SmartNIC Boot Failure Protection via Watchdog API

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Bare-metal hypervisors deployed on smartNICs and other computing devices lack effective boot failure protection, particularly during the gap between firmware hand-off and operating system initialization, leading to silent failures and compromised fault error reporting and recovery.

Innovation Solution

A system is implemented that configures a computing device to install an application programming interface (API) to control a hardware-implemented watchdog during the booting process, enabling it during operating system loading and performing a last refresh before handing off execution to the kernel boot loader, ensuring fault detection and recovery without CPU resource monopolization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a hardware watchdog is enabled during the boot process to detect boot failures, then boot failure protection is improved, but CPU resources may be monopolized during normal operation

Engineering Contradiction:
Improveboot failure protectionVSAvoidCPU resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent enables the hardware watchdog during the boot process before the operating system takes control, performing the protection action preliminarily when it is most needed. The watchdog is configured and enabled by the boot loader or firmware during system initialization, allowing it to monitor critical boot stages without requiring continuous CPU intervention during normal operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The hardware watchdog operates as an independent self-service mechanism that monitors system state without consuming CPU resources. Once enabled, it autonomously detects boot failures and triggers appropriate error handling, freeing the CPU to focus on productive work while maintaining system reliability during critical transitions.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If a single bare-metal hypervisor image is deployed across disparate devices, then adaptability is improved, but boot failure protection may be compromised due to hardware variations

Engineering Contradiction:
Improvehypervisor deployment flexibilityVSAvoidboot failure protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent creates a universal boot loader or firmware layer that implements standardized hardware watchdog control across different device types. This universal interface allows a single hypervisor image to be deployed on disparate hardware platforms while maintaining consistent boot failure protection, as the watchdog mechanism is abstracted through a common control interface that handles hardware variations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary firmware or boot loader layer between the hardware watchdog and the hypervisor. This intermediary provides standardized control functions that work across different hardware platforms, allowing the hypervisor to rely on consistent watchdog behavior regardless of underlying hardware variations, thus maintaining both adaptability and reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If the boot loader disables the hardware watchdog during OS hand-off as per existing specifications, then compliance is improved, but fault detection capability is lost during the protection gap

Engineering Contradiction:
Improvespecification complianceVSAvoidfault detection capability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent performs preliminary configuration of the hardware watchdog during early boot stages, enabling it before the OS hand-off point where it would traditionally be disabled. The watchdog is set up with appropriate timeouts and monitoring parameters in advance, ensuring it remains active during the critical transition period when silent failures could occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the boot loader or firmware continuously monitors watchdog status and system state during the OS hand-off transition. This feedback loop ensures the watchdog remains properly configured and active, detecting faults that would otherwise go unnoticed during the specification-compliant hand-off process.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11803445B2Boot failure protection on smartNICs and other computing devices
Publication Date: 2023.10.31 VMWARE INC
  • US11803445B2 patent drawing
  • US11803445B2 patent drawing
  • US11803445B2 patent drawing

AI summary

Boot failure protection on smartNICs and other computing devices is described. During a power-on stage of a booting process for a computing device, a boot loading environment is directed to install an application programming interface (API) able to be invoked to control operation of a hardware-implemented watchdog. During an operating system loading stage of the booting process, the application programming interface is invoked to enable the hardware-implemented watchdog. During an operating system hand-off stage of the booting process, a last watchdog refresh of the hardware-implemented watchdog is performed, and execution of the boot loading environment is handed off to a kernel boot loader of an operating system. The application programming interface may not be accessible after the hand off to the kernel boot loader.