Method for modifying the memory contents of a main memory of a microcontroller without a separate memory management unit, application of such a method, microcontroller and vehicle

A method for dividing microcontroller memory into component blocks with defined management information allows flexible and efficient software updates without a memory management unit, addressing inflexibility and complexity issues.

JP2025534500APending Publication Date: 2025-10-15MERCEDES BENZ GROUP AG
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2025521006
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-10-14
Filing Date
2023-09-18
Publication Date
2025-10-15

Smart Images

  • Figure 2025534500000001_ABST
    Figure 2025534500000001_ABST
Patent Text Reader

Abstract

The present invention relates to a method for modifying memory contents of a main memory (1) of a microcontroller without a separate memory management unit, wherein a part of the main memory (1) is occupied by a base firmware (2). The method according to the invention is characterized in that when the base firmware (2) is introduced into the main memory (1), at least one component block (3) is written into the main memory (1) together, the component block (3) comprising code elements and memory management information for providing at least one firmware component and / or at least one application program component, and in that in order to modify at least a part of the code elements of the at least one component block (3), a processor of the microcontroller processes the memory management information and writes the written information into a location in the main memory (1) defined by the memory management information, and the memory management information of the modified component block (3) is updated.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a method for modifying the memory contents of a main memory of a microcontroller without a separate memory management unit, of the kind more precisely defined in the preamble of claim 1, to the application of such a method, to a microcontroller and to a vehicle equipped with such a microcontroller. [Background technology]

[0002] Microcontrollers, also known as systems-on-a-chip (SoCs), are used in a wide variety of devices and machines to solve a wide range of tasks, such as controlling household appliances and providing vehicle functionality.

[0003] The control commands executed by the microcontroller are stored in the form of source code on a storage medium. As is common in information technology systems, it may be necessary to install software updates, for example to close security gaps, fix bugs, or provide new features. The microcontroller may have a memory management unit (MMU), which is used to translate the virtual addresses of individual processes processed by the microcontroller into physical addresses on the storage medium used. When a software update is installed, it is necessary to modify the corresponding program code stored on the storage medium. This can be easily done using the memory management unit.

[0004] The tasks handled by a microcontroller are typically relatively simple. In addition, the microcontroller should be manufactured cost-effectively. For these reasons, the complexity of the microcontroller needs to be kept as low as possible. Therefore, the integration of a memory management unit into the microcontroller is often omitted. This makes it difficult to install software updates. Therefore, there is a need to provide a means to allow software updates to be installed on a microcontroller without a memory management unit.

[0005] A possible approach is known from German Patent Application Publication No. 102011106078, which discloses a vehicle unit and a method for operating it. The vehicle unit is a computing unit capable of independently performing software repairs. For this purpose, the vehicle unit has a microkernel architecture. For this purpose, the operating system is partitioned into a main operating system unit, a cryptographic unit, and a monitoring unit. Optionally, a policy unit may also be provided. A basic version of the operating system is stored on a flash drive as a backup image, and the cryptographic unit and monitoring unit monitor the operation of the main operating system unit and reinstall the operating system from the backup image in the event of a malfunction. The provision of a cryptographic unit and a monitoring unit eliminates the need for a separate memory controller. However, the vehicle unit disclosed therein is disadvantageous in that it is based on a microkernel architecture and has associated drawbacks such as slower execution speed, increased synchronization costs (synchronization load) for user processes, and limited hardware access for executed processes. The memory control functions are performed by the monitoring unit and cryptographic unit, which are designed as read-only units. This severely limits the flexibility of adapting the vehicle unit to changing boundary conditions, as the memory management logic cannot be adapted. Summary of the Invention [Problem to be solved by the invention]

[0006] The invention is based on the object of providing an improved method for modifying the memory content of a main memory of a microcontroller without a separate memory management unit, which method allows a particularly simple, reliable and flexible modification of the memory content. [Means for solving the problem]

[0007] According to the invention, this object is achieved by a method for modifying the memory content of a main memory of a microcontroller without a separate memory management unit, having the features of claim 1. Advantageous embodiments and developments, applications of such a method, a microcontroller and a vehicle equipped with such a microcontroller emerge from the claims dependent thereon.

[0008] A standard (generic) way of modifying the memory contents of the main memory of a microcontroller without a separate memory management unit, where a part of the main memory is occupied by the base firmware, is according to the invention: - when the base firmware is installed in the main memory, at least one component block is written together into the main memory, the component block including code elements and memory management information for providing at least one firmware component and / or at least one application program component; - to modify at least a portion of the code elements of at least one component block, the processor of the microcontroller processes the memory management information and writes the information to be written to a location defined by the memory management information in the main memory, so that the memory management information of the modified component block is updated; This improves the

[0009] The main memory of a microcontroller is not a working memory, also known as a random access memory (RAM), but rather a main data carrier containing the source code of the base firmware. For example, the main memory can be a flash memory device. To simplify the structure of the microcontroller, the integration of a memory management unit (MMU) is omitted. However, by using the method according to the present invention, it is possible to change the contents of the main memory after the initial data loading into the main memory. The instructions for controlling (activating) the main memory are themselves contained in a modifiable part of the data structure, which allows for particularly flexible adaptation of the control of the main memory. This allows for particularly flexible use of the microcontroller, even when boundary conditions change.

[0010] Base firmware is an immutable software framework that provides basic functionality. Additional functionality can then be added to this base firmware in the form of one or more component blocks. In addition to supplemental firmware components, application program components can also be written into component blocks, allowing the microcontroller to provide application programs. There are fixed rules, defined by memory management information, as to where in the component blocks information is found that allows the microcontroller's processor to access each associated location in main memory to modify the memory contents.

[0011] The respective information to be written, e.g., software updates, can be communicated to the microcontroller from the outside. The microcontroller has a suitable interface for this. For example, a storage medium such as a USB stick or an SD card can be inserted into a suitable read slot and the written information can be read from it. The microcontroller can also be connected (integrated) into an information technology network of several computing units, and the written information can be obtained via this network. The computing units of this network can be designed as communication modules, which allow information to be obtained via the Internet, e.g., via mobile radio.

[0012] "Writing" in this context means erasing, adding, or overwriting information already present in main memory. In some cases, new component blocks can be written to main memory and appended to existing component blocks. Thus, not only is the memory management information for the component block that was originally last in the chain of component blocks changed, but new memory management information is also defined for the newly created and appended component block.

[0013] Instead of adding a new component block to the existing chain of base firmware and component blocks, the entire contents of main memory may already be divided into base firmware and at least one component block. This one component block may be successively divided into multiple component blocks when memory contents are changed. For example, if main memory has a size of 256 MB, the base firmware occupies 20 MB of that, and a first component block containing additional firmware components occupies 60 MB, then the second (placeholder) component block is 176 MB in size. In this case, this second 176 MB component block may be divided into new second and third component blocks when the memory contents of main memory are changed, or this second 176 MB component block may be split into these component blocks. For example, when writing 56 MB of additional information to main memory, the 176 MB may be divided into a new second component block of 56 MB and a third component block of 120 MB. In this way, the available storage space in main memory may be successively divided into component blocks.

[0014] An advantageous development of the method comprises the following structure for each component block: a length section defining the length of the area occupied by each component block in main memory; a text section including code elements for providing at least one firmware component and / or at least one application program component; an input interface section that defines which input interface is read by each component block to read input data; an output interface section that defines which output interfaces are written by each component block to output output data; and a parameters section defining the execution frequency of firmware components and / or application program components that can be provided by each component block, and application memory requirement information defining the memory size that each firmware component and / or application program component occupies on the RAM of the microcontroller when executing, It is provided that the following is realized.

[0015] Here, the text section represents the relevant portion of the respective component block for providing a firmware component or application program component, and thus contains the actual "payload." In this case, the remaining sections represent memory management information accordingly.

[0016] The length section describes the size of the main memory contents described by each component block. In this case, a notation that can be handled for each main memory design (a notation that can be handled for the specification format and can be handled for the implementation) is chosen, such as file size, number of flash pages, address range, etc. The information is stored contiguously in main memory, creating a sequence or chain of written sections. The microcontroller can then determine exactly where each component block begins and ends in main memory by reading the appropriate written lengths of the portions written by the component blocks.

[0017] A program or program portion provided by each component block may need to read input data and provide output data after being processed by a processor. The input interface section contains information defining which input data needs to be read from which input interface. A component block may contain a single firmware component and / or a single application program component, or multiple firmware components and / or multiple application program components. In that case, for each individual firmware component or each individual application program component, there is a separate interface definition of which input interface and which output interface are used. The output interface section is therefore used to define, as appropriate for each of these program components, which output data is provided and the corresponding identifier of the output interface.

[0018] The parameter section informs (communicates with) the microcontroller how often each individual program component in the component block should be executed. Additionally, the parameter section contains information about how much memory each program component needs to allocate in RAM, ensuring that sufficient memory is allocated in RAM.

[0019] Each component block, i.e., each individual program component included in a component block, can call and use the functions of the base firmware. However, a program component cannot directly call other program components in other component blocks. Communication between component blocks is performed via corresponding input data and output data.

[0020] Here, the code elements contained in the component blocks must be compiled to be position-independent, since the order and location of the component blocks in main memory is unknown. Therefore, the use of global or static variables is not allowed. All information related to the component blocks is passed as function calls.

[0021] According to another advantageous embodiment of the method, variables representing output data that can be output by each component block are written to the microcontroller's RAM at microcontroller startup. "Microcontroller startup" here means that the base firmware is executed by the microcontroller's processor when the microcontroller boots up. A portion of the RAM is initially filled with variables. These variables are representative of the output data that can be generated by the program components of the component blocks. This allows each program component to write its output data to RAM even after the output data has been processed by the processor. These variables can be aggregated into one or more swap files.

[0022] Another advantageous embodiment of the method comprises, at start-up of the microcontroller, determining for each component block, taking into account the respective memory management information, the following information: a mapping structure defining the locations in RAM where the output data that can be generated by each component block is written and the allocation of memory areas in RAM where the input data required by each component block is stored; a function sequence structure defining the order of the respective functions to be processed by the processor to provide the firmware components and / or application program components that can be provided by the respective component blocks; and For each firmware component and / or each application program component of each component block, an output structure defining output data to be written by the respective firmware component and / or application program component; is written to the RAM of the microcontroller.

[0023] Again, "microcontroller boot-up" refers to the execution of the base firmware by the processor when the microcontroller starts up. The mapping structure describes where these variables are written in RAM and, correspondingly, which program components generate which output data and read which input data. This allows each program component, i.e., each firmware component or application program component, to reliably read and output the information it processes.

[0024] The function sequence structure informs (communicates) the microcontroller in what order the program components contained in the component block should be executed to provide a particular function.

[0025] In other words, the output structure describes what variables are output by each program component.

[0026] An input or output interface can be defined with a unique name, a unique version identifier, and a unique (file) size. Variables are passed through each interface. Individual variables can have different sizes.

[0027] Each program component that is executed is passed a pointer to its respective mapping structure each time it is executed.

[0028] In this case, a zero pointer, also known as a NULL pointer, can be passed, allowing individual program components to be arbitrarily considered non-existent.

[0029] The sequence defined via the function sequence structure represents function pointers (function pointers), which are initially formed by the beginning of each text section containing the basic elements of each program component.

[0030] When initializing the microcontroller, the base firmware goes through each component block, reserves the aforementioned areas of RAM, and writes the aforementioned pointers to RAM according to the mapping structure.

[0031] According to another advantageous embodiment of the method according to the invention, each component block is granted direct hardware access to the hardware components of the microcontroller. Thus, individual program components of a component block can be granted or forbidden direct access to the hardware of the microcontroller. The more program components have access to the hardware, the smaller the base firmware can be designed.

[0032] Preferably, write access to RAM is restricted before execution of at least one firmware component and / or at least one application program component of each component block, so that for each component block, only output data that can be output by the respective component block can be written to RAM. In other words, before the components are executed, a memory protection unit (MPU) can be configured so that only the respective portions of RAM to which the output data of each program component is written can be written. This ensures the "freedom of interference" required by ISO 26262.

[0033] The application of the above-described method according to the present invention provides a use for performing software updates of programs stored in the main memory of a microcontroller, in particular for updating the firmware of the microcontroller. Using the method according to the present invention, it is also possible to change the memory contents of the respective main memory of a microcontroller that does not have a separate memory management unit. In this way, programs processed by the microcontroller can be updated, and even new programs can be imported. The firmware of the microcontroller can also be modified in a particularly advantageous manner. For this purpose, the firmware is divided into a base firmware and firmware components provided in component blocks. Here, the base firmware provides basic instructions for controlling the hardware used, for reading the associated interfaces and for addressing the hardware components. The firmware components of the component blocks contain additional functions.

[0034] Furthermore, a microcontroller according to the invention is configured to carry out the above-described method.

[0035] According to the invention, the vehicle is equipped with at least one such microcontroller.

[0036] Further advantageous embodiments of the method according to the invention for modifying the memory content of a main memory of a microcontroller without a separate memory management unit also become apparent from exemplary embodiments which are explained in more detail below with reference to the figures. [Brief explanation of the drawings]

[0037] [Figure 1] 1 is a schematic diagram of the contents of the main memory and working memory of a microcontroller according to the invention; [Figure 2] 10 is a diagram showing the contents of a component block written to the main memory in addition to the base firmware, the contents of which are divided into the contents of the main memory and the contents of the working memory. FIG. DETAILED DESCRIPTION OF THE INVENTION

[0038] Figure 1 shows the main memory 1 and the working memory, also called random access memory (RAM) 4, of a microcontroller according to the invention. The main memory 1 is in particular a flash memory device. Information is stored contiguously in the main memory 1. This information is the source code for implementing various programs. The information is linked together to form a chain.

[0039] A base firmware 2 is shown, followed by at least one component block 3. In the exemplary embodiment shown in FIG. 1, the main memory has a number of component blocks 3, labeled K1 to KN. The main memory 1 may have free memory, and further component blocks 3 are introduced into the main memory 1 when the memory content of the main memory 1 is changed according to the method according to the invention. It is also possible that the main memory 1 is already completely divided into component blocks 3. In this case, a particularly large component block 3 may exist, which may be divided into further component blocks 3 when the content of the main memory 1 is changed. Such component blocks 3 may be understood as placeholders.

[0040] 1 further shows the contents of RAM 4. One can see the base firmware section 2.1 and at least one stack 5, also known as a swap file. The stack 5 stores the compiled code of the corresponding programs executed by the microcontroller's processor, as well as the data each program needs to process. If the processor or microcontroller is configured for parallel processing, also known as multithreading, there may be a separate stack 5 for each task, as shown.

[0041] Furthermore, RAM 4 contains interface information 6 which describes, for each program component, i.e., firmware component and / or application program component, included in component block 3, which input and output interfaces are linked to each other and how they are linked.

[0042] 2 again shows in detail the contents written to the main memory 1 and RAM 4 of each component block 3. Each component block 3 (here, illustratively K1) contains information written to the main memory 1 in the form of a length section 3.1, a text section 3.2, an input interface section 3.3, an output interface section 3.4, and a parameter section 3.5.

[0043] Length section 3.1 defines the area occupied by each component block 3 in main memory 1. Because the component blocks 3 are informationally linked together, this allows the microprocessor to recognize the beginning and end of each of all component blocks 3 and therefore jump directly to each component block 3 in main memory 1 for write or read access.

[0044] Text section 3-2 represents the actual payload of component block 3 and contains code sections for providing the respective firmware or application program components. This is position-independent code, i.e., code that is compiled independently of position, since the order and position of the respective program components from component block 3 is unknown per se.

[0045] Input Interface Section 3.3 describes what input data is required by each program component. Correspondingly, Output Interface Section 3.4 describes what output data is generated by each program component. Input Interface Section 3.3 and Output Interface Section 3.4 can be described by Interface Specification 7, which uniquely describes identifiers such as the name, version information, and / or size of each interface.

[0046] Finally, parameters section 3.5 describes how often each program component of each component block 3 is executed by the microprocessor and how much memory size in the form of each stack 5 or a corresponding percentage of stack 5 is required on RAM 4 by each program component.

[0047] Also shown is the RAM contents of each component block 3. The mapping structure 4.1, function sequence structure 4.2, and output structure 4.3 of each program component can be seen.

[0048] Mapping structure 4.1 describes the structure of pointers to each input and output interface used by component block 3. Functional sequence structure 4.2 describes the order in which each program component contained in component block 3 is processed by the microprocessor. After each program component is processed, output data is finally written to the respective output structure 4.3. [Prior art documents] [Patent documents]

[0049] [Patent Document 1] German Patent Application Publication No. 102011106078

Claims

1. A method for modifying memory contents of a main memory (1) of a microcontroller without a separate memory management unit, wherein a part of said main memory (1) is occupied by a base firmware (2), comprising: - when the base firmware (2) is installed in the main memory (1), at least one component block (3) is written into the main memory (1) together with the base firmware (2), the component block (3) containing code elements and memory management information for providing at least one firmware component and / or at least one application program component; - to modify at least a part of the code element of at least one component block (3), a processor of the microcontroller processes the memory management information and writes the information to be written to a location in the main memory (1) defined by the memory management information, and the memory management information of the modified component block (3) is updated. A method characterized by:

2. For each component block (3), the following structure: a length section (3.1) defining the length of the area occupied by each of said component blocks (3) on said main memory (1); a text section (3.2) containing said code elements for providing said at least one firmware component and / or at least one application program component; an input interface section (3.3) that defines which input interface is read by each of said component blocks (3) to read input data; an output interface section (3.4) that defines which output interface is written by each component block (3) to output output data, and a parameters section (3.5) defining the execution frequency of the firmware and / or application program components that can be provided by each component block (3) and application memory requirement information that defines the memory size that will be occupied on the RAM (4) of the microcontroller when executing each firmware and / or application program component; is realized 2. The method of claim 1.

3. At the start-up of the microcontroller, variables representing output data that can be output by each component block (3) are written into the RAM (4) of the microcontroller.

3. The method according to claim 1 or 2.

4. Upon startup of the microcontroller, for each component block (3) the following information is obtained, taking into account the respective memory management information: a mapping structure (4.1) defining the locations in the RAM (4) where output data producible by each of the component blocks (3) will be written and the allocation of memory areas in the RAM (4) where input data required by each of the component blocks (3) will be stored; a function sequence structure (4.2) defining the respective order of functions to be processed by the processor in order to provide the firmware components and / or application program components that can be provided by the respective component blocks (3); and - for each firmware component and / or each application program component of said respective component block (3), an output structure (4.3) defining the output data to be written by said respective firmware component and / or application program component; is written to the RAM (4) of the microcontroller The method according to any one of claims 1 to 3, characterized in that

5. Each component block (3) is allowed direct hardware access to the hardware components of the microcontroller. The method according to any one of claims 1 to 4, characterized in that

6. For each of the component blocks (3), write access to the RAM (4) is restricted before execution of the at least one firmware component and / or at least one application program component of each of the component blocks (3) so that only output data that can be output by the respective component block (3) can be written to the RAM (4). The method according to any one of claims 1 to 5, characterized in that

7. Application of the method according to any one of claims 1 to 6, characterized by its use for performing software updates of programs stored in the main memory (1) of the microcontroller, in particular for updating the firmware of the microcontroller.

8. A microcontroller characterized by being configured to carry out the method according to any one of claims 1 to 6.

9. A vehicle characterized by at least one microcontroller according to claim 8.

Citation Information

Patent Citations

  • Method of transmitting update data of software and computer

    JP2008065507A

  • Plug-in equipped updateable firmware

    US6789157B1

  • Processing system with component architecture platform support

    US7472380B1

  • Vehicle unit and method for operating the vehicle unit

    DE102011106078A1