A memory firmware upgrade method and memory
By identifying the memory's operating mode and metadata table status, and collaboratively determining the physical and logical states, the problem of firmware upgrade failure in write-protected mode is solved, thus achieving reliable memory operation and data security.
Patent Information
- Application Number
- CN202510983941.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-17
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2045-07-17
AI Technical Summary
When the firmware of a memory enters write-protected mode due to a defect, firmware upgrade operations cannot be performed, causing the operating system to fail to boot. Existing technologies cannot effectively solve this problem.
By identifying the operating mode of the memory, reading the physical and logical states of the metadata table, and jointly determining whether the physical and logical states are normal, the write protection mode is removed and the firmware upgrade operation is performed only when both are normal.
Firmware upgrades are completed securely in write-protected mode, ensuring that firmware defects are fixed, the operating system boots normally, and the memory operates reliably and data is secure.
Smart Images

Figure CN120492007B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of storage, in particular to a firmware upgrade method of a memory and the memory. BACKGROUND
[0002] When an unexpected situation occurs in the algorithm logic of the firmware of the memory, the firmware will autonomously enter a write protection mode to protect data integrity. Once the write protection mode is entered, the host cannot perform any write operation on the memory. The firmware upgrade operation is generally scheduled at the stage when the operating system runs the bootloader or the kernel, which inevitably needs to perform data write operation.
[0003] However, once the firmware of the memory enters the write protection mode due to defects, and it is necessary to perform firmware upgrade operation for repair, since the write protection mode prevents the necessary write operation, the operating system cannot be successfully started and the bootloader cannot be executed. The bootloader is a key stage for performing firmware upgrade operation, and its failure to execute normally will result in the failure of firmware upgrade operation, and ultimately the firmware defects cannot be repaired. Therefore, there is room for improvement. SUMMARY
[0004] The present application provides a firmware upgrade method of a memory and the memory, which can perform firmware upgrade operation in the write protection mode.
[0005] The present application provides a firmware upgrade method of a memory, comprising:
[0006] According to the firmware upgrade request, identifying the working mode of the memory;
[0007] When the memory is in the write protection mode, reading the physical block where the metadata table is located to detect its physical state, and reading the metadata table to analyze its logical state;
[0008] Based on the physical state and the logical state, it is determined that when the physical state is normal and the logical state is normal, the write protection mode of the memory is released, and the firmware upgrade operation is performed.
[0009] In an embodiment of the present application, the step of identifying the working mode of the memory according to the firmware upgrade request comprises:
[0010] According to the firmware upgrade request, it is determined whether the memory can perform write operation:
[0011] If yes, it is determined that the memory is in normal mode, and the firmware upgrade operation is performed;
[0012] Otherwise, it is determined that the memory is in the write protection mode.
[0013] In an embodiment of the present application, the step of identifying and detecting the physical blocks where the metadata tables are located comprises:
[0014] identifying and detecting the physical blocks where the metadata tables are located:
[0015] when all the physical blocks are in the normal state, determining that the physical state is the normal state;
[0016] otherwise, determining that the physical state is the abnormal state.
[0017] In an embodiment of the present application, the step of identifying and detecting the physical blocks where the metadata tables are located comprises:
[0018] identifying and detecting the physical blocks where the metadata tables are located to obtain the erase times and read-write states of each physical block;
[0019] determining the physical state according to the erase times and read-write states of all the physical blocks.
[0020] In an embodiment of the present application, the step of determining the physical state according to the erase times and read-write states of all the physical blocks comprises:
[0021] judging the erase times and read-write states of all the physical blocks:
[0022] when the erase times of all the physical blocks are less than a preset erase threshold and the read-write states of all the physical blocks are in the normal state, determining that the physical state is the normal state;
[0023] otherwise, determining that the physical state is the abnormal state.
[0024] In an embodiment of the present application, the step of reading the metadata tables to analyze the logical states thereof comprises:
[0025] reading and judging the mapping relationships of all the metadata tables:
[0026] when the mapping relationships of all the metadata tables are in the normal state, determining that the logical state is the normal state;
[0027] otherwise, determining that the logical state is the abnormal state.
[0028] In an embodiment of the present application, the step of reading and judging the mapping relationships of all the metadata tables comprises:
[0029] reading and judging the mapping relationships of each metadata table in turn according to a preset reading sequence:
[0030] When the mapping relationship of the currently read metadata table is in the normal state, the mapping relationship of the next metadata table is read and judged until all the mapping relationships of the metadata tables are in the normal state, and the logical state is determined as the normal state.
[0031] When the mapping relationship of the currently read metadata table is in the abnormal state, the logical state is determined as the abnormal state.
[0032] In an embodiment of the present application, the physical state and the logical state are cooperatively determined, and when the physical state is in the normal state and the logical state is in the normal state, the write protection mode of the memory is released, and the step of performing the firmware upgrade operation comprises:
[0033] The physical state and the logical state are determined.
[0034] When the physical state is in the normal state and the logical state is in the normal state, the write protection mode of the memory is released, and the firmware upgrade operation is performed.
[0035] Otherwise, the write protection mode of the memory is maintained, and the firmware upgrade operation is prohibited.
[0036] In an embodiment of the present application, the step of releasing the write protection mode of the memory and performing the firmware upgrade operation comprises:
[0037] The available storage space of the user area of the memory and the data amount of the configuration parameters of the memory when performing initialization are determined.
[0038] When the available storage space is greater than or equal to the data amount of the configuration parameters, the write protection mode of the memory is released, and the firmware upgrade operation is performed after the initialization is completed.
[0039] Otherwise, the write protection mode of the memory is maintained, and the firmware upgrade operation is prohibited.
[0040] The present application also provides a memory, when the memory is in the write protection mode and needs to perform the firmware upgrade operation, the memory performs the firmware upgrade method of the memory to perform the firmware upgrade operation.
[0041] The application has the beneficial effects that: when the memory enters the write protection mode due to the firmware logic defect, the method actively intervenes in the key stage before the operating system starts; the physical reliability is evaluated by reading the erasing times and the reading state of the physical block where the metadata table is located, and the mapping relationship and the data structure of the metadata table are analyzed to verify the logical integrity; only when the physical state and the logical state are both determined to be normal, the write protection mode is safely released and the firmware upgrade operation is performed, so that even in the write protection mode, the detection and repair process can be safely completed in the bootloader stage, the firmware defect can be repaired, the operating system can be normally started, and the reliable operation and data security of the memory are ensured. BRIEF DESCRIPTION OF DRAWINGS
[0042] The accompanying drawings, which are incorporated herein and form a part of the specification, illustrate embodiments consistent with the present application and, together with the description, further serve to explain the principles of the application. It is to be expressly understood that the drawings are included solely for purposes of illustration and are not to be construed as a limitation of the application. It is to be expressly understood that the drawings are included solely for purposes of illustration and are not to be construed as a limitation of the application. The detailed description set forth below in connection with the appended drawings is intended as a description of various embodiments of the application and is not intended to represent the only embodiments in which the present application can be practiced. Each embodiment described in this disclosure is intended to cover all alternatives, modifications and equivalents falling within the scope of the embodiments described herein.
[0043] In the drawings:
[0044] Figure 1 A flowchart of a firmware upgrade method of a memory according to an embodiment of the application. DETAILED DESCRIPTION
[0045] While the application is susceptible to various modifications and alternative forms, specific embodiments thereof have been shown by way of example in the drawings and are herein described in detail. It should be understood, however, that the application is not to be limited to the particular embodiments described, as this can vary. It is to be understood that the application includes all alternatives, modifications and equivalents falling within the scope of the appended claims along with their full scope of equivalents thereunder. Other objectives, features and advantages of the present application will become apparent from the following detailed description, the drawings, and the appended claims.
[0046] It is to be understood that the embodiments provided by the following examples are only illustrative of the present application and are not meant to limit the scope of the application as set forth in the appended claims. The following examples are provided by way of example only and are not meant to limit the scope of the application as set forth in the appended claims.
[0047] In the following description, numerous specific details are discussed to provide a thorough understanding of embodiments of the application. One skilled in the relevant art will recognize, however, that the application can be practiced without one or more of the specific details, or with other methods, components, materials, and so forth. In other instances, well-known structures, materials, or operations are not shown or described in detail in order to avoid obscuring aspects of the application.
[0048] Referring to Figure 1 The application discloses a firmware upgrade method of a memory. The firmware upgrade method can upgrade the firmware of the memory in a specific scenario, which can be a scenario where the memory is in a write protection mode. The firmware upgrade method can include the following steps: step S10, identifying the working mode of the memory according to a firmware upgrade request.
[0049] In some embodiments, step S10 can include the following steps: judging whether the memory can perform a write operation according to the firmware upgrade request: if yes, determining that the memory is in a normal mode, and performing a firmware upgrade operation; otherwise, determining that the memory is in a write protection mode.
[0050] In some embodiments, after receiving the firmware upgrade request, the host system immediately starts a judgment process of the current state of the memory in the BootROM stage. The host system can issue a specific command (such as a CMD2 command) to obtain identity information, which requires the memory to return the complete data of its identity register (CID). The memory responds to the command and returns the current state information stored in its identity register to the host through the data bus. After receiving the identity register data, the host system analyzes the data, and specifically, can obtain the reserved field (Resv field) in the identity register. When the memory enters the write protection mode due to the firmware logic not meeting the expectation, the internal firmware logic will actively update the value of the reserved field to “1”. Therefore, the host system can obtain an explicit indication signal about whether the memory is in a write-inhibiting mode by reading and checking the specific value of the reserved field.
[0051] In some embodiments, if the value of the reserved field of the identity register is equal to “0”, the host system determines that the memory is currently in a normal mode, i.e., an operable read-write mode. At this time, the state of the memory accepting the write command is normal, and the memory is not in a protection state that prevents data writing. After confirming the normal state, the host system does not need to perform an additional write protection clearing operation and immediately starts to perform the firmware upgrade process. The host system sends batch write commands containing new firmware image data to the specified firmware partition of the memory according to the specific requirements of the received firmware upgrade request. These write commands and the new firmware data carried thereby are normally accepted and executed by the memory. The host system continues to perform data transmission until the entire new firmware image is successfully and completely updated to the target storage area of the memory. During or after the process, the host system can perform necessary data verification (such as read-back verification) to ensure the reliability of the firmware upgrade process.
[0052] In some embodiments, if the value of the reserved field of the identity register is equal to "1", the host system determines that the memory is currently in a write-protect mode. The write-protect mode means that the memory refuses to accept any write data command, even the critical data write operation required in the bootloader stage of system startup is blocked. After recognizing this write-protect mode, the host system can determine that the normal write capability required for the firmware upgrade operation is currently shielded or prohibited by the internal logic of the memory.
[0053] In some embodiments, the firmware upgrade method can further include the following steps: step S20, reading the physical block where the metadata table is located to detect its physical state when the memory is in the write-protect mode, and reading the metadata table to analyze its logical state.
[0054] In some embodiments, step S20 can include the following step: step S21, reading the physical block where the metadata table is located to detect its physical state when the memory is in the write-protect mode.
[0055] In some embodiments, step S21 can include the following steps: identifying and detecting the physical block where the metadata table is located: determining that the physical state is normal when all physical blocks are in a normal state; otherwise, determining that the physical state is abnormal.
[0056] In some embodiments, after determining that the memory is in the write-protect mode, the host starts the physical state detection process of the physical block where the metadata table is stored in the memory. In order to start this self-checking mode, the host can issue a specific setting command (such as CMD2 command) in the bootloader stage, and through the specific value combination of specific bits (bit0 to bit15) of its parameters (register address) when sending the command, the memory is told to enter the preset self-checking mode. After receiving this special instruction, the internal firmware logic of the memory is activated, and starts to execute the state detection of the physical block where the metadata table is located in the storage structure.
[0057] In some embodiments, in the step of identifying and detecting the physical block where the metadata table is located, it can specifically include the following steps: identifying and detecting the physical block where the metadata table is located to obtain the erase count and read-write state of each physical block; determining the physical state according to the erase count and read-write state of all physical blocks.
[0058] In some embodiments, the memory first identifies all physical blocks that need to be detected, which are specific physical units that currently save valid metadata, such as the storage location of the core metadata table including the physical block where the mapping relationship table is saved, the physical block where the bad block information table is saved, the physical block where the wear leveling state table is saved, and the physical block where the garbage collection marker table is saved.
[0059] In some embodiments, the physical state detection performed by the memory includes two main components: First, it detects the erase count for each physical block, with the internal firmware logic retrieving the cumulative erase count from the storage cells of each identified physical block. Second, it detects the read status of each physical block, where the memory attempts to perform a preset number of read operations on each target physical block (e.g., reading several specific sectors or pages containing key metadata table content) and verifies that each read operation was successfully completed and that the data validity check flag is normal. The purpose of this check is to promptly detect any potential physical media defects (such as physical damage to NAND flash memory cells that prevents correct data reading).
[0060] In some embodiments, the step of determining the physical state based on the number of erases and read / write status of all physical blocks may specifically include the following steps: determining the number of erases and read status of all physical blocks: when the number of erases of all physical blocks is less than a preset erase threshold and the read status of all physical blocks is normal, the physical state is determined to be normal; otherwise, the physical state is determined to be abnormal.
[0061] In some embodiments, after the memory completes the erase count extraction and read status test for all specified physical blocks, it can enter the comprehensive judgment stage and jointly judge the erase count and read status of all detected physical blocks.
[0062] In some embodiments, regarding the number of erases: the memory can check the number of erases for each physical block one by one to determine whether the number of erases is less than a preset erase threshold (this threshold is preset based on empirical values of the physical characteristics of the memory and the importance of the metadata table, in order to identify the risk that may be approaching the end of its life).
[0063] In some embodiments, for the read status: the memory checks the read operation result report of each physical block to determine whether the read status of the block is normal (i.e., all attempted read operations have been successfully completed and no errors have been reported).
[0064] In some embodiments, the memory will only determine the physical state to be normal if both of the following conditions are met: the number of erases of all detected physical blocks is less than a preset erase threshold and the read state of all detected physical blocks is normal.
[0065] In some embodiments, if the erase count of any physical block is greater than or equal to a preset erase threshold, or the read status of any physical block is reported as an abnormal state (such as read command timeout, check error, read data does not match the stored error correction code, or even the underlying medium reports a physical read failure, etc.), the memory immediately determines that the physical state is in an abnormal state. This determination result represents the health status evaluation of the physical storage unit on which the metadata table relies, and this process is completed by the memory itself performing detection and reporting the result, which fully utilizes its internal information and greatly reduces the complexity of the operation that the host needs to perform in the boot read-only memory stage.
[0066] In some embodiments, step S20 can further include the following step: step S22, reading the metadata table to analyze its logical state when the memory is in the write protection mode.
[0067] In some embodiments, step S22 can include the following steps: reading and judging the mapping relationship of all metadata tables: when the mapping relationship of all metadata tables is in a normal state, determining that the logical state is in a normal state; otherwise, determining that the logical state is in an abnormal state.
[0068] In some embodiments, in the step of reading and judging the mapping relationship of all metadata tables, it can specifically include the following steps: reading and judging the mapping relationship of each metadata table in turn according to a preset reading order: when the mapping relationship of the currently read metadata table is in a normal state, reading and judging the mapping relationship of the next metadata table, until the mapping relationship of all metadata tables is in a normal state, determining that the logical state is in a normal state; when the mapping relationship of the currently read metadata table is in an abnormal state, determining that the logical state is in an abnormal state.
[0069] In some embodiments, after completing the physical state detection, the evaluation of the logical state of the metadata table will continue to check the logical integrity of the internal data structure and their mutual relationship of the metadata table, to prevent system instability caused by mapping errors or table data damage. For example, the mapping relationship of each metadata table can be read and verified one by one according to a preset and rigorous reading order (from low level to high level or from core table to peripheral extension order). For example, the preset reading order can be according to the arrangement order of the mapping relationship table, the bad block table, the wear leveling table, and the garbage collection table.
[0070] In some embodiments, the mapping table can be divided into a primary mapping table and a secondary mapping table. First, the primary mapping table can be read and verified. The primary mapping table is the basis for constructing logical address to physical address conversion. After reading the contents of the primary mapping table, strict checks are performed according to the rules defined by the firmware logic. The main checkpoints can include: whether the mapping table entry points to a valid physical block address range (to ensure that there is no physical address out of bounds, i.e., the target address exceeds the maximum value of the actual physical address of the device); whether the mapping relationship item itself is in the correct format (such as whether the key flag is within the legal range); whether there are other illegal mapping states defined by the firmware logic. If any of the items does not conform to the normal logic rules preset by the firmware (for example, the physical block address pointed to by the mapping item is 0xFFFF, which does not exist), it is immediately determined that the mapping relationship of the metadata table currently read is in an abnormal state. Once any metadata table mapping relationship is abnormal, the memory immediately determines that the entire metadata table is in an abnormal state, and the subsequent check is ended.
[0071] In some embodiments, if the primary mapping table is verified (in a normal state), the physical location information of all currently valid secondary mapping tables is obtained according to the contents of the primary mapping table, and then each secondary mapping table is read in turn. For each read secondary mapping table, strict logical verification is also performed. The verification content includes: checking whether the structure and mapping item format of the secondary mapping table itself is correct; checking whether the secondary mapping table entry points to a valid physical address (also to prevent physical address out-of-bounds errors); checking whether the mapping relationship conforms to other logical rules set by the firmware. At the same time, since reading the secondary mapping table involves actual operation, the execution state of the read command is also monitored to confirm whether there is an error in the reading process itself (such as command timeout, data verification error, etc., which also belong to abnormalities). If it is found that the mapping relationship does not conform to the preset logic rules (for example, the user data block address indicated in the secondary mapping table points to a physically non-existent area) when checking any secondary mapping table, or the reading process itself fails, it is immediately determined that the mapping relationship of the secondary mapping table is in an abnormal state, and the entire logical state is further determined to be in an abnormal state, and the subsequent check is stopped.
[0072] In some embodiments, if the mapping relationship of the primary mapping table and all secondary mapping tables is verified to be normal, other key metadata tables will be read and verified in a preset order. These metadata tables can include, but are not limited to, bad block tables, wear leveling tables, and garbage collection marking tables, etc.
[0073] In some embodiments, for the bad block table, it can be checked whether the physical block address corresponding to the bad block marker recorded in the table is valid (i.e., whether it is within the device physical address range); whether the setting of the bad block marker itself conforms to the firmware rules (such as whether it is within the allowed bad block quantity threshold).
[0074] In some embodiments, for the wear leveling table, it can be checked whether the erase count value of each physical block recorded in the table is within a reasonable range.
[0075] In some embodiments, for the garbage collection mark table, it can be checked whether the mark state is in a legal state defined by the firmware (such as free, valid, invalid, etc.).
[0076] In some embodiments, errors occurring when reading the bad block table, the wear leveling table, and the garbage collection mark table are also considered as exceptions. As long as any situation not conforming to the preset logical rules of the firmware is found in these metadata tables (for example, the number of addresses marked as bad blocks in the bad block table far exceeds the total number of physical blocks of the device), it will be determined that the mapping relationship of the table is in an abnormal state, and the checking process will be terminated immediately, and the logical state of the entire metadata table will be declared as an abnormal state.
[0077] In some embodiments, only when all categories of metadata tables (the primary mapping table, all secondary mapping tables, and the bad block table, the wear leveling table, the garbage collection mark table, and other metadata tables) are checked one by one in the preset order, and no error is found in the mapping relationship or structure of any table that violates the preset logical rules of the firmware (such as physical address out-of-bounds, invalid state, illegal format, data corruption, etc.) and all read operations are successfully completed, it is finally determined that the mapping relationship of all metadata tables is in a normal state, and the final conclusion is drawn that the logical state of the entire metadata table is in a normal state. If an exception is detected for any metadata table at any stage of the above checking order, the memory immediately makes a determination that the logical state is in an abnormal state.
[0078] In some embodiments, the firmware upgrade method can further include the following step: step S30, based on the physical state and the logical state, determining that: when the physical state is in a normal state and the logical state is in a normal state, the write protection mode of the memory is released, and the firmware upgrade operation is performed.
[0079] In some embodiments, after obtaining the physical state detection result and the logical state evaluation result, the memory enters the final cooperative determination stage, that is, the overall situation of the metadata tables of the memory in the physical health level (physical state) and the data structure logical level (logical state) needs to be comprehensively evaluated.
[0080] In some embodiments, step S30 can include the following steps: judging the physical state and the logical state: when the physical state is in a normal state and the logical state is in a normal state, the write protection mode of the memory is released, and the firmware upgrade operation is performed; otherwise, the write protection mode of the memory is maintained, and the firmware upgrade operation is prohibited.
[0081] In some embodiments, if the result of the physical state determination is normal (i.e. none of the physical blocks of the metadata table has exceeded the erase count limit and all the read states are normal), and the result of the logical state determination is also normal (i.e. all the mapping relations and internal data structures of the metadata table comply with the pre-set logical rules of the firmware), the memory preliminarily considers that the metadata table of the memory is healthy and logically complete, and at this time, the conditions for attempting to remove the write protection mode and performing the firmware upgrade are met. The memory then enters the flow of removing the write protection mode and preparing to perform the firmware upgrade operation.
[0082] In some embodiments, if the result of the physical state determination is abnormal (i.e. at least one of the physical blocks has exceeded the erase count limit or the read state is abnormal), or the result of the logical state determination is abnormal (i.e. at least one of the metadata tables has logical errors in the mapping relations or data structures), the memory immediately determines that there is a potential risk of instability in the memory. The memory recognizes that even if a firmware upgrade attempt (FFU) is forcibly performed in the current state, it may fail due to physical damage or logical errors of the metadata table, re-enter the write protection mode after the upgrade, or even cause user data loss during the upgrade process, etc. Therefore, in this case, the memory will forcibly maintain the current write protection mode, and explicitly prohibit the issuance and execution of any firmware upgrade operation instruction. At the same time, in order to facilitate subsequent problem diagnosis and analysis, the internal state will be kept unchanged, and the original scene data (such as error logs, flag states, etc.) that triggered the write protection abnormal state will be preserved without any clearing or resetting operation, so as to ensure that the technical personnel can obtain key information to analyze the root cause of the fault in the subsequent stage.
[0083] In some embodiments, in the step of removing the write protection mode of the memory and performing the firmware upgrade operation, it can specifically include the following steps: judging the available storage space of the user area of the memory and the data amount of the configuration parameters configured by the memory when performing initialization; when the available storage space is greater than or equal to the data amount of the configuration parameters, removing the write protection mode of the memory and performing the firmware upgrade operation after the initialization is completed; otherwise, maintaining the write protection mode of the memory and prohibiting the firmware upgrade operation.
[0084] In some embodiments, when performing the firmware upgrade operation, the memory first needs to ensure whether it has sufficient storage space to complete the subsequent initialization flow and the write operation required by the firmware upgrade. Specifically, the available storage space size of the user data area can be obtained first. The memory compares the available storage space size with the total data amount of the configuration parameters required to be written for the initialization operation of the memory next. The configuration parameters refer to a small amount of key data required to be written for maintaining the running of the boot loader stage.
[0085] In some embodiments, if it is determined that the available storage space of the user area is greater than or equal to the total data amount of the configuration parameters to be written, the memory finally confirms that the condition for safe write protection release is met. The host system then sends a specific instruction to the memory to officially release the write protection mode of the memory. The memory performs internal operations to modify its relevant state flags (such as specific register bits). The host system can confirm that the memory has successfully exited the write protection mode by re-acquiring the identity register (for example, by sending the CMD2 command again and checking the write protection related reserved field in it). After confirming that the write protection mode has been released, the necessary initialization configuration parameters can be written to the memory according to the process. After successfully completing the initialization configuration, the memory immediately starts to safely and completely write new firmware image data to the specified firmware partition according to the firmware upgrade request, and finally completes the firmware upgrade operation.
[0086] In some embodiments, if it is found in the check that the available storage space of the user area is insufficient to accommodate the data amount of the configuration parameters required to be written in the initialization phase (even if the required space is small, but the available space is smaller or even zero), it is determined that the subsequent operation cannot be safely completed. In this case, although the physical state and the logical state of the memory are qualified, the memory still maintains the current write protection mode of the memory, explicitly prohibits the execution of any firmware upgrade operation instruction, and does not write the initialization configuration parameters. Maintaining the write protection mode can prevent the problem from being enlarged by invalid writing in the case of insufficient space. The memory may need to mark the insufficient space as a kind of storage state exception and terminate the current firmware upgrade process.
[0087] As can be seen, in the above scheme, when the memory enters the write protection mode due to firmware logic defects, the method actively intervenes in the key stage before the operating system starts; the physical reliability is evaluated by reading the erase times and reading state of the physical block where the metadata table is located, and the logical integrity is verified by analyzing the mapping relationship and data structure of the metadata table; only when both the physical state and the logical state are determined to be normal, the write protection mode is safely released and the firmware upgrade operation is performed, so that even in the write protection mode, the detection and repair process can be safely completed in the bootloader stage, ensuring that the firmware defects can be repaired and the operating system can be normally started, thereby ensuring the reliable operation and data security of the memory.
[0088] The application also provides a memory. When the memory is in a write protection mode and needs to upgrade firmware, the firmware upgrade method in the above embodiment can be executed to perform a firmware upgrade operation. Specifically, the memory reads a metadata table physical block, detects whether the number of erasures exceeds a standard and whether the reading state is normal to determine a physical state; meanwhile, the metadata table mapping relationship and data structure are analyzed to verify a logical state. Only when the physical state is normal, the logical state is normal, and the available space of the user area meets the writing requirement of the initialization configuration parameters, the write protection mode is automatically released and the firmware upgrade operation is performed; if either the physical or logical state is abnormal, or the available space is insufficient, the write protection mode is maintained, the upgrade is prohibited, and the abnormal state is preserved.
[0089] The above embodiments only exemplarily illustrate the principles and effects of the application, but are not used to limit the application. Any person skilled in the art can modify or change the above embodiments without departing from the spirit and scope of the application. Therefore, all equivalent modifications or changes completed by those skilled in the art without departing from the spirit and technical thought disclosed by the application should be covered by the claims of the application.
Claims
1. A method for firmware upgrade of a memory, the method comprising: The method comprises the following steps: According to the firmware upgrade request, the working mode of the memory is identified; When the memory is in the write protection mode, the physical block where the metadata table is located is identified and detected: when all physical blocks are in the normal state, the physical state is determined to be the normal state; otherwise, the physical state is determined to be the abnormal state; When the memory is in the write protection mode, the mapping relationship of all metadata tables is read and determined: when the mapping relationship of all metadata tables is in the normal state, the logical state is determined to be the normal state; otherwise, the logical state is determined to be the abnormal state; Based on the physical state and the logical state, the write protection mode of the memory is released, and the firmware upgrade operation is performed when the physical state is normal and the logical state is normal.
2. The method of Claim 1, wherein, The step of identifying the working mode of the memory according to the firmware upgrade request comprises: According to the firmware upgrade request, it is judged whether the memory can perform write operation: If yes, it is determined that the memory is in normal mode, and the firmware upgrade operation is performed; Otherwise, it is determined that the memory is in write protection mode.
3. The method of Claim 1, wherein, The step of identifying and detecting the physical block where the metadata table is located comprises: Identify and detect the physical block where the metadata table is located to obtain the erase count and read-write state of each physical block; According to the erase count and read-write state of all physical blocks, the physical state is determined.
4. The method of Claim 3, wherein, The step of determining the physical state according to the erase count and read-write state of all physical blocks comprises: Judge the erase count and read state of all physical blocks: When the erase count of all physical blocks is less than the preset erase threshold, and the read state of all physical blocks is the read normal state, the physical state is determined to be the normal state; Otherwise, the physical state is determined to be the abnormal state.
5. The method for firmware upgrade of memory according to claim 1, wherein, The step of reading and determining the mapping relationship of all metadata tables comprises: According to the preset reading order, the mapping relationship of each metadata table is read and determined in turn: When the mapping relationship of the currently read metadata table is in the normal state, the mapping relationship of the next metadata table is read and determined, until the mapping relationship of all metadata tables is in the normal state, the logical state is determined to be the normal state; When the mapping relationship of the currently read metadata table is in the abnormal state, the logical state is determined to be the abnormal state.
6. The method for firmware upgrade of memory according to claim 1, wherein, The step of determining the physical state and the logical state based on the physical state and the logical state: when the physical state is normal and the logical state is normal, the write protection mode of the memory is released, and the firmware upgrade operation is performed, comprising: Determine the physical state and the logical state: When the physical state is normal, and the logical state is normal, the write protection mode of the memory is released, and the firmware upgrade operation is performed; Otherwise, the write protection mode of the memory is maintained, and the firmware upgrade operation is prohibited.
7. The method of Claim 6, wherein, The step of releasing the write protection mode of the memory and performing the firmware upgrade operation comprises: Judge the available storage space of the user area of the memory and the data amount of the memory when performing initialization to configure parameters: when the available storage space is greater than or equal to the data amount of the configuration parameter, releasing the write protection mode of the memory and performing the firmware upgrade operation after initialization is completed; otherwise, maintaining the write protection mode of the memory and prohibiting the firmware upgrade operation.
8. A memory, comprising: when the memory is in the write protection mode and the firmware upgrade operation is required to be performed, the memory performs the firmware upgrade operation according to the firmware upgrade method of the memory in any one of claims 1-7.
Citation Information
Patent Citations
Method and system for upgrading storage device
CN114003245A
Method and device for intelligently identifying unreliable block in non-volatile storage medium
WO2020248798A1