Server hardware firmware vulnerability increment hot patching method and system

By identifying abnormal power consumption function nodes in the edge computing environment, generating and applying incremental hot patch function code, the resource consumption and power consumption abnormalities caused by full function replacement are resolved, achieving low-power and high-efficiency firmware vulnerability repair.

CN121070677AActive Publication Date: 2025-12-05ZIGUANG HENGYUE TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202511620689.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-07
Publication Date
2025-12-05
Estimated Expiration
2045-11-07

AI Technical Summary

Technical Problem

In existing technologies, full function replacement-based hotfix solutions suffer from problems such as excessive resource consumption, potential service interruptions, and abnormal power consumption in edge computing scenarios where energy efficiency is limited.

Method used

By acquiring the operating status data of multiple functional modules in the server hardware firmware, identifying function nodes with abnormal power consumption, dynamically adjusting the power state and collecting power consumption change data, establishing a mapping relationship between function calls and power consumption modes, generating incremental hot patch function code, and repairing under low power conditions through function jump redirection.

Benefits of technology

It reduces resource consumption in edge computing scenarios, avoids business interruption, and reduces the additional power consumption caused by repair operations, thus meeting the needs of low power consumption and high efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121070677A_ABST
    Figure CN121070677A_ABST
Patent Text Reader

Abstract

The invention provides a server hardware and firmware vulnerability increment hot patching method and system, and relates to the technical field of server hardware and firmware repairation.The method comprises the steps that abnormal function nodes with abnormal power consumption are recognized by obtaining running state data of multiple function modules; dynamically adjusting the power state of a specific module according to the node, and collecting power consumption change data when the power supply changes; then associating the data with a specific module function execution period, and establishing a mapping relation between function call and a power consumption mode to mark a function to be repaired; then generating a corresponding hot patch function code and storing the code in a system memory security area; finally, when the specific module meets the low-power-consumption condition, the to-be-repaired function execution process is switched to a hotfix code through function jump redirection, vulnerability incremental hotfix is completed, server hardware firmware abnormal functions can be accurately recognized, hotfix is generated, the execution process is switched when the specific module is low in power consumption, and firmware vulnerability incremental hotfix is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of server hardware firmware repair, and particularly relates to a server hardware firmware vulnerability incremental hot patch method and system. BACKGROUND

[0002] In the edge computing scenario, servers are usually deployed in industrial sites, remote areas and other environments with limited energy supply. They not only have to bear the core tasks of data collection, localized operation and low-latency response, but also need to strictly control energy consumption to reduce operation and maintenance costs and energy consumption pressure. As the core hub of the interaction between server hardware and software, the stability of hardware firmware directly determines the running state of the device, and firmware vulnerabilities may cause device downtime, data leakage or excessive power consumption. Since edge nodes are usually scattered, large in number and difficult for maintenance personnel to quickly reach the site, firmware vulnerability repair needs to meet the stringent requirements of uninterrupted business operation, low network bandwidth occupation and low storage resource consumption, which poses a high challenge to the energy efficiency and precise operation capability of hot repair technology.

[0003] At present, the mainstream scheme for firmware vulnerability hot repair in this scenario is the hot patch technology based on full function replacement. This scheme first analyzes the firmware image through a static decompilation tool, and locates the target function with vulnerabilities in combination with a vulnerability feature library. Then, according to the code structure and interface specification of the original function, a full replacement hot patch containing complete repair logic is generated. The patch not only covers the vulnerability repair code, but also includes all the normal business logic of the original function. Finally, during system operation, the hot patch is injected into the memory through dynamic loading technology, the execution flow of the original function is suspended and its code segment is overwritten, and then the execution is resumed after the patch is loaded, thereby realizing vulnerability repair without restarting the server.

[0004] However, this scheme has significant defects in the energy efficiency limited scenario of edge computing: full function replacement needs to transmit a patch file containing complete function logic, and for functions with large code size, the patch size is usually large, which takes a long time to transmit under the limited network bandwidth of edge nodes, and occupies too much local storage resource; suspending the execution of the original function during the replacement process will cause a momentary interruption of the business flow, which may cause data loss or response delay for edge businesses with high real-time requirements; in addition, full replacement may break the original power balance due to the modification of associated logic or calling relationship between functions, leading to new power anomaly problems, which is in serious conflict with the core demand of low consumption and high efficiency of edge computing. SUMMARY

[0005] The present application aims to provide a server hardware firmware vulnerability incremental hot patch method and system to solve the problems of excessive resource occupation, easy business interruption and possible power anomaly caused by the full function replacement type hot repair scheme in the energy efficiency limited scenario of the prior art.

[0006] To solve the above technical problems, in a first aspect, the present application provides a server hardware firmware vulnerability incremental hot patch method, comprising:

[0007] Obtain the running state data of a plurality of function modules in the server hardware firmware, identify the abnormal function node with abnormal power consumption based on the running state data;

[0008] According to the abnormal function node, dynamically adjust the power state of a specific module in the function module, and collect the power consumption change data of the specific module in the power supply state change process;

[0009] Correlate the power consumption change data with the function execution period of the specific module, establish the mapping relationship between function call and power consumption mode, and mark the function to be repaired;

[0010] Generate a hot patch function code corresponding to the function to be repaired, and store the hot patch function code in a secure area of the system memory;

[0011] When the specific module meets the low-power consumption condition, the execution flow of the function to be repaired is switched to the hot patch function code through function jump redirection, and the incremental hot repair of the server hardware firmware vulnerability is completed.

[0012] Optionally, the generation of the hot patch function code corresponding to the function to be repaired and the storage of the hot patch function code in the secure area of the system memory comprise:

[0013] Code analysis is performed on the function to be repaired to locate the problem code segment causing abnormal power consumption;

[0014] Based on the problem code segment, a hot patch function code with equivalent function but improved power consumption characteristics is generated, and it is ensured that the hot patch function code and the function to be repaired have the same input and output interfaces;

[0015] The generated hot patch function code is encrypted, the encrypted and signed hot patch function code is written into the secure area of the system memory through a secure memory manager, and the access permission of the secure area is set to read-only attribute through a memory management unit.

[0016] Optionally, the generation of the hot patch function code with equivalent function but improved power consumption characteristics based on the problem code segment and the ensuring that the hot patch function code and the function to be repaired have the same input and output interfaces comprise:

[0017] Instruction-level power consumption analysis is performed on the problem code segment, the core instruction sequence causing abnormal power consumption in the problem code segment is identified, and high-power consumption instructions are replaced with functionally equivalent low-power consumption instruction combinations based on a pre-defined low-power consumption instruction replacement rule.

[0018] reconstructing the control flow structure of the problematic code segment, decomposing the intensive computation loop into multiple sub-loops for staggered execution, and inserting controllable sleep cycles between the sub-loops to reduce the peak power consumption per unit time;

[0019] optimizing the memory access pattern of the problematic code segment, reorganizing the randomly scattered memory access requests into a sequential batch processing access pattern to reduce the active time proportion of the memory controller;

[0020] By replacing, reconstructing and optimizing the content in the problematic code segment, a hot patch function code is generated, and during the code generation stage, the call stack frame layout, parameter passing mechanism and return value processing mode of the hot patch function code are strictly kept consistent with the function to be repaired, and the binary level compatibility of the two is ensured through interface consistency verification.

[0021] Optionally, the associating the power consumption change data with the function execution period of the specific module to establish a mapping relationship between function call and power consumption pattern to mark the function to be repaired comprises:

[0022] corresponding to the function execution period defined by the function call instruction and the function return instruction;

[0023] extracting the power consumption change curve in the corresponding period from the power consumption change data corresponding to each function execution period as the power consumption pattern of the corresponding function;

[0024] comparing the power consumption pattern of each function with the preset normal power consumption range, and marking the corresponding function as the function to be repaired when the power consumption pattern of the function exceeds the normal power consumption range.

[0025] Optionally, the function jump redirection is used to switch the execution flow of the function to be repaired to the hot patch function code when the specific module meets the low power consumption condition, and the vulnerability incremental hot repair of the server hardware firmware is completed, comprising:

[0026] continuously monitoring the current power consumption value of the specific module, and determining that the low power consumption condition is met when the current power consumption value is lower than the preset power consumption threshold;

[0027] When the low power consumption condition is met, the jump address corresponding to the function to be repaired in the function jump table of the server hardware firmware is modified, and the original jump address is replaced by the storage address of the hot patch function code in the safe area of the system memory;

[0028] When the function to be repaired is called, the execution flow is automatically redirected to the hot patch function code through the function jump table.

[0029] The hot patch function code is executed to replace the function of the function to be repaired, and incremental hot repair of the vulnerability of the server hardware firmware is completed.

[0030] Optionally, the power supply state of a specific module in the function module is dynamically adjusted according to the abnormal function node, and power consumption change data of the specific module in the power supply state change process is collected, including:

[0031] The specific module to which the abnormal function node belongs is determined.

[0032] During the continuous running of the server hardware firmware, the power supply voltage and the clock frequency of the specific module are gradually adjusted in a cyclic manner through the power consumption gating circuit.

[0033] After each adjustment of the power supply voltage and the clock frequency is completed, power consumption change data of the specific module is collected, and the power consumption change data includes a current voltage value, a current frequency value, and a corresponding power consumption value.

[0034] Optionally, the running state data of a plurality of function modules in the server hardware firmware is obtained, and an abnormal function node with abnormal power consumption is identified based on the running state data, including:

[0035] Current and voltage measurement values of a plurality of function modules in the server hardware firmware are collected as running state data.

[0036] For each function node in each function module, running state data when the function node is executed is periodically obtained during a normal running stage of the server, and a reference power consumption value of the corresponding function node is determined based on the running state data.

[0037] A power consumption deviation threshold is set, and the power consumption deviation threshold is determined based on a fixed proportion of the reference power consumption value.

[0038] During the running of the server, the current running state data of each function node is continuously monitored and a node power consumption value is calculated, and when the node power consumption value satisfies a predetermined power consumption condition multiple times, the corresponding function node is marked as an abnormal function node with abnormal power consumption, and the predetermined power consumption condition is set according to the reference power consumption value and the power consumption deviation threshold.

[0039] In a second aspect, the present application provides a server hardware firmware vulnerability incremental hot patch system, including:

[0040] An acquisition module is configured to obtain running state data of a plurality of function modules in a server hardware firmware, and identify an abnormal function node with abnormal power consumption based on the running state data.

[0041] The collection module is configured to dynamically adjust a power supply state of a specific module in the function module according to the abnormal function node, and collect power consumption change data of the specific module in a power supply state change process;

[0042] The marking module is configured to associate the power consumption change data with a function execution period of the specific module, establish a mapping relationship between function calling and power consumption mode, and mark the function to be repaired;

[0043] The generation module is configured to generate a hot patch function code corresponding to the function to be repaired, and store the hot patch function code in a secure area of a system memory;

[0044] The repair module is configured to switch an execution flow of the function to be repaired to the hot patch function code through function jump redirection when the specific module meets a low power consumption condition, and complete incremental hot repair of the server hardware firmware vulnerability.

[0045] In a third aspect, the present application provides an electronic device, comprising:

[0046] A memory is configured to store a computer program;

[0047] A processor is configured to execute the computer program to implement the steps of the server hardware firmware vulnerability incremental hot patch method according to the first aspect.

[0048] In a fourth aspect, the present application provides a computer readable storage medium, wherein the computer readable storage medium stores a computer program, and the computer program is executed by a processor to implement the steps of the server hardware firmware vulnerability incremental hot patch method according to the first aspect.

[0049] The server hardware firmware vulnerability incremental hot patch method provided by the present application can accurately identify the function node with abnormal power consumption by obtaining running state data, and can accurately mark the function to be repaired by establishing a mapping relationship between the power consumption change data collected by dynamically adjusting the power supply state and the function execution period. The incremental hot patch code generated is stored in a secure area, and the execution flow is switched through jump redirection only when the specific module meets the low power consumption condition, which not only realizes the incremental repair of the server hardware firmware vulnerability to reduce resource occupation, but also avoids business interruption in the repair process, and can reduce the additional power consumption caused by the repair operation, and is suitable for the low-consumption, high-efficiency and uninterrupted business demand of the firmware hot repair in the energy efficiency limited scenarios such as edge computing.

[0050] Further, the marked function to be repaired is subjected to code analysis to locate the problem code segment causing abnormal power consumption; based on the problem code segment, a hot patch function code with equivalent function but better power consumption characteristics is generated, and it is ensured that the input and output interfaces of the hot patch function code are consistent with those of the function to be repaired; finally, the generated hot patch function code is subjected to encryption processing, the encrypted and signed code is written into the secure area of the system memory by means of the secure memory manager, and the access permission of the secure area is set to read-only by means of the memory management unit. By accurately locating the problem code segment, it is ensured that the generated hot patch can solve the abnormal power consumption problem in a targeted manner; the design of equivalent function and consistent interface ensures the compatibility of the patch and the original system, avoiding functional conflicts; the encryption processing, secure area storage and read-only permission setting effectively prevent the patch from being tampered with or illegally accessed, improve the security of the hot repair process, and further adapt the improved power consumption characteristics to the energy efficiency limited scene requirements. BRIEF DESCRIPTION OF DRAWINGS

[0051] In order to more clearly illustrate the technical solutions of the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiment or prior art description. Obviously, the drawings in the following description are only some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained from these drawings without creative labor.

[0052] Figure 1 A flowchart of a server hardware firmware vulnerability incremental hot patch method provided by an embodiment of the present application;

[0053] Figure 2 A flowchart of a specific embodiment of a server hardware firmware vulnerability incremental hot patch method provided by an embodiment of the present application;

[0054] Figure 3 A structural diagram of a specific embodiment of a server hardware firmware vulnerability incremental hot patch method provided by an embodiment of the present application;

[0055] Figure 4 A structural diagram of a server hardware firmware vulnerability incremental hot patch system provided by an embodiment of the present application. DETAILED DESCRIPTION

[0056] In the edge computing energy efficiency limited scene, the existing firmware hot repair scheme based on full function replacement has obvious defects: the full patch file is large in size, which takes a long time to transmit and occupies too much storage resource under limited bandwidth; suspending the execution of the original function during replacement may cause instantaneous interruption of business, which may lead to data loss or response delay; at the same time, it may destroy the power balance between functions and produce new power consumption anomalies, which is contrary to the demand of low consumption and high efficiency. These problems are caused by the indiscriminate full processing of functions in the scheme, and an accurate, low-consumption and uninterrupted business hot repair method is urgently needed.

[0057] To solve the above problems, the present application provides a server hardware firmware vulnerability incremental hot patch method, the core of which is to identify abnormal power consumption function nodes through running state data, associate power consumption change data with function execution cycle to mark the function to be repaired, generate incremental hot patch and store it in the memory safe area, and complete the repair through function jump redirection when the specific module is in low power consumption. This method greatly reduces the patch size and reduces resource occupation; low power consumption time switching avoids business interruption; accurate positioning of abnormal functions reduces power consumption balance damage, which fundamentally solves the problems of resource consumption, business interruption and power consumption anomaly of the existing scheme, and adapts to the needs of edge computing scene.

[0058] In order to enable the personnel in the technical field to better understand the present application scheme, the present application will be further described in detail below in combination with the drawings and specific embodiments. Obviously, the described embodiments are only part of the embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.

[0059] The core of the present application is to provide a server hardware firmware vulnerability incremental hot patch method, and a specific embodiment thereof is shown in the flowchart as Figure 1 The method comprises:

[0060] S101, acquiring running state data of a plurality of function modules in a server hardware firmware, and identifying abnormal function nodes with abnormal power consumption based on the running state data;

[0061] Optionally, step S101 can specifically include the following steps:

[0062] S1011, collecting current measurement values and voltage measurement values of a plurality of function modules in a server hardware firmware as running state data;

[0063] S1012, for each function node in the function module, periodically acquiring running state data when the function node is executed during normal operation of the server, and determining a reference power consumption value of the corresponding function node based on the running state data;

[0064] S1013, set a power consumption deviation threshold, the power consumption deviation threshold is determined based on a fixed proportion of the reference power consumption value;

[0065] S1014, in the server running process, continuously monitor the current running state data of each function node and calculate the node power consumption value, when the node power consumption value meets the predetermined power consumption condition for multiple times, mark the corresponding function node as an abnormal function node with abnormal power consumption, the predetermined power consumption condition is set according to the reference power consumption value and the power consumption deviation threshold.

[0066] In the embodiment of the application, first, the current measurement value and the voltage measurement value of the plurality of function modules in the server hardware firmware are collected as running state data through step S1011.

[0067] Secondly, through step S1012, for each function node in each function module, the running state data when the function node is executed is recorded multiple times at a fixed time interval in the normal running stage of the server; the power consumption value of each time is calculated according to the recorded running state data each time, the calculation formula is as follows: power consumption value = current measurement value x voltage measurement value, and then the average value obtained by adding the power consumption values multiple times and dividing by the number of records is the reference power consumption value of the corresponding function node.

[0068] Then, through step S1013, the power consumption deviation threshold is set, which is determined based on a fixed proportion of the reference power consumption value.

[0069] Specifically, if the reference power consumption value of a certain function node is calculated to be 60W, and the fixed proportion is set to be 20% according to the stability requirement of the server running, then the reference power consumption value is multiplied by the fixed proportion, that is, 60W x 20% = 12W, which is the power consumption deviation threshold of the function node.

[0070] Finally, through step S1014, in the server running process, the current running state data of each function node is continuously monitored and the node power consumption value is calculated; the calculated node power consumption value is compared with the predetermined power consumption condition, the predetermined power consumption condition is set according to the reference power consumption value and the power consumption deviation threshold, for example, the predetermined power consumption condition is set to node power consumption value > reference power consumption value + power consumption deviation threshold; finally, when the node power consumption value meets the predetermined power consumption condition for multiple times, the corresponding function node is marked as an abnormal function node with abnormal power consumption.

[0071] In practical applications, when the E server hardware firmware is running, the current and voltage of its computing module, storage module, and communication module are first collected as operating status data. Then, for function node E1 of the computing module, function node E2 of the storage module, and function node E3 of the communication module, execution data is recorded 8 times at fixed intervals of 10 seconds during normal server operation, and the reference power consumption values ​​of E1 (55W), E2 (40W), and E3 (35W) are calculated. Then, a fixed ratio of 20% is set to obtain the threshold values ​​of E1 (11W), E2 (8W), and E3 (7W). Finally, each node is continuously monitored, and when the power consumption value of E2 node exceeds 48W (40W+8W) multiple times, E2 is marked as an abnormal function node.

[0072] S102. Based on the abnormal function node, dynamically adjust the power state of a specific module in the functional module, and collect the power consumption change data of the specific module during the power supply state change process.

[0073] Optionally, step S102 may specifically include the following steps:

[0074] S1021. Determine the specific module to which the abnormal function node belongs;

[0075] S1022. During the continuous operation of the server hardware firmware, the power supply voltage and clock frequency of the specific module are gradually adjusted in a cyclic manner through the power consumption gating circuit.

[0076] S1023. After each adjustment of the power supply voltage and clock frequency is completed, the power consumption change data of the specific module is collected. The power consumption change data includes the current voltage value, the current frequency value and the corresponding power consumption value.

[0077] In the above scheme, an abnormal function node refers to a function unit that has been marked as having abnormal power consumption. A specific module refers to the functional module in the server hardware firmware to which the abnormal function node belongs; that is, within which functional module does the abnormal function node execute its specific function? A power gating circuit refers to a circuit component used to control the power supply on / off of the functional module and adjust its power supply parameters. Power consumption change data refers to the set of data reflecting power consumption recorded by the specific module during changes in power supply status. The current voltage value refers to the actual power supply voltage value of the specific module after each adjustment. The current frequency value refers to the clock frequency value corresponding to the specific module after each adjustment. The corresponding power consumption value refers to the power consumption of the specific module under the current voltage and frequency values.

[0078] In this embodiment of the application, the specific module to which the abnormal function node belongs is first determined by step S1021.

[0079] Specifically, in the server hardware firmware, each function node has its clear attribution information, when the abnormal function node A1 is identified, the function module A is the specific module corresponding to the abnormal function node A1 by querying the module function mapping table of the server firmware.

[0080] Secondly, after determining the specific module to be adjusted in the process of continuous running of the server hardware firmware through step S1022, the power consumption gating circuit is used to gradually adjust the power supply voltage and clock frequency of the module in a cyclic manner.

[0081] Specifically, if the initial value of the power supply voltage of the specific module is set to 12V and the fixed step is set to 0.5V, the adjustment mode of step reduction is selected; each time the adjustment is made, the power supply voltage is first reduced by 0.5V from the current value, for example, from 12V to 11.5V, and then the clock frequency is adjusted correspondingly, for example, the original clock frequency is 1GHz, and after the voltage is reduced, the clock frequency is adjusted to 0.9GHz, and the adjustment operation is repeated in this cyclic manner.

[0082] Finally, through step S1023, the current voltage value, the current frequency value and the corresponding power consumption value are collected as the power consumption change data after each adjustment is completed, and the process of dynamically adjusting the power supply state of the specific module according to the abnormal function node and collecting the power consumption change data is completed.

[0083] Specifically, after the power supply voltage of the specific module is adjusted from 12V to 11.5V and the clock frequency is adjusted to 0.9GHz, the current voltage value 11.5V, the current frequency value 0.9GHz and the corresponding power consumption value 55W are collected by the voltage sensor, the frequency sensor and the power consumption detection element respectively, and these three data are combined as the power consumption change data after one adjustment and are stored.

[0084] The overall scheme of S102 above determines the specific module to which the abnormal function node belongs, clearly defines the adjustment object to avoid indiscriminate operation, dynamically adjusts the power supply voltage and clock frequency of the module in a cyclic and gradual manner to ensure stable operation of the module during adjustment, and finally collects the power consumption change data under different power supply states. These data completely present the correlation between the power supply parameters and the power consumption, provide detailed data support for subsequent establishment of function call-power consumption mode mapping and accurate marking of functions to be repaired, and promote the orderly advancement of the vulnerability repair process.

[0085] S103, associating the power consumption change data with the function execution period of the specific module, establishing a mapping relationship between function call and power consumption mode, and marking the function to be repaired;

[0086] Optionally, step S103 can specifically include the following steps:

[0087] S1031, time-corresponding the power consumption change data with a function execution period of the specific module, the function execution period being delimited by a function call instruction and a function return instruction;

[0088] S1032, extracting a power consumption change curve in a corresponding period from the power consumption change data corresponding to each function execution period as a power consumption mode of the corresponding function;

[0089] S1033, comparing the power consumption mode of each function with a preset normal power consumption range, and marking the corresponding function as a function to be repaired when the power consumption mode of the function exceeds the normal power consumption range.

[0090] In the above scheme, the function call instruction refers to a command triggering the start of function execution. The function return instruction refers to a command returning the result after the function execution is completed. The time window of the function execution period refers to the time interval from the occurrence of the function call instruction to the occurrence of the function return instruction. The power consumption mode refers to the overall characteristics represented by the characteristic sequence, which represents the power consumption performance of the function. The function to be repaired refers to the function determined to have an abnormal power consumption mode.

[0091] In the embodiment of the application, firstly, the occurrence time of the function call instruction and the function return instruction is monitored in the execution process of the specific module in step S1031 to determine the time window of each function execution period. Then, the collected power consumption change data is time-stamp corresponding allocated to the time window of each function execution period to ensure that each data corresponds to the execution period of the function.

[0092] Specifically, in the execution process of the data processing module of the specific module of the J-type server, the instruction monitoring program is started, the call instruction of the function J1 is monitored to occur at 14:30:05, the return instruction occurs at 14:30:08, and the time window of the function execution period is determined to be 14:30:05-14:30:08. At the same time, three power consumption change data are collected, the time stamps are 14:30:06, 14:30:07 and 14:30:09, the data with the first two time stamps within the window is allocated to the time window of the function J1, and the data with the third time stamp exceeding the window is temporarily stored for allocation to the corresponding function.

[0093] Secondly, the power consumption change data in the time window of each function execution period is processed in step S1032 to extract the characteristic sequence including the power consumption peak value, the power consumption average value and the power consumption fluctuation frequency, and the characteristic sequence is taken as the power consumption mode of the corresponding function.

[0094] Specifically, in the operation module of the K server, 6 pieces of power consumption data in the execution cycle time window of function K1, i.e., 55W, 58W, 56W, 60W, 57W, and 59W, are processed. It is calculated that the power consumption peak is 60W, the power consumption average is (55+58+56+60+57+59) ÷ 6 = 57.5W, the time window duration is 3 seconds, the power consumption change frequency is 5, and the fluctuation frequency is 5 ÷ 3 ≈ 1.67 times / s. The three characteristic data are combined to form a characteristic sequence, and a power consumption mode of function K1 is formed.

[0095] Finally, the power consumption mode is compared with the pre-stored normal function power consumption characteristic library through step S1033, and the difference degree between the two is calculated. When the difference degree exceeds the set threshold, it is determined that the function is abnormal, and based on the matching result, the function with the abnormal power consumption mode is marked as a function to be repaired.

[0096] Specifically, in the storage module of the L server, the power consumption mode of function L1 (peak value 70W, average value 65W, fluctuation frequency 2 times / s) is compared with the power consumption mode of the storage module normal function (peak value 62W, average value 60W, fluctuation frequency 1.2 times / s) in the normal function power consumption characteristic library. The difference degree between the two is 0.25, and the pre-set difference degree threshold is 0.2. Since the difference degree exceeds the threshold, it is determined that function L1 is abnormal, and it is marked as a function to be repaired.

[0097] The overall scheme of S103 above establishes a complete abnormal function positioning link. The power consumption change data is accurately matched with the function execution cycle through instruction monitoring, avoiding data confusion; the original power consumption data is refined into a power consumption mode containing peak value, average value and fluctuation frequency, simplifying the comparison dimension; finally, it is matched with the normal function power consumption characteristic library, and the function to be repaired is accurately marked through the difference degree. The whole process realizes the conversion from scattered data to clear repair target, ensures the accurate positioning of the function to be repaired, and provides key support for the subsequent targeted hot patch generation and efficient repair process.

[0098] S104, generating a hot patch function code corresponding to the function to be repaired, and storing the hot patch function code in a safe area of the system memory;

[0099] Optionally, step S104 can specifically include the following steps:

[0100] S1041, performing code analysis on the function to be repaired to locate the problem code segment causing abnormal power consumption;

[0101] S1042, generating a hot patch function code with equivalent function but improved power consumption characteristics based on the problem code segment, and ensuring that the hot patch function code has the same input and output interface as the function to be repaired.

[0102] S1043, the generated hot patch function code is encrypted, the encrypted and signed hot patch function code is written into the secure area of the system memory through the secure memory manager, and the access permission of the secure area is set as a read-only attribute through the memory management unit.

[0103] The step S1042 specifically includes the following processes: performing instruction-level power consumption analysis on the problem code segment, identifying a core instruction sequence that causes abnormal power consumption in the problem code segment, and replacing a high-power-consumption instruction with a functionally equivalent low-power-consumption instruction combination based on a predefined low-power-consumption instruction replacement rule; reconstructing the control flow structure of the problem code segment, decomposing a dense computation loop into a plurality of sub-loops for staggered execution, and inserting a controllable sleep period between the sub-loops to reduce the power consumption peak in a unit of time; optimizing the memory access mode of the problem code segment, recombining randomly dispersed memory access requests into a sequential batch processing access mode to reduce the active time proportion of the memory controller; generating the hot patch function code through replacement, reconstruction and optimization of the content in the problem code segment, and strictly maintaining the call stack frame layout, parameter passing mechanism and return value processing mode of the hot patch function code to be completely consistent with the function to be repaired during the code generation stage, and ensuring the binary-level compatibility of the two through interface consistency verification.

[0104] In the above scheme, the problem code segment refers to the execution path part containing a specific instruction sequence that causes abnormal power consumption. The core instruction sequence refers to the key instruction combination in the problem code segment that really causes abnormal power consumption. The low-power-consumption instruction replacement rule refers to a rule that replaces a high-power-consumption instruction with a low-power-consumption instruction while keeping the function unchanged. The dense computation loop refers to a loop code that performs a large amount of computation and runs continuously. The sub-loop refers to a small loop formed after the dense computation loop is split. The controllable sleep period refers to a controllable duration of rest period inserted in the code execution. The memory access mode refers to the way the code accesses the memory. The sequential batch processing access mode refers to the way multiple memory access requests are sequentially and collectively processed. The call stack frame layout refers to the structure of the space allocated in the memory stack when a function is called. The hot patch function code refers to the code used to repair the vulnerabilities of the function to be repaired. The secure memory manager refers to a component responsible for managing the secure area in the system memory. The encrypted and signed hot patch function code refers to the hot patch code that has been encrypted and added with a verification signature. The secure area refers to an area in the system memory that is specially used to store sensitive data and has an access protection mechanism. The memory management unit refers to a hardware component responsible for managing memory access permissions. The read-only attribute refers to the access permission set for the memory area, which can only be read and cannot be modified.

[0105] In the embodiments of the present application, as shown in Figure 2As shown, first, the multi-dimensional code structure of the to-be-repaired function is analyzed by step S1041, and the high-power execution path is identified by constructing a function control flow graph. For example, a control flow graph is constructed for function A1, which shows the execution branches from instruction 1 to instruction 20. By analyzing the power consumption data of each branch, it is found that the branch from instruction 5 to instruction 15 has significantly higher power consumption when executed, and is identified as a high-power execution path. Then, combined with the power consumption change data, the data flow dependency relationship is analyzed to locate the specific instruction sequence that causes abnormal power consumption. For example, by checking the data transfer usage in the high-power path, it is found that the continuous instructions from instruction 8 to instruction 10 cause a sudden increase in power consumption when executed, and are determined as a specific instruction sequence. The execution path containing the specific instruction sequence is marked as a problem code segment that causes abnormal power consumption.

[0106] Secondly, the instruction-level power consumption analysis of the problem code segment is performed by step S1042 to identify the core instruction sequence, and the high-power instruction is replaced by a functionally equivalent low-power instruction combination based on the low-power instruction replacement rule. For example, the high-power multiplication instruction sequence in the problem code segment is replaced by a low-power shift and addition combination instruction according to the rule. Then, the control flow structure is reconstructed, and the intensive calculation loop is decomposed into multiple sub-loops, and a controllable sleep cycle is inserted between the sub-loops. For example, a calculation loop that is executed 100 times in a row is split into 5 sub-loops that are each executed 20 times, and a 1-millisecond sleep is inserted after each sub-loop. Then, the memory access mode is optimized, and the random memory access is reorganized into sequential batch processing access to reduce the active time of the memory controller. During the code generation stage, the call stack frame layout, parameter passing mechanism and return value processing method of the hot patch function are kept consistent with those of the to-be-repaired function, and the binary-level compatibility is ensured through interface consistency verification to generate the hot patch function code.

[0107] Finally, the generated hot patch function code is encrypted by step S1043, for example, using a symmetric encryption algorithm to encrypt the hot patch code to ensure that the code content cannot be easily obtained. The encrypted and signed hot patch function code is written to the secure area of the system memory by the secure memory manager, wherein the secure memory manager first verifies the validity of the encryption signature, and after verification, the code is stored in the specially divided secure area of the memory. The access permission of the secure area is set to read-only by the memory management unit to prevent the hot patch code stored in the area from being accidentally modified or maliciously tampered with.

[0108] In practical application, for the marked function F1 to be repaired in the F server, multi-dimensional code structure analysis is first performed and a control flow graph thereof is constructed, and it is found from the control flow graph that the power consumption of the execution path of "data decoding-data operation-result temporary storage" in the function F1 is obviously higher than that of other paths, the data flow dependency relationship is further analyzed in combination with the power consumption change data of the path, it is determined that the three consecutive multiplication instructions of the "data operation" link are the root cause of the power consumption anomaly, and the "data decoding-data operation-result temporary storage" path containing the three multiplication instructions is marked as a problem code segment; then, instruction-level power consumption analysis is performed on the problem code segment, the three consecutive multiplication instructions are replaced by functionally equivalent shift and addition combination instructions according to the low-power instruction replacement rule, a data processing loop that is continuously executed 200 times in the code is split into 4 sub-loops each of which is executed 50 times, a 2-millisecond controllable sleep cycle is inserted after each sub-loop, and 8 randomly dispersed memory read requests are reorganized into batch access in address order, finally, the hot patch function code is generated and interface consistency verification is performed, and it is confirmed that the call stack frame, parameter passing and return value processing thereof are completely consistent with F1; finally, the generated hot patch function code is encrypted using a preset encryption algorithm and a digital signature is added, after the security memory manager verifies that the digital signature is correct, the hot patch function code is written into the pre-divided secure storage area in the system memory, and the memory management unit of the server performs access permission setting operation on the secure area and configures the permission as read-only, so that the hot patch code can only be read and executed and cannot be modified, and the overall operation of step S104 is completed.

[0109] The overall scheme of S104 above constructs a closed-loop process from problem accurate positioning to hot patch generation and then to secure storage. First, the abnormal power consumption code segment of the function to be repaired is locked through multi-dimensional analysis, then the functionally equivalent, interface compatible and power consumption improved hot patch code is generated through instruction replacement, control flow reconstruction and memory access optimization, and finally the code security is guaranteed through encryption processing, secure area storage and read-only permission setting. The generated hot patch not only solves the original function power consumption anomaly problem, but also ensures the compatibility with the system, and builds a reliable code foundation for the smooth execution of subsequent vulnerability hot repair.

[0110] S105, when the specific module meets the low-power condition, the execution flow of the function to be repaired is switched to the hot patch function code through function jump redirection, and the vulnerability incremental hot repair of the server hardware firmware is completed.

[0111] Optionally, step S105 can specifically include the following steps:

[0112] S1051, continuously monitor the current power consumption value of the specific module, and determine that the low-power condition is met when the current power consumption value is lower than the preset power consumption threshold;

[0113] S1052, when the low-power consumption condition is met, modifying a jump address corresponding to the function to be repaired in a function jump table of a server hardware firmware, replacing the original jump address with a storage address of the hot patch function code in a system memory safe area;

[0114] S1053, when the function to be repaired is called, automatically redirecting an execution flow to the hot patch function code through the function jump table;

[0115] S1054, executing the hot patch function code to replace a function of the function to be repaired, completing incremental hot repair of the vulnerability of the server hardware firmware.

[0116] In the above scheme, the current power consumption value refers to the power consumption of the monitored specific module when running. The preset power consumption threshold refers to the critical power consumption value preset for judging whether the specific module is in a low-power consumption state. The function jump table refers to a table recording the jump address when calling the function in the server hardware firmware. The original jump address refers to the storage address of the function to be repaired originally recorded in the function jump table. The hot patch function code storage address refers to the specific storage location of the hot patch function code in the system memory safe area. The execution flow redirection refers to the process of switching the execution path originally pointing to the function to be repaired to the hot patch function code. The incremental hot repair of the vulnerability refers to the partial repair of only the function to be repaired with the vulnerability without updating the entire firmware.

[0117] In the embodiment of the application, first, the current power consumption value of the specific module is continuously monitored through step S1051, and the power consumption monitoring tool collects the power consumption data of its running every second as the current power consumption value; when the current power consumption value is lower than the preset power consumption threshold, it is determined that the low-power consumption condition is met.

[0118] Secondly, when the low-power consumption condition is met, the entry corresponding to the function to be repaired in the function jump table of the server hardware firmware is found through step S1052, the jump address in the row is modified, the original jump address is replaced with the storage address of the hot patch function code in the system memory safe area, and the update of the jump address is completed.

[0119] Then, when the function to be repaired is called, the server will automatically query the function jump table to find the jump address corresponding to the function to be repaired through step S1053. The address has been modified to the storage address of the hot patch function code, so the execution flow will be automatically redirected from the function to be repaired to the hot patch function code.

[0120] Finally, the hot patch function code is executed through step S1054, which realizes the same function as the to-be-repaired function during running, and the incremental hot repair of the server hardware firmware vulnerability is completed through this function replacement, that is, only the to-be-repaired function is repaired locally, and the server does not need to be restarted or the entire firmware needs to be updated.

[0121] In actual application, in the A type server, for the determined operation module (specific module), the power consumption monitoring program is started to continuously collect the current power consumption value thereof, the preset power consumption threshold of the module is set to 60W, and the collected power consumption values in the monitoring process are 65W, 62W, 58W and 57W in turn. When 58W is collected, it is determined to meet the low power consumption condition because it is lower than the preset threshold; then the technical personnel opens the function jump table through the firmware debugging tool, finds the entry corresponding to the to-be-repaired function A2, replaces the original jump address 0x3000ABCD with the storage address 0x4000EFGH of the hot patch function code in the safe area, saves the modified jump address replacement; when the server runs the data processing task, the task execution triggers the call of the to-be-repaired function A2 at a certain link, the server queries the function jump table, and then automatically redirects the execution flow to the memory area where the hot patch function code is located; after the hot patch function code is run, the server log compression storage function originally responsible by A2 is completed, and the power consumption abnormality of the original function is solved. In this way, only A2 is locally repaired, and the incremental hot repair of the server hardware firmware vulnerability is completed.

[0122] The overall scheme of the above S105 captures the appropriate repair window period with low power consumption monitoring, avoids operation when the module is under high load, and reduces the interference to the business; then automatically completes the jump address modification and execution flow switching, without the need for continuous manual intervention. In an incremental hot repair manner, only the to-be-repaired function is locally repaired, which not only ensures that the hot patch accurately replaces the function of the original function and solves the power consumption abnormality, but also avoids the problems such as system restart and excessive resource occupation caused by full firmware update, realizes the balance between repair effectiveness and business continuity, and perfectly adapts to the repair needs of low consumption and high efficiency of the server in the energy efficiency limited scene of edge computing.

[0123] The following is a complete example for steps 101-105, such as Figure 3As shown, in the process of repairing the server hardware firmware vulnerability of model A, first, the current and voltage measurement values of multiple functional modules such as the operation module and the storage module in the server are collected as running state data. For function A1 in the operation module, the running state data at the time of its 8 executions is recorded at a fixed time interval of 10 seconds during the normal running stage of the server, and the reference power consumption value is calculated to be 60W. A fixed proportion of 20% is set to obtain a power consumption deviation threshold of 12W. Then, the current power consumption value of function A1 is continuously monitored during the running of the server. When it is monitored multiple times that the power consumption value exceeds 72W (60W+12W), function A1 is marked as an abnormal function node.

[0124] Next, it is determined that the specific module to which the abnormal function node A1 belongs is the operation module. The power supply voltage and clock frequency of the operation module are gradually adjusted in a loop manner through the power consumption gate circuit during the continuous running of the server. The power supply voltage is reduced by 0.5V steps from the initial 12V, and the clock frequency is adjusted correspondingly. After each adjustment, the current voltage value, current frequency value and corresponding power consumption value are collected as power consumption change data.

[0125] Then, during the execution process of the operation module, the calling and returning instructions of function A1 are monitored, and the time window of its execution cycle is determined to be 15:20:00-15:20:04. The collected power consumption change data is distributed into the window according to the time stamp, and the data in the window is processed. The power consumption peak value 75W, the power consumption average value 70W and the power consumption fluctuation frequency 2 times / sec are extracted to form the power consumption mode of function A1. The mode is matched with the pre-stored normal function power consumption feature library, and the difference degree is calculated to be 0.25, which exceeds the set threshold of 0.2. Function A1 is marked as a function to be repaired.

[0126] Subsequently, multi-dimensional code structure analysis is performed on function A1, a control flow graph is constructed, and a high-power execution path of "data decoding-data operation-result temporary storage" is identified. Combined with the power consumption change data, three consecutive multiplication instructions in the "data operation" link are located as the problem code segment. Instruction-level power consumption analysis is performed on the problem code segment, the three multiplication instructions are replaced by functionally equivalent shift and addition combination instructions, a continuous execution of 200 times of calculation loop is split into 4 sub-loops each executing 50 times and a 2ms sleep cycle is inserted between the sub-loops, and 8 random and dispersed memory read requests are reorganized into sequential batch processing access. The hot patch function code is generated and verified for interface consistency to ensure that it is completely consistent with the call stack frame layout, parameter passing mechanism and return value processing method of function A1. The hot patch code is encrypted and a digital signature is added, and is written into the secure area of the system memory through the secure memory manager. The access permission of this area is set to read-only by the memory management unit.

[0127] Finally, the current power consumption value of the operation module is continuously monitored, and the preset power consumption threshold is 50W. When the monitored power consumption values are 55W, 52W and 48W in sequence, it is determined that the low power consumption condition is met. At this time, the jump address corresponding to the function A1 in the server firmware function jump table is modified, and the original address 0x10001234 is replaced with the storage address 0x20005678 of the hot patch function code in the safe area. When the server runs the data processing task to trigger the function A1 call, the execution flow is automatically redirected to the hot patch function code through the function jump table. After the hot patch function code is run, the data operation function responsible by the original function A1 is completed, and the power consumption abnormality problem is solved, and finally the vulnerability incremental hot repair of the A type server hardware firmware is completed.

[0128] Figure 4 A structural schematic diagram of a specific embodiment of a server hardware firmware vulnerability incremental hot patch system provided by the embodiment is referred to Figure 4 The system can include:

[0129] The acquisition module 41 is configured to acquire running state data of a plurality of function modules in a server hardware firmware, and identify an abnormal function node with abnormal power consumption based on the running state data.

[0130] The collection module 42 is configured to dynamically adjust a power supply state of a specific module in the function module according to the abnormal function node, and collect power consumption change data of the specific module in a power supply state change process.

[0131] The marking module 43 is configured to associate the power consumption change data with a function execution period of the specific module, establish a mapping relationship between function calling and power consumption mode, and mark a function to be repaired.

[0132] The generation module 44 is configured to generate a hot patch function code corresponding to the function to be repaired, and store the hot patch function code in a safe area of a system memory.

[0133] The repair module 45 is configured to switch the execution flow of the function to be repaired to the hot patch function code through function jump redirection when the specific module meets a low power consumption condition, and complete the vulnerability incremental hot repair of the server hardware firmware.

[0134] The server hardware firmware vulnerability incremental hot patch system of the embodiment is used to implement the foregoing server hardware firmware vulnerability incremental hot patch method, and therefore the specific embodiments of the server hardware firmware vulnerability incremental hot patch system can be seen from the foregoing embodiment part of the server hardware firmware vulnerability incremental hot patch method. The specific embodiments can be referred to the description of the corresponding embodiment part, and will not be described herein.

[0135] The application further provides an electronic device, comprising: a memory for storing a computer program; and a processor for executing the computer program to implement the steps of the server hardware and firmware vulnerability incremental hot patch method.

[0136] The application further provides a computer readable storage medium, wherein the computer readable storage medium stores a computer program, and the computer program is executed by a processor to implement the steps of the server hardware and firmware vulnerability incremental hot patch method.

[0137] In an example embodiment, the computer readable storage medium can include, but is not limited to, a U disk, a read-only memory, a random access memory, a mobile hard disk, a magnetic disk or an optical disk, and various media capable of storing a computer program.

[0138] The embodiments of the application further provide a computer program product, wherein the computer program product comprises a computer program, and the computer program is executed by a processor to implement the steps in the server hardware and firmware vulnerability incremental hot patch method.

[0139] The skilled person can further realize that the units and algorithm steps of the examples described in conjunction with the embodiments disclosed herein can be realized by electronic hardware, computer software or a combination of both. In order to clearly illustrate the interchangeability of hardware and software, the components and steps of the examples have been described in the above description in general terms. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solution. The skilled person can use different methods to realize the described functions for each specific application, but such implementation should not be considered beyond the scope of the application.

[0140] The above describes in detail the server hardware and firmware vulnerability incremental hot patch method and system provided by the application. The principles and implementation manners of the application are described by using specific examples in the present disclosure. The above description of the examples is only used to help understand the method of the application and its core idea. It should be noted that, for those skilled in the art, without departing from the principles of the application, some improvements and modifications can be made to the application, and these improvements and modifications also fall within the protection scope of the application.

Claims

1. A server hardware firmware vulnerability incremental hot patching method, characterized in that, The method comprises the following steps: acquiring running state data of a plurality of function modules in server hardware firmware, identifying an abnormal function node with abnormal power consumption based on the running state data; dynamically adjusting the power state of a specific module in the function modules according to the abnormal function node, and collecting power consumption change data of the specific module in the power state change process; associating the power consumption change data with the function execution period of the specific module, establishing a mapping relationship between function calling and power consumption mode to mark a function to be repaired; generating a hot patch function code corresponding to the function to be repaired, and storing the hot patch function code in a secure area of system memory; when the specific module meets a low-power consumption condition, switching the execution flow of the function to be repaired to the hot patch function code through function jump redirection, and completing incremental hot repair of the server hardware firmware vulnerability.

2. The method of claim 1, wherein, The method comprises the following steps: code analysis is performed on the function to be repaired to locate the problem code segment causing abnormal power consumption; based on the problem code segment, a hot patch function code with equivalent function but improved power consumption characteristics is generated, and it is ensured that the hot patch function code has the same input and output interfaces as the function to be repaired; the generated hot patch function code is encrypted, the encrypted and signed hot patch function code is written into the secure area of system memory through a secure memory manager, and the access permission of the secure area is set to a read-only attribute through a memory management unit.

3. The method of claim 2, wherein, The method comprises the following steps: instruction-level power consumption analysis is performed on the problem code segment to identify the core instruction sequence in the problem code segment that causes abnormal power consumption, and based on a pre-defined low-power consumption instruction replacement rule, high-power consumption instructions are replaced with a combination of functionally equivalent low-power consumption instructions; the control flow structure of the problem code segment is reconstructed, intensive computation loops are decomposed into a plurality of interleaved sub-loops, and controllable sleep periods are inserted between the sub-loops to reduce the power consumption peak value per unit time; the memory access mode of the problem code segment is optimized, random and dispersed memory access requests are reorganized into a sequential batch processing access mode, and the active time proportion of the memory controller is reduced; through replacement, reconstruction and optimization of the content in the problem code segment, a hot patch function code is generated, and during code generation, the calling stack frame layout, parameter passing mechanism and return value processing mode of the hot patch function code are strictly maintained to be identical to those of the function to be repaired, and interface consistency verification is performed to ensure the binary-level compatibility of the two.

4. The method of claim 1, wherein, The method comprises the following steps: corresponding to each function execution period, as a power consumption mode of the corresponding function; comparing the power consumption mode of each function with a preset normal power consumption range, and marking the corresponding function as a to-be-repaired function when the power consumption mode of the function exceeds the normal power consumption range. The method for performing incremental hot repair on the server hardware firmware vulnerability includes:

5. The method of claim 1, wherein, continuously monitoring the current power consumption value of the specific module, and determining that the low power consumption condition is met when the current power consumption value is lower than a preset power consumption threshold; when the low power consumption condition is met, modifying the jump address corresponding to the to-be-repaired function in the function jump table of the server hardware firmware, and replacing the original jump address with the storage address of the hot patch function code in the system memory safe area; when the to-be-repaired function is called, automatically redirecting the execution flow to the hot patch function code through the function jump table; executing the hot patch function code to replace the function of the to-be-repaired function, and completing the incremental hot repair of the server hardware firmware vulnerability. The method includes:

6. The method of claim 1, wherein, determining the specific module to which the abnormal function node belongs; adjusting the supply voltage and clock frequency of the specific module in a cyclic manner through a power consumption gate circuit during the continuous running of the server hardware firmware; after completing the adjustment of the supply voltage and clock frequency each time, collecting the power consumption change data of the specific module, which includes the current voltage value, the current frequency value, and the corresponding power consumption value. The method includes:

7. The method of claim 1, wherein, collecting current measurement values and voltage measurement values of a plurality of function modules in the server hardware firmware as running state data; for each function node in each function module, periodically obtaining the running state data when the function node is executed during the normal running stage of the server, and determining the reference power consumption value of the corresponding function node based on the running state data; setting a power consumption deviation threshold, which is determined based on a fixed proportion of the reference power consumption value; during the running of the server, continuously monitoring the current running state data of each function node and calculating the node power consumption value, and marking the corresponding function node as an abnormal function node with abnormal power consumption when the node power consumption value meets a predetermined power consumption condition multiple times, the predetermined power consumption condition being set according to the reference power consumption value and the power consumption deviation threshold. The method includes:

8. A server hardware firmware vulnerability incremental hot patching system, comprising: ​ An acquisition module is configured to acquire running state data of a plurality of function modules in a server hardware firmware, and identify an abnormal function node with abnormal power consumption based on the running state data; An acquisition module is configured to acquire running state data of a plurality of function modules in a server hardware firmware, and identify an abnormal function node with abnormal power consumption based on the running state data; A marking module is configured to associate the power consumption change data with a function execution period of the specific module, establish a mapping relationship between function calling and power consumption mode, and mark a function to be repaired; A generation module is configured to generate a hot patch function code corresponding to the function to be repaired, and store the hot patch function code in a secure area of a system memory; A repair module is configured to switch an execution flow of the function to be repaired to the hot patch function code through function jump redirection when the specific module meets a low-power consumption condition, and complete incremental hot repair of a vulnerability of the server hardware firmware.

9. An electronic device, comprising: The computer readable storage medium stores a computer program, and the computer program is executed by the processor to implement the steps of the server hardware firmware vulnerability incremental hot patch method according to any one of claims 1 to 7. The computer readable storage medium stores a computer program, and the computer program is executed by the processor to implement the steps of the server hardware firmware vulnerability incremental hot patch method according to any one of claims 1 to 7. ​ 10. A computer-readable storage medium, characterized in that, ​

Citation Information

Patent Citations

  • Firmware repair method, solid state disk controller and solid state disk

    CN112650519A

  • Vulnerability fixing method and device, electronic equipment and storage medium

    CN115688119A

  • Self-checking positioning method and device for abnormal power consumption of water meter, medium and product

    CN118936604A

  • Automatic vulnerability repairing method, storage medium, equipment and product

    CN120234809A

  • The method for reducing entire power consumption of the CPU installed in operation server

    KR1020110065999A