Platform firmware upgrade verification method and cluster management system based on out-of-band management
By using out-of-band management and single-pair Ethernet technology in the cluster management system, the security and efficiency problems of multi-device firmware upgrades in unmanned scenarios are solved, and a secure and fast firmware update process is achieved.
Patent Information
- Application Number
- CN202510082936.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-20
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-01-20
AI Technical Summary
Existing terminal firmware upgrade technology is not suitable for unattended multiple device firmware upgrade scenarios, especially when the device firmware is attacked or failed, and it is impossible to achieve safe and efficient firmware updates.
A cluster management system based on out-of-band management is adopted, through the combination of health management chips, PHY chips and physical switches, a single-pair Ethernet connection between the master and slave devices is realized, and a fast transmission and security verification of firmware files are carried out.
It realizes safe, fast and efficient firmware updates to multiple devices in an unattended scenario, avoids illegal modification of firmware content, and overcomes the disadvantages of inability to update when a device firmware failure or system crash.
Smart Images

Figure CN119987811A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of firmware upgrade, and in particular to a platform firmware upgrade verification method and a cluster management system based on out-of-band management. Background Art
[0002] Firmware is software embedded in hardware that is responsible for controlling and managing the operation of a device. Unlike ordinary software, firmware is usually tightly integrated with the device's hardware and directly affects the performance and functionality of the device.
[0003] Firmware updates and upgrades are a key step in ensuring device performance and security. Firmware updates and upgrades can fix device vulnerabilities, prevent hacker attacks and malware intrusions, improve device performance, enhance device processing power and stability, and enhance device compatibility, ensuring that the device is compatible with new operating systems and applications.
[0004] Today, as business systems become more integrated and complex, the number of devices is increasing rapidly. In unattended cluster management, attacks from the bottom layer are mostly focused on illegal modifications to firmware content. Therefore, the importance of device platform firmware security protection and recovery technology has become apparent.
[0005] In the existing remote firmware upgrade technology for multiple devices, the connection relationship between each device is usually established through the IPMB (Intelligent Platform Management Bus, a two-wire serial bus based on the I2 C protocol). The main process is to operate in the Web management interface, and transmit the files required for the firmware upgrade to each device to execute the firmware upgrade script. Its characteristics are that it does not need to be powered off, and does not require the use of JTAG (Joint Test Action Group, an international standard test protocol) burning tools.
[0006] The existing firmware upgrade technologies mainly include the following situations:
[0007] The disadvantages of implementing terminal firmware upgrades based on wireless technology are that wireless technology has problems such as signal attenuation, signal delay, transmission distance limitation, poor anti-interference, low security, poor stability, and high maintenance costs when deployed on a large scale. It is especially unusable in industry or special industries.
[0008] The disadvantage of upgrading via a wired network or bus based on an in-band management system is that once the underlying firmware is attacked or fails, the device's operating system will not function properly or even crash, and the firmware cannot be restored or upgraded. In addition, the operating system itself is at risk of crashing, which can also make it impossible to upgrade or maintain the device's firmware.
[0009] On-site upgrades require the use of dedicated firmware upgrade equipment to upgrade the firmware on-site through hardware connections. The disadvantages are low efficiency and the need for manual on-site operations, high costs, poor operability, and are not conducive to the maintenance of large quantities of equipment.
[0010] In summary, existing terminal firmware upgrade technologies are not suitable for scenarios where multiple devices are upgraded without human intervention. Summary of the invention
[0011] The main purpose of the present invention is to provide a platform firmware upgrade verification method and a cluster management system based on out-of-band management, aiming to solve the problem that the existing terminal firmware upgrade technology is not suitable for the scenario of unattended firmware upgrade of multiple devices.
[0012] To achieve the above object, the present invention provides a platform firmware upgrade verification method, which is applied to a cluster management system based on out-of-band management, wherein the cluster management system includes multiple devices, at least one of which is a master device, and the other devices are slave devices; the master device is respectively connected to a management terminal and a cloud server for communication; each of the devices includes a health management chip, a PHY chip and a physical switch connected in sequence; the PHY chip and the physical switch are connected via a single-pair Ethernet; the method includes the following steps:
[0013] When a firmware update instruction is detected, the management terminal controls the master device to download a firmware file for update from the cloud server, and the management terminal sends a slave device identifier of the firmware to be updated to the master device;
[0014] Turning on the physical switch corresponding to the master device, and sending a firmware update instruction to the slave device whose firmware is to be updated through the communication bus, so as to turn on the physical switch corresponding to the slave device whose firmware is to be updated, thereby opening a single pair of Ethernet channels between the master device and the slave device whose firmware is to be updated;
[0015] The master device sends a firmware file to the slave device whose firmware is to be updated through the single pair of Ethernet channels.
[0016] Optionally, after the step of sending the firmware file to the slave device whose firmware is to be updated through the single-pair Ethernet channel, the step further includes:
[0017] After the slave device that has received the firmware file has been verified by the verification module and is found to be correct, the corresponding health management chip is controlled to open the SPI channel of the CPU module so that the firmware file is written into the FLASH chip, thereby realizing the firmware update of the slave device.
[0018] Optionally, the method further includes:
[0019] Obtaining operation information of each of the slave devices;
[0020] According to the operation information, it is determined whether to trigger the firmware update instruction.
[0021] Optionally, the step of determining whether to trigger the firmware update instruction according to the operation information includes:
[0022] Determining whether there is a slave device whose firmware is to be updated according to the operation information of each of the slave devices;
[0023] If the slave device with firmware to be updated exists, marking the slave device with firmware to be updated as a device to be updated, and obtaining the slave device identifier corresponding to the device to be updated;
[0024] Determine a firmware update period for each of the devices to be updated, and form a device firmware update sequence table according to the firmware update period for each of the devices to be updated;
[0025] Determining the firmware update time of each device to be updated according to the device firmware update sequence table;
[0026] The firmware update instruction is triggered to perform firmware update on each of the devices to be updated according to the device firmware update sequence table and the firmware update time.
[0027] Optionally, the step of determining the firmware update period of each device to be updated, and forming a device firmware update sequence list according to the firmware update period of each device to be updated, includes:
[0028] Obtaining the load change of each device to be updated in a historical period, and taking the period when the load of each device to be updated is lower than a preset value as the firmware update period corresponding to each device to be updated;
[0029] According to the operation information of each of the devices to be updated, sorting the multiple devices to be updated whose firmware update periods overlap to obtain a sorting result;
[0030] A device firmware update sequence table is formed according to the firmware update period corresponding to each of the to-be-updated devices and the sorting results corresponding to a plurality of the to-be-updated devices whose firmware update periods overlap.
[0031] Optionally, the step of determining the firmware update time of each device to be updated according to the device firmware update sequence table includes:
[0032] Obtaining the firmware update period corresponding to each of the to-be-updated devices in the device firmware update sequence table, and obtaining the set firmware update duration of each of the to-be-updated devices;
[0033] The firmware update time of each device to be updated is determined according to the firmware update period corresponding to each device to be updated and the set firmware update duration, wherein the firmware update times of the devices to be updated do not overlap.
[0034] To achieve the above object, the present invention further proposes a cluster management system based on out-of-band management, comprising a plurality of devices, wherein at least one of the devices is a master device and the rest of the devices are slave devices; the master device is respectively connected to a management terminal and a cloud server for communication; each of the devices comprises a health management chip, a PHY chip and a physical switch connected in sequence; the PHY chip and the physical switch are connected via a single pair of Ethernet;
[0035] The switch state of the physical switch is controlled by the health management chip;
[0036] The physical switch of the master device is turned on when there is a slave device whose firmware is to be updated, and each of the devices is connected via a communication bus, and the communication bus is used to transmit a firmware update instruction between the master device and the slave device, so that the slave device that receives the firmware update instruction turns on the corresponding physical switch;
[0037] The single-pair Ethernet of the device with the physical switch turned on is connected in bus mode, so that the master device with the physical switch turned on can send a firmware file to the slave device with the physical switch turned on through the single-pair Ethernet to perform firmware update on the slave device.
[0038] Optionally, the health management chip is connected to the PHY chip via a MAC port; the GPIO of the health management chip is used to control the switching state of the physical switch; and the MAC port is connected to the PHY chip via an RGMII interface.
[0039] Optionally, the health management chip is any one of BMC, CHMC and MCU.
[0040] Optionally, the same terminal includes a plurality of the devices, each of the devices is a terminal component capable of performing firmware upgrades, and the terminal is any one of a security terminal, a vehicle-mounted terminal, and a computer terminal.
[0041] In the technical solution of the present invention, each device is provided with a health management chip, which is connected to a PHY chip through the health management chip, and the PHY chip is connected to a physical switch, and the PHY chip and the physical switch are connected through a single pair of Ethernet. The physical switch is usually in a closed state. The various devices are also connected through a communication bus, and the command signals between the various devices are transmitted through the communication bus. At the same time, the master device sends the firmware file to the slave device that needs to update the firmware through a single pair of Ethernet, so the control flow and the data flow are split, and the out-of-band management of the cluster management system is realized. The master device sends the firmware file to the slave device through a single pair of Ethernet, which also realizes the rapid transmission of the firmware file and improves the firmware update rate. At the same time, when the firmware of the master device and the slave device fails, the management terminal can be used to control the master device to download the firmware file for updating from the cloud server, and the physical switches of the master device and the slave device to be updated can be turned on, so that the firmware file downloaded by the master device can be transmitted to the slave device that needs to update the firmware through a single pair of Ethernet channels. Therefore, the present invention can also overcome the disadvantage that the firmware update cannot be realized when the device firmware fails or the system crashes in the in-band management technology. The firmware update process in the present invention is controlled by the switch of the physical switch, which can effectively avoid illegal modification of the firmware content of the device in the unattended cluster management, making the firmware update process of the entire system safer. The entire process of the firmware upgrade in the present invention does not require on-site maintenance by technicians. When the firmware update instruction is triggered, a one-to-one connection between the master device and the slave device can be achieved for firmware update. Therefore, the technical solution of the present invention is conducive to solving the problem that the existing terminal firmware upgrade technology is not suitable for the scenario of unattended firmware upgrade of multiple devices. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] Figure 1 It is a hardware schematic diagram of each device in the present invention;
[0043] Figure 2 It is a schematic diagram of the working principle of the cluster management system in the present invention;
[0044] Figure 3 FIG. 1 is a flow chart of the platform firmware upgrade verification method in the first embodiment of the present invention.
[0045] The purpose, features and advantages of the present invention will be further described with reference to the accompanying drawings in conjunction with the embodiments. DETAILED DESCRIPTION
[0046] It should be understood that the specific embodiments described herein are only used to explain the present invention, and are not used to limit the present invention.
[0047] In the following description, suffixes such as "unit", "component" or "unit" used to represent elements are only used to facilitate the description of the present invention, and have no specific meanings. Therefore, "unit", "component" or "unit" can be used in a mixed manner.
[0048] See also Figures 1 to 3 To achieve the above-mentioned purpose, a platform firmware upgrade verification method is provided in a first embodiment of the present invention, which is applied to the cluster management system based on out-of-band management, wherein the cluster management system includes multiple devices, at least one of which is a master device, and the other devices are slave devices; the master device is respectively connected to a management terminal and a cloud server for communication; each of the devices includes a health management chip, a PHY chip and a physical switch connected in sequence; the PHY chip and the physical switch are connected via a single-pair Ethernet; the method includes the following steps:
[0049] Step S10, when a firmware update instruction is detected, the management terminal controls the master device to download a firmware file for update from the cloud server, and the management terminal sends a slave device identifier of the firmware to be updated to the master device;
[0050] Step S20, turning on the physical switch corresponding to the master device, and sending a firmware update instruction to the slave device whose firmware is to be updated through the communication bus, so as to turn on the physical switch corresponding to the slave device whose firmware is to be updated, thereby opening a single pair of Ethernet channels between the master device and the slave device whose firmware is to be updated;
[0051] Step S30: the master device sends the firmware file to the slave device whose firmware is to be updated through the single pair of Ethernet channels.
[0052] In the technical solution of the present invention, each device is provided with a health management chip, which is connected to a PHY chip through the health management chip, and the PHY chip is connected to a physical switch, and the PHY chip and the physical switch are connected through a single pair of Ethernet. The physical switch is usually in a closed state. The various devices are also connected through a communication bus, and the command signals between the various devices are transmitted through the communication bus. At the same time, the master device sends the firmware file to the slave device that needs to update the firmware through a single pair of Ethernet, so the control flow and the data flow are split, and the out-of-band management of the cluster management system is realized. The master device sends the firmware file to the slave device through a single pair of Ethernet, which also realizes the rapid transmission of the firmware file and improves the firmware update rate. At the same time, when the firmware of the master device and the slave device fails, the management terminal can be used to control the master device to download the firmware file for updating from the cloud server, and the physical switches of the master device and the slave device to be updated can be turned on, so that the firmware file downloaded by the master device can be transmitted to the slave device that needs to update the firmware through a single pair of Ethernet channels. Therefore, the present invention can also overcome the disadvantage that the firmware update cannot be realized when the device firmware fails or the system crashes in the in-band management technology. The firmware update process in the present invention is controlled by the switch of the physical switch, which can effectively avoid illegal modification of the firmware content of the device in the unattended cluster management, making the firmware update process of the entire system safer. The entire process of the firmware upgrade in the present invention does not require on-site maintenance by technicians. When the firmware update instruction is triggered, a one-to-one connection between the master device and the slave device can be achieved for firmware update. Therefore, the technical solution of the present invention is conducive to solving the problem that the existing terminal firmware upgrade technology is not suitable for the scenario of unattended firmware upgrade of multiple devices.
[0053] The slave device identification may be a slave device ID number or other identifier.
[0054] Based on the first embodiment of the platform firmware upgrade verification method of the present invention, in the second embodiment of the platform firmware upgrade verification method of the present invention, after step S30, the following steps are further included:
[0055] Step S40, after the slave device that receives the firmware file has been verified by the verification module, controls the corresponding health management chip to open the SPI (Serial Peripheral Interface) channel of the CPU module to write the firmware file into the FLASH chip, thereby realizing the firmware update of the slave device.
[0056] Specifically, the verification module may be a TPM module (Trusted Platform Module). The TPM module is a security chip installed inside a computer, and is mainly used to manage BIOS passwords, monitor underlying status or encryption, and prevent illegal access.
[0057] Specifically, after receiving the firmware file sent by the master device, the slave device in the present invention does not directly update the firmware, but after the verification module verifies that it is correct, the SPI channel of the CPU module is opened to write the firmware into the FLASH chip to complete the firmware update. When the verification module fails to pass the verification, a prompt to stop writing the firmware is issued, thereby avoiding illegal modification of the firmware content and effectively improving the security of the firmware update.
[0058] Specifically, the verification of the firmware file by the verification module may be verification of the verification code of the firmware.
[0059] Based on the first embodiment or the second embodiment of the platform firmware upgrade verification method of the present invention, in a third embodiment of the platform firmware upgrade verification method of the present invention, the method further includes:
[0060] Step S50, obtaining the operation information of each slave device;
[0061] Step S60: determining whether to trigger the firmware update instruction according to the operation information.
[0062] Specifically, in the firmware update function, the master device in the present invention has the function of receiving and sending the firmware file, while each slave device only has the function of receiving the firmware file.
[0063] In addition, each device reports its own operating information to the management terminal, and the management terminal determines whether to trigger a firmware update instruction for each device based on the operating information of each device.
[0064] The operation information includes: device health information, online and offline information, and firmware version number, etc. Through the operation information, you can find unstable symptoms of the device, such as frequent crashes, restarts, abnormal voltage, abnormal current, and abnormal fan speed.
[0065] Furthermore, the management terminal can also actively trigger a firmware update instruction when it is necessary to update the firmware of each slave device, for example, when a new firmware version is available, so as to update the firmware of the master device and the slave devices one by one.
[0066] Based on the third embodiment of the platform firmware upgrade verification method of the present invention, in a fourth embodiment of the platform firmware upgrade verification method of the present invention, step S60 includes:
[0067] Step S61, determining whether there is a slave device with firmware to be updated based on the operation information of each slave device; for example, when the operation information of each slave device is normal and there is no firmware version to be upgraded, it can be considered that there is no slave device with firmware to be updated.
[0068] Step S62, if the slave device whose firmware is to be updated exists, mark the slave device whose firmware is to be updated as a device to be updated, and obtain the slave device identifier corresponding to the device to be updated;
[0069] Step S63, determining the firmware update period of each of the devices to be updated, and forming a device firmware update sequence table according to the firmware update period of each of the devices to be updated;
[0070] Step S64, determining the firmware update time of each device to be updated according to the device firmware update sequence table;
[0071] Step S65, triggering the firmware update instruction to perform firmware update on each of the devices to be updated according to the device firmware update sequence table and the firmware update time.
[0072] Specifically, the firmware update period of each of the to-be-updated devices is used to limit the time interval during which the firmware update is allowed for each of the to-be-updated devices.
[0073] However, the time intervals for allowing firmware updates of various devices in the same terminal may overlap. In the present invention, the process of the master device sending the firmware file to the slave device is a one-to-one transmission process, and a large amount of system resources are occupied during the firmware update process. Therefore, in the present invention, only one device is allowed to perform firmware update within the same time period.
[0074] If the time intervals allowing firmware updates for multiple devices overlap, it is necessary to control each slave device to execute the firmware update in sequence to avoid multiple devices executing the firmware update at the same time.
[0075] Based on the fourth embodiment of the platform firmware upgrade verification method of the present invention, in a fifth embodiment of the platform firmware upgrade verification method of the present invention, step S63 includes:
[0076] Step S631, obtaining the load change of each device to be updated in a historical period, and taking the period when the load of each device to be updated is lower than a preset value as the firmware update period corresponding to each device to be updated;
[0077] Step S632, according to the operating information of each of the devices to be updated, sort the multiple devices to be updated whose firmware update periods overlap to obtain a sorting result; if the firmware update periods of some devices to be updated do not overlap, and the firmware update period reaches the set firmware update duration, the firmware of the device is directly updated in the firmware update period corresponding to these devices to be updated.
[0078] Step S633: forming a device firmware update sequence table according to the firmware update period corresponding to each of the to-be-updated devices and the sorting results corresponding to a plurality of the to-be-updated devices whose firmware update periods overlap.
[0079] Specifically, determine whether the multiple devices to be updated whose firmware update time periods overlap also have non-overlapping firmware update time periods, and whether the non-overlapping firmware update time periods reach the set firmware update duration. If so, perform firmware update on the devices to be updated in the non-overlapping firmware update time period of each of the devices to be updated.
[0080] If the firmware update period does not reach the set firmware update period, the firmware update period with the longest duration among the non-overlapping firmware update periods is selected for firmware update.
[0081] If there are no other non-overlapping firmware update periods for the devices to be updated, the following steps are performed to determine the firmware update sequence of the multiple devices to be updated whose firmware update periods overlap:
[0082] For the multiple devices to be updated whose firmware update periods overlap, the stability of the devices is obtained according to the operation information, and a first weight is obtained according to the stability, wherein the worse the operation stability is, the greater the first weight is assigned.
[0083] Furthermore, the present invention also sets a second weight for each device, and sets the expected upgrade order of each device through the second weight, wherein the device with a higher priority in the expected upgrade order has a larger second weight value;
[0084] For multiple devices to be updated whose firmware update periods overlap, they are sorted from large to small by the product of the first weight and the second weight, and the sorting result of the firmware update order of the multiple devices to be updated whose firmware update periods overlap is determined by sorting from large to small.
[0085] Based on the fourth embodiment or the fifth embodiment of the platform firmware upgrade verification method of the present invention, in the sixth embodiment of the platform firmware upgrade verification method of the present invention, the step S64 includes:
[0086] Step S641, obtaining the firmware update period corresponding to each of the to-be-updated devices in the device firmware update sequence table, and obtaining the set firmware update duration of each of the to-be-updated devices;
[0087] Step S642, determining the firmware update time of each device to be updated according to the firmware update period corresponding to each device to be updated and the set firmware update duration, wherein the firmware update times of the devices to be updated do not overlap.
[0088] For multiple devices to be updated whose firmware update periods overlap, after determining the sorting results of the devices to be updated, firmware update buffer time is reserved between the devices to be updated whose firmware update periods overlap based on the sorting results and the set firmware update duration of each device to be updated, thereby avoiding overlapping of the firmware update times of the devices to be updated.
[0089] Further, after detecting the firmware update instruction, the operation information of each device to be updated is monitored, and the alarm threshold of the health information of each device to be updated is adjusted according to the operation information of each device to be updated;
[0090] When the firmware update time of each device to be updated is reached, the health information of the device to be updated is detected (the health information includes parameters such as voltage, current, fan speed, etc. used to evaluate the current health status of the device to be updated) to see if it reaches the alarm threshold. When the health information does not reach the alarm threshold, the firmware of the device to be updated is updated.
[0091] See also Figure 1 to Figure 2 To achieve the above object, the present invention also provides a cluster management system based on out-of-band management, comprising a plurality of devices, wherein at least one of the devices is a master device and the rest of the devices are slave devices; the master device is respectively connected to a management terminal and a cloud server for communication; each of the devices comprises a health management chip, a PHY (Physical Layer Device) chip and a physical switch connected in sequence; the PHY chip and the physical switch are connected via a single pair of Ethernet;
[0092] The switch state of the physical switch is controlled by the health management chip;
[0093] The physical switch of the master device is turned on when there is a slave device whose firmware is to be updated, and each of the devices is connected via a communication bus, and the communication bus is used to transmit a firmware update instruction between the master device and the slave device, so that the slave device that receives the firmware update instruction turns on the corresponding physical switch;
[0094] The single-pair Ethernet of the device with the physical switch turned on is connected in bus mode, so that the master device with the physical switch turned on can send a firmware file to the slave device with the physical switch turned on through the single-pair Ethernet to perform firmware update on the slave device.
[0095] In the technical solution of the present invention, each device is provided with a health management chip, which is connected to a PHY chip through the health management chip, and the PHY chip is connected to a physical switch, and the PHY chip and the physical switch are connected through a single pair of Ethernet. The physical switch is usually in a closed state. The various devices are also connected through a communication bus, and the command signals between the various devices are transmitted through the communication bus. At the same time, the master device sends the firmware file to the slave device that needs to update the firmware through a single pair of Ethernet, so the control flow and the data flow are split, and the out-of-band management of the cluster management system is realized. The master device sends the firmware file to the slave device through a single pair of Ethernet, which also realizes the rapid transmission of the firmware file and improves the firmware update rate. At the same time, when the firmware of the master device and the slave device fails, the management terminal can be used to control the master device to download the firmware file for updating from the cloud server, and the physical switches of the master device and the slave device to be updated can be turned on, so that the firmware file downloaded by the master device can be transmitted to the slave device that needs to update the firmware through a single pair of Ethernet channels. Therefore, the present invention can also overcome the disadvantage that the firmware update cannot be realized when the device firmware fails or the system crashes in the in-band management technology. The firmware update process in the present invention is controlled by the switch of the physical switch, which can effectively avoid illegal modification of the firmware content of the device in the unattended cluster management, making the firmware update process of the entire system safer. The entire process of the firmware upgrade in the present invention does not require on-site maintenance by technicians. When the firmware update instruction is triggered, a one-to-one connection between the master device and the slave device can be achieved for firmware update. Therefore, the technical solution of the present invention is conducive to solving the problem that the existing terminal firmware upgrade technology is not suitable for the scenario of unattended firmware upgrade of multiple devices.
[0096] The PHY chip is connected to the physical switch via a single-pair Ethernet. Wherein, the device is each terminal component in a terminal (eg, a computer) that needs to be updated with firmware, for example, each device can be a board in the terminal.
[0097] The present invention adopts out-of-band management and uses a dedicated network management channel to achieve network management, ensuring that management data and business data are physically or logically separated.
[0098] SPE (Single Pair Ethernet) refers to Ethernet technology that implements data transmission through two wires. Its main technical features are that it can provide higher data transmission rates and sufficient power supply through fewer wires in a smaller physical size.
[0099] In the present invention, a single-pair Ethernet technology is used to form a network using the network ports of multiple devices under an out-of-band management system, and a solution for the management terminal to perform online firmware upgrades on each device. In addition to being able to achieve remote management and unattended operation of the device, the advantage of a single-pair Ethernet supporting 100M or even 1G Ethernet is also used to greatly improve the speed of firmware upgrades and the stability of information transmission. In addition, since the network is formed in an out-of-band system, the problem of being unable to restore or upgrade the firmware due to device firmware damage or operating system failure is also avoided.
[0100] In the present invention, in multiple device usage scenarios, each device is provided with a chip for health management, and the health management chip includes but is not limited to BMC (Baseboard Management Controller), CHMC (Chassis Management Controller) and one of the MCUs (Microcontroller Units) that implement the same function. Of course, the type of health management chip is not limited thereto, and elements that can implement the same function are similarly included in the protection scope of the present invention, for example, it can also be a software-defined management controller. These health management chips can monitor and manage the device through an out-of-band management system independent of the CPU module operating system. Since its management process is not performed through the CPU module operating system network interface, it can also be managed remotely when the system fails or the network is unavailable.
[0101] The hardware principle block diagram of each device in the present invention is as follows Figure 1 As shown. A PHY chip is added to the MAC port of the health management chip. A single Ethernet pair is connected in bus form between multiple PHYs. Each branch is switched on and off using a physical switch, and the control of the physical switch comes from the GPIO (General-Purpose Input / Output) of the health management chip.
[0102] The steps to implement the firmware update are:
[0103] The management terminal is connected to the shared network port of the master device through ordinary Ethernet (Internet). Through the system operation on the Web side, the master device downloads the firmware for update from the cloud server. At this time, the single-pair Ethernet branches of all slave devices are closed.
[0104] The slave device that needs to update its firmware is notified through the communication bus in the system, and the slave device opens its own single-pair Ethernet channel through the health management chip.
[0105] The master device sends the firmware file via a single Ethernet pair. Since only one branch is opened at this time, it can be sent to the slave device that needs to be updated. This is also the principle of achieving one master and multiple slaves on a single Ethernet pair without a routing device.
[0106] At the same time, in the present invention, by turning on the physical switch of the master device and the physical switch of the slave device, one-to-one data transmission between the master device and the slave device is achieved.
[0107] The communication bus may be an IPMI (Intelligent Platform Management Interface) bus.
[0108] Optionally, the health management chip is connected to the PHY chip via a MAC (Media Access Control) port; the GPIO of the health management chip is used to control the switching state of the physical switch; the MAC port and the PHY chip are connected via an RGMII interface (Reduced Gigabit Media Independent Interface).
[0109] Optionally, the health management chip is any one of BMC, CHMC and MCU.
[0110] Optionally, the same terminal includes a plurality of the devices, each of which is a terminal component capable of performing firmware upgrade, and the terminal is any one of a security terminal, a vehicle-mounted terminal, and a computer terminal. Of course, it may also be other terminals.
[0111] Specifically, a terminal includes a plurality of the devices, and the plurality of the devices of the same terminal are respectively connected to corresponding CPU modules.
[0112] Specifically, the cluster management system of the present invention can simultaneously manage multiple devices in one terminal, and can also manage multiple devices in different terminals.
[0113] When the cluster management system manages multiple devices of a terminal, at least one of the devices is a master device, and the remaining devices are slave devices.
[0114] When the cluster management system manages multiple devices in different terminals, each terminal includes multiple devices. Among the devices in each terminal, at least one device is a master device, and the remaining devices are slave devices.
[0115] Preferably, the device is a terminal component capable of performing firmware upgrade.
[0116] The terminal component includes at least one of a memory unit, a storage unit, different board units, and a functional module; the board unit can be one of a motherboard, a graphics card, a sound card, a storage device, a capture card, and a switch card, and its types are not limited thereto. All terminal components that may involve firmware updates are included in the protection scope of the present invention.
[0117] Furthermore, the master-slave mode configuration and physical switch on-off control of each device network are determined by the health management chip of the device.
[0118] Furthermore, the cluster management system of the present invention can be specifically applied to vehicle-mounted, security, computer and other terminals. In particular, vehicle-mounted and security terminals have a limited number of connections and limited connection space. At the same time, the connection method is not easy to flexibly adjust, and the reserved connection positions are limited. The technical solution of the present invention does not require large-scale improvement of the connection method, can be implemented in a smaller connection space, and only requires two wires to achieve a transmission rate of 100M or even 1G Ethernet. It has a wide range of application prospects, high stability, and strong scalability.
[0119] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus a necessary general hardware platform, and of course by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art can be embodied in the form of a software product, which is stored in a computer-readable storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above, and includes a number of instructions for enabling a terminal device to enter the method described in each embodiment of the present invention.
[0120] In the description of this specification, the description with reference to the terms "an embodiment", "another embodiment", "other embodiments", or "first embodiment to Xth embodiment" etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, method steps or characteristics described may be combined in any one or more embodiments or examples in a suitable manner.
[0121] It should be noted that, in this article, the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or system including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or system. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the existence of other identical elements in the process, method, article or system including the element.
[0122] The serial numbers of the above embodiments of the present invention are only for description and do not represent the advantages or disadvantages of the embodiments.
[0123] The above are only preferred embodiments of the present invention, and are not intended to limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made using the contents of the present invention specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.
Claims
1. A platform firmware upgrade verification method, characterized in that: Applied to a cluster management system based on out-of-band management, the cluster management system includes multiple devices, at least one of which is a master device, and the rest of the devices are slave devices; the master device is respectively connected to a management terminal and a cloud server for communication; each of the devices includes a health management chip, a PHY chip and a physical switch connected in sequence; the PHY chip and the physical switch are connected via a single-pair Ethernet; the method includes the following steps: When a firmware update instruction is detected, the management terminal controls the master device to download a firmware file for update from the cloud server, and the management terminal sends a slave device identifier of the firmware to be updated to the master device; Turning on the physical switch corresponding to the master device, and sending a firmware update instruction to the slave device whose firmware is to be updated through the communication bus, so as to turn on the physical switch corresponding to the slave device whose firmware is to be updated, thereby opening a single pair of Ethernet channels between the master device and the slave device whose firmware is to be updated; The master device sends a firmware file to the slave device whose firmware is to be updated through the single pair of Ethernet channels.
2. The platform firmware upgrade verification method according to claim 1, characterized in that: After the step of sending the firmware file to the slave device whose firmware is to be updated through the single pair of Ethernet channels, the method further includes: After the slave device that has received the firmware file has been verified by the verification module and is found to be correct, the corresponding health management chip is controlled to open the SPI channel of the CPU module so that the firmware file is written into the FLASH chip, thereby realizing the firmware update of the slave device.
3. The platform firmware upgrade verification method according to claim 1, characterized in that: The method further comprises: Obtaining operation information of each of the slave devices; According to the operation information, it is determined whether to trigger the firmware update instruction.
4. The platform firmware upgrade verification method according to claim 3, characterized in that: The step of determining whether to trigger the firmware update instruction according to the operation information includes: Determining whether there is a slave device whose firmware is to be updated according to the operation information of each of the slave devices; If the slave device with firmware to be updated exists, marking the slave device with firmware to be updated as a device to be updated, and obtaining the slave device identifier corresponding to the device to be updated; Determine a firmware update period for each of the devices to be updated, and form a device firmware update sequence table according to the firmware update period for each of the devices to be updated; Determining the firmware update time of each device to be updated according to the device firmware update sequence table; The firmware update instruction is triggered to perform firmware update on each of the devices to be updated according to the device firmware update sequence table and the firmware update time.
5. The platform firmware upgrade verification method according to claim 4, characterized in that: The step of determining the firmware update period of each device to be updated, and forming a device firmware update sequence table according to the firmware update period of each device to be updated, comprises: Obtaining the load change of each device to be updated in a historical period, and taking the period when the load of each device to be updated is lower than a preset value as the firmware update period corresponding to each device to be updated; According to the operation information of each of the devices to be updated, sorting the multiple devices to be updated whose firmware update periods overlap to obtain a sorting result; A device firmware update sequence table is formed according to the firmware update period corresponding to each of the to-be-updated devices and the sorting results corresponding to a plurality of the to-be-updated devices whose firmware update periods overlap.
6. The platform firmware upgrade verification method according to claim 4 or 5, characterized in that: The step of determining the firmware update time of each device to be updated according to the device firmware update sequence table comprises: Obtaining the firmware update period corresponding to each of the to-be-updated devices in the device firmware update sequence table, and obtaining the set firmware update duration of each of the to-be-updated devices; The firmware update time of each device to be updated is determined according to the firmware update period corresponding to each device to be updated and the set firmware update duration, wherein the firmware update times of the devices to be updated do not overlap.
7. A cluster management system based on out-of-band management, characterized in that: It includes multiple devices, at least one of which is a master device, and the rest of the devices are slave devices; the master device is respectively connected to the management terminal and the cloud server for communication; each of the devices includes a health management chip, a PHY chip and a physical switch connected in sequence; the PHY chip and the physical switch are connected via a single Ethernet pair; The switch state of the physical switch is controlled by the health management chip; The physical switch of the master device is turned on when there is a slave device whose firmware is to be updated, and each of the devices is connected via a communication bus, and the communication bus is used to transmit a firmware update instruction between the master device and the slave device, so that the slave device that receives the firmware update instruction turns on the corresponding physical switch; The single-pair Ethernet of the device with the physical switch turned on is connected in bus mode, so that the master device with the physical switch turned on can send a firmware file to the slave device with the physical switch turned on through the single-pair Ethernet to perform firmware update on the slave device.
8. The cluster management system based on out-of-band management according to claim 7, characterized in that: The health management chip is connected to the PHY chip via a MAC port; the GPIO of the health management chip is used to control the switching state of the physical switch; the MAC port and the PHY chip are connected via an RGMII interface.
9. The cluster management system based on out-of-band management according to claim 7, characterized in that: The health management chip is any one of BMC, CHMC and MCU.
10. The cluster management system based on out-of-band management according to any one of claims 7 to 9, characterized in that: The same terminal includes a plurality of the devices, each of which is a terminal component capable of performing firmware upgrades, and the terminal is any one of a security terminal, a vehicle-mounted terminal, and a computer terminal.
Citation Information
Patent Citations
Cluster computer device synchronous upgrade method
CN106685688A
Firmware upgrading control method and system for fast charging protocol and control terminal
CN110457055A
Firmware updating method of electronic equipment, chip, electronic equipment and storage medium
CN111666089A
Master-slave device communication system and method
CN113039546A
Remote data acquisition system based on single-pair Ethernet
CN113126551A