Method and apparatus for upgrading multi-core heterogeneous system on chip
By selecting different memory slots for the MCU and MPU as working and backup slots in a multi-core heterogeneous on-chip system, and synchronizing the slots during upgrades, the problem of the inability of the MCU and MPU to be upgraded independently is solved, realizing a flexible upgrade strategy and improving the robustness and security of the system.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- BEIJING JINGWEI HIRAIN TECH CO INC
- Filing Date
- 2022-12-16
- Publication Date
- 2026-06-16
AI Technical Summary
In the process of upgrading multi-core heterogeneous on-chip systems, the MCU and MPU cannot adopt different upgrade strategies, which limits the flexibility and security of the upgrade.
When the on-chip system is in normal working condition, the MCU and MPU select different memory slots as working and backup memory slots respectively. When an upgrade command is received, the upgrade image of each is written to the backup memory slot. After the system is restarted, the slots are synchronized, thus achieving decoupling of the upgrade of the MCU and MPU.
It achieves decoupling of MCU and MPU upgrades, allowing different upgrade strategies to be adopted, improving the robustness and security of the system, while ensuring the efficiency of online upgrades.
Smart Images

Figure CN116088914B_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of automotive electronics technology, and in particular relates to a method and apparatus for upgrading a multi-core heterogeneous system-on-a-chip. Background Technology
[0002] A System-on-a-Chip (SoC) consists of a Microcontroller Unit (MCU) and a Microprocessor Unit (MPU). The SoC uses two different sizes of non-volatile memory: a smaller one for the MCU and a larger one for the MPU. The memory primarily stores code and data. To ensure the security of SoC upgrades, the memory is divided into two slots. Each memory has its own slot management logic, determining which slot is the currently running slot and which is the backup slot. During an upgrade, the MCU and MPU may be upgraded individually, or both may be upgraded simultaneously.
[0003] When a multi-core heterogeneous SoC is upgraded using Over-the-Air (OTA) technology, to support features such as failure rollback, the two types of memory are uniformly divided into two slots: one slot is the currently running slot, and the other is a backup slot. During an OTA upgrade, the new image for the upgrade is first stored in the backup slot, the SoC is restarted, and after verifying a successful upgrade, the backup slot is switched to the currently running slot, while the previously running slot is switched back to the backup slot.
[0004] In this upgrade method, the MCU and MPU share the same slot for upgrade, which means that the slots of the MCU and MPU can only use the same upgrade strategy, and cannot use different upgrade strategies. Summary of the Invention
[0005] This application provides a method and apparatus for upgrading a multi-core heterogeneous system-on-a-chip, which can solve the problem that MCUs and MPUs cannot be upgraded using different upgrade strategies.
[0006] In a first aspect, embodiments of this application provide a method for upgrading a multi-core heterogeneous system-on-a-chip. The system-on-a-chip includes a microcontroller and a microprocessor. The system-on-a-chip is externally connected to a non-volatile flash memory and an embedded multimedia card (eMMC). The non-volatile flash memory includes a first storage slot and a second storage slot. The first storage slot and the second storage slot are storage slots with the same content. The embedded multimedia card includes two storage slots with different content.
[0007] Upgrade methods for multi-core heterogeneous on-chip systems include:
[0008] When the on-chip system is in normal working condition, the microcontroller selects the first storage slot and the second storage slot as the working storage slot and the backup storage slot, respectively. The microprocessor selects the currently running storage slot among the two storage slots with different contents as the working storage slot and uses the other storage slot as the backup storage slot.
[0009] Upon receiving an upgrade instruction, the upgrade images of the microcontroller and microprocessor are written to their respective backup storage slots.
[0010] Reboot the on-chip system;
[0011] If the on-chip system successfully restarts, the first and second storage slots are synchronized, and the on-chip system upgrade is complete.
[0012] Secondly, embodiments of this application provide a multi-core heterogeneous system-on-a-chip upgrade device, comprising:
[0013] The selection module is used so that, when the on-chip system is in normal working condition, the microcontroller selects the first storage slot and the second storage slot as the working storage slot and the backup storage slot, respectively, and the microprocessor selects the currently running storage slot of the two storage slots with different contents as the working storage slot and uses the other storage slot as the backup storage slot.
[0014] The first writing module is used to write the upgrade images of the microcontroller and the microprocessor into their respective backup storage slots upon receiving an upgrade instruction.
[0015] The reboot module is used to reboot the on-chip system.
[0016] The first synchronization module is used to synchronize the first storage slot with the second storage slot when the on-chip system restarts successfully, thus completing the on-chip system upgrade.
[0017] In this embodiment, the system-on-a-chip (SoC) includes a microcontroller unit (MCU) and a microprocessor. The SoC is externally connected to a non-volatile flash memory and an embedded multimedia card. The non-volatile flash memory includes a first storage slot and a second storage slot, both containing identical content. The embedded multimedia card includes two storage slots with different content. When the SoC is in normal operation, the MCU selects the first and second storage slots as the working and backup storage slots, respectively. The microprocessor selects the currently running storage slot from the two different storage slots as the working storage slot and the other as the backup storage slot. Upon receiving an upgrade command, the upgrade images of the MCU and microprocessor are written to their respective backup storage slots. The SoC is then restarted. If the SoC restarts successfully, the first and second storage slots are synchronized, completing the SoC upgrade. Thus, the MCU and microprocessor can use different storage slots for upgrades, achieving decoupling of the MCU and microprocessor upgrades and enabling them to employ different upgrade strategies. Attached Figure Description
[0018] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0019] Figure 1 This is a flowchart illustrating the multi-core heterogeneous on-chip system upgrade method provided in an embodiment of this application;
[0020] Figure 2 This is a schematic diagram of the state changes of a multi-core heterogeneous on-chip system provided in an embodiment of this application;
[0021] Figure 3 This is a schematic diagram of the structure of the multi-core heterogeneous system-on-a-chip upgrade device provided in the embodiments of this application. Detailed Implementation
[0022] The features and exemplary embodiments of various aspects of this application will be described in detail below. To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain this application and not to limit it. For those skilled in the art, this application can be implemented without some of these specific details. The following description of the embodiments is merely to provide a better understanding of this application by illustrating examples.
[0023] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes said element.
[0024] The multi-core heterogeneous system-on-a-chip upgrade method and apparatus provided in this application will be described in detail below with reference to the accompanying drawings, through specific embodiments and application scenarios.
[0025] Figure 1 This is a flowchart illustrating the multi-core heterogeneous system-on-a-chip (SoC) upgrade method provided in this application embodiment. The multi-core heterogeneous SoC in this application embodiment may include: a microcontroller unit and a microprocessor; the SoC is externally connected to non-volatile flash memory and an embedded multimedia card; the non-volatile flash memory includes a first storage slot and a second storage slot, the first and second storage slots having identical content; and the embedded multimedia card includes two storage slots with different content.
[0026] like Figure 1 As shown, the upgrade method for multi-core heterogeneous on-chip systems may include:
[0027] S101: When the on-chip system is in normal working condition, the microcontroller selects the first storage slot and the second storage slot as the working storage slot and the backup storage slot, respectively. The microprocessor selects the currently running storage slot among the two storage slots with different contents as the working storage slot and uses the other storage slot as the backup storage slot.
[0028] S102: Upon receiving an upgrade instruction, write the upgrade images of the microcontroller and microprocessor to their respective backup storage slots.
[0029] S103: Reboot the on-chip system;
[0030] S104: If the on-chip system restarts successfully, synchronize the first storage slot with the second storage slot, and the on-chip system upgrade is complete.
[0031] The specific implementation methods of each of the above steps will be described in detail below.
[0032] In this embodiment, the system-on-a-chip (SoC) includes a microcontroller unit (MCU) and a microprocessor. The SoC is externally connected to a non-volatile flash memory and an embedded multimedia card. The non-volatile flash memory includes a first storage slot and a second storage slot, both containing identical content. The embedded multimedia card includes two storage slots with different content. When the SoC is in normal operation, the MCU selects the first and second storage slots as the working and backup storage slots, respectively. The microprocessor selects the currently running storage slot from the two different storage slots as the working storage slot and the other as the backup storage slot. Upon receiving an upgrade command, the upgrade images of the MCU and microprocessor are written to their respective backup storage slots. The SoC is then restarted. If the SoC restarts successfully, the first and second storage slots are synchronized, completing the SoC upgrade. Thus, the MCU and microprocessor can use different storage slots for upgrades, achieving decoupling of the MCU and microprocessor upgrades and enabling them to employ different upgrade strategies.
[0033] In some possible implementations of the embodiments of this application, the microcontroller may always select the first storage slot as its working storage slot.
[0034] For example, the non-volatile flash memory includes slot A and slot B. When the on-chip system is operating normally, the microcontroller always selects slot A of the non-volatile flash memory as its working slot and slot B as its backup slot. If the working slot of the microcontroller malfunctions, the backup slot will be activated to improve the robustness and security of the microcontroller. The embedded multimedia card also includes a set of slots A and B. When the on-chip system is operating normally, the microprocessor selects the currently running slot of the embedded multimedia card as its working slot. For example, if slot A of the embedded multimedia card is the currently running slot, then the microprocessor selects slot A of the embedded multimedia card as its working slot and slot B as its backup slot. When the working slot of the microprocessor malfunctions, the backup slot of the microprocessor will not be activated. Because the upgrade image of the microcontroller is much smaller than that of the microprocessor, and critical functions are concentrated in the microcontroller, using two different strategies for upgrading the microcontroller and microprocessor can ensure the efficiency of online upgrades while improving the overall robustness and security of the on-chip system.
[0035] Upon receiving the upgrade command from the OTA manager (master), the upgrade image of the microcontroller is written to slot B of the non-volatile flash memory, and the upgrade image of the microprocessor is written to slot B of the embedded multimedia card; the on-chip system is restarted; if the on-chip system restarts successfully, slot A of the non-volatile flash memory is synchronized with slot B of the non-volatile flash memory, that is, slot B of the non-volatile flash memory is synchronized to slot A of the non-volatile flash memory, and the upgrade of the multi-core heterogeneous on-chip system is completed.
[0036] In some possible implementations of the embodiments of this application, since the microcontroller always selects the first storage slot as its working storage slot, it is necessary to keep the images in the first storage slot and the second storage slot consistent. Therefore, it is necessary to synchronize the first storage slot and the second storage slot.
[0037] In some possible implementations of the embodiments of this application, before S102, the multi-core heterogeneous on-chip system upgrade method provided in the embodiments of this application may further include: writing upgrade flags to the microcontroller and microprocessor to enable the on-chip system to enter the update_begin state.
[0038] In some possible implementations of the embodiments of this application, before S103, the multi-core heterogeneous system-on-a-chip upgrade method provided in the embodiments of this application may further include: modifying the state of the system-on-a-chip to the image_ready state.
[0039] In some possible implementations of the embodiments of this application, after S103, the multi-core heterogeneous on-chip system upgrade method provided in the embodiments of this application may further include: modifying the state of the on-chip system to the start upgrade verification (verify_begin) state, wherein, when the on-chip system is in the start upgrade verification state, the value of the field used to store the upgrade verification state is modified to a value used to indicate that it cannot be started.
[0040] The field used to store the upgrade verification status can be `verify_status`, and the value indicating that the system cannot start can be `unbootable`. When the value of the `verify_status` field is `unbootable`, if the on-chip system restarts unsuccessfully, it will restart again. At this time, because the value of `verify_status` is `unbootable`, the on-chip system will enter a rollback state after restarting.
[0041] In some possible implementations of the embodiments of this application, before S104, the multi-core heterogeneous system-on-a-chip upgrade method provided in the embodiments of this application may further include: modifying the state of the system-on-a-chip to the upgrade verification successful (verify_succ) state.
[0042] In some possible implementations of the embodiments of this application, before S104, the multi-core heterogeneous on-chip system upgrade method provided in the embodiments of this application may further include: communicating with the upgrade management component (OTA master) to confirm whether the upgrade is successful; and if the upgrade management component confirms that the upgrade is successful, changing the status of the on-chip system to the upgrade successful (update_succ) status.
[0043] Typically, the OTA master manages multiple chips simultaneously. During an upgrade, multiple chips are upgraded. The OTA master confirms the upgrade is successful only when it verifies that all chips have been successfully upgraded. This application does not limit the method used by the OTA master to confirm the success of the upgrade; any available method can be applied. When the OTA master confirms the upgrade is successful, it changes the on-chip system's status to "upgrade successful."
[0044] In some possible implementations of the embodiments of this application, before S104, the multi-core heterogeneous on-chip system upgrade method provided in the embodiments of this application may further include: modifying the state of the on-chip system to the start synchronization (sync_begin) state.
[0045] In some possible implementations of the embodiments of this application, after S104, the multi-core heterogeneous on-chip system upgrade method provided in the embodiments of this application may further include: modifying the state of the on-chip system to the sync_finish state.
[0046] In some possible implementations of the embodiments of this application, after S104, the multi-core heterogeneous on-chip system upgrade method provided in the embodiments of this application may further include: clearing the upgrade flag; and modifying the state of the on-chip system to a normal working state.
[0047] In some possible implementations of the embodiments of this application, the multi-core heterogeneous on-chip system upgrade method provided in the embodiments of this application may further include: performing an upgrade rollback when the upgrade rollback conditions are met, wherein meeting the upgrade rollback conditions includes any one of the following:
[0048] The upgrade image failed to be written to the backup storage slot.
[0049] The upgrade management component was confirmed to have failed.
[0050] An upgrade interrupt command was received;
[0051] The on-chip system failed to restart.
[0052] In some possible implementations of the embodiments of this application, performing an upgrade rollback may include: restarting the on-chip system; synchronizing the second storage slot with the first storage slot.
[0053] It should be noted that, for the microcontroller unit, since the first and second storage slots contain identical content, the microcontroller unit always selects the first storage slot as its working storage slot. Therefore, it is necessary to maintain consistency between the images in the first and second storage slots. Thus, during upgrade rollback, the second storage slot needs to be synchronized with the first storage slot. For the microprocessor, since the embedded multimedia card includes two storage slots with different content, during upgrade rollback, it is simply a matter of reselecting the working storage slot from before the upgrade.
[0054] In some possible implementations of the embodiments of this application, before upgrading and rolling back the system on-chip and restarting the system on-chip, the multi-core heterogeneous system on-chip upgrade method provided in the embodiments of this application may further include: modifying the state of the system on-chip to an upgrade rollback state.
[0055] In some possible implementations of the embodiments of this application, after synchronizing the second storage slot with the first storage slot, the multi-core heterogeneous system-on-a-chip upgrade method provided in the embodiments of this application may further include: modifying the state of the system-on-a-chip to the synchronization completed state; clearing the upgrade flag; and modifying the state of the system-on-a-chip to the normal working state.
[0056] In some possible implementations of the embodiments of this application, before synchronizing the second storage slot with the first storage slot, the multi-core heterogeneous system-on-a-chip upgrade method provided in the embodiments of this application may further include: modifying the state of the system-on-a-chip to the start synchronization state.
[0057] In some possible implementations of the embodiments of this application, before synchronizing the second storage slot with the first storage slot, the multi-core heterogeneous system-on-a-chip upgrade method provided in the embodiments of this application may further include: modifying the state of the system-on-a-chip to an update failure state.
[0058] It should be noted that, in the embodiments of this application, synchronizing the first storage slot and the second storage slot means updating the content in the first storage slot to be the same as the content in the second storage slot, that is, using the content in the second storage slot to overwrite the content in the first storage slot; in the embodiments of this application, synchronizing the second storage slot and the first storage slot means updating the content in the second storage slot to be the same as the content in the first storage slot, that is, using the content in the first storage slot to overwrite the content in the second storage slot.
[0059] In some possible implementations of this application's embodiments, the state of the on-chip system can be determined by the states of the two non-volatile flash memory slots and the two embedded multimedia card slots, wherein the states of the two non-volatile flash memory slots and the two embedded multimedia card slots are represented by some field values. For example, when the on-chip system is currently in a normal state, the microcontroller selects slot A of the non-volatile flash memory as its working slot, and the microprocessor selects slot A, currently running on the embedded multimedia card, as its working slot. The correspondence between the on-chip system's state and the field values of the storage slots can then be shown in Table 1.
[0060] Table 1
[0061]
[0062] In Table 1 above, the `sync` field represents the upgrade flag. When the `sync` field is F, it indicates that the microcontroller unit is being upgraded. The `slot` field represents the currently started slot. The `verify_status` field is used to represent the status of each stage. Here, `X` represents the initial value, which can be any value. `bootable` indicates that the on-chip system can be restarted, `unbootable` indicates that the on-chip system cannot be restarted, `verified` indicates verification, `begin_sync` indicates the start of synchronization, the `succ` field represents the storage slot status. When the `succ` field is T, it indicates that the storage slot is in the started state. When the `succ` field is 0, it indicates that the storage slot is in the upgrade state. The `pri` field is used to represent the priority of the storage slot. The microprocessor selects the storage slot with the higher priority as the working storage slot. When the `pri` field is 0, it indicates that the storage slot is in the upgrade state.
[0063] Figure 2 This is a schematic diagram of the state changes of a multi-core heterogeneous on-chip system provided in an embodiment of this application.
[0064] exist Figure 2 When the on-chip system is in normal working condition, restarting the on-chip system will restore it to normal working condition.
[0065] When the on-chip system receives an upgrade command while in normal working condition, it writes an upgrade flag and enters the upgrade start state.
[0066] After successfully writing the upgrade images of the microcontroller and microprocessor into their respective backup storage slots, the system-on-chip enters the upgrade image ready state.
[0067] When the system-on-a-chip is in the upgrade image ready state, the system-on-a-chip is restarted, and at the same time, the system-on-a-chip enters the upgrade verification state.
[0068] After the on-chip system successfully reboots, it enters the upgrade verification success state. At this point, the upgrade image starts successfully on the backup slot.
[0069] When the on-chip system is in the upgrade verification successful state, it communicates with the OTA master to confirm the upgrade. Once the OTA master confirms the successful upgrade, the on-chip system enters the upgrade successful state. Then, the on-chip system enters the synchronization start state.
[0070] When the system-on-chip (SoC) is in the synchronization start state, the backup storage slot of the microcontroller unit is synchronized to the working storage slot. After the backup slot of the storage slot is synchronized to the working slot, the storage slot enters the synchronization complete state. Then, the upgrade flag is cleared, and the SoC enters the normal operation state.
[0071] When the upgrade image fails to be written to the backup slot, the on-chip system fails to restart, or the OTA master confirms the failure, the on-chip system enters the upgrade rollback state.
[0072] When the system-on-a-chip (SoC) is in an upgrade rollback state, it is restarted. After a successful restart, the SoC enters an upgrade failure state. Then, the SoC enters a synchronization start state.
[0073] When the system-on-a-chip (SoC) is in the initial synchronization state during upgrade rollback, the working storage slot of the microcontroller unit (MCU) is synchronized to the backup storage slot. After the working storage slot of the MCU is synchronized to the backup storage slot, the SoC enters the synchronization completion state. Then, the upgrade flag is cleared, and the SoC enters normal operation.
[0074] This application also provides a multi-core heterogeneous system-on-a-chip upgrade device, such as... Figure 3 As shown. Figure 3 This is a schematic diagram of the structure of the multi-core heterogeneous system-on-a-chip upgrade device provided in the embodiments of this application. The multi-core heterogeneous system-on-a-chip upgrade device 300 may include:
[0075] The selection module 301 is used to select the first storage slot and the second storage slot as the working storage slot and the backup storage slot respectively when the on-chip system is in normal working state. The microcontroller selects the currently running storage slot among the two storage slots with different contents as the working storage slot and uses the other storage slot as the backup storage slot.
[0076] The first writing module 302 is used to write the upgrade images of the microcontroller and the microprocessor into their respective backup storage slots upon receiving an upgrade instruction.
[0077] Reboot module 303 is used to reboot the on-chip system;
[0078] The first synchronization module 304 is used to synchronize the first storage slot with the second storage slot when the on-chip system restarts successfully, thus completing the on-chip system upgrade.
[0079] In this embodiment, the system-on-a-chip (SoC) includes a microcontroller unit (MCU) and a microprocessor. The SoC is externally connected to a non-volatile flash memory and an embedded multimedia card. The non-volatile flash memory includes a first storage slot and a second storage slot, both containing identical content. The embedded multimedia card includes two storage slots with different content. When the SoC is in normal operation, the MCU selects the first and second storage slots as the working and backup storage slots, respectively. The microprocessor selects the currently running storage slot from the two different storage slots as the working storage slot and the other as the backup storage slot. Upon receiving an upgrade command, the upgrade images of the MCU and microprocessor are written to their respective backup storage slots. The SoC is then restarted. If the SoC restarts successfully, the first and second storage slots are synchronized, completing the SoC upgrade. Thus, the MCU and microprocessor can use different storage slots for upgrades, achieving decoupling of the MCU and microprocessor upgrades and enabling them to employ different upgrade strategies.
[0080] In some possible implementations of the embodiments of this application, the multi-core heterogeneous system-on-a-chip upgrade device 300 provided in the embodiments of this application may further include:
[0081] The second writing module is used to write upgrade flags to the microcontroller and microprocessor to enable the system-on-chip to enter the upgrade start state.
[0082] In some possible implementations of the embodiments of this application, the multi-core heterogeneous system-on-a-chip upgrade device 300 provided in the embodiments of this application may further include:
[0083] The status modification module is used to change the status of the on-chip system to the upgrade image ready state.
[0084] In some possible implementations of the embodiments of this application, the state modification module may also be used for:
[0085] The system-on-chip's status is changed to "Start Upgrade Verification". When the system-on-chip is in the "Start Upgrade Verification" state, the value of the field used to store the upgrade verification status is a value that indicates that the system cannot be started.
[0086] In some possible implementations of the embodiments of this application, the state modification module may also be used for:
[0087] Change the status of the system-on-chip to "upgrade verification successful".
[0088] In some possible implementations of the embodiments of this application, the multi-core heterogeneous system-on-a-chip upgrade device 300 provided in the embodiments of this application may further include:
[0089] The upgrade confirmation module is used to communicate with the upgrade management component to confirm whether the upgrade was successful.
[0090] Accordingly, the status modification module can also be used to: change the status of the on-chip system to the successful upgrade status when the upgrade management component confirms that the upgrade is successful.
[0091] In some possible implementations of the embodiments of this application, the state modification module may also be used for:
[0092] Change the status of the on-chip system to the start of synchronization state.
[0093] In some possible implementations of the embodiments of this application, the state modification module may also be used for:
[0094] Change the status of the on-chip system to "synchronization complete".
[0095] In some possible implementations of the embodiments of this application, the multi-core heterogeneous system-on-a-chip upgrade device 300 provided in the embodiments of this application may further include:
[0096] The clear module is used to clear the upgrade flag;
[0097] Accordingly, the status modification module can also be used to modify the status of the on-chip system to a normal operating state.
[0098] In some possible implementations of the embodiments of this application, the multi-core heterogeneous system-on-a-chip upgrade device 300 provided in the embodiments of this application may further include:
[0099] The upgrade rollback module is used to perform an upgrade rollback when the upgrade rollback conditions are met. The upgrade rollback conditions include any one of the following:
[0100] The upgrade image failed to be written to the backup storage slot.
[0101] The upgrade management component was confirmed to have failed.
[0102] An upgrade interrupt command was received;
[0103] The on-chip system failed to restart.
[0104] In some possible implementations of the embodiments of this application, the upgrade rollback module may include:
[0105] Reboot submodule, used to restart the on-chip system;
[0106] The synchronization submodule is used to synchronize the second storage slot with the first storage slot.
[0107] In some possible implementations of the embodiments of this application, the state modification module can also be used to: modify the state of the on-chip system to the synchronization completed state; and after clearing the upgrade flag, modify the state of the on-chip system to the normal working state.
[0108] In some possible implementations of the embodiments of this application, the state modification module may also be used for:
[0109] Change the status of the on-chip system to the start of synchronization state.
[0110] In some possible implementations of the embodiments of this application, the state modification module may also be used for:
[0111] Change the status of the system-on-chip to upgrade rollback status.
[0112] In some possible implementations of the embodiments of this application, the state modification module may also be used for:
[0113] Change the status of the on-chip system to "update failed".
[0114] It should be clarified that this application is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of this application is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of this application.
[0115] The functional blocks shown in the above-described block diagram can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of this application are programs or code segments used to perform the required tasks. Programs or code segments can be stored on a machine-readable medium or transmitted over a transmission medium or communication link via data signals carried on a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable read-only memory (EROM), floppy disks, compact disc read-only memory (CD-ROM), optical disks, hard disks, fiber optic media, radio frequency (RF) links, etc. Code segments can be downloaded via computer networks such as the Internet, intranets, etc.
[0116] It should also be noted that the exemplary embodiments mentioned in this application describe methods or systems based on a series of steps or apparatus. However, this application is not limited to the order of the above steps; that is, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.
[0117] The aspects of this disclosure have been described above with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this disclosure. It should be understood that each block in the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that these instructions, executable via the processor of the computer or other programmable data processing apparatus, enable the implementation of the functions / actions specified in one or more blocks of the flowchart illustrations and / or block diagrams. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field-programmable logic circuit. It is also understood that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can also be implemented by special-purpose hardware performing the specified functions or actions, or can be implemented by a combination of special-purpose hardware and computer instructions.
[0118] The above description is merely a specific implementation of this application. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, modules, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. It should be understood that the protection scope of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the protection scope of this application.
Claims
1. A method for upgrading a multi-core heterogeneous on-chip system, characterized in that, The system-on-a-chip includes a microcontroller and a microprocessor. The system-on-a-chip is externally connected to a non-volatile flash memory and an embedded multimedia card. The non-volatile flash memory includes a first storage slot and a second storage slot. The first storage slot and the second storage slot are storage slots with the same content. The embedded multimedia card includes two storage slots with different content. The method includes: When the on-chip system is in normal working condition, the microcontroller selects the first storage slot and the second storage slot as the working storage slot and the backup storage slot, respectively. The microprocessor selects the currently running storage slot among the two storage slots with different contents as the working storage slot and uses the other storage slot as the backup storage slot. Upon receiving an upgrade instruction, the upgrade images of the microcontroller and the microprocessor are written into their respective backup storage slots. The system-on-chip is restarted from the backup storage slots of the microcontroller and microprocessor, respectively. If the on-chip system successfully restarts, the first storage slot and the second storage slot are synchronized, and the on-chip system upgrade is completed.
2. The method according to claim 1, characterized in that, Before writing the upgrade images of the microcontroller and the microprocessor to their respective backup storage slots, the method further includes: An upgrade flag is written to the microcontroller and the microprocessor to enable the system-on-chip to enter the upgrade start state.
3. The method according to claim 2, characterized in that, Before restarting the on-chip system, the method further includes: Change the status of the system-on-chip to upgrade image ready.
4. The method according to claim 3, characterized in that, After restarting the on-chip system, the method further includes: The status of the on-chip system is changed to the start of upgrade verification status, wherein, when the on-chip system is in the start of upgrade verification status, the value of the field used to store the upgrade verification status is a value used to indicate that it cannot be started.
5. The method according to claim 4, characterized in that, Before synchronizing the first storage slot with the second storage slot, the method further includes: Change the status of the system-on-chip to "upgrade verification successful".
6. The method according to claim 5, characterized in that, Before synchronizing the first storage slot with the second storage slot, the method further includes: Communicate with the upgrade management component to confirm whether the upgrade was successful; If the upgrade management component confirms that the upgrade is successful, the status of the on-chip system will be changed to "upgrade successful".
7. The method according to claim 6, characterized in that, Before synchronizing the first storage slot with the second storage slot, the method further includes: Change the state of the on-chip system to the start synchronization state.
8. The method according to claim 7, characterized in that, After synchronizing the first storage slot with the second storage slot, the method further includes: The status of the on-chip system is changed to the synchronization completed state.
9. The method according to claim 8, characterized in that, After modifying the state of the on-chip system to the synchronization completed state, the method further includes: Clear the upgrade flag; The state of the on-chip system is changed to normal working state.
10. The method according to any one of claims 1 to 9, characterized in that, The method further includes: If the conditions for upgrading and rolling back are met, an upgrade and rollback will be performed, wherein the conditions for upgrading and rolling back include any one of the following: The upgrade image failed to be written to the backup storage slot; The upgrade management component was confirmed to have failed. An upgrade interrupt command was received; The on-chip system failed to restart.
11. The method according to claim 10, characterized in that, The upgrade rollback includes: Reboot the system-on-chip; Synchronize the second storage slot with the first storage slot.
12. The method according to claim 11, characterized in that, After synchronizing the second storage slot with the first storage slot, the method further includes: Modify the state of the on-chip system to the synchronization completed state; Clear the upgrade icon; The state of the on-chip system is changed to normal working state.
13. The method according to claim 12, characterized in that, Before synchronizing the second storage slot with the first storage slot, the method further includes: Change the state of the on-chip system to the start synchronization state.
14. The method according to claim 11, characterized in that, Before restarting the on-chip system, the method further includes: The status of the system-on-chip is changed to upgrade rollback status.
15. The method according to claim 11, characterized in that, Before synchronizing the second storage slot with the first storage slot, the method further includes: Change the status of the system-on-chip to "update failed".
16. A multi-core heterogeneous system-on-a-chip upgrade device, characterized in that, The system-on-a-chip includes a microcontroller and a microprocessor. The system-on-a-chip is externally connected to a non-volatile flash memory and an embedded multimedia card. The non-volatile flash memory includes a first storage slot and a second storage slot. The first storage slot and the second storage slot are storage slots with the same content. The embedded multimedia card includes two storage slots with different content. The device includes: The selection module is used so that, when the on-chip system is in normal working condition, the microcontroller selects the first storage slot and the second storage slot as the working storage slot and the backup storage slot, respectively, and the microprocessor selects the currently running storage slot of the two storage slots with different contents as the working storage slot and the other storage slot as the backup storage slot. The first writing module is used to write the upgrade images of the microcontroller and the microprocessor into their respective backup storage slots upon receiving an upgrade instruction. A reboot module is used to reboot the on-chip system from the respective backup storage slots of the microcontroller and microprocessor. The first synchronization module is used to synchronize the first storage slot with the second storage slot when the on-chip system restarts successfully, thus completing the on-chip system upgrade.
Citation Information
Patent Citations
Router and software upgrading method thereof
CN103581008A
Terminal upgrading method and device
CN104754043A