Application mirror image flashing method, system-on-chip, controller and storage medium

By using the processor core of the system-on-a-chip (SoC) and the hardware security engine (HSE) to achieve parallel and synchronous loading of application images and bootloaders, the problems of high maintenance costs and difficulty in ensuring security during ECU software upgrades are solved, enabling flexible and secure ECU software updates.

CN120929110APending Publication Date: 2025-11-11CONTINENTAL AUTOMOTIVE (CHANGCHUN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511156764.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-18
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

Existing technologies for ECU software upgrades suffer from high maintenance costs and difficulty in ensuring security, especially when there is no need to disassemble or rely on complex external equipment, making it difficult to achieve flexible local or remote updates.

Method used

By employing the application image flashing method, and leveraging the processor core and hardware security engine HSE of the system-on-a-chip (SoC), the application image and bootloader are loaded and verified in parallel and synchronously, shortening the startup time and ensuring security and flexibility.

Benefits of technology

It improves the security and efficiency of ECU software upgrades, reduces maintenance costs, supports flexible local or remote updates, and shortens startup time.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120929110A_ABST
    Figure CN120929110A_ABST
Patent Text Reader

Abstract

The invention provides an application mirror image flashing method, a system-on-chip, a controller and a storage medium. According to the specific implementation scheme, when a processor core of the SOC determines that a first partition serves as a current main partition, a first application mirror image and a corresponding first BL are flashed to a second partition; the HSE of the SOC calculates a trust label of the first application mirror image and flashes the trust label to a main table; the processor core of the SOC updates the first application mirror image and the flash address of the first BL to a main table; when the processor core of the SOC controls the controller to be restarted and the target BL of the processor core of the SOC is started to run, the SOC synchronously triggers the target BL to be initialized and the HSE of the SOC loads a first application mirror image for signature verification; when the target BL of the SOC determines that the signature verification result is successful, the processor core of the SOC runs the first application mirror image; and the processor core of the SOC performs memory updating operation according to the running state of the first application mirror image. According to the scheme, due to the fact that loading of the first application mirror image by the HSE and starting operation of the BL are synchronous and parallel, the starting time of the SOC and the controller is shortened.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of software upgrade technology, and in particular to methods for application image flashing, system-on-a-chip, controllers, and storage media. Background Technology

[0002] Bootloader-based ECU (Electronic Control Unit) software flashing is an efficient and secure firmware update method. By pre-installing a dedicated bootloader in the ECU, software upgrades or repairs can be completed without disassembly or reliance on complex external devices. Its core advantages lie in supporting flexible local or over-the-air (OTA) updates, significantly reducing maintenance costs, while meeting the automotive industry's high requirements for functional safety and cybersecurity. It is widely used in vehicle manufacturing, after-sales maintenance, and software iteration for intelligent connected vehicles. Summary of the Invention

[0003] This disclosure provides a method for application image flashing, a system-on-a-chip, a controller, and a storage medium to solve or alleviate one or more technical problems in the prior art.

[0004] On one hand, this disclosure provides a method for application image flashing, applied to a system-on-a-chip (SOC) controller. The controller includes the SOC and memory, the memory including a first partition and a second partition, comprising:

[0005] When the SOC's processor core determines that the first partition is the current primary partition, it will flash the first application image and the corresponding first bootloader (BL) for the upgrade to the second partition.

[0006] The SOC's hardware security engine (HSE) calculates the hash value of the first application image and writes it to the main table as a trust tag.

[0007] The SOC's processor core updates the first application image's write address and the first BL's write address to the first address information in the master table, so that when the controller restarts, the second partition is used as the new master partition and the first partition is used as the backup partition.

[0008] When the SOC's processor core controller restarts and the SOC's processor core target bootloader (BL) starts running, the SOC synchronously triggers the initialization of the target BL and the SOC's HSE loads the first application image for verification based on the first address information.

[0009] The SOC's target BL (Browser Layout) determines that the signature verification result is successful, and the SOC's processor core runs the first application image; and

[0010] The SOC's processor core updates the memory based on the running state of the first application image.

[0011] On the other hand, this disclosure provides a system-on-a-chip (SOC) including:

[0012] The processor core, when determining that the first partition is the current primary partition, flashes the first application image for upgrade and the corresponding first bootloader (BL) to the second partition. It updates the flash address of the first application image and the flash address of the first BL to the first address information in the master table, so that when the controller restarts, the second partition is used as the new primary partition, and the first partition as the backup partition. When the controller restarts and the target bootloader (BL) of the processor core starts running, it synchronously triggers the initialization of the target BL and the SOC's Hardware Security Engine (HSE) to load and verify the first application image based on the first address information. If the target BL determines that the verification result is a successful primary verification, it runs the first application image and performs memory update operations based on the running status of the first application image.

[0013] HSE is used to calculate the hash value of the first application image and write it to the main table as a trust tag, and load the first application image for verification based on the first address information.

[0014] On the other hand, this disclosure provides a controller, including:

[0015] Memory;

[0016] The system-on-a-chip (SOC) of any embodiment of this disclosure or the SOC used to perform the methods of any embodiment of this disclosure; the memory is electrically connected to the SOC.

[0017] On the other hand, this disclosure provides an electronic device, including:

[0018] At least one processor. And

[0019] A memory that is communicatively connected to the at least one processor. Wherein,

[0020] The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the methods of any embodiment of the present disclosure.

[0021] On the other hand, this disclosure provides a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to cause the computer to perform a method according to any embodiment of this disclosure.

[0022] On the other hand, this disclosure provides a computer program product including a computer program that, when executed by a processor, implements a method according to any embodiment of this disclosure.

[0023] According to the scheme disclosed herein, the HSE loads the first application image and the BL starts running synchronously and in parallel, thus shortening the startup time of the SOC and controller.

[0024] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this disclosure, nor is it intended to limit the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description

[0025] In the accompanying drawings, unless otherwise specified, the same reference numerals throughout the various drawings denote the same or similar parts or elements. These drawings are not necessarily drawn to scale. It should be understood that these drawings depict only some embodiments provided according to this disclosure and should not be construed as limiting the scope of this disclosure.

[0026] Figure 1 This is a schematic diagram of a controller according to an embodiment of the present disclosure.

[0027] Figure 2 This is a schematic diagram of a memory according to an embodiment of the present disclosure.

[0028] Figure 3 This is a flowchart illustrating the application image flashing method according to an embodiment of the present disclosure.

[0029] Figure 4 This is a flowchart illustrating the application image flashing method according to an embodiment of the present disclosure.

[0030] Figure 5 This is a flowchart illustrating the application image flashing method according to an embodiment of the present disclosure.

[0031] Figure 6 This is a flowchart illustrating the application image flashing method according to an embodiment of the present disclosure.

[0032] Figure 7A This is a schematic diagram of the master table and backup table before the update according to an embodiment of this disclosure;

[0033] Figure 7B This is a schematic diagram of the updated master table and backup table according to an embodiment of this disclosure;

[0034] Figure 8 This is a flowchart illustrating the application image flashing method according to an embodiment of the present disclosure.

[0035] Figure 9This is a schematic diagram of the master table and backup table after synchronization operation according to an embodiment of this disclosure;

[0036] Figure 10 This is a schematic diagram of the main table and backup table after a rollback operation according to an embodiment of this disclosure;

[0037] Figure 11 This is a schematic diagram illustrating the memory update operation performed according to the application image flashing method of the present disclosure.

[0038] Figure 12 This is a block diagram of an electronic device used to implement the application image flashing method of the embodiments of this disclosure. Detailed Implementation

[0039] The present disclosure will now be described in further detail with reference to the accompanying drawings. The same reference numerals in the drawings denote elements that have the same or similar functions. Although various aspects of embodiments are shown in the drawings, they are not necessarily drawn to scale unless specifically indicated otherwise.

[0040] Furthermore, to better illustrate this disclosure, numerous specific details are set forth in the following detailed description. Those skilled in the art will understand that this disclosure can be practiced without certain specific details. In some instances, methods, means, components, and circuits well known to those skilled in the art have not been described in detail in order to highlight the main points of this disclosure.

[0041] This disclosure provides a method for application image flashing, applied to a controller's system-on-a-chip (SOC). For example... Figure 1 As shown, the controller includes memory and a system-on-chip (SOC), which includes a hardware security engine (HSE) and at least one processor core. Figure 2As shown, the memory includes a first partition and a second partition. In various embodiments of this disclosure, the first partition and the second partition can be each other's primary and backup partitions, that is, neither the first partition nor the second partition is always defined as the primary or backup partition. In the application image flashing scenario, the controller boots in a way that alternates between the two partitions (AB side booting alternately). Specifically, when the controller needs to flash a new upgraded application image V1.0, if the first partition is the primary partition currently enabling the controller to operate normally, then the new upgraded application image V1.0 is flashed to the second partition, which is currently the backup partition. After the controller restarts, the second partition, which has the new upgraded application image V1.0 flashed, is regarded as the primary partition to run the new upgraded application image V1.0 and its corresponding bootloader, while the first partition is used as the backup partition. Subsequently, when the controller needs to write a new upgraded application image V2.0, the second partition becomes the current primary partition, and the new upgraded application image V2.0 is flashed to the first partition, which is currently the backup partition. After the controller restarts, the first partition, which contains the newly upgraded application image V2.0, is designated as the primary partition to run the new application image V2.0 and its corresponding bootloader, while the second partition is used as a backup partition. This process is repeated.

[0042] The controller can be an ECU (Electronic Control Unit), MCU (Microcontroller Unit), VCU (Vehicle Control Unit), etc., without specific limitations. The memory can be Flash Memory.

[0043] like Figures 3 to 5 As shown, this disclosure provides a method for application image flashing, applied to a system-on-a-chip (SOC) controller. The controller includes the SOC and memory, the memory including a first partition and a second partition, comprising:

[0044] Step S101: When the SOC processor core determines that the first partition is the current primary partition, it flashes the first application image and the corresponding first boot program BL for the upgrade to the second partition.

[0045] Step S102: The SOC's hardware security engine (HSE) calculates the hash value of the first application image and writes it to the main table as a trust tag.

[0046] Step S103: The SOC processor core updates the flash address of the first application image and the flash address of the first BL to the first address information in the master table, so that when the controller restarts, the second partition is used as the new master partition and the first partition is used as the backup partition.

[0047] Step S104: When the SOC's processor core control controller restarts and the SOC's processor core target bootloader BL starts running, the SOC synchronously triggers the initialization of the target BL and the SOC's HSE loads the first application image for verification based on the first address information.

[0048] Step S105: If the target BL of the SOC determines that the signature verification result is successful, the processor core of the SOC runs the first application image.

[0049] Step S106: The SOC processor core updates the memory according to the running status of the first application image.

[0050] According to the embodiments of this disclosure, it should be noted that:

[0051] The method of this disclosure can be applied to the OTA (Over-the-Air Technology) upgrade scenario of vehicle ECU, that is, the upgrade based on the first application image.

[0052] The first partition, as the current primary partition, can be understood as the partition where the bootloader and application image run when the controller is running normally (not when the application image is being flashed).

[0053] The main table stores the first target information, the first address information, and the second address information. The main table is fixed in either the first or second partition and will not change when switching between the first and second partitions. Specifically, the first target information stores the hash value of the application image. The first address information stores the primary partition address information (the load address of the application image and the corresponding bootloader). The second address information stores the backup partition address information (the load address of another application image and the corresponding bootloader).

[0054] The backup table stores second target information, third address information, and fourth address information. The backup table is permanently located on either the first or second partition and does not change when the primary partition is switched between the first and second partitions. Furthermore, the primary and backup tables are located on different partitions. The second target information stores the hash value of the application image. The third address information stores the primary partition address information (the load address of the application image and the corresponding bootloader). The fourth address information stores the backup partition address information (the load address of another application image and the corresponding bootloader).

[0055] The SOC's processor core loads the primary partition address information from the master table by default. Therefore, after the first address information is updated to the address of the second partition, the second partition becomes the new primary partition, and the first application image and corresponding boot program in it are run.

[0056] Before performing step S103, i.e. before the OTA software upgrade, such as Figure 7A As shown, the first address information in the master table stores the application image and corresponding bootloader load address on the first partition, which is currently the primary partition. The second address information stores the application image and corresponding bootloader load address on the second partition, which is currently the backup partition. The third address information in the backup table stores the same information as the first address information, and the fourth address information stores the same information as the second address information. This ensures that even if the master table is damaged, the controller can still be started and run according to the original partition based on the backup table.

[0057] After executing step S103, as Figure 7B As shown, the master table is updated. Since the first application image and its corresponding first bootloader (BL) have already been flashed to the second partition, if the first application image and its corresponding first bootloader need to run after a reboot, the second partition needs to be defined as a new master partition so that it can be started after the controller reboots. Therefore, the first address information in the master table needs to be updated to the load address of the first application image and the load address of the first bootloader in the second partition. Simultaneously, to ensure the controller continues to operate normally after a flashing failure, the second address information in the master table can be updated to the original load address of the second application image and its corresponding second bootloader in the first partition, thus converting the original master partition into a backup partition.

[0058] The target bootloader may be the bootloader corresponding to the first application image, or it may be the bootloader corresponding to the second application image that was originally running on the first partition, which is the current primary partition.

[0059] The synchronous triggering of BL initialization and SOC HSE loading of the first application image can be understood as BL initialization and SOC HSE loading of the first application image being executed in parallel.

[0060] HSE loads and verifies the signature of the first application image based on the first address information. This can be understood as follows: HSE determines which application image to load from the second partition based on the first address information. After loading the first application image, it calculates the hash value of the first application image and compares it with the trust label of the first application image in the master table to obtain the main signature verification result of the first application image. Verifying the signature of the first application image can determine its legality and integrity.

[0061] The memory update operation can be understood as follows: if the first application image runs normally, then the master table and backup table are synchronized, as are the first partition and the second partition. Specifically, the third address information in the backup table is updated to the first address information in the master table, the fourth address information in the backup table is updated to the second address information in the master table, and the second target information in the backup table is updated to the first target information in the master table; the application images in both the first and second partitions are flashed to the first application image, and the boot programs in both the first and second partitions are flashed to the first bootloader.

[0062] The memory update operation can also be understood as performing a rollback operation on the main table and backup table, as well as on the first partition and the second partition, if the first application image cannot run normally. Specifically, the first address information in the main table is updated to the third address information in the backup table, the second address information in the main table is updated to the fourth address information in the backup table, and the first target information in the main table is updated to the second target information in the backup table; the application images in both the first and second partitions are flashed to the second application image, and the boot programs in both the first and second partitions are flashed to the boot program BL corresponding to the second application image.

[0063] The hash value of the first application image is used as a trust label to be written to the main table. This can be understood as: HSE directly writes the trust label of the first application image to the main table, or HSE sends the trust label to the processor core of the SOC, and then the processor core writes the trust label to the main table.

[0064] According to the technology of this disclosure, the HSE loading of the first application image and the BL startup are synchronous and parallel, thus shortening the startup time of the SOC and controller. By saving the hash value of the first application image as a trust tag in the main table, when the controller restarts and verifies the first application image, the integrity and legitimacy of the first application image can be determined simply by comparing the hash value of the loaded first application image with its trust tag, without requiring a complete asymmetric algorithm for key verification, thus shortening the startup time of the controller and SOC.

[0065] Figure 4 The upper part of the solid black line in the middle represents the logic steps executed by the running BL, and the lower part of the solid black line represents the logic steps executed by the HSE. Figure 4 The detailed process of "verifying the target information" shown is available for reference. Figure 6 The content shown.

[0066] In one implementation, such as Figure 6As shown, the application image flashing method of this embodiment includes steps S101 to S106, wherein, before step S101, it further includes:

[0067] Step S201: When the controller restarts, the SOC's hardware security engine HSE verifies the signature of the first target information in the master table, where the first target information includes the trust label of the first application image and the target bootloader BL.

[0068] Step S202: If the signature verification is successful, the SOC's HSE triggers the target BL to start running.

[0069] According to the embodiments of this disclosure, it should be noted that:

[0070] Verifying the signature of the first target information can be understood as judging the completeness and legality of the first target information.

[0071] The trust label for the first application image is obtained by calculating the hash value of the first application image that has been flashed to the second partition, and is stored in the main table.

[0072] The target bootloader could be the bootloader corresponding to the first application image, or it could be the bootloader corresponding to the second application image that was originally running on the first partition, which is now the primary partition. For example... Figure 6 , Figure 7B As shown, HSE first verifies the trust label of the first application image in the first target information. If the verification passes, it verifies the first BL corresponding to the first application image. If the verification matches, the first BL is run. If the verification does not match, it verifies the second BL corresponding to the second application image. If the verification matches, the second BL is run.

[0073] According to the technology of the embodiments of this disclosure, by verifying the signature of the first target information, the safe startup of the controller can be guaranteed. This achieves the goal of not sacrificing information security, while simultaneously loading the first application image and starting the BL in parallel through HSE, thus shortening the startup time of the SOC and the controller.

[0074] In one embodiment, the application image flashing method of this disclosure includes steps S101 to S106, step S201 and step S202, and further includes:

[0075] Step S203: If the signature verification fails, the SOC's HSE verifies the second target information in the backup table. The second target information includes the trust label of the second application image that is running on the current primary partition (first partition) and the target bootloader BL.

[0076] Step S204: If the signature verification is successful, the SOC's HSE triggers the target BL to start running.

[0077] According to the embodiments of this disclosure, it should be noted that:

[0078] Verifying the signature of the second target information can be understood as judging the completeness and legality of the second target information.

[0079] The trust label for the second application image is obtained by calculating the hash value of the second application image and stored in the backup table.

[0080] The target bootloader could be the bootloader corresponding to the first application image, or it could be the bootloader corresponding to the second application image that was originally running on the first partition, which is now the primary partition. For example... Figure 6 , Figure 7B As shown, HSE first verifies the trust label of the second application image in the second target information. If the verification passes, it verifies the second BL corresponding to the second application image. If the verification matches, the second BL is run. If the verification does not match, it verifies the first BL corresponding to the first application image. If the verification matches, the first BL is run.

[0081] According to the technology of this disclosure embodiment, by verifying the signature of the second target information, the safe startup of the controller can be guaranteed. This achieves the goal of not sacrificing information security, while simultaneously loading the first application image and starting the BL in parallel through HSE, thus shortening the startup time of the SOC and the controller.

[0082] In one implementation, such as Figure 6 As shown, the application image flashing method of this embodiment includes steps S101 to S106, wherein, in step S104, the HSE of the SOC loads the first application image for signature verification based on the first address information, including:

[0083] The SOC's HSE loads the first application image based on the first address information.

[0084] The SOC's HSE calculates the hash value of the first application image and compares it with the trust label of the corresponding first application image in the main table to obtain the signature verification result of the first application image.

[0085] According to the technology of this disclosure, the integrity and legitimacy of the first application image can be determined simply by comparing the hash value of the loaded first application image with the trust label of the first application image, without the need to use a complete asymmetric algorithm for key verification, thus shortening the startup time of the controller and SOC.

[0086] In one embodiment, the application image flashing method of this disclosure includes steps S101 to S106, and further includes:

[0087] Step S107: The SOC's HSE loads the second application image based on the first address information.

[0088] Step S108: If the signature verification result is a primary signature verification failure, the SOC's HSE calculates the hash value of the second application image and compares it with the trust label of the corresponding second application image in the backup table to obtain the signature verification result of the second application image.

[0089] Step S109: If the verification result shows that the backup verification is successful, the SOC's processor core runs the second application image.

[0090] According to the embodiments of this disclosure, it should be noted that:

[0091] The application scenario is when the first application image fails to be run but the signature verification fails. In this case, the second application image is run so that the controller can still enable the original second application image to start working.

[0092] According to the technology of this disclosure, the integrity and legitimacy of the second application image can be determined simply by comparing the hash value of the loaded second application image with the trust label of the second application image, without the need to use a complete asymmetric algorithm for key verification, thus shortening the startup time of the controller and SOC.

[0093] In one embodiment, the application image flashing method of this disclosure includes steps S101 to S109, and further includes:

[0094] Step S110: If the verification result is that the backup verification failed, the SOC processor core will erase the trust label in the master table and restart the controller.

[0095] According to the embodiments of this disclosure, it should be noted that:

[0096] If both primary and backup signature verification fail, it indicates that the trust label of the first application image is inconsistent with the hash value of the first application image loaded by HSE, and also inconsistent with the hash value of the second application image loaded by HSE. Therefore, it means that the first application image pre-flushed to the backup partition is corrupted. To prevent the controller from becoming unusable, a rollback operation is required to erase the trust label of the first application image in the primary table (e.g., ...). Figure 11 The last line of the rollback operation ("application image corruption requires deletion of the main SYS_IMG, restart and rollback") is shown to ensure that the controller can pass the signature verification and run the second application image smoothly when it restarts and loads the second application image.

[0097] According to the technology of the embodiments of this disclosure, it can be ensured that the controller will not become bricked when the application is flashed, and OTA can be used to trigger a rollback operation after a flashing failure.

[0098] In one implementation, such as Figure 7A , Figure 7B As shown, the application image flashing method of this embodiment includes steps S101 to S104, wherein step S104, updating the flashing address of the first application image and the flashing address of the first BL to the first address information in the main table, includes:

[0099] Step S1041: The SOC processor core updates the primary partition address information in the primary address information of the primary address information in the primary address information of the primary table with the flash address of the first application image and the flash address of the first BL.

[0100] Step S1042: The SOC processor core updates the backup partition address information in the second address information of the main table with the flash address of the second application image currently running on the main partition and the corresponding flash address of the second BL.

[0101] According to the embodiments of this disclosure, it should be noted that:

[0102] like Figure 7B As shown, the master table is updated. Since the first application image and its corresponding first bootloader (BL) have already been flashed to the second partition, if the first application image and its corresponding first bootloader need to run after a reboot, the second partition needs to be defined as a new master partition so that it can be started after the controller reboots. Therefore, the first address information in the master table needs to be updated to the load address of the first application image and the load address of the first bootloader in the second partition. Simultaneously, to ensure the controller continues to operate normally after a flashing failure, the second address information in the master table can be updated to the original load address of the second application image and its corresponding second bootloader in the first partition, thus converting the original master partition into a backup partition.

[0103] According to the technology of the present disclosure embodiments, by updating the master table, after the controller restarts, the second partition, which was originally a backup partition, can be determined as the new primary partition based on the first address information in the master table, while the first partition, which was originally a primary partition, can be determined as the new backup partition, so as to complete the switching of which of the first partition and the second partition is the primary partition.

[0104] In one implementation, such as Figure 8 , 9 As shown in Figure 11, the application image flashing method of this embodiment includes steps S101 to S106, wherein step S106: the processor core of the SOC performs an update operation on the memory according to the running state of the first application image, including:

[0105] Step S1061: When the first application image is running, the SOC's processor core determines the controller's operating status, the version information of the trust label in the master table, and the version information of the target bootloader.

[0106] Step S1062: When the controller is working normally, the version information of the trust label corresponds to the first application image, and the version information of the target bootloader corresponds to the first application image, the SOC's processor core performs the following update operation:

[0107] Step S1063: Perform a synchronization operation on the master table and the backup table to update the third address information in the backup table to the first address information in the master table, update the fourth address information in the backup table to the second address information in the master table, and update the second target information in the backup table to the first target information in the master table (by...). Figure 7B The main table and backup table are updated to Figure 9 (Main table, backup table).

[0108] Step S1064: Perform a synchronization operation on the first partition and the second partition to flash the application images in both partitions to the first application image, and flash the bootloaders in both partitions to the first BL (e.g., ...). Figure 11 (as shown in the first row).

[0109] According to the technology of the embodiments of this disclosure, the target information of the primary partition and the backup partition can be made consistent so that both the primary partition and the backup partition can run the newly flashed first application image.

[0110] In one implementation, such as Figure 10 , 11 As shown, the application image flashing method of this embodiment includes steps S101 to S104, steps S1061 and S1064, and further includes:

[0111] Step S1065: If the controller's operating state is abnormal, or the version information of the trust label does not correspond to the first application image, or the version information of the target bootloader does not correspond to the first application image, the SOC's processor core performs the following update operation:

[0112] Step S1066: Perform a rollback operation on the main table and the backup table to update the first address information in the main table to the third address information in the backup table, update the second address information in the main table to the fourth address information in the backup table, and update the first target information in the main table to the second target information in the backup table (by...). Figure 7B The main table and backup table are updated to Figure 10 (Main table, backup table).

[0113] Step S1067: Perform a rollback operation on the first and second partitions to flash the application images in both partitions to the second application image, and flash the bootloaders in both partitions to the bootloader BL corresponding to the second application image (e.g., ...). Figure 11 (as shown in lines 2 to 5 of the text).

[0114] According to the embodiments of this disclosure, it should be noted that:

[0115] Figure 11 Except for the synchronous operation in the first row, all other operations are rollback operations.

[0116] According to the technology of the embodiments of this disclosure, the target information of the primary partition and the backup partition can be made consistent, so that both the primary partition and the backup partition can run the original second application image in the event that the first application image fails to be written.

[0117] In one example, the scenario is applied before the first application image is flashed, with the first partition serving as the primary partition and the second partition as the backup partition. In step S101, when the first application image and the first bootloader (BL) are flashed to the second partition, as follows... Figure 11 As shown in the left column box of the first row, the application image in the original backup partition column (i.e., the second partition) is updated to "new", and the BL in the original backup partition column is updated to "new". In step S102, when the trust label of the first application image is written to the main table, as shown in the left column box of the first row, the SYS_IMG in the main partition column (i.e., the first partition) is updated to "new", meaning the SYS_IMG of the main partition is the trust label of the first application image. The SYS_IMG in the backup partition column of the first row is the trust label corresponding to the second application image updated after successful writing before the second application image, which is "old". The BL in the main partition column shown in the left column box of the first row is the BL corresponding to the second application image updated after successful writing before the second application image, which is "old". The application image in the main partition column shown in the left column box of the first row is the original application image of the second application image, therefore it is "old".

[0118] Based on this, if the SOC's processor core performs a synchronization operation, the target information (SYS_IMG, BL, application image) originally marked as "old" in both the primary and backup partitions will be updated to the "new" target information. That is, the target information in both the primary and backup partitions will be completely updated to the information corresponding to the first application image. For example... Figure 11 As shown in the box on the right side of the first row.

[0119] If the SOC's processor core performs a rollback operation, the target information (SYS_IMG, BL, application image) marked as "new" in both the original primary and backup partitions will be updated to the "old" target information. That is, the target information in both the primary and backup partitions will be completely updated to the information corresponding to the second application image. For example... Figure 11 The boxes in the right column of the second, third, fourth, and sixth rows are shown.

[0120] In steps S201 to S204, if the primary SYS_IMG (trust label of the first application image) fails verification, the SYS_IMG in the primary partition column shown in the left column box of the first row is updated from "new" to "old or new (damaged)". If the primary BL (BL corresponding to the first application image) fails verification, the BL in the backup partition column shown in the left column box of the first row is updated from "new" to "new (damaged)".

[0121] In step S110, if both primary and backup signature verification fail, the application image in the backup partition is updated from "New" to "New (Corrupted)". Furthermore, to prevent the controller from becoming unusable, a rollback operation is required to erase the trust label of the first application image in the first target information of the primary partition (e.g., ...). Figure 11 The rollback operation in the fourth line of the document, "applicationimage corruption necessitates deletion of the main SYS_IMG followed by a restart and rollback," is shown to ensure that when the controller restarts and loads the second application image of the first partition, the signature verification can be passed and the second application image can run smoothly.

[0122] This disclosure provides a system-on-a-chip (SOC) including:

[0123] The processor core, when determining that the first partition is the current primary partition, flashes the first application image and its corresponding first bootloader (BL) to the second partition. It updates the flash address of the first application image and the flash address of the first BL to the first address information in the master table. This ensures that when the controller restarts, the second partition is used as the new primary partition, and the first partition as a backup partition. When the controller restarts and the target bootloader (BL) of the processor core starts running, it synchronously triggers the initialization of the target BL and the SOC's Hardware Security Engine (HSE) to load and verify the signature of the first application image based on the first address information. If the target BL determines that the signature verification result is successful, it runs the first application image and performs memory update operations based on the running state of the first application image.

[0124] HSE is used to calculate the hash value of the first application image and write it to the main table as a trust tag, and load the first application image for verification based on the first address information.

[0125] In one implementation, the HSE of the SOC is used for:

[0126] When the controller restarts, the signature of the first target information in the master table is verified. The first target information includes the trust label of the first application image and the target bootloader.

[0127] If the signature verification is successful, the target bootloader will be triggered to start running.

[0128] In one implementation, the HSE of the SOC is used for:

[0129] If the signature verification fails, the signature verification is performed on the second target information in the backup table. The second target information includes the trust label of the second application image that is already running on the current primary partition and the target boot program BL.

[0130] If the signature verification is successful, the target bootloader will be triggered to start running.

[0131] In one implementation, the HSE of the SOC is used for:

[0132] Load the first application image based on the first address information;

[0133] Calculate the hash value of the first application image and compare it with the trust tag of the corresponding first application image in the main table to obtain the signature verification result of the first application image.

[0134] In one implementation, the HSE of the SOC is used to: load the second application image according to the first address information; and if the signature verification result is a primary signature verification failure, calculate the hash value of the second application image and compare it with the trust label of the corresponding second application image in the backup table to obtain the signature verification result of the second application image.

[0135] The SOC's processor cores are used to run the second application image if the verification result shows that the backup verification was successful.

[0136] In one implementation, the SOC's processor core is used to: erase the trust label in the master table and restart the controller if the verification result is a backup verification failure.

[0137] In one implementation, the processor core of the SOC is used to: update the primary partition address information in the primary address information of the primary partition table with the flash address of the first application image and the flash address of the first BL; and update the backup partition address information in the secondary address information of the secondary application image currently running on the primary partition and the corresponding flash address of the second BL in the primary partition table.

[0138] In one implementation, the SOC's processor core is used to: determine the controller's operating status, the version information of the trust label in the master table, and the version information of the target bootloader when the first application image is running. If the controller's operating status is normal, the version information of the trust label corresponds to the first application image, and the version information of the target bootloader corresponds to the first application image, the following update operation is performed:

[0139] The master table and the backup table are synchronized to update the third address information in the backup table to the first address information in the master table, update the fourth address information in the backup table to the second address information in the master table, and update the second target information in the backup table to the first target information in the master table.

[0140] Perform a synchronization operation on the first and second partitions to flash the application images in both partitions to the first application image, and flash the bootloaders in both partitions to the first bootloader.

[0141] In one implementation, the SOC's processor core is configured to perform the following update operation in the event of an abnormal controller operating state, a trust tag version information that does not correspond to the first application image, or a target bootloader version information that does not correspond to the first application image:

[0142] Perform a rollback operation on the main table and the backup table to update the first address information in the main table to the third address information in the backup table, update the second address information in the main table to the fourth address information in the backup table, and update the first target information in the main table to the second target information in the backup table.

[0143] Perform a rollback operation on the first and second partitions to flash the application images in both partitions to the second application image, and flash the bootloaders in both partitions to the bootloader BL corresponding to the second application image.

[0144] like Figure 1 As shown, this disclosure provides a controller, including:

[0145] Memory;

[0146] The system-on-a-chip (SOC) described in any of the above embodiments or the system-on-a-chip (SOC) used to perform the methods described in any of the above embodiments; the memory is electrically connected to the SOC.

[0147] Figure 12 This is a structural block diagram of an electronic device according to an embodiment of the present disclosure. Figure 12As shown, the electronic device includes a memory 1710 and a processor 1720. The memory 1710 stores a computer program that can run on the processor 1720. The number of memories 1710 and processors 1720 can be one or more. The memory 1710 can store one or more computer programs, which, when executed by the electronic device, cause the electronic device to perform the methods provided in the above-described method embodiments. The electronic device may also include a communication interface 1730 for communicating with external devices and performing data exchange and transmission.

[0148] If the memory 1710, processor 1720, and communication interface 1730 are implemented independently, they can be interconnected via a bus to communicate with each other. This bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. This bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 12 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.

[0149] Optionally, in a specific implementation, if the memory 1710, processor 1720 and communication interface 1730 are integrated on a single chip, the memory 1710, processor 1720 and communication interface 1730 can communicate with each other through an internal interface.

[0150] It should be understood that the aforementioned processor can be a Central Processing Unit (CPU), or other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. General-purpose processors can be microprocessors or any conventional processor. It is worth noting that the processor can be a processor supporting Advanced Reduced Instruction Set Machines (ARM) architecture.

[0151] Further, optionally, the aforementioned memory may include read-only memory and random access memory, and may also include non-volatile random access memory. The memory may be volatile or non-volatile, or may include both. Non-volatile memory may include read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory may include random access memory (RAM), which serves as an external cache. Many forms of RAM are available by way of example, but not limitation. Examples include Static Random Access Memory (SRAM), Dynamic Random Access Memory (DRAM), Synchronous DRAM (SDRAM), Double Data Rate Synchronous DRAM (DDR SDRAM), Enhanced Synchronous DRAM (ESDRAM), Synchlink DRAM (SLDRAM), and Direct RAMBUS RAM (DR RAM).

[0152] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. A computer program product includes one or more computer instructions. When the computer instructions are loaded and executed on a computer, all or part of the flow or function according to the embodiments of this disclosure is generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions can be transmitted from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, Digital Subscriber Line, DSL) or wireless (e.g., infrared, Bluetooth, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access, or a data storage device such as a server or data center that integrates one or more available media. The available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., Digital Versatile Discs (DVDs)), or semiconductor media (e.g., Solid State Disks (SSDs)). It is worth noting that the computer-readable storage media mentioned in this disclosure can be non-volatile storage media; in other words, they can be non-transient storage media.

[0153] Those skilled in the art will understand that all or part of the steps of the above embodiments can be implemented by hardware or by a program instructing related hardware. The program can be stored in a computer-readable storage medium, such as a read-only memory, a disk, or an optical disk.

[0154] In the description of the embodiments of this disclosure, references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of this disclosure. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of those different embodiments or examples.

[0155] In the description of the embodiments disclosed herein, unless otherwise stated, " / " means "or". For example, A / B can mean A or B. The "and / or" in this document is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone.

[0156] In the description of embodiments of this disclosure, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of embodiments of this disclosure, unless otherwise stated, "a plurality of" means two or more.

[0157] The above description is merely an exemplary embodiment of this disclosure and is not intended to limit this disclosure. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this disclosure should be included within the protection scope of this disclosure.

Claims

1. A method for applying image flashing, applied to a system-on-a-chip (SOC) of a controller, the controller including the SOC and a memory, the memory including a first partition and a second partition, comprising: When the processor core of the SOC determines that the first partition is the current primary partition, it will flash the first application image and the corresponding first bootloader BL for upgrading to the second partition. The SOC's hardware security engine (HSE) calculates the hash value of the first application image and writes it to the main table as a trust tag. The SOC's processor core updates the flash address of the first application image and the flash address of the first BL to the first address information in the master table, so that when the controller restarts, the second partition is used as the new primary partition and the first partition is used as the backup partition. When the processor core of the SOC controls the controller to restart and the target bootloader (BL) of the processor core of the SOC starts running, the SOC synchronously triggers the initialization of the target BL and the HSE of the SOC loads the first application image for signature verification according to the first address information; If the target BL of the SOC determines that the signature verification result is successful, the processor core of the SOC runs the first application image. as well as The processor core of the SOC updates the memory according to the running state of the first application image.

2. The method according to claim 1, wherein before the target bootloader BL of the processor core of the SOC starts running, the method further comprises: When the controller restarts, the SOC's Hardware Security Engine (HSE) verifies the signature of the first target information in the master table, wherein the first target information includes the trust label of the first application image and the target bootloader (BL). If the verification is successful, the HSE of the SOC triggers the target BL to start running.

3. The method according to claim 2, further comprising: If the signature verification fails, the HSE of the SOC verifies the signature of the second target information in the backup table, wherein the second target information includes the trust label of the second application image that is running on the current primary partition and the target boot program BL; If the verification is successful, the HSE of the SOC triggers the target BL to start running.

4. The method according to claim 1, wherein, The SOC's HSE loads the first application image based on the first address information and performs signature verification, including: The SOC's HSE loads the first application image based on the first address information; The SOC's HSE calculates the hash value of the first application image and compares it with the trust tag corresponding to the first application image in the main table to obtain the signature verification result of the first application image.

5. The method according to claim 1, further comprising: The HSE of the SOC loads the second application image based on the first address information; If the signature verification result is a primary signature verification failure, the SOC's HSE calculates the hash value of the second application image and compares it with the trust label of the corresponding second application image in the backup table to obtain the signature verification result of the second application image. If the verification result indicates that the backup verification was successful, the processor core of the SOC will run the second application image.

6. The method according to claim 5, further comprising: If the verification result is a backup verification failure, the SOC's processor core will erase the trust label in the master table and restart the controller.

7. The method according to claim 1, wherein, The SOC's processor core updates the first application image's write address and the first bootstrap's write address to the first address information in the master table, including: The SOC's processor core updates the primary partition address information in the primary address information of the primary table with the primary application image's write address and the primary partition address's write address. The SOC's processor core updates the backup partition address information in the second address information of the main table with the flash address of the second application image running on the current main partition and the corresponding flash address of the second BL.

8. The method according to claim 7, wherein, The processor core of the SOC updates the memory according to the running state of the first application image, including: When the first application image is running, the processor core of the SOC determines the working state of the controller, the version information of the trust tag in the master table, and the version information of the target bootloader; When the controller is functioning normally, the version information of the trust label corresponds to the first application image, and the version information of the target bootloader corresponds to the first application image, the SOC's processor core performs the following update operation: The main table and the backup table are synchronized to update the third address information in the backup table to the first address information in the main table, update the fourth address information in the backup table to the second address information in the main table, and update the second target information in the backup table to the first target information in the main table. The first partition and the second partition are synchronized to flash the application images in both partitions to the first application image and the bootloaders in both partitions to the first bootloader.

9. The method according to claim 8, further comprising: If the controller's operating state is abnormal, or the version information of the trust label does not correspond to the first application image, or the version information of the target bootloader does not correspond to the first application image, the SOC's processor core performs the following update operation: A rollback operation is performed on the main table and the backup table to update the first address information of the main table to the third address information of the backup table, update the second address information of the main table to the fourth address information of the backup table, and update the first target information of the main table to the second target information of the backup table. A rollback operation is performed on the first partition and the second partition to flash the application images in both partitions to the second application image, and to flash the bootloaders in both partitions to the bootloader BL corresponding to the second application image.

10. A system-on-a-chip (SOC) disposed on a controller, the controller including the SOC and a memory, the memory including a first partition and a second partition, the SOC including: The processor core is used to, when the first partition is determined to be the current primary partition, to flash the first application image for upgrade and the corresponding first bootloader BL to the second partition, update the flash address of the first application image and the flash address of the first BL to the first address information of the master table, so that when the controller restarts, the second partition is used as the new primary partition and the first partition is used as the backup partition. When the controller restarts and the target bootloader BL of the processor core starts running, the initialization of the target BL and the hardware security engine HSE of the SOC load the first application image for signature verification according to the first address information. If the target BL determines that the signature verification result is successful, it runs the first application image and performs an update operation on the memory according to the running status of the first application image. as well as The HSE is used to calculate the hash value of the first application image and write it to the main table as a trust tag, and load the first application image for verification based on the first address information.

11. A controller, comprising: Memory; The system-on-a-chip (SoC) of claim 10 or the SoC for performing the methods of claims 1 to 9; The memory is electrically connected to the SOC.

12. An electronic device, comprising: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 1 to 9.

13. A non-transitory computer-readable storage medium storing computer instructions, wherein, The computer instructions are used to cause the computer to perform the method according to any one of claims 1 to 9.

14. A computer program product comprising a computer program that, when executed by a processor, implements the method according to any one of claims 1 to 9.