Method and system for safely updating BIOS firmware through redfish protocol

By performing comprehensive pre-checking and automatic switching of BIOS Flash locations during BIOS firmware update, combining high concurrent execution and real-time progress tracking, the risk of server downtime when the Redfish protocol updates the BIOS firmware is solved, and the security and reliability of the update are improved.

CN120017495AActive Publication Date: 2025-05-16POWERLEADER COMPUTER SYST CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510490060.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-18
Publication Date
2025-05-16
Estimated Expiration
2045-04-18

AI Technical Summary

Technical Problem

When updating the BIOS firmware through the Redfish protocol, the probability of the server being down is high, about 2%, resulting in data loss and service interruption, posing security risks.

Method used

A comprehensive pre-check mechanism is adopted, including hardware health status detection and firmware verification, automatic switching of BIOS Flash locations, high concurrent execution of update requests, real-time query of update progress, and health checks after the update is completed.

Benefits of technology

It significantly improves the security, reliability and efficiency of firmware updates, reduces the risk of failure during the update process, and ensures the stable operation of the server.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017495A_ABST
    Figure CN120017495A_ABST
Patent Text Reader

Abstract

The invention relates to a method and a system for safely updating BIOS (Basic Input / Output System) firmware through a redfish protocol. The method comprises the steps that a CSV file is configured to store a server information table needing to be updated; reading a configuration file, and performing parameter and configuration verification; state detection and BIOS Flash switching: detecting the health state of the server, checking the state of the BIOS Flash, and switching the BIOS Flash to a CPU (Central Processing Unit) when detecting that the BIOS is abnormal; requesting to update BIOS firmware, wherein the GO is used to execute the updated request in a high-concurrency manner; querying an update progress; detecting the position of the BIOS Flash again; when it is detected that the BIOS is abnormal, a BIOS Flash is switched to a CPU; and updating is completed. According to the method, verification modes exist before and after BIOS firmware updating, and high-performance concurrent firmware updating is achieved based on the golang language.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention relates to a method and a system for safely updating BIOS firmware through a redfish protocol, and belongs to the technical field of communications. Background Art

[0002] At present, server firmware updates mainly include BMC (Baseboard Management Controller), BIOS (Basic Input Output System) and CPLD (Complex Programmable Logic Device), and the Redfish protocol, as an emerging out-of-band management interface, provides a convenient way for firmware updates. Compared with the traditional method of updating firmware through the BMC web page, the Redfish interface has higher flexibility and automation, which can effectively reduce manual intervention and improve update efficiency.

[0003] However, in actual applications, updating BIOS firmware through the Redfish protocol also faces many challenges and risks. For example, when using tools such as Postman to update BIOS firmware through network requests, although the operation process is relatively simple, the probability of server downtime during the update process is high, about 2%. After analysis, the main reason is that the BIOS failed to switch to the CPU correctly during the update process, resulting in interruption of running services, which in turn caused the server to crash. This situation will not only lead to data loss and service interruption, but may also cause irreversible damage to the server's hardware, posing a huge security risk. Summary of the invention

[0004] The present invention provides a method and system for securely updating BIOS firmware through the redfish protocol, aiming to solve at least one of the technical problems existing in the prior art.

[0005] The technical solution of the present invention relates to a method for securely updating BIOS firmware through the redfish protocol in a dynamic scenario. The method according to the present invention comprises the following steps: S100, configuring a CSV file to store the server information table to be updated; S200, read the configuration file and perform parameter and configuration verification; S300, status detection and BIOS Flash switching, which includes the steps of: S310, detecting the health status of the server; S320, check the status of BIOS Flash; S330, when a BIOS abnormality is detected, switching the BIOS Flash to the CPU; S400, requesting to update the BIOS firmware; wherein the update request is executed with high concurrency using GO; S500, query update progress; S600, detecting the position of the BIOS Flash again; when a BIOS abnormality is detected, switching the BIOS Flash to the CPU; S700. Update completed.

[0006] Furthermore, in the step S100, the content of the server information table includes the BMC IP, the BMC user name and the BMC password, and the MD5 value used for verification.

[0007] Further, the step S200 includes: S210, determining update configuration parameters; S220, verify whether the IP is reachable; wherein, batch ping verification is performed through GP language to determine whether all BMCs can be connected; S230, verifying whether the updated firmware is correct; wherein, firstly pulling the remote image, and determining the integrity and correctness of the pulled image, and whether the remote image exists, through the MD5 value.

[0008] Furthermore, in step S320, the out-of-band ipmitool.exe tool is used to determine whether the BIOS Flash is in the CPU, and whether a switch is required.

[0009] Further, in step S330, Get the authentication parameters of the target server through the pre-configured ServerConfig structure, construct and execute the ipmitool command line tool call, which establishes a secure management connection by specifying the target IP address, using the secure LANplus protocol, and configuring the administrator username and password; The system triggers the server BIOS flash switching operation by sending a specific original command with a predefined vendor extended opcode and reserved parameter bits; During the command execution process, the system monitors the execution status in real time. When any error occurs, it immediately returns an exception message containing a detailed error description. When the command is successfully executed, it returns nil to indicate that the BIOS flash memory has been switched as expected.

[0010] Further, in step S400, Receive an array containing multiple server configuration parameters as input, establish a concurrency control mechanism by creating a synchronous wait group, and start an independent goroutine execution thread sequence for each server configuration. Each concurrent thread first declares the task start by incrementing the wait group counter, then calls the core updateBIOS function to perform the specific BIOS update operation, and ensures that the wait group counter is decremented when completed through the defer mechanism; During the update process, if an update error occurs on any server, a log message containing the server IP address and error details will be recorded. The main thread will block by waiting for the group synchronization primitive until all concurrent update tasks are completed.

[0011] Further, in step S500, In step S400, in the data returned by each function request, the task id corresponding to each IP is obtained, and the progress of the firmware update is queried based on this tasksid; wherein, the progress status of the firmware update includes Running indicating that the update is in progress and Completed indicating that the update is completed; the system continuously requests the return value of this interface through a timer until the value of Completed is obtained.

[0012] Further, the step S600 includes: S610, after the update is completed, check the BIOS status again; if the BIOS status returned is normal, jump directly to step S630; S620, switch Flash to CPU; S630, check the status of ME to see whether to exit Recovery mode; S640. If you have not exited, execute the ipmitool command to exit Recovery mode.

[0013] The technical solution of the present invention also relates to a computer-readable storage medium on which program instructions are stored, and the above-mentioned method is implemented when the program instructions are executed by a processor.

[0014] The technical solution of the present invention also relates to a system for securely updating BIOS firmware through the redfish protocol, wherein the system includes a computer device, and the computer device includes the above-mentioned computer-readable storage medium.

[0015] The beneficial effects of the present invention are as follows: The method and system for securely updating BIOS firmware through the Redfish protocol proposed in the present invention significantly improve the security, reliability and efficiency of firmware updates through comprehensive pre-checking mechanism, pre-pulling and verification of firmware images, automatic switching of BIOS Flash locations, high-concurrency execution, update progress tracking, and health checks after updates, effectively reducing the risk of failures during the update process and ensuring the stable operation of the server. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 It is a main flow chart of the method according to the present invention.

[0017] Figure 2 is an overall flow chart of the method according to the present invention. DETAILED DESCRIPTION

[0018] The concept, specific structure and technical effects of the present invention will be clearly and completely described below in combination with the embodiments and drawings to fully understand the purpose, scheme and effect of the present invention.

[0019] It should be noted that, unless otherwise specified, when a feature is referred to as being "fixed" or "connected" to another feature, it may be directly fixed or connected to another feature, or it may be indirectly fixed or connected to another feature. The singular forms "a", "said" and "the" used herein are also intended to include the plural forms, unless the context clearly indicates otherwise. In addition, unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art. The terms used in this specification are intended only to describe specific embodiments and are not intended to limit the invention. The term "and / or" used herein includes any combination of one or more of the related listed items.

[0020] It should be understood that, although the term first, second, third etc. may be adopted to describe various elements in the present disclosure, these elements should not be limited to these terms. These terms are only used to distinguish the same type of elements from each other. For example, without departing from the scope of the present disclosure, the first element may also be referred to as the second element, and similarly, the second element may also be referred to as the first element. The use of any and all examples or exemplary language ("for example", "such as" etc.) provided herein is only intended to better illustrate embodiments of the present invention, and unless otherwise required, will not impose limitations on the scope of the present invention.

[0021] Reference Figure 1 In some embodiments, the method for securely updating BIOS firmware through the redfish protocol according to the present invention includes at least the following steps: S100, configuring a CSV file to store the server information table to be updated; S200, read the configuration file and perform parameter and configuration verification; S300, status detection and BIOS Flash switching, which includes the steps of: S310, detecting the health status of the server; S320, check the status of BIOS Flash; S330, when a BIOS abnormality is detected, switching the BIOS Flash to the CPU; S400, requesting to update the BIOS firmware; wherein the update request is executed with high concurrency using GO; S500, query update progress; S600, detecting the position of the BIOS Flash again; when a BIOS abnormality is detected, switching the BIOS Flash to the CPU; S700. Update completed.

[0022] The method and system for securely updating BIOS firmware through the Redfish protocol proposed in the present invention significantly improve the security, reliability and efficiency of firmware updates through comprehensive pre-checking mechanism, pre-pulling and verification of firmware images, automatic switching of BIOS Flash locations, high-concurrency execution, update progress tracking, and health checks after updates, effectively reducing the risk of failures during the update process and ensuring the stable operation of the server.

[0023] Among them, the present invention proposes a comprehensive pre-check mechanism. This mechanism not only includes the verification of IP reachability to ensure smooth network connection between the update server and the target server, but also includes the inspection of hardware health status, such as the operating status of key hardware such as CPU, memory, hard disk, and firmware verification to ensure the integrity and compatibility of the firmware. This comprehensive pre-check mechanism is rarely seen in many automated update tools and can effectively reduce the risk of failure during the update process.

[0024] Before the firmware is updated, the present invention adopts a method of pre-pulling and verifying the firmware image to ensure that the updated firmware is the latest and complete. By interacting with the firmware server, the latest version information of the firmware is obtained, and the downloaded firmware image is verified, thereby avoiding the problem of firmware damage or version mismatch that may occur during the update process.

[0025] In order to increase the intelligence of the update process, the present invention is provided with a function of automatically switching the BIOS Flash position. Before updating, the system will check whether the BIOS Flash is located on the CPU. If not, it will try to automatically switch. This function can effectively avoid the update failure or server downtime caused by incorrect BIOS Flash position.

[0026] Among them, in terms of update execution, the present invention utilizes the high concurrency and high performance characteristics of the golang language to achieve concurrent update execution. This makes it possible to simultaneously update firmware on multiple servers in large-scale update scenarios, significantly improving update efficiency.

[0027] Among them, in order to grasp the update progress in real time, the present invention designs an update progress tracking function. By requesting the update progress in real time, the update status and connection status of each server can be clearly displayed, making the update process more transparent and controllable.

[0028] Among them, in order to ensure the normal operation of the updated server, the present invention performs a health check after the update. After the update is completed, the system will perform BIOS Flash location, ME status and other tests again to ensure that the status of all key hardware and firmware is normal. This series of checks is conducive to ensuring the normal operation of the server and effectively avoiding safety accidents such as downtime.

[0029] In some embodiments, referring to Table 1, the present invention first configures a CSV file for storing the server information table to be updated, including BMC IP, BMC user name and BMC password, etc., and the MD5 value to be verified.

[0030] Table 1 Server information table: BMC_IP BMC_Username BMC_Password MD5_Checksum 192.168.1.101 admin password1 9e107d9d372bb6826bd81d3542a419 192.168.1.102 admin password2 9e107d9d372bb6826bd81d3542a419 192.168.1.103 admin password3 9e107d9d372bb6826bd81d3542a419 In some embodiments, the verification of parameters and configurations of the present invention includes the steps of: S210, determining configuration parameters, wherein the configuration parameters include TransferProtocol: http / https / ftp; ImageURI: address of firmware update; ImageType: BIOS / BMC / CPLD; UpdateSelector: Flash1 / Flash2 / ImageBoth, etc.

[0031] S220, verify whether the IP is reachable. It implements batch ping verification through the Go language to determine whether all BMCs can be connected.

[0032] S230, verify whether the updated firmware is correct. The present invention first pulls the remote image, and determines the integrity and correctness of the pulled image and whether the remote image exists through the md5 value.

[0033] Specifically, when determining the configuration parameters, the present invention pre-configures a JSON format configuration file (see Table 1) containing a transmission protocol type, image file location information, image type, and update strategy, wherein the transmission protocol type is explicitly specified as the HTTP protocol, the image file location information is configured as a uniform resource identifier in a set format through the ImageURI field, the image type field ImageType is explicitly defined as BIOS type firmware, and the update strategy field UpdateSelector is set to "ImageBoth" to indicate the execution of a dual image update mode.

[0034] Furthermore, when verifying whether the IP is reachable, the present invention imports the operating system command execution module to construct a checkNetworkConnectivity function containing a target IP address parameter, creates a process instance for executing the ping command within the function, and configures it to send only a single probe data packet ("-c 1" parameter) to the target IP address, then synchronously executes the process and captures its return value. If and only if the process execution returns an error flag of nil, the network node corresponding to the IP address is determined to be reachable, and the Boolean detection result is output as the function return value, thereby achieving the technical effect of quickly verifying the connectivity of network nodes without relying on the network protocol stack.

[0035] Furthermore, when verifying whether the firmware update is correct, first preset the download address URL of the target BIOS file and the expected MD5 checksum; then initiate an HTTP request through the http.Get() method to obtain the BIOS file. If a network error occurs during the request, the process is terminated immediately and an error message is output. After successfully establishing a connection, the system will continue to monitor the HTTP response status code. When the status code is not 200, the download will be terminated and an abnormal state will be returned; after receiving the data stream normally, the system automatically creates a temporary file with the prefix "bios-update-" locally to store the downloaded content, and initializes the MD5 hash calculator at the same time. The input data stream is written to the temporary file storage area and the hash calculator at the same time through io.MultiWriter for real-time verification calculation.

[0036] See also Figure 1 and Figure 2 In some embodiments, the health detection of the present invention comprises the steps of: S310, check the health status of the server. The present invention uses an out-of-band ipmitool sensor to check the health status of the hardware to ensure that the voltage, temperature, etc. are normal. The system can only perform the BIOS firmware update operation if these parameters are normal.

[0037] S320, check the status of BIOS Flash. The present invention uses the out-of-band ipmitool.exe tool to determine whether BIOS Flash is in the CPU and decide whether it needs to be switched. If the return value in the CPU is 0x0, it is considered that the BIOS works normally and can be updated. If not, it will try to switch it to the CPU.

[0038] S330, switch BIOS Flash to CPU (normally skipped). If the IP is not in the CPU during the verification of whether it is reachable in step S220, the system needs to try to switch the Flash to the CPU, and then synchronously wait to detect the current BIOS Flash status, repeat multiple times, and continue to execute if it can be switched back, otherwise it will report an error.

[0039] Specifically, when detecting the health status of the server, the present invention obtains the connection parameters such as the IP address of the target server through the pre-configured ServerConfig structure, builds and executes the ipmitool command line tool call, wherein the target server IP address is specified through the "-H" parameter, the "-I lanplus" parameter forces the use of the secure LANplus protocol, and the "-U" parameter configures the login user name; the system synchronously captures the command execution output results and execution error information, and immediately determines that the system health check fails and returns a false value when a command execution error occurs or the output content is empty; for the normal output detection results, the system matches the key status words through the containsCritical function, and when the output content does not contain the "critical" keyword, it determines that the server hardware status is normal and returns a true value, otherwise it determines that there is a serious hardware failure.

[0040] Furthermore, when checking the status of BIOS Flash, the present invention obtains the IP address, user name, password and other authentication parameters of the target server through the pre-configured ServerConfig structure, constructs and executes the ipmitool command line tool call, wherein the target server management interface address is specified by the "-H" parameter, the "-I lanplus" parameter specifies the use of the secure LANplus communication protocol, and the "-U" and "-P" parameters respectively configure the authorized administrator account and the corresponding password; the system sends a custom manufacturer extension command through the "raw 0x3A" instruction, and attaches the "email emo" operation code to query the BIOS flashing status; the command output results and error information are synchronously captured during the execution process, and when a command execution error occurs or the output content is a "00" status code, it is determined that the BIOS flashing operation is not ready and returns false, otherwise when a valid response other than "00" is received, it is determined that the BIOS is in a flashable state and returns true.

[0041] Furthermore, when switching BIOS Flash to CPU, the present invention obtains the network address, authentication credentials and other authentication parameters of the target server through the preconfigured ServerConfig structure, constructs and executes the ipmitool command line tool call, wherein a secure management connection is established by specifying the target IP address (-H parameter), adopting the secure LANplus protocol (-I parameter), and configuring the administrator username and password (-U and -P parameters); the system triggers the server BIOS flash switching operation by sending a specific raw command (raw 0x3A) in conjunction with a predefined vendor extended opcode (0x32) and a reserved parameter bit (o___); during the command execution process, the system monitors the execution status in real time, and immediately returns an exception message containing a detailed error description when any error occurs, and returns nil for successful execution to indicate that the BIOS flash has been switched as expected.

[0042] In some embodiments, when the present invention requests to update the BIOS firmware, the high performance and concurrency of GO are utilized to concurrently execute the update requests. The logic and functions of the update function executed with high concurrency are shown below.

[0043] Specifically, see Figure 2, the present invention receives an array containing multiple server configuration parameters as input, establishes a concurrency control mechanism by creating a sync.WaitGroup, starts an independent goroutine execution sequence for each server configuration, and each concurrent thread first declares the start of the task by incrementing the wait group counter (Add method), then calls the core updateBIOS function to perform the specific BIOS update operation, and ensures that the wait group counter is decremented (Done method) through the defer mechanism when completed; during the update process, when any server encounters an update error, log information containing the IP address of the server and error details will be recorded, and the main thread blocks through the wait group synchronization primitive (Wait method) until all concurrent update tasks are completed, thereby realizing the parallel and secure update of the BIOS versions of multiple servers and significantly improving the firmware maintenance efficiency of large-scale server clusters.

[0044] Furthermore, the IP address, authentication information, and firmware download link of the target server are obtained through the configuration parameters, and an HTTPS request conforming to the Redfish RESTful interface specification is constructed, where the target URL is formatted as a standard endpoint of "https: / / <IP address> / redfish / v1 / Updateservice / action / SimpleUpdate"; the request body is encapsulated in JSON format and contains key parameters such as the transport protocol type specified as HTTP, the firmware image URI pointing to the configured download link, and the image type clearly identified as the BIOS type; the system serializes the structured data into a JSON payload through the json.Marshal method, creates a POST request with a basic authentication header (including the administrator username and password), and hands it over to the default HTTP client for execution; after receiving the response, the system first checks the HTTP status code. When the status code is not 200, an update failure message containing the specific error status code is returned, while a successful response confirms that the BIOS update instruction has been received and processed by the server, thereby realizing an automated, secure, and reliable remote BIOS update operation based on industry standard protocols.

[0045] In some embodiments, referring to Figure 2 , when the present invention queries the update progress, when requesting the data returned by each function in step S400, a task id corresponding to an IP can be obtained, and the firmware update progress can be queried through this task id. The progress status generally has two states: Running (indicating that the update is in progress) and Completed (indicating that the update is completed). The system can request this interface in the form of a timer and finally obtain the value of Completed.

[0046] Specifically, the present invention first constructs an HTTP request header containing an authentication token and generates a target URL address, and then starts a timed polling process, initiating a GET request to the server every 2 seconds to obtain task status information. After receiving the response, the system automatically parses the response data in JSON format, extracts the TaskState and TaskStatus fields therein for joint judgment: if it is detected that the task is in a running state (TaskState is "Running" and TaskStatus is "OK"), the polling continues; when the task completion state is identified (TaskState is "Completed" and TaskStatus is "OK"), the system immediately terminates the polling and outputs the completion state as a keyword; if an exception occurs during the request initiation, response reading or data parsing process, or the task status does not meet expectations, the process is immediately interrupted and a null value is returned.

[0047] In some embodiments, see Figure 2 The present invention performs BIOS Flash position detection including the steps of: S610, after the update is completed, the BIOS status is detected again. Specifically, if the returned result shows that it is in place, that is, the BIOS status is normal, then proceed to step S630 to detect the status of the ME.

[0048] S620, switch Flash to CPU (if not in place).

[0049] S630: Check the status of ME to determine whether to exit Recovery mode.

[0050] S640. If you have not exited, execute the ipmitool command to exit Recovery mode.

[0051] Specifically, when the BIOS status is detected again after the update is completed, the present invention sends a preset original command (0x3A emil wmap) to the target server through the IPMITOOL tool. The command establishes a secure connection with the server through the LANPLUS interface protocol, and uses the IP address, user name and password stored in the configuration file for authentication during the connection; the system captures the output result after the command is executed and performs a status judgment. When the output result is "00" or an error occurs in the command execution, the BIOS flash memory status is determined to be abnormal and false is returned, otherwise the BIOS flash memory status is determined to be normal and true is returned.

[0052] Furthermore, when it is necessary to switch Flash to CPU, the system of the present invention first constructs an IPMITool command line instruction, which includes the network address of the target server (-H parameter), the LANPlus interface type (-I parameter), and the user name (-U parameter) and password (-P parameter) required for authentication. In the main body of the instruction, the specific hexadecimal code "0x3A 0x32" is directly sent to the baseboard management controller through the "raw" command, and two "0x00" parameters are attached as operation identifiers. After executing the command, the baseboard management controller will activate the switching process of the backup BIOS Flash chip. If an error occurs during the execution of the command, the system will capture the exception and return an error message containing a prompt of "failed to switch BIOS Flash", otherwise a normal return indicates that the switching instruction has been successfully sent to the remote server.

[0053] Furthermore, when checking the status of ME, the system of the present invention constructs an IPMITool command line instruction including the target server network address (-H parameter), LANPlus interface type (-I parameter), authentication information (-U and -P parameters), and specifies the bridge request (-b6 parameter) and the target device address (-t 0x2c parameter). The management engine status data is requested from the baseboard management controller by sending the original command "raw 0x6 0x4". After the system captures the command output, the blank characters at the beginning and end of the string are first removed, and then the string is split into a status byte array by space. By comparing the status byte with the preset value, it is determined whether the management engine is in recovery mode: when the output is "%0 %3", it is determined to have exited the recovery mode, and when the output is "%1 %2", it is determined to be still in recovery mode. For output that does not conform to the expected format, the system returns an unknown status error.

[0054] Furthermore, when the ipmitool command is executed to exit the Recovery mode, the present invention remotely controls the server management engine to exit the Recovery mode through the IPMI protocol. Specifically, the system constructs an IPMITool command line instruction, which includes the network address of the target server (-H parameter), the LANPlus interface type (-I parameter), the user name (-U parameter) and password (-P parameter) required for authentication, and specifies the bridge request (-b6 parameter) and the target device address (-t 0x2c parameter). The instruction to exit the Recovery mode is sent to the baseboard management controller by sending the original command "raw 0x6 0x2". After the system executes the command, if no error is returned, it indicates that the instruction to exit the Recovery mode has been successfully sent to the server management engine, and the prompt message "Attempted to exit ME Recovery mode" is output; if an error occurs during the execution process, an error message containing the prompt "Failed to exit ME Recovery mode" is returned.

[0055] Finally, wait for all configuration information in the imported CSV file to successfully update the BIOS and the program ends.

[0056] The server firmware intelligent update method provided by the present invention significantly improves the security and reliability of firmware updates through a number of innovative technologies. In the pre-check stage, the system not only verifies IP reachability, but also innovatively adds hardware health status diagnosis and firmware integrity verification, eliminating update failures caused by hardware abnormalities or firmware mismatches from the source. In response to the 2% downtime problem in the traditional method, the system automatically detects the BIOS Flash location before updating, and immediately triggers the switching mechanism when it is found that the CPU is not connected. This key technology completely eliminates the risk of business interruption caused by improper Flash location. In the update execution link, the system uses the high concurrency characteristics of the Go language to achieve large-scale parallel updates, which can effectively improve the update efficiency in the environment of thousands of servers, and provide a visual monitoring interface for operation and maintenance personnel through the real-time progress tracking function. After the update is completed, the system automatically performs a secondary health check, and performs 100% verification of key indicators such as the BIOS Flash location and ME status to ensure that the server is fully restored to normal. According to actual verification, the solution can significantly reduce or even eliminate the update downtime rate, and supports breakpoint continuation and abnormal automatic recovery functions, which significantly improves the intelligence level of data center operation and maintenance, and provides a safe and reliable firmware update solution for large-scale server clusters.

[0057] It should be appreciated that the method steps in the embodiments of the present invention can be implemented or implemented by computer hardware, a combination of hardware and software, or by computer instructions stored in a non-transitory computer readable memory. The method can use standard programming techniques. Each program can be implemented in a high-level process or object-oriented programming language to communicate with a computer system. However, if necessary, the program can be implemented in an assembly or machine language. In any case, the language can be a compiled or interpreted language. In addition, the program can be run on a programmed ASIC for this purpose.

[0058] In addition, the operations of the processes described herein may be performed in any suitable order unless otherwise indicated herein or otherwise clearly contradicted by context. The processes described herein (or variations and / or combinations thereof) may be performed under the control of one or more computer systems configured with executable instructions, and may be implemented as code (e.g., executable instructions, one or more computer programs, or one or more applications) that is executed collectively on one or more processors, by hardware, or a combination thereof. The computer program includes a plurality of instructions that may be executed by one or more processors.

[0059] Further, the method can be implemented in any type of computing platform that is operably connected to a suitable computer, including but not limited to a personal computer, a minicomputer, a mainframe, a workstation, a network or distributed computing environment, a separate or integrated computer platform, or in communication with a charged particle tool or other imaging device, etc. Various aspects of the present invention can be implemented in machine-readable code stored on a non-transitory storage medium or device, whether removable or integrated into a computing platform, such as a hard disk, an optical read and / or write storage medium, an RSM, a ROM, etc., so that it can be read by a programmable computer, and when the storage medium or device is read by the computer, it can be used to configure and operate the computer to perform the process described herein. In addition, the machine-readable code, or portions thereof, can be transmitted via a wired or wireless network. When such media includes instructions or programs that implement the steps described above in conjunction with a microprocessor or other data processor, the invention described herein includes these and other different types of non-transitory computer-readable storage media. When programmed according to the methods and techniques of the present invention, the present invention can also include the computer itself.

[0060] The computer program can be applied to input data to perform the functions described herein, thereby converting the input data to generate output data stored in a non-volatile memory. The output information can also be applied to one or more output devices such as a display. In a preferred embodiment of the present invention, the converted data represents physical and tangible objects, including specific visual depictions of physical and tangible objects produced on the display.

[0061] The above is only a preferred embodiment of the present invention. The present invention is not limited to the above implementation. As long as the technical effect of the present invention is achieved by the same means, any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the scope of protection of the present invention. Within the scope of protection of the present invention, its technical scheme and / or implementation method may have various modifications and changes.

Claims

1. A method for securely updating BIOS firmware via the redfish protocol, characterized in that: The method comprises the following steps: S100, configuring a CSV file to store the server information table to be updated; S200, read the configuration file and perform parameter and configuration verification; S300, status detection and BIOS Flash switching, which includes the steps of: S310, detecting the health status of the server; S320, check the status of BIOS Flash; S330, when a BIOS abnormality is detected, switching the BIOS Flash to the CPU; S400, requesting to update the BIOS firmware; wherein Go is used to execute the update request with high concurrency; S500, query update progress; S600, detecting the position of the BIOS Flash again; when a BIOS abnormality is detected, switching the BIOS Flash to the CPU; S700. Update completed.

2. The method according to claim 1, characterized in that In the step S100, the content of the server information table includes the BMC IP, the BMC user name and the BMC password, and the MD5 value used for verification.

3. The method according to claim 1, characterized in that The step S200 includes: S210, determining update configuration parameters; S220, verify whether the IP is reachable; wherein, batch ping verification is performed through the Go language to determine whether all BMCs can be connected; S230, verifying whether the updated firmware is correct; wherein, firstly pulling the remote image, and determining the integrity and correctness of the pulled image, and whether the remote image exists, through the MD5 value.

4. The method according to claim 1, characterized in that: In step S320, the out-of-band ipmitool.exe tool is used to determine whether the BIOS Flash is in the CPU, and whether switching is required.

5. The method according to claim 4, characterized in that In the step S330, Get the authentication parameters of the target server through the pre-configured ServerConfig structure, construct and execute the ipmitool command line tool call, which establishes a secure management connection by specifying the target IP address, using the secure LANplus protocol, and configuring the administrator username and password; The system triggers the server BIOS flash switching operation by sending a specific original command with a predefined vendor extended opcode and reserved parameter bits; During the command execution process, the system monitors the execution status in real time. When any error occurs, it immediately returns an exception message containing a detailed error description. When the command is successfully executed, it returns nil to indicate that the BIOS flash memory has been switched as expected.

6. The method according to claim 1, characterized in that In the step S400, Receive an array containing multiple server configuration parameters as input, establish a concurrency control mechanism by creating a synchronous wait group, and start an independent goroutine execution thread sequence for each server configuration. Each concurrent thread first declares the task start by incrementing the wait group counter, then calls the core updateBIOS function to perform the specific BIOS update operation, and ensures that the wait group counter is decremented when completed through the defer mechanism; During the update process, if an update error occurs on any server, a log message containing the server IP address and error details will be recorded. The main thread will block by waiting for the group synchronization primitive until all concurrent update tasks are completed.

7. The method according to claim 6, characterized in that In step S500, In step S400, the task id corresponding to each IP is obtained from the data returned by each function, and the progress of the firmware update is queried based on the task id; wherein the progress status of the firmware update includes Running, which indicates that the update is in progress, and Completed, which indicates that the update is completed; the system continuously requests the return value of this interface through a timer until the value of Completed is obtained.

8. The method according to claim 7, characterized in that The step S600 includes: S610, after the update is completed, check the BIOS status again; if the BIOS status returned is normal, jump directly to step S630; S620, switch Flash to CPU; S630, check the status of ME to see whether to exit Recovery mode; S640. If you have not exited, execute the ipmitool command to exit Recovery mode.

9. A computer-readable storage medium, characterized in that: Program instructions are stored thereon, and when the program instructions are executed by a processor, the method according to any one of claims 1 to 8 is implemented.

10. A system for securely updating BIOS firmware via the redfish protocol, characterized in that: include: A computer device comprising a computer readable storage medium according to claim 9.

Citation Information

Patent Citations

  • Basic input and output system firmware updating method, device, equipment and medium

    CN116679962A

  • Method and device for online updating target area of server platform service firmware

    CN117289963A

  • Upgrading method and device of basic input and output system and storage medium

    CN118349262A

  • Server firmware fault reproduction method and device and medium

    CN118519808A

  • Firmware variable update method

    US20160179500A1