A method and system for slice-based OTA upgrade adapting to zero-waiting area constraint

By employing a refined Flash partition layout and a dual-state flag mechanism, the problem of limited resources in the zero-wait-area upgrade scheme in traditional OTA upgrade solutions is solved, achieving highly reliable and efficient firmware upgrades that are compatible with small-capacity Flash devices.

CN121722424BActive Publication Date: 2026-07-03ADVANCED INST OF INFORMATION TECH (AIIT) PEKING UNIV +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202610195157.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-02-11
Publication Date
2026-07-03
Estimated Expiration
2046-02-11

AI Technical Summary

Technical Problem

Traditional OTA upgrade solutions do not mandate the storage location of critical code such as Flash programming functions and interrupt service routines. This results in these codes being allocated to non-zero wait areas, causing Flash erase/write operations to time out in Recovery mode, interrupt response delays, or even system crashes, thus rendering the OTA upgrade function ineffective.

Method used

The flash memory is divided into a recovery zero-wait area, a recovery non-zero-wait area, a normal partition, and a flag partition. This ensures that fast programming functions are stored in the zero-wait area and ordinary functions are stored in the non-zero-wait area. High-reliability firmware upgrades are achieved through the joint verification of OTA status flags and program startup status flags, and a re-upgrade process is triggered in the event of an upgrade anomaly.

Benefits of technology

It enables efficient and reliable OTA upgrades with limited storage resources, preventing devices from permanently failing due to upgrade anomalies and improving the reliability and space utilization of device upgrades.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121722424B_ABST
    Figure CN121722424B_ABST
Patent Text Reader

Abstract

This application proposes a segmented OTA upgrade method and system adapted to zero-wait-area constraints. The method is applied to a terminal device, which includes flash memory with both zero-wait-area and non-zero-wait-area areas. The method includes: responding to a boot signal from the terminal device, calling a bootloader to read an OTA status flag from the non-zero-wait-area; if the OTA status flag is a first download flag, reading a program startup status flag from the non-zero-wait-area; if the program startup status flag is a first startup flag, calling a quick-write program to rewrite the program startup status flag from the first startup flag to a second startup flag, and starting the main program of the terminal device; responding to a successful boot signal from the main program, rewriting the program startup status flag from the second startup flag back to the first startup flag; if the OTA status flag is a second download flag, downloading a new firmware version for OTA upgrade. This application enables segmented OTA upgrades adapted to zero-wait-area constraints.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of OTA upgrade technology, specifically to a fragmented OTA upgrade method and system adapted to zero waiting area constraints. Background Technology

[0002] In terminal devices with limited flash memory capacity (e.g., less than 512KB) (such as low-power IoT nodes, industrial controllers, etc.), traditional OTA upgrade solutions have the following key drawbacks:

[0003] Some controllers' flash memory is divided into a zero-wait region and a non-zero-wait region. Critical execution code, such as flash programming functions and interrupt service routines, must reside in the zero-wait region for stable operation. However, traditional OTA upgrade solutions do not mandate the storage location of essential Recovery mode code, such as flash programming functions and interrupt vector tables. When this code is allocated to the non-zero-wait region, it can cause flash erase / write operations to time out in Recovery mode, interrupt response delays, and even system crashes, rendering the OTA upgrade function completely ineffective. Summary of the Invention

[0004] In view of this, this application proposes a fragmented OTA upgrade method and system adapted to zero-wait-area constraints, which can fully take into account the hard constraints of the zero-wait-area on the code execution location.

[0005] The first aspect of this application proposes a fragmented OTA upgrade method adapted to zero-wait-area constraints. The method is applied to a terminal device, which includes flash memory with a zero-wait-area and a non-zero-wait-area. The zero-wait-area stores a bootloader and a quick-write program; the non-zero-wait-area stores an OTA status flag and a program startup status flag. The method includes:

[0006] In response to the startup signal of the terminal device, the bootloader is invoked to read the OTA status flag from the non-zero wait area;

[0007] If the OTA status flag is the first download flag, then the program startup status flag is read from the non-zero waiting area; the first download flag is used to indicate that there is no OTA upgrade task in the terminal device;

[0008] If the program startup status flag is a first startup flag, then the quick programming program is invoked to rewrite the program startup status flag from the first startup flag to a second startup flag, and the main program of the terminal device is started; the first startup flag is used to indicate that the main program was successfully started last time; the second startup flag is used to indicate that the main program failed to start last time; the main program is an application program that executes the business functions of the terminal device;

[0009] In response to the successful startup signal of the main program, the quick programming program is invoked to rewrite the program startup status flag from the second startup flag back to the first startup flag;

[0010] If the OTA status flag is the second download flag, then the new firmware version is downloaded for OTA upgrade; the second download flag is used to indicate that the OTA upgrade task exists in the terminal device.

[0011] This application embodiment defines the terminal device as including flash memory with a zero-wait area and a non-zero-wait area; the zero-wait area stores the bootloader and quick program writing; the non-zero-wait area stores OTA status flags and program startup status flags, which can fully take into account the hard constraints of the zero-wait area on the code execution position, thereby achieving the purpose of segmented OTA upgrades that adapt to the constraints of the zero-wait area; and through the collaborative verification of the OTA status flags and the program startup status flags, highly reliable firmware upgrades can be achieved, and a re-upgrade process can be triggered when an upgrade is abnormal, preventing the device from becoming "bricked".

[0012] In this embodiment of the application, the flash memory includes: a recovery zero-wait partition, a normal partition, a recovery non-zero-wait partition, and a flag partition;

[0013] The zero-wait partition is used to store programs that execute with zero latency in the startup and recovery modes of the terminal device; the zero-wait partition stores the bootloader, the quick-write program, and the interrupt service routine; the recovery mode refers to the minimized running state of the terminal device's microcontroller during OTA upgrades;

[0014] The normal partition is used to store applications that are used when the terminal device is running normally;

[0015] The recovery non-zero wait partition is used to store programs whose execution speed is less than a preset speed in the recovery mode;

[0016] The flag partition is used to store the OTA status flag and the program startup status flag.

[0017] This application's embodiment divides the Flash memory into a recovery zero-wait area, a recovery non-zero-wait area, a normal partition, and a flag partition, achieving separate storage for fast programming functions and ordinary functions. This effectively adapts to the resource constraints of the zero-wait area. Furthermore, storing fast programming functions in the zero-wait area and ordinary functions in the non-zero-wait area ensures operational efficiency while saving space in the zero-wait area, thus solving the problem of limited resources in the zero-wait area. In addition, through the refined layout of the four partitions, no additional storage space needs to be reserved, significantly improving space utilization and adapting to small-capacity Flash memory below 512KB.

[0018] In this embodiment of the application, the recovery zero-wait partition is located within the zero-wait area, and the starting address of the recovery zero-wait partition is the starting address of the zero-wait area of ​​the memory;

[0019] The normal partition is a contiguous storage space consisting of a zero-wait area and a non-zero-wait area. The starting address of the normal partition is the memory address following the ending address of the restored zero-wait area, and the ending address of the normal partition is located within the non-zero-wait area.

[0020] The recovery non-zero wait partition and the flag partition are located within the non-zero wait area. The starting address of the recovery non-zero wait partition is the next memory address after the ending address of the normal partition, and the starting address of the flag partition is the next memory address after the ending address of the recovery non-zero wait partition.

[0021] In this embodiment of the application, if the OTA status flag is the second download flag, then downloading the new firmware version for OTA upgrade includes:

[0022] If the OTA status flag is the second download flag, then in response to the second download flag, the new version firmware is downloaded, and the quick programming program is invoked to burn the new version firmware to the normal partition to overwrite the old version firmware of the main program; the second download flag is used to indicate that the terminal device has the OTA upgrade task.

[0023] In response to the successful flashing signal, the quick programming program is invoked to rewrite the OTA status flag from the second download flag to the first download flag, and the terminal device is restarted.

[0024] This application embodiment uses a first download flag to represent a no-OAT upgrade task and a second download flag to represent an OTA upgrade task, so that each stage of the OTA upgrade process has a persistent flag, forming a traceable upgrade log; preferably, the first download flag is only rewritten after successful burning to ensure that the firmware integrity verification passes; even if the power is lost during the burning process, it will still be identified as the second download flag after restarting, and the upgrade can be re-executed, avoiding the system from being bricked due to the half-burning state.

[0025] In this embodiment of the application, downloading a new version of firmware in response to the second download flag includes:

[0026] Download the new firmware version of the main program in segments;

[0027] The fragmented firmware data of the new version firmware is burned into the normal partition respectively until all fragmented firmware data of the new version firmware has been received.

[0028] In this embodiment of the application, after the main program starts successfully, the method further includes:

[0029] Continuously monitor the remote server for the availability of new firmware versions;

[0030] If the new firmware version exists on the remote server, the quick programming program is invoked to rewrite the OTA status flag from the first download flag to the second download flag, and the terminal device is restarted.

[0031] In this embodiment of the application, after reading the program startup status flag, the method further includes:

[0032] If the program startup status flag is the second startup flag, then the quick programming program is invoked to rewrite the OTA status flag from the first download flag to the second download flag, and the terminal device is restarted.

[0033] In this embodiment of the application, the storage capacity of the flash memory is less than a preset capacity threshold.

[0034] An embodiment of the second aspect of this application provides a fragmented OTA upgrade system adapted to zero-wait-area constraints. The system is applied to a terminal device, which includes flash memory with a zero-wait-area and a non-zero-wait-area. The zero-wait-area stores a bootloader and a quick-write program; the non-zero-wait-area stores an OTA status flag and a program startup status flag. The system includes:

[0035] An OTA status flag reading module is used to respond to the startup signal of the terminal device by calling the bootloader to read the OTA status flag from the non-zero waiting area;

[0036] The program startup status flag reading module is used to read the program startup status flag from the non-zero waiting area if the OTA status flag is a first download flag; the first download flag is used to indicate that there is no OTA upgrade task in the terminal device;

[0037] The first rewriting module is used to, if the program startup status flag is a first startup flag, call the quick programming program to rewrite the program startup status flag from the first startup flag to a second startup flag, and start the main program of the terminal device; the first startup flag is used to indicate that the main program was successfully started last time; the second startup flag is used to indicate that the main program failed to start last time; the main program is an application program that executes the business functions of the terminal device.

[0038] The second rewriting module is used to call the quick programming program to rewrite the program startup status flag from the second startup flag to the first startup flag in response to the startup success signal of the main program.

[0039] The OTA upgrade module is used to download a new version of firmware for OTA upgrade if the OTA status flag is a second download flag; the second download flag is used to indicate that the OTA upgrade task exists in the terminal device.

[0040] An embodiment of the third aspect of this application provides a computer device including a memory and a processor, the memory and the processor being communicatively connected to each other, the memory storing computer instructions, and the processor executing the computer instructions to perform the fragmented OTA upgrade method with zero wait area constraints described in the first aspect above.

[0041] An embodiment of the fourth aspect of this application provides a computer-readable storage medium storing computer instructions for causing a computer to execute the fragmented OTA upgrade method adapted to zero wait area constraints as described in the first aspect.

[0042] Additional aspects and advantages of this application will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of this application. Attached Figure Description

[0043] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the scope of this application. Furthermore, the same reference numerals denote the same parts throughout the drawings. In the drawings:

[0044] Figure 1 This paper illustrates a flowchart of a fragmented OTA upgrade method adapted to zero waiting area constraints, provided in an embodiment of this application.

[0045] Figure 2This paper illustrates a flowchart of another fragmented OTA upgrade method adapted to zero waiting area constraints, provided in an embodiment of this application.

[0046] Figure 3 This paper shows a schematic diagram of the structure of a fragmented OTA upgrade system adapted to zero waiting area constraints according to an embodiment of this application;

[0047] Figure 4 A schematic diagram of the structure of a computer device provided in one embodiment of this application is shown. Detailed Implementation

[0048] Exemplary embodiments of this application will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of this application are shown in the drawings, it should be understood that this application may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided to enable a more thorough understanding of this application and to fully convey the scope of this application to those skilled in the art.

[0049] It should be noted that, unless otherwise stated, the technical or scientific terms used in this application shall have the ordinary meaning as understood by one of ordinary skill in the art to which this application pertains.

[0050] The following describes the relevant terms used in the embodiments of this application.

[0051] OTA (Over-The-Air Upgrade) refers to a technology where a device downloads and installs new firmware or software updates from a remote server via a wireless network (such as Wi-Fi, 4G, Bluetooth, etc.) without the need for physical connections (such as USB cables, serial ports) or manual intervention.

[0052] A recovery partition is a dedicated, protected storage area in embedded systems, smartphones, IoT devices, or computer systems specifically designed for system recovery, troubleshooting, and firmware upgrades. It contains a lightweight, standalone operating system or boot environment that can be started and used for maintenance even if the main system is damaged.

[0053] Flash memory is a type of non-volatile memory that can retain data for a long time, even after power is off. It is widely used in embedded systems, mobile devices, solid-state drives (SSDs), USB flash drives, IoT terminals, and other scenarios, and is a core hardware component in modern electronic devices for storing program code and critical data.

[0054] In the microcontroller and FLASH domain, the zero-wait area (ZW) refers to a specific region of flash memory where the microcontroller core can read and execute instructions instantly at its own clock frequency without needing to insert a wait cycle. Functions with high real-time requirements, such as fast programming, interrupt handling, and thread scheduling, must run in the zero-wait area; otherwise, it will lead to decreased execution efficiency, execution errors, or even system crashes.

[0055] Traditional OTA upgrade solutions also have the following key drawbacks: serious waste of storage resources: the A / B dual-bank full package upgrade method requires reserving twice the firmware space, which is not feasible for small-capacity Flash devices; unreliable upgrade process: if a single-bank in-situ overwrite upgrade encounters a power outage, communication interruption or write failure, the device will become "bricked" and will be unable to download the upgrade package firmware again, and there is no way to recover in time after the upgrade fails.

[0056] To address the aforementioned issues, this application proposes a fragmented OTA upgrade method adapted to zero-wait-area constraints. Through refined Flash partition layout and a dual-state flag mechanism, it achieves highly reliable and retryable OTA upgrades with minimal resource overhead.

[0057] According to an embodiment of this application, a fragmented OTA upgrade method embodiment adapted to zero wait area constraints is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.

[0058] This embodiment provides a fragmented OTA upgrade method adapted to zero wait area constraints. Figure 1 This is a flowchart of a fragmented OTA upgrade method adapted to zero-wait-area constraints according to an embodiment of this application, as shown below. Figure 1 As shown, the process includes the following steps:

[0059] Step S101: In response to the startup signal of the terminal device, the bootloader is invoked to read the OTA status flag from the non-zero waiting area.

[0060] Specifically, after the terminal device is powered on, the microcontroller (MCU) starts the bootloader from the recovery zero wait area. The bootloader reads the OTA status flag OTAFlag from the flag partition. Both the recovery zero wait area and the flag partition are located in the flash memory of the terminal device.

[0061] In some specific embodiments, the OTA status flags include, but are not limited to, a first download flag and a second download flag; wherein, the first download flag is used to indicate that there is no OTA upgrade task in the terminal device, and the second download flag is used to indicate that there is an OTA upgrade task in the terminal device.

[0062] In some specific embodiments, the flash memory storage capacity of the terminal device is less than a preset capacity threshold. The terminal device includes, but is not limited to, low-power IoT nodes and industrial controllers. The preset capacity threshold is not specifically limited, for example, 512KB.

[0063] In some specific embodiments, the memory storage area can be divided into: recovery zero-wait partition, normal partition, recovery non-zero-wait partition, and flag partition, based on the physical characteristics of the flash memory's zero-wait area and non-zero-wait area, as shown in Table 1:

[0064] Table 1

[0065]

[0066] The zero-wait partition is used to store programs that execute with zero latency in the startup and recovery modes of the terminal device, such as bootloaders, quick-write programs, and interrupt service routines. The recovery mode refers to the minimized running state that the microcontroller of the terminal device enters during OTA upgrades due to firmware corruption, upgrade failure, or forced triggering. The normal partition is used to store applications of the terminal device in normal mode, which refers to the standard working state in which the microcontroller loads and runs the complete business firmware from the normal partition. The non-zero wait partition is used to store programs that execute at a speed lower than a preset speed in the recovery mode. The flag partition is used to store OTA status flags and program startup status flags.

[0067] In some specific embodiments, the recovery zero-wait partition is located within the zero-wait region of the memory, and the starting address of the recovery zero-wait partition is the starting address of the zero-wait region of the memory; the normal partition is a contiguous storage space of the zero-wait region and the non-zero-wait region, the starting address of the normal partition is the memory address following the ending address of the recovery zero-wait region, and the ending address of the normal partition is located within the non-zero-wait region; the recovery non-zero-wait partition and the flag partition are located within the non-zero-wait region of the memory, the starting address of the recovery non-zero-wait partition is the memory address following the ending address of the normal partition, and the starting address of the flag partition is the memory address following the ending address of the recovery non-zero-wait partition.

[0068] In this embodiment, the zero-wait region is a special physical area in the Flash memory of the microcontroller (MCU) of the terminal device. When the CPU reads instructions from this physical area, no wait cycle needs to be inserted, ensuring deterministic high-speed execution. The non-zero wait region refers to a storage area in the microcontroller's flash memory that requires a wait cycle to be inserted when accessing it. When reading instructions or data from this area, several clock cycles must be paused to wait for the data to return, thus the execution speed is relatively slow.

[0069] In this embodiment, the method for configuring the memory address and size of each partition is as follows:

[0070] Restore the zero-wait partition:

[0071] Starting address: The starting address of the zero-wait zone of the Flash memory (default mapping is 0x00000000), ensuring that the system boots first;

[0072] Size calculation: Determined based on the actual size of the code that must be executed at high speed (such as fast programming functions and interrupt service routines);

[0073] Configuration method: Define the FLASH_FAST segment through the link script file (link_recovery.ld), specifying the starting address and length.

[0074] Normal partition:

[0075] Starting address: The address aligned to 4KB after restoring the zero-wait partition cutoff address;

[0076] Size calculation: Subtract the starting address of the normal partition from the starting address of the restored non-zero wait area;

[0077] Configuration method: Define the FLASH segment through the link script file (link.ld), which includes the remaining space of the zero wait area and part of the non-zero wait area space.

[0078] Restore non-zero waiting area:

[0079] Starting address: (Total memory storage capacity - Flag partition size - Recovery non-zero wait area size) aligned forward 4KB;

[0080] Size calculation: Determined based on the total size of the normal recovery mode procedure and temporary data;

[0081] Configuration method: Define the FLASH_SLOW segment through the link script file (link_recovery.ld) to specify the range of non-zero wait area addresses.

[0082] Flag partition OTAFlag:

[0083] Address range: the last 4KB of the Flash physical address (fixed size);

[0084] Stored content: OTAFlag (OTA status flag) and JumpFlag (program startup status flag), providing a basis for determining the status of the upgrade process.

[0085] Step S102: If the OTA status flag is the first download flag, then read the program startup status flag from the non-zero waiting area; the first download flag is used to indicate that there is no OTA upgrade task in the terminal device.

[0086] Specifically, such as Figure 2 As shown: When the OTA status flag OTAFlag ≠ DOWNLOAD, read the program startup status flag JumpFlag.

[0087] In some specific embodiments, the program startup status flag JumpFlag in the flag partition can be read by invoking the bootloader in the recovery zero-wait partition.

[0088] Step S103: If the program startup status flag is the first startup flag, then the quick programming program is called to rewrite the program startup status flag from the first startup flag to the second startup flag, and the main program of the terminal device is started.

[0089] Specifically, the first startup flag SUCCESS indicates that the main program was successfully started last time; the second startup flag FAILED indicates that the main program failed to start last time.

[0090] More specifically, such as Figure 2 As shown: When the program startup status flag is not the second startup flag, that is, JumpFlag ≠ FAILED, that is, the program startup status flag is the first startup flag, i.e., JumpFlag = SUCCESS. Under this condition, the program startup status flag is rewritten to the second startup flag, i.e., JumpFlag = FAILED.

[0091] In some specific embodiments, the OTA status flag and program startup status flag in the flag partition can be rewritten by calling the quick write program in the recovery zero waiting area.

[0092] In this embodiment, if the program startup status flag is the first startup flag, it indicates that the previous main program startup was successful. At this time, the microcontroller rewrites the program startup status flag from the first startup flag to the second startup flag. This rewriting operation is completed by calling a fast programming function in the recovery zero-wait area to ensure that the flag state is preset to a failure state before the main program starts this time. After the program startup status flag is preset, the microcontroller performs a jump operation, switching from the recovery zero-wait area to the entry address of the normal partition, and starts the main program.

[0093] Step S104: In response to the successful startup signal of the main program, the quick programming program is invoked to rewrite the program startup status flag from the second startup flag to the first startup flag.

[0094] Specifically, if the main program startup process of the terminal device completes normally, the fast programming function in the recovery zero-wait area is actively called to rewrite the program startup status flag in the flag partition from the second startup flag to the first startup flag, thereby reporting a successful startup to the bootloader. For example... Figure 2 As shown: Start Normal mode and write JumpFlag=SUCCESS.

[0095] In this embodiment, if the main program fails to execute the startup success confirmation step due to code defects, hardware failures, or initialization errors, the program startup status flag remains unchanged as the second startup flag. The next time the terminal device powers on, the bootloader reads this flag to identify the startup failure status and automatically triggers recovery mode to re-execute the upgrade process, preventing the terminal device from becoming unusable.

[0096] Step S105: If the OTA status flag is the second download flag, then download the new firmware version for OTA upgrade.

[0097] In some specific embodiments, step S105 includes step S1051-:

[0098] Step S1051: If the OTA status flag is the second download flag, then in response to the second download flag, download the new version firmware and call the quick programming program to burn the new version firmware to the normal partition to overwrite the old version firmware of the main program; the second download flag is used to indicate that the terminal device has the OTA upgrade task.

[0099] In some specific embodiments, downloading a new version of firmware in response to the second download flag includes: downloading the new version of firmware of the main program in segments; and burning the segmented firmware data of the new version of firmware into the normal partition respectively until all segmented firmware data of the new version of firmware has been received.

[0100] Specifically, such as Figure 2 As shown: When OTAFlag=DOWNLOAD, the Recovey mode (i.e., recovery mode) is started. In this mode, the 4G network is started, the new version firmware is downloaded in segments, and the segmented firmware data is written to the Normal partition (i.e., normal partition) until the new version firmware is fully received.

[0101] More specifically, if the OTA status flag is the second download flag, it indicates that the terminal device has been triggered to perform an OTA upgrade. At this time, the bootloader jumps to recovery mode. In recovery mode, the main program establishes a connection with the remote server via 4G mobile communication or wireless LAN. The remote server transmits the new firmware version in fixed-size fragments. When each data packet arrives, the interrupt service routine in the recovery zero-wait area immediately responds to the interrupt, moving the data from the network module buffer to the receive buffer of the random access memory. After the new firmware version is received, the recovery mode main program calls the fast programming function in the recovery zero-wait area to erase all contents of the normal partition and write the new firmware version data completely to overwrite the old firmware version.

[0102] Step S1052: In response to the successful burning signal, the quick programming program is invoked to rewrite the OTA status flag from the second download flag to the first download flag, and the terminal device is restarted.

[0103] Specifically, such as Figure 2 As shown: After the new firmware version is received, the OTA status flag is rewritten to the first download flag, i.e., OTAFlag=READY, and a reboot is performed.

[0104] More specifically, after the new firmware is successfully flashed to the normal partition, the recovery mode main program calls the quick programming function in the recovery zero-wait area to rewrite the OTA status flag in the flag partition from the second download flag to the first download flag. After the flag rewriting is complete, the recovery mode main program immediately triggers a software reset, causing the terminal device to restart. During the restart process, the bootloader will again start executing from the recovery zero-wait area.

[0105] In some specific embodiments, after the main program starts successfully, the method further includes steps S201-S202:

[0106] Step S201: Continuously monitor whether a new firmware version exists on the remote server.

[0107] Specifically, such as Figure 2 As shown: When Normal mode is started and JumpFlag=SUCCESS is written, the background starts a 4G network to continuously monitor for new firmware versions.

[0108] More specifically, when the main program successfully starts within the normal partition of the terminal device, the program startup status flag is rewritten from the second startup flag back to the first startup flag to confirm successful startup. Subsequently, a version monitoring task is created to continuously send version query requests to a remote server. Upon receiving the version query request, the remote server retrieves the latest firmware version information corresponding to the device model from its database. The version query request can be sent via 4G mobile communication or a wireless LAN and includes the currently running firmware version number and the device's unique identifier.

[0109] Step S202: If the new firmware version exists on the remote server, the quick programming program is invoked to rewrite the OTA status flag from the first download flag to the second download flag, and the terminal device is restarted.

[0110] Specifically, such as Figure 2 As shown: When a new firmware version is detected, write OTAFlag=DOWNLOAD and perform a reboot.

[0111] More specifically, when the remote server retrieves the latest firmware version information, it sends a program download and upgrade command to the terminal device. When the terminal device's microcontroller determines from the received program download and upgrade command that the remote server has a new firmware version, it calls the flash memory fast programming function in the recovery zero-wait area to rewrite the OTA status flag stored in the flag partition from the first download flag to the second download flag. After the flag rewriting is complete, the main program immediately triggers a software reset, causing the terminal device to restart.

[0112] When the terminal device restarts, the bootloader executes from the starting address of the recovery zero-wait zone and reads the OTA status flag in the flag partition. Since this flag has been rewritten to the second download flag, the bootloader determines that it has entered recovery mode and jumps to the recovery partition to execute the firmware download process. In recovery mode, the new version of firmware is downloaded in segments from a remote server via 4G mobile communication or wireless LAN, and the firmware is burned to the normal partition to overwrite the old version of the target program, completing the entire upgrade process.

[0113] In some specific embodiments, after reading the program startup status flags, the method further includes:

[0114] If the program startup status flag is the second startup flag, then the quick programming program is invoked to rewrite the OTA status flag from the first download flag to the second download flag, and the terminal device is restarted.

[0115] Specifically, such as Figure 2As shown: When JumpFlag=FAILED, write OTAFlag=DOWNLOAD and reboot.

[0116] In this embodiment, when the OTA status flag is the first download flag and the program startup status flag is the second startup flag, it can be determined that the previous main program startup failed. The bootloader then calls the flash memory fast programming function in the zero-wait area to rewrite the OTA status flag in the flag partition from the first download flag to the second download flag. After the flag rewriting is complete, the terminal device is restarted. After the terminal restarts, steps S101 to S105 are executed again.

[0117] Through the above steps, the terminal device can automatically detect the startup failure state without external intervention, force the recovery mode to re-download the firmware, effectively avoid the device from permanent failure due to firmware defects or damage, and realize self-diagnosis and self-recovery functions.

[0118] The embodiments of this application have the following technical effects:

[0119] 1. The Flash memory is divided into a recovery zero-wait area, a recovery non-zero-wait area, a normal partition, and a flag partition to separate the storage of fast programming functions and ordinary functions, so as to adapt to the resource constraints of the zero-wait area. Furthermore, fast programming functions are stored in the zero-wait area and ordinary functions are stored in the non-zero-wait area, which not only ensures running efficiency but also saves space in the zero-wait area, thus solving the problem of limited resources in the zero-wait area.

[0120] 2. Existing technologies rely solely on firmware backup and recovery. This application achieves effective firmware upgrades through the collaborative verification of the OTA status flag OTAFlag and the program startup status flag JumpFlag, and triggers a re-upgrade process when an upgrade anomaly occurs, preventing the device from becoming "bricked" and significantly improving the reliability of device upgrades.

[0121] 3. The partition segment is defined by linking scripts, and the partition address and size are dynamically calculated based on the program size and Flash characteristics, which has the ability to adapt to different chips.

[0122] 4. Compared with existing technologies that require double the firmware space, this invention uses a four-part refined layout, which eliminates the need for additional storage space, greatly improving space utilization and adapting to small-capacity Flash with a capacity of less than 512KB.

[0123] 5. Existing technologies have fixed partition configurations. This invention provides a universal method for calculating partition addresses and sizes, which can be adapted to Flash chips with different capacities and different zero-wait-area ratios without requiring significant code modifications.

[0124] This application also provides a specific embodiment, as shown below:

[0125] The development board enables OTA upgrades of the industrial IoT operating system via a 4G network.

[0126] The chip has a built-in 480KB flash memory storage area, including a 128KB zero-wait area and a 352KB non-zero-wait area, with the address range [0x08000000, 0x08078000).

[0127] When booting from the program flash memory, the program flash memory address is mapped to the 0x00000000 address region, and it can also be accessed in the original address region 0x08000000.

[0128] Program size constraints: The binary files of quick programming-related functions in the Recovery program should be less than 32KB, the binary files of other programs in the Recovery program should be less than 156KB, and the binary files of Normal programs should be less than 288KB.

[0129] Based on the Flash partition address and size configuration method mentioned in the above embodiments, the Flash partition layout of the instance can be obtained, as shown in Table 2:

[0130] Table 2

[0131]

[0132] Corresponding to the above implementation of the fragmented OTA upgrade method adapted to zero-wait-area constraints, this application embodiment also provides a fragmented OTA upgrade system adapted to zero-wait-area constraints, used to execute the fragmented OTA upgrade method adapted to zero-wait-area constraints described in the above embodiments; the system is applied to a terminal device, the terminal device including flash memory with zero-wait-area and non-zero-wait-area; the zero-wait-area stores a bootloader and a quick-write program; the non-zero-wait-area stores an OTA status flag and a program startup status flag; such as Figure 3 As shown, the fragmented OTA upgrade system adapted to zero waiting area constraints includes:

[0133] An OTA status flag reading module is used to respond to the startup signal of the terminal device by calling the bootloader to read the OTA status flag from the non-zero waiting area;

[0134] The program startup status flag reading module is used to read the program startup status flag from the non-zero waiting area if the OTA status flag is a first download flag; the first download flag is used to indicate that there is no OTA upgrade task in the terminal device;

[0135] The first rewriting module is used to, if the program startup status flag is a first startup flag, call the quick programming program to rewrite the program startup status flag from the first startup flag to a second startup flag, and start the main program of the terminal device; the first startup flag is used to indicate that the main program was successfully started last time; the second startup flag is used to indicate that the main program failed to start last time; the main program is an application program that executes the business functions of the terminal device.

[0136] The second rewriting module is used to call the quick programming program to rewrite the program startup status flag from the second startup flag to the first startup flag in response to the startup success signal of the main program.

[0137] The OTA upgrade module is used to download a new version of firmware for OTA upgrade if the OTA status flag is a second download flag; the second download flag is used to indicate that the OTA upgrade task exists in the terminal device.

[0138] Optionally, the flash memory includes: a recovery zero-wait partition, a normal partition, a recovery non-zero-wait partition, and a flag partition; the recovery zero-wait partition is used to store programs that execute with zero latency in the terminal device's startup and recovery modes; the recovery zero-wait partition stores the bootloader, the quick-write program, and the interrupt service routine; the recovery mode refers to the minimized running state of the terminal device's microcontroller during OTA upgrades; the normal partition is used to store applications when the terminal device is running normally; the recovery non-zero-wait partition is used to store programs whose execution speed in the recovery mode is less than a preset speed; the flag partition is used to store the OTA status flag and the program startup status flag.

[0139] Optionally, the recovery zero-wait partition is located within the zero-wait region, and the starting address of the recovery zero-wait partition is the starting address of the zero-wait region of the memory; the normal partition is a contiguous storage space of the zero-wait region and the non-zero-wait region, and the starting address of the normal partition is the memory address following the ending address of the recovery zero-wait region, and the ending address of the normal partition is located within the non-zero-wait region; the recovery non-zero-wait partition and the flag partition are located within the non-zero-wait region, and the starting address of the recovery non-zero-wait partition is the memory address following the ending address of the normal partition, and the starting address of the flag partition is the memory address following the ending address of the recovery non-zero-wait partition.

[0140] Optionally, the OTA upgrade module is further configured to, if the OTA status flag is a second download flag, download a new version of firmware in response to the second download flag, and call the quick programming program to burn the new version of firmware to the normal partition to overwrite the old version of firmware of the main program; the second download flag is used to indicate that the terminal device has the OTA upgrade task; in response to the burning success signal, call the quick programming program to rewrite the OTA status flag from the second download flag to the first download flag, and restart the terminal device.

[0141] Optionally, the OTA upgrade module is also used to download the new version firmware of the main program in segments; and to burn the segmented firmware data of the new version firmware into the normal partition respectively until all segmented firmware data of the new version firmware has been received.

[0142] Optionally, the system further includes: a new firmware monitoring module, used to continuously monitor whether a new firmware version exists on the remote server; if the new firmware version exists on the remote server, the system calls the quick programming program to rewrite the OTA status flag from the first download flag to the second download flag, and restarts the terminal device.

[0143] Optionally, the system further includes: a download flag rewriting module, used to call the quick programming program to rewrite the OTA status flag from the first download flag to the second download flag and restart the terminal device if the program startup status flag is the second startup flag.

[0144] Optionally, the storage capacity of the flash memory is less than a preset capacity threshold.

[0145] The fragmented OTA upgrade system adapted to zero waiting area constraints provided in the above embodiments of this application and the fragmented OTA upgrade method adapted to zero waiting area constraints provided in the embodiments of this application are based on the same inventive concept and have the same beneficial effects as the methods adopted, run or implemented by the applications stored therein.

[0146] This application also provides a computer device for performing the above-described fragmented OTA upgrade method adapted to zero wait area constraints. Please refer to... Figure 4 This illustrates a schematic diagram of a computer device provided by some embodiments of this application. For example... Figure 4As shown, the computer device 4 includes a processor 400, a memory 401, a bus 402, and a communication interface 403. The processor 400, the communication interface 403, and the memory 401 are connected via the bus 402. The memory 401 stores a computer program that can run on the processor 400. When the processor 400 runs the computer program, it executes the fragmented OTA upgrade method adapted to zero wait area constraints provided in the foregoing embodiments of this application.

[0147] The memory 401 may include high-speed random access memory (RAM) or non-volatile memory, such as at least one disk storage device. Communication between this system network element and at least one other network element is achieved through at least one communication interface 403 (which can be wired or wireless), such as the Internet, wide area network, local area network, or metropolitan area network.

[0148] Bus 402 can be an ISA bus, PCI bus, or EISA bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. Memory 401 is used to store programs. After receiving an execution instruction, the processor 400 executes the program. The fragmented OTA upgrade method adapted to zero-wait-region constraints disclosed in the foregoing embodiments can be applied to the processor 400, or implemented by the processor 400.

[0149] The processor 400 may be an integrated circuit chip with signal processing capabilities. In implementation, each step of the above method can be completed by the integrated logic circuitry in the hardware of the processor 400 or by instructions in software form. The processor 400 may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), an off-the-shelf programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly embodied in the execution of a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software modules may reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. The storage medium is located in memory 401. The processor 400 reads the information in memory 401 and, in conjunction with its hardware, completes the steps of the above method.

[0150] The computer device provided in this application embodiment and the sharded OTA upgrade method adapted to zero waiting area constraints provided in this application embodiment are based on the same inventive concept and have the same beneficial effects as the methods they adopt, run or implement.

[0151] This application also provides a computer-readable storage medium corresponding to the fragmented OTA upgrade method adapted to zero wait area constraints provided in the foregoing embodiments. The computer-readable storage medium shown is an optical disc, on which a computer program (i.e., a program product) is stored. When the computer program is run by a processor, it executes the fragmented OTA upgrade method adapted to zero wait area constraints provided in any of the foregoing embodiments.

[0152] It should be noted that examples of the computer-readable storage medium may also include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other optical and magnetic storage media, which will not be elaborated here.

[0153] The computer-readable storage medium provided in the above embodiments of this application and the fragmented OTA upgrade method adapted to zero wait area constraints provided in the embodiments of this application are based on the same inventive concept and have the same beneficial effects as the methods adopted, run or implemented by the applications stored therein.

[0154] It should be noted that:

[0155] Numerous specific details are set forth in the specification provided herein. However, it will be understood that embodiments of this application may be practiced without these specific details. In some instances, well-known structures and techniques have not been shown in detail so as not to obscure the understanding of this specification.

[0156] Similarly, it should be understood that, in order to simplify this application and aid in understanding one or more of the various inventive aspects, in the above description of exemplary embodiments of this application, various features of this application are sometimes grouped together in a single embodiment, figure, or description thereof. However, this disclosure should not be construed as reflecting a schematic diagram in which the claimed application requires more features than are expressly recited in each claim. Rather, as reflected in the following claims, inventive aspects lie in fewer than all features of a single foregoing disclosed embodiment. Therefore, the claims following the detailed description are hereby expressly incorporated into that detailed description, wherein each claim itself is a separate embodiment of this application.

[0157] Furthermore, those skilled in the art will understand that although some embodiments described herein include certain features but not others included in other embodiments, combinations of features from different embodiments are intended to be within the scope of this application and form different embodiments. For example, in the following claims, any of the claimed embodiments can be used in any combination.

[0158] The above description is merely a preferred embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A method for adapting to zero-waiting area constraints for a fragmented OTA upgrade, characterized in that, The method is applied to a terminal device, which includes flash memory with a zero-wait area and a non-zero-wait area, the storage capacity of which is less than a preset capacity threshold. The zero-wait area stores a bootloader and a quick-write program. The non-zero-wait area stores an OTA status flag and a program startup status flag. The zero-wait area is divided into a recovery zero-wait partition, and the non-zero-wait area is divided into a recovery non-zero-wait partition and a flag partition. The normal partition is a contiguous storage space between the zero-wait area and the non-zero-wait area. The recovery non-zero-wait partition is used to store programs whose execution speed in recovery mode is less than a preset speed. The recovery zero-wait partition is used to store the bootloader and the quick-write program. The normal partition is used to store the main program of the terminal device; The flag partition is used to store the OTA status flag and the program startup status flag; the method includes: In response to the startup signal of the terminal device, the bootloader is invoked to read the OTA status flag from the non-zero wait area; If the OTA status flag is the first download flag, then the program startup status flag is read from the non-zero waiting area; the first download flag is used to indicate that there is no OTA upgrade task in the terminal device; If the program startup status flag is a first startup flag, then the quick programming program is invoked to rewrite the program startup status flag from the first startup flag to a second startup flag, and the main program of the terminal device is started; the first startup flag is used to indicate that the main program was successfully started last time; the second startup flag is used to indicate that the main program failed to start last time; the main program is an application program that executes the business functions of the terminal device; In response to the successful startup signal of the main program, the quick programming program is invoked to rewrite the program startup status flag from the second startup flag back to the first startup flag; If the OTA status flag is the second download flag, then the new firmware version is downloaded for OTA upgrade; the second download flag is used to indicate that the OTA upgrade task exists in the terminal device.

2. The method of claim 1, wherein, The flash memory includes: a recovery zero-wait partition, a normal partition, a recovery non-zero-wait partition, and a flag partition; The zero-wait partition is used to store programs that execute with zero latency in the startup and recovery modes of the terminal device; the zero-wait partition stores interrupt service routines; the recovery mode refers to the minimized running state of the microcontroller of the terminal device during OTA upgrades; The normal partition is used to store the applications used when the terminal device is running normally.

3. The method of claim 2, wherein, The recovery zero-wait partition is located within the zero-wait area, and the starting address of the recovery zero-wait partition is the starting address of the zero-wait area of ​​the flash memory; The starting address of the normal partition is the memory address following the ending address of the recovery zero-wait zone, and the ending address of the normal partition is located within the non-zero-wait zone. The recovery non-zero wait partition and the flag partition are located within the non-zero wait area. The starting address of the recovery non-zero wait partition is the next memory address after the ending address of the normal partition, and the starting address of the flag partition is the next memory address after the ending address of the recovery non-zero wait partition.

4. The method according to claim 2, characterized in that, If the OTA status flag is the second download flag, then download the new firmware version for OTA upgrade, including: If the OTA status flag is the second download flag, then in response to the second download flag, the new version firmware is downloaded, and the quick programming program is invoked to burn the new version firmware to the normal partition to overwrite the old version firmware of the main program; the second download flag is used to indicate that the terminal device has the OTA upgrade task. In response to the successful flashing signal, the quick programming program is invoked to rewrite the OTA status flag from the second download flag to the first download flag, and the terminal device is restarted.

5. The method according to claim 4, characterized in that, In response to the second download flag, downloading a new firmware version includes: Download the new firmware version of the main program in segments; The fragmented firmware data of the new version firmware is burned into the normal partition respectively until all fragmented firmware data of the new version firmware has been received.

6. The method according to claim 1 or 2, characterized in that, After the main program starts successfully, the method further includes: Continuously monitor the remote server for the availability of new firmware versions; If the new firmware version exists on the remote server, the quick programming program is invoked to rewrite the OTA status flag from the first download flag to the second download flag, and the terminal device is restarted.

7. The method according to claim 1 or 2, characterized in that, After reading the program startup status flag, the method further includes: If the program startup status flag is the second startup flag, then the quick programming program is invoked to rewrite the OTA status flag from the first download flag to the second download flag, and the terminal device is restarted.

8. A fragmented OTA upgrade system adapted to zero-wait-area constraints, characterized in that, The system is applied to a terminal device, which includes flash memory with a zero-wait area and a non-zero-wait area, the storage capacity of which is less than a preset capacity threshold. The zero-wait area stores a bootloader and a quick-write program. The non-zero-wait area stores an OTA status flag and a program startup status flag. The zero-wait area is divided into a recovery zero-wait partition, and the non-zero-wait area is divided into a recovery non-zero-wait partition and a flag partition. The normal partition is a contiguous storage space between the zero-wait area and the non-zero-wait area. The recovery non-zero-wait partition is used to store programs whose execution speed in recovery mode is less than a preset speed. The recovery zero-wait partition is used to store the bootloader and the quick-write program. The normal partition is used to store the main program of the terminal device; The flag partition is used to store the OTA status flag and the program startup status flag; The system includes: An OTA status flag reading module is used to respond to the startup signal of the terminal device by calling the bootloader to read the OTA status flag from the non-zero waiting area; The program startup status flag reading module is used to read the program startup status flag from the non-zero waiting area if the OTA status flag is a first download flag; the first download flag is used to indicate that there is no OTA upgrade task in the terminal device; The first rewriting module is used to, if the program startup status flag is a first startup flag, call the quick programming program to rewrite the program startup status flag from the first startup flag to a second startup flag, and start the main program of the terminal device; the first startup flag is used to indicate that the main program was successfully started last time; the second startup flag is used to indicate that the main program failed to start last time; the main program is an application program that executes the business functions of the terminal device. The second rewriting module is used to call the quick programming program to rewrite the program startup status flag from the second startup flag to the first startup flag in response to the startup success signal of the main program. The OTA upgrade module is used to download a new version of firmware for OTA upgrade if the OTA status flag is a second download flag; the second download flag is used to indicate that the OTA upgrade task exists in the terminal device.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing the computer to execute the sectional OTA upgrade method with zero wait area constraint according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Remote wireless upgrading method for equipment

    CN105511929A