Vehicle screen upgrade control method and device, electronic equipment and vehicle
By using signature encryption and consistency verification methods, the security and accuracy issues in the vehicle host self-upgrade process are resolved, enabling safe and efficient screen upgrades, avoiding malfunctions such as black screens and lag, and ensuring the stability of vehicle control.
Patent Information
- Application Number
- CN202411682899.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-22
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2044-11-22
AI Technical Summary
When the vehicle's main unit undergoes self-upgrade, it is prone to issues such as black screen, lag, or system crashes, which can lead to safety hazards during control. Existing technologies have neglected the safety and accuracy of the main unit's own upgrade.
By obtaining the signed and encrypted upgrade package, unpacking it using the locally deployed root certificate, performing consistency verification based on the diagnostic identification code and part number, and determining the safe upgrade conditions by combining operating parameters and screen temperature, a separate software upgrade is performed.
Ensure the security and accuracy of the upgrade package, avoid affecting the operation of the host, guarantee a successful screen upgrade on the first try, reduce the risk of failure, and improve upgrade efficiency and security.
Smart Images

Figure CN119718390B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of vehicle technology, and in particular to an upgrade control method, device, electronic device, and vehicle for a vehicle screen. Background Technology
[0002] As the automotive industry increasingly moves towards electrification, connectivity, and intelligence, Electronic Control Units (ECUs) are widely used in vehicles. To mitigate the high costs and negative market impacts associated with vehicle recalls for feature optimization, additions or removals, and repairs, remote upgrade technology has emerged. In this technology, the vehicle's head unit (HUT), acting as the master node for Firmware Over-The-Air (FOTA) software upgrades, is responsible for distributing upgrade packages to ECUs on other Ethernet nodes. However, it has neglected to improve the safety and accuracy of upgrades to the head unit itself. This can lead to issues such as black screens, freezes, or system crashes during the upgrade process, causing temporary gaps in vehicle control and creating safety hazards. Summary of the Invention
[0003] In view of this, the purpose of this application is to provide a method, device, electronic device and vehicle for upgrading a vehicle screen, so as to safely and accurately complete the self-upgrading of the host-controlled screen.
[0004] To achieve the above objectives, this application provides an upgrade control method for a vehicle screen, comprising:
[0005] Obtain the signed and encrypted upgrade package, and unpack the signed and encrypted upgrade package according to the root certificate deployed locally to obtain at least one legitimate upgrade package;
[0006] The target host direct control screen to be upgraded is determined from among multiple screens corresponding to each of the legitimate upgrade packages based on the diagnostic identification code of the legitimate upgrade package, and the consistency verification of the target host direct control screen is performed based on the part number of the legitimate upgrade package.
[0007] In response to the successful consistency check, the system determines whether the safety upgrade conditions are met based on the vehicle's operating parameters and / or the current screen temperature of the target host direct control screen. Then, it performs a separate software upgrade on the target host direct control screen that meets the safety upgrade conditions among the multiple screens according to the legitimate upgrade package.
[0008] Based on the same inventive concept, this disclosure also provides an upgraded control device for a vehicle screen, comprising:
[0009] The upgrade unpacking module is configured to: obtain a signed and encrypted upgrade package, and unpack the signed and encrypted upgrade package according to the root certificate deployed locally to obtain at least one legitimate upgrade package;
[0010] The upgrade verification module is configured to: determine the target host direct control screen to be upgraded corresponding to each of the legitimate upgrade packages based on the diagnostic identification code of the legitimate upgrade package, and perform consistency verification on the target host direct control screen based on the part number of the legitimate upgrade package;
[0011] The security upgrade module is configured to: in response to a successful consistency check, determine whether the security upgrade conditions are met based on the operating parameters and / or the current screen temperature of the target host direct-controlled screen, and perform a separate software upgrade on the target host direct-controlled screen that meets the security upgrade conditions based on the legitimate upgrade package.
[0012] Based on the same inventive concept, this disclosure also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable by the processor, wherein the processor implements the method described above when executing the computer program.
[0013] Based on the same inventive concept, this disclosure also provides a vehicle including an upgraded control device or electronic device for the vehicle screen as described above.
[0014] As can be seen from the above description, the vehicle screen upgrade control method, device, electronic device, and vehicle provided in this application can, after obtaining a signed and encrypted upgrade package, decrypt the signed and encrypted upgrade package according to the root certificate deployed locally to obtain at least one legitimate upgrade package; determine the target host direct control screen to be upgraded among multiple screens corresponding to each legitimate upgrade package based on the diagnostic identification code of the legitimate upgrade package, and perform a consistency check on the target host direct control screen based on the part number of the legitimate upgrade package; in response to the successful consistency check, determine whether the safe upgrade conditions are met based on the vehicle's operating parameters and / or the current screen temperature of the target host direct control screen, and perform individual software upgrades on the target host direct control screens among the multiple screens that meet the safe upgrade conditions based on the legitimate upgrade package. The security of the upgrade package is ensured through signature encryption, and the diagnostic identification code and part number ensure that different legitimate upgrade packages can accurately correspond to their respective target host direct control screens, allowing for individual upgrades of each target host direct control screen. Before performing the upgrade, it is necessary to determine whether the safety upgrade conditions are met based on the operating parameters and / or the current screen temperature of the target host's direct control screen. This ensures that the upgrade process will not affect the operation of the host and that the software will not stop running due to excessive operating temperature, thus ensuring safety and enabling the screen upgrade to be successful on the first attempt. Attached Figure Description
[0015] To more clearly illustrate the technical solutions in this application or related technologies, the drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the drawings described below are only embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0016] Figure 1 This is a flowchart of a vehicle screen upgrade control method according to an embodiment of this application;
[0017] Figure 2 This is a flowchart illustrating the unpacking of the signature encryption upgrade package according to an embodiment of this application;
[0018] Figure 3 This is a flowchart illustrating the process of determining the target host direct control screen in an embodiment of this application.
[0019] Figure 4 This is a flowchart illustrating the consistency verification of the target host's directly controlled screen in an embodiment of this application;
[0020] Figure 5 A flowchart for determining whether the security upgrade conditions are met in this application embodiment;
[0021] Figure 6 This is a schematic diagram of the structure of the vehicle screen upgrade control device according to an embodiment of this application;
[0022] Figure 7 This is a schematic diagram of the structure of an electronic device according to an embodiment of this application. Detailed Implementation
[0023] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with specific embodiments and the accompanying drawings.
[0024] It should be noted that, unless otherwise defined, the technical or scientific terms used in the embodiments of this application should have the ordinary meaning understood by one of ordinary skill in the art to which this application pertains. The terms "first," "second," and similar terms used in the embodiments of this application do not indicate any order, quantity, or importance, but are merely used to distinguish different components. Terms such as "comprising" or "including" mean that the element or object preceding the word encompasses the elements or objects listed after the word and their equivalents, without excluding other elements or objects. Terms such as "connected" or "linked" are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. Terms such as "upper," "lower," "left," and "right" are only used to indicate relative positional relationships; when the absolute position of the described object changes, the relative positional relationship may also change accordingly.
[0025] In this article, it is important to understand that any number of elements in the accompanying figures is for illustrative purposes and not for limitation, and any naming is for distinction only and has no limiting meaning.
[0026] Based on the above background description, the following situations also exist in the related technologies:
[0027] In related technologies, the vehicle's main unit is responsible for distributing upgrade packages to the ECUs of other Ethernet nodes to upgrade these ECUs. However, screens such as the instrument panel screen, central control display screen, ceiling-mounted screen, and passenger-side screen do not have their own independent controllers. The software for these screens is deployed in the main unit. Therefore, screens directly controlled by the main unit and lacking independent controllers are defined as main unit-controlled screens. Thus, upgrading main unit-controlled screens such as the instrument panel screen, central control display screen, ceiling-mounted screen, and passenger-side screen is essentially a self-upgrade of the main unit system. However, during the main unit system's upgrade process, other operations are generally prohibited to avoid conflicts between the upgrade process and the control process, which could lead to a black screen, freeze, or crash in the main unit. A faulty main unit naturally cannot execute the corresponding control commands, resulting in upgrade failure and the inability to execute control commands.
[0028] While current upgrade technologies consider upgrading other controllers, they often neglect improving the safety and accuracy of upgrading the main unit itself. This can lead to issues like black screens, freezes, or crashes during the upgrade process, causing temporary gaps in vehicle control and creating safety hazards. To ensure that the upgrade process does not affect the normal operation of the main unit, a more accurate and secure software upgrade control strategy is needed.
[0029] The vehicle screen upgrade control method, device, electronic device, and vehicle provided in this application embodiment can, after obtaining a signed and encrypted upgrade package, decrypt the signed and encrypted upgrade package according to the root certificate deployed locally to obtain at least one legitimate upgrade package; determine the target host direct control screen to be upgraded corresponding to each legitimate upgrade package based on the diagnostic identification code of the legitimate upgrade package, and perform a consistency check on the target host direct control screen based on the part number of the legitimate upgrade package; in response to the successful consistency check, determine whether the safe upgrade conditions are met based on the operating parameters and / or the current screen temperature of the target host direct control screen, and perform a separate software upgrade on the target host direct control screen that meets the safe upgrade conditions based on the legitimate upgrade package. The security of the upgrade package is ensured by signature encryption, and the diagnostic identification code and part number ensure that different legitimate upgrade packages can accurately correspond to the corresponding target host direct control screens, and each target host direct control screen is upgraded individually. Before performing the upgrade, it is necessary to determine whether the safe upgrade conditions are met based on the operating parameters and / or the current screen temperature of the target host direct control screen to ensure that the upgrade process does not affect the operation of the host and that the software does not stop running due to excessive operating temperature, ensuring security while ensuring a successful screen upgrade in one go.
[0030] The following describes in detail, with reference to the accompanying drawings, the vehicle screen upgrade control method provided by the embodiments of this application.
[0031] In some embodiments, such as Figure 1 As shown, an upgrade control method for a vehicle screen includes steps 101-103.
[0032] Step 101: Obtain the signed and encrypted upgrade package. Unpack the signed and encrypted upgrade package according to the root certificate deployed locally to obtain at least one legitimate upgrade package.
[0033] In practical implementation, it should be noted that the vehicle screen upgrade control method provided in this application embodiment is an online upgrade control method. Offline upgrades require driving the vehicle to a specific location and using a wired upgrade device to connect to the host for upgrade control, which restricts the upgrade location and wastes user time. Therefore, when performing online upgrades, a signed and encrypted upgrade package can be obtained from the cloud platform.
[0034] The cloud platform synchronizes the root certificate with the vehicle's head unit in advance to ensure the encryption and decryption process is successful. Each upgrade package for the head unit's direct control screen is a small data packet (e.g., a DC (Desktop Central) packet). Unlike the encryption of data packets used for other ECU upgrades, the cloud platform signs and encrypts each upgrade data packet for the head unit's direct control screen based on the root certificate.
[0035] For example, the cloud platform performs a hash calculation on the upgrade data packet based on a hash algorithm and the root certificate to obtain a digest of the upgrade data packet, which serves as the digital signature of the upgrade data packet. Then, the plaintext of the upgrade data packet is encrypted to obtain ciphertext, and the ciphertext and digital signature are combined to obtain a single upgrade package for the host-controlled screen. Different single upgrade packages and other upgrade packages used for other ECU upgrades are packaged and integrated into a large signed encrypted upgrade package (e.g., a DP package). Upon receiving an upgrade request from the vehicle's host computer, the signed encrypted upgrade package is sent to the vehicle's host computer.
[0036] After receiving the signed and encrypted upgrade package, the vehicle's main unit needs to unpack the package, which involves splitting and verifying the signature. First, the multiple upgrade packages bundled together are split into at least one single upgrade package and at least one upgrade package for upgrading other ECUs. The upgrade packages for other ECUs are then distributed to their respective ECUs, while the single upgrade package is used for upgrading the main unit itself, specifically for upgrading the software of the instrument cluster screen, central control display screen, ceiling-mounted screen, passenger-side screen, and other screens directly controlled by the main unit.
[0037] The verification and decryption process for a single upgrade package is as follows: The vehicle's main unit decrypts the digital signature based on the root certificate to obtain a corresponding decrypted signature. This decrypted signature verifies that the single upgrade package was sent from a legitimate cloud platform. Then, the encrypted ciphertext in multiple single upgrade packages is decrypted to obtain the corresponding upgrade data packets. Finally, the same hash calculation method is used to hash the upgrade data packets to obtain a corresponding verification signature. This verification signature verifies whether the upgrade data packets have been tampered with. If the decrypted signature matches the verification signature, it indicates that the single upgrade package originates from a legitimate cloud platform and has not been tampered with during transmission, ensuring that the decrypted upgrade data packets are legitimate. Therefore, the single upgrade package is considered a legitimate upgrade package.
[0038] If the decryption signature and the verification signature do not match, there are two possibilities. One is that the encrypted ciphertext of the signature encryption upgrade package was maliciously tampered with during transmission. The tampered ciphertext is altered, and calculating its hash using the same algorithm as the cloud platform will result in a digest that differs from the correct verification signature, leading to a discrepancy between the decryption and verification signatures. The other possibility is that the sender of the signature encryption upgrade package is a malicious cloud platform that does not meet the required standards. This could result in the inability to decrypt the digital signature or an alteration of the decrypted signature, leading to a discrepancy between the decryption and verification signatures.
[0039] Therefore, signing, encrypting, and decompressing based on the root certificate can ensure that the obtained signed and encrypted upgrade package comes from a legitimate channel and that the signed and encrypted upgrade package has not been tampered with during transmission, thus guaranteeing the legitimacy and integrity of the legitimate upgrade package.
[0040] Step 102: Determine the target host direct control screen to be upgraded from among the multiple screens corresponding to each legitimate upgrade package based on the diagnostic identification code of the legitimate upgrade package, and perform a consistency check on the target host direct control screen based on the part number of the legitimate upgrade package.
[0041] In practice, the upgrades to the main unit's directly controlled screens, such as the instrument panel screen, central control display screen, ceiling-mounted screen, and passenger-side screen, are independent of each other. Therefore, it is necessary to identify the corresponding target main unit controlled screen for each legitimate upgrade package. Then, each target main unit controlled screen undergoes a separate software upgrade based on its corresponding legitimate upgrade package. The main unit controlled screen and the upgrade package are matched using a diagnostic identification code. The upgrade package contains its own diagnostic identification code, and each screen's own diagnostic identification code serves as its screen identification code. Matching the screen identification code and the diagnostic identification code ensures the matching between the main unit controlled screen and the legitimate upgrade package, resulting in the target main unit controlled screen to be upgraded corresponding to each legitimate upgrade package. The diagnostic identification code identifies the specific screen and serves as a unique identifier for the identified screen. For example, the diagnostic identification code for the instrument panel screen could be AAAAA, the ceiling-mounted screen could be BBBBB, and the central control screen could be CCCCC.
[0042] After identifying the target host-controlled screen, the matching results need to be verified to ensure accuracy. Each component in the host has its own part number, and each host-controlled screen corresponds to a screen part number. The legitimate upgrade package includes the part number corresponding to the screen to be upgraded. If this part number is the same as the screen part number of the corresponding target host-controlled screen, it means there is no matching problem between the legitimate upgrade package and the host-controlled screen, and the consistency check has passed. The part number serves as the identification identifier for the component, used to determine its identity. For example, the part number corresponding to the instrument panel screen could be AAA, the part number corresponding to the ceiling-mounted screen could be bbbbb, and the part number corresponding to the central control screen could be ccccc.
[0043] If the part number in the legitimate upgrade package does not match the screen part number of the target host's direct-control screen, it indicates a mismatch in the upgrade package and a failure to pass the consistency check. In this case, the upgrade of the target host's direct-control screen with the mismatch can be terminated individually, ensuring that the failure of a single legitimate upgrade package does not prevent the upgrade of all host direct-control screens. This improves the efficiency of host self-upgrades, reduces the damage to overall functionality caused by faults during the upgrade process, and allows for individual upgrades between different host direct-control screens, enhancing both upgrade efficiency and security.
[0044] Step 103: In response to the successful consistency check, determine whether the safety upgrade conditions are met based on the vehicle's operating parameters and / or the current screen temperature of the target host direct control screen, and perform individual software upgrades on the target host direct control screens that meet the safety upgrade conditions among the multiple screens according to the legitimate upgrade package.
[0045] In practice, after the consistency verification passes, the first step is to determine whether the vehicle is permitted to undergo a self-upgrade of the main unit. This requires determining the vehicle's current operating status based on the operating parameters. During a self-upgrade, the main unit must remain operational, meaning it must be continuously powered with sufficient charge to support the completion of all software upgrades for the main unit's directly controlled screens. Furthermore, during the upgrade process, some functions of the main unit's directly controlled screens, such as the instrument panel screen, central control display screen, ceiling-mounted screen, and passenger-side screen, will be temporarily unavailable. Therefore, it is crucial to ensure the vehicle is safely stationary to prevent loss of control or rollback.
[0046] After determining that the vehicle is permitted to perform a self-upgrade of the host based on the operating parameters, it is necessary to further determine whether the screen itself can perform the upgrade function. This is because the external environment and vehicle operation can cause the temperature of the host-controlled screen to change, and different host-controlled screens have different operating temperature ranges. If the current screen temperature exceeds the corresponding operating temperature range, the target host-controlled screen will be unable to perform the full function, or it may experience malfunctions such as freezing, black screen, or crashing. Under these circumstances, performing a system upgrade may result in unknown errors, such as data loss or upgrade failure. Therefore, the target host-controlled screen does not have the capability to perform the upgrade operation at this time, and the safe upgrade conditions are not met. The upgrade operation is prohibited.
[0047] If the current screen temperature is within the corresponding operating temperature range, it means that the target vehicle host can execute the corresponding upgrade process well, determine that the safety upgrade conditions are met, and perform a separate software upgrade on the host-controlled screen that meets the safety upgrade conditions according to the legitimate upgrade package, so as to ensure the accuracy and safety of the upgrade process, and ensure the screen upgrade is successful on the first try while ensuring safety.
[0048] If the operating parameters determine that self-upgrade is not allowed, the safety upgrade conditions are not met; if the current screen temperature determines that the host cannot complete the upgrade function, the safety upgrade conditions are not met; if the operating parameters determine that self-upgrade is not allowed, and the current screen temperature determines that the host cannot complete the upgrade function, the safety upgrade conditions are not met; if the operating parameters determine that self-upgrade is allowed, and the current screen temperature determines that the host can complete the upgrade function, the safety upgrade conditions are met.
[0049] The vehicle screen upgrade control method provided in this application embodiment can ensure the security of the upgrade package through signature encryption, and ensure that different legitimate upgrade packages and corresponding target host direct-controlled screens can be accurately matched through diagnostic identification codes and part numbers, and perform individual upgrades on their respective target host direct-controlled screens. Before performing the upgrade, it is necessary to determine whether the safe upgrade conditions are met based on the operating parameters and / or the current screen temperature of the target host direct-controlled screen, ensuring that the upgrade process will not affect the operation of the host and that the software will not stop running due to excessive operating temperature, thus ensuring security and enabling the screen upgrade to be successful on the first attempt.
[0050] In some embodiments, such as Figure 2 As shown, the signed encrypted upgrade package is unpacked based on the root certificate deployed locally to obtain at least one legitimate upgrade package, including steps 201-202.
[0051] Step 201: Split at least one single upgrade package from the signed encrypted upgrade package.
[0052] In practice, the signed and encrypted upgrade package includes a single upgrade package for host self-upgrade and other upgrade packages for other ECUs. Therefore, these upgrade packages need to be separated from the signed and encrypted upgrade package. The other upgrade packages for other ECUs are distributed to the corresponding ECUs, and the separated single upgrade packages are kept locally. The functions of the instrument panel screen, central control display screen, ceiling screen, and passenger screen are different, so different single upgrade packages are used for each. Therefore, after splitting, at least one single upgrade package will be obtained.
[0053] Step 202: Verify and decrypt the single upgrade package based on the root certificate. Single upgrade packages that pass the verification and decryption are identified as legitimate upgrade packages, while single upgrade packages that fail the verification and decryption are identified as illegitimate upgrade packages.
[0054] In practice, taking a single upgrade package corresponding to the central control display screen as an example, the verification and decryption process for a single upgrade package is as follows:
[0055] First, the vehicle's main unit decrypts the digital signature based on the root certificate to obtain the corresponding decrypted signature that corresponds to the central control display screen (for example, a cloud platform specifically used for upgrade services, the decrypted signature can be represented by code 001; or a cloud platform providing integrated services, the decrypted signature can be represented by code 002). The decrypted signature is used to verify that the single upgrade package was sent by a legitimate cloud platform.
[0056] Then, the encrypted ciphertext in the multiple single upgrade packages is decrypted to obtain the upgrade data package on the central control display screen. The same hash calculation method as the cloud platform is used to perform hash calculation on the upgrade data package to obtain the corresponding verification signature (e.g., 001). The verification signature is used to verify whether the upgrade data package has been tampered with.
[0057] Finally, the legitimacy of a single upgrade package for the central control display screen is determined by comparing whether the decryption signature and the verification signature match. Taking a signed and encrypted upgrade package obtained from a cloud platform specifically used for upgrade services as an example, a correct decryption signature and verification signature both contain 001.
[0058] If the decryption signature and the verification signature are consistent and both are 001, it means that the single upgrade package comes from a legitimate cloud platform that complies with regulations and has not been tampered with during transmission. This ensures that the upgrade data package after decryption is a legitimate upgrade package, and therefore the single upgrade package is a legitimate upgrade package.
[0059] If the decryption signature is 005, it means that the obtained signature encryption upgrade package did not come from a cloud platform specifically used for upgrade services. The sender of the signature encryption upgrade package is a malicious cloud platform that does not meet the regulations, which may result in the inability to decrypt the digital signature or cause the decryption signature after decryption to change, resulting in the decryption signature being inconsistent with the verification signature. Therefore, the split single upgrade package is naturally illegal, and it is determined that the signature verification and decryption failed. The corresponding single upgrade package is an illegal upgrade package.
[0060] If the decryption signature is 001, it means that the obtained signature-encrypted upgrade package comes from a cloud platform specifically used for upgrade services. If the verification signature is 003, it means that the upgrade data package has been tampered with and the central control display screen cannot be upgraded. It is determined that the signature verification and decryption failed, and the corresponding single upgrade package is an illegal upgrade package.
[0061] Therefore, signing, encrypting, and decompressing based on the root certificate can ensure that the obtained signed and encrypted upgrade package comes from a legitimate channel and that the signed and encrypted upgrade package has not been tampered with during transmission, thus guaranteeing the legitimacy and integrity of the legitimate upgrade package.
[0062] In some embodiments, such as Figure 3 As shown, the target host direct control screen to be upgraded is determined from among multiple screens corresponding to each legitimate upgrade package based on the diagnostic identification code of the legitimate upgrade package, including steps 301-302.
[0063] Step 301: Determine the screen identification code for each screen.
[0064] In practice, the upgrades to the main unit's directly controlled screens, such as the instrument panel screen, central control display screen, ceiling-mounted screen, and passenger-side screen, are independent of each other. Therefore, it is necessary to identify the corresponding target main unit's directly controlled screen for each legitimate upgrade package. Then, each target main unit's directly controlled screen undergoes a separate software upgrade based on its corresponding legitimate upgrade package. The main unit's directly controlled screen and the upgrade package are matched using diagnostic identification codes, so it is necessary to first determine the screen identification code for each screen. For example, the screen identification code for the instrument panel screen is 11111, the central control display screen is 11112, the ceiling-mounted screen is 11113, and the passenger-side screen is 11114.
[0065] Step 302: Determine the target screen identification code that matches the diagnostic identification code, and identify the screen corresponding to the target screen identification code as the target host direct control screen.
[0066] In practice, if four legitimate upgrade packages exist, and the diagnostic identification code for the first legitimate upgrade package is 11111, the second legitimate upgrade package is 11112, the third legitimate upgrade package is 11113, and the fourth legitimate upgrade package is 11114, then a matching process is performed based on the consistency of the diagnostic identification code and the screen identification code. The instrument panel screen matches the first legitimate upgrade package; the central control display screen matches the second legitimate upgrade package; the ceiling-mounted screen matches the third legitimate upgrade package; and the passenger-side screen matches the fourth legitimate upgrade package. Therefore, the instrument panel screen becomes the target host direct-control screen for the first legitimate upgrade package; the central control display screen becomes the target host direct-control screen for the second legitimate upgrade package; the ceiling-mounted screen becomes the target host direct-control screen for the third legitimate upgrade package; and the passenger-side screen becomes the target host direct-control screen for the fourth legitimate upgrade package.
[0067] By matching the screen identification code and the diagnostic identification code, the host-controlled screen and the legitimate upgrade package can be matched, providing a basis for individual upgrades of different host-controlled screens.
[0068] In some embodiments, such as Figure 4 As shown, the target host direct control screen is subjected to consistency verification based on the part number of the legitimate upgrade package, including steps 401-403.
[0069] Step 401: Determine the screen component number of the target host direct control screen.
[0070] In practice, after determining the target host direct control screen, in order to ensure the accuracy of the matching process, the matching result needs to be verified. Each component in the host has its own part number, so each host direct control screen corresponds to a screen part number. For example, the screen part number of the instrument panel screen is 00001, the screen part number of the central control display screen is 00002, the screen part number of the ceiling screen is 00003, and the screen part number of the passenger side screen is 00004.
[0071] Step 402: In response to the screen part number and component number being consistent, confirm that the consistency check has passed.
[0072] In practice, if the part number of the first legitimate upgrade package is 00001, the part number of the second legitimate upgrade package is 00002, the part number of the third legitimate upgrade package is 00003, and the part number of the fourth legitimate upgrade package is 00004, then the screen part number is determined to be consistent with the part number, the consistency check is passed, and the upgrade is allowed based on the legitimate upgrade package.
[0073] Step 403: In response to the inconsistency between the screen part number and the component number, it is determined that the consistency check has failed.
[0074] In specific implementation, if the part number of the first legitimate upgrade package is not 00001, the part number of the second legitimate upgrade package is not 00002, the part number of the third legitimate upgrade package is not 00003, and / or the part number of the fourth legitimate upgrade package is not 00004, then the screen part number is determined to be inconsistent with the part number, the consistency check is determined to have failed, and it is not allowed to upgrade the target host direct control screen that has failed the check based on the legitimate upgrade package.
[0075] If the consistency check fails, it indicates that the upgrade package is mismatched. In this case, the upgrade of the target host direct control screen with the mismatch can be terminated individually. This ensures that the mismatch of a single valid upgrade package will not cause all host direct control screens to fail to upgrade, thereby improving the efficiency of host self-upgrade and reducing the degree of damage to the overall upgrade process caused by the matching failure. Upgrading different host direct control screens individually improves upgrade efficiency and security.
[0076] In some embodiments, such as Figure 5 As shown, the safety upgrade conditions are determined based on the operating parameters and / or the current screen temperature of the target host direct control screen, including steps 501-505.
[0077] Step 501: Determine whether the prerequisites for upgrading the target host direct control screen are met based on the operating parameters.
[0078] In practice, after the consistency check passes, the first step is to determine whether the vehicle is allowed to perform a self-upgrade of the host. This requires determining the vehicle's current operating status based on the operating parameters.
[0079] In some embodiments, step 501 includes:
[0080] Step 5011: In response to the power mode being enabled in the operating parameters, determine that the pre-mode conditions are met.
[0081] In practice, upgrading the vehicle host requires ensuring that the vehicle can supply power to the vehicle host so that the vehicle host can operate. Therefore, when the power mode in the operating parameters is in the on mode, the front mode condition is met; when the power mode is in the off mode, the front mode condition is not met.
[0082] Step 5012: In response to the battery charge in the operating parameters being greater than or equal to a preset first charge threshold, determine that the pre-battery condition is met.
[0083] In practice, when the vehicle host upgrades the target host direct control screen, the upgrade process may last for a period of time. It is necessary to ensure that the vehicle host is always turned on before the upgrade is completed. This requires the battery to have sufficient power to maintain the operation of the host. Therefore, when the battery power in the operating parameters is greater than or equal to the preset first power threshold, it is determined that the battery power is sufficient to maintain the long-term operation of the vehicle host to ensure the smooth progress of the upgrade process and to meet the front battery conditions.
[0084] When the battery charge is less than the preset first charge threshold, it is determined that the battery charge is insufficient and may not be able to maintain the operation of the vehicle's main unit for a long time, making it difficult to ensure the smooth progress of the upgrade process. Therefore, it is determined that the front battery condition is not met.
[0085] Step 5013: In response to the fact that the power battery charge in the operating parameters is greater than or equal to the preset second charge threshold, it is determined that the front power battery condition is met.
[0086] In practice, although sufficient battery capacity can be determined when the pre-installed battery conditions are met, the battery's storage capacity decreases with age, leading to an inflated battery capacity value. For example, a new battery with 50% capacity may be equivalent to a battery with 60% capacity after many years of use. However, the first capacity threshold remains constant. If the first capacity threshold is 60%, then a battery with 60% capacity after many years of use would have an equivalent actual capacity of 55%, causing a misjudgment of the pre-installed battery conditions. Therefore, it is necessary to ensure that the battery capacity can be replenished. This requires the power battery to have a certain capacity to charge the battery when its capacity falls below a safe level. However, the power battery also needs to support vehicle operation. Therefore, the power battery capacity in the operating parameters needs to be greater than or equal to a preset second capacity threshold (e.g., 20%) to ensure sufficient power for vehicle operation while also having the ability to charge the battery, ensuring a smooth upgrade process. This confirms that the pre-installed power battery conditions are met.
[0087] If the power battery charge is less than the preset second charge threshold, in order to ensure that the power battery has enough charge to drive the vehicle, additional power consumption is prohibited. At this time, power supply to the battery will be prohibited. Therefore, there is a risk of misjudging the battery charge, and it is determined that the front power battery condition is not met.
[0088] Step 5014: In response to the current vehicle speed being zero in the operating parameters, determine that the preceding vehicle speed condition is met.
[0089] In practice, upgrading the main unit's direct control screen may cause some functions of the vehicle's main unit to become unusable. Therefore, to avoid the risk of loss of control, the vehicle must remain relatively stationary. Specifically, the prerequisite speed condition is met when the current vehicle speed in the operating parameters is zero. If the current vehicle speed is not zero, it means the vehicle is in motion. Upgrading at this time would cause some functions of the vehicle's main unit to malfunction, potentially leading to loss of vehicle control and a traffic accident. Therefore, the prerequisite speed condition is not met when the current vehicle speed is not zero.
[0090] Step 5015: In response to the current gear being either park or neutral in the operating parameters, determine that the forward gear condition is met.
[0091] In practice, to avoid control command errors during the vehicle's lifting process, it's necessary to ensure the vehicle is in neutral or park. In these positions, the vehicle is in a relatively safe state, and the motor will not drive it. This prevents drive commands from being immediately sent to the motor after the upgrade (as commands may be temporarily suspended during the upgrade process), which could cause the vehicle to suddenly lurch forward and create a risk. Therefore, if the current gear in the operating parameters is park or neutral, the prerequisite gear condition is met. If the current gear in the operating parameters is any gear other than park or neutral, the prerequisite gear condition is not met.
[0092] Step 5016: In response to the handbrake status in the operating parameters being either pulled up or clamped, determine that the pre-positioned handbrake condition is met.
[0093] In practice, to prevent the vehicle from rolling away, it's necessary to further ensure that the vehicle's stationary state is not easily changed. Therefore, the handbrake needs to be engaged or clamped to keep the vehicle stationary, ensuring safety during the vehicle's main unit upgrade process. Thus, when the handbrake status in the operating parameters is engaged or clamped (the name for the handbrake activation may vary depending on the vehicle model), the front handbrake condition is met. When the handbrake status in the operating parameters is disengaged or released, the front handbrake condition is not met.
[0094] Step 5017: In response to the high or low voltage status in the operating parameters being either high voltage or low voltage, determine that the pre-energization conditions are met.
[0095] In practice, setting the power mode to "on" only ensures successful battery discharge, but it also requires that the vehicle's main unit is connected to power and that the vehicle's voltage status is confirmed. If the high / low voltage status in the operating parameters is high or low, it indicates that the vehicle's main unit and other controllers within the vehicle are powered on and can execute their corresponding functions, thus fulfilling the prerequisite power-on condition. If the operating parameters show no voltage status, it indicates that the vehicle's main unit and other controllers within the vehicle are not powered on, thus failing to meet the prerequisite power-on condition.
[0096] Step 5018: In response to the simultaneous fulfillment of the front mode condition, front battery bar condition, front power battery condition, front vehicle speed condition, front gear condition, front handbrake condition, and front power-on condition, determine that the upgrade front conditions are met.
[0097] In practice, if the following conditions are met simultaneously: front-mounted mode, front-mounted battery bar, front-mounted power battery, front-mounted vehicle speed, front-mounted gear position, front-mounted handbrake, and front-mounted power-on, it indicates that the vehicle allows the vehicle host to be upgraded and the vehicle host has the ability to complete the self-upgrade. This confirms that the upgrade prerequisites are met, and the host direct control screen can be upgraded.
[0098] Step 5019: In response to the fact that there are unmet conditions among the front mode conditions, front battery bar conditions, front power battery conditions, front vehicle speed conditions, front gear conditions, front handbrake conditions, and front power-on conditions, it is determined that the upgrade front conditions are not met.
[0099] In practice, if any one of the following conditions is not met: front mode condition, front battery bar condition, front power battery condition, front vehicle speed condition, front gear condition, front handbrake condition, or front power-on condition, it indicates that the upgrade may pose certain safety risks. For safety reasons, if the preconditions for the upgrade are not met, the pager screen upgrade is not permitted.
[0100] Step 502: In response to the failure to meet the prerequisite upgrade conditions, determine that the safety upgrade conditions are not met, and issue a prompt to change the vehicle status.
[0101] In practice, if the prerequisites for upgrading are not met, it means that the vehicle determines that upgrading the host-controlled screen would pose a safety risk. Therefore, the upgrade is not allowed regardless of the current screen temperature. Thus, the vehicle status is changed based on the unmet prerequisites to prompt the user to adjust the vehicle status to meet the prerequisites for upgrading, ensuring that the host can be safely upgraded.
[0102] Step 503: In response to meeting the prerequisite upgrade conditions, determine whether there is a risk of upgrade failure based on the current screen temperature.
[0103] In practice, if the prerequisites for upgrading are met, it indicates that the upgrade process will not pose a safety risk, and the vehicle's main unit is allowed to upgrade the main unit's directly controlled screen. However, it is necessary to further determine whether the main unit's directly controlled screen itself has the capability to be upgraded. The determination process is as follows:
[0104] In some embodiments, determining whether there is a risk of upgrade failure based on the current screen temperature includes:
[0105] Step 5031: Determine the operating temperature range of the target host direct control screen.
[0106] In practice, after determining that the vehicle is permitted to perform a self-upgrade of the host based on operating parameters, it is necessary to further determine whether the screen itself can perform the upgrade function. This is because the external environment and vehicle operation can cause temperature changes in the host-controlled screen, and different host-controlled screens have different operating temperature ranges. If the current screen temperature exceeds the corresponding operating temperature range, the target host-controlled screen may be unable to perform its full functions, or may experience malfunctions such as freezing, black screen, or system crashes. In this case, performing a system upgrade may result in incorrect positioning, such as data loss or upgrade failure. For example, the operating temperature range can be (-40°C, 85°C).
[0107] Step 5032: Determine the safe temperature range based on the difference between the working temperature range and the preset safe temperature range, and determine the upper and lower boundary temperatures of the safe temperature range.
[0108] In practice, since the current screen temperature does not remain stable at a single value, the operating temperature range needs to be adjusted to prevent the screen temperature from fluctuating repeatedly within and outside the operating temperature range. Therefore, the operating temperature range needs to be narrowed to obtain a safe temperature range. For example, if the operating temperature range is (-40, 85) and the preset safe temperature difference is 5℃, then the upper boundary temperature of 85℃ and the lower boundary temperature of -40℃ are narrowed inward, that is, the upper boundary temperature is decreased by 5℃ and the lower boundary temperature is increased by 5℃, resulting in a safe temperature range of (-35, 80). The upper boundary temperature of the safe temperature range is 80℃ and the lower boundary temperature is -35℃.
[0109] Step 5033: In response to the current screen temperature being greater than or equal to the upper boundary temperature, or the current screen temperature being less than or equal to the lower boundary temperature, it is determined that there is a risk of upgrade failure.
[0110] In practice, if the current screen temperature is greater than or equal to the upper boundary temperature, it indicates that the current screen temperature is too high, and the upgrade function cannot be executed, indicating a risk of upgrade failure. If the current screen temperature is less than or equal to the lower boundary temperature, it indicates that the current screen temperature is too low, and the upgrade function cannot be executed, indicating a risk of upgrade failure.
[0111] Step 5034: In response to the current screen temperature being lower than the upper boundary temperature and higher than the lower boundary temperature, it is determined that there is no risk of upgrade.
[0112] In practice, if the current screen temperature is lower than the upper boundary temperature but higher than the lower boundary temperature, it means that the target host directly controls the screen at a suitable operating temperature, and the corresponding upgrade function can be executed, confirming that there is no upgrade risk.
[0113] Step 504: In response to the risk of upgrade failure, determine that the conditions for safe upgrade are not met, and issue a screen temperature adjustment prompt.
[0114] In practice, if there is a risk of upgrade failure, it means that the target host's directly controlled screen does not have the capability to perform the upgrade operation, and the conditions for a safe upgrade are not met, so the upgrade operation is prohibited. Simultaneously, a screen temperature adjustment prompt will be displayed so that the user can adjust the screen temperature to a safe range.
[0115] Step 505: In response to the absence of upgrade failure risk, determine that the conditions for a safe upgrade are met.
[0116] In practice, if the current screen temperature is within the corresponding operating temperature range, it means that the target vehicle host can execute the corresponding upgrade process well, confirm that the safety upgrade conditions are met, and perform a separate software upgrade on the host-controlled screen that meets the safety upgrade conditions according to the legitimate upgrade package, so as to ensure the accuracy and safety of the upgrade process, and ensure the screen upgrade is successful on the first try while ensuring safety.
[0117] Since the screen temperature is constantly changing, if there is an initial risk of upgrade failure, the judgment will be changed to indicate no risk if the current screen temperature is within the safe temperature range. However, if the temperature changes again, to avoid repeated changes in the judgment, the judgment needs to be changed back to indicate a risk of upgrade failure if the current screen temperature exceeds the operating temperature range. In other words, the safe temperature range is used as the condition for determining no risk of upgrade failure, or the operating temperature range is used as the condition for switching to a condition indicating a risk of upgrade failure.
[0118] It should be noted that the method in this embodiment can be executed by a single device, such as a computer or server. The method can also be applied in a distributed scenario, where multiple devices cooperate to complete the task. In such a distributed scenario, one of these devices may execute only one or more steps of the method in this embodiment, and the multiple devices will interact with each other to complete the method described.
[0119] It should be noted that the above description describes some embodiments of this application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in a different order than that shown in the above embodiments and still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0120] Based on the same inventive concept, and corresponding to any of the above embodiments, this application also provides an upgrade control device for a vehicle screen.
[0121] refer to Figure 6 The upgrade control device for the vehicle screen includes:
[0122] The upgrade unpacking module 10 is configured to: obtain a signed and encrypted upgrade package, unpack the signed and encrypted upgrade package according to the root certificate deployed locally, and obtain at least one legitimate upgrade package;
[0123] The upgrade verification module 20 is configured to: determine the target host direct control screen to be upgraded corresponding to each legitimate upgrade package based on the diagnostic identification code of the legitimate upgrade package, and perform consistency verification on the target host direct control screen based on the part number of the legitimate upgrade package;
[0124] The upgrade security module 30 is configured to: in response to a successful consistency check, determine whether the security upgrade conditions are met based on the operating parameters and / or the current screen temperature of the target host direct control screen, and perform a separate software upgrade on the target host direct control screen that meets the security upgrade conditions based on a legitimate upgrade package.
[0125] For ease of description, the above devices are described in terms of function, divided into various modules. Of course, in implementing this application, the functions of each module can be implemented in one or more software and / or hardware.
[0126] The apparatus of the above embodiments is used to implement the corresponding vehicle screen upgrade control method in any of the foregoing embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0127] Based on the same inventive concept, corresponding to the methods of any of the above embodiments, this application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the vehicle screen upgrade control method described in any of the above embodiments.
[0128] Figure 7 This embodiment illustrates a more specific hardware structure of an electronic device, which may include a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. The processor 1010, memory 1020, input / output interface 1030, and communication interface 1040 are interconnected internally via the bus 1050.
[0129] The processor 1010 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.
[0130] The memory 1020 can be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage device, dynamic storage device, etc. The memory 1020 can store the operating system and other applications. When the technical solutions provided in the embodiments of this specification are implemented by software or firmware, the relevant program code is stored in the memory 1020 and is called and executed by the processor 1010.
[0131] The input / output interface 1030 is used to connect input / output modules to realize information input and output. Input / output modules can be configured as components within the device (not shown in the figure) or externally connected to the device to provide corresponding functions. Input devices may include keyboards, mice, touchscreens, microphones, various sensors, etc., while output devices may include displays, speakers, vibrators, indicator lights, etc.
[0132] The communication interface 1040 is used to connect a communication module (not shown in the figure) to enable communication between this device and other devices. The communication module can communicate via wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).
[0133] Bus 1050 includes a pathway for transmitting information between various components of the device, such as processor 1010, memory 1020, input / output interface 1030, and communication interface 1040.
[0134] It should be noted that although the above-described device only shows the processor 1010, memory 1020, input / output interface 1030, communication interface 1040, and bus 1050, in specific implementations, the device may also include other components necessary for normal operation. Furthermore, those skilled in the art will understand that the above-described device may only include the components necessary for implementing the embodiments of this specification, and not necessarily all the components shown in the figures.
[0135] The electronic devices described above are used to implement the corresponding vehicle screen upgrade control method in any of the foregoing embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0136] Based on the same inventive concept, corresponding to the methods of any of the above embodiments, this application also provides a non-transitory computer-readable storage medium storing computer instructions for causing the computer to execute the vehicle screen upgrade control method as described in any of the above embodiments.
[0137] The computer-readable medium of this embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transfer medium that can be used to store information accessible by a computing device.
[0138] The computer instructions stored in the storage medium of the above embodiments are used to cause the computer to execute the vehicle screen upgrade control method as described in any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0139] Based on the same inventive concept, corresponding to the methods of any of the above embodiments, this application also provides a vehicle, including the electronic device or vehicle screen upgrade control device of the above embodiments, and executes the vehicle screen upgrade control method as described in any of the above embodiments through the electronic device or vehicle screen upgrade control device of the above embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0140] It is understood that before using the technical solutions of the various embodiments in this disclosure, users will be informed of the type, scope of use, and usage scenarios of the personal information involved in an appropriate manner, and user authorization will be obtained.
[0141] For example, upon receiving a user's active request, a prompt message is sent to the user to explicitly inform them that the requested operation will require the acquisition and use of the user's personal information. This allows the user to independently choose, based on the prompt message, whether to provide personal information to the software or hardware such as electronic devices, applications, servers, or storage media performing the operations of this disclosed technical solution.
[0142] As an optional but not limited implementation, in response to a user's active request, sending a prompt message to the user can be done via a pop-up window, where the prompt message can be presented in text format. Furthermore, the pop-up window can also include a selection control allowing the user to choose "agree" or "disagree" to provide personal information to the electronic device.
[0143] It is understood that the above notification and user authorization process are merely illustrative and do not constitute a limitation on the implementation of this disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of this disclosure.
[0144] Those skilled in the art should understand that the discussion of any of the above embodiments is merely exemplary and is not intended to imply that the scope of this application is limited to these examples; under the concept of this application, the technical features of the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other variations of different aspects of the embodiments of this application as described above, which are not provided in detail for the sake of brevity.
[0145] Additionally, to simplify the description and discussion, and to avoid obscuring the embodiments of this application, the well-known power / ground connections to integrated circuit (IC) chips and other components may or may not be shown in the provided drawings. Furthermore, the apparatus may be shown in block diagram form to avoid obscuring the embodiments of this application, and this also takes into account the fact that the details of the implementation of these block diagram apparatuses are highly dependent on the platform on which the embodiments of this application will be implemented (i.e., these details should be fully understood by those skilled in the art). While specific details (e.g., circuits) have been set forth to describe exemplary embodiments of this application, it will be apparent to those skilled in the art that the embodiments of this application can be implemented without these specific details or with variations thereof. Therefore, these descriptions should be considered illustrative rather than restrictive.
[0146] Although this application has been described in conjunction with specific embodiments thereof, many substitutions, modifications, and variations of these embodiments will be apparent to those skilled in the art from the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) may be used with the embodiments discussed.
[0147] The embodiments of this application are intended to cover all such substitutions, modifications, and variations that fall within the broad scope of the claims of this application. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the embodiments of this application should be included within the protection scope of this application.
Claims
1. A method for upgrading and controlling a vehicle screen, characterized in that, include: Obtain the signed and encrypted upgrade package, and unpack the signed and encrypted upgrade package according to the root certificate deployed locally to obtain at least one legitimate upgrade package; The target host direct control screen to be upgraded is determined from among multiple screens corresponding to each of the legitimate upgrade packages based on the diagnostic identification code of the legitimate upgrade package, and the consistency verification of the target host direct control screen is performed based on the part number of the legitimate upgrade package. In response to the successful consistency check, the system determines whether the safety upgrade conditions are met based on the vehicle's operating parameters and the current screen temperature of the target host direct control screen. Then, it performs a separate software upgrade on the target host direct control screen that meets the safety upgrade conditions among the multiple screens according to the valid upgrade package. The step of determining whether the security upgrade conditions are met based on the operating parameters and the current screen temperature of the target host's directly controlled screen includes: Determine whether the upgrade prerequisites for the target host direct control screen are met based on the operating parameters. In response to the failure to meet the aforementioned upgrade prerequisites, it is determined that the safety upgrade conditions are not met, and a prompt to change the vehicle status is issued. In response to the fulfillment of the upgrade prerequisites, determine whether there is a risk of upgrade failure based on the current screen temperature; In response to the risk of upgrade failure, it is determined that the conditions for a safe upgrade are not met, and a screen temperature adjustment prompt is displayed; Since there is no risk of upgrade failure, the conditions for a safe upgrade have been determined.
2. The vehicle screen upgrade control method according to claim 1, characterized in that, The step of unpacking the signed encrypted upgrade package based on the locally deployed root certificate to obtain at least one legitimate upgrade package includes: At least one single upgrade package is extracted from the signed encrypted upgrade package; The single upgrade package is verified and decrypted based on the root certificate. The single upgrade package that passes the verification and decryption is identified as the legitimate upgrade package, and the single upgrade package that fails the verification and decryption is identified as the illegitimate upgrade package.
3. The vehicle screen upgrade control method according to claim 1, characterized in that, The step of determining the target host direct control screen to be upgraded from among multiple screens corresponding to each legitimate upgrade package based on the diagnostic identification code of the legitimate upgrade package includes: Determine the screen identification code for each screen; A target screen identification code that matches the diagnostic identification code is determined, and the screen corresponding to the target screen identification code is identified as the target host direct control screen.
4. The vehicle screen upgrade control method according to claim 1, characterized in that, The step of performing a consistency check on the target host direct control screen based on the part number of the legitimate upgrade package includes: Determine the screen component number of the target host's directly controlled screen; In response to the screen part number being consistent with the component number, it is determined that the consistency check has passed; In response to the inconsistency between the screen part number and the component number, it is determined that the consistency check has failed.
5. The vehicle screen upgrade control method according to claim 1, characterized in that, The step of determining whether the upgrade prerequisites for the target host direct-control screen are met based on the operating parameters includes: In response to the power mode being enabled in the operating parameters, it is determined that the pre-mode condition is met. In response to the battery charge in the operating parameters being greater than or equal to a preset first charge threshold, it is determined that the front battery condition is met. In response to the fact that the power battery charge in the operating parameters is greater than or equal to a preset second charge threshold, it is determined that the front power battery condition is met. In response to the current vehicle speed being zero in the operating parameters, it is determined that the preceding vehicle speed condition is met; In response to the current gear being either park or neutral in the operating parameters, it is determined that the forward gear condition is met; In response to the handbrake state being either pulled up or clamped in the operating parameters, it is determined that the pre-positioned handbrake condition is met. In response to the high or low voltage state in the operating parameters being either a high voltage state or a low voltage state, it is determined that the pre-energization condition is met. In response to simultaneously satisfying the aforementioned front mode condition, the aforementioned front battery bar condition, the aforementioned front power battery condition, the aforementioned front vehicle speed condition, the aforementioned front gear condition, the aforementioned front handbrake condition, and the aforementioned front power-on condition, it is determined that the aforementioned upgrade prerequisite condition is satisfied. If any of the following conditions are not met: the front mode condition, the front battery bar condition, the front power battery condition, the front vehicle speed condition, the front gear condition, the front handbrake condition, and the front power-on condition, it is determined that the upgrade prerequisite conditions are not met.
6. The vehicle screen upgrade control method according to claim 1, characterized in that, The step of determining whether there is a risk of upgrade failure based on the current screen temperature includes: Determine the operating temperature range of the target host direct control screen. The safe temperature range is determined based on the difference between the operating temperature range and the preset safe temperature range, and the upper and lower boundary temperatures of the safe temperature range are determined. In response to the current screen temperature being greater than or equal to the upper boundary temperature, or the current screen temperature being less than or equal to the lower boundary temperature, it is determined that there is a risk of upgrade failure. In response to the current screen temperature being lower than the upper boundary temperature and higher than the lower boundary temperature, it is determined that there is no risk of upgrade.
7. An upgrade control device for a vehicle screen, characterized in that, include: The upgrade unpacking module is configured to: obtain a signed and encrypted upgrade package, and unpack the signed and encrypted upgrade package according to the root certificate deployed locally to obtain at least one legitimate upgrade package; The upgrade verification module is configured to: determine the target host direct control screen to be upgraded among multiple screens corresponding to each of the legitimate upgrade packages based on the diagnostic identification code of the legitimate upgrade package, and perform consistency verification on the target host direct control screen based on the part number of the legitimate upgrade package; The upgrade security module is configured to: in response to a successful consistency check, determine whether the security upgrade conditions are met based on the vehicle's operating parameters and the current screen temperature of the target host direct control screen, and perform individual software upgrades on the target host direct control screens that meet the security upgrade conditions among the multiple screens according to the legitimate upgrade package; The step of determining whether the security upgrade conditions are met based on the operating parameters and the current screen temperature of the target host's directly controlled screen includes: Determine whether the upgrade prerequisites for the target host direct control screen are met based on the operating parameters. In response to the failure to meet the aforementioned upgrade prerequisites, it is determined that the safety upgrade conditions are not met, and a prompt to change the vehicle status is issued. In response to the fulfillment of the upgrade prerequisites, determine whether there is a risk of upgrade failure based on the current screen temperature; In response to the risk of upgrade failure, it is determined that the conditions for a safe upgrade are not met, and a screen temperature adjustment prompt is displayed; Since there is no risk of upgrade failure, the conditions for a safe upgrade have been determined.
8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that, When the processor executes the program, it implements the method as described in any one of claims 1 to 6.
9. A vehicle, characterized in that, This includes the vehicle screen upgrade control device as described in claim 7 or the electronic device as described in claim 8.
Citation Information
Patent Citations
Vehicle program upgrading method and device, electronic equipment and storage medium
CN115220753A
Upgrading method and device of vehicle-mounted display screen, electronic equipment and storage medium
CN118395510A