Communication device, communication method, and communication program

By distributing traffic volume collection and congestion judgment to VPN GWs, the communication device and method enhance congestion determination accuracy and reduce controller load, addressing the inefficiencies of centralized management in conventional VPN systems.

JP7800662B2Active Publication Date: 2026-01-16NIPPON TELEGRAPH & TELEPHONE CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2024513623
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-04-06
Publication Date
2026-01-16
Estimated Expiration
2042-04-06

AI Technical Summary

Technical Problem

Conventional VPN technologies face issues with high load on controllers due to centralized data management and inaccurate traffic congestion judgment, leading to increased costs and potential errors in congestion determination.

Method used

A communication device and method that includes a measurement unit to measure input and output traffic, a determination unit to detect traffic differences exceeding a threshold, and a control unit to send notifications and limit traffic when congestion is detected, distributing the congestion judgment function to VPN GWs to reduce controller load.

Benefits of technology

Improves the accuracy of traffic congestion determination and reduces the load on the controller by distributing traffic volume collection and congestion judgment to VPN GWs, minimizing discrepancies and errors.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007800662000001
    Figure 0007800662000001
  • Figure 0007800662000002
    Figure 0007800662000002
  • Figure 0007800662000003
    Figure 0007800662000003
Patent Text Reader

Abstract

A Virtual Private Network (VPN) gateway (GW) (10) measures an input traffic amount that is inputted from a relay network (50) used for relaying the communication between sites, and an output traffic amount of data inputted from the relay network (50) that is to be outputted to the site of transmission destination. Then, the VPN GW (10) determines whether the difference between the input traffic amount and the output traffic amount measured is equal to or greater than a predetermined threshold value. When the difference between the input traffic amount and the output traffic amount is equal to or greater than the predetermined threshold value, the VPN GW (10) transmits a predetermined notification to an external controller (20). Thereafter, when having received a notification to the effect that the traffic amount is to be limited, the VPN GW (10) performs a control to limit the output traffic amount for performing the communication.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a communication device, a communication method, and a communication program. [Background technology]

[0002] In the past, congestion could occur when traffic volume exceeded the bandwidth and transfer processing performance allocated by contract between VPN (Virtual Private Network) users and VPN providers. As a result, in relay networks (networks) that relay communications between bases, congestion could lead to a deterioration in communication quality for multiple VPNs, and it was sometimes necessary to add equipment to accommodate the increase in traffic.

[0003] In addition, if congestion occurs and traffic passing through a relay network is lost at the VPN GW (Gateway), one method is to suppress the traffic flow in the relay network by applying bandwidth restrictions before the traffic enters the relay network.For example, a controller collects and centrally manages data on the communication direction and up / down of data for each pair of bases, and suppresses the traffic flow in the relay network by applying bandwidth restrictions to the traffic volume of the VPN GW before and after the relay network before the traffic enters the relay network. [Prior art documents] [Non-patent literature]

[0004] [Non-Patent Document 1] Takayuki Nakamura, Takamasa Narumi, Ken Osaka, "Proposal of a method to suppress inflow traffic to a relay network shared with VPNs," Proceedings of the Institute of Electronics, Information and Communication Engineers General Conference, March 1, 2022 Summary of the Invention [Problem to be solved by the invention]

[0005] However, conventional technologies have had issues such as a high load on the controller and inaccurate traffic congestion judgment. For example, in conventional technologies, the controller centrally manages data and collects data on the communication direction and up / down traffic for each pair of bases. This poses an issue of increased load on the controller when there are many bases. In addition, when the controller acquires traffic from different VPN GWs, there is a tendency for the acquisition time to differ, which can lead to incorrect congestion judgment due to the resulting discrepancy.

[0006] The present invention has been made in consideration of the above, and aims to provide a communication device, a communication method, and a communication program that can appropriately control communication while reducing the cost of information management. [Means for solving the problem]

[0007] In order to solve the above-mentioned problems and achieve the object, the communication device of the present invention is characterized by having a measurement unit that measures the amount of input traffic input from a relay network that relays communication between bases and the amount of output traffic that outputs data input from the relay network to a destination base, a determination unit that determines whether the difference between the input traffic amount and the output traffic amount measured by the measurement unit is greater than or equal to a predetermined threshold, and if the difference between the input traffic amount and the output traffic amount is greater than or equal to the predetermined threshold, sends a predetermined notification to an external device, and a traffic control unit that, when a notification to limit the traffic amount is received, controls communication so that the output traffic amount is limited. [Effects of the Invention]

[0008] According to the present invention, it is possible to improve the accuracy of determining traffic congestion while reducing the load on the controller. [Brief explanation of the drawings]

[0009] [Figure 1]FIG. 1 is a block diagram illustrating an example of a configuration of a communication system according to an embodiment. [Figure 2] FIG. 2 is a block diagram illustrating the configuration of a VPN GW according to this embodiment. [Figure 3] FIG. 3 is a diagram illustrating an example of information stored in the traffic storage unit. [Figure 4] FIG. 4 is a diagram illustrating an example of data notified from the VPN GW to the controller when congestion occurs. [Figure 5] FIG. 5 is a diagram illustrating an example of data notified from the VPN GW to the controller when congestion is resolved. [Figure 6] FIG. 6 is a block diagram illustrating the configuration of the controller of this embodiment. [Figure 7] FIG. 7 is a diagram illustrating an example of information stored in the configuration information storage unit. [Figure 8] FIG. 8 is a diagram illustrating an example of data notified from the controller to the VPN GW when congestion occurs. [Figure 9] FIG. 9 is a diagram illustrating an example of data notified from the controller to the VPN GW when congestion is resolved. [Figure 10] FIG. 10 is a flowchart showing an example of a processing procedure by the VPN GW of this embodiment. [Figure 11] FIG. 11 is a flowchart showing an example of a processing procedure by the VPN GW of this embodiment. [Figure 12] FIG. 12 is a diagram illustrating the conventional problem. [Figure 13] FIG. 13 is a diagram illustrating the effect of the communication system according to the embodiment. [Figure 14] FIG. 14 is a diagram illustrating a computer that executes a program. DETAILED DESCRIPTION OF THE INVENTION

[0010] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS A communication device, a communication method, and a communication program according to the present invention will be described in detail below with reference to the accompanying drawings. However, the present invention is not limited to the following embodiments.

[0011] [Communication system configuration] The configuration of a communication system 1 according to an embodiment will be described. Fig. 1 is a block diagram showing an example of the configuration of a communication system according to an embodiment. As shown in Fig. 1, the communication system 1 includes a plurality of VPN GWs (communication devices) 10A to 10C, a controller 20, a plurality of user locations 30A and 30B, a plurality of server locations 40A and 40B, and a relay NW (for example, a WAN (Wide Area Network)) 50.

[0012] It is assumed that the settings for connecting the various bases required for providing VPN services and various other settings have already been made in communication system 1. It is assumed that user bases 30A and 30B and server bases 40A and 40B are in a state where they can communicate with each other via VPN GW 10A, VPN GW 10B, VPN GW 10C, and relay NW 50 between them.

[0013] It is assumed that the multiple VPN GWs 10A to 10C each have similar functions and configurations, and will be referred to as VPN GW 10 when there is no need to distinguish between them. Furthermore, the multiple user sites 30A and 30B and the multiple server sites 40A and 40B will be referred to as user site 30 and server site 40, respectively, when there is no need to distinguish between them. The configuration shown in FIG. 1 is merely an example, and the specific configuration and the number of devices are not particularly limited. In the figure, it is assumed that the identification information of the user site 30A is "user site 1," the identification information of the user site 30B is "user site 2," the identification information of the server site 40A is "server site 1," and the identification information of the server site 40B is "server site 2."

[0014] The VPN GW10 is a communication device that communicates data sent and received between a subordinate site and another site. The VPN GW10 measures traffic for each pair of a source site and a destination site. For example, in the example of FIG. 1, the VPN GW10A measures the pair of traffic volume input via the relay NW50 for communication data from the source server site 40A and the traffic volume output to the subordinate user site 30A. The VPN GW10A also measures the pair of traffic volume input via the relay NW50 for communication data from the source server site 40B and the traffic volume output to the subordinate user site 30A.

[0015] Furthermore, the VPN GW 10 controls the traffic of data transmitted from a subordinate base to another base in response to an instruction from the controller 20. For example, the VPN GW 10 controls communication in response to an instruction from the controller 20 so as to limit the amount of traffic of data transmitted from the subordinate base, user base 30A, to server base 40A or server base 40B.

[0016] The controller 20 issues instructions to control traffic of each of the VPN GWs 10A to 10C. For example, when the controller 20 receives a notification from the VPN GW 10 that congestion is occurring, the controller 20 instructs the VPN GW 10 that controls the source site to limit the amount of traffic. To give a specific example, when the controller 20 receives a notification from the VPN GW 10A that congestion is occurring between the source server site 40A and the destination user site 30A, the controller 20 instructs the source server site 40A to limit the amount of traffic.

[0017] [VPN GW configuration] 2 is a block diagram illustrating the configuration of a VPN GW according to this embodiment. As illustrated in FIG. 2, the VPN GW 10 according to this embodiment includes a communication processing unit 11, a control unit 12, and a storage unit 13.

[0018] The communication processing unit 11 is realized by a NIC (Network Interface Card) or the like, and controls communication via a telecommunication line such as a LAN (Local Area Network) or the Internet.

[0019] The storage unit 13 stores data and programs necessary for various processes by the control unit 12, and includes a traffic storage unit 13a. For example, the storage unit 13 is a semiconductor memory element such as a RAM (Random Access Memory) or a flash memory, or a storage device such as a hard disk or an optical disk.

[0020] The traffic storage unit 13a stores the traffic volume of data transmitted from a source base to a destination base. For example, as shown in Fig. 3, the traffic storage unit 13a stores, in association with each other, a "source" indicating information identifying the source base, a "destination" indicating information identifying the destination base, an "input / output" indicating whether the data was input via the relay NW 50 or output to a subordinate base, and a "traffic volume" indicating the traffic volume of the input or output data. Fig. 2 is a block diagram illustrating the configuration of a VPN GW of this embodiment.

[0021] The control unit 12 has an internal memory for storing programs that define various processing procedures and required data, and executes various processes using these. For example, the control unit 12 has a traffic measurement unit 12a, a measurement result collection unit 12b, a congestion determination unit 12c, a limit setting unit 12d, and a traffic control unit 12e. Here, the control unit 12 is an electronic circuit such as a CPU (Central Processing Unit) or an MPU (Micro Processing Unit), or an integrated circuit such as an ASIC (Application Specific Integrated Circuit) or an FPGA (Field Programmable Gate Array).

[0022] The traffic measurement unit 12a measures the amount of input traffic input from the relay network 50 that relays communication between bases, and the amount of output traffic that outputs data input from the relay network 50 to a destination base. In other words, for each pair of a source and a destination base, the traffic measurement unit 12a measures the amount of input traffic from the relay network 50 to its own device, and the amount of output traffic from its own device to a subordinate base.

[0023] The measurement result collection unit 12b collects the input traffic volume and output traffic volume measured by the traffic measurement unit 12a, and stores the collected traffic volume in association with information identifying the source base and information identifying the destination base in the traffic storage unit 13a. For example, the measurement result collection unit 12b collects and stores the input and output traffic volume for each base pair measured by the traffic measurement unit 12a at regular intervals (for example, every 5 seconds).

[0024] The congestion determination unit 12c determines whether the difference between the input traffic volume and the output traffic volume measured by the traffic measurement unit 12b is equal to or greater than a predetermined threshold, and if the difference between the input traffic volume and the output traffic volume is equal to or greater than the predetermined threshold, transmits a predetermined notification to the controller 20. For example, if the difference between the input traffic volume and the output traffic volume is equal to or greater than the predetermined threshold, the congestion determination unit 12c transmits a notification to the controller 20 including information identifying the source base stored in the traffic storage unit 13a.

[0025] Specifically, the congestion determination unit 12c periodically calculates the difference between the input and output traffic volumes for each base pair from the contents of the measurement result collection unit 12b, by subtracting the output traffic volume from the input traffic volume.The congestion determination unit 12c then determines that congestion has occurred if any of the calculated differences exceeds a threshold value previously set for congestion determination.

[0026] For example, the congestion determination unit 12c calculates the difference between the input and output traffic volume for each base pair from the contents of the measurement result collection unit 12b at regular intervals (e.g., every 5 seconds). Here, assume that the input and output traffic volumes for an output traffic source of "user base 1" and destination of "server base 1" are 100 Mbps and 50 Mbps, respectively. In this case, if the difference exceeds the congestion determination threshold (10 Mbps), the congestion determination unit 12c determines that congestion has occurred.

[0027] Next, the congestion determination unit 12c determines that the source of the base pair determined to be congested, and the source of other base pairs that have the same destination (hereinafter referred to as the "congestion-occurring base") within the base pair, are subject to traffic restriction.

[0028] For example, the congestion determination unit 12c determines that "user location 1," which is the source of the location pair determined to be congested, and "user location 2," which is the source of another location pair whose destination is "server location 1," the location where congestion has occurred and is the destination of the location pair, are targets for traffic restriction.

[0029] Then, the congestion determination unit 12c transmits a predetermined notification to the controller 20 in order to restrict the amount of output traffic to the relay network 50 from the transmission source subject to traffic restriction. For example, as illustrated in Fig. 4, the congestion determination unit 12c notifies the congestion occurrence point, which is the transmission destination, and the amount of output traffic to the congestion occurrence point, with the congestion flag set to 1, for each transmission source subject to traffic restriction. In the example of Fig. 4, the congestion determination unit 12c transmits a notification to the controller 20 indicating that the transmission source is "user site 1," the transmission destination is "server site 1," the output traffic amount is "50 Mbps," and the congestion flag is "1."

[0030] Then, the congestion determination unit 12c records the content of the notification to the controller 20 in the storage unit 13. Furthermore, when there are multiple transmission sources for the destination where congestion has occurred, the congestion determination unit 12c transmits the above-mentioned predetermined notification to the controller 20 as many times as the number of transmission sources.

[0031] Then, the congestion determination unit 12c determines that the traffic congestion to the destination has been resolved when a predetermined condition is met in any of the base pairs whose destination is a base that matches the congestion-occurring base included in the recorded notification content. For example, the congestion determination unit 12c determines that the traffic congestion to the destination has been resolved when the predetermined condition is met such that the value obtained by subtracting the output traffic volume from the input traffic volume is below a predetermined threshold and the output traffic in the direction of the relay network is below a predetermined limit value.

[0032] Then, when the congestion determiner 12c determines that the traffic congestion to the destination has been resolved, it transmits a predetermined notification to the controller 20. For example, as illustrated in FIG. 5, the congestion determiner 12c transmits information in which the output traffic volume is blanked and the congestion flag is changed to 0 for the destination from which the congestion has been resolved. Note that, if there are multiple destinations from which the congestion has been resolved, the congestion determiner 12c transmits multiple notifications to the controller 20. Then, the congestion determiner 12c deletes the content of the notification to the controller 20 from the storage unit 13.

[0033] When the limit setting unit 12d receives a notification from the controller 20 to limit the traffic volume as a communication device accommodating the source base, the limit setting unit 12d sets a limit value for the traffic volume included in the notification. For example, based on the notification from the controller 20, the limit setting unit 12d sets a limit value for the output traffic volume for traffic control in the relay NW output direction that matches the target source and destination when the setting flag is "1," and cancels the setting of the limit value when the setting flag is "0."

[0034] When the traffic control unit 12e receives a notification to limit the traffic volume, the traffic control unit 12e controls communication so that the output traffic volume is limited. For example, the traffic control unit 12e controls communication so that the output traffic volume is limited to the limit value set by the limit setting unit 12d.

[0035] [Controller Configuration] 6 is a block diagram illustrating the configuration of the controller of this embodiment. As illustrated in FIG. 6, the controller 20 of this embodiment includes a communication processing unit 21, a control unit 22, and a storage unit 23.

[0036] The communication processing unit 21 is realized by a NIC or the like, and controls communication via a telecommunication line such as a LAN or the Internet.

[0037] The storage unit 23 has a configuration information storage unit 23a, and stores data and programs necessary for various processes performed by the control unit 22. For example, the storage unit 23 is a semiconductor memory element such as a RAM or a flash memory, or a storage device such as a hard disk or an optical disk.

[0038] The configuration information storage unit 23a stores information that identifies a base and information that identifies the VPN GW 10 that accommodates the base, in association with each other. For example, as shown in Fig. 7, the configuration information storage unit 23a stores information that identifies a base, "base," and information that identifies the VPN GW 10 that accommodates the base, in association with each other.

[0039] The control unit 22 has an internal memory for storing programs that define various processing procedures and necessary data, and executes various processes using these. For example, the control unit 22 has a control instruction unit 22a. Here, the control unit 22 is an electronic circuit such as a CPU or MPU, or an integrated circuit such as an ASIC or FPGA.

[0040] When the control instruction unit 22a receives a notification of congestion occurrence from the VPN GW accommodating the destination site, it notifies the VPN GW accommodating the source site of a notification to limit the amount of traffic. For example, when the control instruction unit 22a receives a notification of congestion occurrence from the VPN GW 10, it refers to the information stored in the configuration information storage unit 23a and searches for a VPN GW accommodating the source site included in the notification. Explaining this using the examples of FIGS. 4 and 6, for example, when the control instruction unit 22a receives a notification from the VPN GW 10 that the congestion flag is "1," and if the source included in the notification is "user site 1," it refers to the information stored in the configuration information storage unit 23a and searches for "VPN GW1" as the accommodating VPN GW corresponding to "user site 1."

[0041] Then, the control instruction unit 22a transmits a notification to the found VPN GW 10 to limit the amount of output traffic. For example, as shown in Fig. 8, the control instruction unit 22a transmits a notification including information indicating the source and destination of the notification, and that the output traffic amount of the notification is set to a limit value and the setting flag is set to "1". Fig. 8 is a diagram showing an example of data notified from the controller to the VPN GW when congestion occurs.

[0042] Furthermore, when the control instruction unit 22a receives a notification that congestion has been resolved from the VPN GW that accommodates the destination base, it notifies the VPN GW that accommodates the source base of a notification that the traffic volume will be limited. For example, when the control instruction unit 22a receives a notification that congestion has been resolved from the VPN GW 10, it refers to the information stored in the configuration information storage unit 23a and searches for the VPN GW that accommodates the source base included in the notification.

[0043] Then, the control instruction unit 22a transmits a notification to the found VPN GW 10 to notify it of the cancellation of the limit on the output traffic volume. For example, as shown in Fig. 9, the control instruction unit 22a transmits a notification including information in which the sender, destination, and limit value of the notification are blank and the setting flag is set to "0". Fig. 9 is a diagram showing an example of data notified from the controller to the VPN GW when congestion is resolved.

[0044] Here, a series of processes will be specifically described using the example of the communication system in Fig. 1. The measurement result collector 12b of each of VPN GWs 10A to 10C collects and stores the input and output traffic volume for each base pair measured by the traffic measurement unit 12a at regular intervals (for example, every 5 seconds).

[0045] Then, at regular intervals (for example, every 5 seconds), the congestion determination unit 12c of each VPN GW 10A-10C calculates the difference between the input and output traffic volume for each site pair from the contents of the measurement result collection unit 12b. Here, assume that the input and output traffic volumes for an output traffic source of "user site 1" and destination of "server site 1" are 100 Mbps and 50 Mbps, respectively. In this case, if the difference exceeds the congestion determination threshold (10 Mbps), the congestion determination unit 12c determines that congestion has occurred.

[0046] As a result, for example, the congestion determination unit 12c of the VPN GW 10C determines that "user site 1," which is the source of the site pair determined to be congested, and "user site 2," which is the source of another site pair whose destination is "server site 1," the destination of the site pair and the site where congestion has occurred, are to be subject to traffic restriction. The congestion determination unit 12c of the VPN GW 10C also sends a notification to the controller 20 specifying the source as "user site 1," the destination as "server site 1," the output traffic volume as "50 Mbps," and the congestion flag as "1." Similarly, the congestion determination unit 12c of the VPN GW 10C also sends a notification to the controller 20 specifying the source as "user site 2," the destination as "server site 1," the output traffic volume as "30 Mbps," and the congestion flag as "1."

[0047] Then, triggered by the above notifications, the control instruction unit 22a of the controller 20 searches the configuration information storage unit 23A for the VPN GW 10A that accommodates the source "user site 1" and the VPN GW 10B that accommodates the source "user site 2" included in each notification. The control instruction unit 22a then sends a notification to the VPN GW 10A containing information that sets the source to "user site 1," the destination to "server site 1," the limit value to "20 Mbps," and the setting flag to "1." The control instruction unit 22a also sends a notification to the VPN GW 10B containing information that sets the source to "user site 2," the destination to "server site 1," the limit value to "30 Mbps," and the setting flag to "1." The limit values ​​may be determined in advance or may be determined dynamically depending on the congestion state.

[0048] After receiving this notification, limit setting unit 12d of VPN GW10A sets a limit value of 20 Mbps for traffic control unit 12e in the WAN direction through which the traffic passes, based on the information contained in this notification about the source "user site 1" and the destination "server site 1," since the setting flag is "1."

[0049] After receiving this notification, the limit setting unit 12d of VPN GW10B, because the setting flag is "1", sets a limit value of 30 Mbps for the traffic control unit 12e in the WAN direction through which the traffic passes, based on the information contained in this notification about the source "user site 2" and the destination "server site 1".

[0050] After a certain period of time has passed, the amount of output traffic from "user site 2" to "server site 1" decreases to 10 Mbps. Congestion determination unit 12c of VPN GW 10C determines that the congestion has been resolved because the difference between the amount of output traffic from "user site 2" to "server site 1" in the WAN direction and the amount in the site direction is below the congestion determination threshold and the recorded limit value.

[0051] As a result, the congestion determining unit 12c notifies the controller 20 of information that sets the source to "user site 2," the destination to "server site 1," the output traffic volume to blank, and the congestion flag to "0."

[0052] Then, the control instruction unit 22a of the controller 20 notifies information that sets the source to "user site 1," the destination to "server site 1," the output traffic volume to blank, and the congestion flag to "0." The control instruction unit 22a of the controller 20 transmits to the VPN GW 10A a notification including information that sets the source to "user site 1," the destination to "user site 1," the limit value to blank, and the setting flag to "0."

[0053] Furthermore, the control instruction unit 22a of the controller 20 sends to the VPN GW 10B a notification including information that sets the source to "user site 2," the destination to "server site 1," the limit value to blank, and the setting flag to "0." After receiving this notification, the restriction setting unit 12d of the VPN GW 10A cancels the setting of the limit value for the traffic control unit 12e for the WAN direction through which the traffic passes, based on the information of the source "user site 1" and the destination "server site 1" included in the notification, since the setting flag is "0." After receiving this notification, the restriction setting unit 12d of the VPN GW 10B cancels the setting of the limit value for the traffic control unit 12e for the WAN direction through which the traffic passes, based on the information of the source "user site 2" and the destination "server site 1" included in the notification, since the setting flag is "0."

[0054] That is, in the communication system 1, congestion may occur when the traffic volume within the VPN exceeds the line bandwidth and forwarding processing performance of the VPN GWs 10A to 10C that are allocated by contracts or the like between the VPN users at the user sites 30A and 30B and the VPN providers at the server sites 40A and 40B. For this reason, in the communication system 1, it is possible to prevent traffic that would be discarded by the VPN GWs 10A to 10C due to congestion after passing through the relay NW 50 from flowing into the relay NW 50.

[0055] [VPN GW10 processing procedure] Next, an example of the processing procedure of the processing executed by the VPN GW 10 will be described with reference to Fig. 10 and Fig. 11. Fig. 10 and Fig. 11 are flowcharts showing an example of the processing procedure by the VPN GW of this embodiment.

[0056] As illustrated in FIG. 10, the traffic measurement unit 12a of the VPN GW 10 measures the amount of input traffic input from the relay network 50 that relays communication between bases, and the amount of output traffic that outputs data input from the relay network 50 to a destination base (step S101).

[0057] The traffic measurement unit 12a collects the measured traffic volume (step S102). For example, the measurement result collection unit 12b collects the input traffic volume and the output traffic volume measured by the measurement unit 12a, and stores the collected traffic volume in the traffic storage unit 13a in association with information identifying the source base and information identifying the destination base.

[0058] Then, the congestion determination unit 12c determines whether congestion has occurred (step S103). For example, the congestion determination unit 12c determines whether the difference between the input traffic volume and the output traffic volume measured by the measurement unit 12b is equal to or greater than a predetermined threshold, and determines that congestion has occurred if the difference between the input traffic volume and the output traffic volume is equal to or greater than the predetermined threshold. As a result, if the congestion determination unit 12c determines that congestion has occurred (Yes in step S103), it proceeds to the process of step S104. On the other hand, if the congestion determination unit 12c determines that congestion has not occurred (No in step S103), it ends the process.

[0059] In step S104, the congestion determination unit 12c transmits a predetermined notification to the controller 20. For example, when the difference between the input traffic volume and the output traffic volume is equal to or greater than a predetermined threshold, the congestion determination unit 12c transmits a notification to the controller 20 including information identifying the source base stored in the traffic storage unit 13a.

[0060] Then, the congestion determination unit 12c determines whether the congestion has been resolved (step S105). For example, if the value obtained by subtracting the output traffic volume from the input traffic volume is below a predetermined threshold and the output traffic volume in the direction of the relay network is below a predetermined limit value, the congestion determination unit 12c determines that the congestion of traffic to the destination has been resolved. As a result, if the congestion determination unit 12c determines that the congestion has been resolved (Yes in step S105), the congestion determination unit 12c proceeds to the process of step S106. On the other hand, if the congestion determination unit 12c determines that the congestion has not been resolved (No in step S105), the congestion determination unit 12c repeats the process of step S105.

[0061] In step S106, the congestion determining unit 12c transmits a predetermined notification to the controller 20 (step S106). For example, the congestion determining unit 12c notifies the controller 20 of information that the output traffic volume is blanked and the congestion flag is changed to 0 for the destination from which congestion has been resolved.

[0062] As illustrated in FIG. 11, when the limit setting unit 12d of the VPN GW 10 receives a notification from the controller 20 to limit the traffic volume (Yes at step S201), the limit setting unit 12d sets a limit value for the traffic volume (step S202).

[0063] Then, when the limit setting unit 12d receives a notification from the controller 20 to the effect that the traffic limit will be lifted (Yes at step S203), the limit setting unit 12d lifts the limit value of the traffic volume (step S204).

[0064] [Effects of the embodiment] In this way, the VPN GW10 of the communication system 1 according to the embodiment measures the amount of input traffic input from the relay network 50 that relays communications between base stations, and the amount of output traffic output from the relay network 50 to the destination base station. The VPN GW10 then determines whether the difference between the measured input traffic volume and the output traffic volume is equal to or greater than a predetermined threshold, and if the difference between the input traffic volume and the output traffic volume is equal to or greater than the predetermined threshold, sends a predetermined notification to the external controller 20. When the VPN GW10 receives a notification to limit the traffic volume, it controls communication by limiting the output traffic volume. This allows the VPN GW10 to improve the accuracy of determining traffic congestion while reducing the load on the controller 20.

[0065] Here, the effects of the communication system 1 according to this embodiment will be described in comparison with the conventional technology using FIGS. 12 and 13. FIG. 12 is a diagram illustrating a problem with the conventional technology. FIG. 13 is a diagram illustrating the effects of the communication system according to the embodiment. As illustrated in FIG. 12, the controller 200 had to collect data on the relay-site direction and uplink / downlink traffic for each pair of sites. Therefore, the load on the controller 200 increases when there are many sites. Furthermore, if there is a large traffic fluctuation within the data acquisition interval, the controller 200 may experience a difference in the data acquisition time, resulting in a difference in traffic volume between the VPN GWs 100A and 100B. In this case, when the controller 200 acquires traffic from different VPN GWs 100A and 100B, a difference in acquisition time is likely to occur, and this difference may lead to an erroneous determination of congestion.

[0066] In contrast to this, in the communication system 1 according to this embodiment, the function of collecting traffic volume and performing congestion judgment is distributed to the VPN GW 10, as shown in the example of Fig. 13. Furthermore, in order to distribute the congestion judgment function to the VPN GW 10, the traffic volume that was measured at the output point to the relay NW 500 in the conventional technology is changed to the input point from the relay NW 50.

[0067] In the communication system 1 according to this embodiment, for example, when provisioning is performed so that there is no congestion within the relay NW 50, the base output traffic volume and relay input traffic volume match, and therefore traffic volume collection and congestion determination are performed within the VPN GWs 10A and 10C by substituting the relay input traffic volume for the relay output. Also, in the communication system 1, when there is a bandwidth shortage between the VPN GW and the base or when the bandwidth is tight within the VPN GWs 10A and 10C, a difference occurs between the base output traffic volume and the relay input traffic volume, and congestion is determined based on this difference.

[0068] For this reason, the communication system 1 solves the problems of the conventional technology by distributing processing in each VPN GW 10A, 10C and locally processing traffic volume collection processing and congestion determination processing. The VPN GW 10 according to this embodiment can improve the accuracy of traffic congestion determination while reducing the load on the controller 20. In other words, in the communication system 1, the function of collecting traffic volume and determining congestion is distributed to the VPN GWs 10, and the occurrence of congestion is notified from the VPN GWs 10, thereby reducing the load on the controller 20. Furthermore, because the distributed processing, traffic volume collection, and congestion determination processing in each VPN GW 10 are processed within the VPN GW 10, there is no discrepancy in acquisition time, and the possibility of erroneous determination can be reduced.

[0069] [System configuration, etc.] The components of each device shown in the drawings according to the above embodiments are conceptual functional units and do not necessarily have to be physically configured as shown. In other words, the specific form of distribution and integration of each device is not limited to that shown, and all or part of each device can be functionally or physically distributed and integrated in any unit depending on various loads, usage conditions, etc. Furthermore, all or any part of the processing functions performed by each device can be realized by a CPU and a program analyzed and executed by the CPU, or can be realized as hardware using wired logic.

[0070] Furthermore, among the processes described in the above embodiments, all or part of the processes described as being performed automatically can be performed manually, or all or part of the processes described as being performed manually can be performed automatically using a known method.In addition, the information including the processing procedures, control procedures, specific names, various data and parameters shown in the above documents and drawings can be changed as desired unless otherwise specified.

[0071] 〔program〕 It is also possible to create a program written in a computer-executable language that executes the processing performed by the VPN GW 10 or controller 20 described in the above embodiments. In this case, the same effects as those of the above embodiments can be achieved by having a computer execute the program. Furthermore, such a program can be recorded on a computer-readable recording medium, and the program recorded on this recording medium can be read and executed by a computer to achieve processing similar to that of the above embodiments.

[0072] 14 is a diagram showing a computer that executes a program. As shown in the example of FIG. 14, a computer 1000 includes, for example, a memory 1010, a CPU 1020, a hard disk drive interface 1030, a disk drive interface 1040, a serial port interface 1050, a video adapter 1060, and a network interface 1070, and these components are connected by a bus 1080.

[0073] The memory 1010 includes a ROM (Read Only Memory) 1011 and a RAM 1012, as exemplified in FIG. 14. The ROM 1011 stores a boot program such as a BIOS (Basic Input Output System). The hard disk drive interface 1030 is connected to a hard disk drive 1031, as exemplified in FIG. 14. The disk drive interface 1040 is connected to a disk drive 1041, as exemplified in FIG. 14. A removable storage medium such as a magnetic disk or an optical disk is inserted into the disk drive 1041. The serial port interface 1050 is connected to a mouse 1051 and a keyboard 1052, as exemplified in FIG. 14. The video adapter 1060 is connected to a display 1061, as exemplified in FIG. 14.

[0074] 14, the hard disk drive 1031 stores, for example, an OS 1091, an application program 1092, a program module 1093, and program data 1094. That is, the above programs are stored, for example, on the hard disk drive 1031 as program modules in which instructions to be executed by the computer 1000 are written.

[0075] The various data described in the above embodiment are stored as program data, for example, in the memory 1010 or the hard disk drive 1031. The CPU 1020 then reads the program module 1093 and the program data 1094 stored in the memory 1010 or the hard disk drive 1031 into the RAM 1012 as needed, and executes various processing procedures.

[0076] Note that the program module 1093 and program data 1094 related to the program are not limited to being stored in the hard disk drive 1031, and may be stored in, for example, a removable storage medium and read by the CPU 1020 via a disk drive or the like. Alternatively, the program module 1093 and program data 1094 related to the program may be stored in another computer connected via a network (such as a LAN (Local Area Network) or WAN (Wide Area Network)) and read by the CPU 1020 via the network interface 1070.

[0077] Although the present invention has been described above as an embodiment, the present invention is not limited to the description and drawings that form part of the disclosure of the present invention. In other words, other embodiments, examples, and operational techniques that can be made by those skilled in the art based on the present invention are all included in the scope of the present invention. [Explanation of symbols]

[0078] 10, 10A~10C VPN GW 11, 21 Communication processing unit 12, 22 Control section 12a Traffic measurement section 12b Measurement result collection section 12c Congestion determination unit 12d Restriction setting section 12e Traffic Control Section 13, 23 Storage section 13a Traffic storage section 22a Control instruction section 23a Configuration information storage unit 30A, 30B User Sites 40A, 40B server locations 50 Relay Network

Claims

1. a measuring unit that measures, at regular intervals, an input traffic volume input from a relay network that relays communications between bases and an output traffic volume that outputs data input from the relay network to a destination base; a collection unit that collects the input traffic volume and the output traffic volume measured by the measurement unit, and stores the collected traffic volume in a storage unit in association with information identifying a source location and information identifying a destination location; a determination unit that calculates a difference between the input traffic volume and the output traffic volume measured by the measurement unit at regular intervals, determines whether the difference is equal to or greater than a predetermined threshold, and, if the difference between the input traffic volume and the output traffic volume is equal to or greater than the predetermined threshold, transmits a notification to a controller that includes information identifying a source base and information identifying a destination base that are stored in the storage unit; a limit setting unit that sets a limit value for the amount of output traffic in a direction from the location indicated by the information identifying the source location to the location indicated by the information identifying the destination location, based on the information identifying the source location and the information identifying the destination location included in the notification; a traffic control unit that, when receiving a notification to limit the traffic volume, controls communication by limiting the output traffic volume to the limit value set by the limit setting unit; A communication device comprising:

2. 1. A communication method performed by a communication device, comprising: a measuring step of measuring, at regular intervals, an input traffic volume input from a relay network that relays communications between bases and an output traffic volume outputting data input from the relay network to a destination base; a collection step of collecting the input traffic volume and the output traffic volume measured by the measurement step, and storing the collected traffic volume in a storage unit in association with information identifying a source location and information identifying a destination location; a determination step of calculating a difference between the input traffic volume and the output traffic volume measured by the measuring step at regular intervals, determining whether the difference is equal to or greater than a predetermined threshold, and, if the difference between the input traffic volume and the output traffic volume is equal to or greater than the predetermined threshold, transmitting a notification to a controller including information identifying a source base and information identifying a destination base stored in the storage unit; a limit setting step of setting a limit value for the amount of traffic in a direction from the point indicated by the information identifying the source point to the point indicated by the information identifying the destination point, based on the information identifying the source point and the information identifying the destination point included in the notification; a traffic control step of controlling communication by limiting the output traffic volume to the limit value set by the limit setting step when a notification to limit the traffic volume is received; A communication method comprising:

3. a measuring step of measuring, at regular intervals, an input traffic volume input from a relay network that relays communications between bases and an output traffic volume outputting data input from the relay network to a destination base; a collecting step of collecting the input traffic volume and the output traffic volume measured by the measuring step, and storing the collected traffic volume in a storage unit in association with information identifying a source location and information identifying a destination location; a determination step of calculating a difference between the input traffic volume and the output traffic volume measured by the measurement step at regular intervals, determining whether the difference is equal to or greater than a predetermined threshold, and, if the difference between the input traffic volume and the output traffic volume is equal to or greater than the predetermined threshold, transmitting a notification to a controller including information identifying a source base and information identifying a destination base stored in the storage unit; a limit setting step of setting a limit value for the amount of traffic in a direction from the location indicated by the information identifying the source location to the location indicated by the information identifying the destination location, based on the information identifying the source location and the information identifying the destination location included in the notification; a traffic control step of controlling communication by limiting the output traffic volume to the limit value set by the limit setting step when a notification to limit the traffic volume is received; A communication program characterized by causing a computer to execute the above.

Citation Information

Patent Citations

  • Flow control method, device and network device

    CN102025640A

  • Network management system, edge node, and access device

    JP2009177783A

  • Service cooperation device, service cooperation method, and service cooperation program

    JP2013101530A