A firmware updating method and device, electronic equipment and vehicle
By using OTA servers and the firmware update system of electronic devices, and utilizing the upgrade function submodule in the application to update the Bootloader in the common backup area of the controller, the problem of complex and inefficient firmware upgrades in the existing technology is solved, realizing safe and reliable firmware updates, and improving user experience and resource utilization efficiency.
Patent Information
- Application Number
- CN202311281929.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-09-28
- Publication Date
- 2026-02-10
- Estimated Expiration
- 2043-09-28
AI Technical Summary
In the existing technology, upgrading the bootloader firmware of automotive controllers is complex and inefficient, and cannot be performed after the hardware circuitry is installed inside the mechanical housing, affecting the normal response of the system and the user experience.
The firmware update system, which uses OTA servers and electronic devices, utilizes the upgrade function submodule in the application to update the Bootloader through a common backup area without affecting the operation of other submodules. Firmware data is written to the firmware area of the controller using a preset frame data block size, ensuring the security and reliability of the update.
This enables safe and reliable updates to the bootloader without affecting the normal operation of the controller system, improving the efficiency and effectiveness of firmware updates, saving Flash resources, and enhancing the user experience.
Smart Images

Figure CN118540219B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of automobile electronics, and in particular to a firmware updating method and device, an electronic device, and a vehicle. BACKGROUND
[0002] With the development of automobile electronics, automobile controllers have more and more functions, and there are inevitably vulnerabilities and new demand functions in the software development process and released versions, so the software needs to be upgraded, and therefore a Bootloader firmware is designed in the automobile controller to upgrade and update APP programs. As a section of program of an MCU, the Bootloader inevitably has vulnerabilities or needs to be optimized. During the development phase of the controller, the program can be written by a burner through a debugging interface, and if the hardware circuit has been installed in a mechanical shell and on the automobile, it is impossible to upgrade and update the Bootloader of the controller through the burner, and the existing solution is to have a field engineer update and upgrade the Bootloader program through a host computer. Since automobiles are delivered to users in large quantities, the operation of updating and upgrading the Bootloader locally by the field engineer through the host computer is complex and inefficient. SUMMARY
[0003] The embodiments of the present application provide a firmware updating method and device, an electronic device, and a vehicle, which can safely and reliably write firmware data information to be updated into a firmware area of a controller, and improve the efficiency and effectiveness of firmware updating.
[0004] In a first aspect, the embodiments of the present application provide a firmware updating method applied to a first controller, and the method comprises the following steps.
[0005] When an application program of the first controller is running, firmware data information to be updated is acquired.
[0006] The firmware data information to be updated is written into a firmware area of the first controller according to a first preset framing data block size.
[0007] In a second aspect, the embodiments of the present application provide another firmware updating method applied to a second controller, and the method comprises the following steps.
[0008] Firmware data information to be updated is acquired.
[0009] The firmware data information to be updated is sent to the first controller, so that the first controller writes the firmware data information to be updated into a firmware area of the first controller according to a first preset framing data block size when an application program is running.
[0010] In a third aspect, the embodiments of the present application provide a firmware updating device, which is arranged in a first controller, and the device comprises:
[0011] an obtaining unit, configured to obtain firmware data information to be updated when an application of the first controller is running;
[0012] a writing unit, configured to write the firmware data information to be updated into a firmware area of the first controller according to a first preset framing data block size.
[0013] In a fourth aspect, the embodiments of the present application provide another firmware updating device, which is arranged in a controller, and the device comprises:
[0014] an obtaining unit, configured to obtain firmware data information to be updated;
[0015] a sending unit, configured to send the firmware data information to be updated to the first controller, so that the first controller writes the firmware data information to be updated into a firmware area of the first controller according to a first preset framing data block size when an application is running.
[0016] In a fifth aspect, the embodiments of the present application provide an electronic device, which comprises a processor, a memory, a bus and a communication interface, and the processor, the communication interface and the memory are connected through the bus;
[0017] the memory is configured to store a program;
[0018] the processor is configured to call the program stored in the memory through the bus, and execute the method in the first aspect.
[0019] In a sixth aspect, the embodiments of the present application provide another electronic device, which comprises a processor, a memory, a bus and a communication interface, and the processor, the communication interface and the memory are connected through the bus;
[0020] the memory is configured to store a program;
[0021] the processor is configured to call the program stored in the memory through the bus, and execute the method in the second aspect.
[0022] In a seventh aspect, the embodiments of the present application provide a vehicle, which comprises a vehicle body and an electronic device, and the electronic device comprises a first controller and a second controller, the first controller is configured to execute the method in the first aspect to update firmware of the first controller of the vehicle, and the second controller is configured to execute the method in the second aspect to update firmware of the first controller of the vehicle.
[0023] The embodiment of the present application acquires the firmware data information to be updated when the first controller application program runs, and writes the firmware data information to be updated into the firmware area of the first controller according to the first preset framing data block size, so that the firmware data information to be updated can be safely and reliably written into the firmware area of the controller, and the efficiency and effectiveness of firmware updating are improved. BRIEF DESCRIPTION OF DRAWINGS
[0024] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0025] Figure 1 is a structural schematic diagram of a firmware updating system provided by the embodiment of the present application;
[0026] Figure 2 is a flowchart of a firmware updating interaction method provided by the embodiment of the present application;
[0027] Figure 3 is a schematic diagram of an APP running process of an MCU provided by the embodiment of the present application;
[0028] Figure 4 is a flowchart of a firmware updating method provided by the embodiment of the present application;
[0029] Figure 5 is a schematic diagram of a memory space distribution of a controller provided by the embodiment of the present application;
[0030] Figure 6 is a flowchart of another firmware updating method provided by the embodiment of the present application;
[0031] Figure 7 is a flowchart of still another firmware updating method provided by the embodiment of the present application;
[0032] Figure 8 is a flowchart of an MCU starting process provided by the embodiment of the present application;
[0033] Figure 9 is a structural schematic diagram of a firmware updating device provided by the embodiment of the present application;
[0034] Figure 10 is a structural schematic diagram of another firmware updating device provided by the embodiment of the present application;
[0035] Figure 11 is a structural schematic diagram of an electronic device provided by the embodiment of the present application. DETAILED DESCRIPTION
[0036] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present application.
[0037] It should be understood that the terms "comprise" and "include" as used in the specification and the appended claims indicate the presence of the described features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0038] It should also be understood that the terms used in the present application specification are only for the purpose of describing particular embodiments and are not intended to limit the present application. As used in the present application specification and the appended claims, unless otherwise clearly indicated by the context, the singular forms "a", "an" and "the" are intended to include the plural forms as well.
[0039] It should be further understood that the term "and / or" as used in the present application specification and the appended claims means any combination of one or more of the associated listed items and all possible combinations thereof.
[0040] As used in the present application specification and the appended claims, the term "if" can be interpreted as meaning "when" or "once" or "in response to a determination" or "in response to detecting" depending on the context. Similarly, the phrase "if determined" or "if detected [the described condition or event]" can be interpreted as meaning "once determined" or "in response to a determination" or "once detected [the described condition or event]" or "in response to detecting [the described condition or event]" depending on the context.
[0041] In a particular implementation, the electronic device described in the embodiments of the present application includes, but is not limited to, other portable devices such as a mobile phone, a laptop computer or a tablet computer having a touch surface (e.g., a touch screen display and / or a touchpad). It should also be understood that in some embodiments, the device is not a portable communication device, but is a desktop computer having a touch surface (e.g., a touch screen display and / or a touchpad).
[0042] In the following discussion, a terminal including a display and a touch surface is described. However, it should be understood that the terminal can include one or more other physical user interface devices such as a physical keyboard, a mouse, and / or a joystick.
[0043] The terminal supports a variety of applications, such as one or more of the following: a drawing application, a presentation application, a word processing application, a website creation application, a disk authoring application, a spreadsheet application, a game application, a telephone application, a video conferencing application, an e-mail application, an instant messaging application, a workout support application, a photo management application, a digital camera application, a digital camcorder application, a web browsing application, a digital music player application, and / or a digital video player application.
[0044] The various applications that can be executed on the terminal can use at least one common physical user interface device, such as a touch surface. One or more functions of a touch surface and corresponding information displayed in association with the functions on the terminal can be adjusted and / or changed between applications and / or within respective applications. As such, a common physical architecture, such as a touch surface, of the terminal can support a variety of applications with a user interface that is intuitive and transparent to the user.
[0045] At present, in the case of updating the firmware in the automobile controller, in order to ensure the safety and reliability of the upgraded (i.e., updated) firmware Bootloader, the prior art scheme designs a first Bootloader area and a second Bootloader area, the Bootloader is updated to be written into the backup area first, and when executed, the effective one is executed, the disadvantage of the scheme is that one Bootloader area is used more, and certain Flash resources are occupied more. In addition, in the prior art scheme, after power-on or reset, the program runs in the Bootloader main storage area. The Bootloader update code is obtained, the Bootloader backup area is erased, and the update code is written into the backup area. In the technical scheme, the MCU runs in the Bootloader to perform the upgrading task, and the controller cannot normally respond to application services.
[0046] Embodiments of the present application provide a firmware updating method, which is applied to a firmware updating system, the firmware updating system comprising an Over-the-Air Technology (OTA) server and an electronic device, the electronic device comprising a first controller and a second controller, wherein the first controller can comprise a Micro Control Unit (MCU), and the second controller can comprise a System on Chip (SOC).
[0047] The OTA server can acquire the OTA upgrade package and send the OTA upgrade package to the second controller, wherein the OTA upgrade package is obtained by encapsulating an upgrade file in a specified format, and the upgrade file includes firmware data information to be updated; the second controller receives the OTA upgrade package sent by the OTA server and analyzes the OTA upgrade package to obtain the firmware data information to be updated, wherein the firmware data information to be updated includes firmware data to be updated and a firmware data address to be updated; the second controller sends the firmware data to be updated to the first controller, and the first controller writes the firmware data to be updated into a data backup area of the first controller; after determining that the firmware data to be updated is completely written into the data backup area, the firmware data to be updated is read out from the data backup area and written into a firmware area of the first controller according to the firmware address to be updated, so as to update the firmware in the first controller.
[0048] The firmware updating method provided in the embodiments of the present application can use a backup area of an application (i.e., software) APP as a common backup area, use the common backup area as a data backup area of Bootloader when upgrading Bootloader, and then move the Bootloader program in the common backup area to a Bootloader area after the upgrading of Bootloader is completed and verification is successful, so that backup upgrading is realized, the reliability of upgrading is ensured, and no additional Flash resource is occupied. In the embodiments of the present application, the controller runs in an APP program, a sub-module is designed in the APP program and is specially used for upgrading Bootloader, the sub-module is called when upgrading Bootloader, and other sub-modules in the APP normally run and respond to various application services during the upgrading process, so that the normal running of the whole system of the controller is not affected, and the user experience is improved.
[0049] The firmware updating method provided in the embodiments of the present application is applied to a firmware updating system, and the firmware updating system includes an OTA server and an electronic device, the electronic device includes a first controller and a second controller, the OTA server and the electronic device are in communication connection, and the first controller and the second controller are in communication connection.
[0050] For details, please refer to Figure 1 , Figure 1 is a structural schematic diagram of a firmware updating system provided in the embodiments of the present application, as Figure 1As shown, the firmware update system includes an OTA server 11 and an electronic device 12, wherein the electronic device 12 includes a first controller 121 and a second controller 122. Specifically, the OTA server 11 can obtain an OTA upgrade package and send it to the second controller 122. The second controller 122 parses the OTA upgrade package to obtain the firmware data information to be updated and sends the firmware data information to be updated to the first controller 121. The first controller 121 writes the firmware data information to be updated into its firmware area. In some embodiments, the OTA upgrade package is obtained by encapsulating an upgrade file of a specified format, and the upgrade file includes the firmware data information to be updated.
[0051] The firmware update method provided in this application can be applied to scenarios including but not limited to firmware updates on terminals such as vehicles (e.g., cars, motorcycles), ships, and airplanes. This application will illustrate the firmware update method using a vehicle firmware update scenario as an example.
[0052] Please see Figure 2 , Figure 2 This is a flowchart illustrating a firmware update interaction method provided in an embodiment of this application. The firmware update interaction method is applied to a firmware update system, which includes an OTA server and a controller. The controller includes a first controller and a second controller, as shown below. Figure 2 The firmware update method shown in this embodiment may include at least the following steps:
[0053] S201: The OTA server obtains the OTA upgrade package, which is obtained by encapsulating an upgrade file of a specified format. The upgrade file includes the firmware data information to be updated.
[0054] In this embodiment, the OTA server can obtain an OTA upgrade package, which is obtained by encapsulating an upgrade file in a specified format. This upgrade file includes firmware data information to be updated. The specified format upgrade file is obtained by converting an existing upgrade file according to a specified format. This upgrade file is an executable file generated by compiling a firmware (such as a bootloader) project. In some embodiments, the specified format may be an xcd file format.
[0055] S202: The OTA server sends the OTA upgrade package to the second controller.
[0056] S203: The second controller parses the OTA upgrade package to obtain the firmware data information to be updated, and sends the parsed firmware data information to be updated to the first controller.
[0057] In this embodiment, the OTA server can send the OTA upgrade package to the second controller. The second controller can parse the OTA upgrade package to obtain the firmware data information to be updated, and then send the parsed firmware data information to the first controller. Specifically, Figure 1 Taking an example, the OTA server 11 pushes an OTA upgrade package to the second controller 122 in the controller 12. The second controller 122 parses the upgrade package file and sends the obtained firmware data information to be updated to the first controller 121 in the controller 12.
[0058] In some embodiments, the firmware data information to be updated includes at least the firmware data to be updated. In other embodiments, the firmware data information to be updated may also include one or more of the following: firmware data address to be updated, software coding information to be updated, firmware version information to be updated.
[0059] The first controller can be an MCU, as detailed in [reference needed]. Figure 3 The operation flow of the MCU's APP is explained. Figure 3 This is a schematic diagram of the APP operation flow of an MCU provided in an embodiment of this application. The MCU's APP divides various services into sub-modules, such as a network management sub-module, a power management sub-module, and a cloud service sub-module. The MCU interacts with the SOC via SPI and with other ECUs or controllers via CAN. This application adds an upgrade function sub-module to upgrade the MCU's bootloader. The sub-modules execute sequentially and cyclically, so upgrading the bootloader does not affect the functionality of other sub-modules besides the upgrade function sub-module. Since the MCU updates the firmware bootloader within the APP, calling the upgrade function sub-module to update the bootloader, the APP still executes other sub-modules such as the network management sub-module, power management sub-module, and cloud service sub-module, responding to relevant application services, such as power management, without affecting the normal functioning of the system.
[0060] By using a sub-module in the APP program of the first controller MCU to update its firmware, the update function can be implemented without affecting the normal business functions of the system, thereby improving the user experience.
[0061] S204: When the first controller application is running, the first controller obtains the firmware data information to be updated sent by the second controller.
[0062] In this embodiment, the first controller can obtain firmware data information to be updated sent by the second controller while the first controller application is running. The first controller application can be an application on an MCU.
[0063] S205: The first controller writes the firmware data information to be updated into the firmware area of the first controller according to the first preset frame data block size.
[0064] In this embodiment, the first controller can write the firmware data to be updated into its firmware area according to a first preset frame data block size. In some embodiments, the first preset frame data block size is the rate at which the first controller writes the firmware data to be updated into its firmware area.
[0065] In one embodiment, before writing the firmware data information to be updated into the firmware area of the first controller according to the first preset group frame data block size, the first controller may write the firmware data information to be updated into the data backup area of the first controller, which is located in the application backup area of the first controller, wherein the firmware data information to be updated includes at least the firmware data to be updated.
[0066] In one embodiment, when the first controller writes the firmware data to be updated into the firmware area of the first controller according to the first preset frame data block size, it can read the firmware data to be updated from the data backup area after determining that the firmware data to be updated has been completely written into the data backup area of the first controller; and write the read firmware data to be updated into the firmware area of the first controller according to the firmware address to be updated, based on the first preset frame data block size.
[0067] In this embodiment, an OTA upgrade package is obtained through an OTA server and sent to a second controller. The second controller parses the OTA upgrade package to obtain the firmware data information to be updated and sends the parsed firmware data information to be updated to a first controller. When the first controller application runs, the first controller obtains the firmware data information to be updated sent by the second controller and writes the firmware data information to be updated into the firmware area of the first controller according to the first preset frame data block size. This can safely and reliably write the firmware data information to be updated into the firmware area of the controller, improving the efficiency and effectiveness of firmware updates.
[0068] Please see Figure 4 , Figure 4 This is a flowchart illustrating a firmware update method provided in an embodiment of this application. The firmware update method is applied to a first controller, such as... Figure 4 The firmware update method shown in this embodiment may include at least the following steps:
[0069] S401: When the first controller application is running, obtain the firmware data information to be updated.
[0070] In one embodiment, when the first controller obtains firmware data information to be updated, it can receive firmware data information to be updated sent by the second controller. The firmware data information to be updated is obtained by the second controller receiving an OTA upgrade package sent by the OTA server and parsing the OTA upgrade package.
[0071] In one embodiment, when the first controller obtains the firmware data information to be updated, it can receive an OTA upgrade package sent by the OTA server and parse the OTA upgrade package to obtain the firmware data information to be updated.
[0072] S402: Write the firmware data information to be updated into the firmware area of the first controller according to the first preset frame data block size.
[0073] In one embodiment, before writing the firmware data information to be updated into the firmware area of the first controller according to the first preset frame data block size, the first controller may write the firmware data information to be updated into the data backup area of the first controller, which is located in the application backup area of the first controller, wherein the firmware data information to be updated includes at least the firmware data to be updated.
[0074] In some embodiments, the data backup area is located in the first controller, which has a flash memory FLASH that includes four areas: a data backup area, an application APP area, a secondary bootloader area, and a primary bootloader area. The data backup area is a common backup area.
[0075] Specifically, such as Figure 5 As shown, Figure 5 This is a schematic diagram of the memory space distribution of a controller provided in an embodiment of this application, such as... Figure 5As shown, taking the MCU as the first controller as an example, the MCU's FLASH space is divided into four parts starting from address zero: BLOCK1: used to store LittleBootloader; BLOCK2: used to store Bootloader; BLOCK3: used to store APP; BLOCK4: as a data backup area used to store update programs. LittleBootloader is used to determine the firmware update status flag stored in the EEPROM of a specified storage unit. This flag indicates that the firmware update failed. When the flag of the specified storage unit is detected, it is determined that the firmware update failed, and the APP of the first controller is run. When the flag of the specified storage unit is not detected, it is determined that the firmware update was successful, and the Bootloader of the first controller is run. The Bootloader is used to upgrade (i.e., update) the APP program. During APP operation, the APP upgrade program is written to the data backup area (BLOCK4). After the APP program is verified to be complete, the MCU resets and enters the Bootloader, which reads the APP program stored in the data backup area (BLOCK4) and writes it to the APP area (BLOCK3). The APP is the application program of the MCU. When upgrading the Bootloader, the Bootloader program is written to the data backup area (BLOCK4). After the Bootloader verifies the completeness, it reads the data from the data backup area (BLOCK4) and writes it to the Bootloader area (BLOCK2). The data backup area is used to store the upgraded APP program or Bootloader program.
[0076] In one implementation, the firmware data information to be updated also includes the firmware data address to be updated. When the first controller writes the firmware data information to be updated into the data backup area of the first controller, it can determine the data erase address corresponding to the firmware data address to be updated from the data backup area; delete the backup data corresponding to the data erase address in the data backup area; and after deletion, write the firmware data to be updated into the backup area corresponding to the data erase address in the data backup area.
[0077] In one implementation, the first preset frame data block size can be the maximum data volume for each transmission. When the first controller writes the firmware data to be updated into the backup area corresponding to the data erase address in the data backup area, it can send the maximum data volume for each transmission to the second controller, so that the second controller transmits the firmware data to be updated to the first controller according to the maximum data volume. The first controller receives the firmware data sent by the second controller according to the maximum data volume and writes the received firmware data into the data backup area. For example, the first preset frame data block size can be 2K.
[0078] This application embodiment ensures that the firmware of the first controller is updated without affecting the operation of the application when updating, by writing the read firmware data to be updated into the firmware area of the first controller according to the firmware address to be updated based on the first preset frame data block size.
[0079] In one embodiment, when the first controller writes the firmware data information to be updated into the firmware area of the first controller according to the first preset frame data block size, it can read the firmware data to be updated from the data backup area after determining that the firmware data to be updated has been completely written into the data backup area of the first controller; and write the read firmware data to be updated into the firmware area of the first controller according to the firmware address to be updated, based on the first preset frame data block size.
[0080] This embodiment of the application uses a common data backup area to store updated firmware data information, reads firmware data information to be updated from the data backup area, and stores the read firmware data information to be updated in the firmware area of the first controller. This can prevent the system from crashing due to firmware update failure of the first controller. At the same time, it can reasonably allocate the storage space of the first controller and use the data backup area as a common backup area to realize batch update of the firmware of the first controller, save device resources, and improve firmware update efficiency.
[0081] In one embodiment, the firmware data to be updated further includes software coding information to be updated and firmware version information to be updated. Before receiving the firmware data to be updated sent by the second controller, the first controller may send the software coding information and firmware version information stored locally in the first controller to the second controller, so that the second controller can use the locally stored software coding information and firmware version information to determine whether the software coding information to be updated and the firmware version information to be updated meet the update conditions. If it is confirmed that the software coding information to be updated and the firmware version information to be updated meet the update conditions, the second controller receives the firmware data to be updated sent by the second controller. In some embodiments, the firmware version information includes, but is not limited to, the firmware version number.
[0082] In some embodiments, the software coding information to be updated and the firmware version information to be updated meet the update conditions, including: the comparison result between the locally stored software coding information and the software coding information to be updated is consistent, and the firmware version information to be updated is greater than the locally stored firmware version information.
[0083] In one implementation, the first controller can read locally stored software coding information and send it to the second controller, so that the second controller compares the locally stored software coding information with the software coding information in the firmware data information to be updated to obtain a first comparison result. If the first comparison result is consistent, the first controller can read locally stored firmware version information and send it to the second controller, so that the second controller compares the locally stored firmware version information with the firmware version information in the firmware data information to be updated to obtain a second comparison result. If the second comparison result shows that the firmware version information in the firmware data information to be updated is greater than the locally stored firmware version information, it is determined whether the software coding information to be updated and the firmware version information to be updated meet the update conditions.
[0084] In one embodiment, before receiving the firmware data information to be updated sent by the second controller, the first controller may receive a first instruction sent by the second controller. The first instruction is used to instruct the first controller to enter an extended session mode, so that the first controller enters a state that disables fault code setting and / or disables communication message sending.
[0085] In one implementation, after determining whether the software coding information to be updated and the firmware version information to be updated meet the update conditions, the first controller can receive a first instruction sent by the second controller and control the first controller to enter an extended session mode. After entering the extended session mode, the first controller can be controlled to enter a state of disabling fault code setting and / or disabling communication message sending.
[0086] The first controller can receive a second instruction from the second controller after a first time interval following the first instruction sent by the second controller, which indicates that fault code setting is disabled, so as to control the first controller to enter the state of disabling fault code setting.
[0087] The first controller can receive a third instruction from the second controller after a second time interval following the second instruction sent by the second controller, which indicates that communication message transmission is prohibited, thereby controlling the first controller to enter the state of prohibiting communication message transmission.
[0088] In one embodiment, before receiving the firmware data to be updated from the second controller, the first controller may receive a security verification request from the second controller; in response to the security verification request, it calculates a first key based on a preset security verification algorithm and a random number, and sends the random number to the second controller; it receives a second key from the second controller, which is calculated by the second controller based on the preset security verification algorithm and a random number; it compares the first key and the second key, and if the comparison results are consistent, it determines that the security verification of the first controller has passed, and controls the first controller to enter the programming session mode. In some embodiments, the preset security verification algorithm may include a keyword, and the keyword in the preset security verification algorithm used by the first controller may be the same as or different from the keyword in the preset security verification algorithm used by the first controller.
[0089] In one implementation, after the second controller sends a third instruction to the first controller to indicate that communication message transmission is prohibited after a second time interval following the sending of the second instruction, the second controller may send a security verification request to the first controller. The first controller responds to the security verification request by calculating a first key based on a preset security verification algorithm and a random number, and sends a random number to the second controller. The second controller calculates a second key based on the preset security verification algorithm and the random number, and sends the second key to the first controller. The first controller compares the first key and the second key; if the comparison results are consistent, the security verification is deemed successful, and the first controller is controlled to enter a programming session mode. In the programming session mode, the firmware data to be updated is written to the controller's data backup area.
[0090] In one embodiment, when the first controller receives firmware data information to be updated sent by the second controller, it can receive the firmware data information to be updated sent by the second controller at a second preset frame data block size, wherein the second preset frame data block size refers to the receiving rate of the first controller receiving the firmware data information to be updated, that is, the sending rate of the second controller sending the firmware data information to be updated.
[0091] In one embodiment, after the first controller writes the firmware data to be updated into its firmware area according to the first preset frame data block size, it can obtain a first checksum transmitted by the second controller. The first checksum is the sum of each byte of the firmware data to be updated calculated by the second controller. It then obtains each byte of the firmware data to be updated written into the firmware area of the first controller and calculates the sum of each byte to obtain a second checksum. The first checksum is compared with the second checksum. If the comparison results are consistent, the firmware update is determined to be successful. If the comparison results are inconsistent, the step of writing the firmware data to be updated into the data backup area of the first controller is repeated n times, where n is a positive integer. If the comparison results of the first checksum and the second checksum obtained after repeating the step of writing the firmware data to be updated into the data backup area of the first controller n times are inconsistent, the firmware update is determined to be unsuccessful, a firmware update failure flag is generated, the flag is written to a designated storage unit, and a firmware update failure notification message is sent to the second controller. The specified storage unit can be an electrically erasable programmable read-only memory (EEPROM).
[0092] In one embodiment, after the first controller writes the firmware data information to be updated into the firmware area of the first controller according to the first preset group frame data block size, the first controller application can run when a firmware update failure flag is detected after the first controller is powered on or reset; and the new firmware on the first controller can run when no firmware update failure flag is detected after the first controller is powered on or reset.
[0093] In this embodiment, the first controller can acquire firmware data information to be updated during the execution of the first controller application; write the firmware data in the firmware data information to be updated into the data backup area of the first controller; after confirming that the firmware data has been completely written into the data backup area, read the firmware data from the data backup area, and write the firmware data read from the data backup area into the firmware area of the first controller according to the firmware address to be updated in the firmware data information to be updated, thereby updating the firmware in the controller. Updating the firmware of the first controller by storing the update program in a shared data backup area can prevent system paralysis caused by firmware upgrade failure. At the same time, it can reasonably allocate the storage space of the first controller, and using the data backup area as a shared backup area can save device resources.
[0094] Please seeFigure 6 , Figure 6 This is a flowchart illustrating another firmware update method provided in an embodiment of this application. This firmware update method is applied to a second controller, such as... Figure 6 The firmware update method shown in this embodiment may include at least the following steps:
[0095] S601: Obtain firmware data information to be updated.
[0096] In this embodiment of the application, the second controller can receive the OTA upgrade package sent by the OTA server and parse the OTA upgrade package to obtain the firmware data information to be updated.
[0097] S602: Send firmware data information to be updated to the first controller, so that the first controller, when the application is running, writes the firmware data information to be updated into the firmware area of the first controller according to the first preset frame data block size.
[0098] In one embodiment, before sending the firmware data to be updated to the first controller, the second controller may read the software coding information and firmware version information stored locally in the first controller; and use the locally stored software coding information and firmware version information to determine whether the software coding information and firmware version information to be updated meet the update conditions.
[0099] In some embodiments, the software coding information to be updated and the firmware version information to be updated meet the update conditions, including: the comparison result between the software coding information stored locally by the first controller and the software coding information to be updated is consistent, and the firmware version information to be updated is greater than the firmware version information stored locally.
[0100] In one embodiment, before sending the firmware data to be updated to the first controller, the second controller may send a first instruction to the first controller. The first instruction is used to instruct the first controller to enter an extended session mode, so that the first controller enters a state that disables fault code setting and / or disables communication message sending.
[0101] In one embodiment, before sending the firmware data to be updated to the first controller, the second controller may send a security verification request to the first controller, so that the first controller responds to the security verification request, calculates a first key according to a preset security verification algorithm and a random number, and sends the random number to the second controller; receives the random number sent by the first controller, calculates a second key according to the preset security verification algorithm and the random number; and sends the second key to the first controller, so that the first controller compares the first key and the second key, and if the comparison results are consistent, determines that the security verification of the first controller has passed, and controls the first controller to enter the programming session mode.
[0102] In one embodiment, when the second controller sends firmware data information to be updated to the first controller, it may send the firmware data information to be updated to the first controller in a second preset frame data block size.
[0103] In one embodiment, after sending the firmware data to be updated to the first controller, the second controller can calculate the sum of each byte of the firmware data to be updated to obtain a first check value, and send the first check value to the first controller so that the first controller can compare the first check value with a second check value and determine whether the firmware update is successful based on the comparison result. The second check value is the sum of each byte of the firmware data to be updated written to the firmware area of the first controller. The second controller can also receive a firmware update failure notification message sent by the first controller, which is generated and sent by the first controller when it confirms that the firmware update is unsuccessful.
[0104] Please see Figure 7 , Figure 7 This is a flowchart illustrating another firmware update method provided in this application embodiment. The firmware update method is applied to a controller, which includes a first controller and a second controller. The first controller is a System-on-a-Chip (SoC), the second controller is an MCU, and the firmware is a bootloader. Figure 7 The firmware update method shown in this embodiment may include at least the following steps:
[0105] S701: SOC obtains firmware data information to be updated.
[0106] The SOC receives the OTA upgrade package sent by the OTA server and parses the OTA upgrade package to obtain the firmware data information to be updated. The firmware data information to be updated includes the firmware data to be updated, the software coding information to be updated, the firmware version information to be updated, and the firmware data address to be updated. The firmware version information to be updated includes, but is not limited to, the firmware version number to be updated.
[0107] S702: SOC verifies software coding information.
[0108] The SOC reads the software coding information stored locally in the MCU and compares it with the software coding information to be updated in the firmware data. If they are the same, S703 is executed; otherwise, the firmware update process is exited.
[0109] Specific combination Figure 8 The startup process of the MCU will be explained. Figure 8 This is a schematic diagram of an MCU startup process provided in an embodiment of this application, such as... Figure 8As shown, after the MCU starts up, it can enter the LittleBootloader and read the identifier stored in the specified storage unit EEPROM. It then uses the identifier to determine whether the firmware update was successful. If the firmware update is successful, the Bootloader of the first controller is run. If the firmware update is unsuccessful, the APP of the first controller is run.
[0110] S703: The SOC verifies the firmware version information.
[0111] The SOC reads the Bootloader version number (i.e., the firmware version information stored locally) stored on the MCU, and then compares it with the firmware version number to be updated (i.e., the firmware version information to be updated). S707 can only be executed if the firmware version number to be updated is greater than the MCU's Bootloader version number; otherwise, the upgrade process is exited.
[0112] S704: The SOC controls the MCU to enter extended session mode, so that the MCU enters a state that disables fault code setting and / or disables communication message transmission.
[0113] According to the UDS diagnostic protocol, the SOC sends a first instruction to the MCU to enter the extended session mode, thereby controlling the MCU to enter the extended session mode. Then, it sends a second instruction to the MCU to indicate that fault code setting is disabled, thereby causing the MCU to enter the fault code setting disabled state. Next, it sends a third instruction to the MCU to indicate that communication message transmission is disabled, thereby causing the MCU to enter the communication message transmission disabled state.
[0114] S705: The MCU performs security verification on the SOC.
[0115] The SOC sends a security verification request to the MCU and obtains the seed (i.e., random number) in the MCU's response to the security verification request. The MCU calculates the first key based on the preset security verification algorithm and the seed (i.e., random number). The SOC calculates the second key based on the seed (i.e., random number) and the preset security verification algorithm (such as the preset keyword key), and sends the second key to the MCU. If the MCU verifies the key, it executes step S706; otherwise, it exits the firmware update program.
[0116] S706: MCU enters programming session mode.
[0117] S707: The MCU erases the data in the data backup area.
[0118] The MCU determines whether to upgrade (i.e. update) the Bootloader based on the data erase address corresponding to the firmware data address to be updated sent by the SOC, and erases the corresponding size from the starting address of the FLASH data backup area (BLOCK4) according to the size of the Bootloader.
[0119] S708: The SOC sends a data transmission request to the MCU.
[0120] The SOC sends a data transmission request to the MCU, and the MCU replies to the SOC with the maximum amount of data that can be transmitted at one time (i.e., the second preset frame data block size), for example, 2KB of data can be transmitted at one time.
[0121] S709: SOC transmits data to MCU.
[0122] The SOC transmits data (i.e., the firmware data to be updated) to the MCU according to the maximum amount of data that the SOC can transmit at one time, as replied by the MCU. The MCU then starts receiving the data sent by the SOC and assembles the data into packets according to the UDS diagnostic protocol format.
[0123] S710: The MCU writes the transmission data sent by the SOC, i.e., the Bootloader program, starting from the beginning address of the data backup area (BLOCK4).
[0124] The bootloader program starts writing data from the beginning address of the data backup area (BLOCK4), writing 2KB of data at a time. After writing, the data is read out and compared with the written data. If they are the same, the write was successful; otherwise, the write is repeated. The backup area address plus 2048 is used as the address for the next write.
[0125] S711: Determine whether the writing of the Bootloader program is complete. If the result is that the Bootloader program transfer is complete, proceed to step S712. If the result is that the Bootloader program transfer is incomplete, proceed to step S710.
[0126] The end address is used to determine whether writing to the Bootloader is complete. If it is not complete, continue waiting to receive data.
[0127] S712: Verify whether the Bootloader is complete. If the verification result is negative, proceed to step S713. If the verification result is positive, proceed to step S714.
[0128] The program of the Bootloader in the backup area (BLCOK4) is read and the cumulative sum is calculated. Then it is compared with the checksum transmitted by the SOC. If the comparison results are consistent, the Bootloader is confirmed to be intact.
[0129] S713: MCU power-on or reset.
[0130] After the MCU is powered on or reset, if a firmware update failure flag is detected, the MCU's APP program is rerun to confirm that the bootloader upgrade has failed. The SOC restarts the upgrade process, repeating the upgrade process a maximum of n (e.g., 3) times. If no firmware update failure flag is detected, the bootloader upgrade is confirmed to be successful, and the new bootloader on the MCU is run.
[0131] S714: The MCU erases the Bootloader area (BLOCK2).
[0132] S715: The MCU reads the Bootloader program from the starting address of the backup area (BLOCK4) and writes the Bootloader program from the starting address of the Bootloader area (BLOCK2).
[0133] The MCU reads the Bootloader program starting from the beginning address of the backup area (BLOCK4), reading 2KB of data at a time, and then writes 2KB of the Bootloader program starting from the beginning address of the Bootloader area (BLOCK2). After writing, the program is read and compared with the written data. If they are the same, the write was successful; otherwise, it is rewritten. The next read address and write address are the addresses calculated in step S715.
[0134] S716: The address of the MCU control data backup area (BLOCK4) plus 2048 (i.e., the bytes corresponding to the maximum data volume) is used as the next read address, and the address of the Bootloader (BLOCK2) plus 2048 is used as the next write address.
[0135] S717: The MCU determines whether the writing of the Bootloader program is complete. If it is not complete, it continues to execute step S715. If it is determined that the Bootloader program transfer is complete, it executes step S718.
[0136] S718: The MCU verifies whether the Bootloader is complete. If the verification result is complete, proceed to step S713. If the verification result is incomplete, proceed to step S719.
[0137] Read the data from the Bootloader area (BLCOK2) and calculate the cumulative sum (i.e., the second checksum). Then compare it with the checksum transmitted by the SOC (i.e., the first checksum). If the checksum passes, the MCU is reset and the APP is restarted. If the checksum fails, step S715 is executed.
[0138] S719: The MCU determines whether the number of re-executions exceeds the preset number. If it does, the firmware update is determined to have failed, and step S720 is executed.
[0139] Determine whether the number of re-executions exceeds the preset number n (e.g., 3 times), that is, determine whether the re-writing from the data backup area (BLCOK4) to the Bootloader (BLOCK2) exceeds 3 times.
[0140] S720: The MCU writes a firmware update failure flag to the specified memory cell and sends a firmware update failure notification message to the SOC.
[0141] If the verification of reading from the data backup area (BLOCK4) and writing to the Bootloader area (BLOCK2) fails n times, the firmware upgrade is determined to have failed. A firmware update failure flag is written to the EEPROM (i.e., the specified storage unit), and the SOC is notified that the Bootloader update has failed. The MCU is reset and restarted. Upon restarting, the MCU reads the flag stored in the EEPROM in the LittleBootloader area (BLOCK1). If it is a Bootloader upgrade failure flag, the MCU is directly redirected to the APP. This way, the MCU will not fail to run when the Bootloader upgrade fails.
[0142] Please see Figure 9 , Figure 9 This is a schematic diagram of a firmware update device provided in an embodiment of this application. The firmware update device is disposed in a first controller and includes an acquisition unit 901 and a writing unit 902.
[0143] The acquisition unit 901 is used to acquire firmware data information to be updated when the first controller application is running;
[0144] The writing unit 902 is used to write the firmware data information to be updated into the firmware area of the first controller according to the first preset frame data block size.
[0145] Furthermore, when the acquisition unit 901 acquires the firmware data information to be updated, it is specifically used for:
[0146] The system receives firmware data information to be updated from the second controller. The firmware data information to be updated is obtained by the second controller receiving an OTA upgrade package sent by the OTA server and parsing the OTA upgrade package.
[0147] Furthermore, before the writing unit 902 writes the firmware data information to be updated into the firmware area of the first controller according to the first preset frame data block size, it is also used for:
[0148] The firmware data information to be updated is written into the data backup area of the first controller, which is located in the application backup area of the first controller. The firmware data information to be updated includes at least the firmware data to be updated.
[0149] Furthermore, the firmware data information to be updated also includes the firmware data address to be updated; when the writing unit 902 writes the firmware data information to be updated into the data backup area of the first controller, it is specifically used for:
[0150] Determine the data erase address corresponding to the firmware data address to be updated from the data backup area;
[0151] The backup data corresponding to the data erasure address in the data backup area is deleted, and after the deletion, the firmware data to be updated is written into the backup area corresponding to the data erasure address in the data backup area.
[0152] Furthermore, when the writing unit 902 writes the firmware data information to be updated into the firmware area of the first controller according to the first preset frame data block size, it is specifically used for:
[0153] After confirming that the firmware data to be updated has been completely written into the data backup area of the first controller, the firmware data to be updated is read from the data backup area.
[0154] Based on the first preset frame data block size, the read firmware data to be updated is written into the firmware area of the first controller according to the firmware address to be updated.
[0155] Furthermore, the firmware data information to be updated also includes software coding information to be updated and firmware version information to be updated; before the acquisition unit 901 receives the firmware data information to be updated sent by the second controller, it is also used to:
[0156] The software coding information and firmware version information stored locally in the first controller are sent to the second controller so that the second controller can use the locally stored software coding information and firmware version information to determine whether the software coding information to be updated and the firmware version information to be updated meet the update conditions.
[0157] If the software coding information to be updated and the firmware version information to be updated are confirmed to meet the update conditions, the step of receiving the firmware data information to be updated sent by the second controller is executed.
[0158] Furthermore, the software coding information to be updated and the firmware version information to be updated satisfy the update conditions, including: the comparison result between the locally stored software coding information and the software coding information to be updated is consistent, and the firmware version information to be updated is greater than the locally stored firmware version information.
[0159] Furthermore, before receiving the firmware data information to be updated sent by the second controller, the acquisition unit 901 is also used to:
[0160] The system receives a first instruction sent by the second controller, the first instruction being used to instruct the first controller to enter an extended session mode, so that the first controller enters a state of disabling fault code setting and / or disabling communication message transmission.
[0161] Furthermore, before receiving the firmware data information to be updated sent by the second controller, the acquisition unit 901 is also used to:
[0162] Receive the security verification request sent by the second controller;
[0163] In response to the security verification request, a first key is calculated based on a preset security verification algorithm and a random number, and the random number is sent to the second controller;
[0164] The system receives a second key sent by the second controller, which is calculated by the second controller based on the preset security verification algorithm and the random number.
[0165] The first key and the second key are compared. If the comparison results are consistent, the security verification of the first controller is determined to be successful, and the first controller is controlled to enter the programming session mode.
[0166] Furthermore, when the acquisition unit 901 receives the firmware data information to be updated sent by the second controller, it is specifically used for:
[0167] The firmware data information to be updated sent by the second controller is received with a second preset frame data block size.
[0168] Furthermore, after the writing unit 902 writes the firmware data information to be updated into the firmware area of the first controller according to the first preset frame data block size, it is also used for:
[0169] Obtain the first verification value transmitted by the second controller, wherein the first verification value is the sum of each byte of the firmware data to be updated calculated by the second controller;
[0170] Obtain each byte of the firmware data to be updated written to the firmware area of the first controller, and calculate the sum of each byte of the firmware data to be updated written to the firmware area of the first controller to obtain a second verification value;
[0171] Compare the first verification value with the second verification value;
[0172] If the comparison results of the first verification value and the second verification value are consistent, the firmware update is determined to be successful;
[0173] If the comparison results between the first verification value and the second verification value are inconsistent, the step of writing the firmware data information to be updated into the data backup area of the first controller is re-executed;
[0174] If the comparison between the first verification value and the second verification value obtained by re-executing the step of writing the firmware data information to be updated into the data backup area of the first controller is inconsistent, it is determined that the firmware update is unsuccessful, an identifier of the firmware update failure is generated, the identifier is written into the designated storage unit, and a firmware update failure notification message is sent to the second controller.
[0175] Furthermore, after the writing unit 902 writes the firmware data information to be updated into the firmware area of the first controller according to the first preset frame data block size, it is also used for:
[0176] When the firmware update failure flag is detected after the first controller is powered on or reset, the first controller application is run.
[0177] If no flag indicating unsuccessful firmware update is detected after the first controller is powered on or reset, the new firmware on the first controller is run.
[0178] In this embodiment, by obtaining the firmware data information to be updated during the execution of the first controller application, and writing the firmware data information to be updated into the firmware area of the first controller according to the first preset frame data block size, the firmware data information to be updated can be written into the firmware area of the controller safely and reliably, thereby improving the efficiency and effectiveness of firmware updates.
[0179] Please see Figure 10 , Figure 10 This is a schematic diagram of another firmware update device provided in an embodiment of this application. The firmware update device is disposed in a second controller and includes an acquisition unit 1001 and a sending unit 1002.
[0180] Acquisition unit 1001 is used to acquire firmware data information to be updated;
[0181] The sending unit 1002 is used to send firmware data information to be updated to the first controller, so that the first controller writes the firmware data information to be updated into the firmware area of the first controller according to the first preset frame data block size when the application is running.
[0182] Furthermore, when the acquisition unit 1001 acquires the firmware data information to be updated, it is specifically used for:
[0183] Receive the OTA upgrade package sent by the OTA server, and parse the OTA upgrade package to obtain the firmware data information to be updated.
[0184] Furthermore, before sending the firmware data information to be updated to the first controller, the sending unit 1002 is also used for:
[0185] Read the software coding information and firmware version information stored locally in the first controller;
[0186] The software coding information and firmware version information stored locally are used to determine whether the software coding information to be updated and the firmware version information to be updated meet the update conditions.
[0187] Furthermore, the software coding information to be updated and the firmware version information to be updated satisfy the update conditions, including: the comparison result between the locally stored software coding information and the software coding information to be updated is consistent, and the firmware version information to be updated is greater than the locally stored firmware version information.
[0188] Furthermore, before sending the firmware data information to be updated to the first controller, the sending unit 1002 is also used for:
[0189] Send a first instruction to the first controller, the first instruction being used to instruct the first controller to enter an extended session mode, so that the first controller enters a state of disabling fault code setting and / or disabling communication message transmission.
[0190] Furthermore, before sending the firmware data information to be updated to the first controller, the sending unit 1002 is also used for:
[0191] A security verification request is sent to the first controller, so that the first controller responds to the security verification request, calculates the first key according to the preset security verification algorithm and random number, and sends the random number to the second controller;
[0192] The system receives the random number sent by the first controller and calculates the second key based on the preset security verification algorithm and the random number.
[0193] The second key is sent to the first controller, so that the first controller compares the first key and the second key. If the comparison results are consistent, the first controller determines that the security verification of the first controller has passed and controls the first controller to enter the programming session mode.
[0194] Furthermore, when the sending unit 1002 sends the firmware data information to be updated to the first controller, it is specifically used for:
[0195] The firmware data information to be updated is sent to the first controller with a second preset frame data block size.
[0196] Furthermore, the firmware data information to be updated includes at least the firmware data to be updated; after the sending unit 1002 sends the firmware data information to be updated to the first controller, it is also used for:
[0197] The first check value is obtained by summing the byte data of the firmware data to be updated. The first check value is then sent to the first controller so that the first controller compares the first check value with the second check value and determines whether the firmware update is successful based on the comparison result. The second check value is the sum of the byte data of the firmware data to be updated calculated by the first controller and written into the firmware area of the first controller.
[0198] The system receives a notification message from the first controller indicating that the firmware update has failed. This notification message is generated and sent by the first controller when it confirms that the firmware update has failed.
[0199] In this embodiment, the controller can obtain firmware data information to be updated; send the firmware data information to be updated to the first controller, so that when the application is running, the first controller writes the firmware data information to be updated into the firmware area of the first controller according to the first preset frame data block size, which can safely and reliably write the firmware data information to be updated into the firmware area of the controller, thereby improving the efficiency and effectiveness of firmware updates.
[0200] See Figure 11 , Figure 11 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. As shown in the figure, the electronic device in this embodiment may include: one or more processors 1101, a memory 1102, a bus 1103, and a communication interface 1104. The processor 1101, communication interface 1104, and memory 1102 are connected via the bus 1103. The memory 1102 is used to store programs. The processor 1101 is used to call the program stored in the memory via the bus 1103 to execute the following steps:
[0201] When the first controller application is running, obtain the firmware data information to be updated;
[0202] According to the first preset frame data block size, the firmware data information to be updated is written into the firmware area of the first controller.
[0203] Furthermore, when the processor 1101 acquires the firmware data information to be updated, it is specifically used for:
[0204] The system receives firmware data information to be updated from the second controller. The firmware data information to be updated is obtained by the second controller receiving an OTA upgrade package sent by the OTA server and parsing the OTA upgrade package.
[0205] Furthermore, before the processor 1101 writes the firmware data information to be updated into the firmware area of the first controller according to the first preset frame data block size, it is also used to:
[0206] The firmware data information to be updated is written into the data backup area of the first controller, which is located in the application backup area of the first controller. The firmware data information to be updated includes at least the firmware data to be updated.
[0207] Furthermore, the firmware data information to be updated also includes the firmware data address to be updated; when the processor 1101 writes the firmware data information to be updated into the data backup area of the first controller, it is specifically used for:
[0208] Determine the data erase address corresponding to the firmware data address to be updated from the data backup area;
[0209] The backup data corresponding to the data erasure address in the data backup area is deleted, and after the deletion, the firmware data to be updated is written into the backup area corresponding to the data erasure address in the data backup area.
[0210] Furthermore, when the processor 1101 writes the firmware data information to be updated into the firmware area of the first controller according to the first preset frame data block size, it is specifically used for:
[0211] After confirming that the firmware data to be updated has been completely written into the data backup area of the first controller, the firmware data to be updated is read from the data backup area.
[0212] Based on the first preset frame data block size, the read firmware data to be updated is written into the firmware area of the first controller according to the firmware address to be updated.
[0213] Furthermore, the firmware data information to be updated also includes software coding information to be updated and firmware version information to be updated; before receiving the firmware data information to be updated sent by the second controller, the processor 1101 is also used to:
[0214] The software coding information and firmware version information stored locally in the first controller are sent to the second controller so that the second controller can use the locally stored software coding information and firmware version information to determine whether the software coding information to be updated and the firmware version information to be updated meet the update conditions.
[0215] If the software coding information to be updated and the firmware version information to be updated are confirmed to meet the update conditions, the step of receiving the firmware data information to be updated sent by the second controller is executed.
[0216] Furthermore, the software coding information to be updated and the firmware version information to be updated satisfy the update conditions, including: the comparison result between the locally stored software coding information and the software coding information to be updated is consistent, and the firmware version information to be updated is greater than the locally stored firmware version information.
[0217] Furthermore, before receiving the firmware data information to be updated sent by the second controller, the processor 1101 is also used to:
[0218] The system receives a first instruction sent by the second controller, the first instruction being used to instruct the first controller to enter an extended session mode, so that the first controller enters a state of disabling fault code setting and / or disabling communication message transmission.
[0219] Furthermore, before receiving the firmware data information to be updated sent by the second controller, the processor 1101 is also used to:
[0220] Receive the security verification request sent by the second controller;
[0221] In response to the security verification request, a first key is calculated based on a preset security verification algorithm and a random number, and the random number is sent to the second controller;
[0222] The system receives a second key sent by the second controller, which is calculated by the second controller based on the preset security verification algorithm and the random number.
[0223] The first key and the second key are compared. If the comparison results are consistent, the security verification of the first controller is determined to be successful, and the first controller is controlled to enter the programming session mode.
[0224] Furthermore, when the processor 1101 receives the firmware data information to be updated sent by the second controller, it is specifically used for:
[0225] The firmware data information to be updated sent by the second controller is received with a second preset frame data block size.
[0226] Furthermore, after the processor 1101 writes the firmware data information to be updated into the firmware area of the first controller according to the first preset frame data block size, it is also used for:
[0227] Obtain the first verification value transmitted by the second controller, wherein the first verification value is the sum of each byte of the firmware data to be updated calculated by the second controller;
[0228] Obtain each byte of the firmware data to be updated written to the firmware area of the first controller, and calculate the sum of each byte of the firmware data to be updated written to the firmware area of the first controller to obtain a second verification value;
[0229] Compare the first verification value with the second verification value;
[0230] If the comparison results of the first verification value and the second verification value are consistent, the firmware update is determined to be successful;
[0231] If the comparison results between the first verification value and the second verification value are inconsistent, the step of writing the firmware data information to be updated into the data backup area of the first controller is re-executed;
[0232] If the comparison between the first verification value and the second verification value obtained by re-executing the step of writing the firmware data information to be updated into the data backup area of the first controller is inconsistent, it is determined that the firmware update is unsuccessful, an identifier of the firmware update failure is generated, the identifier is written into the designated storage unit, and a firmware update failure notification message is sent to the second controller.
[0233] Furthermore, after the processor 1101 writes the firmware data information to be updated into the firmware area of the first controller according to the first preset frame data block size, it is also used for:
[0234] When the firmware update failure flag is detected after the first controller is powered on or reset, the first controller application is run.
[0235] If no flag indicating unsuccessful firmware update is detected after the first controller is powered on or reset, the new firmware on the first controller is run.
[0236] In this embodiment, the electronic device obtains the firmware data information to be updated when the first controller application is running; and writes the firmware data information to be updated into the firmware area of the first controller according to the first preset frame data block size. This can safely and reliably write the firmware data information to be updated into the firmware area of the controller, thereby improving the efficiency and effectiveness of firmware updates.
[0237] like Figure 11 As shown, the processor 1101 of the electronic device provided in this application embodiment can also be used to call a program stored in the aforementioned memory via the bus 1103 to perform the following steps:
[0238] Obtain firmware data information to be updated;
[0239] The firmware data information to be updated is sent to the first controller so that the first controller, when the application is running, writes the firmware data information to be updated into the firmware area of the first controller according to the first preset group frame data block size.
[0240] Furthermore, when the processor 1101 acquires the firmware data information to be updated, it is specifically used for:
[0241] Receive the OTA upgrade package sent by the OTA server, and parse the OTA upgrade package to obtain the firmware data information to be updated.
[0242] Furthermore, before sending the firmware data to be updated to the first controller, the processor 1101 is also used to:
[0243] Read the software coding information and firmware version information stored locally in the first controller;
[0244] The software coding information and firmware version information stored locally are used to determine whether the software coding information to be updated and the firmware version information to be updated meet the update conditions.
[0245] Furthermore, the software coding information to be updated and the firmware version information to be updated satisfy the update conditions, including: the comparison result between the locally stored software coding information and the software coding information to be updated is consistent, and the firmware version information to be updated is greater than the locally stored firmware version information.
[0246] Furthermore, before sending the firmware data to be updated to the first controller, the processor 1101 is also used to:
[0247] Send a first instruction to the first controller, the first instruction being used to instruct the first controller to enter an extended session mode, so that the first controller enters a state of disabling fault code setting and / or disabling communication message transmission.
[0248] Furthermore, before sending the firmware data to be updated to the first controller, the processor 1101 is also used to:
[0249] A security verification request is sent to the first controller, so that the first controller responds to the security verification request, calculates the first key according to the preset security verification algorithm and random number, and sends the random number to the second controller;
[0250] The system receives the random number sent by the first controller and calculates the second key based on the preset security verification algorithm and the random number.
[0251] The second key is sent to the first controller, so that the first controller compares the first key and the second key. If the comparison results are consistent, the first controller determines that the security verification of the first controller has passed and controls the first controller to enter the programming session mode.
[0252] Furthermore, when the processor 1101 sends the firmware data information to be updated to the first controller, it is specifically used for:
[0253] The firmware data information to be updated is sent to the first controller with a second preset frame data block size.
[0254] Furthermore, the firmware data information to be updated includes at least the firmware data to be updated; after the processor 1101 sends the firmware data information to be updated to the first controller, it is also used to:
[0255] The first check value is obtained by summing the byte data of the firmware data to be updated. The first check value is then sent to the first controller so that the first controller compares the first check value with the second check value and determines whether the firmware update is successful based on the comparison result. The second check value is the sum of the byte data of the firmware data to be updated calculated by the first controller and written into the firmware area of the first controller.
[0256] The system receives a notification message from the first controller indicating that the firmware update has failed. This notification message is generated and sent by the first controller when it confirms that the firmware update has failed.
[0257] In this embodiment, the electronic device obtains firmware data information to be updated and sends the firmware data information to be updated to the first controller, so that the first controller, when the application is running, writes the firmware data information to be updated into the firmware area of the first controller according to the first preset frame data block size. This can safely and reliably write the firmware data information to be updated into the firmware area of the controller, improving the efficiency and effectiveness of firmware updates.
[0258] It should be understood that, in the embodiments of this application, the processor 1101 may be a Central Processing Unit (CPU), but it may also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor.
[0259] The memory 1102 may include read-only memory and random access memory, and provides instructions and data to the processor 1101. A portion of the memory 1102 may also include non-volatile random access memory. For example, the memory 1102 may also store device type information.
[0260] In specific implementation, the processor 1101 described in this application embodiment can execute the embodiments of this application. Figure 2 , Figure 4 , Figure 6 , Figure 7 Any of the firmware update methods described herein can be implemented in the embodiments of this application. Figure 9 or Figure 10 The implementation of the described firmware update device will not be elaborated here.
[0261] This application provides a vehicle, which includes a vehicle body and electronic devices. The electronic devices include a first controller and a second controller. The first controller is used to perform actions such as... Figure 2 , Figure 4 , Figure 7 The method described in any one of the above updates the firmware of the first controller of the vehicle, and the second controller is used to perform, for example... Figure 2 ,like Figure 6 , Figure 7 The method described in either case updates the firmware of the first controller of the vehicle.
[0262] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this application.
[0263] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the terminals and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0264] In the several embodiments provided in this application, it should be understood that the disclosed terminals and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices or units, or may be electrical, mechanical or other forms of connection.
[0265] The steps in the method of this application embodiment can be adjusted, combined, or deleted according to actual needs.
[0266] The units in the terminal of this application embodiment can be merged, divided, and deleted according to actual needs.
[0267] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of the embodiments of this application, depending on actual needs.
[0268] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0269] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0270] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A firmware update method, characterized in that, Applied to a first controller, the method includes: When the first controller application is running, obtain the firmware data information to be updated; According to the size of the first preset frame data block, the firmware data information to be updated is written into the firmware area of the first controller; The process of obtaining the firmware data information to be updated includes: The system receives firmware data information to be updated sent by the second controller. The firmware data information to be updated is obtained by the second controller receiving an OTA upgrade package sent by the OTA server and parsing the OTA upgrade package. Before writing the firmware data information to be updated into the firmware area of the first controller according to the first preset frame data block size, the method further includes: The firmware data information to be updated is written into the data backup area of the first controller. The data backup area is located in the application backup area of the first controller. The data backup area is a public backup area. The firmware data information to be updated includes at least the firmware data to be updated. The firmware data information to be updated also includes the firmware data address to be updated; writing the firmware data information to be updated into the data backup area of the first controller includes: Determine the data erase address corresponding to the firmware data address to be updated from the data backup area; The backup data corresponding to the data erasure address in the data backup area is deleted, and after the deletion, the firmware data to be updated is written into the backup area corresponding to the data erasure address in the data backup area. The step of writing the firmware data information to be updated into the firmware area of the first controller according to the first preset frame data block size includes: After confirming that the firmware data to be updated has been completely written into the data backup area of the first controller, the firmware data to be updated is read from the data backup area. Based on the first preset frame data block size, the read firmware data to be updated is written into the firmware area of the first controller according to the firmware address to be updated.
2. The method according to claim 1, characterized in that, The firmware data information to be updated also includes software coding information to be updated and firmware version information to be updated; before receiving the firmware data information to be updated sent by the second controller, the method further includes: The software coding information and firmware version information stored locally in the first controller are sent to the second controller so that the second controller can use the locally stored software coding information and firmware version information to determine whether the software coding information to be updated and the firmware version information to be updated meet the update conditions. If the software coding information to be updated and the firmware version information to be updated are confirmed to meet the update conditions, the step of receiving the firmware data information to be updated sent by the second controller is executed.
3. The method according to claim 2, characterized in that, The software coding information to be updated and the firmware version information to be updated meet the update conditions, including: the comparison result between the locally stored software coding information and the software coding information to be updated is consistent, and the firmware version information to be updated is greater than the locally stored firmware version information.
4. The method according to claim 1, characterized in that, Before receiving the firmware data information to be updated sent by the second controller, the method further includes: The system receives a first instruction sent by the second controller, the first instruction being used to instruct the first controller to enter an extended session mode, so that the first controller enters a state of disabling fault code setting and / or disabling communication message transmission.
5. The method according to claim 1, characterized in that, Before receiving the firmware data information to be updated sent by the second controller, the method further includes: Receive the security verification request sent by the second controller; In response to the security verification request, a first key is calculated based on a preset security verification algorithm and a random number, and the random number is sent to the second controller; The system receives a second key sent by the second controller, which is calculated by the second controller based on the preset security verification algorithm and the random number. The first key and the second key are compared. If the comparison results are consistent, the security verification of the first controller is determined to be successful, and the first controller is controlled to enter the programming session mode.
6. The method according to claim 1, characterized in that, The method for receiving firmware data information to be updated sent by the second controller includes: The firmware data information to be updated sent by the second controller is received with a second preset frame data block size.
7. The method according to claim 1, characterized in that, After writing the firmware data information to be updated into the firmware area of the first controller according to the first preset frame data block size, the method further includes: Obtain the first verification value transmitted by the second controller, wherein the first verification value is the sum of each byte of the firmware data to be updated calculated by the second controller; Obtain each byte of the firmware data to be updated written to the firmware area of the first controller, and calculate the sum of each byte of the firmware data to be updated written to the firmware area of the first controller to obtain a second verification value; Compare the first verification value with the second verification value; If the comparison results of the first verification value and the second verification value are consistent, the firmware update is determined to be successful; If the comparison results between the first verification value and the second verification value are inconsistent, the step of writing the firmware data information to be updated into the data backup area of the first controller is re-executed; If the comparison between the first verification value and the second verification value obtained by re-executing the step of writing the firmware data information to be updated into the data backup area of the first controller is inconsistent, it is determined that the firmware update is unsuccessful, an identifier of the firmware update failure is generated, the identifier is written into the designated storage unit, and a firmware update failure notification message is sent to the second controller.
8. The method according to claim 7, characterized in that, After writing the firmware data information to be updated into the firmware area of the first controller according to the first preset frame data block size, the method further includes: When the firmware update failure flag is detected after the first controller is powered on or reset, the first controller application is run. If no flag indicating unsuccessful firmware update is detected after the first controller is powered on or reset, the new firmware on the first controller is run.
9. A firmware update method, characterized in that, Applied to a second controller, the method includes: Obtain firmware data information to be updated, which includes firmware data to be updated and firmware data address to be updated; The firmware data to be updated is sent to the first controller so that the first controller writes the firmware data to be updated into the data backup area of the first controller when the application is running. The data backup area is a public backup area. After confirming that the firmware data to be updated has been completely written into the data backup area of the first controller, the firmware data to be updated is read from the data backup area. According to the first preset frame data block size, the read firmware data to be updated is written into the firmware area of the first controller according to the firmware address to be updated.
10. The method according to claim 9, characterized in that, Before sending the firmware data to be updated to the first controller, the method further includes: Receive the OTA upgrade package sent by the OTA server, and parse the OTA upgrade package to obtain the firmware data information to be updated.
11. The method according to claim 9, characterized in that, Before sending the firmware data to be updated to the first controller, the method further includes: Read the software coding information and firmware version information stored locally in the first controller; The software coding information and firmware version information stored locally are used to determine whether the software coding information to be updated and the firmware version information to be updated meet the update conditions.
12. The method according to claim 11, characterized in that, The software coding information to be updated and the firmware version information to be updated meet the update conditions, including: the comparison result between the locally stored software coding information and the software coding information to be updated is consistent, and the firmware version information to be updated is greater than the locally stored firmware version information.
13. The method according to claim 9, characterized in that, Before sending the firmware data to be updated to the first controller, the method further includes: Send a first instruction to the first controller, the first instruction being used to instruct the first controller to enter an extended session mode, so that the first controller enters a state of disabling fault code setting and / or disabling communication message transmission.
14. The method according to claim 9, characterized in that, Before sending the firmware data to be updated to the first controller, the method further includes: A security verification request is sent to the first controller, so that the first controller responds to the security verification request, calculates the first key according to the preset security verification algorithm and random number, and sends the random number to the second controller; The system receives the random number sent by the first controller and calculates the second key based on the preset security verification algorithm and the random number. The second key is sent to the first controller, so that the first controller compares the first key and the second key. If the comparison results are consistent, the first controller determines that the security verification of the first controller has passed and controls the first controller to enter the programming session mode.
15. The method according to claim 9, characterized in that, The step of sending the firmware data information to be updated to the first controller includes: The firmware data information to be updated is sent to the first controller with a second preset frame data block size.
16. The method according to claim 9, characterized in that, The firmware data to be updated includes at least the firmware data to be updated; after sending the firmware data to be updated to the first controller, the method includes: The first check value is obtained by summing the byte data of the firmware data to be updated. The first check value is then sent to the first controller so that the first controller compares the first check value with the second check value and determines whether the firmware update is successful based on the comparison result. The second check value is the sum of the byte data of the firmware data to be updated calculated by the first controller and written into the firmware area of the first controller. The system receives a notification message from the first controller indicating that the firmware update has failed. This notification message is generated and sent by the first controller when it confirms that the firmware update has failed.
17. A firmware update device, characterized in that, The firmware update device is located in the first controller, and the device includes: The acquisition unit is used to acquire firmware data information to be updated when the first controller application is running; The writing unit is used to write the firmware data information to be updated into the firmware area of the first controller according to the first preset group frame data block size. When the acquisition unit acquires the firmware data information to be updated, it is specifically used to receive the firmware data information to be updated sent by the second controller. The firmware data information to be updated is obtained by the second controller receiving the OTA upgrade package sent by the OTA server and parsing the OTA upgrade package. Before writing the firmware data information to be updated into the firmware area of the first controller according to the first preset frame data block size, the writing unit is also used to write the firmware data information to be updated into the data backup area of the first controller. The data backup area is located in the application backup area of the first controller and is a public backup area. The firmware data information to be updated includes at least the firmware data to be updated. The firmware data information to be updated also includes the firmware data address to be updated; when the writing unit writes the firmware data information to be updated into the data backup area of the first controller, it is specifically used to determine the data erase address corresponding to the firmware data address to be updated from the data backup area; delete the backup data corresponding to the data erase address in the data backup area, and after the deletion process, write the firmware data to be updated into the backup area corresponding to the data erase address in the data backup area. When the writing unit writes the firmware data to be updated into the firmware area of the first controller according to the first preset frame data block size, it is specifically used to read the firmware data to be updated from the data backup area after determining that the firmware data to be updated has been completely written into the data backup area of the first controller; and to write the read firmware data to be updated into the firmware area of the first controller according to the firmware address according to the first preset frame data block size.
18. A firmware update device, characterized in that, The firmware update device is located in the second controller, and the device includes: The acquisition unit is used to acquire firmware data information to be updated, wherein the firmware data information to be updated includes firmware data to be updated and firmware data address to be updated. The sending unit is configured to send firmware data information to be updated to the first controller, so that the first controller writes the firmware data information to be updated into the data backup area of the first controller when the application is running. The data backup area is a public backup area. After determining that the firmware data to be updated has been completely written into the data backup area of the first controller, the unit reads the firmware data to be updated from the data backup area. According to the first preset frame data block size, the read firmware data to be updated is written into the firmware area of the first controller according to the firmware address to be updated.
19. An electronic device, characterized in that, The electronic device includes a processor, a memory, a bus, and a communication interface, wherein the processor, the communication interface, and the memory are connected via the bus; The memory is used to store programs; The processor is configured to invoke a program stored in the memory via the bus to execute the method of any one of claims 1-8.
20. An electronic device, characterized in that, The electronic device includes a processor, a memory, a bus, and a communication interface, wherein the processor, the communication interface, and the memory are connected via the bus; The memory is used to store programs; The processor is configured to invoke a program stored in the memory via the bus to execute the method of any one of claims 9-16.
21. A vehicle, characterized in that, The vehicle includes a vehicle body and electronic devices. The electronic devices include a first controller and a second controller. The first controller is configured to update the firmware of the first controller of the vehicle by performing the method as described in any one of claims 1-8, and the second controller is configured to update the firmware of the first controller of the vehicle by performing the method as described in any one of claims 9-16.
Citation Information
Patent Citations
A method for MCU online upgrading
CN109240721A
Vehicle controller firmware upgrading method and system, vehicle controller and storage medium
CN114840235A