SRAM-based FPGA Firmware Remote Update Method and Device

By using the multi-loading method of monolithic FLASH chip partitioning and ICAPE2 module in SRAM type FPGA, the problem of large printed board size and inflexible multi-program switching in traditional methods is solved, and high reliability and miniaturized remote updates are achieved.

CN116302017BActive Publication Date: 2025-07-18SHANGHAI SPACEFLIGHT ELECTRONICS & COMM EQUIP RES INST
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310311259.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-28
Publication Date
2025-07-18
Estimated Expiration
2043-03-28

AI Technical Summary

Technical Problem

The existing SRAM-type FPGA firmware remote update method has the problem of large size of the printed board on satellites and is not suitable for flexible switching of multiple programs. Traditional methods cannot meet the miniaturization and high reliability requirements of on-site processing products.

Method used

The single-chip FLASH chip is used to divide the storage space into the Golden mirror area and multiple Multiboot mirror area. Combined with the ICAPE2 module and the watchdog fallback mechanism, multiple loading and flexible switching are realized, and the program jump and update is controlled through instructions, erase protection and loading time is set, and burned files are generated for remote updates.

Benefits of technology

Reduces device usage, reduces the size of the printed board, and enables flexible switching of multiple programs and high-reliability remote updates, suitable for the multiple loading and on-orbit reconstruction requirements of on-site processing products.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116302017B_ABST
    Figure CN116302017B_ABST
Patent Text Reader

Abstract

The present invention provides a method and device for remotely updating the firmware of an SRAM-based FPGA, including: dividing the storage chip storage space outside the FPGA into a Golden mirror area and multiple Multiboot mirror areas according to the number and size of program bitstream files; setting a module for executing jumps in the jump program, and setting erase protection in the Golden mirror area; determining the complete loading time of each mirror program, and setting the corresponding watchdog fallback time in the xdc files of the Golden mirror area and the Multiboot mirror areas; generating a programming file containing at least two mirror areas and programming it in the FLASH at a specified address; performing remote update and multiple loading operations. Thereby, the printed circuit board design is simplified; each program can implement the switching and update of other programs, making the application more flexible; and the reliability of remote update is improved through the watchdog fallback mechanism.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0002] In recent years, with the rapid development of China's space technology, the on-board processing system functions of various satellites have become more complex, diverse and intelligent. Among them, programmable logic devices represented by static random-access memory (SRAM)-type field-programmable gate arrays (FPGAs) have been widely used due to their low power consumption and high degree of customization. However, SRAM-type FPGAs are vulnerable to single-event upset faults caused by various space radiation particles, and their configured firmware also has a high demand for remote update during the in-orbit flight of satellites. Therefore, researching a safe, reliable, flexible and fast SRAM-type FPGA firmware remote update method suitable for satellite systems is the key to solving the above problems.

[0003] Existing on-board SRAM-type FPGA firmware remote update methods often use anti-single-particle antifuse FPGA chips as the main control chips to control the target SRAM-type FPGA chips, and often equip multiple FLASH (flash memory) chips for triple modular redundancy processing. Although it can ensure safe and reliable remote update, in order to ensure flexible configuration of multiple programs, more chips are required, which occupies a large printed circuit board size and is not conducive to the miniaturization development of on-board processing products.

[0004] Xilinx FPGA recommends the Multiboot solution to achieve on-line reconfiguration of FPGA, that is, it is allowed to selectively load different configuration files from FLASH without power-down restart, so as to achieve multiple loading and remote update through the independent control of FLASH by SRAM-type FPGA. Existing non-spaceborne FPGA remote update methods based on Multiboot are often fixed dual-image systems. Although they can achieve safe and reliable remote update by using mechanisms such as watchdog fallback, their usage scenarios are relatively fixed and not suitable for the situation where multiple programs need to be flexibly switched on the same processing chip. Summary of the Invention

[0005] Aiming at the deficiencies in the prior art, the purpose of the present invention is to provide a method and device for remotely updating SRAM-type FPGA firmware.

[0006] In a first aspect, an embodiment of the present application provides a method for remotely updating SRAM-type FPGA firmware, including:

[0007] Step 1: Divide the storage space of the storage chip outside the FPGA into a Golden image area and multiple Multiboot image areas according to the number and size of program bitstream files;

[0008] Step 2: Set the module for executing the jump in the jump program and set the erase protection in the Golden image area;

[0009] Step 3: Determine the complete loading time of each image program and set the corresponding watchdog fallback time in the xdc files of the Golden image area and the Multiboot image area;

[0010] Step 4: Generate a burn file containing at least two image areas and burn it in the FLASH at the specified address;

[0011] Step 5: Perform remote update and multi-loading operations.

[0012] Optionally, the Golden image area is located at address 0 and serves as the basic program in the firmware without performing updates; the Multiboot image area is located at a high address and serves as the area for storing remote update programs.

[0013] Optionally, Step 2 includes:

[0014] Set the ICAPE2 module controlled by instructions in the program that needs to jump, so that when the instruction arrives, a bitstream of the IPROG command is sent to the reconfiguration module to perform the program jump operation;

[0015] Add the content of the note management program in the program that needs to control the update and set the Golden image area erase protection.

[0016] Optionally, the SRAM-based FPGA uses the xc7k410tffg900 of Xilinx Corporation, and the FLASH chip uses the mt25ql256 of Micron Corporation.

[0017] Optionally, Step 5 includes:

[0018] Step 5.1: Automatically load the Golden image area program after power-on, and send a jump instruction to make the ICAPE2 module send an IPROG command to jump to the program at the corresponding address;

[0019] If the CRC check fails or the loading time exceeds the watchdog setting time, then fallback to the Golden image area program;

[0020] Step 5.2: If an erase instruction is to be sent to perform an erase operation, then selectively erase the specified start-to-end address area in 4KB or 64KB erase modes,

[0021] If there are some unit addresses that fail to be erased, then send an erase instruction and re-erase from the corresponding address until the telemetry signal of the last address erase success is received;

[0022] Step 5.3: If the top-up operation is to be executed, send a top-up instruction, and write the bit file of the update program to the specified FLASH address area;

[0023] If the top-up fails, return telemetry, and select to re-execute Step 5.2 until the telemetry of successful writing to the last address is returned after top-up;

[0024] Step 5.4: Power on again and execute Step 5.1 to switch to running the update program; among them, when the update program is running, switching and update operations can be performed according to remote control instructions.

[0025] Optionally, the remote control and telemetry interface includes: RS422 or 1553B transmission interface.

[0026] Optionally, it further includes:

[0027] Divide the FLASH area into a Golden mirror area and multiple Multiboot mirror areas, so as to complete the storage of multiple programs in one FLASH chip.

[0028] In a second aspect, an SRAM-based FPGA firmware remote update device provided by an embodiment of the present application includes: a firmware setting module, a remote update and loading module, wherein:

[0029] The firmware setting module is used to divide the storage chip storage space outside the FPGA into a Golden mirror area and multiple Multiboot mirror areas according to the number and size of program bit stream files;

[0030] Set the module for executing the jump in the jump program, and set erase protection in the Golden mirror area;

[0031] Determine the complete loading time of each mirror program, and set the corresponding watchdog fallback time in the xdc files of the Golden mirror area and the Multiboot mirror area;

[0032] Generate a burn file containing at least two mirror areas and burn it in the FLASH at the specified address;

[0033] The remote update and loading module is used to execute remote update and multiple loading operations.

[0034] Optionally, the Golden mirror area is located at address 0 and serves as the basic program in the firmware without performing updates; the Multiboot mirror area is located at a high address and serves as the area for storing remote update programs.

[0035] Optionally, the firmware setting module is specifically used for:

[0036] Set the ICAPE2 module controlled by instructions in the program that needs to jump, so that when the instruction arrives, a bitstream of the IPROG command is sent to the reconfiguration module to perform the program jump operation;

[0037] Add the upper note management program content in the program that needs to control the update, and set the erasure protection of the Golden mirror area.

[0038] Optionally, the SRAM-based FPGA uses the xc7k410tffg900 from Xilinx, and the FLASH chip uses the mt25ql256 from Micron.

[0039] Optionally, the remote update and loading module is specifically used for:

[0040] Automatically load the program in the Golden mirror area after power-on, and send a jump instruction to make the ICAPE2 module send the IPROG command to jump to the program at the corresponding address;

[0041] If the CRC check fails or the loading time exceeds the watchdog setting time, then roll back to the program in the Golden mirror area;

[0042] If an erase operation is to be performed, send an erase instruction, and selectively erase the specified start-to-end address area in 4KB or 64KB erase modes,

[0043] If there is a failure to erase some unit addresses, send an erase instruction and re-erase from the corresponding address until the telemetry signal indicating successful erasure of the last address is received;

[0044] If an upper note operation is to be performed, send an upper note instruction, and write the bit file of the update program to the specified FLASH address area;

[0045] If the upper note fails and telemetry is returned, then select to re-execute the erase step until the upper note is successful until the telemetry indicating successful writing of the last address is returned;

[0046] Power on again and execute the jump program to switch to running the update program; among them, when the update program is running, switching and update operations can be performed according to the remote control instruction.

[0047] Optionally, the remote control and telemetry interface includes: RS422 or 1553B transmission interfaces.

[0048] Optionally, the firmware setting module is further used for:

[0049] Divide the FLASH area into a Golden mirror area and multiple Multiboot mirror areas, so as to store multiple programs in one FLASH chip.

[0050] In a third aspect, an embodiment of the present application provides an SRAM-based FPGA firmware remote update device, including: a processor and a memory, where executable program instructions are stored in the memory, and when the processor calls the program instructions in the memory, the processor is configured to:

[0051] Execute the steps of the SRAM-based FPGA firmware remote update method according to any one of the first aspects.

[0052] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium for storing a program, and when the program is executed, it implements the steps of the SRAM-based FPGA firmware remote update method according to any one of the first aspects.

[0053] Compared with the prior art, the present invention has the following beneficial effects:

[0054] In the present application, by using a single-chip FLASH storage chip to store the FPGA firmware, it avoids the traditional method of using anti-fuse FPGAs and multiple FLASH chips in on-board processing products, reduces the use of devices, and shrinks the printed circuit board size. Through the multiple loading method based on ICAPE2 and Multiboot, compared with the traditional dual-mirror system, it can flexibly switch between multiple mirror programs, realizing the full utilization of FLASH resources. By introducing the Golden area write protection mechanism and the watchdog fallback mechanism, it has higher design reliability compared with directly using the Multiboot scheme for multiple loading and remote update, and is suitable for on-board processing products with high reliability requirements. BRIEF DESCRIPTION OF THE DRAWINGS

[0055] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only the embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained according to the provided drawings. By reading the detailed description of the non-limiting embodiments with reference to the following drawings, other features, purposes, and advantages of the present invention will become more obvious:

[0056] Figure 1 It is a schematic diagram of the principle of the Multiboot technical solution in the embodiment of the present application;

[0057] Figure 2 It is a schematic diagram of the process of remote update in the embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0058] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the following will clearly and completely describe the technical solutions in the embodiments of this application with reference to the accompanying drawings in the embodiments of this application. Apparently, the described embodiments are some, but not all, of the embodiments of this application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts shall fall within the scope of protection of this application.

[0059] It should be noted that when a component is referred to as being "fixed to" another component, it can be directly on the other component or there can also be an intermediate component. When a component is considered to be "connected to" another component, it can be directly connected to the other component or there may be an intermediate component at the same time.

[0060] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which this application belongs. The terms used in the specification of this application herein are only for the purpose of describing specific embodiments and are not intended to limit this application. The term "and / or" used herein includes any and all combinations of one or more of the related listed items.

[0061] The terms "first", "second", "third", "fourth", etc. (if any) in the description and claims of this invention and the above-mentioned accompanying drawings are used to distinguish similar objects and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of this invention described herein, for example, can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.

[0062] To reduce device usage, shrink the printed circuit board size, and achieve more flexible and reliable remote updating of the on-board SRAM-based FPGA firmware, the present invention designs a remote updating method based on ICAPE2 and Multiboot to meet the multiple loading and on-orbit reconfiguration requirements of on-board processing products.

[0063] Specifically, in the firmware setting stage, the storage chip storage space outside the FPGA in the on-board processing system is divided into a Golden image area and multiple Multiboot image areas. An ICAPE2 module controlled by instructions is set in the program. The content of the upload management program is added to the program that needs to be controlled for update, and the erase protection of the Golden image area is set. The watchdog fallback time is set in the xdc file, and a burn file is generated and burned to the FLASH. In the operation and use stage of remote update and multi-loading, the program in the Golden image area is automatically loaded after power-on. The ICAPE2 module can be controlled by instructions to jump to the Multiboot program to achieve multi-loading. In case of errors or timeouts, it can fallback to the program in the Golden image area. The upload module can be controlled to perform an upload update operation on the corresponding address of the FLASH by sending erase and upload instructions, realizing the remote update function.

[0064] In an alternative embodiment, a 7-series FPGA of Xilinx Corporation is adopted, and the external storage chip uses a FLASH chip.

[0065] Exemplarily, in the FLASH area division, a Golden image area and multiple Multiboot image areas are adopted to store multiple programs in one FLASH chip; a state machine and an ICAPE2 module are set inside the program to configure the IPROG instruction; relevant statements for the watchdog fallback time are set in the xdc file to implement the timeout fallback mechanism.

[0066] Exemplarily, the host computer sends jump, erase, or upload instructions to select remote update and multi-loading; when erasing, the 4KB or 64KB erase method is used to erase the specified address area. When uploading, the program sub-files of 64B or 256B in size are packetized into remote control data packets for uploading. At the same time, the system performs a sum check on the provided remote control instructions, monitors the process of operating the FLASH, and returns the telemetry signal for monitoring the execution status, enabling breakpoint resumption of erase and upload to ensure the integrity and accuracy of the upload update.

[0067] The technical solutions of the present invention and how the technical solutions of the present application solve the above technical problems will be described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments.

[0068] An embodiment of the present application provides a method for remotely updating the firmware of an SRAM-based FPGA, which may include:

[0069] Step 1: Divide the storage chip storage space outside the FPGA into a Golden image area and multiple Multiboot image areas according to the number and size of the program bitstream files.

[0070] In this embodiment, the Golden image area is located at address 0 and serves as the basic program in the firmware without performing updates; the Multiboot image area is located at a high address and serves as the area for storing remote update programs.

[0071] Exemplarily, the SRAM-based FPGA in this embodiment uses the xc7k410tffg900 from Xilinx, and the FLASH chip uses the mt25ql256 from Micron.

[0072] Step 2: Set the module for executing the jump in the jump program, and set the erase protection in the Golden image area.

[0073] In this embodiment, an ICAPE2 module controlled by an instruction can be set in the program that needs to jump, so that when the instruction arrives, a bitstream of the IPROG command is sent to the reconfiguration module to perform the program jump operation; the content of the annotation management program is added to the program that needs to control the update, and the Golden image area erase protection is set.

[0074] Step 3: Determine the complete loading time of each image program, and set the corresponding watchdog fallback time in the xdc files of the Golden image area and the Multiboot image area.

[0075] Step 4: Generate a programming file containing at least two image areas and program it into the FLASH at the specified address.

[0076] Step 5: Perform remote update and multiple loading operations.

[0077] Exemplarily, Step 5 in this embodiment may include:

[0078] Step 5.1: Automatically load the program in the Golden image area after power-on, and send a jump instruction to make the ICAPE2 module send an IPROG command to perform the jump of the program at the corresponding address;

[0079] If the CRC check fails or the loading time exceeds the watchdog setting time, then fallback to the program in the Golden image area;

[0080] Step 5.2: If an erase instruction is sent to perform an erase operation, then selectively erase the specified start-to-end address area in 4KB or 64KB erase modes,

[0081] If there is a failure to erase some unit addresses, then send an erase instruction and start erasing again from the corresponding address until the telemetry signal indicating successful erase of the last address is received;

[0082] Step 5.3: If it is necessary to execute the top-up operation, send a top-up instruction, and write the bit file of the update program to the specified FLASH address area;

[0083] If the top-up fails, return the telemetry, and select to re-execute Step 5.2 until the telemetry of successfully writing the last address is returned after the top-up;

[0084] Step 5.4: Power on again and execute Step 5.1 to switch to running the update program; among them, when the update program is running, switching and update operations can be performed according to the remote control instruction.

[0085] Optionally, the remote control and telemetry interface includes: RS422 or 1553B transmission interface.

[0086] In this embodiment, the FLASH area can be divided into a Golden mirror area and multiple Multiboot mirror areas, so as to complete the storage of multiple programs in one FLASH chip.

[0087] In this embodiment, by dividing the storage chip storage space outside the FPGA into a Golden mirror area and a Multiboot mirror area; determining the loading time of the program in the Multiboot mirror area to set the watchdog time; generating a burn file containing at least two mirror areas and burning it in the FLASH. For the application scenario of firmware remote update, first load the Golden mirror program, then jump to the application program or execute the update operation in due time. If it fails, roll back to the Golden mirror program. Program switching and update can also be realized when the application program is running. Thus, the use of traditional anti-fuse FPGAs and multiple FLASH chips can be avoided, simplifying the printed circuit board design; each program can realize the switching and update of other programs, making the application more flexible; by setting a rollback mechanism based on the watchdog, the reliability of remote update is effectively improved.

[0088] The embodiment of the present application provides a SRAM-based FPGA firmware remote update device, including: a firmware setting module, a remote update and loading module, where: the firmware setting module is used to divide the storage chip storage space outside the FPGA into a Golden mirror area and multiple Multiboot mirror areas according to the number and size of the program bit stream files; set the module for executing the jump in the jump program, and set the erase protection in the Golden mirror area; determine the complete loading time of each mirror program, and set the corresponding watchdog rollback time in the xdc files of the Golden mirror area and the Multiboot mirror area; generate a burn file containing at least two mirror areas and burn it at the specified address in the FLASH; the remote update and loading module is used to execute remote update and multiple loading operations.

[0089] Optionally, the Golden image area is located at address 0 and serves as the basic program in the firmware without being updated; the Multiboot image area is located at a high address and serves as the area for storing the remote update program.

[0090] Optionally, the firmware setting module is specifically used for:

[0091] Set the ICAPE2 module controlled by instructions in the program to be jumped to, so that when the instruction arrives, a bitstream of the IPROG command is sent to the reconfiguration module to perform the program jump operation;

[0092] Add the annotation management program content to the program that needs to control the update, and set the erase protection for the Golden image area.

[0093] Optionally, the SRAM-based FPGA uses the xc7k410tffg900 from Xilinx, and the FLASH chip uses the mt25ql256 from Micron.

[0094] Optionally, the remote update and loading module is specifically used for:

[0095] Automatically load the Golden image area program after power-on, and send a jump instruction to make the ICAPE2 module send an IPROG command to jump to the program at the corresponding address;

[0096] If the CRC check fails or the loading time exceeds the watchdog setting time, then fallback to the Golden image area program;

[0097] If an erase operation is to be performed, send an erase instruction, and selectively erase the specified start-to-end address area in 4KB or 64KB erase modes,

[0098] If there are some unit address erasures that fail, send an erase instruction and start erasing again from the corresponding address until the telemetry signal indicating successful erasure of the last address is received;

[0099] If an annotation operation is to be performed, send an annotation instruction, and write the bit file of the update program to the specified FLASH address area;

[0100] If the annotation fails and telemetry is returned, then select to re-execute the erase step until the annotation returns telemetry indicating successful writing to the last address;

[0101] Power on again and execute the jump program to switch to running the update program; among them, when the update program is running, switching and update operations can be performed according to remote control instructions.

[0102] Optionally, the remote control and telemetry interface includes: RS422 or 1553B transmission interfaces.

[0103] Optionally, the firmware setting module is further used to:

[0104] The FLASH area is divided into a Golden mirror area and multiple Multiboot mirror areas, so that multiple programs can be stored in one FLASH chip.

[0105] In conjunction with the accompanying drawings, some embodiments of the present application are described in detail below. In the absence of conflict, the following embodiments and features in the embodiments can be combined with each other.

[0106] Figure 1 Schematic diagram of the principle of the Multiboot technical solution in the embodiment of the present application, as shown in Figure 1 As shown, the storage space of the memory chip outside the FPGA is divided into the Golden mirror area and multiple Multiboot mirror areas. When using a 32-bit address FLASH chip, the lower 8 bits of the Multiboot mirror area address default to 8'hFF. When using the PROMFile Generator tool of the Vivado design software to generate an MCS file from multiple bit files, the lower address needs to be filled in with 8'h FF.

[0107] In the ICAPE2 module controlled by the instruction that needs to be jumped, the IPROG command content needs to be provided to the ICAPE2 module in the form of a state machine, and it is executed when the switching instruction arrives, so that the FPGA loads the corresponding bit file according to the specified address. The state machine needs to execute at least 8 states, and the IPROG command content provided is: "synchronization word", "start register write valid", "WBSTAR register configuration address", "instruction register write valid" and "IPROG command execution". Among them, the output timing of ICAPE2 and the output timing of SelectMAP are both bit-flipped formats, so the WBSTAR register address needs to be obtained by byte-flipping the actual write address, and when using a 32-bit address FLASH chip, the write address addr needs to satisfy: WBSTAR[23:0]=addr[31:8].

[0108] The above-mentioned program contents can be left in each Multiboot image area program, so that the FPGA can perform erase and write operations on the FLASH in any program running state.

[0109] The complete loading time of each mirror program needs to be determined by taking the maximum envelope statistics in combination with the loading time under each working condition. While leaving a margin, the watchdog backoff time should be controlled within a reasonable range to avoid excessive timeout waiting time affecting normal operation in orbit.

[0110] The maximum valid number of bits for the watchdog fallback time set in the xdc file is 31 bits, the period is 4000 ns, and relevant description statements should be added to the xdc files of both the Golden and Multiboot images.

[0111] Figure 2 This is a schematic diagram of the remote update process in the embodiments of this application. As Figure 2 shown, the system running states can be divided into three types according to the vertical arrangement in the figure: "Multiboot image N running" representing the update program running, "Golden image running" for the initial running state of the FPGA, and "Multiboot image 1 running" for the waiting timeout running state. The figure shows the operation flow chart of multiple loading and uploading updates in the case where the Golden image contains the uploaded update program.

[0112] Before remote update, split the mcs or bin format program file into multiple sub-files of 64B or 256B in size, and packet them according to the relevant remote control data packet format in combination with information such as the FLASH address. At the same time, add a sum check bit at the end of the remote control data packet.

[0113] When performing the upload operation, verify the correctness of the remote control data packet and the check bit and the correctness of the FLASH operation respectively. If the verification is incorrect, send the corresponding telemetry data, and wait for the correct upload instruction to rewrite or wait for the erase instruction to erase the incorrect written address.

[0114] When the content in the Multiboot image area is damaged or missing due to erasure or other reasons, trigger the CRC verification error or the watchdog timeout fallback to execute the Golden image program to ensure the security and reliability of the system.

[0115] The device in this embodiment can execute the steps in the above method. For the specific implementation process and technical effects, refer to the relevant descriptions in the above method, which will not be elaborated here.

[0116] Those skilled in the art can understand that various aspects of the present invention can be implemented as a system, a method, or a program product. Therefore, various aspects of the present invention can be specifically implemented in the following forms: a complete hardware implementation, a complete software implementation (including firmware, microcode, etc.), or an implementation combining hardware and software aspects, which can be collectively referred to as "circuit", "module", or "platform" here.

[0117] In addition, the embodiments of this application also provide a computer-readable storage medium. The computer-readable storage medium stores computer-executable instructions. When at least one processor of the user device executes the computer-executable instructions, the user device executes the above various possible methods.

[0118] Among them, the computer-readable medium includes computer storage media and communication media, where the communication media includes any medium that facilitates the transmission of a computer program from one place to another. The storage media can be any available medium accessible by a general or special-purpose computer. An exemplary storage media is coupled to the processor, enabling the processor to read information from and write information to the storage media. Of course, the storage media can also be a component of the processor. The processor and the storage media can be located in an ASIC. Additionally, the ASIC can be located in a user device. Of course, the processor and the storage media can also exist as discrete components in a communication device.

[0119] This application also provides a program product. The program product includes a computer program, which is stored in a readable storage medium. At least one processor of the server can read the computer program from the readable storage medium, and the at least one processor executes the computer program to enable the server to implement the method of any of the above embodiments of the present invention.

[0120] Those of ordinary skill in the art can understand that all or part of the steps of implementing the above method embodiments can be completed by hardware related to program instructions. The foregoing program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps including those of the above method embodiments; and the foregoing storage media include: Read-Only Memory (ROM), Random Access Memory (RAM), magnetic disks, or optical disks, etc., which can store program codes.

[0121] It can use a portable compact disc read-only memory (CD-ROM) and includes program codes, and can run on a terminal device, such as a personal computer. However, the program product of the present invention is not limited thereto. In this document, the readable storage medium can be any tangible medium that contains or stores a program, and the program can be used by or in combination with an instruction execution system, device, or component.

[0122] The program product can adopt any combination of one or more readable media. The readable media can be a readable signal medium or a readable storage medium. The readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or component, or any combination of the above. More specific examples (non-exhaustive list) of the readable storage medium include: an electrical connection with one or more wires, a portable disk, a hard disk, a Random Access Memory (RAM), a Read-Only Memory (ROM), an Erasable Programmable Read-Only Memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0123] A computer-readable storage medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries readable program code. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The readable storage medium may also be any readable medium other than the readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the readable storage medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical fiber cable, RF, etc., or any suitable combination of the above.

[0124] The program code for performing the operations of the present invention may be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and also including conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computing device, partially on the user's device, executed as a stand-alone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., by using an Internet service provider to connect through the Internet).

[0125] The various embodiments in this specification are described in a progressive manner, with each embodiment highlighting the differences from other embodiments. The same or similar parts among the various embodiments may be referred to each other. The above description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to these embodiments shown herein, but will conform to the widest scope consistent with the principles and novel features disclosed herein.

[0126] The specific embodiments of the present invention have been described above. It should be understood that the present invention is not limited to the above specific embodiments, and those skilled in the art can make various deformations or modifications within the scope of the claims, which does not affect the essence of the present invention.

Claims

1. A method for remotely updating the firmware of an SRAM-based FPGA, characterized in that, Including: Step 1: Divide the storage space of the external storage chip of the FPGA into a Golden image area and multiple Multiboot image areas according to the number and size of the program bitstream files; among them, the SRAM type FPGA uses the xc7k410tffg900 of Xilinx Corporation, and the FLASH chip uses the mt25ql256 of Micron Corporation; Step 2: Set the module for executing the jump in the jump program and set the erase protection in the Golden image area; the said Step 2 includes: Set the ICAPE2 module controlled by instructions in the program that needs to jump, so that when the instruction arrives, send the bitstream of the IPROG command to the reconfiguration module to execute the program jump operation; Add the annotation management program content in the program that needs to control the update, and set the Golden image area erase protection; Step 3: Determine the complete loading time of each image program, and set the corresponding watchdog fallback time in the xdc files of the Golden image area and the Multiboot image area; Step 4: Generate a burn file containing at least two image areas and burn it in the FLASH according to the specified address; Step 5: Execute the remote update and multi-loading operations; the said Step 5 includes: Step 5.1: Automatically load the program in the Golden image area after power-on, and send a jump instruction to make the ICAPE2 module send the IPROG command to perform the jump of the program at the corresponding address; If the CRC check fails or the loading time exceeds the watchdog setting time, then fallback to the program in the Golden image area; Step 5.2: If an erase instruction is sent to perform the erase operation, then selectively erase the specified start to end address area in the 4KB or 64KB erase mode. If there are some unit addresses that fail to be erased, send the erase instruction and re-erase from the corresponding address until the telemetry signal of the last address erase success is received; Step 5.3: If an annotation instruction is sent to perform the annotation operation, then write the bit file of the update program to the specified FLASH address area; If the annotation fails and returns the telemetry, then select to re-execute Step 5.2 until the annotation returns the telemetry of the last address write success; Step 5.4: Power on again and execute Step 5.1 to switch to the update program to run; Among them, when the update program is running, it can perform switching and update operations according to the remote control instruction.

2. The SRAM-based FPGA firmware remote update method according to claim 1, wherein The Golden image area is located at the 0 address and serves as the basic program in the firmware without performing updates; the Multiboot image area is located at the high address and serves as the area for storing the remote update program.

3. The SRAM-based FPGA firmware remote update method according to claim 1, characterized in that, The remote control and telemetry interface includes: RS422 or 1553B transmission interface.

4. The method for remotely updating the SRAM-based FPGA firmware according to any one of claims 1-3, characterized in that, Also including: Divide the FLASH area into a Golden image area and multiple Multiboot image areas, so as to complete the storage of multiple programs in one FLASH chip.

5. An SRAM - type FPGA firmware remote update device, characterized in that, Including: Firmware setting module, remote update and loading module, where: The firmware setting module is used to divide the storage chip storage space outside the FPGA into a Golden image area and multiple Multiboot image areas according to the number and size of program bitstream files; among them, the SRAM type FPGA uses xc7k410tffg900 of Xilinx Corporation, and the FLASH chip uses mt25ql256 of Micron Corporation; Set the module for executing the jump in the jump program, and set the erase protection in the Golden image area; among them, set the ICAPE2 module controlled by instructions in the program that needs to jump, so that when the instruction arrives, send the bitstream of the IPROG command to the reconfiguration module to execute the program jump operation; add the content of the note management program in the program that needs to control the update, and set the Golden image area erase protection; Determine the complete loading time of each mirror program, and set the corresponding watchdog fallback time in the xdc files of the Golden image area and the Multiboot image area; Generate a burn file containing at least two image areas and burn it in the FLASH at the specified address; The remote update and loading module is used to perform remote update and multiple loading operations. The execution of remote update and multiple loading operations includes: Step 5.1: Automatically load the program in the Golden image area after power-on, and send a jump instruction to make the ICAPE2 module send the IPROG command to perform the jump of the program at the corresponding address; if the CRC check fails or the loading time exceeds the watchdog setting time, then fallback to the program in the Golden image area; Step 5.2: If an erase instruction is sent to perform an erase operation, then selectively erase the specified start to end address area in 4KB or 64KB erase mode. If there are some unit address erasures that fail, then send the erase instruction and start erasing again from the corresponding address until the telemetry signal of the last address erasure success is received; Step 5.3: If an upload instruction is sent to perform an upload operation, then write the bit file of the update program to the specified FLASH address area; if the upload fails and returns telemetry, then select to re-execute Step 5.2 until the upload returns the telemetry of the last address write success; Step 5.4: Power on again and execute Step 5.1 to switch to running the update program; among them, when the update program is running, it can perform switching and update operations according to the remote control instruction.

6. An SRAM - type FPGA firmware remote update device, characterized in that, Including: A processor and a memory. The memory stores executable program instructions. When the processor calls the program instructions in the memory, the processor is used to: Execute the steps of the SRAM type FPGA firmware remote update method according to any one of claims 1 to 4.

7. A computer-readable storage medium for storing a program, characterized in that, When the program is executed, it realizes the steps of the SRAM type FPGA firmware remote update method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Method for remotely upgrading BOOT mirror image file and computer readable medium

    CN112685068A

  • Remote upgrading system and method based on FPGA and medium

    CN113703803A