Network system and communication processing device

JP7914981B1Active Publication Date: 2026-09-03IND SECURITY PROVIDE LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2025169346
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2025-10-07
Publication Date
2026-09-03
Estimated Expiration
2045-10-07

AI Technical Summary

Benefits of technology

【0008】 本発明によれば、ネットワークシステムを構築する際の負担を軽減して、異なるVLANに属する端末装置の間で通信を行わせることができる。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007914981000001_ABST
    Figure 0007914981000001_ABST
Patent Text Reader

Abstract

The present invention provides a network system and communication processing device that reduce the burden of building a network system and enable communication between terminal devices belonging to different VLANs. [Solution] The communication processing device 3, using the forwarding control unit 14, identifies the destination terminal device 2 based on the default gateway address and forwards the communication from the source terminal device 2 to the destination terminal device 2, which belongs to a different VLAN than the VLAN to which the source terminal device 2 belongs. As a result, the communication processing device 3 can enable communication between terminal devices 2 belonging to different VLANs without having to install separate cables for each VLAN or use L3 switches.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a network system and a communication processing device. [Background Art]

[0002] In recent years, various terminal devices such as programmable logic controllers (PLCs), signal processing devices, operation monitoring terminals, data logger servers, and maintenance terminals are connected in industrial network systems, and communication is performed among these devices. In such network systems, all terminal devices are often connected to the same network segment, which has the advantage of facilitating system construction. In order to separate communication for different applications in a network system, there are methods such as physical separation with different cables, and introducing a Layer 3 switch (L3 switch) to assign different network addresses (see, for example, Patent Documents 1, 2 and 3). [Prior Art Documents] [Patent Documents]

[0003] [Patent Document 1] Japanese Unexamined Patent Publication No. 2023-88784 [Patent Document 2] Japanese Unexamined Patent Publication No. 2013-46164 [Patent Document 3] Japanese Unexamined Patent Publication No. 2015-133556 [Summary of the Invention] [Problem to be Solved by the Invention]

[0004] However, when communication is physically separated by cables in a network system, the cost of equipment and wiring increases, which imposes a heavy burden when constructing the network system. Furthermore, when an L3 switch is introduced in a network system to assign different network addresses, it is necessary to change the existing network address scheme, and furthermore, L3 switches are expensive, which also imposes a heavy burden when constructing the network system.

[0005] In view of the above problems, the present invention aims to provide a network system and a communication processing device that can reduce the burden of constructing a network system and enable communication between terminal devices belonging to different VLANs. [Means for solving the problem]

[0006] The present invention provides a network system comprising: a plurality of terminal devices to which IP addresses are assigned; a communication processing device that relays communication between the terminal devices; and a forwarding switch connected to both the terminal devices and the communication processing device, which forwards frames based on MAC addresses, wherein the communication processing device includes: a network address identification unit that recognizes a portion of the fourth octet of the destination IP address of a destination terminal device received from a source terminal device as a network identifier, and identifies the network address to which the destination IP address belongs from a plurality of network addresses that define a common network address range based on the network identifier; a default gateway address identification unit that refers to a routing table that defines the default gateway addresses of each VLAN associated with each network address, and identifies the default gateway address of the VLAN associated with the network address identified by the network address identification unit; and a forwarding control unit that identifies the destination terminal device based on the default gateway address and forwards communication from the source terminal device to the destination terminal device which belongs to a VLAN different from the VLAN to which the source terminal device belongs.

[0007] Furthermore, the communication processing device of the present invention is a communication processing device that communicates with a plurality of terminal devices via a transfer switch to which a plurality of terminal devices are connected, and comprises: a network address identification unit that recognizes a portion of the fourth octet of the destination IP address of a destination terminal device received from a source terminal device as a network identifier, and identifies the network address to which the destination IP address belongs from a plurality of network addresses that define a common network address range based on the network identifier; a default gateway address identification unit that refers to a routing table that defines the default gateway addresses of each VLAN associated with each network address, and identifies the default gateway address of the VLAN associated with the network address identified by the network address identification unit; and a transfer control unit that identifies the destination terminal device based on the default gateway address, and transfers the communication from the source terminal device to the destination terminal device that belongs to a VLAN different from the VLAN to which the source terminal device belongs. [Effects of the Invention]

[0008] According to the present invention, the burden of constructing a network system can be reduced, and communication can be performed between terminal devices belonging to different VLANs. [Brief explanation of the drawing]

[0009] [Figure 1] This is a schematic diagram showing the configuration of the network system. [Figure 2] This is a table showing the configuration of the routing table. [Modes for carrying out the invention]

[0010] Embodiments of the present invention will be described below with reference to Figure 1.

[0011] (1) Overall configuration of the network system Figure 1 is a schematic diagram showing the configuration of an industrial network system 1 according to the present invention. The network system 1 comprises a plurality of terminal devices 2, a communication processing device 3, and a transfer switch 4. The terminal devices 2 according to this embodiment include, for example, an operation monitoring terminal (OPC (OLE for Process Control) 1) 2a, another operation monitoring terminal (OPC 2) 2b, a data logger server (SVR) 2c, a maintenance terminal (Eng PC (Engineering PC)) 2d, a control device (PLC (Programmable Logic Controller)) 2e, and a signal processing device (I / O (Input / Output)) 2f. When not specifically distinguishing between the operation monitoring terminal 2a, the other operation monitoring terminal 2b, the data logger server 2c, the maintenance terminal 2d, the control device 2e, and the signal processing device 2f, they are simply referred to as terminal devices 2. Each terminal device 2 belongs to a different VLAN depending on its application.

[0012] Each terminal device 2 is assigned a unique IP address. The IP address assigned to each terminal device 2 belongs to one of several network address ranges (network addresses described later in Figure 2) defined in the industrial network system 1. In this example, the operation monitoring terminal 2a is assigned "192.168.1.33", the other operation monitoring terminal 2b is assigned "192.168.1.34", the data logger server 2c is assigned "192.168.1.49", the maintenance terminal 2d is assigned "192.168.1.65", the control device 2e is assigned "192.168.1.1", and the signal processing device 2f is assigned "192.168.1.17".

[0013] For example, the IP address "192.168.1.33" assigned to the operation monitoring terminal 2a is in IPv4 format and consists of four parts (octets) of 8 bits each, with a length of 32 bits. Specifically, the IP address "192.168.1.33" is composed of, from left to right, the first octet "192", the second octet "168", the third octet "1", and the fourth octet "33". In this embodiment, the first to third octets define a common network address range, and the upper bits of the fourth octet are used to identify VLANs (Virtual Local Area Networks) for each purpose. For example, the fourth octet "33" is represented as "0010 0001" in binary, and its upper bits (in this case, "0010") are used to identify the network identifier.

[0014] Each terminal device 2 has a MAC address unique to its network interface, and the forwarding switch 4, described later, forwards frames based on the MAC address of each terminal device 2. The forwarding switch 4 is a Layer 2 switch (L2 switch) that forwards frames based on MAC addresses and is connected to both the multiple terminal devices 2 and the communication processing device 3. The forwarding switch 4 is a device that constitutes the network based on the data link layer, which is Layer 2 of the OSI (Open Systems Interconnection) reference model. The L2 switch stores the MAC address of each terminal device 2 connected by a LAN (Local Area Network) cable, knows which terminal device 2 is connected to which port, and when it receives a frame from a terminal device 2, it refers to the destination MAC address of the frame and forwards the frame to the corresponding port.

[0015] Here, the source terminal device (source terminal device) 2 first sends an ARP request to the destination IP address of the destination terminal device (destination terminal device) 2 when communication begins. At this time, the ARP request is sent to the forwarding switch 4 as a broadcast. For example, if the operation monitoring terminal 2a is the source and the control device 2e (IP address "192.168.1.1") is the destination, the operation monitoring terminal 2a will generate an ARP request specifying that the destination IP address is "192.168.1.1", and will send the ARP request to the forwarding switch 4 as a broadcast. The ARP request will include a request for notification of the MAC address corresponding to the control device 2e at "192.168.1.1".

[0016] In this embodiment, the operation monitoring terminal 2a and the control device 2e belong to different VLANs. Since ARP requests can only reach devices belonging to the same VLAN as the communication source, the control device 2e, which belongs to a different VLAN from the operation monitoring terminal 2a, will not receive the request. Therefore, the control device 2e cannot respond to the ARP request from the operation monitoring terminal 2a.

[0017] At this time, the communication processing device 3 has a proxy ARP function and receives an ARP request from the operation monitoring terminal 2a. Here, the communication processing device 3 is the central element responsible for the logical isolation of the network and communication control in this network system 1. When the communication processing device 3 receives an ARP request from the operation monitoring terminal 2a, it sends a proxy ARP response back to the operation monitoring terminal (also called the source terminal device) 2a that sent the ARP request via the forwarding switch 4. In this way, the communication processing device 3 makes the operation monitoring terminal 2a recognize the MAC address of the communication processing device 3 itself. As a result, the operation monitoring terminal 2a recognizes that the MAC address corresponding to "192.168.1.1" is the MAC address of the communication processing device 3, and for subsequent communications to the destination control device (also called the destination terminal device) 2e, it sets the destination MAC address to the communication processing device 3 and sends the communication.

[0018] The communication processing device 3 stores the routing table T shown in FIG. 2, and upon receiving the ARP request from the operation monitoring terminal 2a described above, identifies, based on the routing table T, the VLAN corresponding to the control device 2e with which the operation monitoring terminal 2a attempts to start communication.

[0019] Here, the routing table T shown in FIG. 2 is referred to when the communication processing device 3 relays communication from the terminal devices 2. The routing table T stores, in association with each other: VLAN IDs that are identifiers for respective VLANs; network addresses assigned to the VLANs; default gateway addresses associated with the respective VLANs; information indicating the purpose of each VLAN (described as "Description (purpose)" in FIG. 2); and the maximum number of terminal devices 2 that can belong to the VLAN.

[0020] As shown in FIG. 2, 16 IP addresses can be assigned to each VLAN, and these network addresses each define a common network address range. For example, as for the network addresses, "192.168.1.0 / 28" is assigned to VLAN 11, "192.168.1.16 / 28" to VLAN 12, "192.168.1.32 / 28" to VLAN 13, "192.168.1.48 / 28" to VLAN 14, and "192.168.1.64 / 28" to VLAN 15.

[0021] Each network address defines a common network address range. For example, the network address "192.168.1.0 / 28" indicates a group of addresses in which the upper 4 bits of the fourth octet of the IP address are "0000", and a network identifier is defined by the upper 4 bits "0000". The network address "192.168.1.0 / 28" includes a range where the value of the lower 4 bits of the fourth octet changes from "0000" to "1111", that is, 16 addresses from the IP address "192.168.1.0" to "192.168.1.15".

[0022] Similarly, the network address "192.168.1.16 / 28" indicates an address group in which the upper 4 bits of the fourth octet are "0001", and includes 16 addresses from the IP address "192.168.1.16" to "192.168.1.31". In this manner, for each network address, a plurality of VLANs can be distinguished by making the network identifier different according to the value of the upper 4 bits of the fourth octet.

[0023] A default gateway address is set in association with each VLAN. For example, the default gateway addresses are assigned as follows: "192.168.1.14" for VLAN11, "192.168.1.30" for VLAN12, "192.168.1.46" for VLAN13, "192.168.1.62" for VLAN14, and "192.168.1.78" for VLAN15.

[0024] These default gateway addresses are addresses located on the upper limit side within the network address range of each VLAN, and are set such that the communication processing device 3 functions as a representative address for each VLAN. The communication processing device 3 uses these default gateway addresses to relay communication between terminal devices 2 belonging to different VLANs.

[0025] The information shown in the "Description" column of the routing table T is administrative information indicating the function or purpose of use of terminal devices 2 belonging to each VLAN, and does not directly participate in communication operations. The information indicating the purpose of VLANs defines, for example: VLAN11 is a communication section for control devices, VLAN12 is a communication section for signal processing devices, VLAN13 is a communication section for operation monitoring terminals, VLAN14 is a communication section for data logger servers, and VLAN15 is a communication section for maintenance terminals.

[0026] The number of terminals is specified as 16, which is the maximum number of terminal devices 2 that can belong to a VLAN. In this embodiment, the reason why a maximum of 16 terminal devices 2 can be assigned to each VLAN is that the upper 4 bits of the fourth octet of the IP address are used as the network identifier. That is, one VLAN is defined by the upper 4 bits, and the remaining lower 4 bits (0 to 15) become the terminal identification addresses that can be assigned to that VLAN. Therefore, each VLAN has 2 to the power of 4 (i.e., 0000 to 1111) = 16 possible addresses, and as a result, 16 terminal devices 2 can be assigned.

[0027] In the example described above, when the communication processing device 3 receives an ARP request sent from the operation monitoring terminal 2a to the forwarding switch 4, it refers to the routing table T and identifies that the destination IP address "192.168.1.1" belongs to VLAN 11. Then, the communication processing device 3 uses the default gateway address "192.168.1.14" associated with VLAN 11 to relay the communication from the source, the operation monitoring terminal 2a, to the destination, the control device 2e.

[0028] In this way, the communication processing device 3 uses the VLANs identified based on the routing table T to relay communication from the source terminal device 2 to the destination terminal device 2, thereby enabling communication between terminal devices 2 belonging to different VLANs. This allows for efficient and secure network control by separating communications by purpose using VLANs while maintaining the existing IP address scheme.

[0029] (2) Configuration of the communication processing device Next, the configuration of the communication processing unit 3 will be described. The communication processing unit 3 is composed of one or more processors such as a CPU (Central Processing Unit), and controls various circuits in the communication processing unit 3 to perform predetermined processing by executing an OS (Operating System) stored in memory (not shown), the transfer processing program of the present invention, and other applications.

[0030] The communication processing device 3 comprises a transmitting / receiving unit 10, a network address identification unit 11, a VLAN identification unit 12, a default gateway address identification unit 13, and a forwarding control unit 14. For example, when an ARP request from the operation monitoring terminal 2a to the control device 2e is broadcast to the forwarding switch 4, the transmitting / receiving unit 10 receives the ARP request from the operation monitoring terminal 2a. However, since the control device 2e, which is the communication destination, belongs to a different VLAN than the operation monitoring terminal 2a, it cannot respond to the ARP request from the operation monitoring terminal 2a.

[0031] When the transmitting / receiving unit 10 receives an ARP request from the operation monitoring terminal 2a, it uses the proxy ARP function to send the MAC address of the communication processing device 3 back to the source operation monitoring terminal 2a as a proxy ARP response via the forwarding switch 4. As a result, the MAC address of the communication processing device 3 is registered in the ARP table of the operation monitoring terminal 2a, associated with "192.168.1.1".

[0032] When the network address identification unit 11 receives an ARP request sent from the operation monitoring terminal 2a at the transmission / reception unit 10, it analyzes the destination IP address "192.168.1.1" of the communication destination control device 2e included in the ARP request and recognizes the upper bit "0000" of the fourth octet of the destination IP address ("1" (decimal) = 00000001 (binary)) as the network identifier.

[0033] The network address identification unit 11 refers to the routing table T and identifies the network address "192.168.1.0 / 28" to which the destination IP address "192.168.1.1" belongs, from among multiple network addresses, using the upper 4 bits "0000" of the fourth octet which is used as the network identifier.

[0034] The VLAN identification unit 12 identifies VLAN 11 from among multiple VLANs 11 to VLAN 15, which are associated with each network address in the routing table T, and which corresponds to the network address "192.168.1.0 / 28" identified by the network address identification unit 11. In the routing table T, VLAN 11 is defined as the VLAN to which the communication destination control device 2e belongs, and the default gateway address of VLAN 11 is defined as "192.168.1.14".

[0035] The default gateway address identification unit 13 refers to the routing table T and identifies the default gateway address "192.168.1.14" of VLAN 11, which is associated with the network address "192.168.1.0 / 28" identified by the network address identification unit 11.

[0036] The forwarding control unit 14 refers to the routing table T and identifies the destination control device 2e, which belongs to VLAN 11, a different VLAN from VLAN 13 to which the source operation monitoring terminal 2a belongs. Then, the forwarding control unit 14 uses the default gateway address "192.168.1.14" associated with VLAN 11 to forward the communication from the source operation monitoring terminal 2a to the destination control device 2e. In this way, the communication processing device 3 can establish communication between the operation monitoring terminal 2a, which belongs to VLAN 13, and the control device 2e, which belongs to a different VLAN 11.

[0037] (3) Action and Effects Based on the above, the network system 1 comprises a plurality of terminal devices 2 to which IP addresses are assigned, a communication processing device 3 that relays communication between the terminal devices 2, and a forwarding switch 4 that is connected to both the terminal devices 2 and the communication processing device 3 and forwards frames based on MAC addresses.

[0038] The communication processing device 3, using the network address identification unit 11, recognizes the upper bits of the fourth octet of the destination IP address of the receiving terminal device 2, which was received from the source terminal device 2, as a network identifier. The network address identification unit 11 identifies the network address to which the destination IP address belongs from among multiple network addresses that define a common network address range, based on the network identifier.

[0039] The communication processing device 3 stores a routing table T which defines the default gateway address of each VLAN associated with each network address. The communication processing device 3 uses a default gateway address identification unit 13 to refer to the routing table and identify the default gateway address of the VLAN associated with the network address identified by the network address identification unit 11.

[0040] The communication processing device 3, using the forwarding control unit 14, identifies the destination terminal device 2 based on the default gateway address and forwards the communication from the source terminal device 2 to the destination terminal device 2, which belongs to a different VLAN than the VLAN to which the source terminal device 2 belongs.

[0041] As a result, the communication processing device 3 can enable communication between terminal devices 2 belonging to different VLANs without having to install separate cables or use L3 switches for each VLAN. Therefore, the communication processing device 3 can reduce the burden of building the network system by eliminating the need to install separate cables or use L3 switches for each VLAN. Thus, the network system 1 can enable communication between terminal devices 2 belonging to different VLANs while reducing the burden of building the network system 1.

[0042] The communication processing device 3 can separate communications by purpose using VLANs while maintaining the existing IP address scheme of each terminal device 2, thereby achieving efficient and secure network control. Furthermore, by logically separating communications between each VLAN, interference between the communication paths of the control system, monitoring system, and maintenance system can be prevented, thereby improving the overall security and maintainability of the network system 1.

[0043] (4) Other embodiments In the embodiments described above, the case in which the upper four bits of the fourth octet of the destination IP address are used as the network identifier was explained. However, the present invention is not limited to this, and for example, the upper two bits or upper three bits of the fourth octet may be used as the network identifier, or various parts of the four octets of the destination IP address may be used as the network identifier. For example, if the upper two bits of the fourth octet of the destination IP address are used as the network identifier, four types of network identifiers can be defined; if the upper three bits are used as the network identifier, eight types of network identifiers can be defined; and if the upper four bits are used as the network identifier, sixteen types of network identifiers can be defined, enabling flexible VLAN division according to the application and the number of terminal devices 2.

[0044] In another embodiment, the forwarding control unit 14 may discard the communication from the source terminal device 2 if it cannot identify the VLAN to which the destination terminal device 2 belongs based on some bits of the fourth octet of the destination IP address. The case where the VLAN to which the destination terminal device 2 belongs cannot be identified based on some bits of the fourth octet of the destination IP address is, for example, when the network address to which the destination IP address belongs cannot be identified from the network identifier even by referring to the routing table T.

[0045] Furthermore, although the above-described embodiment described a network system 1 having one communication processing device 3, the present invention is not limited to this, and may also be a network system having multiple communication processing devices 3. In this case, if one communication processing device 3 fails, the other communication processing device 3 can take over the transfer of communication from the source terminal device 2 to the destination terminal device 2 that was being performed by the other communication processing device 3. [Explanation of Symbols]

[0046] 1 Network System 2, 2a, 2b Operation monitoring terminals 2.2c Data Logger Server 2. 2d maintenance terminal 2, 2e Control device 2, 2f Signal Processing Device 3. Communication Processing Device 10 Transmitter / Receiver 11 Network Address Identification Unit 13 Default Gateway Address Identification Section 14 Transfer Control Unit

Claims

1. A network system comprising: a plurality of terminal devices assigned IP addresses; a communication processing device that relays communication between the terminal devices; and a forwarding switch connected to both the terminal devices and the communication processing device, which forwards frames based on MAC addresses, The aforementioned communication processing device is A network address identification unit recognizes a portion of the fourth octet of the destination IP address of a destination terminal device received from a source terminal device as a network identifier, and identifies the network address to which the destination IP address belongs from among multiple network addresses that define a common network address range, based on the network identifier. A default gateway address identification unit refers to a routing table that defines the default gateway address of each VLAN associated with the aforementioned network address, and identifies the default gateway address of the VLAN associated with the network address identified by the network address identification unit, A forwarding control unit that uses the default gateway address to forward communications from the source terminal device to the destination terminal device which belongs to a VLAN different from the VLAN to which the source terminal device belongs, A network system equipped with these features.

2. The system includes a transmitting / receiving unit that receives an ARP request transmitted from the aforementioned communication source terminal device via the transfer switch and sends back a proxy ARP response to the ARP request. The network system according to claim 1.

3. If the forwarding control unit cannot identify the VLAN to which the destination terminal device belongs based on some bits of the fourth octet of the destination IP address, it discards the communication from the source terminal device. The network system according to claim 1.

4. Some bits of the fourth octet are the higher bits. The network system according to claim 1.

5. The upper two bits, upper three bits, or upper four bits of the fourth octet are used as the network identifier. The network system according to claim 4.

6. The terminal device includes at least one of the following: a control device, a signal processing device, an operation monitoring terminal, a data logger server, and a maintenance terminal. The network system according to claim 1.

7. The system has multiple communication processing devices, and if one of the communication processing devices fails, the other communication processing device takes over the transfer of communication from the source terminal device to the destination terminal device that was being performed by the other communication processing device. The network system according to claim 1.

8. A communication processing device that communicates with a terminal device via a transfer switch to which multiple terminal devices are connected, A network address identification unit recognizes a portion of the fourth octet of the destination IP address of a destination terminal device received from a source terminal device as a network identifier, and identifies the network address to which the destination IP address belongs from among multiple network addresses that define a common network address range, based on the network identifier. A default gateway address identification unit refers to a routing table that defines the default gateway address of each VLAN associated with the aforementioned network address, and identifies the default gateway address of the VLAN associated with the network address identified by the network address identification unit, A forwarding control unit that uses the default gateway address to forward communications from the source terminal device to the destination terminal device which belongs to a VLAN different from the VLAN to which the source terminal device belongs, A communication processing device equipped with the following features.

Citation Information

Patent Citations

  • Network system and network failure avoiding method

    JP2013046164A

  • Control server, control method and program

    JP2013070302A

  • Control apparatus and transfer control method

    JP2015133556A

  • Lighting control device and lighting control unit

    JP2023049374A

  • Industrial network system, network management method, and network service providing system

    JP2023088784A