Software update on a secured computing device
Systems and methods are provided that will automatically trigger a migration process on a secured computing device. A migration application may be remotely pushed to one or more secure computing devices. The secured computing device may set a boot priority for a new software on a first location on a hard drive. The secured computing device may detect an existence of a firmware migration variable and migrate the computing device to an updated state.
1 . A method for triggering a migration process, comprising:
at a computing device having a secure boot configuration policy:
setting a boot priority for a new software on a first location on a hard drive;
detecting an existence of a firmware migration variable;
migrating the computing device to an updated state; and
deleting the firmware migration variable.
2 . The method of claim 1 , wherein setting the boot priority for the new software on the first location on the hard drive forces the computing device to boot from the first location on the hard drive after the computing device boots up.
3 . The method of claim 1 , wherein in response to detecting the existence of the firmware migration variable deleting a current policy file before booting up to the new software.
4 . The method of claim 1 , wherein migrating the computing device to the updated state further includes updating the secure boot configuration policy stored in firmware.
5 . A method for triggering software migration process on a computing device running a current software, comprising:
detecting an existence of a migration application on the computing device, wherein the migration application triggers the software migration process, including:
downloading a new software image to a first location on a hard drive;
setting a boot priority for the new software image on the first location on the hard drive;
setting a firmware migration variable for a software migration; and
booting up the computing device;
detecting the existence of the firmware migration variable for the software migration;
performing the software migration; and
deleting the firmware migration variable.
6 . The method of claim 5 , wherein detecting the existence of the migration application is performed after a boot up.
7 . The method of claim 5 , wherein the method further includes identifying a computing device type and a current operating system (OS) running on the computing device.
8 . The method of claim 7 , wherein the method further includes cross-referencing the computing device type to a target computing device type identified by the migration application, cross-referencing the current OS running on the computing device to a target OS identified by the migration application and to proceed with the software migration process when the computing device type match with the target computing device type and when the current OS match with the target OS.
9 . The method of claim 5 , wherein the method further includes verifying a signature of the migration application.
10 . The method of claim 5 , further including repartitioning the hard drive on the computing device.
11 . The method of claim 10 , wherein repartitioning the hard drive further includes shrinking a current system partition.
12 . The method of claim 11 , wherein repartitioning the hard drive further includes creating a new system update partition.
13 . The method of claim 12 , wherein the new software image is downloaded to the new system update partition.
14 . The method of claim 13 , wherein the new software image is a new operating system image.
15 . The method of claim 5 , wherein downloading the new software image to the first location further includes determining a locale type of the computing device and selecting from a plurality of new software locale types, a matching locale type for downloading.
16 . The method of claim 5 , wherein setting the boot priority for the new software image located on the first location forces the computing device to boot the new software image from the first location on the hard drive after the computing device boots up.
17 . The method of claim 12 , wherein installing the new software image further includes deleting the new system update partition.
18 . The method of claim 12 , wherein detecting the existence of the firmware migration variable further includes migrating to the new software.
19 . The method of claim 5 , wherein in response to detecting the existence of the firmware migration variable deleting a current policy file before booting up to the new software.
20 . A method for triggering a software migration process to an updated operating system (OS) on one or more secured computing devices, comprising:
accessing a management service; and
pushing a migration application to selected the one or more secured computing devices, wherein the one or more secured computing devices each include, in firmware, a secure boot configuration policy (SBCP) and are triggered by the migration application to begin the software migration process to the updated OS after a reboot of the one or more secured computing devices based on the migration application setting a firmware migration variable that modifies the SBCP to allow the updated OS, wherein the firmware migration variable is deleted after migration.