Method and apparatus for upgrading OTA data
By dynamically allocating storage partitions in a multi-core heterogeneous system, the problem of insufficient storage resource utilization in OTA upgrades is solved, enabling flexible OTA upgrades and rollback functions, ensuring effective utilization of storage resources and normal vehicle operation.
Patent Information
- Application Number
- CN202411648928.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-18
- Publication Date
- 2025-11-11
- Estimated Expiration
- 2044-11-18
AI Technical Summary
In existing technologies, the storage resources for OTA upgrades are divided into static partitions, which results in insufficient flexibility, ineffective utilization of storage resources, and the inability to roll back in the event of an upgrade failure.
In a multi-core heterogeneous system, storage partitions are dynamically allocated. By obtaining the sub-data of the OTA data to be upgraded and the original storage information, new storage partitions are reallocated to realize the OTA data upgrade. The storage information is updated and rolled back in case of success or failure.
It enables flexible and full utilization of storage resources, avoids resource waste, and can roll back to the previous functional state in the event of an upgrade failure, ensuring normal vehicle operation.
Smart Images

Figure CN119759386B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of over-the-air (OTA) technology for data upgrades, and more particularly to a method and device for upgrading OTA data. Background Technology
[0002] With the increasing popularity of OTA (Over-The-Air) updates for automobiles, more and more users are opting for this feature to upgrade their vehicle's firmware. Currently, OTA updates are a seamless process that does not affect the normal use of the vehicle. Because OTA updates have a rollback feature, if an upgrade fails, the vehicle's functions can be reverted to their state before the upgrade, thus restoring normal operation of the vehicle.
[0003] In related technologies, a mechanism typically employing an A storage area and a B storage area—that is, a running slot and a backup slot—is used to upgrade OTA data. Storage area A stores currently running data, while storage area B stores data to be upgraded. OTA upgrades are performed using data from storage area B, and vice versa. In the event of an OTA upgrade failure, data stored in storage area A is used to roll back the OTA, restoring normal vehicle operation.
[0004] For storage resources such as eMMC and Flash, it is necessary to divide the storage resources into storage area A and storage area B. This partitioning method is a static partitioning method. The partition tables used within the storage areas are also static partition tables. OTA upgrades implemented using this static method lack flexibility and cannot achieve efficient utilization of storage resources. Summary of the Invention
[0005] This application provides an OTA data upgrade method and device to at least solve the above-mentioned technical problems existing in the prior art.
[0006] According to a first aspect of this application, an over-the-air (OTA) data upgrade method is provided, applied to a multi-core heterogeneous system. The multi-core heterogeneous system includes at least two hardware domains; each hardware domain consists of multiple processor cores with different architectures and hardware resources connected to each processor core, and the hardware domains are isolated from each other; each hardware domain is configured with an independently running operating system, and each hardware domain and its operating system constitute a domain system; the method includes:
[0007] Obtain the OTA data to be upgraded;
[0008] The OTA sub-data of each domain system and the original storage information of each domain system are obtained from the OTA data to be upgraded. The original storage information is used to characterize the mapping relationship between the physical address and the logical address of the original storage partition of each domain system. The original storage partition of each domain system is the storage partition allocated to each domain system in the first storage space of the target storage resource.
[0009] Based on the indication information of OTA sub-data of each domain system and the original storage information of each domain system, new storage partitions are allocated for each domain system from the second storage space of the target storage resource.
[0010] Based on the new storage partitions allocated to each domain system, new storage information for each domain system is obtained;
[0011] Based on the new storage information of each domain system, the OTA sub-data of each domain system is upgraded to realize the upgrade of the OTA data to be upgraded in the multi-core heterogeneous system.
[0012] In one possible implementation, the original storage information includes the number of original storage partitions; the number of original storage partitions in each domain system is at least two.
[0013] Based on the indication information of OTA sub-data of each domain system and the original storage information of each domain system, new storage partitions are allocated for each domain system from the second storage space of the target storage resource, including:
[0014] If the indication information of at least one domain system OTA sub-data is used to indicate that the number of storage partitions occupied by the OTA sub-data of the domain system is the same as the number of original storage partitions of the domain system, then the same number of new storage partitions are allocated to the domain system from the second storage space of the target storage resource.
[0015] Wherein, when the new storage information of the domain system is used to represent the mapping relationship between the physical address and the logical address of each new storage partition, the physical address of each new storage partition of the domain system is different from the physical address of each original storage partition, and the logical address of each new storage partition is different from the logical address of each original storage partition.
[0016] In one possible implementation, when the OTA subdata of the domain system occupies the same size as the original storage partitions, the logical address that is consecutive to the logical address of the original storage partitions is used as the logical address of the new storage partitions.
[0017] In one possible implementation, the original storage information includes the number of original storage partitions; the number of original storage partitions in each domain system is at least two.
[0018] Based on the indication information of OTA sub-data of each domain system and the original storage information of each domain system, new storage partitions are allocated for each domain system from the second storage space of the target storage resource, including:
[0019] If the indication information of at least one domain system OTA sub-data is used to indicate that the number of storage partitions occupied by the OTA sub-data of the domain system is different from the number of original storage partitions of the domain system, then the number of new storage partitions required by the OTA sub-data are allocated to the domain system from the second storage space of the target storage resource.
[0020] Wherein, when the new storage information of the domain system is used to represent the mapping relationship between the physical address and logical address of each new storage partition, the physical address of each new storage partition of the domain system is different from the physical address of the original storage partition, and the logical address of each new storage partition is different from the logical address of the original storage partition.
[0021] In one possible implementation, the original storage information includes the original storage partition's occupied size; the allocation of new storage partitions for each domain system from the second storage space of the target storage resource, based on the indication information of each domain system's OTA sub-data and the original storage information of each domain system, includes:
[0022] If the indication information of at least one domain system OTA sub-data is used to indicate that the size of the OTA sub-data of the domain system occupied by the storage partition is different from the size of the original storage partition of the domain system, then multiple new storage partitions of the required size of the OTA sub-data are allocated to the domain system from the second storage space of the target storage resource.
[0023] Wherein, when the new storage information of the domain system is used to represent the mapping relationship between the physical address and the logical address of each new storage partition, the physical address of each new storage partition of the domain system is different from the physical address of the original storage partition, and the logical address of each new storage partition is different from the logical address of the original storage partition.
[0024] In one possible implementation, the target storage resource is used to store at least a first type of data and a second type of data;
[0025] The original storage information is used at least to characterize the mapping relationship between the physical address and logical address of the original storage partition for the first type of data, and the mapping relationship between the physical address and logical address of the original storage partition for the second type of data.
[0026] Based on the indication information of OTA sub-data of each domain system and the original storage information of each domain system, new storage partitions are allocated for each domain system from the second storage space of the target storage resource, including:
[0027] When the OTA sub-data of at least one domain system is first type data, based on the indication information of the OTA sub-data of the domain system and the original storage information of the domain system, a new storage partition is allocated from the second storage space of the target storage resource for the first type data of the domain system, as a new storage partition allocated to each domain system.
[0028] The new storage information of the domain system includes the mapping relationship between the physical addresses of each new storage area and the logical addresses of each new storage partition for the first type of data, and the mapping relationship between the physical addresses and logical addresses of the original storage partitions for the second type of data.
[0029] In one possible implementation, the method further includes:
[0030] When the OTA sub-data of at least one domain system includes a first type of data and a second type of data, based on the indication information of the OTA sub-data of the domain system and the original storage information of the domain system, a new storage partition is allocated from the second storage space of the target storage resource for the first type of data of the domain system and a new storage partition is allocated for the second type of data of the domain system, as the new storage partition allocated to the domain system.
[0031] The physical address of the new storage partition allocated for the first type of data is different from the physical address of the new storage partition allocated for the second type of data.
[0032] The new storage information of the domain system includes the mapping relationship between the physical address and the logical address of each new storage partition for the first type of data, and the mapping relationship between the physical address and the logical address of each new storage partition for the second type of data.
[0033] In one possible implementation, the method further includes:
[0034] Obtain at least one of the following information: the number and size of the storage partitions required for the second type of data;
[0035] Based on at least one of the information, a new storage partition is allocated for the second type of data of the domain system from the second storage space of the target storage resource, the physical address of the new storage partition and the logical address allocated to the new storage partition are obtained, and based on the physical address and logical address of the new storage partition, the mapping relationship between the physical address and logical address of the new storage partition for the second type of data is obtained.
[0036] The physical addresses of the new storage partitions allocated for the second type of data are different from the physical addresses of the original storage partitions for the second type of data, and the logical addresses of the new storage partitions allocated for the second type of data are different from the logical addresses of the original storage partitions for the second type of data.
[0037] In one possible implementation, the method further includes:
[0038] In response to the successful upgrade of the OTA data to be upgraded in the multi-core heterogeneous system, the data stored in the original storage partition of each domain system is deleted, and the original storage partition is assigned to the second storage space of the target storage resource.
[0039] Back up the original storage information of each domain system in the third storage space of the target storage resource. In response to the failure of the OTA data to be upgraded in the multi-core heterogeneous system, obtain the original storage information of each domain system in the third storage space. According to the storage data in the original storage partition in the original storage information of each domain system, restart each domain system to realize the rollback of OTA data.
[0040] According to a second aspect of this application, an upgrade device for Over-the-Air (OTA) data download technology is provided. The device is located in a multi-core heterogeneous system, which includes at least two hardware domains. Each hardware domain consists of multiple processor cores with different architectures within the multi-core heterogeneous system and hardware resources connected to each processor core. The hardware domains are isolated from each other. Each hardware domain is configured with an independently running operating system, and each hardware domain and its operating system constitute a domain system. The device includes:
[0041] The first acquisition unit is used to acquire the OTA data to be upgraded.
[0042] The second obtaining unit is used to obtain OTA sub-data of each domain system and original storage information of each domain system from the OTA data to be upgraded. The original storage information is used to characterize the mapping relationship between the physical address and the logical address of the original storage partition of each domain system. The original storage partition of each domain system is the storage partition allocated to each domain system in the first storage space of the target storage resource.
[0043] The first allocation unit is used to allocate new storage partitions for each domain system from the second storage space of the target storage resource based on the indication information of the OTA sub-data of each domain system and the original storage information of each domain system.
[0044] The third acquisition unit is used to obtain the new storage information of each domain system based on the new storage partitions allocated to each domain system;
[0045] The upgrade unit is used to upgrade the OTA sub-data of each domain system based on the new storage information of each domain system, so as to realize the upgrade of the OTA data to be upgraded in the multi-core heterogeneous system.
[0046] According to a third aspect of this application, an electronic device is provided, comprising:
[0047] At least one processor; and
[0048] A memory communicatively connected to the at least one processor; wherein,
[0049] The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method described in this application.
[0050] According to a fourth aspect of this application, a non-transitory computer-readable storage medium is provided storing computer instructions for causing the computer to perform the methods described in this application.
[0051] According to a fifth aspect of this application, a computer program product is provided, comprising a computer program or instructions that, when executed by a processor, implement the method described in this application.
[0052] The OTA data upgrade method and device of this application re-allocate storage partitions for the domain system every time there is an OTA upgrade request. It is a scheme for dynamically allocating storage partitions for OTA upgrades of the domain system. Compared with the static or fixed partitioning of two slots in related technologies, it has better flexibility and can achieve effective and full utilization of storage resources.
[0053] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this application, nor is it intended to limit the scope of this application. Other features of this application will become readily apparent from the following description. Attached Figure Description
[0054] The above and other objects, features, and advantages of exemplary embodiments of this application will become readily apparent from the following detailed description taken in conjunction with the accompanying drawings. Several embodiments of this application are illustrated in the drawings by way of example and not limitation, in which:
[0055] In the accompanying drawings, the same or corresponding reference numerals indicate the same or corresponding parts.
[0056] Figure 1 A schematic diagram of a multi-core heterogeneous system in an embodiment of this application is shown. Figure 1 ;
[0057] Figure 2A schematic diagram of a multi-core heterogeneous system in an embodiment of this application is shown. Figure 2 ;
[0058] Figure 3 A schematic diagram of a multi-core heterogeneous system in an embodiment of this application is shown. Figure 3 ;
[0059] Figure 4 A schematic diagram illustrating the implementation flow of the OTA data upgrade method in an embodiment of this application is shown;
[0060] Figure 5 A schematic diagram of the structure of a multi-core heterogeneous SOC chip in an embodiment of this application is shown;
[0061] Figure 6 A schematic diagram of static partitioning of storage resources in related technologies is shown;
[0062] Figure 7 This illustration shows a spatial partitioning diagram of the target storage resources in an embodiment of this application;
[0063] Figure 8 A schematic diagram of the logical storage area in an embodiment of this application is shown;
[0064] Figure 9 This application illustrates the partitioning of the dynamic programming space in an embodiment. Figure 1 ;
[0065] Figure 10 This application illustrates the partitioning of the dynamic programming space in an embodiment. Figure 2 ;
[0066] Figure 11 This invention illustrates a schematic diagram of the logical storage areas of each domain system before and during the OTA upgrade in an embodiment of this application.
[0067] Figure 12 This document illustrates the partitioning of the EMMC after a successful OTA upgrade in an embodiment of this application.
[0068] Figure 13 This illustration shows a schematic diagram of the logical storage area of the domain system after a successful OTA upgrade in an embodiment of this application.
[0069] Figure 14 A schematic diagram of the composition structure of the OTA data upgrade device in an embodiment of this application is shown;
[0070] Figure 15 A schematic diagram of the composition structure of the electronic device in an embodiment of this application is shown. Detailed Implementation
[0071] To make the objectives, features, and advantages of this application more apparent and understandable, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0072] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. The described embodiments should not be regarded as limitations on this application. All other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0073] In the following description, references are made to “some embodiments,” which describe a subset of all possible embodiments. However, it is understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.
[0074] In the following description, the terms "first" and "second" are used merely to distinguish similar objects and do not represent a specific ordering of objects. It is understood that "first" and "second" may be interchanged in a specific order or sequence where permitted, so that the embodiments of this application described herein can be implemented in an order other than that illustrated or described herein.
[0075] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.
[0076] It should be understood that in the various embodiments of this application, the sequence number of each implementation process does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0077] Those skilled in the art will understand that this static partitioning of storage resources into storage areas A and B is a partitioning scheme specifically designed for OTA upgrades. When OTA upgrades are not available, the storage areas designated as backup slots in storage areas A and B remain unused and idle, resulting in resource waste and low utilization. During OTA upgrades, if the capacity of the backup slots is insufficient to accommodate the OTA upgrade data, a successful upgrade cannot be achieved. Conversely, if the capacity of the backup slots is excessive, leaving most storage resources idle and unutilized, this also leads to resource waste. Therefore, it can be argued that the static partitioning scheme of running and backup slots specifically for OTA upgrades in related technologies lacks flexibility and fails to achieve effective utilization of storage resources.
[0078] The OTA data upgrade device of this application is located in a multi-core heterogeneous system. The processing logic of the OTA data upgrade method of this application is deployed in a multi-core heterogeneous system. In the embodiments of this application, the multi-core heterogeneous system is a multi-core heterogeneous chip. A multi-core heterogeneous chip refers to a chip that integrates two or more processor cores within a single chip. For example, a single SOC (System-on-a-Chip) chip integrating two or more processor cores. Each processor core in a multi-core heterogeneous chip can act as an independent processor, independently executing the instructions required by each processor core and fulfilling the tasks required by each processor core. It can be understood that a multi-core heterogeneous chip is a chip with multiple processor cores. Compared with a single-core processor chip, the independent operation of each core's tasks can speed up the operation, improve multi-tasking capabilities, and thus bring the advantage of high performance. Moreover, the multiple processors are set on the same chip, which has the advantage of low cost.
[0079] like Figure 1 As shown, the multi-core heterogeneous chip includes multiple processor cores, including a first processor core, a second processor core, ..., an Lth processor core. L is a positive integer greater than or equal to 2, and can be flexibly set according to actual needs. Each processor core is essentially a computing engine, and its type and / or number can differ. The types of processor cores include cores with high computing power and cores with high real-time performance (fast computation). In practical applications, most of the multiple processor cores are of different types, while a few are of the same type. Alternatively, the multiple processor cores can be of different types; thus, the multi-core heterogeneous chip is composed of two or more processor cores with different architectures. Differences in the type and / or number of processor cores can, to a certain extent, achieve architectural differences between the processor cores.
[0080] In practical applications, among all processor cores, as long as there are two or more processor cores of different types, such processor cores can be called multi-core heterogeneous, and chips including these processor cores can be regarded as multi-core heterogeneous chips.
[0081] For example, embedded processors (ARM) offer advantages in low cost and low power consumption, digital signal processors (DSPs) offer advantages in dedicated digital processing, and programmable logic arrays (FPGAs) offer advantages in high-speed processing. Each type of processor is used as a processor core. When these types of processors are designed on the same SoC chip, a multi-core heterogeneous SoC chip is obtained.
[0082] like Figure 2 As shown, each processor core and the hardware resources connected to each other, such as clock controllers, interrupt controllers, and memory space, constitute each hardware domain. That is, a multi-core heterogeneous chip includes multiple hardware domains. In a multi-core heterogeneous chip, each hardware domain is a collection of hardware resources. Different hardware domains are isolated from each other; this isolation can be considered a physical isolation. For example, hardware designs within the same hardware domain may be located close to each other on the multi-core heterogeneous chip, while hardware designs within different hardware domains may be located at different locations on the multi-core heterogeneous chip, thus achieving physical isolation. Of course, the mutual isolation between different hardware domains in this embodiment may not be physical isolation, but logical isolation. This logical isolation can be reflected in the following: hardware resources within the same hardware domain need to use the same communication identifier to access each other within that hardware domain. That is, different hardware resources within the same hardware domain can access each other based on the communication identifier within that hardware domain. Hardware resources within different hardware domains use different communication identifiers to access each other.
[0083] In practical applications, it is preferable to isolate different hardware domains as a form of logical isolation, which can at least save chip space.
[0084] like Figure 3 As shown, in a multi-core heterogeneous chip, an operating system can be configured for each hardware domain. For example, a first operating system can be configured for the first hardware domain, and a second operating system for the second hardware domain. The operating systems configured for different hardware domains can be the same or different, preferably different. For example, the first operating system configured for the first hardware domain is Linux, and the second operating system configured for the second hardware domain is Android. Because Linux has high security and Android is lightweight, tasks with high security requirements in a multi-core heterogeneous system can be executed by Linux, while tasks requiring lightweight operation can be executed by Android. Therefore, different operating systems on different hardware domains can be used in a multi-core heterogeneous system to achieve efficient execution of various tasks.
[0085] In multi-core heterogeneous chips, operating systems can be configured for most hardware domains according to actual needs, while a small number of hardware domains can be left unconfigured, depending on the specific usage.
[0086] In this embodiment, communication needs also exist between hardware domains. When communication needs exist between different hardware domains, an inter-core communication mechanism can be used to achieve communication between hardware domains. Among these, inter-core communication mechanisms in multi-core heterogeneous systems include a mailbox mechanism suitable for instruction transmission and a memory sharing mechanism suitable for data sharing. Inter-core communication within a single SOC chip can ensure data transmission within the same chip, guaranteeing data security and transmission speed.
[0087] Typically, hardware resources differ across different hardware domains, and these differences may manifest in hardware type, model, quantity, and other aspects. This variability, to some extent, reflects the heterogeneity of multi-core heterogeneous systems. As discussed earlier, the multi-core heterogeneity in this application is a hardware-level concept and is unrelated to the software level.
[0088] like Figure 1 As shown, the multi-core heterogeneous chip in this embodiment also includes various types of control units. These control units include, but are not limited to, a power control unit, a non-volatile memory control unit, and a volatile memory control unit. The power control unit controls the power supply unit to provide power to the multi-core heterogeneous chip. The non-volatile memory control unit controls access to non-volatile memory units by at least one processor core in the multi-core heterogeneous chip. The volatile memory control unit controls access to volatile memory units by at least one processor core in the multi-core heterogeneous chip.
[0089] Among them, the power supply unit, non-volatile memory unit, and volatile memory unit, as hardware resources outside the multi-core heterogeneous chip, can be called upon when needed by the multi-core heterogeneous chip. In addition, hardware such as audio output units (such as speakers), audio acquisition units (such as microphones), and video output units (such as displays), as hardware resources outside the multi-core heterogeneous chip, can also be called upon when needed by the multi-core heterogeneous chip to achieve normal audio and video output.
[0090] The OTA data upgrade method of this application is implemented on a multi-core heterogeneous system. The multi-core heterogeneous system involved in the OTA data upgrade method of this application includes M hardware domains, where M is a positive integer greater than or equal to 2. These M hardware domains can be... Figure 2The L hardware domains shown represent all or part of the hardware domains, preferably all of them. Each hardware domain is configured as an independently running operating system, meaning each hardware domain corresponds to one operating system. For example, hardware domain 1 corresponds to the first operating system, hardware domain 2 corresponds to the second operating system, and so on, with hardware domain M corresponding to the Mth operating system. Each hardware domain consists of multiple processor cores with different architectures in a multi-core heterogeneous system and the hardware resources connecting these processor cores. The hardware domains are isolated from each other; this isolation can be physical or logical, as described in the preceding explanation.
[0091] In this application, a hardware domain and its corresponding operating system can constitute a domain system. A multi-core heterogeneous chip may include two or more such domain systems. Each domain system can access system resources through a system bus. System resources may include peripherals such as an integrated circuit bus (I2C), a universal asynchronous transceiver (UART), and interfaces (IO), as well as resources that can be shared between domain systems, such as speakers, microphones, and interrupt controllers.
[0092] Based on their roles, domain systems in a multi-core heterogeneous system can be broadly categorized into two types: application domains and management domains. The number of management domains can be one, two, or more, but one is preferred. The number of application domains is typically two or more. Taking a multi-core heterogeneous system applied to a vehicle as an example, application domains implement various vehicle functions, such as instrument cluster functions and in-vehicle entertainment (IVI) functions. Management domains manage these application domains. In practical applications, instrument cluster functions and in-vehicle entertainment functions can be integrated into different application domains. Thus, a multi-core heterogeneous system applied in a vehicle will have at least two application domains: an instrument cluster domain and an IVI domain. Of course, in addition to application and management domains, different roles can be assigned to domain systems based on actual application requirements. For example, a multi-core heterogeneous system can also include a small system domain and / or a security domain. The security domain ensures the security of the multi-core heterogeneous system, while the small system domain assists other domain systems in realizing the powerful functions of the multi-core heterogeneous system. For example, a small system domain can enable accelerated startup.
[0093] In this application, target storage resources such as EMMC and Flash are divided into different spaces. For example, the divided space includes at least a first storage space and a second storage space. When OTA data to be upgraded is obtained, i.e., when there is an OTA upgrade requirement, new storage partitions are allocated from the second storage space for each domain system based on the indication information of the OTA sub-data of each domain system and the original storage information of each domain system. Based on the new storage partitions allocated to each domain system, the new storage information of each domain system is obtained, thereby realizing the OTA upgrade. In this application, two dedicated storage areas (such as storage area A and storage area B in related technologies) or two types of slots are no longer reserved for OTA upgrades. Instead, when there is an OTA upgrade requirement, new storage partitions are allocated for the OTA upgrade data to realize the OTA upgrade. Each time there is an OTA upgrade, a new storage partition is allocated for the domain system, which is a scheme for dynamically allocating storage partitions for OTA upgrades of domain systems. Compared with the static schemes in related technologies, the dynamic allocation scheme in this application has better flexibility and can achieve effective and full utilization of storage resources.
[0094] The technical solution of this application is described below.
[0095] Figure 4 This illustration shows an OTA data upgrade method in an embodiment of this application. Figure 1 .like Figure 4 As shown, the method includes:
[0096] S101: Obtain OTA data to be upgraded.
[0097] In this step, one of the multiple domain systems within the SOC can be configured to connect to an external network to ensure SOC security. During implementation, one of the domain systems within the SOC—specifically, the operating system of that domain system—receives OTA (Over-The-Air) update data from an external source via the network, or downloads OTA update data from the network, thereby obtaining the OTA update data. The OTA update data can be an OTA update package.
[0098] S102: Obtain OTA sub-data of each domain system and original storage information of each domain system from the OTA data to be upgraded. The original storage information is used to characterize the mapping relationship between the physical address and the logical address of the original storage partition of each domain system. The original storage partition of each domain system is the storage partition allocated to each domain system in the first storage space of the target storage resource.
[0099] In this step, the OTA upgrade package is split into multiple OTA sub-data sets. These sub-data sets are then distributed to various domain systems as their respective OTA upgrade data. Typically, the number of sub-data sets in the OTA upgrade package corresponds to the number of domain systems in the SOC. In this way, each domain system receives one OTA sub-data set as its own OTA upgrade data set.
[0100] The target storage resource can be any type of storage device, such as EMMC, Flash, or RAM. Taking EMMC as an example, it is divided into at least two storage spaces. One storage space—the first storage space—is used to store the current operating data of the domain system to support its normal operation. This is similar to the A partition and non-A / B partitions in the subsequent discussion of storage partitioning. The second storage space is configured as free space, serving as the dynamic planning space in the subsequent discussion. When there is an OTA upgrade requirement, storage partitions can be allocated to each domain system from this free space. Of course, EMMC can also include space for storing the dynamic planning tables of each domain system (which record the original storage information), and space for backing up the dynamic planning tables (at least backing up the dynamic planning tables). (This will be discussed later.) Figure 7 As shown.
[0101] The original storage information of a domain system contains a mapping relationship between the physical address and the logical address of the original storage partition. This original storage information is stored in the dynamic planning tablespace of each domain system. Because each OTA upgrade in this application involves a new allocation of storage partitions, this mapping relationship between the physical and logical addresses of storage partitions changes with each OTA upgrade. The mapping relationship before the OTA upgrade is referred to as the original storage information. After a successful OTA upgrade, this mapping relationship is updated and stored based on the changes in the physical and logical addresses of the newly allocated storage partitions, serving as the original storage information before the next OTA upgrade.
[0102] S103: Based on the indication information of OTA sub-data of each domain system and the original storage information of each domain system, allocate new storage partitions for each domain system from the second storage space of the target storage resource.
[0103] When distributing each OTA sub-data to each domain system, it is also necessary to distribute instruction information for each OTA sub-data to each domain system. This instruction information reveals the required storage space size and / or the number of storage partitions needed for the OTA sub-data upgrade. Combined with the original storage information of the domain system, including the number and / or size of the original storage partitions, it can be determined whether the OTA sub-data upgrade requires increasing or decreasing the number of storage partitions, expanding or shrinking the storage space compared to the original storage partitions allocated to the domain system. This facilitates the allocation of new storage partitions to each domain system from the secondary storage space of the target storage resource.
[0104] S104: Based on the new storage partitions allocated to each domain system, obtain the new storage information for each domain system.
[0105] The new storage information is used at least to characterize the mapping relationship between the physical address and the logical address of the new storage partition allocated to the domain system. Typically, a new storage partition has a physical address, and a logical address is assigned to each new storage partition. By recording the corresponding physical and logical addresses of the same new storage partition, the aforementioned mapping relationship can be obtained.
[0106] S105: Based on the new storage information of each domain system, upgrade the OTA sub-data of each domain system to realize the upgrade of the OTA data to be upgraded in the multi-core heterogeneous system.
[0107] In this step, the OTA sub-data of the domain system is written to the physical address of the new storage partition of the domain system, so that the domain system can restart according to the data written or stored in the new storage partition. Each domain system realizes its own OTA upgrade, thereby realizing the overall OTA upgrade of the SOC.
[0108] In steps S101 to S105, upon obtaining OTA data to be upgraded (i.e., when an OTA upgrade is required), new storage partitions are allocated from the second storage space for each domain system based on the indication information of the OTA sub-data for each domain system and the original storage information of each domain system. Based on the newly allocated storage partitions for each domain system, the new storage information for each domain system is obtained, thereby realizing the OTA upgrade. This application dynamically allocates storage partitions for each domain system for every OTA upgrade, providing better flexibility compared to related technologies that statically or permanently divide storage slots. This avoids wasting storage resources and achieves effective and full utilization of storage resources.
[0109] In this application, each domain system has at least two, and typically more, original storage partitions. Each original storage partition has a physical address and a logical address. OTA sub-data from different domain systems has its own indication information. For example, the indication information for the OTA sub-data of domain system 1 indicates that the number of storage partitions occupied by the OTA sub-data of this domain system is the same as the number of original storage partitions of this domain system. The indication information for the OTA sub-data of domain system 2 indicates that the number of storage partitions occupied by the OTA sub-data of this domain system is different from the number of original storage partitions of this domain system. Based on the actual situation of each domain system, and according to the indication information of the OTA sub-data of each domain system and the original storage information of that domain system, new storage partitions are allocated from the second storage space of the target storage resource for each domain system.
[0110] In this application, considering that the content of the instruction information may differ, the scheme for allocating new storage partitions for each domain system from the second storage space of the target storage resource, based on the instruction information of the OTA sub-data of each domain system and the original storage information of each domain system, can include the following scenarios according to different instruction content:
[0111] Scenario 1: The original storage information includes the number of original storage partitions; the number of original storage partitions for each domain system is at least two. If the indication information of at least one domain system OTA sub-data is used to indicate that the number of storage partitions occupied by the OTA sub-data of that domain system is the same as the number of original storage partitions of that domain system, then the same number of new storage partitions are allocated to that domain system from the second storage space of the target storage resource.
[0112] Scenario one, from the perspective of storage partition usage, states that if the number of storage partitions occupied by OTA sub-data in a domain system is the same as the number of original storage partitions in that domain system, then the same number of storage partitions will be allocated to that domain system from the second storage space. For example, such as... Figure 9 The hardware domain 3 shown (the hardware domain of domain system 3) originally includes partitions 1 through p of partition A. From the free space - dynamic programming space, p partitions are allocated as partition B of this domain system, and these p partitions become the new storage partitions of this domain system.
[0113] It is understandable that, since the new storage partition is obtained from a second storage space different from the first storage space, it is physically different from the original storage partition, and naturally, their physical addresses are different. An address, different from the logical address of the original storage partition, is assigned to the new storage partition as its logical address. Based on this, it can be considered that, when the new storage information of this domain system is used to represent the mapping relationship between the physical addresses and logical addresses of each new storage partition, the physical addresses of each new storage partition in this domain system are different from the physical addresses of each original storage partition, and the logical addresses of each new storage partition are also different from the logical addresses of each original storage partition.
[0114] It should be noted that when allocating logical addresses for a new storage partition, an address that is logically contiguous with the original storage partition can be used as the logical address of the new storage partition. This achieves the effect of logical address contiguousness in the domain system, which facilitates the access of the software layer of the domain system to physical resources such as storage resources.
[0115] In one possible implementation, the number of storage partitions occupied by the OTA sub-data of a domain system is the same as the number of original storage partitions of the domain system. Moreover, the size of each new storage partition occupied by the OTA sub-data of the domain system is the same as the size of each original storage partition. In this way, logical addresses that are contiguous with the logical addresses of each original storage partition can be used as the logical addresses of each new storage partition to facilitate access to storage resources by the software layer.
[0116] Scenario 2: If the indication information of at least one domain system OTA sub-data is used to indicate that the number of storage partitions occupied by the OTA sub-data of the domain system is different from the number of original storage partitions of the domain system, then the number of new storage partitions required by the OTA sub-data are allocated to the domain system from the second storage space of the target storage resource.
[0117] Scenario two considers the number of storage partitions required. If the number of storage partitions required for OTA sub-data in a domain system differs from the number of original storage partitions in that domain system, then the required number of storage partitions for the OTA sub-data will be allocated from the second storage space. For example, such as... Figure 9 The hardware domain 2 shown (the hardware domain of domain system 2) originally includes partitions 1 to m of partition A. The number of partitions required for OTA subdata is m-1. Therefore, m-1 partitions are allocated from the dynamic programming space as partition B of this domain system, and the allocated m-1 partitions become the new storage partitions of this domain system.
[0118] Referring to the explanation of the aforementioned scenario one, if the original storage partition in the first storage space is regarded as partition A, then the partition divided from the free space - dynamic programming space is regarded as partition B. Since partition A and partition B are divided from different storage spaces, their physical addresses are naturally different.
[0119] In scenario two, to clearly distinguish between partition A and partition B, the logical addresses assigned to each new storage partition within partition B are different from the logical addresses of the original storage partitions. Thus, the new storage information of the domain system is obtained, leading to the following conclusion: when the new storage information of the domain system is used to represent the mapping relationship between the physical addresses and logical addresses of each new storage partition, the physical addresses of each new storage partition in this domain system are different from the physical addresses of the original storage partitions, and the logical addresses of each new storage partition are also different from the logical addresses of the original storage partitions. In implementation, logical addresses consecutive to the logical addresses of the original storage partitions can be used as the logical addresses of the new storage partitions to facilitate software-level access to storage resources.
[0120] Scenario 3: If the indication information of at least one domain system OTA sub-data is used to indicate that the size of the storage partition occupied by the OTA sub-data of the domain system is different from the size of the original storage partition of the domain system, then multiple new storage partitions of the required size of the OTA sub-data are allocated for the domain system from the second storage space of the target storage resource.
[0121] Scenario 2 is from the perspective of the size occupied by the storage partition. The original storage information includes the size occupied by the original storage partition. If the size occupied by the OTA sub-data on the storage partition is different from the size of the original storage partition of the domain system, then multiple new storage partitions of the size required by the OTA sub-data are allocated to the domain system from the second storage space of the target storage resource.
[0122] In this scenario, the storage partition size occupied by OTA sub-data can refer to the overall size occupied by the OTA sub-data, which differs from the overall size of the original storage partition. Multiple new storage partitions of the required size for the OTA sub-data are allocated from the second storage space of the target storage resource for the domain system. Alternatively, the storage partition size occupied by OTA sub-data can refer to the size occupied by one or more individual storage partitions, where at least some partitions have a different size than the original storage partitions. For example... Figure 9 The hardware domain 4 shown (the hardware domain of domain system 4) originally had partitions 1 through q of partition A. The new storage partitions required for OTA subdata are partitions 1 through q, which are divided from the dynamic programming space. These q partitions will serve as partition B of this domain system. The size of each storage partition from partitions 1 through q, which are divided from the dynamic programming space, is smaller than the size of partitions 1 through q of partition A, but not all of them are the same size.
[0123] For example Figure 9 The hardware domain 3 shown (the hardware domain of domain system 3) originally had partitions 1 through p of partition A. The new storage partitions required for OTA subdata are partitions 1 through p allocated from the dynamic programming space, with p partitions serving as partition B of this domain system. At least partition 2 of partitions 1 through p allocated from the dynamic programming space must be different in size from partition 2 of partition A.
[0124] Similar to the descriptions of scenarios one and two above, in scenario three, where the new storage information in the domain system is used to represent the mapping relationship between the physical addresses and logical addresses of each new storage partition, the physical addresses of each new storage partition in the domain system are different from the physical addresses of the original storage partitions, and the logical addresses of each new storage partition are also different from the logical addresses of the original storage partitions. In implementation, logical addresses consecutive to the logical addresses of the original storage partitions can be used as the logical addresses of the new storage partitions to facilitate software-level access to storage resources.
[0125] In the three scenarios described above, the number of new storage partitions can be increased or decreased relative to the original storage partitions, and / or the size of one or more individual new storage partitions can be increased or decreased. This application provides a scheme for flexibly allocating storage partitions in a domain system according to actual needs. This flexible allocation scheme maximizes the utilization of storage partitions and avoids wasting storage resources.
[0126] In practical applications, the number of storage partitions occupied by OTA sub-data in a domain system can be more or less than the number of original storage partitions in the domain system. The overall size occupied by OTA sub-data can be greater or less than the overall size occupied by the original storage partitions. The size occupied by OTA sub-data on a single storage partition can be greater or less than the size of a single original storage partition. Regardless of the situation, in this application, by combining the OTA sub-data indication information and the actual occupancy of the original storage partitions in the domain system, a new storage partition is allocated for the OTA sub-data from the free space of the target storage resources. This provides technical support for the dynamic allocation of storage space for OTA upgrade packages.
[0127] like Figure 9 As shown, the first storage space of the target storage resource includes not only partition A (space) but also non-A / B partitions (space). Both partition A and non-A / B partitions are used to store data that maintains the operation of the domain system. If the data stored in partition A is considered first-type data, and the data stored in non-A / B partitions is considered second-type data, then the target storage resource is used to store at least first-type and second-type data.
[0128] An OTA (Over-The-Air) upgrade of sub-data can involve only upgrading the first type of data stored in partition A, or it can involve upgrading not only the first type of data stored in partition A, but also the second type of data stored in non-A / B partitions. Regardless of which type of data is being upgraded, the original storage information must at least characterize the mapping relationship between the physical and logical addresses of the original storage partitions for the first type of data, and the mapping relationship between the physical and logical addresses of the original storage partitions for the second type of data.
[0129] In practical applications, if the OTA sub-data upgrade only involves upgrading the first type of data stored in partition A, that is, when the OTA sub-data of a domain system is first type data, based on the indication information of the OTA sub-data of the domain system and the original storage information of the domain system, a new storage partition is allocated from the second storage space of the target storage resource for the first type of data of the domain system, as the new storage partition allocated to the domain system. The new storage information of the domain system includes the mapping relationship between the physical addresses of each new storage area for the first type of data and the logical addresses of each new storage partition, and the mapping relationship between the physical addresses and logical addresses of the original storage partition for the second type of data.
[0130] In layman's terms, in the aforementioned solution, if the OTA sub-data upgrade only involves upgrading the first type of data stored in partition A, then in the new storage information, only the mapping relationship of the first type of data needs to be updated or changed; the mapping relationship of the second type of data does not need to be updated or changed. This solution is practical and easy to promote.
[0131] The schemes shown in S101 to S105 above, as well as the schemes in the three scenarios mentioned above, are schemes that only involve upgrading the first type of data stored in partition A for OTA sub-data. Schemes that involve upgrading the second type of data are described below.
[0132] In practical applications, if the OTA sub-data upgrade involves not only upgrading the first type of data stored in partition A but also upgrading the second type of data stored in non-A / B partitions, then when the OTA sub-data of at least one domain system includes both first and second type data, based on the indication information of the OTA sub-data of that domain system and the original storage information of that domain system, new storage partitions are allocated from the second storage space of the target storage resource for both the first type of data and the second type of data of that domain system, serving as the new storage partitions allocated to that domain system. The new storage information of the domain system includes the mapping relationship between the physical addresses and logical addresses of each new storage partition for the first type of data, and the mapping relationship between the physical addresses and logical addresses of each new storage partition for the second type of data.
[0133] In layman's terms, in the aforementioned scheme, if the upgrade of OTA sub-data involves not only the upgrade of the first type of data stored in partition A, but also the upgrade of the second type of data stored in non-A / B partitions, then in the new storage information, not only the mapping relationship of the first type of data needs to be updated or changed, but the mapping relationship of the second type of data also needs to be updated or changed.
[0134] It's understandable that, because storage partitions need to be allocated from the second storage space for two different types of data, the physical address of the new storage partition allocated for the first type of data will be different from the physical address of the new storage partition allocated for the second type of data. The logical address allocated to the new storage partition for the first type of data can also be different from the logical address allocated to the new storage partition for the second type of data. Furthermore, in implementation, a logical address contiguous with the logical address allocated to the new storage partition for the first type of data can be allocated to the new storage partition for the second type of data, serving as the logical address of the new storage partition for the second type of data, thus achieving logical address contiguousness.
[0135] As described above, in the upgrade scheme for the first type of data stored in partition A, the number of new storage partitions used to store the first type of data can be increased or decreased relative to the original storage partitions used to store the first type of data, depending on the size of the first type of data involved in the OTA upgrade package. And / or, the size of one or more individual new storage partitions can be increased or decreased. For domain systems, regardless of the situation, it is necessary to update the mapping relationship based on the physical address and logical address of the allocated new storage partitions to provide a certain guarantee for successful OTA upgrades.
[0136] If the OTA upgrade involves upgrading second-type data stored in non-A / B partitions, the following scheme is used to update the physical and logical addresses of the second-type data. When the OTA sub-data of at least one domain system includes first-type data and second-type data, for the second-type data, at least one of the following information is obtained: the number and size of the storage partitions required for the second-type data. Based on this information, a new storage partition is allocated for the second-type data of the domain system from the second storage space of the target storage resource. The physical address of the new storage partition and the logical address allocated to the new storage partition are obtained. Based on the physical and logical addresses of the new storage partition, the mapping relationship between the physical and logical addresses of the new storage partition for the second-type data is obtained.
[0137] In practical applications, if the second type of data requires n storage partitions, then n storage partitions are allocated from the second storage space as areas for storing the second type of data in the OTA sub-data. If the second type of data requires M megabits of storage partitions, then an M megabits of storage area is allocated from the second storage space as an area for storing the second type of data in the OTA sub-data.
[0138] It is understandable that in upgrade schemes for non-A / B partition storage of Type II data, the number of new storage partitions used to store Type II data can be increased or decreased, and / or the size of one or more individual new storage partitions can be increased or decreased, based on at least one of the information in the OTA upgrade package regarding the number and size of storage partitions required for Type II data, relative to the original storage partitions used to store Type II data. For domain systems, regardless of the scenario, it is necessary to update the mapping relationship based on the physical and logical addresses of the allocated new storage partitions to provide a certain guarantee for successful OTA upgrades.
[0139] In the upgrade scheme for second-type data stored in non-A / B partitions, the physical addresses of the new storage partitions allocated to the second-type data differ from the physical addresses of the original storage partitions, and the logical addresses of the new storage partitions allocated to the second-type data also differ from the logical addresses of the original storage partitions. This update ensures the mapping relationship between the physical and logical addresses of the second-type data is maintained. The logical addresses allocated to the new storage partitions can be contiguous with the logical addresses of the original storage partitions to facilitate software access to storage resources.
[0140] There are three possible solutions for upgrading second-type data that is not stored in A / B partitions:
[0141] Scenario A: If the indication information of at least one domain system OTA sub-data is used to indicate that the number of storage partitions occupied by the second type of data in the OTA sub-data of the domain system is the same as the number of original storage partitions (non-A / B partitions) for the second type of data in the domain system, then the same number of new storage partitions are allocated from the second storage space of the target storage resource for the second type of data in the OTA sub-data.
[0142] Scenario B: If the indication information of at least one domain system OTA sub-data is used to indicate that the number of storage partitions occupied by the second type of data in the OTA sub-data of the domain system is different from the number of original storage partitions (non-A / B partitions) for the second type of data in the domain system, then the number of new storage partitions required for the second type of data in the OTA sub-data of the domain system shall be allocated from the second storage space of the target storage resource.
[0143] Scenario C: If the indication information of at least one domain system OTA sub-data is used to indicate that the size of the storage partition occupied by the second type of data in the OTA sub-data of the domain system is different from the size of the original storage partition (non-A / B partition) for the second type of data in the domain system, then multiple new storage partitions of the required size are allocated from the second storage space of the target storage resource for the second type of data of the domain system.
[0144] In scenarios A, B, and C above, the new storage information for the second type of data in the domain system can be used to represent the mapping relationship between the physical addresses and logical addresses of each new storage partition for the second type of data. In this mapping relationship, the physical addresses of each new storage partition for the second type of data in the domain system are different from the physical addresses of each original storage partition for the second type of data, and the logical addresses of each new storage partition for the second type of data are different from the logical addresses of each original storage partition for the second type of data.
[0145] For an understanding of scenarios A, B, and C, please refer to the aforementioned understanding of scenarios one, two, and three; similarities will not be repeated here.
[0146] In practical applications, OTA upgrades mostly involve upgrading the first type of data stored on partition A. Upgrading both the first type of data stored on partition A and the second type of data stored on non-A / B partitions simultaneously is less common. For example, upgrading the operating system of a domain system might involve simultaneously upgrading both types of data stored on two types of partitions (A partitions and non-A / B partitions).
[0147] In this application, for OTA sub-data of each domain system, whether it involves upgrading the first type of data or the second type of data, a new storage partition needs to be allocated from the second storage space of the target storage resource. The mapping relationship is then updated based on the physical and logical addresses of the newly allocated storage partition to achieve the OTA upgrade. This is a scheme for dynamically allocating storage partitions for OTA upgrades of domain systems. Compared with related technologies that use static or fixed partitioning of two types of slots, this application offers greater flexibility and avoids wasting storage resources.
[0148] OTA sub-data for a domain system needs to be written to a new storage partition allocated to that domain system. When the domain system is restarted, it can be restarted according to the data written to the new storage partition, thus achieving an OTA upgrade for the domain system. If the restart is successfully performed according to the data written to the new storage partition, the OTA upgrade is successful. In response to the successful upgrade of the OTA data to be upgraded in the multi-core heterogeneous system, the data stored in the original storage partition is the old data used to maintain the operation of the domain system. Since the old data is no longer needed, the old data stored in the original storage partition of each domain system is deleted, the original storage partition is released, and the original storage partition is allocated to the second storage space of the target storage resource. That is, the original storage partition with deleted data is used as a free partition and allocated or assigned to the second storage space, which can be used as a new storage partition allocated in the next OTA upgrade.
[0149] In this application, the target storage resource may also include a third storage space (such as...). Figure 7 The dynamic programming table (shown as a backup space) is used to back up the original storage information of each domain system. If the OTA upgrade is unsuccessful, in response to the failure of the OTA data upgrade in the multi-core heterogeneous system, the original storage information of each domain system in the third storage space is obtained. Based on the storage data in the original storage partition of each domain system, the domain systems are restarted to achieve OTA data rollback. That is, through the backup of the third storage space, OTA data rollback is achieved, allowing a rollback to the previous running state when the OTA data upgrade fails. This avoids the situation where the multi-core heterogeneous system cannot be used normally due to a failed upgrade and the inability to roll back to the previous running state. The technical solution of this application successfully achieves seamless OTA upgrades and OTA rollback when OTA upgrades fail.
[0150] Figure 5 This is a schematic diagram illustrating the structure of a multi-core heterogeneous SOC chip in an embodiment of this application. Figure 5As shown, a multi-core heterogeneous SOC chip includes four domain systems: Domain System 1 to Domain System 4. Each domain system includes a hardware domain and an independently running operating system (OS). For example, Domain System 1 includes OS1 and Hardware Domain 1, and Domain System 2 includes OS2 and Hardware Domain 2. The target storage resources, EMMC and Flash, are located outside the SOC as an example. Of course, in the technical solution of this application, the target storage resources can also be located inside the SOC. For the case where they are located inside, please refer to the understanding of the case where they are located outside, which will not be elaborated further.
[0151] For SOC security considerations, in the four domain systems, Domain System 1 has a Flash controller, which accesses the external Flash memory. Other domain systems can access the external Flash memory through the Flash controller of Domain System 1. In the four domain systems, Domain System 2 has an EMMC controller, which accesses the external EMMC memory. Other domain systems can access the external EMMC memory through the EMMC controller of Domain System 2.
[0152] Each domain system's OS runs dynamic programming software, Flash front-end software, and eMMC front-end software. Domain system 1's OS runs Flash back-end software. Domain system 2's OS runs eMMC back-end software. Domain system 1's Flash controller accesses external Flash memory. Domain system 2's eMMC controller accesses external eMMC memory. If the SOC chip is configured as follows... Figure 5 As shown in the layering diagram, the OS can reside in the operating system application layer. The dynamic programming software resides in the dynamic programming software layer, while the Flash front-end software and EMMC front-end software reside in the storage controller front-end software driver layer. The Flash back-end software and EMMC back-end software reside in the storage controller back-end software driver layer. The Flash controller and EMMC controller reside in the SOC chip's hardware controller layer. The software involved in each of these layers is an essential part of implementing the technical solution of this application.
[0153] For an OTA upgrade package received by one of the domain systems, such as domain system 3, the OS of domain system 3 splits it into four parts. It sends its own OTA sub-data to the dynamic planning software of domain system 3. The OTA sub-data belonging to other domains is sent to the other domain systems via inter-core communication. Domain systems 1, 2, and 4 receive their own OTA sub-data through inter-core communication. The dynamic planning software of domain systems 1, 2, and 4 executes the methods described in S103-S104 above based on their own OTA sub-data to maintain the dynamic planning status of their respective domain system's storage partitions (this status is reflected in the update of mapping relationships).
[0154] Taking EMMC as the target storage resource as an example, each domain system sends a request regarding dynamic planning to the EMMC backend software of domain system 2 through its own EMMC frontend software. The EMMC backend software determines whether the requester has permission. If permission is granted, it can mark the physical storage partitions allocated to the domain system by the EMMC controller according to the dynamic planning status of the domain system, and write the OTA sub-data of each domain system to the newly allocated storage partitions, enabling the domain system to use them for subsequent upgrades. Each domain system restarts according to the data written in its newly allocated storage partition, thereby realizing the OTA upgrade of the domain system and ultimately the OTA upgrade of the SOC chip.
[0155] Taking EMMC as the target storage resource as an example, such as Figure 6 As shown, in related technologies, the EMMC is statically partitioned into storage areas for each domain system (hardware domain 1 storage area to hardware domain 4 storage area). Once the A storage area (the unshaded portion of the A / B partition) and B storage area (the shaded portion of the A / B partition) of each domain system are statically partitioned, the B storage area can only be used for OTA upgrades and cannot be used for other situations. After static partitioning, the physical partition occupied by each domain system is fixed and will not change. When there is no need for OTA upgrades, the B storage area is idle. Even if the normal operation of the domain system requires the use of the idle storage area, the B storage area cannot be used, which undoubtedly wastes storage resources. Figure 6 For details on partition tables and partition table backups, please refer to the existing relevant descriptions, which will not be repeated here.
[0156] In this application, two dedicated storage areas (such as storage area A and storage area B in related technologies) are no longer reserved for OTA upgrades. Instead, dynamic allocation of storage resources for each domain system is achieved by utilizing dynamic programming software to re-allocate storage resources from the second storage space of the EMMC. This means that a unified, dynamically planarizable storage layout is used to allocate storage partitions within the EMMC, thereby enabling OTA upgrades for each domain system. This is a scheme for dynamically allocating storage partitions within the EMMC, offering good flexibility and avoiding waste of storage resources.
[0157] In this application, the target storage resource, such as EMMC, can be partitioned into spaces. For example... Figure 7As shown, the EMMC is divided into a dynamic planning tablespace, an A / B partition-A partition space, a non-A / B partition space, a dynamic planning space, and a dynamic planning table backup space. The dynamic planning tablespace includes the dynamic planning tables of each domain system. The A partition space and the non-A / B partition space can be used as the first storage space for the target storage resource, such as the EMMC. The dynamic planning space can be used as the second storage space, which is free space reserved for the technical solution of this application. The dynamic planning table backup space can be used as the third storage space, such as the EMMC, to back up the dynamic planning tables of each domain system, so that in the event of an OTA upgrade failure, the backed-up dynamic planning tables can be used for OTA rollback. The A partition space includes multiple partitions allocated to each domain system for storing (first type) data that maintains the normal operation of the domain system. The non-A / B partition space includes multiple partitions allocated to each domain system for storing (second type) data that maintains the normal operation of the domain system.
[0158] In this application, when there is no OTA upgrade requirement, there is no need to specifically allocate a B partition in the EMMC for OTA upgrades. When there is an OTA upgrade requirement, a portion of the storage space is allocated from the dynamic programming space as the B partition space for the domain system, and OTA upgrade data is written to the B partition space. The domain system is then restarted according to the data stored in the B partition space to achieve the OTA upgrade.
[0159] In this application, the dynamic programming tablespace and the dynamic programming table backup space contain the dynamic programming tables of hardware domain 1 to hardware domain 4.
[0160] The dynamic programming table for each hardware domain contains the following:
[0161] Globally Unique Identifier (GPT, GUID Partition Table) (Header): The GPT partition table adopts the standard GUID Partition Table data structure.
[0162] GPT Partition Table (Tail): The GPT partition table uses the standard GUID Partition Table data structure. For details on the GUID Partition Table data structure, please refer to the relevant documentation; it will not be elaborated upon here.
[0163] Dynamic mapping table: Used to represent the mapping relationship between the physical address and logical address of a storage partition. Each domain system's dynamic mapping table maps the physical and logical addresses of the GPT partition table (header and tail) belonging to that domain system, the physical and logical addresses of each partition in the A partition space, the physical and logical addresses of each partition in the B partition space (the B partition space exists during OTA, but does not exist before or after OTA), and the physical and logical addresses of each partition in the non-A / B partition space.
[0164] The EMMC backend software accesses the EMMC based on a dynamic mapping table, in order to read or write data within the partitions of that dynamic mapping table by utilizing the EMMC controller.
[0165] The number of physical address to logical address mappings in the dynamic programming table of a domain system can be determined based on the actual situation of the domain. Typically, mappings are stored in key-value pairs within the dynamic programming table, and the dynamic mapping table within the dynamic programming table records these mappings. In this application, the mappings recorded in the dynamic programming table of the domain system before the OTA upgrade can be used as the original storage information of the domain system. Upon receiving the OTA upgrade package, each domain system can allocate new storage partitions from the dynamic programming space based on its own OTA sub-data. Because new storage partitions have appeared, the mappings in the dynamic mapping table need to be updated, updating the mappings between the physical and logical addresses of the new storage partitions in the dynamic mapping table.
[0166] The specific contents of the dynamic programming tablespace are shown in the table below:
[0167]
[0168]
[0169] It is understandable that, both before and during an OTA upgrade, partitions allocated to the same domain system are typically physically non-contiguous in address space. The technical solution of this application allows for the allocation of contiguous logical addresses to different physical partitions within the same domain system. These contiguous logical addresses can be between different types of physical partitions within the same domain system (e.g., partition A and non-A / B partitions allocated to the domain system), or between partitions within the same type of physical partition (e.g., between partitions within partition A of the domain system, and between partitions within non-A / B partitions). In this way, the non-contiguous physical space of the domain system can be allocated into a space with contiguous logical addresses.
[0170] This application involves, for example Figure 7 The diagram shown illustrates the physical partitioning. In addition, it also involves, for example... Figure 8 The diagram shows a logical partition. Figure 8 A schematic diagram of the logical storage area in an embodiment of this application is shown. For example... Figure 8 As shown, taking domain system 1 as an example, the logical storage area of domain system 1 includes information such as partition table header, each logical partition, and partition table footer. The location of each logical partition in domain system 1 is recorded in the GPT partition table and the spare GPT partition table. In this way, through mapping relationships, discontinuous physical space can be allocated into logically contiguous space, so that the software layer sees a logically contiguous space when accessing the physical space, facilitating access.
[0171] The following describes the detailed process of the technical solution of this application, taking partition A as the running slot for OTA upgrade, a new storage partition (partition B) partitioned from the dynamic programming space as the backup slot for OTA upgrade, and EMMC as the target storage resource.
[0172] 1) Before the SOC chip receives an OTA upgrade package, the dynamic programming tablespace in the EMMC records the mapping relationship between the physical addresses and logical addresses of each domain's current physical partitions (A partitions and non-A partitions). Each domain system reads data from these physical partitions and runs it to maintain the normal operating state of the domain system.
[0173] 2) Within the SOC chip, Domain System 3 can be configured to receive OTA upgrade packages from external sources. The OS of Domain System 3 splits these packages into four parts, sending its own OTA sub-data to the dynamic programming software of Domain System 3. OTA sub-data belonging to other domains is sent to other domain systems via inter-core communication. Domain Systems 1, 2, and 4 receive their own OTA sub-data through inter-core communication. The dynamic programming software running on the OS of Domain Systems 1, 2, and 4 receives their respective OTA sub-data.
[0174] 3) Upon receiving their respective OTA sub-data, the dynamic programming software of each domain system saves its current dynamic programming table to the dynamic programming table backup space to back up the old dynamic programming table before the OTA upgrade. In the event of an OTA upgrade failure, the backed-up old dynamic programming table can be used for rollback.
[0175] 4) Upon receiving their respective OTA sub-data, if each OTA sub-data only involves the upgrade of the first type of data stored in partition A, then the dynamic planning software of each domain system, based on the instruction information of each OTA sub-data, learns the size of the physical partition actually required by each domain system for the OTA sub-data to be upgraded, compared to the current occupancy of the partitions in each domain system, and allocates a physical partition of the corresponding size from the dynamic planning space for the OTA sub-data of each domain as a new storage partition allocated to each domain system.
[0176] In this application, if the currently occupied partition of the domain system for the EMMC is regarded as the running slot for OTA upgrade, and the physical partition required for the OTA sub-data to be upgraded is regarded as the spare slot, then the following four scenarios exist:
[0177] 1. When the number of partitions in the "Spare Slots" exceeds the number of partitions in the "Running Slots," meaning the OTA subdata to be upgraded requires more physical partitions than the domain system currently uses. For example... Figure 9 The hardware domain 1 shown is currently occupied by partitions 1 to n in partition space A. Domain system 1's OTA sub-data requires n+1 partitions, so n+1 partitions are allocated from the dynamic programming space. These n+1 partitions are designated as partition B of domain system 1. The dynamic programming software of domain system 1 records the physical and logical addresses of these n+1 partitions and updates them in the dynamic programming table of domain system 1, thus updating the mapping relationship of the dynamic mapping table. This update at least increases the mapping relationship between the physical and logical addresses of partition B of domain system 1.
[0178] Second, when the number of partitions in the "spare slots" is less than the number of partitions in the "running slots," meaning the number of physical partitions required for the OTA upgrade sub-data is less than the number of partitions currently occupied by the domain system. For example... Figure 9 The hardware domain 2 shown is currently occupied by partitions 1 to m in partition space A. Domain system 2's OTA sub-data requires m-1 partitions, so m-1 partitions are allocated from the dynamic programming space. These m-1 partitions are designated as partition B of domain system 2. The dynamic programming software of domain system 2 records the physical and logical addresses of these m-1 partitions from the dynamic programming space and updates them in the dynamic programming table of domain system 2, thus updating the mapping relationship of domain system 2. This update at least increases the mapping relationship between the physical and logical addresses of partition B of domain system 2.
[0179] In layman's terms, in domain system 2, based on the original A partitions 1 to m, the OTA-upgraded B partition m is deleted. The B partition contains partitions 1 to m-1. The dynamic programming software of hardware domain 2 updates the mapping records of the dynamic mapping table in the dynamic programming table, adding the mapping relationships of each partition to the dynamic mapping table.
[0180] 3. Situations where the number of partitions in the "Spare Slots" remains the same as the number of "Running Slots," but the space occupied by each partition increases. For example... Figure 9 The hardware domain shown is 3. Domain system 3 currently occupies partitions 1 through p in partition space A. Domain system 3's OTA sub-data requires p partitions, but partition 2 among the p partitions needs to be larger than before. Therefore, p partitions are allocated from the dynamic programming space, and the size of partition 2 is increased. The p partitions allocated from the dynamic programming space are designated as partition B of domain system 3. The dynamic programming software of domain system 3 records the physical and logical addresses of the p partitions allocated from the dynamic programming space and updates them to the dynamic programming table of domain system 3, thereby updating the mapping relationship of the dynamic mapping table. This update at least increases the mapping relationship between the physical and logical addresses of partition B of domain system 3.
[0181] IV. Situations where the number of partitions in the "Spare Slots" remains the same as the number of "Running Slots," but the space occupied by each partition is reduced. For example... Figure 9 The hardware domain shown is 4. Domain system 4 currently occupies partitions 1 through q in partition A space. Domain system 4's OTA sub-data requires q partitions, but partition q within those q partitions needs to be smaller than before. Therefore, q partitions are created from the dynamic programming space, and the size of partition q is reduced. The q partitions created from the dynamic programming space become partition B of domain system 4. The dynamic programming software of domain system 4 records the physical and logical addresses of the q partitions created from the dynamic programming space and updates them to the dynamic programming table of domain system 4, thus updating the mapping relationship of the dynamic mapping table. This update at least increases the mapping relationship between the physical and logical addresses of partition B of domain system 4.
[0182] This is understandable, because physical partitions are re-allocated from the dynamic programming space to serve as new storage partitions for each domain system. Therefore, the physical addresses of these new storage partitions for each domain system are different from the physical addresses of the partitions within the A partition space of each domain system. Furthermore, logically contiguous addresses can be allocated to each new storage partition of the domain system as its logical address. In this way, non-contiguous physical partitions within each domain system can be allocated into logically contiguous spaces, facilitating access.
[0183] In most cases, the number of partitions in a "spare slot" is the same as that in a "running slot," with the only difference being the size of each partition. This is typically the case described in scenarios three and four above. However, in practical applications, it's understandable that not only does the number of partitions in a "spare slot" change compared to a "running slot," but the size of at least some of these partitions may also change, such as increasing or decreasing. In this case, combining the relevant content from scenarios one through four above, a new storage partition that meets the OTA sub-data upgrade requirements can be partitioned from the dynamic programming space. This partition space can serve as the B partition space of the domain system. The mapping relationship between the physical and logical addresses of each partition in the B partition space of the domain system is then added to the dynamic mapping table in the dynamic programming table of the domain system.
[0184] It is understandable that the B partition space allocated to the domain system is used to store the OTA sub-data to be upgraded. The data stored in the A partition space of the domain system remains unchanged to facilitate normal operation or rollback before the upgrade.
[0185] The content in step 4) above refers to OTA sub-data for one or more domains that only involves upgrading data stored in partition A. In some application scenarios, such as OTA upgrades of the system itself, upgrades are involved not only for data stored in partition A (Type 1 data) but also for data stored in non-A / B partitions (Type 2 data). For upgrades of data stored in non-A / B partitions, please refer to step 5).
[0186] 5) The dynamic programming software of each domain system parses its respective OTA sub-data. If it finds upgrade data (second type data) related to non-A / B partitions, it calculates the required partition size and / or number of partitions based on the upgrade data belonging to non-A / B partitions in the OTA upgrade data. It then allocates the required size or number of partitions from the dynamic programming space as a new storage partition for the upgrade data related to non-A / B partitions. This new storage partition space can be considered as… Figure 10 The newly added space shown is for the non-A / B partition.
[0187] The dynamic programming software of a domain system will update the dynamic mapping table in the dynamic programming table according to the following four scenarios.
[0188] ① The dynamic programming software determines that the number of partitions occupied by upgrade data related to non-A / B partitions in domain system 1 has increased compared to the original number, such as... Figure 10The hardware domain 1 is shown. The non-A / B partition space of hardware domain 1 consists of partition 1 to partition n-1. Upgrading data requires n partitions, so n partitions are allocated from the dynamic programming space for the upgrade data, serving as new storage partitions for this upgrade data and also as new non-A / B partition space for domain system 1. The dynamic programming software updates the mapping relationships in the dynamic mapping table of domain system 1. For example, it adds the mapping relationship between the physical and logical addresses of each partition in the new non-A / B partition space.
[0189] ② The dynamic programming software found that the number of partitions occupied by upgrade data related to non-A / B partitions in domain system 1 has decreased compared to the original number, such as... Figure 10 The hardware domain 2 is shown. The non-A / B partition space of hardware domain 2 consists of partitions 1 to m. Upgrading data requires m-1 partitions, so m-1 partitions are allocated from the dynamic programming space for the upgrade data (partition 2 is deleted) as new storage partitions for this upgrade data, and also as new space for the non-A / B partitions of domain system 2. The dynamic programming software updates the mapping relationships in the dynamic mapping table of domain system 2. For example, it adds the mapping relationship between the physical addresses and logical addresses of each partition in the newly added space of the non-A / B partitions.
[0190] ③ The dynamic programming software learns that the upgrade data related to non-A / B partitions in domain system 3 has increased the size of one or more partitions compared to the original size, such as... Figure 10 The hardware domain 3 is shown. The number of partitions used for the upgrade data remains the same, but the size of partition 2 needs to be increased. Therefore, the required number of partitions for the upgrade data and the increased size of partition 2 are allocated from the dynamic programming space. These allocated partitions serve as new storage partitions for the upgrade data and also as new space for the non-A / B partitions in domain system 3. The dynamic programming software updates the mapping relationships in the dynamic mapping table of domain system 3. For example, it adds the mapping relationship between the physical and logical addresses of each partition in the new space of the non-A / B partitions.
[0191] ④ The dynamic programming software learns that the size of one or more partitions in domain system 4, which are related to upgrade data for non-A / B partitions, has decreased or shrunk compared to the original size. Figure 10 The hardware domain 4 is shown. The number of partitions used for the upgrade data remains the same, but the size of partition 1 needs to be reduced. Therefore, the required number of partitions for the upgrade data and the size of partition 1 need to be reduced are allocated from the dynamic programming space. These partitions serve as new storage partitions for the upgrade data and also as new space for the non-A / B partitions in domain system 4. The dynamic programming software updates the mapping relationships in the dynamic mapping table of domain system 4. For example, it adds the mapping relationship between the physical and logical addresses of each partition in the new space of the non-A / B partitions.
[0192] Because physical partitions are created from the dynamic programming space to form new storage partitions for the non-A / B partitions of each domain system, the physical addresses of these new storage partitions are different from the physical addresses of the partitions within the non-A / B partition space of each domain system. Furthermore, logically contiguous addresses can be allocated to each new storage partition within the non-A / B partition space of the domain system as its logical address. In this way, non-A / B physical partitions with non-contiguous physical addresses in each domain system can be allocated into logically contiguous spaces for easy access.
[0193] As can be seen from steps 4) and 5), the new storage partitions in the domain system, compared to the partitions before the OTA upgrade requirement, may exhibit variations in the number of partitions, their size, etc. For a single domain system, the specific scenario depends on the specific circumstances. Regardless of the scenario, space sufficient to meet the OTA data upgrade requirements can be allocated from the dynamic planning space, providing a certain level of assurance for OTA upgrades.
[0194] 6) When the dynamic programming software of each domain system updates the mapping relationships in the dynamic mapping table, the dynamic programming software synchronizes the update results to the EMMC backend software through the EMMC frontend software. Specifically, the EMMC frontend software of domain system 2 directly synchronizes the update results to the EMMC backend software. The EMMC frontend software of domain systems 1, 2, and 4 need to synchronize their respective update results to the EMMC backend software located in domain system 2 through an inter-core communication mechanism.
[0195] The EMMC backend software, based on the updated mapping relationships of each domain system, controls the EMMC controller to adjust the ownership of physical partitions, thereby enabling the allocation of storage resources. Specifically, it assigns the identifier of the domain system to each newly allocated physical partition, thus completing the adjustment of physical partitions. For example, it allocates previously idle physical partition 1 to domain system 1, and previously idle physical partition 2 to domain system 2, and so on.
[0196] After the EMMC backend software has completed the above operations for each domain, the dynamic programming software considers that it has successfully allocated the required physical storage resources and still needs to perform the following updates:
[0197] From a physical perspective, partitioning new storage space from the dynamic programming space changes the physical storage space usage of each domain system. Assigning logical addresses to each physical partition also changes the logical storage space of each domain system. For example... Figure 11As shown, consider domain system 1 and domain system 2. Before the OTA upgrade, the logical storage area of domain system 1 included n A partitions and no logical B partitions. During the OTA upgrade, the logical storage area of domain system 1 included n A partitions and B partitions, with one more B partition than A partitions. Before the OTA upgrade, the logical storage area of domain system 2 included m A partitions and no B partitions. During the OTA upgrade, the logical storage area of domain system 2 included m A partitions and B partitions, with one less B partition than A partitions. It is evident that changes in physical partitions lead to changes in the logical partitions of each domain system. To address these changes, the dynamic programming software needs to update the partition table header and footer of each domain system. Specifically, the partition table (header) needs to add the logical location of the B partitions, indicated by logical addresses. The addresses of each partition in the partition table (footer) must remain consistent with those in the partition table (header).
[0198] from Figure 11 As can be seen from the comparison of the dynamic programming table and the partition table before and after the update, before the OTA upgrade, each domain system only contained partition A in the logical storage space. After the update, the logical storage space contains both partition A and partition B, and each partition of A / B uses a different logical address, and the logical addresses of each partition are consecutive.
[0199] 7) Write the OTA sub-data of each domain system to the new physical partition allocated from the dynamic programming space, according to the physical address indicated by the updated dynamic mapping table of each domain system. Reboot each domain system according to the data written to each physical partition.
[0200] If the reboot fails, the OTA upgrade fails. If the reboot succeeds, the OTA upgrade succeeds.
[0201] 8) If the OTA upgrade fails, you can do the following:
[0202] ① Restore the old dynamic programming table that was backed up before the upgrade from the dynamic programming table backup space. Based on the data in the physical partitions recorded in this dynamic programming table, perform OTA data rollback to avoid disrupting the normal use of the domain system.
[0203] Because the upgrade failed, the data stored in the B partition space, or the non-A / B partitions, which were partitioned from the dynamic programming space, is considered useless data. Delete this useless data and release the B partition space, or the non-A / B partitions. Return the released physical space to the EMMC's dynamic programming space in preparation for the next partitioning. Delete the mapping records in the dynamic programming table related to the B partition space, or the newly added space in the B partitions and non-A / B partitions.
[0204] ② Restore the partition table (header) and partition table (tail) before the upgrade from the dynamic planning table backup space, delete the logical partitions corresponding to the B partition space of the A / B partition, and restore the A partition and the logical partitions of the non-A / B partitions before the upgrade.
[0205] The above operations are all performed to enable OTA rollback, in order to avoid the problem of the domain system being unable to be used normally due to OTA upgrade failure and inability to roll back.
[0206] 9) If the OTA upgrade is successful, the domain system will operate normally using the updated dynamic programming table and partition table. Data stored in partition A is considered useless data. The domain system's dynamic programming software will delete this data, releasing partition A and using partition B, which was partitioned from the dynamic programming space, as partition A. Specifically, the dynamic programming software will perform the following operations:
[0207] ① Delete the data stored in partition A of the EMMC, release partition A, delete the mapping relationship between partition A and the physical space to the logical space, and return the released physical space to the dynamic programming space. Name partition B, which is partitioned from the dynamic programming space, partition A.
[0208] ② Update the partition tables and spare partition tables of each domain system, and at least delete the logical partition corresponding to partition A in partition table.
[0209] ③ Synchronize the updated dynamic programming table to the dynamic programming table backup space to achieve backup of the latest dynamic programming table.
[0210] Figure 12 This diagram illustrates the EMMC partitioning after a successful OTA upgrade. This is understandable. Figure 12 This diagram illustrates the EMMC partitioning after a successful upgrade, assuming only upgrade data related to partition A. Within the EMMC, the original partition A space for each domain system is released and allocated to the dynamic programming space, preparing for the next OTA upgrade. Partition B, partitioned from the dynamic programming space, is used as partition A space. After a successful OTA upgrade, each domain system can utilize the data within this partition space to ensure normal operation.
[0211] It is understandable that after an OTA upgrade, the size of the physical partitions occupied by each domain system in the EMMC changes. Compared with the original EMMC usage of each domain system, there may be instances of adding, deleting, expanding, or shrinking partitions, all of which are recorded in the dynamic mapping table. A schematic diagram of the logical storage areas of each domain system after the upgrade can be found here. Figure 13 As shown. In Figure 13Taking an upgrade of only data related to partition A as an example, during an OTA upgrade, because a new storage partition is physically allocated to the domain system, logically, the logical storage area includes not only partition A and non-A / B partitions, but also partition B. After a successful OTA upgrade, the physical partition A is released, and partition B is used as partition A. Logically, the logical storage area includes partition A and non-A / B partitions.
[0212] from Figure 12 and Figure 13 In terms of the upgrade effect shown, at the physical level, there is no need to reserve two dedicated storage areas for OTA upgrades; only one partition A space is required. When OTA upgrades are needed, partition B space is created from the dynamic programming space to utilize the data within partition B for OTA data upgrades. At the logical level, the partitioning of logical storage areas must be consistent with the partitioning at the physical level, and there is no need to reserve two logical storage areas. Thus, OTA upgrades can be achieved without excessive physical and logical resource consumption, proposing a new OTA upgrade solution that minimizes resource consumption.
[0213] Unlike related technologies where physical partitions cannot be changed once assigned to a domain system, this application's solution reallocates B partition space to the domain system for each OTA upgrade request, releasing the original A partition space. This allows the same domain system to occupy different physical partitions during different OTA upgrade requests. Unlike related static partitioning schemes where a single domain system can only occupy a fixed number of physical partitions, this application's solution provides a flexible, dynamic allocation of storage partitions for the domain system. This dynamic allocation scheme offers high flexibility and avoids the resource waste associated with static partitioning.
[0214] Compared to static partitioning schemes, which cannot add, reduce, or expand / shrink partitions, the flexibility of this application's technical solution allows for the addition or reduction of the number of partitions and the expansion or reduction of the size of one or more individual partitions when allocating new storage partitions as B partition space from the dynamic planning space. This enables the fulfillment of various OTA upgrade package upgrade requirements. This scheme, which adjusts the number and / or size of partitions, is more flexible than static partitioning schemes and better suited to the different needs of various OTA upgrade packages.
[0215] In related technologies, static partitioning schemes require reserving two storage areas to achieve OTA upgrades, meaning two sets of partitions are needed. Two sets of partitions undoubtedly increase storage resource consumption and waste. The technical solution in this application eliminates the need for two sets of partitions; generally, reserving one partition for the domain system is sufficient. When OTA upgrades are needed, a new storage partition is created from the dynamically allocated space as the other set of partitions, thus enabling OTA upgrades. OTA upgrades can be achieved without excessive storage resource consumption. This approach is easy to implement and promote in engineering.
[0216] When the multi-core heterogeneous SoC of this application is applied to vehicles, OTA (Over-The-Air) upgrades can be achieved without excessively consuming the vehicle's storage resources. Furthermore, the upgrade flexibility is excellent.
[0217] This application also provides an over-the-air (OTA) data upgrade device, located in a multi-core heterogeneous system. The multi-core heterogeneous system includes at least two hardware domains. Each hardware domain consists of multiple processor cores with different architectures within the multi-core heterogeneous system, as well as hardware resources connected to each processor core. The hardware domains are isolated from each other. Each hardware domain is configured with an independently running operating system, and each hardware domain and its operating system constitute a domain system. Figure 14 As shown, the device includes:
[0218] The first acquisition unit 1001 is used to acquire the OTA data to be upgraded;
[0219] The second obtaining unit 1002 is used to obtain OTA sub-data of each domain system and original storage information of each domain system from the OTA data to be upgraded. The original storage information is used to characterize the mapping relationship between the physical address and the logical address of the original storage partition of each domain system. The original storage partition of each domain system is the storage partition allocated to each domain system in the first storage space of the target storage resource.
[0220] The first allocation unit 1003 is used to allocate new storage partitions for each domain system from the second storage space of the target storage resource based on the indication information of the OTA sub-data of each domain system and the original storage information of each domain system.
[0221] The third obtaining unit 1004 is used to obtain new storage information for each domain system based on the new storage partitions allocated to each domain system;
[0222] The upgrade unit 1005 is used to upgrade the OTA sub-data of each domain system based on the new storage information of each domain system, so as to realize the upgrade of the OTA data to be upgraded in the multi-core heterogeneous system.
[0223] In some embodiments, the original storage information includes the number of original storage partitions; the number of original storage partitions in each domain system is at least two.
[0224] The first allocation unit 1003 is configured to: if the indication information of at least one domain system OTA sub-data indicates that the number of storage partitions occupied by the OTA sub-data of the domain system is the same as the number of original storage partitions of the domain system, then allocate the same number of new storage partitions to the domain system from the second storage space of the target storage resource.
[0225] Wherein, when the new storage information of the domain system is used to represent the mapping relationship between the physical address and the logical address of each new storage partition, the physical address of each new storage partition of the domain system is different from the physical address of each original storage partition, and the logical address of each new storage partition is different from the logical address of each original storage partition.
[0226] In some embodiments, when the OTA subdata of the domain system occupies the same size as the original storage partitions, the logical address that is consecutive to the logical address of the original storage partition is used as the logical address of the new storage partition.
[0227] In some embodiments, the original storage information includes the number of original storage partitions; the number of original storage partitions in each domain system is at least two.
[0228] The first allocation unit 1003 is used for:
[0229] If the indication information of at least one domain system OTA sub-data is used to indicate that the number of storage partitions occupied by the OTA sub-data of the domain system is different from the number of original storage partitions of the domain system, then the number of new storage partitions required by the OTA sub-data are allocated to the domain system from the second storage space of the target storage resource.
[0230] Wherein, when the new storage information of the domain system is used to represent the mapping relationship between the physical address and logical address of each new storage partition, the physical address of each new storage partition of the domain system is different from the physical address of the original storage partition, and the logical address of each new storage partition is different from the logical address of the original storage partition.
[0231] In some embodiments, the original storage information includes the size of the original storage partition;
[0232] The first allocation unit 1003 is used for:
[0233] If the indication information of at least one domain system OTA sub-data is used to indicate that the size of the OTA sub-data of the domain system occupied by the storage partition is different from the size of the original storage partition of the domain system, then multiple new storage partitions of the required size of the OTA sub-data are allocated to the domain system from the second storage space of the target storage resource.
[0234] Wherein, when the new storage information of the domain system is used to represent the mapping relationship between the physical address and the logical address of each new storage partition, the physical address of each new storage partition of the domain system is different from the physical address of the original storage partition, and the logical address of each new storage partition is different from the logical address of the original storage partition.
[0235] In some embodiments, the target storage resource is used to store at least a first type of data and a second type of data; the original storage information is used to characterize at least the mapping relationship between the physical address and logical address of the original storage partition for the first type of data, and the mapping relationship between the physical address and logical address of the original storage partition for the second type of data.
[0236] The first allocation unit 1003 is used for:
[0237] When the OTA sub-data of at least one domain system is first type data, based on the indication information of the OTA sub-data of the domain system and the original storage information of the domain system, a new storage partition is allocated from the second storage space of the target storage resource for the first type data of the domain system, as a new storage partition allocated to each domain system.
[0238] The new storage information of the domain system includes the mapping relationship between the physical addresses of each new storage area and the logical addresses of each new storage partition for the first type of data, and the mapping relationship between the physical addresses and logical addresses of the original storage partitions for the second type of data.
[0239] In some embodiments, the first allocation unit 1003 is configured to:
[0240] When the OTA sub-data of at least one domain system includes a first type of data and a second type of data, based on the indication information of the OTA sub-data of the domain system and the original storage information of the domain system, a new storage partition is allocated from the second storage space of the target storage resource for the first type of data of the domain system and a new storage partition is allocated for the second type of data of the domain system, as the new storage partition allocated to the domain system.
[0241] The physical address of the new storage partition allocated for the first type of data is different from the physical address of the new storage partition allocated for the second type of data.
[0242] The new storage information of the domain system includes the mapping relationship between the physical address and the logical address of each new storage partition for the first type of data, and the mapping relationship between the physical address and the logical address of each new storage partition for the second type of data.
[0243] In some embodiments, the device further includes: a second allocation unit, configured to:
[0244] Obtain at least one of the following information: the number and size of the storage partitions required for the second type of data;
[0245] Based on at least one of the information, a new storage partition is allocated for the second type of data of the domain system from the second storage space of the target storage resource, the physical address of the new storage partition and the logical address allocated to the new storage partition are obtained, and based on the physical address and logical address of the new storage partition, the mapping relationship between the physical address and logical address of the new storage partition for the second type of data is obtained.
[0246] The physical addresses of the new storage partitions allocated for the second type of data are different from the physical addresses of the original storage partitions for the second type of data, and the logical addresses of the new storage partitions allocated for the second type of data are different from the logical addresses of the original storage partitions for the second type of data.
[0247] In some embodiments, the device further includes a first response unit and a second response unit.
[0248] The first response unit is used to respond to the successful upgrade of the OTA data to be upgraded in the multi-core heterogeneous system, delete the data stored in the original storage partition of each domain system, and assign the original storage partition to the second storage space of the target storage resource.
[0249] The second response unit is used to back up the original storage information of each domain system in the third storage space of the target storage resource. In response to the failure of the OTA data to be upgraded in the multi-core heterogeneous system, it obtains the original storage information of each domain system in the third storage space, and restarts each domain system according to the storage data in the original storage partition in the original storage information of each domain system, so as to realize the rollback of OTA data.
[0250] It should be noted that the OTA data upgrade device in this application embodiment solves the problem in a similar way to the aforementioned OTA data upgrade method. Therefore, the implementation process and implementation principle of the OTA data upgrade device can be found in the description of the implementation process and implementation principle of the aforementioned method, and the repeated parts will not be repeated.
[0251] According to embodiments of this application, this application also provides an electronic device and a readable storage medium.
[0252] The electronic device includes at least one processor and a memory communicatively connected to the at least one processor. The memory stores instructions executable by the at least one processor, which, when executed, enable the at least one processor to perform the ISP parameter adjustment method described in this application. The computer instructions are used to cause the computer to perform the OTA data upgrade method described in this application.
[0253] This application also provides a computer program product, including a computer program / instructions, which, when executed by a processor, implement the OTA data upgrade method of this application.
[0254] Figure 15 A schematic block diagram of an example electronic device 800 that can be used to implement embodiments of this application is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the application described and / or claimed herein.
[0255] like Figure 15 As shown, device 800 includes a computing unit 801, which can perform various appropriate actions and processes based on a computer program stored in read-only memory (ROM) 802 or a computer program loaded from storage unit 808 into random access memory (RAM) 803. RAM 803 may also store various programs and data required for the operation of device 800. The computing unit 801, ROM 802, and RAM 803 are interconnected via bus 804. Input / output (I / O) interface 805 is also connected to bus 804.
[0256] Multiple components in device 800 are connected to I / O interface 805, including: input unit 806, such as keyboard, mouse, etc.; output unit 807, such as various types of monitors, speakers, etc.; storage unit 808, such as disk, optical disk, etc.; and communication unit 809, such as network card, modem, wireless transceiver, etc. Communication unit 809 allows device 800 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0257] The computing unit 801 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 801 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 801 performs the various methods and processes described above, such as the OTA data upgrade method. For example, in some embodiments, the OTA data upgrade method may be implemented as a computer software program tangibly contained in a machine-readable medium, such as storage unit 808. In some embodiments, part or all of the computer program may be loaded and / or installed on device 800 via ROM 802 and / or communication unit 809. When the computer program is loaded into RAM 803 and executed by the computing unit 801, one or more steps of the OTA data upgrade method described above may be performed. Alternatively, in other embodiments, the computing unit 801 may be configured to perform the OTA data upgrade method by any other suitable means (e.g., by means of firmware).
[0258] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0259] The program code used to implement the methods of this application may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing device, such that when executed by the processor or controller, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0260] In the context of this application, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. Machine-readable media can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0261] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0262] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as a data server), or computing systems that include middleware components (e.g., an application server), or computing systems that include frontend components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with embodiments of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., a communication network). Examples of communication networks include local area networks (LANs), wide area networks (WANs), and the Internet.
[0263] Computer systems can include clients and servers. Clients and servers are generally located far apart and typically interact via communication networks. Client-server relationships are created by computer programs running on the respective computers and having a client-server relationship with each other. Servers can be cloud servers, servers in distributed systems, or servers incorporating blockchain technology.
[0264] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A method for upgrading data using Over-the-Air (OTA) technology, characterized in that, The invention is applied to a multi-core heterogeneous system, which includes at least two hardware domains. Each hardware domain consists of multiple processor cores with different architectures in the multi-core heterogeneous system and hardware resources connected to each processor core. The hardware domains are isolated from each other. Each hardware domain is configured with an independently running operating system, and each hardware domain and its operating system constitute the domain system; the method includes: Obtain the OTA data to be upgraded; The OTA sub-data of each domain system and the original storage information of each domain system are obtained from the OTA data to be upgraded. The original storage information is used to characterize the mapping relationship between the physical address and the logical address of the original storage partition of each domain system. The original storage partition of each domain system is the storage partition allocated to each domain system in the first storage space of the target storage resource. Based on the indication information of OTA sub-data of each domain system and the original storage information of each domain system, new storage partitions are allocated for each domain system from the second storage space of the target storage resource. Based on the new storage partitions allocated to each domain system, new storage information for each domain system is obtained; Based on the new storage information of each domain system, the OTA sub-data of each domain system is upgraded to realize the upgrade of the OTA data to be upgraded in the multi-core heterogeneous system.
2. The method according to claim 1, characterized in that, The original storage information includes the number of original storage partitions; each domain system has at least two original storage partitions. Based on the indication information of OTA sub-data of each domain system and the original storage information of each domain system, new storage partitions are allocated for each domain system from the second storage space of the target storage resource, including: If the indication information of at least one domain system OTA sub-data is used to indicate that the number of storage partitions occupied by the OTA sub-data of the domain system is the same as the number of original storage partitions of the domain system, then the same number of new storage partitions are allocated to the domain system from the second storage space of the target storage resource. Wherein, when the new storage information of the domain system is used to represent the mapping relationship between the physical address and the logical address of each new storage partition, the physical address of each new storage partition of the domain system is different from the physical address of each original storage partition, and the logical address of each new storage partition is different from the logical address of each original storage partition.
3. The method according to claim 2, characterized in that, When the OTA subdata of the domain system occupies the same size as the original storage partitions, the logical address that is consecutive to the logical address of the original storage partitions will be used as the logical address of the new storage partitions.
4. The method according to claim 1, characterized in that, The original storage information includes the number of original storage partitions; each domain system has at least two original storage partitions. Based on the indication information of OTA sub-data of each domain system and the original storage information of each domain system, new storage partitions are allocated for each domain system from the second storage space of the target storage resource, including: If the indication information of at least one domain system OTA sub-data is used to indicate that the number of storage partitions occupied by the OTA sub-data of the domain system is different from the number of original storage partitions of the domain system, then the number of new storage partitions required by the OTA sub-data are allocated to the domain system from the second storage space of the target storage resource. Wherein, when the new storage information of the domain system is used to represent the mapping relationship between the physical address and logical address of each new storage partition, the physical address of each new storage partition of the domain system is different from the physical address of the original storage partition, and the logical address of each new storage partition is different from the logical address of the original storage partition.
5. The method according to claim 1, characterized in that, The original storage information includes the size of the original storage partition; Based on the indication information of OTA sub-data of each domain system and the original storage information of each domain system, new storage partitions are allocated for each domain system from the second storage space of the target storage resource, including: If the indication information of at least one domain system OTA sub-data is used to indicate that the size of the OTA sub-data of the domain system occupied by the storage partition is different from the size of the original storage partition of the domain system, then multiple new storage partitions of the required size of the OTA sub-data are allocated to the domain system from the second storage space of the target storage resource. Wherein, when the new storage information of the domain system is used to represent the mapping relationship between the physical address and the logical address of each new storage partition, the physical address of each new storage partition of the domain system is different from the physical address of the original storage partition, and the logical address of each new storage partition is different from the logical address of the original storage partition.
6. The method according to claim 1, characterized in that, The target storage resource is used to store at least the first type of data and the second type of data; The original storage information is used at least to characterize the mapping relationship between the physical address and logical address of the original storage partition for the first type of data, and the mapping relationship between the physical address and logical address of the original storage partition for the second type of data. Based on the indication information of OTA sub-data of each domain system and the original storage information of each domain system, new storage partitions are allocated for each domain system from the second storage space of the target storage resource, including: When the OTA sub-data of at least one domain system is first type data, based on the indication information of the OTA sub-data of the domain system and the original storage information of the domain system, a new storage partition is allocated from the second storage space of the target storage resource for the first type data of the domain system, as a new storage partition allocated to each domain system. The new storage information of the domain system includes the mapping relationship between the physical addresses of each new storage area for the first type of data and the logical addresses of each new storage partition, and the mapping relationship between the physical addresses and logical addresses of the original storage partitions for the second type of data.
7. The method according to claim 6, characterized in that, The method further includes: When the OTA sub-data of at least one domain system includes a first type of data and a second type of data, based on the indication information of the OTA sub-data of the domain system and the original storage information of the domain system, a new storage partition is allocated from the second storage space of the target storage resource for the first type of data of the domain system and a new storage partition is allocated for the second type of data of the domain system, as the new storage partition allocated to the domain system. The physical address of the new storage partition allocated for the first type of data is different from the physical address of the new storage partition allocated for the second type of data. The new storage information of the domain system includes the mapping relationship between the physical address and the logical address of each new storage partition for the first type of data, and the mapping relationship between the physical address and the logical address of each new storage partition for the second type of data.
8. The method according to claim 6 or 7, characterized in that, The method further includes: Obtain at least one of the following information: the number and size of the storage partitions required for the second type of data; Based on at least one of the information, a new storage partition is allocated for the second type of data of the domain system from the second storage space of the target storage resource, the physical address of the new storage partition and the logical address allocated to the new storage partition are obtained, and based on the physical address and logical address of the new storage partition, the mapping relationship between the physical address and logical address of the new storage partition for the second type of data is obtained. The physical addresses of the new storage partitions allocated for the second type of data are different from the physical addresses of the original storage partitions for the second type of data, and the logical addresses of the new storage partitions allocated for the second type of data are different from the logical addresses of the original storage partitions for the second type of data.
9. The method according to claim 1, characterized in that, The method further includes: In response to the successful upgrade of the OTA data to be upgraded in the multi-core heterogeneous system, the data stored in the original storage partition of each domain system is deleted, and the original storage partition is assigned to the second storage space of the target storage resource. Back up the original storage information of each domain system in the third storage space of the target storage resource. In response to the failure of the OTA data to be upgraded in the multi-core heterogeneous system, obtain the original storage information of each domain system in the third storage space. According to the storage data in the original storage partition in the original storage information of each domain system, restart each domain system to realize the rollback of OTA data.
10. An upgrade device for Over-the-Air (OTA) data download technology, characterized in that, The device is located in a multi-core heterogeneous system, which includes at least two hardware domains. Each hardware domain consists of multiple processor cores with different architectures in the multi-core heterogeneous system and hardware resources connected to each processor core. The hardware domains are isolated from each other. Each hardware domain is configured with an independently running operating system, and each hardware domain and its operating system constitute the domain system; the device includes: The first acquisition unit is used to acquire the OTA data to be upgraded. The second obtaining unit is used to obtain OTA sub-data of each domain system and original storage information of each domain system from the OTA data to be upgraded. The original storage information is used to characterize the mapping relationship between the physical address and the logical address of the original storage partition of each domain system. The original storage partition of each domain system is the storage partition allocated to each domain system in the first storage space of the target storage resource. The first allocation unit is used to allocate new storage partitions for each domain system from the second storage space of the target storage resource based on the indication information of the OTA sub-data of each domain system and the original storage information of each domain system. The third acquisition unit is used to obtain the new storage information of each domain system based on the new storage partitions allocated to each domain system; The upgrade unit is used to upgrade the OTA sub-data of each domain system based on the new storage information of each domain system, so as to realize the upgrade of the OTA data to be upgraded in the multi-core heterogeneous system.
Citation Information
Patent Citations
Multi-core heterogeneous system-on-chip updating method and device, chip and traffic equipment
CN116775085A
OTA upgrading method, code mirror image loading processing method, system and vehicle
CN117785253A