An electronic device that enables seamless firmware updates and a method for booting from that electronic device

A processor with a single XiP flash memory and external non-XiP memory facilitates seamless OTA updates by storing new firmware in external banks, addressing the blanking period and cost issues of dual flash memory systems.

DE102024134809A1Pending Publication Date: 2025-06-18TELECHIPS INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE102024134809
Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-13
Filing Date
2024-11-26
Publication Date
2025-06-18

AI Technical Summary

Technical Problem

Existing firmware update methods using over-the-air (OTA) updates cause a blanking period during which the processor cannot execute firmware, and using dual flash memories increases chip size and cost.

Method used

A processor with a single flash memory for XiP and an external memory without XiP functionality, connected via wireless communication, allows seamless firmware updates by transferring and storing new firmware in the external memory, which is partitioned into banks, and using a controller to determine the write position based on firmware version or presence.

Benefits of technology

Enables seamless firmware updates without interrupting operation, reduces chip size and cost, and supports multiple firmware backups without size limitations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

An electronic device is provided that is capable of seamlessly updating firmware, comprising a processor having a first firmware stored in a single flash memory that supports a software local execution function (eXecute in place (XiP)) using an external memory, an external memory that is external to the processor and does not have an XiP function and that stores a second firmware, and an interface that receives a third firmware from an external system that has the third firmware by wireless communication (OTA - Over The Air) with the external system.
Need to check novelty before this filing date? Find Prior Art

Description

BackgroundField of InterestThe present disclosure relates to firmware update of a processor, and more particularly, to an electronic device capable of seamless firmware update and a boot method using the electronic device.Description of the Related ArtRecently, a seamless firmware update method has been widely used in systems that support updates using wireless communication (OTA (Over The Air) updates) in the automobile field.This is because a functional boot system is advantageously maintained in the flash memory while the OTA update is in progress, and even if the firmware update (F / W) fails, it is possible to maintain availability by booting with the existing F / W.FIG. 1 is a diagram illustrating the firmware updating operation of a processor having a flash memory present and a firmware switching operation during boot.(a) of FIG. 1 illustrates that firmware A is stored in a flash memory 112 that supports the software local execution function (eXeceute in place (XiP)) using an external memory of the processor 110, and (b) of FIG. 1 illustrates that the existing firmware A in the flash memory 112 for XiP of the processor 110 is updated to firmware B by OTA and the firmware B is executed by a boot loader 120 of the processor 110 during boot.In a method 150 for updating with new firmware B from an external system 100, the flash memory 112 for XiP is being rewritten from the firmware A to the new firmware B, so that a blanking period of the firmware occurs in the flash memory 112 for XiP, and a device 111 inside the processor 110 has a problem that it cannot perform the execution of the firmware A in the flash memory 112 for XiP of the processor 110 during the update.FIG. 2 is a drawing illustrating the firmware updating operation of a processor having an existing dual bank and a firmware changing operation during boot.As shown in (a) of FIG. 2, the processor 210 may include a first flash memory 212 for XiP and a second flash memory 213 for XiP. Firmware A is stored in the first flash memory 212, and firmware B is updated in the second flash memory 213 of the processor 110 from an external system 200, and during the update, an internal or external device 211 of the processor 210 may use the firmware stored in the first flash memory 212 so that seamless operation may be performed.(b) of FIG. 2 illustrates the processor 210 after the update, and at the time of booting after the update, a boot loader 221 of the processor 210 selects 224 a bank to be used from the first flash memory 212 to the second flash memory 213, thereby executing the firmware B.The method of FIG. 2 has an advantage that the processor 210 can execute the firmware in the flash memory 1 212 for XiP even during the update and can maintain availability by booting with the existing firmware A even if the firmware update fails. However, a problem is that by using the processor with two flash memories, the size of the chip increases and the piece price of the chip also increases.OverviewThe present disclosure provides an electronic device capable of performing seamless firmware update using an legacy processor having a flash memory for XiP therein and an external memory for non-XiP, and a boot method using the electronic device.An electronic device capable of performing seamless firmware update includes, in one aspect, a processor including first firmware stored in a single flash memory that supports an eXeceut in place (XiP) software execution function (XiP)) using an external memory; an external memory that is external to the processor and does not have a XiP function and stores second firmware; and an interface that receives third firmware from an external system that has the third firmware by communicating with the external system via Over The Air (OTA).The processor and the external memory may be connected by a data line, and the third firmware of the external system may be transferred to the external memory and written via the data line.The interface may be connected to the processor, and the third firmware received via the interface may be transmitted to the external memory via the processor and written to the external memory.The external memory may be partitioned into a plurality of banks, and each of the partitioned banks may store different firmware.The electronic device may further include: a controller that determines a write position in one of the partitioned banks of firmware to be updated stored in a nonvolatile memory of the processor by checking a flag indicating a version or presence of different firmware written in each of the partitioned banks of the external memory.In another aspect, a boot method of a processor in an electronic device capable of seamless firmware update includes a processor that supports an eXeceut in place (XiP) software local execution function (XiP)) using an external memory, an external memory that is external to the processor and does not have a XiP function, and an interface that receives firmware from an external system that has the firmware through Over The Air (OTA) communication with the external system, wherein the boot method after firmware update includes: an operation state in which the processor attempts to boot using an existing boot loader; an operation state in which, when the booting is successful, the processor enters a boot loader added in an update method and the added boot loader searches the external memory for an available bank; an operation state in which, when a new firmware is present in an available bank, the boot loader copies the new firmware into a flash memory within the processor; and an operation state in which authentication of the new firmware copied into the flash memory within the processor is successful and the booting using the new firmware is successful and a main function of the new firmware is entered.The operating state in which the added boot loader searches the external memory for an available bank may include searching for a bank with a history of the last firmware update.The boot method may further include: an operation state in which, when authentication of the new firmware copied to the flash memory fails or boot using the new firmware fails, the existing firmware in the existing bank is copied to the internal flash memory of the processor, and a main function of the existing firmware is executed after the rollback.In another aspect, an electronic device capable of seamless firmware updating includes: a plurality of processors including firmware executed in a flash memory that supports an eXece in place (XiP) software execution function using an external memory; an external memory that is external to the plurality of processors and does not have a XiP function to store the plurality of firmware; and at least one interface that receives firmware to be updated from an external system including the firmware to be updated by over the air (OTA) with the external system.The plurality of processors and the one external memory may be connected by a data line, and the firmware to be updated may be transmitted from the plurality of processors to the one external memory via the data line and written.The at least one interface may be connected to the plurality of processors, and the firmware to be updated received via the at least one interface may be transmitted to the one external memory via the plurality of processors and written to the one memory.The one external memory may be partitioned into a plurality of banks, and each of the partitioned banks may store different firmware.The electronic device may further include: a controller that determines a write position in one of the partitioned banks of firmware to be updated stored in a nonvolatile memory of the plurality of processors by checking a flag indicating a version or presence of different firmware written in each of the partitioned banks of the one external memory.According to the electronic device capable of seamless firmware update and the boot method using the electronic device of the present disclosure, seamless firmware update can be supported while employing an legacy processor with flash memory for XiP.Moreover, the present disclosure can be implemented at a lower cost than an update device using the existing dual flash memory.Meanwhile, it is possible to perform the update using OTA while using a processor smaller than a processor having a dual flash memory.Moreover, there is no limitation on the number of firmware that can be saved depending on the size of an external flash memory in the OTA update device.Brief Description of the DrawingsFIG. 1 is a drawing illustrating the firmware update method and a firmware changeover operation during boot of the existing processor with a flash memory. FIG. 2 is a drawing illustrating the firmware update method and a firmware changeover operation during boot of the existing processor having two memory banks. FIG. 3 is a drawing for illustrating firmware update using a processor array and a firmware switching operation during boot of a processor array according to an embodiment of the present disclosure. FIG. 4 is a diagram illustrating firmware update using a processor array and a firmware switching operation during boot of a processor array according to another embodiment of the present disclosure. FIG. 5 is a flowchart of booting a processor after firmware update of the processor according to an embodiment of the present disclosure.Detailed DescriptionHereinafter, an embodiment of the present disclosure will be described with reference to the accompanying drawings. Some components that are not related to the gist of the disclosure are omitted or compressed, but the omitted components do not necessarily mean that they are not necessary for the present disclosure, and may be combined and used by a person skilled in the art to which the present disclosure pertains.FIG. 3 is a drawing for illustrating firmware update using a processor array and a firmware switching operation in a processor array during boot according to an embodiment of the present disclosure.As shown in (a) of FIG. 3, a processor array 310 of the present disclosure may include a processor 320, an external memory 360, and an interface 364. The processor 320 and the external memory 360 are connected via a data line 363, and communication between the external system 300 and the processor array 310 is performed via the interface 364. Here, the processor includes an MCU.The external system 300 receives new firmware B 350 via OTA, and then the external system 300 transfers the firmware B to a nonvolatile memory (SRAM, not shown) within the processor 320 by communicating with the processor 320 in which the firmware A stored in a flash memory 322 for XiP within the processor 320 is executed. The interface 364 may use UART, SIP, etc. The new firmware B received by the communication with the external system 300 is written into the external memory 360 via the data line 363.The processor 320 may be a commercially available processor with a flash memory 322 for XiP. The external memory 360 may also be a memory without a XiP function, and may have a dual bank structure including an A bank 361 and a B bank 362.As shown in FIG. 3, the A bank 361 of the external memory 360 stores the firmware A in advance, and the B bank 362 is a blank without firmware, but the firmware may not be written in advance in the A bank 361 and the B bank 362, and the firmware may be written in advance in the B bank 362, and the firmware stored in the A bank 361 may be different from the firmware running in the processor 320.As shown in FIG. 3, the processor array 310 may include a controller 365, and the controller 365 determines a writing location for updated firmware by checking a flag indicating a version or the presence of firmware written in advance in each bank 361 and 362 of the external memory 360. Here, the controller 365 may be disposed within the processor 320 or within the external memory 360.Referring to FIG. 3, the firmware update method using OTA according to an embodiment of the present disclosure is performed in the external memory 360 instead of the internal flash memory 322 of the processor 320, so that even during the OTA update, the device 321 inside or outside the processor 320 executes the firmware A stored in the flash memory 322 inside the processor 320, and thus the operation using the firmware A of the processor 320 is not interrupted.(b) of FIG. 3 shows a state of the processor 310 and the external memory 360 after the OTA update, and it can be seen that the new firmware B is written in the B bank 362 of the external memory 360. When booting after the update, the boot loader 331 of the processor 320 copies the firmware B of the B bank 362 into the flash memory 322 of the processor 320 via the data line 363 and executes the new firmware B.FIG. 4 is a drawing illustrating firmware update using a processor array and a firmware switching operation in the processor array during boot according to another embodiment of the present disclosure.As illustrated in FIG. 4, the processor array 410 according to another embodiment of the present disclosure may include a first processor 420, a second processor 430, an external memory 440, and an interface 460, and the first processor 420 and the second processor 430 are connected to the external memory 440 via a data line 463.As illustrated in FIG. 4, the external memory 440 has a structure including an A bank 441, a B bank 442, a C bank 443, and a D bank 444. In the A bank 441, the firmware A is stored in advance, in the B bank 442, the firmware B is stored in advance, and the C bank 443 and the D bank 444 are blanks without firmware. However, the firmware version stored in the individual banks and the presence of the firmware may be changed variously.The external system 400 receives new firmware C and D 450 sequentially or simultaneously via OTA, and thereafter the external system 400 transfers the new firmware C and D to the internal memory (SRAM, not shown) of the processor 420 and the processor 430 via the first and second interfaces 460 and 461. Thereafter, the new firmware C and D received by OTA communication is written into the C bank 443 and the D bank 444 of the external memory 440 via the data line 463. Here, the functions of the first and second interfaces 460 and 461 may be implemented in one interface.Here, the processor 420 and the processor 430 may be any commercially available processors each having a flash memory 422 and a flash memory 432 for XiP, and may be formed with three or more processors as long as the storage capacity is supported. Moreover, it is illustrated that the external memory 440 is a memory having no XiP function and may include a plurality of banks.Referring to FIG. 4, the processor array 410 further includes a controller 470, and the controller 470 determines a write location of the firmware to be updated by checking a flag indicating a version or presence of firmware written in advance for each bank partitioned in the external memory 440.In this manner, in the processor array 410 including a plurality of processors 420 and 430 and the external memory 440, the external memory 440 is partitioned into a plurality of banks and firmware is stored, so that firmware to be updated can be written into a target processor according to a schedule or a fixed order.FIG. 5 is a flowchart for booting a processor after firmware update according to an embodiment of the present disclosure.The flow chart for booting FIG. 5 is executed in the processor array 310 of FIG. 3, which is an embodiment of the present disclosure, and is executed in the state of the processor 320 and the external memory 360 illustrated in FIG. 3 under (b). First, at the start of the boot (operating state 410), the processor 320 attempts to boot using the existing boot loader (operating state 411), and if the boot fails, the processor 320 enters a restore mode (operating state 412).If the operating state 411 is successful, the processor 320 enters the boot loader 331 added during the update process (operation 413). The added boot loader 331 searches the external memory 360 for an available bank (operation state 414). If there is an available bank, processor 320 selects a high priority bank (operating state 416). Here, the priority may include a bank to which data has been written in the recent past.If no bank is available in operating state 414, a main function of the existing firmware is executed (operating state 415).After the operating state 416, it is checked whether a new firmware is present in the high priority bank (operation 417), and if a new firmware is present in the high priority bank, the new firmware in the high priority bank is copied to the flash memory 322 in the processor 320 (operating state 418).If no new firmware is present in the high priority bank in operating state 417, operating state 415 is executed.If authentication of the new firmware copied to flash memory 322 within processor 320 fails or booting with the new firmware fails after operation 418, the existing firmware in the existing bank is copied to internal flash memory 322 (operation state 420), and the main function of the existing firmware is executed after rollback (operation state 422).If the authentication of the new firmware copied to flash memory 322 within processor 320 and the boot with the new firmware in operation state 419 are successful, the primary function of the new firmware is entered (operation state 421).

Claims

An electronic device capable of seamless firmware update, the electronic device comprising: a processor including a first firmware stored in a single flash memory and supporting an eXece in place (XiP) software local execution function (XiP)) using an external memory; an external memory that is external to the processor and does not have a XiP function and stores a second firmware; and an interface that wirelessly receives a third firmware from an external system with the third firmware by communication with the external system (OTA - O-ver The Air).The electronic device of claim 1, wherein the processor and the external memory are connected by a data line, and the third firmware of the external system is transferred and written to the external memory through the data line.The electronic device according to claim 1 or 2, wherein the interface is connected to the processor, and the third firmware received via the interface is transmitted to the external memory via the processor and written to the external memory.The electronic device of any one of claims 1 to 3, wherein the external memory is partitioned into a plurality of banks, and each of the partitioned banks stores different firmware.The electronic device according to any one of claims 1 to 4, further comprising: a controller that determines a write location in one of the partitioned banks of firmware to be updated stored in a nonvolatile memory of the processor by checking a flag indicating a version or presence of different firmware written in each of the partitioned banks of the external memory.A boot method of a processor in an electronic device capable of seamless firmware update, comprising a processor that supports an eXeceut in place (XiP) software execution function (XiP)) using an external memory, an external memory that is external to the processor and does not have a XiP function, and an interface that receives firmware from an external system having the firmware by communicating with the external system via over the air (OTA), wherein the boot method comprises, after the firmware update: an operation state in which the processor attempts to boot using an existing boot loader; an operation state in which, when the booting is successful, the processor enters a boot loader added in an update method and the added boot loader searches the external memory for an available bank; an operation state in which, when a new firmware is present in an available bank, the boot loader copies the new firmware into a flash memory within the processor; and an operation state in which authentication of the new firmware copied into the flash memory within the processor is successful and the booting using the new firmware is successful enters a main function of the new firmware.The boot method of claim 6, wherein the operating state in which the added boot loader searches the external memory for an available bank comprises searching for a bank having a history of the last firmware update.The boot method according to claim 6 or 7, further comprising: an operation state in which, when authentication of the new firmware copied to the flash memory fails or boot using the new firmware fails, the existing firmware in the existing bank is copied to the internal flash memory of the processor, and a main function of the existing firmware is executed after rollback.An electronic device capable of seamless firmware updating, the electronic device comprising: a plurality of processors including firmware executed in a flash memory that supports an eXece in place (XiP) software execution function using an external memory; an external memory that is external to the plurality of processors and does not have a XiP function for storing the plurality of firmware; and at least one interface that receives firmware to be updated from an external system having the firmware to be updated by over the air (OTA) with the external system.The electronic device according to claim 9, wherein the plurality of processors and the one external memory are connected by a data line, and the firmware to be updated is transmitted from the plurality of processors to the one external memory via the data line and written, wherein the at least one interface is connected to the plurality of processors, and the firmware to be updated received via the at least one interface is transmitted to the one external memory via the plurality of processors and written to the one memory, wherein the one external memory is partitioned into a plurality of banks, and each of the partitioned banks stores different firmware, wherein the electronic device further comprises: a controller that determines a write location in one of the partitioned banks of firmware to be updated stored in a nonvolatile memory of the plurality of processors, by checking a flag indicating a version or presence of different firmware written in each of the partitioned banks of the one external memory.