Microcontroller chip

By designing a microcontroller chip containing multiple flash memory dies to realize the read and write function of MCU chips, the problems of low operating efficiency and poor OTA upgrade capabilities in the existing technology are solved, and the chip performance and OTA upgrade support capabilities are significantly improved.

CN120029648APending Publication Date: 2025-05-23GIGADEVICE SEMICON (BEIJING) INC

Patent Information

Application Number
CN202311568398.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-22
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

In the architecture of existing MCU chips, the FLASH die can only perform one of the operations of read, write and erase at the same time, resulting in a decrease in the operation efficiency of the MCU and poor support for OTA upgrade capabilities.

Method used

Design a microcontroller chip, which is stacked with two or more flash memory dies, converts bus operations into the timing of the bus interface through address mapping control, and realizes the read and write function of each flash memory die.

Benefits of technology

It significantly improves the working performance and operation efficiency of the MCU chip, improves the support capabilities and upgrade efficiency for OTA upgrades, and can roll back to the old version of firmware programs when the OTA upgrade fails, improving the security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120029648A_ABST
    Figure CN120029648A_ABST
Patent Text Reader

Abstract

The invention provides a microcontroller chip which is formed by stacking and sealing a microcontroller bare chip and two or more flash memory bare chips together, and when OTA upgrade and update of a firmware program are needed, the firmware program of an OTA upgrade version can be programmed into a second flash memory bare chip, and the firmware program of an old version is stored in a first flash memory bare chip. Therefore, the process of programming the firmware program of the OTA upgrade version to the second flash memory bare chip does not influence the operation on the first flash memory bare chip, so that the microcontroller chip can realize the function of writing while reading, and the influence of erasing and programming of the flash memory bare chips on the running efficiency of the firmware program is remarkably reduced; according to the technical scheme, the working performance and the operation efficiency of the MCU chip and the supporting capacity and the upgrading efficiency of OTA upgrading are improved, when it is detected that the firmware program of the OTA upgrading version stored in the second flash memory bare chip is invalid after power-on or system reset is conducted again, the firmware program of the corresponding old version can be executed, and the safety of the system is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of integrated circuits, and in particular to a microcontroller chip. Background Art

[0002] MCU (Microcontroller Unit) is a lightweight computing chip and the control core of many electronic devices. It has low power consumption and flexible programmable performance.

[0003] At present, the chip architecture of MCU generally uses the corresponding FLASH memory to store the code and the data generated during the use of MCU. Specifically, an MCU die and a FLASH die (usually nor FLASH) are stacked and packaged together through the system-in-package (SIP) technology. The MCU die directly runs (XIP, excuted in place) the firmware stored in the FLASH die and performs data exchange through bus interfaces such as SPI.

[0004] However, in the architecture of the MCU chip, its FLASH chip can usually only perform one of the operations of reading, writing or erasing at the same time. For example, when the MCU chip is erasing or programming the FLASH chip, the FLASH chip cannot be read at the same time. This greatly reduces the operating efficiency of the MCU on the one hand, and on the other hand, it does not support the OTA (over the air) upgrade capability of the MCU chip well, affecting the upgrade efficiency and upgrade cost of the MCU chip. Summary of the invention

[0005] The object of the present invention is to provide a microcontroller chip, which can improve the operating efficiency of the microcontroller chip and the support capability of OTA upgrade.

[0006] To achieve the above object, the present invention provides a microcontroller chip (i.e., the SIP MCU chip of the present invention), which includes:

[0007] A microcontroller die having at least two sets of bus interfaces;

[0008] At least two flash memory dies, each of which is connected to each group of the bus interfaces in a one-to-one correspondence, and at least two of the flash memory dies are used to store firmware programs;

[0009] The microcontroller die is used to convert the received bus operation into the timing of the bus interface through address mapping control, so as to access each of the flash memory die respectively, and program the OTA upgrade version of the firmware program into the second flash memory die. During the programming process, and after power-on or system reset and when it is detected that the OTA upgrade version of the firmware program in the second flash memory die is invalid, the old version of the firmware program stored in the first flash memory die is executed, and after power-on or system reset and when it is detected that the OTA upgrade version of the firmware program in the second flash memory die is valid, the OTA upgrade version of the firmware program is executed.

[0010] Compared with the existing SIP MCU chip, the microcontroller chip of the present invention is composed of a microcontroller (MCU) die and two or more flash memory (FLASH) dies stacked together, and when an OTA upgrade is required to update the firmware program, the OTA process can program the OTA upgraded version of the firmware program into the corresponding second flash memory die, while the old version of the firmware program is stored in the first flash memory die, so that the process of programming the OTA upgraded version of the firmware program does not affect the operation of the first flash memory die and other flash memory die, so that the microcontroller chip can realize the read while write (read while write, RWW) function, significantly reduce the erasure and programming of the FLASH die on the running efficiency of the firmware program, improve the working performance, running efficiency and OTA upgrade support and upgrade efficiency of the MCU chip, and after power-on or system reset and when it is detected that the OTA upgraded version of the firmware program is invalid, it can execute (i.e. roll back to) the old version of the firmware program stored in the first flash memory die, thereby improving the security of the system.

[0011] Optionally, in the microcontroller chip of the present invention, the versions of the old versions of the firmware program stored in the multiple first flash memory bare chips are different, and the microcontroller bare chip is also used to execute the corresponding version of the old version of the firmware program stored in the specified first flash memory bare chip according to the rollback instruction after the OTA upgrade fails. In this way, multiple versions of firmware program switching can be supported, such as retaining the factory firmware program, tracing back to the initial stable version or the specified version of the firmware program, etc., which is suitable for personalized OTA upgrade strategies, and can realize the functions of reading, writing, erasing, etc. on more flash memory bare chips at the same time, thereby improving the operating efficiency of the system.

[0012] Optionally, in the microcontroller chip of the present invention, the second flash die and the first flash die are used to store corresponding versions of firmware programs, and the remaining flash die are used to store data. Thus, the program code to be run and the data to be accessed are stored separately, further improving the operating efficiency of the system.

[0013] Optionally, the microcontroller die has a memory control module, and the memory control module includes:

[0014] An address mapping circuit is used to map different bus logical addresses of the microcontroller die to different physical addresses of the flash memory die to form a logical address mapping relationship;

[0015] An interface control circuit, used to convert received bus operations into a timing sequence of a bus interface;

[0016] The exchange control circuit is used to control the address mapping circuit to realize the mutual exchange of the logical address mapping relationship of the space storing at least the firmware program of the two second flash memory bare chips and the first flash memory bare chip when the OTA upgrade version of the firmware program in the second flash memory bare chip is valid.

[0017] Therefore, the address mapping and exchange between the microcontroller die and the second flash memory die, the first flash memory die, and the access to the firmware program and related data are realized through hardware modules and logic circuits, with low cost.

[0018] Optionally, the exchange control circuit includes an exchange flag. After the OTA upgrade version of the firmware program is programmed into the second flash die for storage, and after power-on or system reset, the memory control module is also used to perform a self-check on the OTA upgrade version of the firmware program stored in the second flash die. If the self-check passes, the OTA upgrade version of the firmware program is marked as valid, so that the exchange flag is effective, and then the exchange control circuit controls the address mapping circuit to exchange the logical address mapping relationship between the second flash die and the first flash die; if the self-check fails, the stored OTA upgrade version of the firmware program is marked as invalid, so that the exchange flag is invalid, and then the address mapping circuit maintains the original logical address mapping relationship. Therefore, after power-on reset or system reset, the exchange flag can be used to quickly confirm whether the logical address mapping relationship can be exchanged and the OTA upgrade version of the firmware program can be executed. When the OTA upgrade version of the firmware program is invalid, the system can return to the default logical address mapping relationship state in time and execute the old version of the firmware program, thereby improving the security of the system.

[0019] Optionally, in the microcontroller chip of the present invention, both the second flash memory die and the first flash memory die have a code area for storing corresponding firmware programs. After power-on or system reset and when the OTA upgrade version of the firmware program is detected to be valid, the exchange control circuit only exchanges the logical address mapping relationship of the code area of ​​the first flash memory die with the logical address mapping relationship of the code area of ​​the second flash memory die. Therefore, when the OTA upgrade and firmware program are executed, they can be executed only within the logical address range corresponding to the code area of ​​the corresponding flash memory die. The read access speed of this area is not delayed, so that the system can run the firmware program at full speed, further improving the system operation efficiency.

[0020] Optionally, in the microcontroller chip of the present invention, the second flash die and the first flash die both have a code area for storing corresponding firmware programs, and after power-on or system reset and when the OTA upgrade version of the firmware program is detected to be valid, the exchange control circuit only exchanges the logical address mapping relationship of the entire area of ​​the first flash die with the logical address mapping relationship of the entire area of ​​the second flash die. Thus, all logical addresses of the second flash die and the first flash die are swapped by the exchange control circuit, so that the OTA upgrade version of the firmware program in the second flash die can be read out and executed.

[0021] Optionally, the memory control module further includes a first cache area, the capacity of which is equal to the capacity of each of the code areas. After power-on or system reset, when the OTA upgrade version of the firmware program in the second flash memory die is detected to be invalid, the first cache area copies the content in the code area of ​​the first flash memory die. After power-on or system reset, when the OTA upgrade version of the firmware program in the second flash memory die is detected to be valid, the first cache area copies and stores the content in the code area of ​​the second flash memory die. Thus, when the microcontroller chip needs to execute the corresponding firmware program, the firmware program in the code area of ​​the second flash memory die or the first flash memory die can be copied to the first cache area, so that the microcontroller die can run the current firmware program in the first cache area inside it, thereby allowing the programming of the OTA upgrade version of the firmware program and the read, write and erase operations in the first flash memory die and other flash memory die to be performed simultaneously, thereby improving the system operation efficiency.

[0022] Optionally, the memory control module also includes a first cache area, the capacity of the first cache area is greater than the capacity of each of the code areas, and after power-on or system reset and when it is detected that the OTA upgrade version of the firmware program in the second flash memory die is invalid, the first cache area copies the content in the code area of ​​the first flash memory die, and also copies the content in the second flash memory die or the first flash memory die within a specified logical address range outside the logical address range of the code area copied by the first cache area; after power-on or system reset and when it is detected that the OTA upgrade version of the firmware program is valid, the first cache area copies the content in the code area of ​​a flash memory die storing the OTA upgrade version of the firmware program, and also copies the content in the second flash memory die or the first flash memory die within a specified logical address range outside the logical address range of the code area copied by the first cache area. Therefore, when the microcontroller chip needs to execute the corresponding firmware program, the firmware program in the code area of ​​the second flash memory die or the first flash memory die and the specified (i.e., required) content in the second flash memory die or the first flash memory die other than the content in the code area can be copied to the first cache area, so that the microcontroller chip can run the current firmware program in the first cache area inside it and directly read the specified data, thereby maximizing the system operation efficiency.

[0023] Optionally, the microcontroller chip further comprises a second cache area, and except for the content copied in the first cache area, the remaining content stored in the second flash die and the first flash die is accessed by the second cache area after copying on demand or by the timing of the bus interface generated by the interface control circuit; and / or, the second cache area (cache) is composed of a static random access memory, and when a logical address miss occurs in the second cache area, the memory control module copies the corresponding content from the second flash die or the first flash die to the second cache area. In this way, some content that does not require high reading speed can be stored in the storage area of ​​the second flash die or the first flash die that will exceed the logical range corresponding to the code area storing the currently executed firmware program (the access speed of these storage areas has a certain delay), and the memory control module of the microcontroller die is allowed to access the second cache area after copying on demand or directly convert the bus operation into the bus interface timing as needed to read these contents, thereby enabling the microcontroller chip of the present invention to have a wider application range.

[0024] Optionally, the first buffer is composed of a static random access memory or a combination of multiple static random access memories, thereby making the first buffer easy to implement.

[0025] Optionally, after the OTA upgraded version of the firmware program is programmed into the second flash memory die for storage, and after power is restarted or the system is reset, the first cache area first copies the content in the code area of ​​the second flash memory die, and the memory control module performs a self-check on the content copied from the first cache area. If the self-check passes, it indicates that the OTA upgraded version of the firmware program in the second flash memory die is detected to be valid, and the memory control module directly accesses the first cache area to run the OTA upgraded version of the firmware program. If the self-check fails, it indicates that the OTA upgraded version of the firmware program in the second flash memory die is detected to be invalid, and the first cache area re-copies the content in the code area of ​​the first flash memory die, and performs a self-check on the content copied from the first cache area again. When the self-check passes again, it indicates that the old version of the firmware program in the first flash memory die is detected to be valid, and the memory control module directly accesses the first cache area to run the old version of the firmware program. Therefore, after the OTA upgraded version of the firmware program is programmed into the second flash memory die for storage, and after power is restarted or the system is reset, the OTA upgraded version of the firmware program is first checked, and only after the OTA upgraded version of the firmware program fails the check, the old version of the firmware program is checked, thereby being able to run the valid version of the firmware program as quickly as possible through the first cache area.

[0026] Optionally, the memory control module further includes a second cache area, and when the OTA upgrade version of the firmware program in the second flash die is detected to be invalid after power-on or system reset, the second cache area copies the content in the code area of ​​the first flash die, and when the OTA upgrade version of the firmware program in the second flash die is detected to be valid after power-on or system reset, the second cache area copies the content in the code area of ​​the second flash die. The layout of the first cache area (static random access memory, etc.) can be omitted in the microcontroller die, and the area cost of the MCU chip will be reduced.

[0027] Optionally, except for the content copied by the second cache area, the remaining content stored in the second flash memory die and the first flash memory die is accessed by the second cache area after being copied on demand or by the timing of the bus interface generated by the interface control circuit. In this way, some content that does not require high reading speed can be stored in the storage area of ​​these flash memory die that will exceed the logical range corresponding to the code area storing the currently executed firmware program (the access speed of these storage areas has a certain delay), and the memory control module of the microcontroller die is allowed to directly read these contents through the second cache area or directly convert the bus operation into the bus interface timing, thereby enabling the microcontroller chip of the present invention to have a wider range of applications.

[0028] Optionally, the bus interface is an SPI interface, enabling compatibility with the processes of existing SIP MCU chips.

[0029] Optionally, the microcontroller die further has a code error flag bit, which is set when the microcontroller die determines that the firmware programs stored in all the flash dies are invalid, so as to terminate the execution of the firmware program, thereby preventing the microcontroller chip from falling into an infinite loop. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] Those of ordinary skill in the art will understand that the provided drawings are used to better understand the present invention and do not limit the scope of the present invention in any way. Among them:

[0031] Figure 1 is a schematic structural diagram of an existing SIP MCU chip.

[0032] Figure 2 is a schematic structural diagram of another existing SIP MCU chip.

[0033] Figure 3 is a schematic structural diagram of the microcontroller chip (i.e., SIP MCU chip) according to the first embodiment of the present invention.

[0034] Figure 4 is a schematic diagram before and after the exchange of the logical address mapping relationship in the microcontroller chip according to the first embodiment of the present invention.

[0035] Figure 5 is a schematic diagram of the change in the logical address mapping relationship during the OTA upgrade process of the microcontroller chip according to the first embodiment of the present invention.

[0036] Fig. 6A and Figure 6B are schematic diagrams before and after the exchange of the structure and logical address mapping relationship of the microcontroller chip (i.e., SIP MCU chip) according to the second embodiment of the present invention.

[0037] Figure 7 is a schematic flowchart of the OTA upgrade process of the microcontroller chip according to the second embodiment of the present invention.

[0038] Fig. 8A and Figure 8B are schematic diagrams before and after the exchange of the structure and logical address mapping relationship of the microcontroller chip (i.e., SIP MCU chip) according to the third embodiment of the present invention.

[0039] Fig.9A and Fig. 9B are schematic diagrams before and after the exchange of the structure and logical address mapping relationship of the microcontroller chip (i.e., SIP MCU chip) according to the second embodiment of the present invention.

[0040] Fig. 10A and Fig. 10B These are two exemplary schematic diagrams of the exchange of the logical address mapping relationship of the microcontroller chip (ie, the SIP MCU chip) according to the fifth embodiment of the present invention.

[0041] Fig.11 These are two exemplary schematic diagrams of the exchange of the logical address mapping relationship of the microcontroller chip (ie, the SIP MCU chip) according to the sixth embodiment of the present invention. DETAILED DESCRIPTION

[0042] In the following description, a large number of specific details are given in order to provide a more thorough understanding of the present invention. However, it is obvious to those skilled in the art that the present invention can be implemented without one or more of these details. In other examples, in order to avoid confusion with the present invention, some technical features known in the art are not described. It should be understood that the present invention can be implemented in different forms and should not be interpreted as being limited to the embodiments proposed here. On the contrary, providing these embodiments will make the disclosure thorough and complete, and the scope of the present invention will be fully conveyed to those skilled in the art. The same reference numerals represent the same elements from beginning to end. It should be understood that when an element is referred to as "connected to", "coupled" other elements, it can be directly connected to other elements, or there can be intervening elements. On the contrary, when an element is referred to as "directly connected to" other elements, there is no intervening element. When used here, the singular forms of "one", "an" and "said / the" are also intended to include plural forms, unless the context clearly indicates another way. It should also be understood that the term "comprising" is used to identify the presence of features, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, steps, operations, elements, components and / or groups. When used herein, the term "and / or" includes any and all combinations of the relevant listed items.

[0043] The architecture of an existing SIP MCU chip 100 is generally as follows: Figure 1As shown, it stacks and packages an MCU die 101 and a FLASH die 102 (FLASH die, usually nor flash), and the FLASH die 102 stores the firmware required for the operation of the SIP MCU chip 100. The MCU die 101 and the FLASH die 102 are usually connected through a bus interface such as SPI to exchange data, and the MCU die 101 can directly run (XIP, executed in place) the program stored in the FLASH die 102 through the bus interface. The FMC (flash memory controller) module 101a in the MCU die 101 usually logically divides the capacity of the FLASH die 102 into multiple areas to meet the use requirements of software programs, etc. The FMC module 101a is responsible for the mutual mapping, partitioning, permission control, and conversion of read and write instructions of the bus address of the MCU die 101 and the storage address of the FLASH die 102.

[0044] In the above-mentioned SIP MCU chip 100, usually its FLASH die 102 can only perform one of the operations of reading, writing and erasing at the same time. For example, when the MCU die 101 erases or programs certain address spaces of the FLASH die 102, the MCU die 101 cannot read the FLASH die 102 at the same time. At this time, the bus in the MCU die 101 will be temporarily suspended until the FLASH die 102 can respond to the read instruction and return valid data, which greatly reduces the operating efficiency of the MCU. Moreover, since the FLASH die 102 itself cannot read and erase / program at the same time, the architecture of the SIP MCU chip 100 does not support OTA (over the air) upgrade technology well, affecting the upgrade efficiency and upgrade cost of the MCU.

[0045] In addition, in the current consumer electronics field or automotive field and other application scenarios, after the product is sold online to the user, OTA (over the air) technology is usually used to upgrade the firmware program of the product's MCU chip (i.e. update the firmware program), especially in the automotive field, manufacturers can download the upgraded firmware program to the chip of the corresponding electronic device in the car through the wireless network to solve various problems, thereby avoiding expensive recall expenses. This requires the SIP MCU chip to have more complete OTA support capabilities.

[0046] Among them, an important requirement for OTA upgrade of MCU chip is: in order to prevent the upgrade process from being interrupted or errors from occurring, which may lead to upgrade failure, when writing the upgraded firmware program (firmware, i.e. new firmware program, new program code) to FLASH bare chip 102, it is necessary not to affect the firmware program already running on FLASH bare chip 102, and if the upgrade fails, it is necessary to be able to roll back to the old version of the firmware program so that the MCU bare chip 101 can continue to execute the existing firmware program, thereby avoiding affecting the use of the product. However, in the case of Figure 1 In the architecture of the existing SIP MCU chip shown, since the MCU die 101 has only one bus interface (unmarked) connected to the FLASH die 102, when the upgraded firmware program is written to the FLASH die 102, it will inevitably occupy the channel of the bus interface, thereby making it impossible to read the running firmware program from the FLASH die 102, and the FLASH die 102 itself cannot be read and erased / programmed at the same time. Therefore, this architecture inherently does not support the OTA upgrade capability of the MCU chip well.

[0047] Currently, an existing solution is Figure 2 As shown, a code cache 1011 of sufficient capacity is placed in the FMC module 101a of the MCU die 101, and the cache 1011 corresponds to the corresponding storage area in the FLASH die 102 (defined as the code area 102a), and the remaining space of the FLASH die 102 (defined as the data area 102b) is directly accessed by the MCU die 101 through the XIP method or through the data cache 1012 mechanism built into the MCU die 101. After power-on reset, the firmware program in the code area 102a of the FLASH die 102 is copied to the code cache 1011, so that the MCU die 101 can run the current firmware program in the code cache 1011. When the upgraded firmware program is programmed into the code area 102a of the FLASH die 102, the MCU die 101 can still read instructions from the code cache 1011 to continue running the already running firmware program. However, the code cache area 1011 in the MCU die 101 is generally composed of static random access memory SRAM, and the unit area cost of static random access memory SRAM is greater than that of FLASH memory. Therefore, this solution will significantly increase the overall area of ​​the MCU chip due to the large area of ​​the MCU die 101, thereby increasing the cost of the MCU chip product. Figure 2In the architecture shown, the MCU die 101 still has only one bus interface (unmarked) connected to the FLASH die 102, so the programming of the new firmware program and the operation of the data area 102b in the FLASH die 102 still cannot be performed at the same time. For example, when the MCU die 101 reads the data area 102b, the code area 102a of the FLASH die 102 cannot be programmed.

[0048] In order to solve the above problems, the present invention proposes a new SIP MCU chip architecture, which is composed of a microcontroller (MCU) die and two or more flash memory (FLASH) dies stacked together, and each flash memory die is connected to the microcontroller die through a set of bus interfaces (such as SPI interfaces, etc.) connected one by one. Among these flash memory dies, the second flash memory die is used to store the OTA upgraded version of the firmware program, and a first flash memory die is used to store the old version of the firmware program or more first flash memory dies are used to store different old versions of the firmware program, thereby realizing mutual backup of the firmware program between the flash memory dies. When an OTA upgrade is required to update the firmware program, the OTA process can program the OTA upgraded version of the firmware program into the second flash memory die. During the programming process, any operation of the first flash memory die and the remaining flash memory die will not be affected, and different operations between different FLASH die can be performed simultaneously, that is, the read while write (RWW) function of the MCU chip is realized, which significantly reduces the impact of erasing and programming of the FLASH die on the operating efficiency of the firmware program, improves the chip's working performance, system operating efficiency and support for OTA upgrades, and when the OTA upgrade fails, it can enable the system to roll back and execute the old version of the firmware program, thereby improving the security of the system.

[0049] The technical solution proposed by the present invention is further described in detail below in conjunction with the accompanying drawings and specific embodiments. The advantages and features of the present invention will become clearer according to the following description. It should be noted that the accompanying drawings are all in a very simplified form and are not in precise proportions, and are only used to conveniently and clearly assist in explaining the technical solution of the embodiments of the present invention.

[0050] First embodiment

[0051] Please refer to Figure 3 This embodiment provides a microcontroller chip (i.e., the SIP MCU chip of the present invention) 200, which includes a microcontroller die (MCU die) 201, a first flash die (FLASH die) FLASH A, and a second flash die FLASH B encapsulated in the same package, that is, the microcontroller chip 200 is composed of a microcontroller die 201 and two FLASH dies FLASH A and FLASH B stacked together.

[0052] The microcontroller die 201 has two sets of bus interfaces 202a and 202b, the first flash die FLASH A is connected to the microcontroller die 201 through the bus interface 202a, and the second flash die FLASH B is connected to the microcontroller die 201 through the bus interface 202b. The first flash die FLASH A is used to store the old version of the firmware program (i.e., the old code or instruction), and the second flash die FLASH B is used to store the OTA upgraded version of the firmware program (i.e., the OTA upgraded code or instruction). When the first flash die FLASH A and the second flash die FLASH B have stored the corresponding version of the firmware program, the firmware programs in the first flash die FLASH A and the second flash die FLASH B can back up each other.

[0053] In this embodiment, the microcontroller die 201 is used to convert the received bus operation into the timing of the bus interfaces 202a and 202b through address mapping control, so as to access the first flash die FLASH A and the second flash die FLASH B respectively. When an OTA upgrade is required to update the firmware program in the microcontroller chip 200, the OTA process can program the OTA upgraded version of the firmware program into the second flash die FLASH B through the bus interface 202b, and during the programming process, any operation of the microcontroller die 201 on the first flash die FLASH A through the bus interface 202a will not be affected. That is, the programming operation of the OTA upgraded version of the firmware program in the microcontroller chip 200 and the reading, writing and erasing of other data can be performed simultaneously, thereby improving the system operation efficiency and the support capability of the microcontroller chip 200 for OTA upgrades.

[0054] As an example, the bus interfaces 202a and 202b are SPI bus interfaces (eg Figure 3 SPI IF in ).

[0055] In this embodiment, please refer to Figure 3 The microcontroller die 201 has a memory control module FMC (Flash Memory Controller), the first flash die FLASH A is connected to the memory control module FMC through a bus interface 202a, and the second flash die FLASH B is connected to the memory control module FMC through a bus interface 202b. Preferably, the memory control module FMC implements address mapping and exchange between the microcontroller die 201 and the first flash die FLASH A and the second flash die FLASH B, as well as access to firmware programs and related data, etc. through corresponding hardware modules and logic circuits, with low cost.

[0056] As an example, the memory control module FMC is provided with hardware logic circuits such as an address mapping circuit 2011, an interface control circuit 2012, and a swap control circuit 2014. The address mapping circuit 2011 is used to map different bus logical addresses of the microcontroller die 201 to the physical addresses of the first flash memory die FLASH A and the second flash memory die FLASH B, respectively, to form a logical address mapping relationship. For example, in the default state, please refer to Figure 4 In (a), the address mapping circuit 2011 maps the bus logical address range A of the microcontroller die 201 to the physical address of the first flash memory die FLASH A, and maps the bus logical address range B following the bus logical address range A to the physical address of the second flash memory die FLASH B, thereby forming a logical address mapping relationship.

[0057] The interface control circuit 2012 is used to convert the received bus operation into the timing of the bus interface, so as to enable the microcontroller die 201 to access the first flash memory die FLASH A and the second flash memory die FLASH B.

[0058] The exchange control circuit 2013 is used to control the address mapping circuit 2011 to realize the mutual exchange of the logical address mapping relationship between the first flash memory die FLASH A and the second flash memory die FLASH B when the OTA upgrade version of the firmware program has been programmed into the second flash memory die FLASH B and the OTA upgrade version of the firmware program stored in the second flash memory die FLASH B is detected to be valid after power-on reset (POR) or system reset. For example, in the default state, please refer to Figure 4 In (a), the address mapping circuit 2011 maps the bus logical address range A of the microcontroller die 201 to the physical address of the first flash memory die FLASH A, and maps the bus logical address range B following the bus logical address range A to the physical address of the second flash memory die FLASH B, to form a logical address mapping relationship; after the exchange, the address mapping circuit 2011 maps the bus logical address range A of the microcontroller die 201 to the physical address of the second flash memory die FLASH B, and maps the bus logical address range B following the bus logical address range A to the physical address of the first flash memory die FLASH A, to form a logical address mapping relationship after the exchange. Therefore, no matter before or after the power-on reset or system reset, the microcontroller die 201 always starts to fetch instructions from the bus logical address range A to execute the corresponding version of the firmware program (instructions can be read from the 0 logical address or a lower logical address). Figure 4 In the default state shown in (a) of FIG. 1 , the microcontroller die 201 fetches instructions from the logical address range A to execute the old version of the firmware program stored in the first flash die FLASH A. Figure 4 In the post-swap state (ie, swap mode) shown in (b) of FIG. 1 , the microcontroller die 201 fetches instructions from the logic address range A to execute the OTA upgrade version of the firmware program stored in the second flash memory die FLASH B.

[0059] It should be understood that due to different functional requirements in different scenarios, the logical address range exchanged by the exchange control circuit 2013 may be all or part of the storage space of the first flash memory die FLASH A and the second flash memory die FLASH B.

[0060] In this embodiment, when an error occurs during programming the OTA upgrade version of the firmware program into the second flash memory die FLASH B, or the programming is interrupted, or the firmware program written into the OTA upgrade version is damaged, or when the OTA upgrade version of the firmware program programmed into the second flash memory die FLASH B itself is found to have a problem, after the OTA upgrade version of the firmware program is programmed into the second flash memory die FLASH B, and after power is turned on again or the system is reset, the microcontroller chip 200 will detect that the OTA upgrade version of the firmware program stored in the second flash memory die FLASH B is invalid, which means that the OTA upgrade has failed. In this case, the exchange control circuit 2013 will maintain the bus logical address mapping relationship in the above-mentioned default state, that is, the control address mapping circuit 211 still maps the bus logical address range A of the microcontroller die 201 to the physical address of the first flash memory die FLASH A, and still maps the bus logical address range B following the bus logical address range A to the second flash memory die FLASH B, so that after power-on or system reset, the microcontroller die 201 fetches instructions from the logical address range A and still executes the old version of the firmware program stored in the first flash memory die FLASH A, instead of executing the OTA upgraded version of the firmware program stored in the second flash memory die FLASH B, thereby avoiding security problems in product operation.

[0061] In addition, in some cases, when the operator of the OTA upgrade receives user feedback or proactively discovers that there is a problem with the OTA upgrade version of the firmware program that it has previously sent to the user, it will also promptly issue an instruction to roll back to the old version of the firmware program. At this time, after the microcontroller chip 200 receives the instruction, the switching control circuit 2013 will also return to the bus logical address mapping relationship in the above-mentioned default state, that is, the control address mapping circuit 2011 still maps the bus logical address range A of the microcontroller die 201 to the physical address of the first flash memory die FLASH A, and still maps the bus logical address range B of the subsequent bus logical address range A to the physical address of the second flash memory die FLASH B. Therefore, after power-on or system reset, the microcontroller die 201 takes instructions from the logical address range A and still executes the old version of the firmware program stored in the first flash memory die FLASH A, instead of executing the OTA upgrade version of the firmware program stored in the second flash memory die FLASH B, thereby avoiding security problems in product operation.

[0062] Optionally, the swap control circuit 2013 includes a non-volatile swap flag (swap bit, not shown). In the default state (i.e., default mode), the bus logical address range A is mapped to the physical address of the first flash memory die FLASH A, and the bus logical address range B is mapped to the physical address of the second flash memory die FLASH B. After power-on or system reset, if the OTA upgrade version of the firmware program stored in the second flash chip FLASH B passes the verification, the exchange flag is configured to be valid (for example, set to "0") to indicate that the OTA upgrade version of the firmware program stored in the second flash chip FLASH B is valid, thereby causing the system to enter the exchange state (i.e., exchange mode) to map the bus logical address range A to the physical address of the second flash chip FLASH B, and map the bus logical address range B to the physical address of the first flash chip FLASH A, thereby realizing the mutual exchange of the logical address mapping relationship; if the OTA upgrade version of the firmware program stored in the second flash chip FLASH B fails the verification, there is no need to configure the exchange flag (for example, make the exchange flag floating) or configure the exchange flag to be invalid (for example, set it to "1") to indicate that the OTA upgrade version of the firmware program stored in the second flash chip FLASH B is invalid, thereby maintaining the mapping of the bus logical address range A to the physical address of the first flash chip FLASH A, and the mapping of the bus logical address range B to the physical address of the second flash chip FLASH B. Therefore, after power-on or system reset, the swap flag can be used to quickly confirm whether the logical address mapping relationship can be exchanged and the OTA upgraded version of the firmware program can be executed. When the OTA upgraded version of the firmware program is invalid, the system can return to the default logical address mapping relationship state in time and execute the old version of the firmware program, thereby improving the security of the system.

[0063] The OTA upgrade process of the microcontroller chip 200 of this embodiment includes:

[0064] First, please refer to Figure 5 In (a), the physical address of the first flash memory die FLASH A corresponds to the bus logical address range A, the physical address of the second flash memory die FLASH B corresponds to the bus logical address range B, the bus logical address range A is in the low address range, and the starting address of the bus logical address range B is connected to the ending address of the bus logical address range A. In the default state, the microcontroller die 201 will start fetching instructions from the starting address (e.g., address 0) of the bus logical address range A to execute the old version of the firmware program stored in the first flash memory die FLASH A (i.e., code1 is effective), and at this time, the OTA upgraded version of the firmware program has not been written into the second flash memory die FLASH B (i.e., no code2).

[0065] Next, please refer to Figure 5 In (b) of Figure 5 , the microcontroller die 201 writes the firmware program (i.e., code2) of the OTA upgrade version sent by the OTA upgrade server (or the operator of the OTA upgrade) into the corresponding physical address space of the second flash die FLASH B through the mapping relationship of the bus logical address range B, thereby realizing the programming of the second flash die FLASH B. And at this time, the programming of the firmware program (i.e., code2) of the OTA upgrade version in the second flash die FLASH B can run completely in the background and will not have any impact on the old version of the firmware program (i.e., the effective code1) executed in the first flash die FLASH A.

[0066] Then, after power-on or system reset, the microcontroller chip 200 performs a certain verification (or self-check) on the firmware program (i.e., code2) of the OTA upgrade version written into the second flash die FLASH B. If the verification passes, please refer to Figure 5 In (c) of Figure 5 , the configuration swap flag bit is set to be valid to indicate that the firmware program of the OTA upgrade version stored in the second flash die FLASH B is valid (i.e., code2 takes effect), and then the logical address mapping relationship between the second flash die FLASH B and the first flash die FLASH A is swapped, that is, the bus logical address range A of the microcontroller die 201 is mapped to the physical address of the second flash die FLASH B, and the bus logical address range B of the microcontroller die 201 is mapped to the physical address of the first flash die FLASH A to execute the firmware program of the OTA upgrade version. If the process of programming the firmware program of the OTA upgrade version to the second flash die FLASH B is interrupted or damaged, or the OTA operator actively discovers that there is a problem with the firmware program of the OTA upgrade version, etc., resulting in the verification not passing after power-on or system reset, please refer to Figure 5 In (d) of Figure 5 , the swap flag bit in the memory control module FMC of the microcontroller die 201 is not valid to indicate that the firmware program of the OTA upgrade version stored in the second flash die FLASH B is invalid or damaged (i.e., code2 is damaged), and the OTA upgrade fails, and the firmware program rolls back to the old version of the firmware program stored in the first flash die FLASH A (i.e., code1 takes effect) to resume the execution of the firmware program in the first flash die FLASH A, thereby enhancing the security of the system.

[0067] In summary, compared with the existing SIP MCU chip, the microcontroller chip of this embodiment is composed of an MCU die and a first flash die FLASH A and a second flash die FLASH B stacked together, and when an OTA upgrade is required to update the firmware program, the OTA process can program the OTA upgraded version of the firmware program into the second flash die FLASH B, while the old version of the firmware program is stored in the first flash die FLASH A, so that the process of programming the OTA upgraded version of the firmware program into the second flash die FLASH B does not affect the operation of the first flash die FLASH A, so that the microcontroller chip can realize the read while write function (read while write, RWW), significantly reducing the impact of erasing and programming of any flash die in the second flash die FLASH B and the first flash die FLASH A on the running efficiency of the firmware program in the other flash die, improving the working performance, running efficiency, support capability and upgrade efficiency of the MCU chip for OTA upgrades, and after power-on or system reset and when the OTA upgraded version of the firmware program in the second flash die FLASH B is invalid, it can be executed (i.e., rolled back to) the first flash die FLASH The old version of the firmware program stored in A improves the security of the system.

[0068] Second embodiment

[0069] Please refer to Fig. 6A and Figure 6B This embodiment provides a microcontroller chip (i.e., the SIP MCU chip of the present invention) 200, which includes a microcontroller die (MCU die) 201, a first flash die (FLASH die) FLASH A, and a second flash die FLASH B encapsulated in the same package, that is, the microcontroller chip 200 is composed of a microcontroller die 201 and two FLASH die FLASH A and FLASH B stacked together.

[0070] The microcontroller die 201 has a memory control module FMC and two sets of bus interfaces 202a and 202b. The first flash die FLASH A is connected to the memory control module FMC through the bus interface 202a, and the second flash die FLASH B is connected to the memory control module FMC through the bus interface 202b. The first flash die FLASH A is used to store the old version of the firmware program (i.e., the old code or instruction), and the second flash die FLASH B is used to store the OTA upgraded version of the firmware program (i.e., the OTA upgraded code or instruction). When the corresponding versions of the firmware program are stored in the first flash die FLASH A and the second flash die FLASH B, the firmware programs in the first flash die FLASH A and the second flash die FLASH B can back up each other. The memory control module FMC converts the received bus operations into the timing of the bus interfaces 202a and 202b through address mapping control, so as to access the first flash memory die FLASH A and the second flash memory die FLASH B respectively. When OTA upgrade is required to update the firmware program in the microcontroller chip 200, the OTA process can program the OTA upgraded version of the firmware program into the second flash memory die FLASH B through the bus interface 202b, and during the programming process, any operation of the memory control module FMC on the first flash memory die FLASH A through the bus interface 202a will not be affected.

[0071] Compared with the microcontroller chip 200 of the first embodiment, the memory control module FMC of the microcontroller chip 200 of this embodiment further has a first cache area buffer and a second cache area cache, the first flash memory die FLASH A has a code area (i.e., the code area of ​​FLASH A) 203a for storing the old version of the firmware program code1 and other areas 203b except the code area 203a (other areas 203b may also be referred to as the data area of ​​the first flash memory die FLASH A), the second flash memory die FLASH B has a code area (i.e., the code area of ​​FLASH B) 204a for storing the OTA upgraded version of the firmware program code2 and other areas 204b except the code area 204a (other areas 204b may also be referred to as the data area of ​​the second flash memory die FLASH B). Among them, the capacity of the first buffer area buffer, the capacity of the code area 203a and the capacity of the code area 204a are all equal. In the default state, the content in the code area 203a is copied 1:1 to the first buffer area buffer, and the content in the other area 203b of the first flash memory die FLASHA and the code area 204a and the other area 204b of the second flash memory die FLASH B are accessed by the second buffer area cache of the memory control module FMC after being copied as needed, or the interface control circuit directly converts the bus operation into the bus interface timing as needed to access; in the exchange state (that is, the OTA upgraded version of the firmware program code2 has been programmed into the code area 204a of the second flash memory die FLASH B, and the second flash memory die FLASH B is detected after power-on or system reset B), the memory control module FMC only swaps the bus logical address mapping relationship between the code area 203a and the code area 204a relative to the default state, and the bus logical address mapping relationship between the other areas 203b and 204b remains the same, and the content in the code area 204a is copied 1:1 to the first buffer area buffer, and the content in the code area 203a and other areas 203b of the first flash memory bare chip FLASH A and the other areas 204b of the second flash memory bare chip FLASH B are accessed by the second buffer area cache of the memory control module FMC after being copied as needed, or by the interface control circuit directly converting the bus operation into the bus interface timing as needed for access.

[0072] Optionally, the second cache area cache is composed of a static random access memory, and when a logical address miss occurs in the second cache area cache, the memory control module FMC copies corresponding content from the second flash memory die FLASH B or the first flash memory die FLASH A to the second cache area cache.

[0073] Compared with the first embodiment, the technical solution of this embodiment comprehensively considers the balance of performance, cost, flash capacity and other aspects of the microcontroller chip. Moreover, whether in the default state or in the exchange mode after power-on or system reset, the content of the code area corresponding to the specified bus logical address range is copied to the first cache buffer. The microcontroller bare chip directly reads the content of the first cache buffer to achieve the effect of always executing the read firmware program within its specified bus logical address range, thereby achieving a read access speed without delay to the specified bus logical address range during OTA upgrade, so that the firmware program can run at full speed. The content at the logical address beyond the specified bus logical address range can be accessed by copying it on demand through the second cache area cache or by directly converting the bus operation into the bus interface timing for reading and access by the interface control circuit on demand. Since the logical address of the data copied in the second cache area cache is not fixed, a logical address miss may occur; when a miss occurs, the memory control module FMC needs to copy the corresponding content from the second flash die FLASH B or the first flash die FLASH A to the second cache area cache in order to respond to the read request of the MCU, so the read access speed will have a certain delay, which can realize the storage of some content (such as data, etc.) that does not require high reading speed, thereby increasing the scope of application of the microcontroller chip of this embodiment. In addition, copying the firmware program in the code area of ​​the corresponding flash die to the first cache area can enable the microcontroller die to run the current firmware program in the first cache area inside it, thereby enabling the operation of programming the OTA upgrade version of the firmware program into the second flash die and the read, write and erase operation in the first flash die to be performed simultaneously, thereby improving the system operation efficiency.

[0074] Please refer to Fig. 6A and Figure 6B , the following takes the example that the first flash memory die FLASH A and the second flash memory die FLASH B are of the same model and have a capacity of 8MB, the capacity of the code area 203a and 204a are both 2MB, the capacity of the first buffer area buffer is also 2MB, the code area 203a of the first flash memory die FLASH A is the first 2MB physical address space of the first flash memory die FLASH A, and the code area 204a of the second flash memory die FLASH B is the last 2MB physical address space of the second flash memory die FLASH B, to explain the technical solution of this embodiment in detail. Optionally, the first buffer area buffer is composed of a static random access memory with a capacity of 2MB.

[0075] Please refer to Fig. 6AIn the default state, after the microcontroller chip 200 is powered on, the code area 203a of the first flash memory die FLASH A (i.e., the first 2MB space of the flash memory die FLASHA) corresponds to the bus logic address range of 0MB to 2MB of the microcontroller die 201, the other area 203b of the first flash memory die FLASH A corresponds to the bus logic address range of 2MB to 8MB of the microcontroller die 201, the code area 204a of the second flash memory die FLASH B (i.e., the first 2MB space of the flash memory die FLASHA) corresponds to the bus logic address range of 14MB to 16MB of the microcontroller die 201, and the other area 204b of the second flash memory die FLASH B corresponds to the bus logic address range of 8MB to 14MB of the microcontroller die 201. And the content in the code area 203a is overwritten by the first buffer area buffer of the memory control module FMC (i.e., copied to the first buffer area buffer). The contents of the other area 203b of the first flash die FLASH A and the entire second flash die FLASH B are overwritten by the second cache area cache of the memory control module FMC as needed (i.e., copied to the second cache area cache as needed) or accessed by the timing of the bus interface generated by the memory control module FMC as needed. At this time, the microcontroller die 201 directly reads the first cache area buffer to run the old version of the firmware program code1.

[0076] Please refer to Figure 6BWhen the OTA upgrade version of the firmware program (i.e., the new firmware program) is burned (i.e., programmed into the code area 204a), and after a subsequent power-on or system reset, the swap flag bit swap bit in the configuration memory control module FMC is valid, the memory control module FMC only swaps the bus logical address mapping relationship between the code area 203a and the code area 204a, the bus logical address range corresponding to the code area 204a is changed to 0-2MB, and is accessed by the first buffer area buffer, while the bus logical address range corresponding to the code area 203a is changed to 14-16MB, and the access attribute of the code area 203a is changed to be accessed by the second buffer area cache or the timing access of the bus interface generated by the memory control module FMC, the bus logical address mapping relationship between the other areas 203b and 204b remains unchanged and continuous, the other area 203b still corresponds to the bus logical address range of 2MB-8MB of the microcontroller die 201, and the other area 204b corresponds to the bus logical address range of 8MB-14MB of the microcontroller die 201. The contents in the other area 204b of the entire first flash die FLASH A and the second flash die FLASH B are overwritten by the second cache area cache of the memory control module FMC as needed (i.e., copied to the second cache area cache as needed) or accessed by the timing of the bus interface generated by the memory control module FMC as needed. At this time, the microcontroller die 201 directly reads the first cache area buffer to run the OTA upgrade version of the firmware program code2. Obviously, the data access of the other areas 203b and 204b is not affected by whether the exchange mode is entered.

[0077] Optionally, in the microcontroller chip 200 of this embodiment, the memory control module FMC further has a code error flag, which is set when the microcontroller die 201 determines that the firmware programs stored in the first flash die FLASH A and the second flash die FLASH B are invalid, so as to terminate the execution of the firmware program, thereby preventing the microcontroller chip from falling into an infinite loop.

[0078] Please combine Fig. 6A and Figure 6B as well as Figure 7 , the OTA upgrade process of the microcontroller chip 200 of this embodiment includes:

[0079] First, after the power-on reset or system reset is released, the memory control module FMC checks whether the swap flag bit is valid (for example, it is invalid when swap bit=1), and thus determines whether to execute the old version of the firmware program or the OTA upgraded version of the firmware program first after the power-on reset or system reset is released according to the swap flag bit swap bit;

[0080] If the swap bit is checked to be valid, the first buffer area buffer copies the OTA upgrade version of the firmware program code2 in the code area 204a, and performs a self-test on the copied firmware program code2. When the self-test passes, the swap bit is maintained valid to indicate that the OTA upgrade version of the firmware program code2 stored in the code area 204a of the second flash memory die FLASH B is valid, and the memory control module FMC directly accesses the code2 copied in the first buffer area buffer to execute code2, thereby executing the OTA upgrade version of the firmware program first after the power-on reset or system reset release; when the self-test fails, it is necessary to further check whether there is a valid old version of the firmware program code1 in the code area 203a, and at this time it is necessary to switch the swap flag bit swap bit to invalid to indicate that the second flash memory die FLASH The OTA upgrade version of the firmware program code2 stored in the code area 204a of B is invalidated, and at the same time, the first buffer area buffer copies the old version of the firmware program code1 in the code area 203a, and further performs a self-check on the copied firmware program code1. When the self-check of the copied firmware program code1 passes, it indicates that a valid old version of the firmware program code1 is detected in the code area 203a. The memory control module FMC directly accesses the code1 copied in the first buffer area buffer to execute the firmware program code1, and sets the code error flag codeerror to an invalid state (for example, set to "0"). Therefore, when the OTA upgrade version of the firmware program in the second flash memory die is invalid, the old version of the firmware program in the first flash memory die can be rolled back to execute. When the self-check of the copied firmware program code1 fails, it indicates that a valid old version of the firmware program code1 is not detected in the code area 203a. At this time, the code error flag codeerror is directly set to a valid state (for example, set to "1") to end the execution and upgrade of the firmware program to avoid falling into an infinite loop.

[0081] If it is checked that the swap bit is invalid, the first buffer area buffer copies the old version of the firmware program code1 in the code area 203a, and performs a self-check on the copied old version of the firmware program code1. When the self-check passes, the memory control module FMC directly accesses the code1 copied in the first buffer area buffer to execute code1, thereby executing the old version of the firmware program first after the power-on reset or system reset release; when the self-check fails, it can be further checked whether there is a valid OTA upgrade version of the firmware program code2 in the code area 204a. At this time, the first buffer area buffer copies the OTA upgrade version of the firmware program code2 in the code area 204a, and further performs a self-check on the copied firmware program code2. When the self-check of the copied firmware program code2 passes, the swap flag bit swap bit is switched to valid to indicate that there is a valid OTA upgrade version of the firmware program code2 in the code area 204a. The memory control module FMC directly accesses the code2 copied in the first buffer area buffer to execute the OTA upgrade version of the firmware program code2, and sets the code error flag bit code error to an invalid state (for example, set to "0"). When the self-test of the copied firmware program code2 passes, the swap flag bit swap bit is still set to invalid to indicate that there is no valid OTA upgrade version of the firmware program code2 in the code area 204a. At this time, the code error flag bit code error is directly set to a valid state (for example, set to "1") to end the execution and upgrade of the firmware program.

[0082] Third embodiment

[0083] Please refer to Fig. 8A and Figure 8B This embodiment provides a microcontroller chip (i.e., the SIP MCU chip of the present invention) 200, which includes a microcontroller die (MCU die) 201, a first flash die (FLASH die) FLASH A, and a second flash die FLASH B encapsulated in the same package, that is, the microcontroller chip 200 is composed of a microcontroller die 201 and two FLASH die FLASH A and FLASH B stacked together.

[0084] The microcontroller die 201 has a memory control module FMC and two sets of bus interfaces 202a and 202b. The first flash die FLASH A is connected to the memory control module FMC through the bus interface 202a, and the second flash die FLASH B is connected to the memory control module FMC through the bus interface 202b. The first flash die FLASH A is used to store the old version of the firmware program (i.e., the old code or instruction), and the second flash die FLASH B is used to store the OTA upgraded version of the firmware program (i.e., the OTA upgraded code or instruction). When the corresponding versions of the firmware program are stored in the first flash die FLASH A and the second flash die FLASH B, the firmware programs in the first flash die FLASH A and the second flash die FLASH B can back up each other. The memory control module FMC converts the received bus operations into the timing of the bus interfaces 202a and 202b through address mapping control, so as to access the first flash memory die FLASH A and the second flash memory die FLASH B respectively. When OTA upgrade is required to update the firmware program in the microcontroller chip 200, the OTA process can program the OTA upgraded version of the firmware program into the second flash memory die FLASH B through the bus interface 202b, and during the programming process, any operation of the memory control module FMC on the first flash memory die FLASH A through the bus interface 202a will not be affected.

[0085] Compared with the microcontroller chip 200 of the second embodiment, the microcontroller chip 200 of the present embodiment omits the arrangement of the first cache area buffer for 1:1 copying of the contents of the code area of ​​the first flash memory die FLASH A and the second flash memory die FLASH B in the memory control module FMC of the microcontroller die 201. The entire contents of the first flash memory die FLASH A and FLASH B are accessed by the second cache area cache in the memory control module FMC after being copied on demand, or by the memory control module FMC converting bus operations into bus interface timing for access. The area cost of the microcontroller chip 200 of the present embodiment is relatively reduced.

[0086] Similarly, taking the first flash memory die FLASH A and the second flash memory die FLASH B as examples, the models are the same and the capacities are both 8MB, the capacities of the code areas 203a and 204a are both 2MB, the code area 203a of the first flash memory die FLASH A is the first 2MB physical address space of the first flash memory die FLASH A, and the code area 204a of the second flash memory die FLASH B is the last 2MB physical address space of the second flash memory die FLASH B, the principle of the microcontroller chip 200 of this embodiment executing the firmware program is as follows:

[0087] Please refer to Fig. 8A In the default state, after the microcontroller chip 200 of this embodiment is powered on, the code area 203a of the first flash memory die FLASH A (i.e., the first 2MB space of the flash memory die FLASHA) corresponds to the bus logic address range of 0MB to 2MB of the microcontroller die 201, the other area 203b of the first flash memory die FLASH A corresponds to the bus logic address range of 2MB to 8MB of the microcontroller die 201, the code area 204a of the second flash memory die FLASH B (i.e., the first 2MB space of the flash memory die FLASHA) corresponds to the bus logic address range of 14MB to 16MB of the microcontroller die 201, and the other area 204b of the second flash memory die FLASH B corresponds to the bus logic address range of 8MB to 14MB of the microcontroller die 201. At this time, the second cache area cache in the memory control module FMC copies the content in the code area 203a as needed, and the microcontroller die 201 directly reads the content in the second cache area cache to run the old version of the firmware program code1.

[0088] Please refer to Figure 8B , when the OTA upgrade version of the firmware program (i.e., the new firmware program) is burned (i.e., programmed into the code area 204a), and after the subsequent power-on or system reset, the swap flag bit swap bit in the configuration memory control module FMC is valid, the memory control module FMC only swaps the bus logical address mapping relationship between the code area 203a and the code area 204a, and the bus logical address range corresponding to the code area 204a is changed to 0-2MB, and the bus logical address range corresponding to the code area 203a is changed to 14MB-16MB, and the other area 203b still corresponds to the bus logical address range of 2MB-8MB of the microcontroller die 201, and the other area 204b corresponds to the bus logical address range of 8MB-14MB of the microcontroller die 201. At this time, the second cache area cache in the memory control module FMC directly copies the content in the code area 204a on demand, and the microcontroller die 201 directly reads the content in the second cache area cache to run the OTA upgrade version of the firmware program code2.

[0089] Fourth embodiment

[0090] Please refer to Fig.9A and Fig. 9BThis embodiment provides a microcontroller chip (i.e., the SIP MCU chip of the present invention) 200, which includes a microcontroller die (MCU die) 201 and a first flash die (FLASH die) FLASH A and a second flash die FLASH B encapsulated in the same package, that is, the microcontroller chip 200 is composed of a microcontroller die 201 and two FLASH die FLASH A and FLASH B stacked together.

[0091] The microcontroller die 201 has a memory control module FMC and two sets of bus interfaces 202a and 202b. The first flash die FLASH A is connected to the memory control module FMC through the bus interface 202a, and the second flash die FLASH B is connected to the memory control module FMC through the bus interface 202b. The first flash die FLASH A is used to store the old version of the firmware program (i.e., the old code or instruction), and the second flash die FLASH B is used to store the OTA upgraded version of the firmware program (i.e., the OTA upgraded code or instruction). When the corresponding versions of the firmware program are stored in the first flash die FLASH A and the second flash die FLASH B, the firmware programs in the first flash die FLASH A and the second flash die FLASH B can back up each other. The memory control module FMC converts the received bus operation into the timing of the bus interfaces 202a and 202b through address mapping control to access the first flash die FLASH A and FLASH B respectively. When an OTA upgrade is required to update the firmware program in the microcontroller chip 200, the OTA process can program the OTA upgraded firmware program into the second flash die FLASH B through the bus interface 202b. During the programming process, any operation of the memory control module FMC on the first flash die FLASH A through the bus interface 202a will not be affected. The memory control module FMC has a first buffer area and a second cache area.

[0092] Compared with the microcontroller chip 200 of the second embodiment, the total capacity M1 of the first buffer area buffer in the memory control module FMC of the microcontroller chip 200 of this embodiment is respectively greater than the capacity M2 of the code area 203a of the first flash die FLASH A and the capacity M2 of the code area 204a of the second flash die FLASH B. In the default state, the content in the code area 203a of the first flash die FLASH A and the content M1-M2 in the specified logical address range of other areas 203b are copied to the first buffer area buffer, and the remaining content in the other areas 203b of the first flash die FLASH A and the content in the code area 204a and other areas 204b of the second flash die FLASH B are accessed by the second buffer area cache in the memory control module FMC after being copied as needed, or the memory control module FMC directly converts the bus operation into the bus interface timing as needed to read; in the exchange state (that is, the OTA upgrade version of the firmware program code2 has been programmed into the second flash die FLASH B and after power-on or system reset, it is detected that the OTA upgrade version of the firmware program code2 stored in the code area 204a of the second flash memory bare chip FLASH B is valid), the memory control module FMC only swaps the bus logical address mapping relationship between the code area 203a and the code area 204a relative to the default state, and the bus logical address mapping relationship between the other areas 203b and 204b remains the same. At this time, the content in the code area 204a and the content M1-M2 in the specified logical address range of the other areas 203b are copied to the first cache area buffer together, and the code area 203a and the remaining content in the other areas 203b of the first flash memory bare chip FLASH A and the content in the other areas 204b of the second flash memory bare chip FLASH B are accessed by the second cache area cache of the memory control module FMC after being copied on demand or are read by the memory control module FMC by directly converting the bus operation into the bus interface timing.

[0093] Optionally, the second cache area cache is composed of a static random access memory, and when a logical address miss occurs in the second cache area cache, the memory control module FMC copies corresponding content from the second flash memory die FLASH B or the first flash memory die FLASH A to the second cache area cache.

[0094] Compared with the second embodiment, the technical solution of this embodiment can increase the total capacity of the first cache area on the basis of achieving the effect that can be achieved by the second embodiment, and copy the contents of the firmware program and some specified logical address ranges in the first flash memory bare chip (for example, the logical address range is connected to the contents in other areas 203b of the logical address of the code area 203a or 204a copied by the first cache area) to the first cache area, thereby further improving the operating efficiency of the microcontroller chip under the premise that the chip area of ​​the microcontroller chip allows.

[0095] Please refer to Fig.9A and Fig. 9B , below, taking the first flash memory die FLASH A and the second flash memory die FLASH B as an example, the model is the same and the capacity is 8MB, the capacity of the code area 203a and 204a is 2MB, the total capacity of the first cache area buffer is 4MB, and it is composed of the first cache area buffer1 and the first cache area buffer2, both of which have a capacity of 2MB, the code area 203a of the first flash memory die FLASH A is the first 2MB physical address space of the first flash memory die FLASH A, and the code area 204a of the second flash memory die FLASH B is the last 2MB physical address space of the second flash memory die FLASH B, to explain in detail the technical solution of this embodiment.

[0096] Please refer to Fig.9AIn the default state, after the microcontroller chip 200 is powered on, the code area 203a of the first flash memory die FLASH A (i.e., the first 2MB space of the flash memory die FLASHA) corresponds to the bus logic address range of 0MB to 2MB of the microcontroller die 201, the other area 203b of the first flash memory die FLASH A corresponds to the bus logic address range of 2MB to 8MB of the microcontroller die 201, the code area 204a of the second flash memory die FLASH B (i.e., the first 2MB space of the flash memory die FLASHA) corresponds to the bus logic address range of 14MB to 16MB of the microcontroller die 201, and the other area 204b of the second flash memory die FLASH B corresponds to the bus logic address range of 8MB to 14MB of the microcontroller die 201. The content in the code area 203a is overwritten by the first buffer area buffer1 of the memory control module FMC (i.e., copied to the first buffer area buffer1), and the 2MB content in the specified logical address range of the other area 203b (for example, the 2MB content in the logical address range following the logical address of the code area 203a, i.e., the content in the other area 203b with a logical address range of 2MB to 4MB) is overwritten by the first buffer area buffer2 of the memory control module FMC (i.e., copied to the first buffer area buffer2). The remaining 4MB content in the other area 203b of the first flash memory die FLASH A (i.e., the content in the logical address range of 4MB to 8MB) and the content of the entire second flash memory die FLASH B (i.e., the content in the logical address range of 8MB to 16MB) are overwritten by the second buffer area cache of the memory control module FMC as needed (i.e., copied to the second buffer area cache as needed) or accessed by the timing of the bus interface generated by the memory control module FMC as needed. At this time, the microcontroller die 201 directly reads the first buffer area buffer1 to run the old version of the firmware program code1, and directly accesses the content in the first buffer area buffer2 to obtain related data.

[0097] Please refer to Fig. 9B, when the firmware program of the OTA upgrade version (i.e., the new firmware program) is burned (i.e., programmed into the code area 204a), and after subsequent power-on or system reset, when the swap bit in the configuration memory control module FMC is valid, the memory control module FMC only exchanges the bus logical address mapping relationship between the code area 203a and the code area 204a. The bus logical address range corresponding to the code area 204a is changed to 0 - 2MB and is accessed by the first buffer buffer1, while the bus logical address range corresponding to the code area 203a is changed to 14MB - 16MB, and the access attribute of the code area 203a becomes cache access of the second buffer or is accessed by the timing of the bus interface generated by the memory control module FMC. The bus logical address mapping relationships of the other areas 203b and 204b remain unchanged and continuous. The other area 203b still corresponds to the bus logical address range 2MB - 8MB of the microcontroller die 201, and the other area 204b corresponds to the bus logical address range 8MB - 14MB of the microcontroller die 201. The content originally accessed by the first buffer buffer2 in the other area 203b (i.e., the content stored in the bus logical address range 2MB - 4MB) continues to be accessed by the first buffer buffer2. The remaining content of the code area 203a and the other area 203b of the entire first flash die FLASH A and the content of the other area 204b of the second flash die FLASH B are overwritten on demand by the second buffer cache of the memory control module FMC (i.e., copied to the second buffer cache on demand) or are accessed by the timing of the bus interface generated by the memory control module FMC on demand. At this time, the microcontroller die 201 directly reads the first buffer buffer1 to run the firmware program code2 of the OTA upgrade version. Obviously, the data access of the other areas 203b and 204b is not affected by whether it enters the swap mode.

[0098] Obviously, in this embodiment, the space running efficiency of the bus logical address range 0MB - 4MB is the highest.

[0099] The fifth embodiment

[0100] Please refer to Fig. 10A and Fig. 10B , this embodiment provides a microcontroller chip (i.e., the SIP MCU chip of the present invention) 200, which includes a microcontroller die (MCU die) 201, a first flash die (FLASH die) FLASH A, and a second flash die FLASH B encapsulated in the same package. That is, the microcontroller chip 200 is composed of a microcontroller die 201 and two FLASH dies, FLASH A and FLASH B, stacked and encapsulated together.

[0101] The microcontroller die 201 has a memory control module FMC and two sets of bus interfaces 202a and 202b. The first flash die FLASH A is connected to the memory control module FMC through the bus interface 202a, and the second flash die FLASH B is connected to the memory control module FMC through the bus interface 202b. The first flash die FLASH A is used to store the old version of the firmware program (i.e., the old code or instruction), and the second flash die FLASH B is used to store the OTA upgraded version of the firmware program (i.e., the OTA upgraded code or instruction). When the corresponding versions of the firmware program are stored in the first flash die FLASH A and the second flash die FLASH B, the firmware programs in the first flash die FLASH A and the second flash die FLASH B can back up each other. The memory control module FMC converts the received bus operation into the timing of the bus interfaces 202a and 202b through address mapping control to access the first flash die FLASH A and the second flash die FLASH B respectively. When an OTA upgrade is required to update the firmware program in the microcontroller chip 200, the OTA process can program the OTA upgraded firmware program into the second flash die FLASH B through the bus interface 202b, and during the programming process, any operation of the memory control module FMC on the first flash die FLASH A through the bus interface 202a will not be affected. The memory control module FMC has a first buffer area and a second cache area.

[0102] Compared with the microcontroller chip 200 of the fourth embodiment, the microcontroller chip 200 of the present embodiment has a total capacity M1 of the first buffer area in its memory control module FMC that is larger than the capacity M2 of the code area 203a of the first flash die FLASH A and the capacity M2 of the code area 204a of the second flash die FLASH B. In the exchange mode, not only the logical address mapping relationship of the entire area of ​​the first flash die FLASH A and the logical address mapping relationship of the entire area of ​​the second flash die FLASH B are swapped, but also in the first buffer area, in addition to the firmware program being updated from the old version of the firmware program code1 to the OTA upgraded version of the firmware program code2, the copied data is also updated from the content in other areas 203a to the corresponding content in other areas 204a. This embodiment can copy the firmware program and some contents corresponding to a specific logical address range to the first buffer area by increasing the total capacity of the first buffer area, thereby further improving the operating efficiency of the microcontroller chip under the premise that the chip area of ​​the microcontroller chip allows.

[0103] Optionally, the second cache area cache is composed of a static random access memory, and when a logical address miss occurs in the second cache area cache, the memory control module FMC copies corresponding content from the second flash memory die FLASH B or the first flash memory die FLASH A to the second cache area cache.

[0104] Please refer to Fig. 10A and Fig. 10B , below, taking the first flash memory die FLASH A and the second flash memory die FLASH B as having the same model and both having a capacity of 8MB, the capacity of the code areas 203a and 204a as 2MB, the total capacity of the first cache area buffer as 4MB, and being composed of the first cache area buffer1 and the first cache area buffer2 both having a capacity of 2MB, the code area 203a of the first flash memory die FLASH A being the first 2MB physical address space of the first flash memory die FLASH A, the code area 204a of the second flash memory die FLASH B being the first 2MB physical address space of the second flash memory die FLASH B, the content of the code area 203a or the code area 204a being overwritten by the first cache area buffer1, and the content of the designated logical address range (for example, 2MB to 4MB) being overwritten by the first cache area buffer2 as an example, the technical solution of this embodiment will be described in detail.

[0105] Please refer to Fig. 10AIn the default state, after the microcontroller chip 200 is powered on, the code area 203a of the first flash memory die FLASH A (i.e., the first 2MB space of the flash memory die FLASHA) corresponds to the bus logic address range of 0MB to 2MB of the microcontroller die 201, the other area 203b of the first flash memory die FLASH A corresponds to the bus logic address range of 2MB to 8MB of the microcontroller die 201, the code area 204a of the second flash memory die FLASH B (i.e., the first 2MB space of the flash memory die FLASHA) corresponds to the bus logic address range of 8MB to 10MB of the microcontroller die 201, and the other area 204b of the second flash memory die FLASH B corresponds to the bus logic address range of 10MB to 16MB of the microcontroller die 201. The content in the code area 203a is overwritten by the first buffer area buffer1 of the memory control module FMC (i.e., copied to the first buffer area buffer1 in a 1:1 manner), and the content in the specified logical address range (e.g., the content corresponding to the bus logical address range 2MB to 4MB, i.e., the content of the first 2MB in the other area 203b) is overwritten by the first buffer area buffer2 of the memory control module FMC (i.e., copied to the first buffer area buffer2 in a 1:1 manner). The remaining 4MB content in the other area 203b of the first flash memory die FLASH A and the content of the entire second flash memory die FLASH B are overwritten by the second buffer area cache of the memory control module FMC as needed (i.e., copied to the second buffer area cache as needed) or accessed by the timing of the bus interface generated by the memory control module FMC as needed. At this time, the microcontroller die 201 directly reads the first buffer area buffer1 to run the old version of the firmware program code1, and directly accesses the content in the first buffer area buffer2 to obtain relevant data.

[0106] Please refer to Fig. 10B, when the firmware program of the OTA upgrade version (i.e., the new firmware program) is burned (i.e., programmed into the code area 204a), and after subsequent power-on or system reset, when the swap bit in the configuration memory control module FMC is valid, the memory control module FMC exchanges the bus logical address mapping relationships of the code area 203a and the code area 204a, and exchanges the bus logical address mapping relationships of the other area 203b and the other area 204b. That is, the bus logical address range corresponding to the code area 204a is changed to 0 to 2MB, and is copied and accessed by the first buffer buffer1, while the bus logical address range corresponding to the code area 203a is changed to 8MB to 10MB, and the access attribute of the code area 203a becomes on-demand access by the second cache cache or on-demand access by the timing of the bus interface generated by the memory control module FMC. The bus logical address range corresponding to the other area 203b is changed to 10MB to 16MB, and the other area 203b also becomes on-demand access by the second cache cache or on-demand access by the timing of the bus interface generated by the memory control module FMC. And the bus logical address range corresponding to the other area 204b is changed to 2MB to 8MB. Thus, the content in the other area 204b corresponding to the specified logical address range (for example, 2MB to 4MB) is accessed by the first buffer buffer2, and the content in the other area 204b except the specified logical address range (for example, 2MB to 4MB) is still on-demand accessed by the second cache cache or on-demand accessed by the timing of the bus interface generated by the memory control module FMC. That is to say, the content of the entire first flash die FLASH A and the remaining content in the other area 204b of the second flash die FLASH B except the specified logical address range are on-demand overwritten (i.e., on-demand copied to the second cache cache) by the second cache cache of the memory control module FMC or accessed by the timing of the bus interface generated by the memory control module FMC on demand. At this time, the microcontroller die 201 directly reads the first buffer buffer1 to run the firmware program code2 of the OTA upgrade version, and directly reads the first buffer buffer2 to run the specified data in the second flash die FLASH B.

[0107] This embodiment can also achieve the highest space operation efficiency in the bus logical address range of 0MB to 4MB.

[0108] Sixth Embodiment

[0109] Please refer to Fig.11This embodiment provides a microcontroller chip (i.e., the SIP MCU chip of the present invention) 200, which includes a microcontroller die (MCU die) 201 and n flash die (FLASH die) FLASH1 to FLASH n encapsulated in the same package, that is, the microcontroller chip 200 is composed of a microcontroller die 201 and n FLASH die FLASH 1 to FLASH n stacked together. The microcontroller die 201 has a memory control module FMC and n groups of bus interfaces SPI IF_1 to SPI IF_n. The flash die FLASH 1 is connected to the memory control module FMC through the bus interface SPI IF_1, and the flash die FLASH 1 is connected to the memory control module FMC through the bus interface SPI IF_2. By analogy, the flash die FLASH n is connected to the memory control module FMC through the bus interface SPI IF_n.

[0110] The memory control module FMC is provided with hardware logic circuits such as an address mapping circuit 2011, an interface control (ifctrl) circuit 2012 and a swap control (swap ctrl) circuit 2014. These hardware logic circuit modules are similar to those in the first embodiment and will not be described in detail here.

[0111] As an example, a designated i-th flash chip FLASH i among n flash chips FLASH 1 to FLASH n is used as a second flash chip and is used to store an OTA upgraded version of the firmware program, and the remaining (n-1) flash chips FLASH 1 to FLASH i-1 and FLASH i+1 to FLASH n are used as n-1 first flash chips, which store corresponding old versions of the firmware program respectively, and the versions of the firmware programs stored in any two flash chips are different. The memory control module FMC is also used to determine the first flash chip (which may be referred to as the designated first flash chip) storing the old version of the firmware program of the designated version from the first flash chips FLASH 1 to FLASH i-1 and the first flash chips FLASH i+1 to FLASH n according to the rollback instruction after the OTA upgrade fails (including rolling back to the old version of the firmware program of the designated version), so as to execute the old version of the firmware program of the designated version stored in the designated first flash chip. Therefore, by setting different rollback instructions, it is possible to support switching between multiple versions of firmware programs, such as retaining the factory firmware program, rolling back to the initial stable version or a specified version of the firmware program, etc. This is suitable for personalized OTA upgrade strategies, and can realize the functions of reading, writing, and erasing n flash memory chips at the same time, thereby improving the system's operating efficiency.

[0112] As another example, a designated i-th flash die FLASH i among n flash die FLASH 1 to FLASH n is used as a second flash die and is used to store the OTA upgraded version of the firmware program. Among the remaining (n-1) flash die FLASH 1 to FLASH i-1 and FLASH i+1 to FLASH n, a portion of the flash die is used as a first flash die to store the corresponding old version of the firmware program, and the remaining flash die is used to store the corresponding data, wherein the first flash die used to store the corresponding old version of the firmware program can be one or more, and when there are multiple first flash die used to store the corresponding old version of the firmware program, the versions of the old version of the firmware program stored in any two first flash die are different. Thus, the memory control module FMC can determine the first flash die (which can be referred to as the designated first flash die) storing the designated version of the old version of the firmware program among all the first flash die used to store the corresponding old version of the firmware program according to the rollback instruction after the OTA upgrade fails, so as to execute the designated version of the old version of the firmware program stored in the designated first flash die, and then roll back to the designated version of the old version of the firmware program. In addition, the memory control module FMC can determine the flash memory die (which may be referred to as the specified data flash memory die) that stores the specified data or the corresponding specified logical address range in all the flash memory die used to store data according to the corresponding data read instruction, so as to read the specified data stored in the specified data flash memory die or the data within the specified logical address range. The scheme of this example can also support the switching of multiple versions of firmware programs by setting different rollback instructions, such as retaining the factory firmware program, tracing back to the initial stable version or the specified version of the firmware program, etc. It is suitable for personalized OTA upgrade strategies, and can realize the functions of reading, writing, erasing, etc. on n flash memory die at the same time, thereby improving the operating efficiency of the system. At the same time, the program to be run and the data to be accessed can be stored separately, further improving the operating efficiency of the system.

[0113] The above description is only a description of the preferred embodiment of the present invention, and is not intended to limit the scope of the present invention. Any changes or modifications made by a person skilled in the art in the field of the present invention based on the above disclosure shall fall within the scope of protection of the technical solution of the present invention.

Claims

1. A microcontroller chip, It is characterized in that Included in the same package: A microcontroller die having at least two sets of bus interfaces; At least two flash memory dies, each of which is connected to each group of the bus interfaces in a one-to-one correspondence, and at least two of the flash memory dies are used to store firmware programs; The microcontroller die is used to convert the received bus operation into the timing of the bus interface through address mapping control, so as to access each of the flash memory die respectively, and program the OTA upgrade version of the firmware program into the second flash memory die. During the programming process, and after power-on or system reset and when it is detected that the OTA upgrade version of the firmware program in the second flash memory die is invalid, the old version of the firmware program stored in the first flash memory die is executed, and after power-on or system reset and when it is detected that the OTA upgrade version of the firmware program in the second flash memory die is valid, the OTA upgrade version of the firmware program is executed.

2. The microcontroller chip as claimed in claim 1, It is characterized in that The flash memory die includes multiple first flash memory die, and the old version of the firmware program stored in each of the first flash memory die is different. The microcontroller die is also used to execute the corresponding version of the old version of the firmware program stored in the specified first flash memory die according to the rollback instruction after the OTA upgrade fails.

3. The microcontroller chip as claimed in claim 1, It is characterized in that The second flash memory die and the first flash memory die are used to store corresponding versions of firmware programs, and the remaining flash memory die are used to store data.

4. The microcontroller chip according to any one of claims 1 to 3, It is characterized in that The microcontroller die has a memory control module, the memory control module comprising: An address mapping circuit is used to map different bus logical addresses of the microcontroller die to different physical addresses of the flash memory die to form a logical address mapping relationship; An interface control circuit, used to convert received bus operations into a timing sequence of a bus interface; The exchange control circuit is used to control the address mapping circuit to realize the mutual exchange of the logical address mapping relationship of the space storing at least the firmware program of the second flash memory die and the first flash memory die when the OTA upgrade version of the firmware program in the second flash memory die is valid.

5. The microcontroller chip as claimed in claim 4, It is characterized in that The exchange control circuit includes an exchange flag. After the OTA upgrade version of the firmware program is programmed into the second flash memory die for storage, and after power is turned on again or the system is reset, the memory control module is also used to perform a self-check on the OTA upgrade version of the firmware program stored in the second flash memory die. If the self-check passes, it indicates that the OTA upgrade version of the firmware program is valid, so that the exchange flag is effective, and the exchange control circuit controls the address mapping circuit to exchange the logical address mapping relationship between the second flash memory die and the first flash memory die. If the self-check fails, it indicates that the stored OTA upgrade version of the firmware program is invalid, so that the exchange flag is invalid, and the address mapping circuit maintains the original logical address mapping relationship.

6. The microcontroller chip as claimed in claim 4, It is characterized in that The second flash memory die and the first flash memory die both have a code area for storing corresponding firmware programs. After power-on or system reset and when it is detected that the OTA upgraded version of the firmware program in the second flash memory die is valid, the exchange control circuit only exchanges the logical address mapping relationship of the code area of ​​the first flash memory die with the logical address mapping relationship of the code area of ​​the second flash memory die.

7. The microcontroller chip as claimed in claim 4, It is characterized in that The second flash memory die and the first flash memory die both have a code area for storing corresponding firmware programs. After power-on or system reset and when it is detected that the OTA upgraded version of the firmware program in the second flash memory die is valid, the exchange control circuit exchanges the logical address mapping relationship of the entire area of ​​the first flash memory die with the logical address mapping relationship used for the entire area of ​​the second flash memory die.

8. The microcontroller chip as claimed in claim 7, It is characterized in that The memory control module also includes a first cache area, the capacity of the first cache area is equal to the capacity of each of the code areas, and after power-on or system reset and when it is detected that the OTA upgrade version of the firmware program in the second flash memory die is invalid, the first cache area copies the content in the code area of ​​the first flash memory die; after power-on or system reset and when it is detected that the OTA upgrade version of the firmware program in the second flash memory die is valid, the first cache area copies the content in the code area of ​​the second flash memory die.

9. The microcontroller chip as claimed in claim 7, It is characterized in that The memory control module also includes a first cache area, the capacity of which is greater than the capacity of each of the code areas. After power-on or system reset and when it is detected that the OTA upgrade version of the firmware program in the second flash memory die is invalid, the first cache area copies the content in the code area of ​​the first flash memory die, and also copies the content in the second flash memory die or the first flash memory die within a specified logical address range outside the logical address range of the code area copied by the first cache area; after power-on or system reset and when it is detected that the OTA upgrade version of the firmware program in the second flash memory die is valid, the first cache area copies the content in the code area of ​​the second flash memory die, and also copies the content in the second flash memory die or the first flash memory die within the specified logical address range.

10. The microcontroller chip according to claim 8 or 9, It is characterized in that The memory control module further includes a second cache area, and except for the content copied by the first cache area, the remaining content stored in the second flash die and the first flash die is accessed by the second cache area after being copied on demand or by the timing of the bus interface generated by the interface control circuit; and / or The second cache area is composed of a static random access memory, and when a logical address miss occurs in the second cache area, the memory control module copies the corresponding content from the second flash memory die or the first flash memory die to the second cache area.

11. The microcontroller chip according to any one of claims 8 to 10, It is characterized in that The first buffer area is composed of one static random access memory or a combination of multiple static random access memories.

12. The microcontroller chip according to any one of claims 8 to 11, It is characterized in that After the OTA upgrade version of the firmware program is programmed into the second flash memory die for storage, and after power-on or system reset, the first cache area first copies the content in the code area of ​​the second flash memory die, and the memory control module performs a self-check on the content copied from the first cache area. If the self-check passes, it means that the OTA upgrade version of the firmware program in the second flash memory die is detected to be valid, and the memory control module directly accesses the first cache area to run the OTA upgrade version of the firmware program. If the self-check fails, it means that the OTA upgrade version of the firmware program in the second flash memory die is detected to be invalid, and the first cache area re-copies the content in the code area of ​​the first flash memory die, and performs a self-check on the content copied from the first cache area again. When the self-check passes again, it means that the old version of the firmware program in the first flash memory die is detected to be valid, and the memory control module directly accesses the first cache area to run the old version of the firmware program.

13. The microcontroller chip as claimed in claim 7, It is characterized in that The memory control module also includes a second cache area. After power is restarted or the system is reset and it is detected that the OTA upgrade version of the firmware program in the second flash memory die is invalid, the second cache area copies the content in the code area of ​​the first flash memory die. After power is restarted or the system is reset and it is detected that the OTA upgrade version of the firmware program in the second flash memory die is valid, the second cache area copies the content in the code area of ​​the second flash memory die.

14. The microcontroller chip as claimed in claim 13, It is characterized in that Except for the content copied by the second cache area, the remaining content stored in the second flash memory die and the first flash memory die is accessed by the second cache area after being copied on demand or by the timing of the bus interface generated by the interface control circuit.

15. The microcontroller chip as claimed in claim 1, It is characterized in that The bus interface is a SPI interface.

16. The microcontroller chip according to any one of claims 1 to 15, It is characterized in that The microcontroller die also has a code error flag, which is set when the microcontroller die determines that all firmware programs stored in the flash memory die are invalid, so as to terminate the execution of the firmware program.

Citation Information

Patent Citations

  • Firmware upgrading method and system based on a flash memory microcontroller and a flash memory microcontroller

    CN109284117A

  • Firmware upgrading method, device and system, electronic equipment and storage medium

    CN113900693A

  • Firmware storage method and system

    CN114464231A

  • Generating system memory snapshots on memory subsystems with hardware acceleration input / output paths

    CN115687180A

  • System-in-package structure, module structure, transceiver and electronic equipment

    CN217691159U

Cited By

  • Program upgrading method, chip and vehicle

    CN121255250A

  • Program data upgrading processing method of chip, chip and vehicle

    CN121833005A