EtherCAT-Based Encrypted Firmware Upgrade Method, Device, Equipment, and Storage Medium

By adopting the EtherCAT-based encryption firmware upgrade method in IO products, the hardware interface requirements and firmware file leakage during the firmware upgrade process are solved, and a safe and efficient firmware upgrade is achieved.

CN119939609BActive Publication Date: 2025-07-01SHENZHEN MATRIBOX TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510429187.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-08
Publication Date
2025-07-01
Estimated Expiration
2045-04-08

AI Technical Summary

Technical Problem

There are risks of hardware interface requirements and firmware file leakage during the firmware upgrade process.

Method used

The encryption firmware upgrade method based on EtherCAT is adopted. By receiving the encryption firmware sent by the main station and writing it to the backup buffer and firmware update information area, byte filling alignment and encryption are performed to ensure the security of the firmware during the upgrade process.

Benefits of technology

The encryption processing during the firmware upgrade process is realized, the leakage of firmware content is avoided, and the integrity of the firmware is ensured through the verification of cyclic redundancy check value.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939609B_ABST
    Figure CN119939609B_ABST
Patent Text Reader

Abstract

The encrypted firmware upgrade method, device, equipment and medium based on EtherCAT provided by the embodiments of the present disclosure include: entering a boot state according to a boot request; receiving the encrypted firmware, writing the encrypted firmware into a backup buffer, writing the byte information of the encrypted firmware file into a firmware update information area, and setting a file transfer completion flag bit; when receiving an initialization request sent by the master station to enter an initialization state, triggering a slave software restart and executing a boot program when the transfer is completed; when the boot program detects that the byte information of the firmware file received in the firmware update information area is not zero, reading the encrypted firmware in the backup buffer and processing the encrypted firmware to obtain an actual decrypted firmware and calculating an actual cyclic redundancy check value; when the actual cyclic redundancy check value is the same as a preset cyclic redundancy check value, erasing the information in the APP execution area, writing the actual decrypted firmware into the APP execution area, and triggering a slave software restart.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of equipment software technology upgrade and related technical fields. Specifically, it relates to an EtherCAT-based encrypted firmware upgrade method, device, equipment, and storage medium. Background Art

[0002] With the development of industrial automation and Internet of Things technologies, the demand for IO products in industrial automation systems is increasing day by day. These IO products communicate with the system master station through different buses (such as RS485 interfaces, etc.) to achieve data input and output. However, in the mass production of IO products, product iteration, and different scenarios at the user site, firmware upgrade has become an important and frequent requirement, and there is a current situation of different bus extended IO products and their firmware upgrades.

[0003] In the prior art, most slave firmware upgrades use serial ports or 485 interfaces. Therefore, the corresponding hardware of the slave firmware needs to leave corresponding hardware interfaces, and during the upgrade process, the original firmware needs to be placed in the slave, which may lead to the leakage of firmware files. Summary of the Invention

[0004] The embodiments described herein provide an EtherCAT-based encrypted firmware upgrade method, device, equipment, and storage medium to solve the problems existing in the prior art.

[0005] In a first aspect, according to the content of the present disclosure, there is provided an EtherCAT-based encrypted firmware upgrade method, including:

[0006] When receiving a boot request sent by the master station to enter the boot state, enter the boot state according to the boot request;

[0007] When receiving a file transfer request sent by the master station and the file transfer password in the file transfer request passes the verification, receive the encrypted firmware, write the encrypted firmware into the backup buffer, and when the encrypted firmware file reception is completed, write the byte information of the received encrypted firmware file into the firmware update information area, and set the file transfer completion flag bit, where the encrypted firmware is obtained by calculating the preset cyclic redundancy check value after four-byte alignment of the firmware, then appending the preset cyclic redundancy check value to obtain the initial firmware, and then performing byte padding alignment and encryption;

[0008] When receiving an initialization request sent by the master station to enter the initialization state, judge the file transfer completion flag bit. If the transfer is completed, trigger the restart of the slave software and execute the boot program to enable the boot program to detect the byte information of the firmware file in the firmware update information area;

[0009] When receiving that the firmware file byte information received in the firmware update information area detected by the bootloader is not zero, read the encrypted firmware in the backup buffer and process the encrypted firmware to obtain the actual decrypted firmware and calculate the actual cyclic redundancy check value;

[0010] When the actual cyclic redundancy check value is the same as the preset cyclic redundancy check value, erase the information in the APP execution area, erase the firmware update information area, and write the actual decrypted firmware into the APP execution area, thereby triggering the slave software to restart.

[0011] In some embodiments of the present disclosure, when receiving a boot request sent by the master station to enter the boot state and entering the boot state according to the boot request, it includes:

[0012] When receiving a boot request sent by the master station to enter the boot state, obtain the target state in the boot request;

[0013] Write the target state in the boot request into the control bit of the slave station, so that the slave station enters the boot state according to the target state of the control bit.

[0014] In some embodiments of the present disclosure, the reading the encrypted firmware in the backup buffer and processing the encrypted firmware to obtain the actual decrypted firmware and calculate the actual cyclic redundancy check value includes:

[0015] Read the encrypted firmware in the backup buffer and process the encrypted firmware to obtain the actual decrypted firmware;

[0016] Calculate the actual cyclic redundancy check value according to the actual decrypted firmware.

[0017] In some embodiments of the present disclosure, the reading the encrypted firmware in the backup buffer and processing the encrypted firmware to obtain the actual decrypted firmware includes:

[0018] Read the encrypted firmware in the backup buffer, and use a decryption algorithm to decrypt the encrypted firmware to obtain an initial decrypted firmware;

[0019] Based on a data filling algorithm, remove the filling bytes of the initial decrypted firmware to obtain the actual decrypted firmware.

[0020] In some embodiments of the present disclosure, before receiving the encrypted firmware and writing the encrypted firmware into the backup buffer, it further includes:

[0021] Open the firmware write permission.

[0022] In some embodiments of the present disclosure, the method further includes:

[0023] When the byte information of the firmware file received in the firmware update information area detected by the bootloader is zero, run the EtherCAT protocol stack included in the APP execution area.

[0024] In some embodiments of the present disclosure, the method further includes:

[0025] When the actual cyclic redundancy check value is different from the cyclic redundancy check value, trigger the slave software to restart.

[0026] In a second aspect, according to the content of the present disclosure, there is provided an EtherCAT-based encrypted firmware upgrade device, including:

[0027] A boot status entry module, configured to enter the boot status according to a boot request when receiving a boot request for entering the boot status sent by the master station;

[0028] An information writing module, configured to receive an encrypted firmware when receiving a file transfer request sent by the master station and the file transfer password in the file transfer request passes the verification, write the encrypted firmware into the backup buffer, and when the encrypted firmware file reception is completed, write the byte information of the received encrypted firmware file into the firmware update information area, and set a file transfer completion flag bit, where the encrypted firmware is a firmware obtained by performing four-byte alignment on the firmware, calculating a preset cyclic redundancy check value, then appending the preset cyclic redundancy check value to obtain an initial firmware, and then performing byte padding alignment and encryption;

[0029] A start module, configured to, when receiving an initialization request for entering the initialization state sent by the master station, judge the file transfer completion flag bit, if the transfer is completed, trigger the slave software to restart, and execute the bootloader to enable the bootloader to detect the byte information of the firmware file in the firmware update information area;

[0030] An encrypted firmware file processing module, configured to, when the bootloader detects that the byte information of the firmware file received in the firmware update information area is not zero, read the encrypted firmware in the backup buffer and process the encrypted firmware to obtain an actual decrypted firmware and calculate an actual cyclic redundancy check value;

[0031] A firmware update module, configured to, when the actual cyclic redundancy check value is the same as the preset cyclic redundancy check value, erase the information in the APP execution area, erase the firmware update information area, and write the actual decrypted firmware into the APP execution area, thereby triggering the slave software to restart.

[0032] In a third aspect, according to the content of the present disclosure, there is provided a computer device, including:

[0033] One or more processors;

[0034] A storage device for storing one or more programs,

[0035] When the one or more programs are executed by the one or more processors, the one or more processors implement the method described in any one of the first aspects.

[0036] In a fourth aspect, according to the content of the present disclosure, there is provided a computer-readable storage medium having a computer program stored thereon, and when the program is executed by a processor, the method described in any one of the first aspects is implemented.

[0037] The EtherCAT-based encrypted firmware upgrade method, device, equipment, and medium provided by the embodiments of the present disclosure enter the boot state according to a boot request when receiving a boot request sent by a master station to enter the boot state; when receiving a file transfer request sent by the master station and the file transfer password in the file transfer request passes the verification, receive the encrypted firmware, write the encrypted firmware into a backup buffer, and when the encrypted firmware file reception is completed, write the byte information of the received encrypted firmware file into a firmware update information area, and set a file transfer completion flag bit; when receiving an initialization request sent by the master station to enter the initialization state, judge the file transfer completion flag bit, if the transfer is completed, trigger a slave station software restart, and execute a boot program to enable the boot program to detect the byte information of the firmware file in the firmware update information area; when receiving that the byte information of the firmware file received in the firmware update information area detected by the boot program is not zero, read the encrypted firmware in the backup buffer and process the encrypted firmware to obtain an actual decrypted firmware and calculate an actual cyclic redundancy check value; when the actual cyclic redundancy check value is the same as a preset cyclic redundancy check value, erase the information in the APP execution area, erase the firmware update information area, and write the actual decrypted firmware into the APP execution area, and then trigger a slave station software restart. When upgrading the firmware, on the one hand, the firmware written to the slave station is an encrypted firmware to avoid the leakage of the content in the firmware. On the other hand, since the firmware written to the slave station is an encrypted firmware, therefore, through a corresponding decryption method, the encrypted firmware is decrypted, and then by verifying whether the actual cyclic redundancy check value of the decrypted firmware after decryption is the same as the cyclic redundancy check value corresponding to the encrypted firmware file received by the slave station, it is determined whether the slave station has received the complete encrypted firmware, and thus the firmware update is realized.

[0038] The above description is only an overview of the technical solutions of the embodiments of the present application. In order to be able to understand the technical means of the embodiments of the present application more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features, and advantages of the embodiments of the present application more obvious and understandable, the following specifically gives the specific embodiments of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] To more clearly illustrate the technical solutions of the embodiments of the present disclosure, the accompanying drawings of the embodiments will be briefly described below. It should be understood that the following-described accompanying drawings only relate to some embodiments of the present disclosure and do not limit the present disclosure, where:

[0040] Figure 1 is a schematic flowchart of a method for encrypting firmware upgrade based on EtherCAT provided by an embodiment of the present disclosure;

[0041] Figure 2 is a schematic diagram of the partition of a firmware provided by an embodiment of the present disclosure;

[0042] Figure 3 is a schematic flowchart of the specific process of a method for encrypting firmware upgrade based on EtherCAT provided by an embodiment of the present disclosure;

[0043] Figure 4 is a schematic structural diagram of a device for encrypting firmware upgrade based on EtherCAT provided by an embodiment of the present disclosure;

[0044] Figure 5 is a schematic structural diagram of a computer device provided by an embodiment of the present disclosure.

[0045] In the accompanying drawings, labels with the same last two digits correspond to the same elements. It should be noted that the elements in the accompanying drawings are schematic and not drawn to scale. Detailed Embodiments

[0046] In order to make the objectives, technical solutions, and advantages of the embodiments of the present disclosure clearer, the technical solutions of the embodiments of the present disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are some, but not all, of the embodiments of the present disclosure. All other embodiments obtained by those skilled in the art based on the described embodiments of the present disclosure without creative efforts also fall within the scope of protection of the present disclosure.

[0047] Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by those skilled in the art to which the subject matter of the present disclosure belongs. Further, it will be understood that terms such as those defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the specification and the relevant art, and will not be interpreted in an idealized or overly formal form unless otherwise clearly defined herein. As used herein, a statement that two or more parts are "connected" or "coupled" together shall mean that these parts are directly joined together or joined through one or more intermediate components.

[0048] References to "embodiments" in this document mean that the specific features, structures, or characteristics described in connection with the embodiments can be included in at least one embodiment of the present application. The phrase "embodiment" appearing at various positions in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art will explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.

[0049] The term "and / or" in this document is merely a description of the association relationship between associated objects, indicating that there can be three relationships. For example, A and / or B can represent: the existence of A, the simultaneous existence of A and B, and the existence of B. Additionally, the character " / " in this document generally represents an "or" relationship between the associated objects before and after.

[0050] Furthermore, in all embodiments of the present disclosure, terms such as "first" and "second" are only used to distinguish one component (or a part of a component) from another component (or another part of a component).

[0051] In the description of the present application, unless otherwise specified, "a plurality of" means two or more (including two). Similarly, "multiple groups" means two or more groups (including two groups).

[0052] To enable those skilled in the art to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings.

[0053] Based on the problems existing in the prior art, the embodiments of the present disclosure provide an EtherCAT-based encrypted firmware upgrade method. Figure 1 It is a schematic flowchart of an EtherCAT-based encrypted firmware upgrade method provided by the embodiments of the present disclosure. As Figure 1 shown, the specific process of the EtherCAT-based encrypted firmware upgrade method includes:

[0054] S110. When receiving a boot request for entering the boot state sent by the EtherCAT master station, enter the boot state according to the boot request.

[0055] Specifically, as Figure 2 shown, the firmware includes a backup partition, an APP (Application) partition, and a boot program. Among them, the backup partition includes a firmware update information area and a backup buffer, and the APP partition includes an APP execution area.

[0056] In a specific embodiment, after the slave station is first started, the bootloader is executed and the firmware lock is enabled. At this time, the number of bytes received in the firmware update information area of the firmware is zero. The APP execution area of the firmware running on the slave station includes an EtherCAT protocol stack, and receives a boot request sent by the master station to enter the boot state. After the slave station receives the boot request sent by the master station to enter the boot state, it enters the boot state according to the boot request.

[0057] In a specific embodiment, when receiving the boot request sent by the master station to enter the boot state, entering the boot state according to the boot request includes: when receiving the boot request sent by the master station to enter the boot state, obtaining the target state in the boot request; writing the target state in the boot request to the control bit of the slave station, so that the slave station enters the boot state according to the target state of the control bit.

[0058] Specifically, the master station sends a boot request to the slave station. The slave station receives the boot request sent by the master station, and writes the target state in the boot request sent by the master station to the control bit of the slave station. The slave station enters the boot state according to the target state written by the master station to the control bit.

[0059] After the slave station enters the boot state according to the boot request sent by the master station, the master station determines whether the slave station enters the boot state by reading the actual state of the control bit of the slave station.

[0060] S120. When receiving a file transfer request sent by the master station and the file transfer password in the file transfer request passes the verification, receive the encrypted firmware, write the encrypted firmware into the backup buffer, and when the encrypted firmware file reception is completed, write the byte information of the received encrypted firmware file into the firmware update information area, and set the file transfer completion flag bit.

[0061] Among them, the encrypted firmware is obtained by calculating the preset cyclic redundancy check value after aligning the firmware in four-byte units, and then obtaining the initial firmware based on the preset cyclic redundancy check value (appending the preset cyclic redundancy check to the end of the initial firmware), and then performing byte padding alignment and encryption.

[0062] In a specific embodiment, the generation process of the encrypted firmware includes:

[0063] First, obtain the firmware. After aligning the firmware to four-byte alignment, based on the CRC32 (Cyclic Redundancy Check) algorithm, calculate the preset cyclic redundancy check value corresponding to the four-byte aligned firmware. Then, append the calculated preset cyclic redundancy check value to the firmware to form the first initial firmware (i.e., the initial firmware). Next, align the formed first initial firmware through the PKCS7 algorithm (data padding algorithm) to obtain the second initial firmware. Finally, encrypt the obtained second initial firmware through the AES (Advanced Encryption Standard) encryption algorithm to obtain the encrypted firmware.

[0064] After the slave station enters the boot state in step S110, the slave station will receive a file transfer request sent by the master station. If the slave station receives the file transfer request sent by the master station, the slave station will verify the file transfer password in the file transfer request sent by the master station. After the slave station passes the verification of the file transfer password, the slave station receives the encrypted firmware sent by the master station, writes the received encrypted firmware into the backup buffer, and when the encrypted firmware file reception is completed, writes the byte information of the received encrypted firmware file into the firmware update information area and sets the file transfer completion flag.

[0065] In addition, before the slave station receives the encrypted firmware sent by the master station, the slave station opens the permission to write to the firmware to enable the received encrypted firmware to be written into the backup buffer of the firmware, and when the encrypted firmware reception is completed, writes the byte information of the encrypted firmware file into the firmware update information area of the firmware and sets the file transfer completion flag.

[0066] In the specific implementation process, if an error occurs in the transmission of the encrypted firmware file between the slave station and the master station, such as insufficient memory of the slave station or the communication link between the slave station and the master station is disconnected. At this time, the slave station receives the encrypted firmware file with an error, and the file transfer completion flag will indicate that the transmission is not completed.

[0067] S130: When receiving the initialization request sent by the master station to enter the initialization state, judge the file transfer completion flag. If the transfer is completed, trigger the software restart of the slave station and execute the boot program to enable the boot program to detect the byte information of the firmware file in the firmware update information area.

[0068] After writing the encrypted firmware into the backup buffer, and when the reception of the encrypted firmware file is completed, writing the byte information of the encrypted firmware file into the firmware update information area and setting the file transfer completion flag bit, the master station receives the return status sent by the slave station (the return status includes a normal status and an abnormal status, and the return status indicates whether an abnormality occurs when the slave station receives the encrypted firmware file). After the master station receives the return status sent by the slave station as the normal status (at this time, the byte information of the encrypted firmware file can be written into the firmware update information area) and the master station finishes sending the encrypted firmware file (at this time, the file transfer completion flag bit is set to transfer completed), the master station sends an initialization request to the slave station, requesting the slave station to enter the initialization state. After the slave station receives the initialization request sent by the master station to enter the initialization state, the slave station software is restarted. After the slave station software is restarted, the boot program is executed again so that the slave station detects the byte information of the firmware file in the firmware update information area according to the boot program.

[0069] S140. When it is detected that the byte information of the firmware file received in the firmware update information area by the boot program is not zero, read the encrypted firmware in the backup buffer and process the encrypted firmware to obtain the actual decrypted firmware and calculate the actual cyclic redundancy check value.

[0070] Since in step S120, the slave station receives the encrypted firmware sent by the master station, and when the reception of the encrypted firmware file corresponding to the encrypted firmware is completed, the byte information of the encrypted firmware file is written into the firmware update information area. Therefore, during the process of detecting the byte information of the firmware file in the firmware update information area based on the boot program in step S130, it is detected that the byte information of the firmware file received in the firmware update information area is not zero. At this time, step S140 is executed, reading the encrypted firmware in the backup buffer and processing the encrypted firmware to obtain the actual decrypted firmware and calculating the actual cyclic redundancy check value of the actual decrypted firmware.

[0071] In a specific embodiment, reading the encrypted firmware in the backup buffer and processing the encrypted firmware to obtain the actual decrypted firmware and calculate the actual cyclic redundancy check value includes: reading the encrypted firmware in the backup buffer and processing the encrypted firmware to obtain the actual decrypted firmware; calculating the actual cyclic redundancy check value according to the actual decrypted firmware.

[0072] Among them, reading the encrypted firmware in the backup buffer and processing the encrypted firmware to obtain the actual decrypted firmware includes: reading the encrypted firmware in the backup buffer, and using a decryption algorithm to decrypt the encrypted firmware to obtain the initial decrypted firmware; removing the padding bytes of the initial decrypted firmware based on a data padding algorithm to obtain the actual decrypted firmware.

[0073] Since the encrypted firmware received by the slave station in step S120 is obtained by performing four-byte alignment to obtain a cyclic redundancy check value, and then obtaining the initial firmware based on the cyclic redundancy check value, and then performing byte padding alignment and encryption to obtain the firmware. Therefore, when the bootloader detects that the byte information of the firmware file received in the firmware update information area is not zero, it indicates that a firmware upgrade is required at this time. Therefore, the encrypted firmware in the read backup buffer is decrypted to obtain the initial decrypted firmware, and then the padding bytes of the initial decrypted firmware are removed based on the data padding algorithm to obtain the actual decrypted firmware. Finally, the actual cyclic redundancy check value is calculated based on the actual decrypted firmware.

[0074] In a specific implementation step, if the encryption algorithm in step S120 is the AES algorithm and the data padding algorithm is the PKCS7 algorithm, the algorithm for decrypting the encrypted firmware in step S140 is also the AES algorithm, and the algorithm for removing the padding bytes of the initial decrypted firmware is also the PKCS7 algorithm. This embodiment of the present disclosure does not give specific examples in this regard.

[0075] After decrypting the encrypted firmware based on the AES algorithm to obtain the initial decrypted firmware and removing the padding bytes in the initial decrypted firmware based on the PKCS7 algorithm to obtain the actual decrypted firmware, the actual decrypted firmware is aligned in four-byte units, and then the actual cyclic redundancy check value of the decrypted firmware after four-byte alignment is calculated based on the CRC32 algorithm.

[0076] In other implementable ways, when the bootloader detects that the byte information of the firmware file received in the firmware update information area is zero, the EtherCAT protocol stack included in the APP execution area is run.

[0077] Specifically, when the bootloader detects that the byte information of the firmware file received in the firmware update information area is zero, it indicates that during the process of the master station sending the encrypted firmware to the slave station, an error occurred in the transmission process of the slave station receiving the encrypted firmware sent by the master station, the slave station's encrypted firmware write permission, and it was unable to write the encrypted firmware into the backup buffer and write the byte information of the encrypted firmware file into the firmware update information area. At this time, the EtherCAT protocol stack included in the APP execution area is run, and steps S110, S120, and S130 are continued until the bootloader detects that the byte information of the firmware file received in the firmware update information area is not zero, and then steps S140 and S150 are executed.

[0078] S150. When the actual cyclic redundancy check value is the same as the preset cyclic redundancy check value, erase the information in the APP execution area, erase the firmware update information area, and write the actual decrypted firmware into the APP execution area, thereby triggering a software restart of the slave station.

[0079] After calculating the actual cyclic redundancy check value of the encrypted firmware file in the backup buffer in step S150, compare the actual cyclic redundancy check value with the preset cyclic redundancy check value (the preset cyclic redundancy check value is the cyclic redundancy check value calculated after four-byte alignment of the firmware). When the actual cyclic redundancy check value is the same as the preset cyclic redundancy check value, it indicates that the slave station has successfully received the encrypted firmware sent by the master station. At this time, erase the information in the APP execution area (the old firmware), and write the firmware corresponding to the actual decrypted firmware file into the APP execution area, thereby triggering a software restart of the slave station.

[0080] In addition, after erasing the information in the APP execution area and writing the firmware corresponding to the actual decrypted firmware file into the APP execution area, erase the information in the backup buffer and the firmware update information area to facilitate writing a new firmware file into the backup buffer and writing the byte information corresponding to the new firmware file into the firmware update information area during subsequent firmware upgrades.

[0081] In other implementable embodiments, when the actual cyclic redundancy check value is different from the preset cyclic redundancy check value, trigger a software restart of the slave station and execute the bootloader again, so that the bootloader detects the byte information of the firmware file in the firmware update information area. Then, based on the byte information of the firmware file detected by the bootloader, determine whether to execute step S110, step S120, and step S130 or execute step S140 and step S150.

[0082] It should be noted that in the above embodiments, the firmware represents binary content, and the firmware file represents a container for binary content.

[0083] Figure 3 Exemplarily shows a specific flowchart of the EtherCAT-based encrypted firmware upgrade method of the present application.

[0084] The encrypted firmware upgrade method based on EtherCAT provided by the embodiments of the present disclosure enters the boot state according to the boot request when receiving the boot request sent by the master station to enter the boot state; when receiving the file transfer request sent by the master station and the file transfer password in the file transfer request passes the verification, receive the encrypted firmware, write the encrypted firmware into the backup buffer, and when the encrypted firmware file reception is completed, write the byte information of the received encrypted firmware file into the firmware update information area and set the file transfer completion flag bit; when receiving the initialization request sent by the master station to enter the initialization state, judge the file transfer completion flag bit, if the transfer is completed, trigger the slave software to restart and execute the boot program, so that the boot program detects the byte information of the firmware file in the firmware update information area; when receiving that the byte information of the firmware file received in the firmware update information area detected by the boot program is not zero, read the encrypted firmware in the backup buffer and process the encrypted firmware to obtain the actual decrypted firmware and calculate the actual cyclic redundancy check value; when the actual cyclic redundancy check value is the same as the preset cyclic redundancy check value, erase the information in the APP execution area, erase the firmware update information area, and write the actual decrypted firmware into the APP execution area, and then trigger the slave software to restart. When upgrading the firmware, on the one hand, the firmware written to the slave station is an encrypted firmware to avoid the leakage of the content in the firmware. On the other hand, since the firmware written to the slave station is an encrypted firmware, through the corresponding decryption method, the encrypted firmware is decrypted. Furthermore, by verifying whether the actual cyclic redundancy check value of the decrypted firmware after decryption is the same as the cyclic redundancy check value corresponding to the encrypted firmware file received by the slave station, it is determined whether the slave station has received the complete encrypted firmware, and then the firmware update is realized.

[0085] Based on the above embodiments, Figure 4 is a schematic structural diagram of an encrypted firmware upgrade device based on EtherCAT provided by the embodiments of the present disclosure. As Figure 4 shown, the encrypted firmware upgrade device based on EtherCAT includes:

[0086] The boot state entry module 210 is configured to enter the boot state according to the boot request when receiving the boot request sent by the master station to enter the boot state;

[0087] An information writing module 220, configured to receive an encrypted firmware when receiving a file transfer request sent by a master station and the file transfer password in the file transfer request passes verification, write the encrypted firmware into a backup buffer, and when the encrypted firmware file reception is completed, write the byte information of the received encrypted firmware file into a firmware update information area and set a file transfer completion flag bit, where the encrypted firmware is obtained by calculating a preset cyclic redundancy check value after aligning the firmware in four-byte units, then appending the preset cyclic redundancy check value to obtain an initial firmware, and then performing byte padding alignment and encryption;

[0088] A startup module 230, configured to, when receiving an initialization request sent by the master station to enter an initialization state, judge the file transfer completion flag bit, and if the transfer is completed, trigger a slave station software restart and execute a boot program, so that the boot program detects the byte information of the firmware file in the firmware update information area;

[0089] An encrypted firmware file processing module 240, configured to, when receiving that the boot program detects that the byte information of the firmware file received in the firmware update information area is not zero, read the encrypted firmware in the backup buffer and process the encrypted firmware to obtain an actual decrypted firmware and calculate an actual cyclic redundancy check value;

[0090] A firmware update module 250, configured to, when the actual cyclic redundancy check value is the same as the preset cyclic redundancy check value, erase the information in the APP execution area, erase the firmware update information area, and write the actual decrypted firmware into the APP execution area, thereby triggering a slave station software restart.

[0091] The encrypted firmware upgrade device based on EtherCAT provided by the embodiments of the present disclosure enters the boot state according to the boot request when receiving the boot request sent by the master station to enter the boot state; when receiving the file transfer request sent by the master station and the file transfer password in the file transfer request passes the verification, receives the encrypted firmware, writes the encrypted firmware into the backup buffer, and when the encrypted firmware file reception is completed, writes the byte information of the received encrypted firmware file into the firmware update information area, and sets the file transfer completion flag bit; when receiving the initialization request sent by the master station to enter the initialization state, judges the file transfer completion flag bit, if the transfer is completed, triggers the restart of the slave station software, and executes the boot program, so that the boot program detects the byte information of the firmware file in the firmware update information area; when receiving that the byte information of the firmware file received in the firmware update information area detected by the boot program is not zero, reads the encrypted firmware in the backup buffer and processes the encrypted firmware to obtain the actual decrypted firmware and calculates the actual cyclic redundancy check value; when the actual cyclic redundancy check value is the same as the preset cyclic redundancy check value, erases the information in the APP execution area, erases the firmware update information area, and writes the actual decrypted firmware into the APP execution area, and then triggers the restart of the slave station software. When upgrading the firmware, on the one hand, the firmware written to the slave station is encrypted firmware, which avoids the leakage of the content in the firmware. On the other hand, since the firmware written to the slave station is encrypted firmware, therefore, through the corresponding decryption method, the encrypted firmware is decrypted, and then by verifying whether the actual cyclic redundancy check value of the decrypted firmware after decryption is the same as the cyclic redundancy check value corresponding to the encrypted firmware file received by the slave station, it is determined whether the slave station has received the complete encrypted firmware, and then the firmware update is realized.

[0092] In a specific embodiment, the step of entering the boot state according to the boot request when receiving the boot request sent by the master station to enter the boot state includes:

[0093] When receiving the boot request sent by the master station to enter the boot state, obtain the target state in the boot request;

[0094] Write the target state in the boot request into the control bit of the slave station, so that the slave station enters the boot state according to the target state of the control bit.

[0095] In a specific embodiment, the step of reading the encrypted firmware in the backup buffer and processing the encrypted firmware to obtain the actual decrypted firmware and calculating the actual cyclic redundancy check value includes:

[0096] Read the encrypted firmware in the backup buffer and process the encrypted firmware to obtain the actual decrypted firmware;

[0097] Calculate the actual cyclic redundancy check value according to the actual decrypted firmware.

[0098] In a specific embodiment, reading the encrypted firmware in the backup buffer and processing the encrypted firmware to obtain an actual decrypted firmware includes:

[0099] Reading the encrypted firmware in the backup buffer and decrypting the encrypted firmware using a decryption algorithm to obtain an initial decrypted firmware;

[0100] Removing the padding bytes of the initial decrypted firmware based on a data padding algorithm to obtain an actual decrypted firmware.

[0101] In a specific embodiment, before receiving the encrypted firmware and writing the encrypted firmware into the backup buffer, it further includes:

[0102] Opening the firmware write permission.

[0103] In a specific embodiment, the method further includes:

[0104] When the byte information of the firmware file received in the firmware update information area detected by the bootloader is zero, running the EtherCAT protocol stack included in the APP execution area.

[0105] In a specific embodiment, the method further includes:

[0106] When the actual cyclic redundancy check value is different from the cyclic redundancy check value, triggering a restart of the slave software.

[0107] An embodiment of the present application also provides a computer device. For details, please refer to Figure 5 , Figure 5 which is the basic structural block diagram of the computer device in this embodiment.

[0108] The computer device includes a memory 510 and a processor 520 that communicate with each other through a system bus. It should be noted that only the computer device with components 510 - 520 is shown in the figure. However, it should be understood that it is not required to implement all the shown components, and more or fewer components can be implemented alternatively. Among them, those skilled in the art of the present technology can understand that the computer device here is a device that can automatically perform numerical calculations and / or information processing according to pre-set or stored instructions, and its hardware includes but is not limited to microprocessors, application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), digital signal processors (DSPs), embedded devices, etc.

[0109] The computer device can be a computing device such as a desktop computer, a notebook, a handheld computer, and a cloud server. The computer device can perform human-computer interaction with the user through means such as a keyboard, a mouse, a remote control, a touchpad, or a voice control device.

[0110] The memory 510 includes at least one type of readable storage medium. The readable storage medium includes non-volatile memory or volatile memory. For example, flash memory, a hard disk, a multimedia card, a card-type memory (such as an SD or DX memory, etc.), random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, a magnetic disk, an optical disk, etc. RAM can include static RAM or dynamic RAM. In some embodiments, the memory 510 can be an internal storage unit of the computer device. For example, the hard disk or the memory of the computer device. In other embodiments, the memory 510 can also be an external storage device of the computer device. For example, a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, or a Flash Card equipped on the computer device. Of course, the memory 510 can also include both the internal storage unit and the external storage device of the computer device. In this embodiment, the memory 510 is generally used to store the operating system and various application software installed on the computer device, such as the program code of the above method. In addition, the memory 510 can also be used to temporarily store various data that have been output or will be output.

[0111] The processor 520 is generally used to execute the overall operations of the computer device. In this embodiment, the memory 510 is used to store program code or instructions. The program code includes computer operation instructions. The processor 520 is used to execute the program code or instructions stored in the memory 510 or process data. For example, run the program code of the above method.

[0112] In this article, the bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, or the like. The bus system can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, only a thick line is used in the figure, but it does not mean that there is only one bus or one type of bus.

[0113] Another embodiment of the present application further provides a computer-readable medium, which can be a computer-readable signal medium or a computer-readable medium. A processor in the computer reads the computer-readable program code stored in the computer-readable medium, so that the processor can execute the functional actions specified in each step or the combination of steps in the above method; and generate a device that implements the functional actions specified in each block or the combination of blocks in the block diagram.

[0114] The computer-readable medium includes but is not limited to electronic, magnetic, optical, electromagnetic, infrared memories or semiconductor systems, devices or apparatuses, or any suitable combination of the foregoing. The memory is used to store program codes or instructions, and the program codes include computer operation instructions. The processor is used to execute the program codes or instructions of the above method stored in the memory.

[0115] For the definitions of the memory and the processor, reference can be made to the description of the foregoing computer device embodiments, which will not be elaborated here.

[0116] In several embodiments provided by the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only illustrative. For example, the division of modules or units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of the devices or units can be in an electrical, mechanical or other form.

[0117] In each embodiment of the present application, each functional unit or module can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.

[0118] When an integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to execute all or part of the steps of the methods in various embodiments of this application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs.

[0119] Unless the context clearly indicates otherwise, the singular forms of the words used in this specification and the appended claims include the plural, and vice versa. Thus, when referring to the singular, the corresponding plural terms are usually included. Similarly, the terms "comprising" and "including" will be interpreted as inclusive rather than exclusive. Likewise, the term "including" and "or" should be interpreted as inclusive, unless such an interpretation is explicitly prohibited in this specification. Where the term "example" is used in this specification, especially when it is located after a group of terms, the said "example" is merely exemplary and illustrative and should not be considered exclusive or extensive.

[0120] Further aspects and scopes of adaptability become apparent from the description provided herein. It should be understood that the various aspects of this application can be implemented alone or in combination with one or more other aspects. It should also be understood that the description herein and the specific embodiments are for illustrative purposes only and are not intended to limit the scope of this application.

[0121] The above has described several embodiments of the present disclosure in detail. However, obviously, those skilled in the art can make various modifications and variations to the embodiments of the present disclosure without departing from the spirit and scope of the present disclosure. The protection scope of the present disclosure is defined by the appended claims.

Claims

1. An encrypted firmware upgrade method based on EtherCAT, characterized in that: include: When receiving a boot request sent by the master station for entering the boot state, entering the boot state according to the boot request; When a file transfer request sent by a master station is received and the file transfer password in the file transfer request passes verification, an encrypted firmware is received and written into a backup buffer, and when the encrypted firmware file is received, the byte information of the received encrypted firmware file is written into a firmware update information area, and a file transfer completion flag is set, wherein the encrypted firmware is a firmware that is four-byte aligned, and based on a cyclic redundancy check algorithm, a preset cyclic redundancy check value corresponding to the firmware after the four-byte alignment is calculated, and then the calculated preset cyclic redundancy check value is appended to the firmware to form a first initial firmware, and then the formed first initial firmware is aligned by a data filling algorithm to obtain a second initial firmware, and finally the obtained second initial firmware is encrypted by an encryption algorithm to obtain the encrypted firmware; Upon receiving an initialization request sent by the master station for entering an initialization state, determining a file transfer completion flag, and if the transfer is completed, triggering a slave station software restart, and executing a boot program, so that the boot program detects byte information of the firmware file in the firmware update information area; When the boot program detects that the firmware file byte information received in the firmware update information area is not zero, reading the encrypted firmware in the backup buffer and processing the encrypted firmware to obtain the actual decrypted firmware and calculate the actual cyclic redundancy check value; When the actual cyclic redundancy check value is the same as the preset cyclic redundancy check value, erasing the information of the APP execution area, erasing the firmware update information area, and writing the actual decrypted firmware into the APP execution area, thereby triggering a restart of the slave station software; The step of reading the encrypted firmware in the backup buffer and processing the encrypted firmware to obtain the actual decrypted firmware and calculate the actual cyclic redundancy check value includes: Reading the encrypted firmware in the backup buffer, and decrypting the encrypted firmware using a decryption algorithm to obtain initial decrypted firmware; Removing padding bytes of the initial decryption firmware based on a data padding algorithm to obtain actual decryption firmware; According to the actual decrypted firmware, an actual cyclic redundancy check value is calculated.

2. The method according to claim 1, characterized in that: When receiving a boot request sent by the master station for entering the boot state, entering the boot state according to the boot request includes: When receiving a boot request sent by the master station for entering a boot state, obtaining a target state in the boot request; The target state in the boot request is written into the control bit of the slave station, so that the slave station enters the boot state according to the target state of the control bit.

3. The method according to claim 1, characterized in that The receiving of the encrypted firmware and before writing the encrypted firmware into the backup buffer further includes: Enable firmware write permission.

4. The method according to claim 1, characterized in that: The method further comprises: When the boot program detects that the byte information of the firmware file received in the firmware update information area is zero, the EtherCAT protocol stack included in the APP execution area is run.

5. The method according to claim 1, characterized in that The method further comprises: When the actual cyclic redundancy check value is different from the cyclic redundancy check value, a slave station software restart is triggered.

6. An encrypted firmware upgrade device based on EtherCAT, characterized in that: include: A boot state entry module, configured to enter the boot state according to the boot request when receiving a boot request sent by the master station for entering the boot state; An information writing module is used to receive the encrypted firmware and write the encrypted firmware into the backup buffer when the file transfer request sent by the master station is received and the file transfer password in the file transfer request is verified, and when the encrypted firmware file is received, write the byte information of the received encrypted firmware file into the firmware update information area and set the file transfer completion flag, wherein the encrypted firmware is to align the firmware with four bytes, calculate the preset cyclic redundancy check value corresponding to the firmware after the four-byte alignment based on the cyclic redundancy check algorithm, and then append the calculated preset cyclic redundancy check value to the firmware to form a first initial firmware, and then align the formed first initial firmware through the data filling algorithm to obtain the second initial firmware, and finally encrypt the obtained second initial firmware through the encryption algorithm to obtain the encrypted firmware; A startup module, configured to, upon receiving an initialization request from the master station for entering an initialization state, determine a file transfer completion flag, and if the transfer is completed, trigger a slave station software restart, and execute a boot program, so that the boot program detects byte information of the firmware file in the firmware update information area; An encrypted firmware file processing module is used to read the encrypted firmware in the backup buffer and process the encrypted firmware when the boot program detects that the firmware file byte information received in the firmware update information area is not zero, obtain the actual decrypted firmware and calculate the actual cyclic redundancy check value; A firmware update module, configured to, when the actual cyclic redundancy check value is the same as the preset cyclic redundancy check value, erase the information of the APP execution area, erase the firmware update information area, and write the actual decrypted firmware into the APP execution area, thereby triggering a restart of the slave station software; The step of reading the encrypted firmware in the backup buffer and processing the encrypted firmware to obtain the actual decrypted firmware and calculate the actual cyclic redundancy check value includes: Reading the encrypted firmware in the backup buffer, and decrypting the encrypted firmware using a decryption algorithm to obtain initial decrypted firmware; Removing padding bytes of the initial decryption firmware based on a data padding algorithm to obtain actual decryption firmware; According to the actual decrypted firmware, an actual cyclic redundancy check value is calculated.

7. A computer device, characterized in that: include: one or more processors; a storage device for storing one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 5.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the method according to any one of claims 1 to 5 is implemented.

Citation Information

Patent Citations

  • EtherCAT slave station firmware upgrading method and EtherCAT slave station

    CN117742762A

  • IO module firmware upgrading method, device and equipment and readable storage medium

    CN119011329A