Remote firmware upgrade method, device, equipment, storage medium and program product

By controlling the vehicle to enter a set state for firmware upgrade under the conditions of vehicle power-on and battery status, the safety and reliability issues in the remote upgrade process are resolved, ensuring that the upgrade process does not interfere with the normal operation of the vehicle.

CN118690372BActive Publication Date: 2025-11-04CHERY NEW ENERGY AUTOMOBILE TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410762839.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-13
Publication Date
2025-11-04
Estimated Expiration
2044-06-13

AI Technical Summary

Technical Problem

Existing automotive remote firmware upgrade technology has security and reliability issues, especially since upgrading while the vehicle is in use or charging may interfere with normal operation or cause safety hazards.

Method used

By acquiring vehicle power status information and battery status information, firmware upgrades are only performed under specified conditions, including key position status, power battery charging information, and battery voltage, thereby controlling the vehicle to enter an unusable state for the upgrade.

Benefits of technology

While ensuring vehicle safety, we provide reliable OTA firmware upgrade services to avoid interference with normal vehicle operation during the upgrade process, thereby improving system security and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118690372B_ABST
    Figure CN118690372B_ABST
Patent Text Reader

Abstract

The application relates to a remote firmware upgrading method, device, equipment, storage medium and program product, and relates to the technical field of intelligent automobiles. The method is executed by a control system of a vehicle, and the method comprises the following steps: receiving an over-the-air (OTA) notification; the OTA notification is used for indicating that there is a new firmware upgrading item; acquiring vehicle power-on state information and battery state information; the vehicle power-on state information is used for indicating whether the vehicle is in a use state; the battery state information is used for indicating the states of a power battery and a storage battery of the vehicle; in the case that the vehicle power-on state information meets a first specified condition and the battery state information meets a second specified condition, the vehicle is controlled to execute a firmware upgrading item corresponding to the OTA notification. The application can provide OTA firmware upgrading services for the vehicle while ensuring that the vehicle has no safety hazards, and the reliability and safety of the system are improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of intelligent automobiles, and in particular to a remote firmware upgrade method and device, equipment, a storage medium and a program product. BACKGROUND

[0002] With the development trend of the "new four modernizations" of the automobile industry, namely, electrification, intelligentization, networking and sharing, consumers' expectations for automobiles have far exceeded the traditional category of transportation tools.

[0003] In related technologies, automobile firmware over the air (FOTA) upgrade refers to a technology of remotely updating the firmware of a vehicle through a wireless network. FOTA upgrade changes the traditional automobile after-sales maintenance mode, so that the automobile can evolve continuously through remote software updates like a smart phone.

[0004] However, since the automobile contains multiple electronic control units, and the automobile is a high-speed transportation tool, it is crucial to ensure the safety of FOTA upgrade. SUMMARY

[0005] The present application provides a remote firmware upgrade method, device, equipment, storage medium and program product, which provides OTA firmware upgrade service for the vehicle while ensuring that the vehicle has no safety hazards, and improves the reliability and safety of the system; the technical solution content is as follows:

[0006] According to an aspect of the present application, a remote firmware upgrade method is provided, the method is executed by a control system of a vehicle, and the method comprises:

[0007] receiving an over-the-air (OTA) notification; the OTA notification is used to indicate that there is a new firmware upgrade item;

[0008] obtaining vehicle power-on state information and battery state information; the vehicle power-on state information is used to indicate whether the vehicle is in a use state; the battery state information is used to indicate the state of the power battery and the storage battery of the vehicle;

[0009] in a case where the vehicle power-on state information meets a first specified condition and the battery state information meets a second specified condition, controlling the vehicle to execute the firmware upgrade item corresponding to the OTA notification.

[0010] According to an aspect of the present application, a remote firmware upgrade device is provided, the device comprises:

[0011] a receiving module, configured to receive an over-the-air (OTA) notification; the OTA notification is used to indicate that there is a new firmware upgrade item;

[0012] an obtaining module, configured to obtain vehicle power-on state information and battery state information; the vehicle power-on state information is used to indicate whether the vehicle is in use; the battery state information is used to indicate states of a power battery and a storage battery of the vehicle;

[0013] a control module, configured to control the vehicle to perform the firmware upgrade item corresponding to the OTA notification when the vehicle power-on state information meets a first specified condition and the battery state information meets a second specified condition.

[0014] In some embodiments, the vehicle power-on state information comprises key gear state information of the vehicle, and the first specified condition comprises that the key gear of the vehicle is in an OFF gear;

[0015] The battery state information comprises charging information of the power battery and voltage information of the storage battery, and the second specified condition comprises that the power battery is in an uncharged state and the voltage of the storage battery is greater than a first specified threshold.

[0016] In some embodiments, the control module is configured to control the vehicle to be powered on and enter a set state when the vehicle power-on state information meets the first specified condition and the battery state information meets the second specified condition; in the set state, the vehicle cannot be used.

[0017] a control module, configured to control the vehicle to perform the firmware upgrade item corresponding to the OTA notification when the vehicle enters the set state.

[0018] In some embodiments, the apparatus further comprises an archive information obtaining module, configured to obtain vehicle archive information; the vehicle archive information is used to indicate whether the vehicle has been sold; display request information when the vehicle has been sold; the request information is used to request a user whether to agree to upgrade;

[0019] The obtaining module is configured to obtain vehicle power-on state information and battery state information when a user instruction of agreeing to upgrade is received.

[0020] The control module is configured to control the vehicle to perform the firmware upgrade item corresponding to the OTA notification when the vehicle power-on state information meets a third specified condition and the battery state information meets a fourth specified condition.

[0021] In some embodiments, the vehicle power-on state information comprises key state information of the vehicle, the third specified condition comprises that the key state of the vehicle is in an ON state; the battery state information comprises charging information of the power battery and voltage information of the storage battery, and the fourth specified condition comprises that the power battery is in an uncharged state and the voltage of the storage battery is greater than a second specified threshold.

[0022] In some embodiments, the control module is configured to control the vehicle to enter a set state when the vehicle power-on state information satisfies a third specified condition and the battery state information satisfies a fourth specified condition; in the set state, the vehicle cannot be used.

[0023] The control module is configured to control the vehicle to perform the firmware upgrade item corresponding to the OTA notification when the vehicle enters the set state.

[0024] According to another aspect of the present application, a computer device is provided, which comprises a processor and a memory, the memory storing at least one computer instruction, the at least one computer instruction being loaded and executed by the processor to implement the remote firmware upgrade method according to the above aspect.

[0025] According to another aspect of the present application, a computer readable storage medium is provided, which stores at least one computer instruction, the at least one computer instruction being loaded and executed by a processor to implement the remote firmware upgrade method according to the above aspect.

[0026] According to another aspect of the present application, a computer program product is provided, which comprises computer instructions stored in a computer readable storage medium, the computer instructions being read and executed by a processor from the computer readable storage medium to implement the remote firmware upgrade method according to the above aspect.

[0027] The technical scheme provided by the embodiments of the present application can have the following beneficial effects:

[0028] Before the vehicle performs the upgrading task, vehicle power-on state information and battery state information can be acquired, and the upgrading task can be performed only when the vehicle power-on state information and the battery state information both meet corresponding conditions; wherein the vehicle power-on state information can correspond to a use state of the vehicle, and the battery state information can correspond to a state of a power battery and a storage battery of the vehicle; since the upgrading process needs to consume a certain time length, the state of the power battery and the storage battery of the vehicle needs to be in a necessary state, and meanwhile, the upgrading process can interfere with the normal operation of the vehicle, so the use state of the vehicle also needs to be in a necessary state; the above scheme can provide OTA firmware upgrading service for the vehicle while ensuring that the vehicle has no safety hazards, thereby improving the reliability and safety of the system. BRIEF DESCRIPTION OF DRAWINGS

[0029] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed to be used in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can also be obtained by those skilled in the art without creative labor.

[0030] Figure 1 is a schematic diagram of an implementation environment of a remote firmware upgrading method provided by an exemplary embodiment of the present application;

[0031] Figure 2 is a flowchart of a remote firmware upgrading method provided by an exemplary embodiment of the present application;

[0032] Figure 3 is a flowchart of a remote firmware upgrading method provided by an exemplary embodiment of the present application;

[0033] Figure 4 is a background flowchart of a FOTA upgrading scene test strategy method on a new energy vehicle provided by an exemplary embodiment of the present application;

[0034] Figure 5 is a block diagram of a remote firmware upgrading device shown by an exemplary embodiment of the present application;

[0035] Figure 6 is a structural block diagram of a computer device shown by an exemplary embodiment of the present application.

[0036] The drawings herein are incorporated into the specification and form part of the specification, show embodiments consistent with the present application, and together with the specification serve to explain the principles of the present application. DETAILED DESCRIPTION

[0037] For the purposes of the present application, the term "coupled" is used to describe both an indirect coupling and a direct coupling between two entities, where coupling includes use of one or more intermediate couples between two entities. Coupling can be described as a relationship where entities interact with each other (e.g., messaging, memory access, component interaction, adding heat to a system, etc.), and can also be described as an electrical, mechanical, or fluidic connection between two entities as well as any combination of these connections.

[0038] The exemplary embodiments will be described in detail below with reference to the attached drawings.

[0039] The terminology used in the present disclosure is for the purpose of describing particular embodiments only and is not intended to be limiting of the present disclosure. As used in the description of the present disclosure and the appended claims, the singular forms "a", "an" and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise.

[0040] In the embodiments of the present application, the user information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of related data need to comply with relevant laws, regulations and standards of relevant countries and regions. For example, the attack operation and other object behaviors involved in the present application are obtained under full authorization.

[0041] It should be understood that although the terms first, second, etc. can be employed in this disclosure to describe various information, such information should not be limited to these terms. These terms are only used to differentiate one piece of information from another piece of information of the same type. For example, a first parameter can also be referred to as a second parameter without departing from the scope of the present disclosure, and similarly, a second parameter can also be referred to as a first parameter. Depending on the context, the word "if" as used herein can be interpreted as "when" or "upon" or "in response to determining".

[0042] Some terms related to the present application are introduced below:

[0043] 1) Intelligent car: It is the product of the deep integration of the automobile industry and information technology. It realizes partial or complete automatic driving function by integrating advanced sensors, controllers, actuators and other devices, and using information communication, Internet, big data, cloud computing, artificial intelligence and other frontier technologies. Intelligent car is not only a new type of high-tech transportation tool, but also an intelligent mobile space and application terminal. Its main features and capabilities include:

[0044] Human-machine interaction: Provide more intelligent and convenient human-vehicle interaction interfaces such as voice recognition and gesture control, so that drivers and passengers can communicate with the vehicle more naturally and enjoy personalized services.

[0045] Vehicle networking function: Through vehicle wireless communication technology (V2X), intelligent vehicles can exchange information with other vehicles, traffic infrastructure, Internet service platforms, etc., to improve traffic efficiency and enhance safety.

[0046] Safety protection: Integrate various active safety systems such as collision warning, automatic emergency braking, lane keeping assistance, etc., to significantly improve driving safety.

[0047] High efficiency and environmental protection: Especially for new energy intelligent vehicles, using electric, hybrid power and other new energy systems to reduce emissions and promote environmental protection.

[0048] Continuous upgrade: Support OTA technology to remotely update the software and part of the firmware of the vehicle to ensure the continuous evolution and optimization of the vehicle function.

[0049] 2) Over The Air (OTA): It can be understood as a kind of remote wireless upgrade technology. "Over the air" refers to remote wireless means, which means remote management of vehicle applications through mobile communication air interface.

[0050] For example, a typical OTA system framework includes three basic elements, namely the OTA platform in the cloud, the OTA master control on the vehicle side, and the OTA object; among them, the OTA cloud platform is responsible for OTA upgrade package management, vehicle management and OTA release functions, the vehicle side OTA master control is responsible for downloading the upgrade package from the OTA cloud platform and writing it to the target electronic control unit (ECU), and the OTA upgrade object is the main body of the final software writing, which receives software from the master control and completes its own software update.

[0051] 3) Remote firmware upgrade (FOTA): refers to the comprehensive upgrade of vehicle bottom algorithm to top application. Under the premise of not changing the original accessories of the vehicle, the device is upgraded by downloading and writing new firmware program remotely. FOTA includes the upgrade of drivers, systems, functions, applications, etc., and has nothing to do with hardware replacement. FOTA involves the core system of the vehicle, including but not limited to the control system of core components such as the power control system, chassis electronic system, automatic driving system and body control system, which can change the charging and discharging, kinetic energy recovery, acceleration performance, auxiliary driving system logic and other experiences related to deep driving control. In theory, all electronic control units (ECUs) that support firmware updates can be included in the FOTA range.

[0052] In the related art, when the user is driving and there is a system defect and a real vehicle failure, the solution is usually that the automobile manufacturer initiates a recall program, and the user returns to the factory for unified upgrade of the system after receiving the recall program. The automobile manufacturer recalls a vehicle, and the vehicle owner needs to send the vehicle to the 4S store, some need to issue a U disk for upgrade, and some need to be operated manually. The overall recall cost is very high, and the cost of important components will be even higher.

[0053] FOTA technology can repair defects through data packets in a remote and fast manner, greatly avoiding the risks brought by continuous recalls. However, there may be various problems in the current real vehicle FOTA upgrade. In order to ensure the functional safety during the upgrade, the developer needs to develop a very detailed upgrade plan, compatibility test and verification, require the controller to support AB partition rollback strategy, safety verification, record upgrade log in real time, etc. The embodiments of the present application can avoid safety problems that may occur during the upgrade process by controlling the vehicle upgrade conditions during the automobile FOTA upgrade process.

[0054] Please refer to Figure 1 , which shows a schematic diagram of an implementation environment of a remote firmware upgrade method provided by an example embodiment of the present application. As Figure 1 shown, the implementation environment can include a terminal device 110 and a server 120. The terminal device 110 and the server 120 can be directly or indirectly connected through a communication network (wired or wireless communication method), which is not limited in the present application.

[0055] Optionally, the terminal device 110 can be a control system of a smart car, but is not limited thereto. The terminal device 110 can install and run a client of a target application program, which can be an application program with information acquisition and remote firmware upgrade functions, such as a T-BOX (T-BOX). The form of the target application program is not limited in the present application.

[0056] Optionally, the server 120 can be a stand-alone physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services, a cloud database, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDN), and basic cloud computing services such as big data and artificial intelligence platforms. The cloud server of the big data and artificial intelligence platform can provide artificial intelligence cloud services. The server 120 can be a background server of the target application program, used to provide background services for the client of the target application program, such as an OTA cloud platform, an FOTA cloud management system, and the like.

[0057] For example, when there is a new firmware upgrade project for the vehicle, the server 120 sends an OTA notification to the terminal device 110, and the terminal device 110 receives the OTA notification, which indicates that there is a new firmware upgrade project for the corresponding vehicle. The terminal device 110 can obtain vehicle power-on state information and battery state information. The vehicle power-on state information indicates whether the vehicle is in use, and the battery state information indicates the state of the power battery and the storage battery of the vehicle. Accordingly, the terminal device 110 can send the vehicle power-on state information and the battery state information to the server 120. The server 120 determines whether the vehicle power-on state information satisfies a first specified condition and whether the battery state information satisfies a second specified condition, and sends the determination results to the terminal device 110. When the vehicle power-on state information satisfies the first specified condition and the battery state information satisfies the second specified condition, the server 120 creates an upgrade strategy for the corresponding vehicle according to the upgrade package, forms an upgrade task, and sends the upgrade task to the terminal device 110. Accordingly, the terminal device 110 receives the upgrade task and controls the vehicle to perform the firmware upgrade project corresponding to the OTA notification.

[0058] Please refer to Figure 2 , which shows a flowchart of a remote firmware upgrade method provided by an exemplary embodiment of the present application. The method is performed by a control system of a vehicle. Optionally, the control system can be Figure 1 , as shown. The vehicle is an intelligent automobile, as shown in Figure 2 . The method can include steps 210, 220, and 230.

[0059] Step 210: receiving an over-the-air (OTA) notification. The OTA notification indicates that there is a new firmware upgrade project.

[0060] The receiving of the OTA notification can be that the control system of the smart vehicle receives a specified signal (or a specified message) through a mobile network or Wi-Fi, which informs the control system of the smart vehicle that there is a new firmware upgrade project available. For example, the process of receiving the OTA notification can be automatic, and once the control system of the smart vehicle is connected to the Internet, it will periodically check the manufacturer's server to see if there is a new firmware version for the smart vehicle.

[0061] For example, the OTA notification can include brief information about the firmware upgrade project, such as the version number of the new firmware, the upgrade size, the upgrade description (such as improved functions, fixed vulnerabilities, etc.), and whether it needs to be upgraded immediately or can be selected at a more appropriate time.

[0062] For example, the user can receive the OTA notification through the notification bar, pop-up window or specified application interface of the smart vehicle.

[0063] In the embodiments of the present application, the firmware is pushed by the OTA method, so that the user does not need to send the vehicle to the service center, and the related equipment of the vehicle can be kept up to date, and the latest functions and services can be enjoyed.

[0064] Step 220: Obtain vehicle power-on state information and battery state information; the vehicle power-on state information is used to indicate whether the vehicle is in use; the battery state information is used to indicate the state of the power battery and the storage battery of the vehicle.

[0065] The use state can include driving state, navigation state, vehicle entertainment state, etc.

[0066] For example, the control system can obtain the vehicle power-on state information and the battery state information through the internal network of the vehicle (such as the controller area network CAN bus).

[0067] The control system can monitor the vehicle power-on state information through the power management system (PMS), including the key switch state (such as OFF or ON). For example, when the key is inserted and turned to the corresponding position, or the user presses the start button, or the user unlocks and starts the vehicle through the remote control, the PMS will receive the signal and determine that the vehicle enters the power-on or use state.

[0068] The control system can monitor and manage the power battery pack through a battery management system (BMS). For example, the BMS continuously monitors the voltage, current, temperature, and other parameters of the battery through sensors connected to each battery module, evaluates the state of charge (SOC), state of health (SOH), and predicts the range of the battery, and other battery state information.

[0069] The control system can monitor the voltage of the battery in real time through the BMS or sensors directly connected to the battery. For example, a voltage that is too low can indicate that the battery is not fully charged or is aging, and an abnormally high voltage can mean that there is a problem with the charging system. For example, when an abnormal battery state is detected, the control system can alert the user through the dashboard warning light or the vehicle information system, indicating that the battery needs to be checked or replaced.

[0070] As the battery ages, the internal resistance usually gradually increases. Therefore, by regularly measuring the change in internal resistance of the battery, the control system can obtain the degree of aging of the battery.

[0071] Step 230: If the vehicle power-on state information meets the first specified condition and the battery state information meets the second specified condition, the control system controls the vehicle to perform the firmware upgrade project corresponding to the OTA notification.

[0072] For example, the first specified condition described above can be a condition set by the user in advance in the server for determining whether the vehicle power-on state information can perform firmware upgrade; and the second specified condition described above can be a condition set by the user in advance in the server for determining whether the battery state information can perform firmware upgrade.

[0073] For example, the first specified condition described above can be that the vehicle is in a fully powered but non-driving state, so as to avoid potential safety hazards caused by performing upgrade during driving. For another example, the second specified condition described above can be that the battery power is higher than a specified threshold (for example, the specified threshold is 30%), so as to ensure that the vehicle will not be unable to start or data will not be lost due to battery depletion during the upgrade process. For another example, the second specified condition described above can be that the temperature of the battery meets a specified range, so as to ensure that the upgrade is performed in a suitable temperature range and avoid the influence of high temperature or low temperature on the battery life or the upgrade process.

[0074] In the embodiments of the present application, the control vehicle to perform the firmware upgrade project corresponding to the OTA notification can be an electronic control unit (ECU) supporting firmware update, so as to ensure that the vehicle electronic system can obtain function enhancement, bug repair and performance optimization in time. For example, the control system controls the vehicle to upgrade at least one of the following electronic control units: engine control module (ECM), powertrain control module (PCM), transmission control module (TCM), body control module (BCM), airbag control module (ACM), anti-lock braking system (ABS) / electronic stability program (ESP) control module, infotainment system, advanced driver assistance system (ADAS) module, battery management system (BMS).

[0075] Among them, the engine control module (ECM) is responsible for managing the operation of the engine, including fuel injection, ignition timing, etc. Through firmware updates, the engine efficiency, emission control, or operation problems can be optimized; the powertrain control module (PCM) integrates the engine control and transmission control functions of the ECU, and firmware updates can help improve the overall power performance and fuel economy of the vehicle; the transmission control module (TCM) controls the operation of the automatic transmission, and firmware updates can solve the problem of smooth shifting or add new shifting logic; the body control module (BCM) manages the electrical accessories of the vehicle, such as door locks, lights, wipers, etc. Firmware updates can solve small problems in the electrical system or add new functions; the airbag control module (ACM or SRS) is responsible for monitoring the collision sensor and controlling the deployment of the airbag, and firmware updates can optimize the airbag response logic or correct potential safety issues; the anti-lock braking system (ABS) / electronic stability program (ESP) control module manages the vehicle's braking system to prevent skidding, and firmware updates can improve braking efficiency and vehicle stability; the infotainment system includes navigation, audio playback, and communication functions, and firmware updates can add new features, improve user experience, or fix software bugs; the advanced driver assistance system (ADAS) module supports adaptive cruise control, lane keep assist, etc., and firmware updates can help improve the accuracy of the system or add new features; especially for electric vehicles, the battery management system (BMS) manages the charging and discharging of the battery, and firmware updates can help optimize battery performance and extend service life.

[0076] For example, when the vehicle power-on state information meets the first specified condition and the battery state information meets the second specified condition, the Internet of Vehicles intelligent terminal can send a specified signal to the cloud server (the specified signal can indicate that the current vehicle meets the conditions for firmware upgrade); accordingly, after the cloud server receives the above-mentioned specified signal, it can match and issue the corresponding upgrade package information according to the specific model, current software version, etc. of the vehicle; accordingly, after the Internet of Vehicles intelligent terminal receives the above-mentioned upgrade package information, it can check the network connection stability to ensure that there is enough data flow to complete the entire upgrade process.

[0077] After each condition is ready, the control system can start downloading the firmware upgrade package while monitoring the download progress and data integrity; after the download is complete, the control system performs the upgrade without affecting the core functions of the vehicle. During the upgrade process, the control system can continuously monitor the battery status to ensure that the battery has enough power to complete the entire upgrade process and pause the upgrade if necessary to protect the battery. Accordingly, after the upgrade is complete, the Internet of Vehicles intelligent terminal can automatically perform self-detection and function verification to ensure that the upgrade is successful and does not introduce new problems, and feedback the upgrade results and any potential problems to the cloud server or the user for subsequent tracking and optimization.

[0078] To sum up, the scheme shown in the embodiments of the present application can obtain the vehicle power-on state information and the battery state information before the vehicle performs the upgrade task, and the upgrade task can be performed only when the vehicle power-on state information and the battery state information both meet the corresponding conditions; the vehicle power-on state information can correspond to the use state of the vehicle, and the battery state information can correspond to the state of the power battery and the storage battery of the vehicle; since the upgrade process needs to consume a certain time length, the state of the power battery and the storage battery of the vehicle needs to be in a necessary state, and at the same time, the upgrade process can interfere with the normal operation of the vehicle, so the use state of the vehicle also needs to be in a necessary state; the above scheme can guarantee that the vehicle does not have safety hazards while providing the vehicle with OTA firmware upgrade service, thereby improving the reliability and safety of the system.

[0079] Based on the above Figure 2 In a possible implementation scheme of the scheme in the embodiments shown above, the vehicle power-on state information includes key state information of the vehicle, and the first specified condition includes that the key state of the vehicle is in the OFF state; the battery state information includes charging information of the power battery and voltage information of the storage battery, and the second specified condition includes that the power battery is in an uncharged state and the voltage of the storage battery is greater than a first specified threshold.

[0080] In the embodiments of the present application, the control system can read the key state information through the On Board Diagnostics (OBD-II) interface of the vehicle using a diagnostic tool or a smart terminal of the Internet of Vehicles. The key state information refers to different positions of the ignition switch of the vehicle, and different positions correspond to different working modes of the electrical system of the vehicle. The key state of the vehicle in the OFF state means that the vehicle is not powered on and is not in the use state.

[0081] The key state of the vehicle includes the following: the LOCK state: when the key is in the LOCK state, the power supply of the vehicle is cut off, and the steering wheel is locked, which can play a role in preventing theft; the ACC state: the ACC state allows part of the electrical accessories (such as audio, lighting, etc.) of the vehicle to work, but the engine is not started; the OFF state: the OFF state means that the main power of the vehicle is turned off, and the vehicle is powered off; the ON state: when the key is in the ON state, all electrical systems of the vehicle are activated, including the instrument panel, the safety system, etc., but the engine is not necessarily started; the START state: a short rotation to the START state can start the engine, and once the engine is started, the key will usually automatically return to the ON state.

[0082] In the embodiments of the present application, the charging information of the power battery mainly includes the current state of charge (SOC), the charging state (such as charging, full charge, stop charging, etc.), the charging speed (such as charging current, voltage, etc.), the estimated charging completion time, the battery temperature, etc. Among them, the power battery in the above-mentioned uncharged state can be that the vehicle is not connected to the charging pile for charging, or the vehicle is connected to the charging pile, but has not started charging, or the charging has been completed. For example, the control system can obtain the power battery charging information through the vehicle-mounted display screen or the mobile phone APP; for another example, the control system can connect the vehicle through the OBD-II interface using a diagnostic tool or adapter, and read through the specified software.

[0083] In the embodiments of the present application, the voltage information of the storage battery can indicate the current charging level and health status of the vehicle. For example, through the sensors and data analysis capabilities integrated by the Internet of Vehicles intelligent terminal, the control system can obtain the voltage information of the storage battery; for another example, the control system can obtain the voltage information of the storage battery through the voltage information displayed on the instrument panel; for another example, the control system can read the voltage value of the storage battery through the OBD-II interface.

[0084] Among them, the above-mentioned first specified threshold can be set by the developer in the control system or server, or can be set by the user in advance, which is used to judge whether the voltage of the storage battery meets the condition of upgrading. For example, the above-mentioned first specified threshold can be 11.5V, that is, the voltage of the above-mentioned storage battery is greater than the first specified threshold, which can be that the storage battery voltage is greater than 11.5V. From the perspective of safety, OTA upgrading when the vehicle is driving or charging may interfere with the normal operation of the vehicle, and even may cause the vehicle system to crash, thereby causing a safety accident.

[0085] From the functional point of view, OTA upgrading when the vehicle is in the ON gear or in use may affect the control system, entertainment system, navigation system and other functions of the vehicle, causing these functions to be unable to be normally used or to appear abnormally. In addition, if the OTA upgrading involves changes to the vehicle hardware, the hardware performance and service life of the vehicle may also be affected during the upgrading process.

[0086] From the perspective of user experience, OTA upgrading when charging may prolong the charging time and bring additional waiting time to the user. In addition, if unexpected situations occur during the OTA upgrading process, such as upgrading failure or system crash, the user may also be brought additional maintenance cost and time cost.

[0087] Based on the above embodiments, the present embodiment illustrates specific contents that the vehicle power-on state information, the first specified condition, the battery state information, and the second specified condition can include, provides further limiting conditions for whether the vehicle can perform the firmware upgrade item corresponding to the OTA notification, and specifically includes that when the vehicle is being used, the power battery is being charged, and the storage battery is being charged, the vehicle is not controlled to perform the firmware upgrade item corresponding to the OTA notification. The present embodiment can provide OTA firmware upgrade service for the vehicle under the premise of ensuring the safety of the vehicle.

[0088] Based on the solutions in the above various embodiments, the step 230 can be implemented as follows: in the case that the vehicle power-on state information meets the first specified condition and the battery state information meets the second specified condition, waking up the vehicle and entering a set state; in the set state, the vehicle cannot be used; in the case that the vehicle enters the set state, controlling the vehicle to perform the firmware upgrade item corresponding to the OTA notification.

[0089] The above waking up the vehicle can be that the control system activates the power supply of the vehicle, so that the vehicle is converted from the sleep or standby state (i.e. the power-off state) to the power-on state. For example, the TBOX can wake up the whole vehicle by issuing a short message, and after the whole vehicle is woken up, the OTA cloud platform will display the corresponding login message.

[0090] The above set state can be a specified state set by the user in the control system in advance. In the set state, the vehicle is in a state that cannot be used, for example, part of the functions and operations of the vehicle are in a limited state, so as to ensure the smooth progress of the upgrade process and avoid data loss or system damage. For example, the following functions can be disabled or limited during the upgrade:

[0091] Driving function: the vehicle cannot be started or driven, to ensure that the upgrade process will not be interrupted or cause safety hazards due to vehicle movement;

[0092] Electrical accessories: some or all electrical accessories may be temporarily disabled, such as air conditioning systems, audio systems, window lifts, seat adjustments, etc., to reduce power consumption and ensure that the battery has enough power to complete the upgrade;

[0093] Infotainment system: the central screen, navigation system, touch screen function, etc. may be locked to avoid user operation interference with the upgrade process;

[0094] Remote control function: vehicle networking functions such as remote start and door unlocking may be temporarily disabled until the upgrade is complete and the system is restarted;

[0095] Emergency call and safety service: in some cases, the emergency call function (eCall) may be temporarily disabled, but this is rare because safety is the top priority, and most system designs will try to ensure the availability of emergency services;

[0096] Driver assistance systems: functions such as adaptive cruise control, automatic emergency braking, etc. may be suspended to ensure that they are not accidentally activated due to the system update;

[0097] Instrument cluster and indicator lights: other than the necessary indicator lights (such as upgrade progress indication), other instrument cluster displays may be limited or only display the most basic information.

[0098] Based on the above embodiments, the embodiments define the state of the vehicle before performing the firmware upgrade project corresponding to the OTA notification, which can specifically include: in the case that the vehicle power-on state information meets the first specified condition, and the battery state information meets the second specified condition, the control system controls the vehicle to power on, at the same time, controls the vehicle to enter a set state that cannot be used, and then controls the vehicle to perform the firmware upgrade project corresponding to the OTA notification; The embodiment can ensure that the vehicle is in a powered-on state during the upgrade process, but the specified functions cannot be used, that is, although the vehicle has been powered on, the user cannot use the specified functions in the vehicle, so as to create a stable environment for the vehicle, so that the upgrade process can be carried out without interference, and the success rate and safety of the upgrade are guaranteed.

[0099] Based on the schemes shown in the above various embodiments, in one possible implementation scheme, please refer to Figure 3 , which shows a flowchart of a remote firmware upgrade method provided by an example embodiment of the present application. As Figure 3 indicated, before step 220, the remote firmware upgrade method can include step 212 and step 214, step 220 can be implemented as step 220a, and the remote firmware upgrade method can further include step 240.

[0100] Step 212: Obtain vehicle profile information; the vehicle profile information is used to indicate whether the vehicle has been sold.

[0101] Among them, the vehicle profile information can indicate whether the vehicle is in a detected state, a qualified state, an unqualified state, a sold state, an unsold state, etc.

[0102] Step 214: In the case that the vehicle has been sold, display request information; the request information is used to request the user whether to agree to upgrade.

[0103] Among them, the request information can include the specific content of the firmware upgrade project, the time length expected to be occupied by the firmware upgrade project, when the upgrade is expected to be performed, whether to agree to upgrade, etc. For example, two specified controls are displayed, one corresponds to agreeing to upgrade, and the other corresponds to disagreeing to upgrade.

[0104] For example, after the user agrees to upgrade, the user can schedule an upgrade time; for example, the user can decide to perform the firmware upgrade project corresponding to the OTA notification during a non-use period of the vehicle (such as at night, etc.).

[0105] For example, the display request information can be displayed on the user interface of the vehicle display screen when the vehicle is powered on, or the request information can be pushed to the user APP.

[0106] Step 220a: In the case where the user agrees to upgrade, the vehicle power-on state information and the battery state information are obtained.

[0107] The user agrees to upgrade can be that the control system receives that the user triggers the upgrade consent control, or that the control system receives the user's voice form of upgrade consent information.

[0108] Correspondingly, the control system can obtain the vehicle power-on state information and the battery state information, and the specific implementation can refer to the implementation of step 220a, which will not be described here.

[0109] Step 240: In the case where the vehicle power-on state information satisfies the third specified condition and the battery state information satisfies the fourth specified condition, the vehicle is controlled to perform the firmware upgrade project corresponding to the OTA notification.

[0110] For example, the third specified condition can be a condition set by the user in the server to determine whether the vehicle power-on state information can be upgraded, and the fourth specified condition can be a condition set by the user in the server to determine whether the battery state information can be upgraded.

[0111] The implementation of step 240 can refer to the implementation of step 230, which will not be described here.

[0112] Based on the above embodiment, before the vehicle performs the upgrade task, it can be determined whether the corresponding vehicle has been sold. In the case where the vehicle has been sold, the user is requested to agree to the vehicle performing the upgrade task. In the case where the user agrees to perform the upgrade task, the control system obtains the vehicle power-on state information and the battery state information. Then, in the case where the vehicle power-on state information and the battery state information satisfy the corresponding conditions, the control system controls the vehicle to perform the firmware upgrade project corresponding to the OTA notification. Through such logic and strategy, the vehicle can automatically perform OTA firmware upgrade under the premise of ensuring safety and not affecting the user experience, thereby improving the reliability and safety of the system, and improving the information transparency and human-computer interaction experience during the use of the vehicle.

[0113] In a possible implementation scenario based on the solutions of the foregoing embodiments, the vehicle power-on state information includes key state information of the vehicle, and the third specified condition includes that the key state of the vehicle is in an ON state; the battery state information includes charging information of the power battery and voltage information of the storage battery, and the fourth specified condition includes that the power battery is in an uncharged state and the voltage of the storage battery is greater than a second specified threshold.

[0114] The key state of the vehicle in the ON state means that all electrical systems of the vehicle are activated, including the instrument panel, the safety system, and the like, but the engine is not necessarily started; that is, when the key state of the vehicle is in the ON state, the vehicle can be powered on and started by ignition.

[0115] For example, the second specified threshold can be set by a developer in the control system or the server, or can be set by a user in advance, and is used to determine whether the voltage of the storage battery meets the upgrade condition. The second specified threshold can be the same as or different from the first specified threshold.

[0116] Specifically, the storage battery is a core component of the vehicle system and provides power for various electronic devices and systems of the vehicle. If the voltage of the storage battery is too low or too high, it can affect the normal progress of the OTA upgrade, and even can cause upgrade failure or vehicle electrical system failure. In a full power state, the voltage of the storage battery can be close to 13V, and in a completely discharged state, the voltage can be reduced to about 10.5V. For a 12V lead-acid storage battery, the maximum charge can be 16V. Therefore, in a normal case, the voltage range of the storage battery is approximately between 10.5V and 13V.

[0117] If the voltage of the storage battery is already low, and the battery power is further consumed during the OTA upgrade process, it can cause excessive discharge of the battery, and further damage the battery and shorten its service life. Upgrade failure or system crash can cause the user to seek professional repair services, which will bring additional time and financial costs to the user.

[0118] Based on the foregoing embodiments, this embodiment shows specific contents that can be included in the vehicle power-on state information, the third specified condition, the battery state information, and the fourth specified condition, to provide further limiting conditions for whether the vehicle can perform the firmware upgrade item corresponding to the OTA notification, for example, when the power battery of the vehicle is charging and the storage battery is being charged, the vehicle is not controlled to perform the firmware upgrade item corresponding to the OTA notification; this embodiment can provide OTA firmware upgrade services for the vehicle under the premise of ensuring vehicle safety.

[0119] Based on the scheme in each of the above embodiments, the step 240 can be implemented as: in a case where the vehicle power-on state information meets the third specified condition and the battery state information meets the fourth specified condition, controlling the vehicle to enter a set state; in the set state, the vehicle cannot be used; in a case where the vehicle enters the set state, controlling the vehicle to perform a firmware upgrade item corresponding to the OTA notification.

[0120] The set state can be a specified state pre-set by a user in the control system. In the set state, the vehicle is in a state that cannot be used, for example, part of the functions and operations of the vehicle are in a limited state to ensure that the upgrade process proceeds smoothly and avoids data loss or system damage; for another example, the user cannot control the movement of the vehicle, and the control system can control the vehicle to be in a parking (P) gear, for example.

[0121] Based on the above embodiments, this embodiment defines the state before the vehicle performs the firmware upgrade item corresponding to the OTA notification, which can specifically include: in a case where the vehicle power-on state information meets the third specified condition and the battery state information meets the fourth specified condition, the control system controls the vehicle to enter a set state that cannot be used, and then the control system controls the vehicle to perform the firmware upgrade item corresponding to the OTA notification; this embodiment can ensure that the specified functions of the vehicle cannot be used during the upgrade process, create a stable environment for the vehicle, enable the upgrade process to proceed without interference, and guarantee the success rate and safety of the upgrade.

[0122] For example, based on any one or more of the above embodiments, the present embodiment proposes a scene test strategy method for FOTA upgrade on a new energy vehicle, which acquires the vehicle state of the actual vehicle through a TBOX, collects gear information, charging information, battery voltage information, and the like of the vehicle in advance to establish current vehicle state information, and controls the upgrade condition of the vehicle, thereby solving the safety and reliability problems in the FOTA upgrade process.

[0123] Please refer to Figure 4 which shows a background flowchart of the scene test strategy method for FOTA upgrade on a new energy vehicle provided by an example embodiment of the present application. As shown in Figure 4 , the method can specifically include the following steps:

[0124] Step 41: A developer can upload an upgrade package to an OTA cloud platform, the upgrade package corresponding to a new firmware upgrade item existing in a vehicle and specific upgrade data; wherein the upgrade package can include vehicle type, controller, part number, supplier, version number, and the like.

[0125] Subsequently, the OTA cloud platform sends an OTA notification to the vehicle-to-everything (V2X) intelligent terminal. Accordingly, the V2X intelligent terminal receives the OTA notification, obtains the vehicle's power-on status information and battery status information, and if the vehicle's power-on status information meets the first specified condition and the battery status information meets the second specified condition, the V2X intelligent terminal sends the vehicle's upgrade conditions, vehicle power-on status information, and battery status information to the OTA cloud platform.

[0126] Step 42: The OTA cloud platform can create upgrade policies, issue upgrade tasks and push them, and confirm whether to notify the user to upgrade based on the vehicle power status information and battery status information sent by the vehicle network intelligent terminal.

[0127] In the case of silent upgrades, the upgrade strategy needs to be set to OFF, while in the case of user-visual upgrades, the upgrade strategy needs to be set to ON.

[0128] Step 43: The OTA cloud platform can create upgrade tasks based on the upgrade strategy; the upgrade task can upgrade the control systems of core components such as the vehicle power control system, chassis electronic system, autonomous driving system, and body control system; the prerequisites for the upgrade strategy include the gear being in P or N gear, gear being in OFF gear, gear being in ON gear, engine being disabled, battery voltage being greater than 12V, battery charge being greater than 80%, and OBD port being occupied.

[0129] Step 44: The OTA cloud platform sends the upgrade task created in step 43 above to the corresponding vehicle network intelligent terminal; accordingly, after receiving the upgrade task, the vehicle network intelligent terminal can execute the firmware upgrade project corresponding to the upgrade task, and after the upgrade is completed or fails, it will report the upgrade result to the OTA cloud platform.

[0130] For example, after the upgrade task is issued, TBOX will wake up and connect to the FOTA cloud management system after the vehicle is started. If the vehicle is in a dormant state, TBOX will wake up the vehicle by sending an SMS. When the vehicle is woken up, a login message will be displayed, and the vehicle will show an online status. Vehicles in an offline state cannot enter the upgrade process and will be prompted that the upgrade has timed out.

[0131] Step 45: The OTA cloud platform can view the upgrade results uploaded by the vehicle network intelligent terminal.

[0132] When an upgrade fails, the OTA cloud platform can detect the reason for the upgrade failure through the vehicle network intelligent terminal. After the upgrade conditions are met, the upgrade task created in step 43 above can be sent to the vehicle network intelligent terminal again.

[0133] In the method, before the upgrade starts, the normal connection between the TBOX and the OTA cloud platform can be ensured, the remote transmission link is normal, and each controller is normal. The OTA cloud platform can well manage the vehicle model, the vehicle, the version, and the supplier.

[0134] In summary, the method shown in the above embodiments of the application can be applied to the FOTA upgrade scheme on the new energy vehicle. The vehicle state of the real vehicle is acquired through the TBOX, the gear information, the charging information, and the battery voltage information of the vehicle are collected in advance, the current vehicle state information is established, the upgrade conditions of the vehicle are controlled, it is judged whether the conditions meet the requirements before the upgrade and the writing start, and it is prompted that the upgrade is not allowed if the conditions do not meet the requirements. The upgrade conditions of the vehicle include but are not limited to that the key gear is in the OFF gear, the charging state is not in the charging state, and the battery voltage is greater than 11.5V.

[0135] For example, according to the specific upgrade task or the firmware upgrade item, the upgrade conditions of the vehicle can further include that the vehicle is in a powertrain ready state, the engine is in a starting state, the engine is in a prohibited state, the power battery is greater than 30%, the gear is in a P gear or a neutral gear, the Ecall is in a normal state, and the high voltage state is normal.

[0136] According to different scenarios before and after the vehicle is sold, the OTA upgrade scenario is generally divided into silent upgrade and non-silent upgrade. The silent upgrade is mainly used for the upgrade of the vehicle in the inventory state before the vehicle is sold. The OTA cloud platform sends a remote wake-up command, the vehicle is powered on through the TBOX, and is connected to the platform for processing of the upgrade task. The non-silent upgrade is mainly used for the upgrade scenario of the vehicle belonging to the vehicle owner after the vehicle is sold, that is, the user visual upgrade. The software upgrade change needs to be informed to the vehicle owner, and the upgrade is performed with the consent of the vehicle owner.

[0137] If the silent upgrade scenario, after the platform issues a task, the TBOX can download the upgrade package from the OTA cloud platform and upload it to the real vehicle. After the downloading is completed, the battery voltage state, the charging state, and the gear state are detected. If the conditions do not meet the requirements, it is prompted that the preconditions are not met, for example, the ON gear, the charging state, and the low battery voltage are reported as upgrade failures.

[0138] If the user visual upgrade scenario, after a task is issued, the TBOX can detect the charging state and the gear state, and notify the APP and the vehicle machine. After the customer confirms the operation, the upgrade link can be entered.

[0139] During the upgrade, the real vehicle remains in a silent state and cannot be used. Fault alarms can be normal phenomena. After the upgrade is completed, the real vehicle is restarted and returns to the normal state.

[0140] The scheme can protect the FOTA upgrading process on the new energy vehicle, and formulate a TBOX strategy to control the upgrading condition of the vehicle, so as to avoid the security problem caused by the FOTA upgrading process.

[0141] Please refer to Figure 5 , which shows a block diagram of a remote firmware upgrading device according to an example embodiment of the present application, which can be used to perform all or part of the steps performed by the control system of the vehicle in the method shown in Figure 2 , 3 , and the vehicle is a hybrid electric vehicle. The device includes: Figure 5

[0142] The receiving module 501 is configured to receive an over-the-air (OTA) notification. The OTA notification is used to indicate that there is a new firmware upgrading item.

[0143] The obtaining module 502 is configured to obtain vehicle power-on state information and battery state information. The vehicle power-on state information is used to indicate whether the vehicle is in use. The battery state information is used to indicate the state of the power battery and the storage battery of the vehicle.

[0144] The control module 503 is configured to control the vehicle to perform the firmware upgrading item corresponding to the OTA notification when the vehicle power-on state information satisfies a first specified condition and the battery state information satisfies a second specified condition.

[0145] In some embodiments, the vehicle power-on state information includes key gear state information of the vehicle, and the first specified condition includes that the key gear of the vehicle is in the OFF gear.

[0146] The battery state information includes charging information of the power battery and voltage information of the storage battery, and the second specified condition includes that the power battery is in an uncharged state and the voltage of the storage battery is greater than a first specified threshold.

[0147] In some embodiments, the control module 503 is configured to control the vehicle to power on and enter a set state when the vehicle power-on state information satisfies the first specified condition and the battery state information satisfies the second specified condition. In the set state, the vehicle cannot be used.

[0148] The control module 503 is configured to control the vehicle to perform the firmware upgrading item corresponding to the OTA notification when the vehicle enters the set state.

[0149] In some embodiments, the device further includes an archive information obtaining module configured to obtain vehicle archive information. The vehicle archive information is used to indicate whether the vehicle has been sold. In the case that the vehicle has been sold, display request information. The request information is used to request the user whether to agree to upgrade.

[0150] ​The acquisition module 502 is configured to acquire vehicle power-on state information and battery state information when receiving an instruction of user consent to upgrade.

[0151] The control module 503 is configured to control the vehicle to perform a firmware upgrade item corresponding to the OTA notification when the vehicle power-on state information meets a third specified condition and the battery state information meets a fourth specified condition.

[0152] In some embodiments, the vehicle power-on state information includes key status information of the vehicle, and the third specified condition includes that the key status of the vehicle is in an ON status; the battery state information includes charging information of a power battery and voltage information of a storage battery, and the fourth specified condition includes that the power battery is in an uncharged state and the voltage of the storage battery is greater than a second specified threshold.

[0153] In some embodiments, the control module 503 is configured to control the vehicle to enter a set state when the vehicle power-on state information meets the third specified condition and the battery state information meets the fourth specified condition; and the vehicle cannot be used in the set state.

[0154] The control module 503 is configured to control the vehicle to perform a firmware upgrade item corresponding to the OTA notification when the vehicle enters the set state.

[0155] It should be noted that the device provided by the above embodiments is used to implement its functions, and the above-mentioned various functional modules are only used as an example for illustration. In actual application, the above-mentioned functions can be completed by different functional modules according to actual needs, that is, the content structure of the device is divided into different functional modules to complete all or part of the above-described functions.

[0156] As for the device in the above embodiments, the specific manner in which each module performs operations has been described in detail in the embodiments of the method. The technical effects achieved by each module performing operations are the same as those in the embodiments of the method, and will not be described in detail here.

[0157] For reference Figure 6Fig. 6 shows a structural block diagram of a computer device 600 according to an example embodiment of the present application. The structural block diagram can also be implemented as the structural block diagram of the control system or the server in the above-mentioned solutions of the present application. The computer device 600 includes a central processing unit (CPU) 601, a system memory 604 including a random access memory (RAM) 602 and a read-only memory (ROM) 603, and a system bus 605 connecting the system memory 604 and the central processing unit 601. The computer device 600 also includes a mass storage device 606 for storing an operating system 609, application programs 610, and other program modules 611.

[0158] The mass storage device 606 is connected to the central processing unit 601 through a mass storage controller (not shown) connected to the system bus 605. The mass storage device 606 and its associated computer readable media provide nonvolatile storage for the computer device 600. That is, the mass storage device 606 can include a computer readable medium (not shown) such as a hard disk or a compact disc read-only memory (CD-ROM) drive.

[0159] Without loss of generality, the computer readable medium can include computer storage media and communication media. Computer storage media includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storage of information such as computer readable instructions, data structures, program modules or other data. The computer storage media includes RAM, ROM, erasable programmable read only memory (EPROM), electrically-erasable programmable read-only memory (EEPROM) flash or other solid state memory technology, CD-ROM, digital versatile discs (DVD), or other optical storage, magnetic cassettes, magnetic tapes, magnetic disk storage or other magnetic storage devices. Of course, the computer storage media is not limited to the above-mentioned several kinds. The system memory 604 and the mass storage device 606 mentioned above can be collectively referred to as memory.

[0160] According to various embodiments of the present disclosure, the computer device 600 can also operate in connection with a remote computer through a network, such as the Internet. That is, the computer device 600 can connect to the network 608 through the network interface unit 607 connected to the system bus 605, or can connect to other types of networks or remote computer systems (not shown) using the network interface unit 607.

[0161] The memory further includes at least one computer instruction stored in the memory, and the central processing unit 601 implements all or part of the steps in the methods shown in the various embodiments above by executing the at least one computer instruction.

[0162] In an exemplary embodiment, a chip is also provided, which includes programmable logic circuit and program instructions, and when the chip operates on a control system, the program instructions are used to implement the remote firmware upgrade method of the above aspects.

[0163] In an exemplary embodiment, a computer program product is also provided, which includes computer instructions stored in a computer readable storage medium. The processor of the control system reads the computer instructions from the computer readable storage medium, and the processor reads and executes the computer instructions from the computer readable storage medium to implement the remote firmware upgrade method provided by the above method embodiments.

[0164] In an exemplary embodiment, a computer readable storage medium is also provided, which stores computer instructions, and the computer instructions are loaded and executed by the processor to implement the remote firmware upgrade method provided by the above method embodiments.

[0165] Those skilled in the art can understand that all or part of the steps of the above embodiments can be completed by hardware, or can be instructed by programs to complete the related hardware, and the programs can be stored in a computer readable storage medium, and the storage medium mentioned above can be a read-only memory, a magnetic disk or an optical disk, etc.

[0166] Those skilled in the art should realize that in the above one or more examples, the functions described in the embodiments of the present application can be realized by hardware, software, firmware or any combination thereof. When realized by software, these functions can be stored in a computer readable medium or transmitted as one or more instructions or codes on a computer readable medium. The computer readable medium includes computer storage medium and communication medium, wherein the communication medium includes any medium that facilitates the transmission of computer programs from one place to another. The storage medium can be any available medium that can be accessed by a general or special purpose computer.

[0167] The above merely provides the optional embodiments of the present application, and is not intended to limit the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. A remote firmware upgrade method, characterized by, The method is executed by a control system of a vehicle, and the method comprises: receiving an over-the-air (OTA) notification, the OTA notification being used to indicate that there is a new firmware upgrade item; obtaining vehicle profile information, the vehicle profile information being used to indicate whether the vehicle has been sold; in the case where the vehicle has been sold, displaying request information, the request information being used to request a user whether to agree to upgrade; in the case where an instruction of user agreement to upgrade is received, obtaining vehicle power-on state information and battery state information, the vehicle power-on state information being used to indicate whether the vehicle is in a use state, the vehicle power-on state information comprising key profile state information of the vehicle, the battery state information being used to indicate states of a power battery and a storage battery of the vehicle, the battery state information comprising charging information of the power battery and voltage information of the storage battery; in the case where the vehicle power-on state information satisfies a first specified condition and the battery state information satisfies a second specified condition, controlling the vehicle to execute the firmware upgrade item corresponding to the OTA notification; in the case where the vehicle power-on state information satisfies a third specified condition and the battery state information satisfies a fourth specified condition, controlling the vehicle to enter a set state, in the set state, the vehicle cannot be used, the third specified condition comprising that a key profile of the vehicle is in an on (ON) profile, and the fourth specified condition comprising that the power battery is in an uncharged state and the voltage of the storage battery is greater than a second specified threshold value; in the case where the vehicle enters the set state, controlling the vehicle to execute the firmware upgrade item corresponding to the OTA notification.

2. The method of claim 1, wherein, The vehicle power-on state information comprises key profile state information of the vehicle, and the first specified condition comprises that a key profile of the vehicle is in an off (OFF) profile. The battery state information comprises charging information of the power battery and voltage information of the storage battery, and the second specified condition comprises that the power battery is in an uncharged state and the voltage of the storage battery is greater than a first specified threshold value.

3. The method of claim 2, wherein, The controlling the vehicle to execute the firmware upgrade item corresponding to the OTA notification in the case where the vehicle power-on state information satisfies a first specified condition and the battery state information satisfies a second specified condition comprises: in the case where the vehicle power-on state information satisfies the first specified condition and the battery state information satisfies the second specified condition, waking up the vehicle and entering a set state, in the set state, the vehicle cannot be used; in the case where the vehicle enters the set state, controlling the vehicle to execute the firmware upgrade item corresponding to the OTA notification.

4. A remote firmware upgrade apparatus, characterized by comprising: The apparatus comprises: a receiving module, configured to receive an over-the-air (OTA) notification, the OTA notification being used to indicate that there is a new firmware upgrade item; The acquisition module is configured to acquire vehicle profile information, display request information in a case where the vehicle has been sold, and acquire vehicle power-on state information and battery state information in a case where an instruction of user consent to upgrade is received; the vehicle profile information is used to indicate whether the vehicle has been sold, the request information is used to request the user whether to consent to upgrade, the vehicle power-on state information is used to indicate whether the vehicle is in use, and the vehicle power-on state information includes key profile state information of the vehicle; and the battery state information is used to indicate states of a power battery and a storage battery of the vehicle, and the battery state information includes charging information of the power battery and voltage information of the storage battery. The control module is configured to control the vehicle to perform the firmware upgrade item corresponding to the OTA notification in a case where the vehicle power-on state information meets a first specified condition and the battery state information meets a second specified condition, control the vehicle to enter a set state in a case where the vehicle power-on state information meets a third specified condition and the battery state information meets a fourth specified condition, and control the vehicle to perform the firmware upgrade item corresponding to the OTA notification in a case where the vehicle enters the set state; the vehicle cannot be used in the set state, the third specified condition includes that a key profile of the vehicle is in an ON profile, and the fourth specified condition includes that the power battery is in an uncharged state and voltage of the storage battery is greater than a second specified threshold.

5. A computer device, comprising: The computer device includes a processor and a memory, and the memory stores at least one computer instruction, which is loaded and executed by the processor to implement the remote firmware upgrade method according to any one of claims 1 to 3.

6. A computer-readable storage medium, characterized in that, The computer readable storage medium stores at least one computer instruction, which is loaded and executed by the processor to implement the remote firmware upgrade method according to any one of claims 1 to 3.

7. A computer program product, characterised in that, The computer program product includes computer instructions stored in a computer readable storage medium; the computer instructions are read and executed by a processor of a computer device to implement the remote firmware upgrade method according to any one of claims 1 to 3.

Citation Information

Patent Citations

  • Vehicle remote upgrading method, device and equipment and storage medium

    CN111698307A

  • Vehicle remote upgrading method and device, electronic equipment, vehicle-mounted terminal and storage medium

    CN113626056A