Controller upgrading method and device

CN120202646APending Publication Date: 2025-06-24YINWANG INTELLIGENT TECHNOLOGIES CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202280101809.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2022-11-24
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

In the existing technology, dual backup controllers are susceptible to bricking due to power outages when upgrading the boot loader (BL), making it impossible to perform remote upgrades reliably, and the BL program upgrade is affected by the application (APP) version, resulting in a successful upgrade. rate is low.

Method used

By setting up two storage areas in the controller, one as a backup and one as a running area, first upgrade the BL program in the backup area, and switch its role after the upgrade is successful, ensuring that there is always an available BL program during the BL program upgrade process. services to avoid the risk of power outages, and optimize the version matching of APP and BL programs through version number acquisition requests and blacklist mechanisms to ensure successful upgrades.

Benefits of technology

It improves the remote upgrade success rate of the BL program, ensures the stability and reliability of the controller during the upgrade process, enhances the user experience, and avoids upgrade failures due to version mismatch.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120202646A_ABST
    Figure CN120202646A_ABST
Patent Text Reader

Abstract

The invention discloses a controller upgrading method and device, and the method comprises the steps: enabling a controller to carry out BL program upgrading on a first storage region which serves as a backup storage region in the controller through a BL program upgrading package in an upgrading file, and setting the first storage region as a running storage region after the upgrading is successful, the second storage area is set as the backup area, and when the BL program of one storage area is upgraded, the BL program of the other storage area can be used for providing service, so that the situation that the controller becomes a brick due to power failure in the BL program upgrading process is avoided, and the success rate of remote upgrading is increased.
Need to check novelty before this filing date? Find Prior Art

Description

A controller upgrade method and device Technical Field

[0001] The present application relates to the field of automobile diagnostic information technology, and in particular to a controller upgrading method and device. Background Art

[0002] With the evolution of vehicle electrical and electronic architecture, new energy vehicles will have many important electronic control units. Most electronic control units need to be started through a bootloader (BL) program at startup. The BL program is the system's bootloader and is the first code to run after the system is powered on or reset. Its main functions include initialization, security verification, and loading of application programs. For non-dual backup controllers, the BL program also has a unified diagnostic service (UDS) flash function, which updates the application program (APP) in BL program mode. When the controller is mass-produced, the program loaded in the controller may contain errors, requiring software optimization or bug fixes.

[0003] The current dual-backup controller backs up the app, allowing it to be run and updated simultaneously in app mode. While it's technically possible to upgrade the BL program in app mode, the BL program is responsible for basic startup initialization and app loading. This makes it susceptible to power outages and bricking during a BL program upgrade, making it impossible to reliably upgrade remotely.

[0004] Summary of the Invention

[0005] The present application provides a controller upgrade method and device for improving the success rate of remote upgrades.

[0006] In a first aspect, the present application provides a controller upgrade method, wherein the controller includes a first storage area and a second storage area, wherein a boot loader (BL) program is stored in the first storage area and the second storage area, respectively. The method includes: obtaining an upgrade file, wherein the upgrade file includes a BL program upgrade package; upgrading the BL program in the first storage area according to the BL program upgrade package, wherein the first storage area is a backup storage area and the second storage area is a running storage area; and when the BL program in the first storage area is successfully upgraded, setting the first storage area as the running storage area and setting the second storage area as the backup storage area.

[0007] In the above aspect, the BL program upgrade package in the upgrade file is used to first upgrade the first storage area in the controller as a backup storage area. After the upgrade is successful, the first storage area is set as the running storage area, and the second storage area is set as the backup area. When upgrading the BL program in one storage area, the BL program in another storage area can be used to provide services, avoiding the controller from becoming bricked due to power outage during the BL program upgrade process, and improving the success rate of remote upgrades.

[0008] In a possible implementation, after setting the first storage area as the running storage area and setting the second storage area as the backup storage area, the method further includes: upgrading the BL program in the second storage area according to the BL program upgrade package.

[0009] In the above possible implementation manner, after the first storage area is switched to the running storage area, the BL program in the second storage area currently serving as the backup area can be further upgraded. When the first storage area fails, the operation can be switched to the second storage area with the latest BL program, thereby improving the user experience.

[0010] In one possible implementation, before the above steps upgrade the BL program in the first storage area according to the BL program upgrade package, the method further includes: receiving a version number acquisition request from a host computer; sending the base software version number of the application APP in the first storage area to the host computer according to the version number acquisition request; when the base software version number belongs to a blacklist, receiving an instruction from the host computer, the blacklist including version numbers corresponding to which the BL program cannot be upgraded, and the instruction instructing the APP in the first storage area to be upgraded before the BL program in the first storage area.

[0011] In the above possible implementation, since the BL program upgrade in a storage area is sometimes affected by the version of the APP in that storage area, that is, there is a blacklist of APP versions whose corresponding BL program cannot be upgraded, the host computer can use a version number acquisition request to read the base software version number of the APP in the storage area in the controller. The controller can then feedback the base software version number of the APP in the first storage area or the second storage area to the host computer. If the host computer matches the base software version number to be on the blacklist, it indicates that the BL program in the storage area cannot be upgraded under the APP with the current base software version number. Therefore, it is necessary to instruct the controller through an instruction to first upgrade the APP in the storage area, and then upgrade the BL program in the storage area, which can improve the success rate of the BL program upgrade.

[0012] In one possible implementation, the upgrade file also includes an APP upgrade package and / or a calibration Cal file upgrade package. Before the above steps set the first storage area as the running storage area and set the second storage area as the backup storage area, the method also includes: upgrading the APP in the first storage area according to the APP upgrade package; and / or upgrading the Cal file in the first storage area according to the Cal file.

[0013] In the above possible implementations, the upgrade file may also include an APP upgrade package and / or a Cal file upgrade package. That is, the upgrade file may include an APP upgrade package, a Cal file upgrade package, or both, without limitation. Therefore, before switching the first storage area from the backup storage area to the running storage area, the controller also needs to upgrade the APP and / or Cal file in the first storage area. That is, the APP upgrade package will overwrite the storage address of the APP in the first storage area, and the Cal file upgrade package will overwrite the storage address of the Cal file in the first storage area, thereby improving the program version matching.

[0014] In one possible implementation, the upgrade file includes an upgrade address, and the above steps of upgrading the BL program in the first storage area according to the BL program upgrade package include: determining a first erase address according to the upgrade address, where the first erase address is an address for erasing the BL in the first storage area; verifying whether the first erase address is within the address space of the BL program in the first storage area; erasing the content at the first erase address when the verification passes; and storing the data of the BL program upgrade package at the first erase address.

[0015] In the above possible implementation, when the controller is upgrading the BL program in the first storage area based on the BL program upgrade package in the upgrade file, the controller can parse the upgrade address from the upgrade file. This upgrade address may include the erase address corresponding to the BL program upgrade package. Since the controller's storage area is divided into a first storage area and a second storage area, when the BL program in the first storage area needs to be upgraded, the controller can determine the first erase address for the BL program in the first storage area based on the erase address. In this case, the controller can verify the first erase address to see if it is within the address space allocated for the BL program in the first storage area. If it is not within the address space, the controller indicates that the first erase address is incorrect and can provide a negative response to the host computer. If the first erase address is within the address space, the controller indicates that the first erase address is valid and can directly erase the data at the first erase address. The data of the BL program upgrade package can then be stored at the erased first erase address to complete the BL program upgrade in the first storage area. Verifying the erase address within the allocated address space ensures the BL program upgrade is successful and improves the success rate of the BL program upgrade.

[0016] In one possible implementation, the above steps of upgrading the BL program in the second storage area according to the BL program upgrade package include: determining a second erase address according to the upgrade address, where the second erase address is an address for erasing the BL program in the second storage area; verifying whether the second erase address is within the address space of the BL program in the second storage area; erasing the content at the second erase address when the verification passes; and storing the data of the BL program upgrade software package at the second erase address.

[0017] In the above possible implementation, the controller can also determine a second erase address for erasing the BL program in the second storage area based on the upgrade address in the upgrade file. This upgrade address can include the erase address corresponding to the BL program upgrade package. Since the controller's storage area is divided into a first storage area and a second storage area, when the BL program in the second storage area needs to be upgraded, the second erase address for the BL program in the second storage area can be determined based on the erase address. In this case, the controller can verify the second erase address to see if it is within the address space allocated for the BL program in the second storage area. If it is not within the address space, the second erase address is incorrect and a negative response can be fed back to the host computer. If the second erase address is within the address space, the second erase address is valid and the data at the second erase address can be directly erased. The data of the BL program upgrade package can then be stored at the erased second erase address to complete the BL program upgrade in the second storage area. Verifying the erase address within the allocated address space ensures the BL program upgrade is successful and improves the success rate of the BL program upgrade.

[0018] In one possible implementation, before the above steps of setting the first storage area as the running storage area and the second storage area as the backup storage area, the method further includes: verifying whether a hash value of the BL program in the first storage area and a hash value of the BL program in the second storage area are identical; if they are identical, triggering the step of setting the first storage area as the running storage area and the second storage area as the backup storage area; if they are different, verifying the integrity of the BL program in the first storage area; and if the verification is successful, swapping the secure boot setting values ​​of the first storage area and the second storage area, and triggering the step of setting the first storage area as the running storage area and the second storage area as the backup storage area.

[0019] In the above possible implementation, the controller further needs to detect whether the BL program in the first storage area has been upgraded. This can be done by checking whether the BL program in the first storage area and the BL program in the second storage area are identical, for example, by verifying whether the hash value of the BL program in the first storage area and the hash value of the BL program in the second storage area are identical, i.e., comparing the binary code of the BL program in the first storage area with the binary code of the BL program in the second storage area. When the hash values ​​of the binary code of the BL program in the first storage area and the BL program in the second storage area are identical, the controller can be triggered to set the first storage area as the active storage area and the second storage area as the backup storage area. If the hash values ​​of the binary code of the BL program in the first storage area and the BL program in the second storage area are different, it indicates that the BL program in the first storage area has been upgraded, but it is unclear whether the upgrade was successful. In this case, the controller can further verify the integrity of the BL program in the first storage area. If the verification fails, that is, the integrity is insufficient, the BL program of the first storage area can be re-flashed, or a negative response can be fed back to the upper computer. If the verification succeeds, it means that the BL program of the first storage area has been successfully upgraded, and the secure boot setting values ​​of the first storage area and the second storage area can be exchanged. The secure boot setting value is the verification basis for selecting the boot storage area when the controller is reset, that is, the secure boot setting value of the first storage area is switched to the preferred value. After the reset, the controller can use the first storage area as the running storage area to complete the steps of setting the first storage area as the running storage area and setting the second storage area as the backup storage area. Through hash value verification and integrity verification, the upgrade success accuracy of the first storage area switched to the allowed storage area is improved.

[0020] In one possible implementation, after the above steps of upgrading the BL program in the second storage area according to the BL program upgrade package, the method further includes: verifying whether a hash value of the BL program in the first storage area and a hash value of the BL program in the second storage area are the same; and when they are different, triggering the step of upgrading the BL program in the second storage area according to the BL program upgrade package.

[0021] In the above possible implementation, after the BL program in the second storage area is upgraded, a check can be performed to determine whether the hash value of the BL program in the first storage area and the hash value of the BL program in the second storage area are identical, i.e., to determine whether the BL program in the second storage area has been successfully upgraded. If the check fails, i.e., the hash value of the BL program in the first storage area and the hash value of the BL program in the second storage area are different, it indicates that the upgrade of the BL program in the second storage area has failed and needs to be re-upgraded. The step of upgrading the BL program in the second storage area according to the BL program upgrade package can then be performed again. By verifying the hash values ​​of the BL program in the two storage areas and re-upgrading if the hash values ​​are different, the upgrade success rate is improved.

[0022] In a possible implementation, after the above step of upgrading the BL program in the second storage area according to the BL program upgrade package, the method further includes: executing a post-programming phase, where the post-programming phase is used to restore the local communication state.

[0023] In the above possible implementation manner, after the BL program in the second storage area is upgraded, the controller and the host computer can also execute the post-programming stage. The controller makes the controller software effective by resetting, responds to the service instructions of the host computer, completes the necessary reset work, reopens the communication between the controller and the host computer, and starts controlling the diagnostic trouble code (DTC), clearing the DTC, and jumping the diagnostic session to restore the communication status of the controller, so that the controller can be used normally, restore the traffic status in time, and improve the user experience.

[0024] A second aspect of the present application provides a controller upgrade method, wherein the controller includes a first storage area and a second storage area, wherein a boot loader (BL) program is stored in the first storage area and the second storage area, respectively. The method includes: sending a version number acquisition request to the controller, wherein the version number acquisition request is used to read the bottom soft version number of an application program APP in the first storage area; receiving the bottom soft version number from the controller; and when the bottom soft version number belongs to a blacklist, sending an instruction to the controller, wherein the blacklist includes version numbers corresponding to which the BL program cannot be upgraded, and the instruction instructs the APP in the first storage area to be upgraded before the BL program in the first storage area.

[0025] In the above aspect, since the BL program upgrade in a storage area is sometimes affected by the version of the APP in that storage area, that is, there is a blacklist of APP versions that cannot be upgraded by the BL program, the host computer can use a version number acquisition request to read the base software version number of the APP in the storage area of ​​the controller. The controller can then feedback the base software version number of the APP in the first storage area or the second storage area to the host computer. If the host computer matches the base software version number to be on the blacklist, it indicates that the BL program in the storage area cannot be upgraded under the APP with the current base software version number. Therefore, it is necessary to instruct the controller through instructions to upgrade the APP in the storage area first, and then upgrade the BL program in the storage area, which can improve the success rate of the BL program upgrade.

[0026] In a possible implementation, the method further includes: executing a post-programming phase, where the post-programming phase is used to restore a local communication state.

[0027] A third aspect of the present application provides a controller upgrade device that can implement the method described in the first aspect or any possible implementation of the first aspect. The device includes corresponding units or modules for executing the method described above. The units or modules included in the device can be implemented in software and / or hardware. The device can be, for example, a network device, or a chip, chip system, or processor that supports the network device in implementing the method described above. It can also be a logic module or software that can implement all or part of the network device's functions.

[0028] A fourth aspect of the embodiments of the present application provides a controller upgrade device that can implement the method of the second aspect or any possible implementation of the second aspect. The device includes corresponding units or modules for executing the above-mentioned method. The units or modules included in the device can be implemented in software and / or hardware. The device can be, for example, a network device, or a chip, chip system, or processor that supports the network device to implement the above-mentioned method. It can also be a logic module or software that can implement all or part of the network device functions.

[0029] In a fifth aspect, the present application provides a computer device, comprising: a processor coupled to a memory, the memory being configured to store instructions, wherein when the instructions are executed by the processor, the computer device implements the method of the first aspect or any possible implementation of the first aspect. The computer device may be, for example, a network device, or a chip or chip system that supports the network device in implementing the method.

[0030] In a sixth aspect, the present application provides a computer device, comprising: a processor coupled to a memory, the memory being configured to store instructions, wherein when the instructions are executed by the processor, the computer device implements the method of the second aspect or any possible implementation of the second aspect. The computer device may be, for example, a network device, or a chip or chip system that supports the network device in implementing the method.

[0031] The seventh aspect of the present application provides a computer-readable storage medium, which stores instructions. When the instructions are executed by the processor, the method provided by the aforementioned first aspect or any possible implementation of the first aspect, the aforementioned second method or any possible implementation of the second method is implemented.

[0032] In an eighth aspect, the present application provides a computer program product, which includes computer program code. When the computer program code is executed on a computer, it implements the method provided by the aforementioned first aspect or any possible implementation of the first aspect, the aforementioned second method or any possible implementation of the second method. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] FIG1 is a system architecture diagram of a communication transmission provided by an embodiment of the present application;

[0034] FIG2 is a flow chart of a controller upgrade method provided in an embodiment of the present application;

[0035] FIG3 is a schematic diagram of a flow chart of a pre-programming step provided in an embodiment of the present application;

[0036] FIG4 is a schematic diagram of a reprogramming process according to an embodiment of the present application;

[0037] FIG5 is a flow chart of a sectioning operation step provided in an embodiment of the present application;

[0038] FIG6 is a schematic diagram of exchanging secure boot setting values ​​provided by an embodiment of the present application;

[0039] FIG7 is a schematic diagram of the overall flow of a controller upgrade BL program provided in an embodiment of the present application;

[0040] FIG8 is a schematic structural diagram of a controller upgrading device provided in an embodiment of the present application;

[0041] FIG9 is a schematic structural diagram of another controller upgrading device provided in an embodiment of the present application;

[0042] FIG10 is a schematic diagram of the structure of a computer device provided in an embodiment of the present application;

[0043] FIG11 is a schematic structural diagram of another computer device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0044] The embodiments of the present application provide a node upgrade method and device for reducing the workload of a host computer and slave nodes, thereby saving R&D and production costs.

[0045] The following describes the embodiments of the present application in conjunction with the accompanying drawings. Obviously, the embodiments described are only part of the embodiments of the present application, rather than all the embodiments. Those skilled in the art will appreciate that with the development of technology and the emergence of new scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.

[0046] The terms "first," "second," and the like in the specification and claims of this application and in the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a particular order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate so that the embodiments described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "including" and "having," as well as any variations thereof, are intended to cover non-exclusive inclusions, e.g., a process, method, system, product, or apparatus comprising a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units that are not explicitly listed or that are inherent to these processes, methods, products, or apparatus.

[0047] The following first introduces relevant terms and concepts that may be involved in the embodiments of this application.

[0048] (1) Electronic control unit (ECU)

[0049] ECU is also known as driving computer, on-board computer, etc. In terms of usage, it is a car-specific microcomputer controller, also called a car-specific single-chip microcomputer. Like an ordinary computer, it consists of a microprocessor (microcontroller unit, MCU), read-only memory (read-only memory, ROM), random access memory (random access memory, RAM), input / output interface (I / O), analog-to-digital converter (A / D) and large-scale integrated circuits such as shaping and driving.

[0050] The central processing unit (CPU) is the core component of an ECU, performing computational and control functions. For example, when the engine is running, it collects signals from various sensors, performs computations, and converts the results into control signals to control the operation of the controlled object. It also controls memory (such as ROM), I / O, and other external circuits. ECUs generally include self-diagnosis and protection features. When a system fault occurs, it automatically records the fault code in RAM and, using protective measures, reads an alternative program from its native program to maintain operation of the corresponding component (such as the engine). These fault messages are also displayed on the instrument panel and remain persistent, allowing the driver to promptly identify the problem and drive the vehicle to a repair shop. Under normal circumstances, RAM continuously records driving data and uses adaptive programming to learn from this real-time data, providing optimal control to adapt to the driver's driving habits.

[0051] Traditional ECUs have a relatively simple structure. There may be dozens or even hundreds of ECUs on a vehicle, such as the ECU used on the engine and the ECU used on the anti-lock braking system. The functions of each ECU are relatively independent. With the development of digital cars, especially autonomous driving technology, the ECUs on cars have gradually become more complex and tend to be concentrated on a super ECU. As a result, the difficulty of ECU diagnosis has become increasingly greater.

[0052] (2) Host computer

[0053] The host computer refers to a computer device that can directly issue control commands. In the embodiment of the present application, any computer device that can communicate with the ECU based on the UDS protocol can be called a host computer (also called a diagnostic instrument, diagnostic machine, diagnostic tool, etc.). For example, personal computers (PCs), mobile phones, tablet computers and other smart handheld terminal devices, as well as smart wearable devices such as smart bracelets and smart watches, and even single-chip microcomputers, as long as the device can run the corresponding diagnostic software and can communicate with the ECU based on the UDS protocol can be used as the host computer in the embodiment of the present application, and the specific details are not limited here.

[0054] (3) Unified diagnosis service (UDS)

[0055] The development, adaptation, implementation, and maintenance of different diagnostic communication protocols incur unnecessary costs for vehicle manufacturers, system suppliers, and ECU vendors. To address this issue, the various technical protocols and data communication principles were compiled into a standard developed by the International Organization for Standardization (ISO), commonly known as UDS (also known as ISO 14229-1). UDS is a universal automotive diagnostic protocol that is data link-independent. Designed for the application layer of the Open System Interconnection (OSI) model, UDS can be implemented on various automotive buses, such as the Controller Area Network (CAN), Local Interconnect Network (LIN), FlexRay, Ethernet, and K-Line. Currently, most automakers use the UDS on CAN diagnostic protocol. This means using a device (generally referred to as a host computer) to analyze the information / data within the vehicle's ECU. This device communicates with the ECU using UDS (though this is not the only method).

[0056] Please refer to Figure 1. As shown in Figure 1, it is a system architecture diagram of a communication transmission provided in an embodiment of the present application. The communication system includes an over-the-air technology (OTA) server 101 and a dual backup controller 102, wherein the dual backup controller 102 includes a CAN / Ethernet communication module 1021, a flash driver (FlashDriver) module 1022, a flash memory (Flash) storage area 1023, and a central processing unit (CPU) unit 1024.

[0057] The OTA server remotely manages the software through a mobile communication interface. When the firmware is upgraded, the remote OTA server 101 transmits the upgrade instruction to the controller through the CAN / Ethernet communication module 1021 via the intermediate forwarding node 103 for upgrading.

[0058] The Flash storage area 1023 includes area A and area B, wherein area A and area B respectively store a boot loader (BL), an application program (APP), and a calibration (Cal) file.

[0059] The above OTA server is the host computer of this application.

[0060] With the evolution of vehicle electrical and electronic architecture, new energy vehicles will have many important electronic control units. Most electronic control units require booting through the Bootloader (BL) at startup. The BL is the system's boot loader and the first code to run after the system is powered on or reset. Its main functions include initialization, security verification, and loading of application programs. For non-dual backup controllers, the BL also features a unified diagnostic service (UDS) flashing function, which updates application programs (APPs) in BL mode. After controllers enter mass production, the programs loaded into the controllers may contain errors, requiring software optimization or bug fixes.

[0061] The current dual-backup controller backs up the app, allowing it to be run and updated simultaneously in app mode. While it's technically possible to upgrade the BL in app mode, the BL is responsible for basic boot initialization and app loading, making it vulnerable to power outages and bricking during a BL upgrade, making it impossible to reliably upgrade remotely.

[0062] To solve the above problems, an embodiment of the present application provides a controller upgrade method, which is described as follows.

[0063] Please refer to FIG2 , which is a flow chart of a controller upgrade method provided by an embodiment of the present application. The method includes:

[0064] Step 201: The controller obtains an upgrade file, which includes a BL program upgrade package.

[0065] In this embodiment, the upgrade file is provided by the OTA server. When the OTA server wants to upgrade the BL program of the controller, it can send the upgrade file carrying the BL program upgrade package to the controller. Correspondingly, the controller can receive the upgrade file from the OTA server.

[0066] When the host computer determines that the target vehicle's ECU program needs to be upgraded, it can first query the target vehicle's controller information, including the APP version information, through a version query instruction. Then, when selecting the controller's APP version, it selects a version that matches the target vehicle's other ECU versions. The host computer can package the controller's various upgrade packages into a total upgrade file, which includes the BL program upgrade package. The upgrade process then begins, where the host computer sends the upgrade file to the controller.

[0067] Step 202: The controller upgrades the BL program in the first storage area according to the BL program upgrade package. The first storage area is a backup storage area, and the second storage area is a running storage area.

[0068] In this embodiment, the controller may have multiple storage areas, one of which is a running storage area and the other is a backup storage area. Each storage area stores a BL program. This embodiment uses two storage areas as an example. The controller currently uses the BL program in the second storage area, which is the running storage area, to provide BL program services. To maintain BL program services, the controller may first upgrade the BL program in the first storage area, which is the backup storage area, by overwriting the storage address of the BL program in the first storage area with the BL program upgrade package.

[0069] In one example, before the controller upgrades the BL program in the first storage area according to the BL program upgrade package, it also needs to receive a version number acquisition request from the host computer in a pre-programming step, and send the base soft version number of the application APP in the first storage area to the host computer according to the version number acquisition request. When the base soft version number belongs to the blacklist, it receives an instruction from the host computer, and the blacklist includes the corresponding version number that the BL program cannot upgrade, and the instruction instructs the APP in the first storage area to be upgraded before the BL program in the first storage area.

[0070] Specifically, because the BL program upgrade in a storage area is sometimes affected by the version of the APP in that storage area, there is a blacklist of APP versions that cannot be upgraded by the BL program. The host computer can use a version number acquisition request to read the underlying software version number of the APP in the storage area of ​​the controller. The controller can then feedback the underlying software version number of the APP in the first storage area or the second storage area to the host computer. If the host computer matches the underlying software version number to be on the blacklist, it indicates that the BL program in the storage area cannot be upgraded under the APP with the current underlying software version number. Therefore, it is necessary to instruct the controller through instructions to upgrade the APP in the storage area first, and then upgrade the BL program in the storage area.

[0071] Specifically, the pre-programming process is shown in Figure 3: Step 301: Entering the extended session ($10$03); Step 302: Checking pre-programming conditions ($31); Step 303: Disabling the diagnostic trouble code (DTC) ($85$02); Step 304: Disabling communication ($28); and Step 305: Reading the software version number ($22$F1FF). The controller disables DTCs and communication to avoid communication errors and DTC errors.

[0072] The upgrade file may also include an APP upgrade package and / or a Cal file upgrade package, that is, the upgrade file may include an APP upgrade package, a Cal file upgrade package, or may include both an APP upgrade package and a Cal file upgrade package, which is not limited here. Therefore, before switching the first storage area from the backup storage area to the running storage area, the controller also needs to upgrade the APP and / or the Cal file in the first storage area, that is, the APP upgrade package will overwrite the storage address of the APP in the first storage area, and the Cal file upgrade package will overwrite the storage address of the Cal file in the first storage area.

[0073] When a controller is upgrading a BL program in a first storage area based on a BL program upgrade package in an upgrade file, the controller can parse an upgrade address from the upgrade file. The upgrade address can include an erase address corresponding to the BL program upgrade package. Since the controller's storage area is divided into a first storage area and a second storage area, when the BL program in the first storage area needs to be upgraded, the controller can determine a first erase address for the BL program in the first storage area based on the erase address. The controller can then verify the first erase address to see if it is within the address space allocated for the BL program in the first storage area. If it is not within the address space, the controller indicates that the first erase address is incorrect and can provide a negative response to a higher-level computer. If the first erase address is within the address space, the controller indicates that the first erase address is valid and can directly erase the data at the first erase address. The controller can then store the data in the BL program upgrade package at the erased first erase address to complete the upgrade of the BL program in the first storage area.

[0074] Step 203: When the BL program in the first storage area is successfully upgraded, the controller sets the first storage area as the running storage area and sets the second storage area as the backup storage area.

[0075] In this embodiment, after the BL program in the first storage area is upgraded, the currently running storage area can be switched to the first storage area with the upgraded BL program to provide better service. At this time, the first storage area is the running storage area and the second storage area is the backup storage area.

[0076] Before executing step 203, the controller also needs to detect whether the BL program in the first storage area has been upgraded. This can be done by checking whether the BL program in the first storage area and the BL program in the second storage area are identical, for example, by verifying whether the hash value of the BL program in the first storage area and the hash value of the BL program in the second storage area are identical, that is, comparing the binary code of the BL program in the first storage area with the binary code of the BL program in the second storage area. When the hash values ​​of the binary code of the BL program in the first storage area and the BL program in the second storage area are identical, the controller can be triggered to set the first storage area as the running storage area and the second storage area as the backup storage area. If the hash values ​​of the binary code of the BL program in the first storage area and the BL program in the second storage area are different, it indicates that the BL program in the first storage area has been upgraded, but it is unclear whether the upgrade was successful. In this case, the controller can also verify the integrity of the BL program in the first storage area. When the verification fails, that is, the integrity is insufficient, the BL program of the first storage area can be re-flashed, or a negative response can be fed back to the upper computer. When the verification succeeds, it means that the BL program of the first storage area has been successfully upgraded, and the safe boot setting values ​​of the first storage area and the second storage area can be exchanged. The safe boot setting value is the verification basis for selecting the boot storage area when the controller is reset, that is, the safe boot setting value of the first storage area is switched to the preferred value. After the reset, the controller can use the first storage area as the running storage area to complete the steps of setting the first storage area as the running storage area and setting the second storage area as the backup storage area.

[0077] That is, the embodiment of the present application modifies the execution method of erasing memory in the reprogramming stage and adds a zone cutting operation. The process of the reprogramming stage is shown in Figure 4, step 401. Enter the programming session ($10$02); step 402. Security unlock ($27); step 403. Write fingerprint ($2E$F184); step 404. Download the flash driver (FlashDriver); step 405. Erase the memory of the first storage area ($31$01$FF00); step 406. Download the BL program / APP / Cal file; step 407. Determine whether all bytes have been downloaded, if so, execute step 408, otherwise execute step 405; step 408. Programming dependency check; step 409. Zone cutting operation.

[0078] The specific execution process of step 409 can be shown in Figure 5. Step 501: Calculate the hash value of the BL program in the first storage area and the hash value of the BL program in the second storage area; Step 502: Compare the two hash values ​​to see if they are inconsistent. If so, execute step 503; otherwise, execute step 511; Step 503: Verify the integrity of the BL program in the first storage area; Step 504: Determine whether the verification is successful. If so, execute step 505; otherwise, execute step 510; Step 505: Exchange the secure boot setting values ​​of the first storage area and the second storage area; Step 506: Determine whether the exchange is successful. If so, execute step 507; otherwise, execute step 510; Step 507: Modify the configuration of the user configuration block (UCB) and set the first storage area as the next startup operation area; Step 508: Determine whether the setting is successful. If so, execute step 509; otherwise, execute step 510; Step 509: Reply a positive response; Step 510: Reply a negative response; Step 511: Re-update the BL program in the first storage area.

[0079] Figure 6 shows a schematic diagram of swapping the secure boot setting values ​​between the first and second storage areas. Originally, the secure boot setting value for the second storage area was entry 1, and the secure boot setting value for the first storage area was entry 12. After the swap, the secure boot setting value for the second storage area is entry 12, and the secure boot setting value for the first storage area is entry 1. Each subsequent controller startup will first perform a startup verification on entry 1. If the verification passes, the first storage area will be used for startup.

[0080] Among them, the integrity check method can be that if the BL program file was flashed most recently, first check whether the format of the BL program version number is correct (used to verify that the BL program file is flashed instead of the APP or other file, and the BL program version number is fixedly stored at the starting position of the BL program code segment). If the check fails, record the BL program integrity flag BootOK_Flag (uint8) = 0 in the area, store it in EEPROM, and then reply with a negative response; if the BL program version number check passes, it means that the BL program file is flashed, and then perform integrity check on the BL program. If the signature passes, update the encrypted information identification code (cypher-based message authentication code, CMAC) value of the BL program in the area and store it in a certain position of UCB (such as entry12), and then reply with a positive response. Otherwise, record the Boot integrity flag BootOK_Flag (uint8) = 0 in the area, store it in EEPROM, and then reply with a negative response.

[0081] After switching the first storage area to the running storage area, the BL program in the second storage area currently serving as the backup area can be upgraded. When the first storage area fails, the second storage area with the latest BL program can be switched to run, thereby improving user experience.

[0082] In one example, the controller can also determine the second erase address for erasing the BL program in the second storage area based on the upgrade address in the upgrade file. The upgrade address may include the erase address corresponding to the BL program upgrade package. Since the storage area of ​​the controller is divided into a first storage area and a second storage area, when the BL program in the second storage area needs to be upgraded, the second erase address for the BL program in the second storage area can be determined based on the erase address. At this time, the controller can verify the second erase address to see if it is within the address space allocated for the BL program in the second storage area. If it is not within the address space, it indicates that the second erase address is incorrect and a negative response can be fed back to the upper computer. If the second erase address is within the address space, it indicates that the second erase address is valid and the data on the second erase address can be directly erased. Then, the data of the BL program upgrade package can be stored at the erased second erase address to complete the upgrade of the BL program in the second storage area.

[0083] The process of the controller updating the BL program in the second storage area can also refer to the process in FIG. 4 , which will not be described in detail here.

[0084] After the BL program in the second storage area is upgraded, it is also possible to verify whether the hash value of the BL program in the first storage area and the hash value of the BL program in the second storage area are the same, that is, to determine whether the BL program in the second storage area is upgraded successfully. If the verification fails, that is, the hash value of the BL program in the first storage area and the hash value of the BL program in the second storage area are different, it means that the upgrade of the BL program in the second storage area has failed and needs to be upgraded again. In this case, the step of upgrading the BL program in the second storage area according to the BL program upgrade package can be executed again.

[0085] After upgrading the BL program in the second storage area, the controller and the host computer can also execute the post-programming phase. The controller makes the controller software effective by resetting, responds to the service instructions of the host computer, completes the necessary reset work, reopens the communication between the controller and the host computer, and turns on DTC, clears DTC, and jumps the diagnostic session to restore the communication status of the controller so that the controller can be used normally.

[0086] A schematic diagram of the overall process of upgrading the BL program of the controller in an embodiment of the present application can be shown in Figure 7, step 701. The controller obtains the upgrade file; step 702. The controller upgrades the BL program, APP and Cal files in the first storage area; step 703. Detects whether the upgrade of the first storage area is successful, if so, executes step 705, otherwise executes step 704; step 704: The controller stays in the second storage area to run and re-upgrades the program in the first storage area; step 705. The controller switches the running storage area to the first storage area; step 706. The controller upgrades the BL program in the second storage area; step 707. Detects whether the upgrade of the BL program in the second storage area is successful, if so, executes step 708, otherwise executes step 706; step 708. Verifies whether the BL programs in the first storage area and the second storage area are consistent, if so, completes the upgrade, otherwise executes step 702.

[0087] In an embodiment of the present application, the BL program in the first storage area of ​​the controller, which serves as a backup storage area, is first upgraded through the BL program upgrade package in the upgrade file. After the upgrade is successful, the first storage area is set as the running storage area, and the second storage area is set as the backup storage area. When upgrading the BL program in one storage area, the BL program in another storage area can be used to provide services, thereby avoiding the controller from becoming bricked due to power outage during the BL program upgrade process, and improving the success rate of remote upgrades.

[0088] The controller upgrade method is described above. The device for executing the method is described below.

[0089] Please refer to FIG8 , which shows a controller upgrade device provided by an embodiment of the present application. The controller includes a first storage area and a second storage area, wherein the first storage area and the second storage area respectively store a boot loader (BL) program. The device 80 includes:

[0090] The processing unit 801 is configured to obtain an upgrade file, the upgrade file including a BL program upgrade package, and upgrade a BL program in a first storage area according to the BL program upgrade package, where the first storage area is a backup storage area and the second storage area is an operating storage area. When the BL program in the first storage area is successfully upgraded, the first storage area is set as the operating storage area and the second storage area is set as the backup storage area.

[0091] The processing unit 801 is configured to execute steps 201 to 203 in the method embodiment of FIG2 .

[0092] Optionally, the processing unit 801 is further configured to: upgrade the BL program in the second storage area according to the BL program upgrade package.

[0093] Optionally, the apparatus 80 further includes a transceiver unit 802, which is specifically configured to:

[0094] Receive the version number acquisition request from the host computer;

[0095] Send the base software version number of the application APP in the first storage area to the host computer according to the version number acquisition request;

[0096] When the bottom software version number belongs to the blacklist, an instruction is received from the host computer, the blacklist includes the version number corresponding to the BL program that cannot be upgraded, and the instruction instructs the APP in the first storage area to be upgraded before the BL program in the first storage area.

[0097] Optionally, the upgrade file also includes an APP upgrade package and / or a calibration Cal file upgrade package, and the processing unit 801 is further configured to:

[0098] Upgrade the APP in the first storage area according to the APP upgrade package; and / or,

[0099] The Cal file in the first storage area is updated according to the Cal file.

[0100] Optionally, the upgrade file includes an upgrade address, and the processing unit 801 is specifically configured to:

[0101] Determining a first erasing address according to the upgrade address, where the first erasing address is an address for erasing the BL of the first storage area;

[0102] Checking whether the first erase address is in the address space where the BL program in the first storage area is located;

[0103] When the verification passes, the content on the first erasure address is erased;

[0104] The data of the BL program upgrade package is stored in the first erase address.

[0105] Optionally, the processing unit 801 is specifically configured to:

[0106] determining a second erasing address according to the upgrade address, where the second erasing address is an address for erasing the BL program in the second storage area;

[0107] Checking whether the second erase address is in the address space where the BL program in the second storage area is located;

[0108] When the verification passes, the content on the second erase address is erased;

[0109] The data of the BL program upgrade software package is stored in the second erase address.

[0110] Optionally, the processing unit 801 is further configured to:

[0111] Verifying whether a hash value of the BL program in the first storage area and a hash value of the BL program in the second storage area are the same;

[0112] If they are the same, the step of setting the first storage area as the running storage area and the second storage area as the backup storage area is triggered;

[0113] If they are different, verifying the integrity of the BL program in the first storage area;

[0114] When the verification succeeds, the secure boot setting values ​​of the first storage area and the second storage area are exchanged, and the step of setting the first storage area as the running storage area and the second storage area as the backup storage area is triggered.

[0115] Optionally, the processing unit 801 is further configured to:

[0116] Verifying whether a hash value of the BL program in the first storage area and a hash value of the BL program in the second storage area are the same;

[0117] If they are different, a step of upgrading the BL program in the second storage area according to the BL program upgrade package is triggered.

[0118] Optionally, the processing unit 801 is further configured to:

[0119] The post-programming phase is executed, and the post-programming phase is used to restore the local communication state.

[0120] Please refer to FIG. 9 , which shows another controller upgrade device provided by an embodiment of the present application. The controller includes a first storage area and a second storage area, wherein the first storage area and the second storage area respectively store a boot loader (BL) program. The device 90 includes:

[0121] The transceiver unit 901 is configured to send a version number acquisition request to the controller, the version number acquisition request being used to read the base software version number of the application APP in the first storage area, receive the base software version number from the controller, and send an instruction to the controller when the base software version number belongs to a blacklist, the blacklist including version numbers corresponding to which the BL program cannot be upgraded, and the instruction instructing the APP in the first storage area to be upgraded before the BL program in the first storage area.

[0122] Optionally, the apparatus 90 further includes a processing unit 902, and the processing unit 902 is specifically configured to:

[0123] The post-programming phase is executed, and the post-programming phase is used to restore the local communication state.

[0124] FIG10 shows a possible logical structure diagram of a computer device 100 provided in an embodiment of the present application. The computer device 100 includes: a processor 1001, a communication interface 1002, a storage system 1003, and a bus 1004. The processor 1001, the communication interface 1002, and the storage system 1003 are interconnected via the bus 1004. In an embodiment of the present application, the processor 1001 is used to control and manage the actions of the computer device 100. For example, the processor 1001 is used to execute the steps performed by the controller in the method embodiment of FIG2. The communication interface 1002 is used to support communication between the computer device 100. The storage system 1003 is used to store program code and data of the computer device 100.

[0125] The processor 1001 may be a central processing unit (CPU), a general-purpose processor (GPOR), a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic device (PLD), a transistor logic device (TLD), a hardware component, or any combination thereof. It may implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. The processor 1001 may also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, and the like. The bus 1004 may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, for example. Buses may be classified as address buses, data buses, control buses, and the like. For ease of illustration, FIG. 10 shows only one thick line, but this does not imply that there is only one bus or only one type of bus.

[0126] The transceiver unit 802 in the apparatus 80 is equivalent to the communication interface 1002 in the computer device 100 , and the processing unit 801 in the apparatus 80 is equivalent to the processor 1001 in the computer device 100 .

[0127] The computer device 100 of this embodiment may correspond to the controller in the method embodiment of FIG. 2 . The communication interface 1002 in the computer device 100 may implement the functions and / or various steps of the controller in the method embodiment of FIG. 2 . For the sake of brevity, they will not be described in detail here.

[0128] Figure 11 shows a possible logical structure diagram of a computer device 110 provided in an embodiment of the present application. The computer device 110 includes: a processor 1101, a communication interface 1102, a storage system 1103 and a bus 1104. The processor 1101, the communication interface 1102 and the storage system 1103 are interconnected via the bus 1104. In an embodiment of the present application, the processor 1101 is used to control and manage the actions of the computer device 110. For example, the processor 1101 is used to execute the steps performed by the host computer in the method embodiment of Figure 2. The communication interface 1102 is used to support the computer device 110 in communication. The storage system 1103 is used to store the program code and data of the computer device 110.

[0129] The processor 1101 may be a central processing unit (CPU), a general-purpose processor (GPOR), a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic device (PLD), a transistor logic device (TLD), a hardware component, or any combination thereof. It may implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. The processor 1101 may also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, and the like. The bus 1104 may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, for example. Buses may be classified as address buses, data buses, control buses, and the like. For ease of illustration, FIG. 11 shows only one thick line, but this does not imply that there is only one bus or only one type of bus.

[0130] The transceiver unit 901 in the apparatus 90 is equivalent to the communication interface 1102 in the computer device 110 , and the processing unit 902 in the apparatus 90 is equivalent to the processor 1101 in the computer device 110 .

[0131] The computer device 110 of this embodiment may correspond to the host computer in the method embodiment of FIG. 2 . The communication interface 1102 in the computer device 110 may implement the functions and / or various steps of the host computer in the method embodiment of FIG. 2 . For the sake of brevity, they will not be described in detail here.

[0132] It should be understood that the division of units in the above device is merely a division of logical functions. In actual implementation, they can be fully or partially integrated into one physical entity, or they can be physically separated. Moreover, the units in the device can all be implemented in the form of software called through processing elements; or they can all be implemented in the form of hardware; or some units can be implemented in the form of software called through processing elements, and some units can be implemented in the form of hardware. For example, each unit can be a separately established processing element, or it can be integrated into a certain chip of the device. In addition, it can also be stored in the memory in the form of a program, called by a certain processing element of the device and perform the function of the unit. In addition, all or part of these units can be integrated together, or they can be implemented independently. The processing element described here can also be a processor, which can be an integrated circuit with signal processing capabilities. In the implementation process, each step of the above method or each unit above can be implemented by the integrated logic circuit of the hardware in the processor element or in the form of software called through the processing element.

[0133] In one example, the unit in any of the above devices may be one or more integrated circuits configured to implement the above method, such as one or more application specific integrated circuits (ASICs), or one or more digital singnal processors (DSPs), or one or more field programmable gate arrays (FPGAs), or a combination of at least two of these integrated circuit forms. For another example, when the unit in the device can be implemented in the form of a processing element scheduler, the processing element can be a general-purpose processor, such as a central processing unit (CPU) or other processor that can call a program. For another example, these units can be integrated together and implemented in the form of a system-on-a-chip (SOC).

[0134] In another embodiment of the present application, a computer-readable storage medium is provided, in which computer-executable instructions are stored. When the processor of the device executes the computer-executable instructions, the device executes the method executed by the main control node in the above method embodiment.

[0135] In another embodiment of the present application, a computer program product is provided, the computer program product including computer-executable instructions stored in a computer-readable storage medium. When a processor of a device executes the computer-executable instructions, the device performs the method performed by the master control node in the above method embodiment.

[0136] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0137] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.

[0138] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0139] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0140] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

Claims

1. A controller upgrade method, characterized in that: The controller includes a first storage area and a second storage area, wherein a boot loader (BL) program is stored in the first storage area and the second storage area respectively. The method includes: Obtaining an upgrade file, wherein the upgrade file includes a BL program upgrade package; Upgrading the BL program in the first storage area according to the BL program upgrade package, where the first storage area is a backup storage area and the second storage area is a running storage area; When the BL program in the first storage area is successfully upgraded, the first storage area is set as a running storage area, and the second storage area is set as a backup storage area.

2. The method according to claim 1, characterized in that After setting the first storage area as a running storage area and setting the second storage area as a backup storage area, the method further includes: The BL program in the second storage area is upgraded according to the BL program upgrade package.

3. The method according to claim 1 or 2, characterized in that Before upgrading the BL program in the first storage area according to the BL program upgrade package, the method further includes: Receive the version number acquisition request from the host computer; Sending the base software version number of the application APP in the first storage area to the host computer according to the version number acquisition request; When the bottom software version number belongs to the blacklist, an instruction is received from the host computer, the blacklist includes version numbers corresponding to which the BL program cannot be upgraded, and the instruction instructs the APP in the first storage area to be upgraded before the BL program in the first storage area.

4. The method according to any one of claims 1 to 3, characterized in that The upgrade file also includes an APP upgrade package and / or a calibration Cal file upgrade package. Before setting the first storage area as a running storage area and setting the second storage area as a backup storage area, the method further includes: Upgrading the APP in the first storage area according to the APP upgrade package; and / or, The Cal file in the first storage area is updated according to the Cal file.

5. The method according to any one of claims 1 to 4, characterized in that The upgrade file includes an upgrade address, and the upgrading of the BL program in the first storage area according to the BL program upgrade package includes: determining a first erasing address according to the upgrade address, where the first erasing address is an address for erasing the BL of the first storage area; checking whether the first erase address is in the address space where the BL program of the first storage area is located; When the verification passes, erasing the content at the first erasure address; The data of the BL program upgrade package is stored in the first erasure address.

6. The method according to claim 5, characterized in that The step of upgrading the BL program in the second storage area according to the BL program upgrade package includes: determining a second erasure address according to the upgrade address, where the second erasure address is an address for erasing the BL program of the second storage area; checking whether the second erase address is in the address space where the BL program of the second storage area is located; When the verification passes, erasing the content at the second erasure address; The data of the BL program upgrade software package is stored in the second erasure address.

7. The method according to any one of claims 1 to 6, characterized in that Before setting the first storage area as a running storage area and setting the second storage area as a backup storage area, the method further includes: verifying whether a hash value of the BL program in the first storage area is the same as a hash value of the BL program in the second storage area; If they are the same, the step of setting the first storage area as the running storage area and the second storage area as the backup storage area is triggered; If they are different, verifying the integrity of the BL program in the first storage area; When the verification succeeds, the secure boot setting values ​​of the first storage area and the second storage area are exchanged, and the step of setting the first storage area as the running storage area and the second storage area as the backup storage area is triggered.

8. The method according to claim 2, characterized in that After upgrading the BL program in the second storage area according to the BL program upgrade package, the method further includes: verifying whether a hash value of the BL program in the first storage area is the same as a hash value of the BL program in the second storage area; If they are different, the step of upgrading the BL program in the second storage area according to the BL program upgrade package is triggered.

9. The method according to claim 2 or 8, characterized in that After upgrading the BL program in the second storage area according to the BL program upgrade package, the method further includes: A post-programming phase is executed, wherein the post-programming phase is used to restore a local communication state.

10. A controller upgrade method, characterized in that: The controller includes a first storage area and a second storage area, wherein a boot loader (BL) program is stored in the first storage area and the second storage area respectively. The method includes: Sending a version number acquisition request to the controller, wherein the version number acquisition request is used to read the base software version number of the application APP in the first storage area; receiving the bottom software version number from the controller; When the bottom software version number belongs to the blacklist, an instruction is sent to the controller, the blacklist includes version numbers corresponding to BL programs that cannot be upgraded, and the instruction instructs the APP in the first storage area to be upgraded before the BL program in the first storage area.

11. The method according to claim 10, characterized in that The method further comprises: A post-programming phase is executed, wherein the post-programming phase is used to restore a local communication state.

12. A controller upgrade device, characterized in that: The controller includes a first storage area and a second storage area, wherein a boot loader BL program is stored in the first storage area and the second storage area respectively. The device includes: The processing unit is configured to obtain an upgrade file, the upgrade file including a BL program upgrade package, and upgrade the BL program in the first storage area according to the BL program upgrade package, wherein the first storage area is a backup storage area and the second storage area is a running storage area. When the BL program in the first storage area is successfully upgraded, the first storage area is set as the running storage area and the second storage area is set as the backup storage area.

13. The device according to claim 12, characterized in that The processing unit is further configured to: The BL program in the second storage area is upgraded according to the BL program upgrade package.

14. The device according to claim 12 or 13, characterized in that The device further includes a transceiver unit, which is specifically configured to: Receive the version number acquisition request from the host computer; Sending the base software version number of the application APP in the first storage area to the host computer according to the version number acquisition request; When the bottom software version number belongs to the blacklist, an instruction is received from the host computer, the blacklist includes version numbers corresponding to which the BL program cannot be upgraded, and the instruction instructs the APP in the first storage area to be upgraded before the BL program in the first storage area.

15. The device according to any one of claims 12 to 14, characterized in that The upgrade file also includes an APP upgrade package and / or a calibration Cal file upgrade package, and the processing unit is further configured to: Upgrading the APP in the first storage area according to the APP upgrade package; and / or, The Cal file in the first storage area is updated according to the Cal file.

16. The device according to any one of claims 12 to 15, characterized in that The upgrade file includes an upgrade address, and the processing unit is specifically configured to: determining a first erasing address according to the upgrade address, where the first erasing address is an address for erasing the BL of the first storage area; checking whether the first erase address is in the address space where the BL program of the first storage area is located; When the verification passes, erasing the content at the first erasure address; The data of the BL program upgrade package is stored in the first erasure address.

17. The device according to claim 16, characterized in that The processing unit is specifically configured to: determining a second erasure address according to the upgrade address, where the second erasure address is an address for erasing the BL program of the second storage area; checking whether the second erase address is in the address space where the BL program of the second storage area is located; When the verification passes, erasing the content at the second erasure address; The data of the BL program upgrade software package is stored in the second erasure address.

18. The device according to any one of claims 12 to 17, characterized in that The processing unit is further configured to: verifying whether a hash value of the BL program in the first storage area is the same as a hash value of the BL program in the second storage area; If they are the same, the step of setting the first storage area as the running storage area and the second storage area as the backup storage area is triggered; If they are different, verifying the integrity of the BL program in the first storage area; When the verification succeeds, the secure boot setting values ​​of the first storage area and the second storage area are exchanged, and the step of setting the first storage area as the running storage area and the second storage area as the backup storage area is triggered.

19. The device according to claim 13, characterized in that The processing unit is further configured to: verifying whether a hash value of the BL program in the first storage area is the same as a hash value of the BL program in the second storage area; If they are different, the step of upgrading the BL program in the second storage area according to the BL program upgrade package is triggered.

20. The device according to claim 13 or 19, characterized in that The processing unit is further configured to: A post-programming phase is executed, wherein the post-programming phase is used to restore a local communication state.

21. A controller upgrade device, characterized in that: The controller includes a first storage area and a second storage area, wherein a boot loader BL program is stored in the first storage area and the second storage area respectively. The device includes: The transceiver unit is configured to send a version number acquisition request to the controller, the version number acquisition request being used to read the base software version number of the application APP in the first storage area, receive the base software version number from the controller, and when the base software version number belongs to a blacklist, send an instruction to the controller, the blacklist including version numbers corresponding to which the BL program cannot be upgraded, the instruction instructing the APP in the first storage area to be upgraded before the BL program in the first storage area.

22. The device according to claim 21, characterized in that The device further includes a processing unit, which is specifically configured to: A post-programming phase is executed, wherein the post-programming phase is used to restore a local communication state.

23. A computer device, characterized in that: include: a processor coupled to the memory, The processor is configured to execute instructions stored in the memory, so that the computer device performs the method according to any one of claims 1 to 9.

24. A computer device, characterized in that: include: a processor coupled to the memory, The processor is configured to execute instructions stored in the memory, so that the computer device performs the method according to any one of claims 10 to 11.

25. A computer-readable storage medium, characterized in that The computer-readable storage medium stores instructions, and when the instructions are executed by a processor, the method according to any one of claims 1 to 11 is implemented.

26. A computer program product, characterized in that The computer program product includes computer program code, and is characterized in that when the computer program code is run on a computer, the method according to any one of claims 1 to 11 is implemented.

Citation Information

Cited By

  • MCU (Microprogrammed Control Unit) safe starting method integrating function safety

    CN120891769A