Method and apparatus for upgrading
By establishing a secure transmission layer channel between the ECU of an intelligent connected vehicle and the server, upgrade packages can be downloaded directly from the server, solving the problems of long download times and large storage space for upgrade packages from multiple devices, and improving upgrade efficiency and download speed.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2019-12-23
- Publication Date
- 2026-04-14
AI Technical Summary
In intelligent connected vehicles, the download time for upgrade packages of multiple devices is long and consumes a lot of storage space, which increases the load and storage requirements of the car box or gateway.
By establishing a secure transmission layer channel between the ECU and the server in a smart connected vehicle, upgrade packages can be downloaded directly from the server, avoiding downloads through the car box or gateway.
It improves upgrade efficiency and download speed, and reduces the load and storage requirements of car boxes or gateways.
Smart Images

Figure CN113094062B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of vehicle networking technology, and in particular to upgrade methods and devices. Background Technology
[0002] Over-the-air (OTA) technology is a technology that downloads data via wireless networks and is now widely used in software upgrades for devices such as smart TVs, mobile phones, tablets, and set-top boxes. With the development of intelligent connected vehicles, OTA is also increasingly being applied to their software upgrades. Original equipment manufacturers (OEMs) can reduce the number of vehicle recalls, lower operating costs, and quickly respond to user needs by using OTA to upgrade the relevant software or firmware of intelligent connected vehicles, thereby improving the user experience.
[0003] Intelligent connected vehicles include multiple devices, such as a telematics box (T-box), gateway, and electronic control unit (ECU). When multiple devices in an intelligent connected vehicle need to be upgraded, the cloud (or server) sends upgrade packages for these devices to the T-box or gateway. The T-box or gateway receives and verifies the upgrade packages, and after successful verification, sends the upgrade package for each device to the corresponding device. If the upgrade packages for these devices are large, the T-box or gateway not only spends a long time downloading them, but also consumes a large amount of storage space to store them, increasing the load and storage requirements of the T-box or gateway. Summary of the Invention
[0004] This application provides an upgrade method and apparatus that can improve upgrade efficiency and download speed, and reduce the load and storage requirements of the car box or gateway when multiple devices in a smart connected vehicle need to be upgraded.
[0005] To achieve the above objectives, the embodiments of this application adopt the following technical solutions:
[0006] In a first aspect, embodiments of this application provide an upgrade method, the method comprising: receiving upgrade information of the first ECU from a car box or gateway; establishing a first channel with a server based on the upgrade information of the first ECU; receiving an upgrade package of the first ECU from the server through the first channel; and performing an upgrade based on the upgrade package of the first ECU.
[0007] The technical solution provided in the first aspect above allows the first ECU to receive upgrade information from the first ECU of the car box or gateway when it needs to be upgraded. The first ECU establishes a first channel with the server based on the upgrade information of the first ECU, and receives the upgrade package of the first ECU from the server through the first channel. The upgrade is then performed based on the upgrade package of the first ECU. In this way, it is not necessary to download the upgrade package of the first ECU through the car box or gateway, which can improve the upgrade efficiency and download speed, and reduce the load and storage requirements of the car box or gateway.
[0008] In the first possible implementation, the first channel is a transport layer secure channel. Based on the above method, the first ECU can download its upgrade package from the server via the transport layer secure channel instead of through the car box or gateway, thereby improving upgrade efficiency and download speed, and reducing the load and storage requirements of the car box or gateway.
[0009] In one possible implementation, establishing a first channel with the server based on the upgrade information of the first ECU includes: sending a first request message to the server, wherein the first request message is used to request the establishment of the first channel with the server; receiving a first request response message from the server, wherein the first request response message is used to determine the encryption method between the server and the first ECU; sending a first completion message to the server, wherein the first completion message is used to indicate that the first channel between the first ECU and the server has been established; and receiving a first completion response message from the server, wherein the first completion response message is used to indicate that the first channel between the first ECU and the server has been established. Based on the above method, the first ECU can establish a first channel by sending a first request message to the server, receiving a first request response message from the server, sending a first completion message to the server, and receiving a first completion response message from the server, so that the first ECU can download the upgrade package from the server through the first channel instead of downloading the upgrade package through a car box or gateway.
[0010] In one possible implementation, the upgrade information of the first ECU includes the download address of the upgrade package for the first ECU. Based on the above method, since the upgrade information of the first ECU includes the download address of the upgrade package for the first ECU, the first ECU can establish a first channel with the server based on the download address of the upgrade package for the first ECU. This allows the first ECU to download the upgrade package for the first ECU from the server through the first channel, without going through a car box or gateway.
[0011] In one possible implementation, the upgrade information for the first ECU includes instruction information indicating that the first ECU should be upgraded. Based on the above method, since the upgrade information for the first ECU includes instruction information, the first ECU can establish a first channel with the server according to the instruction information, allowing the first ECU to download the upgrade package from the server via the first channel instead of through a car box or gateway.
[0012] In one possible implementation, upgrading based on the upgrade package of the first ECU includes: upgrading based on the upgrade package of the first ECU after verifying the successful signature of the upgrade package. Based on the above method, the first ECU can upgrade based on the upgrade package of the first ECU after verifying the successful signature of the upgrade package, thereby ensuring that the upgrade package of the first ECU has not been tampered with.
[0013] Secondly, embodiments of this application provide an upgrade method, which includes: receiving upgrade information from a plurality of devices from a server, wherein the upgrade information from the plurality of devices includes upgrade information from a first electronic control unit (ECU), the upgrade information from the first ECU being used to instruct the first ECU to establish a first channel with the server; and sending the upgrade information from the first ECU to the first ECU according to the upgrade information from the first ECU.
[0014] The technical solution provided in the second aspect above allows the car box or gateway to receive upgrade information from multiple devices on the server, and send upgrade information of the first ECU to the first ECU according to the upgrade information of the first ECU. This enables the first ECU to establish a first channel with the server based on the upgrade information of the first ECU. As a result, the first ECU can download the upgrade package of the first ECU from the server through the first channel instead of downloading the upgrade package of the first ECU through the car box or gateway, thereby improving upgrade efficiency and download speed, and reducing the load and storage requirements of the car box or gateway.
[0015] In one possible implementation, the first channel is a transport layer secure channel. Based on the above scheme, the car box or gateway can send the upgrade information of the first ECU to the first ECU, so that the first ECU can establish a transport layer secure channel with the server based on the upgrade information. Therefore, the first ECU can download the upgrade package from the server through the transport layer secure channel instead of through the car box or gateway, improving upgrade efficiency and download speed, and reducing the load and storage requirements of the car box or gateway.
[0016] In one possible implementation, the upgrade information of the first ECU includes the download address of the upgrade package for the first ECU. Based on the above scheme, the car box or gateway can send the download address of the upgrade package for the first ECU to the first ECU, so that the first ECU can establish a first channel with the server based on the download address of the upgrade package. Therefore, the first ECU can download the upgrade package from the server through the first channel instead of through the car box or gateway, improving upgrade efficiency and download speed, and reducing the load and storage requirements of the car box or gateway.
[0017] In one possible implementation, the upgrade information for the first ECU includes instruction information indicating that the first ECU should be upgraded. Based on the above scheme, the car box or gateway can send instruction information to the first ECU, enabling the first ECU to establish a first channel with the server according to the instruction information. This allows the first ECU to download its upgrade package from the server via the first channel instead of through the car box or gateway, improving upgrade efficiency and download speed while reducing the load and storage requirements of the car box or gateway.
[0018] In one possible implementation, the upgrade information for the multiple devices also includes an upgrade package for the second ECU; the method further includes sending the upgrade package to the second ECU. Based on the above method, the upgrade information for the multiple devices also includes the upgrade package for the second ECU, so that the car box or gateway can also send the upgrade package to the second ECU, enabling the second ECU to perform an upgrade based on the upgrade package.
[0019] Thirdly, embodiments of this application provide an upgrade method, which includes: sending upgrade information of multiple devices to a car box or gateway, wherein the upgrade information of the multiple devices includes upgrade information of a first electronic control unit (ECU); establishing a first channel with the first ECU based on the upgrade information of the first ECU; and sending an upgrade package of the first ECU to the first ECU through the first channel.
[0020] The technical solution provided in the third aspect above allows the server to send upgrade information of the first ECU to the car box or gateway, establish a first channel with the first ECU based on the upgrade information, and send the upgrade package of the first ECU to the first ECU through the first channel. This enables the first ECU to download the upgrade package from the server through the first channel instead of through the car box or gateway, thereby improving upgrade efficiency and download speed, and reducing the load and storage requirements of the car box or gateway.
[0021] In one possible implementation, the first channel is a transport layer secure channel. Based on the above method, the server can establish a transport layer secure channel with the first ECU according to the upgrade information of the first ECU, so that the first ECU can download the upgrade package from the server through the transport layer secure channel instead of downloading it through the car box or gateway, thereby improving upgrade efficiency and download speed, and reducing the load and storage requirements of the car box or gateway.
[0022] In one possible implementation, establishing a first channel with the first ECU based on its upgrade information includes: receiving first request information from the first ECU, wherein the first request information is used to request the establishment of the first channel with the server; sending first request response information to the first ECU based on the first request information, wherein the first request response information is used to determine the encryption method between the server and the first ECU; receiving first completion information from the first ECU, wherein the first completion information is used to indicate that the first channel between the first ECU and the server has been established; and sending first completion response information to the first ECU based on the first completion information, wherein the first completion response information is used to indicate that the first channel between the first ECU and the server has been established. Based on the above method, the server can establish a first channel by receiving a first request information from the first ECU, sending a first request response information to the first ECU according to the first request information, receiving a first completion information from the first ECU, and sending a first completion response information to the first ECU according to the first completion information. This allows the first ECU to download its upgrade package from the server through a transport layer secure channel instead of through the car box or gateway, thereby improving upgrade efficiency and download speed, and reducing the load and storage requirements of the car box or gateway.
[0023] In one possible implementation, the upgrade information of the first ECU includes the download address of the upgrade package for the first ECU. Based on the above method, the server can establish a first channel with the first ECU according to the download address of the upgrade package, so that the first ECU can download the upgrade package from the server through a transport layer secure channel instead of through the car box or gateway, thereby improving upgrade efficiency and download speed, and reducing the load and storage requirements of the car box or gateway.
[0024] In one possible implementation, the upgrade information for the first ECU includes instruction information indicating that the first ECU should be upgraded. Based on the above method, the server can establish a first channel with the first ECU according to the instruction information, so that the first ECU can download the upgrade package from the server through a transport layer secure channel instead of through the car box or gateway, thereby improving upgrade efficiency and download speed, and reducing the load and storage requirements of the car box or gateway.
[0025] In one possible implementation, the method further includes signing the upgrade package for the first ECU. Based on the above method, the server can sign the upgrade package for the first ECU, enabling the first ECU to verify whether the upgrade package has been tampered with after receiving it, thereby ensuring the security of the first ECU upgrade.
[0026] In one possible implementation, the upgrade information for the multiple devices also includes an upgrade package for the second ECU. Based on the above method, the server can also send the upgrade package for the second ECU to the car box or gateway, enabling the car box or gateway to assist in upgrading the second ECU.
[0027] Fourthly, embodiments of this application provide a communication device that implements the methods and functions described in the first aspect. This function can be implemented in hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the aforementioned functions.
[0028] Fifthly, embodiments of this application provide a communication device that implements the methods and functions described in the second aspect above. This function can be implemented in hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the aforementioned functions.
[0029] Sixthly, embodiments of this application provide a communication device that implements the methods and functions described in the third aspect above. This function can be implemented in hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the aforementioned functions.
[0030] In a seventh aspect, embodiments of this application provide a communication device, including: at least one processor, at least one memory, and a communication interface, wherein the communication interface, the at least one memory, and the at least one processor are coupled together; the communication device communicates with other devices through the communication interface, and the at least one memory is used to store a computer program, such that when the computer program is executed by the at least one processor, it implements the upgrade method as described in the first aspect and its various possible implementations.
[0031] Eighthly, embodiments of this application provide a communication device, including: at least one processor, at least one memory, and a communication interface, wherein the communication interface, the at least one memory, and the at least one processor are coupled together; the communication device communicates with other devices through the communication interface, and the at least one memory is used to store a computer program such that when the computer program is executed by the at least one processor, it implements the upgrade method as described in the second aspect and its various possible implementations.
[0032] Ninthly, embodiments of this application provide a communication device, including: at least one processor, at least one memory, and a communication interface, wherein the communication interface, the at least one memory, and the at least one processor are coupled together; the communication device communicates with other devices through the communication interface, and the at least one memory is used to store a computer program such that when the computer program is executed by the at least one processor, it implements the upgrade method as described in the third aspect and its various possible implementations.
[0033] In a tenth aspect, this application provides a system-on-a-chip (SoC) that can be used in a communication device. The SoC includes at least one processor in which the relevant program instructions are executed to implement the functions of a first ECU according to the method of the first aspect and any design thereof. Optionally, the SoC may further include at least one memory storing the relevant program instructions.
[0034] Eleventhly, this application provides a system-on-a-chip (SoC) that can be used in a communication device. The SoC includes at least one processor in which the relevant program instructions are executed to implement the functions of a car box or gateway according to the method of the second aspect and any design thereof. Optionally, the SoC may further include at least one memory storing the relevant program instructions.
[0035] In a twelfth aspect, this application provides a system-on-a-chip (SoC) that can be used in a communication device. The SoC includes at least one processor in which the relevant program instructions are executed to implement the functions of a server according to the method of the third aspect and any design thereof. Optionally, the SoC may further include at least one memory storing the relevant program instructions.
[0036] In a thirteenth aspect, embodiments of this application provide a computer-readable storage medium, such as a non-transient computer-readable storage medium. A computer program is stored thereon, which, when executed on a computer, causes the computer to perform any of the possible methods described in the first aspect. For example, the computer may be at least one storage node.
[0037] In a fourteenth aspect, embodiments of this application provide a computer-readable storage medium, such as a non-transient computer-readable storage medium. A computer program is stored thereon, which, when executed on a computer, causes the computer to perform any of the possible methods described in the second aspect above. For example, the computer may be at least one storage node.
[0038] In a fifteenth aspect, embodiments of this application provide a computer-readable storage medium, such as a non-transient computer-readable storage medium. A computer program is stored thereon, which, when executed on a computer, causes the computer to perform any of the possible methods described in the third aspect above. For example, the computer may be at least one storage node.
[0039] In a sixteenth aspect, embodiments of this application provide a computer program product that, when run on a computer, causes any of the methods provided in the first aspect to be executed. For example, the computer may be at least one storage node.
[0040] In a seventeenth aspect, embodiments of this application provide a computer program product that, when run on a computer, causes any of the methods provided in the second aspect to be executed. For example, the computer may be at least one storage node.
[0041] In an eighteenth aspect, embodiments of this application provide a computer program product that, when run on a computer, causes any of the methods provided in the third aspect to be executed. For example, the computer may be at least one storage node.
[0042] In a nineteenth aspect, embodiments of this application provide an upgrade system, which may include any one or more of the following: a communication device as in the fourth aspect, or a communication device as in the fifth aspect, or a communication device as in the sixth aspect, or a communication device as in the seventh aspect, or a communication device as in the eighth aspect, or a communication device as in the ninth aspect, or a system chip as in the tenth aspect, or a system chip as in the eleventh aspect, or a system chip as in the twelfth aspect, or a computer-readable storage medium as in the thirteenth aspect, or a computer-readable storage medium as in the fourteenth aspect, or a computer-readable storage medium as in the fifteenth aspect, or a computer program product as in the sixteenth aspect, or a computer program product as in the seventeenth aspect, or a computer program product as in the eighteenth aspect.
[0043] It is understood that any of the communication devices, system chips, computer-readable storage media, computer program products or upgrade systems provided above are used to execute the corresponding methods provided above. Therefore, the beneficial effects they can achieve can be referred to the beneficial effects in the corresponding methods, and will not be repeated here. Attached Figure Description
[0044] Figure 1A This is a schematic diagram of the upgrade system architecture provided in the embodiments of this application;
[0045] Figure 1B A schematic diagram of the vehicle architecture provided for an embodiment of this application;
[0046] Figure 2 This is a schematic diagram of the hardware structure of the communication device provided in the embodiments of this application;
[0047] Figure 3 A flowchart illustrating the upgrade method provided in this application embodiment;
[0048] Figure 4 Flowchart of the upgrade method provided in the embodiments of this application Figure 2 ;
[0049] Figure 5 Flowchart of the upgrade method provided in the embodiments of this application Figure 3 ;
[0050] Figure 6 Flowchart of the upgrade method provided in the embodiments of this application Figure 4 ;
[0051] Figure 7 A schematic diagram of the communication device provided in the embodiments of this application is shown below;
[0052] Figure 8Schematic diagram of the communication device provided in the embodiments of this application Figure 2 ;
[0053] Figure 9 Schematic diagram of the communication device provided in the embodiments of this application Figure 3 ;
[0054] Figure 10 This is a schematic diagram illustrating the composition of the upgrade system provided in an embodiment of this application. Detailed Implementation
[0055] The embodiments of this application will now be described in detail with reference to the accompanying drawings.
[0056] like Figure 1A The diagram shown is a schematic representation of the architecture of the upgrade system provided in an embodiment of this application. Figure 1A In this upgrade system, the vehicle 10 and server 20 (or cloud 30) may be included.
[0057] Figure 1A The vehicle 10 in this context can be an intelligent connected vehicle. Vehicle 10 may include multiple devices. For example, vehicle 10 may include devices such as a T-Box, a gateway, and an ECU. Specifically, the architecture of vehicle 10 can be as follows: Figure 1B As shown.
[0058] Figure 1B This is a schematic diagram of the architecture of a vehicle 10 provided in an embodiment of this application, such as... Figure 1B As shown, vehicle 10 may include T-Box 101, gateway 102, and ECU 103-ECU 107.
[0059] The T-Box 101 and the gateway 102 can be connected via Ethernet. The gateway 102 and the ECU can be connected via Ethernet, controller area network (CAN), local interconnect network (LIN), media oriented system transport (MOST), or FlexRay. For example, the gateway 102 and the ECU 103 can be connected via CAN, and the gateway 102 and the ECU 105 can be connected via LIN.
[0060] Figure 1B The T-Box 101 can communicate with both external devices and internal devices of the vehicle 10. The external devices of the vehicle 10 can be described as devices outside the vehicle 10, for example... Figure 1A Server 20, cloud 30, or user terminal device ( Figure 1A (Not shown); the internal equipment of vehicle 10 may be Figure 1B The devices shown include, for example, gateway 102 or ECU 103, etc.
[0061] Figure 1B The T-Box 101 communicates with the internal devices of the vehicle 10 and can be used to send information to the internal devices of the vehicle 10. For example, the T-Box 101 can send upgrade information for multiple devices to the gateway 102. The T-Box 101 also communicates with the external devices of the vehicle 10 and can be used to receive information from the server 20 or the cloud 30. For example, the T-Box 101 can be used to receive upgrade information for multiple devices from the server 20 or the cloud 30.
[0062] In some embodiments, T-Box 101 may also have the ability to coordinate upgrades of internal devices in vehicle 10. For example, taking upgrade information for multiple devices, including upgrade information for ECU 103 and ECU 105, T-Box 101 can receive upgrade information for multiple devices from server 20, verify the upgrade information for multiple devices, and after successful verification, send the upgrade information for ECU 103 to ECU 103 through gateway 102, and send the upgrade information for ECU 105 to ECU 105 through gateway 102.
[0063] Figure 1B Gateway 102 is a core component of vehicle 10. Gateway 102 can route network data such as CAN, LIN, MOST, or FlexRay across different networks. For example, gateway 102 can receive upgrade information from ECU 103 via T-Box 101 and send the upgrade information from ECU 103 to ECU 103.
[0064] In some embodiments, gateway 102 may also have the ability to coordinate upgrades of internal devices in vehicle 10. For example, taking upgrade information for multiple devices, including upgrade information for ECU 106 and ECU 105, gateway 102 can receive upgrade information for multiple devices from T-Box 101, verify the upgrade information for multiple devices, and after successful verification, send the upgrade information for ECU 106 to ECU 106 and the upgrade information for ECU 105 to ECU 105.
[0065] Figure 1B The ECU in the vehicle 10 can be a microcomputer controller that can perform preset control functions. For example, ECU 104 can be used to control engine operation, and ECU 103 can be used to protect vehicle safety.
[0066] In some embodiments, Figure 1B The ECU in the text can also be an autonomous driving-related device. For example, ECU 105 can be a mobile data center (MDC), and ECU 107 can be a human-machine interaction (HMI) device. The MDC can be the intelligent in-vehicle computing platform of vehicle 10, and the HMI can be the infotainment system of vehicle 10.
[0067] It should be understood that Figure 1B The architecture of vehicle 10 shown is for illustrative purposes only and is not intended to limit the technical solutions of this application. Those skilled in the art should understand that in specific implementations, vehicle 10 may also include other devices, such as on-board diagnostic (OBD) systems or domain controllers, and the number of gateways, domain controllers, and ECUs can be determined according to specific needs.
[0068] Figure 1A The server 20 or cloud 30 can be equipped to discover upgrade information for devices in vehicle 10 and instruct them to be upgraded. For example, when server 20 discovers upgrade information for multiple devices in vehicle 10, it can send the upgrade information for those devices to vehicle 10.
[0069] Figure 1A The server 20 or cloud 30 can also provide services to devices in the vehicle 10. For example, if the ECU 106 is used for navigation, the server 20 or cloud 30 can provide navigation services to the ECU 106.
[0070] It should be understood that Figure 1A The upgrade system shown is for illustrative purposes only and is not intended to limit the technical solutions of this application. Those skilled in the art should understand that in specific implementations, the upgrade system may also include other devices, and the number of vehicles 10, servers 20, or cloud devices 30 can be determined according to specific needs without limitation.
[0071] Optionally, embodiments of this application Figure 1B Each device in the system, such as server 20, cloud 30, T-Box 101, gateway 102, or ECU 106, can be a functional module within a device. It is understood that the functional module can be a component in a hardware device, a software function running on dedicated hardware, or a virtualized function instantiated on a platform (e.g., a cloud platform).
[0072] For example, Figure 1B Each device in the system can be accessed via Figure 2 This is achieved using hardware device 200. Figure 2 The diagram shows a hardware structure of a hardware device applicable to embodiments of this application. The hardware device 200 may include at least one processor 201, a communication line 202, a memory 203, and at least one communication interface 204.
[0073] The processor 201 may be a general-purpose CPU, a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits used to control the execution of the program of the present application.
[0074] Communication line 202 may include a path for transmitting information between the aforementioned components, such as a bus.
[0075] Communication interface 204 uses any transceiver-like device for communicating with other devices or communication networks, such as Ethernet interface, radio access network (RAN) interface, wireless local area network (WLAN) interface, etc.
[0076] The memory 203 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but not limited thereto. The memory may exist independently and be connected to the processor via communication line 202. The memory may also be integrated with the processor. The memory provided in this embodiment of the application is generally non-volatile. The memory 203 is used to store computer execution instructions involved in the scheme of this application and is controlled by the processor 201 for execution. The processor 201 is used to execute computer execution instructions stored in the memory 203, thereby implementing the method provided in the embodiments of this application.
[0077] Optionally, the computer execution instructions in the embodiments of this application may also be referred to as application code, and the embodiments of this application do not specifically limit this.
[0078] In a specific implementation, as one embodiment, the processor 201 may include one or more CPUs, for example... Figure 2 CPU0 and CPU1 in the CPU.
[0079] In a specific implementation, as one example, the hardware device 200 may include multiple processors, for example... Figure 2 Processors 201 and 207 are described herein. Each of these processors may be a single-core (single-CPU) processor or a multi-core (multi-CPU) processor. A processor here may refer to one or more devices, circuits, and / or processing cores used to process data (e.g., computer program instructions).
[0080] In a specific implementation, as one embodiment, the hardware device 200 may further include an output device 205 and an input device 206. The output device 205 communicates with the processor 201 and can display information in various ways. For example, the output device 205 may be a liquid crystal display (LCD), a light-emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector, etc. The input device 206 communicates with the processor 201 and can receive user input in various ways. For example, the input device 206 may be a mouse, keyboard, touchscreen device, or sensing device, etc.
[0081] In a specific implementation, the hardware device 200 can be an embedded device or a device with... Figure 2 Devices with similar structures. This application does not limit the type of hardware device 200 to any particular embodiment.
[0082] The following is combined Figure 1A , Figure 1B and Figure 2 The upgrade method provided in the embodiments of this application will be described in detail.
[0083] It should be noted that the upgrade method provided in this application embodiment can be applied to multiple fields, such as: unmanned driving, autonomous driving, assisted driving, intelligent driving, connected driving, intelligent connected driving, car sharing, etc.
[0084] It should be noted that the message names between network elements or the names of parameters in the messages in the following embodiments of this application are just examples. Other names may be used in the specific implementation. This application does not limit them in this respect.
[0085] It should be noted that in the description of this application, terms such as "first" or "second" are used only for the purpose of distinguishing descriptions and should not be construed as indicating or implying relative importance or order. The "first ECU" and other ECUs with different numbers in this application are used solely for the convenience of the context; the different order numbers themselves do not have specific technical meaning. For example, "first ECU," "second ECU," etc., can be understood as one or any one of a series of ECUs.
[0086] It is understood that in the embodiments of this application, the server, cloud, T-Box, gateway, or ECU may execute some or all of the steps in the embodiments of this application. These steps are merely examples, and the embodiments of this application may also execute other steps or variations thereof. Furthermore, the steps may be executed in different orders as presented in the embodiments of this application, and it is not necessary to execute all the steps in the embodiments of this application.
[0087] like Figure 3 As shown, this application provides an upgrade method, which includes steps 301-305.
[0088] Step 301: The server sends upgrade information for multiple devices to the T-Box / gateway.
[0089] The server can be Figure 1A Server 20 in the middle, the T-Box can be the T-Box in the vehicle, for example, the vehicle can be Figure 1A In vehicle 10, the T-Box can be Figure 1B The T-Box 101 in the system. The gateway can be a gateway in the vehicle; for example, the vehicle could be... Figure 1A Vehicle 10 in the middle, the gateway can be Figure 1B Gateway 102 in the middle.
[0090] It should be noted that the server in this application embodiment can be replaced by the cloud, which can be... Figure 1A Cloud 30.
[0091] The upgrade information for multiple devices may include upgrade information for one or more devices within the vehicle's internal systems.
[0092] One possible implementation is that the upgrade information for multiple devices may include the upgrade information for a first ECU. The upgrade information for the first ECU can be used to instruct the server to establish a first channel with the first ECU.
[0093] The first ECU can be Figure 1B Any of ECUs 103-107. The upgrade information for the first ECU may indicate the address or identifier of the server.
[0094] It should be noted that the upgrade information for multiple devices may include upgrade information for a group of first ECUs. That is, the upgrade information for multiple devices may include upgrade information for two or more first ECUs. This application embodiment uses the case where the upgrade information for multiple devices includes upgrade information for a group of first ECUs as an example. For the case where the upgrade information for multiple devices includes upgrade information for a single first ECU, please refer to the following description, which will not be repeated here.
[0095] In some embodiments, the upgrade information for the first ECU may include a download address for the upgrade package of the first ECU, which may indicate the address of a server. For example, the download address of the upgrade package of the first ECU may be a Uniform Resource Locator (URL) of the server.
[0096] In some embodiments, the upgrade information for the first ECU may include the download address of the upgrade package for the first ECU and the address of the server. For example, the download address of the upgrade package for the first ECU may be the URL of the resource server where the upgrade package for the first ECU is located. Subsequently, after the first ECU and the server establish a first channel, the server can download the upgrade package for the first ECU from the resource server according to the download address of the upgrade package for the first ECU, and send the upgrade package for the first ECU to the first ECU.
[0097] In some embodiments, the upgrade information for the first ECU may include indication information that can be used to indicate an upgrade for the first ECU.
[0098] The indication information may include the identifier of the first ECU and the identifier of the server.
[0099] Optionally, the first ECU is an ECU with a larger upgrade package and / or more frequent upgrades. For example, the first ECU is an MDC or HMI.
[0100] Optionally, prior to step 301, the server and T-Box / gateway establish a second channel.
[0101] The second channel can be a transport layer security (TLS) channel. This second channel can be used for communication between the T-Box / gateway and the server.
[0102] In some embodiments, the server and the T-Box / gateway can establish a second channel through a handshake. After the second channel is successfully established, the server and the T-Box / gateway can communicate in encrypted form.
[0103] The following example illustrates the process of establishing a second channel between a server and a T-Box / gateway through a handshake, using the example of a server and a T-Box / gateway establishing a second channel through four communications.
[0104] Optionally, the server and the T-Box / gateway establish a second channel, including: the server receiving second request information from the T-Box / gateway, wherein the second request information is used to request the establishment of a second channel with the server; the server sending second request response information to the T-Box / gateway based on the second request information, wherein the second request response information is used to determine the encryption method between the server and the T-Box / gateway; the server receiving second completion information from the T-Box / gateway, wherein the second completion information is used to indicate that the second channel between the server and the T-Box / gateway has been established; and the server sending second completion response information to the T-Box / gateway based on the second completion information, wherein the second completion response information is used to indicate that the second channel between the server and the T-Box / gateway has been established.
[0105] The second request information may include the version of the encrypted communication protocol supported by the T-Box / gateway (e.g., TLS 1.2), a first random number, and the encryption method supported by the T-Box / gateway (e.g., asymmetric encryption algorithm (RSA) public key encryption method). The second request information may be named a ClientHello request.
[0106] Optionally, the second request information may also include the compression methods supported by the T-Box / gateway.
[0107] The second request response information may include a second random number, the server's certificate, and the version and encryption method of the encrypted communication protocol used by the server. The second request response information may be named "ServerHello".
[0108] Optionally, the second request response information may include the compression method determined by the server.
[0109] It should be noted that if the encrypted communication protocol versions supported by the server and the T-Box / gateway are inconsistent, the server can disable encrypted communication. In other words, subsequent communication between the server and the T-Box / gateway will not be encrypted.
[0110] Optionally, the second request response information can also be used to request a certificate for the T-Box / gateway.
[0111] The second completion information may include a third random number, a T-Box / gateway encoding change notification, and a T-Box / gateway handshake end notification. The T-Box / gateway encoding change notification can be used to instruct the T-Box / gateway to send information using the encryption method determined in the second request-response information after sending the second completion information. The T-Box / gateway handshake end notification can be used to indicate the end of the T-Box / gateway handshake phase.
[0112] Optionally, the second completion information may also be information that is signed by the second request information, the third random number, the T-Box / gateway encoded change notification, and the T-Box / gateway handshake end notification according to a digest function (e.g., a hash function).
[0113] The second completion response information may include a server encoding change notification and a server handshake end notification. The server encoding change notification can instruct the server to send information using the encryption method determined in the second request response information after sending the second completion response information. The server handshake end notification can indicate the end of the server's handshake phase.
[0114] Optionally, after receiving the second completion information, the server can generate a first session key based on the encryption method determined from the first random number, the second random number, the third random number, and the second request-response information. Subsequently, the server can use the first session key to encrypt information sent to the T-Box / gateway, or the server can use the first session key to decrypt information from the T-Box / gateway.
[0115] Optionally, if the server discovers that there are devices in the vehicle's internal equipment that need to be upgraded, the server sends upgrade information for multiple devices to the T-Box / gateway.
[0116] For example, with Figure 1A and Figure 1B As shown in the example, server 20 receives instruction information from the OEM system, which instructs server 20 to notify vehicle 10 to upgrade the internal equipment of vehicle 10. Server 20 sends upgrade information for multiple devices to T-Box 101 / gateway 102.
[0117] Optionally, the server sends upgrade information for multiple devices to the T-Box / gateway, including: the server signing the upgrade information for the multiple devices to obtain signed upgrade information for the multiple devices; the server encrypting the signed upgrade information for the multiple devices to obtain encrypted upgrade information for the multiple devices; and the server sending the encrypted upgrade information for the multiple devices to the T-Box / gateway.
[0118] The server signing the upgrade information for the multiple devices can include: the server signing the upgrade information for the multiple devices in one layer, or the server signing the upgrade information for the multiple devices in two layers.
[0119] Optionally, the server performs a layer of signing on the upgrade information for the multiple devices, including: the server signing the upgrade information for the multiple devices.
[0120] For example, taking the server performing a layer-by-layer signature on the upgrade information of multiple devices as an example, the server signs the upgrade information of the first ECU according to the first digest function (e.g., hash function) to obtain the signed upgrade information of the first ECU; the server encrypts the signed upgrade information of the first ECU using the first session key to obtain the encrypted upgrade information of the first ECU; the server sends the encrypted upgrade information of the first ECU to the T-Box / gateway.
[0121] Optionally, the server performs a two-layer signature on the upgrade information of the multiple devices, including: the server signs the upgrade information of each device in the upgrade information of the multiple devices to obtain the signed upgrade information of the multiple devices; the server signs the signed upgrade information of the multiple devices.
[0122] For example, taking the server performing a two-layer signature on upgrade information for multiple devices as an example, the server signs the upgrade information of the first ECU according to the second digest function to obtain the first signature information; the server signs the first signature information according to the first digest function to obtain the second signature information; the server encrypts the second signature information using the first session key to obtain the encrypted second signature information; the server sends the encrypted second signature information to the T-Box / gateway. The first digest function and the second digest function can be the same or different.
[0123] Step 302: The T-Box / gateway receives upgrade information from multiple devices on the server, and sends upgrade information to the first ECU based on the upgrade information of the first ECU.
[0124] Optionally, before the T-Box / gateway receives upgrade information from multiple devices on the server, the T-Box / gateway and the server establish a second channel.
[0125] The T-Box / gateway and the server can establish a second channel through a handshake. Once the second channel is successfully established, the T-Box / gateway and the server can communicate in encrypted form.
[0126] The following example illustrates the process of establishing a second channel between a T-Box / gateway and a server through four communications.
[0127] Optionally, the T-Box / gateway and the server establish a second channel, including: the T-Box / gateway sending a second request message to the server, wherein the second request message is used to request the establishment of a second channel with the server; the T-Box / gateway receiving a second request response message from the server, wherein the second request response message is used to determine the encryption method between the server and the T-Box / gateway; the T-Box / gateway sending a second completion message to the server, wherein the second completion message is used to indicate that the second channel between the server and the T-Box / gateway has been established; and the T-Box / gateway receiving a second completion response message from the server, wherein the second completion response message is used to indicate that the second channel between the server and the T-Box / gateway has been established.
[0128] Optionally, after sending the second completion message, the T-Box / gateway can generate a first session key based on the encryption method determined from the first random number, the second random number, the third random number, and the second request-response information. Subsequently, the T-Box / gateway can use the first session key to encrypt information sent to the server, or the T-Box / gateway can use the first session key to decrypt information from the server.
[0129] Optionally, the T-Box / gateway sends the upgrade information of the first ECU to the first ECU based on the upgrade information of the first ECU. This includes: after the T-Box / gateway successfully verifies the upgrade information of the multiple devices, it sends the upgrade information of the first ECU to the first ECU based on the upgrade information of the first ECU.
[0130] For example, taking the server performing a layer-by-layer signature on the upgrade information of multiple devices as an example, the T-Box / gateway uses the first session key to decrypt the upgrade information of the first ECU to obtain the decrypted upgrade information of the first ECU; the T-Box / gateway verifies the decrypted upgrade information of the first ECU according to the first digest function, and after successful verification, sends the decrypted upgrade information of the first ECU to the first ECU.
[0131] For example, taking the server performing a two-layer signature on the upgrade information of multiple devices as an example, the T-Box / gateway decrypts the upgrade information of the first ECU using the first session key to obtain the decrypted upgrade information of the first ECU; the T-Box / gateway verifies the decrypted upgrade information of the first ECU according to the first digest function, and after successful verification, sends the decrypted upgrade information of the first ECU to the first ECU.
[0132] In some embodiments, if the T-Box / gateway fails to verify the upgrade information of the multiple devices, the T-Box / gateway sends a verification failure message to the server, which indicates that the T-Box / gateway verification has failed.
[0133] Step 303: The first ECU receives upgrade information from the first ECU in the T-Box / gateway, and establishes a first channel with the server based on the upgrade information of the first ECU.
[0134] In some embodiments, if the upgrade information of the first ECU includes a download address for the upgrade package of the first ECU, the download address of the upgrade package of the first ECU indicates the address of the server. The first ECU can determine the server based on the download address of the upgrade package of the first ECU and establish a first channel with the server. Subsequently, the first ECU can send the download address of the upgrade package of the first ECU to the server, so that the server can send the upgrade package of the first ECU to the first ECU based on the download address of the upgrade package of the first ECU.
[0135] In some embodiments, if the upgrade information of the first ECU includes a download address for the upgrade package of the first ECU and a server address, the first ECU can determine the server based on the server address and establish a first channel with the server. Subsequently, the first ECU can send the download address of the upgrade package of the first ECU to the server, so that the server can send the upgrade package of the first ECU to the first ECU based on the download address of the upgrade package of the first ECU.
[0136] In some embodiments, if the upgrade information of the first ECU includes instruction information, which includes the identifier of the first ECU and the identifier of the server, the first ECU determines the server based on the server identifier and establishes a first channel with the server. Subsequently, the first ECU can send its identifier to the server so that the server can send the upgrade package of the first ECU to the first ECU based on the first ECU identifier.
[0137] Optionally, if the server performs a two-layer signature on the upgrade information of the multiple devices, the first ECU establishes a first channel with the server based on its upgrade information. This includes: after successfully verifying its upgrade information, the first ECU establishes a first channel with the server based on its upgrade information. For example, the first ECU verifies its upgrade information using a second digest function, and after successful verification, establishes a first channel with the server based on its upgrade information.
[0138] It should be noted that if the server performs a two-layer signature on the upgrade information of the multiple devices, the T-Box / gateway can also verify the upgrade information of the first ECU and send the upgrade information of the first ECU to the first ECU after successful verification. In this way, the first ECU does not need to verify its own upgrade information.
[0139] Further optionally, if the first ECU fails to verify the upgrade information of the first ECU, the first ECU sends a verification failure message to the server, which is used to indicate that the first ECU has failed to verify.
[0140] The first channel can be a TLS channel. The first channel can be used for communication between the first ECU and the server.
[0141] In some embodiments, the first ECU and the server can establish a first channel through a handshake. After the first channel is successfully established, the first ECU and the server can communicate in encrypted form.
[0142] The following example illustrates the process of establishing a first channel between the first ECU and the server through four communications.
[0143] Optionally, the first ECU and the server establish a first channel, including: the first ECU sending a first request message to the server, wherein the first request message is used to request the establishment of a first channel with the server; the first ECU receiving a first request response message from the server, wherein the first request response message is used to determine the encryption method between the server and the first ECU; the first ECU sending a first completion message to the server, wherein the first completion message is used to indicate that the establishment of the first channel between the first ECU and the server is complete; and the first ECU receiving a first completion response message from the server, wherein the first completion response message is used to indicate that the establishment of the first channel between the first ECU and the server is complete.
[0144] The first request information may include the version of the encrypted communication protocol supported by the first ECU (e.g., TLS 1.2), a fourth random number, and the encryption method supported by the first ECU (e.g., asymmetric encryption algorithm (RSA) public key encryption method). The first request information may be named a ClientHello request.
[0145] Optionally, the first request information may also include the compression method supported by the first ECU.
[0146] The first request-response information may include a fifth random number, the server's certificate, and the version and method of the encrypted communication protocol used by the server. This first request-response information may be named "ServerHello".
[0147] Optionally, the first request response information may include the compression method determined by the server.
[0148] It should be noted that if the encrypted communication protocol versions supported by the server and the first ECU are inconsistent, the server can disable encrypted communication. In other words, subsequent communication between the server and the first ECU will not be encrypted.
[0149] Optionally, the first request response information can also be used to request a certificate for the first ECU.
[0150] The first completion information may include a sixth random number, a first ECU code change notification, and a first ECU handshake end notification. The first ECU code change notification can be used to instruct the first ECU to send information using the encryption method determined in the first request-response information after sending the first completion information. The first ECU handshake end notification can be used to indicate the end of the handshake phase for the first ECU.
[0151] Optionally, the first completion information may also be information after signing the first request information, the sixth random number, the first ECU encoding change notification, and the first ECU handshake end notification according to a digest function (e.g., a hash function).
[0152] The first completion response information may include a server encoding change notification and a server handshake end notification. The server encoding change notification can be used to instruct the server to send information using the encryption method determined in the first request response information after sending the first completion response information. The server handshake end notification can be used to indicate the end of the server's handshake phase.
[0153] Optionally, after receiving the first completion information, the server can generate a second session key based on the fourth, fifth, and sixth random numbers and the encryption method determined in the first request-response information. Subsequently, the server can use the second session key to encrypt information sent to the first ECU, or the server can use the first session key to decrypt information from the first ECU.
[0154] It should be noted that when the upgrade information of multiple devices includes the upgrade information of a group of first ECUs, each first ECU can establish a first channel with the server based on the upgrade information of that ECU.
[0155] Step 304: The server establishes a first channel with the first ECU and sends the upgrade package of the first ECU to the first ECU through the first channel.
[0156] In some embodiments, the server and the first ECU can establish a first channel through a handshake. After the first channel is successfully established, the server and the first ECU can communicate in encrypted form.
[0157] The following example illustrates the process of establishing a first channel between the server and the first ECU through four communications.
[0158] Optionally, the server and the first ECU establish a first channel, including: the server receiving first request information from the first ECU, wherein the first request information is used to request the establishment of a first channel with the server; the server sending first request response information to the first ECU based on the first request information, wherein the first request response information is used to determine the encryption method between the server and the first ECU; the server receiving first completion information from the first ECU, wherein the first completion information is used to indicate that the first channel between the server and the first ECU has been established; and the server sending first completion response information to the first ECU based on the first completion information, wherein the first completion response information is used to indicate that the first channel between the server and the first ECU has been established.
[0159] It should be noted that when the upgrade information of multiple devices includes the upgrade information of a group of first ECUs, the server can establish a first channel with each first ECU and send the upgrade package of that ECU to the ECU corresponding to that first channel through the first channel.
[0160] Optionally, the server sends an upgrade package for the first ECU to the first ECU through the first channel, including: the server signing the upgrade package for the first ECU to obtain a signed upgrade package for the first ECU; the server encrypting the signed upgrade package for the first ECU to obtain an encrypted upgrade package for the first ECU; and the server sending the encrypted upgrade package for the first ECU to the first ECU through the first channel.
[0161] For example, taking the server signing the upgrade package of the first ECU using the first digest function as an example, the server signs the upgrade package of the first ECU according to the first digest function to obtain the signed upgrade package of the first ECU; the server encrypts the signed upgrade package of the first ECU using the second session key to obtain the encrypted upgrade package of the first ECU; the server sends the encrypted upgrade package of the first ECU to the first ECU through the first channel.
[0162] Step 305: The first ECU receives the upgrade package from the server through the first channel and performs the upgrade according to the upgrade package.
[0163] Optionally, the first ECU performs an upgrade based on the upgrade package of the first ECU, including: after the first ECU successfully verifies the signature of the upgrade package of the first ECU, the first ECU performs an upgrade based on the upgrade package of the first ECU.
[0164] For example, taking the server signing the upgrade package of the first ECU using the first digest function as an example, the first ECU uses the second session key to decrypt the upgrade package of the first ECU to obtain the decrypted upgrade package of the first ECU; the first ECU verifies the decrypted upgrade package of the first ECU according to the first digest function, and after successful verification, performs the upgrade according to the upgrade package of the first ECU.
[0165] Optionally, the first ECU may be upgraded according to the upgrade package of the first ECU, including: the first ECU installing the upgrade package of the first ECU.
[0166] based on Figure 3The method shown allows the server to send upgrade information for multiple devices to the T-Box / gateway. The T-Box / gateway receives this upgrade information from the server and, based on the upgrade information of the first ECU, sends its own upgrade information to the first ECU. The first ECU receives this upgrade information from the T-Box / gateway and establishes a first channel with the server. The server can then send the upgrade package to the first ECU through this first channel. The first ECU receives the upgrade package from the server and performs the upgrade accordingly. This eliminates the need to download the upgrade package from the first ECU via the T-Box / gateway, improving upgrade efficiency and download speed while reducing the load and storage requirements of the T-Box / gateway.
[0167] It should be noted that the upgrade information of multiple devices may also include the upgrade information of the second ECU, and / or the upgrade information of the gateway, and / or the upgrade information of the T-Box. The T-Box / gateway can send the upgrade information of the corresponding device to the upgrade information of the multiple devices. After receiving the upgrade information of the device, the device can perform the upgrade according to the upgrade information of the device.
[0168] The following example illustrates the upgrade method provided in this application embodiment, using upgrade information from multiple devices, including upgrade information from the second ECU. When the upgrade information from multiple devices includes upgrade information from the gateway and / or upgrade information from the T-Box, please refer to the following... Figure 4 The method shown will not be elaborated further.
[0169] Optionally, the upgrade information for multiple devices may further include upgrade information for the second ECU. The T-Box / gateway can send upgrade information from the second ECU to the second ECU, and the second ECU receives the upgrade information from the second ECU and performs the upgrade accordingly. For example, such as... Figure 4 As shown, Figure 3 The method shown also includes steps 401 and 402.
[0170] Step 401: The T-Box / gateway sends the upgrade information of the second ECU to the second ECU.
[0171] The second ECU can be Figure 1B Any of ECUs 103-107. The second ECU is different from the first ECU.
[0172] The upgrade information for the second ECU may include an upgrade package for the second ECU.
[0173] Optionally, the second ECU is an ECU with a smaller upgrade package and / or less frequent upgrades.
[0174] Step 402: The second ECU receives upgrade information from the second ECU of the T-Box / gateway and performs the upgrade according to the upgrade information of the second ECU.
[0175] Optionally, the second ECU may be upgraded based on its upgrade information, including: the second ECU may install its upgrade package.
[0176] It should be noted that the execution order of steps 401-402 and steps 302-305 is not limited in this application embodiment. For example, steps 401-402 can be executed first, followed by steps 302-305; steps 302-305 can be executed first, followed by steps 401-402; or steps 302-305 and steps 401-402 can be executed simultaneously.
[0177] based on Figure 4 The method shown allows the T-Box / gateway to send upgrade information for the second ECU to the upgrade information of the second ECU when the upgrade information for multiple devices also includes the upgrade information for the second ECU. The second ECU receives the upgrade information from the T-Box / gateway and performs the upgrade according to the upgrade information. In this way, the T-Box / gateway can also assist the second ECU in upgrading.
[0178] The following describes the upgrade method provided in this application embodiment, taking the T-Box's ability to coordinate upgrades of the vehicle's internal devices as an example, where the upgrade information of multiple devices includes the upgrade information of the first ECU and the upgrade information of the second ECU.
[0179] like Figure 5 As shown, this application provides an upgrade method, which includes steps 501-508.
[0180] Step 501: The server sends upgrade information for multiple devices to the T-Box.
[0181] The server can be Figure 1A Server 20 in the middle, the T-Box can be the T-Box in the vehicle, for example, the vehicle can be Figure 1A In vehicle 10, the T-Box can be Figure 1B The T-Box 101 in the series.
[0182] It should be noted that the server in this application embodiment can be replaced by the cloud, which can be... Figure 1A Cloud 30.
[0183] The upgrade information for multiple devices may include upgrade information for the first ECU and the second ECU. A description of the first ECU and its upgrade information can be found in [reference needed]. Figure 3 The description of the first ECU and its upgrade information in the method shown will not be repeated here. For a description of the second ECU and its upgrade information, please refer to [reference needed]. Figure 4 The description of the second ECU and its upgrade information in the method shown will not be repeated here.
[0184] Optionally, before step 501, the server and T-Box establish a second channel. The description of establishing a second channel between the server and T-Box can be found in the section on establishing a second channel between the server and T-Box / gateway in step 301 above, and will not be repeated here.
[0185] Optionally, if the server detects that the first ECU and the second ECU need to be upgraded, the server sends upgrade information for multiple devices to the T-Box.
[0186] For example, with Figure 1A and Figure 1B As shown in the example, server 20 receives instruction information from the OEM system, which instructs server 20 to notify the first ECU and the second ECU to perform an upgrade. Server 20 sends upgrade information for multiple devices to T-Box 101.
[0187] Optionally, the server sends upgrade information for multiple devices to the T-Box, including: the server signing the upgrade information for the multiple devices to obtain signed upgrade information for the multiple devices; the server encrypting the signed upgrade information for the multiple devices to obtain encrypted upgrade information for the multiple devices; and the server sending the encrypted upgrade information for the multiple devices to the T-Box.
[0188] The server signing the upgrade information for the multiple devices can include: the server signing the upgrade information for the multiple devices in one layer, or the server signing the upgrade information for the multiple devices in two layers.
[0189] Optionally, the server performs a layer of signing on the upgrade information of the multiple devices, including: the server signing the upgrade information of the multiple devices.
[0190] For example, taking the server performing a layer-by-layer signature on the upgrade information of multiple devices as an example, the server signs the upgrade information of the first ECU and the upgrade information of the second ECU according to the first digest function (e.g., hash function) to obtain the signed upgrade information of the first ECU and the upgrade information of the second ECU. The server uses the first session key to encrypt the signed upgrade information of the first ECU and the upgrade information of the second ECU to obtain the encrypted upgrade information of the first ECU and the upgrade information of the second ECU. The server sends the encrypted upgrade information of the first ECU and the upgrade information of the second ECU to the T-Box.
[0191] Optionally, the server performs a two-layer signature on the upgrade information of the multiple devices, including: the server signs the upgrade information of each device in the upgrade information of the multiple devices to obtain the signed upgrade information of the multiple devices; the server signs the signed upgrade information of the multiple devices.
[0192] For example, taking the server performing two-layer signature on upgrade information for multiple devices as an example, the server signs the upgrade information of the first ECU according to the second digest function to obtain the first signature information; the server signs the upgrade information of the second ECU according to the third digest function to obtain the second signature information; the server signs the first and second signature information according to the first digest function to obtain the third signature information; the server encrypts the third signature information using the first session key to obtain the encrypted third signature information; the server sends the encrypted third signature information to the T-Box. The first, second, and third digest functions can be the same or different.
[0193] Step 502: The T-Box receives upgrade information from multiple devices on the server.
[0194] Optionally, before the T-Box receives upgrade information from multiple devices on the server, the T-Box and the server establish a second channel. A description of establishing this second channel between the T-Box and the server can be found in step 302 above, which describes the process of establishing a second channel between the T-Box / gateway and the server; it will not be repeated here.
[0195] Optionally, after receiving upgrade information from multiple devices from the server, the T-Box can verify the upgrade information of the multiple devices. If the verification is successful, the T-Box sends the corresponding upgrade information to each of the multiple devices. If the verification fails, the T-Box sends a verification failure message to the server, which is used to indicate that the T-Box has failed the verification.
[0196] For example, taking the server performing a layer-by-layer signature on the upgrade information of multiple devices as an example, the T-Box decrypts the upgrade information of the first ECU and the upgrade information of the second ECU to obtain the decrypted upgrade information of the first ECU and the decrypted upgrade information of the second ECU; the T-Box verifies the decrypted upgrade information of the first ECU and the decrypted upgrade information of the second ECU according to the first digest function, and after successful verification, sends the decrypted upgrade information of the first ECU to the first ECU and the decrypted upgrade information of the second ECU to the second ECU.
[0197] For example, taking the server performing a two-layer signature on the upgrade information of multiple devices as an example, the T-Box decrypts the upgrade information of the first ECU and the second ECU to obtain the decrypted upgrade information of the first ECU and the decrypted upgrade information of the second ECU; the T-Box verifies the decrypted upgrade information of the first ECU and the decrypted upgrade information of the second ECU according to the first digest function, and after successful verification, sends the decrypted upgrade information of the first ECU to the first ECU; the T-Box verifies the decrypted upgrade information of the second ECU according to the third digest function, and if the decrypted upgrade information of the second ECU is successfully verified, it sends the decrypted upgrade information of the second ECU to the second ECU.
[0198] Step 503: The T-Box sends the upgrade information of the first ECU to the first ECU based on the upgrade information of the first ECU.
[0199] Optionally, the T-Box sends the upgrade information of the first ECU to the first ECU based on the upgrade information of the first ECU, including the T-Box forwarding (transparently transmitting) the upgrade information of the first ECU to the first ECU via the gateway based on the upgrade information of the first ECU.
[0200] The gateway can be Figure 1B Gateway 102 in the middle.
[0201] Step 504: The first ECU receives the upgrade information from the first ECU in the T-Box and establishes a first channel with the server based on the upgrade information of the first ECU.
[0202] Optionally, the first ECU receives upgrade information from the first ECU of the T-Box, including receiving upgrade information from the first ECU of the T-Box via a gateway.
[0203] For details on how the first ECU establishes the first channel with the server based on the upgrade information of the first ECU, please refer to the description in step 303 above, which will not be repeated here.
[0204] Step 505: The server establishes a first channel with the first ECU and sends the upgrade package of the first ECU to the first ECU through the first channel.
[0205] Step 506: The first ECU receives the upgrade package from the server through the first channel and performs the upgrade according to the upgrade package.
[0206] For a detailed description of steps 505-506, please refer to the descriptions in steps 304-305 above, which will not be repeated here.
[0207] Step 507: The T-Box sends upgrade information for the second ECU to the second ECU.
[0208] Step 508: The second ECU receives upgrade information from the second ECU of the T-Box and performs the upgrade according to the upgrade information of the second ECU.
[0209] For a detailed description of steps 507-508, please refer to the descriptions in steps 401-402 above, which will not be repeated here.
[0210] It should be noted that the execution order of steps 503-506 and steps 507-508 is not limited in this embodiment. For example, steps 503-506 can be executed first, followed by steps 507-508; steps 507-508 can be executed first, followed by steps 503-506; or steps 503-506 and steps 507-508 can be executed simultaneously.
[0211] based on Figure 5The method shown allows the server to send upgrade information for multiple devices to the T-Box. The T-Box receives this upgrade information from the server and, based on the upgrade information of the first ECU, sends its own upgrade information to the first ECU. The first ECU receives this upgrade information from the T-Box and establishes a first channel with the server. The server can then send the first ECU's upgrade package to the first ECU through this first channel. The first ECU receives the upgrade package from the server and performs an upgrade accordingly. Similarly, the T-Box sends the second ECU's upgrade information to the second ECU, which receives this upgrade information from the T-Box and performs an upgrade. In this way, the second ECU can download its own upgrade package and perform an upgrade through the T-Box, while the first ECU can avoid downloading its own upgrade package through the T-Box. This improves upgrade efficiency and download speed, and reduces the load and storage requirements of the T-Box.
[0212] The following example illustrates the upgrade method provided in this application, using a gateway capable of coordinating upgrades of the vehicle's internal devices, with upgrade information for multiple devices including the upgrade information for the first ECU and the second ECU.
[0213] like Figure 6 As shown, this application provides an upgrade method, which includes steps 601-608.
[0214] Step 601: The server sends upgrade information for multiple devices to the gateway.
[0215] The server can be Figure 1A Server 20 in the middle, the gateway can be the gateway in the vehicle, for example, the vehicle can be Figure 1A Vehicle 10 in the middle, the gateway can be Figure 1B Gateway 102 in the middle.
[0216] It should be noted that the server in this application embodiment can be replaced by the cloud, which can be... Figure 1A Cloud 30.
[0217] The upgrade information for multiple devices may include upgrade information for the first ECU and the second ECU. A description of the first ECU and its upgrade information can be found in [reference needed]. Figure 3 The description of the first ECU and its upgrade information in the method shown will not be repeated here. For a description of the second ECU and its upgrade information, please refer to [reference needed]. Figure 4 The description of the second ECU and its upgrade information in the method shown will not be repeated here.
[0218] Optionally, the server sends upgrade information for multiple devices to the gateway, including: the server sending upgrade information for multiple devices to the T-Box, the T-Box receiving the upgrade information for multiple devices from the server, and forwarding (transparently transmitting) the upgrade information for multiple devices to the gateway.
[0219] Optionally, before the server sends upgrade information for multiple devices to the T-Box, the server and the T-Box establish a second channel. A description of establishing this second channel between the server and the T-Box can be found in step 301 above, and will not be repeated here.
[0220] Optionally, before the T-Box receives upgrade information from multiple devices on the server, the T-Box and the server establish a second channel. A description of establishing this second channel between the T-Box and the server can be found in step 302 above, which describes the process of establishing a second channel between the T-Box / gateway and the server; it will not be repeated here.
[0221] Optionally, if the server detects that the first ECU and the second ECU need to be upgraded, the server sends upgrade information for multiple devices to the gateway.
[0222] For example, with Figure 1A and Figure 1B As shown in the example, server 20 receives instruction information from the OEM system, which instructs server 20 to notify the first ECU and the second ECU to perform an upgrade. Server 20 sends upgrade information for multiple devices to gateway 102.
[0223] Optionally, the server sends upgrade information for multiple devices to the gateway, including: the server signing the upgrade information for the multiple devices to obtain signed upgrade information for the multiple devices; the server encrypting the signed upgrade information for the multiple devices to obtain encrypted upgrade information for the multiple devices; and the server sending the encrypted upgrade information for the multiple devices to the gateway.
[0224] The server signing the upgrade information for the multiple devices can include: the server signing the upgrade information for the multiple devices in one layer, or the server signing the upgrade information for the multiple devices in two layers.
[0225] Optionally, the server performs a layer of signing on the upgrade information for the multiple devices, including: the server signing the upgrade information for the multiple devices.
[0226] For example, taking the server performing a layer-by-layer signature on the upgrade information of multiple devices as an example, the server signs the upgrade information of the first ECU and the upgrade information of the second ECU according to the first digest function (e.g., hash function) to obtain the signed upgrade information of the first ECU and the upgrade information of the second ECU. The server uses the first session key to encrypt the signed upgrade information of the first ECU and the upgrade information of the second ECU to obtain the encrypted upgrade information of the first ECU and the upgrade information of the second ECU. The server sends the encrypted upgrade information of the first ECU and the upgrade information of the second ECU to the gateway.
[0227] Optionally, the server performs a two-layer signature on the upgrade information of the multiple devices, including: the server signs the upgrade information of each device in the upgrade information of the multiple devices to obtain the signed upgrade information of the multiple devices; the server signs the signed upgrade information of the multiple devices.
[0228] For example, taking the server performing a two-layer signature on upgrade information for multiple devices as an example, the server signs the upgrade information of the first ECU according to the second digest function to obtain the first signature information; the server signs the upgrade information of the second ECU according to the third digest function to obtain the second signature information; the server signs the first signature information and the second signature information according to the first digest function to obtain the third signature information; the server encrypts the third signature information using the first session key to obtain the encrypted third signature information; the server sends the encrypted third signature information to the gateway. The first digest function, second digest function, and third digest function can be the same or different.
[0229] Step 602: The gateway receives upgrade information from multiple devices on the server.
[0230] Optionally, the gateway receives upgrade information from multiple devices on the server, including: the gateway receives upgrade information from multiple devices on the T-Box.
[0231] Optionally, after receiving upgrade information from multiple devices from the server, the gateway can verify the upgrade information of the multiple devices. If the verification is successful, the gateway sends the corresponding upgrade information to each of the multiple devices; if the verification fails, the gateway sends a verification failure message to the server, which is used to indicate that the gateway failed to verify.
[0232] For example, taking the server performing a layer-by-layer signature on the upgrade information of multiple devices as an example, the gateway decrypts the upgrade information of the first ECU and the upgrade information of the second ECU to obtain the decrypted upgrade information of the first ECU and the decrypted upgrade information of the second ECU; the gateway verifies the decrypted upgrade information of the first ECU and the decrypted upgrade information of the second ECU according to the first digest function, and after successful verification, sends the decrypted upgrade information of the first ECU to the first ECU and the decrypted upgrade information of the second ECU to the second ECU.
[0233] For example, taking the server performing a two-layer signature on the upgrade information of multiple devices as an example, the gateway decrypts the upgrade information of the first ECU and the upgrade information of the second ECU to obtain the decrypted upgrade information of the first ECU and the decrypted upgrade information of the second ECU; the gateway verifies the decrypted upgrade information of the first ECU and the decrypted upgrade information of the second ECU according to the first digest function, and after successful verification, sends the decrypted upgrade information of the first ECU to the first ECU; the gateway verifies the decrypted upgrade information of the second ECU according to the third digest function, and if the decrypted upgrade information of the second ECU is successfully verified, it sends the decrypted upgrade information of the second ECU to the second ECU.
[0234] Step 603: The gateway sends the upgrade information of the first ECU to the first ECU based on the upgrade information of the first ECU.
[0235] Step 604: The first ECU receives upgrade information from the gateway and establishes a first channel with the server based on the upgrade information.
[0236] For a detailed description of step 604, please refer to the description in step 303 above, which will not be repeated here.
[0237] Step 605: The server establishes a first channel with the first ECU and sends the upgrade package of the first ECU to the first ECU through the first channel.
[0238] Step 606: The first ECU receives the upgrade package from the server through the first channel and performs the upgrade according to the upgrade package.
[0239] For a detailed description of steps 605-606, please refer to the descriptions in steps 304-305 above, which will not be repeated here.
[0240] Step 607: The gateway sends the upgrade information of the second ECU to the second ECU.
[0241] Step 608: The second ECU receives upgrade information from the second ECU of the gateway and performs the upgrade according to the upgrade information of the second ECU.
[0242] For a detailed description of steps 607-608, please refer to the descriptions in steps 401-402 above, which will not be repeated here.
[0243] It should be noted that the execution order of steps 603-606 and steps 607-608 is not limited in this embodiment. For example, steps 603-606 can be executed first, followed by steps 607-608; steps 607-608 can be executed first, followed by steps 603-606; or steps 603-606 and steps 607-608 can be executed simultaneously.
[0244] based on Figure 6 The method shown allows the server to send upgrade information for multiple devices to the gateway. The gateway receives this upgrade information from the server and, based on the upgrade information of the first ECU, sends its own upgrade information to the first ECU. The first ECU receives this upgrade information from the gateway and establishes a first channel with the server. The server can then send the first ECU's upgrade package to the first ECU through this first channel. The first ECU receives the upgrade package from the server and performs an upgrade accordingly. Similarly, the gateway sends upgrade information to the second ECU based on the upgrade information of the second ECU. The second ECU receives this upgrade information from the gateway and performs an upgrade accordingly. Thus, the second ECU can download its own upgrade package through the gateway and perform the upgrade, while the first ECU can avoid downloading its own upgrade package through the gateway. This improves upgrade efficiency and download speed, and reduces the gateway's load and storage requirements.
[0245] The foregoing mainly describes the solutions provided in the embodiments of this application from the perspective of interaction between various devices. It is understood that the aforementioned servers, cloud, T-Box, gateways, or first ECUs, etc., include corresponding hardware structures and / or software modules for executing each function in order to achieve the above-mentioned functions. Those skilled in the art should readily recognize that, in conjunction with the unit and algorithm operations of the various examples described in the embodiments disclosed herein, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed by hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0246] This application embodiment can divide the server, cloud, T-Box, gateway, or first ECU into functional modules according to the above method examples. For example, each function can be divided into its own functional module, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. It should be noted that the module division in this application embodiment is illustrative and only represents one logical functional division; other division methods may be used in actual implementation.
[0247] For example, when dividing the functional modules using an integrated approach. Figure 7 A schematic diagram of a communication device 70 is shown. This communication device 70 can be a chip or system-on-a-chip in a first ECU, or other combined devices or components capable of realizing the functions of the first ECU described above. This communication device 70 can be used to implement the functions of the first ECU involved in the above embodiments.
[0248] As one possible implementation method, Figure 7 The communication device 70 shown includes a receiving module 701 and a processing module 702.
[0249] The receiving module 701 is used to receive upgrade information from the communication device 70 from the car box or gateway.
[0250] The processing module 702 is used to establish a first channel with the server based on the upgrade information of the communication device 70.
[0251] The receiving module 701 is also used to receive an upgrade package from the communication device 70 from the server through the first channel.
[0252] The processing module 702 is also used to perform upgrades according to the upgrade package of the communication device 70.
[0253] Optionally, the first channel is a transport layer secure channel.
[0254] Optionally, the processing module 702 is specifically configured to send a first request message to the server, wherein the first request message is used to request the establishment of the first channel with the server; the processing module 702 is also specifically configured to receive a first request response message from the server, wherein the first request response message is used to determine the encryption method between the server and the first ECU; the processing module 702 is also specifically configured to send a first completion message to the server, wherein the first completion message is used to indicate that the first channel between the communication device 70 and the server has been established; the processing module 702 is also specifically configured to receive a first completion response message from the server, wherein the first completion response message is used to indicate that the first channel between the communication device 70 and the server has been established.
[0255] Optionally, the upgrade information for the communication device 70 includes the download address of the upgrade package for the communication device 70.
[0256] Optionally, the upgrade information of the communication device 70 includes instruction information for indicating an upgrade of the communication device 70.
[0257] Optionally, the processing module 702 is specifically used to perform an upgrade based on the upgrade package of the first ECU after verifying the successful signature of the upgrade package of the first ECU.
[0258] All relevant content of each operation involved in the above method embodiments can be referenced from the functional description of the corresponding functional module, and will not be repeated here.
[0259] In this embodiment, the communication device 70 is presented in an integrated manner, divided into various functional modules. Here, "module" can refer to a specific ASIC, circuitry, a processor and memory executing one or more software or firmware programs, integrated logic circuitry, and / or other devices that can provide the aforementioned functions. In a simplified embodiment, those skilled in the art will recognize that the communication device 70 can employ... Figure 2 As shown in the figure.
[0260] for example, Figure 2 The processor 201 can call the computer execution instructions stored in the memory 203 to cause the communication device 70 to execute the upgrade method in the above method embodiment.
[0261] For example, Figure 7 The functions / implementation process of the receiving module 701 and the processing module 702 can be obtained through Figure 2 The processor 201 in the memory calls computer execution instructions stored in the memory 203 to implement the function. Alternatively, Figure 7 The function / implementation process of the processing module 702 can be achieved through... Figure 2 The processor 201 in the memory calls computer execution instructions stored in the memory 203 to implement this. Figure 7 The function / implementation process of the receiving module 701 can be achieved through... Figure 2 It is implemented using the communication interface 204.
[0262] Since the communication device 70 provided in this embodiment can perform the above-described upgrade method, the technical effects it can achieve can be referred to the above-described method embodiments, and will not be repeated here.
[0263] For example, when dividing the functional modules using an integrated approach. Figure 8A schematic diagram of a communication device 80 is shown. This communication device 80 can be a chip or system-on-a-chip in a T-Box / gateway, or other combined devices or components capable of implementing the aforementioned T-Box / gateway functions. This communication device 80 can be used to implement the functions of the T-Box / gateway involved in the above embodiments.
[0264] As one possible implementation method, Figure 8 The communication device 80 shown includes a receiving module 801 and a transmitting module 802.
[0265] The receiving module 801 is used to receive upgrade information from multiple devices from the server, wherein the upgrade information of the multiple devices includes upgrade information of a first electronic control unit (ECU), and the upgrade information of the first ECU is used to instruct the first ECU to establish a first channel with the server.
[0266] The sending module 802 is used to send the upgrade information of the first ECU to the first ECU according to the upgrade information of the first ECU.
[0267] Optionally, the first channel is a transport layer secure channel.
[0268] Optionally, the upgrade information for the first ECU includes the download address for the upgrade package of the first ECU.
[0269] Optionally, the upgrade information for the first ECU includes instruction information for indicating an upgrade to the first ECU.
[0270] Optionally, the upgrade information for the multiple devices may also include an upgrade package for the second ECU; the sending module 802 is further configured to send the upgrade package for the second ECU to the second ECU.
[0271] All relevant content of each operation involved in the above method embodiments can be referenced from the functional description of the corresponding functional module, and will not be repeated here.
[0272] In this embodiment, the communication device 80 is presented in an integrated manner, divided into various functional modules. Here, "module" can refer to a specific ASIC, circuitry, a processor and memory executing one or more software or firmware programs, integrated logic circuitry, and / or other devices that can provide the aforementioned functions. In a simplified embodiment, those skilled in the art will recognize that the communication device 80 can employ... Figure 2 As shown in the figure.
[0273] for example, Figure 2 The processor 201 can call the computer execution instructions stored in the memory 203 to cause the communication device 80 to execute the upgrade method in the above method embodiment.
[0274] For example, Figure 8 The functions / implementation process of the receiving module 801 and the transmitting module 802 can be obtained through Figure 2 The processor 201 in the memory calls computer execution instructions stored in the memory 203 to implement the function. Alternatively, Figure 8 The functions / implementation process of the receiving module 801 and the transmitting module 802 can be obtained through Figure 2 It is implemented using the communication interface 204.
[0275] Since the communication device 80 provided in this embodiment can execute the above-described upgrade method, the technical effects it can achieve can be referred to the above-described method embodiments, and will not be repeated here.
[0276] For example, when dividing the functional modules using an integrated approach. Figure 9 A schematic diagram of a communication device 90 is shown. This communication device 90 can be a chip or system-on-a-chip in a server, or other combined devices or components capable of implementing the aforementioned server functions. This communication device 90 can be used to implement the server functions involved in the above embodiments.
[0277] As one possible implementation method, Figure 9 The communication device 90 shown includes a transmitting module 901 and a processing module 902.
[0278] The sending module 901 is used to send upgrade information of multiple devices to the car box or gateway, wherein the upgrade information of the multiple devices includes upgrade information of the first electronic control unit (ECU).
[0279] The processing module 902 is used to establish a first channel with the first ECU based on the upgrade information of the first ECU.
[0280] The sending module 901 is also used to send the upgrade package of the first ECU to the first ECU through the first channel.
[0281] Optionally, the first channel is a transport layer secure channel.
[0282] Optionally, the processing module 902 is specifically configured to receive a first request message from the first ECU, wherein the first request message is used to request the establishment of the first channel with the communication device 90; the processing module 902 is further configured to send a first request response message to the first ECU according to the first request message, wherein the first request response message is used to determine the encryption method between the communication device 90 and the first ECU; the processing module 902 is further configured to receive a first completion message from the first ECU, wherein the first completion message is used to indicate that the first channel between the first ECU and the communication device 90 has been established; the processing module 902 is further configured to send a first completion response message to the first ECU according to the first completion message, wherein the first completion response message is used to indicate that the first channel between the first ECU and the communication device 90 has been established.
[0283] Optionally, the upgrade information for the first ECU includes the download address for the upgrade package of the first ECU.
[0284] Optionally, the upgrade information for the first ECU includes instruction information for indicating an upgrade to the first ECU.
[0285] Optionally, the processing module 902 is also used to sign the upgrade package for the first ECU.
[0286] Optionally, the upgrade information for these multiple devices may also include an upgrade package for the second ECU.
[0287] All relevant content of each operation involved in the above method embodiments can be referenced from the functional description of the corresponding functional module, and will not be repeated here.
[0288] In this embodiment, the communication device 90 is presented in an integrated manner, divided into various functional modules. Here, "module" can refer to a specific ASIC, circuitry, a processor and memory executing one or more software or firmware programs, integrated logic circuitry, and / or other devices that can provide the aforementioned functions. In a simplified embodiment, those skilled in the art will recognize that the communication device 90 can employ... Figure 2 As shown in the figure.
[0289] for example, Figure 2 The processor 201 can call the computer execution instructions stored in the memory 203 to cause the communication device 90 to execute the upgrade method in the above method embodiment.
[0290] For example, Figure 9 The functions / implementation process of the sending module 901 and the processing module 902 can be obtained through Figure 2The processor 201 in the memory calls computer execution instructions stored in the memory 203 to implement the function. Alternatively, Figure 9 The function / implementation process of the processing module 902 can be achieved through... Figure 2 The processor 201 in the memory calls computer execution instructions stored in the memory 203 to implement this. Figure 9 The function / implementation process of the sending module 901 can be obtained through Figure 2 It is implemented using the communication interface 204.
[0291] Since the communication device 90 provided in this embodiment can execute the above-described upgrade method, the technical effects it can achieve can be referred to the above-described method embodiments, and will not be repeated here.
[0292] Figure 10 A schematic diagram of the composition of an upgrade system is shown, such as Figure 10 As shown, the upgrade system 100 may include: a server / cloud 1001, a T-Box / gateway 1002, and an ECU 1003. It should be noted that... Figure 10 The accompanying drawings are merely illustrative and are not intended to limit the scope of the embodiments described in this application. Figure 10 The upgrade system 100 shown includes the devices and the number of devices.
[0293] Among them, server / cloud 1001 has the above-mentioned features. Figure 9 The communication device 90 shown can send upgrade information for multiple devices to the T-Box / gateway 1002, establish a first channel with the ECU 1003 based on the upgrade information of the ECU 1003, and send the upgrade package of the ECU 1003 to the ECU 1003 through the first channel.
[0294] T-Box / Gateway 1002 has the above-mentioned features Figure 8 The communication device 80 shown can receive upgrade information from multiple devices on the server / cloud 1001, and send the upgrade information of the ECU 1003 to the ECU 1003 according to the upgrade information of the ECU 1003.
[0295] ECU 1003 has the above-mentioned features Figure 7 The communication device 70 shown can receive upgrade information from ECU 1003 from T-Box / Gateway 1002, establish a first channel with server / cloud 1001 based on the upgrade information of ECU 1003, receive upgrade packages from ECU 1003 from server / cloud 1001 through the first channel, and perform upgrades based on the upgrade packages of ECU 1003.
[0296] It should be noted that all relevant content of each step involved in the above method embodiments can be referenced from the functional description of the corresponding network element of the upgrade system 100, and will not be repeated here.
[0297] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented using software programs, implementation can be, in whole or in part, in the form of a computer program product. This computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the flow or function according to the embodiments of this application is generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions can be transmitted from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device containing one or more servers, data centers, etc., that can be integrated with the medium. The available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid-state disks, SSDs).
[0298] Although this application has been described herein in conjunction with various embodiments, those skilled in the art, by reviewing the accompanying drawings, disclosure, and appended claims, will understand and implement other variations of the disclosed embodiments in carrying out the claimed application. In the claims, the word "comprising" does not exclude other components or operations, and "a" or "an" does not exclude multiple components. A single processor or other unit can implement several functions listed in the claims. While different dependent claims may recite certain measures, this does not mean that these measures cannot be combined to produce good results.
[0299] Although this application has been described in conjunction with specific features and embodiments, it is obvious that various modifications and combinations can be made thereto without departing from the spirit and scope of this application. Accordingly, this specification and drawings are merely exemplary illustrations of this application as defined by the appended claims, and are considered to cover any and all modifications, variations, combinations, or equivalents within the scope of this application. Clearly, those skilled in the art can make various alterations and modifications to this application without departing from the spirit and scope of this application. Thus, if such modifications and modifications of this application fall within the scope of the claims of this application and their equivalents, this application is also intended to include such modifications and modifications.
Claims
1. An upgrade method, characterized in that, The method is applied to a first electronic control unit (ECU), and the method includes: The first ECU receives upgrade information from the car box or gateway; the upgrade information of the first ECU includes the address of the server; The first ECU establishes a first channel with the server based on the server's address. The first channel is a transport layer secure channel and is used for encrypted communication between the first ECU and the server. The first ECU receives the upgrade package sent by the server through the first channel; The first ECU is upgraded according to the upgrade package for the first ECU.
2. The method according to claim 1, characterized in that, Based on the upgrade information of the first ECU, a first channel is established with the server, including: Send a first request message to the server, wherein the first request message is used to request the establishment of the first channel with the server; Receive a first request response information from the server, wherein the first request response information is used to determine the encryption method between the server and the first ECU; Send a first completion message to the server, wherein the first completion message is used to indicate that the first channel between the first ECU and the server has been established; Receive a first completion response message from the server, wherein the first completion response message is used to indicate that the first channel between the first ECU and the server has been established.
3. The method according to any one of claims 1-2, characterized in that, The upgrade information for the first ECU includes the download address for the upgrade package of the first ECU.
4. The method according to any one of claims 1-2, characterized in that, The upgrade information for the first ECU includes instruction information, which is used to indicate that the first ECU should be upgraded.
5. The method according to any one of claims 1-4, characterized in that, The upgrade based on the upgrade package of the first ECU includes: After verifying the successful signature of the upgrade package for the first ECU, the upgrade is performed based on the upgrade package for the first ECU.
6. An upgrade method, characterized in that, The method is applied to a car box or gateway, and the method includes: The car box or gateway receives upgrade information from multiple devices from the server. The upgrade information of the multiple devices includes upgrade information of a first electronic control unit (ECU). The upgrade information of the first ECU includes the address of the server. The address of the server is used to instruct the first ECU to establish a first channel with the server. The first channel is a transport layer secure channel and is used for encrypted communication between the first ECU and the server. The car box or gateway sends the upgrade information of the first ECU to the first ECU based on the upgrade information of the first ECU.
7. The method according to claim 6, characterized in that, The upgrade information for the first ECU also includes the download address for the upgrade package of the first ECU.
8. The method according to claim 6, characterized in that, The upgrade information for the first ECU includes instruction information, which is used to indicate that the first ECU should be upgraded.
9. The method according to any one of claims 6-8, characterized in that, The upgrade information for the multiple devices also includes an upgrade package for the second ECU; the method further includes: Send the upgrade package for the second ECU to the second ECU.
10. An upgrade method, characterized in that, The method is applied to a server, and the method includes: The server sends upgrade information for multiple devices to the car box or gateway, wherein the upgrade information for the multiple devices includes upgrade information for the first electronic control unit (ECU); the upgrade information for the first ECU includes the address of the server. The server establishes a first channel with the first ECU based on the server's address. The first channel is a transport layer secure channel and is used for encrypted communication between the first ECU and the server. The server sends the upgrade package of the first ECU to the first ECU through the first channel.
11. The method according to claim 10, characterized in that, Establish a first channel with the first ECU based on the upgrade information of the first ECU, including: Receive a first request message from the first ECU, wherein the first request message is used to request the establishment of the first channel with the server; A first request response message is sent to the first ECU according to the first request message, wherein the first request response message is used to determine the encryption method between the server and the first ECU; Receive first completion information from the first ECU, wherein the first completion information is used to indicate that the first channel between the first ECU and the server has been established; A first completion response is sent to the first ECU based on the first completion information, wherein the first completion response is used to indicate that the first channel between the first ECU and the server has been established.
12. The method according to any one of claims 10-11, characterized in that, The upgrade information for the first ECU includes the download address for the upgrade package of the first ECU.
13. The method according to any one of claims 10-11, characterized in that, The upgrade information for the first ECU includes instruction information, which is used to indicate that the first ECU should be upgraded.
14. The method according to any one of claims 10-13, characterized in that, The method further includes: Sign the upgrade package for the first ECU.
15. The method according to any one of claims 10-14, characterized in that, The upgrade information for the multiple devices also includes an upgrade package for the second ECU.
16. A communication device, characterized in that, The communication device includes: a receiving module and a processing module; The receiving module is used to receive upgrade information from the communication device via the car box or gateway; the upgrade information of the first ECU includes the address of the server; The processing module is used to establish a first channel with the server based on the server's address. The first channel is a transport layer secure channel, and the first channel is used for encrypted communication between the first ECU and the server. The receiving module is further configured to receive an upgrade package for the communication device sent by the server through the first channel; The processing module is also used to perform upgrades according to the upgrade package of the communication device.
17. The communication device according to claim 16, characterized in that, The processing module is specifically used to send a first request message to the server, wherein the first request message is used to request the establishment of the first channel with the server; The processing module is further specifically configured to receive a first request response information from the server, wherein the first request response information is used to determine the encryption method between the server and the first ECU; The processing module is further specifically configured to send a first completion message to the server, wherein the first completion message is used to indicate that the first channel between the communication device and the server has been established. The processing module is further configured to receive a first completion response information from the server, wherein the first completion response information is used to indicate that the first channel between the communication device and the server has been established.
18. The communication device according to any one of claims 16-17, characterized in that, The upgrade information of the communication device includes the download address of the upgrade package for the communication device.
19. The communication device according to any one of claims 16-17, characterized in that, The upgrade information for the communication device includes instruction information, which is used to indicate the need to upgrade the communication device.
20. The communication device according to any one of claims 16-19, characterized in that, The processing module is specifically used to perform an upgrade based on the upgrade package of the first ECU after verifying that the signature of the upgrade package of the first ECU has been successfully verified.
21. A communication device, characterized in that, The communication device includes: a receiving module and a transmitting module; The receiving module is used to receive upgrade information from multiple devices from the server. The upgrade information of the multiple devices includes upgrade information of a first electronic control unit (ECU). The upgrade information of the first ECU includes the address of the server. The address of the server is used to instruct the first ECU to establish a first channel with the server. The first channel is a transport layer secure channel and is used for encrypted communication between the first ECU and the server. The sending module is used to send the upgrade information of the first ECU to the first ECU according to the upgrade information of the first ECU.
22. The communication device according to claim 21, characterized in that, The upgrade information for the first ECU includes the download address for the upgrade package of the first ECU.
23. The communication device according to claim 21, characterized in that, The upgrade information for the first ECU includes instruction information, which is used to indicate that the first ECU should be upgraded.
24. The communication device according to any one of claims 21-23, characterized in that, The upgrade information for the multiple devices also includes an upgrade package for the second ECU; The sending module is also used to send the upgrade package of the second ECU to the second ECU.
25. A communication device, characterized in that, The communication device includes: a transmitting module and a processing module; The sending module is used to send upgrade information of multiple devices to the car box or gateway, wherein the upgrade information of the multiple devices includes upgrade information of the first electronic control unit (ECU); the upgrade information of the first ECU includes the address of the server. The processing module is used to establish a first channel with the first ECU based on the address of the server. The first channel is a transport layer secure channel and is used for encrypted communication between the first ECU and the server. The sending module is also used to send the upgrade package of the first ECU to the first ECU through the first channel.
26. The communication device according to claim 25, characterized in that, The processing module is specifically configured to receive a first request message from the first ECU, wherein the first request message is used to request the establishment of the first channel with the communication device; The processing module is further configured to send a first request response information to the first ECU based on the first request information, wherein the first request response information is used to determine the encryption method between the communication device and the first ECU; The processing module is further specifically configured to receive first completion information from the first ECU, wherein the first completion information is used to indicate that the first channel between the first ECU and the communication device has been established. The processing module is further configured to send a first completion response to the first ECU based on the first completion information, wherein the first completion response is used to indicate that the first channel between the first ECU and the communication device has been established.
27. The communication device according to any one of claims 25-26, characterized in that, The upgrade information for the first ECU includes the download address for the upgrade package of the first ECU.
28. The communication device according to any one of claims 25-26, characterized in that, The upgrade information for the first ECU includes instruction information, which is used to indicate that the first ECU should be upgraded.
29. The communication device according to any one of claims 25-28, characterized in that, The processing module is also used to sign the upgrade package for the first ECU.
30. The communication device according to any one of claims 25-29, characterized in that, The upgrade information for the multiple devices also includes an upgrade package for the second ECU.
31. A communication device, characterized in that, The communication device includes: At least one processor and memory; The memory stores program instructions that are executed in the at least one processor to perform the function of the first ECU as described in any one of claims 1-5.
32. A communication device, characterized in that, The communication device includes: At least one processor and memory; The memory stores program instructions that are executed in the at least one processor to perform the functions of the car box or gateway as described in any of the methods of claims 6-9.
33. A communication device, characterized in that, The communication device includes: At least one processor and memory; The memory stores program instructions that are executed in the at least one processor to perform the functions of the server as described in any of the methods of claims 10-15.
34. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores program instructions that, when executed, implement the function of the first ECU as described in any one of claims 1-5.
35. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores program instructions that, when executed, perform the functions of the car box or gateway described in any of the methods of claims 6-9.
36. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores program instructions that, when executed, perform the functions of the server as described in any of the methods of claims 10-15.
Citation Information
Patent Citations
Automobile electronic control unit upgrading method and system and terminal device
CN110032382A
Method and system for safely downloading upgrade package
CN110378153A