BMC Firmware Update via Cross-Node Flash Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing multi-node storage systems face challenges in updating firmware, particularly when the BIOS or firmware images are corrupted, as they require booting to an operating system to perform updates, rendering the system inoperable if faulty during power cycling.
Innovation Solution
A method and system where two nodes in a storage system share identical flash images, allowing a Baseboard Management Controller (BMC) to retrieve and update firmware images from a separate node even if the system has not booted, using switch devices with multiplexors to connect BMCs and storage expander controllers to flash ROMs, ensuring continuity and recovery of firmware images.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the system boots to operating system to update firmware, then firmware can be updated, but system becomes inoperable if update fails during power cycling
Solution Approach 1:
The system performs preliminary actions by having the BMC retrieve and validate firmware images from flash ROM during power-on self-test, before the operating system boots. This allows firmware updates to occur during hardware initialization rather than requiring OS-level intervention, preventing system inoperability if updates fail.
Solution Approach 2:
The BMC acts as an intermediary between the flash ROM and the system components. It retrieves firmware images directly from flash ROM during POST, validates them, and coordinates the update process independently of the operating system, ensuring system operability is maintained throughout the update process.
2Adaptability or versatility
If firmware images are stored in in-system writable flash memory, then firmware can be updated, but images can be corrupted
Solution Approach 1:
The system implements beforehand cushioning by validating firmware images during the POST process before they are fully activated. The BMC checks image integrity and validity during hardware initialization, providing a safety mechanism that prevents corrupted images from compromising system operation.
Solution Approach 2:
The BMC performs feedback validation by checking firmware image integrity during POST and reporting status to the system. This feedback mechanism allows the system to detect and respond to potential corruption issues before they affect operational reliability.
Data Source
AI summary
A multiple storage node system including a first and second node is provided. The first node includes a first baseboard management controller (BMC), a first flash ROM configured to store a first flash image, and a first switch device configured to connect the first BMC to the first flash ROM. The second node includes an exact configuration of the first node. The first BMC is connected to the second switch device, and the second flash image is the same as the first flash.


