A Method for Parallel Upgrading of Multiple Homogeneous Nodes Applied to Ocean Buoys
By selecting the main node in the ocean buoy and using the CAN bus broadcast characteristics for parallel upgrades, combined with transmission checksum file integrity checks, the problem of the time-consuming and high error risk of upgrading multiple homogeneous nodes of the ocean buoy is solved, and an efficient and accurate upgrade process is achieved.
Patent Information
- Application Number
- CN202510406283.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-02
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2045-04-02
AI Technical Summary
In the parallel upgrade process of multi-homogeneous nodes of marine buoys, the problem of long upgrade time, the need for a dedicated controller, large communication overhead and high risk of upgrade file errors.
By selecting a node as the master node, using the broadcast characteristics of the CAN bus to send upgrade subfiles to the slave node broadcast, and using the dual verification method of transmission checksum file integrity checking, combined with the query reissue mechanism, the parallel upgrade of multiple homogeneous nodes is achieved.
It greatly reduces the time-consuming upgrade of multiple homogeneous nodes, avoids dependence on dedicated controllers, improves transmission accuracy and file integrity, and reduces the risk of upgrade file errors.
Smart Images

Figure CN119917145B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of ocean buoys, and particularly relates to a method for parallel upgrading of multiple homogeneous nodes applied to ocean buoys. Background Art
[0002] When an ocean buoy monitors a relatively large number of environmental parameters, due to the limitation of the number of acquisition interfaces, it is impossible to complete the acquisition of all parameters with a single collector. One solution is to use multiple collectors to separately collect and record multiple different environmental parameters, and realize the mutual transmission of data through the CAN bus. At this time, each collector is a collector node. The above-mentioned multiple collector nodes adopt the same hardware devices and software codes, and the specific work they are responsible for is determined by the type of the connected sensors. Each collector pre-determines a non-repeating collector node number through software and hardware means. All collector nodes are integrated with CAN communication bus interfaces and are connected to the CAN network in the form of a bus topology without distinction of primary and secondary through the CAN bus. Since the CAN bus has a broadcast characteristic, any message sent by a node in the network can be synchronously received by all other nodes in the network. When upgrading the buoy device code, the same code needs to be upgraded for the above-mentioned multiple collector nodes. These multiple collector nodes with exactly the same hardware and software and networked in the above connection method are multiple homogeneous nodes.
[0003] Parallel upgrading of multiple homogeneous nodes of ocean buoys is an important measure for improving ocean monitoring technology. Ocean buoy devices operate at sea, and there are no conditions for long-term boarding operations due to environmental restrictions. The conventional method of using a dedicated downloader for upgrading requires dedicated equipment and has low automation. Manual operations need to be performed on multiple collector nodes respectively, and the upgrading process is cumbersome.
[0004] In the existing method of automatic serial upgrading (upgrading multiple devices sequentially) through the CAN network, the master node upgrades only one slave node at a time, and all slave nodes in the network need to go through a complete upgrading process. Therefore, there is a problem of long upgrading time.
[0005] In terms of existing parallel upgrade technology, the invention patent with application number 202010605297.X discloses a parallel upgrade method for a parallel system. However, the above scheme requires a data verification interaction every time a data segment is sent, which will cause additional communication overhead. In addition, it uses frames as the verification and resending unit, so there is a lot of verification result transmission loss in the verification and resending process in the case of long data segments. If you want to reduce the transmission loss of the verification result, you need to use short data segments, but this will increase the number of verifications and affect the improvement of its upgrade efficiency. In addition, using frames as the verification and resending unit, it is necessary to temporarily store all data frames of each data segment in the memory (RAM), which is not friendly to small memory devices such as single-chip microcomputers in the case of long data segments. If it is not temporarily stored in RAM, the non-volatile memory (such as TF card) must be frequently operated, which will affect the life of the non-volatile memory on the one hand, and the response speed of the non-volatile memory will become the performance bottleneck of the algorithm on the other hand. At the same time, the scheme requires a dedicated controller to control the upgrade process. When the dedicated controller is damaged, the upgrade control work cannot be completed. In addition, when each module returns a check code string to the controller, there may be a situation where multiple modules compete for the CAN bus at the same time. This process has a certain probability of causing bus communication blockage or delay. It can be seen that the above solution is not the optimal solution to the problem of parallel upgrading of multiple homogeneous nodes, and it requires a special controller, so it cannot be applied to the multi-homogeneous node topology of the ocean buoy described in this article. Summary of the invention
[0006] In view of the above shortcomings of the prior art, the present invention provides a method for parallel upgrading of multiple homogeneous nodes applied to ocean buoys, which solves the technical problems raised in the above background technology.
[0007] To achieve the above objectives, the present invention is implemented through the following technical solutions:
[0008] A method for parallel upgrading of multiple homogeneous nodes applied to an ocean buoy, step 1: selecting one node from multiple homogeneous nodes as a master node, and the other nodes as slave nodes, and sending an upgrade file to the master node;
[0009] Step 2: The master node first clears the residual files, and then sends a pre-upgrade instruction to the slave node. After receiving the pre-upgrade instruction, the slave node first clears the residual files and generates a transmission verification queue, a transmission verification flag buffer, and a file integrity check buffer;
[0010] Step 3: The master node reads the upgrade file data of fixed length in sequence, and generates a file name according to the sequence number of the upgrade file data and stores it in the storage space to generate a sub-file;
[0011] Step 4: The master node broadcasts and sends a sub-file sending start instruction to all slave nodes, which includes the sub-file serial number, the sub-file length, and the checksum of the complete upgrade file;
[0012] Step 5: The master node starts to send the content of the current sub-file to the slave nodes in units of CAN data frames;
[0013] Step 6: All slave nodes simultaneously receive the data frames from the master node, read the frame number and the text data, store them, and at the same time send the text data to the transmission check queue to calculate the transmission checksum;
[0014] Step 7: After the master node finishes sending, it sends a sub-file sending end instruction to all slave nodes. The slave nodes end data reception, storage, and transmission check of the sub-file according to the sub-file sending end instruction;
[0015] Step 8: Repeat Steps 3 to 7 until all sub-files are sent;
[0016] Step 9: The master node queries the file integrity check result from the first slave node. After receiving the instruction, the first slave node performs a file integrity check on all received sub-files in combination with the result in the transmission check flag buffer;
[0017] Step 10: After the master node receives the file integrity check result from the slave node, it reissues the sub-files that fail the file integrity check for the current slave node;
[0018] Step 11: Repeat Steps 9 to 10 until all sub-files of the slave node pass the file integrity check;
[0019] Step 12: Sequentially execute Steps 9 to 11 for other slave nodes in turn until the file integrity checks of all sub-files of all slave nodes pass;
[0020] Step 13: After a period of delay, the master node sends a restart instruction to all slave nodes in a broadcast manner, and then restarts itself to complete the upgrade of the master node. After receiving the restart instruction, the slave nodes start to restart and upgrade.
[0021] In a preferred embodiment, after receiving the upgrade file, the master node first reads the version number of the upgrade file. When the version number does not conflict with the version number stored in itself, it writes the upgrade file into the pre-set application program upgrade partition, and at the same time calculates the number of sub-files to be transmitted based on a preset size.
[0022] In a preferred embodiment, the transmission check queue is a data buffer with a length equal to the data space length of the CAN data frame;
[0023] The transmission verification flag buffer is an array with a length specified by the preset maximum number of sub-files. The X-th element in the transmission verification flag buffer represents the transmission verification status of the X-th sub-file. A value of 0 indicates verification failure, and a value of 1 indicates verification success;
[0024] The file integrity check buffer stores a string of bit streams. The X-th bit represents the file integrity check result of the X-th sub-file. A value of 1 indicates passing the check, and a value of 0 indicates failing the check. The transmission verification of sub-files is used to perform verification checks on the transmission of sub-files over the CAN network.
[0025] In a preferred embodiment, the sub-file generated in step 3 includes a one-byte file header, a data body with a fixed length, and a two-byte verification tail. The verification tail is the verification code calculated by the master node for the data body of the sub-file and is used as prior information for subsequent slave nodes to perform file integrity checks on this file.
[0026] In a preferred embodiment, the sub-file sending start instruction includes the sequence number of the current sub-file, the length of the sub-file, and the verification code of the complete upgrade file at the same time. The slave node generates a blank sub-file with the sequence number as the file name in the storage space according to the sequence number of the sub-file, which is used to store the data of this sub-file received later. The verification code of the complete upgrade file is used to verify the synthesized upgrade file when all sub-files pass the file integrity check and are synthesized into a complete upgrade file.
[0027] In a preferred embodiment, after receiving the sub-file sending start instruction from the master node, the slave node reads the file length of the current sub-file from it, and determines the number of bytes occupied by the frame number part and the data body part respectively in the subsequent sub-file data frames received according to this file length.
[0028] In a preferred embodiment, after the master node sends all the data frames of a sub-file, it calculates the transmission verification code for the current sub-file, and sends a sub-file sending end instruction containing the transmission verification code to all slave nodes. After receiving this instruction, the slave node extracts the transmission verification code from it and compares it with the transmission verification code calculated by itself. If the comparison passes, the corresponding position in the transmission verification flag buffer is set to 1, otherwise it is set to 0.
[0029] In a preferred embodiment, the slave node adopts a dual-buffer mode operation for receiving and storing sub-files:
[0030] First, write the body data of the received data frame into the first buffer, and send the body data of the data frame to the transmission verification queue for transmission verification. If the data frame is the first data frame of the current sub-file, calculate the transmission verification code of the current frame based on the preset initial verification value; otherwise, calculate the transmission verification code of the current frame based on the transmission verification code of the body data of the previous frame of the current sub-file. When the first buffer is full, start writing data to the second buffer and calculate the transmission verification code in the same way. At the same time, write the data in the first buffer into the sub-file generated by the step 4 in the storage space.
[0031] The two buffers are used alternately to synchronize the reception of data frames and the storage of the received data.
[0032] Repeat this process until the sub-file sending end instruction from the master node is received. At this time, the sub-file reception is completed, and the current transmission verification code is the transmission verification code calculated by the slave node for the received sub-file.
[0033] After receiving the sub-file sending end instruction, the slave node determines whether there is still data in the data buffer that has not been stored in the storage space because the buffer is not full. If so, write it into the storage space. At this time, the sub-file storage is completed.
[0034] In the preferred embodiment, after a single sub-file is transmitted, the reception status of the sub-file by each slave node is not immediately checked and retransmission controlled. Instead, a query and retransmission mechanism is adopted. After all sub-files are transmitted, the master node queries the reception status of all sub-files from each slave node in turn and performs retransmission control. Specifically:
[0035] The master node sends a file integrity check instruction containing the target slave node number to all slave nodes. When a slave node receives the file integrity check instruction, it determines whether the target slave node number in the instruction is the same as its own slave node number. If not, it will not execute. If the same, it performs a file integrity check on all sub-files. When performing a file integrity check on one of the sub-files, the slave node first checks whether the result of the sub-file in the transmission verification flag buffer is 1. If it is 1, it means that the transmission verification of the sub-file passes and the file integrity check can be performed. If the file integrity check of the sub-file passes, set the bit corresponding to the sub-file name in the file integrity check buffer to 1; otherwise, still set it to 0. If the result of the sub-file in the transmission verification flag buffer is 0, directly set the bit corresponding to the sub-file in the file integrity check buffer to 0.
[0036] When a slave node performs a file integrity check on a certain sub - file, it calculates the check value for the data body obtained by removing the file header and the check tail from the sub - file. If the calculated check value is the same as the check tail of the sub - file, it indicates that the file integrity check of the sub - file passes;
[0037] After the file integrity checks of all sub - files are completed, the slave node frames the bit stream stored in the file integrity check buffer and sends it to the master node;
[0038] The master node parses the received bit stream of the file integrity detection result. If a certain bit in the bit stream is 0, it re - issues the sub - file corresponding to this bit according to the method from step 3 to step 7;
[0039] Repeat this process until all sub - files of the current slave node pass the file integrity check;
[0040] Query and re - issue other slave nodes in turn until all sub - files of all slave nodes pass the file integrity check.
[0041] The present invention has the following beneficial effects:
[0042] 1. The present invention makes full use of the broadcast characteristic of the CAN bus. The master node uses the broadcast data sending method to broadcast and send the upgraded sub - files to the slave nodes, and uses the query and re - issue method for re - issue control after all sub - files are sent, greatly reducing the upgrade time for multiple homogeneous nodes.
[0043] 2. The present invention does not require a dedicated controller to control the transmission of the upgrade file. Any device node in the CAN network can be temporarily determined as the master node to complete the transmission control of the upgrade file. When a pre - selected master node has a problem, a new master node can be selected from other nodes.
[0044] 3. The present invention adopts a double - check method of transmission checksum and file integrity check. The former ensures the correct transmission of the sub - file on the CAN network, and the latter ensures the correctness of the data body in the sub - file, reducing the risk of upgrade file errors caused by the failure of a single check. Description of the Drawings
[0045] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0046] Figure 1It is a schematic diagram of a multi-homogeneous node network topology applied to an ocean buoy;
[0047] Figure 2 It is a schematic diagram of the topology after selecting the master node in a multi-homogeneous node parallel upgrade method applied to an ocean buoy;
[0048] Figure 3 It is a schematic diagram of the process from step 1 to step 8 in a multi-homogeneous node parallel upgrade method applied to an ocean buoy;
[0049] Figure 4 It is a schematic diagram of the process from step 9 to step 12 in a multi-homogeneous node parallel upgrade method applied to an ocean buoy; Detailed implementation mode
[0050] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0051] The present invention will be further described below with reference to the embodiments.
[0052] Embodiment 1:
[0053] A multi-homogeneous node parallel upgrade method applied to an ocean buoy in this embodiment, which describes steps 1 to 8 by attachment Figure 3 and describes steps 9 to 12 by attachment Figure 4 The specific steps are as follows:
[0054] Step 1: Select an arbitrary homogeneous node in the Figure 1 shown CAN node network, and send the upgrade file to this node with a special command. At this time, this node is the master node, and the master node calculates the number of sub-files according to the length of the upgrade file;
[0055] Step 2: The master node clears the residual files from the last upgrade in its storage space. Meanwhile, it sends a pre-upgrade instruction to other slave nodes. After receiving the pre-upgrade instruction, the slave nodes also clear the residual files from the last upgrade, and then generate a transmission verification queue. This queue is a data buffer with a length of 8 bytes. After each frame of data of the sub-file is received, the text data is written into this buffer, and the current transmission verification code is calculated based on the verification result of the previous data frame of this sub-file. Therefore, the verification result of the last data frame of the sub-file is the transmission verification code of this sub-file. Further, a transmission verification flag buffer with all-zero data is generated. This buffer is a numerical buffer with a preset length of 128 bytes, which stores the transmission verification results of up to 128 sub-files. Each value in it corresponds to the transmission verification result of a sub-file. If the transmission verification of a certain sub-file passes, the value corresponding to this sub-file is written as 1, otherwise it is written as 0. Further, a file integrity check buffer with all-zero data is generated. The file integrity check buffer stores a bit stream with a preset length of 128 bits, which is used to store the file integrity check results of sub-files. Each bit in it corresponds to the file integrity check status of a sub-file. 1 indicates that the file integrity check passes, and 0 indicates that it fails.
[0056] Step 3: The master node sequentially reads a fixed number of bytes of upgrade file data as the data text, calculates the file integrity check verification code for the data text, adds a file header before the data text, and adds the calculated file integrity check verification code to the end of the data text as the verification tail. A file name is generated according to the serial number, and the data set including the file header, data text, and verification tail is stored in the storage space to generate a sub-file. If the remaining length of the upgrade file is less than the above fixed number of bytes, the data is read according to the actual remaining length and a sub-file is generated.
[0057] Step 4: The master node broadcasts and sends a sub-file sending start instruction to all slave nodes, which includes the serial number, length information of the sub-file to be sent, and the complete upgrade file verification code, to inform the slave nodes that the sub-file transmission is about to start. After receiving this instruction, the slave nodes will read the sub-file serial number and generate a blank sub-file named with this serial number in the TF card, then read the sub-file length, and subsequently complete the reception of data frames according to this length. Then it will read the complete upgrade file verification code, which will be used to verify the synthesized complete upgrade file later.
[0058] Step 5: The master node starts to send the content of the current sub-file to the slave nodes in units of CAN data frames. The data space of a CAN data frame is 8 bytes, including a frame number and a data body. If the length of the sub-file is less than or equal to 7*S and S <= 255, the frame number part is 1 byte and the body part is 7 bytes; if the length of the sub-file is greater than 7*255 and less than or equal to 6*S and S <= 65535, the frame number part is 2 bytes and the body part is 6 bytes; if the length of the sub-file is greater than 6*65535 and less than or equal to 5*S and S <= 16777215, the frame number part is 3 bytes and the body part is 5 bytes, and so on. Assuming the frame number part is 2 bytes and the body part is 6 bytes, the master node will continuously read data from the sub-file in 6-byte chunks per frame and broadcast it to all slave nodes.
[0059] Step 6: Since the CAN bus has a broadcast feature, all slave nodes will receive the data frames from the master node simultaneously. Then, they calculate the lengths of the frame number part and the body part of each data frame based on the sub-file length received in Step 4, so as to read the frame number and body data, write the data into the dual data buffer and complete the storage. At the same time, the received body data is sent to the transmission verification queue to calculate the transmission verification code. When receiving the first frame of a certain sub-file, the verification initial value is 0xffff. For non-first frames, the verification initial value is the verification result of the previous frame. Therefore, when the slave node receives the last frame of a certain sub-file and completes the calculation of the transmission verification code, the current transmission verification code is the final transmission verification code of the sub-file calculated by the slave node;
[0060] Step 7: After the master node has sent all the data frames of the current sub-file, it calculates the transmission verification code for all the data of the current sub-file and continues to broadcast a sub-file sending end instruction containing the transmission verification code to all slave nodes. After receiving the instruction, the slave nodes extract the transmission verification code in the instruction and compare it with the transmission verification result calculated during the reception. If the comparison is consistent, the flag corresponding to the current sub-file in the transmission verification flag buffer is set to 1, otherwise it is set to 0. At this time, the current sub-file transmission is completed;
[0061] Step 8: Repeat Steps 3 to 7 until all sub-files have been sent;
[0062] Step 9: The master node queries the file integrity check result from the first slave node in the CAN network. Specifically, the master node sends a file integrity check instruction in the CAN network specifying the target node number as the first slave node number. At this time, all slave nodes will receive the instruction, but only the slave node whose own node number is the same as the target node number in the instruction, that is, the first slave node, will start the file integrity check.
[0063] First, check the first sub-file. Correspondingly, the first slave node first checks whether the first value in the transmission verification flag buffer is 1. If it is not 1, it means that the transmission verification of this sub-file fails. At this time, the file integrity check of this sub-file will be skipped, and the first bit in the file integrity check buffer corresponding to this sub-file (sequence number) will remain the default value of 0. If the transmission verification flag of this sub-file is 1, it means that the transmission verification of this sub-file passes, and the file integrity check can be performed. At this time, Node 1 will read the data of the first sub-file from the storage space, calculate the verification code for its text data, and compare the calculated verification code with the verification tail of the sub-file. If the comparison is consistent, it means that the file integrity check passes, and the first bit in the file integrity check buffer corresponding to this sub-file (sequence number) will be set to 1, otherwise it will remain the default value of 0.
[0064] Perform file integrity checks on other sub-files in the same way.
[0065] If the slave node detects that all the sub-files it stores have passed the file integrity check, it will write the text data of all the sub-files into a composite file in the order specified by the file number. This file is the final upgrade file. Combine the complete upgrade file verification code received from the start instruction of the sub-file transmission to verify the final upgrade file. If the verification passes, write the final upgrade file to the pre-specified application program upgrade partition.
[0066] Regardless of whether all sub-files have passed the file integrity check, send the file integrity check result to the master node.
[0067] Step 10: The master node completes the retransmission of sub-files according to the file integrity check results received from the current slave node.
[0068] During the previous sub-file transmission process, the master node already knew the number of sub-files. Assuming the number of files is n, after receiving the 128-bit file integrity check result from the slave node, the master node only checks the first n bits. The master node first checks the value of the first bit. If it is 0, retransmit the first sub-file according to the method in Steps 3 to 7. If it is 1, no operation is performed. Complete the check of the subsequent n - 1 bits and the retransmission of the corresponding sub-files according to this method. At this time, the current slave node's current retransmission work is completed.
[0069] When the master node retransmits a sub-file, all slave nodes will try to receive the sub-file. If a slave node detects that the sub-file it stores has passed the transmission verification, it will ignore the sub-file, otherwise it will receive the sub-file again.
[0070] Step 11: Repeat Steps 9 and 10 until all sub-files of the current slave node have passed the file integrity check.
[0071] Step 12: The master node sequentially executes Steps 9 to 11 on other slave nodes in order until the file integrity checks for all sub-files of all slave nodes pass.
[0072] Step 13: After 10s, the master node sends a restart instruction to all slave nodes in a broadcast manner and restarts itself to complete the upgrade of the master node, and the slave nodes start to restart and upgrade after receiving the restart instruction.
[0073] In the preferred embodiment, the operation of the slave node for receiving and storing sub-files in a double-buffer mode is as follows:
[0074] First, write the body data of the received sub-file data frame into the first buffer. When the first buffer is full, start writing data into the second buffer, and at the same time write the data in the first buffer into the sub-file generated in Step 4 in the storage space;
[0075] The two buffers are used alternately, so that the reception of data frames and the storage of the received data are synchronized, thus avoiding the influence of data storage time-consuming on the data transmission speed;
[0076] Repeat this process until the end instruction for sending the sub-file from the master node is received. At this time, the reception of the sub-file is completed.
[0077] After the slave node receives the end instruction for sending the sub-file, it will determine whether there is still data in the above data buffer that has not been stored in the storage space because the buffer has not been filled. If so, write it into the storage space. At this time, the storage of the sub-file is completed.
[0078] In this embodiment, by executing the method in the above embodiment, the broadcast characteristic of the CAN bus is fully utilized. The master node broadcasts and sends the upgrade sub-files to the slave nodes by using the broadcast data sending method, and uses the query and reissuing method for reissuing control after all sub-files are sent, greatly reducing the upgrade time-consuming for upgrading multiple homogeneous nodes.
[0079] Based on the implementation in the specific application scenario in the above embodiment:
[0080] 1. The operator prepares the upgrade file to be updated, selects a node on the CAN bus network, here selects Node 2, and transfers the upgrade file to this node in a wired manner. At this time, this node is the master node, and other nodes are slave nodes. At this time, the node topology is shown in Figure 2 . The master node calculates the number of sub-files according to the length of the upgrade file. In this example, the size of the upgrade file is 400KB, and the preset length of the body of a single sub-file is 5120 bytes. Therefore, the number of sub-files is exactly 80.
[0081] 2. The master node searches for its TF card files, deletes the leftover files from the previous upgrade, and then broadcasts a pre-upgrade instruction to all slave nodes. After receiving the pre-upgrade instruction, the slave nodes also delete the leftover files from the previous upgrade in their own TF cards, and then generate a transmission verification queue, a transmission verification flag buffer, and a file integrity check buffer, and clear the three buffers.
[0082] 3. The master node reads 5120 bytes from the upgrade file and writes them to the first sub-file in sequence. When writing, it first writes a one-byte file header to the sub-file, then writes the 5120 bytes of data body read this time, and finally calculates a two-byte verification code for the 5120 bytes of data and writes the verification code to the end of the sub-file as the verification tail, which is the prior information for file integrity check. Therefore, the length of a single sub-file in this example is 5123 bytes.
[0083] 4. The master node sends a sub-file sending start instruction to all slave nodes. The slave nodes read the sequence number of the current sub-file from this instruction, generate a blank sub-file with this sequence number as the file name in the TF card according to this sequence number, then read the length of this sub-file from this instruction, and will complete file reception according to this length later. Finally, it reads the complete upgrade file verification information from the instruction for subsequent verification of the synthesized complete upgrade file.
[0084] 5. The master node starts to send the content of the current sub-file to the slave nodes in units of CAN data frames. In this example, the length of a sub-file is 5123 bytes. Since 5123 <= 7 * 255 does not hold and 5123 <= 6 * 65535 holds, the body part of the data frame is 6 bytes. Then the master node continuously reads 6 bytes of data from the current sub-file as the standard, adds the frame number to generate a CAN data frame, and then sends the data frame to the CAN network. Repeat this process continuously until the current sub-file is completely sent.
[0085] 6. All slave nodes simultaneously receive the data frames from the master node, and calculate the lengths of the frame number part and the text part of each data frame according to the length of the sub-file received in step 4, so as to read the frame number and the text data. Here, the frame number part is 2 bytes and the text part is 6 bytes. After receiving a frame of data, the slave node extracts the 6-byte text data and writes the data into the first data buffer, and at the same time sends the text data to the transmission verification queue to calculate the transmission verification code. If the current data frame is the first frame of the current sub-file, the initial value of the calculated transmission verification code is 0xffff, otherwise it is the transmission verification result of the previous frame. Therefore, the verification code obtained after the slave node receives the last frame of data of the current sub-file and completes the transmission verification calculation is the transmission verification code calculated by the slave node for the overall calculation of the sub-file. Repeat the processes of receiving data frames, writing to the buffer, and verification. When the first buffer is full, start writing data to the second buffer, and at the same time write the data in the first buffer into the sub-file generated in step 4 in the TF card. In this example, the sizes of both buffers are 512 bytes, and the two buffers are used alternately to ensure that the reception of data frames and the storage of the received data are synchronized.
[0086] 7. After the master node finishes sending all the data frames of the current sub-file, it calculates the transmission verification code for all the data of the current sub-file, and continues to broadcast and send a sub-file sending end instruction containing the transmission verification code to all slave nodes; after receiving the instruction, the slave node first judges whether there is still data in the above-mentioned first and second data buffers that has not been stored in the TF card because the buffer has not been filled. If so, write it into the TF card. At this time, the storage of the sub-file is completed. Then extract the transmission verification code in the instruction and compare it with the transmission verification result calculated during the reception. If the comparison is consistent, set the flag corresponding to the current sub-file in the transmission verification flag buffer to 1, otherwise set it to 0. At this time, the transmission of the current sub-file is completed.
[0087] 8. Repeat steps 3 to 7 until all sub-files have been sent.
[0088] 9. After all sub-files are sent, the master node queries the file integrity result from the first slave node in the CAN network. In this example, there are 3 slave nodes, namely node 1, node 3, and node 4. Therefore, the first slave node is node 1. The query operation is that the master node sends a file integrity check instruction with the specified target slave node number being 1 to all slave nodes. At this time, all three slave nodes will receive this instruction. Slave nodes 3 and 4 do not execute this instruction because their own node numbers are inconsistent with the specified slave node number in the instruction. Node 1 starts to perform file integrity check on the sub-files it received because its node number is consistent with the specified slave node number in the instruction. First, check the first sub-file. Correspondingly, the slave node first checks the first data in the transmission verification flag buffer. If this data is 0, it indicates that the sub-file was not correctly received, and there is no need to perform file integrity check. Directly set the first bit in the file integrity check buffer corresponding to the sub-file number to 0, indicating that the file integrity check of this sub-file fails. If the transmission verification flag of this sub-file is 1, it indicates that the transmission verification of this sub-file passes, and file integrity check can be performed. When checking, first read the data of this sub-file from the storage space, and perform verification on the data body after removing the file header and verification tail from the sub-file data. If the verification result is the same as the verification tail, it indicates that the file integrity check of this sub-file passes, and set the first bit in the file integrity check buffer to 1, otherwise still set it to 0. Use the above method to perform file integrity check on all other sub-files. If all sub-files pass the file integrity check, write the data bodies of all sub-files into a combined file in the order specified by the sub-file number and perform verification on the combined file. After the verification passes, write the combined file into the preset program upgrade partition. At this time, this combined file is the final upgrade file. Whether all sub-files pass the file integrity check or not, the slave node will frame the bit stream stored in the file integrity check buffer and send it to the master node. In this example, the data stored in the file integrity check buffer is a bit stream composed of 128 bits in 16 bytes, and it takes about 22 data frames to complete the result sending when sending.
[0089] 10. The master node completes the reissuance of sub-files according to the file integrity check results received from the current slave node.
[0090] During the previous sub-file sending process, the master node already knew the number of sub-files. In this example, the number of sub-files is 80. Therefore, after receiving the file integrity check result with a length of 128 bits from the slave node, the master node only checks the first 80 bits. The master node first checks the value of the first bit. If it is 0, reissue the first sub-file according to the methods in steps 3 to 7. If it is 1, do nothing. Complete the check of the subsequent 79 bits and the reissuance of the corresponding sub-files according to this method. At this time, the current reissuance work of the slave node is completed.
[0091] When the master node reissues a sub-file, all slave nodes will attempt to receive the sub-file. If a slave node detects that the sub-file it stores has passed the transmission verification, it will ignore the sub-file; otherwise, it will receive the sub-file again.
[0092] 11. Repeat steps 9 to 10 until the file integrity check of all sub-files of the first slave node passes.
[0093] 12. Sequentially execute steps 9 to 11 for the remaining slave nodes 3 and 4 in order until the file integrity check of all sub-files of all slave nodes passes.
[0094] 13. After 10s, the master node sends a restart instruction to all slave nodes in a broadcast manner and automatically restarts to complete the upgrade of the master node. After receiving the restart instruction, the slave nodes start to restart and upgrade.
[0095] In summary, the method in the above embodiments makes full use of the broadcast characteristics of the CAN bus. The master node uses the broadcast data sending method to broadcast and send upgrade sub-files to the slave nodes, and uses the query and reissue method for reissue control after all sub-files are sent, greatly reducing the upgrade time of multiple homogeneous node upgrades. Moreover, this method does not require a dedicated controller to control the transmission of upgrade files. Any device node in the CAN network can be temporarily determined as the master node to complete the transmission control of the upgrade files. When a pre-selected master node has problems, a new master node can be selected from other nodes. At the same time, this method adopts a dual verification method of transmission verification and file integrity check. The former ensures the correct transmission of sub-files on the CAN network, and the latter ensures the correctness of the data text in the sub-files, reducing the risk of upgrade file synthesis errors caused by reasons such as single verification failure.
[0096] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements will not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for parallel upgrading of multiple homogeneous nodes applied to ocean buoys, characterized in that: The following steps are involved: Step 1: Select one node from multiple homogeneous nodes as the master node, and the other nodes as slave nodes, and send the upgrade file to the master node; Step 2: The master node first clears the residual files, and then sends a pre-upgrade instruction to the slave node. After receiving the pre-upgrade instruction, the slave node first clears the residual files and generates a transmission verification queue, a transmission verification flag buffer, and a file integrity check buffer; Step 3: The master node reads the upgrade file data of fixed length in sequence, and generates a file name according to the sequence number of the upgrade file data and stores it in the storage space to generate a sub-file; Step 4: The master node broadcasts a sub-file sending start instruction including the sub-file sequence number, sub-file length and a check code of the complete upgrade file to all slave nodes; Step 5: The master node starts to send the content of the current subfile to the slave node in units of CAN data frames; Step 6: All slave nodes simultaneously receive the data frame from the master node, read the frame number and the text data, store them, and send the text data to the transmission verification queue to calculate the transmission verification code; Step 7: After the master node completes the transmission, it sends an end instruction to all slave nodes, and the slave nodes end data reception, storage and sub-file transmission verification according to the end instruction; Step 8: Repeat steps 3 to 7 until all sub-files are sent; Step 9: the master node queries the first slave node for the file integrity check result. After receiving the instruction, the first slave node performs a file integrity check on all received sub-files in combination with the result in the transmission check mark buffer; Step 10: After receiving the file integrity check result from the slave node, the master node reissues the sub-files that have not passed the file integrity check of the current slave node; Step 11: Repeat steps 9 to 10 until all sub-files of the slave node pass the file integrity check; Step 12: Execute steps 9 to 11 on other slave nodes in order, until the file integrity check of all sub-files of all slave nodes passes; Step 13: After a delay of a period of time, the master node sends a restart instruction to all slave nodes in a broadcast manner, and restarts to complete the upgrade of the master node. After receiving the restart instruction, the slave node starts to restart and upgrade.
2. The method for parallel upgrading of multiple homogeneous nodes applied to ocean buoys according to claim 1 is characterized in that: After receiving the upgrade file, the master node first reads the version number of the upgrade file. When the version number does not conflict with the version number stored in itself, the upgrade file is written to the pre-set application upgrade partition, and the number of sub-files to be transferred is calculated based on the preset size.
3. The method for parallel upgrading of multiple homogeneous nodes applied to ocean buoys according to claim 1 is characterized in that: The transmission check queue is a data buffer with a length equal to the length of the CAN data frame data space; The transmission check mark buffer is an array whose length is determined by the preset maximum number of sub-files, and the Xth element in the transmission check mark buffer represents the transmission check status of the Xth sub-file, 0 indicates that the check fails, and 1 indicates that the check succeeds; The file integrity check buffer stores a string of bit streams, the Xth bit represents the file integrity check result of the Xth sub-file, 1 indicates that the check passed, and 0 indicates that the check failed. The transmission check of the sub-file is used to check the transmission of the sub-file on the CAN network.
4. The method for parallel upgrading of multiple homogeneous nodes applied to ocean buoys according to claim 1, characterized in that: The sub-file generated in step 3 includes a one-byte file header, a fixed-length data body, and a two-byte check tail. The check tail is a check code calculated by the master node for the data body of the sub-file, and is used as a priori information for subsequent slave nodes to perform file integrity checks on the file.
5. The method for parallel upgrading of multiple homogeneous nodes applied to ocean buoys according to claim 1, characterized in that: The sub-file sending start instruction includes the sequence number of the current sub-file, the length of the sub-file, and the verification code of the complete upgrade file. The slave node generates a blank sub-file with the sequence number as the file name in the storage space according to the sequence number of the sub-file, which is used to store the data of the sub-file received later. The verification code of the complete upgrade file is used to verify the synthesized upgrade file when all sub-files pass the file integrity check and synthesize the complete upgrade file.
6. The method for parallel upgrading of multiple homogeneous nodes applied to ocean buoys according to claim 1, characterized in that: After receiving the subfile sending start instruction from the master node, the slave node reads the file length of the current subfile and determines the number of bytes occupied by the frame number part and the data body part in the subsequently received subfile data frame according to the file length.
7. The method for parallel upgrading of multiple homogeneous nodes applied to ocean buoys according to claim 1, characterized in that: After the master node has sent all the data frames of a sub-file, it calculates the transmission check code for the current sub-file and sends a sub-file sending end instruction containing the transmission check code to all slave nodes. After receiving the instruction, the slave node extracts the transmission check code from it and compares it with the transmission check code calculated by itself. If the comparison is successful, the corresponding position in the transmission check mark buffer is set to 1, otherwise it is set to 0.
8. The method for parallel upgrading of multiple homogeneous nodes applied to ocean buoys according to claim 3 is characterized in that: The slave node uses double buffer mode for receiving and storing sub-files: First, the body data of the received data frame is written into the first buffer, and the body data of the data frame is sent to the transmission verification queue for transmission verification. If the data frame is the first data frame of the current subfile, the transmission verification code of the current frame is calculated based on the preset initial verification value, otherwise the transmission verification code of the current frame is calculated based on the transmission verification code of the previous frame data body of the current subfile; when the first buffer is full, data is written to the second buffer and the transmission verification code is calculated in the same way, and the data of the first buffer is written into the subfile generated by the step 4 in the storage space; The two buffers are used alternately to synchronize the reception of data frames with the storage of received data; This process is repeated until a sub-file sending end instruction is received from the master node. At this time, the sub-file is received and the current transmission check code is the transmission check code calculated by the slave node for the received sub-file. After receiving the sub-file sending end instruction, the slave node determines whether there is any data in the data buffer that has not been stored in the storage space because the buffer is not full. If there is data, it writes it into the storage space. At this time, the storage of the sub-file is completed.
9. The method for parallel upgrading of multiple homogeneous nodes applied to ocean buoys according to claim 1, characterized in that: After a single sub-file is transmitted, the reception status of each slave node for the sub-file is not immediately checked and resent. Instead, a query resend mechanism is adopted. After all sub-files are sent, the reception status of all sub-files is queried from each slave node in turn and resent is controlled. Specifically, The master node sends a file integrity check instruction containing a target slave node number to all slave nodes. When a slave node receives the file integrity check instruction, it determines whether the target slave node number in the instruction is the same as its own slave node number. If they are not the same, the instruction will not be executed. If they are the same, a file integrity check will be performed on all sub-files. When performing a file integrity check on one of the sub-files, the slave node first checks whether the result of the sub-file in the transmission check mark buffer is 1. If it is 1, it means that the transmission check of the sub-file has passed and the file integrity check can be performed. If the file integrity check of the sub-file has passed, the bit corresponding to the sub-file name in the file integrity check buffer is set to 1, otherwise it is still set to 0. If the result of the sub-file in the transmission check mark buffer is 0, the bit corresponding to the sub-file in the file integrity check buffer is directly set to 0. When the slave node performs a file integrity check on a sub-file, a checksum is calculated for the data body of the sub-file after removing the file header and the checksum tail. If the calculated checksum is the same as the checksum tail of the sub-file, it means that the file integrity check of the sub-file has passed; After the file integrity check of all sub-files is completed, the slave node divides the bit stream stored in the file integrity check buffer into frames and sends them to the master node; The master node parses the received file integrity test result bit stream. If a bit in the bit stream is 0, the master node reissues the sub-file corresponding to the bit according to the method of steps 3 to 7; Repeat this process until all subfiles of the current slave node pass the file integrity check; The other slave nodes are queried and resent in turn until all sub-files of all slave nodes pass the file integrity check.
Citation Information
Patent Citations
Synchronous upgrading method of parallel operation system
CN111857770A
Method and apparatus for a distributed file storage and indexing service
CN101395602A
Wireless and underwater sound communication buoy
CN102571902A