Double-Bootloader self-updating method, device and equipment and storage medium

Through the BootM component of Bootloader's BootM component detects update instructions and sets the jump flag, the problem that dual Bootloaders cannot be updated simultaneously in the existing technology is solved, and the automatic update of dual Bootloaders is realized, which reduces the risk of controller paralysis and improves the stability and reliability of the system.

CN120215985APending Publication Date: 2025-06-27BEIJING JINGWEI HIRAIN TECH CO INC
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510345020.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-21
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

In the existing Bootloader upgrade method, both levels of Bootloaders cannot be updated at the same time, and there is a risk of controller paralysis, resulting in the device not being able to operate normally.

Method used

The BootM component of the bootloader Bootloader performs update instruction detection, sets the jump flag, judges and prepares to enter the corresponding Bootloader update process, ensures that both Bootloaders can be updated and reduces the risk of controller paralysis.

Benefits of technology

Automatic updates of dual Bootloaders have been realized, which improves system stability and reliability, reduces maintenance costs, and reduces the risk of controller paralysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120215985A_ABST
    Figure CN120215985A_ABST
Patent Text Reader

Abstract

The invention provides a double-Bootloader self-updating method and device, equipment and a storage medium, and relates to the technical field of automobile software control, and the method comprises the steps: enabling the equipment to recognize and execute an updating operation at the initial stage of starting through an updating instruction detection function of a BootM assembly, and when a detection result contains an updating instruction, executing the updating operation at the initial stage of starting; and the updating process is ensured to be carried out orderly by setting the value of the jump flag bit. And if the update instruction is not included, the BootM judges and prepares to enter a corresponding Bootloader update process according to the current value of the jump flag bit. And by introducing a reprogramming effective mark BootM, the validity and security of updating can be further ensured during updating. By means of the method, automatic updating of double Bootloaders in the equipment starting process can be achieved according to the actual situation, the stability and reliability of the system are improved, meanwhile, the maintenance cost is reduced, and better use experience is brought to a user.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of automotive software control, and particularly to a dual Bootloader self-update method, device, equipment, and storage medium. Background Art

[0002] Bootloader (Boot) is the first piece of code executed after the device is powered on, used to complete functions such as device hardware initialization, preparing the software environment, stack initialization, and application self-check, and then jumps to the application running address to start the application. For example, the main task of the Bootloader in an automotive electronic control unit (ECU) is to load, update, or upgrade the software (usually embedded software) of the ECU when the vehicle starts to ensure the normal operation and performance of the vehicle system. In some cases, such as to improve device performance, fix errors, add new functions, or meet specific system requirements, it is necessary to upgrade the Bootloader. However, during the Bootloader firmware upgrade process, if certain uncertain factors cause the Bootloader firmware upgrade to fail, the device will become unusable, thus bringing significant economic losses to users.

[0003] In existing Boot upgrade methods, common methods include the single-stage Boot self-update method and the dual Boot update method. For the single-stage Boot self-update method, if power is lost during the update process, the original Boot will not be able to run normally, and the system will jump to the Boot update program to update the Boot again; if there is a problem with this update program, the Boot cannot be successfully updated, which will cause the controller to crash and only the program can be rewritten; while the disadvantage of the dual Boot update scheme is that the single-stage Boot itself cannot be updated. When the single-stage Boot fails to write the second-stage Boot during the refresh process, it is necessary to try to write Boot2 again. If there is a problem with the written file, it will cause the controller to crash and cannot run normally.

[0004] Therefore, how to obtain a Boot update method in which both two-stage Boots can be updated and the risk of controller paralysis can be reduced is a problem that needs to be solved currently. Summary of the Invention

[0005] In view of the above problems, this application provides a dual Bootloader self-update method, including the following content:

[0006] In a first aspect, this application provides a dual Bootloader self-update method, which includes:

[0007] After the device is powered on, the BootM component of the Bootloader checks for update instructions to obtain a detection result;

[0008] If the update instruction is included in the detection result, set the value of the jump flag bit to the first flag bit value; the value of the jump flag bit is used to indicate the Bootloader that the device specifically updates after power-on;

[0009] If the update instruction is not included in the detection result, judge the value of the jump flag bit;

[0010] When the value of the jump flag bit is the first flag bit value, prepare to enter the first Bootloader update;

[0011] When the value of the jump flag bit is the second flag bit value, prepare to enter the second Bootloader update;

[0012] When entering the first Bootloader update, update in the first Bootloader according to the value of the reprogramming valid flag;

[0013] When entering the second Bootloader update, update in the second Bootloader according to the value of the reprogramming valid flag.

[0014] Optionally, before entering the first Bootloader update, the method further includes:

[0015] Reset the value of the jump flag bit;

[0016] Check the validity flag of the first Bootloader. If the validity flag represents valid, jump to the first Bootloader;

[0017] If the validity flag represents invalid, check the validity flag of the second Bootloader;

[0018] If the validity flag represents that the second Bootloader is valid, jump to the second Bootloader;

[0019] If the validity flag represents that the second Bootloader is also invalid, enter an infinite loop loop.

[0020] Optionally, before entering the second Bootloader update, the method further includes:

[0021] Check the validity flag of the second Bootloader. If the validity flag represents valid, jump to the second Bootloader;

[0022] If the validity flag represents invalid, check the validity flag of the first Bootloader;

[0023] If the validity flag represents that the first Bootloader is valid, jump to the first Bootloader;

[0024] If the validity flag represents that the first Bootloader is also invalid, enter an infinite loop loop.

[0025] Optionally, updating in the first Bootloader according to the value of the reprogramming validity flag includes:

[0026] Check the reprogramming validity flag. If the reprogramming validity flag represents invalid, further check the validity flag of the APP;

[0027] If the validity flag of the APP represents valid, check whether an instruction message representing staying in the current Bootloader is received; if received, stay in the first Bootloader; if not received, jump to the APP;

[0028] When staying in the first Bootloader, it is possible to choose to update the APP or update the second Bootloader; after the update is completed, reset the first flag bit.

[0029] Optionally, updating in the second Bootloader according to the value of the reprogramming validity flag includes:

[0030] Check the reprogramming validity flag. If the reprogramming validity flag represents invalid, further check the validity flag of the APP;

[0031] If the validity flag of the APP represents valid, check whether an instruction message representing staying in the current Bootloader is received; if received, stay in the second Bootloader; if not received, jump to the APP;

[0032] When staying in the second Bootloader, it is possible to choose to update the APP or update the first Bootloader; after the update is completed, reset the first flag bit.

[0033] In a second aspect, the present application provides a dual Bootloader self-update device, and the device includes:

[0034] A detection unit, configured to, after the device is powered on, detect an update instruction of the BootM component of the bootloader Bootloader to obtain a detection result;

[0035] A setting unit, configured to set the value of a jump flag bit to a first flag bit value if the update instruction exists in the detection result; the value of the jump flag bit is used to indicate the Bootloader that the device specifically updates after power-on.

[0036] A judgment unit, configured to judge the value of the jump flag bit if the update instruction does not exist in the detection result; when the value of the jump flag bit is the first flag bit value, prepare to enter the first Bootloader update; when the value of the jump flag bit is the second flag bit value, prepare to enter the second Bootloader update.

[0037] An update unit, configured to perform an update in the first Bootloader according to the value of a reprogramming valid flag when entering the first Bootloader update; and perform an update in the second Bootloader according to the value of the reprogramming valid flag when entering the second Bootloader update.

[0038] Optionally, the device further includes a reset unit, configured to reset the value of the jump flag bit before entering the first Bootloader update.

[0039] An inspection unit, configured to inspect the validity flag of the first Bootloader; if the validity flag represents valid, jump to the first Bootloader; if the validity flag represents invalid, inspect the validity flag of the second Bootloader; if the validity flag represents that the second Bootloader is valid, jump to the second Bootloader; if the validity flag represents that the second Bootloader is also invalid, enter an infinite loop loop.

[0040] Optionally, the inspection unit is further configured to inspect the validity flag of the second Bootloader; if the validity flag represents valid, jump to the second Bootloader; if the validity flag represents invalid, inspect the validity flag of the first Bootloader; if the validity flag represents that the first Bootloader is valid, jump to the first Bootloader; if the validity flag represents that the first Bootloader is also invalid, enter an infinite loop loop.

[0041] Optionally, the update unit performing an update in the first Bootloader according to the value of the reprogramming valid flag includes:

[0042] Inspect the reprogramming valid flag; if the reprogramming valid flag represents invalid, further inspect the validity flag of the APP.

[0043] If the validity flag of the APP represents valid, check whether an instruction message representing staying in the current Bootloader is received; if received, stay in the first Bootloader; if not received, jump to the APP;

[0044] When staying in the first Bootloader, it is possible to select to update the APP or update the second Bootloader; after the update is completed, reset the first flag bit.

[0045] Optionally, the update unit performs an update in the second Bootloader according to the value of the reprogramming validity flag, including:

[0046] Check the reprogramming validity flag. If the reprogramming validity flag represents invalid, further check the validity flag of the APP;

[0047] If the validity flag of the APP represents valid, check whether an instruction message representing staying in the current Bootloader is received; if received, stay in the second Bootloader; if not received, jump to the APP;

[0048] When staying in the second Bootloader, it is possible to select to update the APP or update the first Bootloader; after the update is completed, reset the first flag bit.

[0049] In a third aspect, the present application provides a device, the device includes a memory and a processor, the memory is used to store instructions or codes, and the processor is used to execute the instructions or codes so that the device executes the dual Bootloader self-update method introduced in any implementation manner of the foregoing first aspect.

[0050] In a fourth aspect, the present application provides a computer-readable storage medium, in which codes are stored. When the codes are run, the device running the codes implements the dual Bootloader self-update method introduced in any implementation manner of the foregoing first aspect.

[0051] This application provides a dual Bootloader self-update method. First, through the update instruction detection function of the BootM component, the device can identify and execute the update operation at the initial stage of startup, thus improving the flexibility and adaptability of the system. When the detection result contains an update instruction, by setting the value of the jump flag bit, BootM can accurately instruct the device to update a specific Bootloader, ensuring the orderly progress of the update process. At the same time, if the detection result does not contain an update instruction, BootM will judge and prepare to enter the corresponding Bootloader update process according to the current value of the jump flag bit. This design enables the system to flexibly select the update path according to different situations. In addition, by introducing a reprogramming valid flag, BootM can further ensure the effectiveness and security of the Bootloader update when performing the Bootloader update. Only when the value of the reprogramming valid flag meets specific conditions will the first Bootloader or the second Bootloader update operation be executed. On the one hand, this avoids system problems caused by misoperations or invalid instructions, and on the other hand, it can achieve the update of the dual Bootloader. Through this method, the dual Bootloader during the device startup process can be automatically updated according to the actual situation, improving the stability and reliability of the system, reducing the maintenance cost at the same time, and bringing a better user experience. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] To more clearly illustrate the technical solutions in the embodiments or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of this application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0053] Figure 1 It is a flowchart of a dual Bootloader self-update method provided by an embodiment of this application;

[0054] Figure 2 It is a schematic diagram of the memory distribution of a dual Bootloader provided by an embodiment of this application;

[0055] Figure 3 It is a schematic diagram of a dual Bootloader update scenario provided by an embodiment of this application;

[0056] Figure 4 It is a schematic diagram of the structure of a dual Bootloader self-update device provided by an embodiment of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0057] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the following will clearly and completely describe the technical solutions in the embodiments of this application with reference to the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part rather than all of the embodiments of this application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts shall fall within the scope of protection of this application.

[0058] Figure 1 It is a flowchart of a dual Bootloader self-update method provided for the embodiments of this application. In combination with Figure 1 As shown, the dual Bootloader self-update method provided for the embodiments of this application may include:

[0059] S101. After the device is powered on, the BootM component of the bootloader Bootloader detects the update instruction to obtain a detection result.

[0060] As the first piece of code executed after the device is powered on, Bootloader is used to complete functions such as device hardware initialization, preparation of the software environment, stack initialization, and self-check of the application program, and then jumps to the application program running address to start the application program.

[0061] After the system starts, the code running program will enter BootM. As a part of the bootloader, BootM is responsible for managing and controlling some key operations during the startup process. After the code running program enters BootM, the program will execute a series of initialization tasks to ensure that the hardware is in the correct state and prepare for subsequent software loading. After the initialization is completed, BootM will detect whether an update instruction is received and continue subsequent operations based on whether there is an update instruction. The jump flag bit can be specifically set according to the update instruction to implement the selection of subsequent update functions.

[0062] Figure 2 It is a schematic diagram of the memory address distribution of a dual Bootloader provided for the embodiments of this application. Figure 2 The specific flash memory partition diagram of the dual Boot is given, where the BootM module is mainly responsible for managing the firmware startup information and judging the jump area. Bootloader1 and Bootloader2 are independent of each other and both have the functions of mutually flashing, flashing the application software (App), and jumping to the App. The last area is the area divided for the application software (App).

[0063] S102. If the update instruction exists in the detection result, set the value of the jump flag bit to the first flag bit value.

[0064] The value of the first flag bit, Goto_BT1_Flag, can be set to 1, that is, after receiving the update instruction, the value of the jump flag bit is directly set.

[0065] The value of the jump flag bit is used to indicate which Bootloader to specifically update after the device is powered on. For example, when the value of the jump flag bit is 1, it is ready to jump to the first Bootloader, that is, Boot1 is ready to perform subsequent updates. Otherwise, Goto_BT1_Flag defaults to 0, and it is ready to jump to the second Bootloader, that is, Boot2 is ready to perform subsequent updates.

[0066] S103. If the update instruction is not present in the detection result, judge the value of the jump flag bit.

[0067] When the update instruction is present in the detection result, the value of the jump flag bit is directly set. It can be understood that when the update instruction is not present in the detection result, the value of the jump flag bit needs to be further judged according to the actual situation, that is, judge whether the value of the jump flag bit is 1 or 0, so as to further determine whether to jump to the first Bootloader or prepare to jump to the second Bootloader for subsequent updates.

[0068] S104. When the value of the jump flag bit is the value of the first flag bit, prepare to enter the first Bootloader update.

[0069] In one implementation manner of the embodiment of the present application, when it is detected that the value of the jump flag bit is 1, it is considered to jump to the first Bootloader for subsequent updates.

[0070] S105. When the value of the jump flag bit is the value of the second flag bit, prepare to enter the second Bootloader update.

[0071] In one implementation manner of the embodiment of the present application, when it is detected that the value of the jump flag bit is 0, it is considered to jump to the second Bootloader for subsequent updates.

[0072] It can be understood that the corresponding update of the first Bootloader or the second Bootloader according to the value of the jump flag bit can be set by those skilled in the art according to the actual situation. The setting scheme in the embodiment of the present application is only exemplary. That is, the values of the first flag bit and the second flag bit are not uniquely fixed. In one implementable manner, the value of the first flag bit can be 0, and the value of the second flag bit can be 1.

[0073] S106. When entering the update of the first Bootloader, perform the update in the first Bootloader according to the value of the reprogramming valid flag.

[0074] The value of the reprogramming valid flag is used to further determine whether the update can be successfully performed. That is, when the value of the reprogramming valid flag represents invalid, the relevant functions cannot be updated. For example, when entering the update of the first Bootloader, if the value of the reprogramming valid flag represents valid, the first Bootloader can be updated; otherwise, other functions need to be judged and updated.

[0075] Performing the update in the first Bootloader according to the value of the reprogramming valid flag specifically includes: checking the reprogramming valid flag. If the reprogramming valid flag represents invalid, further check the validity flag of the APP. If the validity flag of the APP represents valid, check whether an instruction message representing staying in the current Bootloader is received. If received, stay in the first Bootloader. If not received, jump to the APP. When staying in the first Bootloader, the APP or the second Bootloader can be selected for update. After the update is completed, reset the first flag bit.

[0076] After entering the Boot1 update, first check the reprogramming valid flag. The value of the reprogramming valid flag can be set to 1 or 0. Specifically, it can be set that when the value of the reprogramming valid flag is 1, it means valid, and when it is 0, it means invalid. Then, judge whether the reprogramming valid flag represents invalid or valid according to the specific value, so as to judge the validity. After the judgment is completed, that is, after choosing to update the APP or the second Bootloader, it is necessary to reset the value of the reprogramming valid flag to facilitate the judgment before the next update. The reprogramming valid flag is used to indicate that the software stays in the Boot and starts the flashing function. If it is valid, it stays in Boot1. If the reprogramming valid flag represents invalid, further check the validity of the APP. The checking method is the same as the method for checking the validity of the Boot, and both are realized by judging the validity flag. If the APP is invalid, it stays in Boot1. If the APP is valid, further check whether the Stay in Boot message is received. This message is used to indicate that the software stays in the corresponding Boot, and its function is the same as that of the reprogramming valid flag. When there is no reprogramming flag bit and the APP function is incorrect but the APP is valid, the user hopes to stay in the Boot to update the APP. Since the APP function is incorrect, the reprogramming flag bit cannot be set to valid. At this time, the user can send the Stay in Boot message to make the software stay in the Boot and flash the APP. If the Stay in Boot message is received, stay in Boot1, otherwise jump to the APP. If staying in Boot1, at this time, you can choose to update the APP or Boot2, and then reset.

[0077] Before entering the update of the first Bootloader, the method further includes:

[0078] Reset the value of the jump flag bit; check the validity flag of the first Bootloader. If the validity flag represents valid, jump to the first Bootloader; if the validity flag represents invalid, check the validity flag of the second Bootloader; if the validity flag represents that the second Bootloader is valid, jump to the second Bootloader; if the validity flag represents that the second Bootloader is also invalid, then enter an infinite loop loop.

[0079] Before entering the update of the first Bootloader, it is stated that the jump flag bit is already the first flag bit. Before jumping to Boot1, the Goto_BT1_Flag needs to be reset to avoid the situation where it cannot default to Boot2 after the next power-on. Subsequently, the validity of Boot1 is checked. Validity check is a common function in most Boot jump functions in the current market. After the flashing is completed, some security algorithms are used to check the software validity, and a flag bit is set to indicate whether the software is valid. Before jumping to the software, the validity of the software to be jumped is judged by checking this flag bit, which can prevent the system from malfunctioning due to the invalidity of the software to be jumped. However, when the validity flags of both the first Bootloader and the second Bootloader represent invalid, it enters an infinite loop (loop). In this case, neither of the dual Boot can run, which can be regarded as the controller being paralyzed. At this time, the software needs to be reprogrammed. It can be understood that the situation of entering the loop only occurs when there is only one BootM and both dual Boots are invalid. Since the dual Boots can be flashed to each other, theoretically, it will not enter the loop when one Boot is successfully burned.

[0080] S107. When entering the update of the second Bootloader, update in the second Bootloader according to the value of the reprogramming validity flag.

[0081] When entering the update of the second Bootloader, if the value of the reprogramming validity flag represents valid, the second Bootloader can be updated; otherwise, other functions need to be judged and updated.

[0082] In an implementation method of the embodiment of the present application, updating in the second Bootloader according to the value of the reprogramming validity flag includes: checking the reprogramming validity flag. If the reprogramming validity flag represents invalid, further check the validity flag of the APP; if the validity flag of the APP represents valid, check whether an instruction message representing staying in the current Bootloader is received; if received, stay in the second Bootloader; if not received, jump to the APP; when staying in the second Bootloader, the APP or the first Bootloader can be selected for update; after the update is completed, the first flag bit is reset.

[0083] The value of the reprogramming valid flag can be set to 1 or 0. Specifically, it can be set such that when the value of the reprogramming valid flag is 1, it indicates validity, and when it is 0, it represents invalidity. Then, based on the specific value, it is determined whether the reprogramming valid flag represents invalidity or validity, thereby determining the validity. After the determination is completed, that is, after choosing to update the APP or update the first Bootloader, the value of the reprogramming valid flag needs to be reset to facilitate the determination before the next update.

[0084] When entering the update of the second Bootloader, first check the reprogramming validity. If it is valid, stay in Boot2. If the reprogramming valid flag is found to be invalid, further check the APP validity. If the APP is invalid, stay in Boot2. If the APP is valid, check whether the Stay in Boot message is received. If the Stay in Boot message is received, stay in Boot2; otherwise, jump to the APP. If staying in Boot2, at this time, it is possible to choose to update the APP or Boot1, and then the value of the reprogramming valid flag is reset.

[0085] In an implementation method of the embodiment of the present application, before entering the update of the second Bootloader, the method further includes:

[0086] Check the validity flag of the second Bootloader. If the validity flag represents validity, jump to the second Bootloader; if the validity flag represents invalidity, check the validity flag of the first Bootloader; if the validity flag represents that the first Bootloader is valid, jump to the first Bootloader; if the validity flag represents that the first Bootloader is also invalid, then enter an infinite loop loop.

[0087] After entering the App update, under normal operation, if the first programming instruction, such as 1002, is received, enter the programming session instruction, set the reprogramming valid bit, and perform a reset. If the second programming instruction, such as 10 04, is received, set the Goto_BT1_Flag to 1, set the reprogramming valid bit, and perform a reset.

[0088] In the case of initial burning of BootM and entering a Boot, the dual Bootloader self-update method in the present application can update the dual Boot and the App through the Boot mutual flashing function, and at least ensure the validity of one Boot, thereby reducing the risk of controller paralysis.

[0089] The above specifically introduced a dual Bootloader self-update method provided by the present application. Next, in combination with Figure 3Introduce various application scenarios of the dual Bootloader self-update method provided in this application:

[0090] Figure 3 This is a schematic diagram of a dual Bootloader update scenario provided by an embodiment of this application. Figure 3 In a, it shows the scenario when BootM and Boot1 are initially burned. In this scenario, BootM will jump to Boot1; then in Boot1, Boot2 can be flashed.

[0091] Burning of BootM: BootM is usually the first code burned onto the device because it is responsible for the initial hardware initialization and boot process of the system. BootM is responsible for determining which Bootloader (such as Boot1 or Boot2) to load next. This decision may be based on the device's hardware configuration, specific pin states, or other conditions.

[0092] BootM jumps to Boot1:

[0093] Once BootM has completed the basic hardware initialization and checks, it will decide which Bootloader to jump to according to preset conditions or configurations.

[0094] In this scenario, BootM will jump to Boot1 because Boot1 is the preset main Bootloader for loading and starting the main application (APP). The jump operation usually involves setting specific processor registers or jump instructions to make the processor start executing the code of Boot1.

[0095] Flashing Boot2 in Boot1: After Boot1 starts, it is responsible for loading and starting the main application (APP), but it can also provide additional functions such as Bootloader updates. If Boot2 needs to be updated (for example, to fix errors in Boot2 or add new functions), this operation can be performed in Boot1.

[0096] This scenario provides a flexible Bootloader update mechanism, enabling easy error repair, new function addition, or performance improvement after device deployment. At the same time, it also requires developers to carefully design and manage the Bootloader update process to ensure system stability and security.

[0097] Scenario where both Boot1 and Boot2 exist is shown in b. In this case, when there is no valid application software, BootM defaults to jump to Boot2; Boot2 can update Boot1, which solves the problem that the mainstream dual - Boot update solution in the market cannot update Boot1 through Boot2.

[0098] Scenario when both Boot1 and Boot2 exist is shown in c. In this scenario, after the system is powered on, BootM starts and executes. Since there is no valid application software, BootM defaults to jump to Boot2. In Boot2, APP can be flashed; the user can enter the programming session and perform a reset by sending diagnostic message 10 02. After the reset, BootM jumps to Boot2, so that APP or Boot1 can be re - flashed in Boot2.

[0099] Scenario where both Boot1 and Boot2 exist is shown in d. The user can enter the Boot1 programming session by sending diagnostic message 10 04. After receiving the 10 04 message and resetting, BootM will jump to Boot1, so that APP or Boot2 can be re - flashed in Boot1; by receiving different diagnostic messages, the user can choose to update different Boots. For example, sending message 10 04 means requesting to enter Boot1, and sending message such as 10 05, BootM will jump to the address of Boot2 and perform an update. In the corresponding Bootloader, the user can re - flash APP, Boot1 or Boot2.

[0100] Scenario where both Boot1 and Boot2 exist and there is no App is shown in e. Since it is set in this application that BootM defaults to jump to Boot2, in this case, if the user needs to update Boot2 or the user needs to update App through Boot1, a Command message can be sent through the bus at startup to force BootM to jump to Boot1 and update App in Boot1.

[0101] In this application, the judgment process of entering Boot1 or Boot2 is completed in BootM. The flag bit Goto_BT1_Flag is used, and its default value is 0, which means that the system defaults to jump to Boot2 after power-on. Additionally, when BootM starts, it will detect whether it receives a Command instruction. If it receives the instruction, Goto_BT1_Flag is set to 1, and after startup, BootM will jump to Boot1. This dual Bootloader architecture is usually used to provide a system recovery mechanism. When one Bootloader is damaged, the other Bootloader can be used to recover the system. In addition, it can also be used to update the Bootloader itself without the need for additional hardware tools.

[0102] The method in the above embodiments of this application has at least the following beneficial effects:

[0103] 1. Based on the dual Boot mutual update mechanism in this application, the dual Boot mutual update mechanism can also improve the security of the system, ensuring that at least one Boot is valid and effectively reducing the risk of controller paralysis.

[0104] 2. This application also provides more flexible control power for controller suppliers, enabling them to maintain the Boot1 version and update the Boot2 version when needed to meet the requirements of different OEMs (Original Equipment Manufacturers), that is, customers who choose to entrust other manufacturers to manufacture their own products or product components. This design that comprehensively considers security and flexibility makes the dual Boot mutual update mechanism a more reliable, secure, and adaptable solution.

[0105] 3. This application has advantages in meeting the needs of different OEM customers. For different customers, the Boot2 version can be customized according to their specification requirements, thus meeting the needs of different markets and application scenarios. At the same time, it adapts to the scenario of updating the OEM version Boot2 after-sales, providing more comprehensive services and support.

[0106] The above are some specific implementation manners of a dual Bootloader self-update method provided by the embodiments of this application. Based on this, this application also provides a corresponding device. Next, the device provided by the embodiments of this application will be introduced from the perspective of functional modularization.

[0107] Figure 4 It is a schematic structural diagram of a dual Bootloader self-update device provided by the embodiments of this application. Combining Figure 4 As shown, the dual Bootloader self-update device 400 provided by the embodiments of this application includes:

[0108] The detection unit 410 is configured to, after the device is powered on, detect update instructions of the BootM component of the bootloader and obtain a detection result;

[0109] The setting unit 420 is configured to, if the update instruction exists in the detection result, set the value of the jump flag bit to a first flag bit value; the value of the jump flag bit is used to indicate which bootloader the device specifically updates after being powered on;

[0110] The judgment unit 430 is configured to, if the update instruction does not exist in the detection result, judge the value of the jump flag bit; when the value of the jump flag bit is the first flag bit value, prepare to enter the first bootloader update; when the value of the jump flag bit is the second flag bit value, prepare to enter the second bootloader update;

[0111] The update unit 440 is configured to, when entering the first bootloader update, perform an update in the first bootloader according to the value of the reprogramming valid flag; when entering the second bootloader update, perform an update in the second bootloader according to the value of the reprogramming valid flag.

[0112] In an implementation method of an embodiment of the present application, the device further includes a reset unit configured to reset the value of the jump flag bit before entering the first bootloader update;

[0113] The check unit is configured to check the validity flag of the first bootloader. If the validity flag represents valid, jump to the first bootloader; if the validity flag represents invalid, check the validity flag of the second bootloader; if the validity flag represents that the second bootloader is valid, jump to the second bootloader; if the validity flag represents that the second bootloader is also invalid, enter an infinite loop loop.

[0114] In an implementation method of an embodiment of the present application, the check unit is further configured to check the validity flag of the second bootloader. If the validity flag represents valid, jump to the second bootloader; if the validity flag represents invalid, check the validity flag of the first bootloader; if the validity flag represents that the first bootloader is valid, jump to the first bootloader; if the validity flag represents that the first bootloader is also invalid, enter an infinite loop loop.

[0115] In an implementation method of an embodiment of the present application, the update unit updates in the first Bootloader according to the value of the reprogramming valid flag, including:

[0116] Check the reprogramming valid flag. If the reprogramming valid flag represents invalid, further check the validity flag of the APP. If the validity flag of the APP represents valid, check whether an instruction message representing staying in the current Bootloader is received. If received, stay in the first Bootloader. If not received, jump to the APP. When staying in the first Bootloader, the APP or the second Bootloader can be selected for update. After the update is completed, reset the first flag bit.

[0117] In an implementation method of an embodiment of the present application, the update unit updates in the second Bootloader according to the value of the reprogramming valid flag, including:

[0118] Check the reprogramming valid flag. If the reprogramming valid flag represents invalid, further check the validity flag of the APP;

[0119] If the validity flag of the APP represents valid, check whether an instruction message representing staying in the current Bootloader is received. If received, stay in the second Bootloader. If not received, jump to the APP;

[0120] When staying in the second Bootloader, the APP or the first Bootloader can be selected for update. After the update is completed, reset the first flag bit.

[0121] The embodiment of the present application also provides a corresponding device and a computer storage medium for implementing the solution provided by the embodiment of the present application.

[0122] Among them, the device includes a memory and a processor. The memory is used to store instructions or codes, and the processor is used to execute the instructions or codes so that the device executes the method described in any embodiment of the present application.

[0123] The computer storage medium stores codes. When the codes are run, the device running the codes implements the method described in any embodiment of the present application.

[0124] As can be seen from the description of the above embodiments, those skilled in the art can clearly understand that all or part of the steps in the above-described embodiment methods can be implemented by means of software plus a general hardware platform. Based on such an understanding, the technical solution of the present application can be embodied in the form of a software product, and this computer software product can be stored in a storage medium, such as a read-only memory (ROM) / RAM, magnetic disk, optical disk, etc., including several instructions for causing a computer device (which can be a personal computer, a server, or a network communication device such as a router) to execute the methods described in various embodiments or certain parts of the embodiments of the present application.

[0125] It should be noted that, in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the phrase "including a..." does not exclude the existence of additional identical elements in the process, method, article or device including the said element.

[0126] It should also be noted that the various embodiments in this specification are described in a progressive manner, and the same or similar parts between the various embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the device and apparatus embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiments. The device and apparatus embodiments described above are only illustrative. The units described as separate components may or may not be physically separated, and the components indicated as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative effort.

[0127] The above is only a specific embodiment of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed in the present application should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A dual Bootloader self-update method, characterized in that: The method comprises: When the device is powered on, the BootM component of the bootloader performs update instruction detection and obtains the detection result; If the detection result contains the update instruction, the value of the jump flag is set to the first flag value; the value of the jump flag is used to indicate the Bootloader to be updated after the device is powered on; If the detection result does not contain the update instruction, judging the value of the jump flag bit; When the value of the jump flag is the first flag value, preparing to enter the first Bootloader update; When the jump flag value is the second flag value, prepare to enter the second Bootloader update; When entering the first Bootloader update, updating is performed in the first Bootloader according to the value of the reprogramming valid flag; When entering the second Bootloader update, the second Bootloader is updated according to the value of the reprogramming valid flag.

2. The method according to claim 1, characterized in that Before entering the first Bootloader update, the method further includes: Resetting the value of the jump flag bit; Check the validity flag of the first Bootloader, and if the validity flag indicates validity, jump to the first Bootloader; If the validity flag indicates invalid, checking the validity flag of the second Bootloader; If the validity flag indicates that the second Bootloader is valid, jump to the second Bootloader; If the validity flag indicates that the second Bootloader is also invalid, an infinite loop is entered.

3. The method according to claim 1, characterized in that: Before entering the second Bootloader update, the method further includes: Check the validity flag of the second Bootloader, and if the validity flag indicates validity, jump to the second Bootloader; If the validity flag indicates invalid, checking the validity flag of the first Bootloader; If the validity flag indicates that the first Bootloader is valid, jump to the first Bootloader; If the validity flag indicates that the first Bootloader is also invalid, an infinite loop is entered.

4. The method according to claim 1, characterized in that: The update in the first Bootloader according to the value of the reprogramming valid flag includes: Check the reprogramming validity flag, if the reprogramming validity flag indicates invalid, further check the validity flag of the APP; If the validity flag of the APP indicates validity, check whether a command message indicating staying in the current Bootloader is received; if received, stay in the first Bootloader; if not received, jump to the APP; When staying in the first Bootloader, you can choose to update the APP or update the second Bootloader; after completing the update, reset the first flag.

5. The method according to claim 1, characterized in that The update in the second Bootloader according to the value of the reprogramming valid flag includes: Check the reprogramming validity flag, if the reprogramming validity flag indicates invalid, further check the validity flag of the APP; If the validity flag of the APP indicates validity, check whether a command message indicating staying in the current Bootloader is received; if received, stay in the second Bootloader; if not received, jump to the APP; When staying in the second Bootloader, you can choose to update the APP or update the first Bootloader; after completing the update, reset the first flag.

6. A dual Bootloader self-update device, characterized in that: The device comprises: The detection unit is used for, when the device is powered on, the BootM component of the bootloader performs update instruction detection to obtain a detection result; A setting unit, configured to set the value of a jump flag bit to a first flag bit value if the detection result contains the update instruction; the value of the jump flag bit is used to indicate the Bootloader to be updated after the device is powered on; A judgment unit, configured to judge the value of a jump flag bit if the detection result does not contain the update instruction; when the value of the jump flag bit is the first flag bit value, prepare to enter the first Bootloader update; when the value of the jump flag bit is the second flag bit value, prepare to enter the second Bootloader update; The update unit is used to update the first Bootloader according to the value of the reprogramming valid flag when entering the first Bootloader for update; and to update the second Bootloader according to the value of the reprogramming valid flag when entering the second Bootloader for update.

7. The device according to claim 6, characterized in that The device further comprises a reset unit, configured to reset the value of the jump flag bit before entering the first Bootloader update; A checking unit, configured to check a validity flag of the first Bootloader, and if the validity flag indicates validity, jump to the first Bootloader; if the validity flag indicates invalid, check a validity flag of the second Bootloader; If the validity flag indicates that the second Bootloader is valid, jump to the second Bootloader; if the validity flag indicates that the second Bootloader is also invalid, enter an infinite loop.

8. The device according to claim 6, characterized in that The checking unit is further used to check the validity flag of the second Bootloader, and if the validity flag indicates validity, jump to the second Bootloader; if the validity flag indicates invalid, check the validity flag of the first Bootloader; If the validity flag indicates that the first Bootloader is valid, jump to the first Bootloader; if the validity flag indicates that the first Bootloader is also invalid, enter an infinite loop.

9. A computing device, characterized in that The computing device includes: a memory and a processor; The memory is used to store computer programs; The processor is configured to implement the method according to any one of claims 1 to 5 when executing the computer program.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 5 is implemented.

Citation Information

Cited By

  • Firmware self-management method and device, electronic equipment and storage medium

    CN122132225A