A BMS non-inductive upgrading system and method based on a hardware holding circuit
By maintaining power supply during microcontroller reset through isolation diodes and holding capacitors in the hardware holding circuit, the problem of power interruption during remote upgrades of the battery management system is solved, enabling seamless upgrades and data transmission of the battery management system and ensuring the normal operation of downstream devices.
Patent Information
- Application Number
- CN202610687366.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-05-19
- Publication Date
- 2026-08-25
- Estimated Expiration
- 2046-05-19
AI Technical Summary
The existing battery management system suffers from a technical problem during remote upgrades where microcontroller resets cause power outages, leading to abnormal shutdowns of downstream host equipment and loss of critical business data.
The BMS seamless upgrade system adopts a hardware-based holding circuit. It utilizes the power holding path formed by the isolation diode, holding capacitor and driving transistor in the millisecond-level switching circuit to maintain the output control circuit's external power supply during microcontroller reset. Under the control of the secure firmware, new firmware is written and key operating status parameters are synchronized in the parameter configuration area to ensure power supply continuity.
It solves the power interruption problem caused by microcontroller reset, ensures continuous power supply to downstream host equipment, avoids abnormal shutdown and loss of critical business data, and achieves seamless connection of the upgrade process and seamless data transfer.
Smart Images

Figure CN122239563B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of battery management technology, and in particular to a seamless upgrade system and method for a BMS based on a hardware holding circuit. Background Technology
[0002] As the core control unit of energy storage systems and electric vehicles, the stable operation of the battery management system is directly related to the safety and reliability of the entire energy chain. With the popularization of the Internet of Things and over-the-air technology, upgrading the firmware of the battery management system remotely has become the mainstream operation and maintenance method in the industry. Function iteration and vulnerability repair can be completed without on-site operation by technical personnel. In a typical remote upgrade process, the battery management system receives the new version firmware data packet through the wireless communication module, temporarily stores it in the local memory, and completes the firmware replacement and activation during the idle period after integrity verification.
[0003] However, existing remote upgrade solutions for battery management systems generally follow a serial process of "downloading the complete firmware package, erasing the original firmware storage area after verification, writing the new firmware, and triggering a microcontroller reset to load the new firmware." This process has an unavoidable technical contradiction: the activation of the new firmware inevitably requires the microcontroller to perform a hardware reset. At the moment of reset, all general-purpose input / output pins of the microcontroller will enter a high-impedance state, causing the relay drive signals it controls to be lost. The high-voltage relay will disconnect during the reset, interrupting the external power supply of the battery pack. For downstream host equipment that relies on the battery management system for power supply or communication, this instantaneous power outage will cause abnormal shutdown, resulting in the loss of real-time operating data, reduced equipment lifespan, and may even trigger a cascading reaction of inverter protection in scenarios such as energy storage power stations, posing a safety hazard. If an abnormal power outage occurs during the firmware writing process, the erased original firmware cannot be recovered, and the new firmware has not yet been written, leaving the battery management system in an unrecoverable "bricked" state.
[0004] Therefore, the inventors urgently need a BMS seamless upgrade system and method based on hardware holding circuits to solve the above-mentioned technical problems. Summary of the Invention
[0005] To address the shortcomings of the prior art, this invention provides a seamless upgrade system and method for a BMS based on a hardware holding circuit. The aim is to solve the technical problem in the prior art where the power supply to the external system is interrupted due to microcontroller reset during remote upgrades, which in turn leads to abnormal shutdown of downstream host equipment and loss of critical business data.
[0006] To achieve the above objectives, the technical solution adopted by this invention is: a BMS seamless upgrade system based on a hardware holding circuit, comprising a microcontroller, a communication circuit, an output control circuit, and a memory. The output control circuit includes a millisecond-level switching circuit, which includes an isolation diode, a holding capacitor, and a driving transistor. The positive terminal of the isolation diode is connected to the control pin of the microcontroller, and the negative terminal of the isolation diode is connected to the first terminal of the holding capacitor and the control terminal of the driving transistor, respectively. This forms a charge holding path during microcontroller reset, whereby the unidirectional conductivity of the isolation diode prevents the charge of the holding capacitor from flowing back into the microcontroller, and the holding capacitor maintains the conducting state of the driving transistor. The memory is divided into a safe area, an upgrade area, and a parameter configuration area independent of the safe area and the upgrade area. The parameter configuration area is used to store boot flags and key operating status parameters. The system is configured to maintain the output control circuit's external power supply under the control of the currently running firmware formed by loading and running the firmware of the security zone, while writing data received through the communication circuit into the upgrade zone to form new firmware and perform verification. After successful verification, the firmware of the security zone synchronizes the key operating status parameters to the parameter configuration area. After synchronization, the boot flag in the parameter configuration area is modified to point to the upgrade zone, triggering a microcontroller reset. After the microcontroller resets, it loads the new firmware in the upgrade zone by reading the boot flag in the parameter configuration area. After the new firmware starts, it reads the key operating status parameters from the parameter configuration area to take over control. During this reset, the holding capacitor provides a holding voltage to the control terminal of the drive transistor to maintain the conduction state of the drive transistor, thereby ensuring that the output control circuit's external power supply is uninterrupted.
[0007] Based on the above, the beneficial effect of a hardware-based seamless upgrade system for BMS is to solve the technical problem in the prior art where the power supply to the external system is interrupted due to microcontroller reset during remote upgrades, leading to abnormal shutdown of downstream host equipment and loss of critical business data; mainly reflected in: 1. This invention utilizes a charge holding path composed of an isolation diode, a holding capacitor, and a driving transistor in a millisecond-level switching circuit. During the microcontroller reset, the unidirectional conductivity of the isolation diode prevents the charge of the holding capacitor from flowing back into the microcontroller, and the holding capacitor provides a holding voltage to the control terminal of the driving transistor to maintain the conducting state of the driving transistor. This ensures that the output control circuit does not experience power supply interruption, thus solving the problem of power supply interruption caused by microcontroller reset. 2. This invention maintains the output control circuit's power supply to the outside world under the control of the currently running firmware formed by loading and running the firmware in the security zone, while writing data into the upgrade area to form new firmware, and triggering a reset after the boot flag bit in the parameter configuration area is modified, so that the output control circuit always maintains power output to the outside world throughout the upgrade process. The downstream host equipment can maintain the power supply continuity without performing shutdown or restart operations, thus solving the problem of abnormal shutdown of the downstream host equipment. 3. This invention synchronizes key operating status parameters to the parameter configuration area after the firmware in the security zone passes verification, and reads key operating status parameters from the parameter configuration area after the new firmware starts to take over control. This makes the operating status before and after the upgrade seamless. The business data of the downstream host device is not interrupted or lost because it is always in a normal power supply and stateful operating environment, thus solving the problem of loss of key business data.
[0008] Furthermore, the holding capacitor is a solid electrolytic capacitor, and the capacitance value of the holding capacitor is determined according to the formula C_hold≥I_hold×T_reset / (V_stat-V_min), where C_hold is the capacitance value of the holding capacitor, I_hold is the current consumed by the control terminal of the driving transistor during reset, T_reset is the total time required for the microcontroller to reset from its reset until the new firmware sets the control pin to a high level again, V_stat is the high-level voltage output by the control pin when the microcontroller is running normally, and V_min is the minimum control voltage required to keep the driving transistor on.
[0009] Based on the above, the beneficial effect of the holding capacitor is that it utilizes the characteristics of solid electrolytic capacitors, such as high capacitance stability and low equivalent series resistance over a wide temperature range, to ensure that when the holding capacitor provides a holding voltage to the control terminal of the drive transistor during microcontroller reset, its discharge characteristics are not significantly affected by ambient temperature, thereby ensuring the reliability of the charge holding path.
[0010] Furthermore, the driving transistor is a MOSFET, the control terminal of the driving transistor is the gate, the negative terminal of the isolation diode is connected to the gate of the MOSFET, the first terminal of the holding capacitor is connected to the gate of the MOSFET, and the second terminal of the holding capacitor is grounded.
[0011] Based on the above, the advantages of using a MOSFET are as follows: By employing a voltage-controlled device as the driver, and utilizing its high gate input impedance and extremely low drive current, the holding capacitor only needs to provide nanoamp-level gate leakage current to maintain the conduction state during microcontroller reset. This significantly reduces the demand for holding capacitor capacity within the same reset window, or provides a longer power-down hold time with the same capacitance. The advantage of connecting the negative terminal of the isolation diode to the gate of the MOSFET is that the isolation diode can transmit the high level output from the control pin to the gate and charge the holding capacitor during normal microcontroller operation, while during microcontroller reset... When the control pin becomes high-impedance, the unidirectional conductivity of the isolation diode prevents the charge stored in the holding capacitor from flowing back into the microcontroller through the control pin, ensuring that all the energy stored in the holding capacitor is used only to maintain the gate's on-state voltage. The beneficial effect of grounding the second terminal of the holding capacitor is that connecting the second terminal of the holding capacitor to the system ground potential allows the voltage across its terminals to be directly applied between the gate and source of the MOSFET when the holding capacitor discharges, providing the gate with a complete drive voltage relative to the source. This avoids the drive transistor being mistakenly turned off due to reference potential fluctuations, ensuring the deterministic operation of the millisecond-level switching circuit throughout the entire reset window of the microcontroller.
[0012] Furthermore, the key operating status parameters include at least the battery's state of charge, health status, relay status, and fault code information.
[0013] Based on the above, the benefits of incorporating the state of charge (SOC) into key operating parameters are as follows: First, it allows the new firmware to directly inherit the estimated remaining battery capacity from before the upgrade, eliminating the need for re-initializing the SOC and preventing display jumps or errors due to upgrade resets, thus ensuring the continuity of battery range prediction. Second, it allows the new firmware to immediately obtain battery aging assessment data upon takeover control, eliminating the need to re-accumulate charge / discharge cycle data for health status modeling, ensuring seamless continuation of battery safety warnings and lifespan management strategies. Third, it allows the new firmware to accurately determine the on / off positions of each relay before the upgrade, preventing incorrect switching operations due to unknown relay states after reset, and ensuring topological consistency of the battery pack's external power supply circuits before and after the upgrade. Fourth, it allows the new firmware to fully inherit historical fault information recorded by the system before the upgrade, preventing interruptions in the fault diagnosis record chain due to firmware switching, and ensuring the integrity of fault traceability throughout the battery management system's lifecycle.
[0014] Furthermore, the microcontroller can be reset by executing a software reset command or by causing the watchdog timer to time out.
[0015] Based on the above, the beneficial effects of the software reset instruction are that after the system's boot flag in the parameter configuration area is modified to point to the upgrade area, the reset process can be started immediately without waiting for external hardware trigger conditions, thereby shortening the time interval between modifying the flag and the start of loading the new firmware and reducing unnecessary delays in the upgrade process. The beneficial effect of the watchdog timer timeout trigger reset is that even if an exception occurs in the code segment before the reset is executed or the software reset instruction is not successfully executed due to an infinite loop, the microcontroller can still be reliably reset because the watchdog timer is not cleared in time. This provides a hardware guarantee path for triggering the microcontroller reset that is independent of the main program execution flow, ensuring that the system will inevitably complete the reset action after the boot flag is modified in order to enter the loading process of the new firmware.
[0016] Furthermore, the system is also configured such that: after the new firmware is started, it performs a self-test; if the self-test fails or an upgrade success signal is not sent to the cloud within a preset time, the boot flag in the parameter configuration area is modified to point to the secure area, and the microcontroller is reset again to load the firmware back into the secure area.
[0017] Based on the above, the beneficial effect of performing a self-test after the new firmware starts is that after the new firmware is loaded in the upgrade zone, the system can actively verify the integrity and correctness of the new firmware's operation. This allows potential firmware corruption or compatibility issues to be detected before the new firmware officially takes over the control of the output control circuit, preventing the battery management system from malfunctioning due to prolonged operation of abnormal firmware. The beneficial effect of loading the firmware back to the safe zone is that after the new firmware is determined to be abnormal, by modifying the boot flag in the parameter configuration area and triggering the microcontroller reset again, the system can automatically revert to the firmware version that has been verified through long-term operation in the safe zone before the upgrade. This restores the usable state of the battery management system without manual intervention, ensuring that the continuous power supply to the external system by the output control circuit is not interrupted for a long time due to the abnormality of the new firmware.
[0018] Furthermore, the communication circuit, the output control circuit, and the memory are all electrically connected to the microcontroller.
[0019] Based on the above, the beneficial effects of electrically connecting the communication circuit to the microcontroller are that it enables the microcontroller to receive data packets of new firmware online through the communication circuit, providing a physical transmission channel for the system to complete the writing of new firmware data while maintaining the power supply to the output control circuit, thus realizing the real-time reception of upgrade data and the parallel execution of the upgrade process; the beneficial effects of electrically connecting the output control circuit to the microcontroller are that it enables the microcontroller's control pins to directly drive the millisecond-level switching circuit in the output control circuit, ensuring that the output control circuit can still maintain external power supply through the holding voltage of the holding capacitor during microcontroller reset, thus realizing the electrical connection between the control link and the power-down retention path; the beneficial effects of electrically connecting the memory to the microcontroller are that it enables the microcontroller to directly perform read and write operations on the safe area, the upgrade area, and the parameter configuration area, providing a local high-speed data access path for firmware execution data writing and state synchronization in the safe area, as well as loading the new firmware in the upgrade area after reset, ensuring the feasibility of data operations at each stage of the upgrade process.
[0020] Furthermore, this invention provides a BMS seamless upgrade method based on hardware holding circuitry, comprising the following steps: S1: The system operates normally under the control of the firmware in the secure zone. The microcontroller outputs a high level through the control pin, which charges the holding capacitor through the isolation diode and drives the driver transistor to conduct, so that the output control circuit can continuously supply power to the outside. S2: The communication circuit receives the data packets of the new firmware online and writes the data packets of the new firmware into the upgrade area of the memory. Each time a data packet is written, an integrity check is performed until all data packets are written and the check is passed, so as to form the new firmware in the upgrade area. S3: The firmware of the security zone will synchronize key operating status parameters to the parameter configuration area; S4: Modify the guide flag in the parameter configuration area so that the guide flag points to the area to be upgraded, and then trigger the microcontroller to reset; S5: During the microcontroller reset process, the control pin of the microcontroller becomes a high-impedance state, the isolation diode is turned off, and the holding capacitor begins to discharge to the control terminal of the drive transistor, so as to maintain the conduction state of the drive transistor during the microcontroller reset and ensure that the external power supply is not interrupted. S6: After the microcontroller is reset, the new firmware in the upgrade area is loaded by reading the boot flag bit in the parameter configuration area; S7: After the new firmware starts, it reads the key operating status parameters from the parameter configuration area to restore the working state, and immediately sets the control pin to a high level to charge the holding capacitor to restore the steady state.
[0021] S8: After the new firmware runs stably, a successful upgrade signal is sent to the cloud, and the area to be upgraded is remarked as a new secure area.
[0022] Based on the above, the beneficial effect of S1 is that by ensuring the system is in the safe zone under the control of the firmware before the upgrade process starts, and by having the microcontroller output a high level through the control pin to charge the holding capacitor via the isolation diode, the millisecond-level switching circuit is in a fully loaded ready state before entering the upgrade process, laying the initial energy foundation for the independent power supply of the holding capacitor during the subsequent reset window period. The beneficial effect of S2 is that by using a writing strategy that receives new firmware data packets online and verifies each packet in real time, the formation and verification processes of the new firmware in the upgrade zone are completed synchronously, avoiding the need for retransmission of the entire packet due to a single packet error during centralized verification after all data packets have been written. This reduces intermittent loss while ensuring that the new firmware ultimately formed in the upgrade area has integrity and executability before triggering a reset; the beneficial effect of S3 is that by placing the action of synchronizing key operating state parameters to the parameter configuration area after verification and before the reset trigger, the state data stored in the parameter configuration area is strictly aligned with the operating state of the firmware at the last moment in the security area, providing an accurate state starting point for the new firmware to take over control after startup; the beneficial effect of S4 is that by first modifying the boot flag to point to the upgrade area and then triggering the microcontroller reset, the boot program can immediately determine the correct direction based on the boot flag after the microcontroller reset. The selection of the upgrade area as the loading target avoids the uncertainty or misloading issues that may occur when modifying the flag bit after reset. The beneficial effect of S5 is that by clearly defining the chain of electrical state transitions during the microcontroller reset process—the control pin becoming high-impedance, the isolation diode turning off, and the holding capacitor starting to discharge the control terminal of the drive transistor—the power supply maintenance mechanism within the reset window has a complete logical chain from trigger condition to execution path, ensuring the reproducibility of the technical effect of uninterrupted external power supply. The beneficial effect of S6 is that by prioritizing the reading of the boot flag bit in the parameter configuration area after microcontroller reset before loading the upgrade area... The new firmware ensures that the bootloader's first execution path after the microcontroller is reset is explicitly controlled by the boot flag, avoiding loading errors caused by the hardware settings of the default loading area after reset not matching the upgrade intent. The beneficial effect of S7 is that after the new firmware starts up, it prioritizes reading key operating status parameters from the parameter configuration area to restore the working state and immediately sets the control pins back to high level to charge the holding capacitor. This dual preemptive action allows the new firmware to complete the two key tasks of state inheritance and power restoration as soon as it takes over control, compressing the reset window period to within the initialization time of the new firmware and minimizing the duration of the system in the power holding state.The beneficial effect of S8 is that after the new firmware runs stably, it sends an upgrade success signal to the cloud and re-marks the upgrade area as the new secure area in a closed-loop confirmation process. This allows the cloud to clearly know that the upgrade is complete and can perform subsequent version management. At the same time, the roles of the partitions in the storage are swapped, and the system will use the new secure area as a reliable benchmark in the next round of upgrades, providing a sustainable dual-zone alternation architecture for multiple consecutive upgrades.
[0023] Furthermore, the microcontroller reset period includes the entire process from triggering the reset, executing the boot code, loading the new firmware to the new firmware completing initialization and executing step S7, and the total time of this process does not exceed 200 milliseconds.
[0024] Based on the above, the beneficial effect of a total time of no more than 200 milliseconds is that it provides the maximum discharge time boundary under the most unfavorable operating conditions for calculating the capacitance value of the holding capacitor, so that the selection of the holding capacitor can be designed and verified based on this upper limit value, ensuring that the power supply of the output control circuit is not interrupted in all reset and start-up scenarios of the microcontroller.
[0025] To make the above-mentioned features of the present invention and the objectives to be achieved clearer, the present invention will be further described below in conjunction with the accompanying drawings and specific embodiments. Attached Figure Description
[0026] Figure 1 This is a schematic diagram of the system signal connections of the present invention; Figure 2 : This is a schematic diagram of the memory of the present invention; Figure 3 : This is the circuit diagram of the present invention; Figure 4 : This is a flowchart of the BMS seamless upgrade method of the present invention. Detailed Implementation
[0027] See Figures 1-4 As shown, This invention discloses a seamless upgrade system for a BMS based on a hardware holding circuit, including a microcontroller, a communication circuit, an output control circuit, and a memory. The output control circuit includes a millisecond-level switching circuit, which comprises an isolation diode, a holding capacitor, and a driving transistor. The anode of the isolation diode is connected to a control pin of the microcontroller, and the cathode of the isolation diode is connected to the first terminal of the holding capacitor and the control terminal of the driving transistor, respectively. This forms a charge holding path during microcontroller reset, where the unidirectional conductivity of the isolation diode prevents the charge of the holding capacitor from flowing back into the microcontroller, and the holding capacitor maintains the conducting state of the driving transistor. The memory is divided into a safe area, an upgrade area, and a parameter configuration area independent of the safe area and the upgrade area. The parameter configuration area stores boot flags and key operating status parameters. The system is configured to... While maintaining the output control circuit's external power supply under the control of the currently running firmware formed by loading and running the firmware of the security zone, the data received through the communication circuit is written into the upgrade area to form new firmware and verified. After verification, the firmware of the security zone synchronizes the key operating status parameters to the parameter configuration area. After synchronization, the boot flag in the parameter configuration area is modified to point to the upgrade area and triggers the microcontroller to reset. After the microcontroller resets, it loads the new firmware in the upgrade area by reading the boot flag in the parameter configuration area. After the new firmware starts, it reads the key operating status parameters from the parameter configuration area to take over control. During this reset, the holding capacitor provides a holding voltage to the control terminal of the drive transistor to maintain the conduction state of the drive transistor, thereby ensuring that the output control circuit's external power supply is uninterrupted.
[0028] In this embodiment, the millisecond-level switching circuit is located inside the output control circuit. The control pin is the DSG pin of the microcontroller, the driving transistor is an N-channel enhancement-mode MOS transistor, the source of the driving transistor is grounded, and the drain serves as the output terminal of the output control circuit for external power supply. The storage capacity of the safe area and the upgrade area are equal, and they are logically distinguished by the boot flag bit in the parameter configuration area. The area pointed to by the boot flag bit is the area where the firmware is loaded after the microcontroller is reset. Before the first upgrade, the safe area is used to store a stable version of firmware that has been verified through operation. The upgrade zone is dedicated to receiving and temporarily storing the new firmware. After a successful upgrade, the upgrade zone is remarked as a new security zone, and the original security zone becomes the new upgrade zone for use in the next upgrade. The battery management system to which the system belongs is applied to energy storage systems or electric vehicles to manage the charging and discharging of battery packs and external power supply. Its power supply objects include at least inverters or vehicle controllers. The integrity verification includes performing CRC verification or hash verification on each data packet. The system is also configured to perform signature verification on the new firmware as a whole after all data packets have passed verification to confirm that the firmware source is legitimate and has not been tampered with.
[0029] In this embodiment, the holding capacitor is a solid electrolytic capacitor. The capacitance value of the holding capacitor is calculated and determined according to the formula C_hold≥I_hold×T_reset / (V_stat-V_min), where C_hold is the capacitance value of the holding capacitor, I_hold is the current consumed by the control terminal of the driving transistor during reset, T_reset is the total time required for the microcontroller to reset from its reset until the new firmware sets the control pin to a high level again, V_stat is the high-level voltage output by the control pin when the microcontroller is running normally, and V_min is the minimum control voltage required to keep the driving transistor on.
[0030] In this embodiment, the holding capacitor is a 470μF / 16V solid-state electrolytic capacitor. During normal operation of the microcontroller, the high-level voltage V_stat output from the control pin is 5.0V. The forward voltage drop of the isolation diode is 0.3V. After passing through the isolation diode, the actual voltage applied to the control terminal of the driving transistor is approximately 4.7V. The minimum control voltage V_min required to maintain the driving transistor's conduction is 1.0V. The current consumed by the driving transistor's control terminal during reset, I_hold, is approximately 1mA. The total time T_reset ranges from 50ms to 200ms. Substituting these parameters into the formula, C_hold must be greater than or equal to 100μF. The selected 470μF solid-state electrolytic capacitor provides approximately 4.7 times the safety margin to address the shortened holding time caused by capacitor aging and capacitance decay at low temperatures, ensuring that the system can reliably maintain the driving transistor's conduction state within an operating temperature range of -40℃ to 85℃.
[0031] In this embodiment, the driving transistor is a MOS transistor, the control terminal of the driving transistor is the gate, the negative terminal of the isolation diode is connected to the gate of the MOS transistor, the first terminal of the holding capacitor is connected to the gate of the MOS transistor, and the second terminal of the holding capacitor is grounded.
[0032] In this embodiment, a pull-down resistor is connected in parallel between the gate and source of the MOS transistor. The resistance value of the pull-down resistor is determined according to the voltage division and power consumption required when the control pin outputs a high level normally. It is used to provide a discharge path for the holding capacitor when the system is normally powered off. The isolation diode is in the forward conduction state when the microcontroller is running normally. The high level output by the control pin charges the holding capacitor through the isolation diode and charges the gate of the MOS transistor to establish the gate-source voltage required for conduction. When the microcontroller is reset and the control pin becomes a high-impedance state, the negative potential of the isolation diode is higher than its positive potential due to the energy stored in the holding capacitor. The isolation diode enters the reverse cutoff state, preventing the charge of the holding capacitor from flowing back to the microcontroller through the control pin.
[0033] In this embodiment, the key operating status parameters include at least the battery's state of charge, health status, relay status, and fault code information.
[0034] In this embodiment, the state of charge specifically includes the current remaining battery percentage and available capacity value; the health status includes the battery internal resistance increment and the ratio of actual available capacity to nominal capacity; the relay status includes the current on / off position of the main positive relay and the main negative relay and the adhesion detection flag; the fault code information includes the fault codes at all levels recorded by the firmware of the security zone during operation and the corresponding timestamps; the parameter configuration area serves as a common data exchange area between the firmware of the security zone and the new firmware, and its storage medium is located in the same Flash memory as the security zone and the upgrade area, but the address space is independently divided; the data stored in the parameter configuration area will not be erased during the microcontroller reset.
[0035] In this embodiment, the microcontroller is triggered to reset by executing a software reset instruction or by causing the watchdog timer to time out and trigger a reset.
[0036] In this embodiment, the software reset instruction is a system reset request instruction directly issued by the firmware of the security zone to the kernel of the microcontroller after modifying the boot flag. After responding to the instruction, the microcontroller immediately enters the first address pointed to by the reset vector table and begins to execute the boot code. The watchdog timer is an independent hardware timer built into the microcontroller. After modifying the boot flag, the firmware of the security zone stops clearing the watchdog timer. After reaching a preset timeout threshold, the watchdog timer sends a hardware reset signal to the microcontroller, thereby triggering a reset.
[0037] In this embodiment, the system is further configured to: perform a self-test after the new firmware is started; if the self-test fails or an upgrade success signal is not sent to the cloud within a preset time, the boot flag in the parameter configuration area is modified to point to the secure area, and the microcontroller is reset again to load the firmware back into the secure area.
[0038] In this embodiment, the self-test includes the new firmware verifying the integrity of its own code segment, detecting the availability of the key operating status parameter reading interface, and testing the output function of the control pin. The preset time is timed by a timeout timer set internally by the new firmware. This preset time is determined based on the maximum time required for the new firmware to complete initialization, restore its working state, and establish a communication connection with the cloud. The operation process of loading the firmware back into the secure area shares the same boot program logic as the firmware loading process during normal upgrades. The only difference is that the target of the boot flag is changed from the upgrade area to the secure area.
[0039] In this embodiment, the communication circuit, the output control circuit, and the memory are all electrically connected to the microcontroller.
[0040] In this embodiment, the communication circuit is electrically connected to the microcontroller through the microcontroller's serial communication interface for data interaction with a cloud server or local upgrade terminal. The physical layer interface protocol of the communication circuit is at least one of CAN bus, RS485 bus, or Ethernet. The output control circuit is electrically connected to the microcontroller through the microcontroller's control pin, which is a general-purpose input / output pin. The microcontroller controls the conduction and shutdown of the drive transistor by changing the output level of the control pin. The memory is electrically connected to the microcontroller through the microcontroller's Flash controller interface. The microcontroller performs read, write, and erase operations on the secure area, the upgrade area, and the parameter configuration area through this interface.
[0041] In this embodiment, the present invention discloses a BMS seamless upgrade method based on hardware holding circuit, comprising the following steps: S1: The system operates normally under the control of the firmware in the secure zone. The microcontroller outputs a high level through the control pin, which charges the holding capacitor through the isolation diode and drives the driver transistor to conduct, so that the output control circuit can continuously supply power to the outside. S2: The communication circuit receives the data packets of the new firmware online and writes the data packets of the new firmware into the upgrade area of the memory. Each time a data packet is written, an integrity check is performed until all data packets are written and the check is passed, so as to form the new firmware in the upgrade area. S3: The firmware of the security zone will synchronize key operating status parameters to the parameter configuration area; S4: Modify the guide flag in the parameter configuration area so that the guide flag points to the area to be upgraded, and then trigger the microcontroller to reset; S5: During the microcontroller reset process, the control pin of the microcontroller becomes a high-impedance state, the isolation diode is turned off, and the holding capacitor begins to discharge to the control terminal of the drive transistor, so as to maintain the conduction state of the drive transistor during the microcontroller reset and ensure that the external power supply is not interrupted. S6: After the microcontroller is reset, the new firmware in the upgrade area is loaded by reading the boot flag bit in the parameter configuration area; S7: After the new firmware starts, it reads the key operating status parameters from the parameter configuration area to restore the working state, and immediately sets the control pin back to high level to charge the holding capacitor to restore the steady state.
[0042] S8: After the new firmware runs stably, a successful upgrade signal is sent to the cloud, and the area to be upgraded is remarked as a new secure area.
[0043] In this embodiment, the normal operation described in S1 corresponds to the initial steady state of the battery management system before entering the upgrade process. At this time, the holding capacitor is fully charged, and the voltage across it is approximately equal to the high-level voltage output by the control pin minus the forward conduction voltage drop of the isolation diode. In S2, the communication circuit uses a segmented transmission mechanism to receive data packets of the new firmware. Each data packet carries an independent serial number and a verification field. After each packet is written, the firmware in the security zone immediately calculates the verification value and compares it with the verification field. If the comparison matches, the next packet is requested; if the comparison does not match, the current packet is requested to be retransmitted. In S3, when synchronizing the key operating state parameters, the firmware in the security zone first writes each parameter into the cache page of the parameter configuration area. After all parameters are written, the cache page is refreshed to solidify the storage. In S4, the boot flag is a preset flag in the parameter configuration area. The specific storage unit of the address, whose stored value points to the starting address of the security zone before the firmware of the security zone is modified, and points to the starting address of the upgrade area after modification; the reset window period in S5 is determined by hardware timing, and the reset vector of the microcontroller first points to the boot program area after the reset is released, and the holding capacitor is discharged through the gate input impedance of the driving transistor and the parallel pull-down resistor during the window period; the boot program executed after the microcontroller is reset in S6 first reads the current value of the boot flag bit in the parameter configuration area, calculates the reset vector address of the corresponding firmware area according to the value, and jumps to execute; the upgrade success signal is sent through the communication circuit in S8, and after the upgrade area is remarked as a new security zone, the original security zone becomes the new upgrade area, and the firmware of the original security zone is still retained in the memory as a backup rollback version.
[0044] In this embodiment, the microcontroller reset period includes the entire process from triggering the reset, executing the boot code, loading the new firmware to the new firmware completing initialization and executing step S7, and the total time of this process does not exceed 200 milliseconds.
[0045] In this embodiment, the execution time of the boot code in the total time is approximately 10ms to 20ms, the initialization time of the new firmware is approximately 20ms to 50ms, and the execution time of the new firmware in step S7, which involves reading the key operating status parameters from the parameter configuration area and resetting the control pin to a high level, is approximately 5ms to 10ms. The time limit of no more than 200ms is a test calibration performed under the condition that the microcontroller is in the worst operating condition and the amount of new firmware code reaches the upper limit of the capacity of the upgrade area. The 470μF capacity of the holding capacitor is sufficient to maintain the voltage of the control terminal of the drive transistor above 1.0V within this time limit.
[0046] The above description is merely the optimal embodiment of the present invention and is not intended to limit the present invention. Any modifications or substitutions made by those skilled in the art without departing from the essence and scope of protection of the present invention should also be within the scope of protection of the present invention.
Claims
1. A BMS seamless upgrade system based on hardware holding circuit, characterized in that, The system includes a microcontroller, communication circuitry, output control circuitry, and memory. The output control circuitry includes a millisecond-level switching circuit, which comprises an isolation diode, a holding capacitor, and a driving transistor. The anode of the isolation diode is connected to a control pin of the microcontroller, and the cathode of the isolation diode is connected to both the first terminal of the holding capacitor and the control terminal of the driving transistor. This forms a charge retention path during microcontroller reset, where the unidirectional conductivity of the isolation diode prevents charge from flowing back into the microcontroller from the holding capacitor, and the holding capacitor maintains the conducting state of the driving transistor. The second terminal of the holding capacitor is grounded. The memory is divided into a security area, an upgrade area, and a parameter configuration area independent of the security area and the upgrade area. The parameter configuration area stores boot flags and key operating status parameters. The system is configured to load and run the... Under the control of the current running firmware formed by the firmware in the security zone, while maintaining the output control circuit to supply power to the outside, the data received through the communication circuit is written into the upgrade area to form new firmware and perform verification. After the verification is successful, the firmware in the security zone synchronizes the key operating status parameters to the parameter configuration area. After the synchronization is completed, the boot flag in the parameter configuration area is modified to point to the upgrade area and triggers the microcontroller to reset. After the microcontroller is reset, it loads the new firmware in the upgrade area by reading the boot flag in the parameter configuration area. After the new firmware is started, it reads the key operating status parameters from the parameter configuration area to take over control. During this reset, the holding capacitor provides a holding voltage to the control terminal of the drive transistor to keep the drive transistor in the conducting state, so that the output control circuit can supply power to the outside without interruption.
2. The BMS seamless upgrade system based on hardware holding circuit according to claim 1, characterized in that, The holding capacitor is a solid electrolytic capacitor. The capacitance value of the holding capacitor is calculated and determined according to the formula C_hold≥I_hold×T_reset / (V_stat-V_min), where C_hold is the capacitance value of the holding capacitor, I_hold is the current consumed by the control terminal of the driving transistor during reset, T_reset is the total time required for the microcontroller to reset from its reset until the new firmware sets the control pin to a high level again, V_stat is the high-level voltage output by the control pin when the microcontroller is running normally, and V_min is the minimum control voltage required to keep the driving transistor on.
3. The BMS seamless upgrade system based on hardware holding circuit according to claim 2, characterized in that, The driving transistor is a MOSFET, the control terminal of the driving transistor is the gate, the negative terminal of the isolation diode is connected to the gate of the MOSFET, and the first terminal of the holding capacitor is connected to the gate of the MOSFET.
4. The BMS seamless upgrade system based on hardware holding circuit according to claim 1, characterized in that, The key operating status parameters include at least the battery's state of charge, health status, relay status, and fault code information.
5. A BMS seamless upgrade system based on hardware holding circuit according to claim 1, characterized in that, The microcontroller can be reset by executing a software reset command or by causing the watchdog timer to time out.
6. The BMS seamless upgrade system based on hardware holding circuit according to claim 1, characterized in that, The system is also configured such that: after the new firmware is started, it performs a self-test; if the self-test fails or no upgrade success signal is sent to the cloud within a preset time, the boot flag in the parameter configuration area is modified to point to the secure area, and the microcontroller is reset again to load the firmware back into the secure area.
7. A BMS seamless upgrade system based on hardware holding circuit according to claim 1, characterized in that, The communication circuit, the output control circuit, and the memory are all electrically connected to the microcontroller.
8. A BMS seamless upgrade method based on hardware holding circuitry, applied to the system as described in any one of claims 1 to 7, characterized in that, Includes the following steps: S1: The system operates normally under the control of the firmware in the secure zone. The microcontroller outputs a high level through the control pin, which charges the holding capacitor through the isolation diode and drives the driver transistor to conduct, so that the output control circuit can continuously supply power to the outside. S2: The communication circuit receives the data packets of the new firmware online and writes the data packets of the new firmware into the upgrade area of the memory. Each time a data packet is written, an integrity check is performed until all data packets are written and the check is passed, so as to form the new firmware in the upgrade area. S3: The firmware of the security zone will synchronize key operating status parameters to the parameter configuration area; S4: Modify the guide flag in the parameter configuration area so that the guide flag points to the area to be upgraded, and then trigger the microcontroller to reset; S5: During the microcontroller reset process, the control pin of the microcontroller becomes a high-impedance state, the isolation diode is turned off, and the holding capacitor begins to discharge to the control terminal of the drive transistor, so as to maintain the conduction state of the drive transistor during the microcontroller reset and ensure that the external power supply is not interrupted. S6: After the microcontroller is reset, the new firmware in the upgrade area is loaded by reading the boot flag bit in the parameter configuration area; S7: After the new firmware starts, it reads the key operating status parameters from the parameter configuration area to restore the working state, and immediately sets the control pin to a high level to charge the holding capacitor to restore the steady state.
9. A BMS seamless upgrade method based on hardware retention circuitry according to claim 8, characterized in that, The BMS seamless upgrade method also includes: S8: After the new firmware runs stably, a successful upgrade signal is sent to the cloud, and the area to be upgraded is remarked as a new secure area.
10. A BMS seamless upgrade method based on hardware retention circuitry according to claim 8, characterized in that, The microcontroller reset period includes the entire process from triggering the reset, executing the boot code, loading the new firmware to the new firmware completing initialization and executing step S7, and the total time of this process does not exceed 200 milliseconds.
Citation Information
Patent Citations
Battery management system and wireless upgrading method
CN120812570A
Firmware non-inductive updating method and system for storage device
CN121501320A