Out-of-band Controller for Secure Firmware Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional firmware update methods rely on operating system-based mechanisms, which can fail if the BIOS or microcode is corrupted or if network connectivity is impaired, leading to interrupted operations and user experience issues.

Innovation Solution

An out-of-band (OOB) controller operates independently of the CPU and operating system to receive and apply firmware updates, allowing updates even when the system is unbootable, using remote direct memory access (RDMA) and secure storage mechanisms to ensure seamless and fault-tolerant updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional operating system-based firmware update mechanisms are used, then firmware updates can be applied during normal system operation, but the update process may fail if the BIOS or microcode is corrupted or if network connectivity is impaired

Engineering Contradiction:
Improvefirmware update reliabilityVSAvoidupdate operation continuity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system separates firmware update functionality from the main operating system by implementing an out-of-band controller that operates independently. This segmentation allows the update mechanism to function even when the primary system is corrupted or unavailable, resolving the contradiction between reliability and operational continuity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An out-of-band controller serves as an intermediary component that mediates firmware updates independently of the main CPU and operating system. This intermediary can retrieve and apply updates through alternative pathways (such as direct storage access or out-of-band network interfaces) when primary systems fail, ensuring update reliability without dependency on normal system operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the system operates normally with CPU and operating system, then standard firmware update procedures can be executed, but updates cannot be applied when the system is unbootable or corrupted

Engineering Contradiction:
Improveupdate execution capabilityVSAvoidupdate availability in failed states
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The out-of-band controller is pre-configured with the capability to access storage devices and retrieve firmware updates independently of the main system state. This preliminary preparation of alternative update pathways ensures that updates can be executed even when the system is unbootable, resolving the contradiction between operational capability and availability in failed states.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If firmware updates are performed through the operating system, then updates can be managed with user awareness and control, but the process may be interrupted by user actions or system events

Engineering Contradiction:
Improveuser control over updatesVSAvoidupdate completion assurance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The firmware update functionality is extracted from the operating system environment and relocated to an out-of-band controller. This extraction removes the update process from the realm of user-controlled operations, allowing updates to proceed autonomously without interruption from user actions or system events, thereby ensuring reliable completion while sacrificing some user control.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3758326B1Secure updating of computing system firmware
Publication Date: 2022.02.23 INTEL CORP
  • EP3758326B1 patent drawingFigure 1
  • EP3758326B1 patent drawingFigure 2
  • EP3758326B1 patent drawingFigure 3

AI summary

A system comprising a controller to operate in an out of band fashion with respect to a central processing unit, the controller comprising a memory, and a processing element to request a firmware module from a computing system over a network, and cause the firmware module to be communicated to a storage controller for installation on a storage device.