Remote upgrading method
Through the preset subcontracting mechanism and triple storage protection mechanism, the upgrade failure caused by network signal fluctuations and power supply interruptions during the remote upgrade of the vehicle is solved, and the reliable remote upgrade of the vehicle is achieved.
Patent Information
- Application Number
- CN202510220812.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-27
- Publication Date
- 2025-07-29
AI Technical Summary
During the remote upgrade process, due to external conditions such as network signal fluctuations and power supply interruptions, multiple upgrades failed or could not be turned on. The existing technology cannot effectively solve this problem.
The preset subcontracting mechanism is used to divide the upgrade package into several packages to be deployed, and each package to be deployed is assigned independent verification codes and storage areas. Combined with the triple storage protection mechanism and intelligent reconnection strategy, real-time verification and rolling verification are performed to generate upgrade flags to ensure the integrity of the upgrade process.
It effectively reduces the impact of external conditions on remote upgrades, ensures that the vehicle can successfully complete the upgrade, and improves the reliability and success rate of the upgrade.
Smart Images

Figure CN120386541A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of remote upgrading, and particularly to a remote upgrading method. Background Art
[0002] With the rapid development of Industry 4.0 and intelligent manufacturing, the intelligence and automation levels of industrial vehicles (such as forklifts, AGVs, excavators, etc.) are constantly improving. The traditional software upgrading methods (such as through physical interfaces or manual operations) can no longer meet the needs of modern industries, so the remote upgrading technology has emerged as the times require.
[0003] Industrial vehicles are gradually integrated with sensors, controllers and communication modules, and need to frequently update software to optimize performance, repair vulnerabilities or add new functions. Remote upgrading can quickly respond to market demands and improve the intelligence level of vehicles.
[0004] The main purpose of remote upgrading is to improve the convenience of vehicle system upgrading and reduce after-sales maintenance costs. At present, vehicle system upgrading is divided into two types: local upgrading and remote upgrading. Local upgrading generally uses interfaces such as serial ports, CAN, USB, etc. to communicate with the host computer for upgrading, and someone needs to be beside for assistance. Remote upgrading generally uses network transmission and automatic upgrading without human assistance.
[0005] Patent No. CN202310215232.8 discloses a vehicle software remote upgrading method, system, vehicle and storage medium. Among them, the vehicle software remote upgrading method includes: establishing a network connection with the vehicle to be upgraded and determining the connection result; in response to the connection result indicating a successful connection, obtaining feedback data of the vehicle to be upgraded, where the feedback data at least includes a connection status, a software version and standard timestamp data. Obtaining the standard timestamp data includes: obtaining an initial timestamp; converting the format of the initial timestamp data into a preset format to obtain the standard timestamp data; formulating an upgrade task according to the feedback data; and sending the upgrade task to the vehicle to be upgraded. The above invention solves the technical problem that if too many invalid characters are input, the server will report an error, and then the error will be transmitted to the database, which will cause the cloud system to freeze or even crash, greatly affecting the efficiency of vehicle remote upgrading.
[0006] Patent No. CN202411505006.4 discloses an intelligent connected vehicle remote upgrade device, method, vehicle system, medium and product, which relates to the field of software upgrade of new energy vehicles. The device includes an upgrade service platform, an intelligent vehicle networking module, and an intelligent vehicle to be upgraded module; the upgrade service platform communicates with the intelligent vehicle networking module through a local area network; the upgrade service platform is used to configure the upgrade package, select the intelligent vehicle to be upgraded, and prompt the upgrade status; the intelligent vehicle networking module and the intelligent vehicle to be upgraded module are arranged on the intelligent vehicle to be upgraded; the intelligent vehicle networking module serves as the external communication interface of the intelligent vehicle, receives the upgrade package, and sends the upgrade package to the intelligent vehicle to be upgraded module; the intelligent vehicle to be upgraded module is used to execute the upgrade instruction according to the upgrade package and feedback the upgrade result; during the upgrade process, the intelligent connected vehicle remote upgrade device supports differential upgrade, breakpoint resumption, and software rollback after upgrade failure. The above application can effectively improve the upgrade convenience of intelligent vehicles in special scenarios.
[0007] Although the above patent can perform remote upgrade on the vehicle; when the vehicle is remotely upgraded, due to external conditions such as network signal fluctuations and power supply interruptions, multiple upgrades may fail, the vehicle may not be able to start after upgrade, or may restart repeatedly. Summary of the Invention
[0008] The purpose of the present invention is to provide a remote upgrade method, which can divide the upgrade package into several packages to be deployed through a preset sub-packaging mechanism, and assign independent check codes and storage areas to each package to be deployed, and continuously perform real-time verification and rolling verification; by starting a triple storage protection mechanism and an intelligent reconnection strategy, complete the transmission and verification of the packages to be deployed to generate an upgrade flag bit; thereby ensuring that the vehicle completes remote upgrade and effectively reducing the impact of external conditions on remote upgrade.
[0009] The present invention utilizes the following technical solutions: A remote upgrade method includes the following steps; S1: After the vehicle is powered on, read the key parameters in the storage area, judge the version number, and select the corresponding server response; The key parameters include the interrupt receive byte count, software package version number, upgrade package version number, and overall cyclic redundancy check code; the server responses include verification passed and no upgrade required, large update, verification failed, small update, and abnormal interruption; S2: After judging by the version number, divide the upgrade package into several packages to be deployed according to the preset sub-packaging mechanism, and assign independent check codes and storage areas to each package to be deployed, and continuously perform real-time verification and rolling verification; S3: When an exception occurs during the remote upgrade process, the vehicle simultaneously starts a triple storage protection mechanism and an intelligent reconnection strategy, and then completes the transmission and verification of all packages to be deployed to generate an upgrade flag bit; S4: When the vehicle starts again, move the package to be deployed from different storage areas according to the upgrade flag, complete the verification and judgment of the overall cyclic redundancy check code, and then complete the remote upgrade of the vehicle.
[0010] Preferably, step S1 includes the following steps: S11: Establish a secure access channel through the data identifier read by the electronic diagnostic communication protocol, complete the memory authentication of the vehicle's electronic control unit, initialize the direct access controller, and configure the physical address mapping of the storage area; S12: Read the number of interrupt received bytes according to a fixed offset, parse the software package version number of the current vehicle, obtain the upgrade package version number from the server through vehicle networking, and extract the overall cyclic redundancy check code; S13: Calculate the real-time check code using the generating polynomial and perform tolerance range verification with the overall cyclic redundancy check code: If the tolerance range is less than or equal to X-bit errors, compare the software package version number with the upgrade package version number and go to S14; If the tolerance range is greater than X-bit errors, trigger the verification failure in the server response; The version number includes the major version, minor version, and patch version; S14: If the version numbers are the same, trigger the verification passed and no upgrade is required in the server response; If there is a difference in the major version of the version number, trigger a major update in the server response and perform a forced upgrade on the vehicle; If there is a difference in the minor version of the version number, trigger a minor update in the server response and perform a recommended upgrade on the vehicle; If there is a difference in the patch version of the version number, record the vehicle log and do not trigger an upgrade; If the version number comparison process is interrupted, trigger the interruption exception in the server response, and the vehicle sends a request for retransmission notification to the server.
[0011] Preferably, step S2 includes the following steps: S21: Obtain the space capacity of the upgrade package and detect the network signal strength in real time to start the preset sub-packaging mechanism; S22: If the network signal strength is strong, divide the upgrade package into several to-be-deployed packages that are greater than KB and less than or equal to KB; If the network signal strength is medium, divide the upgrade package into several to-be-deployed packages that are greater than KB and less than or equal to KB; If the network signal strength is weak, divide the upgrade package into several to-be-deployed packages that are greater than KB and less than or equal to KB; And determine the sub-packaging quantity, space capacity, data offset, and verification type of each to-be-deployed package; S23: Establish a sub-packaging index table for all to-be-deployed packages according to the space capacity and data offset; S24: According to the subcontract index table and verification type, perform real-time verification on the independent verification codes of each package to be deployed, and perform rolling verification on the received packages to be deployed according to the number of sub-packages of the packages to be deployed, the preset cumulative threshold, and the transmission progress: S25: Detect bad blocks and verify the remaining space in the storage area, and allocate the storage area according to the type of package to be deployed; S26: If the type of the package to be deployed is a basic function package, allocate this package to the FRAM security area of the storage area; if the type of the package to be deployed is an application data package of the basic function package, allocate this package to the free storage area of the storage area; if the type of the package to be deployed is a critical control package, allocate this package to the mirror storage area of the storage area.
[0012] Preferably, the preset subcontracting mechanism continuously performs real-time subcontracting on the upgrade package during the transmission of the package to be deployed according to the real-time network signal strength, and generates an independent verification code by using the hash algorithm according to the subcontracting time, the number of sub-packages, and the overall cyclic redundancy check code.
[0013] Preferably, step S3 includes the following steps: S31: When an exception occurs during the remote upgrade process, monitor the network signal strength, vehicle voltage, and version number verification of the vehicle in real time, and trigger the exception handling mechanism of the vehicle; S32: If the network signal strength < A milliwatt decibels and lasts for B seconds, it is determined that the network of the current vehicle is interrupted, and the network redundancy strategy is started; if the version number fails to pass the verification continuously for E times, it is determined that the data of the current upgrade package is abnormal, and the rollback mechanism is triggered; S33: If the voltage fluctuation > ±C% and lasts for D milliseconds, it is determined that the power supply of the current vehicle is abnormal, and the triple storage protection mechanism is activated: stop writing the data in the new package to be deployed into the storage area, transfer the DMA buffer data to the FRAM security area, and at the same time start the mirror storage synchronization, and record the exception event code, independent verification code, and exception timestamp in the independent power supply area; S34: After the vehicle completes the exception handling, the vehicle starts the intelligent reconnection strategy: reconnect to the server according to the exception type by using the network channel optimization algorithm or the breakpoint resumption optimization algorithm; S35: After the vehicle completes the reconnection, the server retransmits the successfully transmitted packages to be deployed with K adjacent timestamps according to the exception timestamp, and at the same time performs cross-verification and timestamp continuity check in the storage area; S36: According to the transmission process of the package to be deployed, assign weights and calculate verification values for the integrity of the upgrade package, storage consistency, timestamp continuity, and deployment environment stability, and compare them with the success threshold; S37: If the verification value is equal to the success threshold, the vehicle outputs an upgrade flag bit 1234; if the verification value is not equal to the success threshold, the vehicle prompts a transmission failure.
[0014] Preferably, step S4 includes the following steps: S41: When the vehicle starts, the vehicle detects the upgrade flag bit; S42: If the upgrade flag bit is 1234, it indicates that the package to be deployed has been received, and the corresponding storage area is selected according to the preset policy; if there is no upgrade flag bit, it indicates that the package to be deployed has been received unsuccessfully; S43: Use the double-buffer mechanism to copy the package to be deployed from the storage area to the running partition of the vehicle, and use the generating polynomial to check and judge the overall cyclic redundancy check code; S44: If the check passes, mark the running partition as the active state, restart and load the new version program, and clear the old version backup; if the check fails, trigger the rollback mechanism, automatically restore the original version from the mirror partition, and report the error log to the server at the same time; S45: After each remote upgrade is completed, delete the temporarily stored upgrade package, reset the upgrade flag bit, and update the vehicle log to record the upgrade time, version number, and check result of this time.
[0015] The present invention divides the upgrade package into several packages to be deployed through a preset sub-packaging mechanism, and assigns independent check codes and storage areas to each package to be deployed, and continuously performs real-time checks and rolling checks; by starting a triple storage protection mechanism and an intelligent reconnection strategy, the transmission and check of the package to be deployed are completed to generate an upgrade flag bit; it ensures that the vehicle completes remote upgrade and reduces the impact of external conditions on remote upgrade. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments or related technologies. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.
[0017] Figure 1 It is a principle block diagram of the remote upgrade method; Figure 2 It is a flowchart of the remote upgrade method. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0018] The following will describe the present invention in detail with reference to the drawings and embodiments: As Figure 1 - Figure 2 shown, the remote upgrade method described in the present invention includes the following steps: S1: After the vehicle is powered on, read the key parameters in the storage area, judge the version number, and select the corresponding server response; The key parameters include the interrupt reception byte count, software package version number, upgrade package version number, and overall cyclic redundancy check code; the server responses include verification passed and no upgrade required, large update, verification failed, small update, and abnormal interruption; S2: After judging by the version number, divide the upgrade package into several packages to be deployed according to the preset sub-packaging mechanism, and allocate independent check codes and storage areas for each package to be deployed, while continuously performing real-time verification and rolling verification; S3: When an exception occurs during the remote upgrade process, the vehicle simultaneously activates a triple storage protection mechanism and an intelligent reconnection strategy, and then completes the transmission and verification of all packages to be deployed to generate an upgrade flag bit; S4: When the vehicle starts again, move the packages to be deployed from different storage areas according to the upgrade flag, and complete the verification and judgment of the overall cyclic redundancy check code, thereby completing the vehicle remote upgrade.
[0019] In the present invention, step S1 includes the following steps: S11: Establish a secure access channel through the data identifier for reading in the electronic diagnostic communication protocol, complete the memory authentication of the vehicle electronic control unit, initialize the direct access controller, and configure the physical address mapping of the storage area; S12: Read the interrupt reception byte count according to a fixed offset, parse the software package version number of the current vehicle, obtain the upgrade package version number of the server through vehicle networking, and extract the overall cyclic redundancy check code; S13: Calculate the real-time check code using the generating polynomial and perform tolerance range verification with the overall cyclic redundancy check code: If the tolerance range is less than or equal to X-bit errors, compare and judge the software package version number with the upgrade package version number, and go to S14; If the tolerance range is greater than X-bit errors, trigger the verification failed in the server response; The version number includes the major version, minor version, and patch version; S14: If the version numbers are the same, trigger the verification passed and no upgrade required in the server response; If there is a difference in the major version in the version number, trigger the large update in the server response to perform a forced upgrade on the vehicle; If there is a difference in the minor version in the version number, trigger the small update in the server response to perform a recommended upgrade on the vehicle; If there is a difference in the patch version in the version number, record the vehicle log without triggering an upgrade; If the version number comparison and judgment process is interrupted, trigger the interrupt exception in the server response, and the vehicle sends a request for retransmission notice to the server.
[0020] In the present invention, step S2 includes the following steps: S21: Obtain the space capacity of the upgrade package and detect the network signal strength in real time to activate the preset sub-packaging mechanism; S22: If the network signal strength is strong, divide the upgrade package into several to-be-deployed packages that are greater than KB and less than or equal to KB; if the network signal strength is medium, divide the upgrade package into several to-be-deployed packages that are greater than KB and less than or equal to KB; if the network signal strength is weak, divide the upgrade package into several to-be-deployed packages that are greater than KB and less than or equal to KB; and determine the sub-package quantity, space capacity, data offset, and verification type of each to-be-deployed package; S23: Establish a sub-package index table for all to-be-deployed packages according to the space capacity and data offset; S24: According to the sub-package index table and verification type, perform real-time verification on the independent verification code of each to-be-deployed package, and perform rolling verification on the received to-be-deployed packages according to the sub-package quantity of the to-be-deployed packages, the preset cumulative threshold, and the transmission progress: S25: Perform bad block detection and remaining space verification on the storage area, and allocate the storage area according to the type of to-be-deployed package; S26: If the type of the to-be-deployed package is a basic function package, allocate this to-be-deployed package to the FRAM security area of the storage area; if the type of the to-be-deployed package is an application data packet of the basic function package, allocate this to-be-deployed package to the free storage area of the storage area; if the type of the to-be-deployed package is a key control package, allocate this to-be-deployed package to the mirror storage area of the storage area.
[0021] In the present invention, the preset sub-package mechanism continuously performs real-time sub-packaging on the upgrade package during the transmission of the to-be-deployed package according to the real-time network signal strength, and generates an independent verification code by using the hash algorithm according to the sub-packaging time, sub-packaging quantity, and overall cyclic redundancy check code.
[0022] In the present invention, step S3 includes the following steps: S31: When an exception occurs during the remote upgrade process, perform real-time monitoring on the network signal strength, vehicle voltage, and version number verification of the vehicle, and trigger the exception handling mechanism of the vehicle at the same time; S32: If the network signal strength < A milliwatt decibels and lasts for B seconds, it is determined that the network of the current vehicle is interrupted, and the network redundancy strategy is started; if the version number fails to pass the verification continuously for E times, it is determined that the data of the current upgrade package is abnormal, and the rollback mechanism is triggered; S33: If the voltage fluctuation > ±C% and lasts for D milliseconds, it is determined that the power supply of the current vehicle is abnormal, and the triple storage protection mechanism is activated: stop writing the data in the new package to be deployed into the storage area, transfer the DMA buffer data to the FRAM safe area, and at the same time start the mirror storage synchronization, record the abnormal event code, independent check code and abnormal timestamp in the independent power supply area; S34: After the vehicle completes the abnormal handling, the vehicle starts the intelligent reconnection strategy: reconnect to the server according to the abnormal type using the network channel optimization algorithm or the breakpoint resumption optimization algorithm; S35: After the vehicle completes the reconnection, the server retransmits the successfully transmitted packages to be deployed with K adjacent timestamps according to the abnormal timestamp, and at the same time performs cross-verification and timestamp continuity check in the storage area; S36: According to the transmission process of the package to be deployed, weights are assigned and verification values are calculated for the integrity of the upgrade package, storage consistency, timestamp continuity and deployment environment stability, and compared with the success threshold; S37: If the verification value is equal to the success threshold, the vehicle outputs the upgrade flag bit 1234: if the verification value is not equal to the success threshold, the vehicle prompts that the transmission fails.
[0023] In the present invention, step S4 includes the following steps: S41: When the vehicle starts, the vehicle detects the upgrade flag bit; S42: If the upgrade flag bit is 1234, it indicates that the package to be deployed has been received, and the corresponding storage area is selected according to the preset strategy; if there is no upgrade flag bit, it indicates that the package to be deployed has been received failed; S43: Use the double-buffer mechanism to copy the package to be deployed from the storage area to the running partition of the vehicle, and use the generating polynomial to check and judge the overall cyclic redundancy check code; S44: If the check passes, mark the running partition as the active state, load the new version program after restart, and clear the old version backup; if the check fails, trigger the rollback mechanism, automatically restore the original version from the mirror partition, and at the same time report the error log to the server; S45: After each remote upgrade is completed, delete the temporarily stored upgrade package, reset the upgrade flag bit, and update the vehicle log to record the upgrade time, version number and check result of this time.
[0024] Embodiment 1: The vehicle establishes a secure access channel through the read data identifier of the electronic diagnostic communication protocol, completes the memory authentication of the vehicle's electronic control unit, initializes the direct access controller, and configures the physical address mapping of the storage area; reads the number of interrupt received bytes according to a fixed offset, parses the software package version number of the current vehicle, obtains the upgrade package version number from the server through vehicle networking, and extracts the overall cyclic redundancy check code; calculates the real-time check code using the generating polynomial and verifies the tolerance range with the overall cyclic redundancy check code: if the tolerance range is less than or equal to X-bit errors, compare and judge the software package version number with the upgrade package version number, and go to S14; if the tolerance range is greater than X-bit errors, trigger the check failure in the server response; the version number includes the major version, minor version, and patch version; if the version numbers are the same, trigger the check passed in the server response and no upgrade is required; if there is a difference in the major version of the version number, trigger a major update in the server response and force an upgrade of the vehicle; if there is a difference in the minor version of the version number, trigger a minor update in the server response and recommend an upgrade of the vehicle; if there is a difference in the patch version of the version number, record the vehicle log and do not trigger an upgrade; if the version number comparison and judgment process is interrupted, trigger the interrupt exception in the server response, and the vehicle sends a request for retransmission notice to the server.
[0025] Obtain the space capacity of the upgrade package and detect the network signal strength in real time to start the preset sub-packaging mechanism; if the network signal strength is strong, divide the upgrade package into several deployment packages greater than KB and less than or equal to KB according to the upgrade package space capacity; if the network signal strength is medium, divide the upgrade package into several deployment packages greater than KB and less than or equal to KB according to the upgrade package space capacity; if the network signal strength is weak, divide the upgrade package into several deployment packages greater than KB and less than or equal to KB according to the upgrade package space capacity; and determine the sub-packaging quantity, space capacity, data offset, and check type of each deployment package; establish a sub-packaging index table for all deployment packages according to the space capacity and data offset; perform real-time verification on the independent check code of each deployment package according to the sub-packaging index table and check type, and perform rolling verification on the received deployment packages according to the sub-packaging quantity of the deployment package according to the preset cumulative threshold and transmission progress: perform bad block detection and remaining space verification on the storage area, and allocate the storage area according to the deployment package type: if the deployment package type is the basic function package, allocate this deployment package to the FRAM security area of the storage area; if the deployment package type is the application data packet of the basic function package, allocate this deployment package to the free storage area of the storage area; if the deployment package type is the key control package, allocate this deployment package to the mirror storage area of the storage area.
[0026] When an exception occurs during the remote upgrade process, the vehicle's network signal strength, vehicle voltage, and version number verification are monitored in real time, and the vehicle's exception handling mechanism is triggered: If the network signal strength is < A mWdB and lasts for B seconds, it is determined that the vehicle's network is interrupted, and the network redundancy strategy is activated; If the version number fails to pass the verification E consecutive times, it is determined that the current upgrade package data is abnormal, and the rollback mechanism is triggered; If the voltage fluctuation > ±C% and lasts for D milliseconds, it is determined that the vehicle's power supply is abnormal, and the triple storage protection mechanism is activated: Stop writing the data in the new package to be deployed into the storage area, transfer the DMA buffer data to the FRAM security area, and at the same time enable mirror storage synchronization, record the exception event code, independent verification code, and exception timestamp in the independent power supply area; After the vehicle completes the exception handling, the vehicle starts the intelligent reconnection strategy: According to the exception type, use the network channel optimization algorithm or the breakpoint resumption optimization algorithm to reconnect to the server; After the vehicle completes the reconnection, the server retransmits the successfully transmitted packages to be deployed with K adjacent timestamps according to the exception timestamp, and at the same time performs cross-verification and timestamp continuity check in the storage area; According to the transmission process of the package to be deployed, weights are assigned and verification values are calculated for the integrity of the upgrade package, storage consistency, timestamp continuity, and deployment environment stability, and compared with the success threshold: If the verification value is equal to the success threshold, the vehicle outputs the upgrade flag 1234: If the verification value is not equal to the success threshold, the vehicle prompts that the transmission fails; When the vehicle starts, the vehicle detects the upgrade flag: If the upgrade flag is 1234, it indicates that the package to be deployed has been received, and the corresponding storage area is selected according to the preset strategy; If there is no upgrade flag, it indicates that the package to be deployed has been received unsuccessfully; Use the double-buffer mechanism to copy the package to be deployed from the storage area to the vehicle's running partition, and use the generating polynomial to check the overall cyclic redundancy check code: If the check passes, mark the running partition as the active state, load the new version program after restart, and clear the old version backup; If the check fails, trigger the rollback mechanism, automatically restore the original version from the mirror partition, and report the error log to the server at the same time; After each remote upgrade is completed, delete the temporarily stored upgrade package, reset the upgrade flag, and update the vehicle log to record the upgrade time, version number, and check result of this time.
[0027] Embodiment 2: The vehicle system reads out the data packet size, version, and the number of bytes already received during the last upgrade. The server sends the size, version, and overall CRC check code of the upgrade package to the vehicle system. The vehicle system verifies the software version, upgrade package, and overall CRC data of the upgrade package. If it is detected that the upgrade package is the same as the last uncompleted upgrade package, set the breakpoint position to the number of bytes received during the last upgrade, otherwise set the breakpoint position to 0, and upload the breakpoint to the server; After the server receives the breakpoint position, it starts the upgrade. The server sends data packet by packet and the CRC checksum of each packet to the device from the breakpoint position. The device performs CRC check on each received packet and compares it with the sent CRC. After successful comparison, it writes to area B of the storage device. Each time a packet is received, the byte count is accumulated, and the received byte count, CRC, and software version are stored in the storage device.
[0028] During this process, if the vehicle suddenly loses power or disconnects, repeat step 1 when starting next time. After all data packets are received, perform an overall CRC check. After successful check, set the upgrade flag bit to 1234, and store the upgrade flag, software version, data packets, and overall CRC checksum.
[0029] When the device starts next time, read the upgrade flag. If it is 1234, read the upgrade data in area B and transfer it to area A. When all data transfer is completed, read the data in area A and perform CRC check. If the calculated overall CRC value is the same as the stored overall CRC value, clear the upgrade flag and the total number of received data, otherwise do not clear.
Claims
1. A remote upgrade method, characterized in that: It includes the following steps: S1: After the vehicle is powered on, read the key parameters in the storage area, judge the version number, and select the corresponding server response; The key parameters include the interrupt reception byte count, software package version number, upgrade package version number, and overall cyclic redundancy check code; the server responses include verification passed and no upgrade required, large update, verification failed, small update, and abnormal interruption; S2: After judging by the version number, divide the upgrade package into several packages to be deployed according to the preset sub-packaging mechanism, and assign independent check codes and storage areas to each package to be deployed, while continuously performing real-time verification and rolling verification; S3: When an exception occurs during the remote upgrade process, the vehicle simultaneously activates the triple storage protection mechanism and the intelligent reconnection strategy, and then completes the transmission and verification of all packages to be deployed to generate an upgrade flag bit; S4: When the vehicle starts again, move the packages to be deployed from different storage areas according to the upgrade flag, and complete the verification and judgment of the overall cyclic redundancy check code, thereby completing the remote upgrade of the vehicle.
2. The remote upgrade method according to claim 1, wherein: The step S1 includes the following steps: S11: Establish a secure access channel through the data identifier for reading in the electronic diagnostic communication protocol, complete the memory authentication of the vehicle electronic control unit, initialize the direct access controller, and configure the physical address mapping of the storage area; S12: Read the interrupt reception byte count according to a fixed offset, parse the software package version number of the current vehicle, obtain the upgrade package version number of the server through vehicle networking, and extract the overall cyclic redundancy check code; S13: Calculate the real-time check code using the generating polynomial and perform a tolerance range verification with the overall cyclic redundancy check code: if the tolerance range is less than or equal to X-bit errors, compare and judge the software package version number and the upgrade package version number, and go to S14; if the tolerance range is greater than X-bit errors, trigger the verification failed in the server response; the version number includes the major version, minor version, and patch version; S14: If the version numbers are the same, trigger the verification passed and no upgrade required in the server response; if there is a difference in the major version of the version numbers, trigger the large update in the server response to perform a forced upgrade on the vehicle; if there is a difference in the minor version of the version numbers, trigger the small update in the server response to perform a recommended upgrade on the vehicle; if there is a difference in the patch version of the version numbers, record the vehicle log and do not trigger an upgrade; if the version number comparison and judgment process is interrupted, trigger the interruption exception in the server response, and the vehicle sends a request for retransmission notice to the server.
3. The remote upgrade method according to claim 1, wherein: The step S2 includes the following steps: S21: Obtain the space capacity of the upgrade package and detect the network signal strength in real time to activate the preset sub-packaging mechanism; S22: If the network signal strength is strong, divide the upgrade package into several to-be-deployed packages that are greater than KB and less than or equal to KB according to the space capacity of the upgrade package; if the network signal strength is medium, divide the upgrade package into several to-be-deployed packages that are greater than KB and less than or equal to KB according to the space capacity of the upgrade package; if the network signal strength is weak, divide the upgrade package into several to-be-deployed packages that are greater than KB and less than or equal to KB according to the space capacity of the upgrade package; and determine the sub-package quantity, space capacity, data offset, and verification type of each to-be-deployed package. S23: Establish a sub-packaging index table for all packages to be deployed according to the space capacity and data offset; S24: Perform real-time verification on the independent check code of each package to be deployed according to the sub-packaging index table and the verification type, and perform rolling verification on the received packages to be deployed according to the preset cumulative threshold and transmission progress based on the number of sub-packages of the package to be deployed: S25: Detect bad blocks and verify the remaining space in the storage area, and allocate the storage area according to the type of package to be deployed; S26: If the type of the package to be deployed is a basic function package, then allocate this package to be deployed to the FRAM secure area of the storage area; if the type of the package to be deployed is an application data package which is a basic function package, then allocate this package to be deployed to the free storage area of the storage area; if the type of the package to be deployed is a critical control package, then allocate this package to be deployed to the mirrored storage area of the storage area.
4. The remote upgrade method according to claim 3, characterized in that: The preset sub-packaging mechanism continuously performs real-time sub-packaging on the upgrade package during the transmission of the package to be deployed according to the real-time network signal strength, and generates independent check codes using the hash algorithm based on the sub-packaging time, the number of sub-packages, and the overall cyclic redundancy check code.
5. The remote upgrade method according to claim 1, wherein: The steps in step S3 include the following steps: S31: When an exception occurs during the remote upgrade process, monitor the network signal strength, vehicle voltage, and version number verification of the vehicle in real time, and at the same time trigger the exception handling mechanism of the vehicle; S32: If the network signal strength < A milliwatts per decibel and lasts for B seconds, then determine that the network of the current vehicle is interrupted and start the network redundancy strategy; if the version number fails to pass the verification continuously for E times, then determine that the data of the current upgrade package is abnormal and trigger the rollback mechanism; S33: If the voltage fluctuation > ±C% and lasts for D milliseconds, then determine that the power supply of the current vehicle is abnormal and activate the triple storage protection mechanism: stop writing the data in the new package to be deployed into the storage area, transfer the DMA buffer data to the FRAM secure area, and at the same time enable the mirrored storage synchronization, and record the exception event code, independent check code, and exception timestamp in the independent power supply area; S34: After the vehicle completes the exception handling, the vehicle starts the intelligent reconnection strategy: reconnect to the server according to the exception type using the network channel optimization algorithm or the breakpoint resumption optimization algorithm; S35: After the vehicle completes the reconnection, the server retransmits the successfully transmitted packages to be deployed with K adjacent timestamps according to the exception timestamp, and at the same time performs cross-verification and timestamp continuity check in the storage area; S36: According to the transmission process of the package to be deployed, assign weights and calculate verification values for the integrity of the upgrade package, storage consistency, timestamp continuity, and deployment environment stability, and compare them with the success threshold; S37: If the verification value is equal to the success threshold, then the vehicle outputs the upgrade flag 1234: if the verification value is not equal to the success threshold, then the vehicle prompts that the transmission fails.
6. The remote upgrade method according to claim 1, wherein: The steps in step S4 include the following steps: S41: When the vehicle starts, the vehicle detects the upgrade flag; S42: If the upgrade flag is 1234, it indicates that the package to be deployed has been received, and select the corresponding storage area according to the preset strategy; if there is no upgrade flag, it indicates that the package to be deployed has not been received successfully; S43: Use the double-buffer mechanism to copy the package to be deployed from the storage area to the running partition of the vehicle, and use the generating polynomial to check and judge the overall cyclic redundancy check code; S44: If the verification passes, then mark the running partition as the active state, restart and load the new version program, and clear the old version backup; if the verification fails, then trigger the rollback mechanism, automatically restore the original version from the mirrored partition, and at the same time report the error log to the server; S45: After each successful remote upgrade, delete the temporarily stored upgrade package, reset the upgrade flag, and update the vehicle log to record the upgrade time, version number, and verification result of this upgrade.
Citation Information
Patent Citations
Vehicle software remote upgrading method and system, vehicle and storage medium
CN116208490A
Intelligent network connection vehicle remote upgrading device, method, equipment, medium and product
CN119248323A
Cited By
OTA upgrade log management system and method based on big data
CN121277539A