ECU Replacement and Upgrade Method, Device, Electronic Device and Storage Medium

By generating and verifying the signed authorization file after the ECU replacement, we ensure that the OTA upgrade package is bound to the vehicle asset information, and the OTA upgrade security vulnerability after the ECU replacement is solved, and a safe and efficient writing and upgrading is achieved.

CN118450366BActive Publication Date: 2025-06-10CHONGQING SELIS PHOENIX INTELLIGENT INNOVATION TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202410534765.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-04-30
Publication Date
2025-06-10
Estimated Expiration
2044-04-30

AI Technical Summary

Technical Problem

In the prior art, there may be security vulnerabilities in the OTA upgrade after the ECU replacement, and the identity of the ECU cannot be effectively verified.

Method used

After the replacement of the target ECU in the vehicle is completed, the vehicle computer notifies the cloud server. The cloud server generates an OTA upgrade package including the OTA program upgrade package and the authorization file. The authorization file is determined and signed by the cloud server based on the vehicle asset information. After verifying that the authorization file is passed, the vehicle computer uses the OTA program upgrade package to upgrade the target ECU.

Benefits of technology

By binding the OTA upgrade package and vehicle asset information, we ensure the legality of the target ECU and avoid the upgrade of illegal ECU parts, safe write-through upgrades are achieved, and write-through efficiency and traceability are improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118450366B_ABST
    Figure CN118450366B_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of vehicles, and provides an ECU replacement and upgrade method, device, electronic device and storage medium. After the replacement of the target ECU in the vehicle is completed, the vehicle computer notifies the cloud server, so that the cloud server generates an OTA upgrade package including an OTA program upgrade package and an authorization file after receiving the replacement completion notification. The authorization file is determined by the cloud server based on the vehicle asset information obtained from the vehicle computer and includes a signature. After the vehicle computer verifies the authorization file, it uses the OTA program upgrade package to upgrade the target ECU, thereby avoiding the situation that the target ECU can still be normally upgraded after being replaced with an illegal ECU part, realizing the binding of the OTA upgrade package and the vehicle asset information, ensuring the safe flashing upgrade of a single vehicle, and improving the flashing efficiency and traceability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of vehicles, and in particular, to an ECU replacement and upgrade method, device, electronic device, and storage medium. Background Art

[0002] The vehicle upgrade method based on Over-the-Air Technology (OTA) is a technology that has developed rapidly in the automotive industry in recent years. It allows automobile manufacturers to remotely update and upgrade the software of vehicles through wireless networks. This technology provides automobile manufacturers with a more flexible and efficient way to improve vehicle functions, repair potential problems, and adapt to changing regulations and market demands.

[0003] Vehicles can be upgraded through OTA for the in-vehicle infotainment system (IVI) or the electronic control unit (ECU) mounted under the IVI. Among them, the IVI, such as the Cockpit Domain Controller (CDC) or the Vehicle Box (VBOX), can also be regarded as a relatively complex ECU. In the related art, when performing OTA on the ECU, usually only the OTA cloud platform verifies the upgrade package by means of hash encryption and the like when generating the OTA upgrade package, and the identity of the ECU is not verified. This may lead to security vulnerabilities. Summary of the Invention

[0004] In view of this, the embodiments of this application provide an ECU replacement and upgrade method, device, electronic device, and storage medium to solve the problem that there may be security vulnerabilities in OTA upgrade after ECU replacement in the prior art.

[0005] In the first aspect of the embodiments of this application, an ECU replacement and upgrade method is provided. This method is executed by the IVI, and the method includes:

[0006] In response to the completion of the replacement of the target ECU in the vehicle, the IVI sends a replacement completion message to the cloud server;

[0007] In response to receiving the instruction to obtain asset information sent by the cloud server, send the asset information of the vehicle where the IVI is located to the cloud server;

[0008] Obtain an OTA upgrade package from the cloud server. The OTA upgrade package includes at least an OTA program upgrade package and an authorization file. The OTA upgrade package is generated by the cloud server after receiving the replacement completion message and sent to the IVI. The authorization file is determined by the cloud server according to the vehicle asset information obtained from the IVI, and the authorization file is an authorization file signed using a signature system;

[0009] In response to successful verification of the authorization file in the OTA upgrade package, upgrade the target ECU using the OTA program upgrade package.

[0010] In a second aspect of the embodiments of the present application, an ECU replacement upgrade device is provided, including:

[0011] A sending module, configured to, in response to completion of replacement of the target ECU in the vehicle, the vehicle head unit send a replacement completion message to the cloud server;

[0012] The sending module is further configured to, in response to receiving an instruction from the cloud server to obtain asset information, send the asset information of the vehicle where the vehicle head unit is located to the cloud server;

[0013] A receiving module, configured to obtain an OTA upgrade package from the cloud server, the OTA upgrade package at least including an OTA program upgrade package and an authorization file, the OTA upgrade package being generated by the cloud server after receiving the replacement completion message and sent to the vehicle head unit, the authorization file being determined by the cloud server according to the vehicle asset information obtained from the vehicle head unit, and the authorization file being an authorization file signed using a signature system;

[0014] An upgrade module, configured to, in response to successful verification of the authorization file in the OTA upgrade package, upgrade the target ECU using the OTA program upgrade package.

[0015] In a third aspect of the embodiments of the present application, an electronic device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, and when the processor executes the computer program, the steps of the above method are implemented.

[0016] In a fourth aspect of the embodiments of the present application, a computer-readable storage medium is provided, the computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, the steps of the above method are implemented.

[0017] The beneficial effects of the embodiments of the present application compared with the prior art are as follows: After the replacement of the target ECU in the vehicle is completed in the embodiments of the present application, the vehicle head unit notifies the cloud server, so that the cloud server generates an OTA upgrade package including an OTA program upgrade package and an authorization file after receiving the replacement completion notification, where the authorization file is determined by the cloud server based on the vehicle asset information obtained from the vehicle head unit and includes a signature. After the vehicle head unit successfully verifies the authorization file, the OTA program upgrade package is used to upgrade the target ECU, thereby avoiding the situation that the target ECU can still be normally upgraded after being replaced with an illegal ECU part, realizing the binding of the OTA upgrade package and the vehicle asset information, ensuring the secure flashing upgrade of a single vehicle, and improving the flashing efficiency and traceability. Description of the Drawings

[0018] To more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.

[0019] Figure 1 It is a schematic diagram of the application scenario of the embodiments of the present application.

[0020] Figure 2 It is a schematic flowchart of a method for ECU replacement and upgrade provided by the embodiments of the present application.

[0021] Figure 3 It is a schematic flowchart of a method for a cloud server to generate an OTA upgrade package provided by the embodiments of the present application.

[0022] Figure 4 It is a schematic flowchart of another method for ECU replacement and upgrade provided by the embodiments of the present application.

[0023] Figure 5 It is a schematic diagram of the vehicle asset information included in the authorization document provided by the embodiments of the present application.

[0024] Figure 6 It is a schematic flowchart of yet another method for ECU replacement and upgrade provided by the embodiments of the present application.

[0025] Figure 7 It is a schematic flowchart of still another method for ECU replacement and upgrade provided by the embodiments of the present application.

[0026] Figure 8 It is a schematic flowchart of another method for ECU replacement and upgrade provided by the embodiments of the present application.

[0027] Figure 9 It is a schematic diagram of an ECU replacement and upgrade device provided by the embodiments of the present application.

[0028] Figure 10 It is a schematic diagram of an electronic device provided by the embodiments of the present application. Detailed implementation manners

[0029] In the following description, for the purpose of illustration rather than limitation, specific details such as specific system architectures and technologies are presented to thoroughly understand the embodiments of the present application. However, those skilled in the art should clearly understand that the present application can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid unnecessary details from interfering with the description of the present application.

[0030] A method and device for ECU replacement and upgrade according to an embodiment of the present application will be described in detail below with reference to the accompanying drawings.

[0031] Figure 1 It is a schematic diagram of an application scenario of an embodiment of the present application. The application scenario may include a vehicle 1, a vehicle head unit 2, an ECU 3, an OTA server 4, and a cloud server 5.

[0032] The vehicle head unit 2 is located in the vehicle 1, and it can be the CDC or TBOX in the vehicle. There are multiple ECUs 3 mounted under the vehicle head unit 2. The OTA server 4 is connected to the cloud server 5 and the vehicle head unit 2 respectively. It receives the OTA upgrade instruction sent by the cloud server 5 and forwards the OTA upgrade instruction to the vehicle head unit 2 when it determines that the upgrade condition is met. Further, the vehicle head unit 2 is also connected to the cloud server 5. When it receives the OTA upgrade instruction, it downloads the OTA upgrade package from the cloud server 5 and uses the OTA upgrade package to upgrade and flash the ECU to be upgraded.

[0033] It should be noted that the specific types, quantities, and combinations of the vehicle 1, the vehicle head unit 2, the ECU 3, the OTA server 4, and the cloud server 5 can be adjusted according to the actual requirements of the application scenario, and the embodiments of the present application do not limit this.

[0034] As mentioned above, the vehicle can upgrade the vehicle head unit or the ECU mounted under the vehicle head unit through OTA upgrade. The OTA upgrade technology mainly includes the following aspects:

[0035] 1) Upgrade package production and push: Automobile manufacturers first produce upgrade packages, which usually contain software updates, function enhancements, or repair patches. Subsequently, these upgrade packages are pushed to the vehicle through a wireless communication network (such as a mobile data network or a satellite network).

[0036] 2) Vehicle verification and reception: After receiving the upgrade package, the vehicle will perform a series of verification operations, including checking the integrity and security of the upgrade package. Only the upgrade package that passes the verification will be received by the vehicle and prepared for installation.

[0037] 3) Upgrade process management: The upgrade process usually needs to be carried out when the vehicle is in a stationary state or a specific maintenance mode to ensure that the upgrade process will not affect the normal operation of the vehicle. During the upgrade process, the vehicle will perform a series of code replacement and configuration update operations, and finally complete the software upgrade.

[0038] At the same time, the OTA upgrade technology also has the following defects:

[0039] 1) Security risks: OTA upgrades involve transmitting and receiving data over a network, which increases potential security risks. Hackers may exploit vulnerabilities or weaknesses to launch attacks, tamper with upgrade packages, or steal vehicle data. Therefore, automakers need to invest significant resources to enhance the security of OTA upgrades, including using encryption technologies, verification mechanisms, etc.

[0040] 2) Compatibility issues: Different vehicle models and configurations may have different hardware and software architectures, which may cause OTA upgrades to not proceed smoothly on some vehicles. Manufacturers need to adapt and test for different vehicle models and configurations to ensure the compatibility and stability of upgrade packages.

[0041] 3) User acceptance and operational complexity: Although OTA upgrades bring convenience to users, some users may be skeptical about remote upgrades, fearing potential problems during the upgrade process or impacts on vehicle performance. Additionally, some complex upgrade operations may require users to perform additional settings or operations, increasing the complexity of use.

[0042] In view of this, the embodiments of the present application provide an ECU replacement upgrade method. After the replacement of the target ECU in the vehicle is completed, the in-vehicle unit notifies the cloud server, so that the cloud server generates an OTA upgrade package including an OTA program upgrade package and an authorization file after receiving the replacement completion notification. The authorization file is determined by the cloud server based on the vehicle asset information obtained from the in-vehicle unit and includes a signature. After the in-vehicle unit verifies the authorization file, it uses the OTA program upgrade package to upgrade the target ECU, thereby being able to avoid the normal upgrade of the target ECU even after it is replaced with an illegal ECU part, realizing the binding of the OTA upgrade package with the vehicle asset information, ensuring the secure flashing upgrade of a single vehicle, and improving the flashing efficiency and traceability.

[0043] Figure 2 It is a schematic flowchart of an ECU replacement upgrade method provided by the embodiments of the present application. Figure 2 The ECU replacement upgrade method can be executed by Figure 1 the in-vehicle unit of Figure 2 As shown in

[0044] In step S201, in response to the completion of the replacement of the target ECU in the vehicle, the in-vehicle unit sends a replacement completion message to the cloud server.

[0045] In step S202, in response to receiving the asset information acquisition instruction sent by the cloud server, the in-vehicle unit sends the asset information of the vehicle where the in-vehicle unit is located to the cloud server.

[0046] In step S203, obtain the OTA upgrade package from the cloud server.

[0047] Among them, the OTA upgrade package at least includes an OTA program upgrade package and an authorization file. The OTA upgrade package is generated by the cloud server after receiving the component replacement completion message and sent to the in-vehicle computer. The authorization file is determined by the cloud server according to the vehicle asset information obtained from the in-vehicle computer, and the authorization file is an authorization file that has been signed using the signature system.

[0048] In step S204, in response to successful verification of the authorization file in the OTA upgrade package, the target ECU is upgraded using the OTA program upgrade package.

[0049] In the embodiment of the present application, this method can be executed by the in-vehicle computer in the vehicle. Further, the in-vehicle computer can be, for example, a CDC or a TBOX.

[0050] In the embodiment of the present application, the target ECU in the vehicle can first perform component replacement processing. Among them, the target ECU can be each ECU component mounted under the in-vehicle computer, such as various domain controllers, or other more refined ECU components. Further, the target ECU can also be the in-vehicle computer itself, i.e., the CDC or the TBOX.

[0051] In the embodiment of the present application, after the component replacement of the target ECU in the vehicle is completed, the in-vehicle computer can send a component replacement completion message to the cloud server. After receiving the component replacement completion message, the cloud server sends an asset information acquisition instruction to the in-vehicle computer. Among them, the cloud server can first send the asset information acquisition instruction to the OTA management unit, and then the OTA management unit issues it to the in-vehicle computer when it determines that the forwarding condition is met. The OTA management unit can be, for example, an OTA management server, and the forwarding condition can be, for example, that the target ECU is in an idle state, or other conditions, which are not limited here.

[0052] In the embodiment of the present application, after receiving the asset information acquisition instruction, the in-vehicle computer sends the vehicle asset information of the vehicle itself to the cloud server according to the vehicle's own asset information. It can be understood that the in-vehicle computer can directly send its own vehicle asset information to the cloud server, or first send it to the OTA management unit, and then the OTA management unit forwards it to the cloud server.

[0053] In the embodiment of the present application, after the cloud server obtains the vehicle asset information of the vehicle where the target ECU is located, it generates an OTA upgrade package for the target ECU. The OTA upgrade package at least includes an OTA program upgrade package and an authorization file. The authorization file is determined by the cloud server according to the vehicle asset information and is signed using the signature system. Among them, the file format of the authorization file can be a HEX file, and it can be a data stream.

[0054] In the embodiments of the present application, the cloud server may send the generated OTA upgrade package to the OTA management unit, and when the OTA management unit determines that the upgrade conditions are met, for example, it determines that the target ECU is not the latest version at present, the target ECU is in an idle state, or the target ECU has a partition upgrade function although it is not in an idle state, etc., the OTA upgrade package is sent to the target ECU.

[0055] In the embodiments of the present application, the target ECU receives the OTA upgrade package and parses it to obtain the authorization file and the OTA program upgrade package. Further, the target ECU first verifies the authorization file, and then uses the OTA program upgrade package to upgrade and flash the target ECU when the verification is passed. Among them, what is saved in the OTA program upgrade package may be the Uniform Resource Locator (URL) of the OTA program upgrade package. At this time, the target ECU can download the OTA upgrade package program according to the URL, and then use the downloaded OTA upgrade package program to upgrade and flash the target ECU.

[0056] According to the technical solution provided by the embodiments of the present application, after the replacement of the target ECU in the vehicle is completed, the vehicle-mounted computer notifies the cloud server, so that the cloud server generates an OTA upgrade package including the OTA program upgrade package and the authorization file after receiving the replacement completion notice. The authorization file is determined by the cloud server based on the vehicle asset information obtained from the vehicle-mounted computer and includes a signature. After the vehicle-mounted computer verifies the authorization file and passes, it uses the OTA program upgrade package to upgrade the target ECU, thereby avoiding the situation that the target ECU can still be normally upgraded after being replaced with an illegal ECU part, realizing the binding of the OTA upgrade package and the vehicle asset information, ensuring the safe flashing upgrade of a single vehicle, and improving the flashing efficiency and traceability.

[0057] Figure 3 It is a schematic flowchart of the method for the cloud server to generate an OTA upgrade package provided by the embodiments of the present application. As Figure 3 shown, the method includes the following steps:

[0058] In step S301, in response to receiving the replacement completion message sent by the vehicle-mounted computer, the cloud server creates an OTA upgrade task and generates an OTA program upgrade package.

[0059] In step S302, the cloud server sends an instruction to obtain asset information to the vehicle-mounted computer, and after receiving the vehicle asset information returned by the vehicle-mounted computer, generates an unsigned authorization file based on the vehicle asset information.

[0060] In step S303, the cloud server sends a signature application request to the signature system and receives the signed authorization file from the signature system.

[0061] In step S304, the OTA program upgrade package and the authorization file are assembled to obtain the OTA upgrade package.

[0062] In the embodiment of the present application, after receiving the component replacement completion message sent by the in-vehicle unit, the cloud server may first create an OTA upgrade task and generate an OTA program upgrade package. Next, the cloud server sends an instruction to obtain asset information to the in-vehicle unit, and after receiving the vehicle asset information returned by the in-vehicle unit, generates an unsigned authorization file based on the vehicle asset information.

[0063] In the embodiment of the present application, the cloud server may use a signature system, such as Public Key Infrastructure (PKI), to sign the generated unsigned authorization file for authentication. In one example, the cloud server may send a signature request to the signature system and receive the signed authorization file from the signature system. Finally, the cloud server assembles the OTA program upgrade package and the authorization file to obtain the OTA upgrade package.

[0064] Figure 4 It is a schematic flowchart of another ECU component replacement and upgrade method provided by the embodiment of the present application. Among them, Figure 4 Steps S401 to S403 in the illustrated embodiment are substantially the same as Figure 2 Steps S201 to S203 in the illustrated embodiment, and will not be elaborated here. As Figure 4 shown, this ECU component replacement and upgrade method further includes the following steps:

[0065] In step S404, in response to determining that the in-vehicle unit has enabled the authorization function, the authorization file in the OTA upgrade package is verified, and after the verification passes, the target ECU is upgraded using the OTA program upgrade package.

[0066] In step S405, in response to determining that the in-vehicle unit has not enabled the authorization function, the target ECU is upgraded using the OTA program upgrade package.

[0067] In the embodiment of the present application, the in-vehicle unit may be configured to have and enable the authorization function, or may not have the authorization function, or the authorization function may not be enabled. At this time, after obtaining the OTA upgrade package, the in-vehicle unit may first determine whether the authorization function of the in-vehicle unit is enabled. If it is determined that the in-vehicle unit has enabled the authorization function, the authorization file in the OTA upgrade package may be verified first, and then the target ECU is upgraded using the OTA program upgrade package after the verification passes. Otherwise, if it is determined that the in-vehicle unit has not enabled the authorization function, the target ECU may be directly upgraded using the OTA program upgrade package.

[0068] In the embodiments of the present application, the vehicle asset information at least includes the identity document (ID) of the in-vehicle computer chip, and at least one of the following: random number, in-vehicle computer version number, and in-vehicle computer eigenvalue. Further, the in-vehicle computer eigenvalue includes at least one of the following: the identity of the system in the in-vehicle computer chip, the identity of the hardware in the in-vehicle computer chip, the identity of the software in the in-vehicle computer chip, and the hash value of the software in the in-vehicle computer chip.

[0069] That is to say, the vehicle asset information can include the in-vehicle computer chip ID, which is bound to the in-vehicle computer chip by the OTA upgrade package, so as to ensure that the target ECU for upgrade flashing is the ECU mounted under the legal in-vehicle computer, and realize the secure flashing upgrade of a single vehicle.

[0070] At the same time, to further improve security, the vehicle asset information can also include one or more of a random number, an in-vehicle computer version number, and an in-vehicle computer eigenvalue. Among them, the random number (Number once, Nonce) can be generated by region, that is, each region corresponds to a Nonce, and the Nonce included in the vehicle asset information can be the Nonce of the area to be upgraded where the target ECU is located.

[0071] Figure 5 It is a schematic diagram of the vehicle asset information included in the authorization document provided by the embodiments of the present application. As Figure 5As shown, the authorization file can be generated based on the chip ID (System on Chip Identity, Socid), software version number of the in-vehicle unit, random number Nonce, and the feature value of the in-vehicle unit. Among them, the feature value of the in-vehicle unit can be determined by the ID, hardware ID, software ID, software version number, or hash value of each item in the Bootroom component, Xloader tool, Fastboot mechanism, TEEOS operating system, Boot process, and system. Among them, Bootroom is a component used to start and load the operating system in an embedded system. It is located inside the chip and is a firmware boot program provided by the hardware. Xloader is a tool used to load or program specific hardware and is used to perform specific tasks during system startup or configuration. The Fastboot mechanism is a mechanism for fast startup or flashing, which is used to quickly load a new firmware or operating system image into the domain controller in a specific way during development or maintenance. TEEOS is an operating system running on a hardware security module, which provides a protected execution environment for sensitive data and critical operations. The Boot startup process involves a series of steps from system power-on to the complete loading and running of the operating system or firmware. The Boot process includes hardware initialization, memory configuration, device detection, and loading necessary drivers, etc. The system refers to the entire system of the in-vehicle unit or the entire system of the domain controller where the target ECU is located, which includes hardware, software, and their interactions. In one example, the vehicle asset information in the authorization file can include the hash value of boot, Hash(boot), the hash value of the kernel, Hash(Kernel), and other hash values.

[0072] Furthermore, in addition to including vehicle asset information, the authorization file can also include a signature and a key chain. Among them, the signature and key chain are obtained by the PKI server signing and encrypting the unsigned authorization file.

[0073] In the embodiment of the present application, when the in-vehicle unit verifies the authorization file in the OTA upgrade package, it can first verify the integrity of the authorization file in the OTA upgrade package. When it is determined that the authorization file is complete, it further verifies the vehicle asset information, signature, and key chain in the authorization file. When it is determined that the vehicle asset information in the authorization file is consistent with the vehicle asset information of the vehicle where the in-vehicle unit is located, the signature is consistent, and the key chain is correct, the verification of the authorization file in the OTA upgrade package passes.

[0074] Figure 6 It is a schematic flowchart of another ECU replacement and upgrade method provided by the embodiment of the present application. Among them, Figure 6 Steps S601 to S602 in the shown embodiment are basically the same as Figure 2 Steps S201 to S202 in the shown embodiment,Figure 6 Step S604 in the illustrated embodiment is substantially the same as Figure 2 step S204 in the illustrated embodiment, and will not be elaborated herein. As Figure 6 shown, the ECU replacement and upgrade method further includes the following steps:

[0075] In step S603, in response to receiving an OTA upgrade instruction sent by the Over-the-Air (OTA) management unit, obtain an OTA upgrade package from the cloud server.

[0076] Among them, the OTA upgrade package includes at least an OTA program upgrade package and an authorization file.

[0077] Further, the OTA upgrade instruction is sent by the OTA management unit to the in-vehicle unit when it receives an OTA upgrade instruction sent by the cloud server and determines that the target ECU meets the upgrade conditions.

[0078] In the embodiment of the present application, after the in-vehicle unit sends vehicle asset information to the cloud server, it can obtain an OTA upgrade package from the cloud server when receiving an OTA upgrade instruction sent by the OTA management unit.

[0079] That is to say, after the cloud server receives the vehicle asset information, it can generate an authorization file according to the vehicle asset information, sign the authorization file through PKI interaction, and then assemble the generated OTA program upgrade package of the target ECU and the signed authorization file together to obtain an OTA upgrade package. The cloud server can send an upgrade instruction to the OTA management unit and send the OTA upgrade package along with the upgrade instruction to the OTA management unit.

[0080] In the embodiment of the present application, the OTA management unit can determine whether the target ECU currently meets the upgrade conditions, such as determining whether the target ECU is idle, estimating the upgrade time based on the size of the OTA upgrade package, and determining whether the current remaining power of the target ECU can complete the upgrade. When the OTA management unit determines that the current conditions are met, it sends the OTA upgrade package to the target ECU and sends an OTA upgrade instruction to the target ECU, so that the target ECU downloads the OTA program upgrade package from the cloud server according to the URL address in the OTA upgrade package.

[0081] In the embodiment of the present application, the in-vehicle unit receives an OTA upgrade instruction sent by the OTA management unit, and the network address of the OTA program upgrade package, such as RUL, may also be sent simultaneously with the OTA upgrade instruction. The in-vehicle unit can first verify the authorization file in the OTA upgrade package. After the authorization file is verified, the in-vehicle unit downloads the OTA program upgrade package of the OTA upgrade package from the network address. Finally, the in-vehicle unit uses the downloaded OTA program upgrade package to upgrade and rewrite the target ECU.

[0082] Figure 7 It is a schematic flowchart of yet another ECU replacement and upgrade method provided by an embodiment of the present application. As Figure 7 shown, after the replacement of the target ECU is completed, the cloud server generates an OTA upgrade package, which includes an OTA program upgrade package and an authorization file. The authorization file further includes vehicle asset information, a signature, and a key chain. The cloud server sends the OTA upgrade package to the CDC or the TBOX. When the OTA management unit determines that the upgrade condition is met, it sends a start upgrade and flash instruction to the CDC or the TBOX. After receiving the start upgrade and flash instruction, the CDC or the TBOX uses the OTA upgrade package received from the cloud server to perform upgrade and flash on the target ECU under it.

[0083] Figure 8 It is a schematic flowchart of another ECU replacement and upgrade method provided by an embodiment of the present application. As Figure 8 shown, after the replacement of the target ECU is completed, the cloud server creates an upgrade task for the template ECU, generates an OTA program upgrade package for the template ECU, and sends an instruction to obtain asset information to the OTA management unit. The OTA management unit forwards the instruction to obtain asset information to the CDC or the TBOX. The CDC or the TBOX returns data including the asset information of the vehicle where it is located to the OTA management unit, and the OTA management unit forwards this data to the cloud server. The cloud server generates an unsigned authorization file based on the received vehicle asset information, and then sends a signature request for the authorization file to the signature system. The signature system signs the unsigned authorization file and returns the signed authorization file to the cloud server.

[0084] After receiving the signed authorization file, the cloud server sends an upgrade instruction to the OTA management unit, and at the same time sends the URL of the OTA program upgrade package and the authorization file data stream to the OTA management unit. The OTA management unit determines the upgrade condition. When the upgrade condition is met, it forwards the upgrade instruction, the URL of the OTA program upgrade package, and the authorization file data stream to the target ECU. The target ECU can use the URL of the OTA program upgrade package to download the OTA program upgrade package from the cloud server and verify the authorization file and the upgrade package. Among them, the verification method of the authorization file is as described above, and the verification method of the upgrade package refers to the verification of the OTA upgrade package in the related art, which will not be elaborated here.

[0085] If the verification passes, the CDC or the TBOX can perform target ECU flashing according to the flashing task. The target ECU can be the CDC or the TBOX itself, or an ECU component under it. When flashing, the authorization file and the OTA program upgrade package can be refreshed first, then the flashing is performed, and finally the result is returned. Further, the flashing result can also be returned to the OTA management unit and the cloud server in sequence.

[0086] That is to say, in the OTA scenario of the authorization file, it can be carried out according to the conventional OTA service process first. If the OTA upgrade components this time are CDC or TBOX, or the ECU components under CDC or TBOX, after the cloud server generates the upgrade package, it can send a command to obtain asset information to obtain the asset information of the whole vehicle, where the asset information must include the Socid of CDC or TBOX, the Nonce of the area to be upgraded, and other contents.

[0087] The cloud server can generate an unsigned authorization file based on the vehicle asset information returned by CDC or TBOX and apply for signature from the signature system. After the cloud server obtains the signed authorization file returned by the signature system, it should add the content of the authorization file after the URL of the corresponding upgrade package sent.

[0088] The cloud server sends the upgrade package URL and the authorization file to the OTA management unit (OTA Manager), and then the OTA Manager transfers the upgrade package URL and the authorization file to CDC or TBOX. After CDC or TBOX obtains the upgrade package and the authorization file, it should confirm whether the authorization function has been enabled. If it has been enabled, it verifies the authorization file and the upgrade package to ensure that they match. If the verification fails, it can record the Diagnostic Trouble Code (DTC) to indicate the reason for the error and cannot continue with the flashing; if the verification passes, it performs subsequent operations. On the other hand, if the authorization function has not been enabled, it does not process the authorization file and directly performs the flashing.

[0089] After the verification passes, CDC or TBOX executes the flashing process on the target ECU. After the flashing is completed, it can also generate a snapshot of the vehicle asset information according to the OTA process.

[0090] That is to say, in order to protect the core components in the vehicle and prevent black production vehicle flashing and privileged version vehicle flashing, the ECU replacement and upgrade method provided in the embodiment of this application adds the configuration of domain control startup and binds it to the authorization file. The domain control needs to compare its own information (Socid, Nonce, version number, feature value, etc.) with the content of the authorization file, and the program can start only after the comparison is correct. Further, in the OTA scenario, when upgrading the ECU under the domain control, the upgrade package sent contains two parts of content. One part is the ECU program upgrade package, and the other part is the authorization file. The domain control needs to verify the information (Socid, ECU upgrade package hash, etc.) of the upgrade package, and only after the verification passes can the domain control upgrade the ECU under it.

[0091] By adopting the technical solution of the embodiment of the present application, when replacing parts through OTA upgrade, the flashing package is bound to the chip ID to achieve secure flashing and upgrading of the bicycle. At the same time, the OTA platform and the generation of encryption services achieve one authorization for each vehicle, improving the flashing efficiency and traceability. Further, this solution can effectively avoid black production vehicle flashing and privileged version vehicle flashing, reduce the risk of maintenance, and protect the company's rights and interests; standardize and automate the vehicle part replacement process, improving the user experience; ensure data security and system stability, and reduce the risk of after-sales intervention.

[0092] Any combination of the above optional technical solutions can form an optional embodiment of the present application, which will not be elaborated here one by one.

[0093] The following is an embodiment of the device of the present application, which can be used to execute the method embodiment of the present application. For details not disclosed in the device embodiment of the present application, please refer to the method embodiment of the present application.

[0094] Figure 9 It is a schematic diagram of an ECU part replacement and upgrade device provided by an embodiment of the present application. As Figure 9 shown, the ECU part replacement and upgrade device includes:

[0095] A sending module 901, configured to, in response to the completion of replacement of a target ECU in a vehicle, send a replacement completion message from the vehicle head unit to the cloud server.

[0096] The sending module 901 is further configured to, in response to receiving an instruction for obtaining asset information sent by the cloud server, send the asset information of the vehicle where the vehicle head unit is located to the cloud server.

[0097] A receiving module 902, configured to obtain an OTA upgrade package from the cloud server. The OTA upgrade package includes at least an OTA program upgrade package and an authorization file. The OTA upgrade package is generated by the cloud server after receiving the replacement completion message and sent to the vehicle head unit. The authorization file is determined by the cloud server according to the vehicle asset information obtained from the vehicle head unit, and the authorization file is an authorized file signed using a signature system.

[0098] An upgrade module 903, configured to, in response to successful verification of the authorization file in the OTA upgrade package, use the OTA program upgrade package to upgrade the target ECU.

[0099] According to the technical solution provided by the embodiment of the present application, after the replacement of the target ECU in the vehicle is completed, the vehicle head unit notifies the cloud server, so that the cloud server generates an OTA upgrade package including an OTA program upgrade package and an authorization file after receiving the replacement completion notification. The authorization file is determined by the cloud server based on the vehicle asset information obtained from the vehicle head unit and includes a signature. After the vehicle head unit verifies the authorization file, it uses the OTA program upgrade package to upgrade the target ECU, thereby avoiding the situation that the target ECU can still be normally upgraded after being replaced with an illegal ECU part, realizing the binding of the OTA upgrade package and the vehicle asset information, ensuring the secure flashing upgrade of a single vehicle, and improving the flashing efficiency and traceability.

[0100] In the embodiment of the present application, the cloud server generates the OTA upgrade package in the following manner: in response to receiving the replacement completion message sent by the vehicle head unit, the cloud server creates an OTA upgrade task and generates an OTA program upgrade package; the cloud server sends an instruction to obtain asset information to the vehicle head unit, and after receiving the vehicle asset information returned by the vehicle head unit, generates an unsigned authorization file based on the vehicle asset information; the cloud server sends a signature application request to the signature system and receives the signed authorization file from the signature system; the OTA program upgrade package and the authorization file are assembled to obtain the OTA upgrade package.

[0101] In the embodiment of the present application, the upgrade module 903 is further configured to, in response to determining that the vehicle head unit has enabled the authorization function, verify the authorization file in the OTA upgrade package, and use the OTA program upgrade package to upgrade the target ECU after the verification passes; in response to determining that the vehicle head unit has not enabled the authorization function, use the OTA program upgrade package to upgrade the target ECU.

[0102] In the embodiment of the present application, the vehicle asset information at least includes the vehicle head unit chip identification ID and at least one of the following: a random number, the vehicle head unit version number, and the vehicle head unit feature value; wherein, the vehicle head unit feature value includes at least one of the following: the identification of the system in the vehicle head unit chip, the identification of the hardware in the vehicle head unit chip, the identification of the software in the vehicle head unit chip, the hash value of the system in the vehicle head unit chip, the hash value of the hardware in the vehicle head unit chip, and the hash value of the software in the vehicle head unit chip; the authorization file includes the vehicle asset information, the signature, and the key chain.

[0103] In the embodiment of the present application, passing the verification of the authorization file in the OTA upgrade package includes: passing the integrity verification of the authorization file in the OTA upgrade package; and passing the verification of the vehicle asset information, the signature, and the key chain in the authorization file in the OTA upgrade package.

[0104] In the embodiment of the present application, the receiving module 902 is further configured to obtain an OTA upgrade package from a cloud server in response to receiving an OTA upgrade instruction issued by an OTA management unit of the over-the-air download technology. The OTA upgrade package includes at least an OTA program upgrade package and an authorization file. The OTA upgrade instruction is issued by the OTA management unit to the in-vehicle unit when the OTA management unit receives an OTA upgrade instruction issued by the cloud server and determines that the target ECU meets the upgrade conditions.

[0105] In the embodiment of the present application, the receiving module 902 is further configured to receive an OTA upgrade instruction and an OTA upgrade package issued by an OTA management unit of the over-the-air download technology. The OTA upgrade package includes a network address of an OTA program upgrade package and an authorization file. In response to passing the verification of the authorization file in the OTA upgrade package, the in-vehicle unit downloads the OTA program upgrade package from the network address and uses the OTA program upgrade package to upgrade the target ECU.

[0106] It should be understood that the sequence numbers of the steps in the above embodiments do not represent the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0107] Figure 10 is a schematic diagram of an electronic device provided by an embodiment of the present application. As Figure 10 shown, the electronic device 10 in this embodiment includes: a processor 1001, a memory 1002, and a computer program 1003 stored in the memory 1002 and executable on the processor 1001. When the processor 1001 executes the computer program 1003, the steps in the above-mentioned method embodiments are implemented. Alternatively, when the processor 1001 executes the computer program 1003, the functions of each module / unit in the above-mentioned device embodiments are implemented.

[0108] The electronic device 10 may be a desktop computer, a notebook, a palm computer, a cloud server, and other electronic devices. The electronic device 10 may include, but is not limited to, the processor 1001 and the memory 1002. Those skilled in the art can understand that Figure 10 merely examples of the electronic device 10, which do not constitute a limitation to the electronic device 10, and may include more or fewer components than shown in the figure, or different components.

[0109] The processor 1001 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.

[0110] The memory 1002 may be an internal storage unit of the electronic device 10. For example, the hard disk or memory of the electronic device 10. The memory 1002 may also be an external storage device of the electronic device 10. For example, a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the electronic device 10. The memory 1002 may also include both an internal storage unit and an external storage device of the electronic device 10. The memory 1002 is used to store computer programs and other programs and data required by the electronic device.

[0111] Those skilled in the art can clearly understand that, for the convenience and simplicity of description, only the above division of each functional unit and module is used as an example. In actual applications, the above functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiments can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.

[0112] When the integrated module / unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, to implement all or part of the processes in the above-described embodiment methods of the present application, it can also be completed by instructing relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above-described various method embodiments can be implemented. The computer program can include computer program code, and the computer program code can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disc, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium, etc.

[0113] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the various embodiments of the present application, and should all be included in the protection scope of the present application.

Claims

1. A vehicle electronic control unit ECU replacement and upgrading method, characterized in that: The method is executed by a vehicle computer, and the method includes: In response to the target ECU in the vehicle being replaced, the vehicle computer sends a replacement completion message to the cloud server; In response to receiving an instruction to obtain asset information sent by a cloud server, sending asset information of the vehicle where the vehicle computer is located to the cloud server; In response to receiving an OTA upgrade instruction issued by the space download technology OTA management unit, an OTA upgrade package is obtained from the cloud server, the OTA upgrade package at least including an OTA program upgrade package and an authorization file, the OTA upgrade package is generated by the cloud server after receiving the replacement completion message and sent to the vehicle computer, the authorization file is determined by the cloud server according to the vehicle asset information obtained from the vehicle computer, and the authorization file is an authorization file signed by a signature system; In response to verifying that the authorization file in the OTA upgrade package is successful, using the OTA program upgrade package to upgrade the target ECU; The cloud server generates an OTA upgrade package in the following manner: In response to receiving the replacement completion message sent by the vehicle computer, the cloud server creates an OTA upgrade task and generates an OTA program upgrade package; The cloud server sends an asset information acquisition instruction to the vehicle computer, and after receiving the vehicle asset information returned by the vehicle computer, generates an unsigned authorization file based on the vehicle asset information; The cloud server sends a signature application request to the signature system, and receives a signed authorization document from the signature system; The OTA program upgrade package and the authorization file are assembled to obtain the OTA upgrade package.

2. The method according to claim 1, characterized in that After obtaining the OTA upgrade package, the method further includes: In response to determining that the vehicle computer has turned on the authorization function, verifying the authorization file in the OTA upgrade package, and using the OTA program upgrade package to upgrade the target ECU after the verification passes; In response to determining that the vehicle computer does not enable the authorization function, the target ECU is upgraded using the OTA program upgrade package.

3. The method according to any one of claims 1 to 2, characterized in that: The vehicle asset information includes at least the vehicle chip identification ID and at least one of the following: Random number, vehicle computer version number and vehicle computer characteristic value; The vehicle computer characteristic value includes at least one of the following: The identification of the system in the vehicle chip, the identification of the hardware in the vehicle chip, the identification of the software in the vehicle chip, the hash value of the system in the vehicle chip, the hash value of the hardware in the vehicle chip, and the hash value of the software in the vehicle chip; The authorization document includes vehicle asset information, a signature, and a key chain.

4. The method according to claim 3, characterized in that The verification of the authorization file in the OTA upgrade package is passed, including: The integrity verification of the authorization file in the OTA upgrade package is passed; and The vehicle asset information, signature and key chain in the authorization file in the OTA upgrade package are verified.

5. The method according to claim 1, characterized in that: The OTA upgrade instruction is sent to the vehicle computer by the OTA management unit after receiving the OTA upgrade instruction sent by the cloud server and determining that the target ECU meets the upgrade conditions.

6. The method according to claim 5, characterized in that After sending the vehicle asset information to the cloud server, the method further includes: Receive an OTA upgrade instruction and an OTA upgrade package issued by a space download technology OTA management unit, wherein the OTA upgrade package includes an OTA program upgrade package network address and an authorization file; In response to the authorization file in the OTA upgrade package being verified successfully, the vehicle computer downloads the OTA program upgrade package from the network address and uses the OTA program upgrade package to upgrade the target ECU.

7. A vehicle electronic control unit ECU replacement and upgrading device, characterized in that: include: The sending module is configured to respond to the target ECU in the vehicle being replaced and the vehicle computer sending a replacement completion message to the cloud server; The sending module is further configured to send the asset information of the vehicle where the vehicle computer is located to the cloud server in response to receiving the asset information acquisition instruction sent by the cloud server; A receiving module, configured to obtain an OTA upgrade package from the cloud server in response to receiving an OTA upgrade instruction issued by the space download technology OTA management unit, wherein the OTA upgrade package at least includes an OTA program upgrade package and an authorization file, the OTA upgrade package is generated by the cloud server after receiving the replacement completion message and sent to the vehicle computer, the authorization file is determined by the cloud server according to the vehicle asset information obtained from the vehicle computer, and the authorization file is an authorization file signed by a signature system; An upgrade module is configured to upgrade the target ECU using the OTA program upgrade package in response to verification of the authorization file in the OTA upgrade package; The cloud server generates an OTA upgrade package in the following manner: In response to receiving the replacement completion message sent by the vehicle computer, the cloud server creates an OTA upgrade task and generates an OTA program upgrade package; The cloud server sends an asset information acquisition instruction to the vehicle computer, and after receiving the vehicle asset information returned by the vehicle computer, generates an unsigned authorization file based on the vehicle asset information; The cloud server sends a signature application request to the signature system, and receives a signed authorization document from the signature system; The OTA program upgrade package and the authorization file are assembled to obtain the OTA upgrade package.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Vehicle verification method, related device and system

    CN117195216A