Equipment processing method and device, equipment, storage medium and program product
By performing consistency checks and redundant configuration firmware upgrades on the slave processor after the medical device is powered on, the unreliability problem caused by abnormal firmware upgrades is resolved, ensuring that the device operates normally under abnormal conditions.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-31
- Publication Date
- 2026-04-14
AI Technical Summary
During the firmware upgrade process of medical devices, existing technologies may lead to abnormal upgrades, causing the device to be unable to recognize and execute abnormal applications, thus reducing the reliability of device operation.
After the device is powered on, the system obtains the current field information from the processor's configuration file and performs a consistency check with the standard field information to determine whether a firmware upgrade is needed. In abnormal situations, the system performs upgrades by configuring the firmware redundantly and switches the operating partition when necessary to ensure the device operates normally.
It enables the slave processor to promptly detect and repair abnormal states after the device is powered on, preventing abnormal application execution and ensuring the reliability and flexibility of device operation.
Smart Images

Figure CN121858167A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular to a device processing method, apparatus, device, storage medium, and program product. Background Technology
[0002] With the continuous development of the medical field, in order to ensure the updating and iteration of applications in medical devices, a device processing method can be adopted to burn the new version of firmware information into the memory of the medical device.
[0003] However, when using existing technology to upgrade firmware, there may be upgrade anomalies. If the medical device is powered on directly in this case, the medical device will not be able to recognize the anomaly and will perform master-slave control based on the abnormally upgraded application, which will reduce the reliability of the medical device's operation. Summary of the Invention
[0004] Therefore, it is necessary to provide a device processing method, apparatus, device, storage medium, and program product that can provide reliable device operation in response to the above-mentioned technical problems.
[0005] In a first aspect, this application provides a device processing method, comprising:
[0006] After the device is powered on, the current field information in the preset location of the configuration file is obtained through the slave processor in the device; wherein, the configuration file is the configuration file associated with the slave processor, and the preset location is used to store the identification information of the slave processor;
[0007] If the firmware upgrade of the slave processor is determined to be necessary based on the consistency between the current field information and the standard field information, the firmware upgrade process is performed on the slave processor by configuring the firmware redundantly; wherein, the standard field information is used to identify that the slave processor is in an abnormal state.
[0008] In one embodiment, the method further includes:
[0009] If an abnormal state is detected in the slave processor, the main processor in the device modifies the identification information stored in the preset location in the configuration file to standard field information.
[0010] In one embodiment, determining whether a firmware upgrade is needed for the slave processor based on the consistency between current field information and standard field information includes:
[0011] The processor performs a consistency check between the current field information and the standard field information; if the consistency check result is successful, it is determined that the processor needs to be upgraded.
[0012] In one embodiment, the method further includes:
[0013] If the consistency check fails, run the application associated with the processor.
[0014] In one embodiment, firmware upgrade processing for the slave processor is performed by configuring redundant firmware, including:
[0015] The firmware upgrade of the slave processor is completed by selecting the first partition as the running partition of the slave processor from the redundant partitions associated with the slave processor based on the firmware partition information in the slave processor's historical running record; and burning the target firmware information associated with the second partition in the redundant configuration firmware into the memory associated with the second partition. The second partition is the partition in the redundant partition other than the first partition.
[0016] In one embodiment, after completing the firmware upgrade of the slave processor, the method further includes:
[0017] The processor switches the running partition associated with the processor from the first partition to the second partition and controls the application associated with the processor to run according to the target firmware information associated with the second partition. If the processor detects an application running abnormality, it performs an integrity check on the historical firmware information associated with the first partition. If the integrity check result is that the integrity check passes, the processor switches the running partition associated with the processor from the second partition to the first partition and controls the application associated with the processor to run according to the historical firmware information.
[0018] Secondly, this application also provides a device processing apparatus, comprising:
[0019] The information acquisition module is used to obtain the current field information at a preset location in the configuration file through the slave processor in the device after the device is powered on; wherein, the configuration file is the configuration file associated with the slave processor, and the preset location is used to store the identification information of the slave processor;
[0020] The firmware upgrade module is used to perform firmware upgrade processing on the slave processor when the slave processor determines that a firmware upgrade is needed based on the consistency between the current field information and the standard field information; the standard field information is used to identify that the slave processor is in an abnormal state.
[0021] Thirdly, this application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps:
[0022] After the device is powered on, the current field information in the preset location of the configuration file is obtained through the slave processor in the device; wherein, the configuration file is the configuration file associated with the slave processor, and the preset location is used to store the identification information of the slave processor;
[0023] If the firmware upgrade of the slave processor is determined to be necessary based on the consistency between the current field information and the standard field information, the firmware upgrade process is performed on the slave processor by configuring the firmware redundantly; wherein, the standard field information is used to identify that the slave processor is in an abnormal state.
[0024] Fourthly, this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, performs the following steps:
[0025] After the device is powered on, the current field information in the preset location of the configuration file is obtained through the slave processor in the device; wherein, the configuration file is the configuration file associated with the slave processor, and the preset location is used to store the identification information of the slave processor;
[0026] If the firmware upgrade of the slave processor is determined to be necessary based on the consistency between the current field information and the standard field information, the firmware upgrade process is performed on the slave processor by configuring the firmware redundantly; wherein, the standard field information is used to identify that the slave processor is in an abnormal state.
[0027] Fifthly, this application also provides a computer program product, including a computer program that, when executed by a processor, performs the following steps:
[0028] After the device is powered on, the current field information in the preset location of the configuration file is obtained through the slave processor in the device; wherein, the configuration file is the configuration file associated with the slave processor, and the preset location is used to store the identification information of the slave processor;
[0029] If the firmware upgrade of the slave processor is determined to be necessary based on the consistency between the current field information and the standard field information, the firmware upgrade process is performed on the slave processor by configuring the firmware redundantly; wherein, the standard field information is used to identify that the slave processor is in an abnormal state.
[0030] The aforementioned device processing method, apparatus, device, storage medium, and program product, after the device is powered on, obtains the current field information at a preset location in the configuration file through the slave processor in the device. If the slave processor determines that a firmware upgrade is needed based on the consistency between the current field information and standard field information, it performs a firmware upgrade on the slave processor through redundant configuration. Compared to related technologies that directly run the slave processor after the device is powered on, this method, by modifying the identification information in the configuration file through the main processor to mark the slave processor in an abnormal state, can promptly detect abnormal states of the slave processor after the device is powered on. By performing a firmware upgrade on the abnormal slave processor, the abnormal state of the slave processor is eliminated, avoiding the direct execution of applications in the device while the slave processor is in an abnormal state, thereby ensuring the reliability of device operation. Attached Figure Description
[0031] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the description of the embodiments of this application or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0032] Figure 1 This is a flowchart illustrating a device processing method in one embodiment;
[0033] Figure 2 This is a schematic diagram of the firmware upgrade process in one embodiment;
[0034] Figure 3 This is a schematic diagram of the firmware verification format in one embodiment;
[0035] Figure 4 This is a schematic diagram of the version rollback process in one embodiment;
[0036] Figure 5 This is a flowchart illustrating the device processing method in another embodiment;
[0037] Figure 6 This is a structural block diagram of the device processing apparatus in one embodiment;
[0038] Figure 7 This is an internal structure diagram of an IoT device in one embodiment. Detailed Implementation
[0039] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0040] With the continuous development of the medical field, in order to ensure the updating and iteration of applications in medical devices, a device processing method can be adopted to burn the new version of firmware information into the memory of the medical device.
[0041] However, when using existing technology to upgrade firmware, there may be upgrade anomalies. If the medical device is powered on directly in this case, the medical device will not be able to recognize the anomaly and will perform master-slave control based on the abnormally upgraded application, which will reduce the reliability of the medical device's operation.
[0042] Based on this, in an exemplary embodiment, a device processing method is provided, which will be described using an example of the method being applied to an Internet of Things (IoT) device. Figure 1 As shown, the specific steps include:
[0043] S101: After the device is powered on, the current field information at the preset position in the configuration file is obtained through the slave processor in the device.
[0044] The term "equipment" here refers to IoT devices with upgrade requirements, such as medical devices, i.e., surgical robots. Furthermore, surgical robots, as high-end medical devices integrating precision mechanics, real-time control, sensor feedback, and image processing technologies, generally employ a master-slave control architecture. This architecture requires microsecond-level latency, high synchronization, and determinism in control commands and status feedback between the master (doctor's operating end) and the slave (instrument execution end).
[0045] A slave processor refers to the processor within the lower-level machine of an IoT device, such as the processor in the instrument actuator of a surgical robot. The slave processor can be a Digital Signal Processor (DSP), in which case firmware upgrades can involve upgrading the DSP program running on the DSP processor.
[0046] The configuration file refers to the configuration file associated with the slave processor in the device, used to store the slave processor's attribute information. It can be in Extensible Markup Language (XML) format. The preset location is used to store the slave processor's identification information, for example, an 8-byte slave processor serial number, which is the identifier (ID) assigned to the slave processor by the master processor in the host computer. The current field information refers to the field information stored in the preset location at the current moment; it can be identification information or other modified field information.
[0047] Optionally, after the device is powered on but before it runs, for each slave processor in the device, it is necessary to retrieve the current field information at a preset location from the configuration file associated with that slave processor. For example, the current field information of the first 8 bytes in the configuration file can be retrieved.
[0048] It is worth noting that the identification information of the slave processor is usually dynamically assigned by the IoT device and does not depend on this information in actual operation. Therefore, the initial value of this field in the configuration file can be assigned to other system uses. Based on this, in this embodiment, when an abnormal state of the slave processor is detected, the main processor in the device modifies the identification information stored in a preset location in the configuration file to standard field information. The main processor can be a processor within the host computer of the IoT device, capable of interacting with each slave processor. An abnormal state of the slave processor can be caused by a crash in the slave processor itself, or by an upgrade anomaly during firmware upgrades; this embodiment does not limit this.
[0049] Specifically, if firmware corruption is detected in the slave processor and / or the application associated with the slave processor crashes, it is determined that the slave processor is in an abnormal state. Subsequently, the master processor can modify the identification information stored in a preset location in the slave processor's configuration file at the current moment to standard field information. This allows the slave processor to determine whether it is in an abnormal state based on the current field information in the preset location upon the next power-on.
[0050] S102, if the slave processor determines that a firmware upgrade is needed based on the consistency between the current field information and the standard field information, the slave processor is upgraded by redundantly configuring the firmware.
[0051] The standard field information is used to identify when the slave processor is in an abnormal state. The so-called redundant configuration firmware refers to the firmware information used for firmware upgrades to the slave processor; furthermore, the redundant configuration firmware contains firmware information with redundant configurations.
[0052] Optionally, the slave processor can determine whether a firmware upgrade is needed based on the consistency between the current field information and the standard field information. If a firmware upgrade is determined to be needed, the slave processor can burn the redundant configuration firmware already stored in its local memory into the memory associated with the slave processor to complete the firmware upgrade.
[0053] Furthermore, after detecting that the processor firmware upgrade is complete, the processor can instruct the application associated with the processor to run.
[0054] In the above-described device processing method, after the device is powered on, the current field information at a preset location in the configuration file is obtained by the slave processor in the device. If the slave processor determines that a firmware upgrade is needed based on the consistency between the current field information and the standard field information, a firmware upgrade is performed on the slave processor through redundant configuration. Compared to related technologies that directly run the slave processor after the device is powered on, this method, by modifying the identification information in the configuration file through the master processor to mark the slave processor in an abnormal state, can promptly detect abnormal states of the slave processor after the device is powered on. By performing a firmware upgrade on the abnormal slave processor, the abnormal state of the slave processor is eliminated, avoiding the direct execution of applications on the device while the slave processor is in an abnormal state, thus ensuring the reliability of device operation.
[0055] Based on the above embodiments, this application provides an optional method for determining whether to upgrade the firmware of the slave processor. Specifically, the slave processor performs a consistency check between the current field information and the standard field information; if the consistency check result is that the consistency check passes, it is determined that the slave processor needs to be upgraded.
[0056] In one optional implementation, since standard field information is stored in a preset location when the slave processor is in an abnormal state, the slave processor can perform a consistency check between the current field information and the standard field information. If the consistency check passes, it proves that the slave processor is in an abnormal state, and therefore, the slave processor needs to be upgraded with firmware.
[0057] In another alternative implementation, if the consistency check result is a failure, the application associated with the processor is run.
[0058] Specifically, if the consistency check fails, it proves that the slave processor is not in an abnormal state, and therefore, the application associated with the slave processor can be run directly. It is worth noting that, to ensure the reliability of the verification, even if the consistency check fails, the slave processor can be further assessed by allocating records based on its identifier information to determine if the current field information matches the slave processor's identifier information.
[0059] If the current field information is the identifier of the slave processor, then run the application associated with the slave processor; if the current field information is not the identifier of the slave processor, the device startup phase can be maintained, and a device anomaly message can be sent to the maintenance personnel.
[0060] For example, after the device is powered on, the bootloader of the main processor in the device can be started first. Then, the current field information at the identification information position in the configuration file can be obtained from the processor. If the current field information is standard field information, the device can stay in the bootloader stage (i.e., the boot loading stage) or perform firmware upgrades on the slave processor. If the current field information is identification information, the application associated with the slave processor can be CRC checked by the slave processor, and the application can be run if the CRC check is successful.
[0061] In this embodiment of the application, by performing consistency verification between the current field information and the standard field information, and performing corresponding subsequent processing based on the consistency verification result, the flexibility and reliability of the device operation can be guaranteed.
[0062] Based on the above embodiments, this application provides an optional method for firmware upgrade, such as... Figure 2 As shown, it specifically includes the following:
[0063] S201, the processor selects the first partition as the running partition of the processor from the redundant partitions associated with the processor based on the firmware partition information in the historical operation record of the processor.
[0064] The so-called historical operation record refers to the relevant record information generated by the processor during operation within a historical period, which may include, but is not limited to, the partition identifier used by the processor during operation within the historical period. The so-called running partition is the partition used to support the operation of the processor when the device is running. The so-called first partition is the partition in the redundant partition that serves as the running partition at the current moment.
[0065] Understandably, in medical devices, to ensure synchronized operation and firmware upgrades, a redundant partition design can be employed. This involves configuring two partitions (Party A and Party B) as the operating partition and a non-operating partition, respectively. During firmware upgrades, new firmware information is burned into the non-operating partition. Therefore, the redundant firmware configuration needs to include both Party A and Party B firmware, and these two firmware files must be independent image files.
[0066] In addition, to enhance the integrity and reliability of data in redundant configuration firmware, you can refer to... Figure 3 The firmware verification format diagram shown illustrates that after compiling and generating firmware for each partition, a verification information generation tool automatically adds verification information to a specified location in each firmware image. This information includes, but is not limited to, write time, complete data length, and Cyclic Redundancy Check (CRC) codes corresponding to basic information. Furthermore, to facilitate burning and transmission, after completing the verification information injection, the firmware for partition A and partition B can be merged into a complete composite firmware package, i.e., redundant configuration firmware, according to a predefined format.
[0067] Optionally, when upgrading the firmware of the slave processor, the slave processor can determine the identification information of the running partition within the historical period based on the firmware partition information in the slave processor's historical operation record; then, based on the identification information, the first partition corresponding to the identification information can be selected as the running partition of the slave processor from the redundant partitions associated with the processor.
[0068] S202 completes the firmware upgrade of the slave processor by burning the target firmware information associated with the second partition in the redundant configuration firmware to the memory associated with the second partition.
[0069] The second partition is the redundant partition excluding the first partition; that is, the non-running partition at the current moment. The target firmware information is the firmware information corresponding to the encoding position of the second partition.
[0070] Optionally, after determining that the first partition is the current running partition, the slave processor can burn the target firmware information associated with the second partition in the redundant configuration firmware into the memory corresponding to the second partition of the slave processor to realize firmware upgrade of the slave processor.
[0071] For example, if region A was the running partition during a historical period as represented by the processor's historical operation records, then region A can be used as the running partition at the current moment. In this case, the slave processor can burn the firmware information corresponding to region B in the redundant configuration firmware into the memory of region B, thereby completing the firmware upgrade of the slave processor.
[0072] In this embodiment of the application, by identifying the running partition and burning the corresponding target firmware information into the non-running partition, the rationality and reliability of firmware upgrades can be guaranteed.
[0073] Based on the above embodiments, in this application embodiment, after completing the firmware upgrade of the slave processor, an optional method for version rollback is provided, such as... Figure 4 As shown, it specifically includes the following:
[0074] S401 switches the running partition associated with the processor from the first partition to the second partition by switching the processor from the processor to the second partition, and controls the application associated with the processor to run according to the target firmware information associated with the second partition.
[0075] Understandably, after completing the firmware upgrade of the slave processor (writing the new firmware information into the memory corresponding to the second partition), the new version of the application can be run first. At this point, the running partition associated with the slave processor can be switched from the first partition to the second partition. Subsequently, the application associated with the slave processor can be controlled to run based on the target firmware information burned into the second partition.
[0076] S402 performs an integrity check on the historical firmware information associated with the first partition when an application runtime anomaly is detected by the processor.
[0077] Among these, operational anomalies can be caused by application lag or other issues resulting from version updates. Historical firmware information refers to the firmware information corresponding to older versions of the application.
[0078] Optionally, if an anomaly is detected in the new version of the application during its execution on the processor, the processor can roll back the new version to the old version. In this case, to ensure the reliability of the old version, the processor can first perform an integrity check on the historical firmware information burned into the memory corresponding to the first partition.
[0079] S403, if the integrity verification result is that the integrity verification is passed, switches the running partition associated with the processor from the second partition to the first partition by the processor, and controls the application associated with the processor to run according to the historical firmware information.
[0080] Optionally, if the integrity verification result is that the integrity verification passes, the slave processor can switch the running partition associated with the slave processor from the second partition back to the first partition, and control the application associated with the slave processor to run according to the historical firmware information associated with the first partition. In this case, the version rollback can be achieved without retransmitting the original firmware information.
[0081] In this embodiment, application version rollback is achieved by switching the runtime partition, which significantly reduces the time and bandwidth resources required for rollback. Furthermore, a verification mechanism ensures the reliability of the switching process, enabling rapid recovery from invalid or faulty versions to historically stable versions, greatly improving system robustness and maintainability.
[0082] Based on the above embodiments, in this application embodiment, when the slave processor in the lower-level machine is a DSP processor, another complete firmware upgrade method is provided, specifically including the following steps:
[0083] The first step is to switch the host computer to Bootloader mode and transfer the redundant configuration firmware to the host computer.
[0084] The host computer typically operates in two modes: "Running Mode" (interacting with the DSP application, such as reading data / issuing control commands) and "Bootloader Mode" (handling firmware upgrades only). After switching, the host computer loads the EtherCAT (File Access over EtherCAT, FOE) protocol stack and resets communication parameters (such as Ethernet port / baud rate) to ensure the upgrade process is not interfered with by other services. EtherCAT, or Ethernet for Control Automation Technology, is an Ethernet protocol used for control automation technology. It employs a "fly-read / fly-write" master-slave communication mechanism, featuring high data transmission efficiency and extremely low communication latency, and is widely used in industrial automation and motion control fields with extremely high real-time requirements.
[0085] Optionally, maintenance personnel can trigger a firmware upgrade request through the host computer interface (such as the "Upgrade Mode" button), or the host computer can automatically trigger a firmware upgrade request when it detects that the standard field information is in the preset position of the processor.
[0086] Furthermore, upon detecting a firmware upgrade request, the host computer can be switched to Bootloader mode, and redundant configuration firmware can be transferred to the host computer.
[0087] The second step is for the host computer to verify the redundant configuration firmware stored locally, and then proceed to the third step if the verification passes.
[0088] Optionally, the host computer can perform integrity and authenticity verification on the redundant configuration firmware (e.g., CRC check and basic information verification). If the verification fails, an upgrade failure message is returned directly to instruct the maintenance personnel to handle the issue. If the verification passes, the third step is executed.
[0089] The third step involves the host computer sending a FOE firmware upgrade command to the DSP processor, instructing the DSP program associated with the DSP processor to verify the FOE firmware upgrade command, and then proceeding to the fourth step if the verification is successful.
[0090] The FOE firmware upgrade command may include key parameters such as fixed upgrade command code, target burning area (A / B), total firmware length, full CRC value, and basic information segment CRC value.
[0091] Optionally, the host computer can send a FOE firmware upgrade command to the DSP processor to transmit the core upgrade parameters and notify the DSP processor to prepare to receive the relevant firmware data for the redundant configuration firmware. The DSP program can continuously listen to the FOE port, parse the data packet to see if it contains the preset upgrade command code; if it does, it determines that the command exists; if not, it determines that "the command does not exist" and directly returns an upgrade failure message.
[0092] The fourth step involves the DSP program confirming whether the target firmware burning area is area A or area B, and verifying that the firmware instructions match the input instructions. If they match, proceed to the fifth step. If they do not match, an upgrade failure message is returned directly.
[0093] In the fifth step, the DSP program performs a CRC check on the basic information and analyzes its content. If the check passes, it proceeds to the sixth step. If the check fails, it directly returns an upgrade failure message.
[0094] In the sixth step, the DSP program extracts the basic information content, complete data length, complete data CRC, and time information for subsequent data verification and confirms the burning area for firmware burning.
[0095] The seventh step involves the DSP program erasing the FLASH of the target programming area, then writing the first frame of data from the target programming area into the FLASH, and updating the verification information (write length and CRC).
[0096] Step 8: After the firmware is flashed, the host computer performs a verification comparison. If the verification passes, proceed to step 9. If the verification fails, an upgrade failure message is returned directly.
[0097] In the ninth step, the DSP program writes a firmware completion flag to the current burning area, indicating that the firmware burning is complete, and waits for the FOE transmission completion flag to arrive.
[0098] The tenth step is to configure the partition priority for the next startup of the DSP program on the host computer.
[0099] For example, specify booting from the partition where the processor was upgraded.
[0100] In the eleventh step, the host computer sends a command to the DSP processor to notify it to exit Bootloader mode and run the application.
[0101] Figure 5 This is a flowchart illustrating a device processing method in another embodiment. Based on the above embodiments, this embodiment provides an optional example of a device processing method. (In conjunction with...) Figure 5 The specific implementation process is as follows:
[0102] S501, after the device is powered on, obtains the current field information at a preset position in the configuration file through the slave processor in the device.
[0103] The configuration file is a configuration file associated with the processor, and a preset location is used to store the identification information of the processor.
[0104] Optionally, if an abnormal state is detected in the slave processor, the identification information stored in a preset location in the configuration file can be modified to standard field information by the device's main processor.
[0105] S502: Determine from the processor whether the current field information is consistent with the standard field information. If yes, execute S503; otherwise, execute S505.
[0106] The standard field information is used to identify when the processor is in an abnormal state.
[0107] S503 selects the first partition as the running partition of the slave processor from the redundant partitions associated with the slave processor based on the firmware partition information in the slave processor's historical operation record.
[0108] The S504 completes the firmware upgrade for the slave processor by burning the target firmware information associated with the second partition in the redundant configuration firmware to the memory associated with the second partition.
[0109] The second partition is the redundant partition other than the first partition.
[0110] S505 runs applications associated with the processor.
[0111] Optionally, after completing the firmware upgrade of the slave processor, the slave processor switches the running partition associated with the slave processor from the first partition to the second partition, and controls the application associated with the slave processor to run according to the target firmware information associated with the second partition; if an application is detected to have a running abnormality, the slave processor performs an integrity check on the historical firmware information associated with the first partition; if the integrity check result is that the integrity check passes, the slave processor switches the running partition associated with the slave processor from the second partition to the first partition, and controls the application associated with the slave processor to run according to the historical firmware information.
[0112] The specific processes of S501-S505 described above can be found in the description of the above method embodiments. Their implementation principles and technical effects are similar, and will not be repeated here.
[0113] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.
[0114] Based on the same inventive concept, this application also provides a device processing apparatus for implementing the device processing method described above. The solution provided by this apparatus is similar to the solution described in the above method; therefore, the specific limitations in one or more device processing apparatus embodiments provided below can be found in the limitations of the device processing method described above, and will not be repeated here.
[0115] In one exemplary embodiment, such as Figure 6 As shown, a device processing apparatus 1 is provided, comprising: an information acquisition module 10 and a firmware upgrade module 20, wherein:
[0116] The information acquisition module 10 is used to acquire the current field information at a preset position in the configuration file through the slave processor in the device after the device is powered on; wherein, the configuration file is a configuration file associated with the slave processor, and the preset position is used to store the identification information of the slave processor;
[0117] Firmware upgrade module 20 is used to perform firmware upgrade processing on the slave processor by redundantly configuring firmware when the slave processor determines that a firmware upgrade is needed based on the consistency between the current field information and the standard field information; wherein, the standard field information is used to identify that the slave processor is in an abnormal state.
[0118] In one exemplary embodiment, the device processing apparatus 1 further includes an information modification module, wherein the information modification module is specifically used for:
[0119] If an abnormal state is detected in the slave processor, the main processor in the device modifies the identification information stored in the preset location in the configuration file to standard field information.
[0120] In one exemplary embodiment, the firmware upgrade module 20 is specifically used for:
[0121] The processor performs a consistency check between the current field information and the standard field information; if the consistency check result is successful, it is determined that the processor needs to be upgraded.
[0122] In one exemplary embodiment, the firmware upgrade module 20 is further configured to:
[0123] If the consistency check fails, run the application associated with the processor.
[0124] In one exemplary embodiment, the firmware upgrade module 20 is further configured to:
[0125] The firmware upgrade of the slave processor is completed by selecting the first partition as the running partition of the slave processor from the redundant partitions associated with the slave processor based on the firmware partition information in the slave processor's historical running record; and burning the target firmware information associated with the second partition in the redundant configuration firmware into the memory associated with the second partition. The second partition is the partition in the redundant partition other than the first partition.
[0126] In one exemplary embodiment, the device processing apparatus 1 further includes a version rollback module, wherein, after completing the firmware upgrade of the slave processor, the version rollback module is specifically used for:
[0127] The processor switches the running partition associated with the processor from the first partition to the second partition and controls the application associated with the processor to run according to the target firmware information associated with the second partition. If the processor detects an application running abnormality, it performs an integrity check on the historical firmware information associated with the first partition. If the integrity check result is that the integrity check passes, the processor switches the running partition associated with the processor from the second partition to the first partition and controls the application associated with the processor to run according to the historical firmware information.
[0128] Each module in the aforementioned processing device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in the computer device in hardware form, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each module.
[0129] In one exemplary embodiment, an Internet of Things (IoT) device is provided, which may be a medical device, such as a surgical robot, and its internal structure diagram may be as follows: Figure 7 As shown, the IoT device includes a host computer and a slave computer. The host computer includes a processor, memory, input / output interfaces, communication interfaces, and input devices. The processor, memory, and input / output interfaces are connected via a system bus, and the communication interfaces and input devices are also connected to the system bus via the input / output interfaces. The processor of the host computer provides computing and control capabilities and can be the main processor in the IoT device. The memory of the host computer includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs, and can also store firmware information of various application programs obtained by the host computer. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage media. The input / output interfaces of the host computer are used for exchanging information between the processor and external devices. The input devices of the host computer can be a touch layer covering the display screen, buttons, trackballs, or touchpads on the computer device casing, or external keyboards, touchpads, or mice, etc.
[0130] The lower-level device in an IoT device includes a processor, memory, and a communication interface. Lower-level devices communicate with each other through their respective communication interfaces. The connection can be wired or wireless; wireless connections can be achieved through Wi-Fi, mobile cellular networks, Near Field Communication (NFC), or other technologies. The processor of this lower-level device can be a slave processor in the IoT device, capable of interacting with the main processor in the host computer. The memory of this lower-level device includes non-volatile storage media and internal memory, which can store firmware information for various applications issued by the host computer, as well as various operational data collected during operation.
[0131] Those skilled in the art will understand that Figure 7 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the IoT devices to which the present application is applied. Specific IoT devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0132] In one embodiment, a computer device is also provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps in the above method embodiments.
[0133] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon that, when executed by a processor, implements the steps in the above method embodiments.
[0134] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps in the above method embodiments.
[0135] It should be noted that the data involved in this application (including but not limited to firmware data) is all data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data must comply with relevant regulations.
[0136] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, artificial intelligence (AI) processors, etc., and are not limited to these.
[0137] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.
[0138] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A device processing method, characterized in that, The method includes: After the device is powered on, the current field information at a preset location in the configuration file is obtained through the slave processor in the device; wherein, the configuration file is the configuration file associated with the slave processor, and the preset location is used to store the identification information of the slave processor; If the slave processor determines that a firmware upgrade is needed based on the consistency between the current field information and the standard field information, the firmware upgrade is performed on the slave processor by configuring the firmware redundantly; wherein, the standard field information is used to identify that the slave processor is in an abnormal state.
2. The method according to claim 1, characterized in that, The method further includes: If the slave processor is detected to be in an abnormal state, the main processor in the device modifies the identification information stored in the preset location in the configuration file to the standard field information.
3. The method according to claim 1 or 2, characterized in that, The step of determining whether a firmware upgrade is needed for the slave processor based on the consistency between the current field information and the standard field information includes: The processor performs a consistency check between the current field information and the standard field information. If the consistency check result is successful, it is determined that the slave processor needs to be upgraded with firmware.
4. The method according to claim 3, characterized in that, The method further includes: If the consistency check fails, the application associated with the processor is run.
5. The method according to any one of claims 1-4, characterized in that, The firmware upgrade process for the slave processor through redundant configuration firmware includes: The slave processor selects the first partition as the running partition from the redundant partitions associated with the slave processor based on the firmware partition information in the slave processor's historical operation record. The slave processor burns the target firmware information associated with the second partition in the redundant configuration firmware into the memory associated with the second partition to complete the firmware upgrade of the slave processor; wherein, the second partition is the partition in the redundant partition other than the first partition.
6. The method according to claim 5, characterized in that, After completing the firmware upgrade of the slave processor, the method further includes: The slave processor switches the running partition associated with the slave processor from the first partition to the second partition, and controls the application associated with the slave processor to run according to the target firmware information associated with the second partition; If an application is detected to have a runtime abnormality by the processor, the integrity of the historical firmware information associated with the first partition is verified. If the integrity verification result is that the integrity verification is successful, the running partition associated with the slave processor is switched from the second partition to the first partition through the slave processor, and the application associated with the slave processor is controlled to run according to the historical firmware information.
7. A device for processing equipment, characterized in that, The device includes: The information acquisition module is used to acquire current field information at a preset location in the configuration file through the slave processor in the device after the device is powered on; wherein, the configuration file is the configuration file associated with the slave processor, and the preset location is used to store the identification information of the slave processor; The firmware upgrade module is used to perform firmware upgrade processing on the slave processor by redundantly configuring firmware when the slave processor determines that a firmware upgrade is needed based on the consistency between the current field information and the standard field information; wherein the standard field information is used to identify that the slave processor is in an abnormal state.
8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 6.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.
10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.