Electronic device capable of uninterrupted firmware updates and booting method using electronic device

The method addresses operational interruptions and cost issues in firmware updates by using a processor with one XiP flash memory and external banks for seamless updates, ensuring continuous operation and cost-effectiveness.

JP2025094907APending Publication Date: 2025-06-25TELECHIPS INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024204653
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-13
Filing Date
2024-11-25
Publication Date
2025-06-25

AI Technical Summary

Technical Problem

Existing firmware update methods for processors face challenges such as operational interruptions during updates and increased chip size and cost due to the use of dual flash memories for seamless operation.

Method used

A seamless firmware update method using a processor with one XiP flash memory and an external memory without XiP function, partitioned into multiple banks, allowing firmware to be stored and managed across these banks, with an interface for OTA updates and a controller to manage firmware versions and availability.

Benefits of technology

Enables seamless firmware updates without operational interruptions and reduces costs by using a single XiP flash memory, maintaining device functionality and supporting OTA updates with smaller chip size.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025094907000001_ABST
    Figure 2025094907000001_ABST
Patent Text Reader

Abstract

To provide an electronic device capable of uninterrupted firmware updates using a legacy processor having one internal XiP flash memory and a Non-XiP external memory, and a booting method using the electronic device.SOLUTION: The present invention provides an electronic device capable of uninterrupted firmware updates, comprising: a processor in which first firmware is stored in one flash memory that supports a software execution (eXecute in Place, XiP) function using an external memory; an external memory that is located outside the processor and stores second firmware but does not have the XiP function; and an interface that uses OTA (Over The Air) to communicate with an external system having third firmware and receives the third firmware from the external system.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to firmware update of a processor, and more particularly, to an electronic device capable of seamless firmware update and a booting method using the electronic device.

Background Art

[0002] In recent years, in the automotive field, a seamless firmware update method has been widely used in a system that supports OTA (Over The Air) update.

[0003] The reason is that there are advantages in that a bootable system can be maintained in a flash memory while the OTA update is in progress, and that booting can be performed with the existing F / W even if the firmware (F / W) update fails, thus maintaining usability.

[0004] FIG. 1 is a diagram showing a firmware update process of a processor having one existing flash memory and a firmware change operation during booting.

[0005] FIG. 1(a) shows that firmware A is stored in a flash memory 112 that supports an eXecute in Place (XiP) function using an external memory of a processor 110. FIG. 1(b) shows that the existing firmware A in the XiP flash memory 112 of the processor 110 is updated to firmware B via OTA. During booting, the bootloader 120 of the processor 110 executes firmware B.

[0006] In the process 150 of updating the new firmware B from the external system 100, since the flash memory 112 for XiP is in the process of being used from firmware A to the new firmware B, a blank period of the firmware occurs in the flash memory 112 for XiP, and the device 111 inside the processor 110 has a problem that it cannot operate the firmware A in the flash memory 112 for XiP of the processor 110 during the update.

[0007] Figure 2 is a diagram showing the firmware update process of a processor having an existing dual bank and the firmware change operation during booting.

[0008] As shown in (a) of Figure 2, the processor 210 can include a first flash memory 212 for XiP and a second flash memory 213 for XiP. Firmware A is stored in the first flash memory 212. When the external system 200 updates the firmware B to the second flash memory 213 of the processor 110, during the update, an internal or external device 211 of the processor 210 can use the firmware stored in the first flash memory 212, and an uninterrupted operation is possible.

[0009] (b) of Figure 2 shows the processor 210 after the update. During the booting after the update, the bootloader 221 of the processor 210 will perform the firmware B by selecting 224 the bank to be used from the first flash memory 212 to the second flash memory 213.

[0010] In the method of FIG. 2, even while the update is in progress, the processor 210 can execute the firmware in the XiP flash memory 1212, and even if the firmware update fails, it can be booted with the existing firmware A, which has the advantage of maintaining availability. However, since a processor having two flash memories is used, there is a problem that the chip size becomes larger and the unit price of the chip becomes higher.

Summary of the Invention

Problems to be Solved by the Invention

[0011] A technical problem of the present invention for solving the above-described problems is to provide an electronic device capable of seamless firmware update and a booting method using the electronic device, which uses a legacy processor having one XiP flash memory inside and a non-XiP external memory.

Means for Solving the Problems

[0012] According to one aspect for achieving the above object, an electronic device capable of seamless firmware update, wherein a first firmware is stored in one flash memory that supports a software execution (eXecute in Place, XiP) function using an external memory, a processor, and located outside the processor, an external memory without an XiP function for storing a second firmware, and an interface for receiving the third firmware of the external system through communication with the external system having the third firmware by OTA (Over The Air).

[0013] The processor and the external memory are connected by a data line, and the third firmware of the external system is transmitted to and used in the external memory through the data line.

[0014] The interface is connected to the processor, and the third firmware received via the interface is transmitted to the external memory via the processor and used in the external memory.

[0015] The external memory is partitioned into a plurality of banks, and different firmware can be stored in each of the partitioned banks.

[0016] It is further possible to include a controller that checks a flag indicating the version or presence / absence of different firmware used in each of the partitioned banks of the external memory, and determines a location in one of the partitioned banks to use the firmware to be updated stored in the non-volatile memory of the processor.

[0017] On the other hand, in an electronic device capable of seamless firmware update, comprising a processor that supports a software execute in place (XiP) function using an external memory, an external memory located outside the processor and having no XiP function, and an interface that receives the firmware of an external system having the firmware via communication with the external system, a method for booting the processor after firmware update, comprising: a step in which the processor attempts to boot using an existing bootloader; if the booting is successful, the processor enters an additional bootloader added during the update process, and the additional bootloader searches for available banks in the external memory; if there is new firmware in the available bank, the additional bootloader copies the new firmware to a flash memory inside the processor; and if authentication of the new firmware copied to the flash memory inside the processor is successful and booting using the new firmware is successful, entering the main function of the new firmware.

[0018] The step of searching for whether there is a bank available for use in the external memory of the added bootloader may include the step of searching for a bank with a history of the latest firmware update.

[0019] If the authentication of the new firmware copied to the flash memory fails or the booting using the new firmware fails, the existing firmware in the existing bank is copied to the internal flash memory of the processor, and after rollback, the main function of the existing firmware can be performed.

[0020] On the other hand, a plurality of processors having firmware whose operation is being executed in a flash memory that supports a software execute in place (XiP) function using an external memory, and one external memory located outside the plurality of processors and having no XiP function for storing a plurality of firmwares, and at least one interface for receiving the firmware to be updated that the external system has through communication with the external system having the firmware to be updated by over the air (OTA).

[0021] The plurality of processors and the one external memory are connected by a data line, and the firmware to be updated is transmitted from the plurality of processors to the one external memory through the data line and used.

[0022] The at least one interface is connected to the plurality of processors, and the firmware to be updated received through the at least one interface is transmitted to the one external memory through the plurality of processors and used in the one memory.

[0023] The one external memory is partitioned into a plurality of banks, and different firmwares can be stored in each of the partitioned banks.

[0024] The electronic device can further include a controller that checks flags indicating different firmware versions or the presence or absence used for each of the partitioned banks of the one external memory, and determines a location for using the firmware to be updated stored in the non-volatile memory of each of the plurality of processors in one of the partitioned banks.

Advantages of the Invention

[0025] According to the electronic device capable of seamless firmware update and the booting method using the electronic device of the present invention, seamless firmware update can be supported while using a legacy processor having one flash memory for XiP.

[0026] Also, it can be realized at a lower cost than an existing update device using dual flash memory.

[0027] On the other hand, an update using OTA is possible while using a processor with a smaller size than a processor having dual flash memory.

[0028] Also, in an update device using OTA, there is no limit to the number of firmware that can be backed up depending on the size of the external flash memory.

Brief Description of the Drawings

[0029]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Mode for Carrying Out the Invention

[0030] Hereinafter, preferred embodiments of the present invention will be described with reference to the accompanying drawings. However, some configurations not related to the gist of the invention will be omitted or compressed. However, even if they are omitted configurations, they are not necessarily configurations unnecessary in the present invention, and can be combined and used by those having ordinary knowledge in the technical field to which the present invention belongs.

[0031] FIG. 3 is a diagram showing the firmware change operation in the processor assembly during firmware update and booting using the processor assembly according to an embodiment of the present invention.

[0032] As shown in FIG. 3(a), the processor assembly 310 of the present invention can be composed of a processor 320, an external memory 360, and an interface 364. The processor 320 and the external memory 360 are connected via a data line 363, and communication between the external system 300 and the processor assembly 310 is made via the interface 364. Here, the processor includes an MCU.

[0033] The external system 300 will come to receive the new firmware B (350) via OTA. After that, the external system 300 will transmit the firmware B to the non-volatile memory SRAM (not shown) inside the processor 320 through communication with the processor 320 where the firmware A stored in the XiP flash memory 322 inside the processor 320 is being executed. Here, the interface 364 can use UART, SIP, etc. The new firmware B received through communication with the external system 300 will be used in the external memory 360 via the data line 363.

[0034] Here, the processor 320 may be all commercial processors having one XiP flash memory 322 inside. And the external memory 360 is a memory without XiP function and can have a dual-bank structure composed of a bank A 361 and a bank B 362.

[0035] As shown in FIG. 3, it shows the case where the firmware A is stored in the bank A 361 of the external memory 360 in advance, and the bank B 362 is shown as blank without firmware. However, there may be no pre-used firmware in both the bank A 361 and the bank B 362, and the firmware can be pre-used in the bank B 362. The firmware stored in the bank A 361 may be different from the firmware being executed by the processor 320.

[0036] As shown in FIG. 3, the processor assembly 310 can include a controller 365. The controller 365 will check the flags indicating the version or presence / absence of the pre-used firmware in each of the banks 361, 362 of the external memory 360 and determine the location where the firmware to be updated will be used. Here, the controller 365 can be arranged inside the processor 320 or inside the external memory 360.

[0037] As shown in FIG. 3, the firmware update process using OTA according to an embodiment of the present invention is performed in an external memory 360 other than the flash memory 322 inside the processor 320. Thus, even during the OTA update process, the device 321 inside or outside the processor 320 operates on the firmware A stored in the flash memory 322 in the processor 320, so that the operation using the firmware A of the processor 320 does not stop.

[0038] FIG. 3(b) shows the states of the processor 310 and the external memory 360 after the OTA update, and it can be seen that the new firmware B is used in the B bank 362 of the external memory 360. At the time of booting after the update, the bootloader 331 of the processor 320 copies the firmware B in the B bank 362 to the flash memory 322 of the processor 320 via the data line 363 and operates on the new firmware B.

[0039] FIG. 4 is a diagram showing the firmware change operation in the processor assembly during firmware update and booting using the processor assembly according to another embodiment of the present invention.

[0040] As shown in FIG. 4, the processor assembly 410 according to another embodiment of the present invention can be composed of a first processor 420, a second processor 430, an external memory 440, and an interface 460. The first processor 420 and the second processor 430 are connected to the external memory 440 via a data line 463.

[0041] As shown in FIG. 4, the external memory 440 has a structure composed of a bank A 441, a bank B 442, a bank C 443, and a bank D 444. When firmware A is stored in the bank A 441 in advance and firmware B is stored in the bank B 442, it is shown that the banks C 443 and D 444 are blank without firmware. However, the firmware version and presence stored in each bank can be changed in various ways.

[0042] The external system 400 will successively or simultaneously receive new firmware C and D (450) via OTA. Thereafter, the external system 400 will transmit the new firmware C and D to the internal memory SRAM (not shown) of the processors 420 and 430 via the first and second interfaces 460 and 461. Thereafter, the new firmware C and D received by OTA communication will be used for the banks C 443 and D 444 of the external memory 440 via the data line 463. Here, the functions of the first and second interfaces 460 and 461 can be realized by one interface.

[0043] Here, the processors 420 and 430 may be all commercial processors having one XiP flash memory 422 and 432 inside, and can also be composed of three or more processors as long as the memory capacity is supported. And the external memory 440 is a memory without the XiP function, indicating that the inside can be composed of a plurality of banks.

[0044] As shown in FIG. 4, the processor assembly 410 further includes a controller 470. The controller 470 will check the flag indicating the version or presence of the firmware used in advance for each bank partitioned in the external memory 440, and determine the usage location of the firmware to be updated.

[0045] In this way, by dividing the external memory 440 into a plurality of banks in the processor assembly 410 having a plurality of processors 420, 430 and the external memory 440, and storing the firmware, the firmware to be updated can be used by the target processor according to a schedule or in a determined order.

[0046] FIG. 5 is a booting flowchart of a processor after firmware update according to an embodiment of the present invention.

[0047] The booting flowchart of FIG. 5 is performed in the processor assembly 310 which is an embodiment of the present invention in FIG. 3, and is performed in the states of the processor 320 and the external memory 360 shown in FIG. 3(b). First, when booting starts (step S410), the processor 320 attempts to boot using the existing bootloader (step S411), and when the booting fails, it enters the recovery mode (step S412).

[0048] If the booting is successful in step S411, it enters the bootloader 331 added in the update process (step S413), and the added bootloader 331 searches for available banks in the external memory 360 (step S414). If there are available banks, it selects the bank with the highest priority (step S416). Here, the priority can include the bank with a history of recent data usage.

[0049] If there are no available banks in step S414, it performs the main function of the existing firmware (step S415).

[0050] After step S416, it checks whether there is new firmware in the bank with the highest priority (step S417). If there is new firmware in the bank with the highest priority, it copies the new firmware in the bank with the highest priority to the flash memory 322 inside the processor 320 (step S418).

[0051] If there is no new firmware in the bank with the highest priority in step S417, step S415 is performed.

[0052] After step S418, if authentication of the new firmware copied to the flash memory 322 inside the processor 320 fails or if booting using the new firmware fails, the existing firmware in the existing bank is copied to the internal flash memory 322 (step S420), and after rollback, the main function of the existing firmware is performed (step S422).

[0053] If authentication of the new firmware copied to the flash memory 322 inside the processor 320 is successful in step S419 and booting using the new firmware is successful, the main function of the new firmware is entered (step S421).

Explanation of Signs

[0054] 300, 400 External systems 310, 410 Processor assemblies 320, 420, 430 Processors 360, 440 External memories 364, 460, 461 Interfaces 365, 470 Controllers

Claims

1. An electronic device capable of uninterrupted firmware updates, comprising: A processor in which a first firmware is stored in a flash memory supporting an execute in place (XiP) function using an external memory; an external memory without XiP function that is located outside the processor and stores a second firmware; an interface for receiving the third firmware from an external system via communication with the external system over the air (OTA); An electronic device capable of uninterrupted firmware updates, comprising:

2. 2. The electronic device capable of seamless firmware updates as claimed in claim 1, wherein the processor and the external memory are connected by a data line, and the third firmware of the external system is transmitted to the external memory via the data line for use.

3. 2. The electronic device capable of continuous firmware updates of claim 1, wherein the interface is coupled to the processor, and the third firmware received via the interface is transmitted to the external memory via the processor and used in the external memory.

4. 2. The electronic device capable of seamless firmware updates of claim 1, wherein the external memory is partitioned into a plurality of banks, and different firmware is stored in each of the partitioned banks.

5. The electronic device comprises: The electronic device capable of seamless firmware updates of any one of claims 1 to 4, further comprising a controller that checks a flag indicating the presence or absence of different firmware versions used in each of the partitioned banks of the external memory, and determines where to use the updating firmware stored in the non-volatile memory of the processor for one of the partitioned banks.

6. An electronic device capable of seamless firmware update includes a processor supporting an execute in place (XiP) function using an external memory, an external memory located outside the processor and not having a XiP function, and an interface for receiving firmware held by an external system having firmware through communication with the external system via OTA (Over The Air), A method for booting the processor after the firmware update, comprising: the processor attempting to boot using an existing boot loader; If the booting is successful, the processor enters a boot loader added during the update process, and the added boot loader searches the external memory for an available bank; the boot loader copies new firmware to a flash memory within the processor when new firmware is available in the available bank; entering a main function of the new firmware if authentication of the new firmware copied to the flash memory in the processor is successful and booting using the new firmware is successful; 23. A method for booting a processor, comprising:

7. The step of searching for an available bank in the external memory of the added boot loader includes:

7. The method of claim 6, further comprising the step of searching for a bank having a history of the latest firmware being updated.

8. 7. The processor booting method of claim 6, further comprising the step of copying an existing firmware in an existing bank to the internal flash memory of the processor and performing a main function of the existing firmware after rollback if authentication of the new firmware copied to the flash memory fails or booting using the new firmware fails.

9. A plurality of processors having firmware currently in operation in a flash memory supporting an execute in place (XiP) function using an external memory; an external memory that is located outside the processors and does not have an XiP function and stores a plurality of firmware; At least one interface for receiving the firmware to be updated from an external system via communication with the external system having the firmware to be updated over the air (OTA); An electronic device capable of uninterrupted firmware updates, comprising:

10. 10. The electronic device capable of seamless firmware updates according to claim 9, wherein the plurality of processors and the one external memory are connected by a data line, and the firmware to be updated is transmitted from the plurality of processors to the one external memory via the data line for use.

11. 10. The electronic device capable of seamless firmware updates of claim 9, wherein the at least one interface is coupled to the plurality of processors, and the updating firmware received via the at least one interface is transmitted to the one external memory via the plurality of processors and used in the one memory.

12. 10. The electronic device capable of seamless firmware updates according to claim 9, wherein the single external memory is partitioned into a plurality of banks, and different firmware is stored in each of the partitioned banks.

13. The electronic device comprises: The electronic device capable of seamless firmware updates of any one of claims 9 to 12, further comprising a controller that checks a flag indicating the presence or absence of different firmware versions used in each of the partitioned banks of the one external memory, and determines where to use the updating firmware stored in the non-volatile memory of each of the multiple processors in one of the partitioned banks.