Repository navigation
Open Platform Firmware Update
Platform and device firmware plays a critical role in maintaining system service uptime. Post-deployment firmware updates for security and performance require disruptive system reboots and workload downtime. Deploying updates at scale is highly complex because fixes span multiple subsystems (processor, memory, storage, network, I/O). Currently defined firmware update specifications try to provide pointed solutions (examples GPU firmware update, secure firmware recovery, impactless firmware update), the system level solution requires further co-ordination. Furthermore, firmware updates security co-ordination with OS needs enhancements to create system level firmware update solutions.
Currently there is no single place in OCP co-ordinates the runtime firmware updates. This workstream will serve to co-ordinate the firmware update activities across OCP and co-ordinate new firmware update related initiatives with a goal of enabling efficient and impactless system updates.
To establish an open, standardized framework for runtime firmware updates that maximizes uptime by eliminating reboots, safely preserving platform memory, maintaining continuous security attestation via runtime measurement updates, and enabling native OS-to-firmware coordination across the industry.
Enable Disruption-Free Updates: Apply firmware patches dynamically during runtime to ensure continuous workload execution.
Coordinate Multi-Subsystem Fixes: Orchestrate concurrent or isolated patches safely across processor, memory, and I/O topologies.
Update Runtime Security Measurements: Refresh cryptographic measurements and attestation states dynamically without a reboot.
Pioneer Memory-Preserving Updates: Execute deep firmware updates while completely preserving active system memory contents and workload states.
Establish OS-to-Firmware Orchestration: Create communication channels so firmware can signal the OS to gracefully quiesce or migrate workloads before an update.
- OS Coordination Layer: APIs and notification channels to handshake update events between firmware and the host OS/hypervisor.
- Memory-Preservation Frameworks: Methods for locking and shielding volatile memory domains during a runtime update.
- Dynamic Attestation Protocols: Mechanisms to update security manifests and platform measurements on the fly.
- Subsystem Orchestration Architecture: Standardized sequences for staging and executing multi-subsystem patches.
- Vendor Proprietary Code: Internal implementation details or proprietary code inside vendor firmware binaries.
- Traditional Cold-Boot Methods: Standard update paths mandating complete platform power cycles or full system resets.
- Pure OS/Application Patching: Software updates confined strictly to the operating system or application layers.
| Organization | Representative |
|---|---|
| Microsoft | Vishal Soni |
| Oracle | Sammy Nachimuthu |