Computing system for reducing downtime of computing service

By sharing a single non-volatile memory module in the computing system and simplifying the communication path between the BIOS and BMC flash chip, the boot latency problem is solved, boot performance is improved, hardware costs are reduced, and the commercial service efficiency of the server is enhanced.

CN120872684APending Publication Date: 2025-10-31QUANTA COMPUTER INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411564688.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-08-27
Filing Date
2024-11-05
Publication Date
2025-10-31

AI Technical Summary

Technical Problem

In existing technologies, startup delays caused by firmware checks in the startup process of computing systems affect startup performance and increase server downtime, resulting in direct profit losses, especially for cloud providers.

Method used

A computing system design is provided, which uses a shared single non-volatile memory module to boot the BIOS and BMC. By simplifying the communication path between the BIOS and BMC flash chips, read and write operations are reduced. Combined with the root of trust verification mechanism, the integrity and security of the firmware are ensured.

Benefits of technology

It reduces startup latency, improves the startup efficiency of the computing system, reduces the number and cost of hardware components, and enhances the commercial service efficiency of the server.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120872684A_ABST
    Figure CN120872684A_ABST
Patent Text Reader

Abstract

A computing system includes a CPU, a BMC coupled to the CPU via a first communication protocol, and a boot nonvolatile memory. The BMC comprises a first communication protocol controller, a BMC memory, a root of trust and an internal BMC bus. The internal BMC bus is configured to communicatively couple to the BMC memory, the first communication protocol controller, and the root of trust. The boot nonvolatile memory is coupled to the BMC via the first communication protocol controller. The boot nonvolatile memory is used for storing BIOS firmware and / or BMC firmware.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates generally to a boot procedure in a computing system, and more specifically, generally to a system and method for reducing boot delays caused by firmware checks in a computing system. Background Technology

[0002] Computing systems (such as servers, desktop computers, and laptops) can be deployed in a wide range of environments. Some computing systems rely on batteries and may need to operate at low power to reduce battery consumption. On the other hand, some computing systems may be plugged into a power outlet, where low power operation is not as important as computing performance. Many computing systems maintain a balance between performance and power consumption even when plugged into a power outlet. Regardless of the type of computing system used, it is typically initialized upon power-on. The process of initializing the computing system is called booting. Depending on the specific hardware components of the existing computing system, each system may have a different boot sequence or program. Typically, the computing system stores boot firmware in non-volatile memory verified by a root of trust. The root of trust typically verifies the boot firmware before the computing system uses it. This particular process can reduce boot performance by increasing boot time. This disclosure aims to address the problem of boot performance. Summary of the Invention

[0003] The terms used, embodiments, and similar terms are intended to refer broadly to all subject matter of this invention and the following claims. It should be understood that statements containing these terms should not limit the subject matter described in this invention or limit the meaning or scope of the following claims. The embodiments covered by this invention are defined by the following claims, not by the content of this invention. The summary of the invention is a high-level overview of various aspects of the invention and introduces some concepts that are further described in the detailed description section below. The summary of the invention is not intended to identify key or essential features of the claimed subject matter, nor is it intended to be used alone to determine the scope of the claimed subject matter. This subject matter should be understood by referring to the entire specification of the invention, any or all drawings, and appropriate portions of each claim.

[0004] According to one aspect of this disclosure, a computing system is provided. The computing system includes a central processing unit (CPU), a baseboard management controller (BMC) coupled to the CPU via a first communication protocol, and power-on non-volatile memory. The baseboard management controller includes a first communication protocol controller, BMC memory, a root of trust, and an internal BMC bus. The internal BMC bus is communicatively coupled to the BMC memory, the first communication protocol controller, and the root of trust. The power-on non-volatile memory is coupled to the baseboard management controller via the first communication protocol controller. The power-on non-volatile memory is used to store basic input / output system (BIOS) firmware and / or BMC firmware.

[0005] The foregoing description is not intended to represent every embodiment or aspect of this disclosure. Rather, it provides only examples of some novel aspects and features set forth in this disclosure. The foregoing features and advantages, as well as other features and advantages, will become apparent from the following detailed description of representative embodiments and modes of implementation of the invention when taken in conjunction with the accompanying drawings and the claims. Other aspects of this disclosure will be apparent to those skilled in the art from the detailed description of various embodiments with reference to the drawings and the brief description provided below.

[0006] To provide a better understanding of the above and other aspects of the present invention, specific embodiments are described below in conjunction with the accompanying drawings: Attached Figure Description

[0007] This disclosure, its advantages, and the drawings will be readily understood from the following description of representative embodiments in conjunction with the accompanying drawings. These drawings depict only representative embodiments and should not be construed as limiting the scope of the various embodiments or the claims.

[0008] Figure 1A A functional block diagram of a computing system according to a certain aspect of this disclosure is shown;

[0009] Figure 1B A functional block diagram showing the connection between the BIOS and BMC flash chips on a circuit board in the prior art;

[0010] Figure 2 A functional block diagram showing the connection of the BIOS and BMC flash chip on a circuit board according to a certain aspect of this disclosure;

[0011] Figure 3A flowchart illustrating the communication between the core processor, BMC, BIOS, and BMC flash chip when AC power is turned on, according to a certain aspect of this disclosure;

[0012] Figure 4 A flowchart illustrating the communication between the core processor, BMC, BIOS, and BMC flash chip when a DC power supply is turned on, according to a certain aspect of this disclosure;

[0013] Figure 5 A flowchart illustrating the communication between the BMC and the BIOS and the BMC flash chip when the BIOS is upgraded, according to a certain aspect of this disclosure;

[0014] Figure 6 A flowchart illustrating the state changes of BMC memory allocation according to a certain aspect of this disclosure;

[0015] Figure 7 Schematic (a) illustrates a flowchart of a trust root service according to a certain aspect of this disclosure;

[0016] Figure 7 Schematic (b) shows a flowchart of the first trust root service subprocess according to a certain aspect of this disclosure;

[0017] Figure 8 Schematic (a) shows a flowchart of a second trust root service subprocess according to a certain aspect of this disclosure;

[0018] Figure 8 Schematic (b) shows a flowchart of a third trust root service subprocess according to a certain aspect of this disclosure;

[0019] Figure 8 Schematic (c) shows a flowchart of the fourth trust root service subprocess according to a certain aspect of this disclosure;

[0020] Figure 9 Schematic (a) shows a flowchart of a Redfish service procedure according to a certain aspect of this disclosure;

[0021] Figure 9 Figure (b) shows a flowchart of an SPI BIOS reader service program according to a certain aspect of this disclosure;

[0022] Figure 9 Schematic (c) shows a flowchart of a service sub-process for running a first SPI emulator according to a certain aspect of this disclosure;

[0023] Figure 9 Schematic (d) shows a flowchart of a service subprocess for running a second SPI emulator according to a certain aspect of this disclosure.

[0024] [Symbol Explanation]

[0025] 100: Computing System

[0026] 102: Circuit Board

[0027] 104: Processor

[0028] 106: RAM module

[0029] 108, 142, 204: BMC

[0030] 110: BIOS

[0031] 112, 140, 218: Root of Trust

[0032] 114: I / O Port

[0033] 130, 200: System

[0034] 132, 202: Server motherboard

[0035] 134: External Network

[0036] 136: Ethernet Protocol

[0037] 138: Computer Processor Architecture

[0038] 144: BIOS flash chip

[0039] 146: BMC Flash Chip

[0040] 148a, 148b: SPI multiplexers

[0041] 206: BIOS and BMC flash chip

[0042] 210: SPI controller

[0043] 212: SPI bus emulator

[0044] 214: BMC Processor

[0045] 216: BMC Memory

[0046] 220: Ethernet Controller

[0047] 222, 226: SPI Interface

[0048] 224: Internal BMC bus

[0049] 300, 400, 500: Communications

[0050] 302: Core Processor

[0051] 304: SPI Simulation Service

[0052] 306: Root of Trust Service

[0053] 308: SPI BIOS Reader Service

[0054] 320, 326, 340, 352, 402, 404, 440, 452, 508, 510, 512, 514, 522, 552: Steps 322, 324, 328, 330, 332, 342, 344, 346, 348, 350, 442, 444, 446, 448, 516, 518, 520, 524, 526, 528, 548, 550, 560, 562, 564, 566, 701~705, 711~721, 801~803, 811~817, 901~905, 911~915, 921~922, 931~932: Step 502: Out-of-band management

[0055] 504: Redfish Service

[0056] 506: Internal Network

[0057] 600, 700, 710, 800, 810, 900, 910, 920, 930: Flowchart

[0058] 602, 604, 606, 608, 610, 612: Status

[0059] 620, 622, 624, 626, 628, 630, 632, 634, 636: Transient Detailed Implementation

[0060] Servers utilize multiple CPU cores, memory modules, and input / output (I / O) peripherals as a foundational platform to provide various real-time commercial computing services. The firmware of the hardware and I / O peripherals supporting this platform typically needs to be updated to adapt to new technological requirements. Firmware updates must generally consider security, integrity, and necessary recovery mechanisms. Servers often feature a highly integrated design between management control panels, hardware, and firmware to implement a series of integrity checks, updates, and recovery procedures for firmware components. The complexity of these procedures and the resulting extended downtime reduce the efficiency of commercial server services and increase costs. For cloud providers, the direct profit loss per hour of server downtime can be approximately five million US dollars. Therefore, improving aspects related to server downtime can simultaneously improve server functionality and uptime.

[0061] In computing systems, the processor (such as the central processing unit, CPU) is usually involved in the startup of the BIOS (basic input / output system).

[0062] Providing two non-volatile memory modules on the same computing system, solely for system initialization, is wasteful. The second non-volatile memory module may occupy space on the motherboard that could be used by other components. Physical space on the motherboard is limited, and computer engineering trends aim to install as much hardware as possible on the motherboard to enhance the functionality of the computing system. Furthermore, these trends sometimes involve reducing the size of the motherboard so that the computing system can have a smaller form factor. Reducing hardware components, such as the number of non-volatile memory modules provided on the motherboard, can reduce the financial costs of building the computing system. Therefore, this disclosure provides a system and method for booting both the BIOS and BMC using a single non-volatile memory module. A boot sequence for using the shared single non-volatile memory module is also provided.

[0063] Various embodiments are described with reference to the accompanying drawings, wherein all drawings use the same component reference numerals to denote similar or equivalent components. The drawings are not necessarily drawn to scale and are provided only to illustrate aspects and features of this disclosure. Numerous specific details, relationships, and methods are set forth to provide a comprehensive understanding of certain aspects and features of this disclosure, although those skilled in the art will recognize that these aspects and features can be implemented without one or more of the specific details, relationships, or methods. In some cases, well-known structures or operations are not shown in detail for illustrative purposes. The various embodiments disclosed herein are not necessarily limited to the order of the described actions or events, as some actions may occur in a different order and / or simultaneously with other actions or events. Furthermore, not all actions or events in the drawings are necessary to implement certain aspects and features of this disclosure.

[0064] For the purposes of this detailed description, unless otherwise stated and where appropriate, the singular includes the plural, and vice versa. The word "including" means "including but not limited to." Furthermore, approximate words such as "about," "almost," "substantially," "approximately," etc., may be used in this disclosure, for example, to mean "in," "close to," "nearly," or "within 3-5%," or "within acceptable manufacturing tolerances," or any logical combination thereof. Similarly, the terms "vertical" or "horizontal" are intended to additionally include "within 3-5%" in the vertical or horizontal direction, respectively. Additionally, directional words such as "top," "bottom," "left," "right," "above," and "below" are intended to relate to the equivalent directions described in the reference figures; to be understood from the context of the referenced object or component, such as from its usual location; or as stated herein.

[0065] Referring to Figure 1, a functional block diagram of a computing system 100 is provided. Examples of the computing system 100 include servers, laptops, desktop computers, smartphones, etc. The computing system 100 includes a circuit board 102. The circuit board 102 may be a printed circuit board (PCB) serving as a communication backbone connecting all components and external peripherals of the computing system 100. In some examples, the circuit board 102 is a motherboard including copper interconnects and copper planes for power and signal isolation. The motherboard may include a processor 104, a RAM module 106, a BMC 108, a BIOS 110, a root of trust 112, and / or one or more input / output (I / O) ports 114.

[0066] Although shown singularly in Figure 1, processor 104 may be one or more processors (e.g., one processor, two processors, three processors, etc.). Processor 104 may include multiple central processing units (CPUs) and multiple graphics processing units (GPUs). In some embodiments, the multiple GPUs are independent of the multiple CPUs and communicate with the multiple CPUs via one or more I / O ports 114 on board 102. For example, I / O ports 114 include multiple peripheral component interconnect express (PCIe) slots for receiving multiple GPUs, and multiple CPUs can manage the initialization operation of the multiple GPUs via the PCIe bus standard. The multiple GPUs are coupled to a graphics interface, allowing multiple monitors or screens to be connected to board 102. Processor 104 may be communicatively coupled to a platform controller hub (PCH) or chipset of board 102. The chipset of circuit board 102 can provide access to communication standards, such as Serial Advanced Technology Attachment (SATA) devices, PCIe devices, network interface cards (NICs), redundant array of inexpensive disks (RAID) cards, small computer system interface (SCSI) cards, field programmable gate array (FPGA) cards, etc.

[0067] RAM module 106 may include a dual in-line memory module (DIMM) of double data rate synchronous dynamic random access memory (DDR SDRAM). RAM module 106 is a high-speed volatile memory module that can serve as the main memory for processor 104. The main memory of processor 104 is used when the cache or temporary storage memory of processor 104 does not contain the information required by processor 104. RAM module 106 is a higher-capacity memory compared to the cache or temporary storage memory of processor 104. RAM module 106 may represent multiple RAM modules (e.g., multiple DIMMs, such as two DIMMs, four DIMMs, eight DIMMs, etc.).

[0068] BMC 108 is a dedicated controller (or processor) for managing the operation of computing system 100. In some embodiments, BMC 108 enables remote monitoring of computing system 100 and has communication channels to different components of computing system 100. For example, BMC 108 may allow remote monitoring of fan speed, temperature sensors, hard disk failure, power supply failure, operating system failure, etc. BMC 108 may include an internal temporary cache to facilitate the processing of machine-readable instructions. Several example BMCs include ASPEED AST2300, AST2400, AST2500, or AST2600, etc.

[0069] BIOS 110 represents a read-only memory (ROM) or flash chip provided on circuit board 102, allowing access to and basic settings of the computing system 100. When the computing system 100 boots, BIOS 110 includes instructions (or program code) on how to load basic computer hardware (such as some previously discussed components, like the GPU, keyboard interface, mouse interface, etc.). BIOS 110 includes a self-test, which runs when the computing system 100 is powered on, to ensure that the computing system 100 properly meets the boot requirements. This self-test can be referred to as the BIOS power-on self-test (POST). When the computing system 100 fails the BIOS power-on self-test (POST), it typically provides a series of warning sounds. The form of the warning sounds indicates which hardware component has failed. The BIOS Self-Test (POST) can identify basic problems. For example, the BIOS Self-Test (POST) can provide basic memory checks (such as checking the steps that can be written to or read from memory), basic storage checks (such as checking the hard drive to start and accept commands and / or rotate and allow access), and basic input and output device checks (such as checking whether the keyboard has stuck keys or whether at least one of the keyboard or mouse is connected).

[0070] The program code in BIOS 110 can be updated for various reasons. In one example, a firmware update for BIOS 110 may include driver updates for better control of peripheral devices, such as the mouse and keyboard. A BIOS firmware update may include adding extra functionality, such as updating a text-based BIOS to a graphical user interface (GUI)-based BIOS. Typically, when updating the BIOS 110 firmware, the BIOS settings can be overwritten.

[0071] The root of trust 112 is a complex programmable logic device (CPLD) that performs critical security functions. The root of trust 112 may include keys for cryptographic functions and a secure boot program. The root of trust 112 is used to verify the BMC and / or BIOS image. The root of trust 112 is used to verify updated BIOS images, updated BMC images, etc. The root of trust 112 can verify these images before they are used by the processor 104.

[0072] One or more I / O ports 114 may include SATA ports to connect bus adapters to storage devices, such as hard drives, solid-state drives (SSDs), optical discs, etc. I / O ports 114 may include additional PCI or PCIe ports for receiving adapter cards, such as Ethernet cards, Wi-Fi cards, Bluetooth cards, sound cards, etc. I / O ports 114 may include universal serial bus (USB) ports for connecting peripheral devices or high-capacity storage devices.

[0073] Although Figure 1A Only a single circuit board 102 is provided; the computing system 100 may include multiple nodes having multiple circuit boards. In some embodiments, each circuit board is a server circuit board representing a different server node. In some embodiments, a single BMC (e.g., BMC 108) can manage the operation of multiple circuit boards. In some embodiments, multiple BMCs can manage the operation of multiple circuit boards, such that corresponding circuit boards have corresponding BMCs.

[0074] Reference to Figure 1B This diagram illustrates the out-of-band (OOB) management of the BIOS flash chip 144 and BMC flash chip 146 on a server motherboard 132, and the functional block diagram of system 130 in the prior art. System 130 includes server motherboard 132 and external network 134. Server motherboard 132 obtains access to external network 134 via Ethernet protocol 136. Ethernet protocol 136 supports out-of-band (OOB) communication.

[0075] Server motherboard 132 is a circuit board provided in a computing system (e.g., computing system 100). Server motherboard 132 includes a computer processor architecture 138, a root of trust 140, a BMC 142, a BIOS flash chip 144, a BMC flash chip 146, and SPI multiplexers 148a and 148b. The computer processor architecture 138 may be an x86 architecture or an ARM architecture.

[0076] The server's boot firmware, such as BIOS or UEFI (Unified Extensible Firmware Interface), is stored in non-volatile memory. Figure 1BIn this configuration, the non-volatile memory is the BIOS flash chip 144. The BIOS flash chip 144 has an interface compliant with any industry standard and can be connected between the core processor (included in the computer processor architecture 138) and the erasable programmable read-only memory device. During power-on of the server platform, the root of trust 140 and the designated processor unit check the legitimacy and validity of portions of the BIOS flash chip 144. Then, the boot firmware (e.g., BIOS or UEFI) is loaded from the non-volatile memory (e.g., the BIOS flash chip 144) into the system memory (included in the computer processor architecture 138). The core processor then executes an initialization procedure until the server's operating system is loaded.

[0077] Firmware updates can be performed in-band or out-of-band. When the boot firmware is updated, the root of trust 140 writes the new firmware content to the correct block of non-volatile memory. The root of trust 140 can verify the new BIOS image and / or BMC image destined for BIOS flash chip 144 or BMC flash chip 146, respectively. The term "downtime" refers to the unavailability of core services (internal and / or external) of the server system, device, or application after the server receives the boot firmware update command. The boot firmware update command typically follows by downloading a series of boot firmware contents, verifying the downloaded boot firmware contents, applying the updated downloaded boot firmware contents, or, if the downloaded boot firmware contents fail verification, restoring a restore procedure to an older boot firmware version.

[0078] Computer processor architecture 138 reads from BIOS flash chip 144 using the SPI protocol via SPI multiplexer 148a. BMC flash chip 146 receives the BMC image via SPI multiplexer 148b. Root of trust 140 sets and controls SPI multiplexers 148a and 148b to allow the programming of the BIOS and / or BMC image. When the BIOS and / or BMC image is used by computer processor architecture 138 and / or BMC 142, root of trust 140 also sets and controls SPI multiplexers 148a and 148b.

[0079] The root of trust 140 performs verification on the BIOS flash chip 144 and / or the BMC flash chip 146. The root of trust 140 connects to the BIOS flash chip 144 and / or the BMC flash chip 146 to check the "correctness" of the content. For example, the root of trust 140 can check whether the content has a correct signature or checksum, and whether the stored content is complete. The root of trust 140 performs these checks before each boot process. Only after the checks are complete will the root of trust 140 enable the subsequent boot process and allow the core processor in the computer processor architecture 138 to read from the BIOS flash chip 144 to configure and enable the services provided by the server. During the update of the BIOS image and / or BMC image, the root of trust 140 connects to the SPI interface and programs the corresponding image to the corresponding flash chip.

[0080] The root of trust 140 typically performs a check each time the server boots up to ensure the integrity of the BIOS and / or BMC image. If the BMC 142 fails to properly upgrade or update the BIOS and / or BMC image due to power loss or a corrupted BIOS and / or BMC image, a recovery mechanism is triggered. In some cases, the recovery mechanism includes reading a recovery image to restore the BIOS and / or BMC image. The server motherboard 132 provides complex hardware connections and firmware design to ensure the integrity of the BIOS and / or BMC image. Several embodiments of this disclosure provide methods for reducing... Figure 1B Systems and methods that address the complexity of hardware connectivity and firmware design.

[0081] Typically, the SPI bus is used as the communication interface between the core processor of the computer processor architecture 138 and the erasable programmable read-only memory (e.g., the BIOS flash chip 144). The core processor internally creates the SPI master control logic and communicates with the BIOS flash chip 144, which is configured as an SPI slave. Communication is achieved through SPI industry-standard interfaces for read and write operations (e.g., chip select (CS), synchronous clock (SCLK), master out slave in (MOSI), and master in slave out (MISO)). Whether during server startup, when its root of trust 140 must perform content security checks before the core processor reads the BIOS content, or during BIOS updates, when a previous backup of the BIOS content needs to be completed, the different hardware logic circuits in the root of trust 140 and BMC 142 must cooperate to achieve this goal. Furthermore, the complexity of the circuit design of the root of trust 140, BIOS flash chip 144, and BMC flash chip 146 increases because different SPI masters use multiple multiplexers for read / write operations on non-volatile memory (such as BIOS flash chip 144 and BMC flash chip 146).

[0082] Reference to Figure 2 This illustrates a functional block diagram of an out-of-band management and system 200 for connecting a BIOS and BMC flash chip 206 on a circuit board, according to a certain aspect of this disclosure. The circuit board is similar to or identical to circuit board 102. Figure 1A The circuit board can be identified as server motherboard 202. System 200 includes server motherboard 202 and external network 134. Similar to... Figure 1B The server motherboard 202 obtains access to the external network 134 via Ethernet protocol 136. Ethernet protocol 136 is provided only as an example; any communication protocol that supports out-of-band communication can be used. Although out-of-band communication is used here as an example, access to the external network 134 may also use in-band communication. Therefore, any communication protocol that supports either out-of-band or in-band communication can be used. Similarly, the communication protocol does not need to be a wired communication protocol. Wireless communication protocols, such as Bluetooth, WiFi, etc., can be used to obtain access to the external network 134.

[0083] Server motherboard 202 is a circuit board provided for a computing system (e.g., computing system 100). Server motherboard 202 includes a computer processor architecture 138, a BMC 204, and a BIOS and BMC flash chip 206. In some embodiments, the BIOS and BMC flash chip 206 is provided as a single flash chip. In some embodiments, the BIOS and BMC flash chip 206 includes multiple flash chips having a first flash chip for storing a BIOS image and a second flash chip for storing a BMC image. The BIOS and BMC flash chip 206 is boot non-volatile memory. Boot non-volatile memory is erasable read-only memory or some other memory used to store the BIOS image and / or BMC image.

[0084] Computer processor architecture 138 includes a core processor (e.g., processor 104). Figure 1A The CPU in the processor 104, core memory (e.g., internal memory of processor 104, memory related to RAM module 106, etc.). The computer processor architecture 138 is used to run the operating system of a server with a server motherboard 202. The computer processor architecture 138 typically fetches the BIOS firmware from boot non-volatile memory to initialize server-related hardware and services before booting into the operating system. The computer processor architecture 138 can use a first communication protocol to fetch the BIOS firmware from boot non-volatile memory. Figure 2 In this configuration, the first communication protocol is provided as SPI interface 226. SPI interface 226 facilitates communication between BMC 204 and the core processor of computer processor architecture 138.

[0085] BMC 204 may include an SPI bus emulator 212. The SPI bus emulator 212 can operate in slave mode. The SPI bus emulator 212 is used to respond to read and write requests to the boot-up non-volatile memory from the core processor of the computer processing architecture 138.

[0086] BMC 204 includes SPI controller 210. SPI controller 210 is an example of a first communication protocol controller that facilitates communication between BMC 204 and the BIOS and BMC flash chip 206. SPI interface 222 instructs BMC 204 to read from and / or write to the BIOS and BMC flash chip 206 via SPI interface 222.

[0087] BMC 204 may include BMC processor 214, BMC memory 216, root of trust 218, and Ethernet controller 220. BMC processor 214 and BMC memory 216 cooperate to provide services related to BMC 204. In some embodiments, BMC processor 214 is a quad-core processor. Root of trust 218 provides functionality similar to root of trust 112. Ethernet controller 220 is used to communicate with external network 134 via Ethernet protocol 136. As discussed above, Ethernet is only one example. Ethernet controller 220 can be any network controller used to provide in-band and / or out-of-band communication. BMC processor 214, BMC memory 216, SPI bus emulator 212, SPI controller 210, root of trust 218, and Ethernet controller 220 are communicatively coupled to each other via internal BMC bus 224.

[0088] The internal BMC bus 224 may be a high-speed bus using a different communication protocol than SPI. The internal BMC bus 224 facilitates communication between multiple components within the BMC 204. A portion of the BMC memory 216 may be allocated for storing BIOS firmware and / or BMC firmware. The portion of the BMC memory 216 allocated for storing BIOS firmware and / or BMC firmware may be managed by the root of trust 218 via the internal BMC bus 224. The capacity of the BMC memory 216 may be several orders of magnitude larger than the capacity of the BIOS and BMC flash memory 206. In some embodiments, the BMC memory 216 may have a capacity of at least 1 GB (gigabyte), and the BIOS and BMC flash memory chip 206 may have a capacity of less than 128 MB (megabyte). In some embodiments, the BMC memory 216 may be approximately 16 GB, and the BIOS and BMC flash memory chip 206 may be approximately 64 MB. In the server motherboard 202, since the root of trust 218 is provided in the BMC 204, the communication between the BIOS firmware and the core processor of the computer processor architecture 138 is through the BMC 204.

[0089] In system 200, the computer processor architecture 138 does not need to know the location of the BIOS and BMC flash chip 206. Because the BMC memory 216 has a very large capacity, it can store multiple versions of the BIOS firmware. For example, the root trust 218 can allocate memory locations or space within the BMC memory 216 for the first BIOS firmware, and when the first BIOS firmware is updated to the second BIOS firmware, the root trust 218 can create space within the BMC memory 216 for the second BIOS firmware. The root trust 218 can check the contents of the second BIOS firmware at any time without waiting for a server reboot. Reducing the amount of reading or writing to the BIOS and BMC flash chip 206 helps extend the lifespan of the flash memory.

[0090] In some implementations, the SPI bus emulator 212 responds to read and write requests from the core processor on the SPI industry-standard interface. The core processor directs these requests to boot-up non-volatile memory (e.g., the BIOS flash chip), but SPI industry-standard interface signals intercepted by the BMC 204 and BMC memory 216 are used to respond to the core processor's read and write requests on the SPI industry-standard interface. SPI signals include CS, SCLK, MOSI, and MISO, which can be emulated via the four general-purpose input / output (GPIO) pins of the BMC 204. The BMC 204 can perform these emulations using relevant new runtime services (SPI emulator runtime services), and even the BMC 204's field-programmable gate array (FPGA) can be used to improve the performance of some protocol requests / responses. The SPI controller 210 can read data from the BIOS and BMC flash chip 206, thus making the BIOS and BMC flash chip 206 slave devices that can be read and / or written to by anyone. Compared to Figure 1B The communication path and protocol for reading and writing to the BIOS and BMC flash chip 206 on the server motherboard 132 are simplified. The program code inside the BMC can simulate the above behavior (e.g., FPGA logic).

[0091] Figure 3 This diagram illustrates a flowchart of communication 300 between the core processor 302, BMC 204, BIOS, and BMC flash chip 206 when an alternating current (AC) power supply is turned on, according to a certain aspect of this disclosure. The core processor 302 relates to computer processor architecture 138. Figure 2 The core processor of ). Figure 2 The provided BMC 204 software and hardware components run different services, including SPI emulation service 304, root of trust service 306, and SPI BIOS reader service 308. SPI emulation service 304 implements the above-mentioned functions with SPI bus emulator 212 (…). Figure 2 The Trust Root Service 306 implements the functions related to Trust Root 218. Figure 2 The SPI BIOS reader service 308 implements functions related to the aforementioned SPI controller 210. Figure 2 (Related functions)

[0092] At Figure 3As the AC power is turned on and the DC power is turned off, as indicated in step 320, the BMC operates in DC standby power. In some embodiments, when the server is plugged into an AC outlet, DC standby power is still provided even if the power switch on the server is not turned on. Figure 3 also illustrates the possible actions that may occur when the server is first plugged into an AC outlet. Step 320 indicates that when AC power is available, the BMC 204 is powered on and operates in standby power.

[0093] Upon first insertion into the AC power outlet, after BMC 204 is powered on (step 320), BMC memory 216 is assumed not to contain a valid BIOS binary image (e.g., valid BIOS firmware). Therefore, as provided in step 326, the portion of BMC memory 216 used for the BIOS binary image is unsealed and inactivated.

[0094] In step 322, the SPI BIOS reader service 308 reads the BIOS binary image from the BIOS and BMC flash chip 206 using the SPI interface 222. In step 324, the SPI BIOS reader service 308 uploads the BIOS binary image to the BMC memory 216. A portion of the BMC memory 216 is connected to the root of trust 218 (…). Figure 2 This portion of BMC memory 216 is allocated for storing and maintaining the BIOS binary image. This portion of BMC memory will be referred to herein as BMC allocated memory. The SPIBIOS reader service 308 uploads the BIOS binary image read from the BIOS and BMC flash chip 206 to the BMC allocated memory.

[0095] In step 328, the root trust service 306 initiates a security procedure to check the contents of the BMC allocated memory to ensure that the BIOS binary image is valid or legitimate. After successfully verifying the signature of the BIOS binary image using the public key, in step 330, the root trust service 306 grants read / write access permissions (licenses) to the SPI emulation service 304 to the BIOS SPI memory. Here, read / write access permissions are granted to multiple master devices connected to the SPI emulation service 304 to read from and / or write to the BMC allocated memory of the BMC memory 216. In step 332, the status of the BMC allocated memory is indicated as sealed. The sealed status indicates that the BIOS binary image now stored in the BMC allocated memory has been verified by the root trust service 306.

[0096] Step 340 indicates the DC power supply is on. For example, the power switch on the server is turned on, causing the server to start the startup process. The DC power on event initiates the POST process.

[0097] During the POST procedure, in step 342, the core processor 302 uses the SPI interface 226 to send a request to read the BIOS boot sector to the SPI emulation service 304. The core processor 302 can request to read a specific portion of the BIOS boot sector based on the location or location range provided by the core processor 302. In step 344, the SPI emulation service 304 reads the requested portion of the BIOS binary image from memory allocated by the BMC. In step 346, the SPI emulation service 304 provides the read portion of the BIOS binary image to the core processor 302. Through steps 342 to 346, the core processor 302 stores a copy of the BIOS binary image in memory associated with the core processor. The SPI interface 226 is used to receive the copy of the BIOS binary image. For brevity and clarity, this copy of the BIOS binary image is referred to as the core copy BIOS image.

[0098] Having a kernel copy of the BIOS image in memory associated with core processor 302, core processor 302 can use the kernel copy BIOS image to further perform work related to the POST procedure. In step 348, core processor 302 alerts the root trust service 306 that the POST procedure has been completed.

[0099] In step 350, the root trust service 306 sets the BMC allocated memory status to enabled. The enabled status indicates that the BIOS binary image used by the core processor 302 during the POST process is the same as the BIOS binary image stored in the BMC allocated memory. Step 352 instructs the BMC allocated memory of BMC memory 216 to be both asserted and enabled. In some embodiments, the status is indicated by a flag of a memory region, where a single bit can indicate that the BMC allocated memory is asserted, and another single bit can indicate that it is enabled. Both flags can be asserted to indicate assertion and enabling, and no flag is asserted to indicate unassailed and not enabled. One of the flags can be asserted to indicate either assertion or enabling. Figure 3 The root trust service 306 is shown to perform authentication and validity checks during DC standby power, and these checks are not required when the server is first started. This saves time during startup, especially when the authentication and validity checks performed by the root trust service 306 are completed before the DC power is turned on.

[0100] Figure 4 A flowchart illustrating communication 400 between the core processor 302, BMC 204, BIOS, and BMC flash chip 206 when a DC power supply is turned on, according to a certain aspect of this disclosure, is shown. An example scenario where the server is powered off and operating on DC standby power is applicable. Figure 4 Example. In this case, communication 300 ( Figure 3 This has already occurred, causing the BMC to be in a state of being both started and sealed for memory allocation.

[0101] Step 402 instructs that when BMC allocated memory is started, the trust root service 306 may skip the validity check of the BMC binary image stored in BMC memory 216. Therefore, it is not necessary to perform a check similar to... Figure 3 Steps 328 to 332. Furthermore, step 404 indicates that since the BMC allocated memory status is indicated as sealed, the SPI BIOS reader service 308 can skip reading the BIOS binary image file stored in the BIOS and BMC flash chip 206. Therefore, it is not necessary to perform actions similar to... Figure 3 Steps 322 to 324.

[0102] Step 440 indicates the DC power supply is on. For example, the power switch on the server is turned on, causing the server to begin the startup process, similar to step 340. The DC power supply on event initiates the POST process. The occurrence of the POST process has been previously referred to... Figure 3Explanation. For example, step 442 is similar to or the same as step 342, step 444 is similar to or the same as step 344, step 446 is similar to or the same as step 346, and step 448 is similar to or the same as step 348. Step 452 indicates that the state of BMC memory allocation remains sealed and started. Figure 4 This indicates that it is not necessary to check the BIOS binary image in the boot process every time the server is restarted. Figure 1B The server architecture is the opposite.

[0103] In some implementations, Figure 3 and Figure 4 The following combinations are possible. When BMC 204 is powered on using AC power, it can be assumed that the optimal BIOS binary image was properly burned into the BIOS and BMC flash chip 206 during manufacturing. A new service called SPI BIOS Reader Service 308 can read the complete contents of the BIOS binary image stored in the BIOS and BMC flash chip 206 into the BMC allocated memory. Next, a new BMC security mechanism (e.g., Root of Trust Service 306) performs regularity and security checks on the contents of the BMC allocated memory to ensure the validity of the content. Once confirmed, Root of Trust Service 306 notifies SPI emulation service 304 to allow core processor 302 to respond to all read and write operations to BMC memory 216.

[0104] After the core processor boots up on DC power, the core processor 302 retrieves the BIOS binary image from the BMC allocated memory via SPI emulation service 304 and executes the POST procedure until completion. The BMC allocated memory is set to boot mode upon completion of the POST procedure. After successful security authentication, the BMC can maintain the BIOS binary image in the BMC allocated memory during each DC power cycle, eliminating the need for repeated regularity and security checks, compared to… Figure 1B The server architecture reduces the time required to execute POST programs.

[0105] Figure 5 This diagram illustrates a flowchart of communication 500 between the BMC 204 and the BIOS and BMC flash chip 206 when the BIOS binary image is upgraded, according to a certain aspect of this disclosure. Out-of-band management 502 represents a remote computing device (e.g., a computing device or computing system used by an administrator). Out-of-band management 502 can communicate with the BMC 204 via an Ethernet network, as previously described. Figure 5 In this context, the Ethernet connection can be within an internal network (e.g., internal network 506). BMC 204 can run one or more services to facilitate communication within internal network 506. For example, in... Figure 5In the middle, BMC 204 is running Redfish service 504.

[0106] When the DC power supply is turned off, out-of-band management occurs, and the BMC 204 operates in DC standby mode. Figure 5 In this scenario, step 512 instructs the BMC to allocate memory for startup. Step 514 instructs the BMC to allocate memory for sealing. Therefore, similar to step 404... Figure 4 The reading of the BIOS binary image file can be skipped.

[0107] In step 516, out-of-band management 502 provides the BMC 204 with a command to perform a BIOS upgrade to the Redfish service 504. The command indicates that the Redfish API / redfish / v1 / UpdateService is available for BIOS upgrades. In step 518, the Redfish service 504 notifies the root trust service 306 that the BIOS upgrade has begun. In step 520, in response to the start of the BIOS upgrade, the root trust service 306 sets the BMC memory allocation to disabled. Step 522 instructs the BMC memory allocation to be disabled.

[0108] In step 524, the new BIOS binary image is uploaded to the BMC allocated memory via Redfish service 504. When the BMC allocated memory is replaced by the new BIOS binary image, the BMC allocated memory becomes unsealed. In step 526, the root trust service 306 initiates a security procedure to check the contents of the BMC allocated memory to ensure the BIOS binary image is valid, similar to step 328. Figure 3 Once verified as valid, in step 528, the Trust Root Service 306 grants read / write access permissions to the BIOSSPI memory, similar to step 330. Figure 3 ).

[0109] Step 508 instructs a DC power cycle restart, in which the DC power supply is turned on. Core processor 302 executes the POST procedure as discussed above (e.g., referring to...). Figure 3 In step 548, the core processor 302 alerts or notifies the root trust service 306 about the completion of the POST procedure, similar to step 348 or step 448. With the completion of the POST procedure, in step 550, the root trust service 306 sets the BMC memory allocation status to enabled. Step 552 instructs the BMC memory allocation to be both sealed and enabled.

[0110] In step 560, the root trust service 306 schedules a backup of the BMC allocated memory (e.g., copying the BMC allocated memory). Step 510 instructs the DC power supply to be turned off. Using DC standby power, in step 562, the root trust service 306 notifies the SPI BIOS reader service 308 to back up the new BIOS binary image to the BIOS and BMC flash chip 206. In step 564, the SPI BIOS reader service 308 reads the new BIOS binary image from the BMC memory 216. In step 566, the SPI BIOS reader service 308 programs the new BIOS binary image to the BIOS and BMC flash chip 206.

[0111] Several embodiments of this disclosure use BMC allocated memory as a medium to store updated BIOS binary images (e.g., new BIOS binary images). The root trust service 306 checks the new BIOS binary image and schedules a backup program for the new BIOS binary image to the BIOS and BMC flash chip 206. In some embodiments, if the root trust service 306 cannot verify the new BIOS binary image (e.g., the new BIOS binary image is invalid), the root trust service 306 can perform a recovery operation from the BIOS and BMC flash chip 206. Figure 5 The examples provided reduce the downtime required for server power restarts and BIOS firmware updates.

[0112] In some implementations, the SPI multiplexers 148a and 148b, used for SPI bus circuitry and operation due to multiple SPI masters, are removed. Furthermore, routine security checks at each server DC power-on are also unnecessary. Several embodiments of this disclosure provide, after confirming validity and correctness, checking the updated BIOS binary image from the in-band or out-of-band programmed BMC allocated memory and verifying the signature of the BIOS binary image using a public key. In a future DC power-off state, the root trust service 306 can schedule the backup of the updated BIOS binary image from the BMC allocated memory to the BIOS and BMC flash chip 206. The scheduling of writes to the BIOS and BMC flash chip 206 reduces redundant writes to the BIOS and BMC flash chip 206 compared to... Figure 1B The architecture increases the lifespan of the BIOS and BMC flash chip 206 through lower-frequency writes. Similarly, because validity verification and writes to the BIOS and BMC flash chip 206 occur during DC power-off, server downtime can be used more efficiently, and compared to... Figure 1BThe architecture allows for faster startup. When stored in BMC memory 216, the security of the BIOS binary image is enhanced because any malicious attacks originating from the server's core processor 302 on the SPI interface 226 can be blocked by the SPI bus emulator 212.

[0113] Figure 6 A flowchart 600 illustrates a change in the state of BMC memory allocation according to a certain aspect of this disclosure.

[0114] In state 602, the server is powered on by AC power (e.g., as described above, plugged into an AC power outlet). In state 602, the BMC allocated memory is unsealed and not started, the BIOS binary image of the BMC allocated memory is invalid, and the SPI emulation service 304 does not have read / write access to the BMC allocated memory. See steps 320 and 326.

[0115] Starting from state 602, transient 622 occurs after the DC power is turned on. The BIOS binary image is copied from the BIOS and BMC flash chip 206 to the BMC allocated memory. The root trust service 306 authenticates the copied BIOS binary image as valid, and the core processor 302 successfully completes the POST procedure. Transient 622 leads to state 604. In state 604, the server is running, the BMC allocated memory is sealed and started, the BIOS binary image in the BMC allocated memory is valid, and the SPI emulation service 304 has read and write access permissions to the BMC allocated memory.

[0116] Starting from state 604, if the AC power is turned off and then on, transient 620 occurs to return to state 602. If the BIOS upgrade program is started, transient 628 occurs to enter state 610. In state 610, the server is running, the BMC-allocated memory is changed to be sealed and not enabled, the BIOS binary image of the BMC-allocated memory is changed to be invalid, and the SPI emulation service 304 maintains read and write access to the BMC-allocated memory. Starting from state 604, if the DC power is turned off, transient 630 occurs to reach state 606. In state 606, the server is running on DC standby power, the BMC-allocated memory remains sealed and enabled, the BIOS binary image of the BMC-allocated memory is valid, and the SPI emulation service 304 maintains read / write access to the BMC-allocated memory.

[0117] Starting from state 606, if the DC power supply is restarted, transient 632 occurs to return to state 604. If the AC power supply is turned off and then restarted, transient 620 occurs to return to state 602. If the BIOS upgrade process begins, transient 634 occurs to enter state 608. In state 608, the server continues to operate on DC standby power, the BMC-allocated memory is changed to be sealed or not started, the BIOS binary image of the BMC-allocated memory is set to invalid, and the SPI emulation service 304 maintains read / write access to the BMC-allocated memory.

[0118] Starting from state 608, if the DC power supply is restarted, the BIOS binary image of the BMC-allocated memory is valid, the POST procedure is completed, and then transient 624 occurs to return to state 604. If the AC power supply is turned off and then restarted, transient 620 occurs to return to state 602. The updated BIOS binary image of the BMC-allocated memory is invalid (illegitimate or illegal), and then transient 636 occurs to enter state 612. In state 612, the BMC-allocated memory remains sealed or not started, the BIOS binary image of the BMC-allocated memory remains invalid, and the SPI emulation service 304 maintains read / write access to the BMC-allocated memory.

[0119] When the BIOS binary image for memory allocated by the BMC is invalid, state 610 can also lead to state 612. Starting from state 610, if the DC power supply is restarted (e.g., DC power on and off), the updated BIOS binary image for memory allocated by the BMC becomes valid, and the POST procedure is successfully completed. Then, transient 626 occurs to enter state 604.

[0120] Starting from state 612, after the DC power is turned on, the BIOS binary image is copied by the BIOS and BMC flash chip 206 to the BMC allocated memory. The root trust service 306 verifies that the copied BIOS binary image is valid, the core processor 302 successfully completes the POST procedure, and transient 622 occurs to reach state 604. The letter "A" indicates the connection between state 612 and state 604. After the recovery procedure and the BIOS binary image are retrieved from the BIOS and BMC flash chip 206, a transient occurs between state 612 and state 604.

[0121] On the server, the core processor 302 and BMC 204 operate as two independent ecosystems. After AC power is turned on, BMC 204 begins its own initialization, then emulates the SPI runtime service 304 to provide the BIOS binary image required by the core processor 302 to execute the POST procedure. The BIOS binary image can be upgraded via an out-of-band interface (OOB interface) in either the server's running state or its standby power-off state. Several embodiments of this disclosure utilize both states of BMC-allocated memory to operate a general POST procedure and a specific POST procedure based on the upgraded BIOS binary image.

[0122] Furthermore, from the perspective of the server's core processor 302, the BMC SPI emulation service 304 effectively standardizes the software and hardware requirements for the virtual SPI flash chip because the SPI signals and protocols provided by the SPI bus emulator 212 (e.g., read / write / erase) have specific and fixed IDs. Therefore, the BMC 204 can easily connect to different core processor platforms, such as Intel or AMD, without needing to consider settings or compatibility on the server's core processor side. Figures 7 to 9 This disclosure provides an architecture for processes and subprocesses that can be used across multiple core processor platforms, based on several specific aspects thereof.

[0123] Figure 7 Schematic (a) is a flowchart 700 for a trust root service according to several specific aspects of this disclosure. In step 701, the trust root service sets the variable "BMC allocated memory" to be unsealed and not started. In step 702, the trust root service temporarily stores or registers the callback runtime "BMC allocated memory updated (X)". In step 703, the trust root service invokes "SPI BIOS read service()". In step 704, the trust root service invokes "SPI emulator run service launcher()". In step 705, the trust root service temporarily stores or registers the callbacks "BIOS POST complete()" and "BIOS upgrade start()".

[0124] Figure 7Schematic (b) is a flowchart 710 of the first root trust service sub-process for "BMC allocated memory is updated (X)" in step 702, according to several specific aspects of this disclosure. In step 711, the first root trust service sub-process calls "Verify BIOS signature ()". In step 712, based on the result of the validity check, the first root trust service sub-process determines in steps 713 and 718 whether the BIOS binary image originates from the BIOS and BMC flash chip 206 or from out-of-band. If the validity check indicates an invalid BIOS signature and the BIOS binary image originates from out-of-band, then in step 714, the BMC allocated memory is set to unsealed, and in step 715, "SPI BIOS read service ()" is called. If the validity check indicates an invalid BIOS signature and the BIOS binary image originates from the BIOS and BMC flash chip 206, then in step 716, the first root trust service sub-process calls "Disable SPI emulator running service ()". Then, in step 717, a log is created indicating that the BIOS and BMC flash chip 206 have been created.

[0125] If the validity check indicates a valid BIOS signature, and the BIOS binary image is from the BIOS and BMC flash chip 206, the first root of trust service subprocess determines in step 719 whether the SPI emulator BIOS read service has been started. If it has not been started, in step 720, the SPI emulator BIOS read service is started, and then in step 721, the BMC allocated memory is set to a sealed state.

[0126] Figure 8 Figure (a) illustrates a flowchart 800 of the second root trust service sub-process of step 705, "BIOS POST Complete()", according to a certain aspect of this disclosure. In step 801, if BMC allocated memory is not enabled, then in step 802, BMC allocated memory is enabled. In step 803, the SPI BIOS Read Service() is scheduled to execute on a DC standby power supply with AC power.

[0127] Figure 8Schematic (b) illustrates a flowchart 810 of the third root of trust service sub-process for step 711, "Verifying the BIOS Signature ()," according to a certain aspect of this disclosure. In step 811, the third root of trust service sub-process searches for a signature in the manifest list of memory allocated by the BMC. In step 812, it is determined whether the signature has been found. If not found, then in step 813, the BIOS binary image allocated by the BMC is invalidated and the result is updated. In step 812, if the signature has been found, in step 814, the signature is decoded using the public key to obtain a first hash value. In step 815, a hash operation is performed on the BIOS binary image allocated by the BMC to obtain a second hash value. In step 816, the first hash value and the second hash value are compared. When the two hash values ​​are equal, the BIOS binary image allocated by the BMC is valid. In step 813, the result will be updated regardless of whether the BIOS binary image is valid.

[0128] Figure 8 Schematic (c) shows a flowchart of the fourth root trust service sub-process of step 705, "BIOS upgrade start ()," according to a certain aspect of this disclosure. In step 817, the fourth root trust sub-process sets the BMC allocated memory to be disabled.

[0129] Figure 9 Figure (a) illustrates a flowchart of a Redfish service procedure according to a certain aspect of this disclosure. In step 901, the Redfish service receives a payload of information from an out-of-band BIOS binary image. In step 902, the Redfish service sends a notification "BIOS upgrade started ()". In step 903, if BMC allocated memory is enabled, the upgrade procedure waits until BMC allocated memory is disabled. In step 903, if BMC allocated memory is disabled, in step 904, the Redfish service uploads the payload of the BIOS binary image for BMC allocated memory. In step 905, the Redfish service sends a notification "BMC allocated memory updated (out-of-band)".

[0130] Figure 9Figure (b) illustrates a flowchart 910 for an SPI BIOS reader service routine according to a certain aspect of this disclosure. In step 911, if the BMC allocated memory is unsealed, then in step 914, the BIOS binary image is read from the BIOS and BMC flash chip 206 into the BMC allocated memory. In step 915, a notification indicates "BMC allocated memory updated (flash chip)". In step 911, if the BMC allocated memory is sealed, then in step 912, the BIOS binary image from the BMC allocated memory is read. Then, in step 913, the read BIOS binary image is programmed in the BIOS and BMC flash chip 206.

[0131] Figure 9 Figure (c) illustrates a flowchart 920 of a first SPI emulator runtime service sub-process for step 704, "SPI Emulator Runtime Service Starter ()," according to a certain aspect of this disclosure. In step 921, the first SPI emulator runtime service sub-process installs the SPI emulator communication protocol. In step 922, the read and write protocols of the SPI emulator policy are both set to "true."

[0132] Figure 9 Figure (d) illustrates a flowchart 930 of a second SPI emulator runtime service sub-process according to a certain aspect of this disclosure for step 716, "Disabling SPI Emulator Runtime Service ()". In step 931, the second SPI emulator runtime service sub-process removes the SPI emulator communication protocol. In step 932, the read and write protocols of the SPI emulator policy are both set to "deny".

[0133] Several embodiments of this disclosure provide a combined hardware and software design for a BMC (Browser Controller) for a computing system (e.g., a server). The BMC hardware and software integrate emulation logic for the SPI bus into the BMC chipset, enabling the BMC to respond to read and write operations on one or more core processors via the SPI bus. In some embodiments, the BIOS and BMC firmware binary images are integrated into a single flash chip, and the BIOS firmware is then read from the SPI controller into the BMC memory. The BMC's internal root of trust performs checks and verification of the BIOS firmware. Once the signature is confirmed to be complete and valid, the BIOS firmware is immediately retained in the BMC memory. This eliminates the need for repeated checks every time DC power is turned on. Out-of-band updates to the BIOS firmware are also checked and verified through the BMC memory, and once confirmed to be complete and valid, the BMC writes the new BIOS firmware to a non-volatile flash chip for backup. These embodiments of the disclosure provide, from a server management perspective, enhanced optimization of the computing system's boot process by reducing the UEFI BIOS check and update process, thereby reducing downtime required for boot firmware updates.

[0134] Several embodiments of this disclosure provide a new software stack and hardware interface within the BMC between the core processor, the BIOS, and the BMC SPI flash memory. This new software stack and hardware interface allow for BIOS regularity checks, access, and updates. The new software stack and hardware interface include a hardware SPI bus emulator slave and related runtime services, a BIOS binary image stored in BMC allocated memory, and a root trust service configured for BIOS upgrades. The software stack allows for the management of the BIOS binary image. The BIOS binary image can be checked by the root trust service at any time, rather than only at boot time.

[0135] Although the invention has been described and illustrated with respect to one or more embodiments, other skilled in the art will recognize or understand equivalent changes and modifications upon reading and understanding this specification and the accompanying drawings. Furthermore, while a particular feature of the invention may be disclosed only in one of several embodiments, this feature may be combined with one or more other features of other embodiments, as these features may be desired and advantageous for any given or particular application.

[0136] While various embodiments of the invention have been described above, it should be understood that they are presented by way of example only and not as limiting. Numerous changes may be made to the disclosed embodiments based on the disclosure herein without departing from the spirit or scope of this disclosure. Therefore, the breadth and scope of this disclosure should not be limited by any of the foregoing embodiments. Rather, the scope of this disclosure should be determined by the following claims and their equivalents.

Claims

1. A computing system, comprising: A central processing unit (CPU); A baseboard management controller (BMC) is coupled to the central processing unit via a first communication protocol, the baseboard management controller comprising: First communication protocol controller; One BMC memory; A root of trust; and An internal BMC bus is configured to communicatively couple to the BMC memory, the first communication protocol controller, and the root of trust; and A power-on non-volatile memory is coupled to the baseboard management controller via the first communication protocol controller. The power-on non-volatile memory is configured to store a basic input / output system (BIOS) firmware and / or a BMC firmware.

2. The computing system of claim 1, wherein the baseboard management controller further includes a second communication protocol controller, the second communication protocol controller supporting out-of-band management.

3. The computing system of claim 1, wherein the baseboard management controller is configured to perform an SPI emulator running service for communicating with the central processing unit via an SPI interface, a root of trust service for setting a state related to the BMC memory, and an SPI BIOS reader service for communicating with the boot non-volatile memory.

4. The computing system of claim 3, wherein the root trust service is configured to start or stop multiple memory regions in the BMC memory.

5. The computing system of claim 3, wherein the root trust service is configured to enclose or unenclose multiple memory regions in the BMC memory.

6. The computing system of claim 3, wherein when the memory regions in the BMC memory are sealed and activated, the boot non-volatile memory is serviced by the SPI BIOS reader.

7. The computing system of claim 1, wherein the root of trust is configured to authenticate the contents of the BMC memory via the internal BMC bus before storing a contents of the BMC memory in the boot non-volatile memory as the basic input / output system firmware and / or the BMC firmware.

8. The computing system of claim 1, wherein the baseboard management controller is configured to receive the basic input / output firmware from the power-on non-volatile memory and store the basic input / output firmware in the BMC memory, and the central processing unit is configured to receive the basic input / output firmware stored in the BMC memory to perform a boot operation.

9. The computing system of claim 1, wherein the baseboard management controller further includes a first communication protocol bus emulator operating in a slave mode, the first communication protocol bus emulator being configured to respond to a plurality of read and write requests to the power-on non-volatile memory from the central processing unit.

10. A computing system, comprising: A central processing unit (CPU); A baseboard management controller (BMC) is coupled to the central processing unit via a first communication protocol, the baseboard management controller comprising: First communication protocol controller; One BMC memory; One root of trust; and An internal BMC bus is configured to be communicatively coupled to the BMC memory, the first communication protocol controller, and the root of trust; A first bootable non-volatile memory, coupled to the BMC via the first communication protocol controller, is configured to store a BIOS firmware; and A second bootable non-volatile memory, coupled to the BMC via the first communication protocol controller, is configured to store BMC firmware.