Braking system double-MCU firmware upgrading method and system based on SPI communication

By adopting SPI communication-based methods in the dual MCU braking system, a set of upper computers and diagnostic IDs are used to efficiently streamline firmware upgrades and auxiliary MCU application rollbacks are solved, and the cumbersome and insufficient security problems in traditional methods are ensured, ensuring the safety of the vehicle when the upper computer fails to write.

CN120215992AActive Publication Date: 2025-06-27GELUBO TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510686317.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-27
Publication Date
2025-06-27
Estimated Expiration
2045-05-27

AI Technical Summary

Technical Problem

The traditional dual MCU braking system firmware update method requires two sets of upper computer software and multiple diagnostic IDs. The process is cumbersome and does not support auxiliary MCU application rollback, resulting in the impact of vehicle safety when the upper computer flash fails.

Method used

Using a SPI communication method, a set of host computers and diagnostic IDs is used to update the software of the secondary MCUs by using SPI communication between the main and auxiliary MCUs, and the backup and rollback of the secondary MCU applications are used using the Flash area of ​​the main MCU.

Benefits of technology

It realizes an efficient and streamlined dual MCU firmware upgrade process, supports auxiliary MCU application rollback, ensures vehicle safety when the upper computer fails to write, and is compatible with the diagnostic flush system of a single MCU.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120215992A_ABST
    Figure CN120215992A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of vehicle braking systems, in particular to a braking system double-MCU firmware upgrading method and system based on SPI communication, the system comprises a main MCU, an auxiliary MCU, an upper computer and a vehicle CAN bus, four partitions A, B, A1 and B1 are established in a Flash area of the main MCU, the A partition and the B partition serve as the A partition and the B partition of the main MCU respectively, and the A1 partition and the B1 partition serve as the A1 partition and the B1 partition of the auxiliary MCU respectively; according to the diagnosis flashing system, software updating of the auxiliary MCU is carried out by relying on a vehicle CAN bus, adopting a set of upper computer and diagnosis ID and relying on SPI communication between the main MCU and the auxiliary MCU, meanwhile, application program backup of the auxiliary MCU is carried out by using a Flash area of the main MCU, the operation of application program rollback of the auxiliary MCU is achieved, it is guaranteed that the vehicle is safe, efficient and simplified when flashing of the upper computer fails, and the diagnosis flashing system is compatible with a single MCU.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of vehicle braking systems, and in particular to a method and system for dual-MCU firmware upgrade of a braking system based on SPI communication. Background Art

[0002] A microcontroller (hereinafter referred to as MCU) is the core of an embedded system. With the wide application of embedded systems in fields such as automotive electronics, the multi-microcontroller unit (Multi-MCU) architecture has become the preferred solution for critical systems due to its high reliability. In the braking system of the automotive electronics field, the integrated braking system has been increasingly widely used due to its multiple functions, small volume, and high performance. The integrated braking system has multiple functions, such as anti-lock braking, electronic brake force distribution, electronic parking, etc. To meet the requirements of functional safety, the current electronic parking function of the integrated braking system relies on a dual-MCU control unit, thus having a redundant backup function. The dual-MCU control unit includes two MCUs (hereinafter referred to as the main MCU and the auxiliary MCU). The main MCU has the electronic parking function and other braking functions, while the auxiliary MCU only has the electronic parking function. If any one of the main and auxiliary MCUs fails later, the electronic parking function can still be ensured not to fail.

[0003] Because the integrated braking system has a main and an auxiliary MCU, the firmware of the dual MCUs generally needs to be updated during software updates. The traditional method is to rely on the vehicle CAN bus, stipulate two sets of diagnostic IDs, and update the main and auxiliary MCUs respectively. This method generally requires the vehicle OEM to develop two sets of upper computer software for the braking system, which is cumbersome and time-consuming; at the same time, because the Flash area (non-volatile storage area) of the auxiliary MCU is generally small, it does not support A and B partitions. Once the upper computer loses power during the flashing process, the application program rollback is not supported, and the upper computer needs to be re-flashed to work. Summary of the Invention

[0004] The object of the present invention is to provide a method and system for dual-MCU firmware upgrade of a braking system based on SPI communication, which relies on the vehicle CAN bus, uses a set of upper computer and diagnostic ID, relies on the SPI communication between the main and auxiliary MCUs to update the software of the auxiliary MCU, and at the same time uses the Flash area of the main MCU to back up the application program of the auxiliary MCU, realizes the operation of the auxiliary MCU application program rollback, ensures the vehicle safety when the upper computer flashing fails, is efficient and streamlined, and is compatible with the diagnostic flashing system of a single MCU.

[0005] To achieve the above object, the present invention provides a method for dual-MCU firmware upgrade of a braking system based on SPI communication, including the following steps: S1. Establish four partitions A, B, A1, and B1 in the Flash area of the main MCU. Partition A and partition B serve as the A partition and B partition of the main MCU respectively, and partition A1 and partition B1 serve as the A1 partition and B1 partition of the auxiliary MCU respectively; S2. Use a programmer to flash the initial application program in the corresponding Flash areas of the main MCU and the auxiliary MCU. Flash the initial main MCU application program in partition A of the main MCU, and flash the initial auxiliary MCU application program in partition A1 of the main MCU and the Flash area of the auxiliary MCU itself; S3. Perform pre-programming for CAN network preparation before flashing; S4. Integrate the application software of the main MCU and the auxiliary MCU into an update package. Distinguish the firmware areas of the main MCU and the auxiliary MCU by address. The host computer transfers the flash driver FlashDriver to the RAM area of the main MCU, and simultaneously synchronously transfers it to the RAM area of the auxiliary MCU using SPI communication; S5. Erase the application program in the current B area of the main MCU, the application program in the backup B1 area of the auxiliary MCU, and the application program in the Flash area of the auxiliary MCU itself; S6. Transfer the main MCU application software to area B of the main MCU; S7. Transfer the application software of the auxiliary MCU to area B1 of the main MCU. While transferring to area B1, synchronously transfer the application software of the auxiliary MCU to the Flash area of the auxiliary MCU itself using SPI communication; S8. Perform post-programming to restore the vehicle CAN network and the function of recording diagnostic trouble codes; S9. The main MCU restarts and jumps to run the application program in its own area B, and the auxiliary MCU restarts to run the application program in its own Flash area. Area B1 of the main MCU is also updated and completed for rollback flashing of the auxiliary MCU in case of a flash write failure next time.

[0006] Preferably, in step S2, when the main MCU runs, it jumps to run the application program in partition A through its own bootloader, and the auxiliary MCU runs the application program in its own Flash area.

[0007] Preferably, the SPI communication mechanism is used to transfer FlashDriver and the application program of the auxiliary MCU. When SPI data is transmitted, the SPI data is encapsulated into larger encapsulated data. The encapsulated data consists of an identification group, a CRC check code, and SPI data. The identification group is used to ensure the continuity of data transmission, and the CRC check code is used to ensure the integrity of data transmission. Several SPI communications form a data packet, and receiving or sending a complete data packet is one data exchange.

[0008] Preferably, the identification group includes a normal application program interaction identifier and a program flashing identifier, which are respectively used to distinguish SPI communication frame categories and ensure the continuity identification of data.

[0009] Preferably, the same CRC check algorithm is specified between the main MCU and the secondary MCU for the CRC check code. The CRC check algorithm predefines an array, and uses the received SPI data to perform relevant operations with the data corresponding to the identifier position in the predefined array, and ensures that the calculated check code with the same length as the CRC check code is output. The calculated check code is compared with the CRC check code. If the check codes are the same, the data transmitted by this frame is used; otherwise, it is determined to be invalid.

[0010] Preferably, the data packet transmits flashing data. During flashing transmission, the data packet is divided into an instruction byte and a reserved byte. The instruction byte completely transfers the flashing instruction of the host computer received by the main MCU to the secondary MCU. The instruction byte is responsible for transmitting the diagnostic ID and the data field content of the CAN standard frame. After the secondary MCU receives the data packet and completes internal parsing and processing, it feeds back the CAN diagnostic frame that conforms to the vehicle manufacturer's flashing specification to the main MCU in the form of an SPI data packet again. After the main MCU finishes parsing, it feeds back to the host computer through the CAN bus to complete the diagnostic request - feedback operation during a flashing process. Repeat the above process until the entire flashing process is completed.

[0011] Preferably, the rollback flashing is used to perform rollback flashing of the secondary MCU by the main MCU in the case of an unexpected sudden interruption of the host computer interaction during the flashing process. A secondary MCU flashing failure flag bit is set in the BootLoader of the main MCU. When an unexpected power failure of the host computer occurs during data transmission, and at this time the braking system is still powered on and has not been restarted, the secondary MCU flashing failure flag bit is set. At this time, the Bootloader of the main MCU autonomously uses the secondary MCU application program stored in the Flash area of the main MCU for rollback refreshing. At this time, the SPI communication mechanism and the flashing process are the same as those during normal use of the host computer for flashing communication. After waiting for the rollback refreshing to be completed, the main MCU and the secondary MCU are automatically reset and run the flashed program.

[0012] A dual - MCU firmware upgrade system for a braking system based on SPI communication, including a flasher, a host computer, a vehicle CAN bus, a main MCU, and a secondary MCU; The flasher is used to flash the initial application program in the corresponding Flash areas of the main MCU and the secondary MCU; The main MCU is used to flash the application program in its own Flash area, back up the application program in the Flash area of the secondary MCU, and synchronously transmit data with the secondary MCU through SPI communication; A secondary MCU, which is used to synchronously transmit data with the primary MCU through SPI communication; A host computer, which is used to execute the flashing process and monitor the flashing process; A vehicle CAN bus, which is used to connect the host computer and the primary MCU to ensure data transmission between the primary MCU and the host computer.

[0013] Therefore, the present invention adopts the above-mentioned dual-MCU firmware upgrade method and system for a braking system based on SPI communication, realizes software update of the secondary MCU relying on the vehicle CAN bus, using a set of host computer and diagnostic ID, and relying on SPI communication between the primary and secondary MCUs, and at the same time uses the Flash area of the primary MCU to back up the application program of the secondary MCU, realizes the operation of rolling back the application program of the secondary MCU, ensures the vehicle safety when the host computer flashing fails, is efficient and streamlined, and is compatible with the diagnostic flashing system of a single MCU.

[0014] The present invention has the following beneficial effects: 1. Only one set of host computer and diagnostic ID is required. Compared with the traditional dual-MCU diagnostic flashing system that requires two sets of host computers and diagnostic IDs, it is more efficient and streamlined, and can also be compatible with the diagnostic flashing system of a single MCU.

[0015] 2. Realizes the operation of rolling back the application program of the secondary MCU, ensuring the vehicle safety when the host computer flashing fails. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 It is a flow chart of the dual-MCU firmware upgrade method for a braking system based on SPI communication according to the present invention; Figure 2 It is a structure diagram of a single SPI transmission and data packet under the flashing communication provided by the dual-MCU firmware upgrade method for a braking system based on SPI communication according to the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0017] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. The following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed present invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0018] Embodiment As Figure 1 shown, the dual-MCU firmware upgrade method for a braking system based on SPI communication includes the following steps: S1. Establish four partitions A, B, A1, and B1 in the Flash area of the main MCU. Partition A and partition B are respectively used as the A partition and B partition of the main MCU, and partition A1 and partition B1 are respectively used as the A1 partition and B1 partition of the auxiliary MCU; S2. Use a programmer to flash the initial application program in the corresponding Flash areas of the main MCU and the auxiliary MCU. Flash the initial main MCU application program in partition A of the main MCU, and flash the initial auxiliary MCU application program in partition A1 of the main MCU and the Flash area of the auxiliary MCU itself; S3. Perform pre-programming to prepare the CAN network before flashing; S4. Integrate the application software of the main MCU and the auxiliary MCU into an update package. Distinguish the firmware areas of the main MCU and the auxiliary MCU by address. The host computer transfers the flash driver FlashDriver to the RAM area of the main MCU, and at the same time synchronously transfers it to the RAM area of the auxiliary MCU using SPI communication; S5. Erase the application program in the current B area of the main MCU, the application program in the backup B1 area of the auxiliary MCU, and the application program in the Flash area of the auxiliary MCU itself; S6. Transfer the main MCU application software to area B of the main MCU; S7. Transfer the application software of the auxiliary MCU to area B1 of the main MCU. When transferring to area B1, synchronously transfer the application software of the auxiliary MCU to the Flash area of the auxiliary MCU itself using SPI communication; S8. Perform post-programming to restore the vehicle CAN network and the function of recording diagnostic trouble codes; S9. The main MCU restarts and jumps to run the application program in its own area B, and the auxiliary MCU restarts to run the application program in its own Flash area. Area B1 of the main MCU is also updated and completed, and is used for the rollback flashing of the auxiliary MCU in case of a flashing failure next time.

[0019] In step S2, when the main MCU runs, it jumps to the application program in partition A through its own bootloader, and the auxiliary MCU runs the application program in its own Flash area.

[0020] The SPI communication between the main MCU and the auxiliary MCU transmits application data when the application program works normally. Therefore, a new SPI communication form needs to be established during the flashing transmission to transmit the FlashDriver and the auxiliary MCU application program. When each SPI data communication transmits 8 bits, for the integrity and continuity of the data, it is encapsulated into 16-bit encapsulated data for transmission. The structure diagram is as follows Figure 2As shown in the single - transmission frame structure. The first 8 bits consist of an identification group (5 bits) and a CRC check code (3 bits), and the following 8 bits are the SPI data to be transmitted. The identification group is used to ensure the continuity of data transmission, and the CRC check code is used to ensure the integrity of data transmission. Several SPI communications form a data packet, and receiving or sending a complete data packet is one data exchange. When a data packet consists of n 16 - bit encapsulated data and is managed by a 5 - bit identification group, the maximum value of n is 31. When a data contains 20 16 - bit encapsulated data, a data contains 20 bytes of programming data. List the first 20 (range 0 - 19) of the identification group as the normal application program interaction identifier, and the last 10 (range 20 - 29) as the program programming identifier. In this way, it can not only distinguish the SPI communication frame category but also achieve the continuity identification of data.

[0021] The CRC check code stipulates the same CRC check algorithm between the main and auxiliary MCUs. Because the normal application program data and programming data share the SPI communication transmission channel and the CRC check algorithm, an 8 - bit array with a size of 20 is defined to correspond to the 20 - byte programming data of a data packet for CRC check. Perform relevant operations (such as if the identifier is 29, it is the 10th data in the array, because the program programming identifier range is 20 - 29, so the identifier 29 corresponds to the 10th data in the array; because the normal application program interaction identifier range is 0 - 19, so the identifier 9 also corresponds to the 10th data in the array) between the received 8 - bit data and the data corresponding to the identifier position in the pre - defined 8 - bit array, and ensure that the calculated check code with an output length of 3 bits is obtained. Finally, compare this check code with the received CRC check code. Only when the calculated check code calculated by the receiving party using the 8 - bit data area is the same as the transmitted CRC check code can the data transmitted by this frame be used, otherwise it is determined to be invalid.

[0022] On the other hand, during programming transmission, a data packet transmits 20 bytes of programming data. During programming transmission, the first 10 bytes of the programming data packet are used as instruction bytes, and the last 10 bytes are reserved. The first 10 bytes of the programming data packet should completely transfer the programming instruction from the host computer received by the main MCU to the auxiliary MCU. Transmit the diagnostic ID in the first 2 bytes and the data field content of the CAN standard frame in the following 8 bytes. The SPI single - transmission and data - packet structure diagram under programming communication is as Figure 2As shown in the figure. After receiving the SPI data packet for flashing transmission and completing internal parsing and processing, the slave MCU feeds back the CAN diagnostic frame that complies with the OEM flashing specification to the master MCU in the form of an SPI data packet again. After the master MCU completes the parsing, it feeds back to the flashing host computer through the CAN bus, completing the diagnostic request - feedback operation during one flashing process. Repeat the above process until the entire flashing process is completed.

[0023] When the flashing of the master MCU program is suddenly interrupted, due to the existence of partitions A and B in the master MCU, it will automatically restart; when the flashing of the slave MCU program is suddenly interrupted, the rollback flashing mechanism of the slave MCU needs to be applied. The slave MCU flashing failure flag is set in the BootLoader of the master MCU. At this time, the braking system is still powered on and no restart operation has been performed. Set the slave MCU flashing failure flag. At this time, the Bootloader of the master MCU independently uses the slave MCU application program sealed in the Flash area of the master MCU for rollback refreshing. At this time, the SPI communication mechanism and the flashing process are the same as when using the host computer for flashing communication normally. After waiting for the rollback refreshing to be completed, the master and slave MCUs automatically reset and restart, and run the program after flashing. When the rollback refreshing of the slave MCU fails repeatedly twice, the master MCU needs to push the relevant function failure of the slave MCU to the vehicle, such as the failure related to the vehicle electronic parking function.

[0024] A dual-MCU firmware upgrade system for a braking system based on SPI communication, including a flasher, a host computer, a vehicle CAN bus, a master MCU, and a slave MCU; The flasher is used to flash the initial application program in the corresponding Flash areas of the master MCU and the slave MCU; The master MCU is used to flash the application program in its own Flash area, back up the application program in the Flash area of the slave MCU, and synchronously transmit data with the slave MCU through SPI communication; The slave MCU is used to synchronously transmit data with the master MCU through SPI communication; The host computer is used to execute the flashing process and monitor the flashing process; The vehicle CAN bus is used to connect the host computer and the master MCU to ensure data transmission between the master MCU and the host computer.

[0025] Therefore, the present invention adopts the above-mentioned dual-MCU firmware upgrade method and system for a braking system based on SPI communication, realizes software update of the slave MCU relying on the vehicle CAN bus, using a set of host computer and diagnostic ID, relying on the SPI communication between the master and slave MCUs, and at the same time uses the Flash area of the master MCU to back up the application program of the slave MCU, realizes the operation of rolling back the application program of the slave MCU, ensures the vehicle safety when the host computer flashing fails, is efficient and concise, and is compatible with the diagnostic flashing system of a single MCU.

[0026] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that they can still modify or equivalently replace the technical solutions of the present invention, and these modifications or equivalent replacements do not enable the modified technical solutions to deviate from the spirit and scope of the technical solutions of the present invention.

Claims

1. A method for dual MCU firmware upgrade of a braking system based on SPI communication, characterized in that: It includes the following steps: S1. Establish four partitions A, B, A1, and B1 in the Flash area of the main MCU. Partition A and partition B are respectively used as partition A and partition B of the main MCU, and partition A1 and partition B1 are respectively used as partition A1 and partition B1 of the secondary MCU; S2. Use a programmer to flash the initial application programs in the corresponding Flash areas of the main MCU and the secondary MCU. Flash the initial main MCU application program in partition A of the main MCU, and flash the initial secondary MCU application program in partition A1 of the main MCU and the Flash area of the secondary MCU itself; S3. Perform pre-programming to prepare the CAN network before flashing; S4. Integrate the application software of the main MCU and the secondary MCU into an update package. Distinguish the firmware areas of the main MCU and the secondary MCU by address. The host computer transmits the flash driver FlashDriver to the RAM area of the main MCU, and at the same time synchronously transmits it to the RAM area of the secondary MCU through SPI communication; S5. Erase the application program in the current B area of the main MCU, the application program in the backup B1 area of the secondary MCU, and the application program in the Flash area of the secondary MCU itself; S6. Transmit the main MCU application software to area B of the main MCU; S7. Transmit the application software of the secondary MCU to area B1 of the main MCU. While transmitting to area B1, synchronously transmit the application software of the secondary MCU to the Flash area of the secondary MCU itself through SPI communication; S8. Perform post-programming to restore the vehicle CAN network and the function of recording diagnostic trouble codes; S9. The main MCU restarts and jumps to run the application program in its own area B, and the secondary MCU restarts and runs the application program in its own Flash area. Area B1 of the main MCU is also updated and is used for the rollback flashing of the secondary MCU in case of a flashing failure next time.

2. The method for dual-MCU firmware upgrade of the braking system based on SPI communication according to claim 1, characterized in that: In step S2, when the main MCU runs, it jumps to run the application program in partition A through its own bootloader, and the secondary MCU runs the application program in its own Flash area.

3. The method for dual MCU firmware upgrade of the braking system based on SPI communication according to claim 1, characterized in that: The SPI communication mechanism is used to transmit the FlashDriver and the secondary MCU application program. When SPI data is transmitted, the SPI data is encapsulated into larger encapsulated data. The encapsulated data consists of an identification group, a CRC check code, and SPI data. The identification group is used to ensure the continuity of data transmission, and the CRC check code is used to ensure the integrity of data transmission. Several SPI communications form a data packet, and receiving or sending a complete data packet is regarded as one data exchange.

4. The method for dual-MCU firmware upgrade of the braking system based on SPI communication according to claim 3, wherein: The identification group includes a normal application program interaction identifier and a program flashing identifier, which are respectively used to distinguish the SPI communication frame category and ensure the continuity identification of data.

5. The method for dual MCU firmware upgrade of the braking system based on SPI communication according to claim 3, characterized in that: The CRC check code stipulates the same CRC check algorithm between the main MCU and the auxiliary MCU. The CRC check algorithm predefines an array, performs relevant operations on the received SPI data and the data corresponding to the identifier position in the pre-defined array, and ensures that the calculated check code with the same length as the CRC check code is output. The calculated check code is compared with the CRC check code. If the check codes are the same, the data transmitted in this frame is used; otherwise, it is determined to be invalid.

6. The method for dual MCU firmware upgrade of the braking system based on SPI communication according to claim 3, wherein: The data packet transmits the flashing data. During the flashing transmission, the data packet is divided into an instruction byte and a reserved byte. The instruction byte completely transmits the flashing instruction from the host computer received by the main MCU to the auxiliary MCU. The instruction byte is responsible for transmitting the diagnostic ID and the data field content of the CAN standard frame. After the auxiliary MCU receives the data packet and completes the internal parsing process, it feedbacks the CAN diagnostic frame that conforms to the vehicle manufacturer's flashing specification to the main MCU in the form of an SPI data packet again. After the main MCU completes the parsing, it feedbacks to the host computer through the CAN bus to complete the diagnostic request - feedback operation during a flashing process. Repeat the above process until the entire flashing process is completed.

7. The method for dual-MCU firmware upgrade of a braking system based on SPI communication according to claim 1, wherein: The rollback flashing is used to perform the rollback flashing of the auxiliary MCU by the main MCU in the case of an unexpected sudden interruption in the interaction with the host computer during the flashing process. A flashing failure flag bit for the auxiliary MCU is set in the BootLoader of the main MCU. When an unexpected power failure of the host computer occurs during data transmission, and at this time the braking system is still powered on and no restart operation has been performed, the flashing failure flag bit for the auxiliary MCU is set. At this time, the Bootloader of the main MCU independently uses the auxiliary MCU application program sealed in the Flash area of the main MCU to perform rollback flashing. At this time, the SPI communication mechanism and the flashing process are the same as those during normal flashing communication using the host computer. After waiting for the rollback flashing to be completed, the main MCU and the auxiliary MCU are automatically reset and run the program after flashing.

8. A dual-MCU firmware upgrade system for a braking system based on SPI communication, which adopts the method for upgrading the firmware of the dual-MCUs of the braking system based on SPI communication according to any one of the above claims 1-7, characterized in that: It includes a flasher, a host computer, a vehicle CAN bus, a main MCU, and an auxiliary MCU; The flasher is used to flash the initial application program in the corresponding Flash areas of the main MCU and the auxiliary MCU; The main MCU is used to flash the application program in its own Flash area, back up the application program in the Flash area of the auxiliary MCU, and synchronously transmit data with the auxiliary MCU through SPI communication; The auxiliary MCU is used to synchronously transmit data with the main MCU through SPI communication; The host computer is used to execute the flashing process and monitor the flashing process; The vehicle CAN bus is used to connect the host computer and the main MCU to ensure data transmission between the main MCU and the host computer.

Citation Information

Patent Citations

  • Vehicle onboard double-control-chip system and auxiliary control chip program update method therefor

    CN105426198A

  • Double-MCU system upgrading method, electronic equipment and storage medium

    CN116954658A

  • Security controller upgrading method and system

    CN118642738A

  • Method, device and equipment for upgrading switch firmware based on MCU (Microprogrammed Control Unit) and medium

    CN119149078A