IP Library Granted Patent US 11,100,228
Granted Patent B2
US 11,100,228 · App. 16/171,168 · Granted Aug 24, 2021

System and method to recover FPGA firmware over a sideband interface

Inventors: Johan Rahardjo (Austin, TX); Pavan Kumar Gavvala (Anantapur, IN)
Assignee: Dell Products, L.P.
G06F21/572G06F8/65G06F9/445G06F21/575G06F21/76H04L9/0819H04L9/0861
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,100,228
App. No.
16/171,168
Granted
Aug 24, 2021
Kind
B2
Abstract

Embodiments are described for recovery, via a sideband management bus, of firmware of a device such as an FPGA (Field Programmable Gate Array) card installed within an IHS (Information Handling System). A remote access controller of the IHS generates a security key for the device and transmits it to the device. The remote access controller requests the device to report the current version of the firmware in use by the device. The response from the device is authenticated based on the security key. If the current firmware version reported by the device is consistent with the master firmware version, the device is halted and the current firmware of the device is replaced with the master firmware. The device is initialized based on the master firmware used to update the device firmware.

Claims (49)

1. A method for recovery of firmware of a device installed within an IHS (Information Handling System), the method comprising:

generating a security key for the device installed within the IHS, wherein the security key is generated by a remote access controller also installed within the IHS and that provides remote management of the device, and wherein the remote access controller is coupled to the device via a sideband management bus that provides a signaling pathway within the IHS between the remote access controller and the device, and wherein the device is coupled to a processor of the IHS via an in-line bus, and wherein the remote access controller of the IHS stores a master copy of firmware of the device; and wherein the device comprises an FPGA (Field Programmable Gate Array) coupled to the remote access controller via the sideband management bus that provides a signaling pathway within the IHS between the FPGA and the remote access controller, and wherein the FPGA comprises a management controller that couples the FPGA to the remote access controller within the IHS via the sideband management bus;

transmitting, by the remote access controller, the security key to the device via the sideband management bus that provides a signaling pathway within the IHS between the remote access controller and the device;

requesting, by the remote access controller via the sideband management bus that provides a signaling pathway within the IHS to the device, the device to report a version of firmware in use by the device, wherein the management controller of the FPGA reports the firmware version response to the remote access controller via the sideband management bus;

authenticating, by the remote access controller, a firmware version response from the device based on the security key stored in a secure memory of the remote access controller;

determining, by the remote access controller, when a master firmware version is consistent with the firmware version reported by the device; and

when the reported firmware version is inconsistent with the master firmware version:

halting the operation of the device;

replacing the firmware of the device with the master firmware stored by the remote access controller, wherein the master firmware is transmitted to the device via the sideband management bus the provides a signaling pathway within the IHS between the remote access controller and the device; and

initializing the device using the master firmware.

2. The method of claim 1 , wherein the request for the device to report the firmware version is generated by the remote access controller upon each power cycle of the device.

3. The method of claim 1 , wherein the consistency of the reported firmware with the master firmware is determined by comparing a version specified by a firmware header included in the firmware version response against a version specified by a header of the master firmware stored by the remote access controller.

4. The method of claim 1 , wherein the FPGA maintains firmware in an active partition and in a recovery partition, and wherein the remote access controller replaces firmware in the active partition and the recovery partition of the FPGA with the master firmware stored by the remote access controller.

5. The method of claim 4 , wherein the master firmware stored by the remote access controller replaces the firmware in the active and recovery partitions without the recovery partition of the FPGA being utilized to operate the FPGA.

6. A system for recovery of firmware of device within an IHS (Information Handling System), the system comprising:

a remote access controller installed within the IHS coupled to the device via a sideband management bus that provides a signaling pathway within the IHS between the remote access controller and the device, wherein the device is coupled to a processor of the IHS via an in-line bus, and wherein the remote access controller provides remote management of the device, and wherein the remote access controller stores a master copy of firmware of the device, and wherein the device comprises an FPGA (Field Programmable Gate Array) coupled to the remote access controller via the sideband management bus that provides a signaling pathway within the IHS between the FPGA and the remote access controller, and wherein the FPGA comprises a management controller that couples the FPGA to the remote access controller within the IHS via the sideband management bus, the remote access controller configured to:

generate a security key for the device installed within the IHS, wherein the generated security key is stored in a secure memory of the remote access controller installed within the IHS;

transmit, via the sideband management bus that provides a signaling pathway within the IHS between the remote access controller and the device, the security key to the device;

request, via the sideband management bus that provides a signaling pathway within the IHS between the remote access controller and the device, the device to report a version of firmware in use by the device, wherein the management controller of the FPGA reports the firmware version response to the remote access controller via the sideband management bus;

authenticate a response from the device based on the security key stored in the secure memory of the remote access controller;

determine if the master copy of the firmware stored by the remote access controller is consistent with the active firmware version reported by the device; and

if the reported active firmware version is inconsistent with the master firmware version:

halt the device; and

replace the active firmware of the device with the master firmware; and

the device configured to operate based on firmware stored in an active firmware partition, wherein the device is further configured to:

transmit, via the sideband management bus between the remote access controller and the device, the response reporting the version of the firmware in the active firmware partition;

receive, via the sideband management bus that provides a signaling pathway within the IHS between the remote access controller and the device, master firmware for replacing the firmware in the active partition; and

initialize operations based on the updated active firmware partition.

7. The system of claim 6 , wherein the request for the device to report the firmware version is generated by the remote access controller upon each power cycle of the device.

8. The system of claim 6 , wherein the consistency of the reported firmware with the master firmware is determined by comparing a version specified by a firmware header included in the firmware version response against a version specified by a header of the master firmware stored by the remote access controller.

9. The system of claim 6 , wherein the firmware version reported by the device comprises a signature calculated based on firmware instructions of the device in the active firmware partition.

10. A remote access controller for recovery of firmware of a device and for remote management of the device, the remote access controller comprises:

a sideband management bus that that provides a signaling pathway within the IHS between the remote access controller and the device and wherein the device is coupled to a processor of the IHS via an in-line bus, wherein the device comprises an FPGA (Field Programmable Gate Array) coupled to the remote access controller via the sideband management bus that provides a signaling pathway within the IHS between the FPGA and the remote access controller, and wherein the FPGA comprises a management controller that couples the FPGA to the remote access controller within the IHS via the sideband management bus;

one or more processors; and

a memory device coupled to the one or more processors, wherein the memory device stores a master copy of firmware of the device and a security key for the device, and wherein the memory device stores computer-readable instructions that, upon execution by the one or more processors, cause the remote access controller to:

generate the security key for the device;

transmit, via the sideband management bus that provides a signaling pathway within the IHS between the remote access controller and the device, the security key to the device;

request, via the sideband management bus that provides a signaling pathway within the IHS between the remote access controller and the device, the device to report a current firmware version, wherein the management controller of the FPGA reports the firmware version response to the remote access controller via the sideband management bus;

authenticate a response from the device based on the security key stored by the remote access controller;

determine if the master copy of the firmware stored by the remote access controller is consistent with the active firmware version reported by the device; and

if the reported active firmware version is inconsistent with the master firmware version:

halt the device;

transmit the master firmware to the device via the sideband management bus the provides a signaling pathway within the IHS between the remote access controller and the device;

replace the active firmware of the device with the master firmware; and

initialize the device using the updated firmware.

11. The remote access controller of claim 10 , wherein the request for the device to report a current firmware version is generated by the remote access controller upon each power cycle of the device.

12. The remote access controller of claim 10 , wherein the consistency of the reported firmware with the master firmware is determined by comparing a version specified by a firmware header included in the firmware version response against a version specified by a header of the master firmware stored by the remote access controller.

13. The remote access controller of claim 10 , wherein firmware version reported by the device comprises a signature calculated based on firmware instructions of the device in the active firmware partition.

14. The remote access controller of claim 10 , wherein the FPGA maintains firmware in an active partition and in a recovery partition, and wherein the remote access controller replaces firmware in the active partition and the recovery partition of the FPGA with the master firmware stored by the remote access controller.

Assignments (7)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST AT REEL 052771 FRAME 0906 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0298 →
SECURITY AGREEMENT Recorded May 28, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 052771/0906 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 29, 2018
From: JAIN, SANJEEV KUMAR; KATOCH, ATUL
To: TAIWAN SEMICONDUCTOR MANUFACTURING COMPANY, LTD.
Reel/Frame 047619/0191 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 25, 2018
From: RAHARDJO, JOHAN; GAVVALA, PAVAN KUMAR
To: DELL PRODUCTS, L.P.
Reel/Frame 047316/0356 →
Continuity (1)
Related Publication 20200134183A1 · Apr 30, 2020