Information processing apparatus, recovery method for information processing apparatus, and program
The information processing apparatus addresses the challenge of FPGA firmware verification and recovery by using a recovery program to restore minimal functions when communication fails, enhancing error recovery and reducing service calls.
Patent Information
- Application Number
- JP2024004657
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-01-16
- Publication Date
- 2025-07-29
AI Technical Summary
Existing technologies are inadequate for verifying and recovering Field-Programmable Gate Array (FPGA) firmware due to the need for storing copies of software in advance and inability to cope with changes in hardware, especially when soft errors occur.
An information processing apparatus with a first subsystem that overwrites a recovery program onto the memory of a second subsystem when communication fails, using minimum configuration data to recover FPGA firmware with minimal functions.
Enables effective verification and recovery of various FPGA firmware types, allowing for suitable error recovery methods and reducing service calls by determining the cause of errors.
Smart Images

Figure 2025110683000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an information processing apparatus, a method for recovering the information processing apparatus, and a program.
Background Art
[0002] Generally, an electronic device system such as a printer system is often composed of a controller that controls the entire system and a plurality of peripheral devices. In a system with a relatively simple structure or a small variation in the configuration of peripheral devices, the configuration hardware of the controller is often fixed, and the software that operates the controller also has few variations. In such a system, since the controller is common, cost reduction by mass production is expected, but it is difficult to customize and the development cost becomes high. Such a system is called a fixed configuration system. Details of the fixed configuration system will be described later.
[0003] On the other hand, there is a system in which the functions of an electronic device system are modularized respectively. For example, there is a printer system in which functions such as printing, fixing, and paper conveyance are modularized respectively. According to needs, it is easy to customize by recombining the modules of each function, and the development cost is reduced. In such a system, as a controller for the module, a board equipped with an FPGA (Field-Programmable Gate Array) may be used. An FPGA is a device in which gates (logic circuits) that a designer can program the configuration of a logic circuit in the field (on-site) are integrated. In an FPGA, the circuit structure can be changed by a program, and an optimal circuit without waste can be configured according to the function of the module. It is characterized in that the designer can change the processing content of the FPGA. Such a system is called a variable configuration system with respect to a fixed configuration system. In a variable configuration system, since the software of the controller can be changed according to various peripheral devices, compared with a fixed configuration system, it is easier to change and expand the system. Therefore, there is an advantage that the development cost of the system is lower than that of the fixed configuration system. Details of the variable configuration system will be described later.
[0004] Patent Document 1 proposes an information processing apparatus that detects and recovers forgery by verifying a plurality of partial software that is started step by step, such as BIOS and other software. In the above prior art, a control program for realizing BIOS is stored in a flash ROM, and a copy of the control program for realizing BIOS is stored in a ROM. Then, a BIOS verification unit verifies the BIOS stored in the flash ROM, and if the verification fails, executes a recovery process of the BIOS stored in the flash ROM using the copy of the BIOS stored in the ROM, and issues a BIOS startup instruction to the CPU.
[0005] In addition, Patent Document 2 proposes a system that includes a configuration module and an FPGA, where the configuration module configures (programs) the FPGA when power is turned on and detects soft errors in the FPGA using error correction codes. In the technology of Patent Document 2, when a soft error is detected, the soft error can be avoided without stopping operation by reconfiguring the location where the soft error occurred in the FPGA.
[0006] In addition, Patent Document 3 proposes a system that has two CPUs, a processing program, and a forgery detection program for detecting forgery of the processing program inside the FPGA, and executes the processing program and the forgery detection program on separate CPUs inside the FPGA. In the technology of Patent Document 3, by having the forgery detection program inside the FPGA, it is possible to prevent the forgery detection program from being forged.
Prior Art Documents
Patent Documents
[0007]
Patent Document 1
Patent Document 2
Patent Document 3
Summary of the Invention
Problems to be Solved by the Invention
[0008] However, in the technology of Patent Document 1 described above, since it is necessary to store a copy of the software in the ROM in advance, there is a problem that it is not suitable for verifying and recovering the changeable firmware of the FPGA. Further, in the technologies of Patent Documents 2 and 3 described above, there is a problem that they cannot cope with changes in the FPGA program accompanying changes in the hardware. An object of the present invention is to provide an information processing apparatus suitable for verifying and recovering an FPGA by recovering the firmware of the FPGA with minimum configuration data having the minimum functions of the firmware of the FPGA when an error occurs in the FPGA.
Means for Solving the Problems
[0009] The information processing apparatus of the present invention has one or more units, the one or more units include a unit controller, the unit controller is composed of a first subsystem and a second subsystem, and when the first subsystem cannot communicate with the second subsystem at the time of starting the information processing apparatus, the first subsystem overwrites a recovery program on a memory in which the program of the second subsystem is stored.
Effects of the Invention
[0010] According to the information processing apparatus of the present invention, by recovering the firmware of the FPGA with minimum configuration data having the minimum functions of the firmware of the FPGA, it is possible to cope with verification and recovery of various types of firmware of the FPGA. Further, according to the verification of the present invention, it is possible to select a suitable recovery method for the cause of the error and determine whether to make a service call.
Brief Description of the Drawings
[0011]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Mode for Carrying Out the Invention
[0012] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the invention according to the claims. Although a plurality of features are described in the embodiments, not all of these plurality of features are essential for the invention, and the plurality of features may be arbitrarily combined. Further, in the accompanying drawings, the same or similar configurations are denoted by the same reference numerals, and redundant descriptions are omitted. In the following embodiments, the information processing apparatus according to the present invention will be described by taking an image forming apparatus as an example, but it is not limited to the image forming apparatus and may be a general information processing apparatus.
[0013] Referring to FIG. 1, the hardware configuration of a general image forming apparatus 101 will be described. The image forming apparatus 101 includes a scanner apparatus 102, a printer apparatus 104, an operation unit 105, a storage 106, a FAX apparatus 107, and a controller 103.
[0014] Scanner device 102 optically reads an image of a document and converts it into digital image data. Printer device 104 forms (prints) an image on paper media (paper) based on the digital image data. Operation unit 105 receives a user's operation on this image forming apparatus 101 and presents various information to the user. Note that this operation unit 105 may have a display unit having a touch panel function. Storage 106 is a large-capacity storage device that stores digital image data, control programs, and the like. This storage 106 includes, for example, a hard disk drive (HDD) or an SD memory. FAX device 107 transmits and receives digital image data via a telephone line or the like by facsimile.
[0015] Controller (control unit) 103 is connected to each of the above-described units and controls each unit, whereby various jobs can be executed on image forming apparatus 101. Further, image forming apparatus 101 can transmit and receive digital image data and the like to and from computer 109 via LAN 108. Further, computer 109 can issue a job to image forming apparatus 101 and also give instructions for the device. LAN 108 may be a wired LAN or a wireless LAN connected by a wireless router.
[0016] Scanner device 102 has a document feeding unit 121 that stacks a bundle of documents and automatically feeds the documents, and a scanner unit 122 that optically scans the documents and converts them into digital image data. The converted digital image data is transmitted to controller 103. Printer device 104 has a paper feeding unit 142 that can feed sheets one by one from a bundle of papers, a marking unit 141 for printing image data on the fed paper, and a paper discharging unit 143 for discharging the printed paper.
[0017] Also, the computer 109 issues an instruction to the controller 103 via the LAN 108 to execute a job. In this embodiment, the computer 109 can control the power-off sequence of the image forming apparatus 101 by sending a power-off instruction to the controller 103.
[0018] This image forming apparatus 101 is capable of executing various jobs. Examples of these jobs are shown below. · Copy function Record the image data of the document image read by the scanner device 102 in the storage 106 and perform printing using the printer device 104. · Image transmission function Transmit the image data obtained from the scanner device 102 to the computer 109 via the LAN 108. · Image storage function Store the image read from the scanner device 102 in the storage 106 and perform image transmission or printing as needed. · Image printing function Analyze, for example, the page description language transmitted from the computer 109 and perform printing with the printer device 104.
[0019] Referring to FIG. 2, the hardware configuration of the general controller 103 of the image forming apparatus 101 in FIG. 1 will be described. The controller 103 includes a main system 200 and a subsystem 220. The main system 200 is a so-called general-purpose CPU system. The main system 200 has a CPU 201, a boot ROM 202, a memory 203, a bus controller 204, a non-volatile memory 205, a disk controller 206, a flash disk 207, a USB controller 208, a network interface 210, and an RTC 211.
[0020] The CPU 201 controls the entire main system. The boot ROM 202 stores the boot program. The memory 203 is used by the main CPU 201 as a work memory. The bus controller 204 has a bridging function with the external bus. The non-volatile memory 205 is a memory whose content does not disappear even when the power is turned off. The disk controller 206 controls the storage 106. The flash disk 207 is an SSD or the like, and is a relatively small-capacity non-volatile storage device composed of semiconductor devices. The USB controller 208 controls USB devices connected to the outside of the main system 200. Outside the main system 200, a USB memory 209, an operation unit 105, a storage 106, etc. are connected.
[0021] The subsystem 220 has a relatively small general-purpose sub-CPU system and image processing hardware. The subsystem 220 has a sub-CPU 211, a memory 223, a bus controller 224, a non-volatile memory 225, an image processing processor 226, a printer controller 227, and a scanner controller 228.
[0022] The sub-CPU 211 controls the entire subsystem. The memory 223 is used by the sub-CPU 221 as a work memory. The bus controller 224 has a bridging function with the external bus. The non-volatile memory 225 is a memory whose content does not disappear even when the power is turned off. The image processing processor 226 performs digital image processing in real time. A printer controller 227 and a scanner controller 228 are connected to the image processing processor 226. The printer controller 227 controls the printer device 104 and delivers digital image data to the printer device. The scanner controller 228 controls the scanner device 102 and receives digital image data from the scanner device 102. Note that the FAX device 107 is directly controlled by the sub-CPU 221.
[0023] Note that FIG. 2 is merely a simplified block diagram. For example, the main CPU 201, the sub CPU 221, etc. include a large number of hardware components around the CPU such as a chipset, a bus bridge, a clock generator, etc., but these are simplified in the description of the embodiment because they are unnecessary for the description of the embodiment. The block configuration shown in FIG. 2 does not limit the scope of the present invention.
[0024] Next, the control process by the general controller 103 will be described by taking the image copying (copying) onto paper as an example. When the user instructs the image copying (copying) from the operation unit 105, the main CPU 201 sends an image reading command to the scanner device 102 via the sub CPU 221. As a result, the scanner device 102 optically scans and reads the document, converts it into digital image data corresponding to the image of the document, and inputs it to the image processing processor 227 via the scanner controller 228. The image processing processor 226 temporarily stores the digital image data in the memory 223 by DMA transfer.
[0025] When the main CPU 201 confirms that a certain amount or all of the digital image data has been stored in the memory 223, it issues an image output instruction to the printer device 104 via the sub CPU 221. The sub CPU 221 notifies the image processing processor 226 of the address of the image data in the memory 223, and transmits the digital image data in the memory 223 to the printer device 104 according to the synchronization signal from the printer device 104. At this time, the digital image data is transmitted to the printer device 104 via the image processing processor 226 and the printer controller 227, and the digital image data is printed on the paper (sheet) by the printer device 104.
[0026] Also, when performing printing of a plurality of copies, the main CPU 201 stores the image data in the memory 223 in the storage 106. Then, for the second and subsequent copies, it is possible to output the digital image data read from the storage 106 to the printer device 104 for printing without receiving the digital image data from the scanner device 102.
[0027] In the system configurations described with reference to FIGS. 1 and 2, the functions to be realized are determined in advance. Therefore, it is a system in which the functions to be realized are fixed or, even if they can be changed, only a few variations are assumed. Therefore, the software that controls the controller is also fixed with almost no change to the hardware configuration of the system and the controller module configuration that controls it. In this specification, such a system with fixed functions that is not premised on being changed is referred to as a fixed-configuration system.
[0028] <Embodiment 1> Next, with reference to FIG. 3, a variable-configuration system according to the present embodiment will be described with respect to the fixed-configuration system described above. Similar to FIGS. 1 and 2, a printer system will be described as an example, but the variable-configuration system of the present invention is not limited to a printer system.
[0029] As shown in FIG. 3, the printer system of the present embodiment is configured such that a computer 109 and a print server 110 are connected via a LAN. A user can control the printer system using the computer 109. The print server 110 is connected to a printer unit 301, a fixing unit 302, a paper conveyance unit 303, and other units 304, and controls each of these constituent units. In response to an instruction from the user, the computer 109 transmits print job information to the print server 110. The print server 110 can temporarily store the received print job information and further control each constituent unit to execute the print job.
[0030] The printer unit 301 forms a pattern with toner on a paper surface based on image data. The fixing unit 302 fixes the pattern formed with toner onto the paper surface by heat. The paper conveyance unit 303 takes out paper for printing from a paper supply unit, sequentially moves it to the processing positions of each device, and finally discharges it to a paper discharge unit.
[0031] Furthermore, it is possible to cooperate with other units 304 to execute a printing job. As will be described later, on this platform, the hardware of each unit can be arbitrarily replaced. The units constituting the print server 110 are not limited to these, and may include any other units. The print system shown in FIG. 3 can change the configuration of the print system by replacing units according to the configuration of the printer system. In this specification, a system capable of changing the configuration of such a system is referred to as a variable configuration system with respect to the fixed configuration system described above.
[0032] Next, with reference to FIG. 4, the configuration of the unit controller of the variable configuration system in the present embodiment will be described. In FIG. 3, it was described that a printing job is input from the computer 109 to the print server 110 and the printing job is executed by each unit. The controller including the motherboard 410 shown in FIG. 4 corresponds to the controller of each unit in FIG. 3. The motherboard 410 of each unit has a different function board 412 depending on the function provided, but the basic configuration is the same.
[0033] The unit controller of each unit in the present embodiment is composed of a CPU board 401 and a base board 410. The CPU board 401 is a board on which a CPU is mounted. As the CPU to be mounted, for example, CPUs provided by Intel (registered trademark), Arm (registered trademark), etc. can be considered, but are not limited thereto.
[0034] The base board 410 is equipped with an FPGA 411 and is connected to the CPU board 401. Further, the base board 410 is provided with one or more slots into which the function board 412 can be inserted. The FPGA 411 can change its circuit structure by a program and can configure an optimal circuit according to the function of each unit. In the present embodiment, the FPGA 411 operates with different firmware according to the functions of the printer unit 301, the fixing unit 302, the paper conveyance unit 303, and the other unit 304. The firmware of the FPGA 411 can be changed on-site according to the function of the unit.
[0035] Here, the structure and operation of the FPGA will be described. The FPGA is composed of a gate array and a configuration memory. Instead of realizing a logic circuit with transistors, the FPGA holds the data of the truth table of the logic circuit (configuration data) in the configuration memory and virtually serves as the gates of the logic circuit. For this reason, in the FPGA, the circuit configuration of the gate array of the FPGA can be changed by changing the configuration data. Generally, loading the configuration data into the FPGA is called the configuration of the FPGA. Since the configuration data represents the circuit configuration of the FPGA, it can be called the program of the FPGA.
[0036] Generally, an SRAM is used for the configuration memory of the FPGA. Since the SRAM is volatile, the configuration data is stored in the flash memory, and the configuration data is loaded into the configuration memory of the FPGA when the power is turned on. The flash memory for storing the configuration data is generally provided externally separately from the FPGA, but it may be incorporated into the FPGA and configured as one chip.
[0037] There are also FPGAs that use flash memory instead of SRAM for the configuration memory. Compared to using SRAM for the configuration memory, it has the advantages of lower power consumption and can start up quickly because it does not require loading when powered on. On the other hand, since it requires a manufacturing process specific to flash cells, it has the disadvantage of being costly.
[0038] In a system using such an FPGA, since an FPGA and rewritable firmware are installed, there is a possibility of errors occurring in the FPGA and the firmware. There are two types of FPGA errors: hard errors and soft errors. In the case of a hard error, the FPGA itself is damaged and the error is reproduced even after a restart. Hard errors can be caused by physical impacts due to carelessness or damage due to power abnormalities.
[0039] Recent research has shown that errors can occur in semiconductor devices due to cosmic rays (neutrons) that pour down on the earth. Neutrons may accidentally hit semiconductor devices and invert the data stored as 0s and 1s. Since an FPGA stores circuit information in SRAM, when the 0s and 1s of the SRAM circuit information are inverted, the circuit configuration changes and normal operation becomes impossible. Such an error is called a soft error, and in the case of a soft error, it can often be recovered by restarting or reconfiguring the SRAM of the FPGA from the flash memory.
[0040] Returning to the explanation of FIG. 4. The base board 410 can be replaced with a function board 412, which is a small board. Each unit has a different function to be realized. For example, since the fixing unit 302 needs to generate heat to fix the pigment at a high temperature, components that generate heat are required. On the other hand, the paper conveyance unit 303 requires a motor to convey the paper. The function board 412 is mounted on the base board 410 with different types, numbers, and combinations in order to realize different functions for each unit. The function board 412 can be arbitrarily replaced according to changes in the hardware.
[0041] The base board 410 is provided with a connector 413. The connector 413 is for connecting to the unit cases of each unit and has a plurality of pins. Based on the potential of each pin of the connector 413, the base board 410 can determine which unit it is connected to.
[0042] The printing server 110 receives a printing job from the computer 109 and controls each unit based on the printing job to execute printing. Also, the printing server 110 stores configuration data, which is the firmware program of the FPGA 411. By writing the configuration data into the configuration memory of the FPGA 411, the firmware of the FPGA 411 can be updated.
[0043] The unit controller of the variable configuration system in this embodiment can correspond to the functions of various units by replacing the function board 412. It is difficult for the CPU board 401 to control corresponding to all types of function boards 412. This is because the capacity of the non-volatile memory on the CPU board is usually about several hundred MB, while the types of function boards 412 and their combinations are almost infinite. Therefore, a mechanism for providing a control method to the CPU board according to the combination of the function boards 412 is required, and the FPGA 411 plays that role.
[0044] In this embodiment, the CPU board 401 is configured to update the firmware of the FPGA 411 at startup. The CPU board 401 can communicate with and control the function board 412 via the FPGA 411.
[0045] Referring to FIG. 4, the execution operation of the print job in the unit controller will be described. Each sequence number included in FIG. 4 is indicated by a number starting with "S". The print server 110 receives a print job from the computer 109 and transfers the received print job to the CPU board 401 (S431).
[0046] The CPU board 401 controls the print job for the FPGA 411 (S432). Specifically, the CPU board 401 transfers print information, the number of copies, color settings, etc. of the print job to the FPGA 411. The FPGA 411 receives an instruction from the CPU board 401, controls the function board 412, and executes the print job (S433).
[0047] Referring to FIGS. 4 and 5, the update process of the FPGA firmware when each unit is started will be described. The process described below is realized, for example, by the CPU of the CPU board 401 reading a program stored in the non-volatile memory into the memory and executing it. Hereinafter, each step number of the processes included in the flowchart is indicated by a number starting with "S". The same applies to the subsequent flowcharts.
[0048] By starting the printer system, the process of FIG. 5 is started. In S501, the startup process inside the CPU board 401 of each unit controller is performed. The system is started from the bootloader, and the OS and applications are started. In the present embodiment, the base board 410 is equipped with a flash memory (not shown), and the flash memory functions as a configuration device, and configuration data for operating the FPGA 411 is stored. Along with the startup, the configuration data stored in the flash memory is loaded into the SRAM, which is the configuration memory of the FPGA 411. Hereinafter, the description will be made on the premise of this configuration, but the configurations of the configuration device and the configuration memory are arbitrary. For example, a flash memory may be provided inside the FPGA 411, or the configuration memory itself may be configured with a flash memory.
[0049] In S502, the CPU board 401 determines whether it can communicate with the FPGA 411 of the base board 410. In S502, if communication with the base board 410 is possible (YES), the process proceeds to S511; if communication is not possible (NO), the process proceeds to S521. Here, the case where communication is not possible includes not only the case where communication itself cannot be established, but also the case where communication is possible but some error has occurred and it is not operating normally, including the state where the configuration information of the base board 410 in S511 cannot be obtained.
[0050] In S502, if it is YES, first, the CPU board 401 establishes communication with the base board 410. Next, the FPGA 411 of the base board 410 obtains from the connector 413 which unit the base board 410 itself is inserted into. Also, the FPGA 411 obtains information such as the type and number of function boards 412. Then, the FPGA 411 transfers the obtained unit information and the information of the function board 412 to the CPU board 401 as the configuration information of the base board 410 (S421).
[0051] In S511, the CPU board 401 obtains the configuration information of the base board 410 transferred from the FPGA 412. Then, the CPU board 401 requests the configuration data corresponding to the configuration information of the base board 410 from the print server 110 (S422). This configuration data varies depending on the configuration of the unit and is determined according to the configuration information of the base board 410. The print server 110 transfers predetermined configuration data to the CPU board 401 based on the configuration information (S423).
[0052] In S512, the CPU board 401 stores the configuration data received from the print server 110 in the flash memory, which is the configuration device of the FPGA 411. The FPGA 411 restarts and writes the updated configuration data to the configuration memory. As a result, the FPGA 411 can control the unit based on the latest configuration changed since the previous shutdown. In S513, the CPU board 401 communicates with the base board 410 to complete the startup process of the system.
[0053] Thus, in this embodiment, since the unit controller can detect hardware changes at startup, the firmware of the FPGA 411 is changed along with the hardware changes. Therefore, the printed system having the unit controller of this embodiment is a variable configuration system. In FIG. 5, the flow is started by the startup of the CPU board 401. However, when an error in the configuration data is detected by the error correction code, the processes of S511 to S515 may be performed.
[0054] As described above, the operations of the variable configuration system for executing a print job and the operations when the startup is normal have been explained. Next, with reference to FIG. 5, the operations when an error occurs at startup will be explained. In S502, when the CPU board 401 cannot communicate with the base board 410 (NO), the process proceeds to S521, and the operations below S521 are the operations in case of an error. When communication is impossible, as described above, the operation is not normal and includes a state where the configuration information of the base board 410 in S511 cannot be obtained.
[0055] In S521, it is determined that the startup of the unit controller has failed. If the communication with the FPGA 411 is not normal, it is determined that startup is impossible, and in S522, the print system is shut down. In S523, a service call to the call center is made. Thereafter, a serviceman is dispatched from the call center to perform recovery work.
[0056] Referring to FIG. 6, an example of an error that can occur in a variable configuration system will be described. The examples given here are for illustrative purposes only, and in an actual environment, there are not limited to the examples given here. The errors listed in FIG. 6 are assumed to occur in factories, work sites, etc. These errors may be classified into hard errors and soft errors. Furthermore, there are cases where recovery is possible on-site, cases where recovery is not possible, or cases where recovery is possible depending on the situation.
[0057] First, when the firmware is not written to the configuration device of the FPGA 411, the FPGA 411 cannot be started up. Such a case is a soft error and is considered to be caused by a work mistake in the factory or on-site. Since it can be solved by writing to the flash memory, on-site recovery is possible.
[0058] Next, when there is a logical error in the firmware of the FPGA 411, it is a soft error and is considered to be caused by a failure in the update. This is considered to be caused by an error when writing configuration data to the flash memory or an error when writing the configuration data to the SRAM of the FPGA 411. Such an error can be recovered on-site by rewriting the configuration data to the flash memory or restarting.
[0059] When the FPGA 411 is physically damaged, it is a hard error and is considered to be caused by human destruction or electrical circuit destruction due to power supply abnormality. Since it is necessary to replace the FPGA 411 or the base board 410 itself, on-site recovery is impossible.
[0060] Next, when the firmware of the FPGA 411 operates in an infinite loop, it is a soft error and is considered to be caused by a firmware bug. By updating the flash memory with the correct firmware (configuration data) and restarting, on-site recovery is possible.
[0061] Next, in the case of poor contact between the CPU board 401 and the base board 410, it is a hard error, which is considered to be caused by mistakes in factory or on-site installation work. In this case, whether on-site recovery is possible depends on whether the on-site user can handle it.
[0062] For the startup process shown in FIG. 5, when an error occurs in the FPGA shown in FIG. 6, it is determined that the startup fails in any case, and the system shuts down and a service call is made to the call center. On the other hand, as shown in FIG. 6, depending on the type of error, on-site recovery is possible. If on-site recovery is possible, there is no need for a service technician to be dispatched from the call center, which leads to cost reduction.
[0063] Next, the process of determining whether on-site recovery is possible, performing on-site recovery if it is possible, and making a service call to the call center only when on-site recovery is not possible will be described. The process described below is realized, for example, by the CPU of the CPU board 401 reading out the program stored in the non-volatile memory into the memory and executing it.
[0064] With reference to FIG. 7, the process of performing on-site recovery using the minimum configuration data built into the CPU board 401 will be described. By starting the printer system, the process of FIG. 7 starts. In S701, the startup process inside the CPU board 401 of each unit controller is performed. In S702, it is determined whether the CPU board 401 can communicate with the FPGA 411 of the base board 410. In S702, if communication with the FPGA 411 of the base board 410 is possible (YES), the process proceeds to S711, and the CPU board 401 establishes communication with the base board 410. On the other hand, if communication is not possible (NO), the process proceeds to S721. When communication is not possible, the operation is not normal and includes a state where the configuration information of the base board 410 in S711 cannot be obtained.
[0065] Since the processes of S711 to S713 are the same as those of S511 to S513 in FIG. 5, the description thereof is omitted. In FIG. 7, the flow starts with the startup of the CPU board 401, but the processes of S711 to S715 may be performed when an error in the configuration data is detected by an error correction code.
[0066] When it is determined that the CPU board 401 cannot communicate with the base board 410, the process proceeds to S721. The CPU of the CPU board 401 writes the built-in minimum configuration data, which will be described later, to the configuration device of the FPGA 411. Thereby, the minimum configuration data is reinstalled in the FPGA 411 of the base board 410. Note that the processes below S721 may be performed when an error in the configuration data is detected by an error correction code.
[0067] In S722, when it is determined that the reinstallation of the minimum configuration data has been successful (YES), the process proceeds to S723. In S723, the FPGA 411 attempts to restart by writing the reinstalled minimum configuration data to the SRAM. The recovery process by restart will be described later with reference to FIG. 8.
[0068] In S722, when it is determined that the reinstallation of the firmware has failed (NO), the process proceeds to S724, where the reinstallations of S721 and S722 are retried and repeated until the maximum number of retries is reached. In S724, if the reinstallation of the firmware still fails even after the maximum number of retries is reached, the process proceeds to S725. In S725, the printer system is shut down, and in S726, a service call is made to the call center. Thereafter, a service technician is dispatched from the call center to perform a recovery operation.
[0069] Referring to FIG. 8, the process of S723 in FIG. 7 will be described in detail. The process shown in FIG. 8 is a recovery process when the CPU board 401 fails to communicate with the FPGA 411 of the base board 410 during startup, but then the firmware reinstallation is successful.
[0070] In S801, the CPU board 401 performs a startup process. Here, in S801, it is not necessarily required to restart the CPU board 401, and only the FPGA 411 of the base board 410 may be restarted. The FPGA 411 attempts to restart by writing the reinstalled minimum configuration data to the SRAM. In S802, it is determined whether the CPU board 401 can communicate with the FPGA 411 of the base board 410. If it is determined that communication is not possible (NO), the process proceeds to S821 and it is determined that the recovery has failed. This is because the recovery is not possible even by reinstalling the firmware, so it is judged that on-site recovery is impossible. Then, the process proceeds to S822, the printer system is shut down, and in S823, a service call to the call center is made. After that, a service technician is dispatched from the call center to perform the recovery work.
[0071] On the other hand, in S801, the FPGA 411 restarts by writing the minimum configuration data stored in the flash memory to the SRAM and proceeds to S802. Then, if communication with the CPU board 401 is possible (YES), the process proceeds to S811. In S811, first, the CPU board 401 establishes communication with the base board 410. Then, the CPU board 401 acquires the configuration information of the base board 410 from the FPGA 411 of the base board 410. As described above, the configuration information of the base board 410 can be acquired by the FPGA 411 acquiring the information of the connector 413 and the function board 412 and transferring it to the CPU board 401.
[0072] Then, in S812, the CPU board 401 acquires configuration data from the print server 110 based on the configuration information of the base board 410. This configuration data is the same as that acquired in S512 of FIG. 5 and S712 of FIG. 7, and is different from the minimum configuration data. Details of both will be described later.
[0073] The CPU board 401 writes the acquired configuration data into the flash memory of the base board 410. The FPGA 411 writes the configuration data written into the flash memory into the SRAM and restarts.
[0074] Thereby, the FPGA 411 of the base board 410 operates with the updated configuration data. In S813, the CPU board 401 communicates with the base board 410 and completes the startup.
[0075] Referring to FIG. 9, the minimum configuration data and the configuration data will be described. The configurations of the minimum configuration data and the configuration data shown in FIG. 9 are examples and do not limit the implementation in an actual system. The minimum configuration data is an example of the recovery program in the present invention, and the configuration data is an example of the operation program in the present invention. The operation of the FPGA 411 by the configuration data is referred to as the normal operation, and the operation of the FPGA 411 by the minimum configuration data is referred to as the recovery operation.
[0076] The operation program has all the functions shown in FIG. 9. In normal operation, it acquires the values of each pin of the connector 413 on the base board 410 and determines which unit the base board 410 is mounted on. In normal operation, it acquires the version of the base board 410. This is because the operation may change due to modifications depending on the version of the base board 410. In normal operation, it acquires configuration information such as the configuration (type, number of pieces) of the function board 412. These configuration information are necessary for acquiring configuration data for controlling the function board 412. In normal operation, the FPGA 411 communicates with the CPU board 401 and transfers the acquired configuration information to the CPU board 401. The CPU board 401 acquires predetermined configuration data from the print server 110 based on the configuration information and updates the flash memory with the acquired configuration data. Thereby, the FPGA 411 restarts based on the updated configuration data. After the startup is completed, the FPGA 411 controls the function board 412 and executes a print job while communicating with the CPU board 401.
[0077] The recovery program has a function of acquiring information on the unit on which the base board 410 is mounted, a function of acquiring version information of the base board 410, and a function of acquiring configuration information of the function board 412. It also has a communication function with the CPU board 401. On the other hand, it does not have a function of controlling the function board 412. As described above, this is because the types of the function board 412 and their combinations are almost infinite and the size is large, so it cannot be stored in the non-volatile memory of the CPU board 401. Therefore, in order to store the minimum configuration data in the non-volatile memory of the CPU board 401, the control function of the function board 412 is omitted to limit the capacity to a certain level or less.
[0078] Hereinafter, other embodiments of the present invention will be described. <Embodiment 2> The CPU board 401 communicates with the base board 410 during startup, and determines the corresponding configuration data from the location unit of the base board 410, the version, and the configuration information of the function board 412. Then, it compares with the configuration data of the FPGA 411 of the base board 410. If both are of the same version, it may not be necessary to update the configuration data.
[0079] <Embodiment 3> The minimum configuration data required by the base board 410 may vary depending on the location unit (the environment where it is placed, for example, whether it is a printer unit or a fixing unit). In that case, it is necessary to store multiple types of minimum configuration data in the CPU board 401. Then, it can be transferred to the flash memory of the base board 410 one by one or in a batch, and it is possible to determine which minimum configuration data to use during restart.
[0080] <Embodiment 4> During the recovery process, it is assumed that multiple phenomenon patterns will occur. The corresponding methods vary depending on what kind of phenomena occur. If the minimum configuration data cannot be written, it is highly likely to be an error caused by hardware damage. Since the FPGA 411 itself may be damaged, it is possible for the service technician to prepare the parts in advance.
[0081] If the minimum configuration data can be reinstalled but the configuration data cannot be reinstalled, it is impossible to determine whether it is a software error or a hardware error. In this case, the judgment by the service technician is necessary.
[0082] When the CPU board 401 attempts to recover the base board 410 multiple times and sometimes it can be recovered while other times it cannot, a poor contact between the CPU board 401 and the base board 410 may be considered. In this case, the service technician can narrow down the cause of the error based on the information about what kind of phenomenon it is.
[0083] If the minimum configuration data and the configuration data can both be written to the flash memory and the FPGA 411 can be restarted, it can be simply determined as a software error. In this case, since it is possible to recover on-site, there is no need for the service technician to be dispatched.
[0084] In this way, it is possible to collect information for reference on the countermeasure method based on the phenomenon pattern that occurred in the recovery process. Also, by contacting the call center with the information about the phenomenon that occurred in the recovery process, the cause of the problem can be narrowed down, leading to a reduction in the response time and cost when the service technician is dispatched.
[0085] <Other Embodiments> The present invention can also be realized by supplying a program that realizes one or more functions of the above-described embodiments to a system or device via a network or a storage medium, and having one or more processors in the computer of the system or device read and execute the program. It can also be realized by a circuit (for example, ASIC) that realizes one or more functions.
[0086] The invention is not limited to the above-described embodiments, and various changes and modifications are possible without departing from the spirit and scope of the invention. Therefore, claims are attached to disclose the scope of the invention.
[0087] The disclosure of this specification includes the following information processing apparatus, a method for recovering the information processing apparatus, and a program. (Item 1) An information processing apparatus having one or more units, The above-mentioned one or more units are provided with unit controllers, and the unit controllers are composed of a first subsystem and a second subsystem. When the first subsystem cannot communicate with the second subsystem at the time of startup of the information processing apparatus, the first subsystem overwrites a recovery program in the memory in which the program of the second subsystem is stored. Information processing apparatus. (Item 2) The first subsystem has a CPU, and the second subsystem has an FPGA. The information processing apparatus according to Item 1. (Item 3) The recovery program is stored in the first subsystem. The information processing apparatus according to Item 1 or 2. (Item 4) When the first subsystem and the second subsystem establish communication, the second subsystem collects configuration information of the second subsystem and transfers the configuration information to the first subsystem. The first subsystem acquires an operation program based on the configuration information from a server, and updates the program of the second subsystem with the operation program. The information processing apparatus according to any one of Items 1 to 3. (Item 5) The operation program varies depending on the configuration of the second subsystem. The information processing apparatus according to Item 4. (Item 6) When the recovery cannot be performed by the recovery program, or when the recovery cannot be performed by the operation program, the first subsystem calls the call center to indicate that on-site recovery was not possible. The information processing apparatus according to Item 4 or 5. (Item 7) The recovery program is a program obtained by removing some functions from the operation program. The information processing apparatus according to any one of Items 4 to 6. (Item 8) The removed partial functions are the control functions of the device. The information processing apparatus according to item 7. (Item 9) The recovery program has a function of controlling the startup of the second subsystem, a function of acquiring configuration information of the second subsystem, and a function of communicating with the first subsystem. The information processing apparatus according to item 7. (Item 10) An information processing apparatus having one or more units, The one or more units include a unit controller, and the unit controller is composed of a first subsystem and a second subsystem. When the information processing apparatus is started up, the second subsystem collects configuration information of the second subsystem and transfers the configuration information to the first subsystem. The first subsystem acquires a program based on the configuration information from a server and overwrites the program in a memory where the program of the second subsystem is stored. Information processing apparatus. (Item 11) A recovery method for an information processing apparatus having one or more units including a unit controller composed of a first subsystem and a second subsystem, When the first subsystem cannot communicate with the second subsystem when the information processing apparatus is started up, the first subsystem overwrites a recovery program in a memory where the program of the second subsystem is stored. Recovery method for an information processing apparatus. (Item 12) A program for an information processing apparatus having one or more units including a unit controller composed of a first subsystem and a second subsystem, The program causes a computer of the information processing apparatus to When the first subsystem cannot communicate with the second subsystem at the startup of the information processing apparatus, the first subsystem overwrites a recovery program onto the memory in which the program of the second subsystem is stored. A program for operating as described above.
Explanation of Signs
[0088] 101: Image forming apparatus, 102: Scanner apparatus, 103: Controller (control apparatus), 104: Printer apparatus, 105: Operation unit, 106: Storage, 108: LAN, 109: Computer
Claims
1. An information processing apparatus having one or more units, wherein the one or more units include a unit controller, and the unit controller is composed of a first subsystem and a second subsystem, when the first subsystem cannot communicate with the second subsystem at the startup of the information processing apparatus, the first subsystem overwrites a recovery program on a memory in which the program of the second subsystem is stored, Information processing apparatus.
2. The first subsystem has a CPU, and the second subsystem has an FPGA, The information processing apparatus according to Claim 1.
3. The recovery program is stored in the first subsystem, The information processing apparatus according to Claim 1.
4. When communication is established between the first subsystem and the second subsystem, the second subsystem collects configuration information of the second subsystem and transfers the configuration information to the first subsystem, The first subsystem obtains an operation program based on the configuration information from a server and updates the program of the second subsystem with the operation program, The information processing apparatus according to Claim 1.
5. The operation program varies depending on the configuration of the second subsystem, The information processing apparatus according to Claim 4.
6. When recovery cannot be achieved by the recovery program or when recovery cannot be achieved by the operation program, the first subsystem calls the call center to indicate that on-site recovery was not possible, The information processing apparatus according to Claim 4.
7. The recovery program is a program obtained by removing some functions from the operation program, The information processing apparatus according to Claim 4.
8. The removed some functions are device control functions, The information processing apparatus according to Claim 7.
9. The recovery program has a function of controlling the startup of the second subsystem, a function of obtaining configuration information of the second subsystem, and a function of communicating with the first subsystem, The information processing apparatus according to Claim 7.
10. An information processing apparatus having one or more units, wherein the one or more units include a unit controller, and the unit controller is composed of a first subsystem and a second subsystem, When the information processing device is started, the second subsystem collects configuration information of the second subsystem and transfers the configuration information to the first subsystem; the first subsystem acquires a program based on the configuration information from a server, and overwrites the program in a memory in which the program of the second subsystem is stored; Information processing device.
11. A recovery method for an information processing apparatus having one or more units each including a unit controller configured by a first subsystem and a second subsystem, comprising: If the first subsystem cannot communicate with the second subsystem when the information processing device is started up, the first subsystem overwrites a recovery program in a memory in which a program of the second subsystem is stored. A method for recovering an information processing device.
12. A program for an information processing device having one or more units each including a unit controller configured by a first subsystem and a second subsystem, The program causes a computer of an information processing device to: If the first subsystem cannot communicate with the second subsystem when the information processing device is started up, the first subsystem overwrites a recovery program in a memory in which a program of the second subsystem is stored. A program to make it work.
Citation Information
Patent Citations
Software error correction method of FPGA
JP2005235074A
Program protection device and communication apparatus
JP2012174228A
Information processing device, information processing method and program
JP2022157063A