Program online upgrading system and method of multi-chip board card based on CAN network
Through the CAN network-based multi-chip board online upgrade system, the localization and independent operation problems of DSP+FPGA multi-board online upgrades are solved, efficient and reliable multi-board upgrades are achieved, the hardware structure is simplified, and the upgrade rate is improved.
Patent Information
- Application Number
- CN202510811847.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-18
- Publication Date
- 2025-09-26
AI Technical Summary
The existing DSP+FPGA multi-board online upgrade method has the problems of low localization, inability to operate FLASH independently, complex hardware structure, low efficiency, and can only operate a point-to-point mode of one board.
A multi-chip board online upgrade system based on CAN network is designed. The independent operation of DSP and FPGA boards is realized through the CAN bus. The host computer, master chip and slave chip, CAN interaction module and identification code module are used to realize the upgrade of multiple boards. The subpackaging module and verification module are used to ensure the integrity and status confirmation of the upgrade package.
The independent online upgrade of DSP and FPGA boards is realized, the tools and devices are localized, the upgrade rate is improved, the reliability is high, the hardware circuit is simple, no additional hardware resources are required, and the cost is saved.
Smart Images

Figure CN120704720A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of online upgrading of embedded software, in particular to a system and method for online upgrading of programs of a multi-chip board based on a CAN network. Background Art
[0002] Image processing, optoelectronic countermeasures, radar, satellite, and in-vehicle navigation require DSP+FPGA embedded systems with high computing speed, low power consumption, autonomous control, and high reliability. These devices are often used in harsh environments, making manual upgrades and maintenance extremely inconvenient. Frequent unpacking can also cause uncontrolled damage to the precision equipment. Therefore, online upgrade programs are crucial. Several existing online upgrade methods exist. One requires adding independent hardware chips to update the DSP and FPGA programs separately based on data packet instructions. Another involves receiving data from the FPGA and sending it to the DSP, which then updates the Flash program or the FPGA program based on a protocol. The third involves receiving data from the DSP and then updating the Flash program or the FPGA program based on a protocol. The fourth involves online FPGA program upgrades over the CAN bus. These methods require specialized hardware for online upgrades and complex Flash control processes. They are not fully domestically produced. Updates are point-to-point between the host computer and the processor, preventing multi-board updates. Furthermore, the FPGA update program relies solely on the DSP, which can interfere with the DSP's normal operation and increase susceptibility to external interference. Therefore, in response to the problems existing in the current DSP+FPGA multi-board, it is necessary to design a domestic online upgrade method based on bus FPGA or DSP that can independently operate its own external FLASH. Summary of the Invention
[0003] The purpose of the present invention is to provide a system and method for online program upgrade of a multi-chip board based on a CAN network, mainly to solve the problems of the current DSP+FPGA online upgrade method, such as low localization, inability to independently operate FLASH, complex hardware structure, low efficiency, and point-to-point mode that can only operate one board.
[0004] In order to achieve the above-mentioned purpose, the technical solution adopted by the present invention is to provide a program online upgrade system for a multi-chip board based on a CAN network, characterized in that it includes a host computer and multiple boards; the boards and the host computer communicate via a CAN bus; the boards include a master chip and a slave chip connected to each other, as well as a CAN interaction module and an identification code module; the identification code module provides different identification codes for different boards; the CAN interaction module connects the host computer and the master chip to complete the parsing of the CAN protocol; the host computer uses the identification code to select the board to be upgraded, and sends an upgrade command and an upgrade package to the selected board; after receiving the upgrade command, the board switches from business mode to upgrade mode, uses the hardware resources of conventional business to execute the upgrade business, receives the upgrade package and completes the program upgrade of the master chip or the slave chip; the board also sends a readback package to the host computer; the host computer verifies the readback package to confirm the upgrade status.
[0005] Furthermore, the host computer includes a subpackaging module and a first verification module; the subpackaging module divides the upgrade package into multiple subpackets and sends them to the board through the CAN bus; the upgrade package for the master chip and the upgrade package for the slave chip have different subpacket sizes after being divided by the subpackaging module; the first verification module uses the CAN network to read the readback package from the board, and combines it with the upgrade package to confirm the upgrade status of the board.
[0006] Furthermore, the master chip includes a main memory for storing the program of the master chip; the slave chip includes a slave memory for storing the program of the slave chip; the master chip and the host computer are connected through the CAN interaction module; the master chip and the slave chip are connected through a high-speed parallel interface.
[0007] Furthermore, the main chip includes a second verification module, a first storage module and a readback module; the main chip uses the same hardware resources to execute the regular business in the business mode and the upgrade business in the upgrade mode; the second verification module receives and verifies the integrity of the upgrade package; the main chip uses the first storage module to perform read and write operations on the main memory; the readback module reads data from the main memory through the first storage module to form the readback package, and transmits the readback package back to the host computer through the CAN interaction module.
[0008] Furthermore, the slave chip includes a third verification module and a second storage module; the third verification module receives and verifies the integrity of the upgrade package; and the slave chip uses the second storage module to perform read and write operations on the slave memory.
[0009] The present invention also discloses an upgrade method for a program online upgrade system using a multi-chip board based on a CAN network, which is characterized by comprising the steps of:
[0010] Step S100: the host computer generates the upgrade command for the board to be upgraded; the upgrade command includes the identification code of the board;
[0011] In step S200, the host computer sends the upgrade command to all the boards; the boards receive the upgrade command and compare the identification code contained in the upgrade command with their own identification code; the boards that successfully match the upgrade service execute the upgrade service; the boards that fail to match the upgrade service execute the normal service;
[0012] Step S300, the master chip parses the upgrade command. If it is the master chip upgrade, the process proceeds to step S400; if it is the slave chip upgrade, the process proceeds to step S500; if the parsing error occurs, the process jumps to step S600;
[0013] Step S400: the main chip communicates with the host computer, obtains the upgrade package, and then upgrades the program stored in the main memory; then the process jumps to step S600;
[0014] Step S500: The slave chip communicates with the host computer through the master chip, obtains the upgrade package, and then upgrades the program stored in the slave memory; during the slave chip upgrade process, the master chip can still execute other conventional services;
[0015] Step S600: The main chip terminates the upgrade service and executes the regular service.
[0016] Furthermore, in step S400, the main chip upgrade process includes sub-steps:
[0017] Step S401: the host computer sends an erase command; after the main chip parses the erase command, it uses the first storage module to erase the data in the main memory, and sends a confirmation message to the host computer if successful, or sends an error message to the host computer if failed;
[0018] Step S402: After receiving the confirmation message, the host computer uses a sub-packaging module to split the upgrade package into multiple sub-packages;
[0019] Step S403: the host computer adds a check code to the sub-packet and sends it to the main chip;
[0020] Step S404: The main chip receives the sub-packet and verifies the verification code using the second verification module; if the verification is successful, the main chip writes the sub-packet into the main memory using the first storage module;
[0021] Step S405: If there are any unsent sub-packets, go to step S403; otherwise, go to step S406;
[0022] Step S406: the host computer sends a readback command; after the main chip parses the readback command, it uses the readback module to read the data of the first and last partitions of the main memory as the readback packet, divides it into multiple sub-packets, and transmits them back to the host computer;
[0023] Step S407: After receiving all the sub-packets, the host computer splices them into the read-back packet containing the data of two partitions;
[0024] In step S408, the host computer uses the first verification module to read the data of the first and last partitions in the upgrade package, compares them with the read-back package data, and determines the upgrade status; if they are consistent, the upgrade is determined to be successful, otherwise the upgrade is determined to be failed.
[0025] Furthermore, in step S500, the chip upgrade process includes sub-steps:
[0026] Step S501: The slave chip obtains the size of the upgrade package from the upgrade command, allocates an internal buffer that can accommodate the upgrade package, and waits for the host computer to send the upgrade package.
[0027] Step S502: The host computer uses a sub-packaging module to split the upgrade package into multiple sub-packets, and adds a verification code to each sub-packet;
[0028] Step S503: the host computer sends the sub-packet to the master chip; the master chip forwards the received sub-packet to the slave chip;
[0029] Step S504: The slave chip receives the sub-packet and verifies the verification code using a third verification module; after successful verification, the sub-packets are sequentially stored in an internal cache, and a confirmation message is sent to the host computer using the master chip;
[0030] Step S505: After the host computer receives the confirmation information, if there are sub-packets to be sent, it jumps to step S503; otherwise, it goes to step S506;
[0031] Step S506, the slave chip erases the data in the slave memory using the second storage module;
[0032] In step S507 , the slave chip uses the second storage module to write the assembled upgrade package in the internal cache into the slave memory, and reports the upgrade status to the host computer through the master chip.
[0033] Furthermore, in step S402 and step S502, the host computer utilizes the sub-packaging module to split the upgrade package into a plurality of sub-packages, including the following steps:
[0034] Step S701: Different sub-package sizes are set according to the ownership of the upgrade package; for the upgrade package belonging to the master chip, the sub-package size matches the single-write partition size of the main memory; for the upgrade package belonging to the slave chip, the sub-package size matches the cache size of the master chip for transferring the sub-package;
[0035] Step S702: When the amount of remaining data in the upgrade package is greater than or equal to the sub-package size, proceed to step S703; otherwise, proceed to step S704;
[0036] Step S703: Read data of the same size as the sub-package from the upgrade package to form a new sub-package; then proceed to step S702;
[0037] Step S704: fill the remaining data in the upgrade package with fixed-pattern data until the sum of the size of the data and the filling data is consistent with the sub-package size, and then form a new sub-package using the filled data.
[0038] Furthermore, the slave chip calculates the total number of subpackages to be received using the size of the upgrade package and the size of the subpackage; each time the slave chip receives a subpackage, the total number of subpackages received is accumulated; when the total number of subpackages to be received is equal to the total number of subpackages received, the slave chip determines that all the subpackages have been received.
[0039] In view of the above technical features, the present invention provides a system and method for online program upgrade of a multi-chip board based on a CAN network, which realizes the online upgrade function of the DSP+FPGA board through the CAN bus. Compared with the prior art, the present invention has the following significant advantages: the present invention realizes that the DSP and FPGA can independently operate the FLASH connected to them, and all the tools and devices involved in the implementation are domestically produced. The same host computer can upgrade different DSP+FPGA boards online through the CAN bus, and can also independently upgrade the DSP or FPGA, and the update rate is significantly improved compared to the serial port, and the reliability is high. The present invention makes full use of existing hardware resources, the hardware circuit is simple and does not require additional hardware resources, which saves costs and is an efficient and concise solution. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] Figure 1 This is a system block diagram of a preferred embodiment of the program online upgrade system of a multi-chip board based on a CAN network of the present invention;
[0041] Figure 2 This is a system diagram of a preferred embodiment of the program online upgrade system of a multi-chip board based on a CAN network of the present invention;
[0042] Figure 3 This is a schematic diagram of board connection in a preferred embodiment of a system for online program upgrade of a multi-chip board based on a CAN network of the present invention;
[0043] Figure 4 The present invention is a flowchart of a preferred embodiment of an upgrade method of a program online upgrade system using a multi-chip board based on a CAN network.
[0044] In the figure: 100-host computer, 200-board, 210-master chip, 220-master memory, 230-slave chip, 240-slave memory, 250-CAN interaction module, 260-identification code module;
[0045] 101-subcontracting module, 102-first verification module;
[0046] 211 - second verification module, 212 - first storage module, 213 - readback module;
[0047] 231 - third verification module, 232 - second storage module. DETAILED DESCRIPTION
[0048] Below in conjunction with specific embodiment, further set forth the present invention.Should be understood that these embodiments are only used to illustrate the present invention and are not used in limiting the scope of the present invention.In addition, should be understood that after reading the content taught by the present invention, those skilled in the art can make various changes or modifications to the present invention, and these equivalent forms fall equally within the scope limited by the appended claims of the application.
[0049] See also Figure 1 、 Figure 2 and Figure 3 The present invention discloses an online program upgrade system for a multi-chip card based on a CAN network. As shown in the figure, a preferred embodiment thereof includes a host computer 100 and multiple cards 200. Multiple cards 200 form a CAN network and communicate with the host computer 100 via the CAN bus.
[0050] Each board 200 includes a master chip 210 and a slave chip 230 connected to each other, as well as a CAN interaction module 250 and an identification code module 260. In the CAN network, each board 200 has a different identification code. In the slot of the board 200, the identification code module 260 (CAN ID) is set by pull-up and pull-down resistors. The identification code module 260 reports the identification code to the board 200 based on the pull-up and pull-down states. The identification code is divided into a 5-bit source address and a 5-bit destination address. One of the 5-bit addresses is used to distinguish between the master chip 210 and the slave chip 240. Boards 200 in the same CAN network can communicate with each other. The CAN interaction module 250 is located between the host computer 100 and the master chip 210 and is used to parse the CAN protocol.
[0051] In this embodiment, the master chip 210 is an FPGA chip (SMQ325T from Shenzhen Guowei Electronics Co., Ltd.), while the slave chip 230 is a DSP chip (FT-M6678 from the National University of Defense Technology). The master chip 210 includes a main memory 220, which stores the FPGA program of the master chip 210, namely, the FPGA configuration information and FPGA execution parameters. The slave chip 230 includes a slave memory 240, which stores the program of the slave chip 230, namely, the executable image of the DSP. The main memory 220 and the slave memory 240 are SM25QH256M from Shenzhen Guowei Electronics Co., Ltd.
[0052] On board 200, master chip 210 is directly connected to host computer 100 via the CAN bus. Master chip 220 is responsible for parsing commands sent by host computer 100 and managing slave chip 230. Master chip 210 and slave chip 230 are connected via a high-speed parallel interface (EMIF), enabling high-speed information exchange.
[0053] In the online program upgrade system for multi-chip boards, the host computer 100 uses Loongson processors and can be used not only as a peripheral device but also as a board inserted into a chassis. The CAN bus uses a 1MHz transmission frequency. The host computer 100 is a fixed development tool whose primary function is to control the programming process, parse and distribute upgrade files according to the protocol, and select the target board using buttons on the display interface. The host computer 100 uses the identification code of each board 200 to select the board 200 to be upgraded, thereby sending the upgrade command and upgrade package to the selected board 200. In practice, the host computer 100 broadcasts the upgrade command to the CAN network, but includes the identification code in the upgrade command. This way, while all boards 200 on the CAN network receive the upgrade command, only those with matching identification codes will respond and switch from service mode to upgrade mode, ready to receive subsequent upgrade packages. In the present invention, upgrade tasks are executed in upgrade mode, while regular operations run in service mode. The hardware resources used for upgrade and regular operations are the same, eliminating the need for additional hardware resources for online upgrades. The upgrade service utilizes the hardware resources of the regular service to receive the upgrade package and complete the program upgrade of the master chip 210 or the slave chip 220. During the upgrade process for the master chip 210, the new program data on the master chip 210 is read back, generating a readback packet that is sent back to the host computer 100 via the CAN bus. The host computer 100 combines the upgrade package and the readback packet to confirm the upgrade status of the master chip 210.
[0054] The host computer 100 includes a subpacketization module 101 and a first verification module 102. Due to the size limit of a single transmission, the host computer 100 does not send the entire upgrade package at once. Instead, it first uses the subpacketization module 101 to split the upgrade package into multiple smaller subpackets, and then sends them to the board 200 via the CAN bus. The main chip 210 is an FPGA, and its cache resources are limited. The slave chip 220 is a DSP, which generally has a sufficiently large internal cache. Therefore, for the main chip 210 and the slave chip 220, the subpacketization module 101 will select different subpacket sizes when splitting these upgrade packages, thereby forming different splitting results. However, for the same upgrade package, the size of each subpacket after splitting is consistent, and the insufficient part will be filled with padding data. The first verification module 102 is the last to confirm the upgrade status of the main chip 210 in the upgrade process. It will use the CAN network to read the readback package from the main chip 210, and then compare it with the original upgrade package to confirm that the written data is the expected data.
[0055] The main chip 210 includes a second verification module 211, a first storage module 212, and a readback module 213. Communication between the main chip 210 and the host computer 100 is accomplished using the CAN interaction module 250, which reads and parses control commands sent from the host computer 100. If the parsed control command is an upgrade command, the main chip 210 enters upgrade mode and executes the upgrade service. In this case, the CAN interaction module 250 is responsible for providing data exchange for the upgrade service, such as transmitting upgrade packages, transmitting readback packages, and providing feedback on the upgrade status. Otherwise, the main chip 210 enters service mode and executes regular services. In this scenario, the CAN interaction module 250 provides data exchange for regular services, such as further parsing subsequent control commands and sending feedback information for regular services. During the upgrade service, the second verification module 211 is responsible for receiving the upgrade package and verifying its integrity. During the upgrade service of the main chip 210, the second verification module 211 independently verifies each subpacket of the upgrade package, verifying each subpacket upon receipt. When all sub-packets have passed verification, the upgrade package is considered to have also passed verification. The first storage module 212 implements the storage control function in the main chip 210. The main chip 210 uses the first storage module 212 to perform read and write operations on the main memory 220 connected thereto. Specifically, during the upgrade process, tasks such as erasing the main memory 220, writing each sub-packet, and reading back the updated program are all completed by the first storage module 212. In normal operations, the main chip 210's read and write operations on the main memory 220 are also completed through the first storage module 212. The read-back module 213 is used to read back part of the data in the main memory 220 after the upgrade package has been written to the main memory 220, thereby generating a read-back packet for the host computer 100 to confirm the upgrade status. The read-back module 213 reads data from the main memory 220 through the first storage module 212 to generate a read-back packet, and then uses the CAN interaction module 250 to transmit the read-back packet back to the host computer 100.
[0056] The slave chip 230 includes a third verification module 231 and a second storage module 232. The slave chip 230 is connected to the master chip 210 via a high-speed parallel interface and is not directly connected to the CAN network. The third verification module 231 receives the upgrade package from the high-speed parallel interface with the master chip 210 and then verifies its integrity. In this embodiment, the slave chip 230 has an internal cache that is large enough to accommodate the complete upgrade package. Therefore, the third verification module 231 does not verify each sub-packet, but waits until all sub-packets are spliced in the internal cache of the slave chip 230 before verifying the entire download package as a whole. The slave chip 230 uses the second storage module 232 to perform read and write operations on the slave memory 240 connected thereto. Specifically, during the upgrade process, the erasing operations on the slave memory 240 and the writing operations of the upgrade package are both completed by the second storage module 232. In normal operations, the read and write operations of the slave chip 230 on the slave memory 240 are also completed by the second storage module 232.
[0057] See also Figure 4 The present invention also discloses an upgrade method for an online program upgrade system using a multi-chip board based on a CAN network. A preferred embodiment thereof comprises the steps of:
[0058] Step S1: The host computer generates an upgrade command.
[0059] The host computer reads the corresponding upgrade file according to the upgrade requirements and generates an upgrade command for the board to be upgraded. Specifically, the upgrade command includes the identification code of the board to be upgraded.
[0060] In this embodiment, the upgrade file of the master chip is an FPGA configuration file generated by EDA software, and the upgrade file of the slave chip is a DSP executable image.
[0061] Step S2: The board responds to the upgrade command.
[0062] The host computer broadcasts the upgrade command over the CAN network, sending it to all boards on the CAN network. After a board receives the upgrade command from the CAN interaction module, the main chip extracts the identification code in the upgrade command and compares it with its own identification code. If a match is found, the board enters upgrade mode and begins executing the upgrade. Boards that fail to match ignore the upgrade command, and the relevant boards continue to execute normal operations.
[0063] Step S3: Determine whether the master chip or the slave chip is being upgraded.
[0064] The master chip further parses the upgrade command. If it is a master chip upgrade, the process proceeds to step S4 to enter the master chip upgrade process. If it is a slave chip upgrade, the process proceeds to step S5 to enter the slave chip upgrade process. If the upgrade command parse error occurs, the process jumps to step S6.
[0065] Step S4, enter the main chip upgrade process.
[0066] The main chip communicates with the host computer and uses the upgrade package to upgrade the program stored in the main memory.
[0067] Step S41, erasing the main memory.
[0068] The host computer sends an erase command. After the main chip interprets the erase command, it uses the first storage module to erase the data in the main memory. The size of the erased data depends on the upgrade package. If the erase is successful, a confirmation message is sent to the host computer. If the erase fails, an error message is sent to the host computer.
[0069] Step S42: split the upgrade package into multiple sub-packages.
[0070] After receiving the error message, the host computer will prompt manual processing, and you can retry or abandon the upgrade. After receiving the confirmation message, the host computer will use the sub-packaging module to split the upgrade package into multiple sub-packages.
[0071] The subpacket size matches the single-write partition size of the main memory. This allows a single write operation to the main memory to be initiated after each transfer, while minimizing hardware resource usage. After the subpacket size is set, the subpacket module continuously reads data from the upgrade package according to the packet size, splitting it into smaller subpackets until the remaining data in the upgrade package is less than the subpacket size. If the remaining data in the upgrade package is less than the subpacket size, the remaining data in the upgrade package is first filled into the subpacket, followed by fixed-pattern data until the subpacket size is reached, forming the final subpacket.
[0072] In this embodiment, the partition size of the main memory is 512 bytes, so the valid data size contained in the subpacket is 512 bytes. In the last subpacket, if there is free space, it is filled with 0xFF.
[0073] Step S43: Add a check code to each sub-packet and send it.
[0074] The host computer adds a check code to each sub-packet and sends it to the main chip, making it easier to detect data anomalies during the transmission process.
[0075] Step S44: verify and write the sub-package.
[0076] The main chip receives subpackets using the CAN interaction module and verifies the consistency of the subpackets with the checksum attached to the subpackets using the second verification module, thereby confirming the integrity of the subpackets. If verification is successful, the first storage module writes the received subpackets sequentially to the main memory. Specifically, the first subpacket received is written to the first location of the first partition of the main memory. Subsequent subpackets are arranged in the order of receipt in the write locations of the main memory. In other words, each subpacket corresponds to the size of one partition of the main memory.
[0077] Step S45, determining whether there are any unsent subpackets.
[0078] If there are still unsent sub-packets, jump to step S43 to continue sending and writing. Otherwise, go to step S46.
[0079] Step S46: The host computer sends a read-back command.
[0080] After all packets have been sent, the host computer sends a readback command. After the main chip interprets the readback command, it uses the readback module to read the data from the first and last partitions written to the main memory during the upgrade, and then concatenates them together to form a readback packet. The main chip splits the readback packet into multiple sub-packets and transmits them back to the host computer using the CAN interaction module. In this embodiment, the main chip splits the readback packet into 256-byte sub-packets.
[0081] Step S47: the host computer receives the read-back packet.
[0082] After receiving all the sub-packets, the host computer reassembles them into a readback packet. The assembled readback packet contains the first 256 bytes of the first partition and the last 256 bytes of the last partition written to the main memory during this upgrade, for a total of 512 bytes of data from the two partitions. This is exactly the maximum data that can be carried by a set of CAN packets in this embodiment. In other words, a readback packet can be generated using a set of CAN packets.
[0083] Step S48: Obtain the upgrade status.
[0084] The host computer uses the first verification module to read the data of the first and last partitions from the upgrade package and compares them with the data at the corresponding locations in the readback package. If the two are consistent, the upgrade is considered successful; otherwise, the upgrade is considered unsuccessful. Jump to step S6.
[0085] Step S5, enter the chip upgrade process.
[0086] The slave chip communicates with the host computer through the master chip, and uses the upgrade package to upgrade the program stored in the slave memory. During the slave chip upgrade process, the master chip is responsible for transferring data and can still perform other conventional operations.
[0087] Step S51: Allocate internal cache from the chip.
[0088] The upgrade command includes the size of the subsequent upgrade package. The slave chip obtains the size of the upgrade package from the upgrade command, allocates space in its internal cache to accommodate the upgrade package, and then waits for the host computer to send the upgrade package.
[0089] Step S52: The host computer divides the upgrade package.
[0090] Data from the slave chip must be transferred through the master chip. Furthermore, the transmission of the upgrade package must not affect other services on the master chip. Therefore, the size of the subpacket is limited. The specific size of the subpacket matches the cache size of the master chip for transferring subpackets. After the subpacket size is set, the subpacket module continuously reads data from the upgrade package according to the packet size, splitting it into smaller subpackets until the remaining data in the upgrade package is less than the subpacket size. If the remaining data in the upgrade package is less than the subpacket size, the subpacket is first filled with the remaining data from the upgrade package, followed by fixed-pattern data until the subpacket size is reached, forming the final subpacket.
[0091] The host computer adds a check code to each sub-packet and then sends it to the slave chip, making it easy to detect data anomalies during the transmission process.
[0092] In this embodiment, the subpacketization module transmits the upgrade package in groups of 65 CAN packets. The first CAN packet is a command packet, and the subsequent 64 CAN packets are data packets. Each data packet is 8 bytes, for a total of 512 bytes. If the last group of data packets is less than 64, 0xFF is added.
[0093] Step S53: The host computer sends the sub-packet.
[0094] The host computer sends the sub-packets to the master chip, which then forwards them to the slave chip.
[0095] Step S54: Save the sub-packet from the chip.
[0096] After receiving the sub-packet, the slave chip uses the third verification module and the verification code included in the sub-packet to check the integrity of the sub-packet. After verification, the slave chip saves the sub-packets in a pre-allocated internal buffer and sends a confirmation message to the host computer through the master chip.
[0097] Step S55: After the host computer receives the confirmation information, if there are sub-packets to be sent, it jumps to step S53; otherwise, it goes to step S56.
[0098] In this embodiment, the size of a subpacket is 512 bytes. When creating subpackets, the host computer divides the number of bytes in the upgrade package by 512, takes the result modulo 1, and adds the result to obtain the total number of subpackets to be sent. The number of subpackets sent is counted after each transmission. When the transmission count equals the total number of subpackets, the transmission is considered complete.
[0099] Step S56: Erasing data from the memory of the chip.
[0100] Upon receiving the upgrade command, the slave chip knows the size of the upgrade package. Each subpacket is a fixed size. Therefore, the slave chip divides the upgrade package size by the subpacket size to calculate the total number of subpackets it should receive. Each time the slave chip receives a subpacket, it accumulates the total number of subpackets it has received. When the total number of subpackets it should receive equals the total number of subpackets it has received, the slave chip determines that all subpackets have been received.
[0101] After the slave chip determines that all sub-packets have been received, the second storage module is used to erase the data in the slave memory in preparation for writing the upgrade package. The specific erased size is calculated based on the size of the upgrade package.
[0102] Step S57: writing the upgrade package into the chip.
[0103] The slave chip uses the second storage module to write the complete upgrade package to the slave memory at once, and then reports the upgrade status to the host computer through the master chip. The upgrade status of the slave chip includes specific information such as upgrade completion, slave memory erase failure, or slave memory write failure.
[0104] Step S6, completing the upgrade.
[0105] After the upgrade package is processed, the main chip terminates the upgrade and performs normal operations. The staff reads the upgrade status and considers re-upgrading or checking the device status if it fails.
[0106] The above description is only a preferred embodiment of the present invention and does not limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made by using the contents of the present invention description and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.
Claims
1. A system for online program upgrade of multi-chip boards based on CAN network, characterized in that , including a host computer and multiple boards; the boards and the host computer communicate through the CAN bus; the boards include a master chip and a slave chip connected to each other, as well as a CAN interaction module and an identification code module; the identification code module provides different identification codes for different boards; the CAN interaction module connects the host computer and the master chip to complete the parsing of the CAN protocol; the host computer uses the identification code to select the board to be upgraded, and sends an upgrade command and an upgrade package to the selected board; after receiving the upgrade command, the board switches from business mode to upgrade mode, uses the hardware resources of conventional business to perform the upgrade business, receives the upgrade package and completes the program upgrade of the master chip or the slave chip; the board also sends a readback package to the host computer; the host computer verifies the readback package to confirm the upgrade status.
2. The system for online program upgrade of a multi-chip board based on a CAN network according to claim 1, characterized in that: The host computer includes a subpackaging module and a first verification module; the subpackaging module divides the upgrade package into multiple subpackets and sends them to the board through the CAN bus; the upgrade package for the master chip and the upgrade package for the slave chip have different subpacket sizes after being divided by the subpackaging module; the first verification module uses the CAN network to read the readback package from the board, and combines it with the upgrade package to confirm the upgrade status of the board.
3. The system for online program upgrade of a multi-chip board based on a CAN network according to claim 1, characterized in that: The master chip includes a main memory for storing the program of the master chip; the slave chip includes a slave memory for storing the program of the slave chip; the master chip and the host computer are connected through the CAN interaction module; the master chip and the slave chip are connected through a high-speed parallel interface.
4. The system for online program upgrade of a multi-chip board based on a CAN network according to claim 3, characterized in that: The main chip includes a second verification module, a first storage module, and a readback module; the main chip uses the same hardware resources to execute the regular service in the service mode and the upgrade service in the upgrade mode; the second verification module receives and verifies the integrity of the upgrade package; The main chip uses the first storage module to perform read and write operations on the main memory; the readback module reads data from the main memory through the first storage module to form the readback packet, and transmits the readback packet back to the host computer through the CAN interaction module.
5. The system for online program upgrade of a multi-chip board based on a CAN network according to claim 3, characterized in that: The slave chip includes a third verification module and a second storage module; the third verification module receives and verifies the integrity of the upgrade package; the slave chip uses the second storage module to perform read and write operations on the slave memory.
6. A method for upgrading a program online upgrading system using a multi-chip board based on a CAN network, characterized in that: Contains steps, Step S100, the host computer generates the upgrade command for the board to be upgraded; The upgrade command includes the identification code of the board; Step S200, the host computer sends the upgrade command to all the boards; The board receives the upgrade command and compares the identification code included in the upgrade command with its own identification code; The board that is successfully matched executes the upgrade service; the board that is unsuccessfully matched executes the regular service; Step S300, the master chip parses the upgrade command. If it is the master chip upgrade, the process proceeds to step S400; if it is the slave chip upgrade, the process proceeds to step S500; if the parsing error occurs, the process jumps to step S600; Step S400: the main chip communicates with the host computer, obtains the upgrade package, and then upgrades the program stored in the main memory; Jump to step S600; Step S500: The slave chip communicates with the host computer through the master chip, obtains the upgrade package, and then upgrades the program stored in the slave memory; during the slave chip upgrade process, the master chip can still execute other conventional services; Step S600: The main chip terminates the upgrade service and executes the regular service.
7. The method for upgrading a program online upgrading system using a multi-chip board based on a CAN network according to claim 6, characterized in that: In step S400, the main chip upgrade process includes sub-steps: Step S401: the host computer sends an erase command; after the main chip parses the erase command, it uses the first storage module to erase the data in the main memory, and sends a confirmation message to the host computer if successful, or sends an error message to the host computer if failed; Step S402: After receiving the confirmation message, the host computer uses a sub-packaging module to split the upgrade package into multiple sub-packages; Step S403: the host computer adds a check code to the sub-packet and sends it to the main chip; Step S404: the main chip receives the sub-packet and verifies the verification code using a second verification module; If the verification is successful, the sub-packet is written into the main memory using the first storage module; Step S405: If there are any unsent sub-packets, jump to step S403; Otherwise, proceed to step S406; Step S406, the host computer sends a read-back command; After parsing the read-back command, the main chip uses a read-back module to read the data of the first and last partitions of the main memory as the read-back packet, divides the data into multiple sub-packets, and transmits the sub-packets back to the host computer; Step S407: After receiving all the sub-packets, the host computer splices them into the read-back packet containing the data of two partitions; In step S408, the host computer uses the first verification module to read the data of the first and last partitions in the upgrade package, compares them with the read-back package data, and determines the upgrade status; if they are consistent, the upgrade is determined to be successful, otherwise the upgrade is determined to be failed.
8. The method for upgrading a program online upgrading system using a multi-chip board based on a CAN network according to claim 6, characterized in that: In step S500, the chip upgrade process includes the following sub-steps: Step S501: The slave chip obtains the size of the upgrade package from the upgrade command, allocates an internal buffer that can accommodate the upgrade package, and waits for the host computer to send the upgrade package. Step S502: The host computer uses a sub-packaging module to split the upgrade package into multiple sub-packets, and adds a verification code to each sub-packet; Step S503: the host computer sends the sub-packet to the master chip; the master chip forwards the received sub-packet to the slave chip; Step S504: The slave chip receives the sub-packet and verifies the verification code using a third verification module; after successful verification, the sub-packets are sequentially stored in an internal cache, and a confirmation message is sent to the host computer using the master chip; Step S505: After the host computer receives the confirmation information, if there are sub-packets to be sent, it jumps to step S503; otherwise, it goes to step S506; Step S506, the slave chip erases the data in the slave memory using the second storage module; In step S507 , the slave chip uses the second storage module to write the assembled upgrade package in the internal cache into the slave memory, and reports the upgrade status to the host computer through the master chip.
9. The method for upgrading a program online upgrading system using a multi-chip board based on a CAN network according to any one of claims 7 or 8, characterized in that: In step S402 and step S502, the host computer uses the sub-packaging module to split the upgrade package into multiple sub-packages, which includes the following steps: Step S701: Different sub-package sizes are set according to the ownership of the upgrade package; for the upgrade package belonging to the master chip, the sub-package size matches the single-write partition size of the main memory; for the upgrade package belonging to the slave chip, the sub-package size matches the cache size of the master chip for transferring the sub-package; Step S702: When the amount of remaining data in the upgrade package is greater than or equal to the sub-package size, proceed to step S703; otherwise, proceed to step S704; Step S703: Read data of the same size as the sub-package from the upgrade package to form a new sub-package; Go to step S702; Step S704: fill the remaining data in the upgrade package with fixed-pattern data until the sum of the size of the data and the filling data is consistent with the sub-package size, and then form a new sub-package using the filled data.
10. The method for upgrading a program online upgrading system using a multi-chip board based on a CAN network according to claim 8, characterized in that: The slave chip calculates the total number of subpackets to be received using the size of the upgrade package and the size of the subpackets; each time the slave chip receives a subpacket, the total number of subpackets received is accumulated; When the total number of the receivable subpackets is equal to the total number of the received subpackets, the slave chip determines that all the subpackets are received.