OTA upgrade package management method, vehicle OTA upgrade management system and vehicle
By differentiating the OTA upgrade packages of intelligent controllers and non-intelligent controllers, the problem of repeated downloads of large-capacity upgrade packages is solved, thereby improving upgrade efficiency and bandwidth utilization. This approach is suitable for large-capacity components such as intelligent controllers and driver assistance domain controllers in vehicles.
Patent Information
- Application Number
- CN202511166385.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-20
- Publication Date
- 2025-11-21
AI Technical Summary
In vehicle OTA upgrades, repeated downloads of large-capacity upgrade packages lead to wasted bandwidth and extended upgrade times, especially when some upgrade packages fail to download and the entire package is retransmitted, affecting efficiency.
By differentiating OTA upgrade packages for smart controllers and non-smart controllers, when some upgrade packages fail to download, the large smart controller upgrade packages that have been successfully downloaded are retained, and the software information consistency comparison is used to determine whether to reuse or re-download them, thus avoiding duplicate downloads.
It significantly reduces the amount of repeated downloads of large intelligent controller upgrade packages, improves bandwidth utilization and upgrade efficiency, and is particularly suitable for multi-module OTA upgrade scenarios of large-capacity components such as vehicle infotainment systems and driver assistance domain controllers.
Smart Images

Figure CN120994220A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of vehicle upgrades, specifically an OTA upgrade package management method, a vehicle OTA upgrade management system, and a vehicle. Background Technology
[0002] Over-the-Air (OTA) technology is the core channel for remote vehicle software upgrades. Vehicles download upgrade packages via wireless networks to update and repair ECU firmware, operating systems, or application software. With the rapid expansion of software size for intelligent controllers such as cockpit domain controllers and driver assistance domain controllers, the size of a single upgrade package has generally reached 2GB to 4GB or even higher. Traditionally, all upgrade packages must be successfully downloaded before an upgrade can proceed. If any upgrade package fails to download, all downloaded data is deleted, forcing large upgrade packages to be repeatedly retransmitted, wasting bandwidth and extending upgrade time, thus placing even stricter demands on OTA download efficiency. Summary of the Invention
[0003] This invention provides an OTA upgrade package management method, a vehicle OTA upgrade management system, and a vehicle, in order to reduce the problem of wasted traffic and upgrade delay caused by repeated downloads of large-capacity upgrade packages.
[0004] The technical solution of this invention is as follows: This application also provides a method for managing OTA upgrade packages for intelligent controllers, including: Receive and parse the upgrade trigger command sent by the vehicle communication terminal to obtain the signature information of the new version upgrade package; Based on whether the identification results of historical upgrade packages are stored in the local cache and the consistency comparison results between historical upgrade packages and new version upgrade packages, decide whether to download the new version upgrade package from the cloud; The historical upgrade package is a complete upgrade package stored by the intelligent controller when it received a partial download failure message from the vehicle communication terminal during a previous upgrade task.
[0005] Preferably, the step of selecting whether to download the new version upgrade package from the cloud based on whether the identification results of historical upgrade packages are stored in the local cache and the consistency comparison results between historical upgrade packages and the new version upgrade package includes: Check if the local cache contains a historical upgrade package; When a historical upgrade package exists in the local cache, the consistency between the historical upgrade package and the new version upgrade package is verified by comparing the signature information. When the historical upgrade package and the new version upgrade package are identical, select not to download the new version upgrade package from the cloud; When the historical upgrade package and the new version upgrade package are inconsistent, the historical upgrade package is deleted and the new version upgrade package is downloaded from the cloud.
[0006] Preferably, the step of selecting whether to download the new version upgrade package from the cloud, based on whether the identification results of historical upgrade packages are stored in the local cache and the consistency comparison results between historical upgrade packages and the new version upgrade package, further includes: If the historical upgrade package is not available in the local cache, select to download the new version upgrade package from the cloud.
[0007] Preferably, after selecting to download the new version upgrade package from the cloud, the method further includes: When a message indicating that the upgrade package download failed to complete is received from the vehicle communication terminal, the fully downloaded new version upgrade package is retained. The fully downloaded new version upgrade package will be used as the historical upgrade package when the upgrade trigger command is received again.
[0008] Preferably, after selecting to download the new version upgrade package from the cloud, the method further includes: When a message indicating that the upgrade package download failed to complete is received from the vehicle communication terminal, the partially downloaded upgrade package is deleted if the new version upgrade package has not been fully downloaded.
[0009] This application also provides a method for managing over-the-air (OTA) upgrades for vehicles, including: Receive and parse the upgrade task information sent from the cloud to determine the target controller that needs to download the new version upgrade package; When the target controller includes a non-intelligent controller, download the new version upgrade package of the non-intelligent controller from the cloud; When the target controller includes an intelligent controller, the upgrade trigger command carrying the signature information of each intelligent controller is sent to the corresponding intelligent controller to trigger the corresponding intelligent controller to perform the following operation: based on whether the identification result of the historical upgrade package is stored in the local cache and the consistency comparison result of the historical upgrade package and the new version upgrade package, select whether to download the new version upgrade package from the cloud; The historical upgrade package is a complete upgrade package stored by the intelligent controller when it received a partial download failure message from the vehicle communication terminal during a previous upgrade task.
[0010] Preferably, it determines whether a historical upgrade package exists in the local cache; When a historical upgrade package exists in the local cache, the consistency between the historical upgrade package and the new version upgrade package is verified by comparing the signature information. When the historical upgrade package and the new version upgrade package are identical, the new version upgrade package will no longer be downloaded from the cloud; When the historical upgrade package and the new version upgrade package are inconsistent, delete the historical upgrade package and download the new version upgrade package from the cloud.
[0011] Preferably, when the intelligent controller chooses to download the new version upgrade package from the cloud, the method further includes: When it is detected that the new version upgrade package of all target controllers has not been fully downloaded, delete the new version upgrade packages of all non-smart controllers in this download, and send the upgrade package partial download failure information to the smart controller, triggering the smart controller to retain the new version upgrade package that has been fully downloaded or to delete the new version upgrade package that has been partially downloaded; The fully downloaded new version upgrade package will serve as the historical upgrade package for the next time the smart controller receives an upgrade trigger command.
[0012] This application also provides an OTA upgrade management system for a vehicle, including: an in-vehicle communication terminal and an intelligent controller and a non-intelligent controller connected to the in-vehicle communication terminal; The vehicle-mounted communication terminal is used to: after receiving upgrade task information from the cloud, determine the target controller that needs to download the new version upgrade package based on the upgrade task information; when the target controller includes a non-intelligent controller, directly download the new version upgrade package of the non-intelligent controller from the cloud; when the target controller includes an intelligent controller, send upgrade trigger instructions carrying the signature information of each intelligent controller to the corresponding intelligent controller respectively. Each triggered smart controller performs the following operations: based on whether the identification results of the historical upgrade package are stored in the local cache and the consistency comparison results between the historical upgrade package and the new version upgrade package, it selects whether to download the new version upgrade package from the cloud; The historical upgrade package is a complete upgrade package stored by the intelligent controller when it received information that part of the upgrade package failed to download during a previous upgrade task.
[0013] This application also provides a vehicle including the aforementioned vehicle OTA upgrade management system.
[0014] The beneficial effects of this invention are as follows: By differentiating OTA upgrade packages for intelligent and non-intelligent controllers, this mechanism retains successfully downloaded large intelligent controller upgrade packages (>1GB) when some upgrade packages fail to download. During the next upgrade, it checks the consistency of software information to determine whether to reuse the package: if the software information sent from the cloud matches the locally stored package, it is reused directly to avoid duplicate downloads; otherwise, it is deleted and re-downloaded. Based on the principle of "high cost of large file downloads and detectable version changes," this mechanism effectively solves the inefficiency problem of overall retries due to partial failures in mixed upgrade scenarios. It significantly reduces the amount of duplicate downloads of large intelligent controller upgrade packages, improving bandwidth utilization and upgrade efficiency while ensuring upgrade reliability. It is particularly suitable for multi-module OTA upgrade scenarios involving large-capacity components such as vehicle infotainment systems and driver assistance domain controllers. Attached Figure Description
[0015] Figure 1 This is a flowchart illustrating the OTA upgrade package management method for the intelligent controller in this application embodiment; Figure 2 This is a detailed flowchart illustrating the OTA upgrade package management method for the intelligent controller in the embodiments of this application; Figure 3 This is a flowchart illustrating the OTA upgrade package management method in the embodiments of this application; Figure 4 This is a schematic diagram of the vehicle structure in the embodiments of this application. Detailed Implementation
[0016] Reference Figure 1 This application provides an OTA upgrade package management method for an intelligent controller, including: S101 receives and parses the upgrade trigger command sent by the vehicle communication terminal to obtain the signature information of the new version upgrade package; S102, based on whether the identification results of historical upgrade packages are stored in the local cache and the consistency comparison results between historical upgrade packages and new version upgrade packages, decide whether to download the new version upgrade package from the cloud; The historical upgrade package is a complete upgrade package stored by the intelligent controller when it received a partial download failure message from the vehicle communication terminal during a previous upgrade task.
[0017] In this application embodiment, the intelligent controller refers to a controller with an operating system in the whole vehicle, such as a vehicle system, driver assistance domain controller, etc., with a software capacity exceeding 1GB.
[0018] After parsing the upgrade task information sent from the cloud, the vehicle communication terminal (T-Box) identifies that the vehicle's intelligent controller needs to be upgraded, generates an upgrade trigger command, and actively sends it to the intelligent controller via the in-vehicle network (such as CAN-FD or Ethernet). Specifically, the vehicle communication terminal reports the vehicle version information to the cloud, which compares the vehicle version information with the latest version information on its own database. If an upgrade task is generated when it determines that a controller in the vehicle needs to be upgraded, the T-Box generates upgrade task information.
[0019] In this embodiment, the upgrade task information includes the new version upgrade package software information and signature information corresponding to each target controller that needs to be upgraded. The new version upgrade package software information includes, for example, the software version number, file size, file name, and format of the upgrade package. The signature information includes the hash value of the new version upgrade package. The hash value is generated by the cloud when generating the new version upgrade package for the target controller. For example, the cloud first performs a one-time hash calculation on the entire new version upgrade package file using SHA-256 (or SHA-512) to obtain a fixed-length digest value; the digest value is used as the message body and digitally signed using the cloud's private key (such as PKCS#1v1.5 or PSS signature); finally, the "digest value, signature algorithm identifier, and signature result" are encapsulated together into signature information, which is sent to the vehicle communication terminal along with the upgrade task information, and then forwarded to the intelligent controller by the vehicle communication terminal through the aforementioned upgrade trigger command.
[0020] Among them, reference Figure 2 In this embodiment of the application, step S102 includes: S1021, Check if a historical upgrade package exists in the local cache. The intelligent controller autonomously accesses its local storage partition to check if its own historical upgrade package exists. The query process is achieved, for example, by reading an internally pre-installed upgrade package index file, which records the software information and signature information of the historical upgrade packages currently cached by the controller.
[0021] S1022, when a historical upgrade package exists in the local cache, the consistency between the historical upgrade package and the new version upgrade package is verified by comparing the signature information.
[0022] Specifically, when a historical upgrade package is detected, the smart controller calls the verification module in its security chip: extracts the hash value from the signature information in the header of the historical upgrade package cached locally; and compares the hash values of the two upgrade packages bit by bit by reading the hash value of the new version upgrade package carried in the upgrade trigger instruction, and generates a verification result based on the comparison result.
[0023] S1023, when the historical upgrade package and the new version upgrade package are the same, select not to download the new version upgrade package from the cloud.
[0024] When the verification results show that the historical upgrade package is consistent with the new version, the intelligent controller autonomously decides to skip the download process of the new version upgrade package and instead enter the installation stage based on the historical upgrade package. This reduces the repeated download of upgrade packages and shortens the upgrade time.
[0025] S1024, when the historical upgrade package and the new version upgrade package are inconsistent, select to delete the historical upgrade package and download the new version upgrade package from the cloud.
[0026] When the hash values of historical upgrade packages and new version upgrade packages are inconsistent, in order to upgrade the software according to the latest version upgrade package, the intelligent controller executes the following steps in sequence: clearing local historical upgrade packages through a secure erase command; activating its network module to establish a dedicated connection with the cloud; autonomously controlling the download process and receiving the new version upgrade package according to the block verification mechanism.
[0027] Furthermore, in this embodiment of the application, step S102 further includes: S1025, when the local cache does not contain the historical upgrade package, select to download the new version upgrade package from the cloud.
[0028] When the intelligent controller detects that the corresponding historical upgrade package does not exist in its local cache, it automatically triggers the following download process: The secure communication module sends a download request message to the cloud server. The download request message includes: controller hardware ID, current firmware version number, and security authentication token.
[0029] During download, an encrypted transmission channel conforming to the AUTOSAR standard (TLS1.3) is established, and upgrade package data is received in predefined block sizes (typically 128KB). Each data block is checked with CRC32 in real time and the reception status is fed back.
[0030] After the download is complete, the complete upgrade package is written to the specified non-volatile storage area, and the upgrade package metadata (version number, download timestamp, hash value) is recorded, and the upgrade package index table inside the controller is updated.
[0031] The entire process described above is completed autonomously by the intelligent controller without relying on external main control unit intervention, which meets the requirements of the autonomous upgrade architecture of distributed vehicle ECUs.
[0032] Reference Figure 2 In this embodiment of the application, after selecting to download the new version upgrade package from the cloud, the method further includes: S103, when receiving a message from the vehicle communication terminal that the upgrade package has partially failed to download, the fully downloaded new version upgrade package is retained, and the fully downloaded new version upgrade package will be used as the historical upgrade package when the upgrade trigger command is received again.
[0033] After the intelligent controller completes the download of the new version data package, when it receives a message from the vehicle communication terminal indicating that part of the upgrade package download failed, it automatically retains the fully downloaded new version upgrade package and marks it as pending verification, storing it in non-volatile memory. When the vehicle communication terminal triggers an upgrade command again, the controller will use this retained upgrade package as a historical version for validity verification. By comparing key information such as the version signature and hardware compatibility in the upgrade descriptor sent from the cloud, it intelligently decides whether to directly reuse the upgrade package. This mechanism ensures that in the event of network anomalies or partial component upgrade failures, the large-capacity upgrade package that has been downloaded will not be discarded invalidally. This avoids the waste of resources caused by repeated downloads, ensures the reliability and continuity of the upgrade process, and fully complies with the autonomous upgrade and secure storage requirements of automotive-grade ECUs.
[0034] Reference Figure 2 In this embodiment of the application, after selecting to download the new version upgrade package from the cloud, the method further includes: S104, when receiving a message from the vehicle communication terminal that the upgrade package has partially failed to download, if the new version upgrade package has not been fully downloaded, delete the partially downloaded new version upgrade package.
[0035] If the intelligent controller receives a partial download failure message from the vehicle communication terminal after a new version upgrade package fails for some reason, and detects that the current new version upgrade package has not been fully downloaded, it will automatically trigger a cleanup mechanism for the downloaded portion. This mechanism will use a secure erase command to completely delete the portion of the upgrade package data stored in the temporary buffer, and simultaneously reset the download status flag to ensure that the system returns to its initial state before the upgrade, preparing for a subsequent full download. This mechanism effectively avoids storage space fragmentation and version management chaos caused by interrupted downloads.
[0036] By differentiating OTA upgrade packages for intelligent and non-intelligent controllers, this mechanism retains successfully downloaded large intelligent controller upgrade packages (>1GB) when some upgrade packages fail to download. During the next upgrade, it checks the consistency of software information to determine whether to reuse the package: if the software information sent from the cloud matches the locally stored package, it is reused directly to avoid duplicate downloads; otherwise, it is deleted and re-downloaded. Based on the principle of "high cost of large file downloads and detectable version changes," this mechanism effectively solves the inefficiency problem of overall retries due to partial failures in mixed upgrade scenarios. It significantly reduces the amount of duplicate downloads of large intelligent controller upgrade packages, improving bandwidth utilization and upgrade efficiency while ensuring upgrade reliability. It is particularly suitable for multi-module OTA upgrade scenarios involving large-capacity components such as vehicle infotainment systems and driver assistance domain controllers.
[0037] Reference Figure 3 This application also provides an OTA upgrade package management method, including: S201 receives and parses the upgrade task information sent from the cloud to determine the target controller that needs to download the new version upgrade package; S202, when the target controller includes a non-intelligent controller, download a new version upgrade package for the non-intelligent controller from the cloud; S203, when the target controller includes an intelligent controller, the upgrade trigger command carrying the signature information of each intelligent controller is sent to the corresponding intelligent controller to trigger the corresponding intelligent controller to perform the following operation: based on whether the identification result of the historical upgrade package is stored in the local cache and the consistency comparison result of the historical upgrade package and the new version upgrade package, select whether to download the new version upgrade package from the cloud; The historical upgrade package is a complete upgrade package stored by the intelligent controller when it received a partial download failure message from the vehicle communication terminal during a previous upgrade task.
[0038] In this embodiment, the specific upgrade process of the intelligent controller is the same as that in the foregoing embodiments, and will not be repeated here.
[0039] In this embodiment of the application, when the intelligent controller selects to download the new version upgrade package from the cloud, the method further includes: S103, when it is detected that the new version upgrade package of all target controllers has not been fully downloaded, delete the new version upgrade packages of all non-smart controllers in this download, and send the upgrade package partial download failure information to the smart controller, triggering the smart controller to retain the new version upgrade package that has been fully downloaded or triggering the smart controller to delete the new version upgrade package that has been partially downloaded; The fully downloaded new version upgrade package will serve as the historical upgrade package for the next time the smart controller receives an upgrade trigger command.
[0040] This method employs a differentiated processing strategy for the upgrade process of intelligent and non-intelligent controllers: First, it parses the upgrade task information sent from the cloud to identify the target controller type that needs upgrading. For non-intelligent controllers, the onboard communication terminal directly downloads the corresponding upgrade package from the cloud. For intelligent controllers with autonomous processing capabilities, an upgrade trigger command carrying signature information is sent, authorizing each intelligent controller to autonomously decide on its download behavior. Specifically, the intelligent controller autonomously decides whether to reuse the cache or re-download based on the signature comparison result between the historical upgrade packages stored in its local cache (i.e., the complete upgrade packages retained from previous upgrade tasks due to partial download failures) and the current new version. This achieves an efficient combination of autonomous management of the intelligent controller upgrade process and centralized management of the non-intelligent controller, ensuring the coordination of the overall vehicle upgrade while fully leveraging the local decision-making capabilities of the intelligent controller.
[0041] This application embodiment also provides a vehicle OTA upgrade management system, including: an in-vehicle communication terminal and an intelligent controller and a non-intelligent controller connected to the in-vehicle communication terminal; The vehicle-mounted communication terminal is used to: after receiving upgrade task information from the cloud, determine the target controller that needs to download the new version upgrade package based on the upgrade task information; when the target controller includes a non-intelligent controller, directly download the new version upgrade package of the non-intelligent controller from the cloud; when the target controller includes an intelligent controller, send upgrade trigger instructions carrying the signature information of each intelligent controller to the corresponding intelligent controller respectively. Each triggered smart controller performs the following operations: based on whether the identification results of the historical upgrade package are stored in the local cache and the consistency comparison results between the historical upgrade package and the new version upgrade package, it selects whether to download the new version upgrade package from the cloud; The historical upgrade package is a complete upgrade package stored by the intelligent controller when it received information that part of the upgrade package failed to download during a previous upgrade task.
[0042] The specific control logic of the vehicle communication terminal and intelligent controller during the upgrade package download process is described in the above embodiments and will not be repeated here.
[0043] Figure 4 This is a block diagram illustrating a vehicle 200 according to an exemplary embodiment. For example, vehicle 200 may be a hybrid vehicle, a non-hybrid vehicle, an electric vehicle, a fuel cell vehicle, or other types of vehicle. Vehicle 200 may be an autonomous vehicle, a semi-autonomous vehicle, or a non-autonomous vehicle.
[0044] Reference Figure 4The vehicle 200 may include various subsystems, such as an infotainment system 210, a perception system 220, a decision control system 230, a drive system 240, and a computing platform 250. The vehicle 200 may also include more or fewer subsystems, and each subsystem may include multiple components. Furthermore, each subsystem and component of the vehicle 200 can be interconnected via wired or wireless means. In some embodiments, the infotainment system 210 may include a communication system, an entertainment system, and a navigation system, etc.
[0045] The perception system 220 may include several types of sensors for sensing information about the environment surrounding the vehicle 200. For example, the perception system 220 may include a global positioning system (which may be a GPS system, a BeiDou system, or another positioning system), an inertial measurement unit (IMU), lidar, millimeter-wave radar, ultrasonic radar, and a camera device.
[0046] The decision control system 230 may include a computing system, a vehicle controller, a steering system, a throttle, and a braking system. The drive system 240 may include components that provide power to the vehicle 200. In one embodiment, the drive system 240 may include an engine, an energy source, a transmission system, and wheels. The engine may be one or a combination of internal combustion engines, electric motors, and compressed air engines. The engine is capable of converting energy provided by the energy source into mechanical energy.
[0047] Some or all of the functions of vehicle 200 are controlled by computing platform 250. Computing platform 250 may include at least one processor 251 and memory 252, and processor 251 may execute instructions 253 stored in memory 252.
[0048] Processor 251 can be any conventional processor, such as a commercially available CPU. The processor may also include, for example, a Graphics Processing Unit (GPU), a Field Programmable Gate Array (FPGA), a System on Chip (SOC), an Application Specific Integrated Circuit (ASIC), or a combination thereof.
[0049] The memory 252 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk or optical disk.
[0050] In addition to instruction 253, memory 252 can also store data, such as road maps, route information, vehicle position, direction, speed, and other data. The data stored in memory 252 can be used by computing platform 250.
[0051] In this embodiment of the disclosure, the processor 251 may execute instructions 253 to complete all or part of the steps of the vehicle control method described above.
[0052] This disclosure also provides a computer-readable storage medium having stored thereon computer program instructions that, when executed by a processor, implement the steps of the vehicle control method provided in this disclosure.
[0053] Furthermore, the term “exemplary” is used herein to mean serving as an example, instance, or illustration. Any aspect or design described herein as “exemplary” is not necessarily to be construed as advantageous compared to other aspects or designs. Rather, the use of the term “exemplary” is intended to present the concept in a concrete manner. As used herein, the term “or” is intended to mean an inclusive “or” rather than an exclusive “or.” That is, unless otherwise specified or clear from the context, “X applies A or B” is intended to mean any of the natural inclusive arrangements. That is, “X applies A or B” satisfies any of the foregoing instances if X applies A; X applies B; or both X applies A and B. Additionally, unless otherwise specified or clear from the context to refer to the singular form, the articles “a” and “an” as used in this application and the appended claims are generally understood to mean “one or more.”
[0054] Similarly, although this disclosure has been shown and described with respect to one or more implementations, equivalent variations and modifications will occur to those skilled in the art upon reading and understanding the specification and drawings. This disclosure includes all such modifications and variations and is limited only by the scope of the claims. In particular, with respect to the various functions performed by the components described above (e.g., elements, resources, etc.), unless otherwise indicated, the terminology used to describe such components is intended to correspond to any component (functionally equivalent) that performs the specific function of the described component, even if structurally not equivalent to the disclosed structure. Furthermore, although specific features of this disclosure may have been disclosed with respect to only one of several implementations, such features may be combined with one or more other features of other implementations, as may be desired and advantageous to any given or particular application. Moreover, with regard to the terms “comprising,” “owning,” “having,” “having,” or variations thereof as used in the detailed description or claims, such terms are intended to be inclusive in a manner similar to the term “including.”
[0055] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the following claims.
[0056] It should be understood that this disclosure is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this disclosure is limited only by the appended claims.
[0057] It should be noted that the terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this disclosure are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this disclosure described herein can be implemented in orders other than those illustrated or described herein. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this disclosure. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this disclosure as detailed in the appended claims.
[0058] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "illustrative embodiment," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with an embodiment or example is included in at least one embodiment or example of this disclosure. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.
[0059] Any process or method description in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or more executable instructions for implementing a particular logical function or process, and the scope of preferred embodiments of this disclosure includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order depending on the function involved, as will be understood by those skilled in the art to which embodiments of this disclosure pertain.
[0060] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a system including a processing module, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device. More specific examples (a non-exhaustive list) of computer-readable media include: an electrical connection having one or more wires (control method), a portable computer disk drive (magnetic device), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic device, and portable optical disc read-only memory (CDROM). Furthermore, computer-readable media can even be paper or other suitable media on which programs can be printed, because programs can be obtained electronically, for example, by optically scanning the paper or other media, followed by editing, interpreting, or otherwise processing as necessary, and then stored in computer memory.
[0061] It should be understood that various parts of the embodiments of this disclosure can be implemented in hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented in software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.
[0062] Those skilled in the art will understand that all or part of the steps of the methods described in the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, the program includes one or a combination of the steps of the method embodiments.
[0063] Furthermore, the functional units in the various embodiments of this disclosure can be integrated into a single processing module, or each unit can exist physically separately, or two or more units can be integrated into a single module. The integrated module can be implemented in hardware or as a software functional module. If the integrated module is implemented as a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. The aforementioned storage medium can be a read-only memory, a hard disk, or an optical disk, etc.
[0064] Although embodiments of the present disclosure have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting the present disclosure. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of the present disclosure.
Claims
1. A method for managing OTA upgrade packages for an intelligent controller, characterized in that, include: Receive and parse the upgrade trigger command sent by the vehicle communication terminal to obtain the signature information of the new version upgrade package; Based on whether the identification results of historical upgrade packages are stored in the local cache and the consistency comparison results between historical upgrade packages and new version upgrade packages, decide whether to download the new version upgrade package from the cloud; The historical upgrade package is a complete upgrade package stored by the intelligent controller when it received a partial download failure message from the vehicle communication terminal during a previous upgrade task.
2. The OTA upgrade package management method for intelligent controllers according to claim 1, characterized in that, Based on whether the identification results of historical upgrade packages are stored in the local cache and the consistency comparison results between historical upgrade packages and new version upgrade packages, the steps for deciding whether to download the new version upgrade package from the cloud include: Check if the local cache contains a historical upgrade package; When a historical upgrade package exists in the local cache, the consistency between the historical upgrade package and the new version upgrade package is verified by comparing the signature information. When the historical upgrade package and the new version upgrade package are identical, select not to download the new version upgrade package from the cloud; When the historical upgrade package and the new version upgrade package are inconsistent, the historical upgrade package is deleted and the new version upgrade package is downloaded from the cloud.
3. The OTA upgrade package management method for intelligent controllers according to claim 1, characterized in that, Based on whether the identification results of historical upgrade packages are stored in the local cache and the consistency comparison results between historical upgrade packages and new version upgrade packages, the steps for deciding whether to download the new version upgrade package from the cloud also include: If the historical upgrade package is not available in the local cache, select to download the new version upgrade package from the cloud.
4. The OTA upgrade package management method for intelligent controllers according to claim 1, characterized in that, After selecting to download the new version upgrade package from the cloud, the method further includes: When a message indicating that the upgrade package download failed to complete is received from the vehicle communication terminal, the fully downloaded new version upgrade package is retained. The fully downloaded new version upgrade package will be used as the historical upgrade package when the upgrade trigger command is received again.
5. The OTA upgrade package management method for intelligent controllers according to claim 1, characterized in that, After selecting to download the new version upgrade package from the cloud, the method further includes: When a message indicating that the upgrade package download failed to complete is received from the vehicle communication terminal, the partially downloaded upgrade package is deleted if the new version upgrade package has not been fully downloaded.
6. A method for managing over-the-air (OTA) upgrades for vehicles, characterized in that, include: Receive and parse the upgrade task information sent from the cloud to determine the target controller that needs to download the new version upgrade package; When the target controller includes a non-intelligent controller, download the new version upgrade package of the non-intelligent controller from the cloud; When the target controller includes an intelligent controller, the upgrade trigger command carrying the signature information of each intelligent controller is sent to the corresponding intelligent controller to trigger the corresponding intelligent controller to perform the following operation: based on whether the identification result of the historical upgrade package is stored in the local cache and the consistency comparison result of the historical upgrade package and the new version upgrade package, select whether to download the new version upgrade package from the cloud; The historical upgrade package is a complete upgrade package stored by the intelligent controller when it received a partial download failure message from the vehicle communication terminal during a previous upgrade task.
7. The OTA upgrade management method for vehicles according to claim 6, characterized in that, Determine if a historical update package exists in the local cache; When a historical upgrade package exists in the local cache, the consistency between the historical upgrade package and the new version upgrade package is verified by comparing the signature information. When the historical upgrade package and the new version upgrade package are identical, the new version upgrade package will no longer be downloaded from the cloud; When the historical upgrade package and the new version upgrade package are inconsistent, delete the historical upgrade package and download the new version upgrade package from the cloud.
8. The OTA upgrade management method for vehicles according to claim 6, characterized in that, When the smart controller selects to download the new version upgrade package from the cloud, the method further includes: When it is detected that the new version upgrade package of all target controllers has not been fully downloaded, delete the new version upgrade packages of all non-smart controllers in this download, and send the upgrade package partial download failure information to the smart controller, triggering the smart controller to retain the new version upgrade package that has been fully downloaded or to delete the new version upgrade package that has been partially downloaded; The fully downloaded new version upgrade package will serve as the historical upgrade package for the next time the smart controller receives an upgrade trigger command.
9. An OTA (Over-The-Air) upgrade management system for vehicles, characterized in that, include: The vehicle-mounted communication terminal and the intelligent controller and non-intelligent controller connected to the vehicle-mounted communication terminal; The vehicle-mounted communication terminal is used to: after receiving upgrade task information from the cloud, determine the target controller that needs to download the new version upgrade package based on the upgrade task information; when the target controller includes a non-intelligent controller, directly download the new version upgrade package of the non-intelligent controller from the cloud; when the target controller includes an intelligent controller, send upgrade trigger instructions carrying the signature information of each intelligent controller to the corresponding intelligent controller respectively. Each triggered smart controller performs the following operations: based on whether the identification results of the historical upgrade package are stored in the local cache and the consistency comparison results between the historical upgrade package and the new version upgrade package, it selects whether to download the new version upgrade package from the cloud; The historical upgrade package is a complete upgrade package stored by the intelligent controller when it received information that part of the upgrade package failed to download during a previous upgrade task.
10. A vehicle, characterized in that, Includes the OTA upgrade management system for the vehicle as described in claim 9.