Information processing device, information processing method and computer program
Patent Information
- Application Number
- DE112012005589
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2012-06-11
- Publication Date
- 2025-07-10
- Estimated Expiration
- 2032-06-11
AI Technical Summary
NAND-type flash memories suffer from inferior data reliability due to bit errors caused by charge loss during repeated reads, leading to potential system boot failures or hangs, and existing solutions delay the boot process with error detection and recovery.
An information processing apparatus with a non-volatile memory system that stores boot programs and backup programs, performing error detection in parallel with boot processes, and using backup programs for recovery to quickly reboot with reliable programs.
Enables fast system booting with reliable programs by replacing faulty programs with backups, reducing boot delay and improving reliability.
Abstract
Description
Technical field
[0001] The present invention relates to an information processing device, an information processing method and a computer program. State of the art
[0002] Recently, NAND-type flash memory, which is a type of non-volatile memory, has seen widespread use. Compared to NOR-type flash memory, NAND-type flash memory offers the advantage of higher capacity and lower cost per bit, but suffers from lower data reliability. This is because bit errors can occur due to charge loss when stored data is repeatedly read. Therefore, if a system boot program is stored in NAND-type flash memory, such bit errors can cause the system to fail to boot or hang after booting.
[0003] Patent document 1 describes a control device that reads a first boot program from non-volatile system memory and performs error detection on the first program. If it determines that the first boot program has been improperly modified, it reads a second boot program from non-volatile backup memory and performs error detection on the second boot program. If it determines that the second boot program has been improperly modified, it outputs an error message. If, as a result of the error detection on either the first or second boot program, the control device determines that the boot program has not been improperly modified, it executes a boot process using the boot program. State of the art documents
[0004] Patent document 1: Japanese patent application with publication number 2010-26650 Summary of the invention Problems to be solved by the invention
[0005] The control device described in patent document 1 performs error detection on the boot program read from the non-volatile system memory. If, as a result of this error detection, it determines that the boot program has not been improperly modified, it starts the boot process using the boot program. One problem, therefore, is that the start of the boot process is delayed.
[0006] An object of the present invention is to provide an information processing device, an information processing method and a computer program that can quickly start a boot process of a system and perform a reboot with a highly reliable program when an error is detected in a boot program. Means of solving the problems
[0007] An information processing device according to the present invention comprises: a non-volatile memory with a program area that stores a program for booting a system, and a plurality of backup areas, each storing a backup program identical in content to the program; a process execution means for executing the program stored in the program area to perform a boot process of the system; an error detection means for performing error detection on the program stored in the program area, in parallel with the boot process by the process execution means;and a reboot means for, when the error detection means detects an error in the program, performing a recovery process to replace the program stored in the program space with one of the backup programs stored in the backup spaces, and rebooting the system using the replaced program stored in the program space; wherein, when performing the recovery process, the reboot means refers to history information showing a history of replacing the program with the backup programs, selects the backup program from among the backup programs based on the history information to be used for the replacement, and replaces the program with the selected backup program.
[0008] An information processing method according to the present invention comprises: a process execution step for executing a program for booting a system, stored in non-volatile memory, for performing a boot process of the system, wherein the non-volatile memory has a program area that stores the program and a plurality of backup areas, each storing a backup program that is identical in content to the program; an error detection step for performing error detection on the program stored in the program area, in parallel with the boot process in the process execution step;and a reboot step to perform a recovery process when the error detection step detects an error in the program, to replace the program stored in the program area with one of the backup programs stored in the backup areas, and reboot the system using the replaced program stored in the program area; wherein, when performing the recovery process, the reboot step refers to history information that shows a history of replacing the program with the backup programs, selects the backup program from among the backup programs to be used for replacement based on the history information, and replaces the program with the selected backup program.
[0009] A computer program according to the present invention causes a computer to execute: a process execution step for executing a program for booting a system, stored in non-volatile memory, for performing a boot process of the system, wherein the non-volatile memory comprises a program area that stores the program and a plurality of backup areas, each storing a backup program that is identical in content to the program; an error detection step for performing error detection on the program stored in the program area, in parallel with the boot process in the process execution step;and a reboot step to perform, if the error detection step detects an error in the program, a recovery process to replace the program stored in the program area with one of the backup programs stored in the backup areas and reboot the system using the replaced program stored in the program area; wherein, when performing the recovery process, the reboot step refers to history information that shows a history of replacing the program with the backup programs, selects the backup program from among the backup programs to be used for replacement based on the history information, and replaces the program with the selected backup program. Effect of the invention
[0010] According to the present invention, it is possible to quickly start a boot process of a system and to perform a reboot with a highly reliable program when an error is detected in a boot program. Brief description of the drawings
[0011] Fig. Figure 1 is a block diagram for the schematic representation of the configuration of an information processing device in one embodiment.
[0012] Fig. Figure 2 is a schematic diagram illustrating the storage format of a non-volatile memory.
[0013] Fig. Figure 3 is a block diagram illustrating the functional configuration of the information processing device in the embodiment.
[0014] Fig. Figure 4 is a flowchart illustrating the operation of the information processing device in the embodiment.
[0015] Fig. Figure 5 is a flowchart illustrating a reboot process.
[0016] Fig. Figure 6 is a schematic diagram illustrating the format of boot history information.
[0017] Fig. Figure 7 is a flowchart to illustrate a program (or file) replacement process.
[0018] Fig. Figure 8 is a schematic diagram illustrating the format of replacement flag information.
[0019] Fig. Figure 9 is a flowchart illustrating a backup verification process.
[0020] Fig. Figure 10 is a schematic diagram illustrating processing periods in a configuration that performs boot processes after an error detection.
[0021] Fig. Figure 11 is a schematic diagram illustrating processing periods in the configuration of the embodiment.
[0022] Fig. Figure 12 is a schematic diagram illustrating processing periods in a configuration that performs boot processes and error detection processes in parallel through different processing devices. Modes for carrying out the invention
[0023] One embodiment of the invention will now be explained with reference to the drawings.
[0024] Configuration of an information processing device Fig. Figure 1 is a block diagram for the schematic representation of the configuration of an information processing device. 1 according to this embodiment. The information processing device 1 according to Fig. 1 contains a non-volatile memory 2 , a working memory 3 , a central processing unit (CPU) 4 , a communication unit 5 and an external interface (external IF) 6 .
[0025] The non-volatile memory 2 It is a readable and writable memory, such as NAND-type flash memory, that stores a variety of programs and data. Non-volatile memory 2 It contains a program area that stores a program (hereinafter referred to as the "boot program") for booting a system, and one or more backup areas, each storing a backup program (also referred to as the copied program) that is identical in content to the boot program. The system referred to above is, in particular, a computer system, more precisely the computer system (based around the CPU). 4 ) the information processing device 1 In this example, the non-volatile memory contains 2Furthermore, a data area that stores an application configuration file for booting an application, and one or more backup file areas, each storing a backup file (also referred to as the copied file) that is identical in content to the application configuration file. The number of backup areas and backup file areas is also multiple. The non-volatile memory 2 For each of the boot program, backup programs, application configuration file, and backup files, it stores error capture data to capture errors in the program or file.
[0026] The RAM 3 is powered by the CPU 4 It is used as working memory and stores programs and data that are accessed from non-volatile memory. 2 be read.
[0027] The CPU 4executes programs, such as the one in the non-volatile memory. 2 Stored boot program. The non-volatile memory 2 The CPU, in particular, stores programs and data in blocks; it stores programs and data in blocks. 4 reads (or copies) necessary blocks from non-volatile memory 2 into RAM 3 , performs an access to the working memory 3 through and executes processes described in the program that is loaded into memory 3 is read.
[0028] If the CPU 4 communicates with an external device (externally connected device) via the external interface 6 with the information processing device 1 Once connected, the communication unit transforms 5 the sent and received data according to the communication protocol for communication with the externally connected device.
[0029] The external interface 6 is an interface, such as a Universal Serial Bus (USB) interface, for connecting the information processing device 1 with the externally connected device.
[0030] Fig. Figure 2 is a schematic diagram illustrating the storage format of non-volatile memory. 2 In the example of the Fig. 2. Non-volatile memory stores 2 a boot program 200 to perform a boot process after the system reset of the information processing device 1 and a kernel program 106 for booting an operating system (OS), serving as the boot program. The non-volatile memory 2 In addition, an application configuration file A is stored. 112 and an application configuration file B 114, which each serve as the application configuration file and are each required to boot an application that works with the kernel.
[0031] The non-volatile memory 2 Furthermore, as backup programs, it saves an initial boot program backup. 102 and a second boot program backup 104 , which are identical in content to the boot program 100 are, and a first kernel program backup 108 and a second kernel program backup 110 , each of which is identical in content to the kernel program 106 are. The non-volatile memory 2 It also saves, as backup files, an initial application configuration file A-backup. 116 and a second application configuration file A backup 120 , each identical in content to the application configuration file A 112 are, as well as an initial application configuration file B backup 118and a second application configuration file B backup 122 , which are identical in content to the application configuration file B 114 are.
[0032] Respective checksum values 101 , 103 , 105 , 107 , 109 , 111 , 113 , 115 , 117 , 119 , 121 and 123 will be included in the boot program 100 , first boot program backup 102 , second boot program backup 104 , Kernel program 106 , first kernel program backup 108 , second kernel backup program 110 , Application configuration file A 112 , Application configuration file B 114 , first application configuration file A backup 116 , first application configuration file B backup 118 , second application configuration file A backup 120 and second application configuration file B backup 122, which are stored in non-volatile memory 2 are stored and attached as corresponding error recording data.
[0033] As in Fig. Shown in 2 are the boot program 100 and its checksum value 101 stored in the same block B1; the first boot program backup 102 and its checksum value 103 are stored in the same block B2; the second boot program backup 104 and its checksum value 105 are stored in the same block B3. Block B1 is a program area (also called the original block); blocks B2 and B3 are backup areas (also called the copied blocks). The kernel program 106 and its checksum value 107 are stored in the same block B4; the first kernel program backup 108 and its checksum value 109 are stored in the same block B5; the second kernel program backup 110and its checksum value 111 are stored in the same block B6. Block B4 is a program area (also referred to as the original area); blocks B5 and B6 are backup areas (also referred to as the copied blocks). Regarding the application configuration files, the application configuration file A 112 and its checksum value 113 and the application configuration file B 114 and its checksum value 115 stored in the same block B7; the first application configuration file A backup. 116 and its checksum value 117 and the first application configuration file B backup 118 and its checksum value 119 are stored in the same block B8; the second application configuration file A backup 120 and its checksum value 121 and the second application configuration file B backup 122 and its checksum value 123are stored in the same block B9. Block B7 is a file area (also referred to as the original area); blocks B8 and B9 are backup file areas (also referred to as the copied blocks).
[0034] Furthermore, the non-volatile memory stores 2 a replacement flag information 124 , which is used in a program replacement process and a file replacement process, which will be explained later, as well as boot history information. 126 for recording system boot history. The non-volatile memory 2 can also include replacement order information 128 save, which enters a sequence of backup programs to replace.
[0035] Fig. Figure 2 shows an example of the storage format of non-volatile memory. 2 However, the storage format is not limited to this.
[0036] The boot program100 is programmed so that the CPU 4 the boot program 100 itself and its checksum value 101 , stored in non-volatile memory 2 , to the RAM 3 transferred, an initialization process of the information processing device 1 performs, and then the read target jump to the kernel program 106 executes. The boot program 100 This describes a boot process. The boot program 100 is programmed in the same way, so that the CPU 4 , in parallel with the boot process, an error detection process is executed, which performs a checksum calculation on the boot program 100 performs actions that put into working memory 3 is transferred, and the result of the calculation with the checksum value 101 compares to check if the boot program 100 exhibits any errors (or the error-free operation of the boot program)100 The boot program 100 This describes the error detection process and a parallel control system for the parallel execution of the boot process and error detection process.
[0037] The kernel program 106 is programmed so that the CPU 4 the kernel program 106 itself and its checksum value 107 , stored in non-volatile memory 2 , to the RAM 3 transferred, and executes a system control process that performs a system setting, such as activating peripheral devices including the communication unit 5 The kernel program 106 This describes a boot process for booting the operating system. The kernel program 106 It is also programmed so that the CPU 4 , in parallel with the system control process, executes an error detection process that performs a checksum calculation on the kernel program106 performs actions that put into working memory 3 was transferred, and the result of the calculation with the checksum value 107 in the working memory 3 compares to check if the kernel program 106 exhibits any errors (or the error-free nature of the kernel program) 106 The kernel program 106 This describes the error detection process and a parallel control system for the parallel execution of the boot process and error detection process.
[0038] The application configuration file A 112 This happens after the kernel program boots. 106 executed, and is programmed to cause the CPU 4 the application configuration file A 112 themselves and their checksum value 113 , stored in non-volatile memory 2 , into RAM 3transferred and executes a predetermined process to boot an application. The application configuration file A 112 This describes a boot process for booting the application. The application configuration file A 112 It is also programmed so that the CPU 4 , in parallel with the above process, an error detection process is executed, which performs a checksum calculation on the application configuration file A 112 performs actions that are executed in working memory 3 was transferred, and the result of the calculation with the checksum value 113 in the working memory 3 compares to check if the application configuration file A 112 exhibits any errors (or the error-free status of the application configuration file A) 112 The application configuration file A 112This describes the error detection process and a parallel control system for the parallel execution of the boot process and error detection process.
[0039] The application configuration file B 114 is similar to the application configuration file A 112 , and also describes a boot process, an error detection process and parallel control.
[0040] Furthermore, both the boot program and the boot program are described. 100 , Kernel program 106 , Application configuration file A 112 and application configuration file B 114 a reboot process and a replacement control.
[0041] Fig. Figure 3 is a block diagram illustrating the functional configuration of the information processing device. 1 according to this embodiment. The information processing device 1 according to Fig. 3 contains a parallel processing unit 10, a process execution unit 11 , an error detection unit 12 , a reboot unit 13 and a replacement control unit 14 .
[0042] The parallel processing unit 10 , Process execution unit 11 , fault detection unit 12 , Reboot unit 13 and replacement control unit 14 are through a design, through the CPU 4 , which implements parallel controls, boot processes, error detection processes, reboot processes or replacement controls that are included in the boot program 100 , Kernel program 106 , Application configuration file A 112 or application configuration file B 114 are described.
[0043] The parallel processing unit 10The control system enables the parallel processing of multiple processes, including boot processes and error detection processes, through time division. The parallel processing unit 10 The CPU, in particular, controls 4 , so that it performs multiple processes in parallel, by dividing the CPU's processing time 4 into small segments and an allocation of the small time segments to the processes in sequence.
[0044] The process execution unit 11 executes the boot programs located in the program areas in the non-volatile memory. 2 are stored to perform the boot processes for booting the system. The process execution unit 11 In particular, it executes the boot process, which is part of the boot program. 100 The program described, which is called after the system reset, executes the boot process that is defined in the kernel program. 106As described, this is done by the boot program 100 is called and executes the boot processes specified in the application configuration file A 112 and the application configuration file B 114 are described, which executes a process to boot the applications. The process execution unit. 11 Furthermore, it can perform arithmetic processing or other processing on the applications.
[0045] Parallel to the boot processes by the process execution unit 11 The error detection unit 12 The error detection unit performs a scan of the boot programs and application configuration files stored in the program areas to verify that these files are error-free. 12 This particularly includes error detection in the boot program. 100 , Kernel program 106, Application configuration file A 112 and application configuration file B 114 using the respective error recording data. The error recording unit 12 In particular, it calculates checksum values for the boot program. 100 , Kernel program 106 , Application configuration file A 112 and application configuration file B 114 , which are stored in non-volatile memory 2 The calculated checksum values are stored and are compared with the corresponding checksum values previously stored in the non-volatile memory. 2 are stored to detect whether the boot programs and files have been improperly modified, and informs the reboot unit. 13 the data collection results.
[0046] If the fault detection unit 12 an error in a boot program (the boot program) 100 or kernel program 106 ) detected, the reboot unit performs13 a system reboot using a backup program (the first boot program backup) 102 , second boot program backup 104 , first kernel program backup 108 or second kernel program backup 110 ) which are stored in backup areas to prevent the system from failing or hanging during boot. In this example, if the error capture unit 12 If an error is detected in a boot program, the reboot unit performs the necessary actions. 13 It performs a recovery process to replace the boot program stored in the program area with a backup program stored in the backup areas, and reboots the system using the replaced boot program. During the recovery process, the reboot unit references 13Based on a history information displaying a history of boot program replacements with backup programs (or history information relating to a history where the boot program was replaced with backup programs), the system selects the backup program to be used for the replacement from among the backup programs based on the history information and replaces the boot program stored in the program area with the selected backup program. The history information is stored in the boot history information. 126 in the non-volatile memory 2 Included. The reboot unit 13Furthermore, it can refer to replacement order information that displays a sequence of backup programs for replacement, select the backup program to be used for replacement from among the backup programs based on the replacement order information and history information, and replace the boot program stored in the program area with the selected backup program. The replacement order information displays a sequence in which the backup programs are to be used for replacement and is contained within the replacement order information. 128 in the non-volatile memory 2 Included. When the recovery process is performed, the reboot unit selects. 13The backup program to be used for replacement in the recovery process is selected based on the history information, so that the backup programs are used in the order indicated by the replacement order information. When the recovery process is performed, the reboot unit selects the appropriate program. 13 In one aspect, based on the history information (or the history information and replacement order information), a backup program that was not used for replacement is selected from among the backup programs stored in the backup areas, and the boot program stored in the program area is replaced with the selected backup program. If, on the other hand, the error detection unit 12 If an error is detected in the boot program, the reboot unit will initiate the process. 13 , if the backup areas do not contain a backup program that was not used for the replacement, that the replacement control unit14 executes the program replacement process, which will be described later.
[0047] If the fault detection unit 12 detected an error in an application configuration file (the application configuration file A) 112 or B 114 ) leads the reboot unit 13 reboot the application using a backup file (in the first application configuration file A backup). 116 , second application configuration file A backup 120 , first application configuration file B backup 118 or second application configuration file B backup 122 ), which is stored in the backup file areas. If, in this example, the error detection unit 12 If an error is detected in an application configuration file, the reboot unit will perform the following actions. 13A recovery process is performed to replace the application configuration file stored in the file area with a backup file stored in the backup file areas, and the application is rebooted using the replaced application configuration file. When the recovery process is performed, the reboot unit references 13 Based on a history information displaying a history of the replacement of the application configuration file with the backup files (or a history of when the application configuration file was replaced with the backup files), the system selects the backup file to use for replacement from among the backup files based on the history information and replaces the application configuration file stored in the file space with the selected backup file. The history information is stored in the boot history information. 126in the non-volatile memory 2 Included. The reboot unit 13 Furthermore, it can refer to the replacement order information, which displays a sequence of backup files for replacement. It can select the backup file to use for replacement from among the backup files based on the replacement order information and history information, and replace the application configuration file stored in the file space with the selected backup file. The replacement order information displays a sequence in which the backup files are to be used for replacement and is contained within the replacement order information. 128 in the non-volatile memory 2 included. During the recovery process, the reboot unit selects 13The backup program to be used for replacement in the recovery process is selected based on the history information, ensuring that the backup files are used in the order indicated by the replacement order information. During the recovery process, the reboot unit selects... 13 In one aspect, based on the history information (or the history information and replacement order information), a backup file that was not used for replacement is selected from among the backup files stored in the backup file areas, and the application configuration file stored in the file area is replaced with the selected backup file. If the error capture unit 12 On the other hand, if an error is detected in the application configuration file, the reboot unit will cause the error to occur. 13, if the backup file areas do not contain a backup file that was not used for replacement, that the replacement control unit 14 executes the file replacement process, which is described below.
[0048] If the reboot unit 13 If a boot program is replaced with a backup program during the recovery process, the recovery process copies, for example, the backup program stored in the backup area to the program area as the new boot program, overwriting the boot program stored in the program area with the backup program stored in the backup area. The same applies if an application configuration file is replaced with a backup file.
[0049] The replacement control unit 14It performs the program replacement process to obtain a new boot program from an external source and replace the existing boot program with the new one. If there is an error in a boot program (the boot program), 100 or kernel program 106 The program replacement process is executed if the backup areas do not contain a backup program that has not been used for replacement. The program replacement process is also executed if a boot program (the boot program) is detected. 100 or kernel program 106 ) is updated. In the program replacement process, the replacement control unit receives 14 , in this example, a new boot program to replace a source that is external to the information processing unit 1The system replaces a predetermined backup program stored in the backup areas with the new boot program and replaces the boot program stored in the program area with the replaced predetermined backup program. When the replaced boot program is executed, the replacement control unit takes over. 14 If no error is present, all backup programs except the predetermined backup program are replaced with the replaced predetermined backup program or the replaced boot program; if an error is present, this replaces the boot program stored in the program area with a backup program other than the predetermined backup program.
[0050] The replacement control unit 14It also performs the file replacement process to obtain a new application configuration file from an external source and replaces the existing application configuration file with the new one. If an error occurs in an application configuration file (the application configuration file A), 112 or B 114 The file replacement process is executed if the backup file ranges do not contain a backup file that was not used for replacement. The file replacement process is also executed if an application configuration file (the application configuration file A) is detected. 112 or B 114 ) is updated. The replacement control unit 14 In this example, the file replacement process receives a new application configuration file for replacement from a source that is external to the information processing unit. 1The system replaces a predetermined backup file from the backup files stored in the backup file area with the new application configuration file, and replaces the application configuration file stored in the file area with the replaced predetermined backup file. Then, when the replaced application configuration file is executed, the replacement control unit replaces the existing backup file. 14 If no error occurs, all backup files except the predetermined backup file are replaced with the replaced predetermined backup file or the replaced application configuration file; if an error occurs, this file is replaced with the application configuration file stored in the file space with a backup file other than the predetermined backup file.
[0051] If the replacement control unit 14If a backup program is replaced with a new boot program, the program will, for example, copy the new boot program into the backup area as the new backup program, or overwrite the backup program stored in the backup area with the new boot program. The same applies if a boot program is replaced with a backup program, if a backup file is replaced with a new application configuration file, and so on.
[0052] In the program replacement process and the file replacement process, the new boot program and the application configuration file can be replaced by the replacement control unit. 14 obtained from the external source, it must be identical to the boot program and application configuration file currently located in non-volatile memory. 2 are stored or may be newer versions than the currently stored boot program and application configuration file.
[0053] Operation of the information processing device Fig. Figure 4 is a flowchart illustrating the operation of the information processing device. 1 according to this embodiment. The operation of the information processing device 1 will be referred to below with reference to Fig. 4 described.
[0054] When the system reset is enabled, the CPU performs 4 an access to a predetermined address (hereinafter referred to as the "boot address"), where the boot program 100 in the non-volatile memory 2 is stored, and transfers the boot program. 100 and its checksum value 101 into RAM 3 The CPU 4 The boot program then reads it. 100 from the RAM 3 and executes the boot process, including the initialization process, which is part of the boot program 100is described as (S1). The boot address is a fixed address in this case.
[0055] According to instructions in the boot program 100 As described, the CPU jumps 4 next to the address where the kernel program 106 is stored, and transfers the kernel program. 106 and its checksum value 107 into RAM 3 The CPU 4 The kernel program then reads it. 106 from RAM 3 and executes the one in the kernel program 106 described boot process from (S5)
[0056] When the kernel program boots 106 Once completed, the CPU transfers 4 then the application configuration files A 112 and B 114 for booting the applications that are specified in advance in the kernel, as well as the respective checksum values. 113 and 115 , from non-volatile memory2 into RAM 3 The CPU 4 Then it reads the application configuration files A 112 and B 114 from RAM 3 and executes the boot processes specified in the application configuration files A 112 and B 114 are described to boot the applications, thereby making the intended applications available to a user (S10). The application configuration files A 112 and B 114 can be executed sequentially, one after the other, or in parallel.
[0057] By executing the parallel control described in the boot program 100 , in parallel with the boot process of the boot program 100 In step S1, the CPU performs 4 Meanwhile, the error detection process, which is part of the boot program, is running. 100 as described, and calculates the checksum value of the boot program. 100 (S2). The CPU 4It then determines whether the calculated checksum value matches the checksum value 101 of the boot program 100 if the two do not match (NO in step S3). If the two do not match (NO in step S3), the CPU determines 4 that the boot program 100 It exhibits an invalid bit change and proceeds to the reboot process (S4). During this reboot process, the CPU performs... 4 the replacement process to complete the boot program 100 with the first boot program backup 102 or the second boot program backup 104 to replace and performs a system reboot using the replaced boot program. 100 through. The reboot process (S4) will be explained in detail later.
[0058] If, on the other hand, the calculated checksum value of the boot program 100 with the checksum value 101 If it matches (YES in step S3), the CPU determines 4 that the boot program 100is free from impermissible bit changes, and calculates the checksum value of the kernel program. 106 , which is part of the boot program 100 The following is read (S6). The CPU 4 then determines whether the calculated checksum value 107 of the calculated kernel program 106 if the two do not match (NO in step S7). If the two do not match (NO in step S7), the CPU determines 4 that the kernel program 106 It exhibits an invalid bit change and proceeds to the reboot process (S8). During this reboot process, the CPU performs... 4 the replacement process for replacing the kernel program 106 with the first kernel program backup 108 or the second kernel program backup 110 and performs a system reboot using the replaced kernel program. 106 through. The reboot process (S8) will be described in detail later.
[0059] If the calculated checksum value of the kernel program 106 on the other hand, with the checksum value 107 If it matches (YES in step S7), the CPU determines 4 that the kernel program 106 is free of impermissible bit changes and calculates the checksum value of the application configuration file A 112 , which are part of the kernel program 106 The following is read (S11). The CPU 4 It then determines whether the calculated checksum value matches the checksum value 113 the application configuration file A 112 if the two do not match (NO in step S12). If the two do not match (NO in step S12), the CPU determines 4 , that the application configuration file A 112 exhibits an invalid bit change and proceeds to the reboot process (S13). During this reboot process, the CPU performs... 4 the replacement process to update the application configuration file A 112with the first application configuration file A backup 116 or the second application configuration file A backup 120 to replace and performs a reboot of the application using the replaced application configuration file A 112 through. The reboot process (S13) will be described in detail later.
[0060] If the calculated checksum value of the application configuration file A 112 on the other hand, with the checksum value 113 If it matches (YES in step S12), the CPU determines 4 , that the application configuration file A 112 is free of impermissible bit changes. If another application configuration file is then read, the CPU performs... 4 The same process is performed on the read application configuration file as on application configuration file A. 112The operation was performed (S11, S12); if no other application configuration file is read, it enters a wait state. For example, if the application configuration file B 114 the application configuration file A 112 As read below, the CPU 4 the process on the application configuration file B 114 through the process on the application configuration file A 112 following (S11, S12), and enters a wait state. If the application configuration file B 114 parallel with the application configuration file A 112 when executed, the CPU 4 the process on the application configuration file B 114 parallel to the process on the application configuration file A 112 carry out.
[0061] Steps S1, S5 and S10 in Fig. 4 are through one execution, through the CPU 4, which implements the boot processes described in the boot program, kernel program, or application configuration files. Steps S2 and S3, S6 and S7, and S11 and S12 are executed by the CPU. 4 , which implements error detection processes described in the boot program, kernel program, and application configuration files. Steps S4, S8, and S13 are executed by the CPU. 4 , which implements reboot processes described in the boot program, kernel program, or application configuration files. Steps S1, S5, and S10 are therefore processes within the process execution unit. 11 Steps S2, S3, S6, S7, S11 and S12 are processes in the fault detection unit; and steps S4, S8 and S13 are processes in the reboot unit. 13 . Reboot process
[0062] Fig. Figure 5 is a flowchart illustrating the reboot process. The reboot processes in steps S4, S8, and S13 are shown in... Fig. 4 will be discussed below with reference to Fig. 5 explained.
[0063] First, the reboot process in step S4 is described. During the reboot process in step S4, the CPU holds 4 , as in Fig. As shown in step 5, the boot process (the process in step S1) starts first (S21). The CPU 44 It then refers to and changes the boot history information. 126 , which are stored in non-volatile memory 2 is stored (S22).
[0064] The following is the boot history information. 126 described. In this example, the boot history information is shown. 126 Sources of replacement (or copy) programs and files used for booting. Fig. Figure 6 is a diagram illustrating the format of the boot history information. 126 The boot history information126 in Fig. 6 contains a boot history value for both the boot program 100 , the kernel program 106 , the application configuration file A 112 and the application configuration file B 114 The boot history values for the boot program 100 , the kernel program 106 , the application configuration file A 112 and application configuration file B 114 are located at addresses N, N+1, N+2 and N+3 respectively in the non-volatile memory. 2 recorded. If the boot program 100 When the system boots for the first time, "0" is recorded at address N; the value at address N is held at "0" until the reboot process (S4) is performed. After the reboot process (S4) is performed, the boot program... 100 a program that is included with the first boot program backup 102 When replaced, a "1" is recorded at address N; when the boot program100 a program that is linked to the second boot program backup 104 If the boot program was replaced, a "2" is recorded at address N. Therefore, a "0", "1", or "2" is recorded at address N; the boot history value "0" indicates that the boot program stored in block B1 was not used. 100 is not a program that was replaced in the reboot process (S4), i.e., it is an initial program; the boot history value "1" indicates that the boot program stored in block B1 100 a program that is included with the first boot program backup 102 was replaced in the reboot process (S4); the boot history value “2” indicates that the boot program stored in block B1 was replaced. 100 a program that is linked to the second boot program backup 104 was replaced during the reboot process (S4). The CPU 4 This allows a program to detect a replacement (or copy) source of the boot program. 100is currently used for booting by accessing the boot history value at address N in the boot history information. 126 is referred to or reference is made to it.
[0065] The order of replacing the boot program 100 In this example, the reboot process (S4) is defined such that the first boot program backup 102 used for replacement in the first reboot process, and the second boot program backup. 104 It will be used for replacement in the next reboot process. The same applies to the kernel program. 106 , the application configuration file A 112 and the application configuration file B 114 .
[0066] The non-volatile memory 2 For example, it stores the replacement order information. 128 , which determines the replacement order of backup programs or backup files for both the boot program 100, Kernel program 106 , Application configuration file A 112 and application configuration file B 114 indicates; the CPU 4 determines the replacement order with reference to the replacement order information. 128 The CPU 4 In particular, the processing in and after step S22 is based on the replacement sequence information. 128 through. In this configuration, the replacement order can be changed by modifying the replacement order information. The manufacturer of the information processing device 1 For example, it can set the replacement order to an intended order by storing the replacement order information in non-volatile memory. 2 The information processing device records the intended sequence. 1For example, it can change the replacement order information according to information regarding an error detection rate of each block or other information or operations performed by a user.
[0067] If, returning to Fig. 5, in step S22 the boot history value for the boot program 100 When the CPU is "0", it changes 4 the boot trend value for the boot program 100 on “1”, since the boot program 100 with the first boot program backup 102 is replaced; if the boot history value for the boot program is "1", the CPU changes 4 the boot trend value for the boot program 100 on “2”, since the boot program 100 with the second boot program backup 104 is replaced; if the boot history value for the boot program is "2", the CPU changes 4 the boot trend value for the boot program 100 not.
[0068] The CPU4 This then determines whether it is possible to change the boot program. 100 to replace with a backup program (S23). In particular, if the boot history value is located at address N for the boot program 100 The CPU determines whether the value is "0" or "1". 4 , that a replacement is possible; if the boot history value is equal to "2", this determines that a replacement is not possible. The determination in step S23 is based on the boot history value referenced in step S22, i.e., the boot history value before the change in step S22.
[0069] If it is determined that a replacement is possible (YES in step S23), the CPU replaces 4 the boot program 100 and its checksum value 101 , stored in block B1 with a backup program and its checksum value (S24). If the boot history value for the boot program 100 especially if it is equal to "0", the CPU copies 4the first boot program backup 102 and its checksum value 103 in block B1 as the new boot program 100 and its checksum value 101 ; if the boot history value for the boot program 100 If the value is "1", this copies the second boot program backup. 104 and its checksum value 105 in block B1 as the new boot program 100 and its checksum value 101 If the boot program is replaced 100 and its checksum value 101 Once completed, the CPU performs the following actions 4 a system reboot (S25). Specifically, once the replacement is complete, the CPU performs the following steps: 4 performs a software reset and accesses the boot address to restart the process. Fig. 4 from the beginning. That is, the processing in Fig. 4 returns from step S4 to step S1, and the boot process of the boot program 100is performed again. In this case, the boot program will be executed. 100 After the replacement, the data is read and executed. The process in step S24 is carried out based on the boot history value referenced in step S22, i.e., the boot history value before the change in step S22.
[0070] If, on the other hand, it is determined that a replacement of the boot program is necessary 100 If this is not possible (NO in step S23), the CPU returns 4 A message is displayed indicating that a new boot program must be obtained from an external source, specifically in a display unit (not shown) or similar (S26), and the program replacement process begins to replace the boot program with one from an external source (S27). The program replacement process will be explained later.
[0071] The above description represents the case when the first boot program backup 102and the second boot program backup 104 for replacing the boot program 100 They can be used in this order, however, they can be used in the order of the second boot program backup. 104 and the first boot program backup 102 be used. If, in this case, the boot history value for the boot program 100 When the value is "0", the CPU changes 4 The boot history value is set to "2" and the boot program is replaced. 100 with the second boot program backup 104 ; if the boot history value is "2", this changes the boot history value to "1" and replaces the boot program. 100 with the first boot program backup 102 If the boot history value is "1", the program replacement process is performed without changing the boot history value. The same applies to the kernel program. 106 , the application configuration file A 112and the application configuration file B 114 .
[0072] The following describes the reboot process in step S8. During the reboot process in step S8, the CPU holds 4 , as in Fig. As shown in step 5, the boot process (the process in step S5) starts first (S21). The CPU 4 It then refers to and changes the boot history value at address N + 1 in the boot history information. 126 , which are stored in non-volatile memory 2 is stored (S22).
[0073] The boot history value of address N + 1 in the boot history information 126 is described here. Fig. 6, as in the case of address N, a “0”, “1” or “2” will be entered in address N + 1 in the boot history information. 126 as a boot history value for the kernel program 106 recorded. For the kernel program 106 If the boot history value is "0", it indicates that the kernel program 106, stored in block B4, is not a program that was replaced in the reboot process (S8); the boot history value “1” indicates that the kernel program 106 , stored in block B4, is a program that was included in the first kernel program backup. 108 was replaced in the reboot process (S8); the boot history value “2” indicates that the kernel program 106 , stored in block B4, is a program that uses the second kernel program backup 110 was replaced in the reboot process (S8).
[0074] If, returning to Fig. 5, in step S22 the boot history value for the kernel program 106 When the value is "0", the CPU changes 4 the boot history value for the kernel program 106 on “1”, since the kernel program 106 with the first kernel program backup 108 is replaced; if the boot history value for the kernel program 106 When the value is "1", the CPU changes 4the boot history value for the kernel program 106 on “2”, since the kernel program 106 with the second kernel program backup 110 is replaced; if the boot history value for the kernel program 106 When the value is "2", the CPU changes 4 the boot history value for the kernel program 106 not.
[0075] The CPU 4 This then determines whether it is possible to run the kernel program. 106 to replace with a backup program (S23). In particular, if the boot history value is at address N + 1 for the kernel program 106 The CPU determines whether the value is "0" or "1". 4 , that a replacement is possible; if the boot history value is equal to "2", this determines that a replacement is not possible. The determination in step S23 is performed based on the boot history value referenced in step S22, i.e., the boot history value before any change in step S22.
[0076] If it is determined that a replacement is possible (YES in step S23), the CPU replaces 4 the kernel program 106 and its checksum value 107 , stored in block B4, with a backup program and its checksum value (S24). Especially if the boot history value for the kernel program 106 If the value is "0", the CPU copies 4 the first kernel program backup 108 and its checksum value 109 into block B4 as the new kernel program 106 and its checksum value 107 ; if the boot history value for the kernel program 106 If the value is "1", it copies the second kernel program. 110 and its checksum value 111 in block B4 as the new kernel program 106 and its checksum value 107 If the kernel program is replaced 106 and its checksum value 107 Once completed, the CPU performs the following actions4 a system reboot (S25). Specifically, once the replacement is complete, the CPU performs the following steps: 4 a software reset and access to the boot address where the boot program is located 100 is saved to continue the process in Fig. 4. to be carried out from the beginning. That is, that in Fig. 4 the processing returns from step S8 to step S1, and the boot process of the boot program 100 is performed again. During post-boot processing, the kernel program is executed. 106 After the replacement, the value is read and executed. The process in step S24 is carried out based on the boot history value referenced in step S22, i.e., the boot history value before the change in step S22.
[0077] On the other hand, if it is determined that a replacement of the kernel program is necessary. 106 If this is not possible (NO in step S23), the CPU returns 4a message indicating that a new kernel program must be obtained from an external source (S26), and proceeds to the program replacement process to replace the kernel program. 106 with a kernel program from an external source (S27). The program replacement process will be described in detail later.
[0078] The reboot process in step S13 is explained below. During the reboot process in step S13, the CPU holds 4 , as in Fig. As shown in step 5, the boot process (the process in step S10) starts first (S21). The CPU 4 It then refers to and changes the boot history value at address N + 2 in the boot history information. 126 , which are stored in non-volatile memory 2 is stored (S22).
[0079] The boot history value at address N + 2 in the boot history information 126 is described here. Fig. 6, as in the case of address N, a “0”, “1” or “2” will be entered at address N + 2 in the boot history information. 126 as the boot history value for the application configuration file A 112 recorded. For the application configuration file A 112 If the boot history value is "0", it indicates that the application configuration file A 112 , which is stored in block B7, is not a file that was replaced in the reboot process (S13); the boot history value “1” indicates that the application configuration file A 112 , which is a file in block B7 that is associated with the first application configuration file A backup 116 was replaced in the reboot process (S13); the boot history value “2” indicates that the application configuration file A 112 , which is stored in block B7, is a file associated with the second application configuration file A backup. 120 was replaced in the reboot process (S13).
[0080] If, returning to Fig. 5, in step S22 the boot history value for the application configuration file A 112 When the value is "0", the CPU changes 4 the boot history value for the application configuration file A 112 to “1”, since the application configuration file A 112 with the first application configuration file A backup 116 is replaced; if the boot history value for the application configuration file A 112 When the value is "1", the CPU changes 4 the boot history value for the application configuration file A 112 on “2”, since the application configuration file A 112 with the second application configuration file A backup 120 is replaced; if the boot history value for the application configuration file A 112 When the value is "2", the CPU changes 4 the boot history value for the application configuration file A 112 not.
[0081] The CPU then determines whether it is possible to access the application configuration file A. 112 to replace with a backup file (S23). In particular, if the boot history value is located at address N + 2 for the application configuration file A 112 The CPU determines whether the value is "0" or "1". 4 , that a replacement is possible; if the boot history value is equal to "2", this determines that a replacement is not possible. The determination in step S23 is performed based on the boot history value referenced in step S22, i.e., the boot history value before any change in step S22.
[0082] If it is determined that a replacement is possible (YES in step S23), the CPU replaces 4 the application configuration file A 112 and its checksum value 113, stored in block B7, with a backup file and its checksum value (S24). In particular, if the boot history value for the application configuration file A 112 If the value is "0", the CPU copies 4 the first application configuration file A backup 116 and its checksum value 117 in block B7 as the new application configuration file A 112 and its checksum value 113 ; if the boot history value for the application configuration file A 112 If the value is "1", it copies the second application configuration file A backup. 120 and its checksum value 121 in block B7 as the new application configuration file A 112 and its checksum value 113 If the replacement of the application configuration file A 112 and its checksum value 113 Once completed, the CPU performs the following actions 4a reboot of the application (S25). In particular, when the replacement is complete, the CPU loads 4 the application configuration file A 112 again in the state in which the system (especially the kernel) was booted. The processing in Fig. 4 thus goes from step S13 to step S10, and the application configuration file A 112 The file is read and the application's boot process is restarted. In this case, the application configuration file A is modified. 112 After the replacement, the data is read and executed. The process in step S24 is carried out based on the boot history value referenced in step S22, i.e., the boot history value before any changes in step S22.
[0083] If, on the other hand, it is determined that a replacement of the application configuration file A 112 If this is not possible (NO in step S23), the CPU returns 4a message is displayed indicating that a new application configuration file must be obtained from an external source (S26) and proceeds to the file replacement process to replace application configuration file A. 112 with an application configuration file from an external source (S27). The file replacement process is explained later.
[0084] The reboot process for application configuration file B 114 is the same as that for the application configuration file A 112 .
[0085] If the boot program 100 , the kernel program 106 , the application configuration file A 112 or the application configuration file B 114 When a backup program is used to replace the boot history information, the backup program used for the replacement will be identified with reference to the boot history information. 126This allows you to select a backup program that does not meet the condition that it was used to replace the program and that an error was detected in the replaced program (or to select a backup program in which no error was detected), so that the reboot process can be performed with a more reliable backup program. Immediately after a boot program is replaced with an initial backup, if an error is detected in the boot program, it is possible to select a backup program (for example, a second backup) other than the first backup that is likely to contain an error, in order to perform the reboot process, so that the reboot process can be performed with a more reliable backup program. Program (file) replacement process
[0086] Fig. Figure 7 is a flowchart illustrating the program (or file) replacement process in step S27 in Fig. 5. The program replacement process for the boot program, the program replacement process for the kernel program, and the file replacement process for the application configuration file are described below with reference to Fig. 7. The program (or file) replacement processes for the boot program, kernel program, and application configuration file are performed by a single execution using the CPU. 4 , which implements replacement controls that are described in the boot program, kernel program, or application configuration file.
[0087] First, the program replacement process for the boot program is described. If, in the program replacement process for the boot program, as in Fig. 7, the CPU 4 detects that an external storage device is connected to the external interface 6 Once connected, it reads a new boot program for replacement and its checksum value via the communication unit. 5from the external storage and replaces the first boot program backup. 102 and the checksum value 103 with the new boot program and its checksum value (S31). The external storage is connected to the external interface. 6 the information processing device 1 for example, connected by a user who received the message in step S26 in Fig. 5 has seen, and is, for example, a portable storage device, such as a USB storage device.
[0088] Once the replacement is complete, the CPU changes 4 the replacement flag information 124 (S32).
[0089] The replacement flag information 124 The replacement flag information is described below. 124 Indicates whether the program (or file) replacement process is running. Fig. Figure 8 is a diagram illustrating the format of the replacement flag information. 124The replacement flag information 124 in Fig. 8 contains a respective replacement flag for the boot program. 100 , the kernel program 106 , the application configuration file A 112 or the application configuration file B 114 The replacement flags for the boot program 100 , the kernel program 106 , the application configuration file A 112 and the application configuration file B 114 are located at addresses M, M+1, M+2 and M+3 respectively in the non-volatile memory. 2Each of the replacement flags is normally "0" and changes to "1" when the program (or file) replacement process is executed. A "0" or "1" is recorded at each of the addresses M, M+1, M+2, and M+3; a "0" indicates that the replacement process is not performed for the corresponding program (or file); a "1" indicates that the replacement process is performed for the corresponding program (or file).
[0090] Returning to Fig. 7 changes the CPU 4 In step S32, the replacement flag is set at address M for the boot program. 100 from "0" to "1". The replacement flag "1" for the boot program. 100 indicates that the first boot program backup is running. 102 was replaced with a new boot program, and therefore differs in content from the boot program 100 and the second boot program backup 104 differs.
[0091] The CPU 4The boot program is then replaced. 100 and the checksum value 101 with the replaced first boot program backup 102 and checksum value 103 (S33).
[0092] Once the replacement is complete, the CPU changes 4 the boot trend value for the boot program 100 in the boot history information 126 to “1” (S34) and performs a system reboot (S35). The CPU 4 In particular, it performs a software reset, accesses the boot address, and reads the replaced boot program. 100 and executes these to start the boot process (step S1 in Fig. 4) and the checksum calculation (step S2 in Fig. 4) to be carried out in parallel.
[0093] When the checksum calculation is complete, the CPU refers to... 4 on the replacement flag and the boat progress value for the boat program 100, and if the replacement flag and boot history value are both “1”, it goes to step S36 in Fig. 7. If the replacement flag is "0", it goes to step S3 in Fig. 4; if the replacement flag is equal to “1”, and the boot progress value is equal to “2”, it goes to step S43, which is described later.
[0094] In step S36, the CPU determines 4 , whether the boot program 100 It has any errors. Especially if the boot program... 100 It boots normally and the calculated checksum value matches the checksum value. 101 The CPU determines if it matches. 4 that there is no error; if the boot program 100 If the device does not boot normally, or if the two checksum values do not match, this determines that an error has occurred.
[0095] If it is determined that there is no error (NO in step S36), the CPU changes 4the boot trend value for the boot program 100 to “0” (S37) and replaces the second boot program backup 104 with the first boot program backup 102 (S38). The CPU 4 then sets the replacement flag for the boot program 100 The program replacement process returns to "0" (S39) and ends. After the program replacement process ends, processing proceeds to step S6 in Fig. 4.
[0096] If, on the other hand, an error is determined to have occurred (YES in step S36), the CPU replaces 4 the boot program 100 with the second boot program backup 104 (S40) changes the boot history value for the boot program 100 on “2” (S41) and performs a system reboot (S42). The CPU 4 In particular, it performs a software reset, accesses the boot address, and reads the replaced boot program. 100and executes this to start the boot process (step S1 in Fig. 4) and the checksum calculation (step S2 in Fig. 4) to be carried out in parallel.
[0097] When the checksum calculation is complete, the CPU refers to... 4 on the replacement flag and the boat progress value for the boat program 100 and goes to step S43 if the replacement flag is equal to "1" and the boot progress value is equal to "2". Fig. 7.
[0098] In step S43, the CPU determines 4 , whether the boot program 100 if it has any errors, in the same way as in step S36.
[0099] If it is determined that there is no error (NO in step S43), the CPU informs 4The system informs a user that the new boot program obtained from the external source is faulty, for example, by displaying this fault on a display unit (not shown) in step S44, and terminates the program replacement process. After the program replacement process ends, processing proceeds to step S6. Fig. 4.
[0100] On the other hand, if it is determined that an error has occurred (YES in step S43), the CPU 4 to step S26 in Fig. Returning to 5, the message is again displayed stating that a new boot program must be obtained from an external source, and the program replacement process is executed (S27).
[0101] The following describes the program replacement process for the kernel program. If, in the program replacement process for the kernel program, as in Fig. 7 shown, the CPU 4 detects that an external storage device is connected to the external interface6 Once connected, this reads a new kernel program for replacement and its checksum value from the external memory and replaces the first kernel program backup. 108 and the checksum value 109 with the new kernel program and checksum value (S31).
[0102] Once the replacement is complete, the CPU changes 4 the replacement flag at address M + 1 for the kernel program 106 in the replacement flag information 124 from “0” to “1” (S32).
[0103] The CPU 4 The kernel program is then replaced. 106 and the checksum value 107 with the replaced first kernel program backup 108 and checksum value 109 (S33).
[0104] Once the replacement is complete, the CPU changes 4 the boot history value for the kernel program 106 in the boot history information 126to “1” (S34) and performs a system reboot (S35). The CPU 4 In particular, it performs a software reset, accesses the boot address, and reads the boot program. 100 and executes this, and then reads the kernel program. 106 , to start the boot process of the kernel program 106 (Step S5 in Fig. 4) and the checksum calculation (step S6 in Fig. 4) to be carried out in parallel.
[0105] When the checksum calculation is complete, the CPU refers to... 4 on the replacement flag and the boot history value for the kernel program 106 and, if the replacement flag and the boot progress value are both "1", goes to step S36 in Fig. 7. If the replacement flag is "0", it goes to step S7 in Fig. 4; if the replacement flag is equal to “1” and the boot progress value is equal to “2”, it goes to step S43, which is described later.
[0106] In step S36, the CPU determines 4 , whether the kernel program 106 It has any errors. Especially if the kernel program... 106 It boots normally and the calculated checksum value matches the checksum value. 107 The CPU determines if it matches. 4 that no error exists; if the kernel program 106 If the system does not boot normally, or if the two checksum values do not match, this determines that an error has occurred.
[0107] If it is determined that there is no error (NO in step S36), the CPU changes 4 the boot history value for the kernel program 106 to “0” (S37) and replaces the second kernel program backup 110 with the first kernel program backup 108 (S38). The CPU 4 then sets the replacement flag for the kernel program 106The program replacement process returns to "0" (S39) and ends. After the program replacement process ends, processing proceeds to step S11 in Fig. 4.
[0108] If, on the other hand, an error is determined to have occurred (YES in step S36), the CPU replaces 4 the kernel program 106 with the second kernel program backup 110 (S40) changes the boot history value for the kernel program 106 on “2” (S41), and performs a system reboot (S42). The CPU 4 In particular, it performs a software reset, accesses the boot address, and reads the boot program. 100 and executes this, and then reads the kernel program. 106 , to start the boot process of the kernel program 106 (Step S5 in Fig. 4) and the checksum calculation (S6 in Fig. 4) to be carried out in parallel).
[0109] When the checksum calculation is complete, the CPU refers to... 4on the replacement flag and the boot history value for the kernel program 106 and goes to step S43 if the replacement flag is equal to "1" and the boot progress value is equal to "2". Fig. 7.
[0110] In step S43, the CPU determines 4 , whether the kernel program 106 if it has any errors, in the same way as in step S36.
[0111] If it is determined that there is no error (NO in step S43), the CPU informs 4 The system informs a user that the new kernel program obtained from the external source is faulty (S44) and terminates the program replacement process. After the program replacement process ends, processing proceeds to step S11 in... Fig. 4.
[0112] On the other hand, if an error is determined to have occurred (YES in step S43), the CPU returns 4 to step S26 in Fig. Returning to 5, the message is again displayed indicating that a new kernel program must be obtained from an external source, and the program replacement process is executed (S27).
[0113] Next, the file replacement process for the application configuration file will be explained. If, in the file replacement process for the application configuration file A 112 , as in Fig. 7 shown, the CPU 4 detects that an external storage device is connected to the external interface 6 Once connected, it reads a new application configuration file for replacement and its checksum value from the external storage and replaces the first application configuration file A backup. 116 and the checksum value 117 with the new application configuration file and checksum value (S31).
[0114] Once the replacement is complete, the CPU changes 4the replacement flag at address M + 2 for the application configuration file A 112 in the replacement flag information 124 from “0” to “1” (S32).
[0115] The CPU 4 This then replaces the application configuration file A 112 and the checksum value 113 with the replaced first application configuration file A backup 116 and checksum value 117 (S33).
[0116] Once the replacement is complete, the CPU changes 4 the boot history value for the application configuration file A 112 in the boot history information 126 to “1” (S34) and reboots the application (S35). The CPU 4 In particular, the application configuration file A is read again. 112 in the state in which the system (especially the kernel) was booted, and executes the boot process of the application configuration file A 112 (Step S10 in Fig. 4) and the checksum calculation (step S11 in Fig. 4) parallel through.
[0117] When the checksum calculation is complete, the CPU refers to... 4 on the replacement flag and the boot history value for the application configuration file A 112 and, if the replacement flag and the boot progress value are both "1", goes to step S36 in Fig. 7. If the replacement flag is "0", it goes to step S12 in Fig. 4; if the replacement flag is equal to “1” and the boot progress value is equal to “2”, it goes to step S43, which is described later.
[0118] In step S36, the CPU determines 4 , whether the application configuration file A 112 It contains any errors. In particular, if the application configuration file A 112 It boots normally and the calculated checksum value matches the checksum value. 113 The CPU determines if it matches. 4that there is no error; if the application configuration file A 112 If the system does not boot normally, or if the two checksum values do not match, this determines that an error has occurred.
[0119] If it is determined that there is no error (NO in step S36), the CPU changes 4 the boot history value for the application configuration file A 112 to “0” (S37) and replaces the second application configuration file A backup 120 with the first application configuration file A backup 116 (S38). The CPU 4 Then sets the replacement flag for application configuration file A 112 The CPU resets to "0" (S39) and terminates the file replacement process. After the file replacement process ends, the CPU goes back to "0". 4 into a waiting state.
[0120] If, on the other hand, an error is determined to have occurred (YES in step S36), the CPU replaces 4 the application configuration file A112 with the second application configuration file A backup 120 (S40) changes the boot history value for application configuration file A 112 on “2” (S41), and reboots the application (S42). The CPU 4 In particular, the application configuration file A is read again. 112 in the state in which the system (especially the kernel) was booted, and executes the boot process of the application configuration file A 112 (Step S10 in Fig. 4) and the checksum calculation (step S11 in Fig. 4) parallel through.
[0121] When the checksum calculation is complete, the CPU refers to... 4 on the replacement flag and the boot history value for the application configuration file A 112 , and if the replacement flag is equal to "1" and the boot progress value is equal to "2", it goes to step S43 in Fig. 7.
[0122] In step S43, the CPU determines 4, whether the application configuration file A 112 if it has any errors, in the same way as in step S36.
[0123] If it is determined that there is no error (NO in step S43), the CPU informs 4 A user is informed that the new application configuration file obtained from the external source is faulty (S44), and the file replacement process is terminated. After the file replacement process ends, the CPU 4 into a waiting state.
[0124] On the other hand, if it is determined that an error has occurred (YES in step S43), the CPU 4 to step S26 in Fig. Returning to 5, the message is displayed again, indicating that a new application configuration file must be obtained from an external source, and the file replacement process is executed (S27).
[0125] The file replacement process for application configuration file B 114is the same as that for the application configuration file A 112 . Backup verification process
[0126] The information processing device 1 can perform a backup verification process to check if the backup programs and backup files have any errors (the error-free status of the backup programs and backup files) during periods when error detection processes are in the waiting state during processing. Fig. 4 are. The periods include, in particular, the waiting period from the determination of YES in step S3 in Fig. 4 until the start of step S6, the waiting period from the determination of YES in step S7 until the start of step S11, and the waiting period from the determination of YES in step S12 to the end of step S10. Fig. Figure 9 is a flowchart illustrating the backup verification process. The backup verification process is described below with reference to... Fig. 9 described.
[0127] The CPU 4 compares the first boot program backup 102 with the second boot program backup 104 , to determine if the two match (S51). If the two do not match (NO in step S51), it goes to step S52; if the two match (YES in step S51), it goes to step S52.
[0128] In step S52, the CPU calculates 4 the checksum value of both the first boot program backup 102 as well as the second boot program backup 104 , and determines whether the calculated checksum value of the first boot program backup 102 with the checksum value 103 matches, and whether the calculated checksum value of the second boot program backup is correct. 104 with the checksum value 105 matches. If the checksum value is from one of the first boot program backups 102and the second boot program backup 104 If the two checksum values match, but the other checksum value does not match, the CPU replaces the first one. 4 The other backup program matches the one backup program that has the matching checksum value and proceeds to step S53. If both checksum values of the first boot program backup match 102 and the second boot program backup 104 If they don't match, for example the first boot program backup might be missing. 102 and the second boot program backup 104 with the boot program 100 be replaced or a new boot program obtained from an external source.
[0129] In step S53, the CPU compares 4 the first kernel program backup 108 with the second kernel program backup 110, to determine if the two match. If the two do not match (NO in step S53), it goes to step S54; if the two match (YES in step S53), it goes to step S55.
[0130] In step S54, the CPU calculates 4 the checksum value of both the first kernel program backup 108 as well as the second kernel program backup 110 , and determines whether the calculated checksum value of the first kernel program backup 108 with the checksum value 109 matches, and whether the calculated checksum value of the second kernel program backup matches 110 with the checksum value 111 matches. If the checksum value is from one of the first kernel program backups 108 and the second kernel program backup 110 If the two checksum values match, but the other checksum value does not match, the CPU replaces the first one. 4The other backup program matches the one backup program that has the matching checksum value and proceeds to step S55. If both checksum values of the first kernel program backup match 108 and the second kernel program backup 110 For example, the first kernel program backup might not match. 108 and the second kernel program backup 110 with the kernel program 106 be replaced or a new kernel program obtained from an external source.
[0131] In step S55, the CPU compares 4 the first application configuration file A backup 116 with the second application configuration file A backup 120 , to determine if the two match. If the two do not match (NO in step S55), it goes to step S56; if the two match (YES in step S55), it goes to step S57.
[0132] In step S56, the CPU calculates 4 the checksum value of both the first application configuration file A backup 116 as well as the second application configuration file A backup 120 , and determines whether the calculated checksum value of the first application configuration file A backup 116 with the checksum value 117 matches, and whether the calculated checksum value of the second application configuration file A backup matches. 120 with the checksum value 121 matches. If the checksum value is from one of the first application configuration file A backups 116 and the second application configuration file A backup 120 If the two checksum values match, but the other checksum value does not match, the CPU replaces the first one. 4The other backup file is compared to the one backup file that has the matching checksum value, and the process proceeds to step S57. If both checksum values of the first application configuration file A backup match, the process will proceed to step S57. 116 and the second application configuration file A backup 120 If they do not match, for example the first application configuration file A backup may not be the case. 116 and the second application configuration file A backup 120 with the application configuration file A 112 or replaced by a new application configuration file obtained from an external source.
[0133] In step S57, the CPU compares 4 the first application configuration file B backup 118 with the second application configuration file B backup 122, to determine if the two match. If the two do not match (NO in step S57), it goes to step S58; if the two match (YES in step S57), it ends the backup verification process to enter a wait state.
[0134] In step S58, the CPU performs 4 the same process as in step S56 regarding the first application configuration file B backup 118 and the second application configuration file B backup 122 , and then completes the backup verification process to enter standby mode. Advantages
[0135] The following advantages (1)–(16) can be obtained from the embodiment described above. (1) The information processing device in this embodiment is configured to execute a boot program to perform a system boot process and to perform error detection on the boot program in parallel with the boot process. According to this embodiment, the system boot process can be started faster compared to a configuration that starts the system boot process after error detection has been performed on the boot program. This allows, for example, a faster display of the system's startup or boot screen. The information processing device in this embodiment performs a system reboot using a backup program if an error is detected in the boot program. Thus, if the boot program has an error, the system can be booted with a more reliable boot program.
[0136] As the complexity and sophistication of the devices increase, the amount of data in the boot program grows significantly, leading to an increase in the processing time of the error detection process within the boot program. The configuration that initiates the system's boot process after error detection in the boot program has a problem: the start of the system boot process is significantly delayed. The present embodiment can solve this problem.
[0137] Fig. Figure 10 is a diagram illustrating processing periods in a configuration that performs boot processes after an error detection. Fig. Figure 10 has a horizontal axis which represents time and shows a processing period T1 of the error detection process of a boot program, a processing period T2 of the boot process of the boot program, a processing period T3 of the error detection process of a kernel program, a processing period T4 of the boot process of the kernel program, a processing period T5 of the error detection processes of the application configuration files and a processing period T6 of the boot processes of the application configuration files.
[0138] Fig. Figure 11 is a diagram illustrating processing periods in the configuration of this embodiment. Fig. Figure 11 has a horizontal axis which indicates a time and shows a processing period T11 of the error detection process of the boot program, a processing period T12 of the boot process of the boot program, a processing period T13 of the error detection process of the kernel program, a processing period T14 of the boot process of the kernel program, a processing period T15 of the error detection processes on application configuration files and a processing period T16 of the boot processes of the application configuration files.
[0139] From the Fig. 10 and Fig. 11 It is evident that the start time of the boot processes of the boot program, kernel program and application configuration files in this embodiment is earlier than in the configuration that the boot processes perform after an error detection. (2) If an error is detected in the boot program, the information processing device performs a recovery process to replace the boot program stored in the program area with a backup program stored in the backup areas and reboots the system using the replaced program. In this respect, replacing the faulty boot program with the backup program increases the number of correct boot programs and improves the reliability of system booting. (3) During the recovery process, the information processing device refers to a history log showing the history of program replacements with backup programs and selects the backup program to be used for the replacement. This allows the reboot to be performed with a highly reliable program if an error is detected in the boot program. In particular, it is possible to select a backup program that does not meet the condition of having been used to replace the program and that an error was detected in the replaced program (or to select a backup program in which no error was detected), so that the reboot process can be performed with a more reliable backup program. (4) During the recovery process, the information processing device refers to a replacement order information, which indicates the order in which the backup programs are to be replaced, and selects the backup program to be used for replacement based on the replacement order information and history information. Accordingly, the replacement order can be changed by modifying the replacement order information. This makes it possible, for example, to delay the use of a backup program recorded in a dead block or a block with a high error capture rate in the non-volatile memory, and to preferentially use a more reliable backup program for replacement.A dead block is a block in which normal read or write operations are not possible, such as a block in which the number of rewrite processes has exceeded a predetermined rewrite limit or an initial deficient block in a semiconductor device. (5) During the recovery process, the information processing device selects a backup program that was not used for replacement rather than the backup program that is used for replacement. Therefore, the reboot process can be performed using a highly reliable backup program. (6) In the program replacement process for replacing the boot program with a new boot program, the information processing device receives a new program, replaces a predetermined backup program of the backup programs stored in the backup areas with the new boot program, replaces the boot program stored in the program area with the predetermined backup program, and when the replaced boot program is executed, if no error occurs, replaces one or more of the backup programs other than the predetermined backup program with the replaced predetermined backup program or the replaced boot program, and if an error occurs, replaces the boot program stored in the program area with a backup program other than the predetermined backup program.If, according to this principle, the boot program is replaced with the new boot program, it is possible, if the replaced new boot program has an error (for example, if normal booting is not possible, or if an invalid bit change has been detected), to restore the boot program to its previous state before the replacement within the program space, while retaining the backup of the new boot program. Therefore, if, for example, the new boot program has an error and the system cannot boot, it is possible to prevent a situation in which the boot program cannot be restored to its previous state and the system cannot boot. (7) The information processing device executes an application configuration file to perform an application boot process and performs error detection on the application configuration file concurrently with the boot process. This allows the application boot process to start faster compared to a configuration that starts the application boot process after error detection in the application configuration file. This enables, for example, a faster display of the application's startup screen. Furthermore, if an error is detected in the application configuration file, the information processing device reboots the application using a backup file. Therefore, if the application configuration file contains an error, the application can be booted with a more reliable application configuration file. (8) If an error is detected in the application configuration file, the information processing device performs a recovery process to replace the application configuration file stored in the file space with a backup file stored in the backup file spaces and reboots the application with the replaced application configuration file. Replacing the faulty application configuration file with the backup file increases the number of correct application configuration files and improves the reliability of the application boot process. (9) During the recovery process, the information processing device references history information that displays the history of the replacement of the application configuration file with the backup files and selects the backup file to use for the replacement. This allows the reboot to be performed with a highly reliable file if an error is detected in the application configuration file. In particular, it is possible to select a backup file that is not subject to the condition that it was used to replace the application configuration file and an error was detected in the replaced application configuration file (or to select a backup file in which no error was detected), so that the reboot process can be performed with a more reliable backup file. (10) During the recovery process, the information processing device refers to replacement order information, which indicates the order in which backup files are to be replaced, and selects the backup file to be used for replacement based on the replacement order information and history information. Accordingly, the replacement order can be changed by modifying the replacement order information. This allows, for example, delaying the use of a backup file recorded in a dead block or a block with a high error capture rate in non-volatile memory and preferentially using a more reliable backup file for replacement. (11) During the recovery process, the information processing device selects a backup file that was not used for replacement instead of the backup file used for replacement. Therefore, the reboot process can be performed using a highly reliable backup file. (12) In the file replacement process for replacing the application configuration file with a new application configuration file, the information processing device receives a new application configuration file, replaces a predetermined backup file of the backup files stored in the backup file areas with the new application configuration file, replaces the application configuration file stored in the file area with the predetermined backup file, and, if no error occurs, when the replaced application configuration file is executed, replaces one or more of the backup files other than the predetermined backup file with the replaced predetermined backup file or the replaced application configuration file, and, if an error occurs, replaces the application configuration file stored in the file area with a backup file other than the predetermined backup file.If, according to this principle, the application configuration file is replaced with a new one, and the replaced new application configuration file contains an error (for example, if normal booting is not possible, or if an invalid bit change has been detected), it is possible to restore the application configuration file to its previous state before the replacement, while retaining the backup in the new application configuration file. Therefore, if, for example, the new application configuration file contains an error and the application cannot boot, it is possible to prevent a situation where the application configuration file cannot be restored to its previous state and the application cannot boot. (13) The file area in the non-volatile memory stores a multitude of application configuration files in such a way that the multitude of application configuration files can be read in units of application configuration files. In this respect, data can be transferred from the non-volatile memory to the workspace for each application configuration file, and the transfer time to main memory can therefore be reduced. (14) The file area in the non-volatile memory stores the multitude of application configuration files and the error collection data for each of the multitude of application configuration files. Because, in this respect, the error collection data (for example, the checksum value) is individually appended to each of the application configuration files, the processing time for error collection using the error collection data (for example, the checksum value calculation time) can be reduced compared to a case where error collection data (for example, a checksum value) is appended to a file group containing the multitude of application configuration files. (15) The information processing device performs error detection on the backup programs stored in the backup areas and replaces a backup program in which an error has been detected with a backup program in which no error has been detected. This aspect can improve the reliability of the backup programs. For example, it eliminates the possibility that the replacement of the boot program with a backup program in step S23 of the reboot process (S4 or S8) will result in an error. Fig. 4 is determined to be impossible. (16) The information device performs error detection on the backup files stored in the backup file areas and replaces a backup file in which an error was detected with a backup file in which no error was detected. This aspect can improve the reliability of the backup files. For example, it prevents the possibility that the replacement of the application configuration file with a backup file in step S23 of the reboot process (S13) in Fig. 4 is determined to be impossible.
[0140] The present invention is not limited to the embodiment described above; it can be practiced in various other aspects without departing from the inventive scope.
[0141] The above description represents, for example, a configuration that, when an error is detected in a boot program, performs a replacement of the boot program with a backup program (the recovery process) and then reboots the system; however, the information processing device 1 the backup program into RAM 3 Read to reboot the system without replacing the boot program (the recovery process). The information processing device 1 The backup file can also be stored in RAM. 3 Read to reboot the application without replacing the application configuration file with the backup file (the recovery process). Regarding the boot program (especially the boot program) 100Since the boot program's boot address is the first program read and executed, the recovery process is necessary if the boot address is fixed. However, in a configuration where the boot address can be changed, it is possible to perform the reboot without the recovery process by changing the boot address to the starting address of the backup program.
[0142] The above description represents a configuration in which the non-volatile memory 2 A variety of backup programs store data, but the number of backup programs is not limited to a large number and can be just one. The same applies to the backup files.
[0143] The above description represents a case where the two files of the application configuration file A 112 and application configuration file B 114These are used as the application configuration file; however, the number of application configuration files can be one or more. In practice, more application configuration files are often needed.
[0144] The above description represents a configuration in which the process execution unit 11 and fault detection unit 12 through the same CPU 4 and the same programs are implemented, however the error detection unit 12 in the following forms (a)–(d). (a) The fault detection unit 12 is executed by the CPU 4 , implemented by error detection programs that differ from the boot programs. (b) The fault detection unit 12 is through a design, through a CPU, which differs from the CPU 4differs from error detection processes implemented either in the boot programs or in error detection programs that differ from the boot programs. (c) The CPU 4 contains a large number of processor cores, the process execution unit 11 is implemented by one or more of the processor cores and the error detection unit 12 is implemented by one, another or more of the processor cores, of error detection processes that are either described in the boot programs or in error detection programs that are different from the boot programs. (d) The fault detection unit 12 is implemented through a hardware circuit for error detection.
[0145] In a configuration that executes the boot processes and error detection processes in parallel through different processing devices, as in (b) to (d) above, the boot processes and error detection processes can actually be executed in parallel, and the boot time can be reduced compared to the configuration that starts the system's boot process after an error detection on the boot program.
[0146] Fig. Figure 12 is a diagram illustrating processing periods in a configuration that performs the boot processes and the fault detection processes in parallel through different processing devices. Fig. Figure 12 has a horizontal axis representing time and shows a processing period T21 of the boot program's error detection process, a processing period T22 of the boot program's boot process, a processing period T23 of the kernel program's error detection process, a processing period T24 of the kernel program's boot process, a processing period T25 of the application configuration file's error detection processes, and a processing period T26 of the application configuration file's boot processes.
[0147] From the Fig. 10 and Fig.12 shows that in the configuration which executes the boot processes and the error detection processes in parallel through different processing devices, the end times of the respective boot processes of the boot program, kernel program and application configuration files are earlier than those in the configuration which performs the boot processes after error detection.
[0148] Like the fault detection unit 12 can the reboot unit 13 and replacement control unit 14 in the forms described above (a) to (d).
[0149] The above description, as the history information that displays the history of program replacements with backup programs, represents the boot history values that indicate the replacement sources of the programs. However, the history information is not limited to this and can, for example, include information showing backup programs that were used to replace the program in the past. History information can be prepared for each backup program. For example, a history flag indicating whether the backup program was used to replace the program in the past can be stored in non-volatile memory for each backup program. 2 The history flag is "0" if the backup program was not used for the replacement, and is, for example, "1" if the backup program was used for the replacement. The same applies to the application configuration files.
[0150] The above description represents a configuration that selects a backup program not previously used for replacement based on historical information; however, a different backup program can be selected. For example, if a block in non-volatile memory has not been read for an extended period, the data content within that block may become corrupted over time due to charge loss. The risk of charge loss can be mitigated by ensuring that backup programs are used as consistently as possible during the restore processes. From this perspective, the reboot unit 13It can be configured to select a backup program that has not been read for an extended period of time, based on the history information. This configuration can prevent a loss of data in the non-volatile memory. For example, the backup program that has not been read for an extended period includes the backup program that has not been read for the longest period of time among the backup programs, and a backup program that has not been read for a predetermined period. In this configuration, the history information displays, for example, a period of time for each of the backup programs during which the backup program has not been read. Reference sign 1 Information processing device, 2 non-volatile memory, 3 RAM, 4 CPU, 5 Communication unit, 6 external interface 10 parallel processing unit, 11Process execution unit, 12 Error detection unit, 13 Reboot unit, 14 Replacement control unit, 100 Boot program, 101 , 103 , 105 , 107 , 109 , 111 , 11 , 115 , 117 , 119 , 121 , 123 Checksum value, 102 first boot program backup, 104 second boot program backup, 106 Kernel program, 108 first kernel program backup, 110 second kernel program backup, 112 Application configuration file A, 114 Application configuration file B, 116 first application configuration file A backup, 118 first application configuration file B backup, 120 second application configuration file A backup, 122 second application configuration file B backup, 124 Replacement flag information, 126 Boot history information,128 Replacement sequence information.
Claims
[1] Information processing device, comprising: a non-volatile memory with a program area that stores a program for booting a system, and a multitude of backup areas, each storing a backup program that is identical in content to the program; a process execution means for executing the program stored in the program area, for performing a boot process of the system; an error detection means for performing error detection on the program stored in the program area, in parallel with the boot process by the process execution means; and a reboot means for, when the error detection means detects an error in the program, performing a recovery process to replace the program stored in the program space with one of the backup programs stored in the backup spaces, and rebooting the system using the replaced program stored in the program space; wherein During the recovery process, the reboot tool refers to history information that shows a history of replacing the program with the backup programs, selects the backup program from among the backup programs based on the history information to be used for the replacement, and replaces the program with the selected backup program. [2] Information processing device according to claim 1, wherein in the recovery process the reboot means further refers to a replacement sequence information which indicates a sequence of backup programs for replacement, selects the backup program for replacement from among the backup programs on the basis of the replacement sequence information and the history information, and replaces the program with the selected backup program. [3] Information processing device according to claim 1 or 2, wherein the backup program selected in the recovery process is a backup program that has not been used for replacement. [4] Information processing device according to one of claims 1 to 3, further comprising a replacement means for carrying out a program replacement process for replacing the program with a new program that was not stored in the backup areas, wherein in the program replacement process the replacement means receives the new program, replaces a predetermined backup program of the backup programs stored in the backup program areas with the new program, replaces the program stored in the program area with the predetermined backup program, and when the replaced program is executed, if no error is present, replaces one or more of the backup programs other than the predetermined backup program with the replaced predetermined backup program or the replaced program, and if an error is present, replaces the program stored in the program area with one of the backup programs other than the predetermined backup program. [5] Information processing device according to claim 4, wherein, if the error detection means detects an error in the program, and if the backup areas do not contain a backup program that has not been used for replacement, the replacement means performs the program replacement process. [6] Information processing device according to any one of claims 1 to 5, wherein: The non-volatile memory further comprises a file area that stores an application configuration file for booting an application, and one or more backup file areas, each storing a backup file that is identical in content to the application configuration file; wherein the process execution means executes the application configuration file stored in the file space to perform a boot process of the application; The error detection tool performs error detection on the application configuration file stored in the file space, in parallel with the application's boot process by the process execution tool; and If the error detection tool detects an error in the application configuration file, the reboot tool reboots the application using one or more backup files stored in the one or more backup file areas. [7] Information processing device according to claim 6, wherein when the error detection means detects an error in the application configuration file, the reboot means performs a recovery process to restore the application configuration file stored in the file space with one of the one or more backup files stored in the one or more backup file spaces, and reboots the application using the replaced application configuration file stored in the file space. [8] Information processing device according to claim 7, wherein: the number of one or more backup file areas is multiple; and During the recovery process, the reboot tool refers to history information that shows a history of replacing the application configuration file with the backup files, selects the backup file to be used for replacement from among the backup files stored in the backup file areas based on the history information, and replaces the application configuration file with the selected backup file. [9] Information processing device according to claim 8, wherein the reboot means in the recovery process further refers to a replacement order information which indicates an order of backup files for replacement, selects the backup file to be used for replacement from among the backup files, based on the replacement order information and the history information, and replaces the application configuration file with the selected backup file. [10] Information processing device according to any one of claims 7 to 9, wherein: the number of one or more backup file areas is multiple; and The reboot tool, when performing the recovery process, selects a backup file that was not used for replacement from among the backup files stored in the backup file areas, and replaces the application configuration file stored in the file area with the selected backup file. [11] Information processing device according to any one of claims 6 to 10, wherein: the number of one or more backup file areas is multiple; The replacement tool performs a file replacement process to replace the application configuration file with a new application configuration file; and The replacement agent in the file replacement process receives the new application configuration file, replaces a predetermined backup file of the backup files stored in the backup file areas with the new application configuration file, replaces the application configuration file stored in the file area with the predetermined backup file, and when the replaced application configuration file is executed, if no error occurs, replaces one or more of the backup files other than the predetermined backup file with the replaced predetermined backup file or the replaced application configuration file, and if an error occurs, replaces the application configuration file stored in the file area with one of the backup files other than the predetermined backup file. [12] Information processing device according to claim 11, wherein when the error detection means detects an error in the application configuration file, and when the backup file areas do not contain a backup file that has not been used for replacement, the replacement means performs the file replacement process. [13] Information processing device according to any one of claims 6 to 12, wherein: The file space stores a multitude of application configuration files, each serving as the application configuration file, such that the multitude of application configuration files can be read in units of a single application configuration file; and Each of the one or more backup file areas stores a multitude of backup files that are identical in content to the multitude of application configuration files. [14] Information processing device according to claim 13, wherein: The file area also stores error recording data for each of the application configuration files; The error detection tool performs error detection on the application configuration files stored in the file space, using the error detection data for the application configuration files. [15] Information processing techniques, comprehensive: a process execution step for executing a program to boot a system, stored in non-volatile memory, to perform a boot process of the system, wherein the non-volatile memory has a program area that stores the program and a plurality of backup areas, each storing a backup program that is identical in content to the program; an error detection step to perform error detection on the program stored in the program area, in parallel with the boot process in the process execution step; and a reboot step to perform a recovery process if the error detection step detects an error in the program, in order to replace the program stored in the program area with one of the backup programs stored in the backup areas, and reboot the system using the replaced program stored in the program area; wherein The reboot step during the recovery process refers to history information that shows a history of replacing the program with the backup programs, selects the backup program from among the backup programs to be used for replacement based on the history information, and replaces the program with the selected backup program. [16] Information processing method according to claim 15, wherein the reboot step in the recovery process further refers to a replacement sequence information which indicates an order of backup programs for replacement, selects the backup program from among the backup programs to be used for replacement based on the replacement sequence information and the history information, and replaces the program with the selected backup program. [17] Information processing method according to claim 15 or 16, wherein the backup program selected in the recovery process is a backup program that has not been used for replacement. [18] Information processing method according to any one of claims 15 to 17, further comprising a replacement step for carrying out a program replacement process to replace the program with a new program that was not stored in the backup areas, wherein the replacement step in the program replacement process receives the new program, replaces a predetermined backup program of the backup programs stored in the backup program areas with the new program, replaces the program stored in the program area with the predetermined backup program, and when the replaced program is executed, if no error is present, replaces one or more of the backup programs other than the predetermined backup program with the replaced predetermined backup program or the replaced program, and if an error is present, replaces the program stored in the program area with one of the backup programs other than the predetermined backup program. [19] Information processing method according to claim 18, wherein if the error detection step detects an error in the program, and if the backup areas do not contain a backup program that has not been used for replacement, the program replacement process is carried out. [20] Information processing method according to any one of claims 15 to 19, wherein: The non-volatile memory further comprises a file area that stores an application configuration file for booting an application, and one or more backup file areas, each storing a backup file that is identical in content to the application configuration file; The process execution step executes the application configuration file, which is stored in the file space, to perform a boot process of the application; The error detection step performs error detection on the application configuration file stored in the file area, in parallel with the application's boot process in the process execution step; and If the error detection step detects an error in the application configuration file, the reboot step reboots the application using one or more backup files stored in the one or more backup file areas. [21] Information processing method according to claim 20, wherein when the error detection step detects an error in the application configuration file, the reboot step performs a recovery process to replace the application configuration file stored in the file space with one of the one or more backup files stored in the one or more backup file spaces and reboots the application using the replaced application configuration file stored in the file space. [22] Information processing method according to claim 21, wherein: the number of one or more backup file areas is multiple; and The reboot step during the recovery process refers to history information that shows a history of replacing the application configuration file with the backup files, selects the backup file from among the backup files stored in the backup file areas to be used for replacement based on the history information, and replaces the application configuration file with the selected backup file. [23] Information processing method according to claim 22, wherein the reboot step in the recovery process further refers to a replacement order information which indicates an order of backup files for replacement, selects the backup file from among the backup files to be used for replacement based on the replacement order information and the history information, and replaces the application configuration file with the selected backup file. [24] Information processing method according to any one of claims 21 to 23, wherein: the number of one or more backup file areas is multiple; and During the reboot step of the recovery process, a backup file that was not used for replacement is selected from among the backup files stored in the backup file areas, and the application configuration file stored in the file area is replaced with the selected backup file. [25] Information processing method according to any one of claims 21 to 24, wherein: the number of one or more backup file areas is multiple; The replacement step performs a file replacement process to replace the application configuration file with a new application configuration file; and The replacement process in the file replacement process receives the new application configuration file, replaces a predetermined backup file from the backup files stored in the backup file areas with the new application configuration file, replaces the application configuration file stored in the file area with the predetermined backup file, and when the replaced application configuration file is executed, if no error occurs, replaces one or more of the backup files other than the predetermined backup file with the replaced predetermined backup file or the replaced application configuration file, and if an error occurs, replaces the application configuration file stored in the file area with one of the backup files from the predetermined backup file. [26] Information processing method according to claim 25, wherein, if the error detection step detects an error in the application configuration file, and if the backup file areas do not contain a backup file that has not been used for replacement, the file replacement process is carried out. [27] Information processing method according to any one of claims 20 to 26, wherein: The file space stores a multitude of application configuration files, each serving as the application configuration file, such that the multitude of application configuration files can be read in units of a single application configuration file; and Each of the one or more backup file areas stores a multitude of backup files that are identical in content to the multitude of application configuration files. [28] Information processing method according to claim 27, wherein: The file area also stores error recording data for each of the application configuration files; The error detection step performs error detection on the application configuration files stored in the file area, using the error detection data for the application configuration files. [29] Computer program that causes a computer to execute: a process execution step for executing a program to boot a system, stored in non-volatile memory, to perform a boot process of the system, wherein the non-volatile memory has a program area that stores the program and a plurality of backup areas, each storing a backup program that is identical in content to the program; an error detection step to perform error detection on the program stored in the program area, in parallel with the boot process in the process execution step; and a reboot step to perform, if the error detection step detects an error in the program, a recovery process to replace the program stored in the program area with one of the backup programs stored in the backup areas, and reboot the system using the replaced program stored in the program area; wherein The reboot step during the recovery process refers to history information that shows a history of replacing the program with the backup programs, selects the backup program from among the backup programs to be used for replacement based on the history information, and replaces the program with the selected backup program.
Citation Information
Patent Citations
Fault tolerant recovery block with reduced flash footprint
US20040268116A1
BIOS, computer device and method for recovering BIOS
US20100205423A1
Method for protecting redundant data
US20110093675A1
Information processing system capable of updating a BIOS programme without interrupting or stopping the operational of a system
US5835761A