Firmware updating method, firmware updating device, equipment and storage medium
By dividing the firmware into multiple logical areas and performing incremental updates, the problems of high occupancy, long time and poor compatibility in the prior art firmware update resource are solved, and an efficient and low resource consumption update process is achieved.
Patent Information
- Application Number
- CN202510822186.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-19
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-06-19
AI Technical Summary
The existing firmware update method requires downloading a complete firmware installation package, resulting in high network resource usage, high time cost, low update efficiency, and compatibility issues and waste of resources.
The firmware is divided into multiple logical areas, and the partition to be updated is determined by comparing the version information, and only the data difference is sent for updates, using the incremental update mechanism.
Reduces data transmission, shortens update time, improves operation and maintenance efficiency, reduces resource consumption, and reduces compatibility risks.
Smart Images

Figure CN120335849A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of servers, and particularly to a method for firmware update, a firmware update device, a device, and a storage medium. Background Art
[0002] With the expansion of server scale and the iteration of functions, the update frequency of firmware has gradually increased. Related firmware update methods usually require downloading a complete firmware installation package. However, the complete firmware installation package is huge in size (usually hundreds of megabytes), downloading the complete firmware installation package will consume a large amount of network resources, and the time cost is high, and the update efficiency is low. Summary of the Invention
[0003] In view of the above problems, this application provides a method for firmware update, a firmware update device, a device, and a storage medium.
[0004] According to the first aspect of this application, there is provided a method for firmware update, including: obtaining the version information of each of multiple firmware partitions in the first version firmware installed in a target component, where the multiple firmware partitions are obtained by dividing the firmware into multiple logical regions according to multiple functions of the firmware; comparing the version information of each of the multiple firmware partitions in the currently available second version firmware with the version information of each of the multiple firmware partitions in the first version firmware to determine the partitions to be updated in the multiple firmware partitions of the first version firmware; determining the data difference between the partitions to be updated and the corresponding firmware partitions in the second version firmware to obtain an update data set; and sending the update data set to the target component so that the target component updates the first version firmware according to the update data set.
[0005] The second aspect of this application provides a firmware update device, including: an obtaining module, configured to obtain the version information of each of multiple firmware partitions in the first version firmware installed in a target component, where the multiple firmware partitions are obtained by dividing the firmware into multiple logical regions according to multiple functions of the firmware; a comparison module, configured to compare the version information of each of the multiple firmware partitions in the currently available second version firmware with the version information of each of the multiple firmware partitions in the first version firmware to determine the partitions to be updated in the multiple firmware partitions of the first version firmware; a first determination module, configured to determine the data difference between the partitions to be updated and the corresponding firmware partitions in the second version firmware to obtain an update data set; and a sending module, configured to send the update data set to the target component so that the target component updates the first version firmware according to the update data set.
[0006] The third aspect of this application provides an electronic device, including: one or more processors; a memory, configured to store one or more computer programs, where the above one or more processors execute the above one or more computer programs to implement the steps of the above method.
[0007] The fourth aspect of the present application further provides a computer-readable storage medium, on which a computer program or instruction is stored, and when the computer program or instruction is executed by a processor, the steps of the above method are implemented.
[0008] The fifth aspect of the present application further provides a computer program product, including a computer program or instruction, and when the computer program or instruction is executed by a processor, the steps of the above method are implemented.
[0009] According to the embodiments of the present application, by dividing the firmware into multiple logical regions according to multiple functions of the firmware to obtain multiple firmware partitions, comparing the version information of each firmware partition in the current second version firmware with the version information of each firmware partition in the first version firmware to determine the partition to be updated, then determining the data difference between the partition to be updated and the corresponding firmware partition in the second version firmware to obtain an update data set, and only sending the update data set to the target component. Through this incremental update mechanism, rather than the full update mechanism of sending all data to the target component, the data transmission volume during firmware update can be reduced, the firmware update time can be shortened, the operation and maintenance efficiency can be improved, and resource consumption can be reduced; by dividing the firmware into multiple logical regions according to multiple functions of the firmware, different functional modules can be isolated in independent logical regions, thereby effectively reducing compatibility problems caused by function interaction, version iteration or hardware differences, and improving management efficiency. Thus, at least partially solving the problems of low efficiency and high resource consumption in full update in related methods, and achieving the technical problems of improving update efficiency, reducing time cost and resource consumption. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] Through the following description of the embodiments of the present application with reference to the drawings, the above content and other objects, features and advantages of the present application will become clearer. In the drawings:
[0011] Figure 1 Shows an application scenario diagram of a firmware update method, a firmware update device, a device and a storage medium according to an embodiment of the present application.
[0012] Figure 2 Shows a flowchart of a firmware update method according to an embodiment of the present application.
[0013] Figure 3 Shows a system interaction diagram of a firmware update method according to an embodiment of the present application.
[0014] Figure 4 Shows a schematic diagram of a verification process according to an embodiment of the present application.
[0015] Figure 5 Shows a structural block diagram of a firmware update device according to an embodiment of the present application.
[0016] Figure 6 A block diagram of an electronic device suitable for implementing a firmware update method according to an embodiment of the present application is shown. Detailed implementation manners
[0017] Hereinafter, embodiments of the present application will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present application. In the following detailed description, for the sake of explanation, many specific details are set forth in order to provide a comprehensive understanding of the embodiments of the present application. However, it is obvious that one or more embodiments can also be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessarily confusing the concepts of the present application.
[0018] The terms used herein are merely for describing specific embodiments and are not intended to limit the present application. The terms "including", "comprising", etc. used herein indicate the presence of features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.
[0019] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.
[0020] In the case of using expressions such as "at least one of A, B, and C", generally, it should be interpreted according to the meaning commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include, but is not limited to, a system having only A, only B, only C, having A and B, having A and C, having B and C, and / or having A, B, and C, etc.).
[0021] Related firmware update methods usually require downloading a complete firmware installation package even when the difference between the old and new versions of the firmware is small, that is, it is necessary to download all the contents of the new version of the firmware for a full update.
[0022] Taking the Baseboard Management Controller (BMC) firmware as an example, the BMC firmware is the core component for server hardware management, responsible for monitoring system health status, remote control, fault diagnosis, etc. When users need to update the firmware of the BMC, they usually need to download the complete firmware image file from a specified channel (such as the official website of the server manufacturer, the internal firmware management system, etc.). The above firmware image file is a complete and independent file, containing all the codes, configuration information, and related driver programs required for the normal operation of the BMC. After the user downloads it, they will use a specific tool or through the command line to write this complete firmware image into the BMC to complete the firmware update. This method is simple but inefficient, especially when problems become prominent in large-scale deployments.
[0023] Since the volume of the complete firmware installation package is large, downloading the complete firmware installation package will cause bandwidth waste, occupy a large amount of network resources, resulting in too high resource consumption and long download and write times, leading to high time costs and low update efficiency. In addition, there may be compatibility issues between different versions. Differential updates require strict version matching and are prone to update failures due to version jumps (such as directly updating from an old version to a new version that spans multiple generations by skipping multiple intermediate versions).
[0024] Moreover, the full-scale update of a large-scale server cluster will occupy a large amount of bandwidth and storage resources, increase operating costs, and cause resource waste. Specifically, regardless of how much code actually changes during the update, even if only a few codes change, all data needs to be transmitted during the update. In the scenario of large-scale deployment, it will further lead to high resource consumption.
[0025] Furthermore, the large volume of the firmware installation package also makes the update process vulnerable to network fluctuations, and the risk of update failure in full-scale updates is high. For example, the risk of update interruption or failure and causing system instability is relatively high. In addition, full-scale updates will introduce a large number of code changes, increasing the system compatibility risk, especially in an environment where multiple versions coexist.
[0026] In view of this, an embodiment of the present application provides a firmware update method, including: obtaining the version information of each of multiple firmware partitions in the first version of the firmware installed in a target component, where the multiple firmware partitions are obtained by dividing the firmware into multiple logical regions according to multiple functions of the firmware; comparing the version information of each of the multiple firmware partitions in the currently available second version of the firmware with the version information of each of the multiple firmware partitions in the first version of the firmware to determine the partitions to be updated among the multiple firmware partitions of the first version of the firmware; determining the data differences between the partitions to be updated and the corresponding firmware partitions in the second version of the firmware to obtain an update data set; and sending the update data set to the target component so that the target component updates the first version of the firmware according to the update data set.
[0027] Figure 1 FIG. shows an application scenario diagram of a firmware update method, a firmware update device, a device, and a storage medium according to an embodiment of the present application.
[0028] As Figure 1 shown, the application scenario according to this embodiment may include a server 101 and a target component 102.
[0029] As Figure 1 shown, the server 101 may store a second version of the firmware, and the second version of the firmware may include multiple firmware partitions, and each firmware partition has its own version information. For example, the multiple firmware partitions include firmware partition 1, firmware partition 2... firmware partition N (N is a natural number). The multiple firmware partitions may be obtained by dividing the firmware into multiple logical regions according to multiple functions of the firmware.
[0030] The target component 102 may be installed with a first version of the firmware. Similarly, the first version of the firmware may include multiple firmware partitions, such as firmware partition 1, firmware partition 2... firmware partition N, and each firmware partition has its own version information. Similarly, the firmware partitions may be obtained by dividing the firmware into multiple logical regions according to multiple functions of the firmware. The firmware may have a unified division standard, that is, the firmware division standards in the server 101 and the target component 102 may be the same as each other. The firmware in the target component 102 may be (previously) obtained, for example, downloaded from the server 101.
[0031] For example, the target component 102 (e.g., periodically or upon request from the server 101) may send the version information of each of the multiple firmware partitions in the first version of the firmware to the server 101. The server 101 may execute a method for firmware update, including: obtaining the version information of each of the multiple firmware partitions in the first version of the firmware installed on the target component 102; comparing the version information of each of the multiple firmware partitions in the currently available second version of the firmware with the version information of each of the multiple firmware partitions in the first version of the firmware to determine the partitions to be updated among the multiple firmware partitions of the first version of the firmware; determining the data differences between the partitions to be updated and the corresponding firmware partitions in the second version of the firmware to obtain an update data set; and sending the update data set to the target component 102. After receiving the update data set, the target component 102 may update the first version of the firmware according to the update data set.
[0032] Next, in conjunction with Figures 2 to 4 the method for firmware update according to the embodiments of the present application will be described in detail. In the description, for ease of understanding, the scenario described will be used as an example with reference to Figure 1 the description.
[0033] Figure 2 FIG. shows a flowchart of the method for firmware update according to the embodiments of the present application.
[0034] As Figure 2 shown, the method for firmware update of this embodiment includes operations S210 to S240. This method may be executed by, for example, Figure 1 the server 101 shown.
[0035] In operation S210, obtain the version information of each of the multiple firmware partitions in the first version of the firmware installed on the target component, where the multiple firmware partitions are obtained by dividing the firmware into multiple logical regions according to multiple functions of the firmware. The target component is, for example, Figure 1 the target component 102 shown.
[0036] For example, according to multiple functions of the firmware, the firmware may be divided into multiple logical regions to obtain multiple firmware partitions. Each firmware partition may correspond to a specific function module. For example, firmware partition 1 may correspond to the bootloader module, and firmware partition 2 may correspond to the operating system kernel module, etc.
[0037] Taking the target component including a Baseboard Management Controller (BMC) as an example, the firmware installed in the baseboard management controller may include, for example, firmware partitions corresponding to the following functional modules: a Bootloader module, which can be responsible for functions such as hardware initialization and loading the operating system; an Operating System Kernel (Kernel) module, which can be responsible for managing hardware resources such as the Central Processing Unit (CPU), memory, and devices, and providing basic services for application programs; a Hardware Drivers (Drivers) module, which can be responsible for functions such as network drivers and sensor drivers; a Remote Management Stack (IPMI Stack) module, which can be responsible for out-of-band management of servers and network devices; a Configuration Parameters (Configuration) module, which can be responsible for managing operating parameters; and a User Interface (WebUI) module, which can be responsible for visual display and other functions.
[0038] For example, the version information may include the version numbers of the firmware partitions. The first version of the firmware may be the firmware before the update. Correspondingly, the version information of each of the multiple firmware partitions in the first version of the firmware may include the version number of the version before the update. When each version of the firmware is released, a corresponding configuration file may be generated, and the version numbers of each firmware partition may be recorded through the configuration file. Hash values may also be generated for each firmware partition, and the hash values of each firmware partition may be recorded through the configuration file.
[0039] In operation S220, the version information of each of the multiple firmware partitions in the currently available second version of the firmware is compared with the version information of each of the multiple firmware partitions in the first version of the firmware to determine the partitions to be updated among the multiple firmware partitions of the first version of the firmware.
[0040] The second version of the firmware may be the updated firmware. Correspondingly, the version information of each of the multiple firmware partitions in the second version of the firmware may include the version number of the updated version. Since the firmware update may only update some data, only the version information of some firmware partitions may change after the update. For example, after the firmware is updated, only the version numbers of some firmware partitions change from 1.0 to 1.1, while the version numbers of other firmware partitions do not change.
[0041] Comparing the version information of each of the multiple firmware partitions in the currently available second-version firmware with the version information of each of the multiple firmware partitions in the first-version firmware may include: comparing the version numbers of each of the multiple firmware partitions in the second-version firmware with the version numbers of the corresponding firmware partitions in the first-version firmware. Herein, the so-called "corresponding" may mean that they correspond to the same functional module. For example, the version number of firmware partition 1 in the second-version firmware may be compared with the version number of firmware partition 1 in the first-version firmware (both of these firmware partitions correspond to, for example, the bootloader module), the version number of firmware partition 2 in the second-version firmware may be compared with the version number of firmware partition 2 in the first-version firmware (both of these firmware partitions correspond to, for example, the operating system kernel module), and so on.
[0042] The partition(s) to be updated may include one or more firmware partitions in the first-version firmware whose version information is inconsistent with that of the corresponding firmware partitions in the second-version firmware. For example, the version number of firmware partition 1 in the first-version firmware is 1.0, while the version number of firmware partition 1 in the second-version firmware is 1.1. Since the version number of firmware partition 1 in the first-version firmware is inconsistent with the version number of the corresponding firmware partition in the second-version firmware, the partition to be updated may include firmware partition 1 in the first-version firmware.
[0043] The inconsistent version information of the partition(s) to be updated in the first-version firmware and the second-version firmware indicates that the data of the firmware partition(s) to be updated has been updated. On the other hand, the consistent version information of the other firmware partitions in the first-version firmware except the partition(s) to be updated with the corresponding firmware partitions in the second-version firmware indicates that their data has not changed. Therefore, only the partition(s) to be updated need to be updated, and there is no need to update the other firmware partitions in the first-version firmware except the partition(s) to be updated.
[0044] By dividing the firmware into multiple firmware partitions, the flexibility and efficiency of the update process can be improved, and the compatibility risk can be reduced. And dividing the firmware into multiple firmware partitions can modularize the update process, so that problems in a certain partition will not affect other partitions, thus simplifying firmware management and facilitating problem location.
[0045] In operation S230, determine the data difference between the partition(s) to be updated and the corresponding firmware partitions in the second-version firmware to obtain an update data set.
[0046] For example, perhaps not all the data in the partition(s) to be updated has been updated, but only some data has been updated. Therefore, the data difference between the partition(s) to be updated and the corresponding firmware partitions in the second-version firmware can be determined, and the data in the second-version firmware that is different from the first-version firmware is the update data.
[0047] In operation S240, the updated data set is sent to the target component so that the target component updates the first version of the firmware according to the updated data set.
[0048] For example, only the updated data set can be sent to the target component instead of sending all the data of the second version of the firmware to the target component, so that the target component can perform incremental updates only based on the updated data in the updated data set, rather than performing full-scale updates based on all the data of the second version of the firmware.
[0049] For example, during the process of sending the updated data set to the target component, in the case of a transmission interruption, the target component can record the offset of the last successfully received data block. When requesting to send the updated data set next time, the target component can request the remaining data blocks starting from the position corresponding to the offset from the server. For example, during the process of the server sending the updated data set to the target component, the target component only successfully receives the first 5 data blocks (assuming a total of 5MB), and the 6th data block is interrupted due to factors such as the communication link during transmission. Then the target component can record the offset as 5MB. When requesting to send the updated data set next time, the target component can request the data blocks after 5MB, thus avoiding repeated transmission of the first 5 received data blocks.
[0050] According to an embodiment of the present application, the firmware is divided into multiple logical regions according to multiple functions of the firmware to obtain multiple firmware partitions. The version information of each firmware partition in the current second version of the firmware is compared with the version information of each firmware partition in the first version of the firmware to determine the partition to be updated. Then, the data difference between the partition to be updated and the corresponding firmware partition in the second version of the firmware is determined to obtain the updated data set, and only the updated data set is sent to the target component. Through this incremental update mechanism, rather than the full-scale update mechanism of sending all the data to the target component, the data transmission volume during firmware update can be reduced, the firmware update time can be shortened, the operation and maintenance efficiency can be improved, and the resource consumption can be reduced. Moreover, by dividing the firmware into multiple logical regions according to multiple functions of the firmware, different functional modules can be isolated in independent logical regions, thereby effectively reducing compatibility problems caused by functional interaction, version iteration, or hardware differences and improving management efficiency.
[0051] According to an embodiment of the present application, determining the data difference between the partition to be updated and the corresponding firmware partition in the second version of the firmware to obtain the updated data set can be performed as follows.
[0052] The first data set corresponding to the partition to be updated can be divided into multiple first data units according to a predetermined unit, and the second data set corresponding to the corresponding firmware partition can be divided into multiple second data units according to the predetermined unit.
[0053] For example, the first data set may include all the data corresponding to the partition to be updated, and the second data set may include all the data corresponding to the corresponding firmware partition in the second version firmware. The predetermined unit may include a predetermined number of characters. According to the predetermined unit, the first data set may be divided into a sequence including a plurality of first data units, and the second data set may be divided into a sequence including a plurality of second data units.
[0054] By dividing the first data set and the second data set into a plurality of data units (i.e., a plurality of data blocks) respectively through the predetermined unit, and each data unit includes a plurality of characters, the overall comparison can be performed based on the plurality of data blocks instead of processing each character individually, which can reduce the calculation amount and improve the calculation efficiency.
[0055] In the plurality of second data units, the longest matching sequences at different positions can be determined. Each longest matching sequence includes consecutive second data units at the corresponding positions and matches the sequence of consecutive first data units in the plurality of first data units.
[0056] For example: the first data set is {A, B, C, D}, including a plurality of first data units A, B, C, D; the second data set is {A, B, Y, D}, including a plurality of second data units A, B, Y, D. By matching the plurality of second data units with the plurality of first data units, it can be determined that: in the plurality of second data units, for the position where A is located, the longest matching sequence, that is, the sequence of consecutive second data units that matches the sequence of the largest possible number of consecutive first data units in the first data set, can be {A, B} (in this case, the step of determining the longest matching sequence for the position where B is located can be skipped); in addition, for the position where D is located, the longest matching sequence can be {D}.
[0057] The updated data set can be determined according to the result of determining the longest matching sequence.
[0058] The data content of the second data units in the longest matching sequence is the same as the data content of the corresponding first data units, that is, the data content of the corresponding first data units has not been updated. And the data content of the other data in the plurality of second data units except the longest matching sequence is different from the plurality of first data units, that is, the data content of the other data except the longest matching sequence is the updated data. Therefore, the updated data set can include the other data in the plurality of second data units except the longest matching sequence.
[0059] By dividing the first data set and the second data set into multiple data units according to a predetermined unit and performing searches and matches only within a local range based on the multiple data units instead of a global match, the amount of computation can be reduced and the computational efficiency can be improved. By gradually determining the longest matching sequences at different positions, repeated matches can be avoided and the matching efficiency can be improved. By determining the updated data set according to the results of determining the longest matching sequences, the data differences between the first data set and the second data set can be accurately and efficiently determined, thereby determining the data that needs to be updated. Furthermore, only the data that needs to be updated can be sent, reducing the amount of data transmission, increasing the update speed, and reducing the storage requirements, so that it can be applied to an environment with limited storage resources.
[0060] According to an embodiment of the present application, determining the longest matching sequence may include: matching the multiple first data units with the multiple second data units according to the first hash values respectively corresponding to the multiple first data units and the second hash values respectively corresponding to the multiple second data units to determine the longest matching sequence.
[0061] For example, the hash values of the multiple first data units and the multiple second data units can be calculated respectively to obtain the first hash value and the second hash value. In the case where the first hash value and the second hash value are the same, it indicates that the data contents of the first data unit corresponding to the first hash value and the second data unit corresponding to the second hash value are the same, that is, the above-mentioned first data unit matches the above-mentioned second data unit. The second hash values of the respective second data units included in the longest matching sequence are respectively the same as the hash values of the consecutive first data units among the multiple first data units. Through the first hash value and the second hash value, the longest matching sequence can be efficiently and accurately determined.
[0062] According to an embodiment of the present application, the above firmware update method may further include: determining the minimum difference between the second data set and the first data set according to the determined longest matching sequence; generating an updated data set according to the minimum difference, where the updated data set includes the minimum difference and the position corresponding to the minimum difference.
[0063] For example, the minimum difference may include the other data in the second data set except for the longest matching sequences corresponding to the respective first data units. Still taking the above first data set {A, B, C, D} and the second data set {A, B, Y, D} as an example, since the longest matching sequences include {A, B} and {D}, the minimum difference between the second data set and the first set includes the data unit {Y}. Correspondingly, the updated data set includes the data unit {Y} and the position where the data unit is located in the second data set.
[0064] The updated data set only includes the minimum differences between the second data set and the first data set, rather than all the data in the second data set, and includes the corresponding positions of the minimum differences in the second data set, so that the target component can be updated efficiently and accurately based on the minimum differences and the corresponding positions between the second data set and the first data set.
[0065] According to an embodiment of the present application, the method for firmware update may further include: determining the size of a predetermined unit according to the function corresponding to the partition to be updated.
[0066] The data characteristics of firmware partitions corresponding to different functions may be different, and correspondingly, different sizes of predetermined units may be applicable. For example, the frequency of local modification of data in the bootloader module may be relatively low. Therefore, in the case where the partition to be updated includes a firmware partition corresponding to the bootloader module, a larger predetermined unit may be determined to reduce the matching overhead, and the size of the predetermined unit may be within a first numerical range. While the configuration parameter module has more frequent data updates. Therefore, in the case where the partition to be updated includes a firmware partition corresponding to the configuration parameter module, a smaller predetermined unit may be determined to improve the update accuracy, and the size of the predetermined unit may be within a second numerical range, where the first numerical range is greater than the second numerical range.
[0067] If a smaller predetermined unit is fixedly adopted, it may cause invalid matching for firmware partitions with a lower data update frequency, increasing the calculation overhead; if a larger predetermined unit is fixedly adopted, it may affect the data matching accuracy for firmware partitions with a higher data update frequency. By dynamically determining the size of the predetermined unit according to the function corresponding to the partition to be updated, for example, setting a larger predetermined unit for firmware partitions with a low update frequency and a smaller predetermined unit for firmware partitions with a high update frequency, compared with a fixed predetermined unit size, the matching accuracy can be improved and the calculation overhead can be reduced.
[0068] According to an embodiment of the present application, the updated data set may include multiple updated data subsets, where each of the multiple updated data subsets includes corresponding verification information.
[0069] After generating the updated data set, the server side may divide the updated data set into multiple updated data subsets. Verification information corresponding to each of the multiple updated data subsets may be generated. The verification information may include a digital signature. For example, the server side may use a private key to digitally sign each of the multiple updated data subsets respectively to obtain verification information corresponding to each of the multiple updated data subsets. The multiple updated data subsets and the verification information corresponding to each of the multiple updated data subsets may be sent to the target component together.
[0070] By dividing the update data set into multiple update data subsets and generating corresponding verification information for each update data subset separately, the target component can verify only the currently received update data subset, thereby improving the verification efficiency and reducing the computational overhead. Moreover, by generating corresponding verification information only for each update data subset separately, even if the data of some update data subsets is tampered with, it is possible to quickly locate the tampered update data subset without having to redownload the entire update data set, thus improving the update efficiency.
[0071] According to an embodiment of the present application, sending the update data set to the target component may include: sending multiple update data subsets to the target component respectively, so that the target component verifies the currently received update data subset based on the verification information of the currently received update data subset.
[0072] For example, multiple update data subsets can be sent to the target component respectively, that is, fragmented transmission is performed. The target component verifies based on the verification information of the currently received update data subset. For example, the target component can perform real-time verification every time it receives an update data subset, rather than waiting to receive all the update data subsets before performing unified verification. Further, the security of the transmission process can be ensured through encrypted transmission.
[0073] By performing fragmented transmission on multiple update data subsets and the target component performing verification every time it receives an update data subset, compared with performing unified verification after receiving all the update data subsets, problems with the update data subset can be discovered in a timely manner, avoiding wasting time and bandwidth.
[0074] For example, the target component verifying the currently received update data subset based on the verification information of the currently received update data subset may include: the target component uses the public key of the server side to verify the validity of the digital signature of the update data subset. In the case where the digital signature verification fails, it indicates that the data in the update data subset may have been tampered with. In this case, the target component can refuse to install the update data subset and can also generate an alarm message to prompt the staff to check.
[0075] For example, verification information can also be generated for the entire update data set, such as generating a hash value corresponding to the update data set, or the target component can perform verification based on the verification information of the entire update data set after receiving all the update data subsets. By generating verification information only for the update data set instead of for all firmware data, the target component only needs to verify the data that needs to be updated and does not need to verify all the firmware data, which can reduce the computational overhead and improve the verification efficiency.
[0076] For example, verification information can also be generated for the entire updated data set, and verification information can be generated separately for multiple subsets of the updated data. The verification can be performed based on the verification information of the entire updated data set and each of the multiple subsets of the updated data. By performing double verification on the updated data set and the subsets of the updated data, the verification accuracy can be improved and the data security can be enhanced.
[0077] Furthermore, since there may be time synchronization errors among different devices, a tolerance window with a reasonable size (e.g., ±5 minutes) can be set according to actual requirements, so as to avoid misjudgment caused by minor time deviations among different devices.
[0078] According to an embodiment of the present application, the method for firmware update further includes: the storage area of the firmware partition in the preset storage space includes a main storage sub-area and a standby sub-area; wherein, the main storage sub-area is used to store the firmware partition updated according to the updated data set, and the standby sub-area is used to store the firmware partition of the first version of the firmware, so that in the case where the target component fails to update the firmware partition of the first version of the firmware according to the updated data set, it can roll back to the firmware partition of the first version of the firmware in the standby sub-area.
[0079] For example, the storage area in the preset storage space can be divided into two areas to obtain a main storage sub-area and a standby sub-area. Multiple firmware partitions in the first version of the firmware installed in the target component can be stored in the standby sub-area. After the target component updates the partition to be updated of the first version of the firmware according to the updated data set to obtain the updated firmware partition, the updated firmware partition can be stored in the main storage sub-area, which can provide an independent low-latency recovery channel for the rollback operation and ensure that the device can quickly return to the normal state.
[0080] By storing the updated firmware partition and multiple firmware partitions in the first version of the firmware in different sub-areas of the preset storage space respectively, the system availability can be ensured in the case of firmware update failure, where the firmware update failure may be caused by verification failure of the subset of the updated data, power interruption, etc. Specifically, writing the updated firmware partition into the main storage sub-area will not affect the operation of multiple firmware partitions in the first version of the firmware in the standby sub-area. Therefore, in the case of update failure, it can be forced to re-run from multiple firmware partitions in the first version of the firmware in the standby sub-area, that is, roll back to the firmware partition of the first version of the firmware in the standby sub-area, so as to ensure that the firmware can always be started from an available firmware version and thus ensure that the firmware is always in a workable state. And in the case of successful update, it can be directly run according to the updated firmware partition.
[0081] Through the rollback mechanism, the system can be guaranteed to quickly recover in case of firmware update failure, thus improving system stability. By performing rollback by firmware partition instead of full disk rollback, the computing overhead can be reduced.
[0082] Figure 3 FIG. shows a system interaction diagram of a method for firmware update according to an embodiment of the present application.
[0083] Figure 4 FIG. shows a schematic diagram of a verification process according to an embodiment of the present application.
[0084] Among them, the target component may include, for example, a Baseboard Management Controller (abbreviated as BMC).
[0085] In operation S310, the baseboard management controller may request to update the firmware from the server.
[0086] For example, the baseboard management controller may send the version information of each firmware partition in the first version of the firmware installed in the baseboard management controller to the server. Specifically, the baseboard management controller may send the configuration file of the first version of the firmware to the server. The configuration file may include the version number of each firmware partition and the hash values pre-generated for the multiple firmware partitions.
[0087] In operation S320, after obtaining the version information of each firmware partition in the first version of the firmware, the server may generate an update data set, where the update data set may include multiple update data subsets.
[0088] The first data set may be divided into multiple first data units according to a predetermined unit, the second data set may be divided into multiple second data units, and the longest matching sequences at different positions may be determined in the multiple second data units.
[0089] Determining the longest matching sequences at different positions in the multiple second data units may include, for example: for a sequence including multiple first data units, taking x as a pointer, searching for the longest matching sequence in the sliding window around the corresponding x pointer in the sequence including multiple second data units. The size of the sliding window may be, for example, [x - 64, x + 64]. Searching and matching within the sliding window instead of global search can reduce the amount of calculation. By determining the longest matching string at the current position each time, the global optimum can be approached by ensuring local optimality. By gradually advancing the x pointer for matching, repeated comparison can be avoided.
[0090] In operation S330, the server may send multiple subsets of updated data to the baseboard management controller respectively. By sending only the subsets of updated data instead of the complete firmware installation package, the update efficiency can be improved and the update time can be reduced through the incremental update method. For example, it is found through testing that the data transfer volume of the method of sending the complete firmware installation package is 128MB, and the update time takes 15 to 30 minutes, and the compatibility depends on the firmware version. However, by sending only the subsets of updated data, the data transfer volume can be reduced to 1 to 10MB, the update time can be shortened to 5 to 10 minutes, and cross-version upgrades can be supported.
[0091] In operation S340, after receiving the subsets of updated data, the baseboard management controller may verify and update the firmware.
[0092] As Figure 4 shown, the verification process may include integrity verification. For example, after receiving the subsets of updated data, the baseboard management controller may merge the subsets of updated data with the other firmware partitions except the partition to be updated in multiple firmware partitions of the first version of the firmware to generate new firmware partitions. The hash value of the new firmware partitions can be calculated and compared with the hash value pre-stored in the configuration file. When the hash value of the new firmware partitions is the same as the hash value of the corresponding partitions in the second version of the firmware, it indicates that the data of the new firmware partitions is complete and not tampered with. Therefore, the integrity verification can be passed. Among them, the correct hash values of each firmware partition can be pre-stored in the configuration file. Through the validity verification, it can be verified whether the firmware data is tampered with during transmission, storage, etc., so as to ensure the integrity of the firmware after the update.
[0093] The verification process may also include validity verification. For example, the server side may use the private key to verify the signature of the subsets of updated data. After receiving the subsets of updated data, the baseboard management controller may use the public key of the server to verify the validity of the signature of the subsets of updated data.
[0094] The verification process may also include compatibility verification. For example, when merging the new data set with the other firmware partitions except the partition to be updated in multiple firmware partitions of the first version of the firmware, the dependency relationship between the firmware partitions can be determined. For the firmware partitions with a dependency relationship, they can be merged in a preset order. If it is determined that the Bootloader module depends on the Kernel module, the firmware partitions corresponding to the above two modules can be merged in the preset order. It can be verified whether the merge order corresponds to the preset order. If not, the compatibility verification fails.
[0095] According to an embodiment of the present application, the central server can determine and transmit the updated data set. However, the situation where a large number of devices need to be updated simultaneously will cause an excessive load on the central server. It is also possible for the central server to first push the updated data set to a preset edge server cluster. Multiple edge server nodes in the edge server cluster can cache the updated data set. In the case where a device requests an update, it can directly download the updated data set from the edge node closest to the device without having to access the central server again. Moreover, multiple edge server nodes in the edge server cluster can transmit the updated data set to each other through the Peer-to-Peer (P2P) protocol, thereby reducing the pressure on the central server.
[0096] Based on the above firmware update method, the present application also provides a firmware update device. The following will be combined with Figure 5 to describe this device in detail.
[0097] Figure 5 The block diagram of the firmware update device according to an embodiment of the present application is shown.
[0098] As Figure 5 shown, the firmware update device 500 of this embodiment includes an obtaining module 510, a comparison module 520, a first determination module 530, and a sending module 540.
[0099] The obtaining module 510 is used to obtain the version information of each of the multiple firmware partitions in the first version firmware installed in the target component. The multiple firmware partitions are obtained by dividing the firmware into multiple logical regions according to multiple functions of the firmware. In one embodiment, the obtaining module 510 can be used to perform the operation S210 described above, which will not be elaborated here.
[0100] The comparison module 520 is used to compare the version information of each of the multiple firmware partitions in the currently available second version firmware with the version information of each of the multiple firmware partitions in the first version firmware, and determine the partitions to be updated among the multiple firmware partitions of the first version firmware. In one embodiment, the comparison module 520 can be used to perform the operation S220 described above, which will not be elaborated here.
[0101] The first determination module 530 is used to determine the data difference between the partition to be updated and the corresponding firmware partition in the second version firmware, and obtain the updated data set. In one embodiment, the first determination module 530 can be used to perform the operation S230 described above, which will not be elaborated here.
[0102] A sending module 540 is configured to send the updated data set to a target component, so that the target component updates the first version firmware according to the updated data set. In one embodiment, the sending module 540 may be configured to perform the operation S240 described above, which will not be elaborated here.
[0103] According to an embodiment of the present application, the first determination module includes a first partitioning sub-module, a second partitioning sub-module, a first determination sub-module, and a second determination sub-module.
[0104] The first partitioning sub-module is configured to partition a first data set corresponding to a partition to be updated into a plurality of first data units according to a predetermined unit; the second partitioning sub-module is configured to partition a second data set corresponding to a corresponding firmware partition into a plurality of second data units according to a predetermined unit; the first determination sub-module is configured to determine the longest matching sequences at different positions among the plurality of second data units, each longest matching sequence including consecutive second data units at the corresponding position and matching the sequence of consecutive first data units among the plurality of first data units; the second determination sub-module is configured to determine the updated data set according to the result of determining the longest matching sequences.
[0105] According to an embodiment of the present application, the first determination sub-module includes a matching unit.
[0106] The matching unit is configured to match the plurality of first data units with the plurality of second data units according to the first hash values corresponding to the plurality of first data units and the second hash values corresponding to the plurality of second data units respectively, so as to determine the longest matching sequences.
[0107] According to an embodiment of the present application, the firmware update device further includes a second determination module and a generation module.
[0108] The second determination module is configured to determine the minimum difference between the second data set and the first data set according to the determined longest matching sequences; the generation module is configured to generate the updated data set according to the minimum difference, where the updated data set includes the minimum difference and the corresponding position of the minimum difference.
[0109] According to an embodiment of the present application, the firmware update device further includes a third determination module, configured to determine the size of the predetermined unit according to the function corresponding to the partition to be updated.
[0110] According to an embodiment of the present application, the sending module includes a sending sub-module, configured to send the plurality of updated data subsets to the target component respectively, so that the target component verifies the currently received updated data subset based on the verification information of the currently received updated data subset.
[0111] According to embodiments of the present application, any multiple of the obtaining module 510, the comparison module 520, the first determination module 530, and the sending module 540 may be combined and implemented in one module, or any one of them may be split into multiple modules. Alternatively, at least part of the functions of one or more of these modules may be combined with at least part of the functions of other modules and implemented in one module. According to embodiments of the present application, at least one of the obtaining module 510, the comparison module 520, the first determination module 530, and the sending module 540 may be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on chip, a system on a substrate, a system in a package, an application specific integrated circuit (ASIC), or may be implemented by any other reasonable means such as integrating or packaging circuits, etc., in hardware or firmware, or implemented in any one of the three implementation manners of software, hardware, and firmware, or in an appropriate combination of any several of them. Alternatively, at least one of the obtaining module 510, the comparison module 520, the first determination module 530, and the sending module 540 may be at least partially implemented as a computer program module, and when the computer program module is run, corresponding functions may be executed.
[0112] Figure 6 A block diagram of an electronic device suitable for implementing a firmware update method according to an embodiment of the present application is schematically shown.
[0113] As Figure 6 shown, the electronic device 600 according to an embodiment of the present application includes a processor 601, which may perform various appropriate actions and processes according to a program stored in a read only memory (ROM) 602 or a program loaded from a storage section 608 into a random access memory (RAM) 603. The processor 601 may include, for example, a general microprocessor (such as a CPU), an instruction set processor, and / or a related chipset, and / or a dedicated microprocessor (such as an application specific integrated circuit (ASIC)), and so on. The processor 601 may also include on-board memory for caching purposes. The processor 601 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present application.
[0114] In the RAM 603, various programs and data required for the operation of the electronic device 600 are stored. The processor 601, the ROM 602, and the RAM 603 are connected to each other via the bus 604. The processor 601 performs various operations of the method flow according to the embodiments of the present application by executing the programs in the ROM 602 and / or the RAM 603. It should be noted that the programs can also be stored in one or more memories other than the ROM 602 and the RAM 603. The processor 601 can also perform various operations of the method flow according to the embodiments of the present application by executing the programs stored in one or more memories.
[0115] According to an embodiment of the present application, the electronic device 600 may further include an input / output (I / O) interface 605, and the input / output (I / O) interface 605 is also connected to the bus 604. The electronic device 600 may further include one or more of the following components connected to the input / output (I / O) interface 605: an input part 606 including a keyboard, a mouse, etc.; an output part 607 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage part 608 including a hard disk, etc.; and a communication part 609 including a network interface card such as a LAN card, a modem, etc. The communication part 609 performs communication processing via a network such as the Internet. The drive 610 is also connected to the input / output (I / O) interface 605 as needed. A removable medium 611, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 610 as needed so that a computer program read from it can be installed into the storage part 608 as needed.
[0116] The present application also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or may exist separately without being assembled into the device / apparatus / system. The above computer-readable storage medium carries one or more programs, and when the one or more programs are executed, the method according to the embodiments of the present application is implemented.
[0117] According to an embodiment of the present application, the computer-readable storage medium may be a non-volatile computer-readable storage medium, for example, it may include but is not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In the present application, the computer-readable storage medium may be any tangible medium that contains or stores a program, and this program can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to an embodiment of the present application, the computer-readable storage medium may include the above-described ROM 602 and / or RAM 603 and / or one or more memories other than ROM 602 and RAM 603.
[0118] An embodiment of the present application further includes a computer program product, which includes a computer program, and the computer program contains program code for executing the method shown in the flowchart. When the computer program product runs in a computer system, the program code is used to enable the computer system to implement the method provided by the embodiment of the present application.
[0119] When the computer program is executed by the processor 601, it executes the above functions defined in the system / apparatus of the embodiment of the present application. According to an embodiment of the present application, the above-described systems, apparatuses, modules, units, etc. can be implemented by computer program modules.
[0120] In one embodiment, the computer program may rely on tangible storage media such as optical storage devices and magnetic storage devices. In another embodiment, the computer program may also be transmitted and distributed in the form of a signal on a network medium, and be downloaded and installed through the communication part 609, and / or be installed from the removable medium 611. The program code included in the computer program can be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.
[0121] In such an embodiment, the computer program can be downloaded and installed from the network through the communication part 609, and / or be installed from the removable medium 611. When the computer program is executed by the processor 601, it executes the above functions defined in the system of the embodiment of the present application. According to an embodiment of the present application, the above-described systems, devices, apparatuses, modules, units, etc. can be implemented by computer program modules.
[0122] According to embodiments of the present application, program code for executing the computer programs provided by the embodiments of the present application may be written in any combination of one or more programming languages. Specifically, these computing programs may be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include, but are not limited to, such as Java, C++, Python, the "C" language, or similar programming languages. The program code may be executed entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., through the Internet using an Internet service provider).
[0123] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and combinations of blocks in the block diagram or flowchart, may be implemented by a dedicated hardware-based system for performing the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.
[0124] Those skilled in the art can understand that the features described in the various embodiments of the present application can be combined and / or combined in various ways, even if such combinations or combinations are not explicitly described in the present application. In particular, without departing from the spirit and teachings of the present application, the features described in the various embodiments of the present application can be combined and / or combined in various ways. All such combinations and / or combinations fall within the scope of the present application.
[0125] The above describes the embodiments of the present application. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of the present application. Although the embodiments are described separately above, this does not mean that the measures in the various embodiments cannot be used advantageously in combination. Without departing from the scope of the present application, those skilled in the art can make various substitutions and modifications, and all such substitutions and modifications should fall within the scope of the present application.
Claims
1. A method for firmware update, characterized in that, The method includes: Obtaining the version information of each of multiple firmware partitions in a first version firmware installed in a target component, where the multiple firmware partitions are obtained by dividing the firmware into multiple logical regions according to multiple functions of the firmware; Comparing the version information of each of the multiple firmware partitions in a currently available second version firmware with the version information of each of the multiple firmware partitions in the first version firmware, and determining the partitions to be updated among the multiple firmware partitions of the first version firmware; Determining the data differences between the partitions to be updated and the corresponding firmware partitions in the second version firmware to obtain an update data set; and Sending the update data set to the target component so that the target component updates the first version firmware according to the update data set.
2. The method according to claim 1, wherein The determining the data differences between the partitions to be updated and the corresponding firmware partitions in the second version firmware to obtain an update data set includes: Dividing a first data set corresponding to the partition to be updated into multiple first data units according to a predetermined unit; Dividing a second data set corresponding to the corresponding firmware partition into multiple second data units according to the predetermined unit; Among the multiple second data units, determining the longest matching sequences at different positions, where each longest matching sequence includes consecutive second data units at the corresponding positions and matches a sequence of consecutive first data units among the multiple first data units; Determining the update data set according to the result of determining the longest matching sequences.
3. The method according to claim 2, wherein Determining the longest matching sequences includes: Matching the multiple first data units with the multiple second data units according to first hash values corresponding to the multiple first data units and second hash values corresponding to the multiple second data units to determine the longest matching sequences.
4. The method according to claim 3, characterized in that, The method further includes: Determining the minimum difference between the second data set and the first data set according to the determined longest matching sequences; Generating the update data set according to the minimum difference, where the update data set includes the minimum difference and the positions corresponding to the minimum difference.
5. The method according to claim 2, wherein The method further includes: Determining the size of the predetermined unit according to the function corresponding to the partition to be updated.
6. The method according to claim 1, characterized in that, The update data set includes multiple update data subsets, where each of the multiple update data subsets includes corresponding verification information; The sending the update data set to the target component includes: Sending the multiple update data subsets to the target component respectively so that the target component verifies the currently received update data subset based on the verification information of the currently received update data subset.
7. The method according to claim 1, characterized in that, The method further includes: The storage area of the firmware partition in a preset storage space includes a main storage sub-area and a standby sub-area; Among them, the main storage sub-region is used to store the firmware partition updated according to the update data set, and the spare sub-region is used to store the firmware partition of the first version of the firmware, so that in the case where the target component fails to update the firmware partition of the first version of the firmware according to the update data set, it can roll back to the firmware partition of the first version of the firmware in the spare sub-region.
8. A firmware update device, characterized in that, The device includes: An obtaining module, configured to obtain the version information of each of multiple firmware partitions in the first version of the firmware installed in the target component, where the multiple firmware partitions are obtained by dividing the firmware into multiple logical regions according to multiple functions of the firmware; A comparison module, configured to compare the version information of each of multiple firmware partitions in the currently available second version of the firmware with the version information of each of multiple firmware partitions in the first version of the firmware, and determine the partitions to be updated among the multiple firmware partitions of the first version of the firmware; A first determination module, configured to determine the data difference between the partition to be updated and the corresponding firmware partition in the second version of the firmware, so as to obtain an update data set; and A sending module, configured to send the update data set to the target component, so that the target component updates the first version of the firmware according to the update data set.
9. An electronic device, including: One or more processors; A memory, configured to store one or more computer programs, Characterized in that the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program or instructions stored thereon, characterized in that, The computer program or instruction, when executed by the processor, implements the steps of the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Firmware updating method, device, system and equipment and storage medium
CN118819583A
Firmware upgrading method and device, computer equipment, storage medium and program product
CN119987828A
Firmware Update System
US20140007069A1
Cited By
Refreshing method and device of substrate management controller, storage medium and program product
CN120523500A
Method, device, storage medium and program product for refreshing a baseboard management controller
CN120523500B
Firmware upgrading method, electronic equipment, storage medium and program product
CN120704722A