Firmware upgrading method and system
By introducing a remote firmware upgrade system into the terminal equipment of the unmanned combat platform, the connection between the firmware server, control server and terminal is used to achieve efficient and secure firmware upgrades, solving the problems of low upgrade efficiency and security risks in the existing technology.
Patent Information
- Application Number
- CN202510049346.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-13
- Publication Date
- 2025-05-09
AI Technical Summary
The terminal equipment of the existing unmanned combat platform relies on offline upgrade mode, resulting in low upgrade efficiency, is not conducive to the promotion of new technologies and improvement of existing functions, and poses safety risks.
By establishing a connection between the firmware server and the control server, and using multiple terminals to connect to the firmware server and the control server respectively, remote firmware upgrade is achieved. The specific steps include: the firmware server forms an upgrade task and issues it to the control server. The control server determines the upgrade conditions based on the device parameter information and sends the upgrade reference information, the terminal verifies the public key information and accesses the firmware server to obtain the upgrade installation package for firmware upgrade.
Remote upgrade of the terminal is realized, upgrade efficiency is improved, security is ensured during the remote upgrade process, and security vulnerabilities in a single public key system are avoided.
Smart Images

Figure CN119960796A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular to a firmware upgrade method and system. Background Art
[0002] In the existing technical framework, the terminal equipment of unmanned combat platforms generally relies on offline upgrade mode for software and system updates. Although this traditional upgrade method ensures the security of data transmission to a certain extent and avoids the risks that may be brought about by updating directly through the network, it exposes obvious limitations when facing large-scale deployment scenarios.
[0003] First, it greatly limits the upgrade efficiency, because each upgrade needs to be done manually or through physical media one by one, which is not only time-consuming and labor-intensive, but also difficult to achieve rapid response in emergency situations; secondly, for technologies that require frequent iterations, such an update mechanism is obviously not conducive to the rapid promotion and application of new technologies and the immediate improvement and expansion of existing application functions. Summary of the invention
[0004] The present invention provides a firmware upgrade method and system, which realizes the remote upgrade of a terminal, improves the upgrade efficiency, and ensures the security during the remote upgrade process.
[0005] In a first aspect, an embodiment of the present disclosure provides a firmware upgrade method, which is applied to a firmware upgrade system, wherein the firmware upgrade system includes a firmware server, a control server, and multiple terminals, wherein the firmware server is connected to the control server, and the firmware server and the control server are respectively connected to the terminals, and each terminal is deployed with multiple electronic control units ECU, wherein the method includes:
[0006] By means of the firmware server, when a first upgrade condition is met, an upgrade task for a target ECU is formed and the upgrade task is sent to the control server, wherein the upgrade task at least includes device parameter information of the target ECU and first public key information of the firmware server;
[0007] Determine, by the control server, whether the target ECU meets the second upgrade condition according to the device parameter information, and if so, send upgrade reference information to the target terminal where the target ECU is located, wherein the upgrade reference information includes at least the first public key information of the firmware server, the second public key information of the control server, and upgrade path information;
[0008] The first public key information and the second public key information are verified through the target terminal. When the verification is passed, the firmware server is accessed through the upgrade path information to obtain an upgrade installation package, and the firmware of the target ECU is upgraded based on the upgrade installation package.
[0009] In a second aspect, an embodiment of the present disclosure provides a firmware upgrade system, including:
[0010] A firmware server, a control server and a plurality of terminals, wherein the firmware server is connected to the control server, and the firmware server and the control server are respectively connected to the terminals, and each terminal is deployed with a plurality of electronic control units ECU;
[0011] The firmware server is used to form an upgrade task for the target ECU and send the upgrade task to the control server when the first upgrade condition is met, wherein the upgrade task at least includes device parameter information of the target ECU and first public key information of the firmware server;
[0012] The control server is used to determine whether the target ECU meets the second upgrade condition according to the device parameter information, and if so, send upgrade reference information to the target terminal where the target ECU is located, wherein the upgrade reference information at least includes the first public key information of the firmware server, the second public key information of the control server, and the upgrade path information;
[0013] The target terminal is used to verify the first public key information and the second public key information. When the verification is passed, the target terminal accesses the firmware server through the upgrade path information, obtains the upgrade installation package, and performs firmware upgrade on the target ECU based on the upgrade installation package.
[0014] A firmware upgrade method and system according to an embodiment of the present invention, through the firmware server, when the first upgrade condition is met, an upgrade task for the target ECU is formed and the upgrade task is sent to the control server, the upgrade task at least includes the device parameter information of the target ECU and the first public key information of the firmware server; through the control server, it is determined whether the target ECU meets the second upgrade condition according to the device parameter information, if it does, the upgrade reference information is sent to the target terminal where the target ECU is located, the upgrade reference information at least includes the first public key information of the firmware server, the second public key information of the control server and the upgrade path information; through the target terminal, the first public key information and the second public key information are verified, and when the verification is passed, the firmware server is accessed through the upgrade path information to obtain the upgrade installation package, and the target ECU is upgraded based on the upgrade installation package. The above technical solution realizes the remote upgrade of the terminal, improves the upgrade efficiency, and ensures the security during the remote upgrade process.
[0015] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present invention, nor are they intended to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0017] Figure 1 is a flowchart of a firmware upgrade method provided by Embodiment 1 of the present invention;
[0018] Figure 2 It is a structural diagram of a firmware upgrade system provided by Embodiment 1 of the present invention;
[0019] Figure 3 It is a structural diagram of a firmware upgrade system provided in Embodiment 2 of the present invention. DETAILED DESCRIPTION
[0020] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.
[0021] It should be noted that the terms "first", "second" and "target" in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0022] In order to solve the limitations of offline upgrade methods, many remote upgrade methods have emerged. However, many current remote upgrade solutions use a single public key encryption system to ensure data integrity and confidentiality during the communication process. This method has a significant security vulnerability: if an attacker can successfully hack into the public key server or obtain the root key, the entire trust chain built on the public key system will become vulnerable. Once this happens, not only will a single unmanned combat unit be threatened, but more seriously, all unmanned combat systems using the same public key system may be out of control at the same time, which is extremely easy to be maliciously manipulated, resulting in huge security risks. Therefore, finding a new solution that can both improve upgrade efficiency and enhance security has become an urgent problem to be solved.
[0023] Embodiment 1
[0024] Figure 1 This is a flowchart of a firmware upgrade method provided in Embodiment 1 of the present invention. This embodiment is applicable to remote firmware upgrade scenarios. The method can be executed by a firmware upgrade system, which can be implemented in the form of hardware and / or software.
[0025] Figure 2 is a schematic diagram of the structure of a firmware upgrade system provided by the first embodiment of the present invention, such as Figure 2 As shown, the firmware upgrade system includes a firmware server, a control server and multiple terminals. The firmware server is connected to the control server, and the firmware server and the control server are respectively connected to the terminal. A terminal main control unit and multiple electronic control units (Electronic Control Unit, ECU) are deployed on each terminal. The terminal is connected to the firmware server and the control server respectively through the terminal main control unit, and the terminal main control unit is also connected to each ECU respectively. The firmware upgrade system may also include a time server, which is directly connected to each ECU in the terminal for ECU timing. In addition, if there is no clock component in the firmware server or the control server, the time server may also be connected to the firmware server and the control server accordingly. Among them, the connection method between the firmware server, the control server and the terminal is a radio connection through a wireless network / radio station, and the connection method between the terminal main control unit and each ECU in the terminal can be a radio connection or a wired connection, which is not limited in this embodiment.
[0026] Among them, the firmware server is used to store upgraded images, patches, files, etc., has a storage management function, provides two sets of call interfaces, one private interface and one public interface, the private interface is used to upload the upgrade file and its description information internally, and the public interface is used to send the upgrade file and description information to the terminal, and has four permissions: super administrator role, upgrade snapshot role, upgrade release role, and upgrade target role. The control server is used to manage the entire upgrade process and has a task management function. It is specifically used to store the hardware identification information and software version information of the upgrade target sent by the firmware server, as well as the public key information of the firmware server, collect the hardware identification information and software version information reported by the terminal where the upgrade target is located, issue upgrade instructions and the location of the upgrade file, etc., and has four permissions: super administrator role, upgrade snapshot role, upgrade release role, and upgrade target role. The clock server provides unified timing for the upgrade process and signs the timing information, and has a timing function. The terminal is the device end for deploying the unmanned combat system, which can be a vehicle, an aircraft, or other device end, or even a ship, etc., and this embodiment does not limit this. The terminal includes a terminal main control unit and multiple electronic control units ECU. The terminal main control unit is used to manage the upgrade process of the target ECU as the upgrade target, and the target ECU is used to execute the upgrade process. Compared with the ECU, the terminal main control unit has stronger processing and computing capabilities.
[0027] It can be understood that the firmware upgrade method and system provided by the embodiments of the present invention can be applied not only to unmanned combat scenarios on land, but also to remote upgrades of devices in daily life scenarios.
[0028] like Figure 1 As shown, the method includes:
[0029] S101. Through the firmware server, when a first upgrade condition is met, an upgrade task for a target ECU is generated and sent to a management and control server. The upgrade task includes at least device parameter information of the target ECU and first public key information of the firmware server.
[0030] In this embodiment, the first upgrade condition can be understood as an active upgrade condition, and when certain upgrade controls for the target ECU are triggered, it is determined that the first upgrade condition is met. The target ECU can be understood as the designated ECU to be upgraded. It can be understood that there can be only one target ECU at the same time, but in order to achieve batch upgrades of multiple ECUs and improve the efficiency of firmware upgrades, there can also be multiple target ECUs at the same time. The device parameter information can be understood as the target ECU parameter information, including at least hardware identification information and software version information. The first public key information can be understood as the public key information of the firmware server, which is the public key information formed based on the role signature deployed on the firmware server, including at least four types of role signature information, such as the signature information of the super administrator role, the signature information of the upgrade release role, the signature information of the upgrade snapshot role, and the signature information of the upgrade target role. Among them, the super administrator role has the highest system authority, and its key will be stored offline, signing all other roles including its own role (such as upgrade release role, upgrade snapshot role and upgrade target role); the upgrade release role has the authority to manage the release of upgrade tasks, and its key will be stored online, signing the currently released (latest one to be released) upgrade snapshot role; the upgrade snapshot role has the authority to manage the upgrade tasks of all target ECUs (multiple electronic control units to be upgraded in land unmanned combat systems), signing the upgrade tasks of multiple target ECUs; the upgrade target role has the authority to manage the upgrade tasks of a single target ECU to be upgraded, signing the upgrade tasks of a single target ECU to be upgraded.
[0031] Specifically, when the firmware server receives the upgrade installation package for the target ECU uploaded by calling the private interface, or after receiving the upgrade installation package, the control indicating the upgrade of the target ECU is triggered at a certain time, it is determined that the first upgrade condition for the target ECU is met. At this time, based on the device parameter information of the target ECU and the first public key information of the firmware server, an upgrade task is formed and sent to the control server, so that the control server manages the corresponding upgrade process. When receiving the access request formed by the target terminal where the target ECU is located based on the upgrade task, the public interface is called to transmit the upgrade installation package corresponding to the target ECU to the target terminal.
[0032] S102. Determine whether the target ECU meets the second upgrade condition based on the device parameter information through the management and control server. If so, send the upgrade reference information to the target terminal where the target ECU is located. The upgrade reference information includes at least the first public key information of the firmware server, the second public key information of the management and control server, and the upgrade path information.
[0033] In this embodiment, the second upgrade condition can be understood as a condition for identifying whether the target ECU indicated by the firmware server is consistent with the actual target ECU. The upgrade reference information can be understood as the pre-information used to implement the firmware upgrade, including the first public key information of the firmware server, the second public key information of the control server, and the upgrade path information, wherein the second public key information can be understood as the public key information of the control server, which is the public key information formed based on the role signature deployed on the control server, including at least four types of role signature information, such as the signature information of the super administrator role, the signature information of the upgrade release role, the signature information of the upgrade snapshot role, and the signature information of the upgrade target role. The first public key information and the second public key information are used to enable the terminal to verify whether the upgrade process is safe. The upgrade path information can be understood as the access link to access the firmware server to obtain the upgrade installation package of the target ECU.
[0034] Specifically, after receiving the upgrade task sent by the firmware server, the control server stores the upgrade task, determines the target ECU to be upgraded and the target terminal where the target ECU is located according to the device parameter information in the upgrade task, verifies whether the target ECU on the target terminal is consistent with the target ECU indicated by the firmware server, and if so, determines that the second upgrade condition is met, otherwise, determines that it is not met. If the second upgrade condition is met, the subsequent upgrade process is executed, and the first public key information of the firmware server, the second public key information of the control server, and the upgrade path information are sent to the target terminal where the target ECU is located, so that the target terminal can access the firmware server to obtain the upgrade installation package of the target ECU after verifying the upgrade security, and then execute the firmware upgrade of the target ECU.
[0035] S103. Verify the first public key information and the second public key information through the target terminal. When the verification is successful, access the firmware server through the upgrade path information to obtain the upgrade installation package, and perform firmware upgrade on the target ECU based on the upgrade installation package.
[0036] In this embodiment, the target terminal can be understood as the terminal where the target ECU is located. The upgrade installation package can be understood as upgrade information for upgrading the target ECU, including at least an upgrade file and description information of the upgrade file.
[0037] Specifically, after the target terminal obtains the upgrade reference information sent by the control server, it first verifies the first public key information and the second public key information. When the key pairs of the four roles corresponding to the first public key information and the key pairs of the four roles corresponding to the second public key information match, it is determined that the verification is successful, indicating that the upgrade path information is secure. At this time, the firmware server can be accessed through the upgrade path information to obtain the upgrade installation package for the target ECU, and the firmware of the target ECU can be upgraded based on the upgrade installation package.
[0038] A firmware upgrade method provided by an embodiment of the present invention includes, through a firmware server, when a first upgrade condition is met, forming an upgrade task for a target ECU and sending the upgrade task to a control server, wherein the upgrade task includes at least device parameter information of the target ECU and first public key information of the firmware server; through the control server, determining whether the target ECU meets a second upgrade condition based on the device parameter information, and if so, sending upgrade reference information to a target terminal where the target ECU is located, wherein the upgrade reference information includes at least the first public key information of the firmware server, the second public key information of the control server, and upgrade path information; through the target terminal, verifying the first public key information and the second public key information, and when the verification is passed, accessing the firmware server through the upgrade path information, obtaining an upgrade installation package, and performing a firmware upgrade on the target ECU based on the upgrade installation package. The above technical solution divides the upgrade service background management end into two independent services, one is the firmware server, and the other is the control server; access control is performed on the four roles of the super administrator role, upgrade release role, upgrade snapshot role and upgrade target role for the above two servers; the terminal upgrade master control process needs to perform identity authentication on all roles of each service based on the information provided by the above two services; the upgrade efficiency of the land unmanned combat system can be improved through remote upgrade, and multiple types and quantities can be supported for simultaneous upgrade; by setting up multiple management roles and multiple services to form a secure remote upgrade protection system, it can be ensured that the remote upgrade process of the land unmanned combat system is not easily invaded by hackers, and in the case of the loss of a part of the system key, the entire remote system is not completely controlled by hackers, thereby causing malicious remote control or destruction of the land unmanned combat system, greatly improving the security of the system upgrade process and operation process.
[0039] In one embodiment, when the first upgrade condition is met, an upgrade task for the target ECU is formed and the upgrade task is sent to the control server, including:
[0040] S1011. Obtain an upgrade installation package through a private interface, where the upgrade installation package at least includes an upgrade file and description information of the upgrade file.
[0041] In this embodiment, the private interface is only used for internal calls to realize the interaction of internal files and information. The upgrade file can be understood as a firmware upgrade file or a software update package, which is a new version used to update the existing firmware version on the device, including new functions, performance improvements, security patches, and bug fixes. The description information of the upgrade file refers to a series of metadata related to the upgrade file, which describes important information such as the content, version number, release date, compatibility requirements, and installation steps of the upgrade file.
[0042] Specifically, the firmware server has a public interface and a private interface, and obtains the internally uploaded upgrade installation package for a single ECU or multiple ECUs through the private interface. Each upgrade installation package includes at least an upgrade file and its description information.
[0043] S1012. When the first upgrade condition is met, the first hardware identification information and the first software version information of the target ECU are used as device parameter information, and the signature information of the super administrator role corresponding to the firmware server, the signature information of the upgrade release role, the signature information of the upgrade snapshot role, and the signature information of the upgrade target role are used as the first public key information.
[0044] In this embodiment, the first hardware identification information can be understood as the hardware identification information for the target ECU obtained by the firmware server from the internal client, which is the hardware identification information input or selected by the client, and the hardware identification information can be understood as the identity document (ID) of the target ECU. The first software version information can be understood as the software version information for the target ECU obtained by the firmware server from the internal client, which is the software version information input or selected by the client, and the software version information can be understood as the software update version number, that is, the firmware update version number.
[0045] In this embodiment, after obtaining an indication of a target ECU upgrade triggered by the client (for example, an upgrade installation package for the target ECU is uploaded or an upgrade control for the target ECU is selected and triggered), it is determined that the first upgrade condition is currently met, and the first hardware identification information and the first software version information of the target ECU indicated by the client are used as device parameter information. Based on the four roles of the firmware server itself, namely, the super administrator role, the upgrade release role, the upgrade snapshot role, and the upgrade target role, corresponding signature information is formed respectively, and the first public key information of the firmware server is formed according to the four types of key pairs contained in these four types of signature information.
[0046] S1013. An upgrade task for the target ECU is formed based on the device parameter information and the first public key information, and the upgrade task is sent to the management and control server.
[0047] In this embodiment, the device parameter information for the target ECU and the first public key information of the firmware server itself are combined to form an upgrade task for the target ECU. Based on the connection relationship between the firmware server and the control server, the upgrade task is sent to the control server so that the control server manages the upgrade process for the target ECU.
[0048] In one embodiment, determining whether the target ECU meets the second upgrade condition according to the device parameter information, and if so, sending the upgrade reference information to the target terminal where the target ECU is located, includes:
[0049] S1021. After receiving the upgrade task sent by the firmware server, generate query request information, send the query request information to the target terminal where the target ECU is located, and obtain feedback information sent back by the target terminal.
[0050] In this embodiment, the query request information can be understood as a request for obtaining the current actual device information of the target ECU on the target terminal. The feedback information can be understood as the actual device information of the target ECU returned by the target terminal.
[0051] Specifically, after receiving the upgrade task sent by the firmware server, the management and control server identifies the target terminal where the target ECU is located based on the upgrade task, forms query request information for the target ECU, and sends the query request information to the target terminal where the target ECU is located, so that the target terminal queries the hardware identification information and software version information of the target ECU, and finally obtains the target terminal feedback information, and decrypts and parses the feedback information returned by the target terminal to obtain the hardware identification information and software version information of the target ECU, as well as the terminal status information of the target terminal.
[0052] S1022. Determine whether the target ECU meets a second upgrade condition according to the device parameter information and the feedback information.
[0053] In this embodiment, the device information of the target ECU indicated by the client connected to the firmware server is compared with the device information reported by the target ECU itself. If the two are consistent and the target terminal where the target ECU is located is in a non-operating state at the moment, it indicates that the second upgrade condition is currently met. Otherwise, if any of the above is not met, it is determined that the second upgrade condition is not currently met.
[0054] S1023. If satisfied, the first public key information of the firmware server, the second public key information of the control server, and the upgrade path information of the firmware server are used as upgrade reference information, and the upgrade reference information is sent to the target terminal where the target ECU is located. The second public key information includes the signature information of the super administrator role corresponding to the control server, the signature information of the upgrade release role, the signature information of the upgrade snapshot role, and the signature information of the upgrade target role.
[0055] In this embodiment, corresponding signature information is formed based on the four roles of the super administrator role, upgrade release role, upgrade snapshot role and upgrade target role of the control server itself, and the second public key information of the control server is formed according to the four key pairs contained in the four signature information. According to the upgrade task issued by the firmware server, an access link is formed from the target terminal where the target ECU is located to the firmware server, which serves as the upgrade path information of the firmware server relative to the target ECU. The first public key information of the firmware server, the second public key information of the control server and the upgrade path information of the firmware server are combined as the upgrade reference information of the target ECU, and the upgrade reference information is sent to the target terminal where the target ECU is located, so that the target terminal performs key pair verification based on the upgrade reference information, and executes the firmware upgrade for the target ECU after the verification is completed.
[0056] Further, determining whether the target ECU meets the second upgrade condition according to the device parameter information and the feedback information includes:
[0057] a1. Compare the first hardware identification information in the device parameter information with the second hardware identification information in the feedback information to obtain a first comparison result.
[0058] In this embodiment, the second hardware identification information can be understood as the hardware identification information fed back by the target ECU itself, which is the actual hardware identification information. The first comparison result can be understood as the result indicating whether the first hardware identification information and the second hardware identification information are consistent, including consistency and inconsistency.
[0059] Specifically, the first hardware identification information in the device parameter information and the second hardware identification information in the feedback information are compared to determine whether the hardware identification information indicated by the client corresponding to the firmware server is consistent with the actual hardware identification information reported by the target ECU, and obtain a corresponding first comparison result.
[0060] b1. Compare the first software version information in the device parameter information with the second software version information in the feedback information to obtain a second comparison result.
[0061] In this embodiment, the second software version information can be understood as the software version information fed back by the target ECU itself, which is the actual software version information. The second comparison result can be understood as the result indicating whether the first software version information and the second software version information are consistent, including consistency and inconsistency.
[0062] Specifically, the first software version information in the device parameter information and the second software version information in the feedback information are compared to determine whether the software version information indicated by the client corresponding to the firmware server is consistent with the actual software version information reported by the target ECU, and obtain the corresponding second comparison result.
[0063] c1. If both the first comparison result and the second comparison result indicate that the comparisons are consistent, and the terminal status information in the feedback information meets the upgrade status condition, it is determined that the current target ECU meets the second upgrade condition.
[0064] In this embodiment, the terminal status information can be understood as information indicating whether the terminal is in an operating state, including an operating state and a non-operating state. The upgrade status condition can be understood as a precondition for determining whether the second upgrade condition is met.
[0065] Specifically, if the terminal status information in the feedback information is an operating state (for example, the vehicle as the terminal is in a driving state at this moment), it is determined that the upgrade status condition is not met at present. At this time, even if the first comparison result and the second comparison result both indicate that the comparison is consistent, the target ECU still does not meet the second upgrade condition; if the terminal status information in the feedback information is a non-operating state (for example, the vehicle as the terminal is in a parking state at this moment), and the first comparison result and the second comparison result both indicate that the comparison is consistent, it is determined that the current target ECU meets the second upgrade condition.
[0066] In one embodiment, each terminal further includes a terminal main control unit, which is linked to multiple electronic control units ECU, and correspondingly verifies the first public key information and the second public key information. When the verification is passed, an access request is sent to the firmware server, and the firmware server is accessed through the upgrade path information to obtain an upgrade installation package, and the firmware of the target ECU is upgraded based on the upgrade installation package, including:
[0067] S1031. Obtain the upgrade reference information sent by the management and control server through the terminal main control unit, verify the first public key information and the second public key information in the upgrade reference information, and after the verification is passed, call the public interface of the firmware server, obtain the upgrade installation package for the target ECU through the upgrade path information in the upgrade reference information, and send the upgrade installation package to the target ECU.
[0068] In this embodiment, the public interface is publicly available for invocation, and is used to implement the delivery of the upgrade installation package.
[0069] Specifically, the terminal main control unit obtains the upgrade reference information sent by the control server, parses the upgrade reference information, obtains the first public key information of the firmware server, the second public key information of the control server, and the upgrade path information, first verifies the first public key information and the second public key information, and respectively verifies the signature information of the super administrator role corresponding to the firmware server, the signature information of the upgrade release role, the signature information of the upgrade snapshot role, and the signature information of the upgrade target role for the first public key information, and respectively verifies the signature information of the super administrator role corresponding to the control server, the signature information of the upgrade release role, the signature information of the upgrade snapshot role, and the signature information of the upgrade target role for the second public key information. When all eight signature information are verified, it is determined that the upgrade path information is secure, the public interface of the firmware server is called, the firmware server is accessed based on the upgrade path information, the upgrade installation package corresponding to the target ECU is obtained, and the upgrade installation package is sent to the target ECU, so that the target ECU performs the firmware upgrade according to the upgrade installation package.
[0070] S1032. Obtain an upgrade installation package through the target ECU, and perform a firmware upgrade based on the upgrade installation package.
[0071] In this embodiment, after the target ECU obtains the upgrade installation package forwarded by the terminal main control unit, it performs firmware upgrade based on the upgrade file machine description information in the upgrade installation package.
[0072] Furthermore, the firmware upgrade system also includes a time server, which is connected to the terminal. Accordingly, an upgrade installation package is obtained, and the firmware upgrade is performed based on the upgrade installation package, including:
[0073] a2. Access the time server, obtain the current timestamp, and determine the first version timestamp of the current firmware version.
[0074] In this embodiment, the time server is directly connected to each ECU in the terminal (preferably an ECU without a clock component). The current timestamp can be understood as the timestamp of the current moment. The current firmware version can be understood as the version of the firmware currently being applied by the target ECU. The first version timestamp can be understood as the release timestamp of the current firmware version.
[0075] Specifically, since some ECUs may not have a clock component, the ECU needs to connect to a time server to obtain the current timestamp through the time server. The target ECU also needs to determine the first version timestamp of the current firmware version currently being applied.
[0076] b2. Obtain the upgrade installation package and determine the second version timestamp of the upgrade installation package.
[0077] In this embodiment, the second version timestamp may be understood as the release timestamp of the upgraded (updated) firmware version corresponding to the upgraded installation package.
[0078] Specifically, after the target ECU obtains the upgrade installation package forwarded by the terminal main control unit, it parses the upgrade installation package, obtains the upgrade file and its description information, identifies the description information, determines the release time of the upgrade file, and obtains the second version timestamp.
[0079] c2. If the second version timestamp is between the first version timestamp and the current timestamp, it is determined that the third upgrade condition is currently met, and the firmware is upgraded according to the upgrade installation package.
[0080] In this embodiment, the third upgrade condition can be understood as a condition for the target ECU to verify whether the obtained upgrade installation package is an installation package that is eligible for update.
[0081] Specifically, if the second version timestamp is between the first version timestamp and the current timestamp, that is, in chronological order, the first version timestamp of the current firmware version < the second version timestamp of the upgrade installation package < the current timestamp, it is determined that the third upgrade condition is currently met. At this time, the target ECU downloads and installs the upgrade file according to the description file to implement the latest version of the firmware upgrade.
[0082] In one embodiment, before obtaining the upgrade reference information sent by the management and control server, the method further includes:
[0083] a3. Obtain the query request information sent by the management and control server through the terminal main control unit, determine the current terminal status information of the target terminal based on the query request information, and forward the query request information to the target ECU.
[0084] In this embodiment, the target terminal obtains the query request information sent by the management and control server through the terminal main control unit. The terminal main control unit forwards the query request information to the corresponding target ECU, and determines whether the target terminal is currently in an operating state to obtain the terminal status information.
[0085] b3. Obtain query request information through the target ECU, and feed back the second hardware identification information and the second software version information to the terminal main control unit based on the query request information.
[0086] In this embodiment, the target ECU obtains the query request information forwarded by the terminal main control unit, determines its own second hardware identification information and the second software version information at the current moment based on the query request information, and feeds back the second hardware identification information and the second software version information to the terminal main control unit.
[0087] c3. Through the terminal main control unit, feedback information is formed based on the second hardware identification information and the second software version information fed back by the target ECU, as well as the terminal status information of the target terminal, and the feedback information is returned to the management and control server.
[0088] In this embodiment, the terminal main control unit obtains the second hardware identification information and the second software version information fed back by the target ECU, and forms feedback information based on the second hardware identification information, the second software version information and the terminal status information of the target terminal, and the feedback information is signed by a preset private key, and its corresponding public key is stored inside the control service. The feedback information is returned to the control server according to the original path of receiving the query request information, so that the control server verifies whether the second upgrade condition of the target ECU upgrade is met based on the feedback information.
[0089] Embodiment 2
[0090] Figure 3 FIG. 1 is a schematic diagram of the structure of a firmware upgrade system provided by Embodiment 2 of the present invention. Figure 3 As shown, the system includes:
[0091] The firmware upgrade system adopted in the technical solution includes: a firmware server 21, a control server 22 and a plurality of terminals 23, wherein the firmware server 21 is connected to the control server 22, and the firmware server 21 and the control server 22 are respectively connected to the terminals 23, and each terminal 23 is deployed with a plurality of electronic control units ECU;
[0092] The firmware server 21 is used to form an upgrade task for the target ECU and send the upgrade task to the control server 22 when the first upgrade condition is met, and the upgrade task at least includes the device parameter information of the target ECU and the first public key information of the firmware server 21;
[0093] The control server 22 is used to determine whether the target ECU meets the second upgrade condition according to the device parameter information, and if so, send upgrade reference information to the target terminal 23 where the target ECU is located, wherein the upgrade reference information at least includes the first public key information of the firmware server 21, the second public key information of the control server 22, and upgrade path information;
[0094] The target terminal 23 is used to verify the first public key information and the second public key information. When the verification is successful, the target terminal 23 accesses the firmware server 21 through the upgrade path information to obtain the upgrade installation package, and performs firmware upgrade on the target ECU based on the upgrade installation package.
[0095] Optionally, the system further comprises a time server, and the time server is connected to the terminal 23;
[0096] The time server is used to provide time service for the target ECU in the terminal 23, so that the target ECU determines the third upgrade condition based on the current timestamp obtained after the time service.
[0097] Optionally, the firmware server 21 is specifically used for:
[0098] Obtaining an upgrade installation package through a private interface, wherein the upgrade installation package includes at least an upgrade file and description information of the upgrade file;
[0099] When the first upgrade condition is met, the first hardware identification information and the first software version information of the target ECU are used as device parameter information, and the signature information of the super administrator role, the signature information of the upgrade release role, the signature information of the upgrade snapshot role, and the signature information of the upgrade target role corresponding to the firmware server 21 are used as the first public key information;
[0100] An upgrade task for the target ECU is formed based on the device parameter information and the first public key information, and the upgrade task is sent to the management and control server 22 .
[0101] Optionally, the control server 22 includes:
[0102] A query request module is used to generate query request information after receiving the upgrade task sent by the firmware server, send the query request information to the target terminal 23 where the target ECU is located, and obtain feedback information sent back by the target terminal 23;
[0103] An upgrade judgment module, used for determining whether the target ECU meets a second upgrade condition according to the device parameter information and the feedback information;
[0104] The upgrade information sending module is used to use the first public key information of the firmware server 21, the second public key information of the control server 22 and the upgrade path information of the firmware server 21 as upgrade reference information if the conditions are met, and send the upgrade reference information to the target terminal 23 where the target ECU is located, wherein the second public key information includes the signature information of the super administrator role corresponding to the control server 22, the signature information of the upgrade release role, the signature information of the upgrade snapshot role and the signature information of the upgrade target role.
[0105] Optional, upgrade judgment module, specifically used for:
[0106] Comparing the first hardware identification information in the device parameter information with the second hardware identification information in the feedback information to obtain a first comparison result;
[0107] Comparing the first software version information in the device parameter information with the second software version information in the feedback information to obtain a second comparison result;
[0108] If the first comparison result and the second comparison result both indicate that the comparisons are consistent, and the terminal status information in the feedback information satisfies the upgrade status condition, it is determined that the current target ECU satisfies the second upgrade condition.
[0109] Optionally, each of the terminals 23 further includes a terminal main control unit, and the terminal main control unit is linked to a plurality of electronic control units ECU. Accordingly, in the terminal 23:
[0110] The terminal main control unit is used to obtain the upgrade reference information sent by the control server, verify the first public key information and the second public key information in the upgrade reference information, and after the verification is passed, call the public interface of the firmware server, obtain the upgrade installation package for the target ECU through the upgrade path information in the upgrade reference information, and send the upgrade installation package to the target ECU;
[0111] The target ECU is used to obtain the upgrade installation package and perform firmware upgrade based on the upgrade installation package.
[0112] Optionally, the terminal main control unit is further used for the query request information sent by the control server 22, determining the current terminal status information of the target terminal 23 based on the query request information, and forwarding the query request information to the target ECU;
[0113] The target ECU is further configured to obtain the query request information, and feed back the second hardware identification information and the second software version information to the terminal main control unit based on the query request information;
[0114] The terminal main control unit is further used to form feedback information based on the second hardware identification information and the second software version information fed back by the target ECU, and the terminal status information of the target terminal 23, and return the feedback information to the management and control server 22.
[0115] Optionally, the firmware upgrade system further includes a time server, which is connected to the terminal. Accordingly, the target ECU is specifically used for:
[0116] Access the time server, obtain the current timestamp, and determine the first version timestamp of the current firmware version;
[0117] Obtain the upgrade installation package, and determine the second version timestamp of the upgrade installation package;
[0118] If the second version timestamp is between the first version timestamp and the current timestamp, it is determined that the third upgrade condition is currently met, and the firmware upgrade is performed according to the upgrade installation package.
[0119] Optionally, the super administrator role has the highest authority in the system and signs the upgrade release role, the upgrade snapshot role, and the upgrade target role;
[0120] The upgrade publishing role has the authority to manage the release of upgrade tasks and sign the currently released upgrade snapshot role;
[0121] The upgrade snapshot role has the authority to manage the upgrade tasks of all target ECUs and sign the upgrade tasks of multiple target ECUs;
[0122] The upgrade target role has the authority to manage the upgrade task of the single target ECU currently to be upgraded, and signs the upgrade task of the single target ECU currently to be upgraded.
[0123] The firmware upgrade system provided in the embodiment of the present invention can execute the firmware upgrade method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0124] It should be understood that the various forms of processes shown above can be used to reorder, add or delete steps. For example, the steps described in the present invention can be executed in parallel, sequentially or in different orders, as long as the desired results of the technical solution of the present invention can be achieved, and this document does not limit this.
[0125] The above specific implementations do not constitute a limitation on the protection scope of the present invention. It should be understood by those skilled in the art that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modification, equivalent substitution and improvement made within the spirit and principle of the present invention should be included in the protection scope of the present invention.
Claims
1. A firmware upgrade method, characterized in that: Applied to a firmware upgrade system, the firmware upgrade system includes a firmware server, a control server and multiple terminals, the firmware server is connected to the control server, the firmware server and the control server are respectively connected to the terminals, and multiple electronic control units ECU are deployed on each terminal, the method includes: By means of the firmware server, when a first upgrade condition is met, an upgrade task for a target ECU is formed and the upgrade task is sent to the control server, wherein the upgrade task at least includes device parameter information of the target ECU and first public key information of the firmware server; Determine, by the control server, whether the target ECU meets the second upgrade condition according to the device parameter information, and if so, send upgrade reference information to the target terminal where the target ECU is located, wherein the upgrade reference information includes at least the first public key information of the firmware server, the second public key information of the control server, and upgrade path information; The first public key information and the second public key information are verified through the target terminal. When the verification is passed, the firmware server is accessed through the upgrade path information to obtain an upgrade installation package, and the firmware of the target ECU is upgraded based on the upgrade installation package.
2. The method according to claim 1, characterized in that: When the first upgrade condition is met, forming an upgrade task for the target ECU and sending the upgrade task to the control server includes: Obtaining an upgrade installation package through a private interface, wherein the upgrade installation package includes at least an upgrade file and description information of the upgrade file; When the first upgrade condition is met, the first hardware identification information and the first software version information of the target ECU are used as device parameter information, and the signature information of the super administrator role corresponding to the firmware server, the signature information of the upgrade release role, the signature information of the upgrade snapshot role, and the signature information of the upgrade target role are used as the first public key information; An upgrade task for the target ECU is formed based on the device parameter information and the first public key information, and the upgrade task is sent to the management and control server.
3. The method according to claim 1, characterized in that The determining, according to the device parameter information, whether the target ECU satisfies a second upgrade condition, and if so, sending upgrade reference information to a target terminal where the target ECU is located, comprises: After receiving the upgrade task sent by the firmware server, generating query request information, sending the query request information to the target terminal where the target ECU is located, and obtaining feedback information sent back by the target terminal; determining whether the target ECU meets a second upgrade condition according to the device parameter information and the feedback information; If the conditions are met, the first public key information of the firmware server, the second public key information of the control server and the upgrade path information of the firmware server are used as upgrade reference information, and the upgrade reference information is sent to the target terminal where the target ECU is located. The second public key information includes the signature information of the super administrator role corresponding to the control server, the signature information of the upgrade release role, the signature information of the upgrade snapshot role and the signature information of the upgrade target role.
4. The method according to claim 3, characterized in that The determining whether the target ECU meets the second upgrade condition according to the device parameter information and the feedback information includes: Comparing the first hardware identification information in the device parameter information with the second hardware identification information in the feedback information to obtain a first comparison result; Comparing the first software version information in the device parameter information with the second software version information in the feedback information to obtain a second comparison result; If the first comparison result and the second comparison result both indicate that the comparisons are consistent, and the terminal status information in the feedback information satisfies the upgrade status condition, it is determined that the current target ECU satisfies the second upgrade condition.
5. The method according to claim 1, characterized in that Each of the terminals further includes a terminal main control unit, and the terminal main control unit is linked to a plurality of electronic control units ECU. Accordingly, the first public key information and the second public key information are verified, and when the verification is passed, a firmware server is accessed through the upgrade path information to obtain an upgrade installation package, and the firmware of the target ECU is upgraded based on the upgrade installation package, including: Obtaining, through the terminal main control unit, the upgrade reference information sent by the control server, verifying the first public key information and the second public key information in the upgrade reference information, and after the verification is passed, calling the public interface of the firmware server, obtaining the upgrade installation package for the target ECU through the upgrade path information in the upgrade reference information, and sending the upgrade installation package to the target ECU; The upgrade installation package is obtained through the target ECU, and the firmware is upgraded based on the upgrade installation package.
6. The method according to claim 5, characterized in that Also includes: Obtaining, through the terminal main control unit, the query request information sent by the management and control server, determining the current terminal status information of the target terminal based on the query request information, and forwarding the query request information to the target ECU; Obtaining the query request information through the target ECU, and feeding back the second hardware identification information and the second software version information to the terminal main control unit based on the query request information; Feedback information is formed through the terminal main control unit based on the second hardware identification information and the second software version information fed back by the target ECU and the terminal status information of the target terminal, and the feedback information is returned to the management and control server.
7. The method according to claim 5, characterized in that The firmware upgrade system further includes a time server, and the time server is connected to the terminal. Accordingly, obtaining the upgrade installation package and performing firmware upgrade based on the upgrade installation package includes: Access the time server, obtain the current timestamp, and determine the first version timestamp of the current firmware version; Obtain the upgrade installation package, and determine the second version timestamp of the upgrade installation package; If the second version timestamp is between the first version timestamp and the current timestamp, it is determined that the third upgrade condition is currently met, and the firmware upgrade is performed according to the upgrade installation package.
8. The method according to claim 2 or 3, characterized in that: The super administrator role has the highest authority in the system and signs the upgrade release role, upgrade snapshot role and upgrade target role; The upgrade publishing role has the authority to manage the release of upgrade tasks and sign the currently released upgrade snapshot role; The upgrade snapshot role has the authority to manage the upgrade tasks of all target ECUs and sign the upgrade tasks of multiple target ECUs; The upgrade target role has the authority to manage the upgrade task of the single target ECU currently to be upgraded, and signs the upgrade task of the single target ECU currently to be upgraded.
9. A firmware upgrade system, characterized in that: The system is used to execute the method described in any one of claims 1 to 8, comprising: a firmware server, a control server, and a plurality of terminals, wherein the firmware server is connected to the control server, the firmware server and the control server are respectively connected to the terminals, and each terminal is deployed with a plurality of electronic control units ECU; The firmware server is used to form an upgrade task for the target ECU and send the upgrade task to the control server when the first upgrade condition is met, wherein the upgrade task at least includes the device parameter information of the target ECU and the first public key information of the firmware server; The control server is used to determine whether the target ECU meets the second upgrade condition according to the device parameter information, and if so, send upgrade reference information to the target terminal where the target ECU is located, wherein the upgrade reference information at least includes the first public key information of the firmware server, the second public key information of the control server, and the upgrade path information; The target terminal is used to verify the first public key information and the second public key information. When the verification is passed, the target terminal accesses the firmware server through the upgrade path information, obtains the upgrade installation package, and performs firmware upgrade on the target ECU based on the upgrade installation package.
10. The system according to claim 9, characterized in that Also includes a time server, the time server is connected to the terminal; The time server is used to provide time service for the target ECU in the terminal, so that the target ECU determines the third upgrade condition based on the current timestamp obtained after the time service.
Citation Information
Cited By
Non-inductive upgrade design method for business program in trusted computing environment
CN122065318A
A method for upgrading a service program in a trusted computing environment without user intervention
CN122065318B
Firmware upgrading method, electronic equipment and storage medium
CN122219952A
Firmware upgrade method, electronic device, and storage medium
CN122219952B