Method, apparatus, vehicle and medium for upgrading existing software in a vehicle

By verifying the new and existing functions after the vehicle software upgrade, the safety and stability of the vehicle software upgrade are ensured, solving the problem of vehicles not being able to function properly after the upgrade in the existing technology, and realizing a safe and effective software upgrade.

CN114528003BActive Publication Date: 2025-11-25AUDI AG
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202011321545.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-11-23
Publication Date
2025-11-25
Estimated Expiration
2040-11-23

AI Technical Summary

Technical Problem

During vehicle software upgrades, existing technologies struggle to effectively verify whether the upgraded software meets expectations, potentially leading to vehicle malfunctions or traffic accidents, and also raising safety and compatibility issues.

Method used

By acquiring the update package and verifying the input signals of the new and existing functions, a verification result is generated to determine whether to upgrade the vehicle software, ensuring that the new functions meet expectations and the existing functions are not affected.

Benefits of technology

This improves the safety and stability of vehicle software upgrades, avoids unexpected software upgrades, and enhances the effectiveness and compatibility of software upgrades.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114528003B_ABST
    Figure CN114528003B_ABST
Patent Text Reader

Abstract

Provided are a method, device, vehicle and medium for upgrading existing software in a vehicle. The method for upgrading existing software in a vehicle comprises: obtaining an update package, the update package being used to upgrade existing software in a vehicle and verify the effectiveness of the upgraded software on the vehicle; receiving verification input signals, the verification input signals comprising new function verification input signals and original function verification input signals; determining, based on the new function verification input signals, whether the new function of the upgraded software is consistent with the expectation to generate a new function verification result, and determining, based on the original function verification input signals, whether the original function of the upgraded software is consistent with the existing software to generate an original function verification result; and determining, according to the new function verification result and the original function verification result, whether to upgrade the existing software in the vehicle based on the update package.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of computer, in particular to a method and device for upgrading existing software in a vehicle, a vehicle and a medium. BACKGROUND

[0002] With the progress of society, cars have become a necessary means of transportation for almost every family, making people's lives more and more convenient. Moreover, with the development of various advanced technologies in the automotive field, various increasingly intelligent devices and functions are integrated into cars, which are usually controlled by corresponding ECUs (Electronic Control Units).

[0003] The emergence of OTA technology (Over The Air Technology, i.e. Over The Air Technology or Over The Air Technology) enables car users to upgrade and refresh the corresponding ECUs on the car without going to the dealer or repair shop, thus providing users with a better experience, and the cost is also lower for car manufacturers, so it has gradually become a trend for software upgrades of vehicle-mounted electronic devices.

[0004] However, after downloading new software, its performance is difficult to predict, and if the existing software of the vehicle is upgraded without evaluating the performance of the new software, it may cause the vehicle to be unable to function properly, and even may cause serious traffic accidents.

[0005] The methods described in this section are not necessarily the methods that have been previously conceived or employed. Unless otherwise indicated, it should not be assumed that any method described in this section cannot be employed, or that any method described in this section is the only method that can be employed, because of its inclusion in this section. Similarly, the reference in this section to a problem should not be construed as an indication that the problem was recognized before. SUMMARY

[0006] According to one aspect of the present disclosure, a method for upgrading existing software in a vehicle is provided, comprising: obtaining an update package, the update package being used to upgrade the existing software in the vehicle and verify the effectiveness of the upgraded software on the vehicle; receiving a verification input signal, the verification input signal including a new function verification input signal and an original function verification input signal; determining whether the new function of the upgraded software is consistent with the expectation based on the new function verification input signal to generate a new function verification result, and determining whether the original function of the upgraded software is consistent with the existing software based on the original function verification input signal to generate an original function verification result; and determining whether to upgrade the existing software in the vehicle based on the update package according to the new function verification result and the original function verification result.

[0007] According to another aspect of this disclosure, an apparatus for upgrading software in a vehicle is provided, comprising: an acquisition unit configured to acquire an update package, the update package being used to upgrade existing software in the vehicle and verify the effectiveness of the upgraded software in the vehicle; a receiving unit configured to receive verification input signals, the verification input signals including a new function verification input signal and an existing function verification input signal; a verification unit configured to determine, based on the new function verification input signal, whether the new functions of the upgraded software are consistent with expectations to generate a new function verification result, and based on the existing function verification input signal, whether the existing functions of the upgraded software are consistent with the existing software to generate an existing function verification result; and an upgrade unit configured to determine, based on the new function verification result and the existing function verification result, whether to upgrade the existing software in the vehicle based on the update package.

[0008] According to another aspect of this disclosure, an electronic device is provided, comprising: a processor, and a memory storing a program, the program including instructions that, when executed by the processor, cause the processor to perform the methods described in this disclosure.

[0009] According to another aspect of this disclosure, a vehicle is provided, comprising: the apparatus or electronic device described in this disclosure.

[0010] According to another aspect of this disclosure, a non-transitory computer-readable storage medium is provided that stores a program, the program including instructions that, when executed by one or more processors, cause the one or more processors to perform the methods described in this disclosure.

[0011] According to one or more embodiments of this disclosure, the methods, apparatus, vehicles, and media provided in this disclosure for upgrading existing software in vehicles can improve the security of vehicle software upgrades. Attached Figure Description

[0012] The accompanying drawings exemplify embodiments and form part of the specification, serving together with the textual description to explain exemplary implementations of the embodiments. The illustrated embodiments are for illustrative purposes only and do not limit the scope of the claims. Throughout the drawings, the same reference numerals refer to similar but not necessarily identical elements.

[0013] Figure 1 This is a flowchart illustrating a method 100 for upgrading existing software in a vehicle according to an exemplary embodiment;

[0014] Figure 2 This is a structural block diagram illustrating an apparatus 200 for upgrading existing software in a vehicle according to an exemplary embodiment; and

[0015] Figure 3This is a schematic diagram of an application scenario of a motor vehicle according to an exemplary embodiment of the present disclosure. Detailed Implementation

[0016] In this disclosure, unless otherwise stated, the use of terms such as "first," "second," etc., to describe various elements is not intended to limit the positional, temporal, or importance relationships of these elements; such terms are merely used to distinguish one element from another. In some examples, the first element and the second element may refer to the same instance of that element, while in other cases, based on the context, they may refer to different instances.

[0017] The terminology used in the description of the various examples described in this disclosure is for the purpose of describing particular examples only and is not intended to be limiting. Unless the context explicitly indicates otherwise, an element may be one or more unless the number of elements is specifically limited. Furthermore, the term "and / or" as used in this disclosure covers any one of the listed items and all possible combinations thereof.

[0018] During vehicle software upgrades, after testing their new software, the original equipment manufacturer (OEM) releases it to specific users (e.g., target vehicles). The new software can be downloaded to the user's vehicle via OTA (Over-The-Air).

[0019] For a large number of users, there may be differences between each user's vehicle. For example, different vehicle models may lead to differences in vehicle hardware configuration, or some users may have modified their vehicles, resulting in differences between modified vehicles and other factory-made vehicles. Alternatively, differences in usage frequency may lead to differences in vehicle age, which in turn lead to differences in hardware configuration. These factors can cause many problems when upgrading existing software via OTA technology.

[0020] Furthermore, during the process of downloading software from the cloud using specialized wireless technologies, it is also necessary to ensure the security of data transmission. Therefore, the validity of the upgraded software downloaded to the vehicle needs to be verified. Otherwise, if the upgraded software is compromised by other hackers and downloaded to the vehicle for direct upgrade without verification, it will lead to many security problems.

[0021] Figure 1 A flowchart of a method 100 for upgrading existing software in a vehicle according to an embodiment of the present disclosure is shown.

[0022] At step 101, an update package is obtained, which is used to upgrade the existing software in the vehicle and verify the effectiveness of the upgraded software in the vehicle.

[0023] For example, the update package includes an installer that can modify some system configurations to accommodate the features of the new version, such as registering COM components and modifying the registry.

[0024] For example, the HTTP protocol can be used to detect the availability of a new version of existing software. Specifically, the local version number is sent to the server, which returns a configuration file indicating whether a new version of the existing software is available, along with the download address of the new version. The updater then downloads the installer for the new version according to the URL and executes the installer. For instance, as update packages become larger, the download and installation times also increase, causing users to wait for extended periods. Therefore, a background download and update approach can be adopted.

[0025] For example, a dual-directory update approach can be used, where the new version of the existing software included in the update package is copied to another directory, and then this newly copied version of the existing software is updated in that directory. For example, the version number can be used as the directory name, and the older version of the existing software running in the other directory will not be affected. Therefore, the new version of the existing software included in the update package can be used to upgrade the existing software in the vehicle, or it can be used to verify the effectiveness of the upgraded software in the vehicle before upgrading the existing software.

[0026] At step 102, a verification input signal is received, which includes a new function verification input signal and an existing function verification input signal.

[0027] When upgrading existing software, only some functions are changed in the upgraded software. These functions generally have their own dedicated input signals and expected output signals. In order to ensure that the upgraded software can achieve the original functions, it is also necessary to provide the input signals and expected output signals of the original functions.

[0028] For example, when a new version of existing software is installed on the vehicle's ECU, input signals such as vehicle speed and acceleration are obtained from bus systems such as CAN bus or FlexRay bus.

[0029] In step 103, based on the new function verification input signal, it is determined whether the new function of the upgraded software is consistent with the expectation to generate a new function verification result. Based on the original function verification input signal, it is determined whether the original function of the upgraded software is consistent with the existing software to generate an original function verification result.

[0030] In step 104, based on the verification results of the new function and the verification results of the original function, it is determined whether to upgrade the existing software in the vehicle based on the update package.

[0031] based on Figure 1The method shown for upgrading existing software in a vehicle can verify the upgraded software, thereby improving the security of vehicle software upgrades.

[0032] According to some embodiments, in step 103, the step of determining whether the new function of the upgraded software is consistent with the expectation based on the new function verification input signal to generate a new function verification result includes: calculating the new function verification output signal corresponding to the new function verification input signal based on the update package, and comparing the new function verification output signal with the expected verification output signal to generate a new function verification result.

[0033] For example, in order to verify the changed function and thus realize the "vehicle verification" function, it is necessary to calculate the signal verification of the new function. Specifically, corresponding to the verification input signal of the new function, the verification output signal of the new function is calculated. By comparing the obtained verification output signal of the new function with the expected verification output signal, the verification result of the corresponding new function can be obtained.

[0034] Therefore, verifying whether the new features meet expectations can improve the effectiveness of the upgraded software.

[0035] According to some embodiments, in step 103, the process of generating the verification result of the new function includes: calculating a first new function verification output signal based on the first new function verification input signal in the first number of new function verification input signals; comparing the first new function verification output signal with the expected output signal corresponding to the first new function verification input signal; and when the first new function verification output signal and the expected output signal corresponding to the first new function verification input signal are consistent, it is considered that the verification is successful once.

[0036] For example, a first number of new function verification input signals are prepared, a corresponding first new function output signal is obtained based on the first new function verification input signal, and the first new function output signal is judged. If it meets the expectations, the verification is considered successful.

[0037] By setting and selecting the first number of new function input signals, the effectiveness of the upgraded software can be improved in a targeted manner.

[0038] Furthermore, according to some embodiments, in step 103, the step of determining whether the new function of the upgraded software is consistent with the expectation based on the new function verification input signal to generate a new function verification result includes: counting the number of successful verifications, and when the cumulative number of successful verifications exceeds a threshold or the number of consecutive successful verifications exceeds a threshold, the new function verification result is successful.

[0039] For example, multiple verifications are often required to ensure that new features can work effectively on vehicles. For instance, a threshold for the cumulative number of successful attempts or a threshold for the number of consecutive successful attempts can be set.

[0040] For example, the number of successful verifications can be counted. For instance, when the first number is 10,000, a cumulative success threshold of 9,995 is set, meaning a success rate exceeding 0.05% is required for the verification result of the new function to be considered successful. In other alternative embodiments, a consecutive success threshold of 2,000 is set; when this condition is met, the verification result of the new function is considered successful. The above values ​​are merely illustrative and do not constitute a limitation of this disclosure.

[0041] Setting a threshold for the cumulative number of successful verifications or a threshold for the number of consecutive successful verifications can improve the efficiency of verification.

[0042] To better understand the aforementioned scheme, the verification process of the new function will be described below using a specific function of ACC (Adaptive Cruise Control).

[0043] For example, in the software upgrade, only one function has changed. Let's take the ACC function as an example. Suppose that the existing software's ACC function can only be set when the vehicle speed is greater than 50km / h, while the upgraded software's ACC function can be set when the vehicle speed is greater than 30km / h.

[0044] After the upgrade software is installed on the ECU, the upgraded software's ACC function will also receive input signals from bus systems such as CAN bus or FlexRay bus, such as vehicle speed and acceleration.

[0045] For this "vehicle verification" function, the test condition for the ACC function will be set to a vehicle speed of more than 30 kilometers per hour. If it is on a vehicle with the upgraded software installed, when the vehicle speed is 35 kilometers per hour, there will be a "success counter" for the new function verification. This success counter will count the number of successful verifications, and each successful verification will be counted once by the counter.

[0046] For example, different success thresholds can be set for different functions because different functions have different risk levels. For functions with higher risk levels, a higher success threshold number of times needs to be set, while for functions with lower risk levels, a relatively lower success threshold number of times needs to be set. This setting can ensure the verification effect while also taking into account the verification efficiency.

[0047] For example, if the cumulative success count threshold or consecutive success count threshold for a new ACC feature is set to 100, then once the success counter value exceeds 100, it means that the upgraded software with this new feature can replace the existing software.

[0048] Continuing at step 103, according to some embodiments, the step of determining whether the original function is consistent with the existing software based on the original function verification input signal to generate the original function verification result includes: calculating the original function verification output signal of the upgraded software based on the original function verification input signal of the update package, calculating the original function verification input signal of the existing software based on the existing software to generate the original function output signal of the existing software, and comparing the original function output signal of the upgraded software and the original function output signal of the existing software to generate the original function verification result.

[0049] For example, in order to verify the unchanged function and thus realize the "vehicle verification" function, it is necessary to calculate the original function for signal verification. Specifically, corresponding to the verification input signal of the original function, the verification output signal of the original function is calculated. The obtained original function verification output signal is compared with the expected original function verification output signal to obtain the corresponding original function verification result.

[0050] Therefore, it is possible to verify the original functions to avoid introducing new security risks into the upgraded software.

[0051] Further, in step 103, the step of determining whether the original function of the upgraded software is consistent with the existing software based on the original function verification input signal to generate the original function verification result includes: calculating the first original function verification output signal based on the first original function verification input signal in the second number of original function verification input signals; comparing the first original function verification output signal of the upgraded software with the first original function output signal of the existing software; when the first original function verification output signal of the upgraded software is inconsistent with the first original function output signal of the existing software, it is considered as a verification failure.

[0052] For example, a second number of original function verification input signals are prepared, and a corresponding first original function output signal is obtained based on the first original function verification input signal. The first original function output signal is judged, and if it does not meet the expectations, the verification is deemed to have failed.

[0053] By setting and selecting the second number of original function input signals, the effectiveness of the upgraded software can be improved in a targeted manner.

[0054] Furthermore, in step 103, the step of determining whether the original function of the upgraded software is consistent with the existing software based on the original function verification input signal to generate the original function verification result includes: counting the number of verification failures, and when the cumulative number of verification failures is zero, the original function verification result is successful.

[0055] For example, if the verification result of the original function fails even once, it is considered that the upgraded software cannot perform the original function and the upgraded software cannot be used to upgrade the vehicle.

[0056] This is because upgraded software with new features needs to complete the original functions of existing software. In practical applications, it is necessary to compare the upgraded software and existing software for their original functions to ensure that their outputs are the same as the corresponding functions of the existing software.

[0057] If, during any of the upgraded software outputs a signal that is not expected, or if, during all of the "vehicle verification" processes (collecting 100 successful tests), only once does the original function produce an output that differs from the existing software, then the original function verification result is considered a failure.

[0058] For example, if it fails, in that test case, all the necessary signals in the vehicle will be collected and automatically sent back to the manufacturer's server, where engineers will debug it until they find the problem and make further modifications to the update package. The modified update package will then be redeployed to the dedicated user's vehicle for the next step of verification.

[0059] Verifying the original functions of the upgraded software can improve its effectiveness. This verification process also allows staff to further modify the update package to suit specific vehicles, thus expanding its applicability.

[0060] According to some embodiments of this disclosure, the upgraded software included in the update package can run simultaneously with the existing software in the vehicle.

[0061] For example, after the upgrade software is downloaded to the vehicle's ECU, it will not overwrite the old version of the software, and the vehicle will continue to operate as expected with the old version. Only after verification that the system finds the upgraded software to work as expected is the updated software deemed capable of replacing the old version.

[0062] Since the upgraded software and the existing software in the vehicle can run simultaneously, the verification of the new software does not affect the operation of the existing software, thus improving the compatibility of the verification process.

[0063] Furthermore, determining whether to upgrade the existing software in the vehicle based on the update package according to the verification results of the new function and the verification results of the original function includes: when both the verification results of the new function and the verification results of the original function are successful, then the existing software in the vehicle is upgraded based on the update package.

[0064] If both the verification results for the new features and the results for the existing features are successful, it indicates that the upgraded software included in the update package meets expectations and performs as expected on the vehicle. Through comprehensive verification, the stability of the upgraded software can be improved.

[0065] According to some embodiments of this disclosure, determining whether to upgrade the existing software in the vehicle based on the update package according to the verification results of the new function and the verification results of the original function includes: if either the verification result of the new function or the verification result of the original function is unsuccessful, then the existing software in the vehicle is not upgraded.

[0066] If either the verification result for the new feature or the result for the existing feature fails, it indicates that the upgraded software included in the update package is not as expected, its performance on the vehicle is not as expected, and it cannot pass the verification. This is to avoid adverse consequences caused by unsafe software upgrades.

[0067] Since the verification of the upgraded software is carried out on the vehicle, the verification results are closely linked to the objective conditions of the vehicle, such as the vehicle model and the modified hardware system. The verification results are specific to the vehicle and can fully guarantee the performance of the upgraded software on the specific vehicle, greatly improving the effectiveness and security of the upgraded software.

[0068] According to some embodiments of this disclosure, the method further includes: receiving a user instruction and upgrading the existing software in the vehicle based on the update package before upgrading the existing software in the vehicle based on the update package.

[0069] For example, before actually replacing the existing software, in order to improve the human-computer interaction experience, a message can be popped up at an appropriate time, such as when the next engine starts, displaying "There is a verified new version of software in the car, do you want to update?", and then, according to the user's instructions, they can choose to continue updating or ignore this update.

[0070] Figure 2 This is a structural block diagram illustrating an apparatus 200 for upgrading existing software in a vehicle according to an exemplary embodiment. Figure 2 As shown, an apparatus 200 for upgrading existing software in a vehicle is provided, comprising:

[0071] The acquisition unit 210 is configured to acquire an update package, which is used to upgrade existing software in the vehicle and verify the effectiveness of the upgraded software in the vehicle.

[0072] The receiving unit 220 is configured to receive verification input signals, which include new function verification input signals and existing function verification input signals;

[0073] The verification unit 230 is configured to determine whether the new function of the upgraded software is consistent with the expectation based on the new function verification input signal in order to generate a new function verification result, and to determine whether the original function of the upgraded software is consistent with the existing software based on the original function verification input signal in order to generate an original function verification result.

[0074] The upgrade unit 240 is configured to determine whether to upgrade the existing software in the vehicle based on the update package, according to the verification results of the new functions and the verification results of the original functions.

[0075] based on Figure 2 The device 200 shown is for upgrading existing software in a vehicle, which can verify the upgraded software and improve the security of vehicle software upgrades.

[0076] Furthermore, while specific functions have been discussed above with reference to specific modules, it should be noted that the functions of the modules discussed herein can be divided into multiple modules, and / or at least some functions of multiple modules can be combined into a single module. The specific actions performed by the modules discussed herein include the specific module itself performing the action, or alternatively, the specific module calling or otherwise accessing another component or module performing the action (or performing the action in conjunction with the specific module). Therefore, a specific module performing an action can include the specific module performing the action itself and / or another module that the specific module calls or otherwise accesses to perform the action.

[0077] More generally, this article can describe various technologies within the general context of software and hardware components or program modules. The above regarding... Figure 2The various modules described can be implemented in hardware or in hardware in combination with software and / or firmware. For example, these modules can be implemented as computer program code / instructions configured to execute in one or more processors and stored in a computer-readable storage medium. Alternatively, these modules can be implemented as hardware logic / circuit. For example, in some embodiments, one or more of the acquisition unit 210, receiving unit 220, verification unit 230, and upgrade unit 240 can be implemented together in a system-on-a-chip (SoC). The SoC may include an integrated circuit chip (which includes a processor (e.g., a central processing unit (CPU), microcontroller, microprocessor, digital signal processor (DSP), etc.), memory, one or more communication interfaces, and / or one or more components of other circuitry) and may optionally execute the received program code and / or include embedded firmware to perform functions.

[0078] According to one aspect of this disclosure, an electronic device is provided. The electronic device includes: a processor, and a memory storing a program, the program including instructions that, when executed by the processor, cause the processor to perform the aforementioned method for upgrading existing software in a vehicle.

[0079] According to one aspect of this disclosure, a vehicle is provided. The vehicle includes the aforementioned means or electronic devices for upgrading software within the vehicle.

[0080] According to one aspect of this disclosure, a storage medium is provided. For example, the storage medium is a non-transitory computer-readable storage medium that stores a program including instructions that, when executed by one or more processors, cause the one or more processors to perform the aforementioned method for upgrading existing software in a vehicle. Figure 3 A schematic diagram of an application scenario is shown, including a motor vehicle 2010 and a communication and control system for the motor vehicle 2010. It should be noted that... Figure 3 The structure and function of the vehicle 2010 shown are merely an example; depending on the specific implementation, the vehicle disclosed herein may include... Figure 3 The vehicle 2010 shown has one or more of the structures and functions described above. According to some embodiments, the vehicle 2010 may be as described above. Figure 1 The vehicle described is involved in upgrading existing software within the vehicle.

[0081] Motor vehicle 2010 may include sensors 2110 for sensing the surrounding environment. Sensors 2110 may include one or more of the following sensors: ultrasonic sensors, millimeter-wave radar, lidar (LiDAR), vision cameras, and infrared cameras. Different sensors can provide different detection accuracy and range. Ultrasonic sensors can be installed around the vehicle to measure the distance to objects outside the vehicle using the strong directionality of ultrasound. Millimeter-wave radar can be installed in front of, behind, or other locations on the vehicle to measure the distance to objects outside the vehicle using the characteristics of electromagnetic waves. LiDAR can be installed in front of, behind, or other locations on the vehicle to detect the edges and shape information of objects, thereby enabling object recognition and tracking. Due to the Doppler effect, radar devices can also measure changes in the speed of vehicles and moving objects. Cameras can be installed in front of, behind, or other locations on the vehicle. Vision cameras can capture the situation inside and outside the vehicle in real time and present it to the driver and / or passengers. Furthermore, by analyzing the images captured by the vision cameras, information such as traffic light signals, intersection conditions, and the operating status of other vehicles can be obtained. Infrared cameras can capture objects in night vision conditions.

[0082] The motor vehicle 2010 may also include an output device 2120. The output device 2120 may include, for example, a display and a speaker, to present various outputs or commands. Furthermore, the display may be a touchscreen, allowing input to be detected in different ways. A user graphical interface may be displayed on the touchscreen, enabling the user to access and control the corresponding controls.

[0083] The motor vehicle 2010 may also include one or more controllers 2130. Controller 2130 may include a processor, such as a central processing unit (CPU) or graphics processing unit (GPU), or other dedicated processors, that communicates with various types of computer-readable storage devices or media. Computer-readable storage devices or media may include any non-transitory storage device, which can be any storage device that is non-transitory and capable of storing data, and may include, but is not limited to, disk drives, optical storage devices, solid-state storage, floppy disks, flexible disks, hard disks, magnetic tapes or any other magnetic media, optical discs or any other optical media, read-only memory (ROM), random access memory (RAM), cache memory and / or any other memory chip or cartridge, and / or any other medium from which a computer can read data, instructions, and / or code. Some data in the computer-readable storage device or media represents executable instructions used by controller 2130 to control the vehicle. Controller 2130 may include an autonomous driving system for automatically controlling various actuators in the vehicle. The autonomous driving system is configured to control the powertrain, steering system, and braking system of a motor vehicle 2010 via multiple actuators in response to inputs from multiple sensors 2110 or other input devices, thereby controlling acceleration, steering, and braking respectively, without human intervention or with limited human intervention. Some processing functions of the controller 2130 can be implemented via cloud computing. For example, some processing can be performed using an onboard processor, while other processing can be performed using cloud computing resources. According to some embodiments, the processor can be configured to perform a combination of... Figure 1 The method described above. The processor and its associated computer-readable storage device are as described above. Figure 2 An example of device 200. A computer-readable storage device associated with a processor can be an example of the non-transitory computer-readable storage medium described above. A processor and its associated computer-readable storage device can constitute an example of an electronic device.

[0084] The motor vehicle 210 also includes a communication device 2140. The communication device 2140 includes a satellite positioning module capable of receiving satellite positioning signals from satellite 2012 and generating coordinates based on these signals. The communication device 2140 also includes a module for communicating with a mobile communication network 2013, which can implement any suitable communication technology, such as current or emerging wireless communication technologies (e.g., 5G technology) like GSM / GPRS, CDMA, and LTE. The communication device 2140 may also have a vehicle-to-everything (V2X) module, configured to enable vehicle-to-the-world communication, for example, vehicle-to-vehicle (V2V) communication with other vehicles 2011 and vehicle-to-infrastructure (V2I) communication with infrastructure. Furthermore, the communication device 2140 may also have a module configured to communicate with the user terminal 2014 (including but not limited to smartphones, tablets, or wearable devices such as watches) via, for example, a wireless local area network conforming to the IEEE 802.11 standard or Bluetooth. Using the communication device 2140, the motor vehicle 2010 can access an online server 2015 or a cloud server 2016 via a wireless communication system. This online server or cloud server is configured to provide the motor vehicle with services such as data processing, data storage, and data transmission.

[0085] In addition, Motor Vehicles 2010 also includes Figure 3 The powertrain, steering system, and braking system, etc., used to enable the driving function of a motor vehicle, are not shown in the diagram.

[0086] While embodiments or examples of this disclosure have been described with reference to the accompanying drawings, it should be understood that the methods, systems, and devices described above are merely exemplary embodiments or examples, and the scope of the invention is not limited by these embodiments or examples, but only by the granted claims and their equivalents. Various elements in the embodiments or examples may be omitted or replaced by their equivalents. Furthermore, the steps may be performed in a different order than that described in this disclosure. Further, various elements in the embodiments or examples may be combined in various ways. Importantly, as the technology evolves, many elements described herein can be replaced by equivalents that appear after this disclosure.

Claims

1. A method for upgrading existing software in a vehicle, comprising: Obtain an update package, which is used to upgrade existing software in the vehicle and verify the effectiveness of the upgraded software in the vehicle; Receive verification input signals, including new function verification input signals and existing function verification input signals; Based on the newly added function verification input signal, it is determined whether the newly added function of the upgraded software is consistent with the expectation to generate a new function verification result. Based on the original function verification input signal, it is determined whether the original function of the upgraded software is consistent with the existing software to generate an original function verification result. Based on the verification results of the new features and the verification results of the existing features, determine whether to upgrade the existing software in the vehicle based on the update package. The step of determining whether the new functions of the upgraded software are consistent with expectations based on the new function verification input signal to generate a new function verification result includes: Based on the update package, calculate the new function verification output signal corresponding to the new function verification input signal, and compare the new function verification output signal with the expected verification output signal to generate the new function verification result. The step of determining whether the original function is consistent with the existing software based on the original function verification input signal to generate the original function verification result includes: The original function verification output signal of the upgraded software is generated based on the original function verification input signal calculated based on the update package, and the original function output signal of the existing software is generated based on the original function verification input signal calculated based on the existing software. The original function verification output signal of the upgraded software and the original function output signal of the existing software are compared to generate the original function verification result.

2. The method as described in claim 1, wherein, The step of determining whether the new functions of the upgraded software are consistent with expectations based on the new function verification input signal to generate new function verification results includes: Calculate the first new function verification output signal based on the first new function verification input signal from the first number of new function verification input signals; The first new function verification output signal is compared with the expected output signal corresponding to the first new function verification input signal. When the first new function verification output signal and the expected output signal corresponding to the first new function verification input signal are consistent, the verification is considered successful once.

3. The method as described in claim 2, wherein, The step of determining whether the new functions of the upgraded software are consistent with expectations based on the new function verification input signal to generate new function verification results includes: The system counts the number of successful verifications. When the cumulative number of successful verifications exceeds a threshold or the number of consecutive successful verifications exceeds a threshold, the verification result for the new feature is considered successful.

4. The method of claim 1, wherein, The step of determining whether the original functions of the upgraded software are consistent with the existing software based on the original function verification input signal to generate the original function verification result includes: The first original function verification output signal is calculated based on the first original function verification input signal in the second number of original function verification input signals; The first original function verification output signal of the upgraded software is compared with the first original function output signal of the existing software. If the first original function verification output signal of the upgraded software is inconsistent with the first original function output signal of the existing software, it is considered as a verification failure.

5. The method of claim 4, wherein, The step of determining whether the original functions of the upgraded software are consistent with the existing software based on the original function verification input signal to generate the original function verification result includes: The system counts the number of verification failures. When the cumulative number of verification failures is zero, the original function verification result is considered successful.

6. The method according to any one of claims 1 to 5, wherein, The upgraded software included in the update package can run simultaneously with the existing software in the vehicle.

7. The method of claim 6, wherein, The step of determining whether to upgrade the existing software in the vehicle based on the update package, based on the verification results of the new function and the verification results of the original function, includes: When both the verification results for the new function and the verification results for the existing function are successful, the existing software in the vehicle is upgraded based on the update package.

8. The method of claim 7, further comprising: Before upgrading the existing software in the vehicle based on the update package, a user instruction is received, and the existing software in the vehicle is upgraded based on the update package according to the user instruction.

9. The method of claim 1, wherein, The step of determining whether to upgrade the existing software in the vehicle based on the update package, based on the verification results of the new function and the verification results of the original function, includes: If either the verification result of the new function or the verification result of the original function fails, the existing software in the vehicle will not be upgraded.

10. An apparatus for upgrading existing software in a vehicle, comprising: The acquisition unit is configured to acquire an update package, which is used to upgrade existing software in the vehicle and verify the effectiveness of the upgraded software in the vehicle. The receiving unit is configured to receive verification input signals, which include new function verification input signals and existing function verification input signals. The verification unit is configured to determine whether the new function of the upgraded software is consistent with the expectation based on the new function verification input signal to generate a new function verification result, and to determine whether the original function of the upgraded software is consistent with the existing software based on the original function verification input signal to generate an original function verification result. The upgrade unit is configured to determine, based on the verification results of the new features and the verification results of the existing features, whether to upgrade the existing software in the vehicle based on the update package. The step of determining whether the new functions of the upgraded software are consistent with expectations based on the new function verification input signal to generate a new function verification result includes: Based on the update package, calculate the new function verification output signal corresponding to the new function verification input signal, and compare the new function verification output signal with the expected verification output signal to generate the new function verification result. The step of determining whether the original function is consistent with the existing software based on the original function verification input signal to generate the original function verification result includes: The original function verification output signal of the upgraded software is generated based on the original function verification input signal calculated based on the update package, and the original function output signal of the existing software is generated based on the original function verification input signal calculated based on the existing software. The original function verification output signal of the upgraded software and the original function output signal of the existing software are compared to generate the original function verification result.

11. An electronic device, comprising: processor, and A memory storing a program, the program comprising instructions that, when executed by the processor, cause the processor to perform the method according to any one of claims 1 to 9.

12. A vehicle comprising: The apparatus of claim 10 or the electronic device of claim 11.

13. A non-transitory computer-readable storage medium storing a program, the program comprising instructions that, when executed by one or more processors, cause the one or more processors to perform the method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • System compatibility testing method, test case management method and related devices

    CN105446868A

  • Vehicle controller, program updating method, and non-transitory storage medium that stores program for updating program

    CN110162315A