Information processing device, information processing method and computer program
The information processing device addresses the delay and reliability issues in NAND-like flash memory systems by using parallel execution of boot processes and error recording, and replacing boot programs with backup programs upon error detection, ensuring a quick and reliable reboot.
Patent Information
- Application Number
- DE112012005589
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2012-06-11
- Publication Date
- 2025-05-08
- Estimated Expiration
- 2032-06-11
AI Technical Summary
Existing systems using NAND-like flash memory for booting face delays and reliability issues due to bit errors caused by charging losses, leading to potential system failures or hangs.
An information processing device with a non-volatile memory containing a program area for the boot program and backup areas with identical backup programs, allowing for parallel execution of the boot process and error recording, and a reboot agent that replaces the boot program with a backup program upon error detection to ensure a reliable reboot.
The solution enables a quick start of the boot process and ensures a reliable reboot by replacing the faulty boot program with a backup program, thereby improving system reliability and reducing the risk of failures.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Technical area
[0001] The present invention relates to an information processing apparatus, an information processing method and a computer program. State of the art
[0002] Recently, NAND-type flash memory, a non-volatile memory, has been widely used. Compared with NOR-type flash memory, NAND-type flash memory has the advantage of higher capacity and lower cost per bit, but the disadvantage of poor data reliability, as bit errors can occur due to charge loss when stored data is repeatedly read. Therefore, if a program for booting a system is stored in NAND-type flash memory, the system may fail to boot or hang after booting due to such bit errors.
[0003] JP 2010-26650 A describes a control device that reads a first boot program from a non-volatile system memory and performs error detection on the first program. If it determines that the read first boot program has been illegally modified, it reads a second boot program from a non-volatile backup memory and performs error detection on the second boot program. If it determines that the read second boot program has been illegally modified, it outputs an error message. If the control device determines, as a result of the error detection on the first or second boot program, that the boot program has not been illegally modified, it performs a boot process using the boot program.
[0004] US 2011 / 0 093 675 A1 discloses a method for protecting redundant data, in which, if a working data area and a redundant data area are not destroyed, a power-on self-test (POST) is performed to determine whether the global unique identifiers (GUIDs) of the working data area and the redundant data area are identical. If the GUIDs are different, the data of the working data area is synchronized with the redundant data area. Next, the working data area and the redundant data area are set to use the same memory address space. One of the two areas, the working data area or the redundant data area, is selected for mapping to the memory address space if an operating system is running.
[0005] US 2010 / 0 205 423 A1 describes a BIOS (Basic Input / Output System) comprising a first boot block, a second boot block, and a main BIOS block, and a computer with a control chip and this BIOS. If the programs in the first boot block and the main BIOS block are corrupted, the second boot block can be selected so that the BIOS boots from the second boot block. Meanwhile, a recovery module of the second boot block can be used to restore the first boot block and / or the main BIOS block.
[0006] US 2004 / 0 268 116 A1 discloses allocating a protected memory block containing a backup recovery block to a boot address space, booting a system from the newly allocated backup recovery block, copying the backup recovery block to a visible memory space, and protecting a version of the recovery block in a protected memory space.
[0007] US 5,835,761 A discloses an information processing system capable of updating a BIOS (Basic Input / Output System) program without interrupting or stopping system operation. To this end, the information processing system comprises an update program memory and a BIOS update flag. The update program memory retains the contents stored therein when the power supply to the information processing system is turned off. An update program input device supplies an update program for the basic input / output system to the update program memory to write the program therein while the operating system is running. The update program input device then sets the BIOS update flag.A system loader copies the BIOS update program stored in the update program memory to a memory area of main memory when the BIOS update flag is set during operating system loading. Summary of the inventionProblems to be solved by the invention
[0008] The control device described in JP 2010-26650 A performs error detection on the boot program read from the non-volatile system memory. If it determines, as a result of the error detection, that the boot program has not been illegally modified, it starts the boot process using the boot program. Therefore, one problem is that the start of the boot process is delayed.
[0009] An object of the present invention is to provide an information processing apparatus, an information processing method, and a computer program that can quickly start a boot process of a system and perform a reboot with a highly reliable program when an error is detected in a program for booting. Means to solve the problems
[0010] An information processing apparatus according to the present invention includes: a non-volatile memory having a program area storing a program for booting a system, and a plurality of backup areas each storing a backup program identical in content to the program; process execution means for executing the program stored in the program area to perform a boot process of the system; error detection means for performing error detection on the program stored in the program area in parallel with the boot process by the process execution means;and rebooting means for, when the error detecting means detects an error in the program, performing a recovery process for replacing the program stored in the program area with one of the backup programs stored in the backup areas, and rebooting the system using the replaced program stored in the program area; wherein, in performing the recovery process, the rebooting means refers to history information indicating a history of replacement of the program with the backup programs, selects the backup program to be used for replacement among the backup programs based on the history information, and replaces the program with the selected backup program.
[0011] An information processing method according to the present invention includes: a process execution step of executing a program for booting a system stored in a non-volatile memory to perform a boot process of the system, the non-volatile memory having a program area storing the program and a plurality of backup areas each storing a backup program identical in content to the program; an error detection step of performing error detection on the program stored in the program area in parallel with the boot process in the process execution step;and a reboot step for performing a recovery process when the error detection step detects an error in the program, to replace the program stored in the program area with one of the backup programs stored in the backup areas, and rebooting the system using the replaced program stored in the program area; wherein the reboot step, in performing the recovery process, refers to history information indicating a history of replacement of the program with the backup programs, selects the backup program among the backup programs to be used for replacement based on the history information, and replaces the program with the selected backup program.
[0012] A computer program according to the present invention causes a computer to execute: a process execution step of executing a program for booting a system stored in a non-volatile memory to perform a boot process of the system, the non-volatile memory having a program area storing the program and a plurality of backup areas each storing a backup program identical in content to the program; an error detection step of performing error detection on the program stored in the program area in parallel with the boot process in the process execution step;and a reboot step for, when the error detection step detects an error in the program, performing a restoration process to replace the program stored in the program area with one of the backup programs stored in the backup areas and rebooting the system using the replaced program stored in the program area; wherein the reboot step, in performing the restoration process, refers to history information indicating a history of replacement of the program with the backup programs, selects the backup program to be used for replacement among the backup programs based on the history information, and replaces the program with the selected backup program. Effect of the invention
[0013] According to the present invention, it is possible to quickly start a boot process of a system and perform a reboot with a highly reliable program when an error is detected in a program for booting. Short description of the drawings Fig. 1 is a block diagram schematically showing the configuration of an information processing apparatus in an embodiment. Fig. Figure 2 is a schematic diagram showing the storage format of a non-volatile memory. Fig. 3 is a block diagram showing the functional configuration of the information processing apparatus in the embodiment. Fig. 4 is a flowchart illustrating the operation of the information processing apparatus in the embodiment. Fig. Figure 5 is a flowchart illustrating a reboot process. Fig. Figure 6 is a schematic diagram showing the format of boot history information. Fig. Figure 7 is a flowchart illustrating a program (or file) replacement process. Fig. Figure 8 is a schematic diagram showing the format of replacement flag information. Fig. Figure 9 is a flowchart illustrating a backup verification process. Fig. Figure 10 is a schematic diagram illustrating processing periods in a configuration that performs boot processes after an error detection. Fig. 11 is a schematic diagram showing processing periods in the configuration of the embodiment. Fig. 12 is a schematic diagram illustrating processing periods in a configuration that performs boot processes and error detection processes in parallel by different processing devices. Modes for carrying out the invention
[0014] An embodiment of the invention will now be explained with reference to the drawings. Configuration of an information processing apparatus Fig. 1 is a block diagram schematically illustrating the configuration of an information processing apparatus 1 according to this embodiment. The information processing apparatus 1 according to Fig. 1 contains a non-volatile memory 2, a working memory 3, a central processing unit (CPU) 4, a communication unit 5 and an external interface (external IF) 6.
[0015] The non-volatile memory 2 is a readable and writable memory, such as a NAND-type flash memory, that stores a variety of programs and data. The non-volatile memory 2 includes a program area that stores a program (hereinafter referred to as the "boot program") for booting a system, and one or more backup areas, each storing a backup program (also referred to as the copied program) that is identical in content to the boot program. The system referred to above is, in particular, a computer system, more specifically, the computer system (based around the CPU 4) of the information processing device 1.In this example, the non-volatile memory 2 further includes a data area that stores an application configuration file for booting an application, and one or more backup file areas, each storing a backup file (also referred to as the copied file) whose content is identical to the application configuration file. Furthermore, the number of the one or more backup areas and the number of the one or more backup file areas are each multiple. The non-volatile memory 2 stores error detection data for detecting errors in the program or file for each of the boot program, backup programs, application configuration file, and backup files.
[0016] The main memory 3 is used by the CPU 4 as a working memory and stores programs and data read from the non-volatile memory 2.
[0017] The CPU 4 executes programs, such as the boot program stored in the non-volatile memory 2. Specifically, the non-volatile memory 2 stores programs and data in blocks; the CPU 4 reads (or copies) necessary blocks from the non-volatile memory 2 into the main memory 3, accesses the main memory 3, and executes processes described in the program read into the main memory 3.
[0018] When the CPU 4 communicates with an external device (externally connected device) connected to the information processing device 1 via the external interface 6, the communication unit 5 converts the transmitted and received data according to the communication protocol for communication with the externally connected device.
[0019] The external interface 6 is an interface, such as a Universal Serial Bus (USB) interface, for connecting the information processing device 1 to the externally connected device.
[0020] Fig. 2 is a schematic diagram showing the storage format of the non-volatile memory 2. In the example of Fig. 2, the non-volatile memory 2 stores a boot program 200 for performing a boot process after the system reset of the information processing device 1 and a kernel program 106 for booting an operating system (OS), each serving as the boot program. The non-volatile memory 2 also stores an application configuration file A 112 and an application configuration file B 114, each serving as the application configuration file and each required for booting an application that operates on the kernel.
[0021] The non-volatile memory 2 further stores, as backup programs, a first boot program backup 102 and a second boot program backup 104, each of which is identical in content to the boot program 100, and a first kernel program backup 108 and a second kernel program backup 110, each of which is identical in content to the kernel program 106. The non-volatile memory 2 also stores, as backup files, a first application configuration file A backup 116 and a second application configuration file A backup 120, each of which is identical in content to the application configuration file A 112, as well as a first application configuration file B backup 118 and a second application configuration file B backup 122, each of which is identical in content to the application configuration file B 114.
[0022] Respective checksum values 101, 103, 105, 107, 109, 111, 113, 115, 117, 119, 121 and 123 are assigned to the boot program 100, first boot program backup 102, second boot program backup 104, kernel program 106, first kernel program backup 108, second kernel backup program 110, application configuration file A 112, application configuration file B 114, first application configuration file A backup 116, first application configuration file B backup 118, second application configuration file A backup 120 and second application configuration file B backup 122, which are stored in the non-volatile memory 2, as corresponding error recording data is attached.
[0023] As in Fig. 2, the boot program 100 and its checksum value 101 are stored in the same block B1; the first boot program backup 102 and its checksum value 103 are stored in the same block B2; the second boot program backup 104 and its checksum value 105 are stored in the same block B3. Block B1 is a program area (also called the original block); blocks B2 and B3 are backup areas (also called the copied blocks). The kernel program 106 and its checksum value 107 are stored in the same block B4; the first kernel program backup 108 and its checksum value 109 are stored in the same block B5; the second kernel program backup 110 and its checksum value 111 are stored in the same block B6. Block B4 is a program area (also called the original area); Blocks B5 and B6 are backup areas (also called the copied blocks).Regarding the application configuration files, the application configuration file A 112 and its checksum value 113 and the application configuration file B 114 and its checksum value 115 are stored in the same block B7; the first application configuration file A backup 116 and its checksum value 117 and the first application configuration file B backup 118 and its checksum value 119 are stored in the same block B8; the second application configuration file A backup 120 and its checksum value 121 and the second application configuration file B backup 122 and its checksum value 123 are stored in the same block B9. Block B7 is a file area (also called the original area); blocks B8 and B9 are backup file areas (also called the copied blocks).
[0024] In addition, the non-volatile memory 2 stores replacement flag information 124 used in a program replacement process and a file replacement process, which will be explained later, as well as boot history information 126 for recording system boot history information. The non-volatile memory 2 can further store replacement order information 128 that specifies the order of backup programs to be replaced.
[0025] Fig. 2 shows an example of the storage format of the non-volatile memory 2. However, the storage format is not limited to this.
[0026] The boot program 100 is programmed so that the CPU 4 transfers the boot program 100 itself and its checksum value 101, stored in the non-volatile memory 2, to the main memory 3, performs an initialization process of the information processing device 1, and then executes the read target jump to the kernel program 106. The boot program 100 thus describes a boot process. The boot program 100 is also programmed so that the CPU 4, in parallel with the boot process, executes an error detection process that performs a checksum calculation on the boot program 100 transferred to the main memory 3 and compares the result of the calculation with the checksum value 101 to check whether the boot program 100 has any errors (or the correctness of the boot program 100).The boot program 100 thus describes the error detection process and a parallel control for performing the boot process and error detection process in parallel.
[0027] The kernel program 106 is programmed so that the CPU 4 transfers the kernel program 106 itself and its checksum value 107, stored in the non-volatile memory 2, to the main memory 3, and executes a system control process that performs system settings, such as activating peripheral devices including the communication unit 5. The kernel program 106 thus describes a boot process for booting the OS. The kernel program 106 is also programmed so that the CPU 4, in parallel with the system control process, executes an error detection process that performs a checksum calculation on the kernel program 106 transferred to the main memory 3 and compares the result of the calculation with the checksum value 107 in the main memory 3 to check whether the kernel program 106 has any errors (or the error-free nature of the kernel program 106).The kernel program 106 thus describes the error detection process and a parallel control for performing the boot process and error detection process in parallel.
[0028] The application configuration file A 112 is executed after the kernel program 106 boots and is programmed to cause the CPU 4 to transfer the application configuration file A 112 itself and its checksum value 113, stored in the non-volatile memory 2, to the main memory 3 and execute a predetermined process for booting an application. The application configuration file A 112 thus describes a boot process for booting the application.The application configuration file A 112 is also programmed so that the CPU 4, in parallel with the above process, executes an error detection process that performs a checksum calculation on the application configuration file A 112 transferred to the RAM 3 and compares the calculation result with the checksum value 113 in the RAM 3 to check whether the application configuration file A 112 contains any errors (or the error-free nature of the application configuration file A 112). The application configuration file A 112 thus describes the error detection process and a parallel controller for performing the boot process and error detection process in parallel.
[0029] The application configuration file B 114 is similar to the application configuration file A 112, and also describes a boot process, an error detection process and a parallel control.
[0030] In addition, the boot program 100, kernel program 106, application configuration file A 112 and application configuration file B 114 each describe a reboot process and a replacement control.
[0031] Fig. 3 is a block diagram illustrating the functional configuration of the information processing device 1 according to this embodiment. The information processing device 1 according to Fig. 3 includes a parallel processing unit 10, a process execution unit 11, an error detection unit 12, a reboot unit 13, and a replacement control unit 14.
[0032] The parallel processing unit 10, process execution unit 11, error detection unit 12, reboot unit 13, and replacement control unit 14 are implemented by executing, by the CPU 4, the parallel controls, boot processes, error detection processes, reboot processes, and replacement controls described in the boot program 100, kernel program 106, application configuration file A 112, and application configuration file B 114, respectively.
[0033] The parallel processing unit 10 performs control for parallel processing of multiple processes, including boot processes and error detection processes, through time division. Specifically, the parallel processing unit 10 controls the CPU 4 to execute multiple processes in parallel by dividing the processing time of the CPU 4 into small time segments and allocating the small time segments to the processes in sequence.
[0034] The process execution unit 11 executes the boot programs stored in the program areas in the non-volatile memory 2 to perform the boot processes for booting the system. Specifically, the process execution unit 11 executes the boot process described in the boot program 100 called after the system reset, executes the boot process described in the kernel program 106 called by the boot program 100, and executes the boot processes described in the application configuration file A 112 and the application configuration file B 114, thereby executing a process for booting the applications. The process execution unit 11 may further perform arithmetic processing or other processing on the applications.
[0035] In parallel with the boot processes by the process execution unit 11, the error detection unit 12 performs error detection on the boot programs and application configuration files stored in the program areas to verify the correctness of the boot programs and application configuration files. Specifically, the error detection unit 12 performs error detection on the boot program 100, kernel program 106, application configuration file A 112, and application configuration file B 114 using the respective error detection data.Specifically, the error detection unit 12 calculates checksum values for the boot program 100, kernel program 106, application configuration file A 112, and application configuration file B 114 stored in the non-volatile memory 2, compares the calculated checksum values with the corresponding checksum values previously stored in the non-volatile memory 2 to detect whether the boot programs and files have been illegally modified, and notifies the reboot unit 13 of the detection results.
[0036] When the error detection unit 12 detects an error in a boot program (the boot program 100 or kernel program 106), the reboot unit 13 reboots the system using a backup program (the first boot program backup 102, second boot program backup 104, first kernel program backup 108, or second kernel program backup 110) stored in backup areas to prevent the system from failing or getting stuck during booting. In this example, when the error detection unit 12 detects an error in a boot program, the reboot unit 13 performs a recovery process to replace the boot program stored in the program area with a backup program stored in the backup areas, and reboots the system using the replaced boot program.When performing the recovery process, the reboot unit 13 refers to history information indicating a history of replacement of the boot program with the backup programs (or history information related to a history in which the boot program was replaced with the backup programs), selects the backup program to be used for replacement from among the backup programs based on the history information, and replaces the boot program stored in the program area with the selected backup program. The history information is included in the boot history information 126 in the non-volatile memory 2.The reboot unit 13 can further refer to replacement order information indicating an order of backup programs for replacement, select the backup program to be used for replacement from among the backup programs based on the replacement order information and history information, and replace the boot program stored in the program area with the selected backup program. The replacement order information indicates an order in which the backup programs are to be used for replacement and is included in the replacement order information 128 in the non-volatile memory 2.When the recovery process is performed, the reboot unit 13 selects the backup program to be used for replacement in the recovery process based on the history information, so that the backup programs are used in the order indicated by the replacement order information. When the recovery process is performed, in one aspect, based on the history information (or the history information and replacement order information), the reboot unit 13 selects a backup program that has not been used for replacement from among the backup programs stored in the backup areas, and replaces the boot program stored in the program area with the selected backup program.On the other hand, when the error detection unit 12 detects an error in the boot program, if the backup areas do not contain a backup program that was not used for replacement, the reboot unit 13 causes the replacement control unit 14 to execute the program replacement process, which will be described later.
[0037] When the error detection unit 12 detects an error in an application configuration file (application configuration file A 112 or B 114), the reboot unit 13 reboots the application using a backup file (first application configuration file A backup 116, second application configuration file A backup 120, first application configuration file B backup 118, or second application configuration file B backup 122) stored in the backup file areas. In this example, when the error detection unit 12 detects an error in an application configuration file, the reboot unit 13 performs a recovery process to replace the application configuration file stored in the file area with a backup file stored in the backup file areas and reboots the application using the replaced application configuration file.When performing the recovery process, the reboot unit 13 refers to history information indicating a history of the replacement of the application configuration file with the backup files (or history information related to a history in which the application configuration file was replaced with the backup files), selects the backup file to be used for replacement from among the backup files based on the history information, and replaces the application configuration file stored in the file area with the selected backup file. The history information is included in the boot history information 126 in the non-volatile memory 2.The reboot unit 13 can further refer to the replacement order information indicating an order of the backup files for replacement, select the backup file to be used for replacement from among the backup files based on the replacement order information and history information, and replace the application configuration file stored in the file area with the selected backup file. The replacement order information indicates an order in which the backup files are to be used for replacement and is included in the replacement order information 128 in the non-volatile memory 2.When performing the restore process, the reboot unit 13 selects the backup program to be used for replacement in the restore process based on the history information, so that the backup files are used in the order indicated by the replacement order information. When performing the restore process, the reboot unit 13, in one aspect, selects a backup file that has not been used for replacement from among the backup files stored in the backup file areas based on the history information (or the history information and replacement order information), and replaces the application configuration file stored in the file area with the selected backup file.On the other hand, when the error detection unit 12 detects an error in the application configuration file, if the backup file areas do not contain a backup file that was not used for replacement, the reboot unit 13 causes the replacement control unit 14 to execute the file replacement process described below.
[0038] For example, when the reboot unit 13 replaces a boot program with a backup program during the recovery process, it copies the backup program stored in the backup area to the program area as the new boot program and overwrites the boot program stored in the program area with the backup program stored in the backup area. The same applies to a case where an application configuration file is replaced with a backup file.
[0039] The replacement control unit 14 performs the program replacement process to obtain a new boot program from an external source and replace the boot program with the new boot program. When an error is detected in a boot program (the boot program 100 or kernel program 106), the program replacement process is executed if the backup areas do not contain a backup program that was not used for replacement. The program replacement process is also executed when a boot program (the boot program 100 or kernel program 106) is updated.In the program replacement process, the replacement control unit 14, in this example, obtains a new boot program for replacement from a source external to the information processing unit 1, replaces a predetermined backup program among the backup programs stored in the backup areas with the new boot program, and replaces the boot program stored in the program area with the replaced predetermined backup program. Thus, when the replaced boot program is executed, the replacement control unit 14, if there is no error, replaces all of the backup programs except the predetermined backup program with the replaced predetermined backup program or the replaced boot program, and if there is an error, replaces the boot program stored in the program area with a backup program other than the predetermined backup program.
[0040] The replacement control unit 14 also performs the file replacement process to obtain a new application configuration file from an external source and replaces the application configuration file with the new application configuration file. When an error is detected in an application configuration file (application configuration file A 112 or B 114), the file replacement process is executed if the backup file areas do not contain a backup file that was not used for replacement. The file replacement process is also executed when an application configuration file (application configuration file A 112 or B 114) is updated.In the file replacement process, in this example, the replacement control unit 14 obtains a new application configuration file for replacement from a source external to the information processing unit 1, replaces a predetermined backup file among the backup files stored in the backup file area with the new application configuration file, and replaces the application configuration file stored in the file area with the replaced predetermined backup file. Then, when the replaced application configuration file is executed, the replacement control unit 14, if there is no error, replaces all of the backup files except the predetermined backup file with the replaced predetermined backup file or the replaced application configuration file. If there is an error, it replaces the application configuration file stored in the file area with a backup file other than the predetermined backup file.
[0041] When the replacement control unit 14 replaces a backup program with a new boot program, it copies the new boot program to the backup area as the new backup program, for example, or overwrites the backup program stored in the backup area with the new boot program. The same applies to a case where a boot program is replaced with a backup program, a case where a backup file is replaced with a new application configuration file, and the like.
[0042] In the program replacement process and the file replacement process, the new boot program and the application configuration file obtained by the replacement control unit 14 from the external source may be identical to the boot program and the application configuration file currently stored in the non-volatile memory 2 or may be newer versions than the currently stored boot program and application configuration file.
[0043] Operation of the information processing device Fig. Fig. 4 is a flowchart illustrating the operation of the information processing device 1 according to this embodiment. The operation of the information processing device 1 will be described below with reference to Fig. 4 described.
[0044] When the system reset is enabled, the CPU 4 accesses a predetermined address (hereinafter referred to as the "boot address") where the boot program 100 is stored in the non-volatile memory 2, and transfers the boot program 100 and its checksum value 101 to the main memory 3. The CPU 4 then reads the boot program 100 from the main memory 3 and executes the boot process, including the initialization process described in the boot program 100 (S1). The boot address in this case is a fixed address.
[0045] According to instructions described in the boot program 100, the CPU 4 next jumps to the address where the kernel program 106 is stored and transfers the kernel program 106 and its checksum value 107 to the main memory 3. The CPU 4 then reads the kernel program 106 from the main memory 3 and executes the boot process described in the kernel program 106 (S5).
[0046] When booting of the kernel program 106 is complete, the CPU 4 then transfers the application configuration files A 112 and B 114 for booting the applications specified in advance in the kernel, as well as the respective checksum values 113 and 115, from the non-volatile memory 2 to the main memory 3. The CPU 4 then reads the application configuration files A 112 and B 114 from the main memory 3 and executes the boot processes described in the application configuration files A 112 and B 114 to boot the applications, thereby providing the intended applications to a user (S10). The application configuration files A 112 and B 114 can be executed sequentially one after the other or in parallel.
[0047] Meanwhile, by executing the parallel control described in the boot program 100 in parallel with the boot process of the boot program 100 in step S1, the CPU 4 executes the error detection process described in the boot program 100 and calculates the checksum value of the boot program 100 (S2). The CPU 4 then determines whether the calculated checksum value matches the checksum value 101 of the boot program 100 (S3). If the two do not match (NO in step S3), the CPU 4 determines that the boot program 100 has an illegal bit change and proceeds to the reboot process (S4). In this reboot process, the CPU 4 performs the replacement process to replace the boot program 100 with the first boot program backup 102 or the second boot program backup 104 and reboots the system using the replaced boot program 100. The reboot process (S4) will be explained in detail later.
[0048] On the other hand, if the calculated checksum value of the boot program 100 matches the checksum value 101 (YES in step S3), the CPU 4 determines that the boot program 100 is free of illegal bit changes and calculates the checksum value of the kernel program 106 read following the boot program 100 (S6). The CPU 4 then determines whether the calculated checksum value 107 of the calculated kernel program 106 matches (S7). If the two do not match (NO in step S7), the CPU 4 determines that the kernel program 106 has an illegal bit change and proceeds to the reboot process (S8). In this reboot process, the CPU 4 performs the replacement process to replace the kernel program 106 with the first kernel program backup 108 or the second kernel program backup 110 and reboots the system using the replaced kernel program 106. The reboot process (S8) will be described in detail later.
[0049] On the other hand, if the calculated checksum value of the kernel program 106 matches the checksum value 107 (YES in step S7), the CPU 4 determines that the kernel program 106 is free of illegal bit changes and calculates the checksum value of the application configuration file A 112 read following the kernel program 106 (S11). The CPU 4 then determines whether the calculated checksum value matches the checksum value 113 of the application configuration file A 112 (S12). If the two do not match (NO in step S12), the CPU 4 determines that the application configuration file A 112 has an illegal bit change and proceeds to the reboot process (S13).In this reboot process, the CPU 4 performs the replacement process to replace the application configuration file A 112 with the first application configuration file A backup 116 or the second application configuration file A backup 120, and reboots the application using the replaced application configuration file A 112. The reboot process (S13) will be described in detail later.
[0050] On the other hand, if the calculated checksum value of application configuration file A 112 matches checksum value 113 (YES in step S12), CPU 4 determines that application configuration file A 112 is free of illegal bit changes. Then, when another application configuration file is read, CPU 4 performs the same process on application configuration file A 112 (S11, S12) on the read application configuration file; if no other application configuration file is read, it enters a wait state. For example, if application configuration file B 114 is read following application configuration file A 112, CPU 4 performs the process on application configuration file B 114 following the process on application configuration file A 112 (S11, S12) and enters the wait state.When the application configuration file B 114 is executed in parallel with the application configuration file A 112, the CPU 4 can perform the process on the application configuration file B 114 in parallel with the process on the application configuration file A 112.
[0051] The steps S1, S5 and S10 in Fig. 4 are implemented by CPU 4 executing the boot processes described in the boot program, kernel program, or application configuration files, respectively. Steps S2 and S3, S6 and S7, and S11 and S12 are implemented by CPU 4 executing the error detection processes described in the boot program, kernel program, or application configuration files, respectively. Steps S4, S8, and S13 are implemented by CPU 4 executing the reboot processes described in the boot program, kernel program, or application configuration files, respectively. Steps S1, S5, and S10 are thus processes in the process execution unit 11; steps S2, S3, S6, S7, S11, and S12 are processes in the error detection unit; and steps S4, S8, and S13 are processes in the reboot unit 13. Reboot process
[0052] Fig. Figure 5 is a flowchart illustrating the reboot process. The reboot processes in steps S4, S8, and S13 in Fig. 4 are discussed below with reference to Fig. 5 explained.
[0053] First, the reboot process in step S4 is described. In the reboot process in step S4, the CPU 4 stops as shown in Fig. 5, the CPU 44 first executes the boot process (the process in step S1) (S21). The CPU 44 then references and modifies the boot history information 126 stored in the non-volatile memory 2 (S22).
[0054] The following describes boot history information 126. In this example, boot history information 126 shows replacement sources (or copy sources) of the programs and files used for booting. Fig. 6 is a diagram showing the format of the boot history information 126. The boot history information 126 in Fig. 6 contains a boot history value for each of the boot program 100, the kernel program 106, the application configuration file A 112, and the application configuration file B 114. The boot history values for the boot program 100, the kernel program 106, the application configuration file A 112, and the application configuration file B 114 are recorded at addresses N, N+1, N+2, and N+3, respectively, in the non-volatile memory 2. When the boot program 100 is booted for the first time, "0" is recorded at address N; the value at address N is kept at "0" until the reboot process (S4) is performed. If, after the reboot process (S4) is performed, the boot program 100 is a program replaced with the first boot program backup 102, a "1" is recorded at address N; If the boot program 100 is a program that has been replaced with the second boot program backup 104, a “2” is recorded in the address N.Thus, a "0", "1", or "2" is recorded in the address N; the boot history value "0" indicates that the boot program 100 stored in the block B1 is not a program that was replaced in the reboot process (S4), that is, is an initial program; the boot history value "1" indicates that the boot program 100 stored in the block B1 is a program that was replaced with the first boot program backup 102 in the reboot process (S4); the boot history value "2" indicates that the boot program 100 stored in the block B1 is a program that was replaced with the second boot program backup 104 in the reboot process (S4). The CPU 4 can thus recognize a program that is a replacement source (or copy source) of the boot program 100 currently used for booting by pointing to or referring to the boot history value in the address N in the boot history information 126.
[0055] The order of replacement of the boot program 100 in the reboot process (S4) is defined in this example such that the first boot program backup 102 is used for replacement in the first reboot process, and the second boot program backup 104 is used for replacement in the next reboot process. The same applies to the kernel program 106, the application configuration file A 112, and the application configuration file B 114.
[0056] The non-volatile memory 2 stores, for example, replacement order information 128 indicating the replacement order of the backup programs or backup files for each of the boot program 100, kernel program 106, application configuration file A 112, and application configuration file B 114; the CPU 4 determines the replacement order with reference to the replacement order information 128. Specifically, the CPU 4 performs the processing in and after step S22 based on the replacement order information 128. In this configuration, the replacement order can be changed by changing the replacement order information. For example, the manufacturer of the information processing device 1 can set the replacement order to an intended order by recording the replacement order information indicating the intended order in the non-volatile memory 2.For example, the information processing apparatus 1 may change the replacement order information according to information regarding an error detection rate of each block or other information or operations from a user.
[0057] If, returning to Fig. 5, in step S22, if the boot history value for the boot program 100 is "0", the CPU 4 changes the boot history value for the boot program 100 to "1" because the boot program 100 is replaced with the first boot program backup 102; if the boot history value for the boot program is "1", the CPU 4 changes the boot history value for the boot program 100 to "2" because the boot program 100 is replaced with the second boot program backup 104; if the boot history value for the boot program is "2", the CPU 4 does not change the boot history value for the boot program 100.
[0058] The CPU 4 then determines whether it is possible to replace the boot program 100 with a backup program (S23). Specifically, if the boot history value in address N for the boot program 100 is "0" or "1," the CPU 4 determines that replacement is possible; if the boot history value is "2," it determines that replacement is not possible. The determination in step S23 is made based on the boot history value referenced in step S22, that is, the boot history value before the change in step S22.
[0059] If it is determined that replacement is possible (YES in step S23), the CPU 4 replaces the boot program 100 and its checksum value 101 stored in block B1 with a backup program and its checksum value (S24). Specifically, if the boot history value for the boot program 100 is "0," the CPU 4 copies the first boot program backup 102 and its checksum value 103 in block B1 as the new boot program 100 and its checksum value 101. If the boot history value for the boot program 100 is "1," it copies the second boot program backup 104 and its checksum value 105 in block B1 as the new boot program 100 and its checksum value 101. When the replacement of the boot program 100 and its checksum value 101 is completed, the CPU 4 performs a system reboot (S25). Specifically, when the replacement is completed, the CPU 4 performs a software reset and accesses the boot address to restart the process. Fig. 4 from the beginning. This means that the processing in Fig. 4 returns from step S4 to step S1, and the boot process of the boot program 100 is performed again. In this case, the boot program 100 is read and executed after the replacement. The process in step S24 is performed based on the boot history value referenced in step S22, that is, the boot history value before the change in step S22.
[0060] On the other hand, if it is determined that replacement of the boot program 100 is not possible (NO in step S23), the CPU 4 outputs a message indicating that a new boot program must be obtained from an external source on a display unit (not shown) or the like (S26), and proceeds to the program replacement process for replacing the boot program with a boot program from an external source (S27). The program replacement process will be explained later.
[0061] The above description represents the case where the first boot program backup 102 and the second boot program backup 104 are used to replace the boot program 100 in this order, but they may be used in the order of the second boot program backup 104 and the first boot program backup 102. In this case, if the boot history value for the boot program 100 is "0," the CPU 4 changes the boot history value to "2" and replaces the boot program 100 with the second boot program backup 104; if the boot history value is "2," it changes the boot history value to "1" and replaces the boot program 100 with the first boot program backup 102; if the boot history value is "1," it performs the program replacement process without changing the boot history value. The same applies to the kernel program 106, the application configuration file A 112 and the application configuration file B 114.
[0062] The following describes the reboot process in step S8. In the reboot process in step S8, the CPU 4 stops as shown in Fig. 5, the boot process (the process in step S5) first starts (S21). The CPU 4 then references and changes the boot history value at address N+1 in the boot history information 126 stored in the non-volatile memory 2 (S22).
[0063] The boot history value of address N+1 in boot history information 126 is described here. In Fig. 6, as in the case of address N, a "0", "1", or "2" at address N+1 is recorded in the boot history information 126 as the boot history value for the kernel program 106. For the kernel program 106, the boot history value "0" indicates that the kernel program 106 stored in block B4 is not a program replaced in the reboot process (S8); the boot history value "1" indicates that the kernel program 106 stored in block B4 is a program replaced with the first kernel program backup 108 in the reboot process (S8); the boot history value "2" indicates that the kernel program 106 stored in block B4 is a program replaced with the second kernel program backup 110 in the reboot process (S8).
[0064] If, returning to Fig. 5, in step S22, if the boot history value for the kernel program 106 is "0", the CPU 4 changes the boot history value for the kernel program 106 to "1" because the kernel program 106 is replaced with the first kernel program backup 108; if the boot history value for the kernel program 106 is "1", the CPU 4 changes the boot history value for the kernel program 106 to "2" because the kernel program 106 is replaced with the second kernel program backup 110; if the boot history value for the kernel program 106 is "2", the CPU 4 does not change the boot history value for the kernel program 106.
[0065] The CPU 4 then determines whether it is possible to replace the kernel program 106 with a backup program (S23). Specifically, if the boot history value at address N+1 for the kernel program 106 is "0" or "1," the CPU 4 determines that replacement is possible; if the boot history value is "2," it determines that replacement is not possible. The determination in step S23 is made based on the boot history value referenced in step S22, that is, the boot history value before a change in step S22.
[0066] If it is determined that replacement is possible (YES in step S23), the CPU 4 replaces the kernel program 106 and its checksum value 107 stored in block B4 with a backup program and its checksum value (S24). Specifically, if the boot history value for the kernel program 106 is "0," the CPU 4 copies the first kernel program backup 108 and its checksum value 109 to block B4 as the new kernel program 106 and its checksum value 107. If the boot history value for the kernel program 106 is "1", it copies the second kernel program 110 and its checksum value 111 in the block B4 as the new kernel program 106 and its checksum value 107. When the replacement of the kernel program 106 and its checksum value 107 is completed, the CPU 4 reboots the system (S25).In particular, when the replacement is completed, the CPU 4 performs a software reset and accesses the boot address where the boot program 100 is stored to start the process in . Fig. 4 from the beginning. This means that in Fig. 4, the processing returns from step S8 to step S1, and the boot process of the boot program 100 is performed again. In the post-boot processing, the kernel program 106 is read and executed after the replacement. The process in step S24 is performed based on the boot history value referenced in step S22, that is, the boot history value before the change in step S22.
[0067] On the other hand, if it is determined that replacement of the kernel program 106 is not possible (NO in step S23), the CPU 4 outputs a message indicating that a new kernel program must be obtained from an external source (S26) and proceeds to the program replacement process for replacing the kernel program 106 with a kernel program from an external source (S27). The program replacement process will be described in detail later.
[0068] The reboot process in step S13 is explained below. In the reboot process in step S13, the CPU 4 stops as shown in Fig. 5, the boot process (the process in step S10) first starts (S21). The CPU 4 then references and changes the boot history value at address N+2 in the boot history information 126 stored in the non-volatile memory 2 (S22).
[0069] The boot history value at address N+2 in boot history information 126 is described here. In Fig. 6, as in the case of address N, a "0", "1", or "2" is recorded at address N+2 in the boot history information 126 as the boot history value for the application configuration file A 112. For the application configuration file A 112, the boot history value "0" indicates that the application configuration file A 112 stored in block B7 is not a file replaced in the reboot process (S13); the boot history value "1" indicates that the application configuration file A 112 stored in block B7 is a file replaced with the first application configuration file A backup 116 in the reboot process (S13); the boot history value “2” indicates that the application configuration file A 112 stored in block B7 is a file that was replaced with the second application configuration file A backup 120 in the reboot process (S13).
[0070] If, returning to Fig. 5, in step S22, if the boot history value for the application configuration file A 112 is equal to “0”, the CPU 4 changes the boot history value for the application configuration file A 112 to “1” because the application configuration file A 112 is replaced with the first application configuration file A backup 116; if the boot history value for the application configuration file A 112 is equal to “1”, the CPU 4 changes the boot history value for the application configuration file A 112 to “2” because the application configuration file A 112 is replaced with the second application configuration file A backup 120; if the boot history value for the application configuration file A 112 is equal to “2”, the CPU 4 does not change the boot history value for the application configuration file A 112.
[0071] The CPU then determines whether it is possible to replace the application configuration file A 112 with a backup file (S23). Specifically, if the boot history value at address N+2 for the application configuration file A 112 is "0" or "1," the CPU 4 determines that replacement is possible; if the boot history value is "2," it determines that replacement is not possible. The determination in step S23 is made based on the boot history value referenced in step S22, that is, the boot history value before a change in step S22.
[0072] If it is determined that replacement is possible (YES in step S23), the CPU 4 replaces the application configuration file A 112 and its checksum value 113 stored in block B7 with a backup file and its checksum value (S24). Specifically, if the boot history value for the application configuration file A 112 is "0," the CPU 4 copies the first application configuration file A backup 116 and its checksum value 117 in block B7 as the new application configuration file A 112 and its checksum value 113; If the boot history value for the application configuration file A 112 is "1", it copies the second application configuration file A backup 120 and its checksum value 121 in the block B7 as the new application configuration file A 112 and its checksum value 113. When the replacement of the application configuration file A 112 and its checksum value 113 is completed, the CPU 4 reboots the application (S25).In particular, when the replacement is complete, CPU 4 reloads the application configuration file A 112 in the state in which the system (especially the kernel) was booted. Processing in . Fig. 4 thus proceeds from step S13 to step S10, and the application configuration file A112 is read and the application boot process is performed again. In this case, the application configuration file A112 is read and executed after the replacement. The process in step S24 is performed based on the boot history value referenced in step S22, that is, the boot history value before a change in step S22.
[0073] On the other hand, if it is determined that replacement of the application configuration file A 112 is not possible (NO in step S23), the CPU 4 outputs a message indicating that a new application configuration file must be obtained from an external source (S26) and proceeds to the file replacement process for replacing the application configuration file A 112 with an application configuration file from an external source (S27). The file replacement process will be explained later.
[0074] The reboot process for application configuration file B 114 is the same as for application configuration file A 112.
[0075] When the boot program 100, the kernel program 106, the application configuration file A 112, or the application configuration file B 114 as such is replaced with a backup program, the backup program used for replacement is selected with reference to the boot history information 126. This makes it possible to select a backup program that does not satisfy the condition that it was used for replacing the program and an error was detected in the replaced program (or to select a backup program in which an error was not detected), so that the reboot process can be performed with a more reliable backup program.Immediately after a boot program is replaced with a first backup, if an error is detected in the boot program, it is possible to select a backup program (for example, a second backup) other than the first backup that is likely to have an error to perform the reboot process, so that the reboot process can be performed with a more reliable backup program. Program (file) replacement process
[0076] Fig. Fig. 7 is a flowchart showing the program (or file) replacement process in step S27 in Fig. 5. The program replacement process for the boot program, the program replacement process for the kernel program and the file replacement process for the application configuration file are described below with reference to Fig. 7. The program (or file) replacement processes for the boot program, kernel program, and application configuration file are implemented by execution, by the CPU 4, of the replacement controls described in the boot program, kernel program, and application configuration file, respectively.
[0077] First, the program replacement process for the boot program is described. If the program replacement process for the boot program, as shown in Fig. 7, the CPU 4 detects that an external memory has been connected to the external interface 6, reads a new boot program for replacement and its checksum value via the communication unit 5 from the external memory and replaces the first boot program backup 102 and the checksum value 103 with the new boot program and its checksum value (S31). The external memory is connected to the external interface 6 of the information processing device 1, for example, by a user who reads the message in step S26. Fig. 5 and is, for example, a portable storage device, such as a USB memory.
[0078] When the replacement is completed, the CPU 4 changes the replacement flag information 124 (S32).
[0079] The replacement flag information 124 is described below. The replacement flag information 124 indicates whether the program (or file) replacement process is being executed. Fig. 8 is a diagram showing the format of the replacement flag information 124. The replacement flag information 124 in Fig. 8 contains a respective replacement flag for the boot program 100, the kernel program 106, the application configuration file A 112, and the application configuration file B 114, respectively. The replacement flags for the boot program 100, the kernel program 106, the application configuration file A 112, and the application configuration file B 114 are recorded at addresses M, M+1, M+2, and M+3, respectively, in the non-volatile memory 2. Each of the replacement flags is normally "0" and is changed to "1" when the program (or file) replacement process is executed. A "0" or "1" is recorded at each of the addresses M, M+1, M+2, and M+3; a "0" indicates that the replacement process for the corresponding program (or file) is not performed; a “1” indicates that the replacement process is being performed for the corresponding program (or file).
[0080] Returning to Fig. 7, in step S32, the CPU 4 changes the replacement flag in address M for the boot program 100 from "0" to "1." The replacement flag "1" for the boot program 100 indicates that the first boot program backup 102 has been replaced with a new boot program and therefore differs in content from the boot program 100 and the second boot program backup 104.
[0081] CPU 4 then replaces the boot program 100 and the checksum value 101 with the replaced first boot program backup 102 and checksum value 103 (S33).
[0082] When the replacement is complete, the CPU 4 changes the boot history value for the boot program 100 in the boot history information 126 to "1" (S34) and reboots the system (S35). Specifically, the CPU 4 performs a software reset, accesses the boot address, and reads and executes the replaced boot program 100 to start the boot process (step S1 in Fig. 4) and the checksum calculation (step S2 in Fig. 4) in parallel.
[0083] When the checksum calculation ends, the CPU 4 refers to the replacement flag and the boot history value for the boot program 100, and if the replacement flag and boot history value are both “1”, goes to step S36 in Fig. 7. If the replacement flag is equal to “0”, it goes to step S3 in Fig. 4; if the replacement flag is "1" and the boot history value is "2", it goes to step S43, which will be described later.
[0084] In step S36, the CPU 4 determines whether the boot program 100 has any errors. Specifically, if the boot program 100 boots normally and the calculated checksum value matches the checksum value 101, the CPU 4 determines that there is no error; if the boot program 100 does not boot normally, or if the two checksum values do not match, the CPU 4 determines that there is an error.
[0085] If it is determined that there is no error (NO in step S36), the CPU 4 changes the boot history value for the boot program 100 to "0" (S37) and replaces the second boot program backup 104 with the first boot program backup 102 (S38). The CPU 4 then resets the replacement flag for the boot program 100 to "0" (S39) and ends the program replacement process. After the program replacement process ends, processing proceeds to step S6 in Fig. 4.
[0086] On the other hand, if it is determined that an error exists (YES in step S36), the CPU 4 replaces the boot program 100 with the second boot program backup 104 (S40), changes the boot history value for the boot program 100 to "2" (S41), and reboots the system (S42). Specifically, the CPU 4 performs a software reset, accesses the boot address, and reads and executes the replaced boot program 100 to complete the boot process (step S1 in Fig. 4) and the checksum calculation (step S2 in Fig. 4) in parallel.
[0087] When the checksum calculation ends, the CPU 4 refers to the replacement flag and the boot history value for the boot program 100 and, if the replacement flag is “1” and the boot history value is “2”, goes to step S43 in Fig. 7.
[0088] In step S43, the CPU 4 determines whether the boot program 100 has any errors in the same manner as in step S36.
[0089] If it is determined that there is no error (NO in step S43), the CPU 4 informs a user that the new boot program obtained from the external source is faulty, for example, by displaying it on a display unit (not shown) in step S44, and ends the program replacement process. After the program replacement process ends, processing proceeds to step S6 in Fig. 4.
[0090] On the other hand, if it is determined that an error exists (YES in step S43), the CPU 4 goes to step S26 in Fig. 5, reissues the message indicating that a new boot program must be obtained from an external source, and executes the program replacement process (S27).
[0091] The following describes the program replacement process for the kernel program. If the program replacement process for the kernel program, as described in Fig. 7, the CPU 4 detects that an external memory has been connected to the external interface 6, it reads a new kernel program for replacement and its checksum value from the external memory and replaces the first kernel program backup 108 and the checksum value 109 with the new kernel program and checksum value (S31).
[0092] When the replacement is completed, the CPU 4 changes the replacement flag at address M+1 for the kernel program 106 in the replacement flag information 124 from “0” to “1” (S32).
[0093] CPU 4 then replaces kernel program 106 and checksum value 107 with the replaced first kernel program backup 108 and checksum value 109 (S33).
[0094] When the replacement is complete, the CPU 4 changes the boot history value for the kernel program 106 in the boot history information 126 to "1" (S34) and reboots the system (S35). Specifically, the CPU 4 performs a software reset, accesses the boot address, reads and executes the boot program 100, and then reads the kernel program 106 to start the boot process of the kernel program 106 (step S5 in FIG. Fig. 4) and the checksum calculation (step S6 in Fig. 4) in parallel.
[0095] When the checksum calculation ends, the CPU 4 refers to the replacement flag and the boot history value for the kernel program 106 and, if the replacement flag and the boot history value are both “1”, goes to step S36 in Fig. 7. If the replacement flag is equal to “0”, it goes to step S7 in Fig. 4; if the replacement flag is "1" and the boot history value is "2", it goes to step S43, which will be described later.
[0096] In step S36, the CPU 4 determines whether the kernel program 106 has any errors. Specifically, if the kernel program 106 boots normally and the calculated checksum value matches the checksum value 107, the CPU 4 determines that there is no error; if the kernel program 106 does not boot normally or if the two checksum values do not match, the CPU 4 determines that there is an error.
[0097] If it is determined that there is no error (NO in step S36), the CPU 4 changes the boot history value for the kernel program 106 to "0" (S37) and replaces the second kernel program backup 110 with the first kernel program backup 108 (S38). The CPU 4 then resets the replacement flag for the kernel program 106 to "0" (S39) and ends the program replacement process. After the program replacement process ends, processing proceeds to step S11 in Fig. 4.
[0098] On the other hand, if it is determined that an error exists (YES in step S36), the CPU 4 replaces the kernel program 106 with the second kernel program backup 110 (S40), changes the boot history value for the kernel program 106 to "2" (S41), and reboots the system (S42). Specifically, the CPU 4 performs a software reset, accesses the boot address, reads and executes the boot program 100, and then reads the kernel program 106 to start the boot process of the kernel program 106 (step S5 in Fig. 4) and the checksum calculation (S6 in Fig. 4) to be carried out in parallel).
[0099] When the checksum calculation ends, the CPU 4 refers to the replacement flag and the boot history value for the kernel program 106 and, if the replacement flag is “1” and the boot history value is “2”, goes to step S43 in Fig. 7.
[0100] In step S43, the CPU 4 determines whether the kernel program 106 has any errors in the same manner as in step S36.
[0101] If it is determined that there is no error (NO in step S43), the CPU 4 informs a user that the new kernel program obtained from the external source is faulty (S44) and terminates the program replacement process. After the program replacement process ends, processing proceeds to step S11 in Fig. 4.
[0102] On the other hand, if it is determined that an error exists (YES in step S43), the CPU 4 returns to step S26 in Fig. 5, reissues the message indicating that a new kernel program must be obtained from an external source, and executes the program replacement process (S27).
[0103] Next, the file replacement process for the application configuration file is explained. If in the file replacement process for the application configuration file A 112, as shown in Fig. 7, the CPU 4 detects that an external memory has been connected to the external interface 6, it reads a new application configuration file for replacement and its checksum value from the external memory and replaces the first application configuration file A backup 116 and the checksum value 117 with the new application configuration file and checksum value (S31).
[0104] When the replacement is completed, the CPU 4 changes the replacement flag at address M+2 for the application configuration file A 112 in the replacement flag information 124 from “0” to “1” (S32).
[0105] The CPU 4 then replaces the application configuration file A 112 and the checksum value 113 with the replaced first application configuration file A backup 116 and checksum value 117 (S33).
[0106] When the replacement is completed, the CPU 4 changes the boot history value for the application configuration file A 112 in the boot history information 126 to "1" (S34) and reboots the application (S35). Specifically, the CPU 4 rereads the application configuration file A 112 in the state in which the system (specifically, the kernel) was booted and executes the boot process of the application configuration file A 112 (step S10 in Fig. 4) and the checksum calculation (step S11 in Fig. 4) in parallel.
[0107] When the checksum calculation ends, the CPU 4 refers to the replacement flag and the boot history value for the application configuration file A 112 and, if the replacement flag and the boot history value are both “1”, goes to step S36 in Fig. 7. If the replacement flag is equal to “0”, it goes to step S12 in Fig. 4; if the replacement flag is "1" and the boot history value is "2", it goes to step S43, which will be described later.
[0108] In step S36, the CPU 4 determines whether the application configuration file A 112 has any errors. Specifically, if the application configuration file A 112 boots normally and the calculated checksum value matches the checksum value 113, the CPU 4 determines that there is no error; if the application configuration file A 112 does not boot normally or if the two checksum values do not match, the CPU 4 determines that there is an error.
[0109] If it is determined that there is no error (NO in step S36), the CPU 4 changes the boot history value for the application configuration file A 112 to "0" (S37) and replaces the second application configuration file A backup 120 with the first application configuration file A backup 116 (S38). The CPU 4 then resets the replacement flag for the application configuration file A 112 to "0" (S39) and terminates the file replacement process. After the file replacement process ends, the CPU 4 enters a wait state.
[0110] On the other hand, if it is determined that an error exists (YES in step S36), the CPU 4 replaces the application configuration file A 112 with the second application configuration file A backup 120 (S40), changes the boot history value for the application configuration file A 112 to "2" (S41), and reboots the application (S42). Specifically, the CPU 4 rereads the application configuration file A 112 in the state in which the system (specifically, the kernel) was booted and executes the boot process of the application configuration file A 112 (step S10 in Fig. 4) and the checksum calculation (step S11 in Fig. 4) in parallel.
[0111] When the checksum calculation ends, the CPU 4 refers to the replacement flag and the boot history value for the application configuration file A 112, and if the replacement flag is “1” and the boot history value is “2”, goes to step S43 in Fig. 7.
[0112] In step S43, the CPU 4 determines whether the application configuration file A 112 has any errors in the same manner as in step S36.
[0113] If it is determined that there is no error (NO in step S43), the CPU 4 informs a user that the new application configuration file obtained from the external source is corrupted (S44) and terminates the file replacement process. After the file replacement process ends, the CPU 4 enters a wait state.
[0114] On the other hand, if it is determined that an error exists (YES in step S43), the CPU 4 goes to step S26 in Fig. 5, reissues the message indicating that a new application configuration file must be obtained from an external source, and executes the file replacement process (S27).
[0115] The file replacement process for the application configuration file B 114 is the same as that for the application configuration file A 112. Backup verification process
[0116] The information processing device 1 may perform a backup checking process to check whether the backup programs and backup files have any errors (the accuracy of the backup programs and backup files) in periods when error detection processes are in the waiting state in the processing in Fig. 4. The periods include in particular the waiting period from the determination of YES in step S3 in Fig. 4 to the start of step S6, the waiting period from the determination of YES in step S7 to the start of step S11, and the waiting period from the determination of YES in step S12 to the end of step S10. Fig. Figure 9 is a flowchart illustrating the backup verification process. The backup verification process is described below with reference to Fig. 9 described.
[0117] The CPU 4 compares the first boot program backup 102 with the second boot program backup 104 to determine whether the two match (S51). If the two do not match (NO in step S51), it proceeds to step S52; if the two match (YES in step S51), it proceeds to step S52.
[0118] In step S52, the CPU 4 calculates the checksum value of both the first boot program backup 102 and the second boot program backup 104, and determines whether the calculated checksum value of the first boot program backup 102 matches the checksum value 103, and whether the calculated checksum value of the second boot program backup 104 matches the checksum value 105. If the checksum value of one of the first boot program backup 102 and the second boot program backup 104 matches, but the checksum value of the other does not match, the CPU 4 replaces the other backup program with the one backup program having the matching checksum value and proceeds to step S53.If both checksum values of the first boot program backup 102 and the second boot program backup 104 do not match, for example, the first boot program backup 102 and the second boot program backup 104 can be replaced with the boot program 100 or a new boot program obtained from an external source.
[0119] In step S53, the CPU 4 compares the first kernel program backup 108 with the second kernel program backup 110 to determine whether the two match. If the two do not match (NO in step S53), it proceeds to step S54; if the two match (YES in step S53), it proceeds to step S55.
[0120] In step S54, the CPU 4 calculates the checksum value of both the first kernel program backup 108 and the second kernel program backup 110, and determines whether the calculated checksum value of the first kernel program backup 108 matches the checksum value 109, and whether the calculated checksum value of the second kernel program backup 110 matches the checksum value 111. If the checksum value of one of the first kernel program backup 108 and the second kernel program backup 110 matches, but the checksum value of the other does not match, the CPU 4 replaces the other backup program with the one backup program having the matching checksum value and proceeds to step S55.If both checksum values of the first kernel program backup 108 and the second kernel program backup 110 do not match, for example, the first kernel program backup 108 and the second kernel program backup 110 can be replaced with the kernel program 106 or a new kernel program obtained from an external source.
[0121] In step S55, the CPU 4 compares the first application configuration file A backup 116 with the second application configuration file A backup 120 to determine whether the two match. If the two do not match (NO in step S55), it proceeds to step S56; if the two match (YES in step S55), it proceeds to step S57.
[0122] In step S56, the CPU 4 calculates the checksum value of both the first application configuration file A backup 116 and the second application configuration file A backup 120, and determines whether the calculated checksum value of the first application configuration file A backup 116 matches the checksum value 117, and whether the calculated checksum value of the second application configuration file A backup 120 matches the checksum value 121. If the checksum value of one of the first application configuration file A backup 116 and the second application configuration file A backup 120 matches, but the checksum value of the other does not match, the CPU 4 replaces the other backup file with the one backup file having the matching checksum value and proceeds to step S57.For example, if both checksum values of the first application configuration file A backup 116 and the second application configuration file A backup 120 do not match, the first application configuration file A backup 116 and the second application configuration file A backup 120 may be replaced with the application configuration file A 112 or a new application configuration file obtained from an external source.
[0123] In step S57, the CPU 4 compares the first application configuration file B backup 118 with the second application configuration file B backup 122 to determine whether the two match. If the two do not match (NO in step S57), it proceeds to step S58; if the two match (YES in step S57), it terminates the backup verification process and enters a wait state.
[0124] In step S58, the CPU 4 performs the same process as in step S56 with respect to the first application configuration file B backup 118 and the second application configuration file B backup 122, and then ends the backup verification process to enter the wait state. Advantages
[0125] The following advantages (1)-(16) can be obtained from the above-described embodiment.
[0126] (1) The information processing device in this embodiment is configured to execute a boot program for performing a boot process of a system, and to perform error detection on the boot program in parallel with the boot process. According to this embodiment, the boot process of the system can be started more quickly compared to a configuration that starts the boot process of the system after performing error detection on the boot program. This enables, for example, faster display of the startup screen of the system. The information processing device in this embodiment performs a reboot of the system using a backup program when an error is detected in the boot program. Thus, when the boot program has an error, the system can be booted with a more reliable boot program.
[0127] With the increasing complexity and sophistication of devices, the amount of data in the boot program, in particular, increases dramatically, resulting in an increase in the processing time of the error detection process on the boot program. The configuration that starts the system boot process after the error detection on the boot program has a problem in that the start of the system boot process is significantly delayed. The present embodiment can solve this problem.
[0128] Fig. Figure 10 is a diagram illustrating processing periods in a configuration that performs boot processes after an error detection. Fig. 10 has a horizontal axis representing time, and shows a processing period T1 of the error detection process of a boot program, a processing period T2 of the boot process of the boot program, a processing period T3 of the error detection process of a kernel program, a processing period T4 of the boot process of the kernel program, a processing period T5 of the error detection processes of the application configuration files, and a processing period T6 of the boot processes of the application configuration files.
[0129] Fig. 11 is a diagram showing processing periods in the configuration of this embodiment. Fig. 11 has a horizontal axis indicating time, and shows a processing period T11 of the error detection process of the boot program, a processing period T12 of the boot process of the boot program, a processing period T13 of the error detection process of the kernel program, a processing period T14 of the boot process of the kernel program, a processing period T15 of the error detection processes of application configuration files, and a processing period T16 of the boot processes of the application configuration files.
[0130] From the Fig. 10 and Fig. 11, it can be seen that the start time of the boot processes of the boot program, kernel program, and application configuration files in this embodiment are earlier than those in the configuration that performs the boot processes after an error detection.
[0131] (2) When an error is detected in the boot program, the information processing device performs a recovery process to replace the boot program stored in the program area with a backup program stored in the backup areas, and reboots the system using the replaced program. According to this aspect, by replacing the faulty boot program with the backup program, it is possible to increase the number of correct boot programs and improve the reliability of system booting.
[0132] (3) When performing the recovery process, the information processing device refers to history information indicating the history of program replacement with backup programs and selects the backup program used for replacement. This enables rebooting with a highly reliable program when an error is detected in the boot program. Specifically, it is possible to select a backup program that does not satisfy the condition that it was used for program replacement and an error was detected in the replaced program (or to select a backup program in which an error was not detected), so that the reboot process can be performed with a more reliable backup program.
[0133] (4) In the recovery process, the information processing device refers to replacement order information indicating the order of backup programs for replacement, and selects the backup program used for replacement based on the replacement order information and history information. According to this aspect, the replacement order can be changed by changing the replacement order information. This makes it possible to delay the use of a backup program recorded in a dead block or a block with a high error detection rate in the non-volatile memory, for example, and preferentially use a more reliable backup program for replacement.The dead block means a block in which normal read or write operations are not possible, such as a block in which the number of rewrite processes has exceeded a predetermined rewrite limit or an initial defective block in a semiconductor device.
[0134] (5) In the recovery process, the information processing device selects a backup program that has not been used for replacement as the backup program used for replacement. According to this aspect, the reboot process can be performed with a highly reliable backup program.
[0135] (6) In the program replacement process for replacing the boot program with a new boot program, the information processing device obtains a new program, replaces a predetermined backup program of the backup programs stored in the backup areas with the new boot program, replaces the boot program stored in the program area with the predetermined backup program, and when the replaced boot program is executed, if there is no error, replaces one or more of the backup programs other than the predetermined backup program with the replaced predetermined backup program or the replaced boot program, and if there is an error, replaces the boot program stored in the program area with a backup program other than the predetermined backup program.According to this aspect, when the boot program is replaced with the new boot program, if the replaced new boot program has an error (for example, if normal booting is not possible, or if an illegal bit change is detected), it is possible to restore the boot program in the program area to its previous state before the replacement while retaining the backup of the new boot program. Therefore, if the new boot program has an error and the system cannot boot, it is possible to prevent a situation where the boot program cannot be restored to the previous boot program and the system cannot boot.
[0136] (7) The information processing device executes an application configuration file to perform a boot process of an application and performs error detection on the application configuration file in parallel with the boot process. According to this aspect, the application boot process can be started faster compared to a configuration that starts the application boot process after performing error detection on the application configuration file. This enables, for example, faster display of the application startup screen. Furthermore, when an error is detected in the application configuration file, the information processing device reboots the application using a backup file. Therefore, if the application configuration file has an error, the application can be booted with a more reliable application configuration file.
[0137] (8) When an error is detected in the application configuration file, the information processing device performs a recovery process to replace the application configuration file stored in the file area with a backup file stored in the backup file areas, and reboots the application with the replaced application configuration file. According to this aspect, by replacing the faulty application configuration file with the backup file, it is possible to increase the number of correct application configuration files and improve the reliability of application booting.
[0138] (9) In the recovery process, the information processing device refers to history information indicating the history of replacing the application configuration file with the backup files and selects the backup file used for the replacement. This makes it possible to perform the reboot with a highly reliable file when an error is detected in the application configuration file. Specifically, it is possible to select a backup file that is not subject to the condition that it was used to replace the application configuration file and an error was detected in the replaced application configuration file (or to select a backup file in which an error was not detected), so that the reboot process can be performed with a more reliable backup file.
[0139] (10) In the recovery process, the information processing device refers to replacement order information indicating the order of backup files for replacement, and selects the backup file to be used for replacement based on the replacement order information and history information. According to this aspect, the replacement order can be changed by changing the replacement order information. This allows, for example, delaying the use of a backup file recorded in a dead block or a block with a high error detection rate in the non-volatile memory and preferentially using a more reliable backup file for replacement.
[0140] (11) In the recovery process, the information processing device selects a backup file that has not been used for replacement as the backup file used for replacement. According to this aspect, the reboot process can be performed with a highly reliable backup file.
[0141] (12) In the file replacement process for replacing the application configuration file with a new application configuration file, the information processing device obtains a new application configuration file, replaces a predetermined backup file of the backup files stored in the backup file areas with the new application configuration file, replaces the application configuration file stored in the file area with the predetermined backup file, and when the replaced application configuration file is executed, if there is no error, replaces one or more of the backup files other than the predetermined backup file with the replaced predetermined backup file or the replaced application configuration file, and if there is an error, replaces the application configuration file stored in the file area with a backup file other than the predetermined backup file.According to this aspect, when the application configuration file is replaced with the new application configuration file, if the replaced new application configuration file has an error (for example, if normal booting is not possible, or if an illegal bit change is detected), it is possible to restore the application configuration file in the file space to its previous state before the replacement while retaining the backup in the new application configuration file. Therefore, if the new application configuration file has an error and the application cannot boot, it is possible to prevent a situation where the application configuration file cannot be restored to its previous application configuration file and the application cannot boot.
[0142] (13) The file area in the non-volatile memory stores a plurality of application configuration files such that the plurality of application configuration files can be read in units of application configuration files. According to this aspect, data can be transferred from the non-volatile memory to the work area for each application configuration file, and the transfer time to the working memory can therefore be reduced.
[0143] (14) The file area in the non-volatile memory stores the plurality of application configuration files and the error detection data for each of the plurality of application configuration files. In this aspect, since the error detection data (for example, the checksum value) is individually appended to each of the application configuration files, the processing time for error detection using the error detection data (for example, the checksum value calculation time) can be reduced compared to a case where error detection data (for example, a checksum value) is appended to a file group containing the plurality of application configuration files.
[0144] (15) The information processing device performs error detection on the backup programs stored in the backup areas, and replaces a backup program in which an error has been detected with a backup program in which no error has been detected. According to this aspect, the reliability of the backup programs can be improved. This makes it possible, for example, to suppress the possibility that the replacement of the boot program with a backup program in step S23 in the reboot process (S4 or S8) in Fig. 4 is determined to be impossible.
[0145] (16) The information device performs error detection on the backup files stored in the backup file areas, and replaces a backup file in which an error has been detected with a backup file in which no error has been detected. According to this aspect, the reliability of the backup files can be improved. This makes it possible, for example, to suppress the possibility that the replacement of the application configuration file with a backup file in step S23 in the reboot process (S13) in Fig. 4 is determined to be impossible.
[0146] The present invention is not limited to the embodiment described above; it can be practiced in various other aspects without departing from the inventive scope.
[0147] For example, the above description illustrates a configuration that, when an error is detected in a boot program, replaces the boot program with a backup program (the recovery process) and then reboots the system. However, the information processing device 1 may read the backup program into the RAM 3 to reboot the system without replacing the boot program (the recovery process). Similarly, the information processing device 1 may read the backup file into the RAM 3 to reboot the application without replacing the application configuration file with the backup file (the recovery process). Regarding the boot program (specifically, the boot program 100) that is first read and executed by the boot programs, the recovery process is necessary when the boot address is fixed.However, in a configuration where the boot address can be changed, by changing the boot address to the start address of the backup program, it is possible to perform the reboot without the recovery process.
[0148] The above description illustrates a configuration in which the non-volatile memory 2 stores a plurality of backup programs. However, the number of backup programs is not limited to a plurality and can be one. The same applies to backup files.
[0149] The above description represents a case where two files, Application Configuration File A 112 and Application Configuration File B 114, are used as the application configuration file. However, the number of application configuration files can be one or more. In practice, more application configuration files are often required.
[0150] The above description represents a configuration in which the process execution unit 11 and error detection unit 12 are implemented by the same CPU 4 and the same programs, but the error detection unit 12 may be implemented in the following forms (a)-(d).
[0151] (a) The error detection unit 12 is implemented by executing, by the CPU 4, error detection programs different from the boot programs.
[0152] (b) The error detection unit 12 is implemented by executing, by a CPU different from the CPU 4, error detection processes described either in the boot programs or in error detection programs different from the boot programs.
[0153] (c) The CPU 4 includes a plurality of processor cores, the process execution unit 11 is implemented by one or more of the processor cores, and the error detection unit 12 is implemented by executing, by another or more of the processor cores, error detection processes described either in the boot programs or in error detection programs different from the boot programs.
[0154] (d) The error detection unit 12 is implemented by a hardware error detection circuit.
[0155] In a configuration that executes the boot processes and error detection processes in parallel by different processing devices as in (b) to (d) above, the boot processes and error detection processes can actually be executed in parallel, and the boot time can be reduced, compared with the configuration that starts the boot process of the system after error detection at the boot program.
[0156] Fig. 12 is a diagram illustrating processing periods in a configuration that executes the boot processes and the error detection processes in parallel by different processing devices. Fig. 12 has a horizontal axis representing time, and shows a processing period T21 of the error detection process of the boot program, a processing period T22 of the boot process of the boot program, a processing period T23 of the error detection process of the kernel program, a processing period T24 of the boot process of the kernel program, a processing period T25 of the error detection processes of the application configuration files, and a processing period T26 of the boot processes of the application configuration files.
[0157] From the Fig. 10 and Fig.12, it can be seen that in the configuration that executes the boot processes and the error detection processes in parallel by different processing devices, the end times of the respective boot processes of the boot program, kernel program, and application configuration files are earlier than those in the configuration that executes the boot processes after error detection.
[0158] Like the error detection unit 12, the reboot unit 13 and replacement control unit 14 can be implemented in the forms (a) to (d) described above.
[0159] The above description represents the boot history values indicating the replacement sources of the programs as the history information indicating the history of replacing the programs with the backup programs. However, the history information is not limited to this and may, for example, be information indicating backup programs used to replace the program in the past. The history information may be prepared for each backup program. For each of the backup programs, for example, a history flag indicating whether the backup program was used to replace the past program may be recorded in the non-volatile memory 2. The history flag is "0" if the backup program was not used for replacement, and is "1" if the backup program was used for replacement, for example. The same applies to the application configuration files.
[0160] The above description represents a configuration that selects a backup program that has not been used for replacement based on the history information, however, a different backup program may be selected. For example, in a non-volatile memory, if a read operation has not been performed on a block for a long period of time, the data content in the block may be unduly changed over time due to charge leakage. The risk of charge leakage occurring can be suppressed by sequencing the backup programs as evenly as possible in the recovery processes. From this point of view, the reboot unit 13 may be configured to select a backup program that has not been read for a long period of time based on the history information. This configuration can prevent charge leakage in the non-volatile memory.For example, the backup program that hasn't been read for a long period of time includes the backup program that hasn't been read for the longest period of time among the backup programs, and a backup program that hasn't been read for a predetermined period of time. In this configuration, the history information shows, for example, a time period for each of the backup programs during which the backup program hasn't been read. Reference symbol
[0161] 1 information processing device, 2 non-volatile memory, 3 random access memory, 4 CPU, 5 communication unit, 6 external interface, 10 parallel processing unit, 11 process execution unit, 12 error detection unit, 13 reboot unit, 14 replacement control unit, 100 boot program, 101, 103, 105, 107, 109, 111, 11, 115, 117, 119, 121, 123 checksum value, 102 first boot program backup, 104 second boot program backup, 106 kernel program, 108 first kernel program backup, 110 second kernel program backup, 112 application configuration file A, 114 application configuration file B, 116 first application configuration file A backup, 118 first application configuration file B backup, 120 second application configuration file A backup, 122 second application configuration file B backup, 124 replacement flag information, 126 boot history information, 128 replacement order information.
Claims
[1] Information processing device comprising: a non-volatile memory having a program area storing a program for booting a system and a plurality of backup areas each storing a backup program identical in content to the program; a process execution means for executing the program stored in the program area to perform a boot process of the system; error detection means for performing error detection on the program stored in the program area in parallel with the boot process by the process execution means; and a reboot means for, when the error detection means detects an error in the program, performing a recovery process for replacing the program stored in the program area with one of the backup programs stored in the backup areas, and rebooting the system using the replaced program stored in the program area; wherein when performing the recovery process, the reboot means refers to history information indicating a history of replacement of the program with the backup programs, selects the backup program among the backup programs based on the history information to be used for replacement, and replaces the program with the selected backup program. [2] The information processing apparatus according to claim 1, wherein in the recovery process, the reboot means further refers to replacement order information indicating an order of the backup programs for replacement, selects the backup program for replacement among the backup programs based on the replacement order information and the history information, and replaces the program with the selected backup program. [3] The information processing apparatus according to claim 1 or 2, wherein the backup program selected in the restoration process is a backup program that has not been used for replacement. [4] The information processing apparatus according to any one of claims 1 to 3, further comprising replacing means for performing a program replacing process for replacing the program with a new program which has not been stored in the backup areas, wherein in the program replacing process, the replacing means receives the new program, replaces a predetermined backup program of the backup programs stored in the backup program areas with the new program, replaces the program stored in the program area with the predetermined backup program, and when the replaced program is executed, if there is no error, replaces one or more of the backup programs other than the predetermined backup program with the replaced predetermined backup program or the replaced program, and if there is an error, replaces the program stored in the program area with one of the backup programs other than the predetermined backup program. [5] The information processing apparatus according to claim 4, wherein, when the error detecting means detects an error in the program when the backup areas do not include a backup program that has not been used for replacement, the replacing means performs the program replacement process. [6] Information processing apparatus according to any one of claims 1 to 5, wherein: the non-volatile memory further comprises a file area that stores an application configuration file for booting an application, and one or more backup file areas, each storing a backup file that is identical in content to the application configuration file; wherein the process execution means executes the application configuration file stored in the file space to perform a boot process of the application; the error detection means performs error detection on the application configuration file stored in the file area in parallel with the boot process of the application by the process execution means; and if the error detecting means detects an error in the application configuration file, the rebooting means reboots the application using one of the one or more backup files stored in the one or more backup file areas. [7] The information processing apparatus according to claim 6, wherein when the error detecting means detects an error in the application configuration file, the rebooting means performs a restoration process of restoring the application configuration file stored in the file area with one of the one or more backup files stored in the one or more backup file areas, and reboots the application using the replaced application configuration file stored in the file area. [8] An information processing apparatus according to claim 7, wherein: the number of one or more backup file areas is plural; and when performing the restore process, the reboot means refers to history information indicating a history of replacement of the application configuration file with the backup files, selects the backup file to be used for the replacement from among the backup files stored in the backup file areas based on the history information, and replaces the application configuration file with the selected backup file. [9] The information processing apparatus according to claim 8, wherein the reboot means, in the restoration process, further refers to replacement order information indicating an order of the backup files for replacement, selects the backup file used for replacement among the backup files based on the replacement order information and the history information, and replaces the application configuration file with the selected backup file. [10] Information processing apparatus according to any one of claims 7 to 9, wherein: the number of one or more backup file areas is plural; and the reboot agent, when performing the restore process, selects a backup file that was not used for replacement from among the backup files stored in the backup file areas, and replaces the application configuration file stored in the file area with the selected backup file. [11] Information processing apparatus according to any one of claims 6 to 10, wherein: the number of one or more backup file areas is plural; the replacement means performs a file replacement process to replace the application configuration file with a new application configuration file; and the replacing means, in the file replacing process, receives the new application configuration file, replaces a predetermined backup file of the backup files stored in the backup file areas with the new application configuration file, replaces the application configuration file stored in the file area with the predetermined backup file, and when the replaced application configuration file is executed, if there is no error, replaces one or more of the backup files other than the predetermined backup file with the replaced predetermined backup file or the replaced application configuration file, and if there is an error, replaces the application configuration file stored in the file area with one of the backup files other than the predetermined backup file. [12] The information processing apparatus according to claim 11, wherein, when the error detecting means detects an error in the application configuration file when the backup file areas do not include a backup file that has not been used for replacement, the replacing means performs the file replacement process. [13] Information processing apparatus according to any one of claims 6 to 12, wherein: the file area stores a plurality of application configuration files each serving as the application configuration file, such that the plurality of application configuration files can be read in units of one application configuration file; and each of the one or more backup file areas stores a plurality of backup files that are identical in content to the plurality of application configuration files. [14] An information processing apparatus according to claim 13, wherein: the file area further stores error capture data for each of the application configuration files; the error detection means performs error detection on the application configuration files stored in the file area using the error detection data for the application configuration files. [15] Information processing methods comprising: a process execution step of executing a program for booting a system stored in a non-volatile memory to perform a boot process of the system, the non-volatile memory having a program area storing the program and a plurality of backup areas each storing a backup program identical in content to the program; an error detection step for performing error detection on the program stored in the program area, in parallel with the boot process in the process execution step; and a reboot step for performing a recovery process when the error detection step detects an error in the program to replace the program stored in the program area with one of the backup programs stored in the backup areas, and rebooting the system using the replaced program stored in the program area; wherein the reboot step, when performing the restore process, refers to history information that shows a history of replacement of the program with the backup programs, selects the backup program among the backup programs to be used for replacement based on the history information, and replaces the program with the selected backup program. [16] The information processing method according to claim 15, wherein the reboot step in the restoration process further refers to replacement order information indicating an order of the backup programs for replacement, selects the backup program used for replacement among the backup programs based on the replacement order information and the history information, and replaces the program with the selected backup program. [17] The information processing method according to claim 15 or 16, wherein the backup program selected in the recovery process is a backup program that has not been used for replacement. [18] The information processing method according to any one of claims 15 to 17, further comprising a replacing step of performing a program replacing process for replacing the program with a new program that has not been stored in the backup areas, the replacing step receiving the new program in the program replacing process, replacing a predetermined backup program of the backup programs stored in the backup program areas with the new program, replacing the program stored in the program area with the predetermined backup program, and when the replaced program is executed, if there is no error, replacing one or more of the backup programs other than the predetermined backup program with the replaced predetermined backup program or the replaced program, and if there is an error, replacing the program stored in the program area with one of the backup programs other than the predetermined backup program. [19] The information processing method according to claim 18, wherein, when the error detecting step detects an error in the program when the backup areas do not include a backup program that has not been used for replacement, the program replacement process is performed. [20] Information processing method according to one of claims 15 to 19, wherein: the non-volatile memory further comprises a file area that stores an application configuration file for booting an application, and one or more backup file areas, each storing a backup file that is identical in content to the application configuration file; the process execution step executes the application configuration file stored in the file space to perform a boot process of the application; the error detection step performs error detection on the application configuration file stored in the file area, in parallel with the boot process of the application in the process execution step; and if the error detection step detects an error in the application configuration file, the reboot step reboots the application using one of the one or more backup files stored in the one or more backup file areas. [21] The information processing method according to claim 20, wherein, when the error detecting step detects an error in the application configuration file, the rebooting step performs a recovery process of replacing the application configuration file stored in the file area with one of the one or more backup files stored in the one or more backup file areas and rebooting the application using the replaced application configuration file stored in the file area. [22] An information processing method according to claim 21, wherein: the number of one or more backup file areas is plural; and the reboot step, when performing the restore process, refers to history information indicating a history of replacing the application configuration file with the backup files, selects the backup file to be used for the replacement from among the backup files stored in the backup file areas based on the history information, and replaces the application configuration file with the selected backup file. [23] The information processing method according to claim 22, wherein the reboot step in the restoration process further refers to replacement order information indicating an order of the backup files for replacement, selects the backup file used for replacement among the backup files based on the replacement order information and the history information, and replaces the application configuration file with the selected backup file. [24] Information processing method according to one of claims 21 to 23, wherein: the number of one or more backup file areas is plural; and the reboot step, when performing the restore process, selects a backup file that was not used for replacement from among the backup files stored in the backup file areas, and replaces the application configuration file stored in the file area with the selected backup file. [25] Information processing method according to one of claims 21 to 24, wherein: the number of one or more backup file areas is plural; the replacing step performs a file replacement process to replace the application configuration file with a new application configuration file; and the replacement process in the file replacement process receives the new application configuration file, replaces a predetermined backup file of the backup files stored in the backup file areas with the new application configuration file, replaces the application configuration file stored in the file area with the predetermined backup file, and when the replaced application configuration file is executed, if there is no error, replaces one or more of the backup files other than the predetermined backup file with the replaced predetermined backup file or the replaced application configuration file, and if there is an error, replaces the application configuration file stored in the file area with one of the backup files from the predetermined backup file. [26] The information processing method according to claim 25, wherein, when the error detecting step detects an error in the application configuration file, if the backup file areas do not include a backup file that has not been used for replacement, the file replacement process is performed. [27] Information processing method according to one of claims 20 to 26, wherein: the file area stores a plurality of application configuration files, each serving as the application configuration file, such that the plurality of application configuration files can be read in units of one application configuration file; and each of the one or more backup file areas stores a plurality of backup files that are identical in content to the plurality of application configuration files. [28] An information processing method according to claim 27, wherein: the file area further stores error capture data for each of the application configuration files; the error detection step performs error detection on the application configuration files stored in the file space using the error detection data for the application configuration files. [29] Computer program that causes a computer to perform: a process execution step of executing a program for booting a system stored in a non-volatile memory to perform a boot process of the system, the non-volatile memory having a program area storing the program and a plurality of backup areas each storing a backup program identical in content to the program; an error detection step for performing error detection on the program stored in the program area, in parallel with the boot process in the process execution step; and a reboot step for, when the error detection step detects an error in the program, performing a recovery process for replacing the program stored in the program area with one of the backup programs stored in the backup areas and rebooting the system using the replaced program stored in the program area; wherein the reboot step, when performing the restore process, refers to history information that shows a history of replacing the program with the backup programs, selects the backup program among the backup programs to be used for the replacement based on the history information, and replaces the program with the selected backup program.
Citation Information
Patent Citations
Fault tolerant recovery block with reduced flash footprint
US20040268116A1
BIOS, computer device and method for recovering BIOS
US20100205423A1
Method for protecting redundant data
US20110093675A1
Information processing system capable of updating a BIOS programme without interrupting or stopping the operational of a system
US5835761A