An ETC electronic tag software upgrade system, method, and storage medium
By using a streamlined protocol in ETC electronic tags for software upgrades, the problems of low transmission efficiency and unguaranteed data integrity in multiple tags are solved, and an efficient and reliable software upgrade process is achieved.
Patent Information
- Application Number
- CN202111669357.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-30
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2041-12-30
AI Technical Summary
The existing ETC electronic tag software upgrade solution has problems such as low transmission efficiency and unguaranteed data integrity in multiple tags, resulting in a low success rate of software upgrades.
Using a software upgrade method based on a streamlined protocol, the target software upgrade data is transmitted through the preset streamlined protocol communication between the first microcontroller unit and the second microcontroller unit, and the integrity check of the starting data frame and the accuracy check of the target data frame are performed in the second microcontroller unit.
The transmission efficiency and success rate of software upgrades are improved, and the efficiency of data transmission and the reliability of software upgrades are improved by reducing redundant information in data frames.
Smart Images

Figure CN114417354B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of control technology, and in particular to a software upgrade system, method and storage medium for an ETC electronic tag. Background Art
[0002] Radio frequency identification non-stop toll collection system (ETC) is the most advanced way of road and bridge toll collection at present. Through the dedicated short-range communication between the on-vehicle unit electronic tag (OBU) installed on the vehicle windshield and the roadside unit (RSU) on the ETC lane of the toll station, and using computer networking technology to conduct background settlement processing with the bank, the purpose of vehicles passing through the road and bridge toll station without stopping to pay fees can be achieved. However, the issuance volume of OBU is extremely large. When software needs to be updated, it requires a large amount of manpower and material resources. With the development of communication technology, R & D personnel are more eager to realize the intelligent upgrade of ETC software.
[0003] In the prior art, in the software upgrade of the existing ETC electronic tag based on the CAN bus, the main implementation method is based on the standard UDS protocol. However, this solution is an upgrade solution based on a single ETC electronic tag and cannot be extended to the situation where there are multiple ETC electronic tags in the system, resulting in difficulties in upgrading the ETC electronic tag. In order to achieve the simultaneous upgrade of multiple ETC electronic tags, some technologies have extended based on the UDS protocol and can support the situation of multiple MCU software upgrades. However, the currently extended protocol makes each data frame in the converted transmission data frame carry a frame header, resulting in a large amount of redundant information in the transmission data frame, thus reducing the transmission efficiency of the data frame and the data integrity cannot be guaranteed, leading to a significant reduction in the probability of successful software upgrade. Summary of the Invention
[0004] The embodiments of the present application provide a software upgrade system, method and storage medium for an ETC electronic tag. To provide a basic understanding of some aspects of the disclosed embodiments, a simple summary is given below. This summary part is not a general review, nor is it intended to identify key / important constituent elements or delineate the protection scope of these embodiments. Its sole purpose is to present some concepts in a simple form as a prelude to the subsequent detailed description.
[0005] In a first aspect, the embodiments of the present application provide a software upgrade method for an ETC electronic tag. The ETC tag includes a first microcontroller unit and at least one second microcontroller unit. The first microcontroller unit can communicate with the host computer, and the first microcontroller unit communicates with the second microcontroller unit through a preset simplified protocol;
[0006] When the second microcontroller unit needs to perform a target software upgrade, the host computer creates a secure session with the second microcontroller unit;
[0007] The host computer transparently transmits the target software upgrade data to the second microcontroller unit through the first microcontroller unit; wherein, the target software upgrade data transparently transmitted to the second microcontroller unit includes a start data frame, a plurality of target data frames, and an end data frame. The start data frame and the end data frame include a frame header and data information, and the target data frame does not include a frame header;
[0008] The second microcontroller unit sequentially performs integrity verification on the start data frame and accuracy verification on the target data frames;
[0009] After the accuracy verification passes, the target software upgrade is completed.
[0010] Optionally, the method further includes:
[0011] Before the second microcontroller unit performs the target software upgrade, perform a first target software upgrade on the first microcontroller unit;
[0012] Wherein, there is a dependency relationship between the target upgrade software of the second microcontroller unit and the first target upgrade software of the first microcontroller unit.
[0013] Optionally, before the second microcontroller unit performs the target software upgrade, performing the first target software upgrade on the first microcontroller unit includes:
[0014] Obtain a preset first communication protocol;
[0015] Create a session with the first microcontroller unit using the preset first communication protocol; when the session is successfully established,;
[0016] Transmit the target software upgrade data to the first microcontroller unit to perform a software upgrade on the first microcontroller unit;
[0017] Wherein, the preset first communication protocol includes the UDS protocol.
[0018] Optionally, creating a secure session with the second microcontroller unit includes:
[0019] The host computer performs a legality verification on the second microcontroller unit to determine whether the verification passes;
[0020] If the verification passes, it is determined that the creation of a secure session with the second microcontroller unit is successful;
[0021] Wherein, the legality verification includes:
[0022] Generate a first random number and transparently transmit the first random number to the second microcontroller unit through the first microcontroller unit;
[0023] Receive the encrypted data from the second microcontroller unit, where the encrypted data is obtained by the second microcontroller unit encrypting the second random number with the key in the ETC tag, and the second random number is obtained by performing an exclusive OR operation on the first random number and the MAC address of the ETC tag;
[0024] Decrypt the encrypted data to obtain the plaintext data;
[0025] Perform an exclusive OR operation on the plaintext data and the MAC address of the ETC electronic tag to generate the target data;
[0026] Determine whether to pass the legality verification based on the target data.
[0027] Optionally, the determining whether to pass the legality verification based on the target data includes:
[0028] When the target data is the same as the first random number, determine that the legality verification is passed;
[0029] When the target data is different from the first random number, determine that the legality verification is not passed.
[0030] Optionally, the sequentially performing integrity check on the start data frame and accuracy check on the target data frame includes:
[0031] Perform integrity check on the received start data frame to determine whether the check is passed;
[0032] If the integrity check passes, continue to receive multiple target data frames transparently transmitted by the host computer, and record the payload data values of each target data frame;
[0033] When the end data frame is received, the transmission of the target upgrade software is completed;
[0034] Perform data accuracy check on each received target data frame.
[0035] Optionally, the performing integrity check on the received start data frame to determine whether the integrity check passes includes:
[0036] When the start data frame transparently transmitted by the host computer is received, obtain the frame header of the start data frame;
[0037] Verify whether the start data frame is internal upgrade data, whether it is a start data frame, and whether it is legal according to the frame header of the start data frame;
[0038] If so, determine that the integrity check of the start data frame passes;
[0039] When any verification fails, exit the integrity verification.
[0040] Optionally, performing data accuracy verification on the multiple target data frames and determining whether to upgrade based on the verification result includes:
[0041] Obtain the cyclic redundancy check code in the frame header of the start frame, where the cyclic redundancy check code is used to identify the total payload data value of the target upgrade software;
[0042] Obtain the payload data value of each recorded target data frame;
[0043] After the transmission of each target data frame is completed, calculate the sum of the payload data values of each target data frame, and the sum of the payload data values is identified by a target cyclic redundancy check code;
[0044] When the target cyclic redundancy check code is the same as the cyclic redundancy check code in the frame header of the start frame, the accuracy verification passes.
[0045] In a second aspect, an embodiment of the present application provides a software upgrade system for an ETC electronic tag. The system includes a host computer and an ETC tag. Among them, the ETC tag includes a first microcontroller unit and at least one second microcontroller unit;
[0046] The first microcontroller unit communicates with the second microcontroller unit through a preset reduced protocol;
[0047] The host computer is used to create a secure session with the second microcontroller unit when the second microcontroller unit needs to upgrade the target software;
[0048] The host computer is used to transparently transmit the target software upgrade data to the second microcontroller unit through the first microcontroller unit. Among them, the target software upgrade data transparently transmitted to the second microcontroller unit includes a start data frame, a plurality of target data frames, and an end data frame. The start data frame and the end data frame include a frame header and data information, and the target data frame does not include a frame header;
[0049] The second microcontroller unit is used to perform integrity verification on the start data frame and accuracy verification on the target data frame in sequence;
[0050] After the accuracy verification passes, the target software upgrade is completed.
[0051] In a third aspect, an embodiment of the present application provides a computer storage medium. The computer storage medium stores multiple instructions, and the instructions are suitable for being loaded and executed by a processor to perform the above method steps.
[0052] Fourthly, an embodiment of the present application provides a terminal, which may include: a processor and a memory; wherein, the memory stores a computer program, and the computer program is adapted to be loaded and executed by the processor to perform the above method steps.
[0053] The technical solution provided by the embodiment of the present application may include the following beneficial effects:
[0054] In the embodiment of the present application, when the second microcontroller unit needs to perform target software upgrade, a secure session with the second microcontroller unit is created; the target upgrade software is transparently transmitted to the second microcontroller unit through the first microcontroller unit; wherein, the target software upgrade data transparently transmitted to the second microcontroller unit includes a start data frame, a plurality of target data frames, and an end data frame, the start data frame and the end data frame include a frame header and data information, and the target data frame does not include a frame header; the integrity of the start data frame is verified in sequence, and the accuracy of the target data frame is verified; after the accuracy verification passes, the target software upgrade is completed. Since the software upgrade data is transmitted through a streamlined protocol, only the start data frame and the end data frame in the converted data frame include a frame header, and the remaining data frames only have data information, which improves the transmission efficiency and the probability of successful software upgrade.
[0055] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] The drawings herein are incorporated into the specification and form a part of the specification, showing embodiments consistent with the present invention and used together with the specification to explain the principles of the present invention.
[0057] Figure 1 is a schematic flow chart of a method for software upgrade of an ETC electronic tag provided by an embodiment of the present application;
[0058] Figure 2 is a schematic flow chart of establishing a session between a host computer and a second microcontroller unit provided by an embodiment of the present application;
[0059] Figure 3 is a schematic flow chart of a data integrity verification process provided by an embodiment of the present application;
[0060] Figure 4 is a schematic diagram of a process of software upgrade of an ETC electronic tag provided by an embodiment of the present application;
[0061] Figure 5 is a schematic diagram of a program product provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0062] The following description and the accompanying drawings fully disclose specific embodiments of the present invention, enabling those skilled in the art to practice them.
[0063] It should be clear that the described embodiments are only a part of the embodiments of the present invention, rather than all of them. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts belong to the scope of protection of the present invention.
[0064] When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present invention. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present invention as detailed in the appended claims.
[0065] In the description of the present invention, it should be understood that terms such as "first", "second", etc. are only used for descriptive purposes and cannot be construed as indicating or implying relative importance. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances. In addition, in the description of the present invention, unless otherwise specified, "a plurality of" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after.
[0066] This application provides a software upgrade system, method, and storage medium for an ETC electronic tag to solve the problems existing in the above-related technical problems. In the technical solution provided by this application, since the software upgrade data is transmitted by streamlining the protocol, only the start data frame and the end data frame in the converted data frame contain frame headers, and the remaining data frames only contain data information, thereby reducing the size of the transmitted data, improving the transmission efficiency, and increasing the probability value of successful software upgrade. The following will be described in detail with exemplary embodiments.
[0067] The following will be combined with the attached Figure 1 - attached Figure 4 ... to introduce in detail the software upgrade method for the ETC electronic tag provided by the embodiments of this application. This method can be implemented depending on a computer program and can run on a software upgrade device for an ETC electronic tag based on the von Neumann architecture. This computer program can be integrated into an application or run as an independent tool-type application.
[0068] Please refer to Figure 1 , which is a schematic flowchart of a software upgrade method for an ETC electronic tag provided by the embodiments of this application. As Figure 1As shown, the method of the embodiment of the present application may include the following steps:
[0069] S101, when the second microcontroller unit needs to perform target software upgrade, the host computer creates a secure session with the second microcontroller unit;
[0070] Generally, an ETC tag includes a first microcontroller unit and at least one second microcontroller unit. When software upgrade is required, the first microcontroller unit can be communicatively connected to the host computer, and the first microcontroller unit communicates with the second microcontroller unit through a preset lightweight protocol.
[0071] In a specific embodiment, the ETC tag includes a first microcontroller unit and a second microcontroller unit.
[0072] It can be understood that when the ETC on-vehicle device is an original equipment installation type, the host computer of the present solution can be an on-vehicle device, such as an in-vehicle central control ECU, an in-vehicle T-BOX, etc. The host computer device is connected to the ETC electronic tag through a CAN line, and upgrade data is transmitted through the CAN line to complete software upgrade.
[0073] In another specific embodiment, the host computer of the present solution can also be an external device, which is connected to the ETC tag and performs upgrade when upgrade is required.
[0074] In a specific embodiment, when there are multiple second microcontroller units, the upgrade order of each second microcontroller unit can be determined according to a preset rule, and the host computer upgrades the second microcontroller units in sequence according to the preset rule.
[0075] In this embodiment, before the second microcontroller unit performs target software upgrade, a first target software upgrade is performed on the first microcontroller unit; wherein, there is a dependency relationship between the target upgrade software of the second microcontroller unit and the first target upgrade software of the first microcontroller unit.
[0076] In this embodiment, the first target software to be upgraded by the first microcontroller unit can be the same as the second target upgrade software of the second microcontroller unit. When they are the same, the host computer first upgrades the first microcontroller unit. After the first microcontroller unit is upgraded, the above-mentioned solution is used to perform target upgrade software on the second microcontroller unit to improve the upgrade efficiency and avoid mismatch caused by version differences between the two. In this embodiment, when performing the first target software upgrade on the first microcontroller unit, first obtain a preset first communication protocol, and then create a session with the first microcontroller unit using the preset first communication protocol; when the session is successfully established, transmit the target software upgrade data to the first microcontroller unit to perform software upgrade on the first microcontroller unit; wherein, the preset first communication protocol includes the UDS protocol.
[0077] In this embodiment, when creating a secure session with the second microcontroller unit, the host computer performs a legality verification on the second microcontroller unit to determine whether the verification passes; if the verification passes, it is determined that the creation of the secure session with the second microcontroller unit is successful; wherein, the legality verification includes: generating a first random number, and transmitting the first random number to the second microcontroller unit through the first microcontroller unit; receiving encrypted data from the second microcontroller unit, where the encrypted data is obtained by the second microcontroller unit encrypting a second random number with the key in the ETC tag, and the second random number is obtained by performing an exclusive OR operation on the first random number and the MAC address of the ETC tag.
[0078] Decrypt the encrypted data to obtain plaintext data; perform an exclusive OR operation on the plaintext data and the MAC address of the ETC electronic tag to generate target data; determine whether the legality verification passes based on the target data.
[0079] Among them, the above MAC address can be input or brought in by the ETC tag information.
[0080] Further, when determining whether the legality verification passes based on the target data, when the target data is the same as the first random number, it is determined that the legality verification passes; when the target data is different from the first random number, it is determined that the legality verification fails.
[0081] For ease of description, in this application, the host computer is denoted as host computer tool 04, the second microcontroller unit is denoted as MCU02, and the first microcontroller unit is denoted as MCU01.
[0082] For example Figure 2 as shown Figure 2 is a schematic flow diagram of the host computer establishing a session with the second microcontroller unit. First, the host computer tool 04 sends a random number R1 to MCU02 through MCU01. MCU02 performs an exclusive OR operation on the random number R1 and its own MAC address to obtain a random number R2, then encrypts the random number R2 with the key KEY to obtain ciphertext data R3, and then returns R3 to the host computer tool 04 through MCU01. After the host computer tool obtains the ciphertext data R3, it decrypts the ciphertext data R3 with the public key key to obtain M1, then performs an exclusive OR operation on M1 and the MAC address input by the user to the host computer tool 04 to obtain M2, and finally compares M2 with the random number R1 to determine whether they are consistent. If they are consistent, the host computer and the second microcontroller unit establish a session.
[0083] S102. The host computer transparently transmits the target software upgrade data to the second microcontroller unit through the first microcontroller unit. The target software upgrade data transparently transmitted to the second microcontroller unit includes a start data frame, multiple target data frames, and an end data frame. The start data frame and the end data frame include a frame header and data information, and the target data frame does not include a frame header.
[0084] Specifically, the first microcontroller unit supports CAN bus communication. The software running on the first microcontroller unit supports the UDS protocol, and the software of the first microcontroller unit can be upgraded through a standard upgrade protocol. Customized lightweight data transfer protocols are run on the host computer, the first microcontroller unit, and the second microcontroller unit to ensure the efficiency and security of data transfer between the two.
[0085] S103. The second microcontroller unit sequentially performs integrity verification on the start data frame and accuracy verification on the target data frames.
[0086] In the embodiment of the present application, integrity verification is performed on the received start data frame to determine whether the verification is passed. If the integrity verification is passed, multiple target data frames transparently transmitted by the host computer are continuously received, and the payload data values of each target data frame are recorded. When the end data frame is received, the transmission of the target upgrade software is completed, and data accuracy verification is performed on each received target data frame.
[0087] Specifically, when sequentially performing integrity verification on the start data frame and accuracy verification on the target data frames, first, when the start data frame transparently transmitted by the host computer is received, the frame header of the start data frame is obtained. According to the frame header of the start data frame, it is verified whether the start data frame is internal upgrade data, whether it is a start data frame, and whether it is legal. If so, it is determined that the integrity verification of the start data frame is passed. When any one of the verifications fails, the integrity verification is exited.
[0088] The start frame and the end frame contain 5-byte frame header information, namely CLA, SEQ, INS, P1, and BCC check code. Each check code is sequentially verified. For example, through the CLA field in the start frame, it is determined whether the data is internal upgrade data; through the INS field in the start frame, it is determined whether the data is a start data frame. After the BCC code passes the verification, the integrity verification of the start data frame is completed.
[0089] The start frame also contains an additional 4-byte CRC check value. This check value is the CRC check value of all payload data, that is, the cyclic redundancy check code. This cyclic redundancy check code is directly related to the upgrade software data packet and is a part of the upgrade software data.
[0090] Specifically, when performing integrity verification on the starting data frame and accuracy verification on the target data frame in sequence, obtain the cyclic redundancy check code in the frame header of the starting frame, where the cyclic redundancy check code is used to identify the total payload data value of the target upgrade software; obtain the recorded payload data value of each target data frame; after the transmission of each target data frame is completed, calculate the sum of the payload data values of each target data frame, and this sum of payload data values is identified by a target cyclic redundancy check code; when the target cyclic redundancy check code is the same as the cyclic redundancy check code in the frame header of the starting frame, the accuracy verification passes.
[0091] For example Figure 3 as shown Figure 3 Figure 7 is a schematic diagram of a data integrity verification process provided by the present application. First, after the host computer tool 04 establishes a session with MCU02 through MCU01, when MCU02 receives the first frame of data information frame sent by the host computer tool, it determines whether the data is internal upgrade data. If so, it continues to determine whether it is the starting frame data. If so, it obtains the file size, payload data per frame, total number of payload frames, and CRC value of the payload in the starting data frame header data, and comprehensively determines whether the starting data frame of the upgrade file is legal. If it is legal, it continues to transmit the target data frame and records each received target data frame and its payload data value; when receiving the end data frame sent by the host computer tool, verify the end data frame. After the verification passes, it is determined that after the transmission of each target data frame is completed, data accuracy verification is performed on the received target data frames. Specifically, it calculates the sum of the payload data values of each target data frame and compares it with the total number of payload frames of the target software upgrade data in the starting data frame. When the two are consistent, it is determined that the data accuracy verification passes.
[0092] After the verification passes, delete the historical software package and reinstall the software according to the received data frames.
[0093] Furthermore, the host computer is also used to calculate the transmission efficiency. The calculation formula for the transmission efficiency is as follows: B represents the length of each transmission data frame, P represents the payload length, and R represents the transmission efficiency. Then the transmission efficiency is: R = 1 - (P / B).
[0094] For example, when the byte length is 32 bytes and the frame information length is 5 bytes, the transmission efficiency is 84.3%. If the above protocol design is adopted, the transmission efficiency can reach 100% (the additional 4-byte CRC overhead can be ignored).
[0095] S104, after the accuracy verification passes, the target software upgrade is completed.
[0096] For example Figure 4 as shown Figure 4It is a process schematic block diagram of the software upgrade process of an ETC electronic tag provided by this application. After the host computer upgrade software and the MCU 01 establish a secure session S101 according to the UDS protocol standard, the MCU 01 is upgraded with software. After the data transmission ends, the software upgrade of the MCU 01 is completed. The host computer upgrade software performs data transparent transmission through the UDS protocol of the MCU 01, conducts an internal secure session S201 with the MCU 02, the MCU 02 performs integrity verification S202 on the received data, and the data transmission process S203 is transmitted according to the designed simplified protocol to increase the data transmission efficiency. After the data transmission ends, the accuracy of the data is verified S204.
[0097] In the embodiment of this application, when the second microcontroller unit needs to perform target software upgrade, a secure session with the second microcontroller unit is created; the target upgrade software is transparently transmitted to the second microcontroller unit through the first microcontroller unit; wherein, the target software upgrade data transparently transmitted to the second microcontroller unit includes a start data frame, multiple target data frames, and an end data frame. The start data frame and the end data frame include a frame header and data information, and the target data frame does not include a frame header; the integrity of the start data frame is verified in sequence, and the accuracy of the target data frame is verified; after the accuracy verification passes, the target software upgrade is completed. Since the software upgrade data is transmitted through a simplified protocol, only the start data frame and the end data frame in the data frame after conversion by the simplified protocol include a frame header, and the remaining data frames only have data information, thereby reducing the size of the transmitted data, improving the transmission efficiency, and increasing the probability value of successful software upgrade.
[0098] The embodiment of this application provides a software upgrade system for an ETC electronic tag. The system of the embodiment of this application includes: a host computer and an ETC tag; wherein, the ETC tag includes a first microcontroller unit and at least one second microcontroller unit;
[0099] The first microcontroller unit communicates with the second microcontroller unit through a preset simplified protocol;
[0100] The host computer is used to create a secure session with the second microcontroller unit when the second microcontroller unit needs target software upgrade;
[0101] The host computer is used to transparently transmit the target software upgrade data to the second microcontroller unit through the first microcontroller unit; wherein, the target software upgrade data transparently transmitted to the second microcontroller unit includes a start data frame, multiple target data frames, and an end data frame. The start data frame and the end data frame include a frame header and data information, and the target data frame does not include a frame header;
[0102] The second microcontroller unit is used to sequentially perform integrity verification on the start data frame and accuracy verification on the target data frame;
[0103] After the accuracy verification is passed, the upgrade and update of the target software are completed.
[0104] In the embodiment of the present application, when the second microcontroller unit needs to perform a target software upgrade, a secure session with the second microcontroller unit is created; the target upgrade software is transparently transmitted to the second microcontroller unit through the first microcontroller unit; wherein, the target software upgrade data transparently transmitted to the second microcontroller unit includes a start data frame, a plurality of target data frames, and an end data frame. The start data frame and the end data frame include a frame header and data information, and the target data frame does not include a frame header; the integrity of the start data frame is verified in sequence, and the accuracy of the target data frame is verified; after the accuracy verification is passed, the upgrade and update of the target software are completed. Since the software upgrade data is transmitted through a streamlined protocol, only the start data frame and the end data frame in the data frame after the streamlined protocol conversion contain frame header information, and the remaining data frames only have payload data, thereby reducing the size of the transmitted target software upgrade data, improving the transmission efficiency, and increasing the probability value of successful software upgrade.
[0105] The present invention also provides a computer-readable medium, on which program instructions are stored. When the program instructions are executed by a processor, the software upgrade method of the ETC electronic tag provided by each of the above method embodiments is implemented. The present invention also provides a computer program product containing instructions. When it runs on a computer, the computer is caused to execute the software upgrade method of the ETC electronic tag provided by each of the above method embodiments.
[0106] The embodiment of the present application also provides a computer-readable storage medium corresponding to the software upgrade method of the ETC electronic tag provided by the foregoing embodiment. Please refer to Figure 5 which shows that the computer-readable storage medium is an optical disc 30, on which a computer program (i.e., a program product) is stored. When the computer program is run by a processor, it will execute the software upgrade method of the ETC electronic tag provided by any of the foregoing embodiments.
[0107] It should be noted that examples of computer-readable storage media may also include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory, or other optical and magnetic storage media, which will not be elaborated here one by one.
[0108] The computer-readable storage medium provided by the above embodiment of the present application and the software upgrade method of the ETC electronic tag provided by the embodiment of the present application are based on the same inventive concept and have the same beneficial effects as the methods adopted, run, or implemented by the application programs stored therein.
[0109] The above are only the preferred specific embodiments of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed in the present application should be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.
[0110] Those of ordinary skill in the art can understand that all or part of the processes in the above-described method embodiments can be completed by instructing relevant hardware through a computer program. The program for software upgrade of the ETC electronic tag can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the above-described method embodiments. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only memory, or a random access memory, etc.
[0111] The above-disclosed are only the preferred embodiments of the present application. Of course, the scope of rights of the present application cannot be limited thereby. Therefore, equivalent changes made according to the claims of the present application still fall within the scope covered by the present application.
Claims
1. A software upgrade method based on an ETC electronic tag, characterized in that, The ETC electronic tag includes a first microcontroller unit and at least one second microcontroller unit. The first microcontroller unit can communicate with a host computer, and the first microcontroller unit communicates with the second microcontroller unit through a preset reduced protocol; Among them, the preset reduced protocol enables only the start data frame and the end data frame in the converted data frame to contain frame headers, and the remaining data frames only have data information; When the second microcontroller unit needs to perform target software upgrade, the host computer creates a secure session with the second microcontroller unit; the creation of the secure session with the second microcontroller unit includes: The host computer performs a legality verification on the second microcontroller unit to determine whether the verification passes; If the verification passes, it is determined that the creation of the secure session with the second microcontroller unit is successful; The host computer transparently transmits the target software upgrade data to the second microcontroller unit through the first microcontroller unit; among them, the target software upgrade data transparently transmitted to the second microcontroller unit includes a start data frame, multiple target data frames, and an end data frame. The start data frame and the end data frame include a frame header and data information, and the target data frame does not include a frame header; The second microcontroller unit sequentially performs integrity verification on the start data frame and accuracy verification on the target data frame; After the accuracy verification passes, the target software upgrade is completed.
2. The method according to claim 1, characterized in that, The method further includes: Before the second microcontroller unit performs target software upgrade, perform a first target software upgrade on the first microcontroller unit; Among them, there is a dependency relationship between the target upgrade software of the second microcontroller unit and the first target upgrade software of the first microcontroller unit.
3. The method according to claim 2, characterized in that, Before the second microcontroller unit performs target software upgrade, the performing of the first target software upgrade on the first microcontroller unit includes: Obtain a preset first communication protocol; Create a session with the first microcontroller unit using the preset first communication protocol; When the session is successfully established, transmit the target software upgrade data to the first microcontroller unit to perform software upgrade on the first microcontroller unit; Among them, the preset first communication protocol includes the UDS protocol.
4. The method according to claim 1, characterized in that, The legality verification includes: Generate a first random number and transparently transmit the first random number to the second microcontroller unit through the first microcontroller unit; Receive encrypted data from the second microcontroller unit. Among them, the encrypted data is obtained by the second microcontroller unit encrypting a second random number using the key in the ETC electronic tag, and the second random number is obtained by performing an exclusive OR operation on the first random number and the MAC address of the ETC electronic tag; Decrypt the encrypted data to obtain plaintext data; Perform an exclusive OR operation on the plaintext data and the MAC address of the ETC electronic tag to generate target data; Determine whether the legality verification passes based on the target data.
5. The method according to claim 4, characterized in that, The determining whether the legality verification passes based on the target data includes: When the target data is the same as the first random number, determine that the legality verification passes; When the target data is different from the first random number, determine that the legality verification fails.
6. The method according to claim 1, characterized in that, Performing integrity verification on the starting data frame and accuracy verification on the target data frame in sequence includes: Performing integrity verification on the received starting data frame to determine whether the verification passes; If the integrity verification passes, continue to receive multiple target data frames transparently transmitted by the host computer, and record the payload data values of each target data frame; When the end data frame is received, the transmission of the target upgrade software is completed; Performing data accuracy verification on each received target data frame.
7. The method according to claim 1, characterized in that, The performing integrity verification on the received starting data frame to determine whether the integrity verification passes includes: When the starting data frame transparently transmitted by the host computer is received, obtain the frame header of the starting data frame; Verify whether the starting data frame is internal upgrade data, whether it is a starting data frame, and whether it is legal according to the frame header of the starting data frame; If so, determine that the integrity verification of the starting data frame passes; When any one of the verifications fails, exit the integrity verification.
8. The method according to claim 6, characterized in that, The performing integrity verification on the received starting data frame to determine whether the verification passes includes: Obtain the cyclic redundancy check code in the frame header of the starting data frame, where the cyclic redundancy check code is used to identify the total payload data value of the target upgrade software; Obtain the recorded payload data values of each target data frame; After the transmission of each target data frame is completed, calculate the sum of the payload data values of each target data frame, and the sum of the payload data values is identified by the target cyclic redundancy check code; When the target cyclic redundancy check code is the same as the cyclic redundancy check code in the frame header of the starting data frame, the integrity verification passes.
9. A software upgrade system based on an ETC electronic tag, characterized in that, The system includes a host computer and an ETC electronic tag; wherein, the ETC electronic tag includes a first micro control unit and at least one second micro control unit; The first micro control unit communicates with the second micro control unit through a preset simplified protocol; Wherein, the preset simplified protocol enables only the starting data frame and the end data frame in the converted data frame to include frame headers, and the remaining data frames only have data information; The host computer is used to create a secure session with the second micro control unit when the second micro control unit needs to upgrade the target software; creating the secure session with the second micro control unit includes: the host computer performing a legality verification on the second micro control unit to determine whether the verification passes; If the verification passes, determine that the creation of the secure session with the second micro control unit is successful; The host computer is used to transparently transmit the target software upgrade data to the second micro control unit through the first micro control unit; wherein, the target software upgrade data transparently transmitted to the second micro control unit includes a starting data frame, multiple target data frames, and an end data frame, the starting data frame and the end data frame include a frame header and data information, and the target data frame does not include a frame header; The second micro control unit is used to perform integrity verification on the starting data frame and accuracy verification on the target data frame in sequence; After the accuracy verification passes, the update of the target software upgrade is completed.
10. A computer storage medium, characterized in that, The computer storage medium stores multiple instructions, and the instructions are adapted to be loaded and executed by a processor to perform the method steps as described in any one of claims 1-8.
Citation Information
Patent Citations
Industrial process data transmission method
CN105704150A
Software burning method and device
CN109976767A