Encrypted firmware upgrading method and device based on EtherCAT, equipment and storage medium

Through the EtherCAT-based encryption firmware upgrade method, the hardware interface requirements and firmware leakage problems during the IO product firmware upgrade process are solved, encryption processing and firmware integrity verification are realized, ensuring the security and consistency of the upgrade process.

CN119939609AActive Publication Date: 2025-05-06SHENZHEN MATRIBOX TECH CO LTD

Patent Information

Application Number
CN202510429187.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-08
Publication Date
2025-05-06
Estimated Expiration
2045-04-08

AI Technical Summary

Technical Problem

During the firmware upgrade process, existing IO products need to leave a hardware interface and may lead to firmware file leakage.

Method used

The encryption firmware upgrade method based on EtherCAT is adopted. By receiving the encryption firmware sent by the main station and writing it to the backup buffer and firmware update information area, byte filling alignment and encryption are performed to ensure the security of the firmware during the upgrade process.

Benefits of technology

The encryption processing during the firmware upgrade process is realized, the leakage of firmware content is avoided, and the integrity and consistency of the firmware is ensured through the verification of cyclic redundancy check value.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939609A_ABST
    Figure CN119939609A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides an EtherCAT-based encrypted firmware upgrading method and device, equipment and a medium. The method comprises the steps of entering a guide state according to a guide request; receiving encrypted firmware, writing the encrypted firmware into a backup buffer area, writing byte information of an encrypted firmware file into a firmware updating information area, and setting a file transmission completion flag bit; when an initialization request which is sent by the master station and used for requesting to enter an initialization state is received and transmission is completed, slave station software is triggered to be restarted, and a bootstrap program is executed; when the bootstrap program detects that the byte information of the firmware file received by the firmware update information area is not zero, reading the encrypted firmware of the backup buffer area, processing the encrypted firmware to obtain actual decrypted firmware, and calculating an actual cyclic redundancy check value; and when the actual cyclic redundancy check value is the same as the preset cyclic redundancy check value, erasing the information of the APP execution area, writing the actual decryption firmware into the APP execution area, and triggering the slave station software to be restarted.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of equipment software technology upgrade and related technical fields, and in particular to an EtherCAT-based encrypted firmware upgrade method, device, equipment and storage medium. Background Art

[0002] With the development of industrial automation and IoT technology, the demand for IO products in industrial automation systems is increasing. These IO products communicate with the system master through different buses (such as RS485 interface, etc.) to achieve data input and output. However, in the mass production of IO products, product iterations, and different scenarios of user sites, firmware upgrades have become an important and frequent demand. The current status of different bus expansion IO products and their firmware upgrades is discussed.

[0003] In the prior art, most slave station firmware upgrades use serial ports or 485 interfaces. Therefore, the hardware corresponding to the slave station firmware needs to retain the corresponding hardware interface, and during the upgrade process, the original firmware needs to be placed in the slave station, which may cause the leakage of the firmware file. Summary of the invention

[0004] The embodiments described herein provide an EtherCAT-based encrypted firmware upgrade method, apparatus, device, and storage medium to solve the problems existing in the prior art.

[0005] In a first aspect, according to the content of the present disclosure, there is provided an EtherCAT-based encrypted firmware upgrade method, comprising: When receiving a boot request sent by the master station for entering the boot state, entering the boot state according to the boot request; When a file transfer request sent by a master station is received and the file transfer password in the file transfer request passes verification, the encrypted firmware is received and written into a backup buffer, and when the encrypted firmware file is received, the byte information of the received encrypted firmware file is written into a firmware update information area, and a file transfer completion flag is set, wherein the encrypted firmware is a firmware obtained by calculating a preset cyclic redundancy check value after four-byte alignment of the firmware, and then appending the preset cyclic redundancy check value to obtain the initial firmware, and then performing byte padding alignment and encryption; Upon receiving an initialization request sent by the master station for entering an initialization state, determining a file transfer completion flag, and if the transfer is completed, triggering a slave station software restart, and executing the boot program, so that the boot program detects byte information of the firmware file in the firmware update information area; When the boot program detects that the firmware file byte information received in the firmware update information area is not zero, reading the encrypted firmware in the backup buffer and processing the encrypted firmware to obtain the actual decrypted firmware and calculate the actual cyclic redundancy check value; When the actual cyclic redundancy check value is the same as the preset cyclic redundancy check value, the information of the APP execution area is erased, the firmware update information area is erased, and the actual decrypted firmware is written into the APP execution area, thereby triggering the restart of the slave station software.

[0006] In some embodiments of the present disclosure, when receiving a boot request sent by a master station to request entering a boot state, entering the boot state according to the boot request includes: When receiving a boot request sent by the master station for entering a boot state, obtaining a target state in the boot request; The target state in the boot request is written into the control bit of the slave station, so that the slave station enters the boot state according to the target state of the control bit.

[0007] In some embodiments of the present disclosure, the step of reading the encrypted firmware in the backup buffer and processing the encrypted firmware to obtain the actual decrypted firmware and calculate the actual cyclic redundancy check value includes: Reading the encrypted firmware in the backup buffer and processing the encrypted firmware to obtain actual decrypted firmware; According to the actual decrypted firmware, an actual cyclic redundancy check value is calculated.

[0008] In some embodiments of the present disclosure, the step of reading the encrypted firmware in the backup buffer and processing the encrypted firmware to obtain the actual decrypted firmware includes: Reading the encrypted firmware in the backup buffer, and decrypting the encrypted firmware using a decryption algorithm to obtain initial decrypted firmware; The padding bytes of the initial decrypted firmware are removed based on a data padding algorithm to obtain the actual decrypted firmware.

[0009] In some embodiments of the present disclosure, before receiving the encrypted firmware and writing the encrypted firmware into the backup buffer, the process further includes: Enable firmware write permission.

[0010] In some embodiments of the present disclosure, the method further includes: When the boot program detects that the byte information of the firmware file received in the firmware update information area is zero, the EtherCAT protocol stack included in the APP execution area is run.

[0011] In some embodiments of the present disclosure, the method further includes: When the actual cyclic redundancy check value is different from the cyclic redundancy check value, a slave station software restart is triggered.

[0012] In a second aspect, according to the content of the present disclosure, there is provided an encrypted firmware upgrade device based on EtherCAT, comprising: A boot state entry module, configured to enter the boot state according to the boot request when receiving a boot request sent by the master station for entering the boot state; An information writing module is used to receive the encrypted firmware and write the encrypted firmware into the backup buffer when a file transfer request sent by the master station is received and the file transfer password in the file transfer request is verified, and when the encrypted firmware file is received, write the byte information of the received encrypted firmware file into the firmware update information area and set the file transfer completion flag, wherein the encrypted firmware is the firmware obtained by byte padding alignment and encryption after calculating a preset cyclic redundancy check value after four-byte alignment of the firmware, and then appending the preset cyclic redundancy check value to obtain the initial firmware; A startup module, configured to, upon receiving an initialization request sent by the master station to enter an initialization state, determine a file transfer completion flag, and if the transfer is completed, trigger a slave station software restart, and execute the boot program, so that the boot program detects byte information of the firmware file in the firmware update information area; An encrypted firmware file processing module is used to read the encrypted firmware in the backup buffer and process the encrypted firmware when the boot program detects that the firmware file byte information received in the firmware update information area is not zero, obtain the actual decrypted firmware and calculate the actual cyclic redundancy check value; The firmware update module is used to erase the information of the APP execution area, erase the firmware update information area, and write the actual decrypted firmware into the APP execution area when the actual cyclic redundancy check value is the same as the preset cyclic redundancy check value, thereby triggering the restart of the slave station software.

[0013] In a third aspect, according to the present disclosure, there is provided a computer device, including: one or more processors; a storage device for storing one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors implement any method as described in the first aspect.

[0014] In a fourth aspect, according to the content of the present disclosure, a computer-readable storage medium is provided, on which a computer program is stored, and when the program is executed by a processor, it implements any method as described in the first aspect.

[0015] The EtherCAT-based encrypted firmware upgrade method, device, equipment and medium provided by the embodiments of the present disclosure enter the boot state according to the boot request when receiving a boot request sent by the master station to enter the boot state; receive the encrypted firmware and write the encrypted firmware into the backup buffer when receiving the file transfer request sent by the master station and the file transfer password in the file transfer request is verified; and when the encrypted firmware file is received, write the byte information of the received encrypted firmware file into the firmware update information area and set the file transfer completion flag; when receiving the initialization request sent by the master station to enter the initialization state, judge the file transfer completion flag, if the transfer is completed, trigger the slave station software to restart, and execute the boot program, so that the boot program detects the byte information of the firmware file in the firmware update information area; when the boot program detects that the byte information of the firmware file received in the firmware update information area is not zero, read the encrypted firmware in the backup buffer and process the encrypted firmware to obtain the actual decrypted firmware and calculate the actual cyclic redundancy check value; when the actual cyclic redundancy check value is the same as the preset cyclic redundancy check value, erase the information of the APP execution area, erase the firmware update information area, and write the actual decrypted firmware into the APP execution area, thereby triggering the slave station software to restart. When upgrading the firmware, on the one hand, the firmware written to the slave station is encrypted firmware to avoid leakage of the content in the firmware. On the other hand, since the firmware written to the slave station is encrypted firmware, the encrypted firmware is decrypted through the corresponding decryption method, and then the actual cyclic redundancy check value of the decrypted firmware is verified to be the same as the cyclic redundancy check value corresponding to the encrypted firmware file received by the slave station. It is determined whether the slave station has received the complete encrypted firmware, and then the firmware is updated.

[0016] The above description is only an overview of the technical solution of the embodiment of the present application. In order to more clearly understand the technical means of the embodiment of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the embodiment of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] In order to more clearly illustrate the technical solutions of the embodiments of the present disclosure, the drawings of the embodiments will be briefly described below. It should be noted that the drawings described below only relate to some embodiments of the present disclosure, but are not intended to limit the present disclosure, wherein: Figure 1 It is a flowchart of an EtherCAT-based encrypted firmware upgrade method provided by an embodiment of the present disclosure; Figure 2 It is a partition diagram of a firmware provided by an embodiment of the present disclosure; Figure 3It is a specific flow chart of an EtherCAT-based encrypted firmware upgrade method provided by an embodiment of the present disclosure; Figure 4 It is a structural schematic diagram of an EtherCAT-based encrypted firmware upgrade device provided by an embodiment of the present disclosure; Figure 5 It is a structural diagram of a computer device provided in an embodiment of the present disclosure.

[0018] In the drawings, reference numerals with the same last two digits correspond to the same elements. It should be noted that the elements in the drawings are schematic and not drawn to scale. DETAILED DESCRIPTION

[0019] In order to make the purpose, technical solution and advantages of the embodiments of the present disclosure clearer, the technical solution of the embodiments of the present disclosure will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the described embodiments are part of the embodiments of the present disclosure, rather than all of the embodiments. Based on the described embodiments of the present disclosure, all other embodiments obtained by those skilled in the art without creative work also fall within the scope of protection of the present disclosure.

[0020] Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by a person skilled in the art to which the subject matter of the present disclosure belongs. It will be further understood that terms such as those defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the specification and the relevant art, and will not be interpreted in an idealized or overly formal form unless otherwise explicitly defined herein. As used herein, a statement that two or more parts are "connected" or "coupled" together shall mean that the parts are joined together directly or through one or more intermediate components.

[0021] Reference to "embodiments" herein means that a particular feature, structure, or characteristic described in conjunction with the embodiments may be included in at least one embodiment of the present application. The appearance of the phrase "embodiments" in various locations in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment that is mutually exclusive with other embodiments. It is explicitly and implicitly understood by those skilled in the art that the embodiments described herein may be combined with other embodiments.

[0022] The term "and / or" in this article is only a description of the association relationship of the associated objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists, A and B exist at the same time, and B exists. In addition, the character " / " in this article generally indicates that the associated objects before and after are in an "or" relationship.

[0023] Furthermore, in all embodiments of the present disclosure, terms such as “first” and “second” are used only to distinguish one component (or a part of a component) from another component (or another part of a component).

[0024] In the description of the present application, unless otherwise specified, “plurality” means more than two (including two), and similarly, “plurality groups” means more than two (including two).

[0025] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings.

[0026] Based on the problems existing in the prior art, the present disclosure provides an encrypted firmware upgrade method based on EtherCAT. Figure 1 is a flow chart of an EtherCAT-based encrypted firmware upgrade method provided by an embodiment of the present disclosure, such as Figure 1 As shown in the figure, the specific process of the EtherCAT-based encrypted firmware upgrade method includes: S110 . When receiving a boot request sent by the EtherCAT master station to enter a boot state, enter the boot state according to the boot request.

[0027] Specifically, Figure 2 As shown, the firmware includes a backup partition, an APP (Application) partition and a boot program, wherein the backup partition includes a firmware update information area and a backup buffer, and the APP partition includes an APP execution area.

[0028] In a specific implementation, after the slave station is started for the first time, it executes the boot program and opens the firmware lock. At this time, the number of bytes received in the firmware update information area of ​​the firmware is zero. The slave station runs the EtherCAT protocol stack included in the APP execution area of ​​the firmware, and receives the boot request sent by the master station to enter the boot state. After receiving the boot request sent by the master station to enter the boot state, the slave station enters the boot state according to the boot request.

[0029] In a specific implementation, when a boot request is received from a master station requesting to enter a boot state, entering the boot state according to the boot request includes: when a boot request is received from the master station requesting to enter a boot state, obtaining a target state in the boot request; writing the target state in the boot request into a control bit of the slave station, so that the slave station enters the boot state according to the target state of the control bit.

[0030] Specifically, the master station sends a boot request to the slave station, the slave station receives the boot request sent by the master station, and writes the target state in the boot request sent by the master station into the control bit of the slave station, and the slave station enters the boot state according to the target state written to the control bit by the master station.

[0031] After the slave enters the boot state according to the boot request sent by the master, the master determines whether the slave enters the boot state by reading the actual state of the slave control bit.

[0032] S120. When a file transfer request sent by the master station is received and the file transfer password in the file transfer request is verified, the encrypted firmware is received and written into the backup buffer. When the encrypted firmware file is received, the byte information of the received encrypted firmware file is written into the firmware update information area, and the file transfer completion flag is set.

[0033] Among them, the encrypted firmware is the firmware obtained by calculating the preset cyclic redundancy check value after four-byte alignment of the firmware, and then obtaining the initial firmware based on the preset cyclic redundancy check value (the preset cyclic redundancy check is appended to the end of the initial firmware), and then performing byte padding alignment and encryption.

[0034] In a specific implementation, the generation process of the encrypted firmware includes: First, the firmware is obtained, and then the firmware is four-byte aligned, and based on the CRC32 (Cyclic Redundancy Check) algorithm, a preset cyclic redundancy check value corresponding to the firmware after the four-byte alignment is calculated, and then the calculated preset cyclic redundancy check value is appended to the firmware to form a first initial firmware (that is, the initial firmware), and then the formed first initial firmware is aligned through the PKCS7 algorithm (data filling algorithm) to obtain the second initial firmware, and finally the obtained second initial firmware is encrypted through the AES (Advanced Encryption Standard) encryption algorithm to obtain the encrypted firmware.

[0035] After the slave station enters the boot state in step S110, the slave station will receive a file transfer request sent by the master station. If the slave station receives a file transfer request sent by the master station, the slave station will verify the file transfer password in the file transfer request sent by the master station. After the slave station passes the file transfer password verification, the slave station receives the encrypted firmware sent by the master station, and writes the received encrypted firmware into the backup buffer. When the encrypted firmware file is received, the byte information of the received encrypted firmware file is written into the firmware update information area, and the file transfer completion flag is set.

[0036] In addition, before the slave station receives the encrypted firmware sent by the master station, it opens the permission to write the firmware to write the received encrypted firmware into the firmware's backup buffer, and when the encrypted firmware is received, it writes the byte information of the encrypted firmware file into the firmware update information area of ​​the firmware and sets the file transfer completion flag.

[0037] In the specific implementation process, if the encrypted firmware file transmission between the slave station and the master station fails, for example, the slave station has insufficient memory or the communication link between the slave station and the master station is disconnected, then the slave station receives the encrypted firmware file with an error, and the file transfer completion flag will show that the transfer is incomplete.

[0038] S130. When receiving the initialization request sent by the master station to enter the initialization state, determine the file transfer completion flag. If the transfer is completed, trigger the slave station software to restart and execute the boot program so that the boot program detects the byte information of the firmware file in the firmware update information area.

[0039] After writing the encrypted firmware into the backup buffer, and when the encrypted firmware file is received, the byte information of the encrypted firmware file is written into the firmware update information area, and the file transfer completion flag is set, the master station receives the return status sent by the slave station (the return status includes a normal state and an abnormal state, and the return status indicates whether the slave station receives the encrypted firmware file abnormally). After the master station receives the return status sent by the slave station as a normal state (at this time, the byte information of the encrypted firmware file can be written into the firmware update information area) and the master station sends the encrypted firmware file (at this time, the file transfer completion flag is the transfer completion), the master station sends an initialization request to the slave station, requesting the slave station to enter the initialization state. After receiving the initialization request sent by the master station to enter the initialization state, the slave station triggers the restart of the slave station software. After the slave station software restarts, the boot program is executed again, so that the slave station detects the byte information of the firmware file in the firmware update information area according to the boot program.

[0040] S140, when the boot program detects that the byte information of the firmware file received in the firmware update information area is not zero, read the encrypted firmware in the backup buffer and process the encrypted firmware to obtain the actual decrypted firmware and calculate the actual cyclic redundancy check value.

[0041] Since the slave station receives the encrypted firmware sent by the master station in step S120, and writes the byte information of the encrypted firmware file into the firmware update information area when the encrypted firmware file corresponding to the encrypted firmware is received, therefore, in the process of executing step S130 to detect the byte information of the firmware file in the firmware update information area based on the boot program, it is detected that the byte information of the firmware file received in the firmware update information area is not zero. At this time, step S140 is executed to read the encrypted firmware in the backup buffer and process the encrypted firmware to obtain the actual decrypted firmware and calculate the actual cyclic redundancy check value of the actual decrypted firmware.

[0042] In a specific implementation, the encrypted firmware of the backup buffer is read and processed to obtain the actual decrypted firmware and calculate the actual cyclic redundancy check value, including: reading the encrypted firmware of the backup buffer and processing the encrypted firmware to obtain the actual decrypted firmware; and calculating the actual cyclic redundancy check value based on the actual decrypted firmware.

[0043] Among them, the encrypted firmware of the backup buffer is read and the encrypted firmware is processed to obtain the actual decrypted firmware, including: reading the encrypted firmware of the backup buffer, and using the decryption algorithm to decrypt the encrypted firmware to obtain the initial decrypted firmware; removing the padding bytes of the initial decrypted firmware based on the data padding algorithm to obtain the actual decrypted firmware.

[0044] Since the encrypted firmware received from the station in step S120 is four-byte aligned to obtain a cyclic redundancy check value, and then the initial firmware is obtained based on the cyclic redundancy check value, and then byte-filled, aligned and encrypted to obtain the firmware, when the boot program detects that the byte information of the firmware file received in the firmware update information area is not zero, it indicates that a firmware upgrade is required. Therefore, the encrypted firmware read from the backup buffer is decrypted to obtain the initial decrypted firmware, and then the padding bytes of the initial decrypted firmware are removed based on the data filling algorithm to obtain the actual decrypted firmware, and finally the actual cyclic redundancy check value is calculated based on the actual decrypted firmware.

[0045] In the specific implementation steps, if the encryption algorithm in step S120 is the AES algorithm and the data filling algorithm is the PKCS7 algorithm, the algorithm for decrypting the encrypted firmware in step S140 is also the AES algorithm, and the algorithm for removing the padding bytes of the initial decrypted firmware is also the PKCS7 algorithm. The present disclosed embodiment does not give specific examples for this.

[0046] After decrypting the encrypted firmware based on the AES algorithm to obtain the initial decrypted firmware and removing the padded bytes in the initial decrypted firmware based on the PKCS7 algorithm to obtain the actual decrypted firmware, the actual decrypted firmware is aligned to four bytes and then the actual cyclic redundancy check value of the decrypted firmware after the four-byte alignment is calculated based on the CRC32 algorithm.

[0047] In other possible implementations, when the boot program detects that the byte information of the firmware file received in the firmware update information area is zero, the EtherCAT protocol stack included in the APP execution area is run.

[0048] Specifically, when the boot program detects that the byte information of the firmware file received in the firmware update information area is zero, this indicates that an error occurs in the transmission process of the encrypted firmware sent by the master station to the slave station during the process of the master station sending the encrypted firmware to the slave station. The slave station has no encryption firmware write permission and cannot write the encrypted firmware to the backup buffer, and cannot write the byte information of the encrypted firmware file to the firmware update information area. At this time, the EtherCAT protocol stack included in the APP execution area is run, and steps S110, S120 and S130 are continued until the boot program detects that the byte information of the firmware file received in the firmware update information area is not zero, and steps S140 and S150 are executed.

[0049] S150. When the actual cyclic redundancy check value is the same as the preset cyclic redundancy check value, erase the information of the APP execution area, erase the firmware update information area, and write the actual decrypted firmware into the APP execution area, thereby triggering the slave station software to restart.

[0050] After the actual cyclic redundancy check value of the encrypted firmware file in the backup buffer is calculated in step S150, the actual cyclic redundancy check value is compared with the preset cyclic redundancy check value (the preset cyclic redundancy check value is the cyclic redundancy check value calculated after four-byte alignment of the firmware). When the actual cyclic redundancy check value is the same as the preset cyclic redundancy check value, it indicates that the slave station has normally completed receiving the encrypted firmware sent by the master station. At this time, the information of the APP execution area (old firmware) is erased, and the firmware corresponding to the actual decrypted firmware file is written into the APP execution area, thereby triggering a restart of the slave station software.

[0051] In addition, after erasing the information in the APP execution area and writing the firmware corresponding to the actual decrypted firmware file into the APP execution area, erase the information in the backup buffer and the firmware update information area to facilitate writing the new firmware file into the backup buffer during subsequent firmware upgrades, and writing the byte information corresponding to the new firmware file into the firmware update information area.

[0052] In other possible implementations, when the actual cyclic redundancy check value is different from the preset cyclic redundancy check value, the boot program is executed again by triggering the slave station software to restart, so that the boot program detects the byte information of the firmware file in the firmware update information area, and then determines whether to execute steps S110, S120 and S130 or to execute steps S140 and S150 based on the byte information of the firmware file in the firmware update information area detected by the boot program.

[0053] It should be noted that, in the above embodiments, the firmware represents binary content, and the firmware file represents a container of the binary content.

[0054] Figure 3 The specific flow chart of the encrypted firmware upgrade method based on EtherCAT of the present application is exemplified.

[0055] The EtherCAT-based encrypted firmware upgrade method provided by the embodiment of the present disclosure enters the boot state according to the boot request when a boot request sent by the master station is received and the file transfer password in the file transfer request is verified; the encrypted firmware is received and written into the backup buffer; and when the encrypted firmware file is received, the byte information of the received encrypted firmware file is written into the firmware update information area, and the file transfer completion flag is set; when the initialization request sent by the master station is received and the initialization state is entered, the file transfer completion flag is judged, and if the transfer is completed, the slave station software is restarted, and the boot program is executed so that the boot program detects the byte information of the firmware file in the firmware update information area; when the boot program detects that the byte information of the firmware file received in the firmware update information area is not zero, the encrypted firmware in the backup buffer is read and processed to obtain the actual decrypted firmware and calculate the actual cyclic redundancy check value; when the actual cyclic redundancy check value is the same as the preset cyclic redundancy check value, the information of the APP execution area is erased, the firmware update information area is erased, and the actual decrypted firmware is written into the APP execution area, thereby triggering the slave station software to restart. When upgrading the firmware, on the one hand, the firmware written to the slave station is encrypted firmware to avoid leakage of the content in the firmware. On the other hand, since the firmware written to the slave station is encrypted firmware, the encrypted firmware is decrypted through the corresponding decryption method, and then the actual cyclic redundancy check value of the decrypted firmware is verified to be the same as the cyclic redundancy check value corresponding to the encrypted firmware file received by the slave station. It is determined whether the slave station has received the complete encrypted firmware, and then the firmware is updated.

[0056] Based on the above embodiments, Figure 4 is a schematic diagram of the structure of an encrypted firmware upgrade device based on EtherCAT provided by an embodiment of the present disclosure, such as Figure 4 As shown, the EtherCAT-based encrypted firmware upgrade device includes: A boot state entry module 210, configured to enter the boot state according to the boot request when receiving a boot request sent by the master station for entering the boot state; The information writing module 220 is used to receive the encrypted firmware and write the encrypted firmware into the backup buffer when the file transfer request sent by the master station is received and the file transfer password in the file transfer request is verified, and when the encrypted firmware file is received, write the byte information of the received encrypted firmware file into the firmware update information area and set the file transfer completion flag, wherein the encrypted firmware is the firmware obtained by byte padding alignment and encryption after the firmware is four-byte aligned and the preset cyclic redundancy check value is calculated, and then the preset cyclic redundancy check value is appended to obtain the initial firmware; The startup module 230 is used to determine the file transfer completion flag when receiving the initialization request sent by the master station to enter the initialization state, and if the transfer is completed, trigger the slave station software to restart and execute the boot program so that the boot program detects the byte information of the firmware file in the firmware update information area; The encrypted firmware file processing module 240 is used to read the encrypted firmware in the backup buffer and process the encrypted firmware to obtain the actual decrypted firmware and calculate the actual cyclic redundancy check value when the boot program detects that the firmware file byte information received in the firmware update information area is not zero; The firmware update module 250 is used to erase the information of the APP execution area, erase the firmware update information area, and write the actual decrypted firmware into the APP execution area when the actual cyclic redundancy check value is the same as the preset cyclic redundancy check value, thereby triggering the restart of the slave station software.

[0057] The EtherCAT-based encrypted firmware upgrade device provided by the embodiment of the present disclosure enters the boot state according to the boot request when receiving a boot request sent by the master station to enter the boot state; receives the encrypted firmware and writes the encrypted firmware into the backup buffer when receiving the file transfer request sent by the master station and the file transfer password in the file transfer request passes the verification; and when the encrypted firmware file is received, writes the byte information of the received encrypted firmware file into the firmware update information area, and sets the file transfer completion flag; when receiving the initialization request sent by the master station to enter the initialization state, judges the file transfer completion flag, and if the transfer is completed, triggers the slave station software to restart, and executes the boot program, so that the boot program detects the byte information of the firmware file in the firmware update information area; when the boot program detects that the byte information of the firmware file received in the firmware update information area is not zero, reads the encrypted firmware in the backup buffer and processes the encrypted firmware to obtain the actual decrypted firmware and calculate the actual cyclic redundancy check value; when the actual cyclic redundancy check value is the same as the preset cyclic redundancy check value, erases the information of the APP execution area, erases the firmware update information area, and writes the actual decrypted firmware into the APP execution area, thereby triggering the slave station software to restart. When upgrading the firmware, on the one hand, the firmware written to the slave station is encrypted firmware to avoid leakage of the content in the firmware. On the other hand, since the firmware written to the slave station is encrypted firmware, the encrypted firmware is decrypted through the corresponding decryption method, and then the actual cyclic redundancy check value of the decrypted firmware is verified to be the same as the cyclic redundancy check value corresponding to the encrypted firmware file received by the slave station. It is determined whether the slave station has received the complete encrypted firmware, and then the firmware is updated.

[0058] In a specific implementation manner, when receiving a boot request sent by the master station to request entering the boot state, entering the boot state according to the boot request includes: When receiving a boot request sent by the master station for entering a boot state, obtaining a target state in the boot request; The target state in the boot request is written into the control bit of the slave station, so that the slave station enters the boot state according to the target state of the control bit.

[0059] In a specific implementation, reading the encrypted firmware in the backup buffer and processing the encrypted firmware to obtain the actual decrypted firmware and calculate the actual cyclic redundancy check value includes: Reading the encrypted firmware in the backup buffer and processing the encrypted firmware to obtain actual decrypted firmware; According to the actual decrypted firmware, an actual cyclic redundancy check value is calculated.

[0060] In a specific implementation, the reading of the encrypted firmware in the backup buffer and processing the encrypted firmware to obtain the actual decrypted firmware includes: Reading the encrypted firmware in the backup buffer, and decrypting the encrypted firmware using a decryption algorithm to obtain initial decrypted firmware; The padding bytes of the initial decrypted firmware are removed based on a data padding algorithm to obtain the actual decrypted firmware.

[0061] In a specific implementation manner, the receiving of the encrypted firmware and before writing the encrypted firmware into the backup buffer further includes: Enable firmware write permission.

[0062] In a specific embodiment, the method further comprises: When the boot program detects that the byte information of the firmware file received in the firmware update information area is zero, the EtherCAT protocol stack included in the APP execution area is run.

[0063] In a specific embodiment, the method further comprises: When the actual cyclic redundancy check value is different from the cyclic redundancy check value, a slave station software restart is triggered.

[0064] The present application also provides a computer device. Figure 5 , Figure 5 This is a basic structural block diagram of the computer device in this embodiment.

[0065] The computer device includes a memory 510 and a processor 520 that are connected to each other through a system bus. It should be noted that the figure only shows a computer device with components 510-520, but it should be understood that it is not required to implement all the components shown, and more or fewer components can be implemented instead. Among them, those skilled in the art can understand that the computer device here is a device that can automatically perform numerical calculations and / or information processing according to pre-set or stored instructions, and its hardware includes but is not limited to microprocessors, application specific integrated circuits (Application Specific Integrated Circuit, ASIC), field-programmable gate arrays (Field-Programmable Gate Array, FPGA), digital processors (Digital Signal Processor, DSP), embedded devices, etc.

[0066] Computer devices can be computing devices such as desktop computers, notebooks, PDAs, and cloud servers. Computer devices can interact with users through keyboards, mice, remote controls, touch pads, or voice control devices.

[0067] The memory 510 includes at least one type of readable storage medium, and the readable storage medium includes a non-volatile memory or a volatile memory, such as a flash memory, a hard disk, a multimedia card, a card-type memory (such as an SD or DX memory, etc.), a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a programmable read-only memory (PROM), a magnetic memory, a magnetic disk, an optical disk, etc., and the RAM may include a static RAM or a dynamic RAM. In some embodiments, the memory 510 may be an internal storage unit of a computer device, such as a hard disk or a memory of the computer device. In other embodiments, the memory 510 may also be an external storage device of a computer device, such as a plug-in hard disk, a smart memory card (SMC), a secure digital (SD) card, or a flash card (Flash Card), etc., equipped on the computer device. Of course, the memory 510 may also include both an internal storage unit of the computer device and an external storage device thereof. In this embodiment, the memory 510 is generally used to store an operating system and various application software installed on the computer device, such as the program code of the above method, etc. In addition, the memory 510 may also be used to temporarily store various data that have been output or are to be output.

[0068] The processor 520 is generally used to perform the overall operation of the computer device. In this embodiment, the memory 510 is used to store program codes or instructions, the program code includes computer operation instructions, and the processor 520 is used to execute the program codes or instructions stored in the memory 510 or process data, such as running the program code of the above method.

[0069] In this article, the bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. The bus system can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, only one thick line is used in the figure, but it does not mean that there is only one bus or one type of bus.

[0070] Another embodiment of the present application also provides a computer-readable medium, which may be a computer-readable signal medium or a computer-readable medium. A processor in a computer reads a computer-readable program code stored in the computer-readable medium, so that the processor can execute the functional actions specified in each step or a combination of steps in the above method; and generate a device for implementing the functional actions specified in each block or a combination of blocks in the block diagram.

[0071] Computer-readable media include but are not limited to electronic, magnetic, optical, electromagnetic, infrared memory or semiconductor systems, devices or apparatuses, or any appropriate combination of the foregoing, the memory is used to store program codes or instructions, the program codes include computer operating instructions, and the processor is used to execute the program codes or instructions of the above methods stored in the memory.

[0072] For the definitions of memory and processor, please refer to the description of the aforementioned computer device embodiment and will not be repeated here.

[0073] In the several embodiments provided in the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic, for example, the division of modules or units is only a logical function division, and there may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0074] Each functional unit or module in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.

[0075] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions to enable a computer device (which can be a personal computer, server, or network device, etc.) or a processor (processor) to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk, etc., and other media that can store program codes.

[0076] Unless the context clearly indicates otherwise, the singular form of the words used herein and in the appended claims includes the plural and vice versa. Thus, when referring to the singular, the plural form of the corresponding term is generally included. Similarly, the words "comprise" and "include" are to be interpreted as inclusive rather than exclusive. Likewise, the terms "include" and "or" should be interpreted as inclusive unless such interpretation is expressly prohibited herein. Where the term "example" is used herein, particularly when it is located after a group of terms, the "example" is merely exemplary and illustrative and should not be considered exclusive or comprehensive.

[0077] Further aspects and scopes of adaptability become apparent from the description provided herein. It should be understood that various aspects of the present application can be implemented individually or in combination with one or more other aspects. It should also be understood that the description and specific embodiments herein are intended for purposes of illustration only and are not intended to limit the scope of the present application.

[0078] Several embodiments of the present disclosure are described in detail above, but it is obvious that those skilled in the art can make various modifications and variations to the embodiments of the present disclosure without departing from the spirit and scope of the present disclosure. The protection scope of the present disclosure is defined by the attached claims.

Claims

1. An encrypted firmware upgrade method based on EtherCAT, characterized in that: include: When receiving a boot request sent by the master station for entering the boot state, entering the boot state according to the boot request; When a file transfer request sent by a master station is received and the file transfer password in the file transfer request passes verification, the encrypted firmware is received and written into a backup buffer, and when the encrypted firmware file is received, the byte information of the received encrypted firmware file is written into a firmware update information area, and a file transfer completion flag is set, wherein the encrypted firmware is a firmware obtained by calculating a preset cyclic redundancy check value after four-byte alignment of the firmware, and then appending the preset cyclic redundancy check value to obtain the initial firmware, and then performing byte padding alignment and encryption; Upon receiving an initialization request sent by the master station for entering an initialization state, determining a file transfer completion flag, and if the transfer is completed, triggering a slave station software restart, and executing the boot program, so that the boot program detects byte information of the firmware file in the firmware update information area; When the boot program detects that the firmware file byte information received in the firmware update information area is not zero, reading the encrypted firmware in the backup buffer and processing the encrypted firmware to obtain the actual decrypted firmware and calculate the actual cyclic redundancy check value; When the actual cyclic redundancy check value is the same as the preset cyclic redundancy check value, the information of the APP execution area is erased, the firmware update information area is erased, and the actual decrypted firmware is written into the APP execution area, thereby triggering the restart of the slave station software.

2. The method according to claim 1, characterized in that: When receiving a boot request sent by the master station for entering the boot state, entering the boot state according to the boot request includes: When receiving a boot request sent by the master station for entering a boot state, obtaining a target state in the boot request; The target state in the boot request is written into the control bit of the slave station, so that the slave station enters the boot state according to the target state of the control bit.

3. The method according to claim 1, characterized in that The step of reading the encrypted firmware in the backup buffer and processing the encrypted firmware to obtain the actual decrypted firmware and calculate the actual cyclic redundancy check value includes: Reading the encrypted firmware in the backup buffer and processing the encrypted firmware to obtain actual decrypted firmware; According to the actual decrypted firmware, an actual cyclic redundancy check value is calculated.

4. The method according to claim 3, characterized in that The step of reading the encrypted firmware in the backup buffer and processing the encrypted firmware to obtain the actual decrypted firmware includes: Reading the encrypted firmware in the backup buffer, and decrypting the encrypted firmware using a decryption algorithm to obtain initial decrypted firmware; The padding bytes of the initial decrypted firmware are removed based on a data padding algorithm to obtain the actual decrypted firmware.

5. The method according to claim 1, characterized in that The receiving of the encrypted firmware and before writing the encrypted firmware into the backup buffer further includes: Enable firmware write permission.

6. The method according to claim 1, characterized in that The method further comprises: When the boot program detects that the byte information of the firmware file received in the firmware update information area is zero, the EtherCAT protocol stack included in the APP execution area is run.

7. The method according to claim 1, characterized in that The method further comprises: When the actual cyclic redundancy check value is different from the cyclic redundancy check value, a slave station software restart is triggered.

8. An encrypted firmware upgrade device based on EtherCAT, characterized in that: include: A boot state entry module, configured to enter the boot state according to the boot request when receiving a boot request sent by the master station for entering the boot state; An information writing module is used to receive the encrypted firmware and write the encrypted firmware into the backup buffer when a file transfer request sent by the master station is received and the file transfer password in the file transfer request is verified, and when the encrypted firmware file is received, write the byte information of the received encrypted firmware file into the firmware update information area and set the file transfer completion flag, wherein the encrypted firmware is the firmware obtained by byte padding alignment and encryption after calculating a preset cyclic redundancy check value after four-byte alignment of the firmware, and then appending the preset cyclic redundancy check value to obtain the initial firmware; A startup module, configured to, upon receiving an initialization request sent by the master station to enter an initialization state, determine a file transfer completion flag, and if the transfer is completed, trigger a slave station software restart, and execute the boot program, so that the boot program detects byte information of the firmware file in the firmware update information area; An encrypted firmware file processing module is used to read the encrypted firmware in the backup buffer and process the encrypted firmware when the boot program detects that the firmware file byte information received in the firmware update information area is not zero, obtain the actual decrypted firmware and calculate the actual cyclic redundancy check value; The firmware update module is used to erase the information of the APP execution area, erase the firmware update information area, and write the actual decrypted firmware into the APP execution area when the actual cyclic redundancy check value is the same as the preset cyclic redundancy check value, thereby triggering the restart of the slave station software.

9. A computer device, characterized in that: include: one or more processors; a storage device for storing one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • EtherCAT slave station firmware upgrading method and EtherCAT slave station

    CN117742762A

  • Slave station firmware upgrading method and system

    CN117834429A

  • IO module firmware updating method based on EtherCat coupler

    CN118394393A

  • IO module firmware upgrading method, device and equipment and readable storage medium

    CN119011329A

  • System and method for securely upgrading firmware

    US20030191955A1

Cited By

  • EEPROM data read-write method and device based on real-time industrial Ethernet and medium

    CN120631802A

  • EEPROM data reading and writing method and device based on real-time industrial ethernet and medium

    CN120631802B