BMC Fail-Safe Flashing via Volatile Memory Backup
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing fail-safe flashing techniques for baseboard management controllers (BMCs) often result in loss of critical information during the flashing process, especially when the client fails, leading to potential system failures.
Innovation Solution
A method involving a flasher module that operates in flash mode, copies critical information to volatile memory, upgrades firmware, mixes and matches new critical information, and writes it back to non-volatile memory with user input or after a predetermined time, ensuring data integrity and system stability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the BMC is flashed remotely from a client, then the firmware can be upgraded, but the client failure during flashing causes loss of critical information
Solution Approach 1:
The patent performs preliminary actions by copying critical information from non-volatile memory to volatile memory before the actual firmware flashing operation. This preparatory step ensures that critical information is preserved in a safe location (volatile memory) before the vulnerable flashing process begins, preventing information loss if the client fails during flashing.
Solution Approach 2:
The patent introduces volatile memory as an intermediary between non-volatile memory and the firmware flashing process. Critical information is first copied to volatile memory, which acts as a temporary safe storage during the flashing operation. This intermediary mechanism isolates the critical information from the potentially harmful flashing process while still allowing the upgrade to proceed.
2Ease of operation
If the flashing process is driven by the client side, then remote flashing is enabled, but the BMC loses critical information when client fails
Solution Approach 1:
The patent implements feedback mechanisms by having the BMC periodically report its status and critical information integrity to the client during the flashing process. This feedback allows the system to detect issues early and take corrective actions, maintaining reliability while preserving the remote operation capability. The BMC can alert the client if critical information appears to be at risk.
Solution Approach 2:
The patent enables the BMC to perform self-service during the flashing process by autonomously copying critical information to volatile memory and managing its own state transitions. This self-service capability ensures that the BMC can protect its critical information without continuous client intervention, maintaining reliability even when the client connection is interrupted or fails.
3Duration of action of stationary object
If critical information is stored in non-volatile memory, then data persistence is achieved, but data loss occurs during firmware rewriting
Solution Approach 1:
The patent segments the memory storage by separating critical information from the firmware storage areas. Critical information is copied to a dedicated volatile memory region that is isolated from the firmware flashing operations in non-volatile memory. This segmentation allows firmware rewriting to proceed in one area while critical information remains protected in another, preventing data loss during the rewriting process.
Solution Approach 2:
The patent uses copying as a protective mechanism by creating a duplicate of critical information in volatile memory before the flashing operation. This copy serves as a backup that cannot be accidentally overwritten by firmware rewriting operations. The original in non-volatile memory maintains persistence, while the copy in volatile memory prevents loss during the flashing process.
Data Source
AI summary
An aspect relates to fail safe flashing techniques for a management device of a computer system. A non-volatile memory of the management device stores a current firmware, an actual critical information and a backup critical information, which is rewritable in a booting mode and read-only in a flash mode. A flasher module is launched to operate the management device in the flash mode. The actual critical information is copied to a volatile memory and erased in the non-volatile memory. A replacement firmware is used to upgrade the current firmware. The actual critical information is mixed and matched with a new critical information. A user input is requested to write the mixed and matched critical information back to the non-volatile memory as the actual critical information. When the user input is not received after a first predetermined time period, the mixed and matched critical information is automatically written back.


