Method and system for automatically updating intelligent gateway and synchronizing server
By conducting system self-test and network connection verification of the intelligent gateway, establishing secure communication connections, multi-objective optimization version comparison and intelligent update decisions, the problems of unreliable updates and high security risks in the existing technology are solved, and efficient and secure updates are achieved in the optimal system state.
Patent Information
- Application Number
- CN202510888234.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-30
- Publication Date
- 2025-08-08
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing intelligent gateway update technology lacks a comprehensive assessment of the device resource status, network environment and system security, resulting in unreliable update process, high security risks, and great interference to the operation of equipment business, making it difficult to cope with complex network environments and personalized update needs.
By performing system self-test and network connection verification of the intelligent gateway, obtaining network status information, establishing secure communication connections, performing multi-objective optimization version comparison and intelligent update decision-making, a multi-level early exit decision-making mechanism is adopted, a dual-partition image and an automatic fallback mechanism are introduced, and combined with the edge-cloud collaborative decision-making model is combined to achieve dynamic resource scheduling and security verification.
Improve the adaptability and accuracy of update decisions, ensure that updates are carried out in the optimal system state, reduce the impact of updates on equipment business interruption, and improve the security and reliability of the update process.
Smart Images

Figure CN120455278A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of intelligent gateways, and in particular to a method and system for automatic updating and server synchronization of an intelligent gateway. Background Art
[0002] With the rapid development of the Internet of Things (IoT) and smart gateway technologies, device firmware updates have become critical for maintaining system security and functionality. Traditional firmware update methods often suffer from unreliable update processes, high security risks, and significant disruption to device operations. Especially in critical infrastructure and industrial control systems, firmware update failures can lead to significant production disruptions and financial losses.
[0003] Existing smart gateway update technologies generally lack comprehensive assessment mechanisms for device resource status, network environment, and system security. Update decisions often rely on simple version comparisons, failing to implement intelligent and adaptive update strategies. This single, extensive update model struggles to cope with increasingly complex network environments and the personalized update needs of different types of smart gateway devices. Summary of the Invention
[0004] The main purpose of the present invention is to provide a method and system for automatic update and server synchronization of an intelligent gateway. The present invention improves the adaptability and accuracy of update decisions, realizes dynamic resource scheduling during the update process, and ensures that the update is carried out in the optimal system state.
[0005] To achieve the above object, the present invention provides a method for automatically updating an intelligent gateway and synchronizing with a server, comprising the following steps: Perform system self-check and network connection verification on the intelligent gateway to obtain network status information; Obtaining version information of the intelligent gateway according to the network status information and performing local storage management to obtain an update request data packet; Establishing a secure communication connection with the OTA server based on the update request data packet to obtain a session credential; Using the session credentials to perform version comparison for multi-objective optimization and perform intelligent update decision making to obtain an update execution plan; Download the update file from the OTA server according to the update execution plan and perform integrity verification to obtain a verified firmware image file; The verified firmware image file is deployed to the standby partition and updated and installed, completing status synchronization feedback.
[0006] The present invention also provides an automatic update and server synchronization system for an intelligent gateway, comprising: System self-check module, used to perform system self-check and network connection verification on the intelligent gateway to obtain network status information; A local storage management module is used to obtain the version information of the intelligent gateway according to the network status information and perform local storage management to obtain an update request data packet; A communication connection module, configured to establish a secure communication connection with the OTA server based on the update request data packet and obtain a session credential; a decision-making module, configured to use the session credentials to perform version comparison of multi-objective optimization and perform intelligent update decision-making to obtain an update execution plan; An integrity verification module is used to download the update file from the OTA server according to the update execution plan and perform integrity verification to obtain a verified firmware image file; The update installation module is used to deploy the verified firmware image file to the standby partition and perform update installation to complete status synchronization feedback.
[0007] In summary, the technical solution provided by the present invention realizes the intelligence and precision of the update process through the multi-level early exit decision mechanism of deep neural network, and can dynamically adjust the update strategy according to the device resource status, network environment and security level, significantly improving the adaptability and accuracy of the update decision. Multiple security verification technologies are adopted, including TLS1.3 secure communication, HMAC-SHA256 message authentication, multi-level digital signature verification, etc., to ensure the security of the update process from multiple dimensions of communication, file integrity and source authenticity, and effectively prevent potential network attacks and firmware tampering risks. Dual partition imaging and automatic fallback mechanism are introduced to ensure the atomicity and recoverability of the update process. Even if the new firmware fails to start, the system can quickly fall back to the original version, minimizing the interruption of the update on the device business. An edge-cloud collaborative update decision model is proposed. When the local decision confidence is insufficient, the decision can be offloaded to the cloud, realizing more complex computing models and decision analysis, and balancing computing overhead and decision accuracy. Fine-grained monitoring and analysis of resources such as processor load, memory usage, and storage space enable dynamic resource scheduling during the update process, ensuring that updates are performed in the optimal system state and reducing the negative impact of updates on system performance. BRIEF DESCRIPTION OF THE DRAWINGS
[0008] Figure 1 This is a schematic diagram of the steps of a method for automatic update of an intelligent gateway and synchronization with a server in one embodiment of the present invention; Figure 2 This is a structural block diagram of the automatic update and server synchronization system of the intelligent gateway in one embodiment of the present invention.
[0009] The purpose, features and advantages of the present invention will be further described with reference to the accompanying drawings and in conjunction with the embodiments. DETAILED DESCRIPTION
[0010] In order to make the purpose, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.
[0011] Reference Figure 1 This embodiment provides a method for automatically updating an intelligent gateway and synchronizing with a server, comprising the following steps: S1, perform system self-check and network connection verification on the smart gateway to obtain network status information; Hardware testing is performed on the smart gateway's processor, memory, communication module, and power system. During testing, the processor's operating frequency, temperature, instruction execution status, and cache consistency are analyzed to ensure stable operation of the computing core. The memory's health is assessed through read and write tests, bad block detection, and data integrity verification to ensure its availability and reliability. Testing of the communication module includes physical interface integrity checks, signal strength testing, and module initialization success rate analysis to ensure normal operation of the communication components. Testing of the power system involves monitoring input voltage, output current, temperature changes, and the status of the battery management system to ensure that the device maintains a stable power supply under normal or abnormal conditions. Through the hardware testing steps, information about the health status of each hardware component of the smart gateway is obtained. Based on this hardware status information, the software module's integrity and consistency are verified to ensure that its software environment has not been tampered with or modified abnormally. By verifying the hash values of key software system components, such as the kernel, drivers, system libraries, and applications, and comparing them against stored reference values, the system detects tampering or corruption. Software version numbers and system dependencies are checked to ensure compatibility and consistency between software components. Log files are examined for abnormal behavior, such as crashes, unauthorized access attempts, and unexpected system restarts, to further determine whether the software system is operating properly. This software integrity and consistency verification step provides information about the software system's operational status. Based on the current software status, the intelligent gateway establishes a network connection through its configured network interface to obtain initial connection parameters. The gateway first queries the system configuration file or default settings to determine the currently available network interfaces, including wired, Wi-Fi, and cellular networks. The intelligent gateway selects the most suitable interface based on priority and performs necessary initialization steps, such as setting the IP address, subnet mask, gateway address, and DNS server address. If the selected network interface is Wi-Fi, SSID scanning, signal strength assessment, encryption mode matching, and authentication are performed to ensure successful wireless network access. If the selected network interface is a cellular network, SIM card detection, APN parameter configuration, and mobile signal quality assessment are performed. Through the above method, the smart gateway obtains the initial connection parameters. After successfully establishing a network connection and obtaining the initial connection parameters, the smart gateway analyzes the stability and performance of the network connection. Based on the obtained IP address and gateway address, the device sends ICMP packets to verify network connectivity. The smart gateway sends an ICMP echo request (PING) to a predefined test target address (such as a DNS server or cloud server) and calculates the round-trip delay (or network latency) based on the returned ICMP echo reply. The smart gateway also counts the total number of packets sent and the number of successfully received response packets within a certain time window to calculate the packet loss rate.If the smart gateway's test results for multiple destinations differ significantly, the connectivity of different paths is further analyzed to identify network bottlenecks or instability factors. The current network quality is assessed based on network latency and packet loss rate, and a network status indicator is generated. This assessment uses certain thresholds and historical data comparisons. For example, if network latency is below a certain value and packet loss rate is close to zero, the network quality is considered "Excellent"; if latency is higher but still within an acceptable range and packet loss rate is low, the network quality is considered "Good"; if network latency increases significantly or packet loss rate exceeds a certain percentage, the network status is considered "Unstable"; and if packets are completely undeliverable, the network status is marked as "Unavailable." This assessment method based on network latency and packet loss rate effectively reflects the current network environment of the smart gateway. After completing the network quality assessment, the smart gateway stores the calculated network status indicator in the system configuration file for subsequent update processes and operation and maintenance management. The network status indicator record includes information such as timestamp, network interface type, assessment score, and historical fluctuation trends.
[0012] S2, obtains the version information of the smart gateway according to the network status information and performs local storage management to obtain an update request data packet; Specifically, the currently running version configuration file is read from local storage. This version configuration file is stored in the device's firmware partition or a dedicated storage directory and contains version information for the current operating system, kernel, drivers, applications, and related dependent components. When reading this configuration file, the smart gateway ensures file integrity, verifying that the version file has not been tampered with or damaged through hash verification or digital signature verification. The smart gateway then parses the version configuration file, extracting all relevant version data, including the main firmware version, patch versions, application versions, and configuration parameter versions, and loads this data into memory to obtain the complete version data for the current system. Based on the current system version data, the smart gateway reads historical update records to track device update history. Historical update records, stored in the device's local database or log files, contain information about past update times, update versions, update methods (e.g., OTA or manual upgrades), and update success or failure status. When analyzing these historical update records, the smart gateway checks the version number of the most recently successfully updated version to ensure that the current system version data is consistent with the historical data, avoiding version confusion caused by abnormal rollbacks or incomplete upgrades. It also detects historical update failure records and analyzes their error codes or failure reasons to determine whether additional remedial measures are necessary, such as retrying previously failed update steps or skipping specific version upgrades. After reading historical update data, the smart gateway assesses available storage space to ensure that updates do not fail due to insufficient storage. Based on the current system version data and historical update data, the system calculates the device's remaining available storage space and determines whether it is sufficient to accommodate the new update files. If storage space is insufficient, the smart gateway implements storage optimization strategies, such as cleaning up temporary files, deleting unnecessary log files, and compressing historical update packages, to free up the target storage space. During this cleanup, the system prioritizes deleting recently unused cached data while retaining critical log and configuration files to ensure that the device maintains basic debugging capabilities and historical records. After completing the storage optimization operation, the smart gateway generates a storage status report containing information on current storage partition usage, the amount of freed storage space, and the remaining available space. After completing the storage status assessment, the smart gateway creates a dedicated storage directory for the upcoming update and backs up the system partition. Based on the storage status report, the system creates a directory in local storage specifically for storing the update files and allocates appropriate storage space. To mitigate the risk of update failure, the intelligent gateway creates a backup of the current system partition by copying the existing system image to a backup partition. For devices with redundant partitions, the backup process writes the current system directly to the backup partition. For devices with only a single partition, a compressed system image is created and stored in a separate backup directory.After the backup is complete, the corresponding system backup information is generated, which records important information such as the backup storage location, system image verification code, and backup time, so that it can roll back to the previous version in the event of an update failure. The current system version data, network status information, and device identification information are combined and packaged to obtain an update request data packet. Among them, the system version data is used to describe the current device's operating environment to the server so that the server can match the appropriate update version; the network status information provides the current network quality, latency, and bandwidth, allowing the server to optimize the update strategy based on the network conditions, such as selecting a more appropriate download method or adjusting the update file size; the device identification information includes the device's unique serial number, hardware model, and software platform version, ensuring that the server correctly identifies the device and provides compatible firmware.
[0013] S3, establishes a secure communication connection with the OTA server based on the update request data packet and obtains the session credential; It should be noted that a secure connection request is initiated based on the preset server address. When initiating the update process, the smart gateway reads the preset OTA server address, stored as a domain name, from a locally stored configuration file or security module. The gateway obtains the server's IP address through the Domain Name System (DNS) service. After successfully obtaining the server address, the smart gateway uses Transport Layer Security (TLS 1.3) to establish an encrypted channel with the server, establishing an initial encrypted connection. The TLS 1.3 protocol uses a handshake mechanism, which negotiates a client random number, a server random number, and a shared key to ensure confidentiality, integrity, and replay-resistant security for data transmitted over the communication channel. After successfully establishing the initial encrypted connection, the smart gateway verifies the digital certificate provided by the server to ensure that the connected server is legitimate and trustworthy. The digital certificate is issued by a trusted certificate authority and contains the server's public key, server domain name, validity period, signature algorithm, and certificate chain information. The smart gateway checks the certificate's validity period by comparing the start and expiration dates in the certificate to verify that the current time is within the validity period, thus mitigating security risks caused by certificate expiration. The gateway also verifies the trustworthiness of the certificate's issuer by checking a locally stored list of root certificates to ensure that each intermediate certificate in the certificate chain is signed by a trusted CA, ensuring the integrity of the certificate chain. The smart gateway uses the Online Certificate Status Protocol (OCSP) or Certificate Revocation List (CRL) to check for certificate revocation, thus preventing connections to expired or unsecured servers. If all of these verification steps pass, the server certificate verification result is "trusted." Otherwise, the smart gateway immediately terminates the connection and logs a detailed error message for subsequent troubleshooting and remediation. After obtaining the certificate verification results, the smart gateway constructs an authentication request based on the verification results and the update request packet, ensuring the device's identity is correctly recognized by the OTA server. The authentication request packet contains the device's unique identification information (such as device ID and hardware serial number), current system version data, network status information, and information about the verified server certificate. To ensure that the authentication request data is not tampered with during transmission, the smart gateway uses the SHA256 algorithm based on the Hash Message Authentication Code (HMAC) to generate a message authentication code (MAC). Specifically, the smart gateway uses a shared secret key (pre-set at device production or dynamically obtained through a secure key agreement protocol) and the authentication request data as input. It calculates a fixed-length authentication code using the HMAC-SHA256 algorithm. This authentication code is encapsulated with the original authentication request data to form an authentication request data packet. The authentication request data is then transmitted to the OTA server for identity authentication.During data transmission, the encryption mechanism of the TLS 1.3 protocol effectively prevents data eavesdropping and tampering. After receiving the authentication request packet, the server verifies the validity of the message authentication code, recalculates the HMAC-SHA256 value using the same key shared with the device, and compares it with the authentication code included in the request. If the comparison is successful, data integrity is guaranteed. The server then resolves the device's identity information and matches the device ID and version information with the backend device registration database to confirm the device's legitimacy and the validity of the update request. After completing the identity authentication process, the OTA server generates a unique session identifier, which marks the current update session and ensures consistency and security in subsequent update data exchanges. The server returns the session identifier to the smart gateway via an encrypted communication channel. Upon receipt, the smart gateway verifies its validity, including its format, length, expiration date, and compatibility with the current device state. To prevent the session identifier from being replayed or tampered with during transmission, the smart gateway checks the timestamp or one-time random number in the identifier to ensure that the returned packet is a legitimate response from the server in the current session. After all verifications are passed, the smart gateway saves the session identifier in memory and marks it as a valid session credential. The session credential includes the session identifier returned by the server, the smart gateway's own authentication status, the session parameters of the TLS encryption channel, and the encryption key information.
[0014] S4, uses the session credentials to compare versions of multi-objective optimization and perform intelligent update decision making to obtain an update execution plan; Specifically, the resource utilization metrics in the update request packet are parsed to extract resource status data, including key performance parameters such as processor utilization, memory usage, storage space availability, network bandwidth utilization, and device operating temperature. By parsing these resource utilization metrics, the intelligent gateway understands the device's current system load and resource allocation. Based on this resource status data, a version compatibility analysis request is sent to the OTA server to perform a multi-dimensional evaluation of the target version. This version compatibility analysis verifies whether the target update version is compatible with the current hardware and software environment and assesses changes in system performance, increases or decreases in resource usage, compatibility issues, and potential security risks after the update. Upon receiving the request, the OTA server generates a version compatibility analysis report through big data analysis, matching historical update data, and simulation testing. This report outlines the predicted performance of the target version under the intelligent gateway's current resource status, including resource consumption forecasts, system stability analysis, network traffic changes, and security enhancements or vulnerability fixes. After receiving the version compatibility analysis report, the intelligent gateway uses the data in the report to construct a multi-scenario update decision matrix to address different update requirements and device operating conditions. The update decision matrix includes multiple pre-defined update options, including full local updates, layered updates, deferred updates, and emergency security updates. Each update option corresponds to a specific resource allocation and execution strategy. Full local updates are suitable for scenarios with ample resources and a good network environment, allowing devices to download and install all updates in the shortest possible time. Layered updates break down updates into modules, downloading and installing them incrementally, making them suitable for scenarios with limited resources or network bandwidth. Deferred updates are suitable for situations with high device load or unstable networks, allowing updates to be automatically performed during idle time by setting a time window. Emergency security updates prioritize critical security patches for high-risk vulnerabilities or major security threats, regardless of resource usage or network impact, to ensure device security and stability. After constructing the multi-scenario update decision matrix, the intelligent gateway inputs it into a pre-trained deep neural network model, which uses a multi-level early exit decision-making mechanism to make update decisions. The deep neural network model is divided into multiple decision layers, including security urgency, resource matching, and network impact, with each layer assessing confidence levels along different dimensions.The security urgency layer primarily analyzes whether the target update involves security risk remediation or key functionality enhancements, assigning a score based on the security threat level. When the confidence level exceeds a preset threshold, an urgent update strategy is prioritized. The resource matching layer assesses whether current device resources can support a smooth update process, including processor load, memory usage, and sufficient storage space. When resource matching is high, a full local update or a layered update is preferred. The network impact layer considers current network latency, bandwidth utilization, and packet loss rate to determine the impact of the update on the user experience. When network conditions are poor, a delayed update is preferred to avoid disrupting normal device usage. When the confidence level at any decision-making layer exceeds a preset threshold, the intelligent gateway immediately makes the corresponding update decision, skipping subsequent lengthy calculations for rapid response and efficient decision-making. The confidence level of the update decision is evaluated. If the confidence level of all update options falls below the security threshold, an edge-cloud collaborative decision-making process is triggered. This leverages cloud computing resources and big data analytics capabilities, combined with real-time status data from the device edge, to make a comprehensive, multi-level decision. Edge-cloud collaborative decision-making dynamically accesses more comprehensive update resources (for example, distributed update files obtained through CDN nodes). It also leverages the cloud's model computing capabilities to provide more refined update plans for devices through predictive analysis and simulation testing. After completing the multi-level decision-making process, the intelligent gateway generates a final update execution plan based on the decision results. This update execution plan clearly defines the final update option (such as a fully local update or a layered update) and specifies execution time windows to avoid executing updates during periods of high device load or peak user usage. The execution plan also includes fine-grained resource allocation strategies, such as dynamically adjusting CPU and memory usage priorities in a multi-tasking environment to ensure resource requirements for the update process. The update plan also sets multi-level rollback triggers to address unexpected errors during the update process. For example, in the event of update file verification failure, system startup anomalies, or device reboots during the update process, automatic rollback to the previous version is implemented to ensure stable device operation. For update tasks that involve large amounts of data exchange or require cloud computing support, the execution plan identifies the need for cloud collaborative processing and reserves backup processing options, such as selecting a local low-priority processing mode in the event of cloud service unavailability. After completing these processes, the intelligent gateway stores the update execution plan in memory and enters the update preparation phase to ensure that the update task is automatically executed at the appropriate time.
[0015] S5, downloading the update file from the OTA server according to the update execution plan and performing integrity verification to obtain a verified firmware image file; The update execution plan is parsed for download parameters, extracting key download-related information from the update execution plan. This information includes the OTA server's download address, the required update file version number, the update file size, the transmission protocol (such as HTTPS or MQTT), the download priority, the bandwidth limit, and the retry policy. The smart gateway constructs a download request based on these parameters and sends it to the OTA server via a secure communication channel, explicitly requesting the generation of a customized update package. After receiving the download request, the OTA server generates a customized update package specifically for the smart gateway based on the device ID, current system version, network status, and security policy. During the customized update package generation process, the server automatically selects the most appropriate update content based on the device's hardware characteristics, operating system version, and application scenario, and excludes incompatible components or those that may cause device instability. Simultaneously with the update package generation, the server also generates a metadata file containing important information such as the update package version, file size, SHA256 hash value, block checksum list, digital signature, and a list of compatible hardware platforms. The customized update package metadata file is used to perform a secondary verification of the smart gateway's hardware compatibility. The local hardware information is compared with the hardware compatibility list in the metadata to verify that the hardware requirements of the update package are met. If verification passes, the download process proceeds to the next step. If verification fails, the smart gateway aborts the update process and returns an incompatibility error message to the server to prevent unexpected device failures caused by forced updates. After confirming hardware compatibility, the smart gateway downloads the firmware image file and the corresponding digital signature file from the OTA server using a block-by-block transfer method. The entire firmware image file is divided into several equal-sized data blocks, and the smart gateway downloads these blocks in parallel, maximizing network bandwidth and increasing download speed. While downloading each data block, the smart gateway calculates the SHA256 hash value of the data block and compares it in real time with the block checksum provided in the metadata file to verify the block's integrity. After all data blocks are downloaded, the smart gateway sequentially merges the blocks into the complete firmware image file and calculates a SHA256 hash value for the entire file. The calculated hash value is finally compared with the full-file checksum provided in the metadata file. If the hash values match, the entire file has been downloaded without any data corruption and the verification passes. If the comparison fails, it indicates that the merged file has experienced data loss, tampering, or storage errors. The intelligent gateway automatically deletes the file and re-initiates the download request based on the retry strategy in the update execution plan. After completing the integrity verification, the intelligent gateway performs a format check and structural analysis on the firmware image file based on the final verification results.By analyzing the firmware file's header information, file structure, and internal data organization, the intelligent gateway ensures that the file format conforms to expected standards. For example, for Linux firmware image files, the intelligent gateway checks the file system type (such as EXT4, UBIFS), boot configuration, kernel image, and root file system validity. For specific embedded devices, the intelligent gateway verifies the correct configuration of the device tree, boot loader, and partition table. During the structural analysis process, the intelligent gateway simulates the firmware loading process, checking for format errors and ensuring that the file system can be correctly decompressed and mounted, thereby preventing unexpected errors during the actual installation. After all verification steps pass, the intelligent gateway marks the firmware image file as "verified" and moves it to the designated update directory. The intelligent gateway also records all verification steps and results in a log file, including the download start and end time, download speed of each block, number of retries, integrity verification results, and format check status.
[0016] S6: Deploy the verified firmware image file to the standby partition and perform update installation to complete status synchronization feedback.
[0017] Specifically, a system status checkpoint is created to record the complete checkpoint data for the current smart gateway. This checkpoint data includes the system's operating status, current firmware version, key configuration parameters, network connection status, system log information, and the device's hardware health status. The verified firmware image file is decompressed and deployed to the backup partition. Firmware image files use a compressed format (such as ZIP, TAR.GZ, or LZMA) to reduce network bandwidth and storage space usage during the download process. During the decompression process, the smart gateway gradually unpacks the firmware files to the backup partition. Furthermore, the smart gateway performs integrity checks on each unpacked file during the decompression process, comparing the file's SHA256 hash value or digital signature to ensure no data corruption or loss occurred during the decompression process. Once all files are successfully decompressed and deployed, the smart gateway generates a backup partition deployment result, recording the status of each operation, the decompressed file list, file size, verification results, and the remaining partition space. After obtaining the backup partition deployment result, the smart gateway modifies the bootloader configuration to target the backup partition at the next system startup and sets the system fallback flag. The boot loader is the first software to run during device startup. It is responsible for loading the operating system kernel and initializing the device's hardware resources. In a dual-partition mechanism, the boot loader maintains a boot configuration file (such as a GRUB configuration file or U-Boot environment variables). The smart gateway modifies this configuration file to change the boot path to the new firmware image in the backup partition. A system fallback flag is also set. This flag is stored in non-volatile memory (such as EEPROM or a device-specific secure storage area). If the system boot fails, the boot loader detects it and triggers a fallback mechanism, switching the boot path back to the original stable partition. This secure dual-partition image switching mechanism ensures that the smart gateway maintains a secure boot path during the update process, effectively preventing device bricking or unrecoverable failures caused by firmware update boot failures. After completing the boot loader configuration, the smart gateway performs a controlled system reboot based on the secure dual-partition image switching mechanism. During the system reboot, the boot loader loads the new firmware from the backup partition according to the configured boot target, initializes the system kernel, mounts the root file system, and starts key services. When the new firmware is first booted, the system automatically performs a self-test, which includes hardware initialization, driver loading, auto-start service detection, and system file integrity verification. The purpose of this self-test is to ensure that the new firmware is functioning properly and is compatible with the current hardware and software environment. For example, it verifies that network modules are connected, storage devices are mounted properly, and sensor data is being collected correctly. If any issues are detected during the self-test, such as failure to start certain services, missing critical files, or unresponsive hardware modules, these errors are logged and the subsequent boot process is immediately stopped.Based on the system self-test results, the smart gateway makes different update decisions. If the self-test passes, indicating that all functions and modules of the new firmware are functioning properly, the device clears the previously set fallback flag, makes the new firmware configuration the default boot option through a bootloader update, and synchronizes the new firmware version and related system status information to the OTA server, confirming the new firmware is effective. Synchronized feedback includes update success, a list of modules that passed the self-test, system resource usage, and the current device health status. Upon receiving this feedback, the server updates the device status in the device management platform. If the system self-test fails, the smart gateway automatically triggers the fallback mechanism. If the system boot fails or the self-test fails, the device restarts and automatically loads the old firmware image from the original partition under the control of the bootloader. The smart gateway also logs diagnostic information for the update failure, including the specific steps that failed, the module that failed the self-test, error messages in the system log, hardware status, and the screen output (if any) when the new firmware fails to boot. This diagnostic information is packaged as status synchronization feedback data and sent to the OTA server through an encrypted communication channel. The server analyzes the cause of the failure based on this data and takes measures such as pushing repair patches, adjusting update strategies, or prompting manual intervention.
[0018] In one example, a system self-check and network connection verification are performed on the smart gateway to obtain network status information, including: Perform hardware detection on the processor, memory, communication module and power supply system of the intelligent gateway to obtain hardware status information; Verify the integrity and consistency of software modules based on hardware status information to obtain the software system operation status; Establish a network connection through the configured network interface based on the software system running status and obtain initial connection parameters; Analyze the initial connection parameters, verify network connectivity by sending ICMP packets, and obtain network delay and packet loss rate; The current network quality is evaluated according to the network delay and the packet loss rate to obtain a network status identifier, and the network status identifier is recorded in a system configuration file to obtain network status information.
[0019] In this example, the smart gateway automatically detects the key hardware components of the device through an embedded monitoring program (such as the hardware monitoring service in the underlying BIOS or operating system). These components include the processor (CPU), memory (RAM), communication module (such as WiFi, Ethernet or cellular module) and power system (such as battery or power adapter). During the processor detection process, the smart gateway reads the operating frequency of the processor. , core temperature and the current load , where the processor load is calculated by the formula: in, Indicates the time the processor is active, Indicates the total running time of the processor. Through the above calculation, the intelligent gateway evaluates the health status of the processor and whether the workload is within the safe range in real time. In terms of memory detection, the device monitors the current available memory. and total memory The ratio of to evaluate memory usage is calculated using the formula: Calculated, where Represents memory usage. When the memory usage is too high, the system may have memory leaks or excessive resource consumption, affecting the stability of the software module. During the communication module detection process, the smart gateway reads the working status of the communication module through the module status register and connection status interface, such as the signal strength of the Wi-Fi module. and connection stability The signal strength is expressed by the following formula: in is the received signal power, Is the reference power. Low signal strength will lead to unstable network connection, thus affecting the network communication capability of the device. In terms of power system detection, the smart gateway monitors the input voltage , output current and the remaining battery charge The power supply stability is calculated by output power Evaluate: If the output power fluctuates significantly, it means there is a problem with the power adapter or battery, which affects the device's ability to continue operating. After obtaining the above hardware status information, the smart gateway verifies the integrity and consistency of the software module based on this information. This step is performed by verifying the hash value (such as SHA-256) and version number of the software module. The integrity verification formula of the software module is expressed as: in is the expected hash value of the software module, is a hash function (such as SHA-256), It is the binary data of the software module. If the calculated hash value is consistent with the expected value, it means that the software module has not been tampered with. During the consistency verification process, the smart gateway compares the version number of the software module The expected version of the system ,if , the software module is in a consistent state, otherwise it is necessary to perform version repair or reinstallation. After confirming that the software system is running normally, the smart gateway establishes a network connection through the configured network interface. When establishing a connection, the device sets the initial connection parameters of the network interface , these parameters include IP address , subnet mask , default gateway and DNS servers These parameters are automatically obtained through DHCP (Dynamic Host Configuration Protocol) or set manually. After completing the network interface configuration, the smart gateway sends ICMP (Internet Control Message Protocol) packets to verify network connectivity. The device sends a certain number of ICMP request packets to a predefined server (such as a public DNS server) and records the round-trip time of these packets. and loss rate The network delay is calculated as follows: in Indicates the The response time of the ICMP request. is the number of requests. The formula for calculating the packet loss rate is: in, Indicates the number of lost packets, Indicates the total number of data packets sent. By calculating the network delay and loss rate, the smart gateway evaluates the stability and quality of the current network. Based on the network delay and packet loss rate, the smart gateway generates a network status indicator through the preset network quality evaluation model. The network status identifier is represented by discrete levels. The intelligent gateway records the network status identifier in the system configuration file so that it can automatically select the optimal network configuration and communication strategy during system initialization or update, thereby ensuring stable and reliable network connection of the device.
[0020] In one example, the version information of the smart gateway is obtained based on the network status information and is locally stored and managed to obtain an update request data packet, including: Read the currently running version configuration file from local storage, parse the version configuration file, extract the complete version information and load it into memory to obtain the current system version data; Read historical update records based on the current system version data to obtain update history data; Check available storage space based on update history data, free up target storage space by cleaning up temporary files and log files, and obtain a storage status report; Create an update-specific directory based on the storage status report and create a backup of the current system partition to obtain system backup information; The current system version data, network status information and device identification information are combined and packaged to obtain an update request data packet.
[0021] In this example, the storage path of the version configuration file is located, which is usually in a predefined directory in the device's file system. When reading the version configuration file, the integrity of the file is checked, for example by calculating the file's hash value. and with the expected hash value For comparison, the hash check formula is: in is a hash function (such as SHA-256), It is the original data of the version configuration file. If the file is not tampered with, it means that the file has not been tampered with. Otherwise, the error handling logic will be triggered to avoid using damaged or unsafe version information files. After verifying the integrity of the file, the smart gateway parses the configuration file and extracts specific version information, such as the system kernel version. , driver version , application version And the system patch version Etc., load these data into memory to form a complete system version data structure. After obtaining the current system version data, the smart gateway reads the historical update records based on these data to obtain the device's update history data. The historical update data is stored in a local log database (such as SQLite) or in the form of a log file. The smart gateway obtains the previously executed update version information, update time, update source (such as OTA server or local upgrade), update result (success or failure), and error code or log information by querying the historical update records. Each update data in the historical update record is represented as an update event. ,Include (Updated version), (Update Time), (Update Status) and (Log information). For example, the most recent update event is represented by ,in Indicates the target version of the last update. Indicates the update time. Indicates the update status (1 for success, 0 for failure). After reading the update history data, the smart gateway compares it with the current system version data to ensure that the current system status is the expected latest status. Otherwise, it is necessary to trigger a system self-check or re-execute the update operation. After obtaining the update history data, the smart gateway checks the available storage space of the device to provide sufficient space for subsequent update operations. Available storage space of the device By calculating the total storage capacity Subtract used storage To obtain, the calculation formula is: if Smaller storage space than required for updates , the storage space is freed up by cleaning temporary files and log files. During the cleaning process, the smart gateway will first delete useless cache files, expired log files, and temporarily generated files. Freed storage space It is expressed by the formula: in Indicates the The size of deleted files, The total number of files deleted. After completing the storage space cleanup, the smart gateway generates a storage status report, which includes the current available space. , the list of files to be cleaned up, and the estimated remaining space to see if they can meet the download and deployment requirements of the update files. If the storage status is still insufficient, the system continues to execute more in-depth cleanup strategies, such as deleting old firmware backups or compressing historical log files, to maximize the freeing of available space. After successfully freeing up enough storage space, the smart gateway creates an update-specific directory based on the storage status report and creates a backup for the current system partition. Stores update files, metadata files, and temporary files downloaded from the OTA server during the update process. When creating a backup, the data of the current partition is completely copied to the backup partition or a partition image file is generated. , the partition backup process is expressed by the following formula: in Indicates the data of the current system partition. The backup target location (such as a spare partition or external storage device). After the backup is completed, the smart gateway generates system backup information, including the backup file size, backup location, and backup verification code. and the timestamp of the backup After all preparations are completed, the smart gateway will send the current system version data, the latest network status information And the unique identification information of the device Combine and package to generate update request data packet The data package construction process is expressed as: in It is a data packaging function that converts version data, network status, and device ID into a standardized data format (such as JSON or Protobuf) so that it can be correctly parsed when communicating with the OTA server. During the packaging process, the smart gateway calculates a message authentication code (MAC) for the data packet. To ensure the security and integrity of the data packet during transmission. After completing the generation of the update request data packet, the smart gateway will send the data packet to the OTA server through an encrypted communication channel, wait for the server to return the adapted update file, and then enter the next step of the automatic update process.
[0022] In one example, establishing a secure communication connection with an OTA server based on an update request packet and obtaining a session credential includes: Initiate a secure connection request based on the preset server address, establish an encrypted channel through the TLS 1.3 protocol, and obtain an initial encrypted connection; Perform server certificate verification on the initial encrypted connection, check the certificate validity period, issuer credibility, certificate chain integrity and revocation status, and obtain the certificate verification result; Construct an identity authentication request based on the certificate verification result and the update request data packet, use the HMAC-SHA256 algorithm to generate a message authentication code, and obtain the authentication request data; The authentication request data is transmitted to the OTA server for identity authentication, and the session identifier returned by the server is obtained. The validity of the session identifier is verified and saved in the memory to obtain the session credential.
[0023] In this example, the OTA server address stored locally is read. The address is stored in the form of a domain name. The smart gateway uses the domain name resolution service (DNS) to convert the domain name to Convert to target IP address The process of domain name resolution is as follows: in It is the DNS resolution function. After successfully obtaining the IP address of the target server, the smart gateway initiates a secure connection request based on this address and establishes an encrypted communication channel using the TLS 1.3 protocol. During the TLS handshake phase, the smart gateway (client) and the OTA server (server) exchange public keys using an asymmetric encryption algorithm. and , and negotiate to generate a shared session key . Shared Key The calculation process is expressed as: in is the key exchange algorithm (such as ECDHE), and The random numbers generated for the client and server are separated. The key exchange mechanism based on random numbers and public keys ensures that even if the communication is intercepted, the attacker cannot deduce the actual session key used, thereby ensuring the security of data transmission. After the encrypted channel is established, the smart gateway verifies the digital certificate provided by the server to ensure that the connected server is a legitimate OTA server. The server certificate contains the server's public key ,domain name , Certificate validity period arrive , Issuing Agency and the certificate chain And other key information. Smart gateway checks the current time Is the certificate within its validity period? If the current time exceeds the certificate validity period, the verification fails. Is it in the local trust list to confirm the credibility of the organization. Certificate chain verification recursively checks each level of the certificate chain to ensure that the root certificate The certificate is also trusted and verifies whether the certificate has been revoked through the Online Certificate Status Protocol or the Certificate Revocation List. If all verification steps are passed, the smart gateway generates a certificate verification result. (1 means verification is passed, 0 means failure), otherwise the connection is terminated and the error log is recorded. Then, the smart gateway constructs an authentication request packet based on this result and the update request packet. Update request packet Contains the unique identifier of the device , Current system version information and network status information In order to ensure that the authentication request data is not tampered with during transmission, the smart gateway uses the HMAC-SHA256 algorithm to generate a message authentication code The calculation formula of HMAC (hash-based message authentication code) is: in represents the SHA-256 hash function, is the shared session key, Is the authentication request data. After generating the message authentication code, the intelligent gateway will authenticate the request data with Encapsulated together as an authentication data packet , to ensure the integrity and authenticity of the data. The smart gateway then sends the authentication request data to the The data is transmitted to the OTA server for identity authentication. During the data transmission process, the TLS protocol will encrypt and protect the integrity of the data to prevent the data from being intercepted or tampered by a third party during the transmission process. After the server receives the authentication data, it uses the same HMAC algorithm to recalculate the message authentication code : Then With the received Compare them. If the two are equal, it means that the data has maintained integrity during transmission. Otherwise, the authentication fails and the server will reject the connection request. If the authentication passes, the server generates a unique session identifier for the smart gateway. , the session identifier is generated using a random number or UUID (Universally Unique Identifier) to avoid replay attacks and session hijacking. The server returns the session identifier After that, the smart gateway verifies the validity of the identifier. The verification process includes checking the format of the identifier ,length and timestamp The format of the session identifier is a 16-byte or 32-byte string, and the length must comply with the protocol specification. If the identifier contains timestamp information, the smart gateway verifies whether the timestamp is within a reasonable time limit, for example: in It is the preset time difference tolerance to ensure that the session identifier is not old or invalid. After passing all the verification steps, the smart gateway will Saved in memory as the session credential for this update session .
[0024] In one example, session credentials are used to compare versions of multi-objective optimization and perform intelligent update decision making, resulting in an update execution plan including: Parse the resource utilization indicators in the update request data packet and extract resource status data; Based on the resource status data, the OTA server is requested to perform version compatibility analysis, and a multi-dimensional evaluation of the target version is performed to obtain a version compatibility analysis report. Based on the version compatibility analysis report, a multi-scenario update decision matrix is constructed. The update options include: full local update, layered update, deferred update, and emergency security update. Each update option corresponds to a preset resource configuration and execution strategy. The multi-scenario update decision matrix is input into the deep neural network model, and a multi-level early exit decision mechanism is adopted to conduct layer-by-layer confidence assessment at the security urgency layer, resource matching layer, and network impact layer. When the decision confidence at any layer exceeds the preset threshold, an update decision operation is immediately made; Evaluate the confidence of the update decision operation. If the confidence of all update options is lower than the safety threshold, the edge-cloud collaborative decision process is triggered to obtain a multi-level decision result. Based on the multi-level decision results, an update execution plan is generated. The update execution plan includes update options, execution time windows, fine-grained resource allocation strategies, multi-level rollback trigger conditions, cloud collaborative processing requirements, and backup processing solutions.
[0025] In this example, the resource utilization indicators in the update request data packet are parsed. Resource utilization indicators include processor (CPU) load, memory usage, storage space availability, network bandwidth usage, and device power consumption status. The smart gateway parses the specific fields in these data packets, such as Indicates the CPU load, Indicates memory usage, Indicates the remaining storage space. Indicates network bandwidth usage and Indicates the power consumption of the device. These resource status data are expressed by the following formula: in is the currently active processor thread time, is the total processor runtime, is the total memory capacity, is the currently available memory, is the total storage capacity, is the used storage space. Through these formulas, the smart gateway obtains the resource status data of the current device. Based on the resource status data, it requests version compatibility analysis from the OTA server to perform a multi-dimensional evaluation of the target update version. Version compatibility analysis considers multiple factors such as the device's current hardware configuration, system software version, application dependencies, and network environment. For example, the smart gateway packages the resource status data into a request data packet. , which contains the device identifier , Current system version and resource utilization metrics The request data packet is sent to the OTA server through an encrypted communication channel. After receiving the request, the server generates a version compatibility analysis report through model analysis and historical data comparison. In the report, the server gives the target version Compatibility score based on the current device state , where the score is calculated using the following formula: in arrive These weight coefficients are dynamically adjusted based on the resource requirements of the updated version. For example, for an updated version with high-performance processor requirements, will be higher, and for updates that require more storage space, will account for a larger proportion. Reaching a preset compatibility threshold , it means that the current device can successfully execute the target version update, otherwise it is necessary to select an update strategy with lower resource consumption. Build a multi-scenario update decision matrix based on the version compatibility analysis report. Update Decision Matrix It includes multiple update options, such as full local update, layered update, delayed update and emergency security update. Each update option corresponds to different resource configuration and execution strategy. Full local update is suitable for situations with sufficient resources, layered update is suitable for scenarios with relatively tight resources, delayed update is executed when the network or device load is high, and emergency security update prioritizes device security and will be enforced even if resources are limited. Each update option There are corresponding resource requirements and execution strategies , this information will be filled into the decision matrix for subsequent decision-making models. The multi-scenario update decision matrix is input into the pre-trained deep neural network model. The model adopts a multi-level early exit decision mechanism to evaluate the decision confidence layer by layer through the security urgency layer, resource matching layer and network impact layer. At the security urgency layer, the model calculates the urgency of each update option under the current security situation. , the calculation formula is: in is the risk level of the security incident, is the incident response time. If Exceeding the preset threshold , the model will prioritize the urgent security update option. At the resource matching layer, the model evaluates the matching degree between the resource utilization of the device and the resource requirements of the update option. : in Is the device's current Item resource status, Is the update option The corresponding resource demand value. When the resource matching degree exceeds the threshold When the model selects the update strategy with the best resources, the model analyzes the current network status. and update download requirements By calculating the relationship between and bandwidth utilization : If the network impact is within an acceptable range, real-time updates are preferred, otherwise delayed updates or segmented downloads are selected. If the confidence level of the model is below the safety threshold after all levels of evaluation, , the smart gateway automatically triggers the edge-cloud collaborative decision-making process. The data is sent to the cloud-based decision-making system, where it is further analyzed by a higher-performance model on the cloud, ultimately resulting in a multi-level decision-making result. The decision results include more fine-grained resource allocation recommendations and cloud collaborative processing requirements. For example, when device resources are tight, some computing tasks are completed in the cloud, and the device only needs to receive the final results, thereby reducing local resource consumption. The final update execution plan is generated based on the multi-level decision results. The execution plan contains specific update options. , and set the execution time window , fine-grained resource allocation strategy , multi-level rollback trigger conditions , cloud collaborative processing needs and alternative treatment plans These parameters together form an operational guideline that enables the smart gateway to dynamically adjust its execution strategy during the update process. For example, it can automatically pause downloads when it detects network quality degradation, or immediately initiate a rollback mechanism to restore to the previous stable version when an update fails, thereby ensuring that the device always maintains a secure and stable operating state.
[0026] In this embodiment, a multi-scenario update decision matrix is input into a deep neural network model, and a multi-level early exit decision mechanism is adopted to perform layer-by-layer confidence assessment at the security urgency layer, resource matching layer, and network impact layer, respectively. When the decision confidence at any layer exceeds a preset threshold, an update decision operation is immediately made. The method is characterized in that it includes: preprocessing the multi-scenario update decision matrix, standardizing the update options, resource status data, and network connection parameters, constructing an input feature vector of the deep neural network model, and obtaining a standardized feature matrix; based on the standardized feature matrix, constructing a multi-classification neural network sub-model at the security urgency layer, performing a multi-dimensional assessment of the security level of the update options, the urgency of vulnerability repair, and the potential security risks, calculating the security urgency confidence, and obtaining the security layer decision result; when the confidence of the security layer decision result does not exceed the preset security threshold, entering the resource matching layer, constructing a resource utilization prediction neural network sub-model, and performing a multi-classification assessment of the processor. The load, memory usage, storage space and power status are deeply analyzed and resource compatibility is evaluated, the resource matching layer confidence is calculated, and the resource layer decision result is obtained; when the confidence of the resource layer decision result does not exceed the preset resource threshold, it enters the network impact layer, builds a network performance prediction neural network sub-model, conducts a comprehensive evaluation of the network connection quality, bandwidth utilization, packet loss rate and network delay, calculates the network impact layer confidence, and obtains the network layer decision result; the confidence of the three-layer decision results is correlated and comprehensively evaluated. When the decision confidence of any layer exceeds the corresponding preset threshold, an update decision operation instruction is immediately generated, and the decision analysis process of the subsequent layer is terminated; if the decision confidence of all layers is lower than their respective preset thresholds, the edge-cloud collaborative decision process is triggered, and the detailed decision feature vector, hierarchical analysis results and confidence data are uploaded to the OTA server, and the server executes a more complex deep calculation model to make the final update decision.
[0027] In one example, an update file is downloaded from an OTA server according to an update execution plan and integrity verified to obtain a verified firmware image file, including: Parse the download parameters of the update execution plan, extract the download request information, and send the download request information to the OTA server to request the generation of a customized update package; Based on the metadata file of the customized update package, the hardware compatibility of the smart gateway is reconfirmed to obtain the hardware compatibility verification result; Download the firmware image file and digital signature file using block transfer, calculate the SHA256 hash value of the block and compare it with the block checksum in the metadata to obtain the block integrity verification result; Calculate the overall SHA256 hash value of the merged firmware image file after all blocks are downloaded, and compare it with the full file checksum provided in the metadata to obtain the final verification result of the firmware image file; Format checking and structure analysis are performed based on the final verification result to obtain a verified firmware image file.
[0028] In this example, all parameter information related to the download process is parsed from the update execution plan, including the address of the target OTA server. , version number of the downloaded file , Firmware file size , transmission protocol type (such as HTTP or HTTPS), download priority , bandwidth limitation and retry strategies Such as the maximum number of retries or the retry interval). These download request information will be packaged into a request data packet. , the key information combination in the data packet is expressed as: in It is a packaging function that converts various parameters into a standardized data format (such as JSON or Protobuf) so that the data can be correctly parsed when communicating with the OTA server. After successfully generating the download request data packet, the smart gateway sends the request to the OTA server through an encrypted communication channel (such as TLS 1.3), explicitly requesting the generation of a customized update package. The generation process of the customized update package depends on the hardware configuration of the device, the current system version, and the device configuration. and specific update requirements. For example, when the device's available storage space is Smaller or network bandwidth When limited, the OTA server will select a simplified version of the firmware update package , and when resources are sufficient, the complete firmware package will be pushed When the server generates a customized update package, it also generates a metadata file. , which contains the file size of the update package , block information SHA256 checksum of each data block , the SHA256 hash value of the entire file , digital signature And the hardware compatibility list After the smart gateway receives the metadata file, it will double-check the hardware compatibility of the device to ensure that the new firmware matches the current hardware configuration of the device. (including processor model, memory size, communication module type, etc.) and the compatibility list in the metadata Perform the comparison. The comparison process is expressed as: in Is the compatibility verification function, when If the value is 0, it indicates compatibility; otherwise, it indicates incompatibility. If the device is incompatible, the update process is aborted, the error log is recorded, and the incompatibility error information is fed back to the server to avoid the risk of device unavailability due to forced update. After confirming the hardware compatibility, the smart gateway uses block transmission to download the firmware image file and the corresponding digital signature file from the OTA server. Block transmission is an efficient download method that can transfer the firmware file to the server. Split into equal-sized blocks of data (Each block size is bytes). The device will request these blocks in parallel to maximize the use of network bandwidth. And improve download speed. When downloading each data block, the device also calculates the SHA256 hash value of the data block and compare it with the block checksum provided in the metadata file For real-time comparison, the hash calculation formula is: in is the SHA256 hash function, when If the data block is complete, the device will re-request the data block according to the retry strategy to ensure that the downloaded data block has not been tampered with or damaged. The entire block verification process is expressed as: When all data blocks are verified, ,otherwise , and trigger the error handling process. After completing the download and verification of all data blocks, the smart gateway merges these data blocks into a complete firmware image file in sequence. , and calculate the overall SHA256 hash value of the entire file The calculated hash value Will be compared with the full file checksum provided in the metadata file Perform the final comparison: if , it means that the entire file maintains integrity during the download process, otherwise the system automatically deletes the file and updates the retry strategy in the execution plan. , re-initiate the download request to ensure that the final downloaded file is complete and secure. After the overall verification is passed, the smart gateway performs format check and structure analysis based on the final verification result to ensure that the firmware image file meets the expected format and structure requirements. For example, for the firmware image file of the Linux system, check the file system type (such as EXT4, UBIFS), boot loader configuration , kernel image and the root file system The format checking process is expressed as: If the format check passes , it means the file structure is complete, the smart gateway will verify the firmware image file Mark it as "Verification Passed" and move it to the specified update directory to prepare for the subsequent update installation steps. During the format and structure analysis process, the device simulates the process of loading the firmware to check whether there are format errors and whether the file system can be correctly decompressed and mounted to avoid unexpected errors during the actual installation process. After completing the format check, the smart gateway uses the public key in the device to Digital signature of metadata file Verify that the firmware file is signed and released by a trusted OTA server. The digital signature verification formula is: in Is the digital signature verification function, when If the signature verification is successful, the device will refuse to install the firmware file to avoid potential security threats. After all verifications are passed, the smart gateway records the verification status of the firmware image file in the system log and feeds the status back to the OTA server.
[0029] In one example, the verified firmware image file is deployed to the standby partition and the update installation is performed to complete the status synchronization feedback, including: Create a system status checkpoint, record the checkpoint data of the current smart gateway, and decompress the verified firmware image file to obtain the backup partition deployment result; Modify the boot loader configuration based on the backup partition deployment results, redirect the next system boot target to the backup partition, and set the system fallback flag. When the new firmware fails to boot, it can automatically fall back to the original firmware, building a safe switching mechanism for dual partition images. A controlled system reboot is performed based on a secure switching mechanism of a dual partition image. During the reboot process, the boot loader loads the new firmware. When the new firmware is first started, a self-test operation is performed to obtain the system self-test results. According to the system self-test results, if the self-test passes, the rollback flag is cleared to confirm that the new firmware is officially effective; if the self-test fails, the rollback mechanism is automatically triggered, the original firmware is loaded after restart, and the failure diagnostic information is recorded to complete the status synchronization feedback.
[0030] In this example, the current system status of the device is recorded as checkpoint data so that it can be restored to the previous stable state if an exception occurs during the update process. The system status checkpoint includes the processor status , memory usage , storage partition information , network connection status and the operating status of key system services This information is saved in the form of structured data (such as JSON or binary configuration files) to the device's non-volatile storage, such as EEPROM or a dedicated backup partition. System Status Checkpoint The recording process is expressed as: in It is a state packaging function that ensures that the state data can be loaded correctly when the system is restored. After successfully creating a system state checkpoint, the intelligent gateway decompresses the verified firmware image file to prepare for deploying the new firmware to the backup partition. The firmware image file uses a compressed format (such as ZIP, TAR.GZ or LZMA), and the system uses the corresponding decompression tool Firmware file Decompress it. The decompression process is expressed as: in It is the decompressed firmware content, including the system kernel, root file system, boot loader configuration and application files. During the decompression process, the smart gateway gradually writes these decompressed files to the backup partition. A spare partition is a partition that is separate from the current running partition. Independent storage area, marked by the partition table After all files are decompressed, the system generates a backup partition deployment result. , including the number of files written , the total size of the file And the integrity check results of each file : If the integrity verification of all files passes , it means that the backup partition is ready and the next step is to modify the boot loader configuration. After completing the backup partition deployment, the smart gateway modifies the boot loader configuration, points the next startup target of the system to the backup partition, and sets the system fallback flag The configuration file of the boot loader (such as GRUB, U-Boot) contains the path to the boot partition , kernel loading parameters And start timeout settings The smart gateway will start the partition path Modify to spare partition The address of the , indicating that if the next boot fails, the device should automatically roll back to the current stable partition The operation of modifying the bootloader configuration is expressed by the following formula: The dual-partition image's secure switching mechanism ensures that the device always maintains a secure boot path during the update process, effectively preventing the risk of the device becoming unbootable due to an update failure. After completing the boot loader configuration, the smart gateway performs a controlled system reboot based on the dual-partition image's secure switching mechanism. During the reboot process, the boot loader executes the boot target according to the configured boot target. Load the new firmware in the backup partition. The system first loads the kernel during the boot process , then mount the root file system , then start key system services The new firmware will automatically perform a self-test when it is first started, which includes hardware initialization , driver loading , key service startup verification And system file integrity check . System self-test results The results of each sub-test are combined and expressed by the following formula: in Is the self-test result calculation function, if all sub-item tests pass, then Indicates that the self-test is successful, otherwise Indicates that the self-test failed. Based on the system self-test results, the smart gateway makes different update decisions. If the self-test passed , which means that all functions and modules of the new firmware are running normally, and the device will clear the rollback flag , and mark the current partition as the active partition, making the new firmware configuration the default startup option. At this time, the smart gateway will and system status information Synchronize to the OTA server through an encrypted communication channel so that the remote operation and maintenance system can update the device status record and confirm that the new firmware is officially effective. The status synchronization feedback data packet Expressed as: If the system self-test fails , the smart gateway will automatically trigger the fallback mechanism immediately. The fallback mechanism has been configured in the boot loader. When the device detects a startup failure or a self-test result is a failure, the device will restart again and automatically load the old firmware in the original partition under the control of the boot loader. At the same time, the smart gateway records the diagnostic information of the update failure in detail, including the module that failed the self-test. , Error messages in the system log , hardware status And the screen output when the startup fails (if any). These diagnostic information will be packaged into a status feedback data packet The status feedback data is transmitted to the OTA server through a secure channel so that the server can analyze the cause of the failure and provide subsequent repair or rollback instructions. Through these automated and intelligent system status detection, partition switching, and fallback mechanisms, the smart gateway effectively ensures the security and stability of devices during firmware updates. Whether the update succeeds or fails, the device will synchronously report its status to the server, allowing the remote operation and maintenance system to always have the latest status of the device, ensuring continued high availability and security in complex network and application environments.
[0031] Reference Figure 2 This embodiment provides an automatic update and server synchronization system for an intelligent gateway, including: System self-check module 1, used to perform system self-check and network connection verification on the intelligent gateway to obtain network status information; Local storage management module 2, used to obtain the version information of the intelligent gateway according to the network status information and perform local storage management to obtain an update request data packet; Communication connection module 3, used to establish a secure communication connection with the OTA server based on the update request data packet and obtain a session credential; Decision-making module 4, used to compare versions of multi-objective optimization using session credentials and perform intelligent update decision-making to obtain an update execution plan; Integrity verification module 5, used to download the update file from the OTA server according to the update execution plan and perform integrity verification to obtain a verified firmware image file; The update installation module 6 is used to deploy the verified firmware image file to the standby partition and perform update installation to complete status synchronization feedback.
[0032] In this embodiment, for the specific implementation of each unit in the above system embodiment, please refer to the above method embodiment, which will not be repeated here.
[0033] It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, system, article, or method comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, system, article, or method. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, system, article, or method comprising the element.
[0034] The above description is only a preferred embodiment of the present invention and does not limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made by using the contents of the present invention description and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.
Claims
1. A method for automatic update and server synchronization of an intelligent gateway, characterized in that: The following steps are involved: Perform system self-check and network connection verification on the intelligent gateway to obtain network status information; Obtaining version information of the intelligent gateway according to the network status information and performing local storage management to obtain an update request data packet; Establishing a secure communication connection with the OTA server based on the update request data packet to obtain a session credential; Using the session credentials to perform version comparison for multi-objective optimization and perform intelligent update decision making to obtain an update execution plan; Download the update file from the OTA server according to the update execution plan and perform integrity verification to obtain a verified firmware image file; The verified firmware image file is deployed to the standby partition and updated and installed, completing status synchronization feedback.
2. The method for automatic update and server synchronization of an intelligent gateway according to claim 1, characterized in that: The system self-check and network connection verification of the intelligent gateway to obtain network status information includes: Perform hardware detection on the processor, memory, communication module and power supply system of the intelligent gateway to obtain hardware status information; Verify the integrity and consistency of the software module according to the hardware status information to obtain the software system operation status; Establishing a network connection through a configured network interface based on the running state of the software system to obtain initial connection parameters; Analyzing the initial connection parameters, verifying network connectivity by sending ICMP packets, and obtaining network delay and packet loss rate; The current network quality is evaluated according to the network delay and the data packet loss rate to obtain a network status identifier, and the network status identifier is recorded in a system configuration file to obtain network status information.
3. The method for automatic update and server synchronization of an intelligent gateway according to claim 1, characterized in that: The step of obtaining the version information of the intelligent gateway according to the network status information and performing local storage management to obtain an update request data packet includes: Read the currently running version configuration file from the local storage, parse the version configuration file, extract the complete version information and load it into the memory to obtain the current system version data; Reading historical update records based on the current system version data to obtain update history data; Checking available storage space based on the update history data, freeing up target storage space by cleaning up temporary files and log files, and obtaining a storage status report; Creating an update-specific directory based on the storage status report and creating a backup of the current system partition to obtain system backup information; The current system version data, the network status information and the device identification information are combined and packaged to obtain an update request data packet.
4. The method for automatic update and server synchronization of an intelligent gateway according to claim 1, characterized in that: The establishing a secure communication connection with the OTA server based on the update request data packet to obtain a session credential includes: Initiate a secure connection request based on the preset server address, establish an encrypted channel through the TLS 1.3 protocol, and obtain an initial encrypted connection; Performing server certificate verification on the initial encrypted connection to check the certificate validity period, issuing authority credibility, certificate chain integrity, and revocation status to obtain a certificate verification result; Constructing an identity authentication request based on the certificate verification result and the update request data packet, generating a message authentication code using the HMAC-SHA256 algorithm, and obtaining authentication request data; The authentication request data is transmitted to the OTA server for identity authentication, and a session identifier returned by the server is obtained. The validity of the session identifier is verified and stored in the memory to obtain the session credential.
5. The method for automatic update and server synchronization of an intelligent gateway according to claim 1, characterized in that: The use of the session credentials to perform version comparison for multi-objective optimization and perform intelligent update decision making to obtain an update execution plan includes: Parsing the resource utilization index in the update request data packet to extract resource status data; Based on the resource status data, request a version compatibility analysis from the OTA server, perform a multi-dimensional evaluation of the target version, and obtain a version compatibility analysis report; Based on the version compatibility analysis report, a multi-scenario update decision matrix is constructed, wherein the update options include: full local update, layered update, deferred update, and emergency security update, and each update option corresponds to a preset resource configuration and execution strategy; Input the multi-scenario update decision matrix into a deep neural network model, adopt a multi-level early exit decision mechanism, perform layer-by-layer confidence assessment at the security urgency layer, resource matching layer, and network impact layer, and immediately make an update decision operation when the decision confidence at any layer exceeds a preset threshold; Evaluate the confidence of the update decision operation. If the confidence of all update options is lower than the safety threshold, trigger the edge-cloud collaborative decision process to obtain a multi-level decision result. Based on the multi-level decision results, an update execution plan is generated, which includes update options, execution time windows, fine-grained resource allocation strategies, multi-level rollback trigger conditions, cloud collaborative processing requirements, and backup processing solutions.
6. The method for automatic update and server synchronization of an intelligent gateway according to claim 1, characterized in that: The step of downloading the update file from the OTA server according to the update execution plan and performing integrity verification to obtain a verified firmware image file includes: Parsing download parameters of the update execution plan, extracting download request information, and sending the download request information to the OTA server to request generation of a customized update package; Based on the metadata file of the customized update package, the hardware compatibility of the smart gateway is reconfirmed to obtain a hardware compatibility verification result; Download the firmware image file and digital signature file using block transfer, calculate the SHA256 hash value of the block and compare it with the block checksum in the metadata to obtain the block integrity verification result; Calculate the overall SHA256 hash value of the merged firmware image file after all blocks are downloaded, and compare it with the full file checksum provided in the metadata to obtain the final verification result of the firmware image file; Format checking and structure analysis are performed based on the final verification result to obtain a verified firmware image file.
7. The method for automatic update and server synchronization of an intelligent gateway according to claim 1, characterized in that: The step of deploying the verified firmware image file to the standby partition and performing update installation to complete status synchronization feedback includes: Creating a system status checkpoint, recording the checkpoint data of the current intelligent gateway, and decompressing the verified firmware image file to obtain a standby partition deployment result; Modify the boot loader configuration according to the backup partition deployment result, point the next system startup target to the backup partition, and set the system fallback flag so that it can automatically fall back to the original firmware when the new firmware fails to start, thereby building a safe switching mechanism for the dual partition image; Performing a controlled system restart based on the secure switching mechanism of the dual partition image, wherein the boot loader loads the new firmware during the restart process, and performing a self-test operation when the new firmware is first started to obtain a system self-test result; According to the system self-test results, if the self-test passes, the rollback flag is cleared to confirm that the new firmware is officially effective; if the self-test fails, the rollback mechanism is automatically triggered, the original firmware is loaded after restart, and the failure diagnostic information is recorded to complete the status synchronization feedback.
8. An automatic update and server synchronization system for an intelligent gateway, characterized in that: For implementing the steps of the method according to any one of claims 1 to 7, the system comprises: System self-check module, used to perform system self-check and network connection verification on the intelligent gateway to obtain network status information; A local storage management module is used to obtain the version information of the intelligent gateway according to the network status information and perform local storage management to obtain an update request data packet; A communication connection module, configured to establish a secure communication connection with the OTA server based on the update request data packet and obtain a session credential; a decision-making module, configured to use the session credentials to perform version comparison of multi-objective optimization and perform intelligent update decision-making to obtain an update execution plan; An integrity verification module is used to download the update file from the OTA server according to the update execution plan and perform integrity verification to obtain a verified firmware image file; The update installation module is used to deploy the verified firmware image file to the standby partition and perform update installation to complete status synchronization feedback.
Citation Information
Cited By
UEFI (Unified Extensible Firmware Interface) firmware updating method and device, equipment and storage medium
CN120950107A
UEFI firmware update methods, devices, equipment and storage media
CN120950107B
Atomic transaction-based distributed Web service zero-interruption hot update method and system
CN121056325A
Method and system for zero-downtime hot update of distributed web services based on atomic transactions
CN121056325B
End side AI model OTA updating optimization method and system based on end-cloud collaboration
CN122069260A