Control Plane Chain Booting for Network Element Software Upgrades

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing method of upgrading or downgrading software images in network elements requires rebooting, leading to prolonged downtime and interruptions in network services, as the network element is inoperable for up to five minutes during the process.

Innovation Solution

A method that updates the software image by chain booting the control plane to the new image without restarting the hardware forwarding engines, and optionally prefilling queues with keep-alive messages or reprogramming hardware tables, allowing for minimal disruption to network processing functions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the network element is rebooted to update the software image, then the software image is updated successfully, but the network element is inoperable for a relatively long time (up to five minutes)

Engineering Contradiction:
Improvesoftware image updateVSAvoidnetwork element downtime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The network element is divided into separate functional planes: control plane and data plane. The control plane is updated independently while the data plane remains operational, allowing software image updates without complete system reboot. This segmentation enables the control plane to be updated while data forwarding continues uninterrupted in the data plane.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The new software image is loaded into the control plane memory before the update is activated. The control plane is then chain-booted to the new software image, and only after successful loading are the hardware forwarding engines restarted and reprogrammed. This preliminary loading ensures the update is ready before switching, minimizing operational disruption.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the network element is rebooted to update the software image, then the software image is updated successfully, but network services are interrupted

Engineering Contradiction:
Improvesoftware image updateVSAvoidnetwork service continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The network element is divided into separate functional planes: control plane and data plane. The control plane is updated independently while the data plane remains operational, allowing software image updates without complete system reboot. This segmentation enables the control plane to be updated while data forwarding continues uninterrupted in the data plane.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The data plane maintains continuous network traffic forwarding operations throughout the control plane update process. Hardware forwarding engines continue to process and forward packets based on existing forwarding tables while the control plane is updated. This ensures uninterrupted network service delivery despite the software image update.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If the hardware forwarding engines are restarted to update the software image, then the new software image is applied, but data processing functions are inoperable during the process

Engineering Contradiction:
Improvesoftware image updateVSAvoiddata processing interruption
Core Design Contradiction:
ReliabilityVSDuration of action of moving object

Solution Approach 1:

The new software image is loaded into the control plane memory before the update is activated. The control plane is then chain-booted to the new software image, and only after successful loading are the hardware forwarding engines restarted and reprogrammed. This preliminary loading ensures the update is ready before switching, minimizing operational disruption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system transitions dynamically between software versions in the control plane while maintaining operational data plane functionality. The hardware forwarding engines can be updated individually or in groups, allowing gradual transition rather than simultaneous restart of all components, thereby reducing the duration of data processing interruptions.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10789059B2System and method for accelerated software upgrades
Publication Date: 2020.09.29 ARISTA NETWORKS INC
  • US10789059B2 patent drawing
  • US10789059B2 patent drawing
  • US10789059B2 patent drawing

AI summary

A method and apparatus of a device that updates a software image for a network element is described. In an exemplary embodiment, a device receives a signal to update the network element with the new software image, where the network element includes a plurality of hardware forwarding engines and a control plane. The device further boots the control plane with the new software image, where the booting is accomplished without restarting the control plane. In one embodiment, the device boots the control plane by chain booting from a current software image to the new software image. The device additionally restarts and reconfigures the plurality of hardware forwarding engines. In a further embodiment, the device additionally prefills one or more queues in the hardware forwarding engines with keep-alive messages. These keep-alive messages are transmitted during the time that the control plane is being restarted. In a further embodiment, the hardware forwarding engines are reconfigured without restarting them.