Network Device Control Plane Segmentation for Zero-Downtime Software Upgrades
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Software upgrades in network devices often result in significant downtime, disrupting communication sessions and affecting the entire network due to the need for resetting hardware components and rebooting the device, even when no upgrades are necessary.
Innovation Solution
The method involves separating the data plane from the control plane in network devices, allowing communication sessions to continue uninterrupted during software upgrades or reloads by loading the software image into main memory and using bootstrap code to execute the new software, while minimizing hardware resets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If software upgrades are performed by resetting hardware components and rebooting the network device, then the software upgrade is completed, but the network device experiences significant downtime and communication sessions are disrupted
Solution Approach 1:
The patent segments the network device into two independent planes: control plane and data plane. The control plane handles software upgrades, reloading, and management functions, while the data plane continues to forward traffic and maintain communication sessions. This segmentation allows the control plane to be reset or upgraded without affecting the data plane's operational continuity, thereby enabling software upgrades without significant downtime.
Solution Approach 2:
The patent introduces a bootstrap processor as an intermediary component that facilitates the separation between control and data planes. The bootstrap processor loads and executes control plane software independently from the data plane hardware, allowing control plane operations (including upgrades) to occur without disrupting data plane traffic forwarding. This intermediary mechanism enables the control plane to be updated while the data plane remains operational.
2Reliability
If hardware components are reset during software upgrade, then the software image is properly initialized, but all communication sessions are terminated and network availability is lost
Solution Approach 1:
The patent divides the network device architecture into control plane and data plane segments. The control plane is responsible for software image loading and initialization, while the data plane maintains communication sessions. This segmentation allows the control plane to undergo complete software reinitialization without impacting data plane productivity, as the two planes operate independently with separate execution environments.
Solution Approach 2:
The patent ensures continuity of useful action by maintaining data plane traffic forwarding and communication sessions throughout the control plane software upgrade process. The data plane continues to perform its useful action (traffic forwarding) uninterrupted, while the control plane undergoes its useful action (software upgrade) in parallel. This is achieved through independent execution environments and separate memory spaces for each plane.
3Reliability
If the network device is rebooted from scratch to initialize upgraded software, then the software upgrade is finalized, but the physical layer goes down and causes route flaps and traffic loss
Solution Approach 1:
The patent segments the device reboot process into selective component resets rather than a complete system reboot. Only the control plane components that require software initialization are reset, while the data plane components (physical layer interfaces, forwarding engines) remain operational. This selective segmentation prevents the propagation of harmful effects such as route flaps and traffic loss to the physical layer and external network.
Solution Approach 2:
The patent extracts the control plane software initialization process from the complete device reboot sequence. By taking out only the necessary control plane initialization steps and executing them independently, the patent avoids the harmful side effects of a full reboot (physical layer shutdown, route flaps, traffic loss) while still achieving the goal of finalizing the software upgrade in the control plane.
4Reliability
If a single network device undergoes software reset, then the software is upgraded, but the entire network is affected due to session termination and cascading resets
Solution Approach 1:
The patent segments the network device into isolated control and data planes, and further segments the network into independent device boundaries. This segmentation contains the software upgrade impact to only the control plane of the single device undergoing upgrade, preventing cascading effects to other network devices. The data plane of other devices continues to operate normally, maintaining overall network availability during the upgrade.
Solution Approach 2:
The patent implements preliminary anti-action by maintaining data plane operational status and communication session continuity before, during, and after the control plane software upgrade. By proactively preserving the data plane state and preventing session termination, the patent counteracts the potential harmful cascade effect that would otherwise propagate to other network devices, thereby protecting the entire network from widespread downtime.
Data Source
AI summary
A method and system for resetting a network device. Specifically, in one embodiment, a method is disclosed for upgrading and/or reloading software for a network device with minimal disruption. The method begins by separating operations associated with layer two of an International Standardization Organization Open Systems Interconnect (ISO/OSI) reference model from other layers in the ISO/OSI reference model in a network device. Then, the software operations in layer two of the network device are reset. The software operations are reset while maintaining continuity for a communication session between the network device and other network devices coupled together through a network. Thereafter, for minimal disruption, execution of the software operations is recovered at layer two before continuity of the communication session s terminated.


