Accelerated chip firmware update system, method, compute acceleration card, and artificial intelligence server

CN122733338APending Publication Date: 2026-09-11广州壁仞智能科技有限公司 +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610896966.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-18
Publication Date
2026-09-11

AI Technical Summary

Technical Problem

[0004]然而,在服务器集群中的人工智能服务器需要持续保持运行状态,并且固件升级通常存在较高的升级风险,一旦升级过程中出现干扰,则极易导致固件升级失败,造成加速芯片功能失效,从而减弱人工智能服务器的计算推理性能,甚至使得人工智能服务器的计算推理能力完全丧失

Benefits of technology

[0058]As can be seen from the above scheme, the accelerated chip firmware update system, method, computing accelerator card, and artificial intelligence server disclosed herein use differential upgrade packages to upgrade the accelerated chip firmware. This reduces the size of the firmware transmitted from the host to the computing accelerator card, reduces the PCIe bus bandwidth usage between the host and the computing accelerator card, and improves firmware transmission efficiency. This helps improve the autonomy, security, efficiency, fault tolerance, and compatibility of the accelerated chip firmware update process, improves the reliability and operational efficiency of the accelerated chip firmware update, and helps reduce system downtime risks and manual intervention costs. Furthermore, compared to using a full accelerated chip firmware upgrade package (e.g., an upgrade package including all third-version accelerated chip firmware), this disclosure effectively reduces the bandwidth resources occupied by the transmission of the accelerated chip firmware upgrade package between the host and the computing accelerator card. This allows the host of the artificial intelligence server to improve data transmission efficiency due to the reduced bandwidth resources occupied during the transmission of the accelerated chip firmware upgrade package, such as improving the efficiency of distributing computing tasks to the computing accelerator card, thereby helping to improve the computational inference performance of the artificial intelligence server. When a cluster of artificial intelligence servers contains a large number of acceleration chips that require firmware upgrades, the improvement in the computational inference performance of the cluster will be more significant.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122733338A_ABST
    Figure CN122733338A_ABST
Patent Text Reader

Abstract

The present disclosure relates to the technical field of firmware update, and particularly relates to an acceleration chip firmware update system and method, a computing acceleration card and an artificial intelligence server. The system comprises: a firmware update management unit, configured to receive an acceleration chip firmware differential upgrade package issued by a host and store the acceleration chip firmware differential upgrade package in an upgrade package storage unit, merge differential data in the upgrade package into a backup partition of a dual-partition firmware storage unit to update acceleration chip firmware in the backup partition to a target version when a trigger condition is met, and send partition state setting information and firmware loading partition information to the dual-partition firmware storage unit and an acceleration chip firmware controller respectively; and the acceleration chip firmware controller is configured to reload and execute acceleration chip firmware from a running partition after switching a partition state according to the received firmware loading partition information when a hot reset is performed. The present disclosure helps to improve the reliability and operation and maintenance efficiency of acceleration chip firmware update, and helps to reduce system downtime risk and manual intervention cost.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of firmware update technology, and in particular to an accelerator chip firmware update system, method, computing accelerator card, and artificial intelligence server. Background Technology

[0002] The underlying computational reasoning of artificial intelligence technology requires the support of a large number of computing devices. Dozens, hundreds, or even more AI servers need to work together to complete complex reasoning and computation tasks.

[0003] Accelerator chips, such as GPUs, are core computing components of AI servers. Their firmware, including VBIOS (VGA BIOS, Graphics Card Basic Input / Output System), GSP (GPU System Processor) firmware, and microcode, directly determines the computing performance, stability, and functional compatibility of the accelerator chip. With the continuous expansion of various application scenarios such as AI (Artificial Intelligence) inference, edge computing, and high-performance computing, firmware upgrades for accelerator chips to meet various needs, such as fixing vulnerabilities, optimizing performance, and adding functionality, are becoming increasingly frequent.

[0004] However, AI servers in a server cluster need to be continuously running, and firmware upgrades usually carry a high risk. If interference occurs during the upgrade process, it is very easy to cause the firmware upgrade to fail, resulting in the failure of the acceleration chip, thereby weakening the computational inference performance of the AI ​​server, or even causing the AI ​​server to lose its computational inference ability completely. Summary of the Invention

[0005] In view of this, this disclosure provides an accelerated chip firmware update system, method, computing accelerator card, and artificial intelligence server to help improve the reliability, security, and operational efficiency of firmware updates for accelerated chips, and reduce system downtime risks and manual intervention costs.

[0006] According to one aspect of the embodiments of this disclosure, a system for accelerating chip firmware updates is provided, comprising:

[0007] The upgrade package storage unit is located on the baseboard of the computing accelerator card in the artificial intelligence server;

[0008] A dual-partition firmware storage unit is disposed on the substrate, including a running partition and a backup partition. The running partition and the backup partition are used to store different versions of acceleration chip firmware respectively, and the partition status of the running partition and the backup partition is changed according to the received partition status setting information to switch the partition status of the running partition and the backup partition to each other.

[0009] An acceleration chip firmware controller, disposed in the acceleration chip on the computing accelerator card and coupled to the dual-partition firmware storage unit, is used to load and execute the acceleration chip firmware from the running partition to control the startup and operation of the acceleration chip, and to reload and execute the acceleration chip firmware from the running partition after the partition state is switched according to the received firmware loading partition information during hot reset; and,

[0010] A firmware update management unit, disposed on the substrate and coupled to the upgrade package storage unit, the dual-partition firmware storage unit, and the acceleration chip firmware controller, is used to receive acceleration chip firmware differential upgrade packages sent by the host and store them in the upgrade package storage unit. When the update trigger condition is met, the unit updates the differential data in the acceleration chip firmware differential upgrade package to the acceleration chip firmware in the backup partition, so that the acceleration chip firmware in the backup partition is updated to the target version. The unit also sends the partition status setting information and the firmware loading partition information to the dual-partition firmware storage unit and the acceleration chip firmware controller, respectively.

[0011] In one possible implementation, the update triggering condition includes:

[0012] The firmware update management unit receives at least one of the following: an upgrade command issued by the host, the time reaches a preset update trigger time, or the host enters a low-power state.

[0013] In one possible implementation, when the firmware update management unit detects that the PCIe link with the host is in L2 / L3 power management state, it determines that the host has entered a low-power state.

[0014] In one possible implementation, the firmware update management unit is further configured to verify the target version of the acceleration chip firmware in the backup partition after the acceleration chip firmware in the backup partition is updated to the target version and before sending the partition status setting information and the firmware loading partition information to the dual-partition firmware storage unit and the acceleration chip firmware controller, respectively.

[0015] If the verification is successful, the partition status setting information and the firmware loading partition information are sent to the dual-partition firmware storage unit and the acceleration chip firmware controller, respectively.

[0016] In the event of a verification failure, the target version of the acceleration chip firmware in the backup partition will be restored to the previous version of the acceleration chip firmware.

[0017] In one possible implementation, the accelerated chip firmware update system further includes:

[0018] A timed monitoring unit is installed on the substrate to time the process of updating the difference data to the backup partition, and generates a reset trigger signal when the time reaches a preset time threshold and the difference data has not been updated.

[0019] The firmware update management unit is coupled to the timing monitoring unit and is also used to stop the update of the differential data to the backup partition in response to the received reset trigger signal, and restore the unupdated acceleration chip firmware in the backup partition to the acceleration chip firmware before the update.

[0020] In one possible implementation, the firmware update management unit is further configured to perform integrity verification and signature verification on the acceleration chip firmware differential upgrade package after receiving the acceleration chip firmware differential upgrade package issued by the host and before storing it in the upgrade package storage unit, and store the acceleration chip firmware differential upgrade package in the upgrade package storage unit if the integrity verification and the signature verification are successful.

[0021] If either the integrity check or the signature check fails, the storage of the acceleration chip firmware differential upgrade package is rejected, and a check failure message is sent back to the host.

[0022] In one possible implementation, the acceleration chip firmware controller is further configured to send a startup failure signal to the firmware update management unit in the event that the acceleration chip fails to start.

[0023] The firmware update management unit is also configured to, in response to receiving the boot failure signal, send the partition status setting information to the dual-partition firmware storage unit again, so that the dual-partition firmware storage unit switches the partition status of the running partition and the backup partition to each other again, and send the firmware loading partition information to the acceleration chip firmware controller again, so that when the acceleration chip firmware controller performs a hot reset, it reloads and executes the acceleration chip firmware from the running partition after the partition status has been switched again.

[0024] In one possible implementation, the accelerated chip firmware update system further includes:

[0025] A power monitoring unit, disposed on the substrate, is used to monitor the power supply voltage of the computing accelerator card during the process of updating the differential data to the backup partition, and generate an interrupt signal when the power supply voltage drops to a preset power failure protection threshold.

[0026] The firmware update management unit is coupled to the power monitoring unit and is further configured to, in response to the received interrupt signal, suspend the update of the differential data to the backup partition, and immediately store the current update progress of the differential data, the checksum of the differential data written to the backup partition, and the breakpoint information of the partition status of the dual-partition firmware storage unit into the upgrade package storage unit. After power-on recovery, the breakpoint information is read from the upgrade package storage unit, and the acceleration chip firmware of the backup partition of the dual-partition firmware storage unit is restored to the version before the update based on the breakpoint information.

[0027] In one possible implementation, the firmware update management unit is further configured to send a firmware access pause command to the acceleration chip firmware controller to pause the acceleration chip firmware controller's access to the dual-partition firmware storage unit when the update trigger condition is met and before updating the difference data to the backup partition.

[0028] According to another aspect of the embodiments of this disclosure, a method for accelerating chip firmware updates is provided, including:

[0029] Receive and store the differential firmware upgrade package for the acceleration chip sent by the host;

[0030] When the update trigger condition is met, the difference data in the differential upgrade package of the acceleration chip firmware is updated to the acceleration chip firmware in the backup partition of the dual-partition firmware storage unit, so that the acceleration chip firmware in the backup partition is updated to the target version. The dual-partition firmware storage unit includes a running partition and the backup partition, and the running partition and the backup partition store different versions of acceleration chip firmware respectively.

[0031] Switch the partition states of the running partition and the backup partition to each other;

[0032] During a hot reset, the instruction acceleration chip firmware controller reloads and executes the acceleration chip firmware from the running partition after the partition state has been switched.

[0033] In one possible implementation, the update triggering condition includes:

[0034] The system receives at least one of the following: receiving an upgrade command from the host, the time reaches a preset update trigger time, or the host is detected to have entered a low-power state.

[0035] In one possible implementation, detecting that the host has entered a low-power state includes:

[0036] The PCIe link with the host was detected to be in L2 / L3 power management state.

[0037] In one possible implementation, after the acceleration chip firmware in the backup partition is updated to the target version, and before switching the partition states of the running partition and the backup partition and instructing the acceleration chip firmware controller to reload and execute the acceleration chip firmware from the running partition after the partition state switch during a hot reset, the acceleration chip firmware update method further includes:

[0038] Verify the target version of the acceleration chip firmware in the backup partition;

[0039] In the case of successful verification, the partition states of the running partition and the backup partition are switched to each other, and the instruction acceleration chip firmware controller reloads and executes the acceleration chip firmware from the running partition after the partition state is switched during hot reset.

[0040] In the event of a verification failure, the target version of the acceleration chip firmware in the backup partition will be restored to the previous version of the acceleration chip firmware.

[0041] In one possible implementation, the accelerated chip firmware update method further includes:

[0042] The process of updating the difference data to the backup partition is timed;

[0043] When the timer reaches a preset time threshold and the difference data has not been updated, the update of the difference data to the backup partition is stopped, and the unupdated acceleration chip firmware in the backup partition is restored to the acceleration chip firmware before the update.

[0044] In one possible implementation, after receiving the differential firmware upgrade package for the acceleration chip from the host, and before storing the differential firmware upgrade package for the acceleration chip, the acceleration chip firmware update method further includes:

[0045] The firmware differential upgrade package for the acceleration chip is subjected to integrity verification and signature verification.

[0046] If the integrity verification and the signature verification are successful, the acceleration chip firmware differential upgrade package is stored.

[0047] If either the integrity check or the signature check fails, the storage of the acceleration chip firmware differential upgrade package is rejected, and a check failure message is sent back to the host.

[0048] In one possible implementation, the accelerated chip firmware update method further includes:

[0049] In response to receiving a boot failure signal from the acceleration chip firmware controller, the partition status setting information is sent to the dual-partition firmware storage unit again, causing the dual-partition firmware storage unit to switch the partition status of the running partition and the backup partition to each other again. The firmware loading partition information is sent to the acceleration chip firmware controller again, so that when the acceleration chip firmware controller performs a hot reset, it reloads and executes the acceleration chip firmware from the running partition after the partition status has been switched again.

[0050] In one possible implementation, the accelerated chip firmware update method further includes:

[0051] The power supply voltage of the computing accelerator card is monitored during the process of updating the difference data to the backup partition;

[0052] When the power supply voltage drops to a preset power failure protection threshold, the update of the difference data to the backup partition is paused, and the current update progress containing the difference data, the verification value of the difference data written to the backup partition, and the breakpoint information of the partition status of the dual-partition firmware storage unit are immediately saved.

[0053] After power-on recovery, the saved breakpoint information is read, and the acceleration chip firmware of the backup partition of the dual-partition firmware storage unit is restored to the version before the update based on the breakpoint information.

[0054] In one possible implementation, the accelerated chip firmware update method further includes:

[0055] When the update trigger condition is met, and before updating the difference data to the backup partition, the acceleration chip firmware controller suspends access to the dual-partition firmware storage unit.

[0056] According to another aspect of the present disclosure, a computing accelerator card is provided, including the accelerator chip firmware update system as described in any of the preceding claims.

[0057] According to another aspect of the present disclosure, an artificial intelligence server is provided, including the accelerated chip firmware update system as described in any of the preceding claims.

[0058] As can be seen from the above scheme, the accelerated chip firmware update system, method, computing accelerator card, and artificial intelligence server disclosed herein use differential upgrade packages to upgrade the accelerated chip firmware. This reduces the size of the firmware transmitted from the host to the computing accelerator card, reduces the PCIe bus bandwidth usage between the host and the computing accelerator card, and improves firmware transmission efficiency. This helps improve the autonomy, security, efficiency, fault tolerance, and compatibility of the accelerated chip firmware update process, improves the reliability and operational efficiency of the accelerated chip firmware update, and helps reduce system downtime risks and manual intervention costs. Furthermore, compared to using a full accelerated chip firmware upgrade package (e.g., an upgrade package including all third-version accelerated chip firmware), this disclosure effectively reduces the bandwidth resources occupied by the transmission of the accelerated chip firmware upgrade package between the host and the computing accelerator card. This allows the host of the artificial intelligence server to improve data transmission efficiency due to the reduced bandwidth resources occupied during the transmission of the accelerated chip firmware upgrade package, such as improving the efficiency of distributing computing tasks to the computing accelerator card, thereby helping to improve the computational inference performance of the artificial intelligence server. When a cluster of artificial intelligence servers contains a large number of acceleration chips that require firmware upgrades, the improvement in the computational inference performance of the cluster will be more significant. Attached Figure Description

[0059] Figure 1 This is a schematic diagram illustrating a first embodiment of an accelerated chip firmware update system, according to an illustrative embodiment.

[0060] Figure 2 This is a schematic diagram of a second embodiment of an accelerated chip firmware update system, shown according to an illustrative embodiment.

[0061] Figure 3 This is a schematic diagram of a third embodiment of an accelerated chip firmware update system, shown according to an illustrative embodiment.

[0062] Figure 4 This is a schematic flowchart illustrating a first embodiment of a method for accelerating chip firmware updates, according to an illustrative embodiment.

[0063] Figure 5 This is a schematic diagram of the second process of an accelerated chip firmware update method according to an illustrative embodiment;

[0064] Figure 6 This is a schematic diagram illustrating the process of handling timeouts in differential data updates, based on an illustrative embodiment.

[0065] Figure 7 This is a schematic flowchart illustrating the verification process during the process of receiving and storing the differential upgrade package of the acceleration chip firmware, according to an illustrative embodiment.

[0066] Figure 8 This is a schematic diagram illustrating the power failure protection execution process according to an illustrative embodiment;

[0067] Figure 9 This is a schematic diagram illustrating the execution flow of a specific application scenario of the autonomous upgrade process according to an illustrative embodiment;

[0068] Figure 10 This is a schematic diagram illustrating partition switching of a dual-partition firmware storage unit according to an illustrative embodiment.

[0069] In the attached diagram, the component names represented by each number are as follows:

[0070] 1. Upgrade package storage unit,

[0071] 2. Dual-partition firmware storage unit,

[0072] 3. Accelerate chip firmware controller,

[0073] 4. Firmware update management unit,

[0074] 5. Timed monitoring unit,

[0075] 6. Power monitoring unit,

[0076] 10. Substrate. Detailed Implementation

[0077] To make the objectives, technical solutions, and advantages of this disclosure clearer, the following detailed description is provided with reference to the accompanying drawings and embodiments.

[0078] It should be noted that the terms "first," "second," etc., in the specification, claims, and drawings of this disclosure are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence.

[0079] As used in the specification and claims of this disclosure, “coupled (or connected)” may refer to any direct or indirect means of connection. For example, if a first device is coupled (or connected) to a second device, it should be interpreted as the first device being directly connected to the second device, or the first device being indirectly connected to the second device through other devices or some means of connection.

[0080] In related technologies, the firmware upgrade solution for acceleration chips in artificial intelligence servers mainly has the following problems.

[0081] First, firmware upgrades for accelerator chips rely heavily on the host computer, resulting in poor autonomy. In related technologies, the firmware upgrade process for accelerator chips depends entirely on the host computer's involvement. Upgrades cannot be performed when the host is in hibernation, low-power mode, or experiencing a malfunction. Furthermore, if the host experiences a power outage, restart, or abnormal exit during the upgrade process, the firmware is highly susceptible to corruption, rendering the accelerator chip unusable and difficult to recover. The host computer refers to the management device within an AI server that hosts and manages the computing accelerator cards (including accelerator chips), typically composed of a CPU (Central Processing Unit), memory, storage, and a motherboard.

[0082] Secondly, upgrades are high-risk and lack an effective rollback mechanism. Most related technologies employ a single firmware storage area design, directly overwriting the currently running firmware during upgrades. If firmware verification fails, write errors occur, or startup fails, manual restoration via specialized equipment is required, resulting in extremely high maintenance costs.

[0083] Third, the upgrade process is inefficient and time-consuming. The firmware of the accelerator chip is relatively large, typically ranging from 8 to 64 MB (megabytes). Downloading and writing it takes a long time and consumes a significant amount of PCIe (Peripheral Component Interconnect Express) bus bandwidth between the host and the computing accelerator card, affecting the execution of normal host services.

[0084] Fourth, it lacks power-loss protection and has poor fault tolerance. If a sudden power outage occurs during the firmware upgrade process of related technologies, data corruption may occur in the firmware storage area, causing the acceleration chip to fail to start.

[0085] In view of this, the present disclosure provides an acceleration chip firmware update system, method, computing accelerator card, and artificial intelligence server. It employs differential upgrade packages for acceleration chip firmware to upgrade the acceleration chip firmware, thereby reducing the size of the firmware transmitted from the host to the computing accelerator card, minimizing the PCIe bus bandwidth usage between the host and the computing accelerator card, and improving firmware transmission efficiency. This helps improve the autonomy, security, efficiency, fault tolerance, and compatibility of the acceleration chip firmware update process, thereby enhancing the reliability and operational efficiency of the acceleration chip firmware update, and reducing system downtime risks and manual intervention costs.

[0086] Figure 1 This is a schematic diagram illustrating a first embodiment of an accelerated chip firmware update system, according to an illustrative embodiment. (See diagram below.) Figure 1As shown, the accelerator chip firmware update system of this embodiment mainly includes an upgrade package storage unit 1, a dual-partition firmware storage unit 2, an accelerator chip firmware controller 3, and a firmware update management unit 4. The upgrade package storage unit 1 is disposed on the substrate 10 of the computing accelerator card in the artificial intelligence server. The dual-partition firmware storage unit 2 is disposed on the substrate 10 and includes a running partition and a backup partition. The running partition and the backup partition are used to store different versions of the accelerator chip firmware respectively, and the partition states of the running partition and the backup partition are changed according to the received partition state setting information to switch the partition states of the running partition and the backup partition to each other. The accelerator chip firmware controller 3 is disposed in the accelerator chip on the computing accelerator card and coupled to the dual-partition firmware storage unit 2. The accelerator chip firmware controller 3 is used to load and execute the accelerator chip firmware from the running partition to control the startup and operation of the accelerator chip, and during hot reset, it reloads and executes the accelerator chip firmware from the running partition after the partition state is switched according to the received firmware loading partition information. The firmware update management unit 4 is mounted on the substrate 10 and coupled to the upgrade package storage unit 1, the dual-partition firmware storage unit 2, and the acceleration chip firmware controller 3. The firmware update management unit 4 is used to receive the acceleration chip firmware differential upgrade package sent by the host and store it in the upgrade package storage unit 1. When the update trigger condition is met, the differential data in the acceleration chip firmware differential upgrade package is updated to the acceleration chip firmware in the backup partition, so that the acceleration chip firmware in the backup partition is updated to the target version. The unit 4 also sends partition status setting information and firmware loading partition information to the dual-partition firmware storage unit 2 and the acceleration chip firmware controller 3, respectively. That is, it sends partition status setting information to the dual-partition firmware storage unit 2 and firmware loading partition information to the acceleration chip firmware controller 3.

[0087] Among them, the accelerator chip firmware differential upgrade package refers to an upgrade package that only contains the difference data between the old and new versions of the accelerator chip firmware, and is not the complete accelerator chip firmware.

[0088] In an illustrative embodiment, the running partition and the backup partition are used to store different versions of the acceleration chip firmware, for example, the running partition stores the first version of the acceleration chip firmware and the backup partition stores the second version of the acceleration chip firmware. Based on this, the partition storing the first version of the acceleration chip firmware is named partition A (i.e., the current running partition), and the partition storing the second version of the acceleration chip firmware is named partition B (i.e., the current backup partition).

[0089] In an illustrative embodiment, the firmware update management unit 4 updates the difference data in the differential upgrade package of the acceleration chip firmware to the acceleration chip firmware in the backup partition, so that the acceleration chip firmware in the backup partition is updated to the target version. For example, the firmware update management unit 4 updates the difference data in the differential upgrade package of the acceleration chip firmware to the second version of the acceleration chip firmware in partition B (backup partition), so that the second version of the acceleration chip firmware is updated to the target version, that is, the target version of the acceleration chip firmware. The target version of the acceleration chip firmware can also be called the third version of the acceleration chip firmware. Therefore, the acceleration chip firmware in partition B (backup partition) is updated to the third version.

[0090] In an illustrative embodiment, the dual-partition firmware storage unit 2 changes the partition status of the running partition and the backup partition according to the received partition status setting information. For example, the dual-partition firmware storage unit 2 switches partition A, which stores the first version of the acceleration chip firmware, from the running partition to the backup partition, and switches partition B, which stores the third version of the acceleration chip firmware, from the backup partition to the running partition according to the received partition status setting information.

[0091] In an illustrative embodiment, firmware loading partition information is used to indicate the partition where the accelerator chip loads firmware. Since the design specifies that firmware needs to be loaded from the running partition, the firmware loading partition information indicates the running partition. For example, if the running partition is partition A, the firmware loading partition information indicates partition A; if the running partition is partition B, the firmware loading partition information indicates partition B. During a hot reset, the accelerator chip firmware controller 3 reloads and executes the accelerator chip firmware from the running partition after the partition state switch, based on the received firmware loading partition information. For example, during a hot reset, the accelerator chip firmware controller 3 reloads and executes the accelerator chip firmware (i.e., the third version of the accelerator chip firmware) from partition B (which is now the running partition) storing the third version of the accelerator chip firmware, based on the received firmware loading partition information. Thus, the accelerator chip firmware controller 3 is updated from executing the first version of the accelerator chip firmware to executing the third version of the accelerator chip firmware.

[0092] The differential upgrade package for accelerator chip firmware contains difference data between the target version of the accelerator chip firmware (e.g., the third version of the accelerator chip firmware) and the upgraded version of the accelerator chip firmware (e.g., the second version of the accelerator chip firmware).

[0093] The accelerator chip firmware update system of this disclosure adopts a differential upgrade package approach. Compared to using a full accelerator chip firmware upgrade package (e.g., an upgrade package including all third-version accelerator chip firmware), this effectively reduces the bandwidth resources occupied by the transmission of the accelerator chip firmware upgrade package between the host and the computing accelerator card. This allows the AI ​​server host to improve data transmission efficiency due to the reduced bandwidth usage during the transmission of the accelerator chip firmware upgrade package, for example, improving the efficiency of distributing computing tasks to the computing accelerator card, thereby contributing to the improvement of the AI ​​server's computing inference performance. When a cluster of numerous AI servers contains a large number of accelerator chips that require firmware upgrades, the improvement effect of the accelerator chip firmware update system of this disclosure on the cluster's computing inference performance will be even more significant.

[0094] In the illustrative embodiment, the update triggering conditions include at least one of the following: the firmware update management unit 4 receiving an upgrade command from the host, the time reaching a preset update trigger time, and the host entering a low-power state. In this illustrative embodiment, to minimize the impact on the computational inference performance of the AI ​​server, the update trigger time is preferably during a period with fewer computational inference tasks and lower workload for the AI ​​server. For example, the update trigger time can be set at night or in the early morning, and can be set based on experience; for example, the update trigger time can be set at 2 AM. Furthermore, the host entering a low-power state indicates that the AI ​​server is currently in a relatively idle period. Updating the acceleration chip firmware during this period will not excessively affect the computational inference efficiency of the AI ​​server and ensures the normal performance of the AI ​​server during busy times.

[0095] In the illustrative embodiment, the host and the computing accelerator card are coupled and communicate via a PCIe bus. Therefore, determining whether the host has entered a low-power state can be achieved by monitoring the PCIe bus signals. Accordingly, in the illustrative embodiment, when the firmware update management unit 4 detects that the PCIe link with the host is in an L2 / L3 power management state, it determines that the host has entered a low-power state. The PCIe link power management state is a power-saving mechanism defined in the PCIe specification for the link layer. L2 is the deepest low-power state of the PCIe link, and L3 is the PCIe link off state.

[0096] To ensure the correctness of the target version of the acceleration chip firmware and prevent problems caused by errors in the target version of the acceleration chip firmware controller 3, which could lead to accelerator chip malfunction, in this illustrative embodiment, the firmware update management unit 4 is further configured to verify the target version of the acceleration chip firmware in the backup partition after updating the acceleration chip firmware in the backup partition to the target version, and before sending partition status setting information and firmware loading partition information to the dual-partition firmware storage unit 2 and the acceleration chip firmware controller 3, respectively. Specifically, if the verification is successful, the firmware update management unit 4 sends the partition status setting information and firmware loading partition information to the dual-partition firmware storage unit 2 and the acceleration chip firmware controller 3, respectively; if the verification fails, the firmware update management unit 4 restores the target version of the acceleration chip firmware in the backup partition to the firmware before the update.

[0097] In an illustrative embodiment, a hash check can be used to verify the target version of the acceleration chip firmware. For example, the acceleration chip firmware differential upgrade package contains a hash value of the target version of the acceleration chip firmware (e.g., obtained by the host side using SHA-256 or MD5 hash algorithms). The firmware update management unit 4 calculates the hash value of the target version of the acceleration chip firmware in the backup partition using the same hash algorithm as the host (e.g., if the host uses the SHA-256 hash algorithm, then the firmware update management unit 4 also uses the SHA-256 hash algorithm). The calculated hash value is then compared with the hash value in the acceleration chip firmware differential upgrade package. If they match, the verification is successful; otherwise, the verification fails.

[0098] Figure 2 This is a schematic diagram illustrating a second embodiment of an accelerated chip firmware update system, based on an illustrative embodiment. The process of updating differential data to the backup partition may take too long or stall due to various reasons. To ensure a smooth firmware update and avoid disruption to the normal operation of the AI ​​server caused by interruptions, such as... Figure 2 As shown in the illustrative embodiment, the accelerated chip firmware update system may further include a timing monitoring unit 5. The timing monitoring unit 5 is disposed on the substrate 10 and is used to time the process of updating differential data to the backup partition. When the time reaches a preset time threshold and the differential data has not been updated, a reset trigger signal is generated. The firmware update management unit 4 is coupled to the timing monitoring unit 5. The firmware update management unit 4 is also used to, in response to the received reset trigger signal, stop the update of differential data to the backup partition and restore the incompletely updated accelerated chip firmware in the backup partition to the accelerated chip firmware before the update.

[0099] The coordinated operation of the timing monitoring unit 5 and the firmware update management unit 4 enables rollback recovery in the accelerator chip firmware upgrade process (updating differential data to the backup partition) due to timeout. During the process of restoring the incompletely updated accelerator chip firmware in the backup partition to the firmware before the update, the firmware update management unit 4 can reverse the update process up to the moment the timer reaches a preset time threshold, thus restoring the incompletely updated accelerator chip firmware to the firmware before the update.

[0100] In an illustrative embodiment, the timing monitoring unit 5 may be, for example, a hardware watchdog circuit. In this illustrative embodiment, the time threshold can be set as needed, for example, at any time point between 5 and 20 seconds, such as 10 seconds.

[0101] Furthermore, there is a possibility that although the differential upgrade package for the accelerator chip firmware sent by the sending end (such as the host) is correct, the differential upgrade package received by the receiving end (such as the firmware update management unit 4) may be erroneous due to signal offset or other reasons. An erroneous differential upgrade package will highly likely lead to errors in the final updated target version of the accelerator chip firmware, thereby causing the accelerator chip to malfunction. To avoid this situation and ensure the correctness of the differential upgrade package received by the firmware update management unit 4, in the illustrative embodiment, the firmware update management unit 4 is further configured to perform integrity verification and signature verification on the differential upgrade package after receiving it from the host and before storing it in the upgrade package storage unit 1. If the integrity verification and signature verification are successful, the differential upgrade package is stored in the upgrade package storage unit 1; if either the integrity verification or the signature verification fails, the storage of the differential upgrade package is rejected, and verification failure information is sent back to the host.

[0102] In an illustrative embodiment, integrity verification can be implemented using a redundancy check method. The differential upgrade package of the accelerator chip firmware carries a redundancy check code, such as CRC32. The firmware update management unit 4 uses the redundancy check code and a pre-agreed polynomial identical to the polynomial used to generate the redundancy check code on the host side to perform a modulo-2 division operation to determine whether the differential upgrade package of the accelerator chip firmware is complete. If the differential upgrade package of the accelerator chip firmware is complete, the integrity verification is successful; otherwise, the integrity verification fails.

[0103] In an illustrative embodiment, signature verification can be implemented using the RSA public-key encryption algorithm. The RSA signature is carried in the differential upgrade package of the accelerator chip firmware. The firmware update management unit 4 uses the stored public key to decrypt the RSA signature to obtain a first signature verification hash value. The firmware update management unit 4 performs a hash calculation (e.g., using the SHA-256 hash algorithm) on the payload (e.g., difference data) in the differential upgrade package of the accelerator chip firmware to obtain a second signature verification hash value. The first and second signature verification hash values ​​are compared; if they match, the signature verification is successful; otherwise, the signature verification fails.

[0104] In the illustrative embodiment, there may also be situations where the acceleration chip fails to boot due to reasons such as poor compatibility between the target version of the acceleration chip firmware and the acceleration chip. In such cases, a corresponding rollback operation is required to restore to the original version of the acceleration chip firmware (e.g., the first version of the acceleration chip firmware mentioned above). Based on this, in the illustrative embodiment, the acceleration chip firmware controller 3 is also used to send a boot failure signal to the firmware update management unit 4 in the event of an acceleration chip boot failure. The firmware update management unit 4 is also used to, in response to receiving the boot failure signal, send partition status setting information to the dual-partition firmware storage unit 2 again, causing the dual-partition firmware storage unit 2 to switch the partition status of the running partition and the backup partition to each other again, and send firmware loading partition information to the acceleration chip firmware controller 3 again, so that when the acceleration chip firmware controller 3 performs a hot reset, it reloads and executes the acceleration chip firmware from the running partition after the partition status has been switched again.

[0105] For example, if the accelerator chip firmware controller 3 fails to boot based on the third version of the accelerator chip firmware (located in partition B, currently the running partition), the accelerator chip firmware controller 3 sends a boot failure signal to the firmware update management unit 4. Upon receiving the boot failure signal, the firmware update management unit 4 sends partition status setting information to the dual-partition firmware storage unit 2 again, causing the dual-partition firmware storage unit 2 to switch the partition states of the running partition and the backup partition again. That is, partition B is switched from the running partition to the backup partition, and partition A (which stores the first version of the accelerator chip firmware) is switched from the backup partition to the running partition. The unit then sends firmware loading partition information (indicating partition A is the running partition) to the accelerator chip firmware controller 3 again. When the accelerator chip firmware controller 3 performs a hot reset, it reloads and executes the first version of the accelerator chip firmware from the running partition (partition A) after the partition state has been switched again. This achieves the rollback to the original version of the accelerator chip firmware in the event of a boot failure.

[0106] Figure 3This is a schematic diagram of a third embodiment of an accelerator chip firmware update system, shown in an illustrative embodiment. The power supply state also has a significant impact on the accelerator chip firmware update process. To avoid update failure due to sudden power outages during the firmware update process, which could damage the accelerator chip firmware and cause accelerator chip malfunction, the following measures are taken to avoid these negative impacts: Figure 3 As shown in the illustrative embodiment, the accelerator chip firmware update system of this disclosure may further include a power monitoring unit 6. The power monitoring unit 6 is disposed on the substrate 10 and is used to monitor the power supply voltage of the computing accelerator card during the process of updating differential data to the backup partition, and generate an interrupt signal when the power supply voltage drops to a preset power-down protection threshold. Based on this, the firmware update management unit 4 is coupled to the power monitoring unit 6 and is also used to respond to the received interrupt signal, suspend the update of differential data to the backup partition, and immediately store the current update progress of differential data, the check value of differential data written to the backup partition, and the breakpoint information of the partition status of the dual-partition firmware storage unit 2 into the upgrade package storage unit 1. After power-on recovery, the breakpoint information is read from the upgrade package storage unit 1, and the acceleration chip firmware of the backup partition of the dual-partition firmware storage unit 2 is restored to the version before the update based on the breakpoint information. For example, if the update fails, the breakpoint information is read directly after power-on recovery, and the acceleration chip firmware is restored to the version before the update based on the breakpoint information and the current version of the acceleration chip firmware, and the acceleration chip firmware of the previous version is updated to the backup partition of the dual-partition firmware storage unit 2 again.

[0107] In this illustrative embodiment, assuming the power supply voltage of the computing accelerator card is 12V, the power failure protection threshold can be set to 10.5V. Therefore, when the power monitoring unit 6 detects that the power supply voltage of the computing accelerator card has dropped to 10.5V during the process of updating differential data to the backup partition, it generates an interrupt signal.

[0108] To ensure the smooth execution of the differential data update process to the backup partition and to prevent unpredictable impacts from the accelerator chip firmware controller 3's access to the dual-partition firmware storage unit 2 on the differential data update process, in the illustrative embodiment, the firmware update management unit 4 is further configured to send a firmware access pause command to the accelerator chip firmware controller 3 to pause the accelerator chip firmware controller 3's access to the dual-partition firmware storage unit 2 when the update trigger condition is met and before updating the differential data to the backup partition. Based on this, although the accelerator chip firmware controller 3's access to the dual-partition firmware storage unit 2 is restricted during the differential data update process to the backup partition, it does not completely affect the operation of the accelerator chip's core, ensuring the normal implementation of the accelerator chip's core functions such as computation and inference, and also avoiding the impact of the update process on the accelerator chip's core functions.

[0109] In this illustrative embodiment, the firmware update management unit 4 is an MCU (Microcontroller Unit). In this illustrative embodiment, the firmware update management unit 4 is connected to the host via the PCIe bus and receives the acceleration chip firmware differential upgrade package. In this illustrative embodiment, the firmware update management unit 4 connects to the host via I... 2 The C (Inter-Integrated Circuit) bus or SPI (Serial Peripheral Interface) bus is coupled to the dual-partition firmware storage unit 2 and the acceleration chip firmware controller 3. In an illustrative embodiment, the acceleration chip firmware controller 3 is coupled to the dual-partition firmware storage unit 2 via the SPI bus. In an illustrative embodiment, the acceleration chip firmware differential upgrade package includes difference data, the version number of the target version, the checksum of the complete acceleration chip firmware of the target version, and the signature value used for signature verification.

[0110] In the illustrative embodiment, the difference data refers to the difference between the target version of the acceleration chip firmware (e.g., the third version of the acceleration chip firmware) and the acceleration chip firmware in the backup partition (partition B) (e.g., the second version of the acceleration chip firmware). This is because, before the acceleration chip firmware update, the firmware running on the acceleration chip is the acceleration chip firmware in the running partition (partition A) (e.g., the first version of the acceleration chip firmware). Furthermore, firstly, the acceleration chip firmware in the running partition (partition A) (e.g., the first version of the acceleration chip firmware) is the currently loaded and running firmware and cannot be modified; secondly, the acceleration chip firmware in the running partition (partition A) (e.g., the first version of the acceleration chip firmware) will serve as a backup of the target version of the acceleration chip firmware obtained after the firmware update is completed, ensuring that in the event of a subsequent boot failure, it can be rolled back to the first version of the acceleration chip firmware for reloading and running. Therefore, the difference data is not the difference between the target version of the acceleration chip firmware (e.g., the third version of the acceleration chip firmware) and the acceleration chip firmware in the running partition (partition A) (e.g., the first version of the acceleration chip firmware).

[0111] In an illustrative embodiment, the difference data is obtained on the host side using a differential algorithm based on the target version of the acceleration chip firmware (e.g., the third version of the acceleration chip firmware) and the acceleration chip firmware in the backup partition (B partition) (e.g., the second version of the acceleration chip firmware). Correspondingly, during the process of the firmware update management unit 4 updating the acceleration chip firmware in the backup partition to the target version using the difference data in the acceleration chip firmware differential upgrade package, the acceleration chip firmware in the backup partition can be updated using a synthesis algorithm corresponding to the differential algorithm. In an illustrative embodiment, the differential algorithm can be the BSDiff algorithm or the HDiff algorithm, and correspondingly, the synthesis algorithm can be the BSPatch algorithm or the HPatchz algorithm.

[0112] This disclosure also provides a method for accelerating chip firmware updates. Figure 4 This is a schematic flowchart illustrating a first embodiment of a method for accelerating chip firmware updates, as shown in an illustrative example. Figure 4 As shown in the illustrative embodiment, the accelerated chip firmware update method mainly includes the following steps 401 to 404.

[0113] Step 401: Receive and store the differential upgrade package for the acceleration chip firmware sent by the host.

[0114] Step 402: When the update trigger condition is met, update the difference data in the differential upgrade package of the acceleration chip firmware to the acceleration chip firmware in the backup partition of the dual-partition firmware storage unit, so that the acceleration chip firmware in the backup partition is updated to the target version.

[0115] The dual-partition firmware storage unit includes a running partition and a backup partition, which store different versions of the acceleration chip firmware.

[0116] Step 403: Switch the partition status of the running partition and the backup partition to each other.

[0117] Step 404: During a hot reset, the instruction acceleration chip firmware controller reloads and executes the acceleration chip firmware from the running partition after the partition state is switched.

[0118] In conjunction with the above embodiments of the accelerated chip firmware update system, step 401 may specifically include: the firmware update management unit receiving the accelerated chip firmware differential upgrade package issued by the host and storing it in the upgrade package storage unit.

[0119] In conjunction with the above-described embodiment of the accelerated chip firmware update system, step 402 may specifically include: when the update triggering condition is met, the firmware update management unit updates the difference data in the accelerated chip firmware differential upgrade package to the accelerated chip firmware in the backup partition of the dual-partition firmware storage unit, so that the accelerated chip firmware in the backup partition is updated to the target version.

[0120] In conjunction with the accelerated chip firmware update system of the above embodiments, steps 403 and 404 may specifically include: the firmware update management unit sending partition status setting information and firmware loading partition information to the dual-partition firmware storage unit and the accelerated chip firmware controller, respectively; the dual-partition firmware storage unit switching the partition status of the running partition and the backup partition to each other according to the received partition status setting information; and the accelerated chip firmware controller reloading and executing the accelerated chip firmware from the running partition after the partition status is switched according to the received firmware loading partition information during hot reset.

[0121] In an illustrative embodiment, the update triggering conditions include at least one of the following: receiving an upgrade command from the host, the time reaching a preset update trigger time, and detecting that the host has entered a low-power state.

[0122] In an illustrative embodiment, detecting that the host has entered a low-power state includes detecting that the PCIe link between the host and the host is in an L2 / L3 power management state.

[0123] Figure 5 This is a schematic diagram of the second process of an accelerated chip firmware update method according to an illustrative embodiment, as shown below. Figure 5As shown in the illustrative embodiment, after the acceleration chip firmware in the backup partition is updated to the target version, and before the partition states of the running partition and the backup partition are switched to each other and the acceleration chip firmware controller is instructed to reload and execute the acceleration chip firmware from the running partition after the partition state is switched during a hot reset, that is, after step 402 and before steps 403 and 404, the acceleration chip firmware update method of this disclosure embodiment may further include the following verification step 501.

[0124] Step 501: Verify the target version of the acceleration chip firmware in the backup partition.

[0125] If the verification is successful, steps 402 and 403 are executed, which involves switching the partition states of the running partition and the backup partition, and the instruction acceleration chip firmware controller reloading and executing the acceleration chip firmware from the running partition after the partition state switch during a hot reset. If the verification fails, step 502 is executed.

[0126] Step 502: Restore the target version of the acceleration chip firmware in the backup partition to the acceleration chip firmware before the update.

[0127] Figure 6 This is a schematic diagram illustrating the process of handling timeouts in differential data updates, based on an illustrative embodiment. Figure 6 As shown in the illustrative embodiment, the accelerated chip firmware update method of this disclosure may further include the following difference data update timeout processing flow in steps 601 to 602.

[0128] Step 601: Timing the process of updating the difference data to the backup partition.

[0129] Step 602: When the timer reaches the preset time threshold and the difference data has not been updated, stop the update of the difference data to the backup partition, and restore the unupdated acceleration chip firmware in the backup partition to the acceleration chip firmware before the update.

[0130] In the accelerated chip firmware update system of the above embodiments, step 601 is implemented by a timed monitoring unit.

[0131] In conjunction with the acceleration chip firmware update system of the above embodiments, step 602 may specifically include: when the timing reaches a preset time threshold and the difference data has not been updated, the timing monitoring unit generates a reset trigger signal; in response to the received reset trigger signal, the firmware update management unit stops the update of the difference data to the backup partition and restores the acceleration chip firmware in the backup partition that has not been updated to the acceleration chip firmware before the update.

[0132] Figure 7This is a schematic flowchart illustrating the verification process during the receipt and storage of the accelerator chip firmware differential upgrade package, according to an illustrative embodiment. Figure 7 As shown in the illustrative embodiment, during the execution of step 401, after receiving the differential upgrade package for the acceleration chip firmware issued by the host and before storing the differential upgrade package for the acceleration chip firmware, the acceleration chip firmware update method of this disclosure embodiment may further include the following steps 701 to 703.

[0133] Step 701: Perform integrity verification and signature verification on the accelerated chip firmware differential upgrade package.

[0134] Step 702: If the integrity verification and signature verification are successful, store the differential upgrade package for the acceleration chip firmware.

[0135] Step 703: If either the integrity verification or the signature verification fails, refuse to store the accelerated chip firmware differential upgrade package and send a verification failure message back to the host.

[0136] In an illustrative embodiment, after completing step 404, the accelerator chip firmware update method of this disclosure may further include the following steps: in response to receiving a boot failure signal from the accelerator chip firmware controller, sending partition status setting information to the dual-partition firmware storage unit again to cause the dual-partition firmware storage unit to switch the partition states of the running partition and the backup partition to each other again, and sending firmware loading partition information to the accelerator chip firmware controller again so that when the accelerator chip firmware controller performs a hot reset, it reloads and executes the accelerator chip firmware from the running partition after the partition state has been switched again. Wherein, in the case of accelerator chip boot failure, the accelerator chip firmware controller generates a boot failure signal.

[0137] Figure 8 This is a schematic diagram illustrating the power outage protection execution process according to an illustrative embodiment, such as... Figure 8 As shown in the illustrative embodiment, the accelerated chip firmware update method of this disclosure may further include the following steps 801 to 803.

[0138] Step 801: Monitor the power supply voltage of the computing accelerator card during the process of updating the difference data to the backup partition.

[0139] Step 802: When the power supply voltage drops to the preset power failure protection threshold, pause the update of differential data to the backup partition, and immediately save the current update progress containing differential data, the check value of differential data written to the backup partition, and the breakpoint information of the partition status of the dual-partition firmware storage unit.

[0140] Step 803: After power-on recovery, read the saved breakpoint information and restore the acceleration chip firmware of the backup partition of the dual-partition firmware storage unit to the version before the update based on the breakpoint information.

[0141] In the accelerated chip firmware update system of the above embodiments, step 801 can be implemented by the power monitoring unit.

[0142] In conjunction with the accelerated chip firmware update system of the above embodiments, step 802 may specifically include: when the power supply voltage drops to a preset power failure protection threshold, the power monitoring unit generates an interrupt signal; in response to the received interrupt signal, the firmware update management unit suspends the update of differential data to the backup partition, and immediately stores the current update progress containing differential data, the verification value of differential data written to the backup partition, and the breakpoint information of the partition status of the dual-partition firmware storage unit into the upgrade package storage unit.

[0143] In conjunction with the acceleration chip firmware update system of the above embodiments, step 803 may specifically include: after power-on recovery, the firmware update management unit reads the breakpoint information from the upgrade package storage unit, and restores the acceleration chip firmware of the backup partition of the dual-partition firmware storage unit to the version before the update based on the breakpoint information.

[0144] In an illustrative embodiment, the accelerated chip firmware update method of this disclosure may further include: when the update triggering condition is met, and before updating the difference data to the backup partition, suspending the accelerated chip firmware controller's access to the dual-partition firmware storage unit.

[0145] In the accelerated chip firmware update system of the above embodiments, suspending the accelerated chip firmware controller's access to the dual-partition firmware storage unit can be achieved by the firmware update management unit sending a firmware access suspension command to the accelerated chip firmware controller.

[0146] In application scenarios of the accelerated chip firmware update system and method based on embodiments of this disclosure, the firmware update management unit can be an onboard low-power MCU, which is the core control unit of the accelerated chip firmware update system. The model can be STM32L4 or RP2040 (power consumption <10mA), with a built-in upgrade engine and rollback logic. The communication interface with the host is, for example, a PCIe interface (version 4.0 or 5.0). The accelerated chip firmware controller can be built into the accelerated chip; it is the runtime carrier of the accelerated chip firmware and can receive relevant instructions and information (such as firmware loading partition information) from the firmware update management unit (MCU). The dual-partition firmware storage unit can be a dual-partition flash memory, divided into two partitions, partition A and partition B. Partition A and partition B are respectively set as the running partition and backup partition according to the partition status setting information of the firmware update management unit (MCU). Because the firmware update management unit, the accelerator chip firmware controller, and the dual-partition firmware storage unit are responsible for firmware upgrades beyond the accelerator chip's main function (inference computing), if the data transmission channel (e.g., the PCIe channel) required for the accelerator chip to achieve its main function is called the main band channel, then the firmware update management unit is connected to the accelerator chip firmware controller and the dual-partition firmware storage unit via I / O. 2 The C / SPI bus can be referred to as the sideband control channel. The upgrade package storage unit can use NVRAM (Non-Volatile Random Access Memory), which can store the relevant data in the above embodiments, as well as logs, failure information, etc. generated during the upgrade process. Using NVRAM can ensure that the information is not lost when power is off.

[0147] In the application scenarios of the accelerated chip firmware update system and method based on the embodiments of this disclosure, the control of the entire process is mainly achieved through the software (firmware) architecture built into the MCU.

[0148] The MCU's built-in software can adopt a layered design, including an application layer, an algorithm layer, a hardware abstraction layer, and a storage layer. The application layer mainly includes an autonomous upgrade engine (including differential processing, partition management, state machine control, etc.) and a rollback engine (including anomaly detection, partition switching, breakpoint repair, etc.). The algorithm layer mainly includes synthesis algorithms, hash verification algorithms, and signature verification algorithms corresponding to the differential algorithms on the host side. The hardware abstraction layer mainly includes flash memory drivers, I / O... 2The C / SPI bus driver, power monitoring driver, timing monitoring unit driver (watchdog driver), and power monitoring unit interrupt driver, etc., are included. In the illustrative embodiment, the power monitoring unit triggers an MCU interrupt through GPIO (General-Purpose Input / Output), so the power monitoring unit interrupt driver is a GPIO driver. The storage layer mainly includes an upgrade log management module, a breakpoint storage module, and a checksum management module. In this embodiment, autonomy refers to independent execution detached from the host.

[0149] The application scenarios of the accelerated chip firmware update system and method based on the embodiments of this disclosure mainly include the following four stages.

[0150] Phase 1: Preparation Phase.

[0151] The preparation phase mainly includes the generation of the accelerator chip firmware differential upgrade package on the host side and the storage of the accelerator chip firmware differential upgrade package in the upgrade package storage unit, including:

[0152] Step 11: The host compares the acceleration chip firmware (second version) in the backup partition of the dual-partition firmware storage unit in the accelerator card with the target version of the acceleration chip firmware. Based on the acceleration chip firmware in the backup partition and the target version of the acceleration chip firmware, a differential algorithm is used to obtain the difference data between the target version of the acceleration chip firmware and the acceleration chip firmware in the backup partition, and an acceleration chip firmware differential upgrade package containing the difference data is generated. The acceleration chip firmware differential upgrade package also includes the version number of the target version, the check value of the complete acceleration chip firmware of the target version (e.g., SHA-256 check value), and the signature value used for signature verification (e.g., RSA signature).

[0153] Step 12: The firmware update management unit receives the acceleration chip firmware differential upgrade package sent by the host through the PCIe interface;

[0154] Step 13: The firmware update management unit uses the check value to verify the integrity of the differential upgrade package for the accelerator chip firmware and verifies the signature to ensure that the source of the differential upgrade package for the accelerator chip firmware is legitimate.

[0155] Step 14: After verification, the firmware update management unit will store the accelerated chip firmware differential upgrade package to the upgrade package storage unit.

[0156] Step 15: After successful verification, the firmware update management unit simultaneously reads the current status of the dual-partition firmware storage unit (including the version of the acceleration chip firmware stored in each of the A and B partitions, as well as the respective status of the A and B partitions, using the Active (indicating running status) and backup (indicating backup status) flags recorded in the dual-partition firmware storage unit to characterize the status of the A and B partitions), and replies to the host with the "ready" message, indicating that the preparations for autonomous update have been completed and autonomous update can be performed.

[0157] Step 16: After verification fails, the firmware update management unit refuses to store the acceleration chip firmware differential upgrade package to the upgrade package storage unit and reports the verification failure information to the host.

[0158] Phase Two: Autonomous Renewal Phase.

[0159] This is the core execution phase of the accelerated chip firmware update process, which requires execution to be triggered in response to the fulfillment of preset upgrade trigger conditions. Trigger conditions include at least one of the following: receiving an upgrade command from the host, the time reaching a preset update trigger moment (e.g., 2 AM daily), or detecting that the host has entered a low-power state (PCIe link is in L2 / L3 power state). This phase mainly includes:

[0160] Step 21: The firmware update management unit sends a firmware access pause command to the accelerator chip firmware controller. After receiving the firmware access pause command, the accelerator chip firmware controller pauses access to the dual-partition firmware storage unit (without shutting down the computing function of the accelerator chip, without affecting the computing data and core computing power), and locks the dual-partition firmware storage unit resources to prevent the firmware update process in the dual-partition firmware storage unit from being interfered with by the access of the accelerator chip.

[0161] Step 22: The firmware update management unit reads the differential upgrade package of the acceleration chip firmware in the upgrade package storage unit, calls the synthesis algorithm, and synthesizes the difference data in the differential upgrade package of the acceleration chip firmware into the acceleration chip firmware in the backup partition of the dual-partition firmware storage unit.

[0162] Step 23: The firmware update management unit performs verification on the complete accelerator chip firmware (the version at this time is the target version) in the backup partition. For example, it uses the SHA-256 hash algorithm to obtain the verification value of the complete accelerator chip firmware in the backup partition and compares it with the verification value of the complete accelerator chip firmware of the target version in the accelerator chip firmware differential upgrade package to ensure that the synthesized target version of the accelerator chip firmware is error-free. If the comparison is consistent, the verification is successful; otherwise, the verification fails.

[0163] Step 24: After successful verification, the firmware update management unit sends partition status setting information to the dual-partition firmware storage unit to switch between the running partition and the backup partition. That is, the running partition is switched to the backup partition and the backup partition is switched to the running partition. Thus, the backup partition where the target version of the acceleration chip firmware is located is changed to the running partition. At the same time, the firmware update management unit sends firmware loading partition information to the acceleration chip firmware controller to indicate the partition (i.e., the running partition) for loading firmware, completing the switching of the firmware loading partition on the acceleration chip firmware controller side. This switching can also be called atomic switching.

[0164] Step 25: The firmware update management unit triggers a hot reset of the acceleration chip firmware controller. During the hot reset, the acceleration chip firmware controller reloads and executes the target version of the acceleration chip firmware from the running partition after the partition state is switched. The firmware update management unit reads the startup status code of the acceleration chip firmware controller to determine whether the acceleration chip has started successfully. If it has started successfully (status code = 0x00), the update is successful. If it has started successfully (status code ≠ 0x00), the update has failed and the unit enters rollback mode.

[0165] Phase 3: Abnormal rollback phase.

[0166] The exception rollback phase is a fault-tolerant phase that accelerates the chip firmware update process. This phase needs to be executed in response to preset exception conditions. The exception conditions and corresponding rollback operations mainly include:

[0167] (1) The processor firmware differential upgrade package verification failed. The corresponding rollback operation includes maintaining the partition status of the original running partition and the backup partition, recording the failure log, which corresponds to step 16.

[0168] (2) If the partition write times out, the corresponding rollback operation includes: the timing monitoring unit used for partition write timing triggers the firmware update management unit to reset, so that the firmware update management unit stops updating the differential data to the backup partition, and restores the unupdated acceleration chip firmware in the backup partition to the acceleration chip firmware before the update.

[0169] (3) Partition verification failed (verification failed in step 23). The corresponding rollback operation includes: clearing abnormal data in the backup partition and restoring the original data in the backup partition.

[0170] (4) Acceleration chip startup failure, i.e. the rollback mode entered after the update failure in step 25, includes: the firmware update management unit sends partition status setting information and firmware loading partition information to the dual partition firmware storage unit and the acceleration chip firmware controller respectively, so as to instruct the dual partition firmware storage unit to switch between the running partition and the backup partition again, and to instruct the acceleration chip firmware controller to the new partition for loading firmware (i.e. the running partition). The firmware update management unit triggers the hot reset of the acceleration chip firmware controller again. When the acceleration chip firmware controller is hot reset again, it reloads and updates the previous acceleration chip firmware from the original running partition.

[0171] (5) Power failure, the corresponding rollback operation includes: in response to the trigger interrupt signal of the power monitoring unit, the firmware update management unit immediately saves the breakpoint information to the upgrade package storage unit, and repairs the partition in the dual-partition flash memory according to the breakpoint information after power-on to restore the acceleration chip firmware of the backup partition to the version before the update.

[0172] In addition, during the abnormal rollback phase, the following can be further implemented: rollback reason, timestamp and other information can be recorded in the upgrade package storage unit to form a rollback log. If the host is back online, the firmware update management unit will report the rollback log to the host via PCIe; if the host is offline, it will wait for the host to come online.

[0173] Phase Four: Power Failure Protection Phase. This mainly includes:

[0174] During the upgrade process (steps 21 to 25), the power monitoring unit monitors the power supply voltage and sends an interrupt signal to the firmware update management unit via GPIO when the power supply voltage is lower than a preset threshold (e.g., from 12V to 10.5V).

[0175] In response to receiving an interrupt signal, the firmware update management unit suspends the update and write operation of differential data to the backup partition, and writes the breakpoint information, including the current write progress, the checksum of the written data, and the partition status information, to the upgrade package storage unit.

[0176] The firmware update management unit triggers a reset of the timing monitoring unit to ensure that the timing can be restarted after the next power-on.

[0177] After power-on recovery, the firmware update management unit reads the breakpoint information in the upgrade package storage unit. Based on the breakpoint information, it restores the acceleration chip firmware in the backup partition to the version before the update, completing the state repair. The acceleration chip firmware controller still loads and executes the original acceleration chip firmware from the running partition before the update.

[0178] Figure 9 This is a schematic diagram illustrating the execution flow of a specific application scenario of the autonomous upgrade process, based on an illustrative embodiment.Figure 9 As shown, the execution flow of this application scenario mainly includes the following processes.

[0179] Step 9001: In response to the fulfillment of the update triggering condition, the firmware update management unit sends a firmware access pause command to the acceleration chip firmware controller to pause the acceleration chip firmware controller's access to the dual-partition firmware storage unit, and then executes step 9002.

[0180] Step 9002: The firmware update management unit updates the difference data in the differential upgrade package of the acceleration chip firmware to the acceleration chip firmware in the backup partition, so that the acceleration chip firmware in the backup partition is updated to the target version, and then executes step 9003.

[0181] Step 9003: The firmware update management unit verifies the target version of the acceleration chip firmware in the backup partition. If the verification is successful, proceed to step 9004; if the verification fails, proceed to step 9101.

[0182] Step 9004: The firmware update management unit sends partition status setting information and firmware loading partition information to the dual-partition firmware storage unit and the acceleration chip firmware controller, respectively, and then executes step 9005.

[0183] Step 9005: The dual-partition firmware storage unit changes the partition status of the running partition and the backup partition according to the received partition status setting information, so as to switch the partition status of the running partition and the backup partition to each other, and then executes step 9006.

[0184] Step 9006: During a hot reset, the acceleration chip firmware controller reloads and executes the acceleration chip firmware from the running partition after the partition state is switched, based on the received firmware loading partition information. Then, step 9007 is executed.

[0185] Step 9007: The firmware update management unit reads the startup status code of the acceleration chip firmware controller to determine whether the acceleration chip has started successfully. If so, proceed to step 9008; otherwise, proceed to step 9201.

[0186] Step 9008: Record the startup success log.

[0187] Step 9101: Restore the target version of the acceleration chip firmware in the backup partition to the acceleration chip firmware before the update.

[0188] Step 9201: The firmware update management unit sends the partition status setting information to the dual-partition firmware storage unit again, and sends the firmware loading partition information to the acceleration chip firmware controller again, so that the dual-partition firmware storage unit switches the partition status of the running partition and the backup partition to each other again, and so that when the acceleration chip firmware controller performs a hot reset, it reloads and executes the acceleration chip firmware from the running partition after the partition status has been switched again.

[0189] Step 9301: The timed monitoring unit starts timing during the process of the firmware update management unit updating the difference data to the backup partition. When the timing reaches the preset time threshold and the difference data has not been updated, a reset trigger signal is generated, and then step 9302 is executed.

[0190] Step 9302: In response to the received reset trigger signal, the firmware update management unit stops updating the differential data to the backup partition and restores the unupdated acceleration chip firmware in the backup partition to the acceleration chip firmware before the update.

[0191] Step 9401: During the process of the firmware update management unit updating the difference data to the backup partition, the power monitoring unit monitors the power supply voltage of the computing accelerator card. When the power supply voltage drops to the preset power failure protection threshold, an interrupt signal is generated, and then step 9402 is executed.

[0192] Step 9402: In response to the received interrupt signal, the firmware update management unit suspends the update of differential data to the backup partition, and immediately stores the current update progress containing differential data, the check value of differential data written to the backup partition, and the breakpoint information of the partition status of the dual-partition firmware storage unit into the upgrade package storage unit, and then executes step 9403.

[0193] Step 9403: After power-on recovery, the firmware update management unit reads the breakpoint information from the upgrade package storage unit and restores the acceleration chip firmware of the backup partition of the dual-partition firmware storage unit to the version before the update based on the breakpoint information.

[0194] Figure 10 This is a schematic diagram illustrating partition switching in a dual-partition firmware storage unit, according to an exemplary embodiment. For example... Figure 10 As shown, the dual-partition firmware storage unit includes partition A and partition B. In the initial state, i.e., before firmware updates, partition A is the running partition, containing the acceleration chip firmware version V1.0, and partition B is the backup partition, containing the acceleration chip firmware version V0.9. After updating the difference data to the backup partition, the dual-partition firmware storage unit is in the following state: Figure 10The update status is shown below, where partition B remains a backup partition, but the firmware for the acceleration chip in partition B has been updated to version V1.1. After successful verification of the V1.1 version acceleration chip firmware in partition B (backup partition) and the partition status change, the dual-partition firmware storage unit is in the following state: Figure 10 The upgrade success status shown indicates that partition A has been changed to a backup partition, with the acceleration chip firmware still at version V1.0, while partition B has been changed to a running partition, with the acceleration chip firmware at version V1.1. In the event of a failure to update differential data, a power outage during the update process, or a failure to boot the acceleration chip, the dual-partition firmware storage unit will enter a state similar to... Figure 10 The rolled-back state is shown below. Partition A has been changed back to the running partition, with the acceleration chip firmware still at version V1.0. Partition B has been changed back to the backup partition, with the acceleration chip firmware reverting to version V0.9. Figure 10 It can be seen that the rolled-back state of the dual-partition firmware storage unit is consistent with the initial state, indicating that the accelerated chip firmware update system and method of this disclosure can effectively return to the initial state in the event of accelerated chip firmware update failure, ensuring that the accelerated chip can still use the original version (e.g., ...) when firmware update fails. Figure 10 The accelerated chip firmware (version V1.0 shown) and from Figure 10 It can also be seen that the V1.0 version of the accelerator chip firmware in partition A was not rewritten during the entire firmware update process. This ensures that the security (integrity) of the original accelerator chip firmware (V1.0) used during the firmware update process was not compromised. This allows the accelerator chip to still boot and run normally using the original accelerator chip firmware (V1.0) even if the firmware update fails. This ensures the stable operation of the accelerator chip and the AI ​​server.

[0195] The accelerator chip firmware update system and method of this disclosure improve the autonomy of the accelerator chip firmware update process on the computing accelerator card side. The update process is independent of the host and the PCIe bus connected to the host, and the accelerator chip firmware update is completed when the host is in sleep, low power consumption, or offline. Therefore, it is applicable to edge computing, unattended operation, and other application scenarios. The accelerator chip firmware update system and method of this disclosure help improve the security of firmware updates. It utilizes a dual-partition firmware storage unit to achieve dual-partition backup of different versions of accelerator chip firmware and provides automatic rollback in various update failure scenarios, effectively preventing accelerator chip functional failure. The accelerator chip firmware update system and method of this disclosure help improve the data interaction efficiency between the host and the computing accelerator card. The differential upgrade package of the accelerator chip firmware is smaller than the complete upgrade package, typically accounting for only 10% to 20% of the size of the complete upgrade package. Therefore, the write time can be significantly reduced by 70% or more, and the PCIe bandwidth usage is lower, even down to about 80%. The accelerated chip firmware update system and method of this disclosure improve the fault tolerance of firmware updates. Power-loss protection and timeout protection are employed during the update process, significantly increasing the upgrade fault tolerance rate without requiring manual intervention. The accelerated chip firmware update system and method of this disclosure are highly compatible and applicable to accelerated chips from different manufacturers, supporting VBIOS, GSP firmware, microcode, etc.

[0196] In the illustrative embodiments, the acceleration chip of the acceleration chip firmware update system and method of this disclosure is applicable to SoC chips, etc., wherein the acceleration chip can be any one of GPU (Graphics Processing Unit), TPU (Tensor Processing Unit), NPU (Neural Network Processing Unit), DPU (Deep Learning Processing Unit), APU (Accelerated Processing Unit), and GPGPU (General-Purpose computing on Graphics Processing Unit).

[0197] In an illustrative embodiment, a computing accelerator card is also provided, which includes an accelerator chip firmware update system as described in any of the preceding embodiments.

[0198] In an illustrative embodiment, an artificial intelligence server is also provided, which includes an accelerated chip firmware update system as described in any of the preceding embodiments.

[0199] The above description is merely a preferred embodiment of this disclosure and is not intended to limit this disclosure. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.

Claims

1. A system for accelerating chip firmware updates, characterized in that, include: The upgrade package storage unit is located on the baseboard of the computing accelerator card in the artificial intelligence server; A dual-partition firmware storage unit is disposed on the substrate, including a running partition and a backup partition. The running partition and the backup partition are used to store different versions of acceleration chip firmware respectively, and the partition status of the running partition and the backup partition is changed according to the received partition status setting information to switch the partition status of the running partition and the backup partition to each other. An acceleration chip firmware controller, disposed in the acceleration chip on the computing accelerator card and coupled to the dual-partition firmware storage unit, is used to load and execute the acceleration chip firmware from the running partition to control the startup and operation of the acceleration chip, and to reload and execute the acceleration chip firmware from the running partition after the partition state is switched according to the received firmware loading partition information during hot reset; and, A firmware update management unit, disposed on the substrate and coupled to the upgrade package storage unit, the dual-partition firmware storage unit, and the acceleration chip firmware controller, is used to receive acceleration chip firmware differential upgrade packages sent by the host and store them in the upgrade package storage unit. When the update trigger condition is met, the unit updates the differential data in the acceleration chip firmware differential upgrade package to the acceleration chip firmware in the backup partition, so that the acceleration chip firmware in the backup partition is updated to the target version. The unit also sends the partition status setting information and the firmware loading partition information to the dual-partition firmware storage unit and the acceleration chip firmware controller, respectively.

2. The accelerated chip firmware update system according to claim 1, characterized in that, The update triggering conditions include: The firmware update management unit receives at least one of the following: an upgrade command issued by the host, the time reaches a preset update trigger time, or the host enters a low-power state.

3. The accelerated chip firmware update system according to claim 2, characterized in that: When the firmware update management unit detects that the PCIe link with the host is in L2 / L3 power management state, it determines that the host has entered a low-power state.

4. The accelerated chip firmware update system according to claim 1, characterized in that: The firmware update management unit is further configured to verify the target version of the acceleration chip firmware in the backup partition after the acceleration chip firmware in the backup partition is updated to the target version and before sending the partition status setting information and the firmware loading partition information to the dual-partition firmware storage unit and the acceleration chip firmware controller, respectively. If the verification is successful, the partition status setting information and the firmware loading partition information are sent to the dual-partition firmware storage unit and the acceleration chip firmware controller, respectively. In the event of a verification failure, the target version of the acceleration chip firmware in the backup partition will be restored to the previous version of the acceleration chip firmware.

5. The accelerated chip firmware update system according to claim 1, characterized in that, The accelerated chip firmware update system also includes: A timed monitoring unit is installed on the substrate to time the process of updating the difference data to the backup partition, and generates a reset trigger signal when the time reaches a preset time threshold and the difference data has not been updated. The firmware update management unit is coupled to the timing monitoring unit and is also used to stop the update of the differential data to the backup partition in response to the received reset trigger signal, and restore the unupdated acceleration chip firmware in the backup partition to the acceleration chip firmware before the update.

6. The accelerated chip firmware update system according to claim 1, characterized in that: The firmware update management unit is further configured to perform integrity verification and signature verification on the differential upgrade package of the acceleration chip firmware after receiving the differential upgrade package of the acceleration chip firmware issued by the host and before storing it in the upgrade package storage unit, and store the differential upgrade package of the acceleration chip firmware in the upgrade package storage unit if the integrity verification and the signature verification are successful. If either the integrity check or the signature check fails, the storage of the acceleration chip firmware differential upgrade package is rejected, and a check failure message is sent back to the host.

7. The accelerated chip firmware update system according to claim 1, characterized in that: The acceleration chip firmware controller is also used to send a startup failure signal to the firmware update management unit in the event that the acceleration chip fails to start. The firmware update management unit is also configured to, in response to receiving the boot failure signal, send the partition status setting information to the dual-partition firmware storage unit again, so that the dual-partition firmware storage unit switches the partition status of the running partition and the backup partition to each other again, and send the firmware loading partition information to the acceleration chip firmware controller again, so that when the acceleration chip firmware controller performs a hot reset, it reloads and executes the acceleration chip firmware from the running partition after the partition status has been switched again.

8. The accelerated chip firmware update system according to claim 1, characterized in that, The accelerated chip firmware update system also includes: A power monitoring unit, disposed on the substrate, is used to monitor the power supply voltage of the computing accelerator card during the process of updating the differential data to the backup partition, and generate an interrupt signal when the power supply voltage drops to a preset power failure protection threshold. The firmware update management unit is coupled to the power monitoring unit and is further configured to, in response to the received interrupt signal, suspend the update of the differential data to the backup partition, and immediately store the current update progress of the differential data, the checksum of the differential data written to the backup partition, and the breakpoint information of the partition status of the dual-partition firmware storage unit into the upgrade package storage unit. After power-on recovery, the breakpoint information is read from the upgrade package storage unit, and the acceleration chip firmware of the backup partition of the dual-partition firmware storage unit is restored to the version before the update based on the breakpoint information.

9. The accelerated chip firmware update system according to claim 1, characterized in that: The firmware update management unit is further configured to send a firmware access pause command to the acceleration chip firmware controller to pause the acceleration chip firmware controller's access to the dual-partition firmware storage unit when the update trigger condition is met and before updating the difference data to the backup partition.

10. A method for accelerating chip firmware updates, characterized in that, include: Receive and store the differential firmware upgrade package for the acceleration chip sent by the host; When the update trigger condition is met, the difference data in the differential upgrade package of the acceleration chip firmware is updated to the acceleration chip firmware in the backup partition of the dual-partition firmware storage unit, so that the acceleration chip firmware in the backup partition is updated to the target version. The dual-partition firmware storage unit includes a running partition and the backup partition, and the running partition and the backup partition store different versions of acceleration chip firmware respectively. Switch the partition states of the running partition and the backup partition to each other; During a hot reset, the instruction acceleration chip firmware controller reloads and executes the acceleration chip firmware from the running partition after the partition state has been switched.

11. The method for accelerating chip firmware updates according to claim 10, characterized in that, The update triggering conditions include: The system receives at least one of the following: receiving an upgrade command from the host, the time reaches a preset update trigger time, or the host is detected to have entered a low-power state.

12. The method for accelerating chip firmware updates according to claim 11, characterized in that, The detection of the host entering a low-power state includes: The PCIe link with the host was detected to be in L2 / L3 power management state.

13. The method for accelerating chip firmware updates according to claim 10, characterized in that, After the acceleration chip firmware in the backup partition is updated to the target version, and before switching the partition states of the running partition and the backup partition and instructing the acceleration chip firmware controller to reload and execute the acceleration chip firmware from the running partition after the partition state switch during a hot reset, the acceleration chip firmware update method further includes: Verify the target version of the acceleration chip firmware in the backup partition; In the case of successful verification, the partition states of the running partition and the backup partition are switched to each other, and the instruction acceleration chip firmware controller reloads and executes the acceleration chip firmware from the running partition after the partition state is switched during hot reset. In the event of a verification failure, the target version of the acceleration chip firmware in the backup partition will be restored to the previous version of the acceleration chip firmware.

14. The method for accelerating chip firmware updates according to claim 10, characterized in that, The accelerated chip firmware update method further includes: The process of updating the difference data to the backup partition is timed; When the timer reaches a preset time threshold and the difference data has not been updated, the update of the difference data to the backup partition is stopped, and the unupdated acceleration chip firmware in the backup partition is restored to the acceleration chip firmware before the update.

15. The method for accelerating chip firmware updates according to claim 10, characterized in that, After receiving the differential firmware upgrade package for the acceleration chip from the host, and before storing the differential firmware upgrade package for the acceleration chip, the acceleration chip firmware update method further includes: The firmware differential upgrade package for the acceleration chip is subjected to integrity verification and signature verification. If the integrity verification and the signature verification are successful, the acceleration chip firmware differential upgrade package is stored. If either the integrity check or the signature check fails, the storage of the acceleration chip firmware differential upgrade package is rejected, and a check failure message is sent back to the host.

16. The method for accelerating chip firmware updates according to claim 10, characterized in that, The accelerated chip firmware update method further includes: In response to receiving a boot failure signal from the acceleration chip firmware controller, the partition status setting information is sent to the dual-partition firmware storage unit again, causing the dual-partition firmware storage unit to switch the partition status of the running partition and the backup partition to each other again. The firmware loading partition information is sent to the acceleration chip firmware controller again, so that when the acceleration chip firmware controller performs a hot reset, it reloads and executes the acceleration chip firmware from the running partition after the partition status has been switched again.

17. The method for accelerating chip firmware updates according to claim 10, characterized in that, The accelerated chip firmware update method further includes: The power supply voltage of the computing accelerator card is monitored during the process of updating the difference data to the backup partition; When the power supply voltage drops to a preset power failure protection threshold, the update of the difference data to the backup partition is paused, and the current update progress containing the difference data, the verification value of the difference data written to the backup partition, and the breakpoint information of the partition status of the dual-partition firmware storage unit are immediately saved. After power-on recovery, the saved breakpoint information is read, and the acceleration chip firmware of the backup partition of the dual-partition firmware storage unit is restored to the version before the update based on the breakpoint information.

18. The method for accelerating chip firmware updates according to claim 10, characterized in that, The method for accelerating chip firmware updates also includes: When the update trigger condition is met, and before updating the difference data to the backup partition, the acceleration chip firmware controller's access to the dual-partition firmware storage unit is suspended.

19. A computing accelerator card, characterized in that, Including the accelerated chip firmware update system as described in any one of claims 1 to 9.

20. An artificial intelligence server, characterized in that, Including the accelerated chip firmware update system as described in any one of claims 1 to 9.