Method for repairing firmware storage area of baseboard management controller
By separating a second recovery area in the server's flash memory that is read-only by default and switching to read-write mode when it cannot pass other recovery paths, the problem that the firmware storage area of the substrate management controller is damaged at the same time in DoS attacks is solved, and the normal operation of the server is achieved.
Patent Information
- Application Number
- CN202311779539.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-21
- Publication Date
- 2025-06-24
AI Technical Summary
In DoS attacks, the firmware storage area in the server's substrate management controller may be damaged simultaneously, resulting in the inability to repair through the existing PFR recovery mechanism.
By separating a second restore area in the flash memory that is defaulted to read-only mode, and under the control of the programmable logic device, when it is impossible to recover through the first restore area and the temporary storage area, the second restore area is switched to the read-write mode, and the current area is restored.
Ensure that the firmware storage area of the substrate management controller can still be restored through the second recovery area when all other recovery paths fail, ensuring the normal operation of the server.
Smart Images

Figure CN120197172A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method for repairing a firmware storage area, and particularly to a method for repairing a firmware storage area of a baseboard management controller. Background Art
[0002] A server may be maliciously attacked by hackers to prevent the server from operating properly. Among them, one of the common attack methods is a denial-of-service attack (hereinafter referred to as a DoS attack). In a DoS attack, a hacker may replace the image file in the baseboard management controller (hereinafter referred to as BMC) in the server with a damaged image file to paralyze the server.
[0003] The platform firmware resilience (hereinafter referred to as PFR) of the server can protect the image file from unauthorized modification by detecting whether the firmware and key data are damaged, and recover the damaged image file from a good image file when necessary, thereby providing resilience for the firmware image file.
[0004] When the server is initially powered on, PFR enters the pre-boot environment, that is, the T-1 mode. In the T-1 mode, all other firmware with possible startup interfaces (platform path controller, central processing unit, BMC, etc.) are in the reset state, and only the programmable logic device (hereinafter referred to as PLD) is powered on and started. The PFR CPLD first verifies the BMC memory (FLASH). If the verification fails, it means that the image file stored in this area is damaged and is regarded as a bad area. Then the PFR CPLD will erase the bad area where the verification fails and use the firmware image file to restore the memory data. If the verification is successful, it will enter the normal startup mode of Boot guard, and then it is the T0 mode.
[0005] In the existing PFR security architecture, the memory used by the BMC includes an active area, a recovery area, and a staging area. The active area stores the uncompressed and directly executable firmware, the recovery area stores the compressed backup file, and the staging area is a temporary buffer for upgrading.
[0006] If only the current area is a bad area, the current area can be restored by the restoration area. If only the restoration area is a bad area, the restoration area can be restored by the temporary storage area. If only the temporary storage area is a bad area, it is regarded as being in the correct operating state, and whether the temporary storage area is a bad area can be ignored without any action required.
[0007] If the current area and the temporary storage area are damaged simultaneously, the PFR CPLD can restore the damage of the current area by the restoration area and can ignore whether the temporary storage area is damaged. If the current area and the restoration area are damaged simultaneously, it is a serious platform error. The PFR CPLD can restore the damage of the restoration area by the temporary storage area and then restore the damage of the current area by the restoration area. If the restoration area and the temporary storage area are damaged simultaneously, it is a serious platform error. The PFR CPLD allows the BMC to start with the current area, but restricts the update of the current area and requires providing the update of the restoration area.
[0008] However, if the current area, the restoration area, and the temporary storage area are damaged simultaneously, they cannot be restored by the PFR CPLD. Summary of the Invention
[0009] Therefore, an object of the present invention is to provide a method for repairing a substrate management controller firmware storage area.
[0010] Then, the method for repairing the substrate management controller firmware storage area of the present invention is executed by a computer device. The computer device includes a substrate management controller, a programmable logic device electrically connected to the substrate management controller, and a flash memory electrically connected to the substrate management controller and the programmable logic device. The flash memory has a current area, a first restoration area, and a temporary storage area. The current area, the first restoration area, and the temporary storage area store a first firmware image related to the substrate management controller. The method includes a step (A), a step (B), a step (C), a step (D), a step (E), and a step (F).
[0011] In this step (A), the baseboard management controller divides a second recovery area in the flash memory. The second recovery area stores a second firmware image related to the baseboard management controller. The second recovery area can be switched between a read-only mode and a read-write mode, and the second recovery area defaults to the read-only mode. In this step (B), the programmable logic device detects whether the baseboard management controller is operating normally. In this step (C), when it is detected that the baseboard management controller is operating abnormally, it means that the current area is a bad area. The programmable logic device determines whether the first recovery area and the temporary storage area of the flash memory are bad areas. In this step (D), when it is determined that both the first recovery area and the temporary storage area are bad areas, the programmable logic device generates and sends an unlock instruction to the baseboard management controller to cause the baseboard management controller to switch the second recovery area of the flash memory to the read-write mode. In this step (E), the programmable logic device restores the current area according to the second recovery area. In this step (F), the programmable logic device generates and sends a lock instruction to the baseboard management controller to cause the baseboard management controller to switch the second recovery area of the flash memory to the read-only mode.
[0012] Specifically, the programmable logic device is electrically connected to the baseboard management controller via a general-purpose input / output pin. Wherein, in step (B), the programmable logic device determines whether the general-purpose input / output pin is at a high potential to determine whether the baseboard management controller is operating normally. When the programmable logic device determines that the general-purpose input / output pin is at a high potential, it determines that the baseboard management controller is operating abnormally. When the programmable logic device determines that the general-purpose input / output pin is at a low potential, it determines that the baseboard management controller is operating normally.
[0013] Specifically, the programmable logic device is via a system management bus. Wherein, in step (B), the programmable logic device issues a poll via the system management bus and determines whether a response from the baseboard management controller has not been received after the number of polls reaches a threshold to determine whether the baseboard management controller is operating normally. When the programmable logic device determines that a response from the baseboard management controller has not been received after the number of polls reaches the threshold, it determines that the baseboard management controller is operating abnormally. When the programmable logic device determines that a response from the baseboard management controller has been received before the number of polls reaches the threshold, it determines that the baseboard management controller is operating normally.
[0014] Specifically, step (C) includes the following steps: (C-1) The programmable logic device determines whether the temporary storage area is a bad area, and (C-2) when it is determined that the temporary storage area is a bad area, the programmable logic device determines whether the first recovery area is a bad area. When it is determined that the first recovery area is a bad area, step (D) is performed.
[0015] In particular, step (C) further includes the following steps: (C-3) When it is determined that the temporary storage area is not a bad area, the programmable logic device copies the temporary storage area to the first recovery area, and (C-4) the programmable logic device decompresses the first recovery area to the active area.
[0016] In particular, step (C) further includes the following steps: (C-5) When it is determined that the first recovery area is not a bad area, the programmable logic device decompresses the first recovery area to the active area.
[0017] In particular, the programmable logic device stores a first hash value related to the temporary storage area and a second hash value related to the first recovery area. The temporary storage area included in the flash memory also stores a temporary storage area hash value, and the first recovery area also stores a recovery area hash value. Among them, in step (C-1), the programmable logic device compares the first hash value with the temporary storage area hash value to determine whether the temporary storage area is a bad area. When it is compared that the first hash value is different from the temporary storage area hash value, the programmable logic device determines that the temporary storage area is a bad area. When it is compared that the first hash value is the same as the temporary storage area hash value, the programmable logic device determines that the temporary storage area is not a bad area. In step (C-2), the programmable logic device compares the second hash value with the recovery area hash value to determine whether the first recovery area is a bad area. When it is compared that the second hash value is different from the recovery area hash value, the programmable logic device determines that the first recovery area is a bad area. When it is compared that the second hash value is the same as the recovery area hash value, the programmable logic device determines that the first recovery area is not a bad area.
[0018] In particular, the programmable logic device stores a first set value. Among them, in step (A), the second recovery area of the flash memory also stores a second set value. In step (D), the unlock instruction includes the first set value, so that when the baseboard management controller compares the first set value with the second set value and they are the same, the second recovery area is switched to the read / write mode.
[0019] In particular, the first set value is the sum of each bit of a media access control address of the baseboard management controller.
[0020] In particular, in step (A), the second firmware image stored in the second recovery area is a different version from the first firmware image.
[0021] Compared with the prior art, the method for repairing the firmware storage area of the baseboard management controller of the present invention allows the baseboard management controller to divide a second recovery area defaulting to the read-only mode in the flash memory to ensure that the second recovery area is not infringed. When both the first recovery area and the temporary storage area are bad areas, that is, when recovery cannot be performed by PFR, the programmable logic device restores the current use area according to the second recovery area to ensure the normal use of the baseboard management controller. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] Other features and effects of the present invention will be clearly presented in the embodiments with reference to the accompanying drawings, wherein:
[0023] Figure 1 is a block diagram illustrating a computer device for implementing an embodiment of the method for repairing the firmware storage area of the baseboard management controller of the present invention; and
[0024] Figure 2 is a flowchart illustrating the embodiment of the method for repairing the firmware storage area of the baseboard management controller of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0025] Before the present invention is described in detail, it should be noted that in the following description, similar elements are denoted by the same reference numerals.
[0026] Refer to Figure 1 , which illustrates a computer device 1 for implementing the method for repairing the firmware storage area of the baseboard management controller of the present invention, including a flash memory 11, a multiplexer (MUX) 12, a programmable logic device (PLD) 13, and a baseboard management controller 14.
[0027] The flash memory 11 is used by the baseboard management controller 14 and has a current use area 111, a first recovery area 112, and a temporary storage area 113. The current use area 111, the first recovery area 112, and the temporary storage area 113 store a first firmware image related to the baseboard management controller 14. The temporary storage area 113 also stores a temporary storage area hash value, and the first recovery area 112 also stores a recovery area hash value.
[0028] The multiplexer 12 is electrically connected to the flash memory 11, the programmable logic device 13, and the baseboard management controller 14 via a serial peripheral interface bus (SPI) 100.
[0029] The programmable logic device 13 is electrically connected to the baseboard management controller 14 via a general-purpose input / output (GPIO) pin 101 and a system management bus (SMBus) 102. The programmable logic device 13 stores a first hash value related to the temporary area 113, a second hash value related to the first recovery area 112, and a first setting value.
[0030] It should be noted that, in this embodiment, the computer device 1 is, for example, a server, and the programmable logic device 13 is, for example, a field programmable gate array (FPGA). In other embodiments, the programmable logic device 13 may also be a complex programmable logic device (CPLD), which is not limited thereto.
[0031] It should be particularly noted that the first setting value is the sum of each bit of a media access control (MAC) address of the baseboard management controller 14. For example, the media access control address of the baseboard management controller 14 is 4C38D5223AA0. If the sum is calculated in hexadecimal, 0x04 + 0x0C + 0x03 + 0x08 + 0x0D + 0x05 + 0x02 + 0x02 + 0x03 + 0x0A + 0x0A + 0x00, then the first setting value is 0x48.
[0032] Refer to Figure 1 、 2 , an embodiment of the method for repairing the firmware storage area of the baseboard management controller 14 of the present invention will be described below in terms of the steps included in this embodiment.
[0033] In step 21, the baseboard management controller 14 divides a second recovery area 114 in the flash memory 11. The second recovery area 114 stores a second firmware image related to the baseboard management controller 14 and a second setting value. The second recovery area 114 can be switched between a read-only mode and a read-write mode, and the second recovery area 114 defaults to the read-only mode.
[0034] It should be noted that, in this embodiment, the first firmware image and the second firmware image are of different versions, and the second firmware image is the previous version of the first firmware image. In other embodiments, the first firmware image may be the same as the second firmware image, which is not limited thereto.
[0035] It should be particularly noted that the baseboard management controller 14 allocates the second recovery area 114 from the free memory addresses in the flash memory 11.
[0036] In step 22, the programmable logic device 13 detects whether the baseboard management controller 14 is operating normally. When it is detected that the baseboard management controller 14 is operating normally, the process repeats step 22; when it is detected that the baseboard management controller 14 is operating abnormally, it indicates that the current area is a bad area, and the process proceeds to step 23.
[0037] It is worth noting that in this embodiment, the general-purpose input / output pin 101 and the system management bus 102 are used to double-confirm whether the baseboard management controller 14 is operating normally. Specifically, the programmable logic device 13 determines whether the general-purpose input / output pin 101 is at a high potential. When the programmable logic device 13 determines that the pin is at a high potential, the programmable logic device 13 sends a poll via the system management bus 102 and determines whether a response from the baseboard management controller 14 has not been received after the number of polls reaches a threshold. When the programmable logic device 13 determines that no response from the baseboard management controller 14 has been received after the number of polls reaches the threshold, it is determined that the baseboard management controller 14 is operating abnormally. In other embodiments, it is also possible to confirm whether the baseboard management controller 14 is operating normally only with the general-purpose input / output pin 101 or the system management bus 102. That is, when the programmable logic device 13 determines that the general-purpose input / output pin 101 is at a high potential, it is determined that the baseboard management controller 14 is operating abnormally. When the programmable logic device 13 determines that the general-purpose input / output pin 101 is at a low potential, it is determined that the baseboard management controller 14 is operating normally. Or when the programmable logic device 13 determines that no response from the baseboard management controller 14 has been received after the number of polls reaches the threshold, it is determined that the baseboard management controller 14 is operating abnormally. When the programmable logic device 13 determines that a response from the baseboard management controller 14 has been received before the number of polls reaches the threshold, it is determined that the baseboard management controller 14 is operating normally.
[0038] It should be noted that when it is determined that the baseboard management controller 14 is operating abnormally, a mailbox (not shown in the figure) in the programmable logic device 13 will display an error message.
[0039] In step 23, the programmable logic device 13 determines whether the temporary area 113 is a bad area. When it is determined that the temporary area 113 is not a bad area, the process proceeds to step 24; when it is determined that the temporary area 113 is a bad area, the process proceeds to step 26.
[0040] It should be noted that, in this embodiment, the programmable logic device 13 compares the first hash value with the hash value of the temporary storage area to determine whether the temporary storage area 113 is a bad area. When it is compared that the first hash value is different from the hash value of the temporary storage area, the programmable logic device 13 determines that the temporary storage area 113 is a bad area. When it is determined that the first hash value is the same as the hash value of the temporary storage area, the programmable logic device 13 determines that the temporary storage area 113 is not a bad area, but this is not limited thereto.
[0041] In step 24, the programmable logic device 13 copies the temporary storage area 113 to the first restoration area 112.
[0042] In step 25, the programmable logic device 13 decompresses the first restoration area 112 to the active area 111 and repeats step 22.
[0043] In step 26, the programmable logic device 13 determines whether the first restoration area 112 is a bad area. When it is determined that the first restoration area 112 is not a bad area, the process proceeds to step 27; when it is determined that the first restoration area 112 is a bad area, the process proceeds to step 28.
[0044] It should be noted that, in this embodiment, the programmable logic device 13 compares the second hash value with the hash value of the restoration area to determine whether the first restoration area 112 is a bad area. When it is compared that the second hash value is different from the hash value of the restoration area, the programmable logic device 13 determines that the first restoration area 112 is a bad area. When it is compared that the second hash value is the same as the hash value of the restoration area, the programmable logic device 13 determines that the first restoration area 112 is not a bad area, but this is not limited thereto.
[0045] In step 27, the programmable logic device 13 decompresses the first restoration area 112 to the active area 111 and repeats step 22.
[0046] In step 28, the programmable logic device 13 generates and transmits an unlocking instruction including the first set value to the baseboard management controller 14.
[0047] In step 29, the baseboard management controller 14 compares whether the first set value is the same as the second set value. When it is compared that the first set value is the same as the second set value, the process proceeds to step 30; when it is compared that the first set value is different from the second set value, the process proceeds to step 34.
[0048] In step 30, the baseboard management controller 14 switches the second restoration area 114 of the flash memory 11 to the read / write mode.
[0049] In step 31, the programmable logic device 13 restores the active area 111 according to the second restoration area 114, that is, the programmable logic device 13 decompresses the second restoration area 114 to the active area 111.
[0050] It should be noted that in this embodiment, since the second firmware image stored in the second restoration area 114 is a different version from the first firmware image, the first firmware image is, for example, the latest version, and the second firmware image is, for example, the previous version. The user can confirm whether the active area 111 is restored according to the second restoration area 114 based on the firmware image version in the restored active area 111. After rebooting, the user, for example, remotely updates the latest version of the firmware image to the staging area 113. The programmable logic device 13 will copy the staging area 113 to the first restoration area 112 to repair the first restoration area 112 and decompress the first restoration area 112 to the active area 111 so that the baseboard management controller 14 runs the latest version of the firmware.
[0051] It should be further noted that after the programmable logic device 13 decompresses the second restoration area 114 to the active area 111, a log related to the repair with the second restoration area 114 will be generated. After the next boot, the user can choose to remotely update the latest version of the firmware image to the staging area according to the log, then copy the staging area 113 to the first restoration area 112 and decompress the first restoration area 112 to the active area 111 so that the baseboard management controller 14 can execute the latest version of the firmware.
[0052] In step 32, the programmable logic device 13 generates and transmits a locking instruction to the baseboard management controller 14 and repeats step 22.
[0053] In step 33, the baseboard management controller 14 switches the second restoration area 114 of the flash memory 11 to the read-only mode.
[0054] In step 34, the baseboard management controller 14 generates an error message.
[0055] It should be particularly noted that the second recovery area 114 is defaulted to the read-only mode, and hackers cannot tamper with the second recovery area 114. If the first recovery area 112 is tampered with by hackers to become a bad area, basically the external network port (RJ45) will be closed. Before the first recovery area 112 is repaired, hackers have no chance to tamper with the second recovery area 114. Therefore, the probability that the second recovery area 114 is tampered with and cannot be used is almost zero. In other embodiments, the unlocking instruction may not include the first set value. After receiving the unlocking instruction, the baseboard management controller 14 directly switches the second recovery area 114 of the flash memory 11 to the read-write mode, that is, steps 29 and 34 are not executed.
[0056] In summary, for the method for repairing the firmware storage area of the baseboard management controller 14 of the present invention, by the baseboard management controller 14 partitioning the second recovery area 114 defaulted to the read-only mode in the flash memory 11 to ensure that the second recovery area 114 is not infringed, and when both the first recovery area 112 and the temporary storage area 113 are bad areas, that is, cannot be restored by PFR, the programmable logic device 13 transmits the unlocking instruction including the first set value to the baseboard management controller 14, so that when the baseboard management controller 14 confirms that the first set value is the same as the second set value, it switches the second recovery area 114 of the flash memory 11 to the read-write mode, and the programmable logic device 13 then restores the current use area 111 according to the second recovery area 114 to ensure that the baseboard management controller 14 can be used normally. Therefore, the object of the present invention can be truly achieved.
[0057] The above is only the specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.
Claims
1. A method for repairing a firmware storage area of a baseboard management controller, which is executed by a computer device. The computer device includes a baseboard management controller, a programmable logic device electrically connected to the baseboard management controller, and a flash memory electrically connected to the baseboard management controller and the programmable logic device. The flash memory has an active area, a first recovery area, and a temporary area. The active area, the first recovery area, and the temporary area store a first firmware image related to the baseboard management controller, and it is characterized in that, The method includes the following steps: (A) The baseboard management controller divides a second recovery area in the flash memory. The second recovery area stores a second firmware image related to the baseboard management controller. The second recovery area can be switched between a read-only mode and a read-write mode, and the second recovery area defaults to the read-only mode; (B) The programmable logic device detects whether the baseboard management controller is operating normally; (C) When it is detected that the baseboard management controller is operating abnormally, it means that the current area is a bad area. The programmable logic device judges whether the first recovery area and the temporary storage area of the flash memory are bad areas; (D) When it is judged that both the first recovery area and the temporary storage area are bad areas, the programmable logic device generates and sends an unlock instruction to the baseboard management controller, so that the baseboard management controller switches the second recovery area of the flash memory to the read-write mode; (E) The programmable logic device restores the current area according to the second recovery area; (F) The programmable logic device generates and sends a lock instruction to the baseboard management controller, so that the baseboard management controller switches the second recovery area of the flash memory to the read-only mode.
2. The method for repairing the substrate management controller firmware storage area according to claim 1, wherein, The programmable logic device is electrically connected to the baseboard management controller via a general-purpose input / output pin. Among them, in step (B), the programmable logic device judges whether the general-purpose input / output pin is at a high level to judge whether the baseboard management controller is operating normally. When the programmable logic device judges that the general-purpose input / output pin is at a high level, it is determined that the baseboard management controller is operating abnormally. When the programmable logic device judges that the general-purpose input / output pin is at a low level, it is determined that the baseboard management controller is operating normally.
3. The method for repairing the substrate management controller firmware storage area according to claim 1, wherein The programmable logic device is via a system management bus. Among them, in step (B), the programmable logic device issues a poll via the system management bus and judges whether the baseboard management controller response has not been received when the number of poll times reaches a threshold, to judge whether the baseboard management controller is operating normally. When the programmable logic device judges that the baseboard management controller response has not been received when the number of poll times reaches the threshold, it is determined that the baseboard management controller is operating abnormally. When the programmable logic device judges that the baseboard management controller response has been received when the number of poll times does not reach the threshold, it is determined that the baseboard management controller is operating normally.
4. The method for repairing a substrate management controller firmware storage area according to claim 1, wherein Step (C) includes the following steps: (C-1) The programmable logic device judges whether the temporary storage area is a bad area; and (C-2) When it is judged that the temporary storage area is a bad area, the programmable logic device judges whether the first recovery area is a bad area; When it is judged that the first recovery area is a bad area, step (D) is performed.
5. The method for repairing the substrate management controller firmware storage area according to claim 4, wherein, Step (C) further includes the following steps: (C-3) When it is judged that the temporary storage area is not a bad area, the programmable logic device copies the temporary storage area to the first recovery area; and (C-4) The programmable logic device decompresses the first recovery area to the current area.
6. The method for repairing the substrate management controller firmware storage area according to claim 4, wherein, Step (C) further includes the following steps: (C-5) When it is determined that the first recovery area is not a bad area, the programmable logic device decompresses the first recovery area to the active area.
7. The method for repairing the substrate management controller firmware storage area according to claim 4, wherein The programmable logic device stores a first hash value related to the temporary area and a second hash value related to the first recovery area. The temporary area included in the flash memory also stores a temporary area hash value, and the first recovery area also stores a recovery area hash value. Among them, in step (C-1), the programmable logic device compares the first hash value with the temporary area hash value to determine whether the temporary area is a bad area. When it is compared that the first hash value is different from the temporary area hash value, the programmable logic device determines that the temporary area is a bad area. When it is compared that the first hash value is the same as the temporary area hash value, the programmable logic device determines that the temporary area is not a bad area. In step (C-2), the programmable logic device compares the second hash value with the recovery area hash value to determine whether the first recovery area is a bad area. When it is compared that the second hash value is different from the recovery area hash value, the programmable logic device determines that the first recovery area is a bad area. When it is compared that the second hash value is the same as the recovery area hash value, the programmable logic device determines that the first recovery area is not a bad area.
8. The method for repairing the substrate management controller firmware storage area according to claim 1, wherein The programmable logic device stores a first set value. Among them, in step (A), the second recovery area of the flash memory also stores a second set value. In step (D), the unlock instruction includes the first set value, so that when the baseboard management controller compares that the first set value is the same as the second set value, it switches the second recovery area to the read / write mode.
9. The method for repairing a substrate management controller firmware storage area according to claim 8, wherein, The first set value is the sum of each bit of a media access control address of the baseboard management controller.
10. The method for repairing the substrate management controller firmware storage area according to claim 1, wherein, In step (A), the second firmware image stored in the second recovery area is a different version from the first firmware image.