Out-of-band Firmware Update Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional processor firmware updates in server systems require administrators to switch between out-of-band and in-band management interfaces multiple times, leading to asynchronous errors and other issues during the update process.

Innovation Solution

A firmware update system that receives a single out-of-band command to unlock firmware storage devices, transmit an update package to the operating system for updating, and subsequently lock the devices, eliminating the need for frequent interface switching.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If administrators switch between out-of-band and in-band management interfaces multiple times to complete firmware updates, then firmware can be updated, but the update process becomes complex and error-prone due to asynchronous operations

Engineering Contradiction:
Improvefirmware update reliabilityVSAvoidupdate process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the out-of-band and in-band management interfaces into a unified firmware update process. The remote access controller (out-of-band) and operating system engine (in-band) work together through a coordinated protocol where the remote access controller initiates the update, the operating system engine executes it, and the remote access controller restores security settings, all through a single administrative action that eliminates the need for multiple interface switches

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a firmware update package as an intermediary artifact that bridges the out-of-band and in-band management domains. This package contains the firmware image and update metadata, and is transmitted from the remote access controller to the operating system engine, serving as a standardized interface that simplifies the interaction between the two management planes

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If administrators manually manage write protection states through multiple commands, then firmware storage devices can be protected, but the update process time increases due to sequential operations

Engineering Contradiction:
Improvefirmware storage protectionVSAvoidupdate process time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by having the remote access controller disable write protection on firmware storage devices before the operating system engine executes the firmware update, and then automatically re-enable write protection after the update completes. This automated sequence eliminates manual intervention and reduces the time administrators spend managing protection states

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent ensures continuity of useful action by maintaining the firmware update process as an uninterrupted sequence of operations. The remote access controller and operating system engine coordinate to keep the update process flowing continuously from initiation through completion, with automated write protection management ensuring seamless transitions between protected and updateable states

Inventive Principle:
Principle #20Continuity of useful action

3Ease of operation

If firmware storage devices remain unlocked during update, then updates can be applied, but security risks increase due to potential unauthorized modifications

Engineering Contradiction:
Improvefirmware update easeVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by having the remote access controller automatically re-enable write protection on firmware storage devices immediately after the operating system engine completes the firmware update. This preemptive security measure counteracts the temporary vulnerability created by unlocking the devices during the update process, ensuring that the window of exposure is minimized and automatically closed

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS11842186B2Firmware update system
Publication Date: 2023.12.12 DELL PROD LP
  • US11842186B2 patent drawing
  • US11842186B2 patent drawing
  • US11842186B2 patent drawing

AI summary

A firmware update system includes firmware storage device(s), an operating system engine coupled to the firmware storage device(s), and a remote access controller device coupled to the firmware storage device(s) and the operating system engine. The remote access controller device receives a single out-of-band firmware update command and, in response, performs a firmware storage device unlock operation to unlock the firmware storage device(s), transmits a firmware update package including a firmware update utility and a firmware update image to the operating system engine to cause the operating system engine to utilize the firmware update utility to update firmware stored in the firmware storage device(s) that was unlocked with the firmware update image and, subsequent to the operating system engine updating the firmware stored in the at least one firmware storage device that was unlocked, performs a firmware storage device lock operation to lock the firmware storage device(s).