference to FIGS. 4 and 5. FIG. 4 is a diagram for explaining the problems when the UPnP IGD is not used.

[0039] Generally, the NAPT router 301 separates the global IP address space such as the Internet 900 from the private IP address space (local) within the house. For this reason, as shown in FIG. 4, the communication packet 401 transmitted from the server 400 in the Internet 900 to the user terminal 200 within the house cannot cross the NAPT router 301 and cannot reach the user terminal 200. The UPnP IGD is used as a technology for NAT traversal (also called NAT crossing) to solve this problem.

[0040] An example of NAT traversal using the UPnP IGD is shown in FIG. 5. First, a request (open request 202) to open an external port is sent (S1104) from the user terminal 200 which is a UPnP Control Point to the NAPT router 301 which is a UPnP Device. At this time, the port number for which the opening is requested is specified. FIG. 5 shows an example of the case where a request is made to open the external port of port number 2222. Hereinafter, the port for which the opening is requested in the open request 202 is called the requested port.

[0041] Note that the open request 202 is implemented by an AddPortMapping action using SOAP (Simple Object Access Protocol). Also, before performing this action, phases such as discovery of the UPnP Device and acquisition of the Device Description are performed. Since these are well-known procedures, detailed explanations are omitted.

[0042] When receiving the open request 202 from the user terminal 200, the NAPT router 301 makes a permission setting on the filter for the global IP address and the port number 304 of the requested port. FIG. 5 exemplifies the case where a permission setting is made for "yyy.yyy.yyy.yyy:2222".

[0043] Then, the NAPT router 301 returns a response (200 OK) 305 indicating that it has accepted the opening request 202 to the user terminal 200 (S1105). As a result, the requested port is opened, and thereafter, for communication packets from the NAPT router 301, this source IP address and port number (in the example of FIG. 5, "yyy. yyy. yyy. yyy:2222") 304 are used as the source IP address and port number.

[0044] After this interaction, when a communication packet addressed to this source IP address and port number 304 is sent from the server 400 (S1106), the NAPT router 301 converts the destination of the communication packet to the user terminal 200 that is the source of the opening request 202 and forwards it (S1107).

[0045] Converting the communication packet sent to a specific port to a specific destination in this way is called port forwarding processing. When a general NAPT router 301 receives an external port opening request 202 by UPnP IGD, it simultaneously performs settings for this port forwarding processing. Specifically, for example, the destination of the conversion is managed as a forwarding route table for each port.

[0046] However, when the NAPT router 301 has the MAP-E function and operates in the MAP-E mode, there are restrictions on available ports.

[0047] That is, as shown in FIG. 6, assume that the user terminal 200 makes an opening request 202 to the NAPT router 301 operating in the MAP-E mode to open the external port with port number 2222 (S1104). At this time, as shown in this figure, if the port with port number 2222 is not included in the available ports 303, the NAPT router 301 cannot open the requested port.

[0048] In such a case, the conventional NAPT router 301 returns an error 306 to the requesting user terminal 200 (S1108). Then, the NAPT router 301 neither opens the external port nor performs port forwarding settings. Therefore, communication packets sent from the server 400 (S1109) and reaching the NAPT router 301 via the Border Relay 500 (S1110) cannot pass beyond the NAPT router 301 without being port-forwarded to the user terminal 200.

[0049] Thus, in an environment with limited available ports, P2P communication may not be able to be performed normally with only the UPnP function. In this embodiment, a new function is added to the NAPT router to solve this problem.

[0050] A functional block diagram of the NAPT router 300 of this embodiment for solving this problem is shown in FIG. 7(a).

[0051] As shown in this figure, the NAPT router 300 of this embodiment includes a NAPT processing unit 310, a MAP-E processing unit 320, a UPnP processing unit 330, a requested port conversion unit 340, a port forwarding setting unit 350, and a management table 380, and connects between the Internet and the local area network.

[0052] The NAPT processing unit 310 executes the NAPT function of performing the conversion between the private address and the global address of the communication packet as described above. In this embodiment, for example, an address conversion table associating the addresses to be converted is created in the management table 380, and according to this conversion table, the local IP address and port number and the global IP address and port number are converted to realize the transmission and reception of communication packets.

[0053] The MAP-E processing unit 320 encapsulates IPv4 packets and converts them into IPv6 packets, or vice versa. That is, it IPv6-encapsulates the IPv4 packets from the user terminal 200. Then, the IPv6 packets are transferred to the Border Relay 500, where they are decapsulated and returned to IPv4 packets and reach the server 400.

[0054] The UPnP processing unit 330 realizes the above-described UPnP function. That is, when receiving an open request 202 with a specified port number from the user terminal 200, it opens the port.

[0055] When the request port conversion unit 340 receives an open request 202 specifying a port other than an available port from the user terminal 200, it selects a port to be opened (open port) from the available ports, converts the requested port to the selected open port, and notifies the UPnP processing unit 330.

[0056] The request port conversion unit 340 manages available ports. The available ports are managed in the available port table 381. That is, when the request port conversion unit 340 receives an open request 202 specifying other than an available port, it refers to the available port table 381, searches for an empty port, and selects an open port from among them. At this time, if there is no empty port, the request port conversion unit 340 conventionally instructs the UPnP processing unit 330 to return an Error. In response, the UPnP processing unit 330 returns an Error to the user terminal 200 that is the request source.

[0057] An example of the available port table 381 is shown in FIG. 7(b). In the available port table 381, for each port number 381a of each port, the allocation target 381b is stored. In the allocation target 381b, for example, the allocated service (protocol, etc.), the IP address and port number of the user terminal 200 that is the source of the opening request are registered. Note that when the requested port included in the opening request 202 is a port other than the available port, the IP address and port number of the user terminal 200 that is the source of the request are registered in the allocation target 381b in association with the port number 381a of the opened port after conversion.

[0058] In the example of this figure, among the initial available ports, since the allocation targets 381b are already registered in 10001 and 20003, the currently available ports are four: 10002, 10003, 20001, and 20002.

[0059] Also, the available port table 381 may be used in combination with the transfer path table described later.

[0060] In this way, the NAPT router 300 of the present embodiment includes the requested port conversion unit 340, so that port opening can be realized even in a case where port opening by UPnP IGD could not be normally performed in the past.

[0061] The notified UPnP processing unit 330 processes the port after conversion as the requested port.

[0062] The port forwarding setting unit 350 sets a transfer path (port forwarding path) using the external port opened by the UPnP processing unit 330. The port forwarding setting unit 350 generates and manages, for example, a transfer path table. The transfer path table is a table that manages the local address of the destination user terminal 200 in association with the port number of the opened port.

[0063] Note that the user terminal 200 functions as a UPnP Control Point. That is, it sends an opening request 202 to the NAPT router 300 by specifying the port number of the requested port for opening.

[0064] [Description of Operations] FIG. 8 shows an image of the operation of the NAPT router 300 in the communication system 100 of the present embodiment.

[0065] An opening request (action request) 202 for port opening by UPnP IGD is sent from the user terminal 200 functioning as a UPnP Control Point to the NAPT router 300 functioning as a UPnP Device (S1201). In the example of this figure, the opening request 202 requests the opening of the external port with port number 2222 as the requested port.

[0066] Since the NAPT router 300 is operating in MAP-E mode, the available ports are limited. Here, as before, 6 ports are available. Among these available ports 303, the port with port number 2222, which is the requested port, is not included. Therefore, the conventional NAPT router 301 returns an error (Error) 306.

[0067] However, in the NAPT router 300 of the present embodiment, the port number of the requested port is automatically converted by the requested port conversion unit 340. That is, the requested port conversion unit 340 selects one port from among the available ports 303 as the opening port. At this time, as described above, the requested port conversion unit 340 refers to the available port table 381 and selects the available ports 303. Then, it notifies the UPnP processing unit 330 of the requested port (opening port) after conversion.

[0068] Thereafter, the requested port conversion unit 340 updates the available port table 381. Specifically, it registers the source IP address and port number 201 of the user terminal 200 that is the source of the opening request 202 in association with the port number of the opening port.

[0069] Then, the NAPT router 300 opens its external IP address and the port number 308 of the open port to the outside (S1203). Here, the case where the port with the port number 10001 is selected as the open port is exemplified. Then, the UPnP processing unit 330 returns a response (200 OK) 305 indicating that the open request has been accepted to the user terminal 200 (S1202).

[0070] The server 400 sends an IPv4 packet toward the open external IP address and port number 308 of the NAPT router 300 (S1204). The sent IPv4 packet is encapsulated into an IPv6 packet by the Border Relay 500 and reaches the NAPT router 300 as an IPv6 packet (S1205). Then, it is decapsulated from the IPv6 packet by the NAPT router 300 and transferred as an IPv4 packet to the IP address and port number 201 of the user terminal 200 (S1206). As a result, P2P is realized even under the available port restriction.

[0071] [Sequence] As an example, the change of the address will be described according to the sequence diagram of FIG. 9.

[0072] Here, the user terminal 200 has "xxx.xxx.xxx.xxx.1111" as the IP address and port of the local area network. The NAPT router 300 has "yyy.yyy.yyy.yyy" as the external (global) IP address and has a set of six ports shown in FIG. 8 as the available port 303. The server 400 has "zzz.zzz.zzz.zzz:3333" as the terminal IP address and port. Hereinafter, in FIG. 9, xxx, yyy, and zzz in the address are represented as x, y, and z, respectively.

[0073] The user terminal 200 sends an open request for port opening by the UPnP IGD (step S1301). Here, the case where the requested port is "2222" is exemplified.

[0074] Upon receiving this, the request port conversion unit 340 of the NAPT router 300 converts the request port "2222" to the available port "10001" (step S1302). Then, the port forwarding setting unit 350 performs port forwarding setting on the converted port "10001" (step S1303). And the UPnP processing unit 330 returns a response ( "200 OK") indicating that the setting is completed (step S1304).

[0075] Next, the change in the address when a communication packet is transmitted from the user terminal 200 to the server 400 will be described. Note that the communication packet transmitted from the user terminal 200 to the server 400 originally passes through without opening the port by UPnP. Therefore, it is possible to transmit without the session of the above port opening. Here, for the purpose of supplementing the image of the NAPT function described above, the description will focus on the change in the address.

[0076] The IPv4 packet transmitted from the user terminal 200 to the server 400 is generated with the source address "xxx.xxx.xxx.xxx.1111" and the destination address "zzz.zzz.zzz.zzz.3333" and is transmitted (step S1305). Note that the source address is the local address of the user terminal 200, and the destination address is the global address of the server 400.

[0077] In the NAPT router 300, the NAPT processing unit 310 performs address conversion, and the MAP-E processing unit 320 encapsulates the IPv4 packet into an IPv6 packet (step S1306). Then, the generated IPv6 packet is transmitted to the Border Relay 500 (step S1307). At this time, the source address of the transmitted communication packet is "yyy.yyy.yyy.yyy.10001", and the destination address is "zzz.zzz.zzz.zzz:3333".

[0078] At the border relay 500, the received IPv6 packet is decapsulated to obtain an IPv4 packet (step S1308). Then, the obtained IPv4 packet is sent to the server 400 (step S1309). At this time, the source address is "yyy.yyy.yyy.yyy:10001" and the destination address is "zzz.zzz.zzz.zzz:3333".

[0079] The communication packet sent from the user terminal 200 has its source address and port thus converted at the NAPT router 300 and reaches the server 400 within the Internet 900.

[0080] General NAPT routers 301, 300 are equipped with a stateful packet inspection (SPI) function. With this SPI function, within a few minutes while the session of this communication remains, communication packets from the server 400 to the user terminal 200 can also pass through the NAT without port opening by means such as UPnP. Therefore, during this period, P2P communication is possible without opening ports. Note that the SPI function is a function that records data sent from the LAN to the WAN (Internet), compares it with the data returned from the WAN, determines whether there is any fraud in the received data based on the information at the time of transmission, and permits the passage of communication only when it is determined to be normal.

[0081] On the other hand, after the session is deleted, in order to pass the communication packet sent from the server 400 in the direction of the user terminal 200, port opening is necessary. In the example of this figure, the port is opened by the processing of steps S1301 to S1304 described above. Therefore, when the server 400 conducts P2P communication with the user terminal 200, the server 400 sends a communication packet to the external IP address and port "yyy.yyy.yyy.yyy:10001" where the port of the NAPT router 300 is opened. That is, the server 400 generates and sends a communication packet with the source address "zzz.zzz.zzz.zzz:3333" and the destination address "yyy.yyy.yyy.yyy:10001" (step S1311).

[0082] The Border Relay 500 encapsulates this communication packet into an IPv6 packet (step S1312) and transmits it to the NAPT router 300 (step S1213). At this time as well, the source address is "zzz.zzz.zzz.zzz:3333" and the destination address is "yyy.yyy.yyy.yyy:10001".

[0083] The MAP-E processing unit 320 of the NAPT router 300 decapsulates the received IPv6 packet to obtain an IPv4 packet. Then, the NAPT processing unit 310 converts the destination of the obtained IPv4 packet to the IP and port of the user terminal 200 (step S1314) and transmits it to the user terminal 200 (step S1315). At this time, the source address is "zzz.zzz.zzz.zzz.3333" and the destination address is "xxx.xxx.xxx.xxx.1111". As a result, P2P communication is realized.

[0084] [Port Forwarding Setting Process] Here, the flow of the port forwarding setting process (the above S1301 to S1304) by UPnP in the NAPT router 300 of the present embodiment will be described. FIG. 10 is the processing flow of the port forwarding setting process of the present embodiment.

[0085] First, the UPnP processing unit 330 of the NAPT router 300 waits for a release request from the user terminal 200 (step S1401).

[0086] When a release request from the user is received (S1401; Yes), the UPnP processing unit 330 determines whether the requested port included in the release request is an available port (step S1402).

[0087] If the requested port is not an available port (S1402: No), the requested port conversion unit 340 searches for an available port among the available ports (step S1403). Then, if there is an available port (S1403: Yes), it selects a port to be converted from among the available ports (step S1404). Then, it converts the requested port to the selected port (step S1405). It notifies the UPnP processing unit 330 of this.

[0088] Then, the port forwarding setting unit 350 performs port forwarding setting with the converted requested port (step S1406). Also, the UPnP processing unit 330 responds with a setting completion response to the source user terminal 200 (step S1407) and ends the process.

[0089] In step S1402, if it is determined that the requested port is an available port, steps S1403 to S1405 are not performed and the process proceeds to step S1406. Also, if there is no available port in step S1403, the UPnP processing unit 330 returns an Error to the source user terminal 200 (step S1408) and ends the process.

[0090] [Hardware Configuration] FIG. 11 is a block diagram showing an example of the hardware configuration of the NAPT router 300. As shown in this figure, the NAPT router 300 includes a processor (CPU) 391, a memory 392, and a communication interface (communication I / F) 393.

[0091] The communication I / F 393 is used to communicate with other network node devices constituting the communication system 100. The communication I / F 393 may include, for example, a network interface card (NIC) compliant with the IEEE 802.3 series. Alternatively, the communication I / F 393 may be used to perform wireless communication. For example, the communication I / F 393 may be used to perform wireless LAN communication or mobile communication defined in 3GPP (3rd Generation Partnership Project; registered trademark).

[0092] It may include an interface for connecting to a LAN and an interface for connecting to a WAN (Internet network). It communicates with the user terminal 200 via the LAN. It communicates with the Border Relay 500 and the server 400 via the WAN.

[0093] The memory 392 stores a group of software modules. Also, the memory 392 stores various information. Specifically, the memory 392 stores an available port table 381, an address translation table, a transfer path table, etc. The memory 392 is composed of a combination of a volatile memory and a non-volatile memory. The memory 392 may include a storage located away from the processor 391. In this case, the processor 391 may access the memory 392 via an input / output interface (not shown).

[0094] The processor 391 reads and executes software (computer program) from the memory 392 to realize each function of the NAPT router 300 described in the above embodiments. The processor 391 may be, for example, a microprocessor, an MPU (Micro Processing Unit), or a CPU (Central Processing Unit). The processor 391 may include a plurality of processors.

[0095] In the above example, the computer program can be stored using various types of non-transitory computer readable media and supplied to a computer. Non-transitory computer readable media include various types of tangible storage media. Examples of non-transitory computer readable media include magnetic recording media, magneto-optical recording media (such as magneto-optical disks), CD-ROM (Read Only Memory), CD-R, CD-R / W, and semiconductor memories. Magnetic recording media may be, for example, flexible disks, magnetic tapes, or hard disk drives. Semiconductor memories may be, for example, mask ROM, PROM (Programmable ROM), EPROM (Erasable PROM), flash ROM, or RAM (Random Access Memory). Also, the computer program may be supplied to the computer by various types of transitory computer readable media. Examples of transitory computer readable media include electrical signals, optical signals, and electromagnetic waves. Transitory computer readable media can supply the computer program to the computer via wired communication paths such as electric wires and optical fibers, or wireless communication paths.

[0096] Also, the user terminal 200 includes at least an arithmetic unit such as a CPU, a storage device such as a memory, and a communication interface. Each of the above functions is realized by the arithmetic unit loading and executing a program stored in the storage device in its work area. Also, various types of information (data) are stored in the storage device.

[0097] As described above, in the communication system 100 of the present embodiment, the NAPT router 300 includes a request port conversion unit 340. Thus, when a request port that is not an available port by the UPnP IGD is requested, inside the NAPT router 300, the request port is automatically converted to one of the available ports. Then, port opening is set for the converted port (open port), and completion of the setting (normal termination) is returned to the UPnP Control Point (user terminal 200). Also, port forwarding is set for the converted port to realize P2P communication.

[0098] Therefore, according to the present embodiment, in an environment where there are restrictions on the available ports of the NAPT router 300, such as operation in MAP-E mode, the possibility of using port opening by the UPnP IGD is increased, and the possibility of enabling P2P communication is also increased. At this time, there is no need to add other facilities such as a STUN server, and this can be realized only by the NAPT router 300.

[0099] Conventionally, in an environment with restrictions on available ports, there are many cases where port opening by the UPnP IGD cannot be performed normally. For example, UPnP on the NAPT router 301 operating in MAP-E mode is restricted or disabled. However, according to the present embodiment, the possibility of using UPnP on the NAPT router 300 operating in MAP-E mode is increased without adding new hardware. That is, the UPnP IGD can be made available under port restrictions, and the possibility of realizing P2P communication is increased. Therefore, the user's effort is reduced, and at the same time, convenience is improved.

[0100] <Modification Example 1> In addition, in the above embodiment, MAP-E is given as an example of the case where there are restrictions on the available ports of the NAPT router 300. However, the present embodiment can also be used in an environment (shared address method) where there are restrictions on available ports other than MAP-E.

[0101] <Modification Example 2> Also, in the above embodiment, the UPnP processing unit 330 and the request port conversion unit 340 refer to the request port included in the release request 202, determine whether it is included in the available ports, and only when it is not included, convert it to an available port and release that port. However, the determination process may not be performed. That is, when the NAPT router 300 is operating in a mode where the available ports are restricted, when the request port conversion unit 340 receives the release request 202, it selects a port to be released from the available ports and notifies the UPnP processing unit 330 of it as the release port.

[0102] In this case, the release request 202 may not include the port number of the specific request port.

[0103] <Modification Example 3> In the above embodiment, when the request port conversion unit 340 receives the release request 202, it searches the entire available port table 381 to extract an empty port, but it is not limited to this. For example, a pre-assigned order may be set for each available port, and it may be configured to assign according to that order for each request.

[0104] Also, in the case of MAP-E, after a block of consecutive ports (port set) continues as available ports, the port number skips, and then a block of consecutive ports becomes available ports. For example, ports with port numbers 1 to 10, 21 to 30, and 41 to 50 are set as available ports.

[0105] Among such port sets, a port set to be used at the time of conversion may be determined in advance, and it may be configured to preferentially search within it to extract an empty port. Also, a search priority order may be determined for each port set. By configuring in this way, since the search range is narrowed, it leads to speeding up the processing at the time of selecting the conversion port accordingly.

[0106] Also, in the case of MAP-E, available ports are established without overlap for each user terminal 200. Therefore, for example, port number 381a may be registered for each user terminal 200. In this case, when the request port conversion unit 340 receives the release request 202, it searches for an available port from among the group of port numbers 381a that are managed in association with the user terminal 200 that is the source of the release request 202.

[0107] Note that in the flowcharts used in the above description, a plurality of steps (processes) are described in order, but the execution order of each step is not limited to the described order. For example, the order of the illustrated steps can be changed within the range where the content is not impaired, such as executing each process in parallel.

[0108] As described above, each embodiment of the present invention has been described. However, the present invention is not limited to the above-described embodiments, and further modifications, substitutions, and adjustments can be made without departing from the basic technical idea of the present invention. For example, the network configurations and the configurations of each element shown in each drawing are examples for facilitating the understanding of the present invention, and are not limited to the configurations shown in these drawings.

[0109] Finally, the preferred forms of the present invention will be summarized. (Appendix 1) A router that connects between the Internet and a local area network and has a NAPT (Network Address Port Translation) function, a request port conversion unit that, when receiving a release request from a first device connected to the local area network, uses a port selected from among the available ports of the router as a release port; a UPnP (Universal Plug and Play) processing unit that releases the release port; and a port forwarding setting unit that sets a transfer path using the released release port. (Appendix 2) In the router described in Appendix 1, there are restrictions on the available ports, The request port conversion unit preferably determines whether the request port is included in the available ports, and if not, converts the request port into the open port. (Appendix 3) In the router according to Appendix 2, equipped with the MAP-E (Mapping of Address and Port with Encapsulation) function, it is desirable for the request port conversion unit to determine whether the request port included in the open request is included in the available ports in the MAP-E function. (Appendix 4) In the router according to any one of Appendices 1 to 3, it is desirable for the UPnP processing unit to transmit a reply indicating normal termination to the first device after opening the open port. (Appendix 5) A communication method executed by a computer that configures a router having a NAPT (Network Address Port Translation) function and connects between the Internet and a local area network, comprising: a request port conversion step of using, as an open port, a port selected from the available ports of the router when receiving an open request from a first device connected to the local area network; a UPnP (Universal Plug and Play) processing step of opening the open port; a port forwarding step of setting a transfer path using the opened open port. (Appendix 6) In a computer that configures a router having a NAPT (Network Address Port Translation) function and connects between the Internet and a local area network, when receiving an open request from a first device connected to the local area network, a request port conversion procedure of using, as an open port, a port selected from the available ports of the router; A UPnP (Universal Plug and Play) processing procedure for opening the open port, and A program for executing a port forwarding procedure for setting a transfer path using the opened open port. Note that each form of Supplementary Note 5-6 can be developed into the form of Supplementary Note 2-4.

[0110] In addition, each disclosure of the above patent documents and the like shall be incorporated herein by reference. Within the scope of the entire disclosure of the present invention (including the claims), further modifications and adjustments of the embodiments or examples can be made based on the basic technical idea. Also, within the scope of the disclosure of the present invention, various combinations or selections of various disclosure elements (including each element of each claim, each element of each embodiment or example, each element of each drawing, etc.) are possible. That is, the present invention naturally includes all disclosures including the claims, and various modifications and corrections that could be made by those skilled in the art according to the technical idea. In particular, regarding the numerical ranges described in this document, any numerical value or small range included within the range should be construed as specifically described even in the absence of separate description.

Explanation of Reference Numerals

[0111] 100: Communication system, 101: Communication system, 200: User terminal, 201: IP address and port number, 202: Opening request, 300: NAPT router, 301: NAPT router, 302: IP address and port number, 303: Available port, 304: IP address and port number, 305: Response, 306: Error, 308: IP address and port number, 310: NAPT processing unit, 320: MAP-E processing unit, 330: UPnP processing unit, 340: Request port conversion unit, 350: Port forwarding setting unit, 380: Management table, 381: Available port table, 381a: Port number, 381b: Allocation target, 391: Processor (CPU), 392: Memory, 393: Communication I / F, 400: Server, 401: Communication Packet, 500: Border Relay, 900: Internet

Claims

1. A router that connects between the Internet and a local area network and has a Network Address Port Translation (NAPT) function, a request port conversion unit that, when receiving a release request from a first device connected to the local area network, uses a port selected from the available ports of the router as the release port, a UPnP (Universal Plug and Play) processing unit that opens the release port, and a port forwarding setting unit that sets a transfer path using the opened release port, and the request port conversion unit manages the available ports using an available port table, wherein the available port table stores, in association with a port number, unassigned information that is information indicating that the port having the port number is available because it is assigned to a target or unassigned, the request port conversion unit, when receiving the release request, selects the port number stored in association with the unassigned information in the available port table, uses the port specified by the port number as the release port, and registers the IP address and port number of the first device in association with the selected port number. A router.

2. The router according to claim 1, wherein an assignment order is preset in the available port table in association with the port number, and the request port conversion unit selects the port number stored in association with the unassigned information each time the release request is received according to the assignment order. A router.

3. The router according to claim 1, wherein consecutive port numbers associated with the unassigned information in the available port table are defined as a port set, and a port set from which the request port conversion unit selects the port number is predetermined among the port sets. A router.

4. The router according to claim 3, wherein a search priority for each port set is predetermined. A router.

5. The router according to claim 1, where there are restrictions on the available ports, and the request port conversion unit determines whether the request port included in the release request is included in the available ports, and if not, converts the request port into the release port. A router.

6. The router according to claim 5, comprising a MAP-E (Mapping of Address and Port with Encapsulation) function, wherein the requested port conversion unit determines whether the requested port included in the release request is included in the available ports in the MAP-E function.

7. The router according to claim 1, wherein the UPnP processing unit transmits a reply indicating normal termination to the first device after opening the open port.

8. A communication method executed by a computer that configures a router having a NAPT (Network Address Port Translation) function and connects between the Internet and a local area network, comprising: a requested port conversion step of receiving a release request from a first device connected to the local area network and using, as an open port, a port selected from the available ports of the router; a UPnP (Universal Plug and Play) processing step of opening the open port; a port forwarding step of setting a transfer path using the opened open port, wherein in the requested port conversion step, the computer manages the available ports using an available port table, the available port table stores, in association with a port number, information indicating a target assigned to the port having the port number or unassigned information indicating that the port is an available port because it is unassigned, the computer upon receiving the release request, selects, in the available port table, the port number stored in association with the unassigned information, uses the port specified by the port number as the open port, and registers the IP address and port number of the first device in association with the selected port number.

9. A program for causing a computer that configures a router having a NAPT (Network Address Port Translation) function and connects between the Internet and a local area network to execute the communication method according to claim 8.

Citation Information

Patent Citations

  • Program, communication device, and communication method

    JP2021052240A