Firmware upgrading system and method

By introducing spare memory into the firmware upgrade system, the logic controller checks and handsses it over to the management controller for writing, solving the problem that the management controller cannot handle business during the upgrade process, and achieving efficient firmware upgrades.

CN120335845AActive Publication Date: 2025-07-18INSPUR SUZHOU INTELLIGENT TECH CO LTD

Patent Information

Application Number
CN202510820583.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-18
Publication Date
2025-07-18
Estimated Expiration
2045-06-18

AI Technical Summary

Technical Problem

During the server firmware upgrade process, the management controller cannot handle business normally.

Method used

The backup memory is introduced. When the logic controller receives the control of the backup memory when receiving the firmware upgrade instruction, performs verification and handes the control to the management controller after passing. The management controller then writes the upgraded firmware to the main memory to avoid resetting the management controller.

Benefits of technology

This improves the firmware upgrade efficiency, and the management controller can still handle business normally during the upgrade process, avoiding the problem of being unable to work for a long time.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120335845A_ABST
    Figure CN120335845A_ABST
Patent Text Reader

Abstract

The invention discloses a firmware upgrading system and method, and relates to the technical field of firmware, and the firmware upgrading method comprises the steps that a standby memory is newly arranged in the firmware upgrading system, and in the upgrading process, when a logic controller obtains a first firmware upgrading instruction, the control right of the standby memory is obtained. Moreover, when the control right of the standby memory is obtained, the upgrade firmware is read from the standby memory, and the upgrade firmware is verified. And when the verification is passed, a verification completion notification is sent to the management controller, and the control right of the main memory and the control right of the standby memory are both handed over to the management controller. Therefore, the management controller can automatically read the upgrade firmware from the standby memory and write the upgrade firmware into the main memory to complete firmware upgrade operation. In the firmware upgrading operation process, the logic controller does not need to perform reset operation on the management controller, so that the management controller can normally perform business processing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of firmware, and particularly to a firmware upgrade system and method. Background Art

[0002] With the rapid development of the Internet, various network attack means emerge in an endless stream. For example, a Permanent Denial of Service (PDoS) attack will tamper with the firmware (FW) of a server, resulting in the server malfunctioning, and the server must be re-flashed with the firmware to return to normal.

[0003] In the current Platform Firmware Resilience (PFR) technology, to avoid such failures, when upgrading the firmware, the management controller stores the upgraded firmware in a temporary area of the flash memory (a storage area dedicated to storing the upgraded firmware) and notifies the logic controller. When receiving the notification, the logic controller first resets the management controller, obtains control of the flash memory, reads the upgraded firmware from the upgrade storage area and performs a verification. After the verification passes, it then overwrites and writes the upgraded firmware to the active area of the flash memory (used to store the main firmware, and when loading the firmware, the management controller loads the firmware from the active area). Finally, after completing the migration operation, the reset of the management controller is released, and the control of the flash memory is returned to the management controller. The management controller can re-read the upgraded firmware from the active area of the flash memory for loading. However, during the firmware upgrade operation process, the management controller is in a state where it cannot normally process business. Summary of the Invention

[0004] This application provides a firmware upgrade system and method to solve the problem that the management controller cannot normally process business during the firmware upgrade operation process.

[0005] This application provides a firmware upgrade system, which includes a management controller, a logic controller, a main memory, and a backup memory; The logic controller is configured to, when receiving a first firmware upgrade instruction sent by the management controller, take over the control of the backup memory to read the pre-written upgraded firmware from the backup memory; perform a verification operation on the upgraded firmware to obtain a verification result corresponding to the upgraded firmware; when determining that the verification result is passed, send a verification completion notification to the management controller; transfer the control of the backup memory to the management controller; A management controller, which is configured to, when receiving a verification completion notification and taking over the control right of the standby memory, read the upgraded firmware from the standby memory, and overwrite and write the read upgraded firmware into the main memory as the upgraded main firmware, so as to complete the firmware upgrade operation of the main memory.

[0006] This application also provides a firmware upgrade method. The firmware upgrade method is applied to the above firmware upgrade system. The firmware upgrade system includes a management controller, a logic controller, a main memory, and a standby memory. The method includes: When receiving a first firmware upgrade instruction sent by the management controller, the logic controller takes over the control right of the standby memory, so as to read the pre-written upgraded firmware from the standby memory; perform a verification operation on the upgraded firmware to obtain a verification result corresponding to the upgraded firmware; when it is determined that the verification result passes, send a verification completion notification to the management controller; transfer the control right of the standby memory to the management controller; When receiving a verification completion notification and taking over the control right of the standby memory, the management controller reads the upgraded firmware from the standby memory, and overwrite and write the read upgraded firmware into the main memory as the upgraded main firmware, so as to complete the firmware upgrade operation of the main memory.

[0007] Through this application, a standby memory is newly set up in the firmware upgrade system. The original main memory is still used to store the main firmware, so that the management controller can load the main firmware from it to execute services. The standby memory is used to store the upgraded firmware, so that the logic controller can read the upgraded firmware from the standby memory for verification. The upgraded firmware and the main firmware are physically isolated, and the original main firmware will not be interfered during the verification of the upgraded firmware. During the upgrade process, when the logic controller obtains a first firmware upgrade instruction, it obtains the control right of the standby memory, rather than the control right of the main memory. And when obtaining the control right of the standby memory, it first reads the upgraded firmware from it and performs a verification operation on the upgraded firmware. When the verification passes, it sends a verification completion notification to the management controller and hands over the control right of the standby memory to the management controller. In this way, the management controller can automatically read the upgraded firmware from the standby memory and write it into the main memory to complete the firmware upgrade operation. During the firmware upgrade operation, there is no need to reset the management controller, and the management controller can still normally load the main firmware for business processing. Description of the Drawings

[0008] To more clearly illustrate the embodiments of the present application, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0009] Figure 1 Schematic diagram of the architecture of a firmware upgrade system provided by an embodiment of the present application; Figure 2 Schematic diagram of the architecture of another firmware upgrade system provided by an embodiment of the present application; Figure 3 Schematic diagram of the process of switching the memory control right provided by an embodiment of the present application; Figure 4 Schematic diagram of the architecture of yet another firmware upgrade system provided by an embodiment of the present application; Figure 5 Schematic diagram of the architecture of yet another firmware upgrade system provided by an embodiment of the present application; Figure 6 Schematic diagram of the process of a firmware upgrade method provided by an embodiment of the present application. Detailed implementation manners

[0010] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0011] It should be noted that in the description of the present application, the terms "include", "comprise" or any other variant thereof are intended to cover a non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. The terms "first", "second", etc. in the present application are used to distinguish similar objects and are not used to describe a specific order or sequence.

[0012] In order to enable those skilled in the art of the present technology to better understand the solution of the present application, the present application will be further described in detail below in conjunction with the accompanying drawings and specific implementation manners.

[0013] The present application provides a firmware upgrade system, as Figure 1 shown, the firmware upgrade system may include a management controller 10, a logic controller 20, a main memory 30, and a backup memory 40. The management controller 10 is electrically connected to the logic controller 20. For example, it is connected through an I2C bus and a reset signal line link. The management controller 10 can be electrically connected to the main memory 30 and the backup memory 40 respectively, and the logic controller 20 can be electrically connected to the main memory 30 and the backup memory 40 respectively.

[0014] Among them, the management controller 10 can be a Baseboard Management Controller (BMC), and the logic controller 20 can be a Complex Programmable Logic Device (CPLD) or a Field Programmable Gate Array (FPGA). Both the main memory 30 and the backup memory 40 can be Flash. The main memory 30 is used to store the main firmware, and the backup memory 40 is used to store the backup firmware. The I2C bus is used to transmit the first firmware upgrade instruction, the second firmware upgrade instruction, etc. The reset signal line link is used to transmit a reset signal (Reset, RST), for example, a reset enable signal or a reset release signal.

[0015] The logic controller 20 is configured to: when receiving the first firmware upgrade instruction sent by the management controller 10, take over the control right of the backup memory 40 to read the pre-written upgrade firmware from the backup memory 40. Perform a verification operation on the upgrade firmware to obtain a verification result corresponding to the upgrade firmware. When it is determined that the verification result passes, send a verification completion notification to the management controller 10. Transfer the control right of the backup memory 40 to the management controller 10.

[0016] The management controller 10 is configured to: when receiving the verification completion notification and taking over the control right of the backup memory 40, read the upgrade firmware from the backup memory 40 and overwrite the read upgrade firmware into the main memory 30 as the upgraded main firmware to complete the firmware upgrade operation of the main memory 30.

[0017] Among them, the upgrade firmware can be the firmware of the management controller 10.

[0018] Specifically, when a firmware upgrade operation is required, the management controller 10 will actively send a first firmware upgrade instruction to the logic controller 20. In this way, after receiving the first firmware upgrade instruction, the logic controller 20 can know that the upgrade firmware has been written to the backup memory 40 and a verification operation needs to be performed. Since the control right of the backup memory 40 was originally held by the management controller 10, when the logic controller 20 receives the first firmware upgrade instruction, it can first take over the control right of the backup memory 40. After taking over the control right of the backup memory 40, the logic controller 20 can first obtain a preset key from a preset storage location and read the upgrade firmware from the backup memory 40. Furthermore, the logic controller 20 can verify the upgrade firmware based on the preset key to obtain a verification result corresponding to the upgrade firmware. Then, the logic controller 20 can execute the upgrade operation corresponding to the verification result. The verification result can generally be divided into passed and failed. Correspondingly, the upgrade operation executed by the logic controller 20 corresponding to the verification result can include the following two situations: In the first situation, when it is determined that the verification result fails, a verification failure notice can be sent to the management controller 10.

[0019] When the logic controller 20 determines that the verification result fails, it indicates that there is an error in the upgrade firmware. At this time, a verification failure notice can be sent to the management controller 10. When the management controller 10 receives the verification failure notice, it can record this error information and save it for subsequent debugging operations.

[0020] In the second situation, when it is determined that the verification result passes, a verification completion notice can be sent to the management controller 10. Transfer the control right of the backup memory 40 to the management controller 10.

[0021] When the logic controller 20 determines that the verification result passes, it indicates that the upgrade firmware is error-free and the upgrade operation can continue. Since the purpose of the firmware upgrade operation is to upgrade the main firmware in the main memory 30, the main firmware in the main memory 30 needs to be upgraded based on the upgrade firmware stored in the backup memory 40. Considering that the logical resources of the logic controller 20 are limited, directly burning the firmware by the logic controller 20 has low efficiency. Therefore, when the logic controller 20 determines that the verification result corresponding to the upgrade firmware passes, it can transfer the control right of the backup memory 40 to the management controller 10, and the management controller 10 burns the upgrade firmware with higher efficiency. It should be noted that under normal working conditions, the management controller 10 has the control right of the main memory 30, and the logic controller 20 does not need to handle the control right of the main memory 30.

[0022] In this way, when the management controller 10 receives the verification completion notification and takes over the control right of the standby memory 40, it can first read the upgraded firmware from the standby memory 40 and overwrite it into the main memory 30 as the upgraded main firmware. Thus, the firmware upgrade operation of the main memory 30 is completed. The management controller 10 can load the upgraded main firmware from the main memory 30 and execute business operations using the upgraded main firmware.

[0023] Alternatively, when the management controller 10 receives the verification completion notification and takes over the control right of the standby memory 40, it can start timing. When the timing duration reaches the preset duration, it then reads the upgraded firmware from the standby memory 40 and overwrites it into the main memory 30 as the upgraded main firmware.

[0024] In some alternative embodiments, if the management controller 10 fails to load the main firmware from the main memory 30, it can send a loading failure notification to the logic controller 20. The logic controller 20 can then transfer the control right of the standby memory 40 to the management controller 10. After the management controller 10 takes over the control right of the standby memory 40, it can read the standby firmware from the third storage area of the standby memory 40 and overwrite it into the main memory, and re-execute the firmware loading operation. Performing the recovery operation by the management controller 10 is more efficient.

[0025] In the firmware upgrade system of the embodiments of the present application, a new standby memory 40 is provided in the firmware upgrade system. The original main memory 30 is still used to store the main firmware so that the management controller 10 can load the main firmware from it to execute business. The standby memory 40 is used to store the upgraded firmware so that the logic controller 20 can read the upgraded firmware from the standby memory 40 for verification. The upgraded firmware and the main firmware are physically isolated and will not interfere with the original main firmware during the verification of the upgraded firmware. During the upgrade process, when the logic controller 20 obtains the first firmware upgrade instruction, what it obtains is the control right of the standby memory 40, rather than the control right of the main memory 30. And when it obtains the control right of the standby memory 40, it first reads the upgraded firmware from it and performs a verification operation on the upgraded firmware. When the verification passes, it sends a verification completion notification to the management controller 10 and transfers the control right of the standby memory 40 to the management controller 10. In this way, the management controller 10 can automatically read the upgraded firmware from the standby memory 40 and write it into the main memory 30 to complete the firmware upgrade operation. During the firmware upgrade operation process, there is no need to reset the management controller 10, and the management controller 10 can still normally load the main firmware for business processing.

[0026] The following makes a comparative description of the traditional technology and the present application.

[0027] In the conventional technology, an active area and a temporary area are set in a memory. Among them, the temporary area is used to store the upgraded firmware, and the active area is used to store the main firmware. Since a memory can only have one upstream control source, and there may be interference between the two areas, during the verification operation of the upgraded firmware, the logic controller 20 needs to reset the management controller 10 so that the memory only has the logic controller 20 as the upstream control source. However, the management controller 10 cannot perform business processing normally. Further, in the conventional technology, the operation of burning and upgrading the firmware is performed by the logic controller 20, that is, the logic controller 20 needs to first read the upgraded firmware from the temporary area and then overwrite and write it to the active area. Due to the limited logic resources of the logic controller 20, the burning operation efficiency is low. For example, the upgrade time usually takes 0.5 to 1 hour. In this way, the time for the management controller 10 to be unable to perform business processing normally is relatively long.

[0028] During the reset upgrade operation of the present application, there is no need to reset the management controller 10, and the burning operation of the upgrade component originally performed by the logic controller 20 is assigned to the management controller 10 for execution, which improves the firmware upgrade efficiency and at the same time avoids the problem that the management controller 10 is in a state where it cannot work normally for a long time.

[0029] In addition, in the conventional technology, the upgraded firmware and the main firmware are stored in a memory, and the management controller 10 is in a reset state during the verification process. Therefore, when the verification of the upgraded firmware fails, the management controller 10 needs to reload the main firmware. However, when the verification result of the upgraded firmware of the present application fails, there is no need to reload the main firmware.

[0030] In some optional embodiments, the management controller 10 is further configured to send a second firmware upgrade instruction to the logic controller 20 when receiving the upgraded firmware sent by the target device. The logic controller 20 is further configured to transfer the control right of the standby memory 40 to the management controller 10 when receiving the second firmware upgrade instruction. The management controller 10 is further configured to write the upgraded firmware into the standby memory 40 when taking over the control right of the standby memory 40. When it is determined that the upgraded firmware has been completely written into the standby memory 40, a first firmware upgrade instruction is sent to the logic controller 20.

[0031] Specifically, the target device can establish a communication connection with the management controller 10, which can be an electrical connection or a network connection. The user can upload the upgrade firmware to the target device, and the target device can send the upgrade firmware to the management controller 10. Since in normal operation, the management controller 10 generally does not have the control right of the standby memory 40 by default, when the management controller 10 receives the upgrade firmware, it can send a second firmware upgrade instruction to the logic controller 20 to obtain the control right of the standby memory 40. When the logic controller 20 receives the second firmware upgrade instruction and determines that a firmware upgrade operation needs to be performed currently, it can transfer the control right of the standby memory 40 to the management controller 10. When the management controller 10 obtains the control right of the standby memory 40, it can write the upgrade firmware into the standby memory 40, and after notifying the completion of the write operation, send a first firmware upgrade instruction to the logic controller 20 for the logic controller 20 to take over the control right of the standby memory 40 and perform the verification operation of the upgrade firmware.

[0032] Correspondingly, for the above-mentioned situation 1, when the management controller 10 receives the verification failure notice sent by the logic controller 20, it can also send an alarm notice to the target device to indicate that the target device determines that there is a problem with the upgrade firmware and resend the upgrade firmware. In addition, when the logic controller 20 determines that the verification result fails, it can promptly delete the upgrade firmware stored in the standby memory 40 to avoid the damaged upgrade firmware causing a failure to the server.

[0033] In the firmware upgrade system of the embodiment of the present application, the logic controller 20 temporarily grants the management controller 10 the control right of the standby memory 40 only after receiving a clear firmware upgrade instruction, avoiding unauthorized access or tampering and improving the overall security of the system.

[0034] In some optional embodiments, during the power-on process, the main firmware can also be verified first to avoid server failures. Correspondingly, the logic controller 20 can also be used to obtain the control right of the main memory 30 after power-on. When obtaining the control right of the main memory 30, read the main firmware from the main memory 30. Perform a verification operation on the main firmware to obtain a verification result corresponding to the main firmware. When it is determined that the verification result corresponding to the main firmware passes, perform a reset release operation on the management controller 10 and transfer the control right of the main memory 30 to the management controller 10. The management controller 10 can also be used to read the main firmware from the main memory 30 and load the main firmware when taking over the control right of the main memory 30.

[0035] Specifically, before the server is powered on, neither the logic controller 20 nor the management controller 10 obtains the control rights corresponding to the main memory 30 and the backup memory 40, respectively. After the logic controller 20 is powered on, the control right of the main memory 30 can be obtained first, the main firmware can be read from the main memory 30, and the preset key can be read from the preset storage location. Further, the logic controller 20 can perform a verification operation on the read main firmware based on the preset key to obtain a verification result corresponding to the main firmware. When it is determined that the verification result corresponding to the main firmware is passed, it means that the main firmware is safe and the management controller 10 can use the main firmware normally. In addition, since the management controller 10 is still in a reset state during the power-on process, when the logic controller 20 determines that the verification result corresponding to the main firmware is passed, it can send a reset signal to the management controller 10 through the reset signal transmission line. When the management controller 10 detects the reset signal, it can release the reset state and enter the daily working state. In addition, the logic controller 20 also needs to transfer the control right of the main memory 30 to the management controller 10, so that when the management controller 10 takes over the control right of the main memory 30, it can read the main firmware from the main memory 30 for loading, so as to perform subsequent business operations.

[0036] In the firmware upgrade system of the embodiment of the present application, after power-on, the logic controller 20 can first verify the main firmware stored in the main memory 30. When it is determined after verification that the main firmware is not damaged, the reset state of the management controller 10 is released, and the control of the main memory 30 is transferred to the management controller 10. This can ensure that the management controller 10 can safely load the firmware and avoid malfunctions caused by firmware damage.

[0037] In some optional embodiments, the logic controller 20 is also used to obtain control over the backup memory 40 after power-on. When the control over the backup memory 40 is obtained, the backup firmware is read from the backup memory 40. A verification operation is performed on the backup firmware to obtain a verification result corresponding to the backup firmware. When it is determined that the verification result corresponding to the main firmware is not passed, and the verification result corresponding to the backup firmware is passed, the main firmware stored in the main memory 30 is overwritten with the backup firmware to complete the firmware recovery operation of the main memory 30. When it is determined that the firmware recovery operation is completed, the management controller 10 is reset again, and the control over the main memory 30 is transferred to the management controller 10.

[0038] Specifically, since the main firmware stored in the main memory 30 may be damaged, after power-on, the logic controller 20 can also obtain the control right of the backup memory 40, so as to read the backup firmware from the backup memory 40, and based on a preset key, perform a verification operation on the read backup firmware to obtain a verification result corresponding to the backup firmware. In this way, when the logic controller 20 determines that the verification result corresponding to the main firmware fails and the verification result corresponding to the backup firmware passes, the backup firmware can be promptly overwritten and written into the main memory 30 as the restored main firmware. When it is determined that the firmware restoration operation is completed, the logic controller 20 then performs a reset release operation on the management controller 10 and transfers the control right of the main memory 30 to the management controller 10. In this way, when the management controller 10 takes over the control right of the main memory 30, it can read the main firmware from the main memory 30 for loading to perform subsequent service operations. Or, when the logic controller 20 determines that the verification result corresponding to the main firmware fails and the verification result corresponding to the backup firmware also fails, the server cannot be started normally and waits for the operation and maintenance personnel to handle it. Or, when the logic controller 20 determines that the verification result corresponding to the main firmware passes and the verification result corresponding to the backup firmware fails, after performing a reset release operation on the management controller 10, an error message can be sent to the management controller 10, and the management controller 10 can record this error message and send it to the target device for subsequent debugging.

[0039] In the firmware upgrade system according to the embodiment of the present application, when it is detected that the main firmware verification fails, the logic controller 20 can automatically use the backup firmware for restoration, which can avoid the problem that the server cannot be started due to the damage of the main firmware.

[0040] In some optional embodiments, the backup memory 40 may include a first storage area and a second storage area. Among them, the first storage area can be used as a temporary area to store the upgrade firmware, and the second storage area can be used to store the backup firmware. Correspondingly, the management controller 10 can specifically be used to obtain a first starting address, and based on the first starting address, store the upgrade firmware in the first storage area of the backup memory 40. The management controller 10 can also be used to load the upgrade firmware. When it is determined that the upgrade firmware is loaded, obtain a second starting address, and based on the first starting address and the second starting address, overwrite and write the upgrade firmware stored in the first storage area into the second storage area as the upgraded backup firmware.

[0041] Among them, the first starting address can be the starting address of the first storage area, and the second starting address can be the starting address of the second storage area.

[0042] Specifically, in order to avoid the impact of the upgraded firmware on the original main firmware, a first storage area can be set in the backup memory 40 for temporarily storing the upgraded firmware. Also, in order to avoid the situation where the main firmware cannot run properly due to an error in loading it, a second storage area can also be set in the backup memory 40 for storing the backup firmware. When the management controller 10 receives the upgraded firmware, it can first obtain the first starting address, and then use the first starting address as the starting storage address to store the upgraded firmware in the first storage area.

[0043] In addition, in order to ensure that the backup firmware is also the latest version, after the management controller 10 finishes loading the upgraded firmware, it can also perform an upgrade operation on the backup firmware. Based on the first starting address, it reads the upgraded firmware from the first storage area and uses the second starting address as the starting storage address to overwrite and write the upgraded firmware into the second storage area. In this way, the upgrade operation of the backup firmware can be completed. The management controller 10 can also notify the logic controller 20 through the I2C bus that the backup firmware has also completed the upgrade operation and then regain control of the backup memory 40.

[0044] In some alternative embodiments, before the backup firmware in the second storage area is upgraded, if the management controller 10 fails to load the main firmware from the main memory 30, it can send a loading failure notification to the logic controller 20. The logic controller 20 can then transfer the control right of the backup memory 40 to the management controller 10. After the management controller 10 takes over the control right of the backup memory 40, it can read the backup firmware from the second storage area of the backup memory 40 and overwrite it into the main memory, and then re-execute the firmware loading operation. Performing the recovery operation by the management controller 10 instead of the logic controller 20 has a higher recovery efficiency.

[0045] In the firmware upgrade system according to the embodiments of the present application, by storing the upgraded firmware in an independent first storage area instead of directly overwriting the original main firmware, the problem that the management controller 10 cannot run properly due to a write failure or firmware exception during the upgrade process is effectively avoided. Also, after successfully loading the upgraded firmware, the management controller 10 will synchronize it to the second storage area to ensure that the backup firmware is always the latest version, avoiding the problem that the backup firmware may lag behind the main firmware version. In addition, having the management controller 10 upgrade the backup firmware has a higher efficiency, and the logic controller 20 does not need to perform a reset operation on the management controller 10, which can avoid the problem that the management controller 10 cannot work properly.

[0046] In some alternative embodiments, such as Figure 2As shown, the firmware upgrade system includes a first selection circuit 50 and a second selection circuit 60. Among them, both the first selection circuit 50 and the second selection circuit 60 respectively include a plurality of switches. Both the first selection circuit 50 and the second selection circuit 60 can be multiplexers (MUX). The first selection circuit 50 is electrically connected to the main memory 30, the management controller 10, and the logic controller 20 respectively. The second selection circuit 60 is electrically connected to the backup memory 40, the management controller 10, and the logic controller 20 respectively.

[0047] In the structure as Figure 2 shown, the logic controller 20 can allocate the control right of the main memory 30 by controlling the switches of the first selection circuit 50, and allocate the control right of the backup memory 40 by controlling the switches of the second selection circuit 60. Accordingly, the specific processing of the logic controller 20 can be as follows: First, after power-on, the logic controller 20 can set the switch corresponding to itself in the first selection circuit 50 to the second state to obtain the control right of the main memory 30.

[0048] Among them, the second state is used to indicate that the corresponding communication link is connected, and the first state is used to indicate that the corresponding communication link is disconnected.

[0049] Specifically, before the firmware upgrade system is powered on, all switches of the first selection circuit 50 and the second selection circuit 60 are in the first state. After the logic controller 20 is powered on, it needs to first perform a verification operation on the main firmware. Accordingly, the logic controller 20 can set the switch corresponding to itself in the first selection circuit 50 to the second state to connect the communication link between the logic controller 20 and the main memory 30, that is, it can obtain the control right of the main memory 30 and read the main firmware from the main memory 30 for verification operation.

[0050] Second, after power-on and when the verification result corresponding to the main firmware passes, the logic controller 20 can set the switch corresponding to itself in the first selection circuit 50 to the first state, and set the switch corresponding to the management controller 10 in the first selection circuit 50 to the second state to transfer the control right of the main memory 30 to the management controller 10.

[0051] Specifically, after power-on, when the logic controller 20 verifies that the main firmware is error-free, it can set the switch corresponding to itself in the first selection circuit 50 to the first state to disconnect the communication link between the logic controller 20 and the main memory 30. Moreover, the logic controller 20 also needs to set the switch corresponding to the management controller 10 in the first selection circuit 50 to the second state to connect the communication link between the logic controller 20 and the main memory 30. In this way, the logic controller 20 can transfer the control right of the main memory 30 to the management controller 10.

[0052] Third, after power-on, the logic controller 20 can also set the switch corresponding to itself in the second selection circuit 60 to the second state to obtain the control right of the backup memory 40.

[0053] Specifically, after power-on, the logic controller 20 can also perform a verification operation on the backup firmware (which can be performed after completing the verification operation on the main firmware). Correspondingly, the logic controller 20 can set the switch corresponding to itself in the second selection circuit 60 to the second state to connect the communication link between the logic controller 20 and the backup memory 40, that is, it can obtain the control right of the backup memory 40.

[0054] Fourth, when the logic controller 20 receives the second firmware upgrade instruction sent by the management controller 10, the logic controller 20 can set the state of the switch corresponding to itself in the second selection circuit 60 to the first state, and set the state of the switch corresponding to the management controller 10 in the second selection circuit 60 to the second state to transfer the control right of the backup memory 40 to the management controller 10.

[0055] Specifically, since the logic controller 20 has obtained the control right of the backup memory 40 during the verification process of the backup firmware, and when it receives the second firmware upgrade instruction sent by the management controller 10, it is determined that the current management controller 10 needs to write the upgraded firmware into the backup memory 40. Therefore, the logic controller 20 can set the switch corresponding to itself in the second selection circuit 60 to the first state to disconnect the communication link between the logic controller 20 and the backup memory 40, and set the switch corresponding to the management controller 10 in the second selection circuit 60 to the first state to connect the communication link between the management controller 10 and the backup memory 40, that is, complete the transfer operation of the control right of the backup memory 40.

[0056] Fifth, when the logic controller 20 receives the first firmware upgrade instruction sent by the management controller 10, the logic controller 20 can set the state of the switch corresponding to the management controller 10 in the second selection circuit 60 to the first state, and set the state of the switch corresponding to itself in the second selection circuit 60 to the second state, so as to take over the control right of the standby memory 40 (that is, re-acquire the control right of the standby memory 40).

[0057] Specifically, when the logic controller 20 receives the first firmware upgrade instruction sent by the management controller 10, it indicates that the management controller 10 has written the upgraded firmware into the standby memory 40, and the next verification operation needs to be performed. Therefore, the logic controller 20 can set the switch corresponding to the management controller 10 in the second selection circuit 60 to the first state to disconnect the communication link between the management controller 10 and the standby memory 40, and set the switch corresponding to itself in the second selection circuit 60 to the second state to connect the communication link between the logic controller 20 and the standby memory 40, that is, take over the control right of the standby memory 40.

[0058] In the power-on and upgrade processes, the change of the control rights of the main memory 30 and the standby memory 40 can be as Figure 3 shown.

[0059] In some alternative embodiments, during the process of the logic controller 20 verifying the upgraded firmware, the management controller 10 can also be used to detect the progress and verification result of the verification operation of the logic controller 20.

[0060] Specifically, the first selection circuit 50 can include a first data interface (denoted as S1), a second data interface (denoted as S2), a third data interface (denoted as D1), and a first enable interface (denoted as EN1). The second selection circuit 60 can include a fourth data interface (denoted as S3), a fifth data interface (denoted as S4), a sixth data interface (denoted as D2), and a second enable interface (denoted as EN2). The logic controller 20 can include a seventh data interface (denoted as A2), a third enable interface (denoted as A3), and a fourth enable interface (denoted as A4). Among them, the third data interface of the first selection circuit 50 is electrically connected to the main memory 30, and the sixth data interface of the second selection circuit 60 is electrically connected to the standby memory 40. The third enable interface of the logic controller 20 can be electrically connected to the first enable interface of the first selection circuit 50, and the fourth enable interface of the logic controller 20 can be electrically connected to the second enable interface of the second selection circuit 60. The seventh data interface of the logic controller 20 can be electrically connected to the second data interface of the first selection circuit 50 and the fifth data interface of the second selection circuit 60 respectively.

[0061] The data interface of the management controller 10 can be one or multiple. Correspondingly, according to the number of data interfaces, the structure of the firmware upgrade system also varies. The following introduces two cases in detail.

[0062] Case 1: When the management controller 10 includes one data interface, the structure of the firmware upgrade system can be as Figure 4 shown. Among them, the management controller 10 can include an eighth data interface (denoted as A1). The eighth data interface of the management controller 10 is electrically connected to the first data interface of the first selection circuit 50 and the fourth data interface of the second selection circuit 60 respectively.

[0063] Case 2: When the management controller 10 includes multiple data interfaces, the structure of the firmware upgrade system can be as Figure 5 shown. Among them, the management controller 10 can include a ninth data interface (which can be denoted as A5) and a tenth data interface (which can be denoted as A6). The ninth data interface of the management controller 10 is electrically connected to the first data interface of the first selection circuit 50, and the tenth data interface of the management controller 10 can be electrically connected to the fourth data interface of the second selection circuit 60.

[0064] For Case 2, during the process of the management controller 10 performing the firmware upgrade operation on the main memory 30, it can read the upgrade firmware from the backup memory 40 through the tenth data interface and write the read upgrade firmware into the main memory 30 through the ninth data interface. In this way, the operations of reading the upgrade firmware and writing the upgrade firmware can be executed in parallel, further improving the efficiency of the firmware upgrade operation.

[0065] The firmware upgrade system according to the embodiment of the present application is connected to the main memory 30 through the first selection circuit 50 and to the backup memory 40 through the second selection circuit 60, so that both the logic controller 20 and the management controller 10 can be used as the upstream control devices of the two memories. Moreover, the backup memory 40 stores the upgrade firmware, and the main memory 30 stores the main firmware. The main firmware and the upgrade firmware are physically isolated. During the verification of the upgrade firmware stored in the backup memory 40, no impact will be caused to the main firmware in the main memory 30, and the management controller 10 can still use the main firmware to perform normal business operations. Correspondingly, during the verification of the upgrade firmware by the logic controller 20, there is no need to reset the management controller 10, and the management controller 10 can still perform normal business operations, for example, execute monitoring and record logs. If the management controller 10 is in a reset state during the verification of the upgrade firmware, it cannot perceive the specific execution content of the logic controller 20 (for example, the information that the verification of the upgrade firmware fails), nor can it be debugged. Moreover, when the management controller 10 is in a reset state, it cannot establish a network connection with external devices, and the operation and maintenance personnel cannot perform debugging through remote access. They can only connect to the logic controller 20 through the specified debugging hardware interface for debugging, for example, the Joint Test Action Group (JTAG) interface. Since the debugging hardware interface will be removed when the server is shipped, before debugging, it is also necessary to disassemble the board and lead out the debugging hardware interface by soldering wires, which greatly increases the complexity of debugging. However, the present application does not require resetting the management controller 10, which can enable the management controller 10 to establish a network connection with external devices, and the operation and maintenance personnel can perform debugging through remote access, greatly reducing the complexity of debugging.

[0066] The firmware upgrade method provided by the present application can be implemented by the above firmware upgrade system. As Figure 6 shown, the specific processing steps of the firmware upgrade method may include: Step S601, when the logic controller receives the first firmware upgrade instruction sent by the management controller, it takes over the control right of the backup memory so as to read the pre-written upgrade firmware from the backup memory.

[0067] Step S602, the logic controller performs a verification operation on the upgrade firmware to obtain a verification result corresponding to the upgrade firmware.

[0068] Step S603, when the logic controller determines that the verification result is passed, it sends a verification completion notification to the management controller.

[0069] Step S604, the logic controller transfers the control right of the backup memory to the management controller.

[0070] Step S605: When the management controller receives the verification completion notice and takes over the control right of the standby memory, it reads the upgraded firmware from the standby memory and overwrites and writes the read upgraded firmware into the main memory as the upgraded main firmware to complete the firmware upgrade operation of the main memory.

[0071] The specific processing of steps S601 to S605 is similar to the above processing and will not be elaborated here.

[0072] In the firmware upgrade method according to the embodiment of the present application, during the upgrade process, when the logic controller obtains the first firmware upgrade instruction, it obtains the control right of the standby memory instead of the main memory. Moreover, when obtaining the control right of the standby memory, it first reads the upgraded firmware from it and performs a verification operation on the upgraded firmware. When the verification passes, it sends a verification completion notice to the management controller and hands over the control right of the standby memory to the management controller. In this way, the management controller can automatically read the upgraded firmware from the standby memory and write it into the main memory to complete the firmware upgrade operation. During the firmware upgrade operation, there is no need to reset the management controller, and the management controller can still normally load the main firmware for business processing.

[0073] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases, the former is a better implementation method.

[0074] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in this article can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.

[0075] The above has introduced in detail a firmware upgrade system and method provided by the present application. Specific examples are used in this article to elaborate on the principle and implementation manner of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application. It should be noted that for those of ordinary skill in the art in the technical field, without departing from the principle of the present application, several improvements and modifications can be made to the present application, and these improvements and modifications also fall within the protection scope of the present application.

Claims

1. A firmware upgrade system, characterized in that The firmware upgrade system includes a management controller, a logic controller, a main memory, and a backup memory; The logic controller is configured to, when receiving a first firmware upgrade instruction sent by the management controller, take over the control right of the backup memory, so as to read a pre-written upgrade firmware from the backup memory; Perform a verification operation on the upgrade firmware to obtain a verification result corresponding to the upgrade firmware; when it is determined that the verification result is passed, send a verification completion notification to the management controller; Transfer the control right of the backup memory to the management controller; The management controller is configured to, when receiving the verification completion notification and taking over the control right of the backup memory, read the upgrade firmware from the backup memory, and overwrite the read upgrade firmware into the main memory as the upgraded main firmware to complete the firmware upgrade operation of the main memory.

2. The firmware upgrade system according to claim 1, wherein The management controller is further configured to, when receiving the upgrade firmware sent by the target device, send a second firmware upgrade instruction to the logic controller; The logic controller is further configured to, when receiving the second firmware upgrade instruction, transfer the control right of the backup memory to the management controller; The management controller is further configured to, when taking over the control right of the backup memory, write the upgrade firmware into the backup memory; When it is determined that the upgrade firmware is completely written into the backup memory, send the first firmware upgrade instruction to the logic controller.

3. The firmware upgrade system according to claim 2, wherein The logic controller is further configured to, after power-on, obtain the control right of the main memory; when obtaining the control right of the main memory, read the main firmware from the main memory; Perform a verification operation on the main firmware to obtain a verification result corresponding to the main firmware; When it is determined that the verification result corresponding to the main firmware is passed, perform a de-reset operation on the management controller, and transfer the control right of the main memory to the management controller; The management controller is further configured to, when taking over the control right of the main memory, read the main firmware from the main memory and load the main firmware.

4. The firmware upgrade system according to claim 3, wherein The logic controller is further configured to, after power-on, obtain the control right of the backup memory; when obtaining the control right of the backup memory, read a backup firmware from the backup memory; perform a verification operation on the backup firmware to obtain a verification result corresponding to the backup firmware; When it is determined that the verification result corresponding to the main firmware is not passed and the verification result corresponding to the backup firmware is passed, overwrite the main firmware stored in the main memory with the backup firmware to complete the firmware recovery operation of the main memory; when it is determined that the firmware recovery operation is completed, perform a de-reset operation on the management controller, and transfer the control right of the main memory to the management controller.

5. The firmware upgrade system according to claim 4, characterized in that The backup memory includes a first storage area; the management controller is specifically configured to: Obtain a first starting address; Based on the first starting address, store the upgrade firmware in the first storage area of the backup memory.

6. The firmware upgrade system according to claim 5, wherein The backup memory further includes a second storage area; the management controller is further configured to load the upgraded firmware; when it is determined that the upgraded firmware has been loaded, obtain a second starting address, and based on the first starting address and the second starting address, overwrite and write the upgraded firmware stored in the first storage area to the second storage area as the upgraded backup firmware.

7. The firmware upgrade system according to any one of claims 1 to 6, characterized in that The firmware upgrade system includes a first selection circuit, and the first selection circuit is electrically connected to the main memory, the management controller, and the logic controller respectively; The logic controller is specifically configured to: Set the state of the switch corresponding to the logic controller in the first selection circuit to a first state, and set the state of the switch corresponding to the management controller in the first selection circuit to a second state, so as to transfer the control right of the main memory to the management controller.

8. The firmware upgrade system according to claim 7, wherein The firmware upgrade system further includes a second selection circuit, and the second selection circuit is electrically connected to the backup memory, the management controller, and the logic controller respectively; The logic controller is specifically configured to: Set the state of the switch corresponding to the management controller in the second selection circuit to the first state, and set the state of the switch corresponding to the logic controller in the second selection circuit to the second state, so as to take over the control right of the backup memory.

9. The firmware upgrade system according to claim 8, wherein The logic controller is specifically configured to: Set the state of the switch corresponding to the logic controller in the second selection circuit to the first state, and set the state of the switch corresponding to the management controller in the second selection circuit to the second state, so as to transfer the control right of the backup memory to the management controller.

10. A firmware upgrade method, characterized in that, The firmware upgrade method is applied to the firmware upgrade system according to any one of claims 1 to 9. The firmware upgrade system includes a management controller, a logic controller, a main memory, and a backup memory; the method includes: When the logic controller receives a first firmware upgrade instruction sent by the management controller, it takes over the control right of the backup memory, so as to read the pre-written upgraded firmware from the backup memory; perform a verification operation on the upgraded firmware to obtain a verification result corresponding to the upgraded firmware; when it is determined that the verification result is passed, send a verification completion notification to the management controller; transfer the control right of the backup memory to the management controller; When the management controller receives the verification completion notification and takes over the control right of the backup memory, it reads the upgraded firmware from the backup memory, and overwrites and writes the read upgraded firmware to the main memory as the upgraded main firmware, so as to complete the firmware upgrade operation of the main memory.

Citation Information

Patent Citations

  • Real-time firmware upgrading system and method

    CN111666094A

  • Electronic equipment and starting method

    CN112199235A

  • PFR-based firmware upgrading method, system and equipment and storage medium

    CN114579982A

  • Firmware upgrading method

    CN117075943A

  • Drive unit

    JP2023152082A

Cited By

  • Firmware upgrading system and method

    CN120560694A

  • Firmware upgrade system and method

    CN120560694B

  • Firmware upgrade circuit, firmware upgrade method, server, device and program product

    CN121433694A