Blade Server Power Authorization via Dual-Use I/O Line
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
When the firmware of a blade management controller in an information handling system is corrupted, it cannot obtain power ON authorization from the chassis controller, leading to potential overcurrent conditions or failure to power up, as the 'boot block' mode lacks communication protocols and memory capacity, and adding complexity is undesirable.
Innovation Solution
Implementing a module monitor board that allows the blade management controller to request power-up permission over a secondary control bus if communication with the chassis controller is lost, ensuring safe power-up by checking available power and updating power budget tables, thereby bypassing the need for user intervention and preventing overcurrent conditions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the BMC firmware application is corrupted and runs in boot block mode, then the BSM can potentially power ON without authorization, but this may exceed the PSU power budget capacity resulting in overcurrent conditions that shut down the entire blade server chassis
Solution Approach 1:
A new communication channel is introduced as an intermediary between the MMB and BMC. This channel uses a dual-use I/O line that can operate in both IPMI and legacy modes, allowing the MMB to send power authorization commands directly to the BMC even when the BMC is in boot block mode and cannot communicate over the normal IPMI bus. This intermediary communication path resolves the contradiction by enabling controlled power authorization without requiring full BMC firmware functionality.
Solution Approach 2:
The system changes the operational parameters of the communication interface by implementing a dual-use I/O line that can switch between different communication modes. When the BMC is corrupted, the system transitions from requiring IPMI protocol communication to using a simpler legacy communication mode that the boot block can understand. This parameter change allows power authorization to proceed despite the firmware corruption, while still maintaining power budget management through the MMB.
2Reliability
If a BSM is not allowed to power ON when BMC is corrupted, then overcurrent conditions are prevented, but the BSM must be returned to the manufacturer since there is no way to program the BSM without powering it up
Solution Approach 1:
The dual-use I/O line serves as an intermediary that enables a simplified programming mode for corrupted BMCs. By allowing communication through this alternative channel, the system enables field programming of the BMC without requiring the BSM to be returned to the manufacturer. The MMB can send programming commands through this intermediary channel, resolving the contradiction between preventing overcurrent conditions and enabling ease of repair.
3Reliability
If the BMC is allowed to communicate normally with the chassis controller, then power ON authorization can be obtained, but this requires sufficient memory capacity and communication protocols that are not available in boot block mode
Solution Approach 1:
The system changes the communication parameters by implementing a dual-use I/O line that can operate in a simplified legacy mode when the BMC is in boot block mode. This reduces the memory capacity and protocol requirements needed for communication. The MMB can send simple power authorization commands through this reduced-parameter channel that the boot block can understand with minimal resources, resolving the contradiction between maintaining authorized power control and reducing device complexity requirements.
4Reliability
If complexity is added to the boot block to add communication protocols, then power ON authorization can be obtained, but this is undesirable since firmware bugs at the boot block level cannot be fixed in the field
Solution Approach 1:
The dual-use I/O line implements a universal communication interface that can operate in multiple modes. It can function as a full IPMI communication channel when the BMC is healthy, and as a simplified legacy channel when the BMC is in boot block mode. This multi-functionality allows the boot block to remain simple while still enabling power authorization through the MMB, resolving the contradiction between obtaining power authorization and maintaining boot block simplicity.
Data Source
AI summary
An information handling system having a plurality of blade server modules (BSMs) and power supply units (PSUs) uses a module monitor board (MMB) to monitor and control a power budget of the PSUs by each individual BSM requesting authorization from the MMB in order to power ON and boot-up. A blade management controller (BMC) may communicate with the MMB over a communications bus. However, if the firmware application controlling the BMC has been corrupted the BMC it may run in a “boot block” mode and not contain the intelligence necessary to obtain power ON authorization from the MMB. A single, existing input-output (I/O) line from the MMB to the BMC may be utilized to indicate power ON authorization for the respective BSM. The MMB and BMC may be adapted for preventing the BSM from powering ON without proper authorization from the MMB and that the BMC will always power ON the BSM when enough power is available from the PSU. A dual-use of the I/O line may be used for providing a pseudo-communications channel between the MMB and the BMC when the BMC may be in the BOOT BLOCK mode.


