IP Library Granted Patent US 12,131,148
Granted Patent B2
US 12,131,148 · App. 17/500,244 · Granted Oct 29, 2024

Failsafe update of bootloader firmware

Inventors: Piotr Wolnowski (Gdańsk, PL); Pawel Raasz (Gdańsk, PL)
Assignee: CARRIER CORPORATION
G06F8/654
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,131,148
App. No.
17/500,244
Granted
Oct 29, 2024
Kind
B2
Abstract

A method of updating firmware stored in a non-volatile memory of a controller is disclosed. The non-volatile memory includes a first set of memory blocks configured to store a bootloader for the controller. The method includes storing a bootloader update application in a second set of memory blocks of the non-volatile memory, and storing a jump code in an initial memory block of the first set of memory blocks, wherein the jump code comprises an instruction to jump to an initial memory block of the second set of memory blocks.

Claims (23)

1. A system comprising:

a controller comprising a non-volatile memory that stores firmware for the controller, wherein the non-volatile memory comprises a first set of memory blocks that store a bootloader for the controller, wherein the non-volatile memory is configured such that each memory block of the first set of memory blocks can be erased individually;

wherein the system is configured to update the firmware by:

storing a bootloader update application in a second set of memory blocks of the non-volatile memory; and

replacing an initial memory block of the first set of memory blocks with a jump code such that the bootloader stored in the first set of memory blocks is partially erased, wherein the jump code comprises an instruction to jump to an initial memory block of the second set of memory blocks;

wherein the system is configured to provide energy internally to the controller when the controller loses external power so that at least one memory block of the non-volatile memory can be erased and written to without the controller receiving external power in order to guarantee that the jump code will be successfully stored.

2. The system of claim 1 , wherein the system is configured to determine whether the controller is receiving external power before storing the jump code in the initial memory block of the first set of memory blocks.

3. The system of claim 1 , wherein the system is configured to store a new bootloader for the controller in the non-volatile memory by:

storing data blocks of the new bootloader other than one or more initial data blocks of the new bootloader in memory blocks of the first set of memory blocks other than the one or more initial memory blocks;

determining whether the controller is receiving external power; and then

storing the one or more initial data blocks of the new bootloader in the one or more initial memory blocks of the first set of memory blocks.

4. The system of claim 1 , wherein the system is a fire protection system or an intrusion detection system.

5. A method of updating firmware stored in a non-volatile memory of a controller, wherein the non-volatile memory comprises a first set of memory blocks that store a bootloader for the controller, the method comprising:

storing a bootloader update application in a second set of memory blocks of the non-volatile memory, wherein the non-volatile memory is configured such that each memory block of the first set of memory blocks can be erased individually; and

replacing an initial memory block of the first set of memory blocks with a jump code such that the bootloader stored in the first set of memory blocks is partially erased, wherein the jump code comprises an instruction to jump to an initial memory block of the second set of memory blocks; and

wherein, when the controller loses external power, energy is provided internally to the controller so that at least one memory block of the non-volatile memory can be erased and written to without the controller receiving external power in order to guarantee that the jump code will be successfully stored.

6. The method of claim 5 , further comprising determining whether the controller is receiving external power before storing the jump code in the initial memory block of the first set of memory blocks and when it is determined that the controller is receiving external power, storing the jump code in the initial memory block of the first set of memory blocks.

7. The method of claim 5 , further comprising determining whether the jump code has already been stored in the initial memory block of the first set of memory blocks before storing the jump code in the initial memory block of the first set of memory blocks and/or before determining whether the controller is receiving external power.

8. The method of claim 5 , further comprising determining whether a new bootloader has been stored in the first set of memory blocks before storing the jump code in the initial memory block of the first set of memory blocks and/or before determining whether the controller is receiving external power and/or before determining whether the jump code has already been stored in the initial memory block of the first set of memory blocks.

9. The method of claim 5 , further comprising storing a new bootloader for the controller in the non-volatile memory by storing data blocks of the new bootloader other than one or more initial data blocks of the new bootloader in memory blocks of the first set of memory blocks other than the one or more initial memory blocks.

10. The method of claim 9 , further comprising determining whether the controller is receiving external power before storing the one or more initial data blocks of the new bootloader in the one or more initial memory blocks of the first set of memory blocks.

11. A method of updating firmware stored in a non-volatile memory of an embedded controller of a fire protection device or an intrusion detection device, the method comprising updating the firmware of the embedded controller using the method of claim 5 .

12. The method of claim 5 , wherein only a portion of the bootloader is erased, the portion being less than the entire bootloader.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 10, 2025
From: CARRIER CORPORATION; CARRIER GLOBAL CORPORATION; CARRIER FIRE & SECURITY EMEA; CARRIER FIRE & SECURITY, LLC; CARRIER CANADA CORPORATION; CLIMATE, CONTROLS & SECURITY ARGENTINA S.A.; KIDDE IP HOLDINGS , INC.; KIDDE LTD.; KIDDE PRODUCTS LTD.; CARRIER TRANSICOLD AUSTRIA GMBH; CARRIER TRANSICOLD FRANCE SCS
To: KIDDE FIRE PROTECTION, LLC
Reel/Frame 072829/0383 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 17, 2024
From: WOLNOWSKI, PIOTR; RAASZ, PAWEL; CARRIER FIRE & SECURITY POLSKA SP. Z O. O.
To: CARRIER CORPORATION
Reel/Frame 068006/0176 →
Priority Claims (1)
EP 20275177.2 · Nov 30, 2020 · regional
Continuity (1)
Related Publication 20220171614A1 · Jun 2, 2022