Firmware upgrading method and device, intelligent terminal and storage medium

By forming a trusted execution environment on the motherboard of the smart terminal, storing and obtaining pre-stored firmware from it for upgrading, the problem of firmware upgrades occupying more hardware resources and poor security in the existing technology is solved, and the effect of reducing resource occupation and improving security is achieved.

CN119987803APending Publication Date: 2025-05-13WUXI RONGKA TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411817588.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-11
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The firmware upgrade method of existing smart terminals occupies a lot of hardware resources, and has poor file security, making it easy to be attacked.

Method used

By forming a trusted execution environment on the motherboard of the smart terminal, pre-stored firmware is stored, and when upgrading is required, pre-stored firmware is obtained from the trusted execution environment for upgrading. This method includes reading the hardware configuration and firmware version number of the functional device, generating control policies to determine whether an upgrade is required, and updating the firmware in the backup area after the upgrade is successful.

Benefits of technology

It reduces the use of hardware resources on peripheral devices, improves firmware security, and reduces the risk of being attacked.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119987803A_ABST
    Figure CN119987803A_ABST
Patent Text Reader

Abstract

The invention discloses a firmware upgrading method and device, an intelligent terminal and a storage medium. The firmware upgrading method is applied to the intelligent terminal, the intelligent terminal comprises a functional device connected with a mainboard, a trusted execution environment in which pre-stored firmware is stored is formed in the mainboard, and the firmware upgrading method comprises the steps that hardware configuration of the functional device is read according to a starting instruction, and configuration information is formed; reading a firmware version number of the functional device, comparing the firmware version number with a version number of pre-stored firmware, and outputting a comparison result; generating a control strategy according to the comparison result and the configuration information, and judging whether firmware of the functional device needs to be upgraded or not according to the control strategy; after it is confirmed that the firmware of the functional device needs to be upgraded, pre-stored firmware stored in the trusted execution environment is obtained, and firmware upgrading and firmware backup of the functional device are started. According to the technical scheme, occupation of hardware resources of the peripheral equipment can be effectively reduced, the security of the file can be improved, and the risk of being attacked is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of sensor technology, and in particular to a firmware upgrade method, device, intelligent terminal and storage medium. Background Art

[0002] Smart terminals refer to a type of embedded computer system devices, whose architecture framework is consistent with the embedded system architecture, but the application scenarios are more specific, so their architecture is more detailed. Smart terminals usually have the ability to access the Internet, and can be equipped with various operating systems and customized with various functions according to user needs. Common smart terminals include mobile smart terminals, in-vehicle smart terminals, smart TVs, and wearable devices.

[0003] At present, the firmware upgrade of peripheral devices of smart terminals is mostly local upgrade. For example, smart terminals using the Android operating system usually store the upgraded firmware files in the Android file system. If the upgrade fails, the device firmware is restored by the hardware device storage backup area.

[0004] However, firmware recovery based on hardware memory will occupy the hardware resources of peripheral devices, and the backup files and firmware upgrade files of the Android file system are at risk of being attacked, and the security is poor. Summary of the invention

[0005] In view of the defects in the prior art, the present invention provides a firmware upgrade method which can effectively reduce the hardware resource occupation of peripheral devices, improve the security of files, and reduce the risk of being attacked.

[0006] The present application discloses a firmware upgrade method, which is applied to an intelligent terminal, wherein the intelligent terminal includes a mainboard and a functional device connected to the mainboard, wherein the mainboard forms a trusted execution environment, and the trusted execution environment stores pre-stored firmware. The firmware upgrade method includes:

[0007] Reading the hardware configuration of the functional device according to the startup instruction to form configuration information;

[0008] Reading the firmware version number of the functional device, comparing the firmware version number with the version number of the pre-stored firmware, and outputting the comparison result;

[0009] generating a control strategy according to the comparison result and the configuration information, and judging whether the firmware of the functional device needs to be upgraded according to the control strategy;

[0010] After confirming that the firmware of the functional device needs to be upgraded, the pre-stored firmware stored in the trusted execution environment is obtained, and the firmware upgrade of the functional device is started.

[0011] In one aspect, the trusted execution environment is provided with a storage area and a backup area;

[0012] Before the step of inputting the start instruction, the method includes:

[0013] The pre-stored firmware is stored in the storage area, and the pre-stored firmware is stored in the backup area.

[0014] In one aspect, after the step of initiating the firmware upgrade of the functional device, the method further comprises:

[0015] If the upgrade is successful, the pre-stored firmware in the storage area is updated to the backup area.

[0016] In one aspect, after the step of initiating the firmware upgrade of the functional device, the method further includes:

[0017] If the upgrade fails, the pre-stored firmware in the backup area is obtained, and the firmware upgrade of the functional device is restarted based on the pre-stored firmware in the backup area.

[0018] In one aspect, a rich execution environment is also formed in the main board, a download control unit is provided in the rich execution environment, the download control unit is used to control the download processing of the firmware, a firmware management unit is provided in the trusted execution environment, the firmware management unit is used to manage the downloaded files and backup files of the firmware, the functional device is connected to the download control unit in the rich execution environment, the firmware management unit is connected to the storage area and the backup area, and the download control unit is communicatively connected to the firmware management unit.

[0019] In one aspect, a download management module is provided in the trusted execution environment, and the download management module is used to control the download processing of the firmware, manage the downloaded files and backup files of the firmware, and the download management module is respectively connected to the storage area and the backup area, and the download management module is communicatively connected to the functional device.

[0020] In one aspect, a rich execution environment is also formed in the main board, a download channel is established in the functional device, and the rich execution environment and the executable environment establish a communication connection with the download channel.

[0021] In order to solve the above problems, the present application also provides a firmware upgrade device, the firmware upgrade device comprising:

[0022] A reading module, the reading module is used to read the hardware configuration of the functional device according to the startup instruction to form configuration information; the reading module is also used to read the firmware version number of the functional device, compare the firmware version number with the version number of the pre-stored firmware, and output the comparison result;

[0023] A judgment module, wherein the judgment module generates a control strategy according to the comparison result and the configuration information, and judges whether the firmware of the functional device needs to be upgraded according to the control strategy;

[0024] A startup module, after confirming that the firmware of the functional device needs to be upgraded, obtains the pre-stored firmware stored in the trusted execution environment and starts the firmware upgrade of the functional device.

[0025] In order to solve the above problems, the present application also provides an intelligent terminal, which includes a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the method described above when executing the computer program.

[0026] In order to solve the above problem, the present application also provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method described above is implemented.

[0027] The beneficial effects of the present invention are embodied in that: by storing pre-stored firmware in a trusted execution environment, when the firmware of a functional device needs to be upgraded, the pre-stored firmware is obtained from the trusted execution environment. In this way, the pre-stored firmware is retrieved from the outside of the functional device, reducing the occupation of the hardware resources of the functional device itself. Moreover, since the pre-stored firmware is stored in a trusted execution environment, the security protection capability of the pre-stored firmware is improved. It can be seen that the technical solution of the present application can effectively reduce the occupation of hardware resources of peripheral devices, and can also improve the security of files and reduce the risk of being attacked. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following is a brief introduction to the drawings required for the specific embodiments or the description of the prior art. In all the drawings, similar elements or parts are generally identified by similar reference numerals. In the drawings, the elements or parts are not necessarily drawn according to the actual scale.

[0029] Figure 1 This is a schematic diagram of the process steps of the firmware upgrade method in this application;

[0030] Figure 2 A schematic diagram of the process steps for storing pre-stored firmware in the firmware upgrade method of this application;

[0031] Figure 3 A schematic diagram of the process steps for a successful firmware upgrade in the firmware upgrade method of this application;

[0032] Figure 4 A schematic diagram of the process steps in the firmware upgrade method of this application if the upgrade fails;

[0033] Figure 5 This is a schematic diagram of the functional modules of the first embodiment of the smart terminal in this application;

[0034] Figure 6 This is a schematic diagram of the functional modules of the second embodiment of the smart terminal in this application;

[0035] Figure 7 This is a schematic diagram of the functional modules of the third embodiment of the smart terminal in this application.

[0036] 110, download control unit; 120, firmware management unit; 130, storage area; 140, backup area; 150, download management module. DETAILED DESCRIPTION

[0037] The following embodiments of the technical solution of the present invention are described in detail in conjunction with the accompanying drawings. The following embodiments are only used to more clearly illustrate the technical solution of the present invention, and are therefore only used as examples, and cannot be used to limit the protection scope of the present invention.

[0038] It should be noted that, unless otherwise specified, the technical terms or scientific terms used in this application should have the common meanings understood by those skilled in the art to which the present invention belongs.

[0039] like Figure 1 As shown, the firmware upgrade method is applied to smart terminals, which can be mobile smart terminals, vehicle-mounted smart terminals, smart TVs, wearable devices, etc. Smart terminals include a mainboard and functional devices connected to the mainboard. The mainboard is also called a mainboard, a system board, or a motherboard. It is one of the most basic and important components of a computer. The mainboard is generally a rectangular circuit board, on which the main circuit system that makes up the computer is installed, and the control switch interface. The mainboard forms a Trusted Execution Environment (TEE), which is a security mechanism built in a computing system. It is an operating environment independent of other areas of the system that is constructed based on a hardware isolation mechanism. TEE creates a secure environment through hardware technology to ensure the security of the code and data running in it, and prevent attackers from accessing or tampering with it.

[0040] In this application, the functional device can be understood as a peripheral device that can transfer data with the mainboard. The functional device can be NFC (Near Field Communication), WIFI (wireless communication) or Fingerprint (fingerprint recognition), or other production line tools on the smart terminal.

[0041] Trusted execution environment has at least the following advantages: 1. Hardware isolation: TEE is isolated from the main operating system and other applications through hardware-level technology. This means that even if the main system is attacked or invaded, the code and data in the TEE can still remain secure. 2. Integrity protection: The integrity of the code and data running in the TEE is guaranteed, that is, unauthorized modifications can be detected and blocked. 3. Confidentiality protection: Only authorized access can obtain data in the TEE, effectively preventing the leakage of sensitive information.

[0042] Trusted Execution Environment has a wide range of application scenarios: it is applicable to many fields, such as mobile payment, digital copyright protection, key data processing in IoT devices, etc. In the IoT, the control instructions of smart home devices are processed in TEE to ensure family security and privacy.

[0043] The trusted execution environment stores pre-stored firmware. The smart terminal can store the firmware in the trusted execution environment before leaving the factory, or store it in the trusted execution environment when the smart terminal system is upgraded. The firmware upgrade method includes:

[0044] Step S10, read the hardware configuration of the functional device according to the startup instruction to form configuration information; the startup instruction can be actively input, or it can be automatically generated when the intelligent terminal is turned on, or the startup instruction can be generated regularly. Through the startup instruction, the hardware configuration of the functional device itself begins to be read, and different functional devices have different hardware configurations. For upgrading the firmware, the hardware configuration of some functional devices does not support the upgrade, and some hardware configurations are relatively high and can support firmware upgrades. The configuration information obtained mainly determines whether it can meet the requirements of the firmware upgrade.

[0045] Step S20, read the firmware version number of the functional device, compare the firmware version number with the version number of the pre-stored firmware, and output the comparison result; the firmware usually has a version number and a firmware file, and the firmware that supports the operation of the functional device itself has a firmware version number. By obtaining the firmware version number, it can be compared with the pre-stored firmware version number to clearly understand whether there is a version difference between the two, thereby outputting the comparison result, that is, whether there is a difference, and the size of the difference in the version numbers of the two when there is a difference.

[0046] Step S30: Generate a control strategy based on the comparison result and the configuration information, and determine whether the firmware of the functional device needs to be upgraded based on the control strategy; the control strategy can be used to comprehensively determine whether the version number of the functional device needs to be upgraded. For example, if the comparison result shows that there is a version difference between the two, and the configuration information determines that the hardware of the functional device also supports firmware upgrade, the control strategy can be used to control the firmware upgrade.

[0047] For another example, if the comparison result determines that there is no difference between the two versions, or if the configuration information determines that the hardware of the functional device does not support firmware upgrade, the control strategy can be used to stop the firmware upgrade. The control strategy can also determine whether to upgrade based on the user's active choice.

[0048] Step S40: after confirming that the firmware of the functional device needs to be upgraded, obtain the pre-stored firmware stored in the trusted execution environment and start upgrading the firmware of the functional device.

[0049] In this embodiment, by storing pre-stored firmware in a trusted execution environment, when the firmware of a functional device needs to be upgraded, the pre-stored firmware is obtained from the trusted execution environment. In this way, the pre-stored firmware is retrieved from the outside of the functional device, reducing the occupation of the hardware resources of the functional device itself. Moreover, since the pre-stored firmware is stored in a trusted execution environment, the security protection capability of the pre-stored firmware is improved. It can be seen that the technical solution of the present application can effectively reduce the occupation of hardware resources of peripheral devices, and can also improve the security of files and reduce the risk of being attacked.

[0050] like Figure 2 As shown, in one embodiment of the present application, a storage area 130 and a backup area 140 are provided in the trusted execution environment; two independent areas are divided in the trusted execution environment, and the storage area 130 and the backup area 140 can store files respectively.

[0051] Before entering the start command, include:

[0052] Step S01, storing the pre-stored firmware in the storage area 130, and storing the pre-stored firmware in the backup area 140. It can be seen that the pre-stored firmware is stored in two locations, that is, the storage area 130 and the backup area 140 both store the pre-stored firmware, so that when the pre-stored firmware in the storage area 130 is damaged, the pre-stored firmware in the backup area 140 can be read. Of course, the number of backup areas 140 is not limited to one, and can be multiple.

[0053] In addition, the storage area 130 and the backup area 140 are both in a trusted execution environment, so that the pre-stored firmware in the storage area 130 and the backup area 140 can be well protected to reduce the possibility of being attacked.

[0054] like Figure 3 As shown, in one embodiment of the present application, after the step of starting the firmware upgrade of the functional device, the following steps are included:

[0055] Step S51, if the upgrade is successful, the pre-stored firmware in the storage area 130 is updated to the backup area 140. After the upgrade is successful, it means that the functional device currently uses the firmware in the storage area 130. In order to retain the firmware used by the functional device, to facilitate subsequent re-upgrade, or to ensure that the functional device can be upgraded again when needed when the file in the storage area 130 is damaged, the pre-stored firmware after the upgrade is successfully updated to the backup area 140. Thereby, the firmware in the backup area 140 is consistent with the firmware version used by the functional device.

[0056] like Figure 4 As shown, in one embodiment of the present application, after the step of starting the firmware upgrade of the functional device, it also includes:

[0057] Step S52: if the upgrade fails, the pre-stored firmware in the backup area 140 is obtained, and the firmware upgrade of the functional device is restarted based on the pre-stored firmware in the backup area 140. Generally speaking, the upgrade failure may be caused by the damage of the pre-stored firmware in the storage area 130. In this case, the pre-stored firmware in the backup area 140 is extracted, and the firmware of the functional device is upgraded again through the pre-stored firmware in the backup area 140. Thus, at least a double-layer guarantee is formed to ensure that the firmware can be upgraded smoothly.

[0058] In one embodiment of the present application, a Rich Execution Environment (REE) is also formed in the mainboard, which means that a general operating system such as Android and iOS can be run in the operating system runtime environment. REE is an open environment and is vulnerable to attacks. The relationship between the Rich Execution Environment and the Trusted Execution Environment is that the Trusted Execution Environment is a secure area on the central processing unit that can ensure that sensitive data is processed in an isolated and trusted environment, thereby protecting it from software attacks in the REE. Compared with REE, TEE can provide stronger processing power and larger memory space.

[0059] A download control unit 110 is provided in the rich execution environment, and the download control unit 110 is used to control the download process of the firmware. A firmware management unit 120 is provided in the trusted execution environment, and the firmware management unit 120 is used to manage the download files and backup files of the firmware. The functional device is connected to the download control unit 110 in the rich execution environment, and the firmware management unit 120 is connected to the storage area 130 and the backup area 140. The download control unit 110 is connected to the firmware management unit 120 in communication. In this embodiment, the functional device is connected to the rich execution environment, and then the download control unit 110 in the rich execution environment and the firmware management unit 120 in the trusted execution environment perform data transmission, so that the firmware file in the trusted execution environment can be extracted.

[0060] like Figure 5 As shown, the following is an example based on this embodiment:

[0061] 1. The default pre-stored firmware is stored in the storage area 130 and the backup area 140 or the terminal production line tool in the trusted execution environment. The storage area 130 may include files of NFC Firmware File, WIFI Firmware File, and Other Firmware File. The backup area 140 may include files of NFC Restore File, WIFI Restore File, and Other RestoreFile. The pre-stored firmware is written into the storage area 130 by downloading the control unit 110 (Download CA) to the firmware management unit 120 (Download TA), and backed up to the backup area 140. The pre-stored firmware may be in plain text, provided encrypted by the peripheral equipment manufacturer, or provided after signing. The pre-stored firmware includes the firmware version number and the firmware file. It is optional to attach the firmware signature and others.

[0062] 2. After the smart terminal is started, a startup command is generated, and the NFC HAL, WIFI HAL or Other HAL component reads the hardware configuration of the functional device to form configuration information. The formation of configuration information is an important basis for determining whether an upgrade is required.

[0063] 3. The NFC HAL, WIFI HAL or Other HAL components access the Download TA unit in the trusted execution environment through the Download CA module, and read the version number of the firmware pre-stored in the trusted execution environment of the smart terminal, that is, the version number saved in the NFCFirmware File, WIFI Firmware File and Other Firmware File files. And compare the firmware version number of the functional device itself.

[0064] 4. By judging the version numbers of the two, the control strategy decides whether to start the upgrade. The control situations of the general control strategy include no upgrade, different version upgrade or higher version upgrade. If it is a different version upgrade or a higher version upgrade, the NFCHAL, WIFI HAL or Other HAL component accesses the Download TA unit in the trusted execution environment through the Download CA unit, obtains the NFC Firmware File, WIFI Firmware File and Other Firmware File files, and starts the upgrade process.

[0065] 5. If the upgrade is successful, the NFC HAL, WIFI HAL or Other HAL component accesses the Download TA in the trusted execution environment through the Download CA unit, and updates the NFC Firmware File, WIFI Firmware File and Other Firmware File files to the NFC Restore File, WIFI Restore File and Other RestoreFile files respectively.

[0066] 6. If the upgrade fails, the NFC HAL, WIFI HAL or Other HAL components access the Download TA module in the trusted execution environment through the Download CA module, obtain the NFC Restore File, WIFI Restore File and Other Restore File files, and start the backup file upgrade. Among them, functional modules such as NFCC, WIFI or Other perform data interaction in a rich execution environment. The download control unit 110 performs data communication through the interactive interface (TEE Client API). The NFCHAL, WIFI HAL or Other HAL components then communicate with the corresponding APP (Application) through their respective NFC Service, WIFI Service or Other Service.

[0067] In one embodiment of the present application, a download management module 150 is provided in the trusted execution environment. The download management module 150 is used to control the download processing of the firmware, manage the downloaded files and backup files of the firmware, and the download management module 150 is respectively connected to the storage area 130 and the backup area 140. The download management module 150 is in communication connection with the functional device. In this embodiment, the functional device directly interacts with the trusted execution environment for data, and the download and management of the firmware files are all in the trusted execution environment, which can better reduce attacks.

[0068] like Figure 6 As shown, the following is an example based on this embodiment:

[0069] 1. The default pre-stored firmware is stored in the storage area 130 and the backup area 140 or the terminal production line tool in the trusted execution environment. The storage area 130 may include SE Firmware File, Fingerprint Firmware File and Other Firmware File. The backup area 140 may include SE Restore File, Fingerprint Restore File and Other Restore File. The pre-stored firmware is written to the storage area 130 by the download management module 150 (Download Module) and backed up to the backup area 140. The pre-stored firmware may be in plain text, encrypted or signed by the peripheral equipment manufacturer. The pre-stored firmware includes the firmware version number and the firmware file. It is optional to attach the firmware signature and other options.

[0070] 2. After the intelligent terminal is started, a startup instruction is generated, and the SE Service or Fingerprint TA component reads the hardware configuration of the functional device to form configuration information.

[0071] 3. The SE Service or Fingerprint TA component reads the version number of the firmware pre-stored in the trusted execution environment of the intelligent terminal, namely the version number stored in the SE Firmware File, Fingerprint Firmware File and Other Firmware File files, through the download management module 150, and compares the firmware version number of the functional device itself.

[0072] 4. By judging the version numbers of the two, the control strategy decides whether to start the upgrade. The control situations of the general control strategy include no upgrade, different version upgrade or higher version upgrade. If it is a different version upgrade or a higher version upgrade, the SEService or Fingerprint TA component accesses the SE Firmware File, Fingerprint Firmware File and Other Firmware File files through the download management module 150 to start the upgrade process.

[0073] 5. If the upgrade is successful, the SE Service or Fingerprint TA component updates the SEFirmware File, Fingerprint Firmware File and Other Firmware File files to the SERestore File, Fingerprint Restore File and Other Restore File files respectively through the download management module 150.

[0074] 6. If the upgrade fails, the SE Service TA or Fingerprint TA component obtains the SE Restore File, Fingerprint Restore File and Other Restore File files through the download management module 150, and starts the backup file upgrade. Among them, functional components such as SE and Fingerprint communicate with the trusted execution environment. For example, the SEService TA component communicates with the OMA Service in the rich execution environment through the OMA-TAGP TEE SE API module.

[0075] In one embodiment of the present application, a rich execution environment is also formed in the mainboard, a download channel is established in the functional device, and the rich execution environment and the executable environment establish a communication connection with the download channel. Data interaction between the rich execution environment and the executable environment can be achieved through the download channel established in the functional device.

[0076] like Figure 7 As shown, the following is an example based on this embodiment:

[0077] 1. The default pre-stored firmware is stored in the storage area 130 and the backup area 140 or the terminal production line tool in the trusted execution environment. The storage area 130 may include SE Firmware File and Firmware File. The backup area 140 may include SE Restore File and NFC Restore File. The pre-stored firmware is written into the storage area 130 by the download management module 150 (Download Module) and backed up to the backup area 140. The pre-stored firmware may be in plain text, encrypted or signed by the peripheral equipment manufacturer. The pre-stored firmware includes the firmware version number and the firmware file. It is optional to attach the firmware signature and other options.

[0078] 2. After the smart terminal is started, a startup instruction is generated, and the NFC HAL component reads the hardware configuration of the functional device to form configuration information.

[0079] 3. The NFC HAL component accesses the download management module 150 in the trusted execution environment through the SE HAL component, and reads the version number of the firmware pre-stored in the trusted execution environment of the smart terminal, that is, the version number in the NFC Firmware File. More specifically, the SE Service TA component reads the version number stored in the trusted execution environment of the smart terminal, that is, the SE FirmwareFile and NFC Firmware File files through the download management module 150. And compares the firmware version number of the functional device itself.

[0080] 4. By judging the version numbers of the two, the control strategy decides whether to start the upgrade. The control situations of the general control strategy include no upgrade, different version upgrade or higher version upgrade. If it is a different version upgrade or a higher version upgrade, the NFCHAL component accesses the SE Service TA component through the SE HAL component, and then accesses the SEFirmware File and NFC Firmware File files through the download management module 150 to start the upgrade process.

[0081] 5. The SEService (TA) component sends NFC firmware download initialization to the For NFC Download module in SE, and the For NFC Download module establishes a download channel with NFCC through the swp channel.

[0082] 6. The SEService (TA) component obtains the NFC Firmware File through the Download Module module and sends an upgrade instruction.

[0083] 7. SE receives the upgrade instruction through the For NFC Download module, and sends the upgrade instruction to NFCC through the download channel established with NFCC to complete the upgrade process.

[0084] 8. If the upgrade is successful, the SE ServiceTA component updates the SE Firmware File and NFC Firmware File files to the SE Restore File and NFC Restore File files respectively through the download management module 150.

[0085] 9. If the upgrade fails, the SE ServiceTA component obtains the SE RestoreFile and NFC Restore File files through the download management module 150 and starts the backup file upgrade. The Applet is a small application program written in the Java programming language.

[0086] The present application also provides a firmware upgrade device, which includes: a reading module, a judgment module and a starting module.

[0087] The reading module is used to read the hardware configuration of the functional device according to the startup instruction to form configuration information; the reading module is also used to read the firmware version number of the functional device, compare the firmware version number with the version number of the pre-stored firmware, and output the comparison result; the judgment module generates a control strategy based on the comparison result and the configuration information, and judges whether the firmware of the functional device needs to be upgraded based on the control strategy; after confirming that the firmware of the functional device needs to be upgraded, the startup module obtains the pre-stored firmware stored in the trusted execution environment and starts the firmware upgrade of the functional device.

[0088] In this embodiment, by storing pre-stored firmware in a trusted execution environment, when the firmware of a functional device needs to be upgraded, the pre-stored firmware is obtained from the trusted execution environment through a reading module, and the pre-stored firmware is retrieved from the outside of the functional device, thereby reducing the occupation of the hardware resources of the functional device itself. Moreover, since the pre-stored firmware is stored in a trusted execution environment, the security protection capability of the pre-stored firmware is improved. It can be seen that the technical solution of the present application can effectively reduce the occupation of hardware resources of peripheral devices, and can also improve the security of files and reduce the risk of being attacked.

[0089] The present application also provides a smart terminal, which includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the method described above is implemented. When the processor executes the computer program, the steps in each embodiment of the firmware upgrade method for each smart terminal described above are implemented, such as Figure 1 S10 to S40 shown.

[0090] Among them, the computer program can be divided into one or more modules, one or more modules are stored in the memory and executed by the processor to complete the present application. One or more modules can be a series of computer program instruction segments that can complete specific functions, and the instruction segments are used to describe the execution process of the computer program in the intelligent terminal. For example, the computer program can be divided into a reading module, a judgment module, and a startup module, and the specific functions of each module are as above.

[0091] The intelligent terminal may include, but is not limited to, a processor and a memory. Those skilled in the art will understand that the processor may be a central processing unit, or other general-purpose processors, digital signal processors, application-specific integrated circuits, off-the-shelf programmable gate arrays or other programmable logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc. The memory may be an internal storage unit of the intelligent terminal, such as a hard disk or memory of the intelligent terminal. The memory may also be an external storage device of the intelligent terminal, such as a plug-in hard disk, a smart memory card, a flash memory card, etc. equipped on the intelligent terminal. Furthermore, the memory may include both an internal storage unit and an external storage device of the intelligent terminal.

[0092] The present application also provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the method described above is implemented.

[0093] The specific embodiments and beneficial effects of the computer-readable storage medium in this application can be found in the above-mentioned firmware upgrade method, which will not be repeated here.

[0094] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or replace some or all of the technical features therein by equivalents. These modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present invention, and they should all be included in the scope of the claims and specification of the present invention.

Claims

1. A firmware upgrade method, characterized in that: The firmware upgrade method is applied to an intelligent terminal, the intelligent terminal includes a mainboard and a functional device connected to the mainboard, the mainboard forms a trusted execution environment, the trusted execution environment stores pre-stored firmware, and the firmware upgrade method includes: Reading the hardware configuration of the functional device according to the startup instruction to form configuration information; Reading the firmware version number of the functional device, comparing the firmware version number with the version number of the pre-stored firmware, and outputting the comparison result; generating a control strategy according to the comparison result and the configuration information, and judging whether the firmware of the functional device needs to be upgraded according to the control strategy; After confirming that the firmware of the functional device needs to be upgraded, the pre-stored firmware stored in the trusted execution environment is obtained, and the firmware upgrade of the functional device is started.

2. The firmware upgrade method according to claim 1, characterized in that: The trusted execution environment is provided with a storage area and a backup area; Before the step of inputting the start instruction, the method includes: The pre-stored firmware is stored in the storage area, and the pre-stored firmware is stored in the backup area.

3. The firmware upgrade method according to claim 2, characterized in that: After the step of starting the firmware upgrade of the functional device, the method further comprises: If the upgrade is successful, the pre-stored firmware in the storage area is updated to the backup area.

4. The firmware upgrade method according to claim 2, characterized in that: After the step of starting the firmware upgrade of the functional device, the method further includes: If the upgrade fails, the pre-stored firmware in the backup area is obtained, and the firmware upgrade of the functional device is restarted based on the pre-stored firmware in the backup area.

5. The firmware upgrade method according to claim 1, characterized in that: A rich execution environment is also formed in the main board, and a download control unit is provided in the rich execution environment. The download control unit is used to control the download processing of the firmware. A firmware management unit is provided in the trusted execution environment. The firmware management unit is used to manage the downloaded files and backup files of the firmware. The functional device is connected to the download control unit in the rich execution environment, the firmware management unit is connected to the storage area and the backup area, and the download control unit is communicatively connected to the firmware management unit.

6. The firmware upgrade method according to claim 1, characterized in that: A download management module is provided in the trusted execution environment, and the download management module is used to control the download processing of the firmware, manage the downloaded files and backup files of the firmware, and the download management module is respectively connected to the storage area and the backup area, and the download management module is communicatively connected to the functional device.

7. The firmware upgrade method according to claim 1, characterized in that: A rich execution environment is also formed in the main board, a download channel is established in the functional device, and the rich execution environment and the executable environment establish a communication connection with the download channel.

8. A firmware upgrade device, characterized in that: The firmware upgrade device comprises: A reading module, the reading module is used to read the hardware configuration of the functional device according to the startup instruction to form configuration information; the reading module is also used to read the firmware version number of the functional device, compare the firmware version number with the version number of the pre-stored firmware, and output the comparison result; A judgment module, wherein the judgment module generates a control strategy according to the comparison result and the configuration information, and judges whether the firmware of the functional device needs to be upgraded according to the control strategy; A startup module, after confirming that the firmware of the functional device needs to be upgraded, obtains the pre-stored firmware stored in the trusted execution environment and starts the firmware upgrade of the functional device.

9. An intelligent terminal, characterized in that: The intelligent terminal includes a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the method according to any one of claims 1 to 7 when executing the computer program.

10. A computer-readable storage medium storing a computer program, wherein the computer program, when executed by a processor, implements the method according to any one of claims 1 to 7.