Firmware upgrading method and device, electronic equipment, storage medium and program product
Connect CPLD to the multiplexer through the substrate controller, obtain and safely verify the upgrade file, determine and upgrade the target CPLD, solving the problem of low CPLD firmware upgrade efficiency and achieving safe and efficient firmware upgrade.
Patent Information
- Application Number
- CN202510308639.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-14
- Publication Date
- 2025-07-18
AI Technical Summary
In the prior art, CPLD's firmware upgrade efficiency is low, requiring on-site maintenance and interrupting business operations.
Connect multiple CPLDs to the multiplexer through the substrate controller, obtain the upgrade files of the remote server, perform security verification, determine the target CPLD, and connect the target CPLD through the multiplexer to perform firmware upgrade.
It has realized the security upgrade and efficient firmware upgrade of CPLD, improved the firmware upgrade efficiency of CPLD, and flexibly selected the upgrade target CPLD.
Smart Images

Figure CN120335831A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of software upgrade, and particularly to a firmware upgrade method, apparatus, electronic device, storage medium, and program product. Background Art
[0002] Complex Programmable Logic Devices (CPLDs) are widely used in fields such as servers and network devices. With the change of device usage scenarios and the continuous progress of technology, it is necessary to upgrade the firmware of CPLDs to repair vulnerabilities, improve performance, or add new functions to maintain the efficient operation of the devices.
[0003] Currently, the firmware upgrade methods for CPLDs can include upgrading through a Joint Test Action Group (JTAG) programmer (hereinafter referred to as JTAG programmer). Using a JTAG programmer for firmware upgrade requires technicians to open the device case, accurately find the JTAG interface of the CPLD, and correctly connect the JTAG programmer.
[0004] In the above upgrade process, upgrading through a JTAG programmer requires on-site maintenance and interruption of business operations, resulting in low efficiency of firmware upgrade for CPLDs. Summary of the Invention
[0005] This application provides a firmware upgrade method, apparatus, electronic device, storage medium, and program product to solve the technical problem of low efficiency of firmware upgrade for CPLDs in the prior art.
[0006] In a first aspect, this application provides a firmware upgrade method, which is applied to a baseboard controller. The baseboard controller is connected to a multiplexer, and the multiplexer is connected to multiple Complex Programmable Logic Devices (CPLDs). The method includes:
[0007] Obtain an upgrade file sent by a remote server;
[0008] Perform security verification processing on the upgrade file to obtain a verification result;
[0009] If the verification result is verification passed, determine a target CPLD among multiple CPLDs according to the upgrade file, and connect to the target CPLD through the multiplexer;
[0010] Perform firmware upgrade on the target CPLD according to the upgrade file.
[0011] In this way, by performing a security check on the upgrade file, the security of the upgrade file is increased, and the secure upgrade of the CPLD is achieved. Moreover, by connecting multiple CPLDs through a multiplexer, the target CPLD to be upgraded can be flexibly selected, improving the firmware upgrade efficiency of the CPLD.
[0012] Optionally, for the method described above, perform a security check process on the upgrade file to obtain a check result, including:
[0013] Parse the upgrade file to obtain an image file, a digital signature, a public key, and a public key certificate chain;
[0014] According to the public key certificate chain, verify the validity of the public key to obtain a verification result, where the verification result includes valid verification and invalid verification;
[0015] When the verification result is valid verification, perform a check process on the image file according to the public key and the digital signature to obtain a check result, where the check result includes passing the check and failing the check.
[0016] In this way, by performing a security check on the upgrade file, the security of the upgrade file is increased, and the secure upgrade of the CPLD is achieved, improving the firmware upgrade efficiency of the CPLD.
[0017] Optionally, for the method described above, perform a check process on the image file according to the public key and the digital signature to obtain a check result, including:
[0018] Decrypt the digital signature according to the public key to generate a first hash value;
[0019] Perform a hash operation on the image file to generate a second hash value;
[0020] Determine whether the first hash value and the second hash value match;
[0021] If so, determine that the check result is passing the check;
[0022] If not, determine that the check result is failing the check.
[0023] In this way, by performing a security check on the upgrade file, the security of the upgrade file is increased, and the secure upgrade of the CPLD is achieved, improving the firmware upgrade efficiency of the CPLD.
[0024] Optionally, in the method described above, the substrate controller includes a first interface, the first interface is connected to the multiplexer, the multiplexer includes a plurality of physical channels, and each physical channel is respectively connected to each CPLD. Determining a target CPLD among the plurality of CPLDs according to the upgrade file and connecting the target CPLD through the multiplexer includes:
[0025] Determine the target firmware identifier to be upgraded according to the upgrade file;
[0026] Send scan signals to the CPLDs corresponding to the respective physical channels through the first interface and the multiplexer;
[0027] Receive the firmware information sent by the CPLDs corresponding to the respective physical channels;
[0028] Determine the target CPLD among the plurality of CPLDs according to the multiple firmware information and the target firmware identifier, and connect the target CPLD through the multiplexer.
[0029] In this way, by connecting multiple CPLDs through a multiplexer, the target CPLD to be upgraded can be flexibly selected, improving the firmware upgrade efficiency of the CPLD.
[0030] Optionally, in the method described above, determining the target CPLD among the plurality of CPLDs according to the multiple firmware information and the target firmware identifier, and connecting the target CPLD through the multiplexer includes:
[0031] Generate a channel mapping table according to the multiple firmware information, where the channel mapping table includes a plurality of physical channels and the firmware information of the CPLD corresponding to each physical channel;
[0032] Determine the target CPLD corresponding to the target firmware identifier according to the channel mapping table;
[0033] Determine the target channel among the plurality of physical channels according to the target CPLD and the channel mapping table;
[0034] Connect the target CPLD through the multiplexer according to the target channel.
[0035] In this way, by connecting multiple CPLDs through a multiplexer, the target CPLD to be upgraded can be flexibly selected, improving the firmware upgrade efficiency of the CPLD.
[0036] Optionally, in the method described above, upgrading the firmware of the target CPLD according to the upgrade file includes:
[0037] Send the upgrade file to the memory of the target CPLD;
[0038] In response to the remote activation instruction sent by the remote server, a hardware reset signal is sent to the target CPLD, so that the target CPLD loads the upgrade file to implement firmware upgrade.
[0039] In this way, the target CPLD to be upgraded can be flexibly selected for remote update, improving the firmware upgrade efficiency of the CPLD.
[0040] In a second aspect, the present application provides a firmware upgrade device, which is applied to a baseboard controller. The baseboard controller is connected to a multiplexer, and the multiplexer is connected to multiple complex programmable logic devices CPLDs. The device includes:
[0041] An acquisition module, configured to acquire an upgrade file sent by a remote server;
[0042] A verification module, configured to perform security verification processing on the upgrade file to obtain a verification result;
[0043] A determination module, configured to, if the verification result is verification passed, determine a target CPLD from multiple CPLDs according to the upgrade file, and connect to the target CPLD through the multiplexer;
[0044] An upgrade module, configured to perform firmware upgrade on the target CPLD according to the upgrade file.
[0045] Optionally, for the device as described above, the verification module is specifically configured to:
[0046] Parse the upgrade file to obtain an image file, a digital signature, a public key, and a public key certificate chain;
[0047] Verify the validity of the public key according to the public key certificate chain to obtain a verification result, where the verification result includes verification valid and verification invalid;
[0048] When the verification result is verification valid, perform verification processing on the image file according to the public key and the digital signature to obtain a verification result, where the verification result includes verification passed and verification not passed.
[0049] Optionally, for the device as described above, the verification module is specifically configured to:
[0050] Decrypt the digital signature according to the public key to generate a first hash value;
[0051] Perform a hash operation on the image file to generate a second hash value;
[0052] Determine whether the first hash value matches the second hash value;
[0053] If so, determine that the verification result is verification passed;
[0054] If not, determine that the verification result is verification failed.
[0055] Optionally, for the device as described above, the substrate controller includes a first interface, the first interface is connected to the multiplexer, the multiplexer includes a plurality of physical channels, and each physical channel is respectively connected to each CPLD. The determining module is specifically configured to:
[0056] Determine the target firmware identifier to be upgraded according to the upgrade file;
[0057] Send scan signals to the CPLDs corresponding to the respective physical channels through the first interface and the multiplexer respectively;
[0058] Receive the firmware information sent by the CPLDs corresponding to the respective physical channels;
[0059] Determine the target CPLD among the multiple CPLDs according to the multiple firmware information and the target firmware identifier, and connect the target CPLD through the multiplexer.
[0060] Optionally, for the device as described above, the determining module is specifically configured to:
[0061] Generate a channel mapping table according to the multiple firmware information, where the channel mapping table includes a plurality of physical channels and the firmware information of the CPLD corresponding to each physical channel;
[0062] Determine the target CPLD corresponding to the target firmware identifier according to the channel mapping table;
[0063] Determine the target channel among the multiple physical channels according to the target CPLD and the channel mapping table;
[0064] Connect the target CPLD through the multiplexer according to the target channel.
[0065] Optionally, for the device as described above, the upgrade module is specifically configured to:
[0066] Send the upgrade file to the memory of the target CPLD;
[0067] In response to the remote activation instruction sent by the remote server, send a hardware reset signal to the target CPLD, so that the target CPLD loads the upgrade file to implement firmware upgrade.
[0068] In a third aspect, the present application provides an electronic device, including: a processor, and a memory communicatively connected to the processor;
[0069] The memory stores computer-executable instructions;
[0070] The processor executes the computer-executable instructions stored in the memory to implement the method according to any one of the first aspect.
[0071] In a fourth aspect, the present application provides a computer-readable storage medium storing computer-executable instructions, which are used to implement the method according to any one of the first aspect when executed by a processor.
[0072] In a fifth aspect, the present application provides a computer program product including a computer program, which implements the method according to any one of the first aspect when executed by a computer.
[0073] The firmware upgrade method, device, electronic device, storage medium and program product provided by the present application are applied to a baseboard controller. The baseboard controller is connected to a multiplexer, and the multiplexer is connected to multiple complex programmable logic devices (CPLDs). By obtaining an upgrade file sent by a remote server; performing a security verification process on the upgrade file to obtain a verification result; if the verification result is passed, determining a target CPLD among the multiple CPLDs according to the upgrade file, and connecting the target CPLD through the multiplexer; performing firmware upgrade on the target CPLD according to the upgrade file. In this way, by performing a security verification on the upgrade file, the security of the upgrade file is increased, and the secure upgrade of the CPLD is realized. Moreover, by connecting multiple CPLDs through the multiplexer, the target CPLD to be upgraded can be flexibly selected, improving the firmware upgrade efficiency of the CPLD. BRIEF DESCRIPTION OF THE DRAWINGS
[0074] The drawings herein are incorporated into the specification and constitute a part of the specification, showing embodiments consistent with the present application and used together with the specification to explain the principles of the present application.
[0075] Figure 1 It is a schematic diagram of an application scenario provided by an embodiment of the present application;
[0076] Figure 2 It is a schematic flowchart of a firmware upgrade method provided by an embodiment of the present application;
[0077] Figure 3 It is a schematic flowchart of another firmware upgrade method provided by an embodiment of the present application;
[0078] Figure 4 It is a schematic flowchart of yet another firmware upgrade method provided by an embodiment of the present application;
[0079] Figure 5A schematic flowchart of another firmware upgrade method provided by an embodiment of the present application;
[0080] Figure 6 A schematic structural diagram of a firmware upgrade device provided by an embodiment of the present application;
[0081] Figure 7 A schematic structural diagram of an electronic device provided by an embodiment of the present application.
[0082] Through the above-mentioned drawings, specific embodiments of the present application have been shown, and more detailed descriptions will be provided hereinafter. These drawings and textual descriptions are not intended to limit the scope of the concept of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. Detailed implementation manners
[0083] Exemplary embodiments will be described in detail herein, and examples thereof are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.
[0084] It should be noted that although terms such as "first" and "second" are used in the embodiments of the present application to describe various information, this information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. Optionally, without departing from the scope of the present application, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information.
[0085] It should be understood that the terms "comprising" and "including" indicate the presence of the previously mentioned features, steps, operations, but do not exclude the presence, occurrence, or addition of one or at least one other feature, step, operation. The term "and / or" used in the present application can be interpreted inclusively, or means any one or any combination. Optionally, "A and / or B" means "any one of the following: A; B; A and B". Additionally, the character " / " in this text generally represents an "or" relationship between the associated objects before and after.
[0086] Complex Programmable Logic Devices (CPLDs) are widely used in fields such as servers and network devices. With the changes in device usage scenarios and the continuous progress of technology, it becomes necessary to upgrade the firmware of CPLDs to repair vulnerabilities, improve performance, or add new functions to maintain the efficient operation of the devices.
[0087] Currently, the methods for firmware upgrade of CPLD can include upgrading through a Joint Test Action Group (JTAG) programmer (hereinafter referred to as JTAG programmer). When using a JTAG programmer for firmware upgrade, technicians need to open the device case, accurately locate the JTAG interface of the CPLD, and correctly connect the JTAG programmer.
[0088] In the above upgrade process, upgrading through a JTAG programmer requires on-site maintenance and interruption of business operations, resulting in a low efficiency of firmware upgrade for CPLD.
[0089] To solve the above technical problems, an embodiment of the present application provides a firmware upgrade method, which is applied to a baseboard controller. The baseboard controller is connected to a multiplexer, and the multiplexer is connected to multiple Complex Programmable Logic Devices (CPLDs). By obtaining the upgrade file sent by a remote server, performing security verification processing on the upgrade file to obtain a verification result, if the verification result is verification passed, determining the target CPLD, and connecting to the target CPLD through the multiplexer, and performing firmware upgrade on the target CPLD through the upgrade file. In this way, by performing security verification on the upgrade file, the security of the upgrade file is increased, and the secure upgrade of CPLD is realized. Moreover, by connecting multiple CPLDs through a multiplexer, the target CPLD to be upgraded can be flexibly selected, improving the firmware upgrade efficiency of CPLD.
[0090] Next, Figure 1 , an application scenario of firmware upgrade will be illustrated by way of example.
[0091] Figure 1 This is a schematic diagram of an application scenario provided by an embodiment of the present application. Please refer to Figure 1 , Figure 1 It may include a baseboard controller, a multiplexer, and multiple CPLDs.
[0092] The baseboard controller can be connected to the multiplexer, and the multiplexer can be connected to multiple CPLDs.
[0093] The baseboard controller can be an independent microcontroller integrated on a computer or server motherboard. The baseboard controller can communicate through a network interface and various communication protocols, such as an Ethernet interface, IPMI protocol, etc. The baseboard controller can, when operating independently of the main system, monitor the hardware status in real time, including temperature, voltage, fan speed, etc. It can also implement operations such as remote power-on, power-off, and firmware update, providing strong support for the stable operation and convenient management of devices in fields such as data centers, enterprise servers, and industrial control.
[0094] A multiplexer may include multiple analog switches or multiple digital switches. The multiplexer can select one from multiple input signals and transmit it to a single output terminal. In the scenario of firmware upgrade, the multiplexer can be used to select different CPLDs to communicate with the board controller.
[0095] CPLD can be used to implement high-speed forwarding and switching of data. CPLD can handle functions such as routing, filtering, and priority control of data packets to ensure efficient transmission of data in the network.
[0096] The following uses specific embodiments to elaborate in detail on the technical solution of this application and how the technical solution of this application solves the above technical problems. These several specific embodiments below can be combined with each other, and for the same or similar concepts or processes, they may not be repeated in some embodiments. The embodiments of this application will be described below in conjunction with the accompanying drawings.
[0097] The following elaborates in detail on the technical solution shown in this application through specific embodiments. It should be noted that the following several embodiments can exist independently or be combined with each other, and for the same or similar content, it will not be repeated in different embodiments.
[0098] Figure 2 It is a schematic flowchart of a firmware upgrade method provided by an embodiment of this application. The execution subject of the embodiment of this application can be a board controller, the board controller is connected to a multiplexer, and the multiplexer is connected to multiple Complex Programmable Logic Devices (CPLDs). The firmware upgrader can be implemented by software or by a combination of software and hardware. Please refer to Figure 2 , the method includes:
[0099] S201. Obtain the upgrade file sent by the remote server.
[0100] The remote server can be a computer system that stores and manages various software upgrade files. The remote server can centrally manage the upgrade files of all devices, facilitating unified maintenance and update, and can provide upgrade file services for multiple devices simultaneously.
[0101] The upgrade file can include a mirror file, key information, configuration information, etc.
[0102] The key information can include a digital signature, a public key, a public key certificate chain, etc., which are not limited here.
[0103] The key information can be used for security verification.
[0104] The upgrade file can fix the vulnerabilities in the existing firmware of the CPLD, add new functions, or optimize performance.
[0105] A connection can be established with a remote server through a network interface. After the connection is established, a request is sent to the remote server according to a pre-configured protocol to request an upgrade file, so that after the remote server receives the request, it sends the upgrade file to the baseboard controller, and the baseboard controller obtains the upgrade file sent by the remote server.
[0106] Among them, the network interface can include Ethernet, etc.
[0107] The pre-configured protocol can include HTTP, FTP, etc.
[0108] For example, in an implementation based on the HTTP protocol, the BMC sends an HTTP GET request to the server, indicating the path and name of the upgrade file to be obtained, and the server returns the upgrade file in the form of an HTTP response.
[0109] S202. Perform a security verification process on the upgrade file to obtain a verification result.
[0110] To ensure the integrity and authenticity of the upgrade file and prevent the file from being tampered with or infected with a virus during transmission, it is necessary to perform a security verification on it.
[0111] The security verification process can be based on an encryption algorithm or a hash algorithm to determine whether the upgrade file is secure.
[0112] Parse the upgrade file to obtain an image file and key information, and through the key information, perform a security verification process on the image file to obtain a verification result.
[0113] Optionally, if the verification result is that the verification fails, generate an alarm message and send the alarm message to the remote server.
[0114] S203. If the verification result is that the verification passes, determine the target CPLD among multiple CPLDs according to the upgrade file, and connect the target CPLD through a multiplexer.
[0115] The target CPLD can be the CPLD to be upgraded corresponding to the upgrade file.
[0116] The upgrade file includes a firmware identifier corresponding to the target CPLD.
[0117] The firmware identifier can be the CPLD number, model, etc.
[0118] If the verification result is that the verification passes, determine the target firmware identifier according to the upgrade file, determine the target CPLD corresponding to the target firmware identifier among multiple CPLDs, and control the internal switch of the multiplexer to connect the communication interface of the BMC to the interface of the target CPLD.
[0119] S204. Perform firmware upgrade on the target CPLD according to the upgrade file.
[0120] The process of firmware upgrade can be to write the image file in the upgrade file into the storage area of the CPLD to replace the original firmware.
[0121] The image file can be the program code for the CPLD to run, to control various functions and behaviors of the CPLD.
[0122] The image file can be determined according to the upgrade file, and the image file is transmitted to the memory of the target CPLD to perform firmware upgrade on the target CPLD.
[0123] Optionally, perform firmware upgrade on the target CPLD according to the upgrade file: send the upgrade file to the memory of the target CPLD; in response to the remote activation instruction sent by the remote server, send a hardware reset signal to the target CPLD to enable the target CPLD to load the upgrade file to achieve firmware upgrade.
[0124] Among them, the remote activation instruction can be used to trigger the firmware upgrade operation of the target CPLD.
[0125] The hardware reset signal can be used to reset the hardware state of the target CPLD.
[0126] The firmware upgrade method provided in this embodiment is applied to a baseboard controller. The baseboard controller is connected to a multiplexer, and the multiplexer is connected to multiple complex programmable logic devices CPLD. By obtaining the upgrade file sent by the remote server; performing security verification processing on the upgrade file to obtain a verification result; if the verification result is verified to pass, determine the target CPLD among multiple CPLDs according to the upgrade file, and connect to the target CPLD through the multiplexer; perform firmware upgrade on the target CPLD according to the upgrade file. In this way, by performing security verification on the upgrade file, the security of the upgrade file is increased, and the secure upgrade of the CPLD is achieved. Moreover, by connecting multiple CPLDs through the multiplexer, the target CPLD to be upgraded can be flexibly selected, improving the firmware upgrade efficiency of the CPLD.
[0127] Next, in combination with Figure 3 , the process of performing security verification processing on the upgrade file to obtain a verification result (S202) will be explained.
[0128] Figure 3 It is a schematic flowchart of another firmware upgrade method provided by an embodiment of the present application. On the basis of the above embodiment, refer to Figure 3 , this method includes:
[0129] S301. Parse the upgrade file to obtain an image file, a digital signature, a public key, and a public key certificate chain.
[0130] The image file can be used to upgrade the CPLD. The image file may include the updated program code and configuration information required for the CPLD to run.
[0131] The digital signature can be used to encrypt the image file to prove the source and integrity of the image file.
[0132] The digital signature can be obtained by the remote server encrypting the hash value of the image file with the private key.
[0133] The public key can be the key corresponding to the private key in the remote server. The public key can be used to verify the security of the digital signature.
[0134] The public key certificate chain can be used to verify the legality and authenticity of the public key.
[0135] The public key certificate chain can be issued by a certificate authority.
[0136] The public key certificate chain can include the relevant information of the public key and the digital signature of the certificate authority.
[0137] The upgrade file can be parsed according to a predefined file format and protocol to obtain the image file, digital signature, public key, and public key certificate chain.
[0138] S302. According to the public key certificate chain, verify the validity of the public key to obtain the verification result.
[0139] The verification result includes valid verification and invalid verification.
[0140] The validity verification can be used to check whether the public key is legal, whether it is within the validity period, and whether it is issued by a trusted certificate authority.
[0141] The verification result can be used to judge the validity verification of the public key, which is divided into valid verification and invalid verification.
[0142] The validity period of the certificate in the public key certificate chain can be checked to determine whether the certificate has expired. If the certificate has not expired, verify the digital signature of each certificate in the public key certificate chain through the public key until the verification of the certificate corresponding to the target public key passes, then determine the verification result as valid verification; otherwise, determine the verification result as invalid verification.
[0143] S303. Judge whether the verification result is invalid verification.
[0144] If so, execute S304;
[0145] If not, execute S305.
[0146] For example, the verification result can be judged by checking the flag bit or return value of the verification result.
[0147] S304. Determine that the verification result is a verification failure.
[0148] S305. Decrypt the digital signature according to the public key to generate a first hash value.
[0149] The first hash value can be the hash value obtained by decrypting the digital signature with the public key.
[0150] According to the public key, the decryption function in the asymmetric algorithm library can be called, and the digital signature can be decrypted by the decryption function to obtain the first hash value.
[0151] S306. Perform a hash operation on the mirror file to generate a second hash value.
[0152] The hash operation can be used to convert data of any length into a hash value of a fixed length.
[0153] By performing a hash operation on the mirror file, a unique hash value can be obtained to verify the integrity of the file.
[0154] The second hash value can be the result of performing a hash operation on the mirror file.
[0155] The preset hash algorithm can be determined, and the content of the mirror file can be hashed by the hash algorithm to obtain the second hash value.
[0156] S307. Determine whether the first hash value and the second hash value match.
[0157] If so, execute S308;
[0158] If not, execute S304.
[0159] Determine whether the first hash value is the same as the second hash value.
[0160] S308. Determine that the verification result is a verification success.
[0161] In the embodiments of the present application, the implementation content of each step can refer to the description of the corresponding step or operation in the above method embodiment, and the repeated content will not be elaborated.
[0162] The firmware upgrade method provided in this embodiment obtains an image file, a digital signature, a public key, and a public key certificate chain by parsing and processing the upgrade file; validates the validity of the public key according to the public key certificate chain to obtain a verification result, where the verification result includes valid verification and invalid verification; when the verification result is valid verification, decrypts the digital signature according to the public key to generate a first hash value; performs a hash operation on the image file to generate a second hash value; determines whether the first hash value and the second hash value match; if so, determines that the verification result is verification passed; if not, determines that the verification result is verification failed. In this way, by performing a security check on the upgrade file, the security of the upgrade file is increased, and the secure upgrade of the CPLD is achieved. Moreover, by connecting multiple CPLDs through a multiplexer, the target CPLD to be upgraded can be flexibly selected, improving the firmware upgrade efficiency of the CPLD.
[0163] In a possible implementation manner, the baseboard controller includes a first interface, the first interface is connected to the multiplexer, and the multiplexer includes multiple physical channels, and each physical channel is respectively connected to each CPLD.
[0164] Next, in combination with Figure 4 , the process (S203) of determining the target CPLD from the upgrade file and connecting the target CPLD through the multiplexer will be explained.
[0165] Figure 4 This is a schematic flowchart of another firmware upgrade method provided in the embodiments of the present application. On the basis of the above embodiments, refer to Figure 4 , this method includes:
[0166] S401. Determine the target firmware identifier to be upgraded according to the upgrade file.
[0167] The upgrade file can be parsed and processed to determine the target firmware identifier to be upgraded.
[0168] S402. Send a scan signal to the CPLD corresponding to each physical channel through the first interface and the multiplexer respectively.
[0169] The first interface can be used to communicate with the multiplexer.
[0170] The physical channel can be the actual physical line connecting the multiplexer and the CPLD.
[0171] The physical channel can be used to transmit signals and data. Each physical channel can correspond to a specific CPLD.
[0172] The scan signal can be a specific signal used to trigger the CPLD to feedback its own firmware information.
[0173] Each CPLD can be notified to report the current firmware information through a scan signal.
[0174] A scan signal can be sent to the multiplexer through the first interface, received by the multiplexer, and then sent to the corresponding CPLD through each physical channel respectively.
[0175] S403. Receive the firmware information sent by the CPLD corresponding to each physical channel.
[0176] The firmware information can be the relevant data about the firmware of the CPLD stored internally.
[0177] The firmware information can include information such as the firmware version number, manufacturer, production date, etc.
[0178] The firmware information sent by each CPLD can be received through the multiplexer, and the firmware information of each CPLD sent by the multiplexer can be received through the first interface.
[0179] S404. Generate a channel mapping table based on multiple firmware information.
[0180] The channel mapping table can record the association relationship between the physical channel and the corresponding CPLD firmware information.
[0181] The channel mapping table includes multiple physical channels and the firmware information of the CPLD corresponding to each physical channel.
[0182] Multiple firmware information can be analyzed and processed to generate a channel mapping table.
[0183] S405. Determine the target CPLD corresponding to the target firmware identifier according to the channel mapping table.
[0184] According to the target firmware identifier, the firmware information of each CPLD in the channel mapping table can be traversed to determine the target CPLD corresponding to the target firmware identifier.
[0185] S406. Determine the target channel among multiple physical channels according to the target CPLD and the channel mapping table.
[0186] The target channel can be used to connect the physical channel between the target CPLD and the multiplexer.
[0187] A communication connection can be established with the target CPLD through the multiplexer for subsequent firmware upgrade operations.
[0188] According to the target CPLD, the channel mapping table can be traversed to determine the target channel among multiple physical channels.
[0189] S407. Connect the target CPLD according to the target channel through the multiplexer.
[0190] A control signal can be sent to the multiplexer. The control signal includes a target channel. After receiving the control signal through the multiplexer, the switch or selection circuit in the multiplexer is adjusted according to the target channel in the control signal, and the first interface is connected to the target channel.
[0191] In the firmware upgrade method provided in this embodiment, the target firmware identifier to be upgraded is determined according to the upgrade file. Scan signals are respectively sent to the CPLDs corresponding to each physical channel through the first interface and the multiplexer, and the firmware information sent by the CPLDs corresponding to each physical channel is received. According to the multiple firmware information, a channel mapping table is generated. The channel mapping table includes multiple physical channels and the firmware information of the CPLD corresponding to each physical channel. According to the channel mapping table, the target CPLD corresponding to the target firmware identifier is determined. According to the target CPLD and the channel mapping table, the target channel is determined among the multiple physical channels, and the target CPLD is connected through the multiplexer according to the target channel. In this way, by performing a security check on the upgrade file, the security of the upgrade file is increased, and the secure upgrade of the CPLD is realized. Moreover, by connecting multiple CPLDs through the multiplexer, the target CPLD to be upgraded can be flexibly selected, improving the firmware upgrade efficiency of the CPLD.
[0192] Next, in conjunction with Figure 5 , the technical solution shown in this application will be described through specific examples.
[0193] Figure 5 It is a schematic flowchart of another firmware upgrade method provided in an embodiment of this application. See Figure 5 , this method includes:
[0194] S501. Obtain the upgrade file sent by the remote server.
[0195] S502. Parse and process the upgrade file to obtain an image file, a digital signature, a public key, and a public key certificate chain.
[0196] S503. Verify the validity of the public key according to the public key certificate chain to obtain a verification result.
[0197] S504. Determine whether the verification result is invalid verification.
[0198] If so, execute S505;
[0199] If not, execute S506.
[0200] S505. Determine that the verification result is verification failure.
[0201] S506. Decrypt the digital signature according to the public key to generate a first hash value.
[0202] S507. Perform a hash operation on the image file to generate a second hash value.
[0203] S508. Determine whether the first hash value and the second hash value match.
[0204] If so, execute S509;
[0205] If not, execute S505.
[0206] S509. Determine that the verification result is verification passed.
[0207] After S509, execute S510.
[0208] S510. Determine the target firmware identifier to be upgraded according to the upgrade file.
[0209] S511. Send scan signals to the CPLDs corresponding to each physical channel through the first interface and the multiplexer respectively.
[0210] S512. Receive the firmware information sent by the CPLDs corresponding to each physical channel.
[0211] S513. Generate a channel mapping table according to multiple firmware information.
[0212] S514. Determine the target CPLD corresponding to the target firmware identifier according to the channel mapping table.
[0213] S515. Determine the target channel among multiple physical channels according to the target CPLD and the channel mapping table.
[0214] S516. Connect the target CPLD according to the target channel through the multiplexer.
[0215] S517. Upgrade the firmware of the target CPLD according to the upgrade file.
[0216] The execution process of S501 - S517 can refer to the execution process of the above steps, which will not be elaborated here.
[0217] In this way, by performing a security verification on the upgrade file, the security of the upgrade file is increased, and the secure upgrade of the CPLD is realized. Moreover, by connecting multiple CPLDs through the multiplexer, the target CPLD to be upgraded can be flexibly selected, improving the firmware upgrade efficiency of the CPLD.
[0218] Figure 6 This is a schematic structural diagram of a firmware upgrade device provided by an embodiment of the present application. Please refer to Figure 6, the firmware upgrade device 600 includes an acquisition module 601, a verification module 602, a determination module 603, and an upgrade module 604, where,
[0219] The acquisition module 601 is used to acquire the upgrade file sent by the remote server;
[0220] The verification module 602 is used to perform security verification processing on the upgrade file to obtain a verification result;
[0221] The determination module 603 is used to, if the verification result is verification passed, determine a target CPLD among multiple CPLDs according to the upgrade file, and connect the target CPLD through the multiplexer;
[0222] The upgrade module 604 is used to perform firmware upgrade on the target CPLD according to the upgrade file.
[0223] Optionally, for the device as described above, the verification module 602 is specifically used for:
[0224] Perform parsing processing on the upgrade file to obtain an image file, a digital signature, a public key, and a public key certificate chain;
[0225] According to the public key certificate chain, perform validity verification on the public key to obtain a verification result, where the verification result includes verification valid and verification invalid;
[0226] When the verification result is verification valid, perform verification processing on the image file according to the public key and the digital signature to obtain a verification result, where the verification result includes verification passed and verification not passed.
[0227] Optionally, for the device as described above, the verification module 602 is specifically used for:
[0228] Decrypt the digital signature according to the public key to generate a first hash value;
[0229] Perform a hash operation on the image file to generate a second hash value;
[0230] Determine whether the first hash value and the second hash value match;
[0231] If so, determine that the verification result is verification passed;
[0232] If not, determine that the verification result is verification not passed.
[0233] Optionally, for the device as described above, the substrate controller includes a first interface, the first interface is connected to the multiplexer, the multiplexer includes a plurality of physical channels, and each physical channel is respectively connected to each CPLD. The determining module 603 is specifically configured to:
[0234] Determine the target firmware identifier to be upgraded according to the upgrade file;
[0235] Send scan signals to the CPLDs corresponding to the respective physical channels through the first interface and the multiplexer respectively;
[0236] Receive the firmware information sent by the CPLDs corresponding to the respective physical channels;
[0237] Determine the target CPLD among the multiple CPLDs according to the multiple firmware information and the target firmware identifier, and connect the target CPLD through the multiplexer.
[0238] Optionally, for the device as described above, the determining module 603 is specifically configured to:
[0239] Generate a channel mapping table according to the multiple firmware information, where the channel mapping table includes a plurality of physical channels and the firmware information of the CPLD corresponding to each physical channel;
[0240] Determine the target CPLD corresponding to the target firmware identifier according to the channel mapping table;
[0241] Determine the target channel among the multiple physical channels according to the target CPLD and the channel mapping table;
[0242] Connect the target CPLD through the multiplexer according to the target channel.
[0243] Optionally, for the device as described above, the upgrade module 604 is specifically configured to:
[0244] Send the upgrade file to the memory of the target CPLD;
[0245] In response to the remote activation instruction sent by the remote server, send a hardware reset signal to the target CPLD, so that the target CPLD loads the upgrade file to implement firmware upgrade.
[0246] Figure 7 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application. Please refer to Figure 7 , the electronic device 700 may include: a memory 701, a processor 702, and a transceiver 703.
[0247] The memory 701 is used to store program instructions;
[0248] The processor 702 is used to execute the program instructions stored in the memory, so as to enable the electronic device 700 to execute the above method.
[0249] The transceiver 703 may include: a transmitter and / or a receiver. The transmitter may also be referred to as a sender, a transmitter, a transmission port, a transmission interface, or other similar descriptions, and the receiver may also be referred to as a receiver, a receiving port, a receiving interface, or other similar descriptions. Exemplarily, the memory 701, the processor 702, and the transceiver 703 are interconnected with each other through a bus 704.
[0250] The embodiment of the present application also provides a computer program product, which can be executed by a processor. When the computer program product is executed, the above method can be implemented.
[0251] The firmware upgrade device, electronic device, computer-readable storage medium, and computer program product of the embodiment of the present application can execute the technical solutions shown in the above embodiment of the firmware upgrade method, and their implementation principles and beneficial effects are similar, so details are not described herein again.
[0252] It should be noted that, for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the present application is not limited by the described action sequence, because according to the present application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to the present application.
[0253] Further, it should be noted that although the steps in the flowchart are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps has no strict order restriction, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowchart may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same moment, but can be executed at different moments. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed alternately or alternately with at least a part of other steps or sub-steps or stages of other steps.
[0254] It should be understood that the above device embodiments are only illustrative, and the devices of the present application can also be implemented in other ways. For example, the division of units / modules in the above embodiments is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units, modules, or components can be combined, or can be integrated into another system, or some features can be ignored or not executed.
[0255] In addition, unless otherwise specified, in each embodiment of the present application, each functional unit / module can be integrated into one unit / module, or each unit / module can exist physically alone, or two or more units / modules can be integrated together. The above integrated unit / module can be implemented in the form of hardware or in the form of a software program module.
[0256] When the integrated unit / module is implemented in the form of hardware, the hardware can be a digital circuit, an analog circuit, etc. The physical implementation of the hardware structure includes but is not limited to transistors, memristors, etc. Unless otherwise specified, the processor can be any suitable hardware processor, such as a CPU, GPU, FPGA, DSP, and ASIC, etc. Unless otherwise specified, the storage unit can be any suitable magnetic storage medium or magneto-optical storage medium, such as resistive random access memory (RRAM), dynamic random access memory (DRAM), static random access memory (SRAM), enhanced dynamic random access memory (EDRAM), high-bandwidth memory (HBM), hybrid memory cube (HMC), etc.
[0257] When the integrated unit / module is implemented in the form of a software program module and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a memory and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in each embodiment of the present application. The aforementioned memory includes: USB flash drives, read-only memory (ROM), random access memory (RAM), mobile hard disks, magnetic disks, or optical discs, etc., which are various media that can store program codes.
[0258] In the above embodiments, the descriptions of the various embodiments each have their own emphasis. For parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments. The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as falling within the scope described in this specification.
[0259] Those skilled in the art will readily conceive of other embodiments of the present application after considering the specification and practicing the invention disclosed herein. The present application is intended to cover any variations, uses, or adaptations of the present application, which follow the general principles of the present application and include known common knowledge or conventional technical means in the technical field not disclosed in the present application. The specification and examples are only to be considered as exemplary, and the true scope and spirit of the present application are pointed out by the following claims.
[0260] It should be understood that the present application is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present application is only limited by the appended claims.
Claims
1. A firmware upgrade method, characterized in that Applied to a substrate controller, the substrate controller is connected to a multiplexer, and the multiplexer is connected to multiple complex programmable logic devices (CPLDs). The method includes: Obtain an upgrade file sent by a remote server; Perform security verification processing on the upgrade file to obtain a verification result; If the verification result is verification passed, determine a target CPLD among the multiple CPLDs according to the upgrade file, and connect to the target CPLD through the multiplexer; Perform firmware upgrade on the target CPLD according to the upgrade file.
2. The method according to claim 1, wherein Performing security verification processing on the upgrade file to obtain a verification result includes: Perform parsing processing on the upgrade file to obtain an image file, a digital signature, a public key, and a public key certificate chain; According to the public key certificate chain, perform validity verification on the public key to obtain a verification result, and the verification result includes verification valid and verification invalid; When the verification result is verification valid, perform verification processing on the image file according to the public key and the digital signature to obtain a verification result, where the verification result includes verification passed and verification failed.
3. The method according to claim 2, wherein Performing verification processing on the image file according to the public key and the digital signature to obtain a verification result includes: Decrypt the digital signature according to the public key to generate a first hash value; Perform a hash operation on the image file to generate a second hash value; Determine whether the first hash value and the second hash value match; If so, determine that the verification result is verification passed; If not, determine that the verification result is verification failed.
4. The method according to any one of claims 1 to 3, characterized in that, The substrate controller includes a first interface, the first interface is connected to the multiplexer, the multiplexer includes multiple physical channels, and each physical channel is respectively connected to each CPLD. Determining a target CPLD among the multiple CPLDs according to the upgrade file and connecting to the target CPLD through the multiplexer includes: Determine a target firmware identifier to be upgraded according to the upgrade file; Send scan signals to the CPLDs corresponding to each physical channel through the first interface and the multiplexer respectively; Receive the firmware information sent by the CPLDs corresponding to each physical channel; Determine a target CPLD among the multiple CPLDs according to the multiple firmware information and the target firmware identifier, and connect to the target CPLD through the multiplexer.
5. The method according to claim 4, characterized in that, Determining a target CPLD among the multiple CPLDs according to the multiple firmware information and the target firmware identifier and connecting to the target CPLD through the multiplexer includes: Generate a channel mapping table according to the multiple firmware information, and the channel mapping table includes multiple physical channels and the firmware information of the CPLD corresponding to each physical channel; Determine the target CPLD corresponding to the target firmware identifier according to the channel mapping table; Determine a target channel among the multiple physical channels according to the target CPLD and the channel mapping table; Connect to the target CPLD through the multiplexer according to the target channel.
6. The method according to any one of claims 1-5, characterized in that Perform firmware upgrade on the target CPLD according to the upgrade file, including: Send the upgrade file to the memory of the target CPLD; In response to the remote activation instruction sent by the remote server, send a hardware reset signal to the target CPLD to enable the target CPLD to load the upgrade file to implement firmware upgrade.
7. A firmware upgrade device, characterized in that, Applied to a baseboard controller, the baseboard controller is connected to a multiplexer, and the multiplexer is connected to multiple complex programmable logic devices CPLDs. The device includes: An acquisition module for acquiring an upgrade file sent by a remote server; A verification module for performing security verification processing on the upgrade file to obtain a verification result; A determination module for, if the verification result is verification passed, determining a target CPLD among multiple CPLDs according to the upgrade file, and connecting the target CPLD through the multiplexer; An upgrade module for performing firmware upgrade on the target CPLD according to the upgrade file.
8. An electronic device, characterized in that, Including: A processor and a memory communicatively connected to the processor; The memory stores computer execution instructions; The processor executes the computer execution instructions stored in the memory to implement the method according to any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that, Computer execution instructions are stored in the computer-readable storage medium, and when the computer execution instructions are executed by a processor, they are used to implement the method according to any one of claims 1 to 6.
10. A computer program product, characterized in that, Including a computer program, which when executed by a processor implements the method according to any one of claims 1-6.
Citation Information
Cited By
Firmware loading device, method and system, programmable control device, medium and product
CN121143907A