Virtual Bus Device for OS-Independent Firmware Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing management engine technologies face challenges in providing secure and independent firmware and software updates to platforms, especially when the operating system is corrupted or not present, as they rely on the host OS for management and provisioning processes.

Innovation Solution

A management engine with a configurable virtual bus device allows for secure, independent firmware and software updates by simulating a bus device, using protocols like Client Initiated Remote Access, and managing bus configuration requests, enabling updates even when the OS is absent or corrupted.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the management engine relies on the host operating system for firmware and software updates, then the updates can be managed through standard OS mechanisms, but the updates cannot be performed when the OS is corrupted or not present

Engineering Contradiction:
Improvefirmware update capabilityVSAvoidindependence from host OS state
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the update management functionality into a separate virtual bus device that operates independently from the host OS. The management engine creates a virtual PCI bus device that can receive and process update requests without requiring the host OS to be functional, allowing firmware updates even when the OS is corrupted or absent.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The virtual bus device acts as an intermediary between the external update source and the management engine's internal firmware. This intermediary layer enables update transactions to be initiated and processed through standard PCI bus protocols while bypassing the need for a functioning host OS, thus resolving the contradiction between reliability and OS dependency.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the management engine uses direct network access for updates, then updates can be performed independently of the host OS, but the device complexity increases

Engineering Contradiction:
Improveindependence from host OSVSAvoidupdate mechanism complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The virtual bus device leverages existing PCI bus protocols and management engine capabilities to provide update functionality. By reusing established communication protocols and the existing network interface controller, the patent achieves OS-independent updates without significantly increasing device complexity, as the virtual device shares underlying hardware resources.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If the management engine simulates a bus device for updates, then secure updates can be performed without host OS involvement, but the ease of operation decreases

Engineering Contradiction:
Improvesecure update capabilityVSAvoidupdate provisioning simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent creates a virtual copy of a PCI bus device within the management engine's address space. This virtual device replica allows standard PCI configuration mechanisms to be used for secure update transactions, maintaining compatibility with existing update tools and protocols while enabling secure updates independent of the host OS state.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP2363803B1Virtual bus device using management engine
Publication Date: 2018.07.11 INTEL CORP
  • EP2363803B1 patent drawingFigure 1~3
  • EP2363803B1 patent drawingFigure 2
  • EP2363803B1 patent drawingFigure 4~5

AI summary

A management engine may be used to trap configuration cycles during the boot process and thereafter in response to operating system enumeration. As a result, a virtual bus device can be created. The bus device may be used to provision software to the platform even when the operating system is corrupted or non-functional.