Magnetic disk device
By introducing key management and firmware status detection and repair functions into the disk device, the problem of lack of protection and difficulty in repairing firmware updates in the prior art is solved, and reliable updates and automatic repairs of firmware are achieved.
Patent Information
- Application Number
- CN202410179742.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-12-21
- Filing Date
- 2024-02-18
- Publication Date
- 2025-06-24
AI Technical Summary
Existing disk devices lack the protection function of firmware updates, which can easily lead to abnormal firmware due to unintentional updates, which will lead to inability to boot and difficult to resolve the state.
Nonvolatile memory and controller are introduced into the disk device, and firmware update protection is realized by reading and programming the keys in the key area, and the function of detecting and repairing firmware status is achieved.
Effectively protect the firmware from unintentional updates, ensure that the firmware is in a normal state, improve the reliability of the disk device, and realize the automatic repair function of the firmware.
Smart Images

Figure CN120197173A_ABST
Abstract
Description
[0001] This application claims priority based on Japanese Patent Application No. 2023-215598 (filing date: December 21, 2023). This application incorporates the entire contents of the base application by reference thereto. Technical Field
[0002] Embodiments of the present invention relate to a disk device. Background Art
[0003] In a disk device, firmware update (rewrite) is performed through protocol communication between a SoC (System-on-a-Chip) that constitutes a main controller and a non-volatile memory that stores the firmware. Conventionally, a disk device does not have a protection function for firmware update (rewrite). Therefore, an unintended firmware update may be performed from the outside.
[0004] In addition, conventionally, there has been no function to detect and repair a firmware breakage at an arbitrary interval when the firmware is broken. When the firmware is not in a normal state due to breakage or unintended update, the disk device sometimes does not start. In a state where the disk device does not start, it is also difficult to analyze the state. Summary of the Invention
[0005] An embodiment of the present invention provides a disk device that maintains firmware in a normal state and has high reliability.
[0006] The disk device according to the embodiment includes: a non-volatile memory having a firmware area that stores firmware and a key area that stores a first key; and a controller that enables firmware update when the first key is read from the key area and a second key is programmed into the key area. Brief Description of the Drawings
[0007] Figure 1 is a block diagram showing the configuration of a disk device according to an embodiment.
[0008] Figure 2 is a flowchart showing steps in updating firmware.
[0009] Figure 3 is a block diagram for explaining firmware update.
[0010] Figure 4 is a flowchart showing an example of steps of a process for detecting and repairing the state of firmware.
[0011] Figure 5 is continued from Figure 4 and is a flowchart showing an example of steps of a process for detecting and repairing the state of firmware.
[0012] Figure 6 is a flowchart that follows Figure 4 and shows an example of the steps of a process for detecting and repairing the state of firmware.
[0013] Figure 7 is a block diagram for explaining the repair of firmware in the case where one of the first firmware and the second firmware is normal and the other is abnormal.
[0014] Explanation of Reference Numerals
[0015] 1... Disk device, 11... Disk, 13... Head, 60... MPU, 70... Non-volatile memory, 71... Firmware area, 72... Key area, 100... Host system, 130... Main controller, F1... First firmware, F2... Second firmware. Detailed Description of the Embodiment
[0016] Hereinafter, embodiments of the present invention will be described with reference to the drawings. In addition, the disclosure is merely an example, and appropriate changes that can be easily conceived by those skilled in the art while maintaining the gist of the invention are of course included in the scope of the present invention. Further, in order to make the drawings and the description clearer, there are cases where the widths, thicknesses, shapes, etc. of the respective parts are schematically shown as compared with the actual state, but this is merely an example and does not limit the interpretation of the present invention. Further, in this specification and each drawing, sometimes the same reference numerals are given to elements that are the same as those already described with respect to the drawings that have appeared before, and detailed descriptions are appropriately omitted.
[0017] Hereinafter, while referring to the attached Figure 1 a disk device according to an embodiment will be described in detail.
[0018] First, the configuration of the disk device 1 will be described.
[0019] Figure 1 is a block diagram showing the configuration of the disk device 1.
[0020] As Figure 1 shown, the disk device 1 includes a rectangular housing 10, a disk 11 as a storage medium disposed within the housing 10, a spindle motor (SPM) 12 that supports and rotates the disk 11, and a head 13 having a write head 13W for writing data to the disk 11 and a read head 13R for reading data from the disk 11.
[0021] The disk device 1 includes a head actuator 14 that moves the head 13 to an arbitrary track on the disk 11 and positions it. The head actuator 14 includes a carriage assembly 15 that supports the head 13 in a movable manner, and a voice coil motor (VCM) 16 that rotates the carriage assembly 15.
[0022] The disk device 1 includes a head amplifier IC (preamplifier) 30 that drives the head 13, a main controller 130, a driver IC 20, a non-volatile memory 70, a volatile memory 80, and a buffer memory 90. The head amplifier IC 30 is electrically connected to the head 13.
[0023] The head amplifier IC 30 includes a read amplifier and a write driver. The read amplifier amplifies the read signal read from the disk 11 by the read head 13R and outputs it to the main controller 130 (more specifically, a read / write (R / W) channel 40 described later). The write driver outputs a write current corresponding to the signal output from the R / W channel 40 to the write head 13W.
[0024] The main controller 130 and the driver IC 20 are configured, for example, as a control circuit board (not shown) provided on the back side of the housing 10. The main controller (controller) 130 is implemented, for example, using a large-scale integrated circuit (LSI) called a system-on-a-chip (SoC) in which a plurality of elements are integrated on a single chip. The main controller 130 includes an R / W channel 40, a hard disk controller (HDC) 50, and a microprocessor (MPU) 60. The main controller 130 is electrically connected to the VCM 16 and the SPM 12 via the driver IC 20. The HDC 50 can be connected to a host system (host) 100.
[0025] The R / W channel 40 is a signal processing circuit that reads and writes data. The HDC 50 controls data transfer between the host 100 and the R / W channel 40 according to an instruction from the MPU 60. The HDC 50 is electrically connected to the R / W channel 40, the MPU 60, the non-volatile memory 70, the volatile memory 80, and the buffer memory 90. In addition, the main controller 130 (HDC 50) and the non-volatile memory 70 may be connected via a wireless line.
[0026] The non-volatile memory 70 is a semiconductor memory that records the stored data even when the power supply is disconnected. In one example, the non-volatile memory 70 is a flash ROM (Flash Read Only Memory: FROM). The non-volatile memory 70 has a firmware area 71 that stores firmware and a key area 72 that stores keys. In one example, two pieces of firmware are stored in the firmware area 71.
[0027] In the non-volatile memory 70, different addresses are allocated to the key area 72 and the firmware area 71. In addition, the initial value of the key when manufacturing the disk device 1 is an inherent value, such as the serial number of the control circuit board (SerialNumber).
[0028] The volatile memory 80 is a semiconductor memory that loses the stored data when the power supply is disconnected. The volatile memory 80 stores data required for processing in each part of the disk device 1. The volatile memory 80 is, for example, a DRAM (Dynamic Random Access Memory), or an SDRAM (Synchronous Dynamic Random Access Memory).
[0029] The buffer memory 90 is a semiconductor memory that temporarily records data and the like transmitted and received between the disk device 1 and the host 100. In addition, the buffer memory 90 can be integrally formed with the volatile memory 80. The buffer memory 90 is, for example, a DRAM, an SRAM (Static Random Access Memory), an SDRAM, a FeRAM (Ferroelectric Random Access Memory), an MRAM (Magnetoresistive Random Access Memory), or the like.
[0030] The MPU 60 is the main control unit of the disk device 1, and executes control of read / write operations and servo control required for positioning the head 13. When performing a write operation, the MPU 60 controls the VCM 16 via the driver IC 20 in accordance with a command from the host 100 or the like, positions the head 13 at a predetermined position on the disk 11, and writes data.
[0031] When performing a read operation, the MPU 60 controls the VCM 16 via the driver IC 20 in accordance with a command from the host 100 or the like, positions the head 13 at a predetermined position on the disk 11, and reads data.
[0032] Here, the processing that the main controller 130 can perform will be described.
[0033] When the main controller 130 receives a firmware update command (FW update command) for updating the firmware in the firmware area 71 from the host 100, it can update the firmware by implementing a predetermined protocol (step) using the key.
[0034] The main controller 130 can read a key from the key area and program information containing the key into the key area. In addition, in the following description, "program" can be alternatively expressed as "store", "write", or "overwrite".
[0035] The main controller 130 can change the key read from the key area (referred to as the "first key") to a second key different from the first key.
[0036] The main controller 130 can generate the following key information, which is key information obtained by associating the update period, the number of updates, etc. received from the host 100 with the key.
[0037] The main controller 130 can copy one of the two firmware to the other.
[0038] The main controller 130 can determine whether the firmware in the firmware area 71 is normal for an arbitrary period. The above-mentioned arbitrary period is, for example, the period from the timing when the disk device 1 is started to the timing of the next start of the disk device 1. In addition, the above-mentioned arbitrary period can be appropriately changed according to a command from the user via the host 100.
[0039] When the firmware is abnormal, the main controller 130 can notify the user of information related to whether the firmware is normal via the host 100. Moreover, the main controller 130 can repair the firmware by copying the firmware determined to be normal to the firmware determined to be abnormal.
[0040] The disk device 1 is configured as described above.
[0041] Next, the process for updating the firmware will be described.
[0042] Figure 2 It is a flowchart showing the steps when updating the firmware. Figure 3 It is a block diagram for explaining the update of the firmware.
[0043] As Figure 2 and Figure 3 shown, when the main controller 130 receives a FW update command (S1a) from the host 100 and starts the process for updating the firmware, the main controller 130 reads a key (referred to as the "first key") from the key area 72 (S2a).
[0044] Next, the main controller 130 changes the first key to a second key different from the first key (S3a). More specifically, the main controller 130 adds a randomly generated random value α to the first key to change the first key to the second key. The random value α is, for example, a pseudo-random number or a random variable.
[0045] Next, the main controller 130 generates key information in which the information of the update time and the update frequency is associated with the second key (S4a). More specifically, the main controller 130 adds a time stamp of the update time and the update frequency to the end of the second key.
[0046] Then, the main controller 130 programs the key information into the key area 72 (S5a). In one example, when the key information is programmed into the key area 72, the firmware in the nonvolatile memory 70 outputs a notification signal to the main controller 130 notifying that the key information has been programmed.
[0047] Next, the main controller 130 determines whether the key information is programmed into the key area 72 (S6a). In one example, the main controller 130 determines whether the key information is programmed into the key area 72 based on whether the main controller 130 receives a notification signal.
[0048] In the case where it is determined that the key information is not programmed into the key area 72 (S6a), the main controller 130 moves to step S2a. Figure 2 Although not shown, when the determination is made as described above, the main controller 130 may end the process for updating the firmware.
[0049] When determining that the key information is programmed in the key area 72 ( S6a ), the main controller 130 enables the firmware update ( S7a ). More specifically, the main controller 130 sets the protection bit in the firmware area 71 to 0, thereby releasing the protection of the firmware area 71 .
[0050] Next, the main controller 130 updates the firmware according to the FW update command from the host 100 (S8a). Here, an example of the procedure of step S8a is described below.
[0051] The main controller 130 obtains information of one of the two firmwares (for example, the first firmware F1). Then, if the firmware is encrypted, the main controller 130 restores the firmware, updates the firmware according to the FW update command, and encrypts the updated firmware. Then, the main controller 130 sends the updated firmware to the firmware area 71.
[0052] Then, the main controller 130 duplicates the updated firmware ( S9 a ). More specifically, the main controller 130 copies one updated firmware (eg, the first firmware F1 ) to the other updated firmware (eg, the second firmware F2 ).
[0053] Next, the main controller 130 prohibits the update of the firmware (S10a), and ends the process for updating the firmware. More specifically regarding step S10a, the main controller 130 protects the firmware area 71 by setting the protection bit in the firmware area 71 to 1.
[0054] In addition, in the present embodiment, steps S3a and S4a may not be implemented. In this case, after the main controller 130 reads the first key from the key area 72 (S2a), the main controller 130 programs the key information including the second key identical to the first key into the key area 72 (S5a).
[0055] Alternatively, in the present embodiment, step S3a may not be implemented. In this case, after the main controller 130 reads the first key from the key area 72 (S2a), the main controller 130 generates key information associating the information of the update period with the second key identical to the first key (S4a).
[0056] Moreover, in the present embodiment, step S4a may not be implemented. In this case, after the main controller 130 changes the first key to a second key different from the first key (S3a), the main controller 130 programs the key information including the second key different from the first key into the key area 72 (S5a).
[0057] Next, the process of detecting and repairing the state of the firmware will be described.
[0058] Figure 4 FIG. is a flowchart showing an example of steps of a process of detecting and repairing the state of the firmware. Figure 5 is continued after Figure 4 FIG. is a flowchart showing an example of steps of a process of detecting and repairing the state of the firmware. Figure 6 is continued after Figure 4 FIG. is a flowchart showing an example of steps of a process of detecting and repairing the state of the firmware. Figure 7 FIG. is a block diagram for explaining the repair of the firmware in the case where one of the first firmware and the second firmware is normal and the other is abnormal.
[0059] As Figures 4 to 7 shown, when starting the process of detecting and repairing the state of the firmware, first, the main controller 130 detects the presence or absence of damage to the first firmware F1 and the second firmware F2 (S1b), and performs error correction on the codes of the first firmware F1 and the second firmware by ECC (Error Correction Code) (S2b). ECC is a method for correcting data errors. In addition, in step S2b, the error correction by ECC may also be implemented programmatically by the firmware in the firmware area 71.
[0060] Next, the main controller 130 determines whether the first firmware F1 is normal (S3b), and then determines whether the second firmware F2 is normal (S4b, S5b). In one example, the main controller 130 determines it is normal when no damage is detected in step S1b or error correction can be performed in step S2b. Additionally, the main controller 130 determines it is abnormal when damage is detected in step S1b and error correction cannot be performed in step S2b.
[0061] When it is determined that both the first firmware F1 and the second firmware F2 are normal (S3b, S4b), the main controller 130 proceeds to step S1b.
[0062] When it is determined that both the first firmware F1 and the second firmware F2 are abnormal (S3b, S5b), the main controller 130 notifies the user via the host 100 that the first firmware F1 and the second firmware F2 are abnormal (S6b), and ends the process of detecting and repairing the status of the firmware.
[0063] Regarding step S6b, more specifically, the main controller 130 issues an alarm indicating that both the first firmware F1 and the second firmware F2 cannot be corrected.
[0064] When it is determined that the first firmware F1 is abnormal (S3b) and the second firmware F2 is normal (S5b), the main controller 130 notifies the user via the host 100 that the first firmware F1 is abnormal (S7b). More specifically, the main controller 130 issues an alarm indicating that the first firmware F1 is damaged and the second firmware F2 is normal.
[0065] Next, the main controller 130 reads the second firmware F2 determined to be normal (S8b), and sets the protection bit to 0 to enable firmware update (S9b).
[0066] Next, the main controller 130 copies the second firmware F2 to the first firmware F1 (S10b), sets the protection bit to 1 to prohibit firmware update (S11b), and ends the process of detecting and repairing the status of the firmware.
[0067] When it is determined that the first firmware F1 is normal (S3b) and the second firmware F2 is abnormal (S4b), the main controller 130 notifies the user via the host 100 that the second firmware F2 is abnormal (S12b). More specifically, the main controller 130 issues an alarm indicating that the second firmware F2 is damaged and the first firmware F1 is normal.
[0068] Next, the main controller 130 reads the first firmware F1 determined to be normal (S13b), and sets the protection bit to 0 to enable firmware update (S14b).
[0069] Next, the main controller 130 copies the first firmware F1 to the second firmware F2 (S15b), sets the protection bit to 1 to prohibit firmware update (S16b), and ends the process of detecting and repairing the status of the firmware.
[0070] The effects of this embodiment will be described.
[0071] According to the disk device 1 according to this embodiment, when the main controller 130 reads the first key and programs the information including the second key, firmware update can be enabled. Thus, the firmware can be protected from unintended updates.
[0072] Moreover, the initial value of the key is the serial number of the control circuit board. Thus, the initial value of the key can be set to an inherent value different from that of other disk devices.
[0073] The main controller 130 changes the first key to a second key different from the first key. Thus, the protection performance of the firmware can be improved.
[0074] The main controller 130 generates key information associating the information of the update period with the second key. Thus, it can be determined whether the firmware update is intended.
[0075] By using the above configuration of the key, the security level of the firmware can be improved, and it can be suppressed that the firmware becomes abnormal due to an unintended update.
[0076] The main controller 130 determines whether the first firmware F1 and the second firmware F2 are normal. When it is determined that at least one of the first firmware F1 and the second firmware F2 is abnormal, information related to whether the first firmware F1 and the second firmware F2 are normal is notified to the user. Thus, the user can identify the abnormality of the firmware.
[0077] The main controller 130 determines whether the firmware is normal based on error correction and breakage detection by ECC. Moreover, error correction and breakage detection by ECC can be performed at an arbitrary interval. Thus, it can be determined whether the firmware is normal at an interval desired by the user.
[0078] When the main controller 130 determines that one of the two firmwares is normal and the other is abnormal, it copies the firmware determined to be normal to the firmware determined to be abnormal. Thus, even if one of the firmwares is broken, the firmware can be automatically repaired.
[0079] In summary, through the above configuration, a disk device 1 that can maintain the firmware in a normal state and has high reliability can be obtained.
[0080] Although the embodiments of the present invention have been described, the above-described embodiments are presented as examples and are not intended to limit the scope of the invention. The above novel embodiments can be implemented in various other ways, and various omissions, substitutions, and changes can be made without departing from the gist of the invention. The above embodiments and their modifications are included in the scope and gist of the invention and are included in the invention described in the claims and its equivalents.
Claims
1. A magnetic disk device comprising: a nonvolatile memory having a firmware area storing firmware and a key area storing a first key; and The controller enables the firmware to be updated when the first key is read from the key area and information including the second key is programmed into the key area.
2. The magnetic disk device according to claim 1, The controller is configured as a control circuit substrate. The first key is a serial number of the control circuit board.
3. The magnetic disk device according to claim 1, The controller changes the first key to the second key different from the first key.
4. The magnetic disk device according to claim 1, The controller generates key information in which information on the update time of the firmware is associated with the second key.
5. A magnetic disk device comprising: Host, operated by the user; The nonvolatile memory has a firmware area storing the first firmware and the second firmware; as well as The controller determines whether the first firmware and the second firmware are normal at an arbitrary period, and when it is determined that at least one of the first firmware and the second firmware is abnormal, notifies the user via the host of information related to whether the first firmware and the second firmware are normal.
6. The magnetic disk device according to claim 5, the controller, performing error correction by ECC and detecting the presence or absence of damage on the first firmware and the second firmware at an arbitrary period, If the error can be corrected or there is no damage, it is considered normal. If error correction cannot be performed and there is damage, it is judged to be abnormal.
7. The magnetic disk device according to claim 5, The controller copies the first firmware to the second firmware when it is determined that the first firmware is normal and the second firmware is abnormal.