A virtual connection is an agreement to transfer data between two or more entities according to certain procedures. With connection-oriented packet switching, virtual connections are established for particular traffic flows prior to transferring data. Establishing a virtual connection usually entails setting up the route along which the traffic will flow and establishing parameters, such as virtual connection identifiers, along this route.
The equivalence of connection-oriented packet switching may be equivalent with circuit switching in the sense that connection-oriented packet switching may provide a quality of service that is comparable to the quality of services provided by circuit switching. Fast circuit switching and connection-oriented packet switching may be implemented in the same network using common network elements. U.S. Pat. No. 7,149,210 discloses network operation based on fast circuit switching. Network operation based on connection-oriented packet switching is discussed herein.
There are a number of conditions that need to be met for connection-oriented packet switching to be comparable or generally equivalent to circuit switching. These conditions depend on the specific application. The key condition is that delays though the packet switching network must not significantly impact the application.
A typical communications network may comprise access networks, which connect users to network nodes, and a backbone network interconnecting the nodes. In the case of telephone networks, the network nodes are referred to as central offices, or COs, and the backbone network is referred to as the interoffice network. Referring to
Access networks may connect customers to an interoffice network and carry customer traffic to and from the network. From an interoffice network perspective, access networks may be viewed as data sources and sinks. Since the early days of telephone networks, access has been provided by running twisted pairs of copper wire from the customer premises to the COs supporting subscriber connections, which are referred to as serving wire centers (SWCs). Even today most access lines are twisted pairs. The capacity of twisted pair access line has been greatly enhanced through the use of digital subscriber line (DSL) techniques. Subscribers can also access the network via coaxial cable, or fiber optic lines, or by wireless, commonly radio, links.
Typically, network nodes may be interconnected by fiber optic cables which can support very high data rates via a hierarchy of data channels. Different fibers within a cable separate signals spatially and may be viewed as space channels. Multiple signals at different wavelengths may be transported within a fiber so that each space channel may be viewed as containing multiple wavelength channels. Similarly, the signals at each wavelength can be divided into multiple repetitive time intervals, which may be viewed as time slot channels.
The Synchronous Optical Network (SONET) and the Synchronous Digital Hierarchy (SDH) standards define frame structures and data rates for the time-slotted signals used in an embodiment of the network. SONET/SDH frames have a repetition interval of 125 microseconds and data rates that are multiples of 51.84 Mb/s, the fundamental SONET data rate. The fundamental SONET frame, the Synchronous Transport Signal (STS-1), has a payload that contains approximately 800 bytes and supports a data rate of approximately 50 Mb/s. Each byte within the payload can be viewed as corresponding to a digital signal level 0 channel, referred to as DS0. This may support a data rate of 64 Kb/s. Higher order SONET frames may be formed by byte interleaving of fundamental frames. For example, STS-3 frame, which is equivalent to the fundamental SDH frame, may be formed by byte interleaving of three STS-1 frames. Higher order SONET/SDH frames are equivalent to a large number of DS0 time slots.
Referring to
Control signals are used to establish physical and virtual connections. These include end-to-end connections between users, connections between end users and the network, and connections between network elements. Typically, a physical connection would support multiple virtual connections.
Network users include clients, the consumers of communication services, and servers, the providers of communication services. Although clients can communicate with clients and servers with servers, most of the communications is assumed to be between clients and servers, and most of the data is assumed to flow downstream from servers to clients. Although clients can communicate with clients and servers with servers, most of the communications may generally be between clients and servers, and most of the data may generally flow downstream from servers to clients.
With the approach shown in
Traffic from multiple users 304 is multiplexed at SWC 310 and sent on to label switch 312 over a common physical connection. Similarly, traffic from packet switch 312 is demultiplexed at SWC 310 and sent to users over separate access lines.
Multi-Protocol Label Switching (MPLS) is a connection-oriented technique that may be used to provide guaranteed quality of service for IP traffic (and other types of traffic). With the IP/MPLS approach, virtual connections called label switched paths (LSPs) are established, and labels are attached to IP packets to identify particular LSPs. Forwarding of a packet is based on the 20 bit label in the MPLS header rather than on the 32 bit IP address (for IP version 4) in the IP header, which makes forwarding easier to implement. With MPLS, network capacity can be reserved along the LSP so that the quality of service for a traffic flow can be guaranteed.
A consensus is forming around IP data and MPLS transport. Thus, the preferred embodiment of the integrated network is based on IP and MPLS. Data associated with various applications, including voice and video, would be encapsulated in IP packets. LSPs would be established, and MPLS headers would be attached to IP packets and used to transport data along LSPs.
Control signaling for establishing and managing physical and virtual connections may be based on Generalized MPLS (GMPLS) standards. The network elements (or sub-elements) involved with control signaling and the set of network channels containing the control signals are collectively referred to as the control plane, specifically for the preferred embodiment, the GMPLS control plane.
MPLS labels can be stacked, and multiple LSPs can be nested in a higher level LSP. The signaling protocols can be used to control the network capacity assigned to an LSP containing multiple virtual connections. This gets us back to common channel signaling, with the control signaling separate from the data transport and with a signaling connection able to control multiple data connections, in this case virtual connections.
As shown in
At server premises 404, a physical layer interface 422 may be SONET over fiber 424 to multilplexer 428. The Generic Framing Procedure (GFP) 426 provides layer 2 functions associated with packet framing, i.e., determining where packets begin and end. MPLS 416 supports the end-to-end virtual connections with multiple clients. Again, IP 418, UDP 420, and the application protocol 421 run over MPLS 416.
Multiplexer 410 may statistically multiplex and demultiplex IP data from and to multiple users 402. Multiplexers 410 may operate at layer 2 of the OSI model, using Ethernet 414 or some other layer 2 protocol. Routers 430 and 432 may operate at the MPLS layer, which can be viewed as lying between layers 2 and 3. Labeled packets may be forwarded without reading the IP header. To accommodate legacy equipment and networks, router 428/430 needs to be able to accommodate unlabeled packets. If the MPLS label is missing, router 428/43 processes the packet using current IP transport procedures.
For labeled packets, IP 418 runs on top of MPLS 416 and is not used by the network. Similarly, TCP and the application protocol run on top of IP 418. For streaming applications, the User Datagram Protocol 420 (UDP) would normally be used instead of TCP.
The protocols of
Where applicable, the signaling protocols listed above may be used to support a guaranteed quality of service. However, these protocols are exemplary, and are not intended to be limiting. Generally, control signaling functions are needed, which are not included in these protocols. Thus, extensions of these protocols or additional signaling are required. The real the issue is not which protocols are used, but how signaling is used in conjunction with label switching to enable a quality of service comparable to quality of service provided by circuit switching.
The heart of network 100 (described above) is a generic switch 500, which is illustrated by
Signals are switched in both space and time. Each of the input lines (or space channels) is broken up into time intervals (or time channels). If an input signal contains multiple carrier frequencies or wavelengths, the signal would be converted to signals on multiple lines prior to switching. Thus, a single fiber containing multiple channels may be equivalent to multiple fibers each containing a single wavelength channel. The generic switch maps space-time channels at its input onto space time channels at its output.
Generic switch 500 in
Switch 500 of
Each ISDN time slot contains one byte of data. The ISDN frame containing the time slots is repeated 8000 per second. The generic switch maps time-space cells at input 600 onto time-space cells at output 602. The switching matrix contains 8 times 23 elements, with each element identifying the output line that is the destination of the data contained in a particular time slot on a particular input line. The
Data on each of the N input lines 604 of (
With circuit switching operation, the time slot interchange and space switching functions within the generic switch may be controlled via the control plane based on information provided in the signaling channels. The controller may monitor the signaling channels and may determine the switching pattern for mapping input space-time channels onto output space-time channels. This pattern may include time slot interchange parameters for all input and output lines and space switching parameters for all time slots. The time slots may be viewed as implicit labels that identify particular data flows associated with the data within the time slots. With circuit switching, the switching pattern is predetermined for each connection through the switch. The switching pattern is modified whenever a connection is established or released or when the number of channels assigned to a connection is varied. The controller would send updated interchange and switching parameters to the buffers and the space switch, respectively, whenever the switching pattern is modified. This modification of the switching pattern may be viewed as dynamically changing the implicit labels associated with the time slots.
Packet switching operation of the generic switch may be similar, but is generally more complex. As with circuit switching operation, time slot interchange and space switching patterns are determined by the controller. Unlike the circuit switching case, the switching pattern is not predetermined for packet switching operation. Instead the switching pattern must be determined on-the-fly based on explicit labels contained in the packet headers. The controller must read the header of each packet entering the switch. If the header indicates that the packet is part of an existing data flow, the routing through the network is generally already determined and the output line is generally available in an existing table. Otherwise, the routing of the packet will have to be determined by the routing algorithm, which may involve the exchange of control messages with other switches. Once the output line for the packet is determined, the controller must determine when the packet should be read out of the input and output buffers. Also, the packet header may need to be modified as the packet passes through the switch. The on-the-fly processing described above make the latency and throughput requirements on the controller considerably more stringent for packet switching compared to the corresponding requirements for circuit switching.
With circuit switching, network capacity is dedicated to a particular connection and the quality of service (QoS) can be guaranteed. With connection-oriented packet switching, it is possible to provide a guaranteed QoS for a particular data flow, by reserving a sufficient amount of network capacity for the virtual connections supporting the particular data flow. This is sometimes referred to as circuit emulation. One issue is how to ensure that sufficient capacity is allocated to particular data without wasting network capacity.
Ensuring a guaranteed QoS is closely tied to control signaling. For the embodiment of the network previously described, the operation that would provide a guaranteed QoS for a particular data flow may proceed as follows.
End-to-end virtual connections (LSPs) may be established between the end users with at least one LSP for the data flow in each direction.
The data flow may be monitored at its source to determine the data rate and to estimate changes in the data rate before they occur. The source may request that sufficient capacity to accommodate the required data rate be assigned to an LSP in advance of when the capacity is required. The network may allocate capacity in advance along the LSP for a certain time interval such that this capacity may be sufficient to accommodate the data flow. The time interval may be adjusted based on the latency, e.g. delay, of the application associated with the data flow. Capacity may be requested and allocated only as required to accommodate the actual data flow.
A simplified packet switching network 700 shown in
For the network of
Allocating a capacity sufficient to accommodate the total amount of data generated by the source over the time interval ensures that all the data from the particular source can be transferred within the time interval. It also ensures that the maximum delay is less than the time interval. This situation illustrated by
The situation would be more complex if the data traverses more than two packet switching elements. However, the basic concept remains the same. For a more complex network with multiple packet switching elements, each packet switching element along the LSP may act as a data source and may request that capacity be allocated for the link to the next packet switch along the LSP. Sufficient network capacity may need to be provided along all the links of the LSP. For successive links along the LSP, the time interval would need to be offset by some small amount to allow for the link propagation delays and fixed delays through the packet switching elements. Thus, the maximum delay could be greater than the time interval. However in most cases, a guaranteed QoS may be supported for a packet switching network with multiple packet switching elements if the time interval is small enough and if sufficient capacity is allocated along the LSP.
In summary, the approach described above involves allocating to a particular traffic flow a certain amount of network capacity over a certain time interval. This allows a guaranteed quality of services to be provided for the particular traffic flow and distinguishes this invention from the prior art.
IP global addresses cause vulnerabilities that can be exploited by certain threats.
Even if the data is encrypted, an intruder may determine traffic patterns and may direct certain attacks against particular sites. Encryption of IP headers may counteract these threats, but complicate transport and may limit interoperability.
If switching/forwarding is based on MPLS labels rather IP addresses, IP headers become superfluous for transport though the network. Thus, for labeled packets, the IP headers (and possibly TCP and UDP headers) may be stripped off at the sending end and re-inserted at the receiving end. Note that an MPLS header identifies an LSP, which in turn can be associated with the route traversed the packets, including the source and destination of the packets.
For unlabeled packets, IP headers 902 may be used in the label switches, and possibly the multiplexers, to determine where to route the packets. Thus, IP headers 902 need to be retained for unlabeled packets. Also, IP headers 902 need to be re-inserted as the data enters a network segment that does not have MPLS capabilities. Re-insertion of the IP headers as the packets leave the network (or network segment) allows the network to maintain compatibility with user equipment and legacy networks.
Removing IP headers 902 (and other headers) may reduce the overhead and improve transport efficiency, which is significant for voice applications over low capacity access lines.
Security could be enhanced by suppressing IP headers 902. MPLS headers 910 have only local significance. If the control channels are secure, then an intruder would not be able determine the source and destination of a packet from MPLS headers 910. Thus, stripping IP headers 902 prevents an intruder from performing a traffic analysis and complicates a denial-of-service attack. Removal of IP headers 902 may enhance security even if the data is not encrypted. However, for sensitive data that needs protection, end-to-end encryption should be employed.
Security must be provided for the control plane so that connections can be securely established and channel capacity can be securely allocated. Controls signals between network elements and between users and network elements may be encrypted using IPSec or other well established techniques. Also, network elements may police user requests to guard against improper requests for connections or network capacity. It is easier to provide security for the control plane than for end-to-end data flows. Data rates are generally much lower for the control plane, and latency requirements are less stringent. This implies that optimizing control plane traffic flows is less important than optimizing end-to-end data flows between users.
The suppression of IP headers 902 to achieve greater transport efficiency and enhanced security clearly distinguishes this invention from the prior art.
This application claims the benefit under 35 U.S.C. 119 (e) of U.S. Provisional Patent Application No. 60/799,701, filed May 11, 2006 by Kevin A. DeMartino for “Equivalence of Fast Circuit Switching and Connection-Oriented Packet Switching,” which patent application is hereby incorporated herein by reference.
| Number | Date | Country | |
|---|---|---|---|
| 60799701 | May 2006 | US |