Processor Microcode Update Without Restart
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In cloud computing environments, updating processor microcode to fix security flaws and software bugs is challenging due to the need for minimal disruption to ongoing operations, especially when multiple users share resources via hypervisors, as conventional methods require restarting the computing device and can be difficult to coordinate without impacting customer experience.
Innovation Solution
A method to update processor microcode without restarting the device by receiving a microcode patch from a trusted source, authenticating it, and applying it using system management mode or other isolated execution modes, allowing the patch to be stored in volatile memory and reapplied on every reset, ensuring security and flexibility without permanent changes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional microcode updating methods are used, then security flaws and software bugs can be fixed, but device restart is required which disrupts ongoing operations and impacts customer experience
Solution Approach 1:
The patent applies preliminary action by preparing and validating the microcode patch before applying it to the running system. The patch is authenticated, decrypted, and validated in advance within the isolated execution environment, ensuring it is ready for immediate application without requiring system restart. This preliminary preparation resolves the contradiction by enabling security updates while maintaining operational continuity.
Solution Approach 2:
The patent introduces an intermediary isolated execution environment that acts as a mediator between the running hypervisor and the microcode updating process. This intermediary environment allows patch authentication, decryption, and validation to occur without interfering with ongoing customer operations. The isolated environment serves as a buffer that enables security updates while preserving operational continuity.
2Reliability
If microcode patching is performed in shared cloud computing environments, then security updates can be applied, but coordination becomes difficult without significantly impacting customer experience
Solution Approach 1:
The patent applies segmentation by dividing the microcode updating process into distinct isolated stages: patch reception, authentication, decryption, validation, and application. Each stage occurs in an isolated execution environment that is separated from the running hypervisor and customer workloads. This segmentation simplifies coordination by providing a clear, structured process that can be executed without interfering with shared cloud resources.
Solution Approach 2:
The isolated execution environment serves as an intermediary that simplifies coordination in shared cloud environments. It provides a dedicated space for patch processing that does not require coordination with other customers or services. The intermediary environment handles the complexity of patch authentication and validation, making the overall update process easier to coordinate while maintaining security and operational continuity.
3Reliability
If device restart is required for microcode updates, then complete system reset ensures patch application, but service interruption occurs which degrades customer experience
Solution Approach 1:
The patent applies continuity of useful action by enabling microcode patching to occur in the running system without interruption to customer services. The isolated execution environment allows the hypervisor to continue executing customer workloads while the patch is authenticated, validated, and applied in parallel. This maintains continuous useful action by preventing service interruption while ensuring complete patch application.
Solution Approach 2:
The patent uses preliminary action by completing all necessary patch validation and authentication steps before the patch is applied to the running system. This preliminary verification ensures patch application completeness without requiring a subsequent system restart. The patch is thoroughly checked in advance, allowing it to be safely applied while the system continues to operate, thus eliminating service interruption.
Data Source
AI summary
Approaches are described for updating code and/or instructions in one or more computing devices. In particular, various embodiments provide approaches for updating the microcode of one or more processors of a computing device without requiring a restart of the computing device and without disrupting the various components (e.g., applications, virtual machines, etc.) executing on the computing device. The microcode updates can be performed on host computing devices deployed in a resource center of a service provider (e.g., cloud computing service provider), where each host computing device may be executing a hypervisor hosting multiple guest virtual machines (or other guest applications) for the customers of the service provider.


