Blade Server Power Authorization via Dual-Use I/O Line

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

When the firmware of a blade management controller in an information handling system is corrupted, it cannot obtain power ON authorization from the chassis controller, leading to potential overcurrent conditions or failure to power up, as the 'boot block' mode lacks communication protocols and memory capacity, and adding complexity is undesirable.

Innovation Solution

Implementing a module monitor board that allows the blade management controller to request power-up permission over a secondary control bus if communication with the chassis controller is lost, ensuring safe power-up by checking available power and updating power budget tables, thereby bypassing the need for user intervention and preventing overcurrent conditions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the BMC firmware application is corrupted and runs in boot block mode, then the BSM can potentially power ON without authorization, but this may exceed the PSU power budget capacity resulting in overcurrent conditions that shut down the entire blade server chassis

Engineering Contradiction:
ImproveAbility to power on BSM without firmware corruption issuesVSAvoidPower budget management and overcurrent prevention
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A new communication channel is introduced as an intermediary between the MMB and BMC. This channel uses a dual-use I/O line that can operate in both IPMI and legacy modes, allowing the MMB to send power authorization commands directly to the BMC even when the BMC is in boot block mode and cannot communicate over the normal IPMI bus. This intermediary communication path resolves the contradiction by enabling controlled power authorization without requiring full BMC firmware functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the operational parameters of the communication interface by implementing a dual-use I/O line that can switch between different communication modes. When the BMC is corrupted, the system transitions from requiring IPMI protocol communication to using a simpler legacy communication mode that the boot block can understand. This parameter change allows power authorization to proceed despite the firmware corruption, while still maintaining power budget management through the MMB.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If a BSM is not allowed to power ON when BMC is corrupted, then overcurrent conditions are prevented, but the BSM must be returned to the manufacturer since there is no way to program the BSM without powering it up

Engineering Contradiction:
ImprovePower budget management and overcurrent preventionVSAvoidAbility to program and service BSM
Core Design Contradiction:
ReliabilityVSEase of repair

Solution Approach 1:

The dual-use I/O line serves as an intermediary that enables a simplified programming mode for corrupted BMCs. By allowing communication through this alternative channel, the system enables field programming of the BMC without requiring the BSM to be returned to the manufacturer. The MMB can send programming commands through this intermediary channel, resolving the contradiction between preventing overcurrent conditions and enabling ease of repair.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the BMC is allowed to communicate normally with the chassis controller, then power ON authorization can be obtained, but this requires sufficient memory capacity and communication protocols that are not available in boot block mode

Engineering Contradiction:
ImproveAuthorized power ON controlVSAvoidMemory capacity and communication protocol requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system changes the communication parameters by implementing a dual-use I/O line that can operate in a simplified legacy mode when the BMC is in boot block mode. This reduces the memory capacity and protocol requirements needed for communication. The MMB can send simple power authorization commands through this reduced-parameter channel that the boot block can understand with minimal resources, resolving the contradiction between maintaining authorized power control and reducing device complexity requirements.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If complexity is added to the boot block to add communication protocols, then power ON authorization can be obtained, but this is undesirable since firmware bugs at the boot block level cannot be fixed in the field

Engineering Contradiction:
ImprovePower ON authorization capabilityVSAvoidBoot block firmware complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The dual-use I/O line implements a universal communication interface that can operate in multiple modes. It can function as a full IPMI communication channel when the BMC is healthy, and as a simplified legacy channel when the BMC is in boot block mode. This multi-functionality allows the boot block to remain simple while still enabling power authorization through the MMB, resolving the contradiction between obtaining power authorization and maintaining boot block simplicity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7350090B2Ensuring power availability to a blade server when blade management controller is corrupted
Publication Date: 2008.03.25 DELL PROD LP
  • US7350090B2 patent drawing
  • US7350090B2 patent drawing
  • US7350090B2 patent drawing

AI summary

An information handling system having a plurality of blade server modules (BSMs) and power supply units (PSUs) uses a module monitor board (MMB) to monitor and control a power budget of the PSUs by each individual BSM requesting authorization from the MMB in order to power ON and boot-up. A blade management controller (BMC) may communicate with the MMB over a communications bus. However, if the firmware application controlling the BMC has been corrupted the BMC it may run in a “boot block” mode and not contain the intelligence necessary to obtain power ON authorization from the MMB. A single, existing input-output (I/O) line from the MMB to the BMC may be utilized to indicate power ON authorization for the respective BSM. The MMB and BMC may be adapted for preventing the BSM from powering ON without proper authorization from the MMB and that the BMC will always power ON the BSM when enough power is available from the PSU. A dual-use of the I/O line may be used for providing a pseudo-communications channel between the MMB and the BMC when the BMC may be in the BOOT BLOCK mode.