Multi-homogeneous-node parallel upgrading method applied to ocean buoy

By selecting the main node in the ocean buoy and broadcasting the upgrade subfiles using the CAN bus, combined with the transmission checksum file integrity check, the problem of the time spent in parallel upgrades of multiple homogeneous nodes in the ocean buoy and relying on a dedicated controller is solved, and an efficient and reliable upgrade process is achieved.

CN119917145AActive Publication Date: 2025-05-02SHANDONG JINGHAI INSTR EQUIP CO LTD
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
CN202510406283.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-02
Publication Date
2025-05-02
Estimated Expiration
2045-04-02

AI Technical Summary

Technical Problem

In the parallel upgrade process of multi-homogeneous nodes of marine buoys, the problem of long upgrade time, the need for a dedicated controller, large communication overhead and low file integrity check efficiency.

Method used

By selecting a node as the master node, using the broadcast characteristics of the CAN bus to broadcast and upgrade the subfile to the slave node, and using the transmission checksum file integrity checking dual verification method, the query reissue mechanism is used for reissue control, avoiding the dependence of dedicated controllers.

Benefits of technology

It greatly reduces the time-consuming upgrade of multiple homogeneous nodes, improves upgrade efficiency, reduces communication overhead, and enhances the reliability of file integrity checks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119917145A_ABST
    Figure CN119917145A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of ocean buoys, in particular to a multi-homogeneous-node parallel upgrading method applied to ocean buoys, which comprises the following steps of: randomly selecting one node in a CAN (Controller Area Network) consisting of a plurality of homogeneous nodes as a main node, and sending an upgrading file to the main node; the master node divides the upgrade file into a plurality of sub-files according to a preset length, all the sub-files are sent to other slave nodes on the CAN network in a broadcast mode according to a sequence, and correct communication is ensured through file transmission verification; file integrity check is combined with a query reissuing method to perform file check and reissuing control, so that correct and rapid transmission of the upgrade file is realized. According to the method, the broadcast characteristic of the CAN bus is fully utilized, a file reissuing method of query reissuing is provided, and the upgrading time consumption of parallel upgrading of multiple homogeneous nodes is greatly reduced; and meanwhile, the correctness of data transmission is ensured by utilizing dual verification of file transmission verification and file integrity verification, and the risk of upgrading failure is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of ocean buoys, and in particular to a method for parallel upgrading of multiple homogeneous nodes applied to ocean buoys. Background Art

[0002] When the ocean buoy monitors a large number of environmental parameters, it is limited by the number of collection interfaces, and one collector cannot complete the collection of all parameters. One solution is to use multiple collectors to collect and record a variety of different environmental parameters separately, and realize data transmission through the CAN bus. At this time, each collector is a collector node. The above multiple collector nodes use the same hardware equipment and software code. The specific work they are responsible for is determined by the model of the connected sensor. Each collector pre-determines a non-repetitive collector node number through software and hardware means. All collector nodes are integrated with CAN communication bus interfaces and are connected to the CAN network in the form of bus topology through the CAN bus without distinction of primary and secondary. Since the CAN bus has a broadcast feature, the message sent by any node in the network can be synchronously received by all other nodes on the network. When upgrading the buoy equipment code, it is necessary to upgrade the same code for the above multiple collector nodes. These multiple collector nodes with exactly the same hardware and software and networked in the above connection method are multi-homogeneous nodes.

[0003] Parallel upgrade of multiple homogeneous nodes of ocean buoys is an important measure to improve ocean monitoring technology. Ocean buoy equipment operates at sea, and due to environmental restrictions, there is no condition for long-term registration operation. The conventional method of upgrading with a dedicated downloader requires special equipment, has a low degree of automation, and requires manual operation of multiple collector nodes separately, making the upgrade process cumbersome.

[0004] In the existing method of automatic serial upgrade (upgrade of multiple devices in sequence) through the CAN network, the master node only upgrades one slave node at a time, and all slave nodes in the network need to go through a complete upgrade process, so there is a problem of time-consuming upgrade.

[0005] In terms of existing parallel upgrade technology, the invention patent with application number 202010605297.X discloses a parallel upgrade method for a parallel system. However, the above scheme requires a data verification interaction every time a data segment is sent, which will cause additional communication overhead. In addition, it uses frames as the verification and resending unit, so there is a lot of verification result transmission loss in the verification and resending process in the case of long data segments. If you want to reduce the transmission loss of the verification result, you need to use short data segments, but this will increase the number of verifications and affect the improvement of its upgrade efficiency. In addition, using frames as the verification and resending unit, it is necessary to temporarily store all data frames of each data segment in the memory (RAM), which is not friendly to small memory devices such as single-chip microcomputers in the case of long data segments. If it is not temporarily stored in RAM, the non-volatile memory (such as TF card) must be frequently operated, which will affect the life of the non-volatile memory on the one hand, and the response speed of the non-volatile memory will become the performance bottleneck of the algorithm on the other hand. At the same time, the scheme requires a dedicated controller to control the upgrade process. When the dedicated controller is damaged, the upgrade control work cannot be completed. In addition, when each module returns a check code string to the controller, there may be a situation where multiple modules compete for the CAN bus at the same time. This process has a certain probability of causing bus communication blockage or delay. It can be seen that the above solution is not the optimal solution to the problem of parallel upgrading of multiple homogeneous nodes, and it requires a special controller, so it cannot be applied to the multi-homogeneous node topology of the ocean buoy described in this article. Summary of the invention

[0006] In view of the above shortcomings of the prior art, the present invention provides a method for parallel upgrading of multiple homogeneous nodes applied to ocean buoys, which solves the technical problems raised in the above background technology.

[0007] To achieve the above objectives, the present invention is implemented through the following technical solutions: A method for parallel upgrading of multiple homogeneous nodes applied to an ocean buoy, step 1: selecting one node from multiple homogeneous nodes as a master node, and the other nodes as slave nodes, and sending an upgrade file to the master node; Step 2: The master node first clears the residual files, and then sends a pre-upgrade instruction to the slave node. After receiving the pre-upgrade instruction, the slave node first clears the residual files and generates a transmission verification queue, a transmission verification flag buffer, and a file integrity check buffer; Step 3: The master node reads the upgrade file data of fixed length in sequence, and generates a file name according to the sequence number of the upgrade file data and stores it in the storage space to generate a sub-file; Step 4: The master node broadcasts a sub-file sending start instruction including the sub-file sequence number, sub-file length and a check code of the complete upgrade file to all slave nodes; Step 5: The master node starts to send the content of the current subfile to the slave node in units of CAN data frames; Step 6: All slave nodes simultaneously receive the data frame from the master node, read the frame number and the text data, store them, and send the text data to the transmission verification queue to calculate the transmission verification code; Step 7: After the master node completes the transmission, it sends a sub-file transmission end instruction to all slave nodes, and the slave nodes end data reception, storage and sub-file transmission verification according to the sub-file transmission end instruction; Step 8: Repeat steps 3 to 7 until all sub-files are sent; Step 9: the master node queries the first slave node for the file integrity check result. After receiving the instruction, the first slave node performs a file integrity check on all received sub-files in combination with the result in the transmission check mark buffer; Step 10: After receiving the file integrity check result from the slave node, the master node reissues the sub-files that have not passed the file integrity check of the current slave node; Step 11: Repeat steps 9 to 10 until all sub-files of the slave node pass the file integrity check; Step 12: Execute steps 9 to 11 on other slave nodes in order, until the file integrity check of all sub-files of all slave nodes passes; Step 13: After a delay of a period of time, the master node sends a restart instruction to all slave nodes in a broadcast manner, and then restarts itself to complete the upgrade of the master node. After receiving the restart instruction, the slave node starts to restart and upgrade.

[0008] In a preferred embodiment, after receiving the upgrade file, the master node first reads the version number of the upgrade file. When the version number does not conflict with the version number stored in itself, the upgrade file is written to a pre-set application upgrade partition, and the number of sub-files to be transferred is calculated based on the preset size.

[0009] In a preferred embodiment, the transmission check queue is a data buffer having a length equal to the length of the CAN data frame data space; The transmission check mark buffer is an array whose length is determined by the preset maximum number of sub-files, and the Xth element in the transmission check mark buffer represents the transmission check status of the Xth sub-file, 0 indicates that the check fails, and 1 indicates that the check succeeds; The file integrity check buffer stores a string of bit streams, the Xth bit represents the file integrity check result of the Xth sub-file, 1 indicates that the check passed, and 0 indicates that the check failed. The transmission check of the sub-file is used to check the transmission of the sub-file on the CAN network.

[0010] In a preferred embodiment, the sub-file generated in step 3 includes a one-byte file header, a fixed-length data body, and a two-byte check tail. The check tail is a check code calculated by the master node for the data body of the sub-file, and is used as a priori information for subsequent slave nodes to perform file integrity checks on the file.

[0011] In a preferred embodiment, the sub-file sends a start instruction that includes the serial number of the current sub-file, the length of the sub-file, and the verification code of the complete upgrade file. The slave node generates a blank sub-file with the serial number as the file name in the storage space according to the serial number of the sub-file, which is used to store the data of the sub-file received later. The verification code of the complete upgrade file is used to verify the synthesized upgrade file when all sub-files pass the file integrity check and synthesize the complete upgrade file.

[0012] In a preferred embodiment, after receiving the sub-file sending start instruction from the master node, the slave node reads the file length of the current sub-file and determines the number of bytes occupied by the frame number part and the data body part in the subsequently received sub-file data frame based on the file length.

[0013] In a preferred embodiment, after the master node sends all data frames of a sub-file, it calculates a transmission verification code for the current sub-file and sends a sub-file sending end instruction containing the transmission verification code to all slave nodes. After receiving the instruction, the slave node extracts the transmission verification code from it and compares it with the transmission verification code calculated by itself. If the comparison is successful, the corresponding position in the transmission verification flag buffer is set to 1, otherwise it is set to 0.

[0014] In a preferred embodiment, the slave node operates in a double buffer mode for receiving and storing sub-files: First, the body data of the received data frame is written into the first buffer, and the body data of the data frame is sent to the transmission verification queue for transmission verification. If the data frame is the first data frame of the current subfile, the transmission verification code of the current frame is calculated based on the preset initial verification value, otherwise the transmission verification code of the current frame is calculated based on the transmission verification code of the previous frame data body of the current subfile; when the first buffer is full, data is written to the second buffer and the transmission verification code is calculated in the same way, and the data of the first buffer is written into the subfile generated by the step 4 in the storage space; The two buffers are used alternately to synchronize the reception of data frames with the storage of received data; This process is repeated until a sub-file sending end instruction is received from the master node. At this time, the sub-file is received and the current transmission check code is the transmission check code calculated by the slave node for the received sub-file. After receiving the sub-file sending end instruction, the slave node determines whether there is any data in the data buffer that has not been stored in the storage space because the buffer is not full. If there is data, it writes it into the storage space. At this time, the storage of the sub-file is completed.

[0015] In a preferred embodiment, after a single sub-file is transmitted, the reception status of the sub-file of each slave node is not immediately checked and resent, but a query resent mechanism is adopted. After all sub-files are sent, the reception status of all sub-files is queried from each slave node in turn and resent control is performed, specifically: The master node sends a file integrity check instruction containing a target slave node number to all slave nodes. When a slave node receives the file integrity check instruction, it determines whether the target slave node number in the instruction is the same as its own slave node number. If they are not the same, the instruction will not be executed. If they are the same, a file integrity check will be performed on all sub-files. When performing a file integrity check on one of the sub-files, the slave node first checks whether the result of the sub-file in the transmission check mark buffer is 1. If it is 1, it means that the transmission check of the sub-file has passed and the file integrity check can be performed. If the file integrity check of the sub-file has passed, the bit corresponding to the sub-file name in the file integrity check buffer is set to 1, otherwise it is still set to 0. If the result of the sub-file in the transmission check mark buffer is 0, the bit corresponding to the sub-file in the file integrity check buffer is directly set to 0. When the slave node performs a file integrity check on a sub-file, a checksum is calculated for the data body of the sub-file after removing the file header and the checksum tail. If the calculated checksum is the same as the checksum tail of the sub-file, it means that the file integrity check of the sub-file has passed; After the file integrity check of all sub-files is completed, the slave node divides the bit stream stored in the file integrity check buffer into frames and sends them to the master node; The master node parses the received file integrity test result bit stream. If a bit in the bit stream is 0, the master node reissues the sub-file corresponding to the bit according to the method of steps 3 to 7; Repeat this process until all subfiles of the current slave node pass the file integrity check; Query and resend other slave nodes in turn until all sub-files of all slave nodes pass the file integrity check The present invention has the following beneficial effects: 1. The present invention makes full use of the broadcast characteristics of the CAN bus. The master node uses the broadcast data sending method to broadcast the upgrade sub-file to the slave node. After all sub-files are sent, the query re-sending method is used to control the re-sending, which greatly reduces the upgrade time of multiple homogeneous nodes.

[0016] 2. The present invention does not require a dedicated controller to control the transmission of upgrade files. Any device node in the CAN network can be temporarily determined as a master node to complete the transmission control of the upgrade file. When a pre-selected master node has a problem, one of the other nodes can be selected as a new master node.

[0017] 3. The present invention adopts a dual verification method of transmission verification and file integrity check. The former ensures the correct transmission of the sub-file on the CAN network, and the latter ensures the correctness of the data body in the sub-file, reducing the risk of upgrade file errors caused by single verification failure. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the prior art descriptions are briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention, and for ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0019] Figure 1 A schematic diagram of a multi-homogeneous node network topology applied to ocean buoys; Figure 2 A topological diagram of a multi-homogeneous node parallel upgrade method applied to an ocean buoy after selecting a master node; Figure 3 A flowchart of steps 1 to 8 of a method for parallel upgrading of multiple homogeneous nodes applied to an ocean buoy is shown; Figure 4 A flowchart of steps 9 to 12 of a method for parallel upgrading of multiple homogeneous nodes applied to an ocean buoy is shown; DETAILED DESCRIPTION

[0020] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0021] The present invention will be further described below in conjunction with the embodiments.

[0022] Embodiment 1: The embodiment of the present invention is a method for parallel upgrading of multiple homogeneous nodes applied to an ocean buoy. Figure 3 Describe steps 1 to 8, as shown in the attached Figure 4Describe steps 9 to 12. The specific steps are as follows: Step 1: Figure 1 Select any homogeneous node in the CAN node network shown, and send the upgrade file to the node with a special command. At this time, the node is the master node, and the master node calculates the number of sub-files according to the length of the upgrade file; Step 2: The master node clears the residual files from the last upgrade in its own storage space, and sends a pre-upgrade instruction to other slave nodes. After receiving the pre-upgrade instruction, the slave node will also clear the residual files from the last upgrade, and then generate a transmission verification queue. The queue is a data buffer with a length of 8 bytes. After each frame of data of the sub-file is received, the text data will be written into the buffer, and the current transmission verification code will be calculated based on the verification result of the previous data frame of the sub-file. Therefore, the verification result of the last data frame of the sub-file is the transmission verification code of the sub-file; further generate a transmission verification mark buffer with data of all zeros, which is A numerical buffer with a preset length of 128 bytes is used to store the transmission verification results of up to 128 sub-files, where each numerical value corresponds to the transmission verification result of a sub-file. If the transmission verification of a sub-file passes, the numerical value corresponding to the sub-file is written as 1, otherwise it is written as 0; further generate a file integrity check buffer with all zero data, and the file integrity check buffer stores a bit stream with a preset length of 128 bits, which is used to store the file integrity check results of the sub-files, where each bit corresponds to the file integrity check status of a sub-file, 1 indicates that the file integrity check passes, and 0 indicates that it fails; Step 3: The master node reads the fixed-byte upgrade file data in sequence as the data body, calculates the file integrity check code for the data body, adds a file header before the data body, and adds the calculated file integrity check code to the end of the data body as the check tail, generates a file name according to the sequence number, and stores the above data set including the file header, data body, and check tail into the storage space to generate a sub-file. If the remaining upgrade file length is less than the above fixed number of bytes, the data is read according to the actual remaining length and a sub-file is generated; Step 4: The master node broadcasts a sub-file sending start instruction containing the sequence number, length information and complete upgrade file verification code of the sub-file to be sent to all slave nodes, informing the slave nodes that the sub-file transmission is about to begin. After receiving the instruction, the slave node will read the sub-file sequence number and generate a blank sub-file named with the sequence number in the TF card, and then read the sub-file length. Subsequently, the data frame is received according to the length, and then the complete upgrade file verification code is read, which is subsequently used to verify the synthesized complete upgrade file; Step 5: The master node starts to send the content of the current sub-file to the slave node in units of CAN data frames. The data space of the CAN data frame is 8 bytes, including the frame number and the data body. If the sub-file length is less than or equal to 7*S and S<=255, the frame number part is one byte and the body part is seven bytes; if the sub-file length is greater than 7*255 and less than or equal to 6*S and S<=65535, the frame number part is two bytes and the body part is six bytes; if the sub-file length is greater than 6*65535 and less than or equal to 5*S and S<=16777215, the frame number part is three bytes and the body part is five bytes, and so on. Assuming that the frame number part is two bytes and the body part is 6 bytes, the master node will continuously read data from the sub-file with a size of 6 bytes per frame and broadcast it to all slave nodes.

[0023] Step 6: Since the CAN bus has a broadcast feature, all slave nodes will simultaneously receive the data frame from the master node, and then calculate the length of the frame number part and the text part of each data frame according to the length of the sub-file received in step 4, so as to read the frame number and text data, write the data into the double data buffer and complete the storage, and at the same time send the received text data to the transmission check queue to calculate the transmission check code. When the first frame of a sub-file is received, the initial check value is 0xffff, and the initial check value of the non-first frame is the check result of the previous frame. Therefore, when the slave node receives the last frame of a sub-file and completes the calculation of the transmission check code, the current transmission check code is the final transmission check code of the sub-file calculated by the slave node; Step 7: After the master node has sent all the data frames of the current sub-file, it will calculate the transmission check code for all the data of the current sub-file, and continue to broadcast a sub-file sending end instruction containing the transmission check code to all slave nodes; after receiving the instruction, the slave node extracts the transmission check code in the instruction and compares it with the transmission check result calculated during the receiving process. If the comparison is consistent, the corresponding flag of the current sub-file in the transmission check flag buffer is set to 1, otherwise it is set to 0. At this time, the transmission of the current sub-file is completed; Step 8: Repeat steps 3 to 7 until all sub-files are sent; Step 9: The master node queries the first slave node in the CAN network for the file integrity check result. The specific operation is that the master node sends a file integrity check instruction with the specified target node number as the first slave node number to the CAN network. At this time, all slave nodes will receive the instruction, but only the slave node whose node number is the same as the target node number in the instruction, that is, the first slave node, will start the file integrity check.

[0024] First check the first sub-file. Corresponding to the sub-file serial number, the first slave node first checks whether the first value of the transmission check mark buffer is 1. If it is not 1, it means that the transmission check of the sub-file fails. At this time, the file integrity check of the sub-file will be skipped, and the first bit of the file integrity check buffer corresponding to the sub-file (serial number) will remain at the default value of 0. If the transmission check mark of the sub-file is 1, it means that the transmission check of the sub-file passes, and the file integrity check can be performed. At this time, node 1 will read the data of the first sub-file from the storage space, calculate the check code for its body data, and compare the calculated check code with the check tail of the sub-file. If the comparison is consistent, it means that the file integrity check passes, and the first bit of the file integrity check buffer corresponding to the sub-file (serial number) will be set to 1, otherwise it will remain at the default value of 0.

[0025] Perform file integrity check on other sub-files in the same way.

[0026] If the slave node detects that all sub-files stored in it have passed the file integrity check, the data bodies of all sub-files are written into a composite file in the order specified by the file numbers. This file is the final upgrade file. The final upgrade file is verified in combination with the complete upgrade file verification code received from the sub-file sending start instruction. If the verification passes, the final upgrade file is written into the pre-specified application upgrade partition.

[0027] Regardless of whether all sub-files pass the file integrity check, the file integrity check result is sent to the master node.

[0028] Step 10: The master node completes the resending of the sub-file according to the file integrity check result received from the current slave node.

[0029] In the previous sub-file sending process, the master node already knows the number of sub-files. Assuming the number of files is n, after receiving the 128-bit file integrity check result from the slave node, the master node only checks the first n bits. The master node first checks the value of the first bit. If it is 0, it resends the first sub-file according to the method from step 3 to step 7. If it is 1, no operation is performed. The subsequent n-1 bit checks and the resending of the corresponding sub-files are completed according to this method. At this time, the resending work of the current slave node is completed.

[0030] When the master node resends a sub-file, all slave nodes will try to receive the sub-file. If a slave node detects that the sub-file stored in itself has passed the transmission verification, it will ignore the sub-file. Otherwise, it will receive the sub-file again.

[0031] Step 11: Repeat steps 9 and 10 until all sub-files of the current slave node pass the file integrity check.

[0032] Step 12: The master node executes steps 9 to 11 on other slave nodes in sequence until the file integrity check of all sub-files of all slave nodes passes.

[0033] Step 13: After 10 seconds, the master node broadcasts a restart command to all slave nodes and restarts itself to complete the upgrade of the master node. After receiving the restart command, the slave node starts to restart and upgrade.

[0034] In a preferred embodiment, the operation of receiving and storing sub-files from the node in double buffer mode is as follows: First, the text data of the received sub-file data frame is written into the first buffer, and when the first buffer is full, data is written into the second buffer, and at the same time, the data of the first buffer is written into the sub-file generated by step 4 in the storage space; The two buffers are used in turn to synchronize the reception of data frames with the storage of received data, thus avoiding the impact of time-consuming data storage on data transmission speed; This process is repeated until a sub-file sending end instruction is received from the master node, at which point the sub-file reception is complete.

[0035] After receiving the sub-file sending end instruction, the slave node will determine whether there is any data in the above data buffer that has not been stored in the storage space because the buffer is not full. If there is data, it will be written into the storage space. At this time, the sub-file storage is completed.

[0036] In this embodiment, the broadcast characteristics of the CAN bus are fully utilized through the execution of the method in the above embodiment. The master node broadcasts the upgrade sub-file to the slave node using the broadcast data sending method. After all sub-files are sent, the query re-sending method is used to control the re-sending, which greatly reduces the upgrade time of multiple homogeneous nodes.

[0037] Based on the implementation of the above embodiments in specific application scenarios: 1. The operator prepares the upgrade file to be updated, selects a node on the CAN bus network, here selects node 2, and transmits the upgrade file to the node in a wired manner. At this time, the node is the master node and the other nodes are slave nodes. At this time, the node topology is shown in Figure 2 The master node calculates the number of sub-files based on the length of the upgrade file. In this example, the upgrade file size is 400KB, and the default length of a single sub-file body is 5120 bytes, so the number of sub-files is exactly 80.

[0038] 2. The master node searches for its own TF card files, deletes the remaining files from the last upgrade, and then broadcasts the pre-upgrade command to all slave nodes. After receiving the pre-upgrade command, the slave node will also delete the remaining files from the last upgrade in its own TF card, and then generate a transmission verification queue, a transmission verification flag buffer, and a file integrity check buffer, and clear the three buffers.

[0039] 3. The master node reads 5120 bytes from the upgrade file and writes them into the first sub-file in sequence. When writing, a one-byte file header is first written to the sub-file, and then the 5120-byte data body read this time is written. Finally, a two-byte checksum is calculated for the 5120-byte data, and the checksum is written to the end of the sub-file as a checksum tail, which is used as a priori information for file integrity check. Therefore, in this example, the length of a single sub-file is 5123 bytes.

[0040] 4. The master node sends a sub-file sending start instruction to all slave nodes. The slave node reads the sequence number of the current sub-file from the instruction, and generates a blank sub-file with the sequence number as the file name in the TF card according to the sequence number. Then, the length of the sub-file is read from the instruction. The file reception will be completed according to the length. Finally, the complete upgrade file verification information is read from the instruction for the subsequent verification of the synthesized complete upgrade file.

[0041] 5. The master node starts to send the content of the current subfile to the slave node in units of CAN data frames. In this example, the length of a subfile is 5123 bytes. Since 5123<=7*255 is not true and 5123<=6*65535 is true, the body of the data frame is 6 bytes. The master node continuously reads data from the current subfile based on 6 bytes and adds the frame number to generate a CAN data frame, and then sends the data frame to the CAN network. Repeat this process until the current subfile is completely sent.

[0042] 6. All slave nodes simultaneously receive data frames from the master node, and calculate the length of the frame number part and the text part of each data frame according to the length of the sub-file received in step 4, so as to read the frame number and text data, where the frame number part is 2 bytes and the text part is 6 bytes. After receiving a frame of data, the slave node extracts 6 bytes of text data and writes the data into the first data buffer, and at the same time sends the text data to the transmission verification queue to calculate the transmission verification code. If the current data frame is the first frame of the current sub-file, the initial value of the calculated transmission verification code is 0xffff, otherwise it is the transmission verification result of the previous frame. Therefore, the verification code obtained after the slave node receives the last frame of the current sub-file and completes the transmission verification calculation is the transmission verification code calculated by the slave node for the sub-file as a whole. Repeat the process of receiving data frames, writing buffers and verifying. When the first buffer is full, start writing data to the second buffer, and write the data of the first buffer into the sub-file generated by step 4 in the TF card. In this example, the size of the two buffers is 512 bytes, and the two buffers are used in turn to ensure that the reception of data frames and the storage of received data are synchronized.

[0043] 7. After the master node has sent all the data frames of the current sub-file, it will calculate the transmission check code for all the data of the current sub-file, and continue to broadcast a sub-file sending end instruction containing the transmission check code to all slave nodes; after receiving the instruction, the slave node first determines whether there is any data in the first and second data buffers that has not been stored in the TF card due to the incomplete buffer. If there is data, it will be written to the TF card. At this time, the sub-file storage is completed, and then the transmission check code in the instruction is extracted and compared with the transmission check result calculated during the receiving process. If the comparison is consistent, the corresponding flag of the current sub-file in the transmission check mark buffer is set to 1, otherwise it is set to 0. At this time, the current sub-file transmission is completed. 8. Repeat steps 3 to 7 until all sub-files have been sent.

[0044] 9. After all sub-files have been sent, the master node queries the file integrity result from the first slave node in the CAN network. In this example, there are three slave nodes, namely, node 1, node 3, and node 4. Therefore, the first slave node is node 1. The query operation is that the master node sends a file integrity check instruction with the designated target slave node number as 1 to all slave nodes. At this time, all three slave nodes will receive the instruction. Slave nodes 3 and 4 do not execute the instruction because their node numbers are inconsistent with the slave node number specified in the instruction. Node 1 starts to perform file integrity checks on the sub-files it receives because its node number is consistent with the slave node number specified in the instruction. First check the first sub-file. Corresponding to the sub-file sequence number, the slave node first checks the first data in the transmission check mark buffer. If the data is 0, it indicates that the sub-file is not received correctly and there is no need to perform a file integrity check. The first bit of the file integrity check buffer corresponding to the sub-file sequence number is directly set to 0, indicating that the file integrity check of the sub-file has not passed. If the transmission check mark of the sub-file is 1, it means that the transmission check of the sub-file has passed, and the file integrity check can be performed. When checking, the data of the sub-file is first read from the storage space, and the data body after removing the file header and the check tail from the sub-file data is checked. If the check result is the same as the check tail, it means that the file integrity check of the sub-file has passed, and the first bit of the file integrity check buffer is set to 1, otherwise it is still set to 0. Use the above method to perform file integrity checks on all other sub-files. If all sub-files pass the file integrity check, the data body of all sub-files is written into a composite file in the order specified by the sub-file sequence number and the composite file is checked. After the check passes, the composite file is written into the preset program upgrade partition. At this time, the composite file is the final upgrade file. Regardless of whether all sub-files pass the file integrity check, the slave node will send the bit stream stored in the file integrity check buffer to the master node after framing. In this example, the data stored in the file integrity check buffer is a bit stream consisting of 16 bytes and a total of 128 bits. When sending, it takes about 22 data frames to complete the result transmission.

[0045] 10. The master node completes the resending of the sub-file based on the file integrity check result received from the current slave node.

[0046] In the previous sub-file sending process, the master node already knows the number of sub-files. In this example, the number of sub-files is 80. Therefore, after receiving the 128-bit file integrity check result from the slave node, the master node only checks the first 80 bits. The master node first checks the value of the first bit. If it is 0, it resends the first sub-file according to the method from step 3 to step 7. If it is 1, no operation is performed. The subsequent 79-bit check and the resend of the corresponding sub-file are completed according to this method. At this time, the resend work of the current slave node is completed.

[0047] When the master node resends a sub-file, all slave nodes will try to receive the sub-file. If a slave node detects that the sub-file stored in itself has passed the transmission verification, it will ignore the sub-file. Otherwise, it will receive the sub-file again.

[0048] 11. Repeat steps 9 to 10 until the file integrity check of all subfiles of the first slave node passes.

[0049] 12. Execute steps 9 to 11 on the remaining slave nodes 3 and 4 in order, until the file integrity check of all subfiles of all slave nodes passes.

[0050] 13. After 10 seconds, the master node broadcasts a restart command to all slave nodes and automatically restarts to complete the upgrade of the master node. After receiving the restart command, the slave node starts to restart and upgrade.

[0051] In summary, the method in the above embodiment makes full use of the broadcast characteristics of the CAN bus. The master node broadcasts the upgrade sub-file to the slave node using the broadcast data sending method, and uses the query retransmission method to control the retransmission after all the sub-files are sent, which greatly reduces the upgrade time of multiple homogeneous nodes. In addition, the method does not require a dedicated controller to control the transmission of the upgrade file. Any device node in the CAN network can be temporarily determined as the master node to complete the transmission control of the upgrade file. When a pre-selected master node has a problem, one of the other nodes can be selected as a new master node. At the same time, the method adopts a dual verification method of transmission verification and file integrity check. The former ensures the correct transmission of the sub-file on the CAN network, and the latter ensures the correctness of the data body in the sub-file, reducing the risk of upgrade file synthesis errors caused by single verification failure and other reasons.

[0052] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features may be replaced by equivalents. Such modifications or replacements will not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for parallel upgrading of multiple homogeneous nodes applied to ocean buoys, characterized in that: The following steps are involved: Step 1: Select one node from multiple homogeneous nodes as the master node, and the other nodes as slave nodes, and send the upgrade file to the master node; Step 2: The master node first clears the residual files, and then sends a pre-upgrade instruction to the slave node. After receiving the pre-upgrade instruction, the slave node first clears the residual files and generates a transmission verification queue, a transmission verification flag buffer, and a file integrity check buffer; Step 3: The master node reads the upgrade file data of fixed length in sequence, and generates a file name according to the sequence number of the upgrade file data and stores it in the storage space to generate a sub-file; Step 4: The master node broadcasts a sub-file sending start instruction including the sub-file sequence number, sub-file length and a check code of the complete upgrade file to all slave nodes; Step 5: The master node starts to send the content of the current subfile to the slave node in units of CAN data frames; Step 6: All slave nodes simultaneously receive the data frame from the master node, read the frame number and the text data, store them, and send the text data to the transmission verification queue to calculate the transmission verification code; Step 7: After the master node completes the transmission, it sends an end instruction to all slave nodes, and the slave nodes end data reception, storage and sub-file transmission verification according to the end instruction; Step 8: Repeat steps 3 to 7 until all sub-files are sent; Step 9: the master node queries the first slave node for the file integrity check result. After receiving the instruction, the first slave node performs a file integrity check on all received sub-files in combination with the result in the transmission check mark buffer; Step 10: After receiving the file integrity check result from the slave node, the master node reissues the sub-files that have not passed the file integrity check of the current slave node; Step 11: Repeat steps 9 to 10 until all sub-files of the slave node pass the file integrity check; Step 12: Execute steps 9 to 11 on other slave nodes in order, until the file integrity check of all sub-files of all slave nodes passes; Step 13: After a delay of a period of time, the master node sends a restart instruction to all slave nodes in a broadcast manner, and restarts to complete the upgrade of the master node. After receiving the restart instruction, the slave node starts to restart and upgrade.

2. The method for parallel upgrading of multiple homogeneous nodes applied to ocean buoys according to claim 1 is characterized in that: After receiving the upgrade file, the master node first reads the version number of the upgrade file. When the version number does not conflict with the version number stored in itself, the upgrade file is written to the pre-set application upgrade partition, and the number of sub-files to be transferred is calculated based on the preset size.

3. The method for parallel upgrading of multiple homogeneous nodes applied to ocean buoys according to claim 1 is characterized in that: The transmission check queue is a data buffer with a length equal to the length of the CAN data frame data space; The transmission check mark buffer is an array whose length is determined by the preset maximum number of sub-files, and the Xth element in the transmission check mark buffer represents the transmission check status of the Xth sub-file, 0 indicates that the check fails, and 1 indicates that the check succeeds; The file integrity check buffer stores a string of bit streams, the Xth bit represents the file integrity check result of the Xth sub-file, 1 indicates that the check passed, and 0 indicates that the check failed. The transmission check of the sub-file is used to check the transmission of the sub-file on the CAN network.

4. The method for parallel upgrading of multiple homogeneous nodes applied to ocean buoys according to claim 1, characterized in that: The sub-file generated in step 3 includes a one-byte file header, a fixed-length data body, and a two-byte check tail. The check tail is a check code calculated by the master node for the data body of the sub-file, and is used as a priori information for subsequent slave nodes to perform file integrity checks on the file.

5. The method for parallel upgrading of multiple homogeneous nodes applied to ocean buoys according to claim 1, characterized in that: The sub-file sending start instruction includes the sequence number of the current sub-file, the length of the sub-file, and the verification code of the complete upgrade file. The slave node generates a blank sub-file with the sequence number as the file name in the storage space according to the sequence number of the sub-file, which is used to store the data of the sub-file received later. The verification code of the complete upgrade file is used to verify the synthesized upgrade file when all sub-files pass the file integrity check and synthesize the complete upgrade file.

6. The method for parallel upgrading of multiple homogeneous nodes applied to ocean buoys according to claim 1, characterized in that: After receiving the subfile sending start instruction from the master node, the slave node reads the file length of the current subfile and determines the number of bytes occupied by the frame number part and the data body part in the subsequently received subfile data frame according to the file length.

7. The method for parallel upgrading of multiple homogeneous nodes applied to ocean buoys according to claim 1, characterized in that: After the master node has sent all the data frames of a sub-file, it calculates the transmission check code for the current sub-file and sends a sub-file sending end instruction containing the transmission check code to all slave nodes. After receiving the instruction, the slave node extracts the transmission check code from it and compares it with the transmission check code calculated by itself. If the comparison is successful, the corresponding position in the transmission check mark buffer is set to 1, otherwise it is set to 0.

8. The method for parallel upgrading of multiple homogeneous nodes applied to ocean buoys according to claim 3 is characterized in that: The slave node uses double buffer mode for receiving and storing sub-files: First, the body data of the received data frame is written into the first buffer, and the body data of the data frame is sent to the transmission verification queue for transmission verification. If the data frame is the first data frame of the current subfile, the transmission verification code of the current frame is calculated based on the preset initial verification value, otherwise the transmission verification code of the current frame is calculated based on the transmission verification code of the previous frame data body of the current subfile; when the first buffer is full, data is written to the second buffer and the transmission verification code is calculated in the same way, and the data of the first buffer is written into the subfile generated by the step 4 in the storage space; The two buffers are used alternately to synchronize the reception of data frames with the storage of received data; This process is repeated until a sub-file sending end instruction is received from the master node. At this time, the sub-file is received and the current transmission check code is the transmission check code calculated by the slave node for the received sub-file. After receiving the sub-file sending end instruction, the slave node determines whether there is any data in the data buffer that has not been stored in the storage space because the buffer is not full. If there is data, it writes it into the storage space. At this time, the storage of the sub-file is completed.

9. The method for parallel upgrading of multiple homogeneous nodes applied to ocean buoys according to claim 1, characterized in that: After a single sub-file is transmitted, the reception status of each slave node for the sub-file is not immediately checked and resent. Instead, a query resend mechanism is adopted. After all sub-files are sent, the reception status of all sub-files is queried from each slave node in turn and resend is controlled. Specifically, The master node sends a file integrity check instruction containing a target slave node number to all slave nodes. When a slave node receives the file integrity check instruction, it determines whether the target slave node number in the instruction is the same as its own slave node number. If they are not the same, the instruction will not be executed. If they are the same, a file integrity check will be performed on all sub-files. When performing a file integrity check on one of the sub-files, the slave node first checks whether the result of the sub-file in the transmission check mark buffer is 1. If it is 1, it means that the transmission check of the sub-file has passed and the file integrity check can be performed. If the file integrity check of the sub-file has passed, the bit corresponding to the sub-file name in the file integrity check buffer is set to 1, otherwise it is still set to 0. If the result of the sub-file in the transmission check mark buffer is 0, the bit corresponding to the sub-file in the file integrity check buffer is directly set to 0. When the slave node performs a file integrity check on a sub-file, a checksum is calculated for the data body of the sub-file after removing the file header and the checksum tail. If the calculated checksum is the same as the checksum tail of the sub-file, it means that the file integrity check of the sub-file has passed; After the file integrity check of all sub-files is completed, the slave node divides the bit stream stored in the file integrity check buffer into frames and sends them to the master node; The master node parses the received file integrity test result bit stream. If a bit in the bit stream is 0, the master node reissues the sub-file corresponding to the bit according to the method of steps 3 to 7; Repeat this process until all subfiles of the current slave node pass the file integrity check; The other slave nodes are queried and resent in turn until all sub-files of all slave nodes pass the file integrity check.

Citation Information

Patent Citations

  • Synchronous upgrading method of parallel operation system

    CN111857770A

  • Method and apparatus for a distributed file storage and indexing service

    CN101395602A

  • Wireless and underwater sound communication buoy

    CN102571902A

  • Remote upgrading method and device for IPMC program of ATCA structure

    CN104615455A

  • Batch automatic upgrade method for weblogic cluster patch

    CN107634860A