Network termination device

The network termination device addresses the issue of increased traffic in ZTP systems by caching installation materials and rerouting traffic to a local cache container, effectively reducing the need for remote data transfers.

WO2026047788A1PCT designated stage Publication Date: 2026-03-05NT T INC
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2024/030153
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-08-26
Publication Date
2026-03-05

AI Technical Summary

Technical Problem

The existing zero-touch provisioning (ZTP) systems for network terminals require large-scale communication systems due to the need for a ZTP server at each location, leading to increased traffic when installation materials are transferred from a remote location.

Method used

A network termination device with a detection unit, processing unit, and monitoring unit that caches installation materials in a cache container, and changes routing settings to direct traffic to the cache container, reducing the need for direct transfers from remote locations.

Benefits of technology

Reduces the amount of traffic by locally caching installation materials and directing requests to a cache container, thereby minimizing the frequency of data retrieval from remote locations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024030153_05032026_PF_FP_ABST
    Figure JP2024030153_05032026_PF_FP_ABST
Patent Text Reader

Abstract

A VxLAN termination device (200) comprises: a detection unit (231) that detects a trigger such as a link-up of a network terminal (300); a CPU (230) in which a cache container (232) operates, the cache container having cached therein installation materials for network terminals stored in a ZTP server (110); and a monitoring unit (221) that, when the trigger is detected, starts monitoring a DHCP Offer (510) that notifies the network terminal of the address of the ZTP server. The CPU changes the routing setting on the basis of the DHCP Offer so that traffic requesting an installation material from the network terminal is directed to the cache container.
Need to check novelty before this filing date? Find Prior Art

Description

Network Termination Device

[0001] The present invention relates to a network termination device, and more particularly to a network termination device used for zero-touch provisioning of a connected network terminal.

[0002] To build flexible networks, white-box switches, which allow for the free combination of hardware and software, have been developed. In white-box switches, users can freely select the network operating system (OS). When setting up a white-box, installation materials such as OS files, licenses, and initial configurations are distributed from a Zero Touch Provisioning (ZTP) server.

[0003] The zero-touch provisioning (ZTP) function is a function that installs OS files, etc., in network devices. This ZTP function generally uses DHCP (Dynamic Host Control Protocol) to notify a network terminal of the address of a ZTP server that stores installation materials such as OS files (see Non-Patent Document 1).

[0004] When using ZTP functionality with network terminals at multiple locations, DHCP uses L2 broadcast, which requires a ZTP server at each location, resulting in a large-scale communication system. To simplify the system, however, it is possible to aggregate ZTP servers at a single location using, for example, a Virtual eXtensible Local Area Network (VxLAN).

[0005] 9, a ZTP server 110, a DHCP server 130, and a VxLAN termination device 150A are located at a predetermined location A. The VxLAN termination device 150A establishes a virtual L2 tunnel 5 on the L3 network 3 with a VxLAN termination device 150B located at another location B. A plurality of network terminals 300 are connected to the VxLAN termination device 150B.

[0006] The VxLAN termination device 150A also establishes an L2 tunnel 5 with a VxLAN termination device 150C located at location C. The VxLAN termination device 150A also establishes an L2 tunnel 5 with a VxLAN termination device 150D located at location D. A network terminal 300 is connected to the VxLAN termination devices 150C and 150D.

[0007] Here, the network terminal 300 sends DHCP Discover 500. In response, the DHCP server 130 notifies the address of the ZTP server 110 by sending DHCP Offer 510. As a result, the network terminal 300 obtains the installation materials from the ZTP server 110. Note that the number of network terminals 300 placed at each location is arbitrary. Also, the number of locations is arbitrary.

[0008] “Zero Touch Provisioning,” Cisco, [online], [Retrieved July 26, 2024], Internet <URL: https: / / www.cisco.com / c / ja_jp / td / docs / ios-xml / ios / prog / configuration / 166 / b_166_programmability_cg / b_166_programmability_cg_chapter_01.pdf>

[0009] 9 has the advantage that the ZTP servers 110 can be consolidated at a single location A that is remote from the location (e.g., location B) where the network terminal 300 is located. However, every time a network terminal 300 located at another location uses the ZTP function, the installation materials at location A are transferred one by one to the other location, which increases the amount of traffic.

[0010] The present invention has been made in view of the above-mentioned circumstances, and an object of the present invention is to reduce the amount of traffic caused by the transfer of installation materials from remote locations.

[0011] The network termination device of the present invention includes a detection unit that detects a trigger, which is any one of a notification from an operator, a link-up of a network terminal, the receipt of a specific packet, and the occurrence of a specific event; a processing unit that runs a cache container that caches installation materials for the network terminal stored in a ZTP (Zero Touch Provisioning) server; and a monitoring unit that, when the trigger is detected, starts monitoring a DHCP (Dynamic Host Control Protocol) Offer that notifies the network terminal of the address of the ZTP server, and is characterized in that the processing unit changes routing settings based on the DHCP Offer so that traffic requesting the installation materials from the network terminal is directed to the cache container.

[0012] According to the present invention, it is possible to reduce the amount of traffic caused by transferring installation materials from remote locations.

[0013] FIG. 1 is a schematic configuration diagram of a communication system including a VxLAN termination device according to a first embodiment of the present invention. FIG. 2 is a diagram showing the flow of processing in the communication system shown in FIG. 1. FIG. 3 is a diagram showing the flow of processing in the communication system shown in FIG. 3. FIG. 4 is a schematic configuration diagram of a communication system including a VxLAN termination device according to a third embodiment of the present invention. FIG. 5 is a diagram showing the flow of processing in the communication system shown in FIG. 7. FIG. 8 is a diagram showing the flow of processing in the communication system shown in FIG. 7. FIG. 9 is a schematic configuration diagram of a conventional communication system.

[0014] The VxLAN termination device according to this embodiment will be described in detail below with reference to the drawings. (Communication System) As shown in Fig. 1, in a communication system 1, a VxLAN termination device (network termination device) 200 according to the first embodiment is placed at a predetermined location B. A plurality of network terminals 300 are connected to the VxLAN termination device 200. The VxLAN termination device 200 establishes a virtual L2 tunnel 5 on an L3 network 3 between the VxLAN termination device 200 and a VxLAN termination device 150A placed at a location A different from location B.

[0015] A ZTP server 110 and a DHCP server 130 are located at location A. The ZTP server 110 stores installation materials for the network terminal 300. In response to a request from the network terminal 300, the DHCP server 130 notifies the network terminal 300 of the address of the ZTP server 110.

[0016] Although not shown in the figure, the communication system 1 also has VxLAN termination devices 200 according to this embodiment located at locations C and D other than location A. The number of network terminals 300 located at each location is arbitrary. The number of locations is also arbitrary.

[0017] First Embodiment A VxLAN termination device 200 includes a detection unit 231, a CPU (processing unit) 230, and a monitoring unit 221. The VxLAN termination device 200 also includes an ASIC (Application Specific Integrated Circuit) 220, a memory 240, and a port 250. Here, the ASIC 220 includes the monitoring unit 221, and the CPU 230 includes the detection unit 231.

[0018] The detection unit 231 detects a predetermined trigger. The trigger is any one of a notification from an operator, a link-up of the network terminal 300, the reception of a specific packet, and the occurrence of a specific event. In the following, as an example, the detection unit 231 detects, as a trigger, that the network terminal 300 is connected to the port 250 and linked up.

[0019] When the monitoring unit 221 detects a trigger, it starts monitoring the DHCP Offer 510. The DHCP Offer 510 is a message that notifies the network terminal 300 of the address of the ZTP server 110. The CPU 230 runs a cache container 232. The cache container 232 caches installation materials for the network terminal 300 that are accumulated in the ZTP server 110. The cache container 232 holds the installation materials for the network terminal 300 in advance. For example, before supporting the target network terminal 300, the cache container 232 can cache installation materials when supporting ZTP for another network terminal 300. If the cache container 232 does not hold the installation materials required for the target network terminal 300, it can request the relevant installation materials from the ZTP server 110.

[0020] Based on the DHCP Offer 510, the CPU 230 changes the routing settings so that traffic requesting installation materials from the network terminal 300 is directed to the cache container 232. In this embodiment, the CPU 230 activates the cache container 232 when a trigger is detected. The CPU 230 includes a rewriting unit 233. The rewriting unit 233 rewrites the address of the DHCP Offer 510 to the address of the cache container 232.

[0021] The monitoring unit 221 has a DHCP snooping function. The DHCP snooping function is a function for snooping (peeking at) DHCP messages. When the monitoring unit 221 snoops the DHCP Offer 510, it notifies the rewriting unit 233 of the contents of the DHCP Offer 510. When the rewriting unit 233 receives a notification from the monitoring unit 221, it rewrites the contents of the message and passes the rewritten message (DHCP Offer 520) to the monitoring unit 221. The monitoring unit 221 passes the message (DHCP Offer 520) obtained from the rewriting unit 233 to the network terminal 300, rather than the snooped DHCP Offer 510. In FIG. 1, DHCP Offer 520 indicates that the address in DHCP Offer 510 has been rewritten to the address of cache container 232 .

[0022] Next, the operation of the VxLAN termination device 200 in the communication system 1 will be described with reference to FIG. 2 (and also with reference to FIG. 1 as appropriate). First, the network terminal 300 links up (step S11). As a result, in the VxLAN termination device 200, the detection unit 231 detects a trigger (step S13), and the monitoring unit 221 starts monitoring DHCP (step S15). Furthermore, when the CPU 230 detects the trigger, it starts the cache container 232 (step S17).

[0023] Then, the network terminal 300 broadcasts DHCP Discover 500 (step S19). As a result, the DHCP server 130 transmits DHCP Offer 510 (step S21). Meanwhile, in the VxLAN termination device 200, the monitoring unit 221 snoops the DHCP Offer 510 (step S23). Then, the rewriting unit 233 of the VxLAN termination device 200 rewrites the address of the DHCP Offer 510 (step S25). That is, the rewriting unit 233 rewrites the address of the ZTP server written in the DHCP Offer 510 and steers it to the cache container 232.

[0024] Then, the network terminal 300 receives the DHCP Offer 520 (the message rewritten by the rewriting unit 233) (step S27). Subsequently, the network terminal 300 sends a message requesting installation materials (hereinafter simply referred to as materials) to the address of the cache container 232 (step S29).

[0025] Then, the cache container 232 of the VxLAN termination device 200 determines whether or not it holds the material (step S31). If the cache container 232 holds the material (step S31: Yes), it transmits the material to the network terminal 300 (step S33). As a result, the network terminal 300 acquires the material (step S35). In Fig. 1, OS File 530 indicates the material acquired by the network terminal 300.

[0026] On the other hand, if the cache container 232 does not hold the relevant material (step S31: No), it requests the material from the ZTP server 110 (step S37). Then, the ZTP server 110 sends the material to the cache container 232 (step S39), and the cache container 232 transfers the material to the network terminal 300 (step S41). As a result, the network terminal 300 acquires the material (step S35). Note that if the VxLAN termination device 200 has not detected an event for a certain period of time, it can stop the cache container 232 and snoop function to reduce the CPU load.

[0027] Second Embodiment Next, a VxLAN termination device 200B according to a second embodiment will be described with reference to Fig. 3. Note that the same components as those in the first embodiment are denoted by the same reference numerals, and the description thereof will be omitted. As shown in Fig. 3, in a communication system 1B, a VxLAN termination device 200B according to the second embodiment is disposed in location B.

[0028] The VxLAN termination device 200B includes a detection unit 231, a CPU 230B, and a monitoring unit 221. The VxLAN termination device 200B also includes an ASIC 220, a memory 240, and a port 250. Here, the ASIC 220 includes the monitoring unit 221, and the CPU 230B includes the detection unit 231.

[0029] In the second embodiment, the CPU 230B activates the cache container 232 when a trigger is detected. However, the CPU 230B includes an ACL rewriting unit (setting rewriting unit) 235 instead of the rewriting unit 233 (see FIG. 1). The ACL rewriting unit 235 changes the access permission settings recorded in the memory 240 so that traffic is directed to the cache container 232. The memory 240 stores an ACL (Access Control List) 540. The ACL 540 is provided separately from the routing table and corresponds to a policy table.

[0030] When the monitoring unit 221 snoops the DHCP Offer 510, it notifies the ACL rewriting unit 235 of the contents of the DHCP Offer 510. When the ACL rewriting unit 235 receives a notification from the monitoring unit 221, it controls network access by rewriting the ACL 540 to a setting that permits only packets addressed to the IP address of the cache container 232. Note that the ACL rewriting unit 235 can restore the ACL 540 to its original setting when it confirms, for example, that the target network terminal 300 has requested installation materials from the cache container 232.

[0031] Next, the operation of the VxLAN termination device 200B in the communication system 1B will be described with reference to Fig. 4 (and Fig. 3 as appropriate). Note that the same processes as those in Fig. 2 are denoted by the same reference numerals and their description will be omitted. The processes from step S11 to step S23 shown in Fig. 4 are the same as the processes from step S11 to step S23 shown in Fig. 2.

[0032] In the VxLAN termination device 200B, when the monitoring unit 221 snoops the DHCP Offer 510 (step S23), the ACL rewriting unit 235 rewrites the ACL 540 (step S26). Then, the network terminal 300 receives the DHCP Offer 510 (step S28). Note that the DHCP Offer 510 received by the network terminal 300 is the same as the message sent by the DHCP server 130.

[0033] The processing from step S29 to step S41 shown in Fig. 4 is the same as the processing from step S29 to step S41 shown in Fig. 2. When the VxLAN termination device 200B does not detect an event for a certain period of time, it can stop the cache container 232 and the ACL rewriting unit 235 to reduce the CPU load.

[0034] Third Embodiment Next, a VxLAN termination device 200C according to a third embodiment will be described with reference to Fig. 5. Note that the same components as those in the first embodiment are denoted by the same reference numerals, and the description thereof will be omitted. As shown in Fig. 5, in a communication system 1C, the VxLAN termination device 200C according to the third embodiment is disposed in location B.

[0035] The VxLAN termination device 200C includes a detection unit 231, a CPU 230C, and a monitoring unit 221. The VxLAN termination device 200C also includes an ASIC 220, a memory 240, and a port 250. Here, the ASIC 220 includes the monitoring unit 221, and the CPU 230C includes the detection unit 231.

[0036] In the third embodiment, the CPU 230C constantly operates the cache container 237. The cache container 237 is a ZTP container having a DHCP relay function and a cache function. The DHCP relay function is a function that receives a DHCP Offer 510 sent from the DHCP server 130 and forwards the DHCP Offer 510 to the destination.

[0037] Next, the operation of the VxLAN termination device 200C in the communication system 1C will be described with reference to Fig. 6 (and Fig. 5 as appropriate). Note that the same processes as those in Fig. 2 are denoted by the same reference numerals and their description will be omitted. The processes from step S11 to step S15 shown in Fig. 6 are the same as the processes from step S11 to step S15 shown in Fig. 2.

[0038] In the VxLAN termination device 200C, the cache container 237 is always running regardless of triggers. Then, the network terminal 300 broadcasts a DHCP Discover 500 (step S19). This causes the DHCP server 130 to transmit a DHCP Offer 510 (step S21). Meanwhile, in the VxLAN termination device 200C, the cache container 237 relays the DHCP Offer 510 (step S22). The monitoring unit 221 snoops the DHCP Offer 510 sent from the cache container 237 to the network terminal 300 (step S23).

[0039] The processing from step S25 to step S41 shown in FIG. 6 is the same as the processing from step S25 to step S41 shown in FIG. 2, if the cache container 232 is replaced with the cache container 237.

[0040] (Fourth Embodiment) Next, a VxLAN termination device 200D according to a fourth embodiment will be described with reference to Fig. 7. Note that the same components as those in the third embodiment are denoted by the same reference numerals, and description thereof will be omitted. As shown in Fig. 7, in a communication system 1D, a VxLAN termination device 200D according to the fourth embodiment is disposed in location B.

[0041] The VxLAN termination device 200D includes a detection unit 231, a CPU 230D, and a monitoring unit 221. The VxLAN termination device 200D also includes an ASIC 220, a memory 240, and a port 250. Here, the ASIC 220 includes the monitoring unit 221, and the CPU 230D includes the detection unit 231.

[0042] In the fourth embodiment, the CPU 230D can, for example, constantly operate the cache container 239. The cache container 239 is a ZTP container that has a role of assisting the ZTP server 110 in location A. The cache container 239 obtains information such as the assigned IP address required for the DHCP Offer 510 (hereinafter referred to as information for DHCP) from the ZTP server 110 in advance.

[0043] The cache container 239 receives DHCP Discover 500 and replies with DHCP Offer 510 on behalf of the ZTP server 110. The cache container 239 replies to a material request from the network terminal 300 on behalf of the ZTP server 110, and if the material data is not available, it queries the ZTP server 110. The cache container 239 appropriately synchronizes with the ZTP server 110 to update the data.

[0044] Next, the operation of the VxLAN termination device 200D in the communication system 1D will be described with reference to FIG. 8 (and also with reference to FIG. 7 as appropriate). Note that the same processes as those in FIG. 6 are denoted by the same reference numerals, and their description will be omitted. In the VxLAN termination device 200D, the cache container 239 operates constantly, regardless of triggers, for example. For example, in response to a request from the cache container 239, the DHCP server 130 transmits DHCP information to the cache container 239 (step S1). As a result, in the VxLAN termination device 200D, the cache container 239 acquires the DHCP information (step S3).

[0045] The processing from step S11 to step S15 shown in Fig. 8 is the same as the processing from step S11 to step S15 shown in Fig. 6. Then, the network terminal 300 broadcasts DHCP Discover 500 (step S19). As a result, the cache container 239 receives DHCP Discover 500 and replies with DHCP Offer 510 (step S20).

[0046] The processing from step S23 to step S41 shown in FIG. 8 is the same as the processing from step S23 to step S41 shown in FIG. 6, if the cache container 237 is replaced with the cache container 239.

[0047] In the VxLAN termination device 200D, the cache container 239 can be temporarily operated in response to event detection instead of constantly operating. For example, in the VxLAN termination device 200D, when the detection unit 231 detects a trigger (step S13), the cache container 239 can be started. In this case, if the VxLAN termination device 200D does not detect an event for a certain period of time, it can stop the cache container 239 and the snoop function to reduce the CPU load.

[0048] [Effects] As described above, the VxLAN termination device 200 includes a detection unit 231 that detects a trigger, which is any one of a notification from an operator, a link-up of the network terminal 300, the reception of a specific packet, and the occurrence of a specific event; a CPU 230 that runs a cache container 232 that caches installation materials for the network terminal 300 that are accumulated in the ZTP (Zero Touch Provisioning) server 110; and a monitoring unit 221 that, upon detecting a trigger, starts monitoring a DHCP (Dynamic Host Control Protocol) Offer that notifies the network terminal 300 of the address of the ZTP server 110. The CPU 230 is characterized in that it changes routing settings based on the DHCP Offer 510 so that traffic requesting installation materials from the network terminal 300 is directed to the cache container 232.

[0049] In this way, the VxLAN termination device 200 stores the installation materials for the connected network terminal 300 in the cache container 232. If the data of the installation materials required by the network terminal 300 is not stored locally, the VxLAN termination device 200 can request the data from the ZTP server 110 located at another location. Therefore, the VxLAN termination device 200 can reduce the frequency of retrieving data from a remote location. As a result, the VxLAN termination device 200 can reduce the amount of traffic caused by transferring installation materials from a remote location. Furthermore, if network terminals 300 are deployed at multiple bases and the ZTP servers 110 are aggregated at remote locations, deploying a VxLAN termination device 200 at each base allows the network terminal 300 to receive the installation materials from the cache container deployed at each base.

[0050] In the VxLAN termination device 200 , the CPU 230 is characterized by including a rewriting unit 233 that rewrites the address in the DHCP Offer 510 to the address of the cache container 232 .

[0051] By doing this, the VxLAN termination device 200 sends to the network terminal 300 a DHCP Offer 520 in which the address in the DHCP Offer 510 has been rewritten to the address of the cache container 232. As a result, the network terminal 300 requests the installation materials with the address of the cache container 232 as the destination. Therefore, it is possible to change the routing settings so that traffic requesting the installation materials from the network terminal 300 is reliably directed to the cache container 232.

[0052] In the VxLAN termination device 200B, the CPU 230B is characterized by including an ACL rewriting unit 235 that changes the access permission setting recorded in the memory 240 so that traffic is directed to the cache container 232.

[0053] In this way, the VxLAN termination device 200B can rewrite the ACL 540 when it recognizes the arrival of the DHCP Offer 510, thereby directing packets requesting installation materials to the cache container 232. Therefore, it is possible to change the routing settings so that traffic requesting installation materials from the network terminal 300 is reliably directed to the cache container 232.

[0054] In the VxLAN termination device 200, the CPU 230 activates the cache container 232 when a trigger is detected.

[0055] By doing this, the VxLAN termination device 200 temporarily operates the cache container 232 that holds the installation materials for the network terminal 300, thereby reducing the CPU load compared to when the cache container 232 is operated constantly.

[0056] It should be noted that the present invention is not limited to the above-described embodiments, and many modifications can be made by a person skilled in the art within the technical spirit of the present invention. For example, the trigger is not limited to a link-up of a network terminal, but may be based on a notification from an operator, detection of a specific packet, or detection of a specific event.

[0057] 1, 1B, 1C, 1D Communication system 110 ZTP server 130 DHCP server 150A, 150B, 150C, 150D VxLAN termination device 200, 200B, 200C, 200D VxLAN termination device (network termination device) 220 ASIC 221 Monitoring unit 230, 230B, 230C, 230D CPU (processing unit) 231 Detection unit 232, 237, 239 Cache container 233 Rewriting unit 235 ACL rewriting unit (setting rewriting unit) 240 Memory 300 Network terminal 510, 520 DHCP Offer 540 ACL

Claims

1. A network termination device comprising: a detection unit that detects a trigger, which is any one of a notification from an operator, a link-up of a network terminal, the receipt of a specific packet, and the occurrence of a specific event; a processing unit that operates a cache container that caches installation materials for the network terminal stored in a ZTP (Zero Touch Provisioning) server; and a monitoring unit that, when the trigger is detected, begins monitoring a DHCP (Dynamic Host Control Protocol) Offer that notifies the network terminal of the address of the ZTP server, wherein the processing unit changes routing settings based on the DHCP Offer so that traffic requesting the installation materials from the network terminal is directed to the cache container.

2. The network termination device according to claim 1, wherein the processing unit includes a rewriting unit that rewrites the address in the DHCP Offer to the address of the cache container.

3. The network termination device according to claim 1, characterized in that the processing unit is provided with a setting rewriting unit that changes the access permission setting recorded in memory so that the traffic is directed to the cache container.

4. The network termination device according to claim 2 or 3, wherein the processing unit activates the cache container when the trigger is detected.

Citation Information

Patent Citations

  • Service provisioning method, device and system in coaxial cable system

    EP2879329A1

  • Proxy distribution device, content distribution system, content distribution method, and content distribution program

    JP2014239322A

  • Communication device, communication system, test method, and program

    JP2023129689A

  • Utilizing a Gateway for the Assignment of Internet Protocol Addresses to Client Devices in a Shared Subset

    US20120011230A1

  • Constructing and operating high-performance unified compute infrastructure across geo-distributed datacenters

    US20150317169A1