Dual-Bank Firmware Update via Warm Reboot
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Firmware updates in computing systems often disrupt application performance and lead to downtime due to the need for system reinitialization, causing data loss and suboptimal system availability, especially in cloud environments where multiple virtual machines share firmware.
Innovation Solution
Implementing a multi-staged firmware update process where patches are written to a secondary non-volatile memory initially, allowing a warm reboot to apply updates without suspending applications, and ensuring data integrity through authentication and shadowing of the firmware image.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If firmware update is performed by writing patch to firmware image using firmware interfaces, then firmware security and reliability are improved, but system downtime increases and application performance deteriorates
Solution Approach 1:
The firmware storage is segmented into dual banks (first bank and second bank), allowing updates to be applied to one bank while the other remains operational. This enables firmware updates without system downtime by switching between banks.
Solution Approach 2:
The update firmware is written to a secondary non-volatile memory before being applied to the primary firmware. This preliminary action allows the update to be prepared and authenticated without interrupting system operations, and the switch to updated firmware can occur seamlessly.
2Reliability
If control shifts from OS to firmware subsystem during firmware update, then firmware update can be performed, but application operations are suspended and system availability decreases
Solution Approach 1:
A secondary non-volatile memory acts as an intermediary for storing update firmware. This allows the OS to prepare and authenticate updates without requiring control to shift to the firmware subsystem, maintaining system availability during the update process.
Solution Approach 2:
The update firmware is written to secondary non-volatile memory in advance and authenticated before being applied. This preliminary preparation allows the firmware update to occur without suspending application operations, as the update is ready to be switched in seamlessly.
3Reliability
If firmware update is performed, then firmware issues are addressed, but data loss occurs and applications cannot restore to last state
Solution Approach 1:
The system maintains a backup firmware bank and uses secondary non-volatile memory to store update firmware before application. This cushioning mechanism ensures that if an update fails or causes data loss, the system can revert to the previous firmware state, preserving application data integrity.
Solution Approach 2:
The update firmware is copied to secondary non-volatile memory and authenticated before being applied to the primary firmware. This copying process creates a verified backup that prevents data loss by ensuring only authenticated updates are applied, and the original firmware remains intact until successful update completion.
4Reliability
If traditional firmware update process is used, then firmware can be updated, but multiple virtual machines sharing firmware experience severe disruption
Solution Approach 1:
The firmware is segmented into dual banks that can be independently updated. This allows one bank to serve multiple virtual machines while the other bank is being updated in the background, enabling firmware updates without disrupting virtual machine operations.
Solution Approach 2:
Update firmware is written to secondary non-volatile memory and authenticated in advance, allowing the update to be applied atomically across all virtual machines sharing the firmware. This eliminates severe disruption by ensuring the update is ready and verified before affecting any virtual machine operations.
Data Source
AI summary
Example techniques for updating a firmware, such as BIOS, are disclosed. Upon receiving an update, it is determined whether a secondary non-volatile memory is defined for the firmware. If the secondary non-volatile memory is defined, the update may be written in the secondary non-volatile memory. Further, to apply the update, a warm reboot of the firmware may be performed. The warm reboot causes an OS of the computing system to restart, while preserving data associated with applications running on the computing system.


