Updating software and/or firmware on utility node devices, such as smart utility meters, control devices, sensors, etc., is currently complex and time consuming. For example, due to different versions of the software or firmware that are installed on the devices and/or different types of devices, the devices may require different update files to upgrade to a newer version of the software or firmware. In addition, because the update files are relatively large, and are transmitted wirelessly to the utility node devices, the upgrade process requires a substantial amount of time to both transmit the update files to the devices and perform the update at the devices. Accordingly, there is an increasing need to update software and firmware of utility node devices in an efficient manner.
The detailed description is set forth with reference to the accompanying figures. In the figures, the left-most digit(s) of a reference number identifies the figure in which the reference number first appears. The use of the same reference numbers in different figures indicates similar or identical items or features.
As discussed above, current techniques for updating software and/or firmware on a utility node device, such as smart utility meter, control device, sensor, etc., are complex and time consuming.
This disclosure describes, in part, techniques for updating software/firmware on a utility node device by utilizing an update package that includes update items related to different types of the software/firmware. In particular implementations, the utility node device may receive the update package and selectively install one or more of the multiple update items based on a type of the software/firmware that is currently installed on the device. The different types of software/firmware may relate to different versions of the software/firmware (e.g., versions 1 and 2) and/or different types of hardware (e.g., main memory of the utility node, communication hardware, etc.). For example, a utility node device including version 2 of a driver may be upgraded to version 3 of the driver by installing a portion of an update package that relates to version 3 of the driver, while ignoring another portion of the update package that relates to version 1 of the driver. In another example, a utility node may update an operating system stored in main memory by installing a portion of an update package that relates to the operating system, while ignoring another portion of the update package that relates to a modem module that is stored external to the main memory. In some instances, this may allow a single update package to be, for example, broadcast or otherwise provided to multiple different devices that may need different updates or portions of the updates, such as in the case when different devices are operating with different types of software/firmware.
In some embodiments, the multiple update items of the update package may comprise delta files that contain differences between different types of software/firmware. For instance, an update package for a driver that includes versions 1-3, may include a delta file containing differences between versions 1 and 2 and another delta file containing differences between versions 2 and 3. This may enable a utility node device to install the update relatively quickly, given that the update items are smaller than full versions of the software/firmware. Further, the relatively small delta files may allow the update package to be transmitted over a wireless connection in a time-efficient manner.
This disclosure also describes, in part, techniques for updating a system set of a utility node device by utilizing a multi-system set configuration. In particular implementations, the utility node device may include multiple system sets with one system set generally operating in an “active” state (e.g., operational state). The multiple system sets may include a first system set that is generally configured to act as an “active” system set, and one or more “idle” system sets that are in an idle state (e.g., non-operational) when the first system set is in the active or operational state. In one example, the one or more idle system sets may include a second system set that is idle when the first system set is active, but is configured to be made active when the first system set is non-operational or in an idle state. The multiple system sets may also include a third system set (e.g., “fail-safe” system set) that is generally idle, but is configured to be made active when the first and second system sets are non-operational. In some instances, the third system set may comprise a factory installed set that remains unmodified (e.g., unalterable). In other embodiments, additional system sets may be used. A system set may comprise an operating system that includes a kernel and a root file system.
During an update of a system set on the utility node device, the idle system set may be updated with a newer version of the system set, while the active system set may remain operational (e.g., carry-out normal utility node functions). The idle system set may be updated on a version-by-version basis until a specified version is reached (e.g., a newest version of the system set). In some instances, the idle system set is updated from delta files that contain differences between different versions of the system set. By updating the idle system set and leaving the active system set in its current condition, the utility node device may maintain operation of the device (e.g., continue to collect metering data, continue to relay network traffic, etc.) during the update process.
After the idle system set has been updated, the utility node device may enable the idle system set and perform one or more system checks to determine whether the newly activated system set (previous idle system set) is operating properly. In the event that the newly activated system set is not operating properly, the utility node device may revert to the previously activated system set. Thereafter, if the active system set does not operate properly, the utility node device may enable the fail-safe system set. By utilizing multiple system sets, the utility node device may maintain operation of the device, even in the event that one or more of the system sets become non-operational.
As used herein, a “system set” may generally comprise software, firmware, and/or data to operate the utility node. A system set may comprise an operating system that includes (i) a kernel that manages hardware resources of the utility node and/or (ii) a root file system that includes data to operate the utility node, such as files that fulfill utility node functionality and data storage (e.g., applications, libraries, scripts, database data, etc.).
The update techniques are described herein in the context of utility node devices implemented as any of a variety of computing devices, such as smart utility meters, sensors, control devices, transformers, switches, relays, or the like. In general, the utility node devices are configured in a communication network, such as a “mesh” network in which nodes relay information from node-to-node, a “star” network in which nodes send information to a designated node, a “mobile” or “handheld” network in which nodes broadcast or “bubble up” their information to be collected by a mobile or handheld reader device that follows a route to read the meters, and/or other networks. Although the update techniques are discussed herein in the context of utility node devices configured in a utility network, these techniques may alternatively, or additionally, be applicable to other types of computing devices and/or networks.
This brief introduction is provided for the reader's convenience and is not intended to limit the scope of the claims, nor the proceeding sections. Furthermore, the techniques described in detail below may be implemented in a number of ways and in a number of contexts. One example implementation and context is provided with reference to the following figures, as described below in more detail. It is to be appreciated, however, that the following implementation and context is but one of many.
Example Architecture
In general, an update package may include update items for updating any type of software/firmware of the nodes 102. For example, the package may include items for updating low-level boot-up binary data (e.g., u-boot), mid-level kernel data, high-level operating system data (which may include the kernel data and root file system data), binary data for external device(s) (e.g., monolithic data), a module, an application, a device driver, and so on.
As illustrated in
Each of the nodes 102 may be implemented as any of a variety of computing devices such as, for example, smart utility meters (e.g., electric, gas, and/or water meters), control devices, sensors (e.g., temperature sensors, weather stations, frequency sensors, etc.), transformers, routers, servers, relays (e.g., cellular relays), switches, valves, combinations of the foregoing, or any device couplable to a communication network and capable of sending and/or receiving data. In some cases, the nodes 102 may include different types of nodes (e.g., smart meters, cellular relays, sensors, etc.), different generations or models of nodes, and/or nodes that otherwise are capable of transmitting on different channels and using different modulation techniques, data rates, protocols, signal strengths, and/or power levels. In these cases, the architecture 100 may represent a heterogeneous network of nodes.
In the example of
The package creation service 108 may create an update package 112 to be used at the nodes 102 for upgrading software/firmware. In some examples, the service 108 is associated with the head-end service 106, while in other examples the service 108 may comprise a third party. The package 112 may include one or more update items to upgrade software/firmware that is already installed on the nodes 102 and/or to add new software/firmware to the nodes 102. In some instances, the update items are configured to update one or more versions of utility node software/firmware. By way of example, the package 112 may include an update item (e.g., file image) to upgrade an operating system of a utility node from version 2 to version 3 and another update item to upgrade the operating system from version 3 to version 4.
In some instances, an update item of the update package 112 may comprise a delta file that contains differences between different versions of the software/firmware, such as sequential versions of the software/firmware. Here, the particular version of the software/firmware may be represented by the update item. A delta file may be relatively small in size in comparison to a full version of software/firmware. To illustrate, if version 3 of an operating system includes a new module, but is otherwise the same as version 2 of the operating system, the update package 112 may include a delta file that includes only the new module. By including different versions of software/firmware in the package 112 and/or representing the different versions with delta files in the package 112, the nodes 102 may be updated with relatively small amounts of data, in comparison to previous update processes which utilized multiple monolithic update packages. Further, in some instances, because the nodes 102 may be configured with logic to determine what update items to apply/install, a same update package may be broadcast or otherwise provided to multiple nodes that are configured differently.
The package creation service 108 may also generate package description data (PDD) 114 describing contents of the update package 112. The PDD 114 may sometimes be referred to as a “release manifest,” indicating that the data 114 is associated with a new release of software/firmware (e.g., a new version of the software/firmware). The PDD 114 may be utilized to assist the head-end service 106 and/or nodes 102 to identify the contents of the update package 112, determine what update items to install/apply, and so on. By way of example, the PDD 114 may include:
As illustrated in
The head-end service 106 may perform processing to prepare the update package 112 for distribution and/or cause an update package to be distributed to the nodes 102. In some instances, the head-end service 106 may represent and/or be associated with a central office of a utility. Additionally, or alternatively, the service 106 may include a centralized meter data management system which performs processing, analysis, storage, and/or management of data received from the nodes 102.
The head-end service 106 may include one or more computing devices 116, such as servers, personal computers, laptop computers, etc., configured to repackage the package 112 to form a repackaged package 118. The repackaged package 118 may be created by selecting update items of the package 112 that are applicable to updating a particular group of the nodes 102. For instance, if the nodes 102A-102C are identified to be updated to version 3 of an operating system, and the nodes 102A-102C already include versions 1 and 2, then the service 106 may select an update item to update the operating system from version 2 to version 3 and leave out an update item to update the operating system from version 1 to version 2.
As illustrated in
After the head-end service 106 has identified nodes of the utility node network 104 to update, through either the interface 122 or separate processing, the service 106 may distribute the repackaged package 118 and/or the package 112 to the identified nodes. In one example, the service 106 sends the repackaged package 118 and/or the package 112 to an edge device of the network 110 for distribution to one or more of the nodes 102. Although the repackaged package 118 is illustrated as being distributed in the example of
Although the example of
The node 102A may be representative of one or more of the nodes 102 of the utility node network 104. As discussed above, the node 102A may be configured to update its software/firmware (e.g., system set, etc.). In the example of
When the repackaged package 118 is activated at the node 102A to update software/firmware, the node 102A may determine one or more update items of the package 118 to apply to the node 102A. For example, the node 102A may identify a current version of software/firmware that is installed on the node 102A and update items that are applicable to updating the current version to a newer version of the software/firmware. The node 102A may then apply/install the one or more determined update items on a version-by-version basis until a particular version of the software/firmware is reached. As noted above, in some instances the update items may comprise delta files that contain differences between versions of software/firmware.
In some embodiments, the package 118 may include one or more update items that relate to updating system sets 126 of the node 102A. Here, the node 102A may apply/install the one or more update items to an idle system set while an active system set remains operational (e.g., carries-out normal operations). As illustrated in
Example Head-End Service
As used herein, the term “module” is intended to represent example divisions of software for purposes of discussion, and is not intended to represent any type of requirement or required method, manner or necessary organization. Accordingly, while various “modules” are discussed, their functionality and/or similar functionality could be arranged differently (e.g., combined into a fewer number of modules, broken into a larger number of modules, etc.). Further, while certain functions and modules are described herein as being implemented by software and/or firmware executable on a processor, in other embodiments, any or all of the modules may be implemented in whole or in part by hardware (e.g., as an ASIC, a specialized processing unit, etc.) to execute the described functions.
As illustrated in
The memory 204 may also include a package activation module 210 configured to schedule updates at the nodes 102 and send activation messages to the nodes 102. The module 210 may enable the head-end service 106 to activate an update package at the nodes 102 at a particular time, such as a number of hours, days, or weeks after the update package is transmitted to the nodes 102. To activate an update package, the module 210 may cause an activation message to be sent to a particular node or group of nodes to instruct the particular node or group of nodes to update software/firmware by applying update items of an update package that has already been received.
Further, the memory 204 may include a communication module 212 to communicate with one or more of the nodes 102. In some instances, the module 212 may send and/or receive messages from an edge device of the utility node network 104 via the backhaul network 110.
As illustrated in
Example Utility Node Device
In one example, all or part of the baseband processor 310 may be configured as a software (SW) defined radio. In one implementation, the baseband processor 310 provides frequency and/or channel selection functionality to the radio 302. For example, the SW defined radio may include mixers, filters, amplifiers, modulators and/or demodulators, detectors, etc., implemented in software executed by a processor or application specific integrated circuit (ASIC) or other embedded computing device(s). The SW defined radio may utilize processor(s) 312 and software defined and/or stored in memory 314. Alternatively, the radio 302 may be implemented at least in part using analog components.
The processing unit 304 may include the one or more processors 312 communicatively coupled to the memory 314. The memory 314 may be configured to store the system sets 126 including an active system set, an idle system set, and a fail-safe system set, discussed in further detail below in reference to
The update module 316 may be configured to update software/firmware of the node 102A. To implement this functionality, the update module 316 may include an item identification module 322, a validation module 324, and transfer module 326. The item identification module 322 may process an update package to identify (e.g., determine) one or more update items of an update package that are applicable to updating software/firmware on the node 102A. The one or more items may be identified based on package description data describing contents of the update package, a particular version of the software/firmware that is installed on the node 102A, a type of the node 102A, and/or other information. If, for example, the node 102A includes version 1 of a driver, and the driver is to be updated to version 3, the module 322 may identify update items of the update package that are related to versions 2 and 3. Alternatively, if the node 102A does not have version 1 of the driver installed yet, versions 1-3 may be identified to be applied during the update.
The validation module 324 may be configured to validate one or more conditions related to updating one or more update items. For example, the module 324 may perform one or more validation checks to check that a device type of the node 102A matches a device type of a particular update item, check that a prerequisite update item has been applied to the node 102A, check that the node 102A is not operating on a secondary power source (e.g., battery), or check any other function, data, or configuration of the node 102A.
Upon performing the one or more validation checks, the validation module 324 may determine a level of compliance with the one or more checks and proceed with an update based on the level of compliance. If, for example, the level of compliance is relatively low (e.g., less than half of the checks are satisfied), the module 324 may prevent the update from being performed. While, if the level of compliance is relatively high (e.g., more than half of the checks are satisfied), the module 324 may proceed with the update. In one example, the level of compliance includes one of three levels of severity comprising: level 1—less than a first threshold number of validation checks failed (continue applying an update item), level 2—more than the first number of validation checks failed but less than a second threshold number failed (move to next update item and do not apply the current update item), level 3—more than the second threshold number of validation checks failed (stop entire update process). In some instances, the PDD 114 may specify how the level of compliance is determined and/or the level of compliance needed to proceed with applying one or more update items. By performing one or more validation checks, the module 324 may avoid applying/installing update items that are not applicable, such as update items that are related to a version of software/firmware that has already been installed on the node 102A.
The transfer module 326 may be configured to perform different processes to a transfer an update item to the node 102A. The transfer process may be based on a type of the update item (e.g., a type of software/firmware to which an update item is applicable). In some instances, there may be different processes for applying/installing different types of update items on the node 102A. As such, the transfer module 326 may be configured to perform such processes. To illustrate, the module 326 may utilize a first set of techniques to install an update item related to a driver of the node 102A and utilize a second set of techniques to install an update item related to a system set of the node 102A.
In instances when an update item relates to a system set of the node 102A, the update module 316 may apply/install the update item to the idle system set (e.g., a system set that is in an “idle” or “non-operational” state). The idle system set may be updated while the active system set maintains regular operations (e.g., collects consumption data, communicates with other nodes, etc.). After the idle system set is updated, the module 316 may enable the idle system set to take-over operations of the node 102A and become the “active” system set. One or more system checks may then be performed to determine whether the previous idle system set (which is now active) is operating properly. In the event that the idle system set is not operating properly, the utility node device may revert to the previous active system set. Thereafter, if the active system set does not operate properly, the utility node may enable the fail-safe system set to take-over operations of the node 102A. By doing so, the node 102A may maintain operation, even in instances when one or more system sets fail.
The metrology module 318 may be configured to collect consumption data of one or more resources (e.g., electricity, water, natural gas, etc.). The consumption data may include, for example, electricity consumption data, water consumption data, and/or natural gas consumption data. The consumption data may include data generated at the node 102A, another node (e.g., the nodes 102B, 102C, etc.), or a combination thereof. The collected consumption data may be transmitted to a data collector in the case of a star network or, in the case of a mesh network, to one or more other nodes 102 for eventual propagation to the head-end service 106 or another destination. In some instances, consumption data is collected at the node 102A while software/firmware of the node 102A is being updated.
The memory 314 (as well as the memory 204 and all other memory described herein) may comprise computer-readable media and may take the form of volatile memory, such as random access memory (RAM) and/or non-volatile memory, such as read only memory (ROM) or flash RAM. Computer-readable media includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storage of information such as computer-readable instructions, data structures, program modules, or other data for execution by one or more processors of a computing device. Examples of computer-readable media include, but are not limited to, phase change memory (PRAM), static random-access memory (SRAM), dynamic random-access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disks (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information for access by a computing device. As defined herein, computer-readable media does not include communication media, such as modulated data signals and carrier waves.
Example Processes
The processes 400, 500, and 600 (as well as each process described herein) are illustrated as a logical flow graph, each operation of which represents a sequence of operations that can be implemented in hardware, software, or a combination thereof. In the context of software, the operations represent computer-executable instructions stored on one or more computer-readable storage media that, when executed by one or more processors, perform the recited operations. Generally, computer-executable instructions include routines, programs, objects, components, data structures, and the like that perform particular functions or implement particular abstract data types. The order in which the operations are described is not intended to be construed as a limitation, and any number of the described operations can be combined in any order and/or in parallel to implement the process. Further, any number of the individual operations may be omitted.
At 402, the head-end service 106 may receive (e.g., obtain) the update package 112 from the package creation service 108. The update package 112 may include a plurality of update items for updating different types of utility node software/firmware. In some instances, the plurality of update items comprises delta files that each contain a difference between two or more versions of the utility node software/firmware. At 402, the package description data (PDD) 114 may also be received along with the package 112 or separately.
At 404, the head-end service 106 may identify one or more utility nodes to update and/or information related to updating the one or more utility nodes. The information may include a version of utility node software and/or firmware that is currently installed on the one or more utility nodes, a device type of the one or more utility nodes, hardware of the one or more utility nodes, and/or an end-version of utility node software/firmware to which the one or more utility nodes will be updated. In some instances, the interface 122 is displayed to a user to enable the user to select the one or more utility nodes and/or to enable the user to provide the information related to updating the one or more utility nodes.
At 406, the head-end service 106 may repackage the update package 112 to form the repackaged package 118. The package 118 may include one or more update items that are applicable to updating the one or more identified utility nodes, such as one or more update items that are applicable to a version of software/firmware that is already installed on a device and/or that are applicable to hardware of a device. The repackaging may be based on the PDD 114 and/or the information received at 404 related to updating the one or more identified utility nodes (e.g., current version installed on node, device type, hardware, end-version, etc.). To illustrate, if a particular type of utility node (e.g., poly-phase, single phase, etc.) has been selected to be updated, the service 106 may reference the PDD 114 to identify an update item that is designed for the particular type of utility node. The identified update item may be included in the repackaged package 118. In some instances, the PDD 114 may be modified based on the update items included in the repackaged package 118. Although the operation 406 is illustrated as being included in the process 400, in some instances the operation 406 may be omitted.
At 408, the head-end service 106 may cause the repackaged package 118 and/or the update package 112 to be sent to the one or more nodes identified at 404. The package 112 and/or 118 may be sent along with the PDD 114 to enable a node to identify contents of the package 112 and/or 118. The package 112 and/or 118 may be sent to the one or more nodes through an edge (e.g., cellular relay, cellular router, edge router, DODAG root, etc.) which serves as a connection point of a utility node network. As illustrated in the example of
At 410, the head-end service 106 may cause the one or more nodes that received the package 112 and/or 118 to update utility node software/firmware. Here, the service 106 may send an activation message to the one or more nodes instructing the one or more nodes to update the utility node software/firmware by applying/installing one or more update items included in the package 112 and/or 118.
At 504, the node 102A may receive the activation message 412 from the head-end service 106. The message 412 may be received directly from the service 106 and/or through one or more other upstream nodes of the network. The message 114 may instruct the node 102A to activate the package 112 and/or 118, that is, to update the utility node software/firmware by applying/installing one or more update items of the package 112 and/or 118.
At 506, the node 102A may archive data of the node 102A, such as data of a system set, operating system, module, driver, and so on. For example, the node 102A may store an image of an active system set so that the node 102A may revert to this system set in the event that an error occurs while updating utility node software/firmware. Additionally, or alternatively, the node 102A may store back-up data that is common across multiple system sets. The data may be stored in a data store 508 associated with the node 102A.
At 510, the node 102A may identify one or more of the plurality of update items that are included in the package 112 and/or 118 to apply/install on the node 102A. The identification may be based on a version of utility node software/firmware that is currently installed on the node 102A. That is, the node 102A may identify which update items are applicable to updating a current version of utility node software/firmware. Alternatively, or additionally, the identification may be based on a type of hardware of the node 102A or associated with the node 102A. In one example, the node 102A may reference the PDD 114 to identify the update items that are applicable to updating the utility node software/firmware. As illustrated in
At 514, the node 102A may perform one or more validation checks 516 to verify that the one or more update items 512 may be applied to the node 102A. The one or more validation checks 516 may comprise checking that a device type of the node 102A matches a device type of an update item to be applied, checking that a prerequisite update item has been applied to the node 102A, checking that the node 102A is not operating on a secondary power source (e.g., battery), or checking any other function, data, or configuration of the node 102A. Based on the results of one or more validation checks 516, the node 102A may determine a level of compliance with the one or more validation checks 516. If, for example, a threshold number of the one or more validation checks 516 are satisfied the level of compliance may be relatively high, while if the threshold number is not satisfied the level of compliance may be relatively low.
At 518, the node 102A may apply/install the one or more update items 512 to the node 102A. This may allow software/firmware that is associated with the one or more update items 512 to be updated to, for example, a newer version of the software/firmware. In some instances, the node 102A may refrain from applying/installing other update items of the package 112 and/or 118 that were not identified to be applied. Further, in some instances the one or more update items may only be applied if the level of compliance of the one or more validation checks 516 is above a particular threshold. When, for example, an update item of the one or more update items 512 is related to a system set update for the node 102A, the process 500 may proceed to the process 600 discussed in detail below.
In some instances, when an update item is being applied to the node 102A at 518, a specific transfer process may be used for updating software/firmware on the node 102A that is associated with the update item. That is, the specific transfer process may describe how the update item is actually transferred to the node 102A. The specific process may be configurable by, for example, third parties so that the third parties may be enabled to update software/firmware in specific manner.
As noted above, the node 102A may include different system sets to maintain operation of the node 102A. In general, at any given time, only a single system set may be operating (e.g., “active”). The different system sets may include a first system set that is generally configured to act as an “active” system set, a second system set (e.g., “idle” system set) that is configured to operate when the first system set is non-operational or in an “idle” state, and a third system set (e.g., “fail-safe” system set) that is configured to operate when the first and second system sets are non-operational. In some instances, the third system set may comprise a factory installed set that remains unmodified on the node 102A. As such, the third system set may be a permanent system set that enables the node 102A to operate in the event that the first and second system sets are not operating properly. A system set may generally include a kernel and a root file system.
At 602, the node 102A may prepare to update a system set of the node 102A. For example, the node 102A may prepare an idle system set to be updated with an update item related to a system set. This may include clearing out an idle system set and/or copying an active system set to the idle system set. By doing so, the idle system set may be updated with a current version of the active system set, which may be a newer version than the idle system set version.
At 604, the node 102A may update the idle system set of the node 102A by applying/installing at least a portion of an update package to the idle system set. The idle system set may be updated while an active system set manages operations of the node 102A (e.g., performs normal processing). In instances when the update package includes update items that relate to different system set versions, the idle system set may be updated by applying one or more update items that are applicable to a current version of the idle system set. To illustrate, if the idle system set (e.g., the set copied into the idle system set from the active system set) comprises version 2, and the update package includes versions 1-3 of a system set, then update items for version 3 may be applied to the idle system set. The update items may be applied on a version-by-version basis in a sequential manner (e.g., starting at an earlier version and progressing toward a latest version). In some instances, the update items comprise delta files that each contain a difference between system set versions.
At 606, the node 102A may enable the idle system set to manage operation of the node 102A. That is, the idle system set may be set to an “active” state and the active system set may be set to an “idle” state. The idle system set may be enabled by reconfiguring and/or rebooting the node 102A into the idle system set.
At 608, the node 102A (now operating with the previously idle system set) may determine whether operation of the previous idle system set satisfies one or more operational criteria, such as determining that kernel and operating system files are compatible, system level applications can communicate with each other and/or external devices, database data is not corrupt, required files and correct versions were installed and are compatible, etc. When the one or more operational criteria are satisfied, the node 102A may utilize the updated idle system set, at 610. That is, the node 102A may operate with the idle system set in the “active” state. Alternatively, when, at 608, the one or more operational criteria are not satisfied, the process 600 may proceed to 612.
At 612, the node 102A may enable the previously active system set by reconfiguring and/or rebooting the node 102A into the previously active system set. Here, the node 102A may “rollback” or “revert” to the previous system set. In reverting to the previous system set, any data that was archived in relation to the previously active system set may be restored (e.g., data archived at 506 of
After reverting to the previously active system set, the node 102A may, at 614, determine whether operation of the active system set satisfies one or more operational criteria. When the one or more operational criteria are satisfied, the node 102A may utilize the previously active system set, at 616. That is, the node 102A may operate with the previously active system set in the “active” state. Alternatively, when, at 614, the one or more operational criteria are not satisfied, the process 600 may, at 618, enable a fail-safe system set (e.g., permanent system set). The fail-safe system set may be installed at the factory where the node 102A is constructed or configured. In some instances, the node 102A may report to the head-end service 106 whether or not the previous system was enabled at 612 and/or whether or not the fail-safe system set was enabled at 618. By utilizing different system sets, the node 102A may maintain operation of the node 102A, even in the event that one or more system sets fail.
Example User Interface
The interface 700 may include a map area 702 to display a geographical area where one or more utility nodes are located, such as a map of a neighborhood, city, etc. The map area 702 may be selectable to enable a user to select utility nodes. In the example of
As illustrated, the interface 700 may represent different types of utility nodes with different icons. For example, an icon 704 may be associated with a data collector, an icon 706 may be associated with a water meter, an icon 708 may be associated with a gas meter, and an icon 710 may be associated with an electricity meter. Although interface 700 presents the icons 704-710 based on a general functionality of the utility nodes, the interface 700 may alternatively, or additionally, present icons based on any type of information associated with the utility nodes.
The interface 700 may include drop-down menus 712-716 to enable a user to select different information for updating nodes of a utility network. Through the drop-down menu 712 the user may select a group of utility nodes, such as nodes associated with a same device type (e.g., a smart meter, cellular relay, router, sensor, poly phase or single phase device, and so on). Through the drop-down menu 714, the user may select software/firmware to be updated on utility nodes and through the drop-down menu 716 the user may select an end-version to which utility nodes will be updated. In one example, the drop-down menu 716 may allow a user to select a latest available version of software/firmware. The interface 700 may also include a button 718 to begin an update process after, for example, providing information in the drop-down menus 712-716.
In one example of the interface 700, the map area 702 may display a plurality of icons that represent utility nodes of a utility network. As a user interacts with the interface 700, the interface 700 may receive a selection from the user identifying one or more utility nodes to update. For example, the user may select icons located within an area 720 (e.g., area encompassed by the dotted rectangle). The interface 700, or a device associated with the interface 700, such as the device 120 and/or 116 of
Example Memory Structure of a Utility Node
In one example of use of the memory structure 800, the system set partition 802 may be in an “active” state, meaning that the system set partition 802 is being used to operate the utility node. Meanwhile, the system set partition 804 and fail-safe system set partition 806 may be in an “idle” state (e.g., inactive). In this configuration, when an update to a system set is requested, the system set 804 may be updated while the system set partition 802 maintains operation of the utility node. After the update, the system set partition 804 may be enabled to take-over operation of the utility node and the system set partition 802 may be set to an “idle” state. If the system set partition 804 is non-operational, the system set partition 802 may be reactivated. Thereafter, if the system set partition 802 is non-operational, the fail-safe system set partition 806 may be activated.
In some instances, the fail-safe system set partition 806 may be configured to be activated when any type of error occurs on the utility node. For example, the fail-safe system set partition 806 may be enabled when data becomes corrupt in the system set partitions 802 and 804 (e.g., in the case of virus or other harmful data), the system set partitions 802 and 804 are unable to boot, database data or other files are corrupt, hardware communication fails, files are missing, a system set configuration does not satisfies one or more criteria, etc. As such, the fail-safe system set partition 806 may generally act as a second backup in case any problems occur on the system set partitions 802 and 804.
Although embodiments have been described in language specific to structural features and/or methodological acts, it is to be understood that the disclosure is not necessarily limited to the specific features or acts described. Rather, the specific features and acts are disclosed herein as illustrative forms of implementing the embodiments.
This application claims priority to and is a continuation of U.S. patent application Ser. No. 13/717,418, filed on Dec. 17, 2012, the entire contents of which are incorporated herein by reference.
Number | Name | Date | Kind |
---|---|---|---|
6305015 | Akriche | Oct 2001 | B1 |
6493871 | McGuire et al. | Dec 2002 | B1 |
6587684 | Hsu et al. | Jul 2003 | B1 |
6876644 | Hsu et al. | Apr 2005 | B1 |
6938075 | Abbott et al. | Aug 2005 | B1 |
7000230 | Murray | Feb 2006 | B1 |
7313791 | Chen | Dec 2007 | B1 |
7461374 | Balint | Dec 2008 | B1 |
7526539 | Hsu | Apr 2009 | B1 |
7721110 | Kouznetsov | May 2010 | B2 |
7743372 | Armstrong et al. | Jun 2010 | B2 |
7761865 | Stienhans | Jul 2010 | B2 |
7779402 | Abernethy | Aug 2010 | B2 |
7797695 | Motta | Sep 2010 | B2 |
7802246 | Kennedy et al. | Sep 2010 | B1 |
7805719 | O'Neill | Sep 2010 | B2 |
7837959 | Cheng et al. | Nov 2010 | B2 |
7870550 | Qureshi et al. | Jan 2011 | B1 |
7873959 | Zhu et al. | Jan 2011 | B2 |
7921419 | Chatterjee | Apr 2011 | B2 |
7958502 | Motta | Jun 2011 | B2 |
8205194 | Fries et al. | Jun 2012 | B2 |
8209680 | Le | Jun 2012 | B1 |
8233893 | Chen | Jul 2012 | B2 |
8245219 | Agarwal et al. | Aug 2012 | B2 |
8316364 | Stein | Nov 2012 | B2 |
8341210 | Lattyak et al. | Dec 2012 | B1 |
8381021 | Howard et al. | Feb 2013 | B2 |
8407687 | Moshir et al. | Mar 2013 | B2 |
8539479 | Kemmler | Sep 2013 | B2 |
8627310 | Ashok et al. | Jan 2014 | B2 |
8656386 | Baimetov et al. | Feb 2014 | B1 |
8667479 | Johnsson et al. | Mar 2014 | B2 |
8677343 | Averbuch et al. | Mar 2014 | B2 |
8701102 | Appiah | Apr 2014 | B2 |
8745614 | Banerjee et al. | Jun 2014 | B2 |
8769127 | Selimis | Jul 2014 | B2 |
8924950 | McDonald | Dec 2014 | B2 |
20040168165 | Kokkinen | Aug 2004 | A1 |
20040261072 | Herle | Dec 2004 | A1 |
20140173579 | McDonald et al. | Jun 2014 | A1 |
20140173580 | McDonald et al. | Jun 2014 | A1 |
Number | Date | Country |
---|---|---|
2048561 | Apr 2009 | EP |
2002333990 | Nov 2002 | JP |
2004094832 | Mar 2004 | JP |
2006031455 | Jul 2004 | JP |
2006298260 | Apr 2005 | JP |
2006350850 | Jun 2005 | JP |
2006502615 | Jan 2006 | JP |
2006293512 | Oct 2006 | JP |
2010518693 | May 2010 | JP |
WO2009074444 | Jun 2009 | WO |
Entry |
---|
Cadar et al, “Multi-version Software Updates”, IEEE, pp. 36-40, 2012. |
Pukall et al, “JavAdaptor: Unrestricted Dynamic Software Updates for Java ”, ACM, pp. 989-991, 2011. |
Cadar et al, Multi-version Software Updates:, IEEE, pp. 36-40, 2012. |
Thao et al, “Using Versioned Tree Data Structure, Change Detection and Node Identity for Three-Way XML Merging”, ACM, pp. 77-86, 2010. |
Halpin et al, “Dynamic Provenance for SPARQL Updates using Named Graphs ”, ACM, pp. 287-288, 2014. |
Wong et al, “Managing and Querying Multi-Version XML Data with Upda te Logging”, ACM, pp. 74-81, 2002. |
Yasmin et al, “Security Issues Related with DNS Dynamic Updates for Mobile Nodes: A Survey ”, ACM, pp. 1-6, 2010. |
Nilsson et al, “Key Management and Secure Software Updates in Wireless Process Control Environments”, ACM, pp. 100-108, 2008. |
Hosek, et al., “Safe Software Updates via Multi-version Execution”, IEEE, 2013, pp. 612-621. |
Office action for U.S. Appl. No. 13/717,395, mailed on Apr. 15, 2014, McDonald et al., “Utility Node Software/Firmware Update Through a Multi-Type Package”, 17 pages. |
Office action for U.S. Appl. No. 13/717,418, mailed on Apr. 15, 2014, McDonald et al., “Utilizing a Multi-System Set Configuration to Update a Utility Node System Set”, 16 pages. |
PCT Search Report and Written Opinion mailed Jan. 28, 2014 for PCT Application # PCT/US13/69298. |
PCT Search Report and Written Opinion mailed Apr. 16, 2014 for PCT Application No. PCT/US13/69289, 15 Pages. |
Pukall, et al., “JavAdaptor: Unrestricted Dynamic Software Updates for Java”, ICSE ' 11, ACM, 2011, pp. 989-991. |
Wahler, et al., “Dynamic Software Updates for Real-Time Systems”, ACM, 2009, pp. 1-6. |
Wernli, et al., “Using First-class Contexts to realize Dynamic Software Updates”, IWST '11, ACM, 2011, pp. 1-11. |
Australian Examination Report No. 1 mailed Apr. 21, 2016 for Australian patent application No. 2013364075, a counterpart foreign application of U.S. Pat. No. 8,924,950, 2 pages. |
The Japanese Office Action mailed Aug. 9, 2016 for Japanese patent application No. 2015-547946, a counterpart foreign application of U.S. Pat. No. 8,924,950 (Japanese Pat. Appl. No. 2015-547946 is a counterpart foreign application due to having a substantively identical disclosure to U.S. Appl. No. 14/566,333). |
Number | Date | Country | |
---|---|---|---|
20150095900 A1 | Apr 2015 | US |
Number | Date | Country | |
---|---|---|---|
Parent | 13717418 | Dec 2012 | US |
Child | 14566333 | US |