Program upgrading method and device
By verifying the identification number and check code in the embedded microcontroller, the correctness problem of application program upgrade in the embedded microcontroller is solved, ensuring that there are no errors in the program during the download process and realizing reliable upgrade of the MCU.
Patent Information
- Application Number
- CN202510927183.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-04
- Publication Date
- 2025-09-12
AI Technical Summary
In embedded microcontrollers, due to the small storage space, existing technologies make it difficult to verify whether new applications are correct, resulting in upgrade failures or MCU failure to start.
By receiving and verifying the identification number, cumulative check code and reprogramming flag, it ensures that the downloaded application matches the boot program, and performs verification during the download process to avoid incorrect writing.
Ensure the correctness of the application during the upgrade process, avoid MCU startup failure or upgrade failure due to program mismatch, and improve the reliability of program upgrade.
Smart Images

Figure CN120631407A_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the technical field of computer programs, and in particular, relates to a program upgrading method and device. Background Art
[0002] In related program upgrade technologies, for the upgrade of applications in embedded microcontrollers (MCUs), the boot loader corresponding to the application pre-installed in the MCU is generally used to download the new application from the host computer and write it to the corresponding location, thereby completing the upgrade of the application in the MCU.
[0003] However, when upgrading an application in an MCU, due to the small internal storage space of the embedded MCU, the diagnostic protocol used to verify the newly written application cannot be stored in the embedded MCU, making it difficult to verify whether the new application is correct. Summary of the Invention
[0004] The embodiments of the present application provide a program upgrade method and apparatus, which can ensure that during the upgrade, no errors occur in the download process of the newly written application program, and the correct application program for the upgrade is obtained.
[0005] In a first aspect, an embodiment of the present application provides a program upgrade method, applied to a controller, the controller including a first boot program and a first application program; the method comprising:
[0006] In response to initiating an upgrade of the first application, receiving a preset identification number, and verifying whether the received identification number is correct using the identification number of the first boot program;
[0007] If the received identification number is correct, erasing the first application;
[0008] receiving a communication frame, the communication frame including a frame identifier and program data for constituting a second application, the second application being used to replace the first application;
[0009] When the frame identifier indicates an end frame, obtaining a cumulative check code of the communication frame;
[0010] When the acquired cumulative verification code is consistent with the preset cumulative verification code, it is determined that the downloading of each program data of the second application program is completed.
[0011] Furthermore, before responding to initiating the upgrade of the first application, the method further includes:
[0012] receiving an instruction to initiate an upgrade;
[0013] Write a reprogramming flag into the preset reprogramming flag bit;
[0014] Restart the first boot program and read the written reprogramming flag from the reprogramming flag bit;
[0015] Determine whether the written reprogramming flag is consistent with the preset reprogramming flag value;
[0016] When the written reprogramming flag is consistent with the preset reprogramming flag value, the upgrade of the first application is started.
[0017] Furthermore, after determining whether the written reprogramming flag is consistent with the preset reprogramming flag value, the method further includes:
[0018] When the written reprogramming flag is inconsistent with the preset reprogramming flag value, the current application valid flag is read from the preset application valid flag bit;
[0019] Determine whether the current application valid flag is consistent with the preset application valid value;
[0020] When the application validity flag is inconsistent with the preset application validity value, the upgrade of the first application is started.
[0021] Furthermore, after receiving the instruction to start the upgrade, the method further includes:
[0022] Check whether the reprogramming flag has been written into the reprogramming flag, and check whether the preset application valid flag has been written into the application valid flag;
[0023] When the reprogramming flag is not written into the reprogramming flag bit and the application valid flag is not written into the application valid flag bit, the upgrade of the first application is started.
[0024] Furthermore, before receiving the preset identification number, the method further includes:
[0025] Receive security keys;
[0026] After verifying that the security key is correct, wait to receive the preset identification number.
[0027] The identification number of the first boot program includes a first product number and a first version number of the first boot program; the preset identification number includes a second product number and a second version number of the second boot program;
[0028] Further, using the identification number of the first boot program to verify whether the received identification number is correct includes:
[0029] Verify that the second product number is consistent with the first product number and that the second version number is greater than the first version number;
[0030] In the case that the second product number is consistent with the first product number, and the second version number is greater than the first version number, it is determined that the received identification number is correct.
[0031] Further, after receiving the communication frame, the method further includes:
[0032] In the case where the frame identifier indicates that the frame is a program frame, downloading program data for constituting a second application from the communication frame;
[0033] Using the cumulative check code calculated for the previous communication frame as the initial value, the cumulative check code for the current communication frame is calculated;
[0034] Continue to receive the next communication frame until the frame identifier of the received communication frame indicates that it is an end frame.
[0035] Wherein, the communication frame also includes a single frame check code of the current frame;
[0036] Furthermore, before downloading the program data for constituting the second application from the communication frame, the method further includes:
[0037] Use the preset initial value to calculate the single frame check code;
[0038] Compare the calculated single frame check code with the single frame check code in the current communication frame to see if they are consistent;
[0039] If they are consistent, it is determined that the currently received communication frame is valid.
[0040] Furthermore, after obtaining the cumulative check code of the communication frame, the method further includes:
[0041] When the acquired cumulative verification code is inconsistent with the preset cumulative verification code, all downloaded program data is erased and the security key is received again.
[0042] In a second aspect, an embodiment of the present application provides a program upgrade device, which is applied to a controller, wherein the controller includes a first boot program and a first application program; the device includes:
[0043] a startup module configured to, in response to initiating an upgrade of the first application, receive a preset identification number and verify whether the received identification number is correct using the identification number of the first boot program;
[0044] an erasing module, configured to erase the first application if the received identification number is correct;
[0045] A receiving module, configured to receive a communication frame, the communication frame including a frame identifier and program data for constituting a second application program, the second application program being configured to replace the first application program;
[0046] An acquisition module, configured to acquire a cumulative check code of a communication frame when the frame identifier indicates an end frame;
[0047] The verification module is used to determine that the downloading of each program data of the second application program is completed when the acquired cumulative verification code is consistent with the preset cumulative verification code.
[0048] In a third aspect, an embodiment of the present application provides an electronic device, the device comprising:
[0049] a processor and a memory storing computer program instructions;
[0050] When the processor executes the computer program instructions, it implements any of the above program upgrade methods.
[0051] In a fourth aspect, an embodiment of the present application provides a computer storage medium, on which computer program instructions are stored. When the computer program instructions are executed by a processor, a program upgrade method as described in any of the above items is implemented.
[0052] In a fifth aspect, an embodiment of the present application provides a method for upgrading a program as described in any one of the preceding items, which causes the electronic device to execute instructions in a computer program product when the instructions are executed by the processor of the electronic device.
[0053] In a sixth aspect, an embodiment of the present application further provides a vehicle, the vehicle including a program upgrade device or an electronic device, and the electronic device executes any one of the program upgrade methods above.
[0054] The program upgrade method and device of the embodiment of the present application, after starting the upgrade of the first application, based on the received identification number, determines whether the received identification number is correct by comparing the received identification number with the identification number of the current first boot program, wherein, since the received identification number is the identification number of the second boot program, the second boot program is the boot program corresponding to the second application. When the second application is used to replace the first application for upgrade, if the identification number of the received second boot program matches the identification number of the current first boot program, it is verified that the first boot program and the second boot program match, thereby proving that the second application to be written and used to replace the first application can be applied to the current first boot program, thereby avoiding the upgrade failure caused by the inconsistency with the first boot program after the second application is written.
[0055] Furthermore, based on the fact that the received identification number is correct, after erasing the current first application and receiving the communication frame, one or more program data of the second application can be downloaded from the communication frame, and when the frame identifier in the communication frame represents the end frame, it is determined that all the program data downloaded to the second application is completed.
[0056] Among them, when the end frame is received, the cumulative check code of the last communication frame can be obtained, and by verifying the cumulative check code, it is possible to verify whether the downloaded second application is correct, thereby ensuring that when upgrading, the written second application does not have any errors during the download process, and the second application composed of the various program data obtained is correct. BRIEF DESCRIPTION OF THE DRAWINGS
[0057] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0058] Figure 1 This is a schematic diagram of the MCU structure of a program upgrade method provided in an embodiment of the present application;
[0059] Figure 2 This is a flowchart of a program upgrade method provided in an embodiment of the present application;
[0060] Figure 3 This is a schematic diagram of the structure of a communication frame of a program upgrade method provided in an embodiment of the present application;
[0061] Figure 4 This is a logical diagram of a program upgrade method provided in an embodiment of the present application;
[0062] Figure 5 This is a schematic diagram of the structure of a program upgrade device provided in an embodiment of the present application;
[0063] Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0064] The features and exemplary embodiments of various aspects of the present application will be described in detail below. In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below in conjunction with the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain the present application, rather than to limit the present application. For those skilled in the art, the present application can be implemented without the need for some of these specific details. The following description of the embodiments is merely to provide a better understanding of the present application by illustrating the examples of the present application.
[0065] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, the elements defined by the phrase "comprising..." do not exclude the presence of other identical elements in the process, method, article, or device comprising the elements.
[0066] As described in the background technology section, the relevant program upgrade technology is still difficult to meet the needs of actual work.
[0067] The vehicle is equipped with an embedded microcontroller (MCU), such as Figure 1 As shown, the embedded MCU is provided with a random access memory (RAM) area, an electrically erasable programmable read only memory (EEPROM) area, and a read-only memory (ROM) area.
[0068] The ROM area is provided with a Bootloader partition for storing a boot program (Bootloader program, BT program), and an APP partition for storing an application program (Application program, APP program).
[0069] A reprogramming flag bit and other information about the RAM are set in the RAM area, and a reprogramming flag can be set in the reprogramming flag bit.
[0070] The EEPROM area is provided with an APP program valid flag bit and other information about the EEPROM. The APP program valid flag bit can be used to set an APP program valid flag.
[0071] When upgrading the APP program in the ROM area, a new APP program for updating the current APP program can be downloaded from the host computer. During the downloading, the downloading of the APP program can be guided by the BT program.
[0072] In the process of implementing this application, it was found that in the relevant program upgrade technology, when upgrading the APP program in the MCU, if there is an error in the downloaded APP program, for example, the downloaded APP program does not match the current BT program in version, the downloaded APP program will be used normally, but the MCU will not be able to start.
[0073] The BT program is often burned into the MCU when it leaves the factory, and the embedded MCU is encapsulated in a shell. Therefore, if the downloaded APP program does not match the BT program in the current MCU, the MCU cannot be started. The MCU can only be disassembled and the APP program can be debugged and flashed.
[0074] Therefore, it is very important to ensure that the APP program to be downloaded is correct and matches the BT program.
[0075] On the other hand, in addition to the possibility of downloading the wrong APP program when downloading, it is also possible that due to communication interference or other communication problems, when downloading the correct APP program, the downloaded program data may be garbled or erroneous.
[0076] Therefore, in addition to ensuring that the APP program to be downloaded is correct, you also need to ensure that the new APP program is correct after downloading it and before starting the new APP program. Otherwise, if the APP program contains garbled characters or errors, once you try to start the new APP program, the MCU will not be able to start correctly.
[0077] Therefore, it is very important to verify that the downloaded program data does not contain garbled characters or errors.
[0078] However, due to the small storage space of the embedded MCU, it is difficult to use the Unified Diagnostic Services (UDS) protocol to ensure that the downloaded APP program is correct. Similarly, due to the small storage space, it is also impossible to update the APP program by downloading it in the AB partition.
[0079] In order to solve the problems of the prior art, the embodiments of the present application provide a program upgrade method and device.
[0080] The following describes in detail the program upgrade method provided in the embodiment of the present application with reference to the accompanying drawings.
[0081] Figure 2 A flowchart of a program upgrade method provided by an embodiment of the present application is shown.
[0082] refer to Figure 2A program upgrade method according to an embodiment of the present application is applied to a controller, which includes a first boot program and a first application program.
[0083] The controller may be an embedded MCU, and the first boot program may also be referred to as the first BT program in this application. Figure 1 The BT program currently stored in the Bootloader partition of the MCU; the first application program may also be referred to as the first APP program in this application, Figure 1 The APP program currently stored in the APP partition of the MCU.
[0084] The method may specifically include the following steps S201 to S205:
[0085] S201: In response to starting an upgrade of the first application, a preset identification number is received, and the identification number of the first boot program is used to verify whether the received identification number is correct.
[0086] The identification number received by the MCU is the identification number of the BT program that matches the APP program to be written into the MCU.
[0087] In one example, when starting the upgrade of the first APP program, the MCU can communicate with the host computer, so that when starting the upgrade of the first APP program, the MCU can receive an identification number from the host computer.
[0088] The MCU stores the identification number of the current BT program. Based on the identification number received from the host computer, the received identification number can be compared with the currently stored identification number.
[0089] Furthermore, by comparison, it can be determined whether the received identification number is correct based on the currently stored identification number, thereby determining whether the APP program to be written corresponding to the received identification number can also be matched and used with the BT program represented by the currently stored identification number.
[0090] When the received identification number is correct, it is considered that the APP program to be written can be matched and used with the currently stored BT program; when the received identification number is incorrect, it is considered that the APP program to be written cannot be matched and used with the currently stored BT program.
[0091] S202: If the received identification number is correct, delete the first application.
[0092] In one example, based on the judgment of the received identification number in the aforementioned step, if the received identification number is correct, the MCU can erase the first APP program currently stored in the APP partition, thereby preparing storage space for the APP program to be written.
[0093] S203: Receive a communication frame, where the communication frame includes a frame identifier and program data for constituting a second application program, where the second application program is used to replace the first application program.
[0094] Among them, the second application program can also be referred to as a second APP program in this application, and is the APP program to be written in the aforementioned steps, and the second APP program is stored in the host computer.
[0095] Based on the communication between the host computer and the MCU, when the MCU downloads the second APP program from the host computer, the MCU completes the download of the second APP program by receiving communication frames from the host computer multiple times.
[0096] In each received communication frame, such as Figure 3 As shown, it includes a frame identifier, a communication identifier (communication ID), a frame function identifier and a data part.
[0097] Among them, such as Figure 3 As shown, the data portion includes a piece of program data for constituting the second APP program, and an address corresponding to the program data of this frame.
[0098] The frame function identifier may also be referred to as a frame identifier in this application.
[0099] Based on this, each time a communication frame is received, the frame identifier of the current frame and the program data of the second APP program can be read from the communication frame.
[0100] S204: When the frame identifier indicates an end frame, obtain a cumulative check code of the communication frame.
[0101] The frame identifier in each communication frame can be characterized as a program frame or an end frame.
[0102] The cumulative check code may be, for example, a cyclic redundancy check code (CRC) obtained through cumulative calculation. In this embodiment, the cumulative check code may also be referred to as a cumulative CRC.
[0103] In one example, after each communication frame is acquired, the frame identifier in the communication frame may be identified.
[0104] Furthermore, based on the recognition of the frame identifier, if the frame identifier represents an end frame, the accumulated CRC calculated based on the communication frame can be obtained.
[0105] In some cases, the received end frame may include a cumulative CRC calculated based on the end frame. Accordingly, based on the recognition of the frame identifier, if the frame identifier represents an end frame, the calculated cumulative CRC can be obtained from the end frame.
[0106] S205: When the acquired cumulative verification code is consistent with the preset cumulative verification code, it is determined that the downloading of each program data of the second application program is completed.
[0107] The preset accumulated CRC may be obtained by the MCU from the host computer.
[0108] In one example, when the frame identifier of the current communication frame indicates an end frame, the MCU may receive a preset cumulative CRC from the host computer. The preset cumulative CRC may be pre-calculated by the host computer according to the expected transmission order of the communication frames.
[0109] Based on the cumulative CRC obtained in the above steps, the obtained cumulative CRC can be compared with the preset cumulative CRC to determine whether the obtained cumulative CRC is consistent with the preset cumulative CRC.
[0110] Based on the above comparison, if the obtained cumulative CRC is consistent with the preset cumulative CRC, it can be considered that the various program data currently written to the APP partition did not have garbled characters or errors due to communication interference during downloading. It can be determined that the various program data currently written to constitute the second APP program are correct, and it can be determined that the second APP program has completed downloading.
[0111] Based on this, after starting the upgrade of the first APP program, based on the received identification number, by comparing the received identification number with the identification number of the current first BT program, it is determined whether the received identification number is correct.
[0112] Among them, since the received identification number is the identification number of the second BT program, and the second BT program is the BT program corresponding to the second APP program, when the second APP program is used to replace the first APP program for upgrading, if the identification number of the received second BT program can match the identification number of the current first BT program, it can be verified that the first BT program and the second BT program match, thereby proving that the second APP program to be written and used to replace the first APP program can be applied to the current first BT program, thereby avoiding the upgrade failure due to mismatch with the first BT program after the second APP program is written.
[0113] Furthermore, when the received identification number is correct, each time a communication frame is received, the frame identifier in the communication frame is used to determine whether the communication frame is the last communication frame used to download program data. When the frame identifier represents an end frame, the communication frame can be the last communication frame, and it is determined that all program data has been downloaded to the second application.
[0114] Furthermore, when the end frame is received, the cumulative check code of the last communication frame can be obtained, and by verifying the cumulative check code, it can be verified whether the downloaded second application is correct, thereby ensuring that when upgrading, the written second application does not have any errors during the download process, and the second application composed of the various program data obtained is correct.
[0115] In another embodiment of the present application, before starting the upgrade of the first APP program, after receiving the indication to start the upgrade, a reprogramming flag can be written in the reprogramming flag bit and the first BT program can be restarted. After restarting the first BT program, the reprogramming flag can be read and whether the upgrade of the first APP program is started can be decided by judging whether the reprogramming flag is valid.
[0116] The MCU may receive an instruction to start the upgrade from the host computer through communication with the host computer.
[0117] In one example, based on the received instruction to start the upgrade, the MCU may Figure 1 The reprogramming flag is written into the reprogramming flag bit shown.
[0118] Furthermore, after writing the reprogramming flag, the MCU restarts the first BT program by performing a reboot.
[0119] Further, after restarting the first BT program, you can Figure 1 The reprogramming flag written above is read from the reprogramming flag bit in .
[0120] Accordingly, the preset reprogramming flag value can be compared with the written reprogramming flag. If the reprogramming flag value is consistent with the read reprogramming flag, it is considered that the upgrade of the first APP program can be started.
[0121] Based on this, based on writing the reprogramming flag in the reprogramming flag bit, after restarting the first BT program, by comparing the preset reprogramming flag value with the written reprogramming flag, it is possible to verify whether the upgrade behavior is incorrect before starting the upgrade.
[0122] In another embodiment of the present application, based on the comparison between the preset reprogramming flag value and the written reprogramming flag, if the reprogramming flag value is inconsistent with the read reprogramming flag, it is not necessary to immediately upgrade the first APP program, and judge whether the current APP valid flag in the APP valid flag is valid. Specifically, the current APP valid flag can be compared with the preset APP valid value to judge whether the current APP valid flag is valid, so that the upgrade of the first APP program can be started when the current APP valid flag is invalid.
[0123] Among them, the APP valid flag read from the APP valid flag bit can be used, for example, to characterize the version of the first APP program currently stored in the MCU; the preset APP valid value can be used, for example, to characterize the version of the second APP program to be written.
[0124] In one example, based on the comparison of the reprogramming flag in the above steps, when the reprogramming flag is inconsistent with the reprogramming flag value, it is possible to further Figure 1 Read the APP valid flag of the first APP program.
[0125] Furthermore, the preset APP validity value and the read APP validity flag may be utilized.
[0126] If the preset APP valid value is consistent with the read APP valid flag, it is considered that the second APP program to be written is not suitable for replacing the current first APP program, that is, there is no need to start upgrading the current first APP program.
[0127] If the preset APP valid value is inconsistent with the read APP valid flag, it is considered that the second APP program currently to be written can be used to replace the current first APP program, that is, the current first APP program can be upgraded.
[0128] Based on this, in this embodiment, when the reprogramming flag is inconsistent with the reprogramming flag value, by comparing the read APP valid flag with the preset APP valid value, it is possible to verify whether the second APP program to be written is suitable for upgrading the second APP program, thereby realizing whether to start the upgrade from the perspective of the current APP program when the reprogramming flag is inconsistent with the reprogramming flag value.
[0129] In another embodiment of the present application, in some scenarios, the first APP program is not stored in the APP partition in the MCU. For example, in an MCU that has just been shipped from the factory, only the first BT program is often burned, and no APP program has been flashed.
[0130] In this case, since no APP program is stored in the MCU, the corresponding APP valid flag is not stored in the APP valid flag bit, and therefore it is impossible to determine whether to start the upgrade by comparing the APP valid flag with the APP valid value in the aforementioned embodiment.
[0131] Based on this, the MCU can check Figure 1 Check whether the reprogramming valid flag has been written into the reprogramming valid flag bit in the APP register, and check whether the APP valid flag has been written into the APP valid flag bit.
[0132] Furthermore, if any reprogramming valid flag is not written into the reprogramming valid flag bit, and any APP valid flag is not written into the APP valid flag bit, it is considered that no APP program is stored in the APP partition of the current MCU.
[0133] Furthermore, when it is determined that no APP program is stored in the APP partition of the current MCU, downloading of the second APP program may be initiated.
[0134] In this embodiment, the operation of downloading the second APP program is the same as the operation of upgrading the first APP program. Therefore, starting the download of the second APP program may be equivalent to starting the upgrade of the first APP program.
[0135] Based on this, in this embodiment, by checking whether there are corresponding valid flags in the reprogramming valid flag and the APP valid flag, it can be determined whether there is any APP program in the MCU, thereby enabling the download of the second APP program to be started when there is no APP program in the MCU.
[0136] In another embodiment of the present application, before receiving the identification number, the MCU may determine whether to start receiving the identification number by verifying the received security key.
[0137] Among them, the MCU can receive the security key from the host computer through communication with the host computer.
[0138] In one example, before the MCU receives the identification number from the host computer, it may receive a security key from the host computer.
[0139] Furthermore, after the MCU receives the security key, it may verify the security key.
[0140] Furthermore, based on the verification of the security key, when the security key is verified to be correct, it is considered that the current communication behavior is in a safe state and the identification number can be prepared to be received.
[0141] Based on this, in this embodiment, a security key is used to verify whether the communication between the MCU and the host computer is secure, thereby further ensuring the correctness of the second APP program to be written.
[0142] In another embodiment of the present application, when using the identification number of the first BT program to verify whether the received identification number is correct, the correctness of the received identification number can be determined by verifying the product number and version number in the identification number.
[0143] The identification number of the first BT program includes the first product number and the first version number of the first BT program.
[0144] The received identification number includes a second product number and a second version number of the second BT program.
[0145] In one example, when verifying the received identification number, the second product number may be compared to the first product number, and the second version number may be compared to the first version number.
[0146] Furthermore, when comparing the second product number with the first product number, it can be verified whether the second product number is consistent with the first product number; when comparing the second version number with the first version number, it can be verified whether the second version number is greater than the first version number.
[0147] Furthermore, based on the above verification, when the second product number is consistent with the first product number, it is considered that the second BT program and the first BT program currently in the MCU are products of the same series.
[0148] When the second version number is greater than the first version number, it is considered that the version of the second BT program is newer than the current version of the first BT program in the MCU, and it can be considered that the second BT program is compatible with the current first BT program.
[0149] Therefore, when the second product number is consistent with the first product number and the second version number is greater than the first version number, it is considered that the received identification number is correct, and the second APP program corresponding to the received identification number can be matched and used with the current first BT program.
[0150] Based on this, in this embodiment, through the product number and version number in the identification number, by comparing the first product number with the second product number, and comparing the first version number with the second version number, it can be verified whether the second BT program is compatible with the current first BT program. When the second BT program is compatible with the current first BT program, the received identification number can be considered correct.
[0151] In another embodiment of the present application, each time a communication frame is received and the frame identifier of the communication frame is identified, if the frame identifier of the communication frame is identified as a program frame, the program data can be downloaded from the communication frame, and the cumulative CRC of the previous communication frame can be used as the initial value to calculate the cumulative CRC of the current communication frame, and then continue to receive the next communication frame.
[0152] In one example, after receiving a communication frame from the host computer each time, the MCU identifies the frame identifier in the communication frame.
[0153] Furthermore, after identifying the frame identifier, if the frame identifier indicates a program frame, the MCU downloads the program data carried in the communication frame and calculates the accumulated CRC of the current communication frame.
[0154] Furthermore, after the cumulative CRC is calculated, the next communication frame is received.
[0155] In an example of this embodiment, if the current communication frame is the first communication frame received during the upgrade process, a predetermined value, such as 0, is used as an initial value to calculate the accumulated CRC of the first communication frame.
[0156] If the current communication frame is not the first communication frame, the accumulated CRC of the previous communication frame is used as the initial value to calculate the accumulated CRC of the current communication frame.
[0157] Based on this, in this embodiment, by identifying the frame identifier, when the frame identifier is represented as a program frame, the program data of the second APP program can be downloaded, and the cumulative CRC of the current communication frame can be calculated by the cumulative CRC of the previous communication frame. Accordingly, the cumulative CRC of each communication frame can be related to the cumulative CRC of the previous communication frame. That is to say, the calculated cumulative CRC of the last communication frame is related to the cumulative CRC of each previous communication frame, and is related to the receiving order of each communication frame. For example, if any communication frame is missing or the order of the communication frames is disordered due to problems such as communication interference, the cumulative CRC of the last communication frame cannot match the pre-calculated preset cumulative CRC, so that the cumulative CRC can be used to verify whether the communication frame is received correctly, thereby ensuring that the received program data is correct.
[0158] In another embodiment of the present application, after receiving each communication frame, before downloading program data from the communication frame, a single-frame check code can be calculated for the communication frame using a preset initial value, and by verifying whether the single-frame check code is consistent with the preset single-frame check code, it is determined whether the currently received communication frame is valid.
[0159] The single-frame check code may also be referred to as a single-frame CRC in this embodiment, and may be, for example, a cyclic redundancy check code calculated using a preset initial value.
[0160] like Figure 3 As described above, each communication frame also includes a frame CRC, which is pre-calculated by the host computer and preset into a single frame CRC in the communication frame.
[0161] In one example, after each communication frame is received, in order to ensure that the currently received communication frame is correct, a single-frame CRC may be calculated for the current communication frame using a preset initial value, for example, 0 as the initial value.
[0162] Furthermore, a single-frame CRC preset in the communication frame is read from the communication frame.
[0163] Furthermore, it is verified whether the read preset single-frame CRC is consistent with the calculated single-frame CRC.
[0164] If the preset single-frame CRC is consistent with the calculated single-frame CRC, the currently received communication frame is considered valid, and the program data in the communication frame is downloaded.
[0165] If the preset single-frame CRC is inconsistent with the calculated single-frame CRC, the currently received communication frame is considered invalid, and program data is not downloaded from the communication frame, and the next communication frame is received.
[0166] Based on this, this embodiment calculates a single frame check code for each communication frame and verifies the single frame check code, thereby verifying the current communication frame, thereby ensuring the correctness of the program data downloaded from each communication frame.
[0167] In another embodiment of the present application, when the frame identifier in the communication frame represents an end frame, after obtaining the cumulative CRC of the last communication frame, the obtained cumulative CRC is verified. If it is inconsistent with the preset cumulative CRC, all currently downloaded program data is erased and the security key is received again.
[0168] In one example, after comparing the obtained cumulative CRC with the preset cumulative CRC, if the obtained cumulative CRC is inconsistent with the preset cumulative CRC, it is considered that there is a download error in all the currently downloaded program data.
[0169] Furthermore, when it is determined that the downloaded program data is erroneous, all downloaded program data may be erased and the download of program data may be restarted.
[0170] Furthermore, when resuming downloading of program data, execution can be started from re-receiving the security key.
[0171] Based on this, in this embodiment, by verifying whether the obtained cumulative CRC is consistent with the preset cumulative CRC, it can be found whether there are errors in all the program data currently downloaded, and when it is verified that the downloaded program data is wrong, the erroneous program data can be erased in time and the download of the program data can be started again.
[0172] In another embodiment of the present application, Figure 4 It shows a logic diagram of program upgrade, and specifically shows steps S401-S418 executed by the MCU when the first APP program is upgraded.
[0173] In this embodiment, after the MCU receives the upgrade instruction of the first APP program from the host computer, it can further execute Figure 4 In S401, a reprogramming flag is written.
[0174] Further, in Figure 1 After the reprogramming flag is written into the reprogramming flag bit in , S402 is executed and the MCU is restarted.
[0175] In this step, by restarting the MCU and entering the first BT program after the restart, the first BT program can be restarted, and then S403 is further executed to read the reprogramming flag.
[0176] In this step, the MCU can Figure 1 The reprogramming flag in the reads the reprogramming flag and receives the preset reprogramming flag value from the host computer.
[0177] Further, execute S404 to determine whether it is valid.
[0178] In this step, the MCU may compare the reprogramming flag with the reprogramming flag value to see whether they are consistent. If they are consistent, the judgment result of S404 is yes; if they are inconsistent, the judgment result of S404 is no.
[0179] If the judgment result of S404 is yes, S405 is further executed to start the upgrade.
[0180] When the judgment result of S404 is no, S406 is further executed to read the APP valid flag, and S407 is further executed to determine whether they are consistent.
[0181] In this step, it can be determined whether the APP valid flag read from the APP valid flag bit is consistent with the preset APP valid value.
[0182] If the APP valid flag is inconsistent with the APP valid value after comparison, the judgment result of S407 is no, and S405 is further executed; if the APP valid flag is consistent with the APP valid value after comparison, the judgment result of S407 is yes, then the first APP will not be upgraded, and S408 will be further executed to enter the current APP.
[0183] After the MCU executes S405 , it further executes S409 to receive the security key, and after receiving the security key, it executes S410 to determine whether the security key is correct.
[0184] In this step, if it is determined that the security key is incorrect, the judgment result of S410 is no, and the value S409 is returned; if it is determined that the security key is correct, the judgment result of S410 is yes, and S411 is further executed to receive the product number and version number.
[0185] In this step, the MCU may receive the product number and version number of the second BT program from the host computer.
[0186] After receiving the product number and version number, step S412 may be further executed to determine whether the product number and version number are correct.
[0187] In this step, the MCU may determine whether the received product number is consistent with the product number of the current first BT program, and whether the received version number is greater than the version number of the current first BT program.
[0188] If the received product number is consistent with the product number of the current first BT program, and the received version number is greater than the version number of the current first BT program, the judgment result of S412 is considered to be yes; if the received product number is inconsistent with the product number of the current first BT program, or the received version number is less than or equal to the version number of the current first BT program, the judgment result of S412 is considered to be no.
[0189] Furthermore, when the judgment result of S412 is no, the process returns to S409; when the judgment result of S412 is yes, the process further executes S413 to erase the current APP program.
[0190] In this step, the MCU erases the currently stored first APP program, and after erasing, executes S414 to receive program data.
[0191] In this step, after erasing the currently stored APP program, the program data is downloaded from the communication frame, and after downloading the program data of the current communication frame, S415 is further executed to determine whether it is an end frame.
[0192] In this step, the frame identifier in the communication frame can be identified to determine whether the frame identifier represents an end frame.
[0193] When the frame identifier indicates that the frame is an end frame, the judgment result of S415 is yes; when the frame identifier does not indicate that the frame is an end frame, the judgment result of S415 is no.
[0194] When the judgment result of S415 is no, the process returns to S414; when the judgment result of S415 is yes, the process further executes S416 to judge whether the accumulated CRC is correct.
[0195] In this step, whether the obtained cumulative CRC is consistent is determined by comparing the obtained cumulative CRC with the preset cumulative CRC.
[0196] When the accumulated CRCs are inconsistent, the judgment result of S416 is no, and S417 is further executed to erase all program data.
[0197] In this step, if the obtained cumulative CRC is consistent with the preset cumulative CRC, it proves that there are errors in all the downloaded program data, and after erasing all the program data, return to S409 to re-download the program data of the second APP program.
[0198] When the accumulated CRCs are consistent, the judgment result of S416 is yes, and S418 can be selected to be executed to write the APP valid flag.
[0199] Specifically, in this step, if the result of the judgment in S416 is yes, it can be considered that the upgrade of the second APP program has been completed. Accordingly, the version of the second APP program can be written to be used in the next subsequent upgrade.
[0200] Furthermore, based on the execution of S418, S408 may be further executed to enter the current APP, that is, the second APP program that has completed the upgrade.
[0201] Based on this, in this embodiment, after the MCU receives the upgrade instruction from the host computer, it can determine whether the upgrade of the first APP program can be started by comparing the reprogramming flag and the APP valid flag. After starting the upgrade of the first application, based on the received identification number, by comparing the received identification number with the identification number of the current first boot program, it is determined whether the received identification number is correct. Here, since the received representation number can be, for example, the identification number of the second boot program, the second boot program is the boot program corresponding to the second application. When the second application is used to replace the first application for upgrade, if the identification number of the received second boot program can match the identification number of the current first boot program, the effect of verifying that the first boot program matches the second boot program is achieved, thereby proving that the second application to be written and used to replace the first application can be applicable to the current first boot program, thereby avoiding the upgrade failure caused by the inconsistency with the first boot program after the second application is written.
[0202] Furthermore, based on the fact that the received identification number is correct, after erasing the current first application and receiving the communication frame, one or more program data of the second application can be downloaded from the communication frame, and when the frame identifier in the communication frame represents the end frame, it is determined that all the program data that have been downloaded to the second application has been downloaded. Based on this, the cumulative check code of the last communication frame is calculated, and by verifying the cumulative check code, it is verified whether the downloaded second application is correct, thereby ensuring that when upgrading, the written second application does not have any errors during the download process, and the second application composed of the obtained program data is correct.
[0203] Based on the same inventive concept, corresponding to any of the above-mentioned embodiments and methods, an embodiment of the present application further provides a program upgrade device, which is applied to a controller, and the controller includes a first boot program and a first application program.
[0204] refer to Figure 5 , the program upgrades the device, including:
[0205] The starting module 501 is configured to receive a preset identification number in response to starting an upgrade of the first application program, and verify whether the received identification number is correct using the identification number of the first boot program;
[0206] An erasing module 502, configured to erase the first application if the received identification number is correct;
[0207] A receiving module 503 is configured to receive a communication frame, the communication frame including a frame identifier and program data for constituting a second application program, the second application program being configured to replace the first application program;
[0208] An acquisition module 504 is configured to acquire a cumulative check code of a communication frame when the frame identifier indicates an end frame;
[0209] The verification module 505 is configured to determine that the downloading of each program data of the second application program is completed when the acquired cumulative verification code is consistent with a preset cumulative verification code.
[0210] In one embodiment, before initiating the upgrade of the first application, the startup module 501 is specifically configured to:
[0211] receiving an instruction to initiate an upgrade;
[0212] Write a reprogramming flag into the preset reprogramming flag bit;
[0213] Restart the first boot program and read the written reprogramming flag from the reprogramming flag bit;
[0214] Determine whether the written reprogramming flag is consistent with the preset reprogramming flag value;
[0215] When the written reprogramming flag is consistent with the preset reprogramming flag value, the upgrade of the first application is started.
[0216] Furthermore, after determining whether the written reprogramming flag is consistent with the preset reprogramming flag value, the starting module 501 is further configured to:
[0217] When the written reprogramming flag is inconsistent with the preset reprogramming flag value, the current application valid flag is read from the preset application valid flag bit;
[0218] Determine whether the current application valid flag is consistent with the preset application valid value;
[0219] When the application validity flag is inconsistent with the preset application validity value, the upgrade of the first application is started.
[0220] Furthermore, after receiving the instruction to start the upgrade, the starting module 501 is further configured to:
[0221] Check whether the reprogramming flag has been written into the reprogramming flag, and check whether the preset application valid flag has been written into the application valid flag;
[0222] When the reprogramming flag is not written into the reprogramming flag bit and the application valid flag is not written into the application valid flag bit, the upgrade of the first application is started.
[0223] Furthermore, before receiving the preset identification number, the starting module 501 is further configured to:
[0224] Receive security keys;
[0225] After verifying that the security key is correct, wait to receive the preset identification number.
[0226] In another embodiment, the identification number of the first boot program includes a first product number and a first version number of the first boot program; the preset identification number includes a second product number and a second version number of the second boot program;
[0227] The receiving module 503 uses the identification number of the first boot program to verify whether the received identification number is correct, specifically including:
[0228] The receiving module 503 verifies whether the second product number is consistent with the first product number, and whether the second version number is greater than the first version number;
[0229] In the case that the second product number is consistent with the first product number, and the second version number is greater than the first version number, the receiving module 503 determines that the received identification number is correct.
[0230] Furthermore, after the receiving module 503 receives the communication frame, it executes:
[0231] In the case where the frame identifier indicates that the frame is a program frame, downloading program data for constituting a second application from the communication frame;
[0232] Using the cumulative check code calculated for the previous communication frame as the initial value, the cumulative check code for the current communication frame is calculated;
[0233] Continue to receive the next communication frame until the frame identifier of the received communication frame indicates that it is an end frame.
[0234] Wherein, the communication frame also includes a single frame check code of the current frame;
[0235] Before the receiving module 503 downloads the program data for constituting the second application from the communication frame, the following steps are further executed:
[0236] Use the preset initial value to calculate the single frame check code;
[0237] Compare the calculated single frame check code with the single frame check code in the current communication frame to see if they are consistent;
[0238] If they are consistent, it is determined that the currently received communication frame is valid.
[0239] In another embodiment, after obtaining the cumulative check code of the communication frame, the obtaining module 504 is further configured to:
[0240] When the acquired cumulative verification code is inconsistent with the preset cumulative verification code, all downloaded program data is erased and the security key is received again.
[0241] For the convenience of description, the above devices are described as being divided into various modules according to their functions. Of course, when implementing the embodiments of the present application, the functions of each module can be implemented in the same or multiple software and / or hardware.
[0242] The apparatus of the above embodiment is used to implement the corresponding program upgrade method in any of the above embodiments, and has the beneficial effects of the corresponding method embodiment, which will not be described in detail here.
[0243] Based on the same inventive concept, corresponding to any of the above-mentioned embodiment methods, an embodiment of the present application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and runnable on the processor, wherein when the processor executes the program, the program upgrade method of any of the above embodiments is implemented.
[0244] Figure 6 A schematic diagram of the hardware structure of an electronic device provided in an embodiment of the present application is shown.
[0245] The electronic device may include a processor 601 and a memory 602 storing computer program instructions.
[0246] Specifically, the processor 601 may include a central processing unit (CPU), or an application specific integrated circuit (ASIC), or may be configured to implement one or more integrated circuits of the embodiments of the present application.
[0247] Memory 602 may include a large capacity memory for data or instructions. By way of example and not limitation, memory 602 may include a hard disk drive (HDD), a floppy disk drive, a flash memory, an optical disk, a magneto-optical disk, a magnetic tape, or a universal serial bus (USB) drive, or a combination of two or more of these. Where appropriate, memory 602 may include removable or non-removable (or fixed) media. Where appropriate, memory 602 may be internal or external to the electronic device. In a particular embodiment, memory 602 is a non-volatile solid-state memory.
[0248] The memory 602 may include a read-only memory (ROM), a random access memory (RAM), a magnetic disk storage medium device, an optical storage medium device, a flash memory device, an electrical, optical, or other physical / tangible memory storage device. Thus, generally, the memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., a memory device) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the method according to an aspect of the present disclosure.
[0249] The processor 601 implements any one of the program upgrade methods in the above embodiments by reading and executing computer program instructions stored in the memory 602 .
[0250] In one example, the electronic device may further include a communication interface 603 and a bus 610. Figure 6 As shown, the processor 601, the memory 602, and the communication interface 603 are connected via a bus 610 and communicate with each other.
[0251] The communication interface 603 is mainly used to implement communication between various modules, devices, units and / or equipment in the embodiments of the present application.
[0252] Bus 610 includes hardware, software or both, couples the parts of electronic equipment to each other.For example, but not limitation, bus may include Accelerated Graphics Port (AGP) or other graphics buses, Enhanced Industry Standard Architecture (EISA) bus, Front Side Bus (FSB), Hyper Transport (HT) interconnection, Industry Standard Architecture (ISA) bus, InfiniBand interconnection, Low Pin Count (LPC) bus, memory bus, Micro Channel Architecture (MCA) bus, Peripheral Component Interconnect (PCI) bus, PCI-Express (PCI-X) bus, Serial Advanced Technology Attachment (SATA) bus, Video Electronics Standards Association local (VLB) bus or other suitable bus or two or more of these combinations. In appropriate cases, bus 610 may include one or more buses. Although the present application embodiment describes and shows specific bus, the application considers any suitable bus or interconnection.
[0253] The electronic device can execute the program upgrade method in the embodiment of the present application based on the verification of the identification number and the accumulated CRC, thereby achieving Figure 1Describes the program upgrade method.
[0254] In addition, in conjunction with the program upgrade method in the above embodiments, the present application embodiment can provide a computer storage medium for implementation. The computer storage medium stores computer program instructions; when the computer program instructions are executed by a processor, any one of the program upgrade methods in the above embodiments is implemented.
[0255] An embodiment of the present application also provides a computer program product, including a computer program, which implements any one of the program upgrade methods in the above embodiments when the computer program is processed and executed.
[0256] It should be understood that the present application is not limited to the specific configurations and processes described above and illustrated in the figures. For the sake of brevity, a detailed description of known methods is omitted here. In the above embodiments, several specific steps are described and illustrated as examples. However, the method process of the present application is not limited to the specific steps described and illustrated. Those skilled in the art can make various changes, modifications, and additions, or change the order of the steps after understanding the spirit of the present application.
[0257] The functional blocks shown in the above-described block diagram can be implemented as hardware, software, firmware or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of the present application are programs or code segments that are used to perform the required tasks. The program or code segment can be stored in a machine-readable medium, or transmitted on a transmission medium or a communication link by a data signal carried in a carrier wave. "Machine-readable medium" can include any medium that can store or transmit information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROMs, flash memories, erasable ROMs (EROMs), floppy disks, CD-ROMs, optical disks, hard disks, optical fiber media, radio frequency (RF) links, etc. The code segment can be downloaded via a computer network such as the Internet, an intranet, etc.
[0258] Based on the same inventive concept, corresponding to any of the above-mentioned embodiments, the present application also provides a vehicle, which includes a program upgrade device and / or electronic device of any of the above-mentioned embodiments, and the electronic device executes any of the above-mentioned program upgrade methods.
[0259] It should also be noted that the exemplary embodiments mentioned in this application describe some methods or systems based on a series of steps or devices. However, this application is not limited to the order of the above steps. In other words, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.
[0260] Aspects of the present disclosure have been described above with reference to the flowcharts and / or block diagrams of the methods, devices (systems) and computer program products according to the embodiments of the present disclosure. It should be understood that each box in the flowchart and / or block diagram and the combination of each box in the flowchart and / or block diagram can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer or other programmable data processing device to produce a machine so that these instructions executed by the processor of the computer or other programmable data processing device enable the implementation of the function / action specified in one or more boxes of the flowchart and / or block diagram. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor or a field programmable logic circuit. It is also understood that each box in the block diagram and / or flowchart and the combination of the boxes in the block diagram and / or flowchart can also be implemented by dedicated hardware that performs the specified function or action, or can be implemented by a combination of dedicated hardware and computer instructions.
[0261] The above description is only a specific embodiment of the present application. Those skilled in the art will clearly understand that for the convenience and brevity of description, the specific working processes of the systems, modules and units described above can refer to the corresponding processes in the aforementioned method embodiments, and will not be repeated here. It should be understood that the scope of protection of the present application is not limited thereto. Any person skilled in the art can easily think of various equivalent modifications or replacements within the technical scope disclosed in the present application, and these modifications or replacements should be included in the scope of protection of the present application.
Claims
1. A program upgrade method, characterized in that: Applied to a controller, the controller includes a first boot program and a first application program; the method includes: In response to initiating an upgrade of the first application, receiving a preset identification number, and verifying whether the received identification number is correct using the identification number of the first boot program; If the received identification number is correct, erasing the first application; receiving a communication frame, the communication frame including a frame identifier and program data for constituting a second application, the second application being used to replace the first application; When the frame identifier indicates an end frame, obtaining a cumulative check code of the communication frame; When the acquired cumulative verification code is consistent with the preset cumulative verification code, it is determined that the downloading of each program data of the second application program is completed.
2. The program upgrade method according to claim 1, wherein: Before initiating the upgrade of the first application in response, the method further includes: receiving an instruction to initiate an upgrade; Write a reprogramming flag into the preset reprogramming flag bit; Restarting the first boot program, and reading the written reprogramming flag from the reprogramming flag bit; Determine whether the written reprogramming flag is consistent with the preset reprogramming flag value; When the written reprogramming flag is consistent with the preset reprogramming flag value, the upgrade of the first application is started.
3. The program upgrade method according to claim 2, characterized in that: After determining whether the written reprogramming flag is consistent with the preset reprogramming flag value, the method further includes: When the written reprogramming flag is inconsistent with the preset reprogramming flag value, the current application valid flag is read from the preset application valid flag bit; Determine whether the current application valid flag is consistent with the preset application valid value; When the application validity flag is inconsistent with the preset application validity value, the upgrade of the first application is started.
4. The program upgrade method according to claim 2, wherein: After receiving the instruction to start the upgrade, the method further includes: Checking whether the reprogramming flag has been written into the reprogramming flag, and checking whether the preset application valid flag has been written into the application valid flag; When the reprogramming flag is not written into the reprogramming flag bit and the application valid flag is not written into the application valid flag bit, the upgrade of the first application is started.
5. The program upgrade method according to claim 1, wherein: Before receiving the preset identification number, the method further includes: Receive security keys; When the security key is verified to be correct, the system waits for receiving a preset identification number.
6. The program upgrade method according to claim 1, wherein: The identification number of the first boot program includes a first product number and a first version number of the first boot program; the preset identification number includes a second product number and a second version number of the second boot program; The using the identification number of the first boot program to verify whether the received identification number is correct includes: Verify whether the second product number is consistent with the first product number, and whether the second version number is greater than the first version number; In the case that the second product number is consistent with the first product number, and the second version number is greater than the first version number, it is determined that the received identification number is correct.
7. The program upgrade method according to claim 1, wherein: After receiving the communication frame, the method further includes: In a case where the frame identifier indicates a program frame, downloading program data for constituting the second application from the communication frame; Using the cumulative check code calculated for the previous communication frame as the initial value, the cumulative check code for the current communication frame is calculated; Continue to receive the next communication frame until the frame identifier of the received communication frame indicates that it is an end frame.
8. The program upgrade method according to claim 7, characterized in that: The communication frame also includes a single frame check code of the current frame; Before downloading the program data for constituting the second application from the communication frame, the method further includes: Use the preset initial value to calculate the single frame check code; Compare the calculated single frame check code with the single frame check code in the current communication frame to see if they are consistent; If they are consistent, it is determined that the currently received communication frame is valid.
9. The program upgrade method according to claim 5, characterized in that: After acquiring the cumulative check code of the communication frame, the method further includes: When the acquired cumulative verification code is inconsistent with the preset cumulative verification code, all downloaded program data is erased and the security key is received again.
10. A program upgrade device, characterized in that: Applied to a controller, the controller includes a first boot program and a first application program; the device includes: a startup module configured to, in response to initiating an upgrade of the first application, receive a preset identification number and verify whether the received identification number is correct using the identification number of the first boot program; an erasing module, configured to erase the first application if the received identification number is correct; a receiving module, configured to receive a communication frame, wherein the communication frame includes a frame identifier and program data for constituting a second application program, wherein the second application program is configured to replace the first application program; An acquisition module, configured to acquire a cumulative check code of a communication frame when the frame identifier indicates an end frame; The verification module is used to determine that the downloading of each program data of the second application program is completed when the acquired cumulative verification code is consistent with the preset cumulative verification code.