Online upgrading method and system for embedded software of intelligent washing machine

Through a two-factor authentication solution of physically uncloned functions and chaotic encryption, combined with dynamic channel quality parameters and hierarchical verification, the insufficient identity authentication and transmission reliability problems of the online upgrade system of embedded software of the intelligent washing machine are solved, and a safe and reliable upgrade process is achieved.

CN120498676APending Publication Date: 2025-08-15SHENZHEN KAILU INNOVATION TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510709881.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-29
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

The existing smart washing machine embedded software online upgrade system has problems such as insufficient identity authentication strength, poor transmission reliability, and easy interruption of the upgrade process, which leads to system crashes in complex home network environments.

Method used

Using a two-factor authentication scheme based on physically uncloned functions and chaotic encryption, end-to-end security authentication and reliable upgrades are achieved through device unique credential binding, dynamic channel quality parameter adjustment, Galohua Domain Network Coding and Chaotic Encryption, hierarchical verification and three-state transaction management.

Benefits of technology

Effectively prevent unauthorized access and firmware tampering, improve transmission reliability and the reliability of the upgrade process, ensure data integrity and system consistency, and avoid system crashes caused by accidental interruptions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498676A_ABST
    Figure CN120498676A_ABST
Patent Text Reader

Abstract

The invention relates to the field of Internet of Things equipment security upgrading, and discloses an intelligent washing machine embedded software online upgrading method and system, and the method comprises the following steps: 1, a server side stores an encrypted upgrading program file and calculates a verification value, issues the verification value in a wireless manner at a set time, generates an equipment uniqueness voucher based on a physical unclonable function, and sends the equipment uniqueness voucher to the server side; establishing equipment identity binding; 2, dynamically calculating a network coding parameter based on the equipment uniqueness voucher according to a real-time channel quality parameter; and 3, based on the network coding parameters, carrying out dynamic block network coding transmission on the upgrade data, and generating an encrypted upgrade data packet by adopting chaotic encryption in the transmission process. According to the invention, an end-to-end security authentication system is realized by binding the unique voucher of the equipment and establishing an encrypted transmission channel. According to the scheme, the unauthorized access and firmware tampering are effectively prevented by utilizing the dual guarantee of hardware features and a cryptographic algorithm.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of security upgrade of Internet of Things devices, and in particular to a method and system for online upgrade of embedded software of a smart washing machine. Background Art

[0002] With the rapid development of the Internet of Things (IoT), smart washing machines and other home appliances are increasingly adopting embedded systems for functional control. As a key means of maintaining device security and enhancing functionality, online upgrade technology must address challenges such as complex home network environments and limited device resources while ensuring upgrade reliability. Current mainstream upgrade solutions typically include basic modules such as encrypted firmware transmission, verification, and resumable downloads. However, in actual deployments, they still face security vulnerabilities and instability.

[0003] Existing online upgrade systems for embedded software in smart washing machines often use fixed encryption keys and static block partitioning strategies, making them difficult to adapt to dynamically changing home network environments. Authentication mechanisms often rely on software-generated keys, which pose a risk of reverse engineering. The transmission process lacks real-time channel quality awareness, leading to a surge in retransmission rates in situations of signal interference. Data verification often relies on a single CRC mechanism, which cannot effectively detect malicious tampering. Furthermore, transaction management during the upgrade process is insufficient, and unexpected interruptions can easily lead to system crashes. These flaws collectively limit the security and reliability of the upgrade system.

[0004] This paper addresses the issue of insufficient device authentication strength in existing technologies by proposing a two-factor authentication scheme based on physically unclonable functions and chaotic encryption. This scheme extracts the inherent hardware characteristics of the device to generate an unclonable key seed, which, combined with a dynamic chaotic sequence, enables real-time updates of the encryption key. This effectively addresses the vulnerability of traditional software keys to copying and replay. This solution improves authentication security while avoiding additional hardware costs, making it suitable for resource-constrained embedded environments. Summary of the Invention

[0005] The purpose of the present invention is to provide a method and system for online upgrading of embedded software of a smart washing machine, which solves the problems of existing upgrading solutions in a complex home network environment, such as insufficient identity authentication strength, poor transmission reliability, and easy interruption of the upgrading process leading to system crash.

[0006] To achieve the above objectives, the present invention is implemented through the following technical solutions: a method for online upgrading of embedded software of a smart washing machine, comprising the following steps: Step 1: The server stores the encrypted upgrade program file and calculates the checksum. It then sends the updated program file wirelessly at the set time. It generates a unique device credential based on a physically unclonable function and establishes device identity binding. Step 2: Dynamically calculating network coding parameters based on the device unique credential according to the real-time channel quality parameters; Step 3: Based on the network coding parameters, the upgrade data is dynamically divided into blocks and network coded for transmission, and chaotic encryption is used to generate encrypted upgrade data packets during the transmission process; Step 4: Perform layered verification on the received encryption upgrade data packet, including packet-level cyclic redundancy check and shard hash tree verification; Step 5: Atomically commit the verified upgrade data through the three-state transaction management mechanism, including state transition control among the prepare state, commit state, and complete state. Step 6: When the layer verification fails or the state transfer times out, a safe rollback operation is triggered to restore to the state before the upgrade. Preferably, the step 1 includes: The upgrade program file is encrypted using AES-256-CBC mode, and the initialization vector is generated by a true random number on the server; The upgrade package is sent via the MQTT protocol from 02:00 to 04:00 every day. The data package format is: Packet=(Header,EncryptedData,CRC32,Timestamp); Among them: Header contains device ID and fragment sequence number; Extract the set of physical unclonable function features of the smart washing machine microcontroller unit: PUF={p0,p1,...,p 23}p i ∈{0,1} 8 ; The PUF feature is combined with a true random number to generate a unique public key for the device: K pub =Hash(PUF|R); Where: R∈{0,1} 128 is a random sequence generated by a true random number generator; ∥ represents a data concatenation operation; Hash(·) is a cryptographic hash function.

[0007] Preferably, dynamically determining the data transmission strategy in step 2 includes: Get the channel quality parameter set: C=(RSSI,SNR,P L ); Among them: RSSIdBm: received signal strength indicator; Signal-to-noise ratio; P L =N loss / N total : Historical packet loss rate; Calculate dynamic block size: B=256·[1+α·tanh(β(RSSI-R0))]; Where: α: block adjustment coefficient; β: signal strength sensitivity factor; R0: reference signal strength; Determine network coding parameters: Where: θ2: historical transmission success rate variance; λ: channel attenuation factor.

[0008] Preferably, the step three includes: Construct a random reversible encoding matrix in a Galois field: G∈GF(2 m ) (n+k)×n ; Where: GF(2 m ) means 2 m Element Galois Field; m: the number of field bits; n and k: encoding parameters; Generate a chaotic dynamic encryption key sequence: Where: (x i ,y i ) is the numerical solution of the chaotic system; Represents a bitwise exclusive OR operation; Perform encrypted encoding transmission: Where: X j ∈GF(2 m ) n is the original data block; L is the key sequence period length.

[0009] Preferably, the step 4 includes: Perform packet-level cyclic redundancy check: CRC calc (D i )≡CRC recv ; Where: D i For the i-th received data packet; CRC calc Is the calculated check code; CRC recv The checksum carried by the data packet; construct the shard Merkle hash tree: H node =Hash(H left ∥H right ); H root =Hash(H1∥H2∥…∥H N ); Among them: H node H is the hash value of the middle node of the tree;root is the root hash value; N is the total number of data shards; Verify root hash consistency: H root ≡H blockchain ; Among them: H blockchain The pre-set root hash stored for the blockchain.

[0010] Preferably, the step five includes: Initialize the three-state transaction state machine: State∈{S pre ,S com ,S fin}; Where: S pre : Preparation state, store upgrade data in temporary area; S com : Submit state, execute program image switching; S fin : Completed state, update the system boot flag; Define the state transition conditions: S com →S fin :WriteFlag=Success; Where: V: data shard set; Valid(v): shard verification function; WriteFlag: FLASH write operation status flag; perform atomic commit operation: Where: Δt: state dwell time; T max : is the preset timeout threshold; Safe rollback operations include: When FLASH writing fails, the original firmware is restored from the backup area address 0x08060000; The system is reset by triggering the hardware watchdog, and the reset delay time is T reset =500ms.

[0011] Preferably, the chaotic system in step 3 is an improved Lorenz system: Where: σ: Prandtl number; ρ: Rayleigh number; β: geometry factor; PUF: PUF feature weighting function; p i : PUF feature bit.

[0012] Preferably, the step 4 further comprises: The successfully verified root hash value is written into the blockchain, generating a blockchain transaction containing the timestamp τ and the device ID: in: Real-time clock millisecond timestamp; K priv =Hash(PUF|R|SN): device private key, SN is the serial number.

[0013] Preferably, when in S com In the state, if the FLASH storage voltage V flash <V min , then trigger: S com →S pre ifV flash <2.7V; Where: V min =2.7V: minimum operating voltage of FLASH memory.

[0014] The present invention also provides an online upgrade system for embedded software of an intelligent washing machine, a server subsystem, comprising: Encrypted storage unit, used for AES-256-CBC encrypted upgrade files; Scheduled delivery unit, configure cron task scheduler; Wireless communication module, supporting MQTT / CoAP protocol; Security encryption module: used to perform device identity binding; Dynamic transmission module: used for adaptive data encoding transmission; Hierarchical verification module: used for multi-level data integrity verification; Transaction management module: used for atomic upgrade control; Safe rollback module: used for system status recovery.

[0015] In summary, the present invention includes at least one of the following beneficial technical effects: 1. This invention implements an end-to-end secure authentication system by binding unique device credentials and establishing an encrypted transmission channel. This solution leverages hardware features and cryptographic algorithms for dual protection, effectively preventing unauthorized access and firmware tampering.

[0016] 2. This invention uses a dynamic parameter adjustment mechanism based on channel quality, intelligently matching network coding schemes and block strategies. This technology automatically balances transmission rate and reliability based on real-time environmental changes, improving upgrade success rates under complex network conditions.

[0017] 3. This invention integrates fast packet verification with a layered verification architecture based on blockchain evidence storage, ensuring data integrity from reception to storage. This design, through a progressive verification mechanism, achieves deep security while ensuring efficiency.

[0018] 4. This invention uses a three-state transaction management model, combined with hardware protection circuitry, to ensure the atomicity and consistency of firmware write operations. This mechanism effectively prevents system state confusion caused by unexpected interruptions and ensures the reliable completion of the upgrade process. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] Figure 1 Flow chart of the method of the present invention. DETAILED DESCRIPTION

[0020] The following is combined with Figure 1 , the present invention is described in further detail.

[0021] This invention provides a method and system for online upgrading embedded software in smart washing machines. By binding unique device credentials and establishing an encrypted transmission channel, this system implements an end-to-end secure authentication system. This solution leverages hardware features and cryptographic algorithms to provide dual security, effectively preventing unauthorized access and firmware tampering.

[0022] like Figure 1 As shown, the online upgrade method of the embedded software of the smart washing machine includes the following steps: Step 1: The server stores the encrypted upgrade program file and calculates the checksum. It then sends the updated program file wirelessly at the set time. It generates a unique device credential based on a physically unclonable function and establishes device identity binding. Step 2: Based on the real-time channel quality parameters, the network coding parameters are dynamically calculated based on the device’s unique credentials; Step 3: Based on the network coding parameters, the upgrade data is dynamically divided into blocks and transmitted using network coding. During the transmission process, chaotic encryption is used to generate encrypted upgrade data packets. Step 4: Perform layered verification on the received encryption upgrade data packet, including packet-level cyclic redundancy check and shard hash tree verification; Step 5: Atomically commit the verified upgrade data through the three-state transaction management mechanism, including state transition control among the prepare state, commit state, and complete state. Step 6: When the layer verification fails or the state transfer times out, a safe rollback operation is triggered to restore to the state before the upgrade.

[0023] The implementation of step one involves a dual mechanism of server-side upgrade preparation and device-side identity authentication, building a trusted upgrade foundation by combining cryptographic algorithms with hardware features. The server uses AES-256-CBC encryption mode to process the upgrade program file, where the initialization vector (IV) is generated by a true random number generator integrated into the hardware security module (HSM), ensuring that the randomness of each encryption process meets cryptographic security requirements. The encrypted data packet is transmitted via the MQTT protocol within a preset time window, preferably set to 02:00 to 04:00 daily. This time period corresponds to the low load period of the home network, which can reduce the probability of channel conflicts.

[0024] The device-side identity binding process is implemented based on the Physical Unclonable Function (PUF), which extracts the initial power-on value of the SRAM memory inside the microcontroller unit as the PUF feature source. The feature set of 24 physical storage units is defined as: PUF = {p0, p1, ..., p 23}where p i ∈{0,1} 8 ; Each feature bit p i The initial state of the cell at SRAM address 0x2000+i is determined by the process deviation during chip manufacturing and is physically unique and cannot be cloned. To enhance the anti-cracking ability of the identity credential, the PUF feature is concatenated with the 128-bit true random number R, and the SHA3256 hash function is used to generate the device's unique public key: K pub =Hash(PUF|R); The symbol ∥ represents a byte-level concatenation operation. The true random number R is generated by the device's built-in quantum noise source TRNG module and stored in a one-time programmable (OTP) memory to prevent replay attacks during subsequent upgrades.

[0025] The encryption upgrade data packet adopts a structured encapsulation format, which includes four parts: protocol header, encrypted data, checksum and timestamp: Packet=(Header,EncryptedData,CRC32,Timestamp); The protocol header is embedded with the device unique identifier (ID) and the fragment sequence number field, where the device ID and the public key K pub One-way binding is performed to prevent device identity forgery. The timestamp field uses 64-bit Unix time format with millisecond accuracy to protect against replay attacks. The length of the encrypted data segment is preferably set to 256 bytes to match the dynamic block size parameter in subsequent steps.

[0026] During the identity authentication phase, the server verifies the legitimacy of the device through the preset device public key whitelist. The verification process uses a challenge-response mechanism, and the server generates a random number N s Sent to the device, the device uses the PUF private key K priv To digitally sign: Sign=ECDSA(K priv ,Hash(N s ∥R)); where K priv The private key is generated using a key derivation function using the PUF signature and the device serial number (SN), ensuring it cannot be exported. This mechanism effectively prevents man-in-the-middle attacks while also minimizing the security risks associated with key storage.

[0027] The scheduled delivery mechanism is implemented through a distributed task scheduler, synchronizing the status of upgrade tasks across the server cluster. When the preset time window arrives, the scheduler pushes encrypted upgrade packages in batches by device group. The grouping strategy is optimized based on device location and network operator to reduce cross-network transmission latency. Data packets are transmitted using the MQTT protocol with QoS level 1, ensuring at-least-once delivery, and using message ID deduplication to prevent duplicate processing.

[0028] This step establishes the fundamental security framework for the upgrade process by combining timing control, hardware signature encryption, and structured data encapsulation. The introduction of PUF technology fundamentally eliminates the possibility of device identity cloning, while the timing window mechanism effectively reduces the disruption of the upgrade process to daily user use. While ensuring security, this technical solution also accounts for the resource constraints of home IoT devices, providing a reliable authentication and data encryption foundation for subsequent steps.

[0029] In this embodiment, the implementation of step 2 is based on real-time channel state perception and adaptive coding strategy, and a balance between transmission efficiency and reliability is achieved through a dynamic parameter adjustment mechanism. The construction of the channel quality parameter set includes multi-dimensional physical layer indicators, which are defined as follows: C=(RSSI,SNR,P L ); The received signal strength indicator (RSSI) is directly obtained through the physical layer register of the wireless communication module. Its dimension is dBm, which represents the current signal attenuation level. The signal-to-noise ratio (SNR) is calculated by the baseband processor. The calculation formula is: Historical packet loss rate (P L ) is maintained using a sliding window statistical method, defined within the last 10 transmission cycles: This indicator reflects the long-term stability characteristics of the network environment and provides a historical reference for encoding parameters.

[0030] The calculation of dynamic block size introduces the hyperbolic tangent function to achieve nonlinear adjustment. The core formula is: B = 256 [1 + α tanh (β (RSSI - R0))]; The adjustment coefficient α is preferably set to 0.5 to control the amplitude of the block size change; the sensitivity factor β is set to 0.1 to adjust the slope of the RSSI response to block size; and the reference signal strength R0 is set to -75dBm, which corresponds to the medium strength threshold of a typical home WiFi signal. When the real-time RSSI is higher than R0, the tanh function outputs a positive value, increasing the block size to improve throughput; otherwise, the block size is reduced to enhance interference resistance.

[0031] The network coding parameters are determined using a hierarchical decision-making mechanism. First, the number of basic blocks n is calculated based on the historical transmission success rate variance θ2: θ2 is calculated by counting the transmission results of each shard during the last 20 upgrades, reflecting the fluctuation characteristics of channel quality. L And the channel attenuation factor λ is used to calculate the number of redundant blocks k: The decay factor λ is preferably set to 0.5 to adjust the impact of packet loss rate on redundancy. The exponential function is designed to rapidly increase redundancy at low packet loss rates and gradually saturate at high packet loss rates, avoiding excessive resource consumption.

[0032] The dynamic parameter update mechanism is event-driven, triggering recalculation when an RSSI change exceeding ±3dB or an SNR fluctuation exceeding 2dB is detected. The calculation process is optimized using fixed-point arithmetic, converting floating-point operations to Q15 format to accommodate the computational characteristics of embedded processors. All parameter calculation results are temporarily stored in dual-port RAM for direct access by the subsequent encoding and transmission module.

[0033] This step integrates real-time channel measurements with historical statistical data analysis to build an adaptive transmission parameter system. The introduction of a hyperbolic tangent function effectively smooths parameter fluctuations caused by sudden changes in signal strength, while redundant block calculation based on exponential relationships strikes a balance between reliability and efficiency. This technical solution enables transmission strategies to automatically adapt to complex and changing home network environments, providing an optimized parameter foundation for subsequent encrypted transmission.

[0034] In this embodiment, the implementation of step 3 is based on the fusion mechanism of Galois field network coding and chaotic dynamic encryption, and a secure transmission system is constructed through the synergy of matrix operations and nonlinear dynamic systems. m ) constructs a random reversible coding matrix G, whose dimensions are determined by the parameters n and k determined in the previous step: G∈GF(2 m ) (n+k)×n ; The field bit number m is preferably set to 8, corresponding to the byte alignment operation, which is convenient for embedded processor implementation. The matrix elements are generated using a pseudo-random number algorithm, and the initial seed value is generated by a linear feedback shift register (LFSR), and the determinant of any submatrix consisting of n rows is in GF(2 8 ) domain is not zero, ensuring the reversibility of the decoding process.

[0035] The generation of chaotic dynamic encryption keys relies on the improved Lorenz system, whose differential equation is defined as: The system parameters σ, ρ, and β are set to 10, 28, and 8 / 3 respectively, forming a classical chaotic attractor. The perturbation term f(PUF) is calculated from the device identity characteristics: This design injects the physical unclonability of the PUF into the chaotic system, strongly correlating the key sequence with the device's hardware characteristics. The numerical solution uses the fourth-order Runge-Kutta discretization method, with an optimal step size of 0.01, to balance computational accuracy and resource consumption.

[0036] During the key sequence generation process, the chaotic variable x i and y i Extract and combine the decimal part of the digits: The modulo-1 operation extracts the fractional portion of the chaotic trajectory, amplifying the sensitivity of the system's initial value. The exclusive-OR operation eliminates statistical deviations from the chaotic variables, enhancing the randomness of the key. The generated key sequence period, L, is preferably set to 1024, enabling low-memory key management through a circular buffer.

[0037] The encryption code transmission process performs the cascade operation of Galois field linear transformation and stream cipher encryption, and divides the original data into blocks X j ∈GF(2m)n is processed as follows: Matrix multiplication in GF(2 8) domain via a lookup table, preferably using a 256×256-byte precomputed multiplication table. XOR operations are performed at byte granularity to align with the byte alignment requirements of subsequent verification steps. Encrypted data packets are transmitted over the physical layer via time-division multiplexing, with the slice index and matrix version identifier embedded in the header of each data frame.

[0038] The dynamic blocking mechanism is linked to encoding parameters. When changes in channel quality trigger an adjustment to the block size B, the number of columns n in the encoding matrix G is updated synchronously, and the matrix parameters are notified to the receiving end via control messages. Matrix version management uses a rolling update strategy, retaining the old matrix for three transmission cycles after successful reception confirmation to prevent decoding failures caused by transmission delays.

[0039] This step combines the error correction capabilities of network coding with the unpredictability of chaotic encryption, improving transmission reliability while also protecting data confidentiality. The introduction of Galois Field operations effectively reduces the computational complexity of encoding and decoding, while the injection of PUF signatures into the chaotic system fundamentally eliminates the possibility of key cloning. This technical solution achieves an optimal balance of security and efficiency in resource-constrained embedded environments.

[0040] In this embodiment, step 4 uses a layered verification architecture to implement multi-level verification of data integrity, building defense in depth by combining packet-level rapid detection with fragmentation-level verification. The packet-level cyclic redundancy check (CRC) first performs a preliminary screening of the received data unit, defining the verification relationship as: CRC calc (D i )≡CRC recv ; Among them D i Represents the payload part of the i-th received data packet, CRC calc This is implemented using the 32-bit polynomial 0xEDB88320, and the checksum covers all data in the protocol header except the CRC field. The checksum calculation is performed by a hardware accelerator, preferably using the built-in CRC unit of the STM32 series chip to achieve single-cycle byte processing. Shard hash tree verification uses an improved Merkle tree structure, with leaf nodes generated from encrypted shard data: H j =SHA3-256(C j ∥j); Where j is the fragment number, which is bound to the packet header information to prevent location tampering. The intermediate node hash is generated by cascade calculation: H node =SHA3-256(H left ∥H right ∥Height); The height parameter Height is introduced to avoid hash conflicts between nodes at different levels. The root hash is ultimately generated by combining all first-level intermediate nodes: H root =SHA3-256(H1∥H2∥…∥H N ); This structure supports partial hash path verification, and when a single shard anomaly is detected, only log2N level proof data needs to be uploaded.

[0041] Root hash consistency verification is implemented through blockchain smart contracts, and the verification conditions are defined as: H root ≡H blockchain ; Among them H blockchain When an upgrade task is released, the server writes it to the blockchain, storing it in a composite key consisting of a timestamp τ and the device ID. The verification process invokes the Ethereum light node protocol, obtaining on-chain data through simplified payment verification (SPV), and employing the elliptic curve digital signature algorithm (ECDSA) to verify the authenticity of the data source.

[0042] The layered verification mechanism establishes a progressive verification process. Packets failing CRC verification trigger a direct retransmission mechanism, while hash tree verification anomalies initiate a shard-level repair process. All verified shard data is temporarily stored in a buffer memory with ECC verification until the root hash consistency is confirmed and released to the next processing stage. Intermediate state information generated during the verification process is backed up in non-volatile memory to prevent loss of verification progress due to unexpected power outages.

[0043] This step achieves a balance between resource efficiency and security by integrating lightweight validation with strong cryptographic verification mechanisms. The Merkle tree structure optimizes the amount of verification data, adapting to low-bandwidth IoT environments. The introduction of blockchain technology ensures the immutability of the verification baseline value, forming a decentralized trust anchor. This technical solution provides a multi-verified, reliable data source for subsequent atomic submissions.

[0044] In this embodiment, step 5 realizes atomic control of the upgrade process through the three-state transaction management mechanism, and adopts the finite state machine model to ensure that the system maintains consistency under abnormal circumstances. The state set is defined as: State∈S p re,S c om,S f in; The ready state S p re corresponding to the upgrade data is temporarily stored in the temporary storage area, and the submission state S c om executes the firmware image switching operation and completes the state S fIn updates the system boot configuration. Non-volatile storage of each state is implemented in a specific sector of FLASH. Independently powered FRAM is preferably used to store key state variables to prevent state loss due to power outages. State transition conditions are strictly defined by predicate logic. From the prepared state to the committed state, the universal quantifier constraint must be met: Where V is the set of data slices verified in step 4. The verification function Valid(v) checks the reversibility of the slice decryption results and the decoding matrix. This condition ensures that all slice data is complete and available before entering the critical write phase. The transition from the submitted state to the completed state depends on the FLASH operation status flag: S com →S fin :WriteFlag=Success; The write flag is set by the FLASH controller hardware and triggers an interrupt update after the page programming operation is completed. When a voltage fluctuation or write protection signal is detected, the controller automatically sets the error flag and blocks the state transition.

[0045] The atomic commit operation implements timeout rollback protection through the watchdog timer, and the decision function is defined as: Time threshold T max The optimal setting is 5 seconds, covering a typical FLASH write cycle. The state dwell time Δt is measured by a high-precision timer, and a compensation algorithm is used to eliminate the effects of clock drift. When a rollback operation is executed, the temporary area backup data is automatically restored and the state machine is reset to the initial state.

[0046] The transaction management mechanism enables the hardware write protection lock during state transition to prevent accidental modification of key configuration areas. com The write enable signal of the FLASH controller is directly coupled to the state machine output to ensure that the firmware area can be modified only in compliance state. The voltage monitoring circuit samples the VDD pin level in real time. When V flash When the voltage is less than 2.7V, the write operation is suspended immediately and the state rollback is triggered.

[0047] This step transforms the firmware upgrade process into a transactional operation with atomicity, consistency, isolation, and durability by introducing a transactional state control model. The collaborative design of hardware-level write protection and the state machine effectively prevents system crashes caused by partial writes, while the time constraint mechanism provides a deterministic recovery path for exception handling. This technical solution achieves near-database transaction-level reliability within the constraints of embedded resources.

[0048] In this embodiment, step six implements a multi-level anomaly detection and hierarchical recovery mechanism to achieve safe system rollback, building a comprehensive protection system that covers hardware failures, software errors, and operation timeouts. The anomaly detection subsystem includes three parallel monitoring channels: a CRC checksum exception flag, a state machine timeout signal, and a FLASH voltage monitoring interrupt. Triggering an anomaly in any channel initiates the rollback process, with priority being hardware failure > operation timeout > checksum error.

[0049] The rollback operation implements a dual-area recovery strategy, with the primary FLASH area at address 0x08000000 mirrored by the backup area at address 0x08060000. When a write failure is detected, the DMA controller automatically initiates data migration.

[0050] memcpy(0x08000000,0x08060000,size); The preferred hardware-accelerated bit-width transfer mode and 32-bit bus transmission ensure that the recovery process is completed within 10ms. After the recovery is completed, the bootloader verifies the backup area signature. The signature algorithm uses the device public key generated in step 1 for verification.

[0051] The hardware watchdog timer (WDT) provides the ultimate safeguard mechanism, forcing a reset when the recovery operation times out or the system deadlocks. Reset delay time T reset By configuring the prescaler, preferably set to 500ms, the state of key peripherals can be saved. The watchdog feeding signal is maintained by the various submodules of the state machine. If any module times out, the watchdog is not fed in time and a reset is triggered.

[0052] The voltage monitoring circuit realizes continuous sampling of analog quantity. flash When the voltage drops below 2.7V, the comparator directly cuts off the FLASH programming voltage and simultaneously sets the fault register. This hardware protection mechanism operates independently of the main processor, ensuring that unsafe writes are prevented even in the event of a system crash. The monitoring circuit includes a low-pass filter with a time constant of 100μs to effectively suppress false triggering caused by power supply noise.

[0053] The rollback process log is recorded in non-volatile memory and contains the exception type, timestamp, and system status snapshot. The log structure adopts a circular buffer design and defines: LogEntry=(ErrCode,τ,State,CRC32); The error code ErrCode is mapped to a predefined fault classification table, and the state information State contains key register dump data. The log upload mechanism is executed first after the system is reset and submitted to the server for analysis through the blockchain interface in step 4.

[0054] This step integrates hardware-level protection with software recovery strategies to ensure the system can be restored to a known safe state even in extreme abnormal situations. The dual-zone storage design eliminates single points of failure, while the hardware-based watchdog and voltage monitoring mechanisms overcome the reliability limitations of the software layer. This technical solution forms a complete closed loop from abnormality detection to state recovery, providing ultimate security for the firmware upgrade process.

[0055] The smart washing machine embedded software online upgrade system described below and the smart washing machine embedded software online upgrade method described above can refer to each other.

[0056] Smart washing machine embedded software online upgrade system, including: The server subsystem includes: Encrypted storage unit, used for AES-256-CBC encrypted upgrade files; Scheduled delivery unit, configure cron task scheduler; Wireless communication module, supporting MQTT / CoAP protocol; Security encryption module: used to perform device identity binding; Dynamic transmission module: used for adaptive data encoding transmission; Hierarchical verification module: used for multi-level data integrity verification; Transaction management module: used for atomic upgrade control; Safe rollback module: used for system status recovery.

[0057] The system of this embodiment can be used to execute the above method embodiments, and its principles and technical effects are similar, so they will not be repeated here.

[0058] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.

Claims

1. A method for online upgrading of embedded software of a smart washing machine, characterized in that: The following steps are involved: Step 1: The server stores the encrypted upgrade program file and calculates the checksum. It then sends the updated program file wirelessly at the set time. It generates a unique device credential based on a physically unclonable function and establishes device identity binding. Step 2: Dynamically calculating network coding parameters based on the device unique credential according to the real-time channel quality parameters; Step 3: Based on the network coding parameters, the upgrade data is dynamically divided into blocks and network coded for transmission, and chaotic encryption is used to generate encrypted upgrade data packets during the transmission process; Step 4: Perform layered verification on the received encryption upgrade data packet, including packet-level cyclic redundancy check and shard hash tree verification; Step 5: Atomically commit the verified upgrade data through the three-state transaction management mechanism, including state transition control among the prepare state, commit state, and complete state. Step 6: When the layer verification fails or the state transfer times out, a safe rollback operation is triggered to restore to the state before the upgrade.

2. The method for online upgrading of embedded software of a smart washing machine according to claim 1, characterized in that: The step one comprises: The upgrade program file is encrypted using AES-256-CBC mode, and the initialization vector is generated by a true random number on the server; The upgrade package is sent via the MQTT protocol from 02:00 to 04:00 every day. The data package format is: Packet=(Header,EncryptedData,CRC32,Timestamp); Among them: Header contains device ID and fragment sequence number; Extract the set of physical unclonable function features of the smart washing machine microcontroller unit: PUF={p0,p1,...,p 23 }pi∈{0,1} 8 ; The PUF feature is combined with a true random number to generate a unique public key for the device: Kpub = Hash(PUF||R); Where: R∈{0,1} 128 is a random sequence generated by a true random number generator; || represents a data concatenation operation; Hash(·) is a cryptographic hash function.

3. The method for online upgrading of embedded software of a smart washing machine according to claim 1, characterized in that: The step 2 of dynamically determining the data transmission strategy includes: Get the channel quality parameter set: C=(RSSI,SNR,P L ); Among them: RSSIdBm: received signal strength indicator; Signal-to-noise ratio; P L =N loss / N total : Historical packet loss rate; Calculate dynamic block size: B=256·[1+α·tanh(β(RSSI-R0))]; Where: α: block adjustment coefficient; β: signal strength sensitivity factor; R0: reference signal strength; Determine network coding parameters: Where: θ2: historical transmission success rate variance; λ: channel attenuation factor.

4. The method for online upgrading of embedded software of a smart washing machine according to claim 1, characterized in that: The step three includes: Construct a random reversible encoding matrix in a Galois field: G∈GF(2 m ) (n+k)×n ; Where: GF(2 m ) means 2 m Element Galois Field; m: the number of field bits; n and k: encoding parameters; Generate a chaotic dynamic encryption key sequence: Where: (x i ,y i ) is the numerical solution of the chaotic system; ⊕ represents the bitwise exclusive OR operation; Perform encrypted encoding transmission: Where: X j ∈GF(2 m ) n is the original data block; L is the key sequence period length.

5. The method for online upgrading of embedded software of a smart washing machine according to claim 1, characterized in that: The fourth step includes: Perform packet-level cyclic redundancy check: CRC calc (D i )≡CRC recv ; Where: D i For the i-th received data packet; CRC calc Is the calculated check code; CRC recv The checksum carried by the data packet; construct the shard Merkle hash tree: H node =Hash(H left ||H right ); H root =Hash(H1||H2||…||H N ); Among them: H node H is the hash value of the middle node of the tree; root is the root hash value; N is the total number of data shards; Verify root hash consistency: H root ≡H blockchain ; Among them: H blockchain The pre-set root hash stored for the blockchain.

6. The method for online upgrading of embedded software of a smart washing machine according to claim 1, characterized in that: The step five includes: Initialize the three-state transaction state machine: State∈{S pre ,S com ,S fin }; Where: S pre : Preparation state, store upgrade data in temporary area; S com : Submit state, execute program image switching; S fin : Completed state, update the system boot flag; Define the state transition conditions: S com →S fin :WriteFlag=Success; Where: V: data shard set; Valid(v): shard verification function; WriteFlag: FLASH write operation status flag; perform atomic commit operation: Where: Δt: state dwell time; T max : is the preset timeout threshold; Safe rollback operations include: When FLASH writing fails, the original firmware is restored from the backup area address 0x08060000; The system is reset by triggering the hardware watchdog, and the reset delay time is T reset =500ms.

7. The method for online upgrading of embedded software of a smart washing machine according to claim 4, characterized in that: The chaotic system in step 3 is an improved Lorenz system: Where: σ: Prandtl number; ρ: Rayleigh number; β: geometry factor; PUF feature weighting function; pi: PUF feature bit.

8. The method for online upgrading of embedded software of a smart washing machine according to claim 1, characterized in that: The step 4 further includes: The successfully verified root hash value is written into the blockchain, generating a blockchain transaction containing the timestamp τ and the device ID: in: Real-time clock millisecond timestamp; K priv =Hash(PUF||R||SN): device private key, SN is the serial number.

9. The method for online upgrading of embedded software of a smart washing machine according to claim 1, characterized in that: The state transition condition in step 5 also includes: When in S com In the state, if the FLASH storage voltage V flash <V min , then trigger: S com →S pre if V flash <2.7V; Where: V min =2.7V: minimum operating voltage of FLASH memory.

10. An online upgrade system for embedded software of a smart washing machine, according to the online upgrade method for embedded software of a smart washing machine according to any one of claims 1 to 9, characterized in that: include: The server subsystem includes: Encrypted storage unit, used for AES-256-CBC encrypted upgrade files; Scheduled delivery unit, configure cron task scheduler; Wireless communication module, supporting MQTT / CoAP protocol; Security encryption module: used to perform device identity binding; Dynamic transmission module: used for adaptive data encoding transmission; Hierarchical verification module: used for multi-level data integrity verification; Transaction management module: used for atomic upgrade control; Safe rollback module: used for system status recovery.

Citation Information

Cited By

  • Ground source heat pump system whole-process intelligent monitoring and energy efficiency management method

    CN121742323A