Band control device, band control method, band control program, and network system

The bandwidth control device addresses VPN congestion by measuring and adjusting transmission limits based on reception traffic volumes, improving VPN reliability by preventing invalid traffic and swiftly managing congestion.

JP7704227B2Active Publication Date: 2025-07-08NIPPON TELEGRAPH & TELEPHONE CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2023578353
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-02-07
Publication Date
2025-07-08
Estimated Expiration
2042-02-07

AI Technical Summary

Technical Problem

Conventional congestion resolution techniques in VPNs struggle to quickly respond to the generation of invalid traffic due to congestion, leading to insufficient reliability, as they rely on step-by-step throttling adjustments and repeated calculations to manage router IF bandwidth, which is inefficient and slow.

Method used

A bandwidth control device and method that measures transmission and reception traffic volumes for each communication pair, setting limits based on reception traffic volume to prevent congestion, thereby restricting transmission volumes to maintain network reliability.

Benefits of technology

The solution effectively suppresses invalid traffic and quickly responds to congestion by adjusting transmission limits, enhancing VPN reliability by matching transmission with reception traffic volumes and reducing congestion-related packet loss.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007704227000001
    Figure 0007704227000001
  • Figure 0007704227000002
    Figure 0007704227000002
  • Figure 0007704227000003
    Figure 0007704227000003
Patent Text Reader

Abstract

Provided are a band control device, a band control method, a band control program, and a network system that improve the reliability of a VPN. A measurement result holding unit (101) acquires and holds, for each combination of a transmission source and a transmission destination that communicate with each other via a WAN (400), the measurement values of a traffic volume transmitted to the WAN (400) and a traffic volume received by the transmission destination. For each combination, if a difference obtained by subtracting the received traffic volume from the transmitted traffic volume is equal to or greater than a threshold value, a control determination unit (102) restricts the transmitted traffic volume such that the restricted transmitted traffic volume falls within a restriction value that is constituted by the measurement value of the received traffic volume.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a bandwidth control device, a bandwidth control method, a bandwidth control program, and a network system.

Background Art

[0002] In recent years, as a service provided by communication carriers to users, VPN (Virtual Private Network) has attracted attention. VPN is a technology that virtually separates a communication network for each user using technologies such as LAN (Local Area Network) and MPLS (Multi-Protocol Label Switching), and allows the traffic of each user to flow within each virtual network. VPN is often used especially for highly confidential communications such as between corporate bases.

[0003] Also, ensuring the reliability of a communication network is one of the important services for communication carriers. For example, maintenance at the time of a failure and rapid resolution of congestion are required of communication carriers. This is the same for communication using VPN.

[0004] Conventionally, as a congestion resolution technology in VPN, when congestion occurs on a link, a technology has been proposed to throttle based on the weight assigned to each base station with respect to the rate of the output traffic of the router that accommodates each base station to the provider network owned by the communication carrier. Furthermore, by this technology, the minimum bandwidth of communication between each base station can be ensured. As a secondary effect of this technology, it is possible to prevent the inflow of invalid traffic into the provider network. Here, invalid traffic refers to traffic that reaches the router that accommodates each base station after passing through the provider network and is discarded due to the congestion of the transfer processing performance of the router or the IF (Interface) bandwidth connecting the router to the base station.

Prior Art Documents

Non-Patent Documents

[0005]

Non - Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0006] However, the technique of adding throttling to the traffic rate based on the weight assigned to each site has restrictions imposed on the congestion of the router's IF bandwidth. For this reason, even when using this technique, it is difficult to suppress the generation of invalid traffic due to congestion caused by transfer processing performance. Also, in this technique, the amount of throttling is increased step - by - step until the occurrence of congestion is suppressed. Thus, in order to calculate the appropriate amount of throttling, repeated calculations are performed until convergence to a certain value, so even when using this technique, it is difficult to quickly respond to the generation of invalid traffic. Therefore, in the conventional congestion - elimination techniques, the response to the generation of invalid traffic is insufficient, and it is difficult to improve the reliability of the VPN.

[0007] The present invention has been made in view of the above, and an object thereof is to improve the reliability of a VPN.

Means for Solving the Problems

[0008] In order to solve the above-described problems and achieve the object, the measurement result holding unit acquires and holds measurement values of the transmission traffic volume to the predetermined network and the reception traffic volume of the destination for each pair of the transmission source and the destination of communication via the predetermined network. The control determination unit subtracts the reception traffic volume from the transmission traffic volume for each pair, and when the difference is equal to or greater than a threshold value, restricts the transmission traffic volume after restriction so that it falls within the limit value with the measured value of the reception traffic volume as the limit value.

Advantages of the Invention

[0009] According to the present invention, the reliability of the VPN can be improved.

Brief Description of the Drawings

[0010]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Embodiments for Carrying Out the Invention

[0011] Hereinafter, an embodiment of the bandwidth control device, bandwidth control method, bandwidth control program, and network system disclosed in the present application will be described in detail with reference to the drawings. Note that the bandwidth control device, bandwidth control method, bandwidth control program, and network system disclosed in the present application are not limited by the following embodiments.

[0012] [Configuration of Network System] FIG. 1 is a system configuration diagram of the network system according to the embodiment. Using FIG. 1, the configuration of the network system 1 according to the present embodiment will be described. The network system 1 includes a gateway control device 10, WAN (World Area Network) equipment 40, and a WAN 400. Further, the network system 1 includes a user base 211 having a plurality of UEs (Use Equipment) 221, a user base 212 having a plurality of UEs 222, and a user base 311 having a plurality of UEs 321. Also, the network system 1 includes VPN gateways 231, 232, 233, 331, and 332. Also, the network system 1 includes a server base 251 where a server 261 is arranged, a server base 252 where a server 262 is arranged, a server base 351 where a server 361 is arranged, and a server base 352 where a server 362 is arranged.

[0013] User sites 211 and 212, VPN gateways 231, 232, and 233, and server sites 251 and 252 form VPN 20. The VPN gateways 231, 232, and 233 are connected by logical paths represented by thick lines superimposed on the WAN 400. The VPN gateways 231, 232, and 233 communicate with each other via the logical paths.

[0014] Each UE 221 of the user site 211 is connected to the VPN gateway 231 via the network of the user site 211. Also, each UE 222 of the user site 212 is connected to the VPN gateway 232 via the network of the user site 212. Also, the server 261 is connected to the VPN gateway 233 via the network of the server site 251. Also, the server 262 is connected to the VPN gateway 233 via the network of the server site 252.

[0015] The user site 211 communicates with the server sites 251 and 252 via the VPN gateways 231 and 233. Also, the user site 212 communicates with the server sites 251 and 252 via the VPN gateways 232 and 233. Also, the user site 211 and the user site 212 communicate with each other via the VPN gateways 231 and 232.

[0016] User site 311, VPN gateways 331 and 332, and server sites 351 and 352 form VPN 30. The VPN gateway 331 and the VPN gateway 332 are connected by logical paths represented by thick lines superimposed on the WAN 400. The VPN gateway 331 and the VPN gateway 332 communicate with each other via the mutual logical path.

[0017] Also, the UE 321 at the user site 311 is connected to the VPN gateway 331 via the network of the user site 311. Also, the server 361 is connected to the VPN gateway 332 via the network of the server site 351. Also, the server 362 is connected to the VPN gateway 332 via the network of the server site 352. The user site 311 communicates with the server sites 351 and 352 via the VPN gateways 331 and 332.

[0018] The WAN 400 is a provider network and is an example of a predetermined network. The WAN facility 40 includes various devices for managing the WAN 400. The WAN facility 40 is a shared facility for the VPNs 20 and 30. The WAN facility 40 superimposes the logical paths between the VPN gateways 231, 232, and 233 on the WAN 400. Also, the WAN facility 40 superimposes the logical paths between the VPN gateways 331 and 332 on the WAN 400.

[0019] The gateway control device 10 is a bandwidth control device. The gateway control device 10 is connected to each of the VPN gateways 231, 232, 331, 233, and 332. The gateway control device 10 predicts and detects the occurrence of congestion using the transmission traffic volume and the reception traffic volume of each of the VPN gateways 231, 232, 331, 233, and 332. Here, the transmission traffic volume is the output traffic volume directed to the WAN 400. Also, the reception traffic volume is the output traffic volume directed to each of the user sites 211, 212, or 311, or the server sites 251, 252, 351, or 352. Further, the gateway control device 10 suppresses the occurrence of congestion by controlling the communication bandwidth of the source in the logical path where congestion is predicted, and suppresses the inflow of invalid traffic into the WAN 400. The details of the gateway control device 10 will be described below.

[0020] FIG. 2 is a block diagram of a network system including details of a gateway control device and a VPN gateway. Here, communication between user sites 211 and 212 and server sites 251 and 252 in VPN 20 of FIG. 1 will be described as an example.

[0021] The VPN gateway 231 includes traffic control units 201 to 204, a distribution unit 205, a measurement result notification unit 206, and a limit setting unit 207. The VPN gateway 232 includes traffic control units 201A to 204A, a distribution unit 205A, a measurement result notification unit 206A, and a limit setting unit 207A. The VPN gateway 233 includes traffic control units 201B to 204B and 201C to 204C, a distribution unit 205B, a measurement result notification unit 206B, and a limit setting unit 207B.

[0022] The VPN gateways 231, 232, and 233 each have the same functions. Specifically, the traffic control units 201 and 202 have the same functions as the traffic control units 201A, 202A, 203B, 204B, 203C, and 204C. The traffic control units 203 and 204 have the same functions as the traffic control units 203A, 204A, 201B, 202B, 201C, and 202C. The distribution unit 205 has the same function as the distribution units 205A and 205B. The measurement result notification unit 206 has the same function as the measurement result notification units 206A and 206B. The limit setting unit 207 has the same function as the limit setting units 207A and 207B. Since each unit has the same function in this way, the VPN gateway 231 will be described as an example here. When not distinguishing each of the VPN gateways 231 to 233, it is called "VPN gateway 200".

[0023] The traffic control unit 201 and the traffic control unit 203 are arranged as a pair for each output direction of the base station direction and the WAN direction with respect to the traffic between the user base station 211 and the server base station 251. Similarly, the traffic control unit 202 and the traffic control unit 204 are arranged as a pair for each output direction of the base station direction and the WAN direction with respect to the traffic between the user base station 211 and the server base station 252. Here, since two server base stations 251 and 252 are taken as examples of communication partners, two pairs are arranged, but the pairs are arranged according to the number of destinations. For example, in FIG. 1, since there is also a user base station 212 as a communication partner of the user base station 211, pairs are arranged for the traffic between the user base station 211 and the user base station 212.

[0024] The traffic control unit 201 controls the traffic from the user base station 211 to the server base station 251. The traffic control unit 201 has a queue 271. The traffic control unit 201 measures the output traffic volume, that is, the transmission traffic volume, which is the amount of traffic output from the queue 271 toward the WAN 400. Then, the traffic control unit 201 outputs the measured output traffic volume to the measurement result notification unit 206.

[0025] Also, when the traffic control unit 201 controls the output traffic volume to suppress the congestion of the traffic from the user base station 211 to the server base station 251, it receives the setting of the limit value of the output traffic volume from the limit setting unit 207. Then, the traffic control unit 201 restricts the output of the traffic from the queue 271 so that the output traffic volume falls within the set limit value.

[0026] The traffic control unit 202 controls the traffic from the user base station 211 to the server base station 252. The traffic control unit 202 has a queue 272. The traffic control unit 202 measures the output traffic volume, that is, the transmission traffic volume, which is the amount of traffic output from the queue 272 toward the WAN 400. Then, the traffic control unit 202 outputs the measured output traffic volume to the measurement result notification unit 206.

[0027] Also, when the traffic control unit 202 controls the output traffic volume to suppress the congestion of the traffic directed from the user base point 211 to the server base point 252, it receives the setting of the limit value of the output traffic volume from the limit setting unit 207. Then, the traffic control unit 202 restricts the output of the traffic from the queue 272 so that the output traffic volume falls within the set limit value.

[0028] The traffic control unit 203 controls the traffic directed from the server base point 251 to the user base point 211. The traffic control unit 203 has a queue 273. The traffic control unit 203 measures the output traffic volume, that is, the received traffic volume, which is the amount of traffic output from the queue 273 toward the user base point 211. Then, the traffic control unit 203 outputs the measured output traffic volume to the measurement result notification unit 206.

[0029] The traffic control unit 204 controls the traffic directed from the server base point 252 to the user base point 211. The traffic control unit 204 has a queue 274. The traffic control unit 204 measures the output traffic volume, that is, the received traffic volume, which is the amount of traffic output from the queue 274 toward the user base point 211. Then, the traffic control unit 204 outputs the measured output traffic volume to the measurement result notification unit 206.

[0030] FIG. 3 is a diagram showing a part of the traffic transmitted and received in the network system. Here, the traffic transmitted and received by the VPN gateways 231 and 233 will be described. For example, the VPN gateway 231 has a communication bandwidth of 1 Gbps with the WAN 400. Also, the VPN gateway 232 has a communication bandwidth of 1 Gbps with the WAN 400. Also, the VPN gateway 233 has a communication bandwidth of 1 Gbps with the server base point 251 and a communication bandwidth of 5 Gbps with the server base point 252.

[0031] The VPN gateway 231 stores the traffic sent from the user site 211 to the server site 251 in the queue 271, and transmits it to the VPN gateway 233 via the WAN 400. For example, as shown in FIG. 3, the traffic sent from a plurality of UEs 221 to the server 261 is stored in the queue 271, and these traffic are collectively output from the queue 271 to the WAN 400. Further, the VPN gateway 231 stores the traffic sent from the user site 211 to the server site 252 in the queue 272, and transmits it to the VPN gateway 233 via the WAN 400. Further, the VPN gateway 231 stores the traffic sent from the user site 211 to the user site 212 in the queue 275, and transmits it to the VPN gateway 232 via the WAN 400.

[0032] The VPN gateway 233 receives the traffic sent from the server site 251 to the user site 211 from the WAN 400, stores it in the queue 273, and transmits it to the user site 211. For example, as shown in FIG. 3, when there is no traffic from the server 261 to the UE 221, the storage of traffic in the queue 273 and the output of traffic from the queue 273 are not performed. Further, the VPN gateway 231 receives the traffic sent from the server site 252 to the user site 211 from the WAN 400, stores it in the queue 274, and transmits it to the user site 211. Further, the VPN gateway 231 stores the traffic sent from the user site 212 to the user site 211 in the queue 276, and transmits it to the user site 211.

[0033] Here, a case where the VPN gateway 233 has queues 241 to 248 for transmitting traffic will be described. The traffic 281 is traffic for the server site 251. The traffic 282 is traffic for the server site 252.

[0034] The VPN gateway 233 receives the traffic sent from the user site 211 to the server site 251 from the WAN 400, stores it in the queue 241, and transmits it towards the server site 251. Also, the VPN gateway 233 receives the traffic sent from the user site 212 to the server site 251 from the WAN 400, stores it in the queue 242, and transmits it towards the server site 251. Also, the VPN gateway 233 stores the traffic sent from the server site 251 to the user site 211 in the queue 243 and transmits it towards the VPN gateway 231 via the WAN 400. Also, the VPN gateway 233 stores the traffic sent from the server site 251 to the user site 212 in the queue 244 and transmits it towards the VPN gateway 232 via the WAN 400.

[0035] The VPN gateway 233 receives the traffic sent from the user site 211 to the server site 252 from the WAN 400, stores it in the queue 245, and transmits it towards the server site 252. Also, the VPN gateway 233 receives the traffic sent from the user site 212 to the server site 252 from the WAN 400, stores it in the queue 246, and transmits it towards the server site 252. Also, the VPN gateway 233 stores the traffic sent from the server site 252 to the user site 211 in the queue 247 and transmits it towards the VPN gateway 231 via the WAN 400. Also, the VPN gateway 233 stores the traffic sent from the server site 252 to the user site 212 in the queue 248 and transmits it towards the VPN gateway 232 via the WAN 400.

[0036] Returning to FIG. 2, the description will be continued. The measurement result notification unit 206 receives the input of the output traffic volume from the traffic control units 201 to 204. Then, the measurement result notification unit 206 notifies the measurement result holding unit 101 of the gateway control device 10 of the measurement results of the output traffic volume by the traffic control units 201 to 204 at regular intervals. Here, the regular interval can be, for example, a 5-second interval. At this time, the measurement result notification unit 206 notifies the output traffic volume by adding information on the transmission source, transmission destination, and output direction of the traffic passing through each traffic control unit 201 to 204, as well as information on the VPN GW ID. The output direction is either the WAN direction or the base station direction. In this case, the base station direction is the direction of the user base station 211. Also, the VPN GW ID is an identifier assigned to be unique to each of the VPN gateways 231, 232, 331, 233, and 332.

[0037] FIG. 4 is a diagram showing an example of the notification content from the measurement result notification unit to the gateway control device. Referring to FIG. 4, the notification of the output traffic volume by the VPN gateway 231 will be described. Here, the VPN GW ID of the VPN gateway 231 is #1. In this case, the measurement result notification unit 206 transmits the content shown in the notification content 501 of FIG. 4 to the gateway control device 10. Specifically, the measurement result notification unit 206 notifies #1, which is the identifier of the VPN gateway 231, as the VPN GW ID. Further, for the traffic going to the server base station 251, the measurement result notification unit 206 sets the traffic transmission source as the user base station 211, the traffic transmission destination as the server base station 251, and the output direction as the WAN direction. Also, the measurement result notification unit 206 notifies 100 Mbps as the output traffic volume from the queue 271. Also, for the traffic going to the server base station 252, the measurement result notification unit 206 sets the traffic transmission source as the user base station 211, the traffic transmission destination as the server base station 252, and notifies the output direction as the WAN direction. Also, the measurement result notification unit 206 notifies 50 Mbps as the output traffic volume from the queue 272.

[0038] Returning to FIG. 2, the description will be continued. The restriction setting unit 207 receives a notification of traffic control from the control instruction unit 103 of the gateway control device 10. FIG. 5 is a diagram showing an example of the content of the notification from the gateway control device to the restriction setting unit. The restriction setting unit 207 receives a notification of traffic control including the source, destination, restriction value, and setting flag. The setting flag is information indicating whether the notification instructs the setting of a restriction or the release of a restriction. Here, when the setting flag is "1", it is a notification instructing the setting of a restriction, and when the setting flag is "0", it is a notification instructing the release of a restriction.

[0039] For example, the case of setting a restriction of 20 Mbps on the traffic from the user site 211 to the server site 251 will be described. As shown in the notification content 502, the restriction setting unit 207 receives a notification in which the source is the user site 211, the destination is the server site 251, the restriction value is 20 Mbps, and the setting flag is "1". Also, in the case of a notification with the setting flag "0" instructing the release of the setting, the restriction setting unit 207 receives a notification of information representing a blank such as "-" as the setting value.

[0040] Then, the restriction setting unit 207 extracts the traffic control unit 200 whose output direction matching the target source and destination is the WAN direction according to the notification received from the gateway control device 10. For example, when receiving the notification of the notification content 502 in FIG. 5, the restriction setting unit 207 extracts the traffic control unit 201 whose source is the user site 211, the destination is the server site 251, and the output direction is the WAN 400. Then, for the extracted traffic control unit 200, when the setting flag is "1", the restriction value of the output traffic volume is set, and when the setting flag is "0", the setting of the restriction value is released. For example, if receiving the notification of the notification content 502 in FIG. 5, the restriction setting unit 207 sets the output traffic volume to 20 Mbps for the traffic control unit 201.

[0041] Returning to FIG. 2, the description will continue. The traffic distribution unit 205 receives the input of the traffic input to the VPN gateway 231 from the user site 211 or the WAN 400. Then, the traffic distribution unit 205 determines the source and destination sites of the input traffic according to information such as the destination IP address and source IP address included in the traffic. Then, the traffic distribution unit 205 distributes the traffic to any one of the traffic control units 201 to 204 according to the determination result.

[0042] For example, the transfer process in FIG. 3 is an example of the process executed by the traffic distribution unit 205. The traffic distribution unit 205 distributes the traffic input from the user site 211 to any one of the queues 271, 272, or 275. Also, the traffic distribution unit 205 distributes the traffic input from the WAN 400 to any one of the queues 273, 274, or 276. Also, the traffic distribution unit 205B distributes the traffic input from the WAN 400 to any one of the queues 241, 242, 245, or 246. Also, the traffic distribution unit 205B distributes the traffic input from the server sites 251 or 252 to any one of the queues 243, 244, 247, or 248.

[0043] Next, the gateway control device 10 will be described. The gateway control device 10 includes a measurement result holding unit 101, a control determination unit 102, and a control instruction unit 103.

[0044] The measurement result holding unit 101 receives the notification of the output traffic volume measured by the traffic control units 201 to 204 from the measurement result notification unit 206 of each VPN gateway 231. The measurement result holding unit 101 similarly receives the notification of the output traffic volume from the VPN gateway 232 and the VPN gateway 233. Then, the measurement result holding unit 101 holds the respective notification contents from the VPN gateways 231, 232, and 233.

[0045] FIG. 6 is a diagram showing an example of the holding information held by the measurement result holding unit. Here, the VPN GW ID of the VPN gateway 232 is #2, and the VPN GW ID of the VPN gateway 233 is #3. As shown in the holding information 503 of FIG. 6, the measurement result holding unit 101 holds the source, destination, and output direction of the traffic corresponding to each output traffic volume, and the output traffic volume, in association with the source VPN GW ID.

[0046] As described above, the measurement result holding unit 101 acquires and holds the measured values of the transmission traffic volume to the WAN 400 and the reception traffic volume of the destination for each pair of the source and destination of the communication via the WAN 400.

[0047] Returning to FIG. 2 to continue the description. The control determination unit 102 checks the holding information held by the measurement result holding unit 101 at a predetermined interval. Here, the predetermined interval may be the same as or different from the notification interval by the measurement result notification unit 206 of the VPN gateway 200. The predetermined interval can be, for example, the same 5 seconds as the notification interval of the measurement result notification unit 206 of the VPN gateway 200. Then, the control determination unit 102 calculates, for each pair of the source and destination, the difference obtained by subtracting the output traffic volume in the base direction from the output traffic volume in the WAN direction, that is, the difference obtained by subtracting the reception traffic volume from the transmission traffic volume, from the content of the holding information held by the measurement result holding unit 101.

[0048] Next, the control determination unit 102 determines whether there is a calculated result in which the difference is equal to or greater than a predetermined congestion determination threshold value for each calculated result having the same destination. In this case, the sources in the calculated results may be different. The congestion determination threshold value can be set, for example, to a value at which congestion is considered to occur statistically if the difference is greater than or equal to that value. For example, the congestion determination threshold value can be set to 10 Mbps. Then, when there is a difference equal to or greater than the congestion determination threshold value, the control determination unit 102 determines that congestion has occurred or has occurred at the destination. Hereinafter, including the case where congestion is about to occur, it is said that "congestion has occurred".

[0049] For the traffic addressed to the destination where congestion has occurred, the control determination unit 102 performs the following processing to limit the amount of output traffic to the WAN 400. The control determination unit 102 selects one source from each piece of data having as the destination the destination where congestion has occurred in the holding information held by the measurement result holding unit 101. In this case, the control determination unit 102 selects the source regardless of the magnitude of the difference. That is, since congestion has occurred at the destination, the control determination unit 102 overall restricts data transmission to that destination in order to eliminate the congestion.

[0050] The control determination unit 102 acquires the traffic data from the source selected to the destination where congestion has occurred from the holding information held by the measurement result holding unit 101. Here, the control determination unit 102 acquires two pieces of data, i.e., the data from the VPN gateway 200 accommodating the source and the data from the VPN gateway 200 accommodating the destination, as the traffic data.

[0051] Next, the control determination unit 102 extracts the output traffic amount in the output direction being the base direction and the VPN GW ID of the VPN gateway 200 accommodating the selected source in the selected traffic data. Here, the output traffic amount in the output direction being the base direction is the output traffic amount measured by the VPN gateway 200 accommodating the source where congestion has occurred and directed to the source where congestion has occurred, and is the received traffic amount.

[0052] Next, the control determination unit 102 notifies the control instruction unit 103 of the selected source, the destination where congestion has occurred, the output traffic amount in the base direction, the extracted VPN GW ID, and information with the excess flag set to "1". Further, the control determination unit 102 records the destination where congestion has occurred as the congestion-occurring base, records the information of the selected source and the extracted VPN GW ID, and records the output traffic amount in the base direction as the limit value.

[0053] When there are multiple sources for the traffic to the destination where convergence has occurred, the control determination unit 102 repeats the process of limiting the same output traffic volume for each source.

[0054] For example, for the case where the measurement result holding unit 101 holds the holding information 503 shown in FIG. 6, the process for limiting the output traffic volume by the control determination unit 102 will be described. The control determination unit 102 calculates the difference between the WAN direction and the site direction of the traffic data 531 and 532 with the user site 211 as the source and the server site 251 as the destination as 100 - 20 = 80. Also, the control determination unit 102 calculates the difference between the WAN direction and the site direction of the traffic data 533 and 534 with the user site 212 as the source and the server site 251 as the destination as 30 - 30 = 0. Here, for example, when the convergence determination threshold is 10 Mbps, the difference in the traffic represented by the data 531 and 532 is equal to or greater than the convergence determination threshold. Therefore, the control determination unit 102 determines that convergence has occurred at the server site 251.

[0055] Next, the control determination unit 102 selects the user site 211 as the source of the traffic. Next, the control determination unit 102 acquires the traffic data 531 and 532 with the user site 211 as the source. Next, the control determination unit 102 acquires 20 Mbps, which is the output traffic volume in the site direction, from the data 532. Further, the control determination unit 102 extracts #1, which is the VPN GW ID of the VPN gateway 231 accommodating the user site 211.

[0056] Also, the control determination unit 102 selects the user site 212 with a small difference in output traffic volume as the source of the traffic. Next, the control determination unit 102 acquires the traffic data 533 and 534 with the user site 212 as the source. Next, the control determination unit 102 acquires 30 Mbps, which is the output traffic volume in the site direction, from the data 534. The control determination unit 102 extracts #2, which is the VPN GW ID of the VPN gateway 232 accommodating the user site 212.

[0057] FIG. 7 is a diagram showing an example of the content of the notification of the restriction setting from the control determination unit to the control instruction unit. The control determination unit 102 notifies the control instruction unit 103 of the notification content 504 shown in FIG. 7. The control determination unit 102 notifies #1 as the extracted VPN GW ID for the user site 211, notifies the user site 211 as the transmission source, and notifies the server site 251 as the destination where congestion has occurred. Further, the control determination unit 102 notifies 20 Mbps as the output traffic volume in the direction of the site, and notifies information with the excess flag set to "1". Also, the control determination unit 102 notifies #2 as the extracted VPN GW ID for the user site 212, notifies the user site 212 as the transmission source, and notifies the server site 252 as the destination where congestion has occurred. Further, the control determination unit 102 notifies 30 Mbps as the output traffic volume in the direction of the site, and notifies information with the excess flag set to "1".

[0058] Also, the control determination unit 102 records the server site 251, which is the destination where congestion has occurred, as the congestion-occurring site. Further, the control determination unit 102 records the user site 211 as the transmission source, #1 as the VPN GW ID, and 20 Mbps as the limit value. Similarly, the control determination unit 102 records the user site 212 as the transmission source, #2 as the VPN GW ID, and 30 Mbps as the limit value.

[0059] As described above, for each pair of the transmission source and the destination of the communication via the predetermined network, when the difference obtained by subtracting the measured value of the received traffic volume from the measured value of the transmitted traffic volume is equal to or greater than the threshold value, the control determination unit 102 sets the measured value of the received traffic volume as the limit value and performs restriction so that the restricted transmitted traffic volume falls within the limit value. Also, for each pair in which the difference is equal to or greater than the threshold value and the destination in the pair is set as the destination in itself, the control determination unit 102 sets the measured value of the received traffic volume as the limit value and performs restriction so that the restricted transmitted traffic volume falls within the limit value.

[0060] In addition, the control determination unit 102 makes the following determination regarding the traffic with the recorded convergence occurrence site as the destination. The control determination unit 102 determines whether there is traffic in the traffic with each site as the source, where the difference between the output traffic volume in the WAN direction and the site direction is less than the convergence determination threshold value and the output traffic volume in the WAN direction is less than the limit value. If, in the traffic with any site as the source, the difference in the output traffic volume is below the convergence determination threshold value and the output traffic volume in the WAN direction is less than the limit value, the control determination unit 102 determines that the convergence with the convergence occurrence site as the destination has been resolved.

[0061] Then, as shown in the notification content 505 in FIG. 8, the control determination unit 102 notifies the control instruction unit 103 of information including the destination where the convergence has been resolved, the source of the traffic to which the output traffic volume limit has been applied, and the excess flag set to "0". FIG. 8 is a diagram showing an example of the notification content of the restriction release from the control determination unit to the control instruction unit. In this case, since it is the release of the output traffic volume limit, as shown in the notification content 505, the notification of the output traffic volume may not be performed. If there are multiple sources of traffic to which the output traffic volume limit has been applied, the control determination unit 102 issues notifications to the control instruction unit 103 for each of those sources. After that, the control determination unit 102 deletes the information of the destination for which the restriction release has been instructed from the recorded convergence occurrence site.

[0062] As described above, when the difference between the source and destination of the communication via the restricted WAN 400 is less than the threshold value and the transmitted traffic volume is less than the limit value, the control determination unit 102 releases the restriction.

[0063] The control instruction unit 103 receives a notification regarding the limitation of the output traffic volume from the control determination unit 102. When the excess flag included in the notification is "1", the control instruction unit 103 notifies the VPN gateway 200 that matches the VPN GW ID specified in the notification of an instruction to execute the limitation of the output traffic volume. Specifically, the control instruction unit 103 transmits a notification with the information of the source and destination specified in the notification, and sets the limitation value and the setting flag of the output traffic volume in the WAN direction to "1".

[0064] On the contrary, when the excess flag included in the notification is "0", the control instruction unit 103 notifies the VPN gateway 200 that matches the VPN GW ID specified in the notification of an instruction to cancel the limitation of the output traffic volume. Specifically, the control instruction unit 103 transmits a notification with the information of the source and destination specified in the notification, and sets the setting flag to "0" and the limitation value to blank.

[0065] FIG. 9 is a diagram showing an overview of the control of the output traffic volume when congestion occurs. FIG. 9 shows a state where congestion has occurred in the traffic transmitted and received by the VPN gateways 231, 232, and 233 shown in FIG. 3. Although there are other sources for which the output traffic volume can be limited, here, the overall overview of the output traffic volume limitation procedure will be described by limiting it to the cases where the user site 211, the server site 251, and the server site 252 are the sources.

[0066] The gateway control device 10 obtains the difference between the output traffic volume in the site direction of the VPN gateway 233 of the traffic transmitted from the user site 211 to the server site 251 and the output traffic volume in the WAN direction at the VPN gateway 231. Then, since the difference is equal to or greater than the congestion determination threshold value, the gateway control device 10 determines that congestion P1 has occurred at the server site 251, which is the destination of the traffic. Due to this congestion P1, packet loss occurs in the packets sent to the server site 251.

[0067] In this case, the gateway control device 10 selects the user site 211 as one of the sources of the traffic destined for the server site 251. Then, the gateway control device 10 limits the output traffic volume 291 from the queue 271 to the WAN 400, using the output traffic volume 292 from the queue 241 to the server site 251 as the limit value.

[0068] Also, the gateway control device 10 calculates the difference between the output traffic volume in the direction of the VPN gateway 232 and the output traffic volume in the WAN direction at the VPN gateway 233 for the traffic transmitted from the server site 252 to the user site 212. Then, since the difference is equal to or greater than the congestion determination threshold, the gateway control device 10 determines that congestion P2 has occurred at the user site 212, which is the destination of the traffic. Due to this congestion P2, packet loss occurs for the packets sent to the user site 212.

[0069] In this case, the gateway control device 10 selects the user site 211 as one of the sources of the traffic destined for the user site 212. Then, the gateway control device 10 limits the output traffic volume 294 from the queue 275 to the WAN 400, using the output traffic volume from the VPN gateway 232 for the traffic from the user site 211 to the user site 212 as the limit value. Also, the gateway control device 10 selects the server site 252 as one of the sources of the traffic destined for the user site 212. Then, the gateway control device 10 limits the output traffic volume 293 from the queue 248 to the WAN 400, using the output traffic volume from the VPN gateway 232 for the traffic from the server site 252 to the user site 212 as the limit value.

[0070] [Bandwidth Limiting Process] FIG. 10 is a flowchart of the bandwidth limiting process by the gateway control device according to the embodiment. Next, with reference to FIG. 10, the overall flow of the bandwidth limiting process by the gateway control device 10 according to the present embodiment will be described.

[0071] The measurement result holding unit 101 acquires the output traffic volume from each VPN gateway 200 and holds it as holding information (step S1).

[0072] The control determination unit 102 refers to the holding information held by the measurement result holding unit 101 and calculates the difference between the output traffic volume in the WAN direction and the output traffic volume in the base direction for each traffic for each pair of source and destination (step S2).

[0073] Next, the control determination unit 102 determines whether there is a destination for which the obtained difference is equal to or greater than the congestion determination threshold (step S3). If there is no destination for which the difference is equal to or greater than the congestion determination threshold (step S3: negative), the bandwidth control process proceeds to step S8.

[0074] On the other hand, if there is a destination for which the difference is equal to or greater than the congestion determination threshold (step S3: positive), the control determination unit 102 determines that congestion has occurred at that destination. Then, the control determination unit 102 selects one source for the destination where congestion has occurred (step S4).

[0075] Next, the control determination unit 102 notifies the control instruction unit 103 of an instruction to execute control, with the limit value of the output traffic volume in the WAN direction from the VPN gateway 200 accommodating the source as the output traffic volume to the destination from the VPN gateway 200 accommodating the destination. The control instruction unit 103 notifies the limit value to the VPN gateway 200 accommodating the selected source and restricts the output traffic volume from the selected source to the destination to the limit value. That is, the control instruction unit 103 restricts the transmission traffic volume of the selected source to the reception traffic volume of the destination (step S5).

[0076] Next, the control determination unit 102 determines whether the restriction of the output traffic volume has been completed for all sources for the destination where congestion has occurred (step S6). If there is a remaining source for which the output traffic volume has not been restricted (step S6: negative), the bandwidth control process returns to step S4.

[0077] On the other hand, when the restriction on the output traffic volume has ended for all the sources (step S6: affirmative), the control determination unit 102 stores the source where congestion has occurred as the congestion occurrence base point (step S7).

[0078] Next, the control determination unit 102 determines whether there is a congestion occurrence base point that is the destination of traffic whose difference is less than the congestion determination threshold and whose output traffic volume in the WAN direction is less than the limit value (step S8).

[0079] Next, when there is no congestion occurrence base point that is the destination of traffic whose difference is less than the congestion determination threshold and whose output traffic volume in the WAN direction is less than the limit value (step S8: negative), the gateway control device 10 ends the bandwidth control process.

[0080] On the other hand, when there is a congestion occurrence base point that is the destination of traffic whose difference is less than the congestion determination threshold and whose output traffic volume in the WAN direction is less than the limit value (step S8: affirmative), the control determination unit 102 executes the following process. The control determination unit 102 selects one source for the congestion occurrence base point (step S9).

[0081] Next, the control determination unit 102 notifies the control instruction unit 103 to lift the restriction on the output traffic volume from the selected source to the congestion occurrence base point. The control instruction unit 103 instructs the VPN gateway 200 accommodating the selected source to lift the restriction on the output traffic volume from the selected source to the congestion occurrence base point and lifts the restriction (step S10).

[0082] Thereafter, the control determination unit 102 determines whether the release of the restriction for all the sources for the congestion occurrence base point has been completed (step S11). When there is a source for which the release of the restriction has not been performed (step S11: negative), the bandwidth control process returns to step S9.

[0083] On the other hand, when the restriction release for all the sources is completed (step S11: affirmative), the gateway control device 10 ends the bandwidth control process. The gateway control device 10 repeats the above bandwidth control process at predetermined intervals.

[0084] [Effect by Gateway Control Device] As described above, the gateway control device 10, which is a bandwidth control device according to the present embodiment, determines that congestion has occurred at the destination of the traffic when the difference between the transmission traffic volume and the reception traffic volume in each traffic is equal to or greater than the congestion determination threshold value. Then, the gateway control device 10 restricts the transmission traffic volume to the reception traffic volume in the traffic between the congested destination and each source for that destination.

[0085] As a result, the transmission traffic volume can be made to match based on the measured value of the reception traffic volume, and it becomes possible to suppress the occurrence of invalid traffic to the WAN, such as traffic that cannot reach each site despite passing through the WAN. Also, by restricting the invalid traffic volume at the source based on the result of the decrease in the reception traffic volume due to congestion caused by the transfer processing capacity, it becomes possible to suppress the congestion caused by the transfer processing capacity. Further, by calculating the limit value based on the reception traffic volume, it becomes possible to quickly respond to the occurrence of invalid traffic. By these means, the bandwidth control device according to the present embodiment can improve the reliability of the VPN.

[0086] [System Configuration, etc.] Moreover, each component of each illustrated device is functionally conceptual and does not necessarily have to be physically configured as shown in the figures. That is, the specific forms of distribution and integration of each device are not limited to those shown in the figures, and all or part of them can be functionally or physically distributed or integrated in any unit according to various loads, usage situations, etc. Furthermore, each processing function performed by each device can be realized in whole or in any part by a CPU (Central Processing Unit) and a program analyzed and executed by the CPU, or can be realized as hardware by wired logic.

[0087] Also, among the various processes described in this embodiment, all or part of the processes described as being automatically performed can be manually performed, or all or part of the processes described as being manually performed can be automatically performed by a known method. In addition, the processing procedures, control procedures, specific names, and information including various data and parameters shown in the above documents and drawings can be arbitrarily changed unless otherwise specified.

[0088] [Program] As an embodiment, the gateway control device 10, which is a bandwidth control device, can be implemented by installing a bandwidth control program that executes the above information processing as package software or online software on a desired computer. For example, by causing the information processing device to execute the above bandwidth control program, the information processing device can function as the gateway control device 10. The information processing device mentioned here includes desktop or notebook personal computers. In addition, other information processing devices include mobile communication terminals such as smartphones, mobile phones, and PHS (Personal Handy-phone System), and further include slate terminals such as PDAs (Personal Digital Assistant) within its scope.

[0089] In addition, the bandwidth control device can also be implemented as a service providing device that uses the terminal device used by the user as a client and provides the client with the service related to the above bandwidth control process. For example, the bandwidth control device is implemented as a server device that provides a bandwidth control service for performing bandwidth control. In this case, the server device may be implemented as a Web server, or may be implemented as a cloud that provides the service related to the above bandwidth control process by outsourcing.

[0090] FIG. 11 is a diagram showing an example of a computer that executes a bandwidth control program. The computer 1000 has, for example, a memory 1010 and a CPU 1020. In addition, the computer 1000 has a hard disk drive interface 1030, a disk drive interface 1040, a serial port interface 1050, a video adapter 1060, and a network interface 1070. These components are connected by a bus 1080.

[0091] The memory 1010 includes a ROM (Read Only Memory) 1011 and a RAM (Random Access Memory) 1012. The ROM 1011 stores a boot program such as a BIOS (BASIC Input Output System), for example. The hard disk drive interface 1030 is connected to the hard disk drive 1090. The disk drive interface 1040 is connected to the disk drive 1100. A removable storage medium such as a magnetic disk or an optical disk is inserted into the disk drive 1100, for example. The serial port interface 1050 is connected to, for example, a mouse 1110 and a keyboard 1120. The video adapter 1060 is connected to, for example, a display 1130.

[0092] The hard disk drive 1090 stores, for example, an OS 1091, application programs 1092, program modules 1093, and program data 1094. That is, a classification program that defines each process of the gateway control device 10 having the same function as the gateway control device 10 is implemented as a program module 1093 in which executable code by a computer is described. The program module 1093 is stored in, for example, the hard disk drive 1090. For example, a program module 1093 for executing the same processing as the functional configuration in the gateway control device 10 is stored in the hard disk drive 1090. Note that the hard disk drive 1090 may be replaced by an SSD (Solid State Drive).

[0093] Also, the setting data used in the processing of the above-described embodiment is stored as program data 1094 in, for example, the memory 1010 or the hard disk drive 1090. Then, the CPU 1020 reads out the program module 1093 and the program data 1094 stored in the memory 1010 or the hard disk drive 1090 into the RAM 1012 as needed, and executes the processing of the above-described embodiment.

[0094] Note that the program module 1093 and the program data 1094 are not limited to being stored in the hard disk drive 1090, and may be stored in, for example, a removable storage medium and read by the CPU 1020 via a disk drive 1100 or the like. Alternatively, the program module 1093 and the program data 1094 may be stored in another computer connected via a network (LAN (Local Area Network), WAN (Wide Area Network), etc.). Then, the program module 1093 and the program data 1094 may be read by the CPU 1020 from another computer via the network interface 1070.

Description of Reference Numerals

[0095] 1 Network system 10 Gateway control device 20, 30 VPN 40 WAN equipment 101 Measurement result holding unit 102 Control determination unit 103 Control instruction unit 201~204, 201A~204A, 201B~204B, 201C~204C Traffic control unit 205, 205A, 205B Branching unit 206, 206A, 206B Measurement result notification unit 207, 207A, 207B Limit setting unit 211, 212, 311 User site 221, 222, 321 UE 200, 231, 232, 233, 331, 332 VPN gateway 251, 252, 351, 352 Server site 261, 262, 361, 362 Server 241~248, 271~276 Queue 400 WAN

Claims

1. A measurement result holding unit that acquires and holds measurement values of the transmission traffic volume to the predetermined network and the reception traffic volume of the transmission destination for each pair of a transmission source and a transmission destination of communication via the predetermined network; For each pair, when the difference obtained by subtracting the measurement value of the reception traffic volume from the measurement value of the transmission traffic volume is equal to or greater than a threshold value, using the measurement value of the reception traffic volume as a limit value, a control determination unit that performs a limit so that the transmission traffic volume after the limit falls within the limit value A bandwidth control device characterized by comprising the above.

2. For each pair in which the difference is equal to or greater than the threshold value and the transmission destination in the pair is the transmission destination of the control determination unit itself, using the measurement value of the reception traffic volume as a limit value, the bandwidth control device according to claim 1, characterized in that a limit is performed so that the transmission traffic volume after the limit falls within the limit value.

3. For the pair for which the limit has been performed, when the difference is less than the threshold value and the transmission traffic volume is less than the limit value, the bandwidth control device according to claim 1 or 2, characterized in that the limit is released.

4. The measurement result holding unit acquires and holds the measurement values of the transmission traffic volume to the virtual network and the reception traffic volume of the transmission destination for each pair of the transmission source and the transmission destination of the communication passing through the virtual network obtained by virtually separating the predetermined network, the bandwidth control device according to any one of claims 1 to 3.

5. A bandwidth control method executed by a bandwidth control device, A step of acquiring and holding measurement values of the transmission traffic volume to the predetermined network and the reception traffic volume of the transmission destination for each pair of a transmission source and a transmission destination of communication via the predetermined network; For each pair, when the difference obtained by subtracting the measurement value of the reception traffic volume from the measurement value of the transmission traffic volume is equal to or greater than a threshold value, using the measurement value of the reception traffic volume as a limit value, a step of performing a limit so that the transmission traffic volume after the limit falls within the limit value A bandwidth control method characterized by including the above.

6. An information acquisition step of acquiring and holding measurement values of the transmission traffic volume to the predetermined network and the reception traffic volume of the transmission destination for each pair of a transmission source and a transmission destination of communication via the predetermined network; For each group, when the difference obtained by subtracting the measured value of the received traffic volume from the measured value of the transmitted traffic volume is equal to or greater than a threshold value, a control step of using the measured value of the received traffic volume as a limit value and restricting the transmitted traffic volume after restriction so as to fall within the limit value A bandwidth control program, characterized in that it causes a computer to execute the program.

7. A network system having a communication control device that controls communication via a predetermined network and a bandwidth control device that controls the communication control device, The communication control device measures the amount of transmitted traffic to the predetermined network and the amount of received traffic at the transmission destination for each pair of the transmission source and the transmission destination of the communication, and notifies the bandwidth control device of the measured values, The bandwidth control device, A measurement result holding unit that acquires and holds the measured values from the communication control device, A control determination unit that, for each group, when the difference obtained by subtracting the measured value of the received traffic volume from the measured value of the transmitted traffic volume is equal to or greater than a threshold value, uses the measured value of the received traffic volume as a limit value and causes the communication control device to perform a restriction so that the transmitted traffic volume after restriction falls within the limit value A network system, characterized by comprising the above components.

Citation Information

Patent Citations

  • Device for controlling router, router, ip-VPN system and method for controlling router

    JP2006345173A

  • Transmission rate control method, transmission rate controller, and transmission rate control program

    JP2008160302A

  • Congestion detection control system and congestion detection control method

    JP2016076833A

  • Communication system, control apparatus, information collection method and program

    WO2014157460A1