AMT program brushing method capable of preventing wrong brushing
By defining the vehicle model identification VehicleID_P in the AMT program and building a universal safety algorithm parameter group in the BootLoader and service tools, the high cost problem caused by customized safety algorithms in the design of different models is solved, and the accuracy and safety update of the AMT program is achieved.
Patent Information
- Application Number
- CN202411971614.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-30
- Publication Date
- 2025-05-06
AI Technical Summary
Due to the customized security algorithms designed by different models, the iteration cost, calibration cost and program version management cost when writing AMT program is sharply increased.
By defining the vehicle model identifier VehicleID_P in the AMT program and building a universal security algorithm parameter group in BootLoader and service tools, using VehicleID for program checksum security algorithm verification to ensure the accuracy and security of program updates.
It reduces program maintenance costs, ensures consistency between program checks and security algorithm verification, avoids malicious tampering of AMT programs, and thus avoids AMT programs incorrectly brushing.
Smart Images

Figure CN119938094A_ABST
Abstract
Description
Technical Field
[0001] The invention relates to an AMT program flashing method, and in particular to an AMT program flashing method that prevents error flashing. Background Art
[0002] At present, the electronically controlled mechanical automatic transmission (AMT) has rapidly occupied the domestic and international commercial vehicle market. Different vehicle configurations (such as engine, clutch, retarder, rear axle speed ratio and tire radius) will lead to inconsistent calibration parameters of the same AMT program. When the whole vehicle AMT program needs to be updated for function upgrades or software vulnerability repairs, it is necessary to flash the AMT program that matches the vehicle configuration. If the wrong program is flashed, the vehicle will not be able to drive normally, and in serious cases, it will endanger personal safety. However, the same AMT controller has the same flashing process. In order to avoid wrong flashing, different models need to be isolated during the flashing process.
[0003] Currently, the AMT program flashing process is controlled by the BootLoader in the AMT controller. It is usually necessary to design customized security algorithms for different vehicle models, so different BootLoader versions need to be managed. When the AMT application layer, bottom layer and BootLoader are upgraded, due to the customization of the security algorithm, any code upgrade will require reintegration of multiple versions of the AMT program and recalibration according to different versions of the AMT program, resulting in a sharp increase in the AMT program iteration cost, calibration cost and program version management cost.
[0004] The Chinese patent with publication number CN115543376A discloses a software refresh error-proof flashing method, which pre-identifies the software to be refreshed and the size and length of the file to be flashed, then reads the hardware version number to determine whether the controller hardware to be refreshed is the required hardware, and uses CRC32 or CRC16 algorithm to verify the file when flashing the driver file and APP file to ensure the consistency of data flashing and prevent the situation of incorrect software flashing. Finally, the hardware version, software version and software part number are read after the software refresh is completed. Although this method can improve the accuracy of flashing while ensuring the refresh efficiency of the AMT controller, the relevant hardware, corresponding software version and corresponding software number for the software refresh need to be manually added in the flashing configuration, and the customized Bootloader mechanism is still used. Summary of the invention
[0005] The purpose of the present invention is to solve the technical problem that the iteration cost, calibration cost and program version management cost increase sharply when flashing the AMT program due to the customized safety algorithm designed for different vehicle models, and to provide an AMT program flashing method that prevents error flashing.
[0006] To achieve the above object, the technical solution adopted by the present invention is:
[0007] A method for flashing an AMT program to prevent error flashing is special in that it includes the following steps:
[0008] Step 1. Define the vehicle type identification VehicleID_P in the AMT program, assign VehicleID_P to VehicleID, and after the AMT program is flashed into the AMT controller, store VehicleID in the AMT controller; set different universal safety algorithm parameter groups for different vehicle type identifications, and then build the universal safety algorithm parameter groups into the service tool and AMT controller respectively;
[0009] Step 2: When a program update request is received, the service tool is used to read the value of VehicleID_P from the AMT program that has been flashed; the BootLoader reads the value of VehicleID from the AMT controller and assigns it to VehicleID_sig, and the service tool reads the value of VehicleID from VehicleID_sig of the BootLoader, thereby obtaining the vehicle model identification VehicleID_P of the original AMT program in the AMT controller;
[0010] Step 3: The service tool compares the values of VehicleID_P and VehicleID. If they are the same, it executes step 4; otherwise, it rejects the program update.
[0011] Step 4. The BootLoader obtains the corresponding general security algorithm parameter group Para[VehicleID_sig] according to the value of VehicleID_sig, and the service tool obtains the corresponding general security algorithm parameter group Para[VehicleID] according to the value of VehicleID;
[0012] Step 5: The service tool sends a seed request to BootLoader, and BootLoader generates a seed array seed[] and sends it to the service tool;
[0013] Step 6: Input seed[] and Para[VehicleID_sig] into the general security algorithm built into the BootLoader to obtain the key key[VehicleID_sig]. At the same time, input seed[] and Para[VehicleID] into the general security algorithm built into the service tool to obtain the key key[VehicleID], and send the key[VehicleID] calculated by the service tool to the BootLoader.
[0014] Step 7. BootLoader compares key[VehicleID] and key[VehicleID_sig]. If the two are consistent, it will feedback to the service tool that the decryption is successful, and the service tool will start to update the program, and will flash the AMT program into the AMT controller to complete the flashing of the AMT program; otherwise, it will feedback to the service tool that the decryption is unsuccessful and the program update is rejected.
[0015] Further, in step 1, the VehicleID is stored in the NVRAM area in the AMT controller;
[0016] The VehicleID_P is stored in a fixed address in the AMT program calibration area.
[0017] Furthermore, step 2 is specifically as follows:
[0018] 2.1. When receiving a program update request, the service tool reads the value of VehicleID_P from the fixed address flashed into the AMT program;
[0019] 2.2. The service tool sends a request to read VehicleID to BootLoader through UDS22 service;
[0020] 2.3. BootLoader reads the mapped memory of VehicleID and assigns it to VehicleID_sig, then assigns the value on VehicleID_sig to the DID that supports service tool access, and sends a DID response to the service tool through the UDS 62 service;
[0021] 2.4. The service tool reads the VehicleID on the DID that supports service tool access, thereby obtaining the vehicle model identification VehicleID_P of the original AMT program in the AMT controller.
[0022] Furthermore, in step 2.3, the DID supporting access by the service tool only provides read permission to the service tool.
[0023] Furthermore, step 5 is specifically as follows:
[0024] The service tool sends a seed request to the BootLoader through the UDS27 05 service. The BootLoader generates a seed array seed[] and sends it to the service tool through the UDS 67 05 service.
[0025] Furthermore, in step 6, the general security algorithm built into the BootLoader is the same as the general security algorithm built into the service tool.
[0026] Furthermore, in step 6, the key [VehicleID] is sent to the BootLoader, specifically:
[0027] The service tool sends key[VehicleID] to the BootLoader via the UDS27 06 service.
[0028] Furthermore, in step 7, the feedback of decryption success to the service tool is specifically:
[0029] Feedback the decryption success to the service tool through UDS 67 06 service response;
[0030] The feedback to the service tool that the decryption fails is specifically:
[0031] The decryption failure is reported to the service tool through the UDS 7F 27 35 service response.
[0032] Compared with the prior art, the present invention has the following beneficial technical effects:
[0033] 1. In the AMT program flashing method for preventing wrong flashing provided by the present invention, a universal safety algorithm is implanted in the BootLoader, and different vehicle models can be isolated by using the same Bootloader, which greatly reduces the program maintenance cost;
[0034] 2. In the AMT program flashing method for preventing wrong flashing provided by the present invention, the connection between the vehicle type identification VehicleID_P in the AMT program and the BootLoader and the service tool is established through VehicleID, and the AMT program and the vehicle type information are matched one by one through VehicleID_P. At the same time, VehicleID_P controls the parameter group used in the general security algorithm of the BootLoader and the service tool, ensuring the consistency of the program verification and the security algorithm verification;
[0035] 3. In an AMT program flashing method for preventing wrong flashing provided by the present invention, the vehicle type identification of the AMT program to be flashed is compared with the vehicle type identification of the original AMT program in the AMT controller before the program is updated. Only when they are the same can the flashing process be allowed. At the same time, the general security algorithm parameter group and seed array corresponding to the vehicle type identification are input into the general security algorithm built into the service tool and the BootLoader, and the service tool is verified. If the keys calculated by the general security algorithm built into the service tool and the BootLoader are consistent, the program update is allowed, which can prevent the AMT program from being maliciously tampered with, thereby further preventing the AMT program from being flashed wrongly;
[0036] 4. In the AMT program flashing method for preventing wrong flashing provided by the present invention, the VehicleID is stored in the NVMRAM area in the AMT controller, and the BootLoader can access the mapped memory of the area. The value corresponding to the memory is assigned to the DID that the BootLoader supports service tools to access. The service tool requests the DID to clarify the vehicle model information of the original AMT program of the AMT controller;
[0037] 5. In the AMT program flashing method for preventing error flashing provided by the present invention, BootLoader only provides the service tool with read permission to support the service tool to access DID, but no write permission, which can prevent the service tool from making erroneous modifications or malicious tampering. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] Figure 1 is a flow chart of the method of the present invention;
[0039] Figure 2 This is a schematic diagram of vehicle type identification reading in an embodiment of the present invention;
[0040] Figure 3 Schematic diagram of data exchange between the service tool and BootLoader and verification of the service tool security algorithm in an embodiment of the present invention. DETAILED DESCRIPTION
[0041] The following is a further detailed description of the AMT program flashing method for preventing wrong flashing proposed by the present invention in conjunction with the accompanying drawings and specific embodiments. It should be understood by those skilled in the art that these embodiments are only used to explain the technical principles of the present invention and are not intended to limit the scope of protection of the present invention.
[0042] A method for flashing an AMT program to prevent error flashing, such as Figure 1 As shown, the following steps are included:
[0043] Step 1. Define the vehicle type identification VehicleID_P in the AMT program, assign VehicleID_P to VehicleID, and after the AMT program is flashed into the AMT controller, store VehicleID in the AMT controller; set different universal safety algorithm parameter groups for different vehicle type identifications, and then build the universal safety algorithm parameter groups into the service tool and AMT controller respectively.
[0044] VehicleID_P is compiled to a fixed address in the AMT program calibration area during program integration. VehicleID_P is the calibration value and supports offline and online changes. VehicleID_P is assigned to VehicleID. Changing VehicleID_P can change the value of VehicleID. VehicleID is stored in the NVRAM area in the AMT controller, which can be accessed by BootLoader at the same time. The connection between VehicleID_P and BootLoader in the AMT program is established through VehicleID. The value of VehicleID is assigned to DID by BootLoader. During the program flashing process, the service tool requests the DID to clarify the vehicle model identification of the original AMT program in the AMT controller. The connection between VehicleID_P in the AMT program and the service tool is established through DID.
[0045] Among them, offline modification of VehicleID_P can ensure that the AMT program corresponds to the vehicle information one by one. The vehicle model identification in the AMT controller is determined by the VehicleID_P of its internal AMT program. Online modification of VehicleID_P can support calibration personnel to repeatedly modify VehicleID during the algorithm debugging phase, thereby testing the parameter group of the input BootLoader and service tool security algorithm without multiple program updates. Figure 2 As shown, VehicleID_P can change the mapped memory A of VehicleID stored in the NVRAM area of the AMT controller. By powering off or resetting the AMT controller, the value of mapped memory A can be assigned to VehicleID. When VehicleID_P is changed, VehicleID is also changed accordingly. After powering on or resetting the AMT controller, the BootLoader can read the changed VehicleID from mapped memory B and assign it to DID. The AMT program can also read the changed VehicleID from mapped memory A.
[0046] Step 2: When receiving a program update request, the service tool reads the value of VehicleID_P from the AMT program that has been flashed; the BootLoader reads the value of VehicleID from the AMT controller and assigns it to VehicleID_sig, and the service tool reads the value of VehicleID from VehicleID_sig of the BootLoader. Specifically:
[0047] 2.1. When receiving a program update request, the service tool reads the value of VehicleID_P from the AMT program flashed into it;
[0048] 2.2, such as Figure 3 As shown, the service tool sends a request to read VehicleID to the BootLoader in the AMT controller through the UDS22 service;
[0049] 2.3. BootLoader reads the mapped memory B of VehicleID and assigns it to VehicleID_sig. Then it assigns the value on VehicleID_sig to the DID that supports service tool access and sends a DID response to the service tool through the UDS 62 service.
[0050] 2.4. The service tool reads the VehicleID on the DID that supports service tool access, thereby obtaining the vehicle model identification VehicleID_P of the original AMT program in the AMT controller.
[0051] The value of VehicleID is determined by VehicleID_P, so the service tool can clearly identify the vehicle model identification VehicleID_P of the original AMT program in the AMT controller.
[0052] In this step, the DID that supports service tool access only opens read permissions to the service tool to prevent the service tool from tampering with the vehicle model identification.
[0053] Step 3. The service tool compares the values of VehicleID_P and VehicleID. If the two are the same, it means that the vehicle type identification VehicleID_P of the AMT program flashed into the AMT controller is consistent with the vehicle type identification VehicleID_P of the original AMT program in the AMT controller, and execute step 4; otherwise, it means that the AMT program flashed into the AMT controller does not match the vehicle information, and the program update is rejected.
[0054] Step 4. The BootLoader obtains the corresponding general safety algorithm parameter group Para[VehicleID_sig] according to the value of VehicleID_sig, and the service tool obtains the corresponding general safety algorithm parameter group Para[VehicleID] according to the value of VehicleID.
[0055] like Figure 2As shown, BootLoader reads the mapped memory B of VehicleID and assigns the mapped memory B to VehicleID_sig to obtain the parameter group Para[VehicleID_sig] for inputting the BootLoader security algorithm. At the same time, BootLoader assigns VehicleID_sig to DID. The service tool reads the value of DID from BootLoader through the UDS22 service to obtain VehicleID, thereby obtaining its corresponding universal security algorithm parameter group Para[VehicleID]. If VehicleID_P and VehicleID are the same, the program verification passes and enters the security algorithm verification stage.
[0056] Step 5: Figure 3 As shown, the service tool sends a seed request to the BootLoader through the UDS27 05 service. The BootLoader generates seed[] and sends it to the service tool through the UDS 67 05 service.
[0057] Step 6: Input seed[] and Para[VehicleID_sig] into the general security algorithm built into the BootLoader to obtain the key key[VehicleID_sig]. At the same time, input seed[] and Para[VehicleID] into the general security algorithm built into the service tool to obtain the key key[VehicleID], and the service tool sends key[VehicleID] to the BootLoader through the UDS27 06 service. The security algorithm built into the BootLoader is the same as the security algorithm built into the service tool.
[0058] Step 7. BootLoader compares key[VehicleID] and key[VehicleID_sig]. If they are consistent, the service tool is informed of the successful decryption through the UDS 67 06 service response. The service tool starts to update the program and writes the AMT program to the AMT controller to complete the writing of the AMT program. Otherwise, the service tool is informed of the failed decryption through the UDS 7F 27 35 service response and the program update is rejected.
[0059] When the AMT program needs to be updated due to function upgrades or software vulnerability repairs, a two-step verification process is required to ensure that the vehicle model corresponds to the AMT program. The first step is program verification, and the second step is security algorithm verification. When the service tool receives a program update request, it enters the program verification phase. It first reads the VehicleID_P at a fixed address in the AMT program that is flashed, and then reads the VehicleID stored in the AMT controller through the UDS22 service by the BootLoader. The value of the VehicleID stored in the AMT controller is determined by the VehicleID_P of the original AMT program in the AMT controller. If the two are inconsistent, it means that the vehicle model identification of the AMT program that is flashed is inconsistent with the vehicle model identification of the original AMT program in the AMT controller, and the flashing process is refused. If the two are consistent, it means that the vehicle model identification of the AMT program that is flashed is consistent with the vehicle model identification of the original AMT program in the AMT controller, and the flashing process is allowed. Before erasing the original AMT program of the AMT controller, the service tool security algorithm verification phase is entered, and the security algorithm of the service tool is verified using the value of the same vehicle model identification. If the verification passes, it means that the service tool has a built-in security algorithm that is the same as the AMT controller BootLoader and is an approved service tool. In this case, the service tool is allowed to update the program. If it fails, it means that the service tool is inconsistent with the AMT controller BootLoader security algorithm and is an unapproved service tool. In order to prevent illegal tampering, the program update is refused.
[0060] In this embodiment, the service tool security algorithm verification can only be performed after the program verification passes. If only the service tool security algorithm verification passes, it may cause the AMT program that does not correspond to the vehicle model information to be flashed into the AMT controller. The reason is that the service tool security algorithm verification process is a verification between the service tool and the original AMT program of the AMT controller, which has nothing to do with the AMT program flashed in. In this embodiment, the program verification is first performed to ensure that the AMT program flashed in matches the vehicle model information, and then the service tool security algorithm verification is performed to prevent the AMT program from being maliciously tampered with, thereby avoiding the AMT program from being flashed incorrectly.
Claims
1. A method for flashing an AMT program to prevent error flashing, characterized in that: The following steps are involved: Step 1. Define the vehicle identification VehicleID_P in the AMT program, assign VehicleID_P to VehicleID, and after the AMT program is flashed into the AMT controller, store VehicleID in the AMT controller; set different universal safety algorithm parameter groups for different vehicle identifications, and then build the universal safety algorithm parameter groups into the service tool and AMT controller respectively; Step 2: When a program update request is received, the service tool is used to read the value of VehicleID_P from the AMT program that has been flashed; the BootLoader reads the value of VehicleID from the AMT controller and assigns it to VehicleID_sig, and the service tool reads the value of VehicleID from VehicleID_sig of the BootLoader, thereby obtaining the vehicle model identification VehicleID_P of the original AMT program in the AMT controller; Step 3: The service tool compares the values of VehicleID_P and VehicleID. If they are the same, it executes step 4; otherwise, it rejects the program update. Step 4. The BootLoader obtains the corresponding general security algorithm parameter group Para[VehicleID_sig] according to the value of VehicleID_sig, and the service tool obtains the corresponding general security algorithm parameter group Para[VehicleID] according to the value of VehicleID; Step 5: The service tool sends a seed request to BootLoader, and BootLoader generates a seed array seed[] and sends it to the service tool; Step 6. Input seed[] and Para[VehicleID_sig] into the general security algorithm built into the BootLoader to obtain the key key[VehicleID_sig]. At the same time, input seed[] and Para[VehicleID] into the general security algorithm built into the service tool to obtain the key key[VehicleID], and send the key[VehicleID] calculated by the service tool to the BootLoader. Step 7. BootLoader compares key[VehicleID] and key[VehicleID_sig]. If the two are consistent, it will feedback to the service tool that the decryption is successful, and the service tool will start to update the program, and will flash the AMT program into the AMT controller to complete the flashing of the AMT program; otherwise, it will feedback to the service tool that the decryption is unsuccessful and the program update is rejected.
2. The AMT program flashing method for preventing error flashing according to claim 1, characterized in that: In step 1, the VehicleID is stored in the NVRAM area of the AMT controller; The VehicleID_P is stored in a fixed address in the AMT program calibration area.
3. The AMT program flashing method for preventing error flashing according to claim 2 is characterized in that: Step 2 is as follows: 2.
1. When receiving a program update request, the service tool reads the value of VehicleID_P from the fixed address flashed into the AMT program; 2.
2. The service tool sends a request to read VehicleID to BootLoader through UDS22 service; 2.
3. BootLoader reads the mapped memory of VehicleID and assigns it to VehicleID_sig, then assigns the value on VehicleID_sig to the DID that supports service tool access, and sends a DID response to the service tool through the UDS 62 service; 2.
4. The service tool reads the VehicleID on the DID that supports service tool access, thereby obtaining the vehicle model identification VehicleID_P of the original AMT program in the AMT controller.
4. The AMT program flashing method for preventing error flashing according to claim 3 is characterized in that: In step 2.3, the DID supporting service tool access only provides read permission to the service tool.
5. A method for flashing an AMT program with error-proof flashing according to any one of claims 1 to 4, characterized in that: Step 5 is as follows: The service tool sends a seed request to the BootLoader through the UDS27 05 service. The BootLoader generates a seed array seed[] and sends it to the service tool through the UDS 67 05 service.
6. The AMT program flashing method for preventing wrong flashing according to claim 5 is characterized in that: In step 6, the general security algorithm built into the BootLoader is the same as the general security algorithm built into the service tool.
7. The AMT program flashing method for preventing wrong flashing according to claim 6 is characterized in that: In step 6, the key [VehicleID] is sent to the BootLoader, specifically: The service tool sends key[VehicleID] to the BootLoader via the UDS27 06 service.
8. The AMT program flashing method for preventing error flashing according to claim 7 is characterized in that: In step 7, the decryption success is fed back to the service tool, specifically: Feedback the decryption success to the service tool through UDS 67 06 service response; The feedback to the service tool that the decryption fails is specifically: The decryption failure is reported to the service tool through the UDS 7F 27 35 service response.
Citation Information
Patent Citations
Software refreshing mistake-proofing flashing method
CN115543376A
Cited By
AMT control program batch generation and modification method
CN120803538A
AMT control program batch generation and modification method
CN120803538B