Vehicle over-the-air upgrade method and device, electronic equipment and storage medium

By receiving upgrade task information from the cloud and upgrading the ECU sequentially, the problem of vehicle upgrade task termination caused by ECU upgrade failure was solved, improving ECU upgrade efficiency and completion rate, and enhancing user experience.

CN116456327BActive Publication Date: 2026-08-25VOYAH AUTOMOBILE TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310099828.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-03
Publication Date
2026-08-25
Estimated Expiration
2043-02-03

AI Technical Summary

Technical Problem

In existing technologies, failure to upgrade the electronic control unit (ECU) leads to the termination of the entire vehicle upgrade task, resulting in a low upgrade completion rate and a poor user experience.

Method used

Receive upgrade task information from the cloud, upgrade ECUs that meet the conditions in sequence, determine whether the ECU that fails to upgrade or does not meet the conditions is a high-risk ECU, if so, end the task, otherwise determine whether it is the last ECU, if not, continue to check the next ECU until the task ends.

Benefits of technology

It improves the efficiency and completion rate of ECU upgrades, and enhances the user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116456327B_ABST
    Figure CN116456327B_ABST
Patent Text Reader

Abstract

The application provides a vehicle OTA upgrading method and device, electronic equipment and a storage medium. The method comprises the following steps: receiving upgrading task information issued by a cloud; and based on the upgrading task information, sequentially upgrading each electronic control unit meeting an upgrading condition until the last electronic control unit in the electronic control units needing to be upgraded in the upgrading task is upgraded. The method realizes multiple special screening and judgment on the electronic control units failing in the upgrading process, thereby upgrading each electronic control unit as much as possible, improving the upgrading efficiency and completion rate of the electronic control unit, and improving the user experience.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of OTA upgrade technology, and more specifically, to a vehicle OTA upgrade method, a vehicle OTA upgrade device, an electronic device, and a storage medium. Background Technology

[0002] Currently, with the improvement of over-the-air (OTA) upgrade capabilities for vehicles, the number of electronic control units (ECUs) in a single OTA upgrade task is gradually increasing. In existing technologies, if an ECU upgrade fails, the entire vehicle upgrade task is terminated, and the failed ECU will not be upgraded again. This results in a low completion rate for vehicle ECU upgrades, leading to problems such as a poor user experience.

[0003] Therefore, a new technical solution is urgently needed to solve the above-mentioned technical problems. Summary of the Invention

[0004] The summary section introduces a series of simplified concepts, which will be further explained in detail in the detailed description section. The summary section of this invention is not intended to limit the key features and essential technical features of the claimed technical solution, nor is it intended to determine the scope of protection of the claimed technical solution.

[0005] In a first aspect, the present invention proposes a vehicle OTA upgrade method, comprising: receiving upgrade task information sent from the cloud, wherein the upgrade task information includes the upgrade order, upgrade method, upgrade strategy, and corresponding software package to be downloaded for electronic control units; based on the upgrade task information, sequentially upgrading each electronic control unit that meets the upgrade conditions, until the last electronic control unit in the upgrade task is upgraded; for unupgraded electronic control units that fail to upgrade or do not meet the upgrade conditions, determining whether the unupgraded electronic control unit is a high-risk electronic control unit; if so, ending the upgrade task; if not, determining whether the unupgraded electronic control unit is the last electronic control unit in the upgrade task, and ending the upgrade task if the unupgraded electronic control unit is the last electronic control unit in the upgrade task; if the unupgraded electronic control unit is not the last electronic control unit in the upgrade task, determining again whether the next unupgraded electronic control unit is a high-risk electronic control unit based on the upgrade order, until the upgrade task ends.

[0006] Optionally, the method further includes uploading upgrade failure information corresponding to the unupgraded electronic control unit to the cloud so that the cloud updates the upgrade record.

[0007] Optionally, the method further includes: determining again whether the unupgraded electronic control unit meets the upgrade conditions; if so, skipping the current unupgraded electronic control unit and upgrading the next electronic control unit based on the upgrade order; if not, ending the upgrade task.

[0008] Optionally, after the upgrade task is completed, the method further includes: sending the upgrade task information back to the cloud so that the cloud updates the upgrade record, wherein the upgrade task information includes electronic control unit upgrade success information and electronic control unit upgrade failure information; based on the upgrade task information, deleting the software package corresponding to the successfully upgraded electronic control unit and storing the software package corresponding to the failed upgraded electronic control unit.

[0009] Optionally, the upgrade conditions include that the current software version of at least one electronic control unit is inconsistent with the target version deployed in the cloud.

[0010] Optionally, the method further includes: downloading the software package from the cloud when the upgrade conditions are met; during the download process, if the vehicle-mounted device loses connection with the content delivery network, the vehicle-mounted device automatically records the download breakpoint so that the download can continue from the breakpoint when the download conditions are met again.

[0011] Optionally, after the software package is downloaded, the method further includes: performing a signature verification operation on the software package; if the signature verification passes, the electronic control unit upgrade operation begins; if the signature verification fails, a new software package is downloaded again.

[0012] Secondly, a vehicle OTA upgrade device is proposed, comprising: a task receiving module for receiving upgrade task information sent from the cloud, wherein the upgrade task information includes the upgrade sequence, upgrade method, upgrade strategy, and corresponding software package to be downloaded for electronic control units; an upgrade module for sequentially upgrading each electronic control unit that meets the upgrade conditions based on the upgrade task information, until the last electronic control unit in the upgrade task is upgraded; and a judgment module for determining whether an un-upgraded electronic control unit is a high-risk electronic control unit for upgrade failures or failure to meet upgrade conditions. If so, the upgrade task is terminated; otherwise, it is determined whether the un-upgraded electronic control unit is the last electronic control unit in the upgrade task. If the un-upgraded electronic control unit is the last electronic control unit in the upgrade task, the upgrade task is terminated. If the un-upgraded electronic control unit is not the last electronic control unit in the upgrade task, the next un-upgraded electronic control unit is determined again based on the upgrade sequence to determine whether it is a high-risk electronic control unit, until the upgrade task is completed.

[0013] Thirdly, an electronic device is also proposed, including a processor and a memory, wherein the memory stores computer program instructions, which are executed by the processor to perform the vehicle OTA upgrade method described above.

[0014] Fourthly, a storage medium is also proposed, on which program instructions are stored. When the program instructions are run, they are used to execute the vehicle OTA upgrade method described above.

[0015] The vehicle OTA upgrade method proposed in this invention receives upgrade task information from the cloud, which includes the upgrade order, upgrade method, upgrade strategy, and corresponding software packages to be downloaded for electronic control units (ECUs). Based on the upgrade task information, each ECU that meets the upgrade conditions is upgraded sequentially until the last ECU in the upgrade task is upgraded. For ECUs that fail to upgrade or do not meet the upgrade conditions, it is determined whether the ECU is a high-risk ECU. If so, the upgrade task ends; otherwise, it is determined whether the ECU is the last ECU in the upgrade task. If it is, the upgrade task ends; otherwise, it is determined whether the next ECU is a high-risk ECU based on the upgrade order, until the upgrade task ends. This method achieves multiple special screening and judgment of ECUs that fail to upgrade during the upgrade process, thereby upgrading as many ECUs as possible, improving the upgrade efficiency and completion rate, and enhancing the user experience.

[0016] The vehicle OTA upgrade method of the present invention, other advantages, objectives and features of the present invention will be apparent in part from the following description, and in part will be understood by those skilled in the art through study and practice of the present invention. Attached Figure Description

[0017] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit this specification. Furthermore, the same reference numerals denote the same parts throughout the drawings. In the drawings:

[0018] Figure 1 A schematic flowchart of a vehicle OTA upgrade method according to an embodiment of the present invention is shown;

[0019] Figure 2A schematic flowchart of a vehicle OTA upgrade method according to another embodiment of the present invention is shown;

[0020] Figure 3 A schematic block diagram of a vehicle OTA upgrade device according to an embodiment of the present invention is shown; and

[0021] Figure 4 A schematic block diagram of an electronic device according to an embodiment of the present invention is shown. Detailed Implementation

[0022] According to the above technical solution, by receiving upgrade task information from the cloud, which includes the upgrade sequence, upgrade method, upgrade strategy, and corresponding software packages to be downloaded for electronic control units (ECUs), the system sequentially upgrades each ECU that meets the upgrade conditions until the last ECU in the upgrade task is upgraded. For ECUs that fail to upgrade or do not meet the upgrade conditions, the system determines whether the ECU is a high-risk ECU. If so, the upgrade task ends; otherwise, it determines whether the ECU is the last ECU in the upgrade task. If it is, the upgrade task ends; otherwise, it determines whether the next ECU is a high-risk ECU based on the upgrade sequence, and so on, until the upgrade task ends. This achieves multiple special screening and judgment of ECUs that fail to upgrade during the upgrade process, thereby upgrading as many ECUs as possible, improving the upgrade efficiency and completion rate, and enhancing the user experience.

[0023] The terms "first," "second," "third," "fourth," etc. (if present) in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus. The technical solutions of the embodiments of this application will now be clearly and completely described in conjunction with the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them.

[0024] This invention proposes a method for over-the-air (OTA) upgrades for vehicles. Figure 1 A schematic flowchart of a vehicle OTA upgrade method 100 according to an embodiment of the present invention is shown. Figure 1 As shown, method 100 may include the following steps.

[0025] Step S110: Receive upgrade task information sent from the cloud. The upgrade task information includes the upgrade sequence, upgrade method, upgrade strategy, and corresponding software packages to be downloaded for the electronic control unit.

[0026] For example, the upgrade order of electronic control units (ECUs) can be determined based on the dependencies between ECU upgrade software packages, without further limitations. Specifically, the software package acquisition method can be that the vehicle to be upgraded obtains it from a link address based on the ECU identifier, without further limitations. Specifically, it can be determined whether each ECU on the vehicle needs to perform an upgrade by comparing its current version with the target version of the ECU in the cloud, and thus whether the corresponding ECU software package needs to be downloaded. If at least one ECU on the vehicle has a current version that is inconsistent with the task version in the upgrade task information sent from the cloud, then the upgrade task sent from the cloud is received. The upgrade task information includes the ECU upgrade order, upgrade method, upgrade strategy, and the corresponding software package to be downloaded. Specifically, the download conditions of the ECU software package can be detected at preset intervals, such as 1 minute.

[0027] Step S120: Based on the upgrade task information, upgrade each electronic control unit that meets the upgrade conditions in sequence until the last electronic control unit in the upgrade task that needs to be upgraded is upgraded.

[0028] For example, the upgrade condition could be the difference between the current version of each electronic control unit on the vehicle and the target version of the electronic control unit in the cloud. Specifically, if there is a difference between the current version of the electronic control unit on the vehicle and the target version of the electronic control unit in the cloud, the electronic control unit is determined to be an electronic control unit that meets the upgrade condition. The difference between the current version of each electronic control unit and the target version of the electronic control unit in the cloud can be a difference in quantity, etc., and is not specifically limited here.

[0029] After each electronic control unit (ECU) is successfully upgraded in step S120, step S130 is executed: determining whether the ECU currently being upgraded is the last ECU in the upgrade task. If it is determined that the ECU currently being upgraded is the last ECU, step S160 is executed to end the upgrade task. Otherwise, if it is determined that the ECU currently being upgraded is not the last ECU in the upgrade task, the subsequent ECUs are upgraded sequentially until the last ECU in the upgrade task is upgraded, and then the upgrade task ends.

[0030] During the upgrade process of electronic control units, there may be upgrade failures or failures to meet the upgrade conditions, resulting in unupgraded electronic control units. For such electronic control units, step S140 is executed to determine whether the currently unupgraded electronic control unit is a high-risk electronic control unit.

[0031] Specifically, a high-risk electronic control unit (ECU) can be an ECU that affects vehicle breakdown or vehicle start / stop. If the currently unupgraded ECU is a high-risk ECU, then step S160 is executed to end the upgrade task. Conversely, if the currently unupgraded ECU is not a high-risk ECU, then step S150 is executed to determine whether the currently unupgraded ECU is the last ECU in the upgrade task. If so, then step S160 is executed to end the upgrade task. Conversely, if the currently unupgraded ECU is not the last ECU in the upgrade task, then step S140 is executed again to determine whether the next unupgraded ECU is a high-risk ECU based on the upgrade order, and the above steps are repeated until the upgrade task is completed.

[0032] The vehicle OTA upgrade method proposed in this invention receives upgrade task information from the cloud, which includes the upgrade order, upgrade method, upgrade strategy, and corresponding software packages to be downloaded for electronic control units (ECUs). Based on the upgrade task information, each ECU that meets the upgrade conditions is upgraded sequentially until the last ECU in the upgrade task is upgraded. For ECUs that fail to upgrade or do not meet the upgrade conditions, it is determined whether the ECU is a high-risk ECU. If so, the upgrade task ends; otherwise, it is determined whether the ECU is the last ECU in the upgrade task. If it is, the upgrade task ends; otherwise, it is determined whether the next ECU is a high-risk ECU based on the upgrade order, until the upgrade task ends. This method achieves multiple special screening and judgment of ECUs that fail to upgrade during the upgrade process, thereby upgrading as many ECUs as possible, improving the upgrade efficiency and completion rate, and enhancing the user experience.

[0033] Optionally, the method further includes uploading upgrade failure information corresponding to the unupgraded electronic control unit to the cloud so that the cloud updates the upgrade record.

[0034] For example, upgrade failure information may include all current and future information that distinguishes the unupgraded electronic control unit from other electronic control units in the vehicle, including version information, function information, name information, and risk level information of the unupgraded electronic control unit. No further limitations are made here. Preferably, if the unupgraded electronic control unit is a high-risk unit, it can be marked. When upgrading the vehicle's electronic control units again, this high-risk unit can be skipped, thus quickly completing the upgrade operation. This method, by uploading the upgrade failure information corresponding to the unupgraded electronic control unit to the cloud, allows for real-time monitoring and recording of the upgrade status and current version information of the vehicle's electronic control units, facilitating future upgrades of the vehicle's electronic control units.

[0035] Optionally, the method further includes: determining again whether the unupgraded electronic control unit meets the upgrade conditions; if so, skipping the current unupgraded electronic control unit and upgrading the next electronic control unit based on the upgrade order; if not, ending the upgrade task.

[0036] For example, if an unupgraded electronic control unit (ECU) meets the upgrade conditions (i.e., its version differs from the target version and it is neither a high-risk ECU nor the last ECU to be upgraded), the current unupgraded ECU is skipped, and the next ECU is upgraded based on the upgrade order. If an unupgraded ECU does not meet the upgrade conditions (i.e., its version does not differ from the target version), the upgrade task is terminated. This method, by performing a secondary check on whether the unupgraded ECU meets the upgrade conditions, achieves multiple screenings of ECUs that fail to upgrade during the upgrade process, thereby improving the ECU upgrade completion rate.

[0037] Figure 2 A schematic flowchart of a vehicle OTA upgrade method according to another embodiment of the present invention is shown.

[0038] like Figure 2 As shown, after the upgrade task is completed, method 100 may also include the following steps:

[0039] Step S170: The upgrade task information is sent back to the cloud so that the cloud updates the upgrade record. The upgrade task information includes information on successful upgrade of the electronic control unit and information on failed upgrade of the electronic control unit.

[0040] For example, successful electronic control unit (ECU) upgrade information may include: the latest version information, function information, name information, and upgrade completion time of the upgraded ECU; failed ECU upgrade information may include: the current version information, function information, name information, and reason for upgrade failure of the failed ECU. This method, by transmitting upgrade task information back to the cloud, updates the upgrade records in the cloud. This upgrade task information includes successful and failed ECU upgrade information, enabling precise control over the upgrade status of the vehicle's ECUs. This lays the foundation for future upgrades of the vehicle's ECUs, thereby saving operational steps and time in subsequent ECU upgrade processes.

[0041] Step S180: Based on the upgrade task information, delete the software packages corresponding to the successfully upgraded electronic control units, and store the software packages corresponding to the failed upgrade electronic control units.

[0042] For example, the vehicle-side components can delete the software packages corresponding to the currently successfully upgraded electronic control units (ECUs) based on upgrade task information, while storing the software packages of ECUs that failed to upgrade in the storage area. This method, by deleting the software packages corresponding to successfully upgraded ECUs and storing the software packages corresponding to ECUs that failed to upgrade based on upgrade task information, saves overall vehicle storage space and provides the necessary resources for re-upgrading ECUs that failed, thus saving time and steps associated with re-upgrading ECUs.

[0043] Optionally, the upgrade conditions include that the current software version of at least one electronic control unit is inconsistent with the target version deployed in the cloud.

[0044] Specifically, if the current version of at least one electronic control unit (ECU) on the vehicle is inconsistent with the version in the upgrade task information sent from the cloud, then the upgrade task sent from the cloud will be received. This method determines the upgrade status of the ECU by comparing vehicle-cloud version information, shortening the download time of unupgraded ECU software packages, reducing data consumption, and saving upgrade time for the entire vehicle's ECUs.

[0045] Optionally, the method further includes: downloading the software package from the cloud when the upgrade conditions are met; during the download process, if the vehicle-mounted device loses connection with the content delivery network, the vehicle-mounted device automatically records the download breakpoint so that the download can continue from the breakpoint when the download conditions are met again.

[0046] For example, when upgrade conditions are met, the vehicle-mounted device can request to download the electronic control unit (ECU) software package from the content delivery network (CDN) and simultaneously store the software package in the OTA cache area of ​​the TBOX. During the download process, if the vehicle loses connection to the CDN due to a power outage or other abnormal situation, the vehicle-mounted component can automatically record the most recent breakpoint in the software package download. When the vehicle meets the download conditions again, it can resume downloading the software package based on the power outage record recorded by the vehicle-mounted component. This method, by downloading the software package from the cloud when upgrade conditions are met, and automatically recording the download breakpoint if the vehicle loses connection to the CDN during the download process, allows the download to resume from the breakpoint after the download conditions are met again. This achieves breakpoint resumption of the ECU software package download, avoiding the need to restart the download process due to sudden network interruptions, and reducing bandwidth consumption.

[0047] Optionally, after the software package is downloaded, the method further includes: performing a signature verification operation on the software package; if the signature verification passes, the electronic control unit upgrade operation begins; if the signature verification fails, a new software package is downloaded again.

[0048] For example, the system can determine whether the target version of the software package is stored in the vehicle's storage space based on the software version cache information of the electronic control unit reported by the vehicle. If it is, a signature verification operation is performed on the software package. If the signature verification is successful, the electronic control unit upgrade operation begins; if the signature verification fails, the new software package is downloaded again. Preferably, if the target version software package is not in the vehicle's storage space, it can be marked for download. The above method, by verifying the signature of the software package, avoids electronic control unit upgrade failures caused by file tampering or software package corruption, thereby improving the upgrade efficiency of the electronic control unit and the user's upgrade experience.

[0049] According to a second aspect of the present invention, the present invention provides a vehicle OTA upgrade device. Figure 3 A schematic block diagram of a vehicle OTA upgrade device 300 according to an embodiment of the present invention is shown. Figure 3 As shown, the device 300 may include: a task receiving module 310, an upgrade module 320, and a judgment module 330.

[0050] The task receiving module 310 is used to receive upgrade task information sent from the cloud. The upgrade task information includes the upgrade sequence, upgrade method, upgrade strategy of the electronic control unit, and the corresponding software package to be downloaded.

[0051] The upgrade module 320 is used to upgrade each electronic control unit that meets the upgrade conditions sequentially based on the upgrade task information, until the last electronic control unit in the upgrade task that needs to be upgraded is upgraded.

[0052] The judgment module 330 is used to determine whether an un-upgraded electronic control unit is a high-risk electronic control unit for an un-upgraded electronic control unit that has failed to upgrade or does not meet the upgrade conditions. If it is, the upgrade task is terminated. If not, it is determined whether the un-upgraded electronic control unit is the last electronic control unit in the upgrade task. If the un-upgraded electronic control unit is the last electronic control unit in the upgrade task, the upgrade task is terminated. If the un-upgraded electronic control unit is not the last electronic control unit in the upgrade task, the next un-upgraded electronic control unit is determined again based on the upgrade order to determine whether it is a high-risk electronic control unit, until the upgrade task is completed.

[0053] According to a third aspect of the present invention, an electronic device is also provided. Figure 4 A schematic block diagram of an electronic device 400 according to an embodiment of the present invention is shown. Figure 4 As shown, the electronic device 400 may include a processor 410 and a memory 420. The memory 420 stores computer program instructions, which are executed by the processor 410 to perform the vehicle OTA upgrade method described above.

[0054] According to a fourth aspect of the present invention, a storage medium is also provided, on which program instructions are stored, which, when executed, are used to perform the vehicle OTA upgrade method described above. The storage medium may, for example, include a storage component of a tablet computer, a hard disk of a computer, a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a portable compact disc read-only memory (CD-ROM), a USB memory, or any combination of the above storage media. The computer-readable storage medium may be any combination of one or more computer-readable storage media.

[0055] Those skilled in the art can understand the specific details and beneficial effects of the vehicle OTA upgrade device, electronic equipment, and storage medium by reading the above description of the vehicle OTA upgrade method, and will not be repeated here for the sake of brevity.

[0056] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and / or device can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0057] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0058] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0059] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0060] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit it. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.

Claims

1. A vehicle OTA upgrade method, characterized in that, include: Receive upgrade task information sent from the cloud, wherein the upgrade task information includes the upgrade sequence, upgrade method, upgrade strategy and corresponding software package to be downloaded for the electronic control unit; Based on the upgrade task information, each electronic control unit that meets the upgrade conditions is upgraded sequentially until the last electronic control unit in the upgrade task that needs to be upgraded is upgraded. For unupgraded electronic control units (ECUs) that fail to upgrade or do not meet the upgrade conditions, determine whether the unupgraded ECU is a high-risk ECU. If so, end the upgrade task. If not, determine whether the unupgraded ECU is the last ECU in the upgrade task. If the unupgraded ECU is the last ECU in the upgrade task, end the upgrade task. If the unupgraded ECU is not the last ECU in the upgrade task, determine whether the next unupgraded ECU is a high-risk ECU based on the upgrade order, until the upgrade task ends.

2. The vehicle OTA upgrade method as described in claim 1, characterized in that, The method further includes: Upgrade failure information corresponding to the unupgraded electronic control unit is uploaded to the cloud so that the cloud updates the upgrade record.

3. The vehicle OTA upgrade method as described in claim 1 or 2, characterized in that, After the upgrade task is completed, the method further includes: The upgrade task information is sent back to the cloud so that the cloud updates the upgrade record. The upgrade task information includes electronic control unit upgrade success information and electronic control unit upgrade failure information. Based on the upgrade task information, delete the software packages corresponding to the successfully upgraded electronic control units, and store the software packages corresponding to the electronic control units that failed to upgrade.

4. The vehicle OTA upgrade method as described in claim 1 or 2, characterized in that, in, The upgrade conditions include that the current software version of at least one electronic control unit is inconsistent with the target version deployed in the cloud.

5. The vehicle OTA upgrade method as described in claim 4, characterized in that, The method further includes: If the upgrade conditions are met, the software package will be downloaded from the cloud. If the vehicle loses connection with the content delivery network during the download process, the vehicle automatically records the download breakpoint so that it can continue downloading the software package from the breakpoint once the download conditions are met again.

6. The vehicle OTA upgrade method as described in claim 5, characterized in that, After the software package has been downloaded, the method further includes: The software package is verified. If the verification is successful, the electronic control unit upgrade operation begins. If the verification fails, a new software package is downloaded again.

7. A vehicle OTA upgrade device, characterized in that, include: The task receiving module is used to receive upgrade task information sent from the cloud. The upgrade task information includes the upgrade sequence, upgrade method, upgrade strategy, and corresponding software package to be downloaded for the electronic control unit. The upgrade module is used to upgrade each electronic control unit that meets the upgrade conditions sequentially based on the upgrade task information, until the last electronic control unit among the electronic control units that need to be upgraded in the upgrade task is upgraded. The judgment module is used to determine whether an un-upgraded electronic control unit (ECU) that has failed to upgrade or does not meet the upgrade conditions is a high-risk ECU. If so, the upgrade task is terminated. If not, it is determined whether the un-upgraded ECU is the last ECU in the upgrade task. If the un-upgraded ECU is the last ECU in the upgrade task, the upgrade task is terminated. If the un-upgraded ECU is not the last ECU in the upgrade task, the module determines whether the next un-upgraded ECU is a high-risk ECU based on the upgrade order, until the upgrade task is completed.

8. An electronic device, characterized in that, It includes a processor and a memory, wherein the memory stores computer program instructions, which, when executed by the processor, are used to perform the vehicle OTA upgrade method as described in any one of claims 1 to 6.

9. A storage medium storing program instructions that, when executed, perform the vehicle OTA upgrade method as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • OTA upgrading method for vehicle ECU and system thereof

    CN111478897A

  • Multi-ECU upgrading method based on OTA

    CN112104736A