Firmware Partitioning for Multi-OS Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Legacy data processing systems face challenges in efficiently managing and isolating multiple operating systems within a single processing system, as they typically rely on BIOS or EFI models that lack flexibility in resource allocation and visibility control, leading to limitations in debugging, virtualization, and resource hiding.

Innovation Solution

The implementation of firmware-based partitioning techniques that create distinct partitions within a processing system, allowing for separate operating systems and resource allocation, using device hide registers and ACPI parameters to hide processing units and RAM from the main OS, enabling independent execution environments for debugging and other applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional BIOS or EFI models are used to manage multiple operating systems, then the system structure remains simple, but flexibility in resource allocation and visibility control is limited

Engineering Contradiction:
Improveflexibility in resource allocationVSAvoidsystem structure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the processing system into distinct partitions (first partition and second partition), each capable of running different operating systems independently. This segmentation enables flexible resource allocation while maintaining a manageable structure through clear partition boundaries.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements nesting by placing one partition inside another, where the first partition contains a first operating system and the second partition contains a second operating system. This nested structure allows multiple operating systems to coexist within a single processing system, providing flexibility without requiring complete system redesign.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Reliability

If hardware-based partitioning is used to create separate execution environments, then OS independence is achieved, but the cost and complexity increase significantly

Engineering Contradiction:
ImproveOS independenceVSAvoidhardware-based partitioning complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent substitutes the mechanical hardware-based partitioning approach with a software/firmware-based solution. Instead of using physical hardware partitions, the invention uses firmware structures and memory management to create logical partitions that provide OS independence without requiring expensive hardware modifications.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent applies copying by creating virtual representations of hardware resources within each partition. Each partition has its own view of memory and devices, with the system maintaining separate memory spaces and device mappings for each partition, enabling OS independence through virtual copying rather than physical duplication.

Inventive Principle:
Principle #26Copying

3Productivity

If additional software layers are added to manage multiple operating systems, then resource management improves, but the system complexity and overhead increase

Engineering Contradiction:
Improveresource management efficiencyVSAvoidsoftware layers complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing a multi-functional firmware structure that handles multiple operating systems through a single unified approach. The firmware provides common services to both partitions while maintaining their independence, reducing the need for separate software layers for each operating system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the management of multiple operating systems into a unified firmware structure. Instead of requiring separate software layers for each OS, the invention combines resource management functions into a single firmware layer that serves both partitions, reducing overall system complexity while maintaining efficient resource management.

Inventive Principle:
Principle #5Merging (Combining)

4Adaptability or versatility

If device hide registers and ACPI parameters are used to hide processing units and RAM, then debugging and fault prediction capabilities improve, but the firmware complexity increases

Engineering Contradiction:
Improvedebugging capabilityVSAvoidfirmware complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies parameter changes by modifying ACPI parameters and device hide registers to control the visibility of processing units and RAM to different operating systems. By changing these parameters, the system can hide specific resources from certain partitions, enabling debugging and fault prediction capabilities without requiring fundamental firmware redesign.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10120695B2Method and apparatus to support separate operating systems in partitions of a processing system
Publication Date: 2018.11.06 INTEL CORP
  • US10120695B2 patent drawing
  • US10120695B2 patent drawing
  • US10120695B2 patent drawing

AI summary

A processing system with multiple processing units may support separate operating systems (OSs) in separate partitions. During an initialization process, a preboot manager in the processing system may copy software to a sequestered area of memory in the processing system. The preboot manager may also configure the processing system to hide the sequestered area of memory from a first partition of the processing system. Also, the preboot manager may use a first processing unit in the processing system to boot an OS on the first partition, and the preboot manager may transmit a boot trigger from the first processing unit to a second processing unit in the processing system. The boot trigger may cause the second processing unit to use the software in the sequestered area of memory to boot a second partition of the processing system. Other embodiments are described and claimed.