In-Service Software Reload for Network Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional methods for software upgrades in network devices require hardware resets and reboots, leading to significant downtime and disruptions in network traffic, which is not suitable for in-service upgrades, especially in microkernel environments.

Innovation Solution

The implementation of an in-service software reload method that allows network devices to upgrade software without rebooting hardware, using a microkernel that operates in a protected address space, enabling user-level processes to be shut down without affecting the kernel, and utilizing checkpointed data for restarts, allowing continuous network traffic forwarding.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional software upgrade methods are used requiring hardware reset and reboot, then software can be upgraded to new versions with fixes and enhancements, but network device downtime increases significantly and network traffic is disrupted

Engineering Contradiction:
Improvesoftware upgrade capabilityVSAvoidnetwork device downtime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system divides the network device into separate virtualization layers: a virtualization layer that manages hardware resources and a virtual machine layer that runs software applications. This segmentation allows the software layer to be upgraded independently without affecting the hardware layer, enabling continuous operation during software updates.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A virtualization layer acts as an intermediary between the hardware and software layers. This intermediary abstracts the hardware resources and allows software to be upgraded in the virtual machine environment without requiring hardware reset or reboot, thus maintaining network traffic flow during upgrades.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If hardware components are reset during software upgrade, then upgraded software can be initialized properly, but network traffic forwarding is interrupted

Engineering Contradiction:
Improvesoftware initializationVSAvoidnetwork traffic forwarding
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The architecture separates hardware initialization from software initialization by introducing a virtualization layer. The hardware layer remains operational and continues forwarding traffic, while the software layer is initialized independently within virtual machines, allowing both hardware functionality and software updates to coexist without interruption.

Inventive Principle:
Principle #1Segmentation

3Reliability

If network device is rebooted from scratch to initialize upgraded software, then software upgrade is completed, but delivery of network traffic is interrupted

Engineering Contradiction:
Improvesoftware upgrade completionVSAvoidtraffic delivery interruption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by maintaining the hardware layer in an operational state before software upgrades. The virtualization layer is configured in advance to support independent software initialization, so when software upgrades occur, the hardware layer is already prepared to continue traffic forwarding without interruption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The hardware layer continues its useful action of forwarding network traffic continuously during software upgrades. The virtualization architecture enables the software layer to be upgraded while the hardware layer maintains uninterrupted traffic flow, achieving continuity of the primary network function throughout the upgrade process.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS8190720B1Performing an in-service software reload on a network device
Publication Date: 2012.05.29 CISCO TECHNOLOGY INC
  • US8190720B1 patent drawing
  • US8190720B1 patent drawing
  • US8190720B1 patent drawing

AI summary

A software reload is executed. The hardware associated with the network device continues to forward network traffic during the software reload. Also, a kernel of the network device operates unaffected in a protected address space throughout the software reload. Further, the kernel preserves local checkpointed and shared memory data. Application processes running on the network node are shut down gracefully. The reloaded software is brought up and the network device is resynchronized.