Method and device for upgrading system firmware at AFDX (Avionics Full Duplex Switched Ethernet) end

Through AFDX virtual link and DMA technology, the AFDX side system firmware is efficient, reliable, and no disassembly upgraded, solving the problems of long upgrade time and dependence on hosts in the existing technology, ensuring the reliability and flexibility of the upgrade process.

CN120378304APending Publication Date: 2025-07-25XIAN YUNWEI ZHILIAN TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510417029.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-03
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

The existing AFDX-side system firmware upgrade method requires disassembly or rely on host-side software, and the upgrade time is long, so there is a risk that the upgrade cannot be continued after the upgrade fails.

Method used

Through the AFDX side system firmware upgrade method, AFDX's virtual link is used for upgrade data transmission, combined with DMA technology for FLASH writing, and the firmware upgrade process is divided into the main functional area and the backup area to achieve efficient upgrades without disassembly and without relying on the host.

Benefits of technology

It realizes efficient upgrades without disassembly and does not rely on the host. The upgrade time is short and can continue after the upgrade fails, with high real-time and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120378304A_ABST
    Figure CN120378304A_ABST
Patent Text Reader

Abstract

The invention relates to an AFDX end system firmware upgrading method and device. Upgrading is achieved through interaction between upgrading equipment and a PS of an upgraded end. A specific virtual link of the AFDX is adopted as a communication link for upgrading, interaction between an upgrading end and protocol processing software running on an upgraded end PS is achieved, upgrading data are not provided for a driver when the protocol processing software is upgraded, and therefore the disassembly process is avoided, and efficient and reliable upgrading can be achieved by using the existing AFDX link without depending on a host.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of avionics, and in particular, to a method and device for firmware upgrade of an AFDX end system. Background Art

[0002] AFDX (Avioics Full Duplex Switched Ethernet) is established based on commercial switched Ethernet with improvements in aspects such as real-time performance and reliability according to the special requirements of avionics. An AFDX end system is an Ethernet card that has realized AFDX-specific functions such as real-time performance and reliability. The AFDX network card is connected to a computer through a PCIE / EMIF / SRIO interface, and the computer uses the AFDX network card to send data, with various functions defined by the technology. Figure 1 The AFDX end system framework diagram is shown.

[0003] The AFDX end system network card is implemented by an SoC (System on Chip), which includes two parts: a PS (Processing System) and a PL (Programmable Logic). This enables it to not only have the advantages of an ASIC in terms of energy consumption, performance, and compatibility, but also have the advantages of FPGA hardware programmability. At the same time, the software programmability of the processor and the hardware programmability of the FPGA are perfectly integrated to provide unparalleled system performance, flexibility, and scalability.

[0004] Due to the PS and PL architectures, the firmware update and upgrade of the SoC become relatively frequent, so the upgrade method is particularly important. Currently, the common upgrade methods are JTAG and ARINC615A. Using JTAG for upgrade requires removing the AFDX card to expose the JTAG interface for normal upgrade, and the JTAG upgrade time is relatively long, thus increasing a large amount of labor and material costs. ARINC615A can be upgraded without removing the card, but ARINC615A is overly dependent on the application software on the host side (HOST). If there is no application software on the host side that supports ARINC615A, online upgrade cannot be performed. When using ARINC615A for upgrade, if an unexpected power failure occurs after the upgrade fails, then after power-on again, ARINC615A cannot be used for upgrade anymore, and only disassembly and using JTAG for upgrade can be performed. Summary of the Invention

[0005] In order to overcome at least one deficiency in the prior art, this application provides a method and device for firmware upgrade of an AFDX end system.

[0006] In a first aspect, a method for upgrading the firmware of an AFDX end system is provided, including:

[0007] Step 1, the upgrading device sends a request for obtaining version information to the device to be upgraded using a specific virtual link; after the protocol processing software in the PS of the device to be upgraded receives the request for obtaining version information, it obtains the board version information, encapsulates it into a specific frame format, and sends it to the upgrading device; the device to be upgraded is an AFDX end system card.

[0008] After the upgrading device receives the board version information, it determines whether the device to be upgraded needs to be upgraded; if the device to be upgraded does not need to be upgraded, the upgrading process is exited, and the user is informed that the current version is the latest version. If the device to be upgraded needs to be upgraded, step 2 is executed.

[0009] Step 2, the upgrading device sends mode switching requests to the device to be upgraded multiple times, and the message content of each sent mode switching request is different; after the protocol processing software in the PS of the device to be upgraded correctly receives the messages multiple times, it switches to the upgrade mode.

[0010] Step 3, after the upgrading device determines that the protocol processing software has switched to the upgrade mode, it sends upgrade file information to the device to be upgraded; after the device to be upgraded receives the upgrade file information, it returns a message indicating correct receipt of the file to the upgrading device; after the upgrading device receives the message indicating correct receipt of the file, it executes step 4.

[0011] Step 4, the upgrading device divides the upgrade file into multiple Blocks and sends them to the protocol processing software one by one; after the protocol processing software receives a Block, it performs verification. If the verification is incorrect, it returns an error message to the upgrading device to inform the upgrading device to resend the Block. If the verification is correct, it saves the received Block to the DDR and returns a message indicating correct acceptance to the upgrading device; after the upgrading device receives the message indicating correct acceptance, it sends the next Block until the protocol processing software receives all the Blocks and returns a message indicating that the upgrade file has been received completely.

[0012] Step 5, after the upgrading device receives the message indicating that the upgrade file has been received completely, it sends a start upgrade command to the protocol processing software; after the protocol processing software receives the start upgrade command, it returns a message indicating start upgrade to the upgrading device and performs the upgrade operation.

[0013] Step 6, after the upgrading device receives the message indicating start upgrade, it periodically obtains the upgrade progress and error information. If it receives an error message, it stops obtaining the upgrade progress and sends a prompt of upgrade failure to the upgrading device. If it does not receive an error message, when the upgrade progress reaches 100%, it stops obtaining the upgrade progress and sends a prompt of upgrade success to the upgrading device.

[0014] In one embodiment, in step 5, the upgrade operation is performed, including:

[0015] Step 51, compare the upgrade file with the upgrade file information obtained in step 3 to determine whether the received upgrade file is correct. If it is correct, execute step 52; if it is incorrect, return an error message to the upgrade device.

[0016] Step 52, perform an erasing operation on the content of the FLASH main function area.

[0017] Step 53, use DMA to write the upgrade file into the FLASH main function area.

[0018] Step 54, read the content written into the FLASH and compare it with the content of the upgrade file saved in the DDR to determine whether the writing is correct. If it is incorrect, send an error message to the upgrade device.

[0019] In a second aspect, an AFDX end-system firmware upgrade device is provided, including an upgrade device and an end to be upgraded, and the end to be upgraded is an AFDX end-system card. The AFDX end-system firmware upgrade device is used to implement the above-mentioned AFDX end-system firmware upgrade method.

[0020] Compared with the prior art, the present application has the following beneficial effects:

[0021] 1. It can be upgraded without disassembling the machine. Even if the power is accidentally cut off during the upgrade failure, the upgrade can continue after power-on.

[0022] 2. It does not depend on the host-side application software. Even without a host, the board can be upgraded as long as it is powered separately.

[0023] 3. The upgrade efficiency is high, and the upgrade duration is only one-tenth of that of JTAG and one-eighth of that of ARINC615A.

[0024] 4. Use the AFDX link for upgrading, which has high real-time performance and high reliability.

[0025] 5. Use DMA to write to the FLASH to achieve efficient upgrading. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] The present application can be better understood by referring to the following description in conjunction with the accompanying drawings. The drawings, together with the following detailed description, are included in this specification and form a part of this specification. In the drawings:

[0027] Figure 1 The AFDX end-system framework diagram is shown;

[0028] Figure 2 The schematic diagram of the AFDX end-system firmware upgrade device is shown;

[0029] Figure 3 shows a schematic diagram of the FLASH partition;

[0030] Figure 4 shows the schematic diagram of the method for upgrading the AFDX end - system firmware. Detailed implementation manners

[0031] In the following, exemplary embodiments of the present application will be described with reference to the accompanying drawings. For the sake of clarity and conciseness, not all features of the actual embodiments are described in the specification. However, it should be understood that many embodiment - specific decisions may be made during the development of any such actual embodiment to achieve the specific goals of the developer, and these decisions may vary with different embodiments.

[0032] Here, it should also be noted that, in order to avoid obscuring the present application with unnecessary details, only the device structures closely related to the solution of the present application are shown in the drawings, while other details less related to the present application are omitted.

[0033] It should be understood that the present application is not limited to the described embodiments only due to the following description with reference to the drawings. In this document, where feasible, embodiments can be combined with each other, features can be replaced or borrowed between different embodiments, and one or more features can be omitted in one embodiment.

[0034] The present application provides an AFDX end - system firmware upgrade device, which realizes the upgrade through the interaction between the upgrade device and the PS of the device to be upgraded. Figure 2 shows the schematic diagram of the AFDX end - system firmware upgrade device. Refer to Figure 2 , the AFDX end - system firmware upgrade device includes an upgrade device and the device to be upgraded, and the device to be upgraded is an AFDX end - system card.

[0035] Without affecting the normal business, a specific virtual link of AFDX (such as virtual link 0) is used as the upgrade communication link to realize the interaction between the upgrade device and the protocol processing software running on the PS of the device to be upgraded, and the upgrade data is no longer provided to the driver. In this way, both the disassembly process is avoided and the independence from the host is achieved. Moreover, the existing AFDX link can be used for efficient and reliable upgrade.

[0036] To avoid the situation of upgrade failure and inability to continue the online upgrade after accidental power failure, the FLASH (flash memory) is partitioned into a main function area and a backup area. Figure 3 shows the schematic diagram of the FLASH partition.

[0037] When the AFDX version leaves the factory, the same bin file is burned into the main function area and the backup function area; during subsequent upgrades, only the content of the main function area is upgraded; when the content of the main function area is complete, the SoC will preferentially load the content of the main function area; when the content of the main function area becomes incomplete due to a failed upgrade, the SoC will load the content of the backup function area, thus ensuring that the upgrade can be carried out again.

[0038] During the entire upgrade process, writing to the FLASH is undoubtedly the most time-consuming. Therefore, DMA (Direct Memory Access) is used to write to the FLASH to improve the upgrade efficiency.

[0039] Figure 4 The schematic diagram of the AFDX end-system firmware upgrade method is shown. Refer to Figure 4 , and the method mainly includes the following steps:

[0040] Step 1, the upgrade device uses a specific virtual link to send a version information acquisition request to the device to be upgraded; after the protocol processing software in the PS of the device to be upgraded receives the version information acquisition request, it acquires the board version information, encapsulates it into a specific frame format, and sends it to the upgrade device; the device to be upgraded is the AFDX end-system card; here, the board version information includes the versions of the PS, PL, etc.

[0041] After the upgrade device receives the board version information, it determines whether the device to be upgraded needs to be upgraded; if the device to be upgraded does not need to be upgraded, the upgrade process is exited and the user is informed that the current version is the latest; if the device to be upgraded needs to be upgraded, step 2 is executed.

[0042] Step 2, the upgrade device sends multiple mode switching requests to the device to be upgraded, and the message content of each sent mode switching request is different; after the protocol processing software in the PS of the device to be upgraded correctly receives the messages multiple times, it switches to the upgrade mode.

[0043] Since the upgrade link uses the existing virtual link of AFDX for the upgrade, to prevent similar messages from causing incorrect mode entry during normal communication, the mode switching requires n requests and confirmations, and the message content is different each time. The protocol processing software of the PS can perform the mode switching only after correctly receiving the n messages; otherwise, it is considered a misoperation and the mode switching is not performed.

[0044] Step 3, after the upgrade device determines that the protocol processing software has switched to the upgrade mode, it sends upgrade file information to the device to be upgraded. Here, the upgrade file information includes information such as file size, CRC, file name, etc.; after the device to be upgraded receives the upgrade file information, it returns a message of correctly receiving the file information to the upgrade device; after the upgrade device receives the message of correctly receiving the file information, it executes step 4.

[0045] Step 4: Upgrade the device with 1 KB as a block, divide the upgrade file into multiple blocks, and send them to the protocol processing software one by one. After receiving a block, the protocol processing software performs a verification. If the verification fails, it returns an error message to the upgrade device to inform it to resend the block. If the verification is correct, it saves the received block to the DDR (Double Data Rate Synchronous Dynamic Random Access Memory) and returns a message indicating correct reception to the upgrade device. After receiving the message indicating correct reception, the upgrade device sends the next block until the protocol processing software receives all blocks and returns a message indicating that the upgrade file has been received completely.

[0046] Step 5: After receiving the message indicating that the upgrade file has been received completely, the upgrade device sends a start upgrade command to the protocol processing software. After receiving the start upgrade command, the protocol processing software returns a message indicating start upgrade to the upgrade device and performs the upgrade operation, which specifically includes:

[0047] Step 51: Compare the upgrade file with the upgrade file information obtained in Step 3 to determine whether the received upgrade file is correct. If it is correct, execute Step 52. If it is incorrect, return an error message to the upgrade device.

[0048] Step 52: Perform an erase operation on the content of the FLASH main function area.

[0049] Step 53: Use DMA to write the upgrade file to the main function area of the FLASH.

[0050] Step 54: Read the content written to the FLASH and compare it with the content of the upgrade file saved in the DDR to determine whether the writing is correct. If it is incorrect, send an error message to the upgrade device.

[0051] Step 6: After receiving the message indicating start upgrade, the upgrade device periodically obtains the upgrade progress and error information. If it receives an error message, it stops obtaining the upgrade progress and sends a prompt of upgrade failure to the upgrade device. If it does not receive an error message, when the upgrade progress reaches 100%, it stops obtaining the upgrade progress and sends a prompt of upgrade success to the upgrade device.

[0052] In summary, the present application has the following technical effects:

[0053] 1. It can be upgraded without disassembling the machine. Even if the power accidentally fails during the upgrade, it can continue to be upgraded after power-on.

[0054] 2. It does not depend on the host-side application software. Even without a host, the board can be upgraded as long as it is powered separately.

[0055] 3. High upgrade efficiency, with the upgrade duration being only one-tenth of that of JTAG and one-eighth of that of ARINC615A.

[0056] 4. Use the AFDX link for upgrade, featuring high real-time performance and high reliability.

[0057] 5. Use DMA to write to the FLASH to achieve efficient upgrade.

[0058] As mentioned above, the above are only various implementation manners of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claimed rights.

Claims

1. A method for firmware upgrade of an AFDX end system, characterized in that, Including: Step 1: The upgrading device sends a request for obtaining version information to the device to be upgraded using a specific virtual link; After the protocol processing software in the PS of the device to be upgraded receives the request for obtaining version information, it obtains the board version information, encapsulates it into a specific frame format, and sends it to the upgrading device; The device to be upgraded is an AFDX end system card; After the upgrading device receives the board version information, it determines whether the device to be upgraded needs to be upgraded; If the device to be upgraded does not need to be upgraded, the upgrade process is exited and the user is informed that the current version is the latest. If the device to be upgraded needs to be upgraded, Step 2 is executed; Step 2: The upgrading device sends mode switching requests to the device to be upgraded multiple times, and the message content of each sent mode switching request is different; After the protocol processing software in the PS of the device to be upgraded correctly receives the messages multiple times, it switches to the upgrade mode; Step 3: After the upgrading device determines that the protocol processing software has switched to the upgrade mode, it sends upgrade file information to the device to be upgraded; After the device to be upgraded receives the upgrade file information, it returns a message indicating correct receipt of the file to the upgrading device; After the upgrading device receives the message indicating correct receipt of the file, it executes Step 4; Step 4: The upgrading device divides the upgrade file into multiple Blocks and sends them to the protocol processing software one by one; After the protocol processing software receives a Block, it performs a check. If the check is incorrect, it returns an error message to the upgrading device to inform the upgrading device to resend the Block. If the check is correct, it saves the received Block to the DDR and returns a message indicating correct acceptance to the upgrading device; After the upgrading device receives the message indicating correct acceptance, it sends the next Block until the protocol processing software receives all Blocks and returns a message indicating that the upgrade file has been received completely to the upgrading device; Step 5: After the upgrading device receives the message indicating that the upgrade file has been received completely, it sends a start upgrade command to the protocol processing software; After the protocol processing software receives the start upgrade command, it returns a message indicating start of upgrade to the upgrading device and performs the upgrade operation; Step 6: After the upgrading device receives the message indicating start of upgrade, it periodically obtains the upgrade progress and error information. If it receives an error message, it stops obtaining the upgrade progress and sends a prompt of upgrade failure to the upgrading device. If it does not receive an error message, when the upgrade progress reaches 100%, it stops obtaining the upgrade progress and sends a prompt of upgrade success to the upgrading device.

2. The method according to claim 1, wherein, In Step 5, the upgrade operation includes: Step 51: Compare the upgrade file with the upgrade file information obtained in Step 3 to determine whether the received upgrade file is correct. If it is correct, execute Step 52. If it is incorrect, return an error message to the upgrading device; Step 52: Perform an erasing operation on the content of the main function area of the FLASH; Step 53: Use DMA to write the upgrade file to the main function area of the FLASH; Step 54: Read the content written to the FLASH and compare it with the content of the upgrade file saved in the DDR to determine whether the writing is correct; if not, send an error message to the upgrade device.

3. An AFDX end system firmware upgrade device, characterized in that It includes an upgrade device and an end to be upgraded, and the end to be upgraded is an AFDX end system card; the AFDX end system firmware upgrade device is used to implement the AFDX end system firmware upgrade method described in any one of claims 1-2.