In-System Firmware Provisioning via Manageability Engine
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional computing devices require separate components like flash storage for firmware, which increases costs and design complexity, and lack effective recovery mechanisms for compromised or missing firmware.
Innovation Solution
Implementing a hardware platform with a nonvolatile storage device that can store system firmware and using a manageability engine to provision firmware from an external source, ensuring security and eliminating the need for separate firmware storage components.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate components like flash storage are used for firmware storage, then firmware can be stored and executed, but hardware platform cost and design complexity increase
Solution Approach 1:
The patent merges the firmware storage function into the main nonvolatile storage device that is already part of the hardware platform. Instead of using a separate flash storage component, the system utilizes the existing nonvolatile storage device to store both firmware and operating system data, thereby eliminating the need for additional dedicated firmware storage components and reducing overall hardware complexity
Solution Approach 2:
The nonvolatile storage device is designed to serve multiple functions: storing the operating system, storing firmware for platform initialization, and providing data persistence. This multi-functional approach allows a single component to replace what would traditionally require multiple separate components, reducing hardware complexity while maintaining all necessary storage capabilities
2Ease of manufacture
If firmware is stored in separate components, then firmware can be independently managed, but manufacturing cost increases
Solution Approach 1:
By combining firmware storage with the main nonvolatile storage device, the patent reduces the total quantity of hardware components needed. The system eliminates separate flash storage components while maintaining the ability to store and manage firmware, thereby reducing both component count and associated manufacturing costs
Solution Approach 2:
The patent enables firmware to be provisioned from external sources and copied into the nonvolatile storage device during system initialization or updates. This copying mechanism allows flexible firmware management without requiring physical firmware components to be pre-installed or manually attached during manufacturing
3Productivity
If ROM code is used for initial execution, then hardware platform can start operation, but firmware cannot be updated or recovered if compromised
Solution Approach 1:
The patent implements a boot sequence where the system first executes ROM code to initialize hardware, then loads firmware from the nonvolatile storage device into volatile memory for execution. This preliminary action of loading firmware from persistent storage enables both initial operation and subsequent firmware updates or recovery, as the system can reload firmware from the nonvolatile storage device if it becomes compromised
Solution Approach 2:
The system is designed to discard firmware from volatile memory when needed (such as during updates or recovery operations) and recover by reloading firmware from the nonvolatile storage device. This mechanism allows the platform to recover from firmware corruption or attacks by重新 loading firmware from the persistent storage medium
4Device complexity
If firmware is stored in nonvolatile storage device, then separate firmware components are eliminated, but secure external provisioning capability is reduced
Solution Approach 1:
The patent introduces a manageability engine as an intermediary component that facilitates secure external firmware provisioning. This mediator handles authentication, authorization, and secure data transfer between external sources and the nonvolatile storage device, ensuring that firmware updates can be performed securely without compromising system security or requiring complex hardware changes
Data Source
AI summary
A hardware platform includes a nonvolatile storage device that can store system firmware as well as code for the primary operating system for the hardware platform. The hardware platform includes a controller that determines the hardware platform lacks functional firmware to boot the primary operating system from the storage device. The controller accesses a firmware image from an external interface that interfaces a device external to the hardware platform, where the external device is a firmware image source. The controller provisions the firmware from the external device to the storage device and initiates a boot sequence from the provisioned firmware.


