A method and system for implementing a server PSU service non-sensing firmware update

CN122614404APending Publication Date: 2026-08-21SHENZHEN TONGTAIYI INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610688391.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-19
Publication Date
2026-08-21

AI Technical Summary

Technical Problem

[0009]本发明的目的在于解决现有技术中更新操作影响业务、时机受限、灵活性差的问题,提供一种实现服务器PSU业务无感固件更新的方法及系统

Benefits of technology

[0049]本发明中的实现服务器PSU业务无感固件更新的方法通过逻辑PSU虚拟化及对上层业务系统屏蔽底层物理PSU个体状态的上报机制,在固件更新全过程中,使主机操作系统、管理平台及业务应用感知到的始终是状态正常、供电稳定的逻辑电源。即使在单PSU离线更新的情况下,上报状态仍为“正常”,预期内的更新告警被过滤或降级,避免了传统方法中因固件更新引发的误告警或业务中断。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122614404A_ABST
    Figure CN122614404A_ABST
Patent Text Reader

Abstract

The application discloses a kind of methods and systems for realizing server PSU service no-sense firmware update, method includes: BMC real-time monitoring whole machine power consumption, CPU utilization, memory utilization and network I / O flow, when index is lower than dynamic adjustable threshold in preset duration, it is judged to enter safety update window;BMC virtualizes redundant PSU as logical PSU, shields individual state of bottom layer physical PSU to upper layer service system;Before updating, BMC instructs the output capacitor of to-be-updated PSU to be charged to first voltage, instructs working PSU to be promoted to second voltage and lower than first voltage, closes the main power output of to-be-updated PSU, uses capacitor charge to compensate transient current gap, working PSU takes over load, to-be-updated PSU safely off-line;Carry out firmware update, restore voltage after completion and reaccess. By logical PSU virtualization and state shielding, upper layer system is always perceived to normal power supply state, filters expected update alarm, realizes the PSU firmware update of service zero perception, guarantees business continuity.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of server management technology and relates to a method and system for implementing seamless firmware updates for server PSU services. Background Technology

[0002] In server management, to ensure high availability, servers are typically equipped with redundant power supply units (PSUs). These PSUs continuously supply power to critical components such as the server motherboard, backplane, expansion boards, conversion boards, GPU, RAID cards, and PCIe when powered on, forming the cornerstone of stable system operation. In actual operation and maintenance, firmware upgrades are often necessary to resolve potential problems with the PSUs or improve their functionality.

[0003] Currently, existing PSU firmware update methods mainly fall into the following categories:

[0004] The forced update method during power-on involves forcibly updating the firmware of a single PSU via the Baseboard Management Controller (BMC) when the server is powered on and configured with redundant power supplies. This method may affect or even interrupt ongoing services due to transient load switching, voltage fluctuations, or other factors during the update process.

[0005] The update method during shutdown involves updating the firmware of a single PSU via the BMC after the server is completely shut down. While this method is safe, it requires the interruption of all services, resulting in a long downtime and making it unsuitable for scenarios with stringent availability requirements.

[0006] The offline flashing method involves physically removing the PSU from the server, connecting it to a personal computer (PC), and using specialized software to flash the firmware offline. This method is cumbersome, inefficient, and also requires interrupting business operations and physically removing the device.

[0007] Whether updating while the system is off or forced to update at startup, existing PSU firmware update methods inevitably lead to service interruptions. Even with redundant power supply configurations, updating a single PSU at startup can cause voltage fluctuations due to momentary load switching, thus affecting the stability of sensitive services such as high-performance computing and real-time data processing. Existing methods are rigid in their timing of updates, typically requiring maintenance personnel to manually select off-peak periods for operation, lacking flexibility and intelligence, and failing to meet the urgent needs of modern data centers for business continuity and automated operation and maintenance.

[0008] Therefore, there is an urgent need for a firmware update method that can achieve seamless updates for server PSU services, in order to solve the problems of update operations affecting services, limited timing, and poor flexibility in existing technologies. Summary of the Invention

[0009] The purpose of this invention is to solve the problems of update operations affecting business, limited timing, and poor flexibility in the prior art, and to provide a method and system for realizing seamless firmware updates for server PSU services.

[0010] To achieve the above objectives, the present invention employs the following technical solution:

[0011] A method for implementing seamless firmware updates for server PSU services includes the following steps:

[0012] S1, the Baseboard Management Controller (BMC) monitors the server's multi-dimensional hardware metrics in real time, including overall power consumption, CPU utilization, memory utilization, and network I / O traffic. When all metrics are below the corresponding dynamically adjustable thresholds for a preset duration, the system enters the security update window.

[0013] S2, BMC virtualizes at least two redundant PSUs in the server into logical PSUs, shielding the upper-layer business system from the individual state of the underlying physical PSUs.

[0014] S3, before updating the target PSU_A, the BMC performs coordinated charging / discharging and seamless switching control, specifically including:

[0015] S31, the BMC instruction to the PSU_A to be updated to charge its output capacitor to a first voltage, which is higher than the PSU's nominal output voltage;

[0016] S32, BMC instruction for the currently operating PSU_B to raise its output voltage to a second voltage, which is higher than the nominal output voltage but lower than the first voltage;

[0017] S33, BMC shuts down the main power output of PSU_A, uses the charge stored in the output capacitor of PSU_A to discharge instantaneously to the bus, and compensates for the transient current gap caused by the exit of PSU_A. At the same time, the voltage loop of PSU_B responds and takes over all load current, so that PSU_A can be safely taken offline.

[0018] After S4 and PSU_A went offline, BMC performed a firmware update on PSU_A.

[0019] S5. After the firmware update is completed, the BMC will power on PSU_A and connect it to the power supply system, while restoring the output voltage of all PSUs in the logic PSU to the nominal value.

[0020] The dynamically adjustable threshold in S1 is periodically adjusted based on historical load data; BMC collects historical load data for different time periods on a weekly basis, analyzes the low-business periods, selects the median of each indicator within that period as the new trigger threshold, and updates the historical baseline weekly.

[0021] In S31, the voltage difference between the first voltage and the second voltage is configured within a safe range of 0.2V to 0.6V, with a default value of 0.3V; wherein, the first voltage is 105% to 110% of the PSU's nominal output voltage, and the second voltage is 102.5% to 105% of the PSU's nominal output voltage.

[0022] The firmware update for PSU_A in S4 specifically includes:

[0023] BMC downloads the PSU firmware file from the TFTP server via the TFTP protocol;

[0024] BMC sets the PSU_A to be updated to update mode via the PMBus / I2C bus;

[0025] BMC uses a block write method to write the firmware into PSU_A;

[0026] After writing is complete, switch PSU_A back to working mode.

[0027] It also includes a firmware update rollback process: before the firmware is actually written to the Flash memory of PSU_A, if any hardware indicator is detected to deteriorate beyond the safety threshold, the BMC will stop the update process. Specifically, the BMC first exits the update mode of PSU_A and switches to the working mode, so that PSU_A reloads the old firmware stored in its Flash. Then, the BMC restores the voltage of all PSUs in the logic PSU to the nominal value through a voltage adjustment command, restores the normal redundancy mode, and adjusts the voltage of each PSU according to the load balance to make the current tend to stabilize.

[0028] A system for enabling seamless firmware updates for server PSU services includes:

[0029] Monitoring layer: Used to collect multi-dimensional hardware metrics of the server in real time, including overall power consumption, CPU utilization, memory utilization, and network I / O traffic;

[0030] Management layer: Includes an intelligent management coordinator, which makes security update window decisions based on data feedback from the monitoring layer and issues monitoring and decision instructions;

[0031] Virtualization Abstraction Layer: Includes a logical PSU manager, which is used to virtualize at least two redundant PSUs into a single logical PSU, present a normal power status to the upper-layer business systems, and perform fine-grained coordination and control over the underlying physical PSUs.

[0032] Physical Execution Layer: Includes physical PSU_A, physical PSU_B and active ORing energy buffer circuit, used to receive control commands from the management layer, perform coordinated charging and discharging, seamless switching and firmware update operations, and feed back the execution results and status confirmation to the management layer.

[0033] The intelligent management coordinator has a built-in intelligent update decision engine, which executes the following judgment logic: if the overall power consumption is less than 50%, CPU utilization is less than 30%, memory utilization is less than 60%, and network I / O traffic is less than 25% for 5 minutes, then a firmware update license is triggered.

[0034] When the logical PSU manager reports the logical power status to the upper layer through the standard management interface IPMI or Redfish, the following mapping rules are executed:

[0035] Always report the PSU's existence status as "existing";

[0036] As long as the bus voltage is within the normal range, the power supply status will always be reported as normal.

[0037] During a single PSU update, the overall status is reported as normal; an anomaly is only reported when all PSUs fail.

[0038] The reported total power consumption is the total power consumption of the system bus, not the power consumption of a single PSU.

[0039] Filter or downgrade expected update-related alarms to logs to prevent them from triggering interruption alarms.

[0040] In the coordinated charging / discharging and seamless switching control, the timing control is as follows:

[0041] First, issue a command to the PSU_A to be updated to precharge its output capacitor and increase its output voltage to 12.6V;

[0042] Then, a command is sent to the working PSU_B to precharge its output capacitor and increase its output voltage to 12.3V;

[0043] Then, MOSFET_Q1 of PSU_A is turned off, while MOSFET_Q2 of PSU_B is turned on. The capacitor array maintains the load power supply during the switching period, thus achieving continuous stability of the output bus.

[0044] Each PSU in the physical execution layer integrates a firmware update security unit, which includes:

[0045] The buffer is used to temporarily store the firmware data sent by BMC through the PMBus / I2C bus and its first CRC check value before the firmware is written to Flash.

[0046] The verification module is used to calculate the second CRC check value of the firmware data in the buffer area and compare the second CRC check value with the first CRC check value;

[0047] The update control module only writes the firmware data in the buffer to the PSU's Flash memory to complete the firmware update if the second CRC check value matches the first CRC check value. If the comparison is inconsistent, or if an abort command is received from the BMC before the firmware is written to the Flash, the PSU automatically exits the update mode and switches to the working mode, reloads the old firmware stored in the Flash, and at the same time, the BMC sends a voltage recovery command to all PSUs in the logic PSU to synchronously restore the output voltage to the nominal value and reconnects the offline PSUs to the power supply system in parallel.

[0048] Compared with the prior art, the present invention has the following beneficial effects:

[0049] The method for achieving seamless firmware updates for server PSU services in this invention utilizes logical PSU virtualization and a mechanism that shields the upper-layer business system from the reporting mechanism of the underlying physical PSU's individual status. Throughout the firmware update process, the host operating system, management platform, and business applications always perceive a logical power supply that is in a normal state and has a stable power supply. Even in the case of a single PSU offline update, the reported status remains "normal," and expected update alarms are filtered or downgraded, avoiding false alarms or service interruptions caused by firmware updates in traditional methods.

[0050] The BMC in this invention does not simply rely on a single threshold. Instead, it monitors multiple hardware metrics in real time, including overall power consumption, CPU utilization, memory utilization, and network I / O traffic. It requires all metrics to remain below dynamically adjustable thresholds for a preset duration before entering the safe update window. This mechanism effectively avoids performing update operations during peak business hours or periods of sudden load fluctuations. Compared to existing technologies that rely on manually selecting off-peak times or simply forcing updates, it significantly reduces the risk of performance fluctuations caused by load switching, achieving unattended, adaptive intelligent operation and maintenance.

[0051] This invention forms a voltage buffer by pre-charging the output capacitor of the PSU to be updated to a first voltage higher than its nominal value, while simultaneously boosting the output voltage of the working PSU to a second voltage. Upon turning off the PSU to be updated, the charge stored in its output capacitor is immediately released to the bus to compensate for the current shortfall; the voltage loop of the working PSU simultaneously takes over the entire load. This process achieves zero-millisecond interruption or extremely low voltage drop within microseconds of the output bus voltage, completely solving the problem of sensitive devices such as CPUs, GPUs, and RAID cards being reset or experiencing performance degradation due to voltage transient drops during traditional redundant power supply switching, ensuring zero impact of online firmware updates on hardware power supply. Attached Figure Description

[0052] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0053] Figure 1 This is a system overview diagram of the present invention;

[0054] Figure 2 This is a flowchart of the intelligent update decision engine of the present invention;

[0055] Figure 3 This is the energy (voltage) buffering and seamless switching control diagram of the present invention;

[0056] Figure 4 This is a flowchart of the firmware update process of the present invention;

[0057] Figure 5 This is the logical PSU state mapping diagram of the present invention. Detailed Implementation

[0058] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. The components of the embodiments of the present invention described and shown in the accompanying drawings can generally be arranged and designed in various different configurations.

[0059] Therefore, the following detailed description of the embodiments of the invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely to illustrate selected embodiments of the invention. All other embodiments obtained by those skilled in the art based on the embodiments of the invention without inventive effort are within the scope of protection of the invention.

[0060] It should be noted that similar labels and letters in the following figures indicate similar items. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.

[0061] A method for implementing seamless firmware updates for server PSU services according to the present invention includes the following steps:

[0062] S1, the Baseboard Management Controller (BMC) monitors the server's multi-dimensional hardware metrics in real time, including overall power consumption, CPU utilization, memory utilization, and network I / O traffic. When all metrics are below the corresponding dynamically adjustable thresholds for a preset duration, a security update window is entered. The dynamically adjustable thresholds in S1 are periodically adjusted based on historical load data. The BMC collects historical load data for different time periods on a weekly basis, analyzes the low-traffic periods, selects the median of each metric within that period as the new trigger threshold, and updates the historical baseline weekly.

[0063] S2, BMC virtualizes at least two redundant PSUs in the server into logical PSUs, shielding the upper-layer business system from the individual state of the underlying physical PSUs.

[0064] S3, before updating the target PSU_A, the BMC performs coordinated charging / discharging and seamless switching control, specifically including:

[0065] In S31, the BMC instruction to the PSU_A to be updated charges its output capacitor to a first voltage, which is higher than the PSU's nominal output voltage. The voltage difference between the first voltage and the second voltage in S31 is configured within a safe range of 0.2V to 0.6V, with a default value of 0.3V. The first voltage is 105% to 110% of the PSU's nominal output voltage, and the second voltage is 102.5% to 105% of the PSU's nominal output voltage.

[0066] S32, BMC instruction for the currently operating PSU_B to raise its output voltage to a second voltage, which is higher than the nominal output voltage but lower than the first voltage;

[0067] S33, BMC shuts down the main power output of PSU_A, uses the charge stored in the output capacitor of PSU_A to discharge instantaneously to the bus, and compensates for the transient current gap caused by the exit of PSU_A. At the same time, the voltage loop of PSU_B responds and takes over all load current, so that PSU_A can be safely taken offline.

[0068] After S4 and PSU_A go offline, BMC performs a firmware update for PSU_A; the firmware update for PSU_A specifically includes:

[0069] BMC downloads the PSU firmware file from the TFTP server via the TFTP protocol;

[0070] BMC sets the PSU_A to be updated to update mode via the PMBus / I2C bus;

[0071] BMC uses a block write method to write the firmware into PSU_A;

[0072] After writing is complete, switch PSU_A back to working mode.

[0073] S5. After the firmware update is completed, the BMC will power on PSU_A and connect it to the power supply system, while restoring the output voltage of all PSUs in the logic PSU to the nominal value.

[0074] Firmware update rollback process: Before the firmware is actually written to the Flash memory of PSU_A, if any hardware indicator is detected to deteriorate beyond the safety threshold, the BMC will stop the update process. Specifically, the BMC first exits the update mode of PSU_A and switches to the working mode, causing PSU_A to reload the old firmware stored in its Flash. Then, the BMC restores the voltage of all PSUs in the logic PSU to the nominal value through voltage adjustment commands, restores the normal redundancy mode, and adjusts the voltage of each PSU according to the load balance to make the current tend to stabilize.

[0075] A system for implementing seamless firmware updates for server PSU services according to the present invention includes:

[0076] Monitoring layer: Used to collect multi-dimensional hardware metrics of the server in real time, including overall power consumption, CPU utilization, memory utilization, and network I / O traffic;

[0077] Management layer: Includes an intelligent management coordinator, which makes security update window decisions based on data feedback from the monitoring layer and issues monitoring and decision instructions; The intelligent management coordinator has a built-in intelligent update decision engine, which executes the following decision logic: If the following conditions are met simultaneously: total power consumption <50%, CPU utilization <30%, memory utilization <60%, network I / O traffic <25%, and the above conditions are maintained for 5 minutes, then a firmware update license is triggered.

[0078] Virtualization Abstraction Layer: Contains a logical PSU manager, used to virtualize at least two redundant PSUs into a single logical PSU, presenting a unified normal power status to upper-layer business systems, and performing fine-grained coordination and control over the underlying physical PSUs. When the logical PSU manager reports the logical power status to the upper layer through the standard management interface IPMI or Redfish, it executes the following mapping rules:

[0079] Always report the PSU's existence status as "existing";

[0080] As long as the bus voltage is within the normal range, the power supply status will always be reported as normal.

[0081] During a single PSU update, the overall status is reported as normal; an anomaly is only reported when all PSUs fail.

[0082] The reported total power consumption is the total power consumption of the system bus, not the power consumption of a single PSU.

[0083] Filter or downgrade expected update-related alarms to logs to prevent them from triggering interruption alarms.

[0084] Physical Execution Layer: This layer includes physical PSU_A, physical PSU_B, and an active ORing energy buffer circuit. It receives control commands from the management layer, performs coordinated charging / discharging, seamless handover, and firmware update operations, and feeds back the execution results and status confirmations to the management layer. The timing control for coordinated charging / discharging and seamless handover is as follows:

[0085] First, issue a command to the PSU_A to be updated to precharge its output capacitor and increase its output voltage to 12.6V;

[0086] Then, a command is sent to the working PSU_B to precharge its output capacitor and increase its output voltage to 12.3V;

[0087] Then, MOSFET_Q1 of PSU_A is turned off, while MOSFET_Q2 of PSU_B is turned on. The capacitor array maintains the load power supply during the switching period, thus achieving continuous stability of the output bus.

[0088] Each PSU in the physical execution layer integrates a firmware update security unit, which includes:

[0089] The buffer is used to temporarily store the firmware data sent by BMC through the PMBus / I2C bus and its first CRC check value before the firmware is written to Flash.

[0090] The verification module is used to calculate the second CRC check value of the firmware data in the buffer area and compare the second CRC check value with the first CRC check value;

[0091] The update control module only writes the firmware data in the buffer to the PSU's Flash memory to complete the firmware update if the second CRC check value matches the first CRC check value. If the comparison is inconsistent, or if an abort command is received from the BMC before the firmware is written to the Flash, the PSU automatically exits the update mode and switches to the working mode, reloads the old firmware stored in the Flash, and at the same time, the BMC sends a voltage recovery command to all PSUs in the logic PSU to synchronously restore the output voltage to the nominal value and reconnects the offline PSUs to the power supply system in parallel.

[0092] Example

[0093] This embodiment provides a method for implementing seamless firmware updates for server PSU services. This method is applied to server systems equipped with redundant power supply units (PSUs) and baseboard management controllers (BMCs). The following description uses a typical 1+1 redundant PSU configuration (i.e., PSU_A and PSU_B jointly power the system) as an example, and details the technical solution of this invention with specific parameters.

[0094] I. Dynamic Judgment of Multi-Dimensional Load Monitoring and Security Update Window

[0095] BMC monitors the server's multi-dimensional hardware metrics in real time, including overall power consumption, CPU utilization, memory utilization, and network I / O traffic. In this embodiment, BMC collects these metrics every 5 seconds via the IPMI interface. To determine whether to enter the security update window, BMC's built-in intelligent update decision engine uses the following judgment logic: a firmware update permission signal is triggered only when all metrics continuously meet the following conditions for 5 minutes: "Overall power consumption < 50% of full load power consumption", "CPU utilization < 30%", "Memory utilization < 60%", and "Network I / O traffic < 25%".

[0096] To adapt to cyclical changes in workload, the trigger threshold can be dynamically adjusted based on historical baselines. The Business Controller (BMC) records and stores historical workload data from the past 1-2 weeks on a weekly basis. Specifically, from Monday to Sunday, the BMC collects data every 5 minutes during four time periods: 4:00-6:00 AM, 10:00-12:00 PM, 4:00-6:00 PM, and 10:00-12:00 AM. By analyzing this historical data, the BMC can identify periods of low workload (e.g., early Sunday morning). Subsequently, the BMC selects the median of each indicator during this low-workload period as the new trigger threshold and updates the historical baseline weekly. For example, if historical data shows that the median power consumption, CPU utilization, memory utilization, and network I / O traffic were 45% and 25% respectively on early Sunday morning, the trigger threshold for the following week will be dynamically adjusted to these values.

[0097] II. Logical PSU Virtualization Grouping

[0098] Before triggering the update process, BMC virtualizes the physically independent PSU_A and PSU_B into a single logical PSU. This logical PSU acts as an independent "logical power management module," presenting a unified and stable logical power state to upper-layer business systems (such as host operating systems, management platforms, and business applications), while providing fine-grained coordination and control over the lower-layer physical PSUs.

[0099] III. Coordinated charging and discharging and seamless switching control

[0100] Once the security update window decision is approved, the BMC decides to update the firmware of PSU_A. To prevent a drop in output bus voltage due to PSU_A going offline, the BMC performs the following coordinated charge / discharge and seamless switching steps:

[0101] Step 1: Pre-charging (creating a voltage buffer)

[0102] The BMC sends a manufacturer-defined voltage regulation command to the PSU_A to be updated via the PMBus / I2C bus. Upon receiving the command, the firmware inside the PSU_A charges its output capacitor from the nominal value of 12.0V to 12.6V. This voltage value is within ±10% of the PSU's nominal output voltage regulation range (10.8V~13.2V), which complies with safety specifications.

[0103] Step 2: Increase the output voltage of the working PSU

[0104] Simultaneously, the BMC sends a voltage regulation command to the currently operating PSU_B via the PMBus / I2C bus, gradually increasing its output voltage from 12.0V to 12.3V. At this time, the output capacitor voltage of PSU_A (12.6V) is higher than the output voltage of PSU_B (12.3V), with a voltage difference of 0.3V. This difference can be configured within the range of 0.2V to 0.6V according to engineering margins and safety strategies; this embodiment uses the recommended default value of 0.3V.

[0105] Step 3: Perform the switch and offline process

[0106] The BMC sends a command to shut down the main power output of PSU_A, disconnecting its internal power circuitry from the bus. Within microseconds of PSU_A's disconnection, a small portion of the charge stored in its output capacitor (12.6V, higher than the bus voltage) is immediately released to the bus to compensate for the transient current gap caused by PSU_A's exit. Simultaneously, the voltage loop of PSU_B responds rapidly, taking over all load current. During this process, the output bus voltage experiences almost no drop (drop time less than 50 microseconds, amplitude less than 1% of the nominal value), and sensitive hardware such as the CPU and GPU are completely unaffected. At this point, PSU_A is safely and completely offline, and the BMC can begin firmware updates for it.

[0107] IV. Firmware Download, Flashing, and Rollback Mechanism

[0108] After PSU_A goes offline, BMC downloads the target PSU firmware file from a pre-configured TFTP server via the TFTP protocol. Once the download is complete, BMC sets PSU_A to update mode via the PMBus / I2C bus.

[0109] During the firmware flashing process, the BMC does not directly write the firmware to the Flash memory of the PSU_A. Instead, it first writes the firmware data and its first CRC checksum to the internal buffer of the PSU_A. The PSU_A integrates a firmware update security unit, which calculates the second CRC checksum of the firmware data in the buffer and compares it with the incoming first CRC checksum.

[0110] If the two are consistent, the update control module of PSU_A will write the firmware data in the cache to the Flash memory in a block writing manner (first erase the target block, then write the new data) to complete the firmware update.

[0111] If the two are inconsistent, or if the BMC detects that any hardware indicator (such as total power consumption, CPU utilization, etc.) suddenly deteriorates beyond the safety threshold before the firmware is actually written to Flash, the rollback process will be triggered immediately.

[0112] The specific steps of the rollback process are as follows:

[0113] The BMC first commands PSU_A to exit update mode and switch back to operating mode. At this point, PSU_A's Flash memory still stores the old firmware, which PSU_A reloads and executes. Subsequently, the BMC uses voltage regulation commands to synchronously restore the output voltage of all PSUs in the logical PSU group (i.e., PSU_A and PSU_B) to the nominal value of 12.0V, allowing PSU_A to reconnect to the power supply bus in parallel. Finally, the BMC fine-tunes the voltage of each PSU according to a load balancing algorithm, stabilizing the output current and restoring the system to normal redundant power supply mode. Throughout the rollback process, since PSU_B remains online, the services are unaware of any abnormalities.

[0114] V. Recovery and Synchronization After Update

[0115] If the firmware flash is successful and no rollback is triggered, the BMC first exits PSU_A from update mode and powers it back on. Next, the BMC simultaneously sends voltage regulation commands to both PSU_A and PSU_B, synchronously adjusting their output voltages back to the nominal value of 12.0V. At this point, PSU_A is reconnected in parallel to the power supply system, sharing the load current with PSU_B. The BMC then fine-tunes the output voltage of each PSU according to real-time load balancing requirements, making the current distribution more balanced, thus completing the entire firmware update process.

[0116] VI. Logical PSU's state masking of upper-layer business systems

[0117] Throughout the entire firmware update process (including pre-charging, switching, offline flashing, and recovery stages), the virtualized logical PSU consistently reports its status to the upper layer via the standard management interface (IPMI or Redfish) according to the following rules:

[0118] a) Always report the PSU's existence status as "existing";

[0119] b) As long as the output bus voltage is within the normal range (e.g., 11.8V~12.2V), the power supply status will always be reported as "normal";

[0120] c) During a single power supply update (PSU_A is offline, PSU_B is powered separately), the overall status is reported as "normal" and "abnormal" is only reported when both power supplies fail.

[0121] d) The reported total power consumption is the total power consumption of the system bus (i.e., the sum of the output power of PSU_A and PSU_B), not the power consumption of a single PSU;

[0122] e) Expected alarms related to update operations (such as "PSU_A enters firmware update mode", "PSU_A offline", etc.) are filtered or downgraded to log information and do not trigger any interruption alarms that affect services.

[0123] Through the aforementioned virtual state mapping, the host operating system, management platform, and business applications perceive a completely normal logical power supply that has not changed throughout the entire PSU firmware update process, thereby achieving a truly "business-unnoticed" firmware update.

[0124] The above are merely preferred embodiments of the present invention and are not intended to limit the present invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A method for implementing seamless firmware updates for server PSU services, characterized in that, Includes the following steps: S1, the Baseboard Management Controller (BMC) monitors the server's multi-dimensional hardware metrics in real time, including overall power consumption, CPU utilization, memory utilization, and network I / O traffic. When all metrics are below the corresponding dynamically adjustable thresholds for a preset duration, the system enters the security update window. S2, BMC virtualizes at least two redundant PSUs in the server into logical PSUs, shielding the upper-layer business system from the individual state of the underlying physical PSUs. S3, before updating the target PSU_A, the BMC performs coordinated charging / discharging and seamless switching control, specifically including: S31, the BMC instruction to the PSU_A to be updated to charge its output capacitor to a first voltage, which is higher than the PSU's nominal output voltage; S32, the BMC instruction for the currently operating PSU_B is to raise its output voltage to a second voltage, which is higher than the nominal output voltage but lower than the first voltage; S33, BMC shuts down the main power output of PSU_A, uses the charge stored in the output capacitor of PSU_A to discharge instantaneously to the bus, and compensates for the transient current gap caused by the exit of PSU_A. At the same time, the voltage loop of PSU_B responds and takes over all load current, so that PSU_A can be safely taken offline. After S4 and PSU_A go offline, BMC performs a firmware update on PSU_A. S5. After the firmware update is completed, the BMC will power on PSU_A again and connect it to the power supply system, while restoring the output voltage of all PSUs in the logic PSU to the nominal value.

2. The method for implementing seamless firmware updates for server PSU services as described in claim 1, characterized in that, The dynamically adjustable threshold in S1 is periodically adjusted based on historical load data; BMC collects historical load data for different time periods on a weekly basis, analyzes the low-business periods, selects the median of each indicator within that period as the new trigger threshold, and updates the historical baseline weekly.

3. The method for implementing seamless firmware updates for server PSU services as described in claim 1, characterized in that, In S31, the voltage difference between the first voltage and the second voltage is configured within a safe range of 0.2V to 0.6V, with a default value of 0.3V; wherein, the first voltage is 105% to 110% of the PSU's nominal output voltage, and the second voltage is 102.5% to 105% of the PSU's nominal output voltage.

4. The method for implementing seamless firmware updates for server PSU services as described in claim 1, characterized in that, The firmware update for PSU_A in S4 specifically includes: BMC downloads the PSU firmware file from the TFTP server via the TFTP protocol; BMC sets the PSU_A to be updated to update mode via the PMBus / I2C bus; BMC uses a block write method to write the firmware into PSU_A; After writing is complete, switch PSU_A back to working mode.

5. The method for implementing seamless firmware updates for server PSU services as described in claim 1, characterized in that, It also includes a firmware update rollback process: before the firmware is actually written to the Flash memory of PSU_A, if any hardware indicator is detected to deteriorate beyond the safety threshold, the BMC will stop the update process. Specifically, the BMC first exits the update mode of PSU_A and switches to the working mode, so that PSU_A reloads the old firmware stored in its Flash. Then, the BMC restores the voltage of all PSUs in the logic PSU to the nominal value through a voltage adjustment command, restores the normal redundancy mode, and adjusts the voltage of each PSU according to the load balance to make the current tend to stabilize.

6. A system for implementing seamless firmware updates for server PSU services, characterized in that, include: Monitoring layer: Used to collect multi-dimensional hardware metrics of the server in real time, including overall power consumption, CPU utilization, memory utilization, and network I / O traffic; Management layer: Includes an intelligent management coordinator, which makes security update window decisions based on data feedback from the monitoring layer and issues monitoring and decision instructions; Virtualization Abstraction Layer: Includes a logical PSU manager, which is used to virtualize at least two redundant PSUs into a single logical PSU, present a normal power status to the upper-layer business systems, and perform fine-grained coordination and control over the underlying physical PSUs. Physical Execution Layer: Includes physical PSU_A, physical PSU_B and active ORing energy buffer circuit, used to receive control commands from the management layer, perform coordinated charging and discharging, seamless switching and firmware update operations, and feed back the execution results and status confirmation to the management layer.

7. The system for implementing seamless firmware updates for server PSU services as described in claim 6, characterized in that, The intelligent management coordinator has a built-in intelligent update decision engine, which executes the following judgment logic: if the overall power consumption is less than 50%, CPU utilization is less than 30%, memory utilization is less than 60%, and network I / O traffic is less than 25% for 5 minutes, then a firmware update license is triggered.

8. The system for implementing seamless firmware updates for server PSU services as described in claim 6, characterized in that, When the logical PSU manager reports the logical power status to the upper layer through the standard management interface IPMI or Redfish, the following mapping rules are executed: Always report the PSU's existence status as "existing"; As long as the bus voltage is within the normal range, the power supply status will always be reported as normal. During a single PSU update, the overall status is reported as normal; an anomaly is only reported when all PSUs fail. The reported total power consumption is the total power consumption of the system bus, not the power consumption of a single PSU. Filter or downgrade expected update-related alarms to logs to prevent them from triggering interruption alarms.

9. A system for implementing seamless firmware updates for server PSU services as described in claim 6, characterized in that, In the coordinated charging / discharging and seamless switching control, the timing control is as follows: First, issue a command to the PSU_A to be updated to precharge its output capacitor and increase its output voltage to 12.6V; Then, a command is sent to the working PSU_B to precharge its output capacitor and increase its output voltage to 12.3V; Then, MOSFET_Q1 of PSU_A is turned off, while MOSFET_Q2 of PSU_B is turned on. The capacitor array maintains the load power supply during the switching period, thus achieving continuous stability of the output bus.

10. A system for implementing seamless firmware updates for server PSU services as described in claim 6, characterized in that, Each PSU in the physical execution layer integrates a firmware update security unit, which includes: The buffer is used to temporarily store the firmware data and its first CRC check value sent by the BMC through the PMBus / I2C bus before the firmware is written to the Flash. The verification module is used to calculate the second CRC check value of the firmware data in the buffer area and compare the second CRC check value with the first CRC check value; The update control module only writes the firmware data in the buffer to the PSU's Flash memory to complete the firmware update when the second CRC check value matches the first CRC check value. If the comparison is inconsistent, or if an abort command is received from the BMC before the firmware is written to the Flash, the PSU automatically exits the update mode and switches to the working mode, reloads the old firmware stored in the Flash, and at the same time, the BMC sends a voltage recovery command to all PSUs in the logic PSU to synchronously restore the output voltage to the nominal value and reconnects the offline PSUs to the power supply system in parallel.