Multi-firmware refreshing method and device, electronic equipment and storage medium

By signing and hash verification of the target image file, parsing and matching firmware and hardware data, writing firmware files in sequence and rolling back on failure, it solves the inefficiency of multi-firmware refresh and version compatibility issues, ensuring device security and reliability.

CN120335844AActive Publication Date: 2025-07-18INSPUR SUZHOU INTELLIGENT TECH CO LTD

Patent Information

Application Number
CN202510823647.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-19
Publication Date
2025-07-18
Estimated Expiration
2045-06-19

AI Technical Summary

Technical Problem

In the prior art, multiple firmware refresh efficiency is low, version compatibility issues lack a unified integrity verification mechanism, high operation and maintenance costs, and failure to refresh may lead to inconsistent equipment status.

Method used

By obtaining the target image file, signature file and hash value, parsing metadata after verification and matching firmware and hardware data, writing firmware files in the order of multiple firmware refreshes, and rolling back on failure, ensuring version compatibility and security.

Benefits of technology

Improves the efficiency of multi-firmware refresh, ensures version compatibility and device security, and avoids the risk of device unavailability caused by failure of some firmware updates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120335844A_ABST
    Figure CN120335844A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-firmware refreshing method and device, electronic equipment and a storage medium, and relates to the technical field of computers, a target mirror image file comprises firmware files of multiple target firmware, and the multi-firmware refreshing efficiency is improved; verifying the signature file and the standard hash value of the target mirror image file, if verification succeeds, matching firmware metadata in the target mirror image file with hardware metadata, and if matching succeeds, writing a target version firmware file in the target mirror image file into corresponding target firmware. The security of the target mirror image file and the version compatibility of the target firmware and the hardware configuration are ensured; the multiple target version firmware files are sequentially written into the corresponding target firmware according to the multi-firmware refreshing sequence, and the version dependence problem during multi-firmware refreshing is solved; and if the current target version firmware file fails to be written, rollback of multiple target firmware is supported, and the risk that equipment is unavailable due to the fact that partial firmware fails to be updated is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular, to a multi-firmware refreshing method, device, electronic device, and storage medium. Background Art

[0002] When refreshing multiple firmware, generally, a single-image method is used to refresh a single firmware, and the single image is encrypted and security-checked. This method is time-consuming and error-prone; moreover, since there are version constraint relationships among multiple firmware, the refresh order and compatibility are set manually by users. This method lacks intelligent management and cannot effectively ensure the security of firmware refreshing; in addition, the firmware files corresponding to multiple scattered firmware may be tampered with, and this method lacks a unified integrity check mechanism; furthermore, if the refresh fails, manual rollback is required, resulting in high operation and maintenance costs, and this method may cause the server to enter an inconsistent state due to the failure of some firmware to be refreshed. Summary of the Invention

[0003] This application provides a multi-firmware refreshing method, device, electronic device, and storage medium to at least solve the problems of low efficiency of multi-firmware refreshing, version compatibility issues, lack of a unified integrity check mechanism, and high operation and maintenance costs in related technologies.

[0004] This application provides a multi-firmware refreshing method, and the multi-firmware refreshing method includes: Obtain a target image file, a signature file of the target image file, and a standard hash value, where the target image file at least includes metadata of the target image file and target version firmware files corresponding to multiple target firmware spliced in the multi-firmware refresh order; Verify the signature file and the standard hash value of the target image file; If the verification fails, generate a prompt indicating that the signature verification fails or the hash verification fails; If the verification is successful, parse the metadata of the target image file to obtain firmware metadata and hardware metadata corresponding to multiple target firmware, and match the firmware metadata of multiple target firmware with the corresponding hardware metadata; If the matching fails, generate a prompt indicating that the firmware and hardware versions are incompatible; If the matching is successful, obtain and save the current versions of multiple target firmware in the target server, and write the multiple target version firmware files into the corresponding target firmware in the multi-firmware refresh order; If the writing of the current target version firmware file fails, roll back multiple target firmware according to the current versions of multiple target firmware, and generate a prompt indicating that the writing fails; If the writing of multiple target version firmware files is successful, update the current versions of multiple target firmware to the corresponding target versions.

[0005] The present application also provides a multi-firmware refreshing device, which includes: A first obtaining module, configured to obtain a target image file, a signature file of the target image file, and a standard hash value, where the target image file at least includes metadata of the target image file and target version firmware files corresponding to multiple target firmwares concatenated in the multi-firmware refreshing order; A verification module, configured to verify the signature file and the standard hash value of the target image file; A first prompting module, configured to generate a prompt of signature verification failure or hash verification failure if the verification fails; An analysis module, configured to analyze the metadata of the target image file if the verification is successful, to obtain firmware metadata and hardware metadata corresponding to multiple target firmwares; A matching module, configured to match the firmware metadata of multiple target firmwares with the corresponding hardware metadata; A second prompting module, configured to generate a prompt of incompatible firmware and hardware versions if the matching fails; A second obtaining module, configured to obtain and save the current versions of multiple target firmwares in a target server if the matching is successful; A writing module, configured to sequentially write multiple target version firmware files into corresponding target firmwares in the multi-firmware refreshing order; A rollback module, configured to roll back multiple target firmwares according to the current versions of the multiple target firmwares if the writing of the current target version firmware file fails; A third prompting module, configured to generate a prompt of writing failure; An updating module, configured to update the current versions of multiple target firmwares to corresponding target versions if the writing of multiple target version firmware files is successful.

[0006] The present application also provides an electronic device, including: a memory, configured to store a computer program; a processor, configured to at least implement a multi-firmware refreshing method including the following steps when executing the computer program: Obtain a target image file, a signature file of the target image file, and a standard hash value, where the target image file at least includes metadata of the target image file and target version firmware files corresponding to multiple target firmwares concatenated in the multi-firmware refreshing order; Verify the signature file and the standard hash value of the target image file; If the verification fails, generate a prompt of signature verification failure or hash verification failure; If the verification is successful, parse the metadata of the target image file to obtain the firmware metadata and hardware metadata corresponding to multiple target firmware, and match the firmware metadata of multiple target firmware with the corresponding hardware metadata; If the matching fails, generate a prompt indicating that the firmware and hardware versions are incompatible; If the matching is successful, obtain and save the current versions of multiple target firmware in the target server, and write the multiple target version firmware files into the corresponding target firmware in sequence according to the multi-firmware refresh order; If the writing of the current target version firmware file fails, roll back multiple target firmware according to the current versions of multiple target firmware, and generate a prompt indicating that the writing fails; If the writing of multiple target version firmware files is successful, update the current versions of multiple target firmware to the corresponding target versions.

[0007] This application also provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, it at least implements a multi-firmware refresh method including the following steps: Obtain a target image file, a signature file and a standard hash value of the target image file. The target image file at least includes the metadata of the target image file and the target version firmware files corresponding to multiple target firmware spliced according to the multi-firmware refresh order; Verify the signature file and the standard hash value of the target image file; If the verification fails, generate a prompt indicating that the signature verification fails or the hash verification fails; If the verification is successful, parse the metadata of the target image file to obtain the firmware metadata and hardware metadata corresponding to multiple target firmware, and match the firmware metadata of multiple target firmware with the corresponding hardware metadata; If the matching fails, generate a prompt indicating that the firmware and hardware versions are incompatible; If the matching is successful, obtain and save the current versions of multiple target firmware in the target server, and write the multiple target version firmware files into the corresponding target firmware in sequence according to the multi-firmware refresh order; If the writing of the current target version firmware file fails, roll back multiple target firmware according to the current versions of multiple target firmware, and generate a prompt indicating that the writing fails; If the writing of multiple target version firmware files is successful, update the current versions of multiple target firmware to the corresponding target versions.

[0008] This application also provides a computer program product, including a computer program. When the computer program is executed by a processor, it at least implements a multi-firmware refresh method including the following steps: Obtain the target image file, the signature file of the target image file, and the standard hash value. Among them, the target image file at least includes the metadata of the target image file and the target version firmware files corresponding to multiple target firmware files spliced in the multi-firmware refresh order; Verify the signature file and the standard hash value of the target image file; If the verification fails, generate a prompt indicating that the signature verification fails or the hash verification fails; If the verification is successful, parse the metadata of the target image file to obtain the firmware metadata and hardware metadata corresponding to multiple target firmware files, and match the firmware metadata of multiple target firmware files with the corresponding hardware metadata; If the matching fails, generate a prompt indicating that the firmware and hardware versions are incompatible; If the matching is successful, obtain and save the current versions of multiple target firmware files in the target server, and write the multiple target version firmware files into the corresponding target firmware in the multi-firmware refresh order; If the writing of the current target version firmware file fails, roll back multiple target firmware files according to the current versions of multiple target firmware files, and generate a prompt indicating that the writing fails; If the writing of multiple target version firmware files is successful, update the current versions of multiple target firmware files to the corresponding target versions.

[0009] Through this application, the firmware files of multiple target firmware files are included in the target image file, improving the multi-firmware refresh efficiency; verifying the signature file and the standard hash value of the target image file, if the verification is successful, matching the firmware metadata in the target image file with the hardware metadata, if the matching is successful, writing the target version firmware file in the target image file into the corresponding target firmware, ensuring the security of the target image file and the version compatibility between the target firmware and the hardware configuration; writing the multiple target version firmware files into the corresponding target firmware in the multi-firmware refresh order, solving the version dependency problem during multi-firmware refresh; if the writing of the current target version firmware file fails, supporting the rollback of multiple target firmware files to avoid the risk of device unavailability caused by the failure of partial firmware updates. Brief Description of the Drawings

[0010] To more clearly illustrate the embodiments of the present application, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0011] Figure 1 It is a schematic flow chart of a multi-firmware refresh method in an embodiment; Figure 2Schematic flowchart of the step of generating and uploading a target image file in a multi-firmware refreshing method in an embodiment; Figure 3 Block diagram of the structure of a multi-firmware refreshing device in an embodiment; Figure 4 Internal structure diagram of an electronic device in an embodiment. Detailed implementation manners

[0012] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0013] It should be noted that in the description of the present application, the terms "include", "comprise" or any other variant thereof are intended to cover a non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. The terms "first", "second", etc. in the present application are used to distinguish similar objects, rather than to describe a specific order or sequence.

[0014] In order to enable those skilled in the art in the technical field to better understand the solution of the present application, the present application will be further described in detail below in conjunction with the accompanying drawings and specific implementation manners.

[0015] In one embodiment, as Figure 1 shown, a multi-firmware refreshing method is provided. The multi-firmware refreshing method includes: Obtain a target image file, a signature file of the target image file, and a standard hash value. Among them, the target image file at least includes metadata of the target image file and target version firmware files corresponding to multiple target firmwares spliced according to the multi-firmware refreshing order; Verify the signature file and the standard hash value of the target image file; If the verification fails, generate a prompt indicating that the signature verification fails or the hash verification fails; If the verification is successful, parse the metadata of the target image file to obtain firmware metadata and hardware metadata corresponding to multiple target firmwares, and match the firmware metadata of multiple target firmwares with the corresponding hardware metadata; If the matching fails, generate a prompt indicating that the firmware and hardware versions are incompatible; If the match is successful, obtain and save the current versions of multiple target firmware in the target server, and write the multiple target version firmware files into the corresponding target firmware in the multi-firmware refresh order. If the writing of the current target version firmware file fails, roll back the multiple target firmware according to the current versions of the multiple target firmware, and generate a prompt for the writing failure. If the writing of all multiple target version firmware files is successful, update the current versions of the multiple target firmware to the corresponding target versions.

[0016] In a specific implementation, this embodiment defines an image file format including metadata and a partition of the target version firmware file. A digital signature and a standard hash value can also be added to the image file format. This image file format supports the compatibility encapsulation of multi-vendor firmware. After generating prompts such as signature verification failure, hash verification failure, writing failure, version error, and hardware version incompatibility, the multi-firmware refresh process is stopped. If the hardware and firmware versions match successfully, create a server snapshot, back up the current version of the target firmware to the temporary storage area; write the target firmware one by one in the multi-firmware refresh order, such as refreshing the baseboard management controller first and then updating the basic input / output system, and perform a read-back verification for each completed target firmware. If all target firmware are verified successfully, delete the backup and submit the refreshed versions of the corresponding target firmware.

[0017] Specifically, the target image file includes the firmware files of multiple target firmware, which improves the multi-firmware refresh efficiency; verify the signature file and the standard hash value of the target image file. If the verification is successful, match the firmware metadata in the target image file with the hardware metadata. If the match is successful, write the target version firmware file in the target image file into the corresponding target firmware, ensuring the security of the target image file and the version compatibility between the target firmware and the hardware configuration; write the multiple target version firmware files into the corresponding target firmware in the multi-firmware refresh order, solving the version dependency problem during multi-firmware refresh; if the writing of the current target version firmware file fails, support the rollback of multiple target firmware, avoiding the risk of device unavailability caused by the failure of some firmware updates.

[0018] In one embodiment, verifying the signature file and the standard hash value of the target image file includes: Verify the signature file according to the public key to obtain the signature verification result; If the signature verification result is verification failure, generate a prompt for signature verification failure; If the signature verification result is verification success, calculate the current hash value of the target image file, and compare the current hash value with the standard hash value to obtain the hash verification result; If the hash verification result is verification failure, generate a prompt for hash verification failure; If the hash verification result is successful, it is determined that the target image file verification is successful.

[0019] In one embodiment, the firmware metadata at least includes the target version corresponding to the target firmware, and the hardware metadata at least includes the version range corresponding to the target firmware. Matching the firmware metadata of multiple target firmwares with the corresponding hardware metadata includes: Matching the target versions of multiple target firmwares with the corresponding version ranges; If the target versions of multiple target firmwares are not within the corresponding version ranges, it is determined that the version matching of multiple target firmwares fails; If the target versions of multiple target firmwares are within the corresponding version ranges, it is determined that the matching of multiple target firmware versions is successful.

[0020] In a specific implementation, this embodiment checks the compatibility between the firmware module and the current hardware configuration, including: ① Version matching: Comparing the version number of the firmware module with the version number recommended by the hardware manufacturer. If the firmware version is too old or too new, it may not be compatible with the current hardware configuration; ② Hardware model matching: Checking whether the list of hardware models supported by the firmware module includes the model of the current hardware. If not, the firmware module may not be compatible with the current hardware; ③ Configuration parameter matching: Comparing the configuration parameters of the firmware module with the actual configuration parameters of the hardware. If there are mismatched configuration parameters, it may cause the firmware to fail to run correctly or the performance to decline; ④ Interface and performance matching: Checking whether the firmware module supports the interface specifications and performance parameters of the hardware. For example, if the hardware supports a high-speed serial bus interface, but the firmware module only supports a low-speed serial bus interface, there may be a compatibility problem.

[0021] Specifically, through version matching, hardware model matching, configuration parameter matching, and interface and performance matching, etc., the compatibility between the target firmware and the hardware configuration is ensured.

[0022] In one embodiment, rolling back multiple target firmwares according to the current versions of the multiple target firmwares includes: According to the current versions of the multiple target firmwares, obtaining the current version firmware files corresponding to the multiple target firmwares; Writing the multiple current version firmware files into the corresponding target firmwares in sequence according to the multi-firmware refresh order; If all the multiple current version firmware files are written successfully, it is determined that the rolling back of the multiple target firmwares is successful.

[0023] In a specific implementation, if the writing of the current target version firmware file fails in this embodiment, the successfully written target firmware and the current target firmware are rolled back according to the snapshot in the multi-firmware refresh order, and the refresh is stopped. Finally, a refresh log can be generated to record the status, time consumption, and error codes of each target firmware.

[0024] Specifically, write the target version firmware file to the corresponding target firmware according to the multi-firmware refresh order, and perform a read-back verification after each target firmware is completed. If the writing of the current target firmware fails, roll back the multiple target firmwares to avoid the risk of device unavailability caused by the failure of some firmware updates.

[0025] In one embodiment, as Figure 2 shown, before obtaining the target mirror file, the signature file of the target mirror file, and the standard hash value, the multi-firmware refresh method further includes: Obtain the target versions and version constraint conditions corresponding to multiple target firmwares; According to the target versions corresponding to the multiple target firmwares, obtain the target version firmware files corresponding to the multiple target firmwares; Based on the target versions and version constraint conditions corresponding to the multiple target firmwares, determine whether the target server meets the multi-firmware refresh requirements; If the target server does not meet the multi-firmware refresh requirements, generate a version error prompt; If the target server meets the multi-firmware refresh requirements, generate a target mirror file according to the version constraint conditions and the target version firmware files corresponding to the multiple target firmwares. Among them, the target mirror file at least includes a target mirror header and target mirror content. The target mirror header at least includes metadata of the target mirror file, and the target mirror content at least includes the target version firmware files corresponding to the multiple target firmwares concatenated in the multi-firmware refresh order; Calculate the standard hash value of the target mirror file, and sign the standard hash value with the private key to obtain a signature file; Upload the target mirror file, the signature file of the target mirror file, and the standard hash value to the target server.

[0026] In a specific embodiment, this embodiment obtains the target versions, vendor IDs, and dependency tables corresponding to multiple target firmware; parses the dependency tables to obtain the version constraint conditions for each target firmware, such as "the version of the baseboard management controller needs to be greater than or equal to 2.1 to be compatible with the basic input / output system of version 3.0". If there are conflicts between the target version and the current version of the baseboard management controller and the constraint version in the version constraint conditions, or there are conflicts between the target version and the current version of the basic input / output system and the constraint version in the version constraint conditions, a version error is prompted; according to the target versions corresponding to multiple target firmware, obtains the target version firmware files corresponding to multiple target firmware; generates global metadata, including the version number of the image file, the creation time of the image file, the target server model, the firmware module index table (including start offset, length, check value), etc.; determines the multi-firmware update order according to the version constraint conditions, concatenates each firmware file into a continuous binary stream according to the multi-firmware update order, and records the partition information in the metadata; uses an asymmetric encryption algorithm to sign the metadata and the image content.

[0027] Specifically, integrating multiple firmware files into a single image file enables multi-firmware updates to be completed in a single operation, improving the efficiency of multi-firmware updates; before synthesizing the image file, first judge whether the target server meets the multi-firmware update requirements based on the target versions and version constraint conditions corresponding to multiple target firmware, ensuring the version compatibility of all firmware; calculating the hash value of the entire target image header and target image content and signing it to ensure the security of the target image file.

[0028] In one embodiment, judging whether the target server meets the multi-firmware update requirements based on the target versions and version constraint conditions corresponding to multiple target firmware includes: According to the version constraint conditions corresponding to multiple target firmware, obtains multiple constraint firmware and the constraint versions corresponding to multiple constraint firmware; According to the firmware name, obtains the target version and the current version of multiple constraint firmware; Compares the target version and the current version of multiple constraint firmware with the corresponding constraint versions; If the target version and the current version of multiple constraint firmware are inconsistent with the corresponding constraint versions, it is determined that the target server does not meet the multi-firmware update requirements; If the target version or the current version of multiple constraint firmware is consistent with the corresponding constraint version, it is determined that the target server meets the multi-firmware update requirements.

[0029] Specifically, before synthesizing the image file, comparing the target version and the current version of multiple constraint firmware with the corresponding constraint versions ensures the version compatibility of all firmware.

[0030] In a specific implementation, for example, the target version of the Baseboard Management Controller is 3.0.0, and it depends on the Basic Input / Output System with version 2.0.0 and the Complex Programmable Logic Device with version 2.0.0. The required Baseboard Management Controller version is 2.0.0 and the Complex Programmable Logic Device version is 2.0.0; the target version of the Basic Input / Output System is 3.0.0, and it depends on the Baseboard Management Controller with version 3.0.0. If the current version of the Baseboard Management Controller is 2.0.0, the current version of the Complex Programmable Logic Device is 2.0.0, and the current version of the Basic Input / Output System is 2.0.0, it is determined that the target server meets the multi-firmware refresh requirements; otherwise, it is determined that the target server does not meet the multi-firmware refresh requirements.

[0031] In one embodiment, generating a target image file according to the version constraint conditions corresponding to multiple target firmware and the target version firmware files includes: Obtaining the multi-firmware refresh order according to the version constraint conditions corresponding to multiple target firmware; Concatenating the target version firmware files corresponding to multiple target firmware into target image content according to the multi-firmware refresh order; Generating metadata for the target image file according to the firmware metadata, hardware metadata corresponding to multiple target firmware, and the partition information of the target version firmware files in the target image content, and using the metadata of the target image file as the target image header; Generating a target image file according to the target image content and the target image header.

[0032] In a specific implementation, for example, the target version of the Baseboard Management Controller is 3.0.0, and it depends on the Basic Input / Output System with version 2.0.0 and the Complex Programmable Logic Device with version 2.0.0. The required Baseboard Management Controller version is 2.0.0 and the Complex Programmable Logic Device version is 2.0.0; the target version of the Basic Input / Output System is 3.0.0, and it depends on the Baseboard Management Controller with version 3.0.0. If the current version of the Baseboard Management Controller is 2.0.0, the current version of the Complex Programmable Logic Device is 2.0.0, and the current version of the Basic Input / Output System is 2.0.0, the multi-firmware refresh order is Baseboard Management Controller 2.0.0 → 3.0.0 → → Basic Input / Output System 2.0.0 → 3.0.0.

[0033] In one embodiment, obtaining the target version and current version of multiple constrained firmware according to the firmware name includes: Dividing the firmware in the target server into target firmware and other firmware respectively according to the firmware names corresponding to multiple target firmware; According to the firmware names of multiple constrained firmwares, the multiple constrained firmwares are respectively divided into target constrained firmwares and other constrained firmwares, where the firmware name of the target constrained firmware is the same as the firmware name of the target firmware in the target server, and the name of the other constrained firmware is the same as the firmware name of the other firmware in the target server; If the constrained firmware is a target constrained firmware, obtain the target version and the current version of the constrained firmware; If the constrained firmware is an other constrained firmware, obtain the current version of the constrained firmware; Compare the target version and the current version of the multiple constrained firmwares with the corresponding constrained versions, including: If the constrained firmware is a target constrained firmware, compare the target version and the current version of the constrained firmware with the corresponding constrained versions respectively; If the constrained firmware is an other constrained firmware, compare the current version of the constrained firmware with the corresponding constrained version.

[0034] In a specific implementation, for example, the target version of the baseboard management controller is 3.0.0, and it depends on the basic input / output system with version 2.0.0 and the complex programmable logic device with version 2.0.0; the target version of the basic input / output system is 3.0.0, and it depends on the baseboard management controller with version 3.0.0. Then, determine that the baseboard management controller and the basic input / output system are target constrained firmwares, and the complex programmable logic device is an other constrained firmware. That is, the target constrained firmware is the constrained firmware that needs to be upgraded, and the other constrained firmware is the constrained firmware that does not need to be upgraded and has a version dependency relationship with the target constrained firmware.

[0035] Specifically, according to the version constraint conditions, it is necessary to consider not only the version constraint relationship between multiple target firmwares, but also the version constraint relationship between the target firmware and other firmwares, so as to ensure the version compatibility during the multi-firmware refresh process.

[0036] In a specific implementation, this embodiment takes the update of the basic input / output system, the baseboard management controller, and the complex programmable logic device of a general server as an example: 1.1 Import the basic input / output system_target version firmware file, the baseboard management controller_target version firmware file, and the complex programmable logic device_target version firmware file through an image generator; 1.2 Parse the firmware header of the target version firmware file to obtain the metadata containing the version constraint conditions; 1.3 Package the modules in the order of the baseboard management controller → the basic input / output system → the complex programmable logic device, calculate the standard hash value of the metadata and the overall packaged module through a secure hash algorithm, and sign the standard hash value through an asymmetric encryption algorithm; 1.4 Output a target image file including the target version firmware files corresponding to the baseboard management controller, the basic input / output system, and the complex programmable logic device in accordance with the image file format of metadata, firmware module partitioning, digital signature, and standard hash value.

[0037] 2.1 The administrator uploads the target image file to the target server and executes the refresh command. 2.2 After the refresh agent verifies the signature and hash value, it determines whether the target server meets the refresh requirements. 2.3 If it meets the requirements, sequentially refresh the baseboard management controller, the basic input / output system, and the complex programmable logic device, and ensure data consistency through read-back verification after each write. 2.4 After all are successful, the server automatically restarts and loads the new version of the target firmware. 2.5 If any node fails during the refresh process, automatically roll back the successfully refreshed target firmware and the currently failed target firmware to the original version according to the multi-firmware refresh order.

[0038] Among them, the image generator runs on the management terminal and is used to provide a graphical user interface and a command-line interface, supporting firmware file import, metadata editing, and image generation; the refresh agent is deployed on the target server and is used for image parsing, security verification, and firmware writing operations; the central controller (optional) is used for data center-level management, supporting batch image distribution and status monitoring.

[0039] It should be understood that although Figure 1 、 Figure 2 the steps in the flowchart are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise clearly stated in this article, there is no strict order limit for the execution of these steps, and these steps can be executed in other orders. Moreover, Figure 1 、 Figure 2 at least a part of the steps in

[0040] In one embodiment, as Figure 3 shown, a multi-firmware refresh device is provided, and the multi-firmware refresh device includes: The first acquisition module is used to acquire the target image file, the signature file, and the standard hash value of the target image file, where the target image file at least includes the metadata of the target image file and the target version firmware files corresponding to multiple target firmwares spliced according to the multi-firmware refresh order. A verification module for verifying the signature file and the standard hash value of the target image file; A first prompting module for generating a prompt of signature verification failure or hash verification failure if the verification fails; A parsing module for parsing the metadata of the target image file to obtain firmware metadata and hardware metadata corresponding to multiple target firmware if the verification is successful; A matching module for matching the firmware metadata of multiple target firmware with the corresponding hardware metadata; A second prompting module for generating a prompt of incompatible firmware and hardware versions if the matching fails; A second obtaining module for obtaining and saving the current versions of multiple target firmware in the target server if the matching is successful; A writing module for sequentially writing multiple target version firmware files into the corresponding target firmware according to the multi-firmware refresh order; A rollback module for rolling back multiple target firmware according to the current versions of multiple target firmware if the writing of the current target version firmware file fails; A third prompting module for generating a prompt of writing failure; An update module for updating the current versions of multiple target firmware to the corresponding target versions if the writing of multiple target version firmware files is successful.

[0041] In one embodiment, the verification module is specifically configured to: Verify the signature file according to the public key to obtain a signature verification result; If the signature verification result is verification failure, generate a prompt of signature verification failure; If the signature verification result is verification success, calculate the current hash value of the target image file and compare the current hash value with the standard hash value to obtain a hash verification result; If the hash verification result is verification failure, generate a prompt of hash verification failure; If the hash verification result is verification success, determine that the target image file verification is successful.

[0042] In one embodiment, the firmware metadata at least includes the target version of the corresponding target firmware, and the hardware metadata at least includes the version range of the corresponding target firmware. The matching module is specifically configured to: Match the target versions of multiple target firmware with the corresponding version ranges; If the target versions of multiple target firmware are not within the corresponding version ranges, determine that the version matching of multiple target firmware fails; If the target versions of multiple target firmware are within the corresponding version ranges, determine that the version matching of multiple target firmware is successful.

[0043] In one embodiment, the rollback module is specifically configured to: Obtain the current version firmware files corresponding to multiple target firmware based on the current versions of the multiple target firmware; Write the multiple current version firmware files into the corresponding target firmware in the multi-firmware refresh order; If all the multiple current version firmware files are successfully written, determine that the rollback of the multiple target firmware is successful.

[0044] In one embodiment, the multi-firmware refresh device further includes: A third acquisition module, configured to acquire the target versions and version constraint conditions corresponding to multiple target firmware; A fourth acquisition module, configured to acquire the target version firmware files corresponding to multiple target firmware according to the target versions of the multiple target firmware; A judgment module, configured to judge whether the target server meets the multi-firmware refresh requirements based on the target versions and version constraint conditions corresponding to the multiple target firmware; A fourth prompt module, configured to generate a version error prompt if the target server does not meet the multi-firmware refresh requirements; A generation module, configured to generate a target image file according to the version constraint conditions and target version firmware files corresponding to the multiple target firmware if the target server meets the multi-firmware refresh requirements, where the target image file at least includes a target image header and target image content, the target image header at least includes metadata of the target image file, and the target image content at least includes the target version firmware files corresponding to the multiple target firmware spliced in the multi-firmware refresh order; A calculation module, configured to calculate the standard hash value of the target image file; A signature module, configured to sign the standard hash value according to the private key to obtain a signature file; A transmission module, configured to upload the target image file, the signature file of the target image file, and the standard hash value to the target server.

[0045] In one embodiment, the judgment module is specifically configured to: Obtain multiple constraint firmware and the constraint versions corresponding to the multiple constraint firmware according to the version constraint conditions corresponding to the multiple target firmware; Obtain the target version and current version of the multiple constraint firmware according to the firmware name; Compare the target version and current version of the multiple constraint firmware with the corresponding constraint versions; If the target version and current version of the multiple constraint firmware are inconsistent with the corresponding constraint versions, determine that the target server does not meet the multi-firmware refresh requirements; If the target version or current version of multiple constraint firmware is consistent with the corresponding constraint version, it is determined that the target server meets the multi-firmware refresh requirement.

[0046] In one embodiment, the generation module is specifically configured to: Obtain the multi-firmware refresh order according to the version constraint conditions corresponding to multiple target firmware; Concatenate the target version firmware files corresponding to multiple target firmware into target image content according to the multi-firmware refresh order; Generate metadata for the target image file according to the firmware metadata, hardware metadata corresponding to multiple target firmware, and the partition information of the target version firmware files in the target image content, and use the metadata of the target image file as the target image header; Generate a target image file according to the target image content and the target image header.

[0047] For the specific limitations of the multi-firmware refresh device, reference can be made to the limitations on the multi-firmware refresh method in the above text, which will not be elaborated here. Each module in the above multi-firmware refresh device can be implemented in whole or in part by software, hardware, and their combinations. The above modules can be embedded in the processor in the electronic device in hardware form or independent of it, or stored in the memory in the electronic device in software form, so as to facilitate the processor to call and execute the operations corresponding to the above modules.

[0048] In one embodiment, an electronic device is provided, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the following steps are implemented: Obtain the target image file, the signature file and the standard hash value of the target image file, where the target image file at least includes the metadata of the target image file and the target version firmware files corresponding to multiple target firmware concatenated according to the multi-firmware refresh order; Verify the signature file and the standard hash value of the target image file; If the verification fails, a prompt for signature verification failure or hash verification failure is generated; If the verification is successful, parse the metadata of the target image file to obtain the firmware metadata and hardware metadata corresponding to multiple target firmware, and match the firmware metadata of multiple target firmware with the corresponding hardware metadata; If the matching fails, a prompt for incompatible firmware and hardware versions is generated; If the matching is successful, obtain and save the current versions of multiple target firmware in the target server, and write the multiple target version firmware files into the corresponding target firmware in sequence according to the multi-firmware refresh order; If the writing of the current target version firmware file fails, roll back multiple target firmwares according to their current versions, and generate a prompt indicating the writing failure. If the writing of multiple target version firmware files is successful, update the current versions of the multiple target firmwares to the corresponding target versions.

[0049] When the program instructions are read and executed by one or more processors, operations corresponding to the steps in the foregoing method embodiments can also be performed. Reference can be made to the descriptions above, and details are not repeated here. Figure 4 , which exemplarily shows the architecture of the electronic device. Specifically, it may include a processor 410, a video display adapter 411, a disk drive 412, an input / output interface 413, a network interface 414, and a memory 420. The above-mentioned processor 410, video display adapter 411, disk drive 412, input / output interface 413, network interface 414, and the memory 420 can be communicatively connected through a communication bus 430.

[0050] Among them, the processor 410 can be implemented in ways such as a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in this application.

[0051] The memory 420 can be implemented in forms such as a read-only memory (ROM), a random access memory (RAM), a static storage device, a dynamic storage device, etc. The memory 420 can store an operating system 421 for controlling the operation of the electronic device 400, and a basic input / output system (BIOS) 422 for controlling the low-level operations of the electronic device 400. In addition, a web browser 423, a data storage management 424, an icon font processing system 425, etc. can also be stored. The above-mentioned icon font processing system 425 can be the application program that specifically implements the operations of the foregoing steps in the embodiments of this application. In short, when implementing the technical solutions provided in this application through software or firmware, the relevant program codes are stored in the memory 420 and called and executed by the processor 410.

[0052] The input / output interface 413 is used to connect to the input / output module to achieve information input and output. The input / output module can be configured as a component in the device (not shown in the figure), or can be externally connected to the device to provide corresponding functions. Among them, the input device can include a keyboard, a mouse, a touch screen, a microphone, various sensors, etc., and the output device can include a display, a speaker, a vibrator, an indicator light, etc.

[0053] The network interface 414 is used to connect to a communication module (not shown in the figure) to achieve communication interaction between this device and other devices. Among them, the communication module can achieve communication through a wired method (such as USB, network cable, etc.), or can achieve communication through a wireless method (such as a mobile network, WIFI, Bluetooth, etc.).

[0054] The bus 430 includes a path to transmit information between various components of the device (such as the processor 410, the video display adapter 411, the disk drive 412, the input / output interface 413, the network interface 414, and the memory 420).

[0055] In addition, the electronic device 400 can also obtain information on specific collection conditions from a virtual resource object collection condition information database (not shown in the figure) for conditional judgment.

[0056] It should be noted that although the above-mentioned electronic device 400 only shows the processor 410, the video display adapter 411, the disk drive 412, the input / output interface 413, the network interface 414, the memory 420, the bus 430, etc., in the specific implementation process, the electronic device may also include other components necessary for normal operation. In addition, those skilled in the art can understand that the above device may also only include the components necessary to implement the solution of the present application, and does not necessarily include all the components shown in the figure.

[0057] From the description of the above embodiments, those skilled in the art can clearly understand that the present application can be implemented by means of software plus a necessary general hardware platform. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product can be stored in a storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to enable an electronic device (which can be a personal computer, a cloud server, or a network device, etc.) to execute the methods of various embodiments or some parts of the embodiments of the present application.

[0058] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented: Obtain the target image file, the signature file of the target image file, and the standard hash value. Among them, the target image file at least includes the metadata of the target image file and the target version firmware files corresponding to multiple target firmware spliced in the multi-firmware update order; Verify the signature file and the standard hash value of the target image file; If the verification fails, generate a prompt indicating that the signature verification fails or the hash verification fails; If the verification is successful, parse the metadata of the target image file to obtain the firmware metadata and hardware metadata corresponding to multiple target firmware, and match the firmware metadata of multiple target firmware with the corresponding hardware metadata; If the matching fails, generate a prompt indicating that the firmware and hardware versions are incompatible; If the matching is successful, obtain and save the current versions of multiple target firmware in the target server, and write the multiple target version firmware files into the corresponding target firmware in the multi-firmware update order; If the writing of the current target version firmware file fails, roll back multiple target firmware according to the current versions of multiple target firmware, and generate a prompt indicating that the writing fails; If the writing of multiple target version firmware files is successful, update the current versions of multiple target firmware to the corresponding target versions.

[0059] Those of ordinary skill in the art can understand that all or part of the processes of implementing the methods in the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to memory, storage, database or other media used in the various embodiments provided in the present application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.

[0060] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

[0061] The above embodiments only represent several implementation manners of the present application, and their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several deformations and improvements can still be made, and these all belong to the protection scope of the present application.

[0062] In one embodiment, a computer program product is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented: Obtain a target image file, a signature file and a standard hash value of the target image file. Among them, the target image file at least includes metadata of the target image file and target version firmware files corresponding to multiple target firmware spliced in the multi-firmware update order; Verify the signature file and the standard hash value of the target image file; If the verification fails, generate a prompt indicating that the signature verification fails or the hash verification fails; If the verification is successful, parse the metadata of the target image file to obtain firmware metadata and hardware metadata corresponding to multiple target firmware, and match the firmware metadata of multiple target firmware with the corresponding hardware metadata; If the matching fails, generate a prompt indicating that the firmware and hardware versions are incompatible; If the matching is successful, obtain and save the current versions of multiple target firmware in the target server, and write the multiple target version firmware files into the corresponding target firmware in the multi-firmware update order; If the writing of the current target version firmware file fails, roll back the multiple target firmware according to the current versions of the multiple target firmware, and generate a prompt indicating that the writing fails; If the writing of multiple target version firmware files is successful, update the current versions of multiple target firmware to the corresponding target versions.

[0063] In one embodiment, a computer program product is provided, including a non-volatile computer-readable storage medium. The non-volatile computer-readable storage medium stores a computer program. When the computer program is executed by a processor, the following steps are implemented: Obtain a target image file, a signature file and a standard hash value of the target image file. Among them, the target image file at least includes metadata of the target image file and target version firmware files corresponding to multiple target firmware spliced in the multi-firmware update order; Verify the signature file and standard hash value of the target image file; If the verification fails, generate a prompt indicating that the signature verification fails or the hash verification fails; If the verification is successful, parse the metadata of the target image file to obtain the firmware metadata and hardware metadata corresponding to multiple target firmware, and match the firmware metadata of multiple target firmware with the corresponding hardware metadata; If the matching fails, generate a prompt indicating that the firmware and hardware versions are incompatible; If the matching is successful, obtain and save the current versions of multiple target firmware in the target server, and write the multiple target version firmware files into the corresponding target firmware in sequence according to the multi-firmware refresh order; If the writing of the current target version firmware file fails, roll back multiple target firmware according to the current versions of multiple target firmware, and generate a prompt indicating that the writing fails; If the writing of multiple target version firmware files is successful, update the current versions of multiple target firmware to the corresponding target versions.

[0064] Those of ordinary skill in the art can understand that all or part of the processes of implementing the methods in the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a computer program product. When the computer program is executed, it can include the processes of the embodiments of the above methods.

[0065] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as these combinations of technical features do not conflict, they should be considered as the scope recorded in this specification.

[0066] The above embodiments only express several implementation manners of the present application, and their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several deformations and improvements can still be made, and these all belong to the protection scope of the present application.

Claims

1. A multi-firmware refreshing method, characterized in that, The method includes: Obtain a target image file, a signature file of the target image file, and a standard hash value, where the target image file at least includes metadata of the target image file and target version firmware files corresponding to multiple target firmwares spliced in the multi-firmware update order; Verify the signature file and the standard hash value of the target image file; If the verification fails, generate a prompt indicating that the signature verification fails or the hash verification fails; If the verification is successful, parse the metadata of the target image file to obtain firmware metadata and hardware metadata corresponding to the multiple target firmwares, and match the firmware metadata of the multiple target firmwares with the corresponding hardware metadata; If the matching fails, generate a prompt indicating that the firmware and hardware versions are incompatible; If the matching is successful, obtain and save the current versions of the multiple target firmwares in the target server, and write the multiple target version firmware files to the corresponding target firmwares in sequence according to the multi-firmware update order; If the writing of the current target version firmware file fails, roll back the multiple target firmwares according to the current versions of the multiple target firmwares, and generate a prompt indicating that the writing fails; If all the multiple target version firmware files are written successfully, update the current versions of the multiple target firmwares to the corresponding target versions.

2. The method according to claim 1, wherein The verification of the signature file and the standard hash value of the target image file includes: Verify the signature file according to the public key to obtain a signature verification result; If the signature verification result is verification failure, generate a prompt indicating that the signature verification fails; If the signature verification result is verification success, calculate the current hash value of the target image file, and compare the current hash value with the standard hash value to obtain a hash verification result; If the hash verification result is verification failure, generate a prompt indicating that the hash verification fails; If the hash verification result is verification success, determine that the target image file verification is successful.

3. The method according to claim 1, wherein The firmware metadata at least includes the target version corresponding to the target firmware, and the hardware metadata at least includes the version range corresponding to the target firmware. The matching of the firmware metadata of the multiple target firmwares with the corresponding hardware metadata includes: Match the target versions of the multiple target firmwares with the corresponding version ranges; If the target versions of the multiple target firmwares are not within the corresponding version ranges, determine that the version matching of the multiple target firmwares fails; If the target versions of the multiple target firmwares are within the corresponding version ranges, determine that the version matching of the multiple target firmwares is successful.

4. The method according to claim 1, wherein The rolling back of the multiple target firmwares according to the current versions of the multiple target firmwares includes: According to the current versions of the multiple target firmwares, obtain the current version firmware files corresponding to the multiple target firmwares; Write the multiple current version firmware files to the corresponding target firmwares in sequence according to the multi-firmware update order; If all the multiple current version firmware files are written successfully, determine that the rolling back of the multiple target firmwares is successful.

5. The method according to claim 1, wherein Before obtaining the target image file, the signature file of the target image file, and the standard hash value, the method further includes: Obtain the target versions and version constraint conditions corresponding to the multiple target firmware; Obtain the target version firmware files corresponding to the multiple target firmware according to the target versions corresponding to the multiple target firmware; Based on the target versions and version constraint conditions corresponding to the multiple target firmware, determine whether the target server meets the multi-firmware update requirements; If the target server does not meet the multi-firmware update requirements, generate a version error prompt; If the target server meets the multi-firmware update requirements, generate the target image file according to the version constraint conditions and target version firmware files corresponding to the multiple target firmware, where the target image file at least includes a target image header and target image content, and at least includes metadata of the target image file in the target image header, and the target image content at least includes the target version firmware files corresponding to the multiple target firmware spliced according to the multi-firmware update order; Calculate the standard hash value of the target image file, and sign the standard hash value with the private key to obtain a signature file; Upload the target image file, the signature file of the target image file, and the standard hash value to the target server.

6. The method according to claim 5, wherein The determining whether the target server meets the multi-firmware update requirements based on the target versions and version constraint conditions corresponding to the multiple target firmware includes: Obtain multiple constraint firmware and the constraint versions corresponding to the multiple constraint firmware according to the version constraint conditions corresponding to the multiple target firmware; Obtain the target version and current version of the multiple constraint firmware according to the firmware name; Compare the target version and current version of the multiple constraint firmware with the corresponding constraint versions; If the target version and current version of the multiple constraint firmware are inconsistent with the corresponding constraint versions, determine that the target server does not meet the multi-firmware update requirements; If the target version or current version of the multiple constraint firmware is consistent with the corresponding constraint version, determine that the target server meets the multi-firmware update requirements.

7. The method according to claim 5, wherein The generating the target image file according to the version constraint conditions and target version firmware files corresponding to the multiple target firmware includes: Obtain the multi-firmware update order according to the version constraint conditions corresponding to the multiple target firmware; Splice the target version firmware files corresponding to the multiple target firmware into the target image content according to the multi-firmware update order; Generate metadata of the target image file according to the firmware metadata, hardware metadata corresponding to the multiple target firmware, and partition information of the target version firmware files in the target image content, and use the metadata of the target image file as the target image header; Generate the target image file according to the target image content and the target image header.

8. A multi-firmware refreshing device, characterized in that, The device includes: A first acquisition module, configured to acquire a target image file, a signature file of the target image file, and a standard hash value, where the target image file at least includes metadata of the target image file and target version firmware files corresponding to multiple target firmware spliced according to the multi-firmware update order; A verification module for verifying the signature file and standard hash value of the target image file; A first prompting module for generating a prompt of signature verification failure or hash verification failure if the verification fails; A parsing module for parsing the metadata of the target image file to obtain the firmware metadata and hardware metadata corresponding to the multiple target firmware if the verification is successful; A matching module for matching the firmware metadata of the multiple target firmware with the corresponding hardware metadata; A second prompting module for generating a prompt of incompatible firmware and hardware versions if the matching fails; A second obtaining module for obtaining and saving the current versions of the multiple target firmware in the target server if the matching is successful; A writing module for sequentially writing multiple target version firmware files into the corresponding target firmware according to the multi-firmware refresh order; A rollback module for rolling back the multiple target firmware according to the current versions of the multiple target firmware if the writing of the current target version firmware file fails; A third prompting module for generating a prompt of writing failure; An updating module for updating the current versions of the multiple target firmware to the corresponding target versions if the writing of the multiple target version firmware files is successful.

9. An electronic device, characterized in that, Comprising: A memory for storing a computer program; A processor for implementing the steps of the multi-firmware refreshing method according to any one of claims 1 to 7 when executing the computer program.

10. A computer-readable storage medium, characterized in that, A computer program is stored in the computer-readable storage medium, wherein the computer program implements the steps of the multi-firmware refreshing method according to any one of claims 1 to 7 when executed by a processor.

Citation Information

Patent Citations

  • Firmware updating method and device and computer readable storage medium

    CN109992288A

  • Multi-firmware upgrading method and device

    CN110119280A

  • Firmware upgrading method, system and device and readable storage medium

    CN116610336A

  • Server firmware upgrading method and device, equipment and storage medium

    CN116610343A

  • Method for upgrading electronic control units of whole vehicle in mutual dependence mode

    CN117130634A

Cited By

  • Firmware management method and device, equipment, storage medium and program product

    CN120780296A

  • GW5 camera firmware burning device and method

    CN120994210A

  • BIOS (Basic Input / Output System) refreshing method and device

    CN121764485A