System storage configuration method, double-Bank uninterruptible power version conflict prevention online upgrading method and electronic equipment

By dividing it into a loading domain and a running domain in the system storage area, and using the dual Bank Flash mode to divide the space, the version conflict problem in the dual Bank continuous power upgrade solution is solved, and the fast and stable online upgrade and version switching are achieved.

CN120045214APending Publication Date: 2025-05-27TAIWEI MICROELECTRONICS (ZHUHAI) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411387260.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-09-30
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

The existing technology has version conflicts in the dual Bank continuous power upgrade solution, resulting in wasting RAM resources and failure in upgrading.

Method used

By dividing the system storage area into a loading domain and a running domain, and using dual Bank Flash mode to divide the Flash space and RAM space, the firmware online upgrade and version switching can be achieved.

Benefits of technology

It realizes continuous and rapid switching of dual Bank firmware online upgrades under the premise of constant power and no waiting, avoiding version conflicts and waste of RAM resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120045214A_ABST
    Figure CN120045214A_ABST
Patent Text Reader

Abstract

The invention discloses a system storage configuration method, a double-Bank uninterruptible power version conflict prevention online upgrading method and electronic equipment, and the system storage configuration method provides a precondition of data storage for uninterruptible rapid switching during online upgrading of double-Bank firmware through reasonable arrangement of a storage space. The double-Bank uninterruptible power version conflict prevention online upgrading method provided by the invention can realize version conflict prevention during online upgrading on the premise of uninterruptible power and no waiting. The invention provides a safe upgrading mode for application occasions with high requirements and incapability of long-time power failure and long-time control separation, and has great improvement guiding significance for the maintenance upgrading mode of electronic equipment such as a digital power supply.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of storage configuration and firmware online upgrade, and specifically relates to a system storage configuration method, an online upgrade method for preventing version conflicts without power-off in a dual-Bank, and a corresponding electronic device. Background Art

[0002] Currently existing power-off-free upgrade solutions include a software switching solution based on Bootload and a dual-Bank power-off-free upgrade solution, which are introduced separately below.

[0003] I. The software switching solution based on Bootload realizes power-off-free upgrade by accessing the operation interfaces provided by other firmware partitions through Bootload.

[0004] The software switching solution based on Bootload has the following disadvantages:

[0005] 1. It is necessary to independently partition the Bootload partition, and the Bootload code itself cannot be upgraded;

[0006] 2. The old and new firmwares need to occupy different Flash addresses and RAM addresses respectively. Therefore, for the deployed products, it is necessary to identify the running firmware version and the running partition situation, otherwise the upgrade will fail;

[0007] 3. Since some interrupts and some variables of Bootload need to be shared with the upgraded firmware, it is difficult for subsequent maintenance.

[0008] II. Dual-Bank upgrade solution: The dual-Bank power-off-free upgrade solution requires the Flash of the MCU to support the dual-Bank mode. During the upgrade, the currently used Bank can burn the new firmware into the idle Bank, then set the Bank Map mapping bit, and then perform a switching operation through the chip hardware.

[0009] The dual-Bank power-off-free upgrade solution has the following disadvantages:

[0010] 1. Since the Bank switching only operates on the Flash partition and cannot operate on the RAM partition, it is necessary to allocate different RAM spaces for different partitions, resulting in a version conflict problem;

[0011] 2. Due to the version conflict problem, a large amount of RAM space will be freed up during operation (the space occupied by the unused firmware), resulting in a waste of RAM resources. Summary of the Invention

[0012] In order to solve the above problems, the present invention provides a system storage configuration method, an online upgrade method for preventing version conflicts without power-off in a dual-Bank, and a corresponding electronic device.

[0013] A system storage configuration method includes: dividing the system storage area into a loading domain and a running domain, where the loading domain is a spatial description of the code stored in Flash, and the running domain is a spatial description of the code in Flash or RAM during operation; dividing the Flash space into a Bank0 space and a Bank1 space using a dual-Bank Flash mode, and the loading domain includes a fixed information area, a fixed code area, and other code areas respectively divided from the Bank0 space and the Bank1 space; characterized in that the running domain is divided into a user interrupt vector table area, an upgrade interrupt vector table area, a system code area, a stack area, an RW and ZI global variable area, a user code area, a shared variable area, a fixed information area, and a fixed code area; the RAM space is divided into: a RAM-A area for storing the stack, a RAM-B area for shared variables, a RAM-C area for user code, and a RAM-D area for use during the upgrade phase.

[0014] As a preferred technical solution, the other code areas of the Bank0 space and the Bank1 space respectively include a communication programming component, a service area, a shared variable space, a basic code area, an in-FLASH interrupt vector table area, a stack area, and an RW and ZI global variable area.

[0015] As a preferred technical solution, the in-FLASH interrupt vector table area, the communication programming component, the system code area, the user code area, the fixed information area, and the fixed code area of the running domain corresponding to the Bank0 space and the Bank1 space are configured in the FLASH.

[0016] As a preferred technical solution, the shared variable area, the stack area, and the RW and ZI global variable area of the running domain corresponding to the Bank0 space and the Bank1 space are configured in the RAM.

[0017] As a preferred technical solution, the RAM space is divided into: a RAM-A area for storing the stack, a RAM-B area for shared variables, a RAM-C area for user code, and a RAM-D area for use during the upgrade phase.

[0018] As a preferred technical solution, by means of the method of making a Bin file, the fixed information area, the fixed code area, and the other code areas of the Bank0 space and the Bank1 space are respectively compiled and output as three independent Bin files for use during later programming.

[0019] An online upgrade method for preventing version conflicts in a dual - Bank without power - off provided by the present invention is based on the system storage configuration method described above; it is characterized in that it includes: S1, execute the main() entry; S2, initialize the system and point to the interrupt vector table in the Bank0 user area; S3, execute the basic initialization BaseInit(); S4, perform the re - initialization ReInit(); S5, repeatedly detect the user service and determine whether there is an upgrade requirement. If so, enter S6; S6, construct the upgrade segment code area; S7, point to the interrupt vector table in the Bank0 upgrade area and execute the firmware download process; S8, build the business code area of the new firmware; S9, execute the bank switching task; S10, point to the interrupt vector table in the Bank0 upgrade area and jump to the goto statement of the re - initialization.

[0020] As a preferred technical solution, the process of the bank switching task includes: a1, construct the code space in the upgrade area; a2, point the interrupt pointer to the upgrade area interrupt; a3, while the upgrade area interrupt code temporarily takes over the interrupt response, receive the firmware information; a4, burn the idle bank area; a5, erase the original RAM space and construct the code in the new firmware RAM area; a6, switch the bank mapping and point the interrupt pointer to the user area interrupt; a7, the user area interrupt code takes over the interrupt response again.

[0021] As a preferred technical solution, the MCU, FLASH, and RAM cooperate to execute the online upgrade method for preventing version conflicts in a dual - Bank without power - off described in claim 8.

[0022] As a preferred technical solution, the electronic device is a digital power device.

[0023] The present invention mainly solves the version conflict problem that different firmware occupies different partitions and realizes the following functions: 1. Only one set of code needs to be maintained for a single product; 2. Switching between versions does not affect the normal code working function. The present invention has great guiding significance for the maintenance and upgrade methods of electronic devices such as digital power supplies. After using this solution, the digital power supply outputs continuously and stably, without the need to stop the work of the server and data center, avoiding the problems of service interruption and version conflicts caused by upgrading the power supply. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] Figure 1 It is the schematic diagram of the area configuration of the system storage configuration method provided by the embodiment of the present invention.

[0025] Figure 2 It is the distribution diagram of the loading domain in the system storage configuration method provided by the embodiment of the present invention.

[0026] Figure 3 It is the distribution diagram of the running domain in the system storage configuration method provided by the embodiment of the present invention.

[0027] Figure 4 This is a flowchart of the online upgrade method for dual - Bank power - off - free anti - version - conflict provided by an embodiment of the present invention.

[0028] Figure 5 This is a flowchart of the switching between banks in the online upgrade method for dual - Bank power - off - free anti - version - conflict provided by an embodiment of the present invention. Detailed implementation manners

[0029] The following explains and illustrates the technical solutions of the embodiments of the present invention with reference to the accompanying drawings of the embodiments of the present invention. However, the following embodiments are only the preferred embodiments of the present invention, not all of them. Based on the embodiments in the implementation manners, other embodiments obtained by those skilled in the art without creative efforts all fall within the protection scope of the present invention.

[0030] The system storage configuration method provided by the present invention aims to provide the prerequisite for data storage for the uninterrupted and fast switching during the online upgrade of dual - Bank firmware, so that the online upgrade method for dual - Bank power - off - free anti - version - conflict provided by the present invention can achieve the uninterrupted and fast switching during the online upgrade of dual - Bank firmware without power - off and without waiting. In the implementation process of the implementation scheme of the present invention, the following technical problems need to be considered first and the following technical requirements need to be achieved:

[0031] First of all, it is necessary to ensure that the new and old firmware is based on the same set of code, and the key is to implement the function of sharing the same section of RAM space between the new and old codes. The difficulty lies in ensuring that the code being run cannot be erased, and at the same time, the code in the RAM space needs to be upgraded; secondly, during the upgrade process, it is necessary to ensure that each function accessed by the interrupt can be accessed normally. The upgrade in the Flash space is an operation on another Bank and does not affect the access of this Bank. However, the RAM space will have a blank period due to erasure and upgrade, so this solution needs to focus on solving the interrupt access requirements during this blank period.

[0032] Based on the above - mentioned technical difficulties, the present invention starts from the configuration of the storage space and provides a new implementation scheme, which includes the following functional modules:

[0033] 1. Communication and programming module, used for communication and transmission with the host computer, and performing the function of programming the obtained firmware to the specified address.

[0034] 2. Fixed information area, used to build the operating environment for future upgraded firmware and the operating environment setup before switching between different firmwares.

[0035] 3. Fixed code area, storing the code for switching operations to ensure that the stack during the entire switching period is not polluted.

[0036] 4. User area, generally referring to the content that runs within its respective firmware and needs to run in RAM, which needs to be copied from the Flash space to RAM before the switching operation is executed.

[0037] 5. Shared variable area, used to transfer the control variables shared between the two firmwares to achieve the problem of non-disruptive interruption of the control logic.

[0038] 6. Shared stack area, which is the dynamic space used by the programming language and cannot be missing.

[0039] 7. Interrupt vector table, including user interrupt vector table and upgrade stage interrupt vector table.

[0040] 8. User code area.

[0041] 9. Upgrade code area.

[0042] The storage situations of the above-mentioned various modules in Flash and RAM during operation are as Figure 1 shown. The Flash space is divided into Bank0 space and Bank1 space using the dual-Bank Flash mode; the RAM space is manually divided into 4 areas, including: RAM-A area for storing the stack, RAM-B area for shared variables, RAM-C area for user code, and RAM-D area for the upgrade stage.

[0043] Among them, first, the firmware partitioning function needs to be implemented. The compiler divides the area into a loading domain and a running domain. The loading domain is the space description of the code stored in Flash, and the running domain is the space description of the code in Flash or RAM during operation. In this solution, the loading domain needs to be divided into a fixed information area, a fixed code area, and other code areas, as Figure 2 shown. By means of making Bin files, these three loading domains are compiled and output as three independent Bin files for later use during burning. The running domain is divided into a user interrupt vector table area, an upgrade interrupt vector table area, a system code area, a stack area, RW and ZI global variable areas, a user code area, a shared variable area, a fixed information area, and a fixed code area, and the distribution situation is as Figure 3 shown.

[0044] During the firmware switching stage, it is necessary to read the fixed information area of the new firmware to build the content of the RAM space, and it is necessary to reference the global variables of the compiler to construct the fixed information. These variables include: the loading start address, the running start address, and the area length of the business code in the user code area; the loading start address, the running start address, and the area length of the shared variable area; the loading start address, the running start address, and the area length of the code in the upgrade stage. These information are the offset sources for implementing the copy of the new code from Flash to RAM.

[0045] Among them, the composition of the fixed code area has the following characteristics and requirements:

[0046] 1) Each firmware comes with its own user code segment and upgrade code segment, and this code area in different firmwares should be exactly the same;

[0047] 2) The main() function must be saved in this area, and all operations from the main() function to the jump point belong to the fixed code area;

[0048] 3) The execution addresses of this code are the same;

[0049] 4) When calling business or peripheral functions of different firmwares within this code, it needs to be called in the form of a sub-function.

[0050] The execution logic of the fixed code area is as Figure 4 shown, and the operations executed by the fixed code area are shaded in gray.

[0051] An online upgrade method for a dual-Bank power-off prevention version conflict, based on the system storage configuration method described above; it is characterized in that it includes: S1, execute the main() entry; S2, initialize the system and point to the interrupt vector table of the Bank0 user area; S3, execute the basic initialization BaseInit(); S4, switch and re-initialize ReInit(); S5, repeatedly detect user services and judge whether there is an upgrade requirement, if so, enter S6; S6, construct the upgrade segment code area; S7, point to the interrupt vector table of the Bank0 upgrade area and execute the firmware download process; S8, build the business code area of the new firmware; S9, execute the bank switching task; S10, point to the interrupt vector table of the Bank0 upgrade area and jump to the goto statement of the re-initialization.

[0052] Among them, when the Bank is switched, the entire Flash will perform a mapping switch, so it is necessary to ensure that during the entire switching stage, the program pointer, stack space, etc. do not have address offset changes.

[0053] In addition, the process of interrupt handling is as follows: Each firmware needs to first ensure that a default interrupt vector table is stored at the starting address, because the interrupt vector table is the internal Reset_Handler() reset handle that is preferentially read and executed when the MCU starts, otherwise the MCU cannot start normally. During the upgrade process, use the interrupt vector table and its temporary interrupt code in the upgrade code segment, so that the code in the user code area can be updated. Each firmware comes with its own user code segment and upgrade code segment, so code iteration does not need to consider the conflict problem between the old and new firmwares.

[0054] In addition, the user area contains user code and global variables used by the Bank. During compilation, global variables and static local variables are compiled into the RW and ZI areas. The access to these variables essentially reads and writes their addresses fixed in the RAM area. Generally, the compilation configuration places the RW and ZI areas and the stack in the same area. However, in this solution, to avoid the mutual influence of global variables of different firmware, the RW and ZI areas are divided into the user area, thus isolating the variable spaces of different firmware.

[0055] The code in the user area actually specifically refers to the user code running in the RAM area. Because the code in the Flash area is automatically mapped and used newly by the Bank switch, while the code in the RAM area needs to be manually copied and processed. This part of the code needs to be declared to belong to the dedicated RAM area first.

[0056] See Figure 5 As shown, in this embodiment, the process of the bank switching task includes: a1. Construct the code space of the upgrade area; a2. Point the interrupt pointer to the upgrade area interrupt; a3. While the upgrade area interrupt code temporarily takes over the interrupt response, receive the firmware information; a4. Burn the idle bank area; a5. Erase the original RAM space and construct the code of the new firmware RAM area; a6. Switch the bank mapping and point the interrupt pointer to the user area interrupt; a7. The user area interrupt code takes over the interrupt response again.

[0057] In the above solution, first construct the upgrade code area. After reading the fixed information area of the currently running firmware, obtain the information of the upgrade code segment, then use this information to construct the content of the upgrade segment, and then point the interrupt vector pointer to the upgrade code segment; then communicate with the host computer to obtain the firmware information of the new firmware and perform Flash burning; after the burning is completed, use the firmware information of the new firmware to build the user code area and user interrupt code of the new firmware, and then perform Flash mapping switching and point the interrupt vector table to the new user interrupt vector table.

[0058] In the above embodiment, since there are only two statements for the switching action and the pointing action, the switching time is very short.

[0059] After reading the fixed information area, obtain the loading address, running address, and area length of the RAM area occupied by the firmware, and then perform the environment setup work, that is, copy the code from the loading area to the running area. At the same time, the global variables in the RW and ZI areas are also copied to the RAM area synchronously with this operation, completing the initialization work of the global variables.

[0060] Finally, for the design of the shared variable area, the main considerations are as follows: Global variables are mainly used to store global variables related to control that need to be passed between the old and new firmware. This part shares a piece of RAM space, and users need to decide whether to process it according to the situation during the switch. This solution mainly plans this non-erased area for transmission and use.

[0061] In this solution, the following mechanisms are mainly used to achieve the function of ensuring that the old and new firmware use the same code during the power-on-free upgrade process:

[0062] 1. The user area interrupt system is used to collect, calculate, and output the control logic environment;

[0063] 2. The upgrade area interrupt system temporarily takes over the interrupt response to update the code in the original user area;

[0064] 3. The data packet sending and receiving function is placed in the main loop of main(). This process can be interrupted without affecting the control output;

[0065] 4. The firmware burning and running environment is also placed in the main loop of main();

[0066] 5. The position of the switching action code is fixed to ensure the normal reading of the program pointer before and after the switch.

[0067] When this technical solution realizes the power-on-free upgrade, the old and new codes share the same set of space, and there is no need to specifically distinguish the order of the old and new versions. It has great guiding significance for improving the maintenance and upgrade methods in the digital power industry. For products that have been manufactured and burned with firmware of different iterative versions, there is no need to distinguish the partition differences between the firmware directly, and the product upgrade and iteration can be done more conveniently.

[0068] The above embodiments are only for full disclosure and not for limiting the preferred embodiments of the present invention. Any replacement of equivalent technical features based on the creative concept of the present invention without creative labor shall be regarded as the scope disclosed in this application.

Claims

1. A system storage configuration method, comprising: The system storage area is divided into a loading domain and a running domain. The loading domain is a description of the space where the code is stored in the Flash, and the running domain is a description of the space in the Flash or RAM during the running of the code. The Flash space is divided into Bank0 space and Bank1 space using the dual-Bank Flash mode, and the loading domain includes the fixed information area, the fixed code area and other code areas respectively divided from the Bank0 space and the Bank1 space; it is characterized in that the running domain is divided into a user interrupt vector table area, an upgrade interrupt vector table area, a system code area, a stack area, a RW and ZI global variable area, a user code area, a shared variable area, a fixed information area and a fixed code area; the RAM space is divided into: a RAM-A area for storing the stack, a RAM-B area for shared variables, a RAM-C area for user code, and a RAM-D area used in the upgrade stage.

2. The system storage configuration method according to claim 1, characterized in that: The other code areas of the Bank0 space and the Bank1 space respectively include communication burning components, service area, shared variable space, basic code area, interrupt vector table area in FLASH, stack area, RW and ZI global variable areas.

3. The system storage configuration method according to claim 2, characterized in that: The interrupt vector table area, communication burning component, system code area, user code area, fixed information area and fixed code area in the FLASH of the operation domain corresponding to the Bank0 space and the Bank1 space are configured in the FLASH.

4. The system storage configuration method according to claim 3, characterized in that: The shared variable area, stack area, RW and ZI global variable area of ​​the operating domain corresponding to the Bank0 space and the Bank1 space are respectively configured in the RAM.

5. The system storage configuration method according to claim 4, characterized in that: The RAM space is divided into: RAM-A area for storing the stack, RAM-B area for shared variables, RAM-C area for user code, and RAM-D area used during the upgrade phase.

6. The system storage configuration method according to claim 5, characterized in that: With the help of the method of making Bin files, the fixed information area, fixed code area and other code area of ​​Bank0 space and Bank1 space are compiled and output into three independent Bin files for use in later burning.

7. A dual-bank online upgrade method for preventing version conflicts without power failure, based on the system storage configuration method of claim 6; characterized in that: include: S1, execute main() entry; S2, system initialization, and point to Bank0 user area interrupt vector table; S3, perform basic initialization BaseInit(); S4, switch to re-initialization ReInit(); S5, repeatedly detect user services and determine whether there is an upgrade requirement, if yes, enter S6; S6, construct the upgrade segment code area; S7, point to the interrupt vector table of Bank0 upgrade area and execute the firmware download process; S8. Build the business code area of ​​the new firmware; S9, execute the bank switching task; S10, point to the interrupt vector table of the Bank0 upgrade area and jump to the re-initialized goto statement.

8. The online upgrade method for preventing version conflicts without power failure of dual banks according to claim 7, wherein the process of the bank switching task comprises: a1. Build the upgrade area code space; a2. The interrupt pointer points to the upgrade area interrupt; a3. The upgrade area interrupt code temporarily takes over the interrupt response and receives firmware information; a4, burn the free bank area; a5, erase the original RAM space and build the new firmware RAM area code; a6. Switch bank mapping, and the interrupt pointer points to the user area interrupt; a7. The user area interrupt code takes over the interrupt response again.

9. An electronic device, comprising MCU, FLASH, and RAM, characterized in that: The MCU, FLASH and RAM cooperate to execute the dual-bank online upgrade method for preventing version conflicts without power failure as described in claim 8.

10. The electronic device according to claim 9, characterized in that: The electronic device is a digital power supply device.