Management Engine Network Firmware Update via Bootable Image
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computing devices face challenges in updating firmware components without disrupting normal operating system functions, particularly for components like hard disk drives, which require a bootable image to update firmware outside the normal OS environment, often relying on physical media or remote server access.
Innovation Solution
A system utilizing a firmware update server, management engine, and update manager to deliver and apply bootable images over a network, allowing for secure, out-of-band updates by creating a stand-alone OS environment and redirecting data access to secure memory, enabling updates without a functioning OS.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If firmware updates are performed outside the normal OS environment using traditional bootable images, then firmware can be updated for components like hard disk drives, but the delivery process requires physical media or remote server access which increases device complexity and operational inconvenience
Solution Approach 1:
The management engine acts as an intermediary between the primary processor and the firmware update process. It receives bootable images from the network, stores them in secure memory, and facilitates the update process without requiring direct physical media insertion or complex remote server access procedures. This intermediary role simplifies the user interface while maintaining reliable update capabilities.
2Reliability
If firmware updates require a bootable image to be delivered via physical media, then updates can be applied to components, but the process requires system shutdown and manual intervention which reduces productivity
Solution Approach 1:
The system performs preliminary actions by automatically receiving and storing bootable images in secure memory before they are needed. The management engine prepares the update environment in advance, so when an update is required, the system can proceed more efficiently without requiring manual media insertion or extensive preparation steps at the moment of update.
Solution Approach 2:
The management engine enables self-service by automatically handling the receipt, storage, and facilitation of firmware updates without requiring manual intervention. The system serves itself by managing the entire update delivery process from network reception to secure storage, reducing the need for user actions and improving overall productivity.
3Productivity
If firmware updates are performed while the OS is running, then system availability is maintained, but traditional components like hard disk drives cannot be updated because they lack access to their firmware during normal operation
Solution Approach 1:
The management engine serves as an intermediary that enables firmware updates to occur while the OS remains running. It provides the necessary interface between the running system and the update process, allowing components to be updated without requiring full system shutdown, thus maintaining productivity while enabling update flexibility.
4Ease of operation
If bootable images are stored on remote servers, then physical media is eliminated, but network dependency increases and update delivery may fail without network connectivity
Solution Approach 1:
The system extracts the bootable image from the network environment and stores it locally in secure memory on the device. This extraction removes the immediate network dependency for the actual update process. The bootable image is taken out from the remote server and placed in a local, reliable storage location that does not require network connectivity for access during the update process.
Solution Approach 2:
The system performs the action of receiving and storing the bootable image in advance, before the actual firmware update is needed. By preliminarily acquiring and storing the update image locally in secure memory, the system eliminates the need for network access during the critical update moment, ensuring reliability even when network connectivity is unavailable at the time of update execution.
Data Source
AI summary
Embodiments of systems and methods for applying a component update using a management engine are disclosed. A computing device may include a management engine to store a bootable image containing an update for a component of the computing device in a secured memory location and configure the computing device to boot from the bootable image. Such configuration may include configuring the computing device for integrated device electronics redirection (IDE-R) to the bootable image. A firmware update server may generate the bootable image containing the update, digitally sign the bootable image, and transmit the bootable image to the computing device for the update to be applied. The firmware update server may sign the bootable image with an original equipment manufacturer key, such as a firmware signing key. The firmware update server may notify all computing devices connected to a network that the update is available. Other embodiments are described and claimed.


