IP Library Granted Patent US 8,595,716
Granted Patent B2
US 8,595,716 · App. 13/081,274 · Granted Nov 26, 2013

Failsafe firmware updates

Inventors: Brent Keller (Rochester, NY); John Sotack (Rochester, NY); Alan Hayter (Victor, NY)
Assignee: Robert Bosch GmbH
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,595,716
App. No.
13/081,274
Granted
Nov 26, 2013
Kind
B2
Abstract

A method of updating an electronic device. The device has a non-volatile memory divided into at least three non-overlapping sections, a bootstrap image section, a updater image section, and a application image section. The method includes erasing the application image section of the non-volatile memory, receiving a firmware update, writing the firmware update into the application image section, rebooting the electronic device, determining one of an application program and an updater program resides in the application image section, executing the application program when the application program is determined to reside in the application image section, erasing the updater image section of the non-volatile memory when the updater program is determined to reside in the application image section, and moving the updater program from the application image section to the updater image section.

Claims (28)

1. A method of updating an electronic device having a non-volatile memory divided into at least three non-overlapping sections, a bootstrap image section, a updater image section, and an application image section, the method comprising:

erasing the application image section of the non-volatile memory;

receiving a firmware update;

writing the firmware update into the application image section, the firmware update including one of an application program and an updater program;

rebooting the electronic device;

determining whether the firmware update written into the application image section is an application program or an updater program;

executing the program residing in the application image section when the firmware update written into the application image section is determined to be an application program;

erasing the updater image section of the non-volatile memory when the firmware update written into the application image section is determined to be an updater program;

moving the firmware update updater program from the application image section to the updater image section and obtaining a new application program after moving the updater program from the application image section to the updater image section.

2. The method of claim 1 , further comprising validating the firmware update in the application image section after writing the firmware update into the application image section and before rebooting the electronic device.

3. The method of claim 2 , further comprising writing an application image header after the firmware update is validated and before rebooting the electronic device.

4. The method of claim 3 , wherein an updater image header is erased after the application image header is written and validated, if the firmware update is an updater program update.

5. The method of claim 1 , further comprising validating the updater program in the updater image section after moving the updater program from the application image section to the updater image section.

6. The method of claim 5 , further comprising writing an updater image header and erasing an application image header after the updater program in the updater image section has been validated.

7. The method of claim 1 , wherein the application program calls routines in the updater program.

8. The method of claim 1 , wherein the updater program does not call routines in the application program.

9. An electronic device, the electronic device comprising:

an interface configured to communicate with a second device external to the electronic device;

a non-volatile memory having

an application image section made up of a first writable block and containing an application program, and

an updater image section made up of a second writable block and containing an updater program; and

a controller coupled to the interface and the non-volatile memory and configured to receive an updater program update from the interface and to write the updater program update into the application image section after erasing the application program, to validate the updater program update written into the application image section, to move the updater program update from the application image section to the updater image section after erasing the updater program and obtaining a new application program after moving the updater program from the application image section to the updater image section.

10. The electronic device of claim 9 , wherein the non-volatile memory includes a bootstrap image section, the bootstrap image section having a bootstrap program for determining if a valid program exists in the updater image section and the application image section.

11. The electronic device of claim 10 , wherein the bootstrap program executes a program in the application image section when a valid program exists in the application image section.

12. The electronic device of claim 10 , wherein the bootstrap program executes a program in the updater image section when a valid program does not exist in the application image section.

13. The electronic device of claim 9 , wherein the controller is configured to obtain a new application program after moving the updater program from the application image section to the updater image section.

14. The electronic device of claim 9 , wherein the controller is configured to validate the updater program in the updater image section after moving the updater program from the application image section to the updater image section.

15. The electronic device of claim 14 , wherein the controller is configured to write an updater image header and erase an application image header after the updater program in the updater image section has been moved to the updater image section and validated.

Assignments (3)
TERMINATION AND RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY RECORDED AT REEL 73363, FRAME 0729 Recorded May 4, 2026
From: GLAS TRUST CORPORATION LIMITED
To: ELECTRO-VOICE DYNACORD LLC (F/K/A BOSCH SECURITY SYSTEMS, LLC, F/K/A BOSCH SECURITY SYSTEMS, INC.)
Reel/Frame 075499/0896 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 28, 2025
From: BOSCH SECURITY SYSTEMS, LLC (FKA BOSCH SECURITY SYSTEMS, INC.)
To: GLAS TRUST CORPORATION LIMITED
Reel/Frame 073363/0729 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 18, 2011
From: KELLER, BRENT A.; SOTACK, JOHN D.; HAYTER, ALAN
To: BOSCH SECURITY SYSTEMS, INC.; ROBERT BOSCH GMBH
Reel/Frame 027251/0305 →
Continuity (1)
Related Publication 20120260244A1 · Oct 11, 2012