Upgrading method and related device

By actively identifying abnormal status and generating policy information for automatic rescue and upgrading, the "brick-turning" problem caused by the failure of upgrading core components is solved, and the rescue efficiency and user experience are improved.

CN119960814APending Publication Date: 2025-05-09YINWANG INTELLIGENT TECHNOLOGIES CO LTD

Patent Information

Application Number
CN202311437157.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-10-30
Publication Date
2025-05-09

AI Technical Summary

Technical Problem

In the existing OTA upgrade plan, the failure to upgrade the core components of the vehicle may cause the core components to become bricked, requiring operational personnel to participate in the rescue, which is inefficient and poor user experience.

Method used

The vehicle actively recognizes abnormal status information, generates the first policy information to automatically rescue and upgrade the core components, ignores a certain number of upgrade condition inspection results, and realizes automatic rescue without manual participation.

Benefits of technology

It improves the efficiency of vehicle rescue, reduces operating costs, improves user experience, and simplifies the judgment of conditions and related processing processes before upgrading.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119960814A_ABST
    Figure CN119960814A_ABST
Patent Text Reader

Abstract

An upgrading method and a related device are applied to the technical field of networked vehicles. The method is applied to the vehicle, the vehicle comprises a first component, under the condition that the first component breaks down, the first component is upgraded according to first strategy information, and the first strategy information is used for indicating the neglect of the checking result of N upgrading conditions, or the first strategy information is used for indicating the neglect of executing the checking of the N upgrading conditions. And under the condition that the first component does not fail, checking M upgrading conditions according to the second strategy information, and upgrading the first component under the condition that the checking of the M upgrading conditions is passed. Wherein N and M are integers greater than 0. According to the method and the device, when the core component (namely the first component) of the vehicle is abnormal, the vehicle end actively recognizes the abnormal state information and generates the first strategy information to rescue the core component, and the automatic rescue mode without manual rescue can reduce the operation cost and is beneficial to improving the rescue efficiency and improving the user experience.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of connected vehicles, and in particular to an upgrading method and related devices. Background Art

[0002] As Internet of Vehicles technology continues to mature, Internet of Vehicles services are also gradually improving. Over-the-air technology (OTA), as a remote upgrade method, is also developing towards vehicle terminals. In the existing OTA upgrade solution, if the core components of the vehicle fail to be upgraded, the core components will become "bricked". In this case, operators are required to participate in the rescue, such as using a tow truck or near-end flashing to restore the vehicle. This rescue method is not efficient and the user experience is also poor. Summary of the invention

[0003] The embodiments of the present application provide an upgrade method and related devices, which can improve the efficiency of vehicle rescue and help improve user experience.

[0004] In the first aspect, the embodiment of the present application provides an upgrade method, which is executed by a terminal, and the terminal can be the terminal itself, or a unit or circuit or module (such as a chip) with corresponding functions in the terminal, and the present application is not limited to this. Exemplarily, the present application is schematically illustrated with the terminal being a vehicle, and the vehicle includes a first component, and the method includes:

[0005] In the case of a failure of the first component, upgrading the first component according to first policy information, wherein the first policy information is used to indicate to ignore results of N upgrade condition checks, or the first policy information is used to indicate to ignore execution of the N upgrade condition checks, where N is an integer greater than 0;

[0006] In the case that the first component is not faulty, M upgrade condition checks are performed according to the second policy information, where M is an integer greater than 0; in the case that the M upgrade condition checks are passed, the first component is upgraded, wherein passing the first upgrade condition check includes the result of the first upgrade condition check being successful, and the first upgrade condition check is any one of the M upgrade condition checks.

[0007] In the embodiment of the present application, when a core component of the vehicle (i.e., the first component) is abnormal, the vehicle actively identifies the abnormal status information and generates the first strategy information to rescue / upgrade the core component. This automatic rescue method without human participation in the rescue can reduce operating costs, while helping to improve rescue efficiency and enhance user experience. It should be understood that rescuing the core component based on the first strategy information can simplify the condition judgment and related processing procedures before the upgrade, so as to complete the flashing of the core component.

[0008] In a possible implementation manner, the first policy information is associated with the second policy information, the second policy information comes from a server, and the first policy information is determined by the vehicle or preconfigured in the vehicle.

[0009] In this implementation, the first policy information can be the policy information automatically generated by the vehicle when a core component fails or the policy information pre-configured in the vehicle that is read. The first policy information has the meaning of indicating an emergency rescue task. Therefore, the vehicle completes the rescue of the core component according to the first policy information determined by itself. This automatic diagnosis and identification and automatic rescue and repair method is conducive to improving rescue efficiency and user experience. The second policy information is the policy information sent by the server to the vehicle when the core component does not fail. The second policy information has the meaning of indicating a normal OTA upgrade task. Therefore, the vehicle can complete the OTA upgrade task according to the second policy information sent by the receiving server.

[0010] In a possible implementation, the method further includes:

[0011] Acquiring abnormal state information of the first component;

[0012] Determine a first abnormality level according to the abnormal state information, where the first abnormality level belongs to one of multiple abnormality levels, and the multiple abnormality levels are used to describe the severity of the fault;

[0013] In the case where the first component fails, upgrading the first component according to the first policy information includes:

[0014] When the first abnormality level meets a preset condition, the first component is upgraded according to the first policy information.

[0015] In this implementation, the abnormal state information of the vehicle (or each component in the vehicle) can be obtained, and the corresponding abnormal level can be determined according to the abnormal state information obtained, and then the strategy information can be selected to perform the upgrade task according to the relationship between the abnormal level and the preset condition. Taking the abnormal state information of the first component as an example, when the abnormal state information of the first component is obtained, and based on the abnormal state information of the first component, it is determined that the corresponding first abnormal level meets the preset condition, the first component can be upgraded according to the first strategy information.

[0016] In a possible implementation manner, the multiple abnormality levels are positively correlated with the fault severity;

[0017] The first abnormality level meets the preset conditions, including:

[0018] The first abnormality level is not lower than a level threshold.

[0019] In this implementation, multiple abnormality levels are positively correlated with the severity of the fault, that is, the higher the abnormality level, the more serious the fault. When the first abnormality level is higher than or equal to the level threshold, the first component is upgraded according to the first strategy information, so that the core component of the vehicle can be automatically rescued and repaired when an abnormality occurs in the core component of the vehicle.

[0020] In a possible implementation, the multiple abnormality levels are negatively correlated with the fault severity;

[0021] The first abnormality level meets the preset conditions, including:

[0022] The first abnormality level is not higher than a level threshold.

[0023] In this implementation, multiple abnormality levels are negatively correlated with the severity of the fault, that is, the lower the abnormality level, the more serious the fault. When the first abnormality level is lower than or equal to the level threshold, the first component is upgraded according to the first strategy information, so that the core component of the vehicle can be automatically rescued and repaired when an abnormality occurs in the core component of the vehicle.

[0024] In a possible implementation, the first component is a power-related component of the vehicle. That is, the core component of the vehicle is the power-related component of the vehicle. It should be understood that when a power-related component of the vehicle fails, it will affect the normal use of the entire vehicle, so emergency rescue is required.

[0025] In a possible implementation manner, the power-related components include one or more of the following:

[0026] Battery management system (BMS), micro controller unit (MCU), or power distribution unit (PDU).

[0027] Optionally, the power-related components may also be a keyless entry and start system (passive entry passive start, PEPS), etc., which is not limited in this application.

[0028] In a possible implementation manner, the N upgrade condition checks include one or more of the following:

[0029] Pull the high-voltage signal to check, pull the vehicle ignition signal to check, check the vehicle's power battery percentage, check the vehicle's speed, check the vehicle's gear position, check the vehicle's ignition status, check the vehicle's on-board diagnostic interface status, check whether the vehicle allows whole-vehicle upgrade or whole-vehicle flashing, check the vehicle's handbrake status, check the vehicle's fast charging gun connection status, check the vehicle's charging gun connection status, check the vehicle's fuel filler cap status, check the vehicle's battery percentage, or notify the vehicle to enter upgrade mode.

[0030] In a possible implementation manner, the step of upgrading the first component according to the first policy information includes:

[0031] The first component is upgraded at a first moment according to the first policy information.

[0032] In a possible implementation manner, the upgrading the first component according to the first policy information at the first moment includes:

[0033] When the user is not in the car, the first component is upgraded according to the first policy information at the first moment.

[0034] In this implementation, when the user is not in the vehicle, the vehicle can upgrade the first component according to the first strategy information at the scheduled time (eg, the first moment), which is more in line with the actual scenario and makes the applicability of this solution higher.

[0035] In a possible implementation manner, before upgrading the first component according to the first policy information at the first moment, the method further includes:

[0036] releasing a first vehicle control signal, where the first vehicle control signal is a signal associated with executing the M upgrade condition checks;

[0037] A second vehicle control signal is activated, where the second vehicle control signal is a signal associated with the first strategy information.

[0038] In this implementation, the vehicle releases the first vehicle control signal before the scheduled time arrives, which is beneficial to vehicle energy saving. In addition, by pulling up the second vehicle control signal, it is beneficial to directly upgrade the first component according to the first strategy information after the first moment arrives, which is beneficial to improve rescue efficiency.

[0039] In a possible implementation manner, the second vehicle control signal is included in the first vehicle control signal.

[0040] In a possible implementation manner, the step of upgrading the first component according to the first policy information includes:

[0041] When the user is in the car, the first component is upgraded according to the first policy information.

[0042] In this implementation mode, when the user is in the car, the first component needs to be upgraded directly according to the first strategy information. This is conducive to implementing vehicle rescue as soon as possible in the scenario where the user needs to use the car, meeting the user's car needs and improving the user experience.

[0043] In a possible implementation manner, before upgrading the first component according to the first policy information, the method further includes:

[0044] Obtaining a first user instruction;

[0045] Based on the first user instruction, the first component is upgraded according to the first policy information.

[0046] In this implementation, the user can input / select an operation instruction (such as a first user instruction) on the user interface / visualization interface. The first user instruction is used to trigger the vehicle to upgrade the first component according to the first strategy information. This method of triggering upgrades based on user instructions enhances user participation, which in turn helps to improve user satisfaction.

[0047] In the second aspect, the embodiment of the present application provides an upgrade method, which is executed by a server, and the server can be the server itself, or a unit or circuit or module (such as a chip) with corresponding functions in the server, which is not limited in the present application. Exemplarily, the present application is schematically described with the server as the execution subject, and the method includes:

[0048] generating second strategy information;

[0049] sending the second strategy information to the vehicle;

[0050] The vehicle includes a first component, the second policy information is associated with M upgrade condition checks, the M upgrade condition checks are upgrade condition checks corresponding to when the first component is not faulty, the second policy information is associated with the first policy information, the first policy information is upgrade policy information corresponding to when the first component is faulty, the first policy information is used to indicate the result of ignoring the N upgrade condition checks, or the first policy information is used to indicate ignoring the execution of the N upgrade condition checks, M is an integer greater than 0, and N is an integer greater than 0.

[0051] In an embodiment of the present application, the second policy information is the policy information sent by the server to the vehicle when the core component (such as the first component) has not failed. The second policy information has the meaning of indicating a normal OTA upgrade task. Therefore, the vehicle can complete the OTA upgrade task based on the second policy information sent by the receiving server.

[0052] In a possible implementation manner, the first strategy information is determined by the vehicle or preconfigured in the vehicle.

[0053] In a possible implementation manner, the first component is a power-related component of the vehicle.

[0054] In a possible implementation manner, the power-related components include one or more of the following:

[0055] BMS, MCU, or PDU.

[0056] In a possible implementation manner, the N upgrade condition checks include one or more of the following:

[0057] Pull the high-voltage signal to check, pull the vehicle ignition signal to check, check the vehicle's power battery percentage, check the vehicle's speed, check the vehicle's gear position, check the vehicle's ignition status, check the vehicle's on-board diagnostic interface status, check whether the vehicle allows whole-vehicle upgrade or whole-vehicle flashing, check the vehicle's handbrake status, check the vehicle's fast charging gun connection status, check the vehicle's charging gun connection status, check the vehicle's fuel filler cap status, check the vehicle's battery percentage, or notify the vehicle to enter upgrade mode.

[0058] In a third aspect, an embodiment of the present application provides an upgrade device, which may be a vehicle, the vehicle including a first component, and the device including:

[0059] a processing unit, configured to upgrade the first component according to first policy information when the first component fails, wherein the first policy information is used to indicate to ignore results of N upgrade condition checks, or the first policy information is used to indicate to ignore execution of the N upgrade condition checks, where N is an integer greater than 0;

[0060] The processing unit is used to perform M upgrade condition checks according to the second policy information when the first component is not faulty, where M is an integer greater than 0; the processing unit is used to upgrade the first component when the M upgrade condition checks pass, wherein passing the first upgrade condition check includes a result of the first upgrade condition check being successful, and the first upgrade condition check is any one of the M upgrade condition checks.

[0061] In a possible implementation manner, the first policy information is associated with the second policy information, the second policy information comes from a server, and the first policy information is determined by the vehicle or preconfigured in the vehicle.

[0062] In a possible implementation manner, the processing unit is further configured to:

[0063] Acquiring abnormal state information of the first component;

[0064] Determine a first abnormality level according to the abnormal state information, where the first abnormality level belongs to one of multiple abnormality levels, and the multiple abnormality levels are used to describe the severity of the fault;

[0065] When the first component fails, the processing unit is configured to upgrade the first component according to the first policy information:

[0066] When the first abnormality level meets a preset condition, the first component is upgraded according to the first policy information.

[0067] In a possible implementation manner, the multiple abnormality levels are positively correlated with the fault severity;

[0068] The first abnormality level meets the preset conditions, including:

[0069] The first abnormality level is not lower than a level threshold.

[0070] In a possible implementation, the multiple abnormality levels are negatively correlated with the fault severity;

[0071] The first abnormality level meets the preset conditions, including:

[0072] The first abnormality level is not higher than a level threshold.

[0073] In a possible implementation manner, the first component is a power-related component of the vehicle.

[0074] In a possible implementation manner, the power-related components include one or more of the following:

[0075] BMS, MCU, or PDU.

[0076] In a possible implementation manner, the N upgrade condition checks include one or more of the following:

[0077] Pull the high-voltage signal to check, pull the vehicle ignition signal to check, check the vehicle's power battery percentage, check the vehicle's speed, check the vehicle's gear position, check the vehicle's ignition status, check the vehicle's on-board diagnostic interface status, check whether the vehicle allows whole-vehicle upgrade or whole-vehicle flashing, check the vehicle's handbrake status, check the vehicle's fast charging gun connection status, check the vehicle's charging gun connection status, check the vehicle's fuel filler cap status, check the vehicle's battery percentage, or notify the vehicle to enter upgrade mode.

[0078] In a possible implementation manner, the step of upgrading the first component according to the first policy information includes:

[0079] The first component is upgraded at a first moment according to the first policy information.

[0080] In a possible implementation manner, the upgrading the first component according to the first policy information at the first moment includes:

[0081] When the user is not in the car, the first component is upgraded according to the first policy information at the first moment.

[0082] In a possible implementation manner, before upgrading the first component according to the first policy information at the first moment, the processing unit is further configured to:

[0083] releasing a first vehicle control signal, where the first vehicle control signal is a signal associated with executing the M upgrade condition checks;

[0084] A second vehicle control signal is activated, where the second vehicle control signal is a signal associated with the first strategy information.

[0085] In a possible implementation manner, the second vehicle control signal is included in the first vehicle control signal.

[0086] In a possible implementation manner, when the first component is upgraded according to the first policy information, the processing unit is configured to:

[0087] When the user is in the car, the first component is upgraded according to the first policy information.

[0088] In a possible implementation manner, before upgrading the first component according to the first policy information, the processing unit is configured to:

[0089] Obtaining a first user instruction;

[0090] Based on the first user instruction, the first component is upgraded according to the first policy information.

[0091] Regarding the technical effects brought about by the third aspect and any possible implementation method, reference may be made to the introduction of the technical effects corresponding to the first aspect and the corresponding implementation method.

[0092] In a fourth aspect, an embodiment of the present application provides an upgrade device, which may be a server, and includes:

[0093] A processing unit, configured to generate second strategy information;

[0094] a transceiver unit, configured to send the second strategy information to the vehicle;

[0095] The vehicle includes a first component, the second policy information is associated with M upgrade condition checks, the M upgrade condition checks are upgrade condition checks corresponding to when the first component is not faulty, the second policy information is associated with the first policy information, the first policy information is upgrade policy information corresponding to when the first component is faulty, the first policy information is used to indicate the result of ignoring the N upgrade condition checks, or the first policy information is used to indicate ignoring the execution of the N upgrade condition checks, M is an integer greater than 0, and N is an integer greater than 0.

[0096] In a possible implementation manner, the first strategy information is determined by the vehicle or preconfigured in the vehicle.

[0097] In a possible implementation manner, the first component is a power-related component of the vehicle.

[0098] In a possible implementation manner, the power-related components include one or more of the following:

[0099] BMS, MCU, or PDU.

[0100] In a possible implementation manner, the N upgrade condition checks include one or more of the following:

[0101] Pull the high-voltage signal to check, pull the vehicle ignition signal to check, check the vehicle's power battery percentage, check the vehicle's speed, check the vehicle's gear position, check the vehicle's ignition status, check the vehicle's on-board diagnostic interface status, check whether the vehicle allows whole-vehicle upgrade or whole-vehicle flashing, check the vehicle's handbrake status, check the vehicle's fast charging gun connection status, check the vehicle's charging gun connection status, check the vehicle's fuel filler cap status, check the vehicle's battery percentage, or notify the vehicle to enter upgrade mode.

[0102] Regarding the technical effects brought about by the fourth aspect and any possible implementation manner, reference may be made to the introduction of the technical effects corresponding to the second aspect and the corresponding implementation manner.

[0103] Optionally, in the upgrading device described in any one of the third to fourth aspects and any one of the possible implementation modes:

[0104] In one design, the upgrade device is a communication device. When the upgrade device is a communication device, the transceiver unit may be a transceiver, or an input / output interface; the processing unit may be at least one processor. Optionally, the transceiver may be a transceiver circuit. Optionally, the input / output interface may be an input / output circuit.

[0105] In another design, the upgrade device is a chip (system) or circuit used in a communication device. When the upgrade device is a chip (system) or circuit used in a communication device, the transceiver unit may be a communication interface (input / output interface), interface circuit, output circuit, input circuit, pin or related circuit on the chip (system) or circuit; the processing unit may be at least one processor, processing circuit or logic circuit.

[0106] In a fifth aspect, an embodiment of the present application provides an upgrade device, which includes a processor. The processor is coupled to a memory and can be used to execute instructions in the memory to implement the method of any aspect of the first to second aspects and any possible implementation method. Optionally, the upgrade device also includes a memory. Optionally, the upgrade device also includes a communication interface, and the processor is coupled to the communication interface.

[0107] In a sixth aspect, an embodiment of the present application provides an upgrade device, comprising: a logic circuit and a communication interface. The communication interface is used to receive information or send information; the logic circuit is used to receive information or send information through the communication interface, so that the upgrade device executes the method of any aspect of the first to second aspects and any possible implementation method.

[0108] In the seventh aspect, an embodiment of the present application provides a computer-readable storage medium, which is used to store a computer program (also referred to as code, or instructions); when the computer program is run on a computer, the method of any aspect of the first to second aspects above and any possible implementation method is implemented.

[0109] In an eighth aspect, an embodiment of the present application provides a computer program product, which includes: a computer program (also referred to as code, or instructions); when the computer program is executed, it enables the computer to execute any one of the first to second aspects above and any possible implementation method.

[0110] In a ninth aspect, an embodiment of the present application provides a chip, the chip including a processor, the processor being used to execute instructions, when the processor executes the instructions, the chip executes the method of any aspect of the first to second aspects and any possible implementation method. Optionally, the chip also includes a communication interface, the communication interface being used to receive or send signals.

[0111] In the tenth aspect, an embodiment of the present application provides a vehicle end, which includes at least one upgrade device as described in the third aspect, or the upgrade device as described in the fourth aspect, or the upgrade device as described in the fifth aspect, or the upgrade device as described in the sixth aspect, or the chip as described in the ninth aspect.

[0112] In the eleventh aspect, an embodiment of the present application provides a system, which includes a vehicle and a server, wherein the vehicle is used to execute the method of the above-mentioned first aspect and any possible implementation method, and the server is used to execute the method of the above-mentioned second aspect and any possible implementation method.

[0113] In addition, in the process of executing the method described in any aspect of the first aspect to the second aspect and any possible implementation method, the process of sending information and / or receiving information in the above method can be understood as a process in which the processor outputs information, and / or a process in which the processor receives input information. When outputting information, the processor can output the information to the transceiver (or communication interface, or sending module) so that it can be transmitted by the transceiver. After the information is output by the processor, it may also need to be processed otherwise before it reaches the transceiver. Similarly, when the processor receives input information, the transceiver (or communication interface, or sending module) receives the information and inputs it into the processor. Furthermore, after the transceiver receives the information, the information may need to be processed otherwise before it is input into the processor.

[0114] Based on the above principle, for example, the sending information mentioned in the above method can be understood as the processor outputting information. For another example, the receiving information can be understood as the processor receiving input information.

[0115] Optionally, for the operations of transmitting, sending and receiving involved in the processor, if there is no special explanation, or if they do not conflict with their actual functions or internal logic in the relevant descriptions, they can be more generally understood as operations such as processor output, reception and input.

[0116] Optionally, in the process of executing the method described in any aspect of the first aspect to the second aspect and any possible implementation method, the processor may be a processor specifically used to execute these methods, or a processor that executes these methods by executing computer instructions in a memory, such as a general-purpose processor. The memory may be a non-transitory memory, such as a read-only memory (ROM), which may be integrated with the processor on the same chip or may be separately arranged on different chips. The embodiment of the present application does not limit the type of memory and the arrangement of the memory and the processor.

[0117] In a possible implementation manner, the at least one memory is located outside the device.

[0118] In yet another possible implementation, the at least one memory is located within the device.

[0119] In another possible implementation, part of the at least one memory is located inside the device, and another part of the memory is located outside the device.

[0120] In the present application, the processor and the memory may also be integrated into one device, that is, the processor and the memory may also be integrated together. BRIEF DESCRIPTION OF THE DRAWINGS

[0121] Figure 1 This is a system architecture diagram of an OTA upgrade provided by this application;

[0122] Figure 2 This is another system architecture diagram of OTA upgrade provided by this application;

[0123] Figure 3 is a functional block diagram of a vehicle 10 provided by the present application;

[0124] Figure 4 It is a schematic diagram of a scenario in which the function of the core component provided by the present application fails;

[0125] Figure 5 It is a flowchart of the upgrade method provided in the embodiment of the present application;

[0126] Figure 6 A schematic diagram of the structure of an upgrade device provided in an embodiment of the present application;

[0127] Figure 7 A schematic diagram of the structure of an upgrade device provided in an embodiment of the present application;

[0128] Figure 8 A schematic diagram of the structure of a chip provided in an embodiment of the present application. DETAILED DESCRIPTION

[0129] The embodiments of the present application are described below in conjunction with the drawings in the embodiments of the present application. It should be noted that in the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or descriptions. Any embodiment or design described as "exemplary" or "for example" in the present application should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a concrete way.

[0130] The "at least one" mentioned in the embodiments of the present application refers to one or more, and "plurality" refers to two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can be represented by: a, b, c, (a and b), (a and c), (b and c), or (a and b and c), where a, b, c can be single or multiple. "And / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can be represented by: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. The character " / " generally indicates that the associated objects before and after are in an "or" relationship.

[0131] Furthermore, unless otherwise specified, the ordinal numbers such as "first" and "second" used in the embodiments of the present application are used to distinguish multiple objects, and are not used to limit the order, timing, priority or importance of multiple objects. For example, the first message and the second message are only used to distinguish different message types, and do not indicate that the structures, importance, etc. of the two messages are different.

[0132] First, some terms in this application are explained to facilitate understanding by those skilled in the art.

[0133] 1. OTA technology is a technology for downloading data through wireless networks. It has been widely used in the upgrade of vehicles, smart homes (TVs, gateways, refrigerators, etc.), mobile terminals (mobile phones, tablets, etc.), set-top boxes and other devices. OTA technology mainly performs automatic upgrades by downloading OTA upgrade packages (it also supports upgrades by copying OTA upgrade packages to SD cards). OTA upgrades are fast and have little impact on data, so OTA upgrades have become the main way to upgrade terminal functions. For example, for vehicles, vehicle manufacturers (original equipment manufacturers, OEMs, or original equipment manufacturers) use OTA technology to upgrade related hardware or software of vehicles, which helps manufacturers reduce recall costs, respond to needs quickly, and improve user experience.

[0134] Among them, the OTA server is a server responsible for managing the OTA upgrade process (or called OEM server, also called OEM cloud or OTA cloud). The terminal (for example, it can be a vehicle, TV, mobile phone, tablet computer, set-top box and other devices) is equipped with an OTA module (or called OTA upgrade control component). The OTA module can transmit information with the OTA server to complete the upgrade of components on the terminal (including both software and hardware, or the entire vehicle).

[0135] 2. Telematics box, also known as car box (Tbox or T-box), is a compound word of telecommunications (Telecommunications) and information science (Informatics) for long-distance communication. It can be literally defined as a service system that provides information through computer systems, wireless communication technology, satellite navigation devices, and Internet technology for exchanging text, voice and other information built into transportation tools such as cars, aviation, ships, and trains. Simply put, it connects vehicles to the Internet through wireless networks to provide car owners with various information necessary for driving and life.

[0136] 3. Electronic control unit (ECU), in terms of usage, is a microcomputer controller for automobiles. Like ordinary computers, it consists of a microprocessor (such as a central processing unit (CPU)), memory (read only memory (ROM), random access memory (RAM)), input / output interface (I / O), analog-to-digital converter (A / D), and large-scale integrated circuits such as shaping and driving. The on-board control unit in the embodiment of the present application is the electronic control unit.

[0137] 4. Vehicle Control Unit (VCU), also known as the vehicle controller of electric vehicles. VCU is the assembly controller of the electric vehicle power system, responsible for coordinating the work of various components such as the engine, drive motor, gearbox, power battery, etc., and has the function of improving the vehicle's power performance, safety performance and economy. It is the core component of the electric vehicle control system, and is the core control device used to control the start, operation, advance and retreat, speed, stop of the electric vehicle motor and other electronic devices of the electric vehicle. As the core component of the pure electric vehicle control system, VCU undertakes the tasks of data exchange, safety management, driver intention interpretation, and energy flow management. VCU collects motor control system signals, accelerator pedal signals, brake pedal signals and other component signals, and after comprehensive analysis and response judgment based on the driver's driving intention, monitors the actions of the lower-level component controllers, and plays a key role in the normal driving of the car, braking feedback of battery energy, network management, fault diagnosis and processing, vehicle status monitoring and other functions.

[0138] 5. Human-machine interface (HMI), also known as human-machine interface, user interface or user interface, is the medium for interaction and information exchange between the system and the user. It realizes the conversion between the internal form of information and the form acceptable to humans.

[0139] 6. The controller area network (CAN) bus is one of the most widely used fieldbuses in the world. It is highly valued for its high reliability and good error detection capabilities, and is widely used in automotive computer control systems and industrial environments with harsh ambient temperatures, strong electromagnetic radiation and high vibration. The CAN bus is a widely used fieldbus with great application prospects in the fields of industrial measurement and control and industrial automation. CAN is a bus-type serial communication network. The CAN bus has the advantages of reliability, real-time and flexibility in data communication. In order to make the design transparent and the execution flexible, the CAN bus structure is divided into two physical layers and a data link layer (including the logical link control sublayer LLC and the medium access control sublayer (MAC)) in accordance with the International Organization for Standardization (ISO) / Open System Interconnection Reference Model (OSI) standard model.

[0140] In order to better understand the upgrade method provided by the embodiment of the present application, the system architecture and business scenarios of the embodiment of the present application are described below. It should be noted that the system architecture and business scenarios described in this application are to more clearly illustrate the technical solution of the present application, and do not constitute a limitation on the technical solution provided by the present application. It is known to those of ordinary skill in the art that with the evolution of the system architecture and the emergence of new business scenarios, the technical solutions provided by this application are also applicable to similar technical problems.

[0141] See also Figure 1 , Figure 1 1 is a system architecture diagram of an OTA upgrade provided by the present application, which may include a terminal 101 and an OTA server 102, wherein:

[0142] The OTA server 102 is a server that interacts with the terminal 101 during the OTA upgrade process. The OTA server 102 may include an OTA cloud-side upgrade management module 1020 and an OTA cloud-side upgrade package management module 1021. Generally speaking, the OTA server may indicate to the terminal that a certain control unit needs to be upgraded. Optionally, the OTA server may also send the upgrade data of the ECU to the terminal through the OTA cloud-side upgrade package management module 1021. In some specific implementation scenarios, the OTA server is also referred to as an OTA cloud or cloud-side server or server, etc.

[0143] Optionally, the OTA cloud-side upgrade package management module 1021 and the OTA cloud-side upgrade management module 1020 may be two independent hardware. In other words, the OTA cloud-side upgrade package management module 1021 may be a separate server that provides the terminal 101 with a service for downloading the installation package.

[0144] The terminal 101 is a terminal equipped with a control unit, such as a vehicle. The terminal 101 can obtain upgrade data through the OTA server 102 to upgrade the control unit.

[0145] The control unit in the embodiment of the present application may include all units in the terminal that are suitable for OTA upgrade, such as ECU, etc. The following embodiments are all described by taking ECU as an example.

[0146] Optionally, the terminal 101 may include an OTA terminal side upgrade management module 1010 and an OTA terminal side ECU upgrade package management module 1011. Optionally, the terminal 101 may also include an OTA terminal side ECU upgrade management unit 1012 ( Figure 1). Among them, the OTA terminal side upgrade management module 1010 can interact with the OTA cloud side upgrade management module 1020, and obtain the upgrade information from the OTA cloud side upgrade management module 1020 according to the software information of each ECU in the terminal 101 collected by the OTA terminal side ECU upgrade management unit 1012, and then trigger the OTA terminal side ECU upgrade package management module 1011 to download the installation package. The OTA terminal side ECU upgrade package management module 1011 can interact with the OTA cloud side upgrade package management module 1021 to download and manage the installation package. The OTA terminal side ECU upgrade management unit 1012 is responsible for the specific ECU upgrade (rollback) processing.

[0147] In some specific implementation scenarios, such as Figure 2 The system architecture diagram of another OTA upgrade provided by the present application is shown. Taking the terminal 101 as a vehicle as an example, the vehicle can be a vehicle based on the vehicle electrical and electronic (E / E) architecture, and the vehicle can include at least one of the following components: mobile data center (MDC), human-machine interaction (HMI), end-side upgrade management unit gateway (gateway, GW), car box (telematics box, T-box, or TCU), electronic control unit (electronic control unit, ECU), etc. Among them, GW is the core component in the whole vehicle electrical and electronic architecture. As the data interaction hub of the whole vehicle network, it can route network data such as control area network (CAN), local interconnect network (LIN), multimedia data transmission (MOST), FlexRay, etc. in different networks. MDC is the intelligent on-board computing platform of the vehicle. T-box is mainly used to communicate with the outside of the vehicle, the background system and the mobile phone application (APP). HMI is the information input, entertainment and interaction system of the vehicle. ECU can be a vehicle-specific microcomputer controller.

[0148] Exemplarily, an update master module (which can be regarded as OTAmaster) is deployed in the GW of the terminal 101, and an update slave module (which can be regarded as OTAslave) is deployed in multiple components of the terminal 101. The update master module in the GW can communicate with the upgrade slave modules in other components, and can also communicate with the OTA server 102. The OTA master module can also be deployed in other components of the vehicle, or can be an independent module independent of other components, which is not limited in the embodiments of the present application.

[0149] Exemplarily, the OTA terminal side upgrade management module 1010, the OTA terminal side ECU upgrade package management module 1011 and the OTA terminal side ECU upgrade management unit 1012 in the terminal 101 can be units in the MDC. The OTA terminal side upgrade management module 1010 can specifically establish a connection with the OTA cloud side upgrade management module 1020 through a T-box; the OTA terminal side ECU upgrade package management module 1011 can also specifically establish a connection with the OTA cloud side upgrade package management module 1021 through a T-box.

[0150] Among them, the terminal 101 usually has only one OTA terminal side upgrade management module 1010, which can be deployed in a T-box or a gateway, and the OTA terminal side ECU upgrade package management module 1011 can be deployed separately in the terminal 101. Optionally, the functionally related ECUs in the terminal 101 can be grouped together and managed by jointly deploying an OTA terminal side ECU upgrade package management module 1011 and an OTA terminal side ECU upgrade management unit 1012. Among them, the OTA terminal side ECU upgrade package management module 1011 and the OTA terminal side ECU upgrade management unit 1012 are interconnected through GW.

[0151] For ease of understanding, this application is mainly illustrated by taking the terminal as a vehicle. Figure 3 1 is a functional block diagram of a vehicle 10 provided in an embodiment of the present application. The vehicle 10 may include various subsystems, such as a travel system 110, a sensor system 120, a control system 130, one or more peripheral devices 140, a power supply 150, a computer system 160, and a user interface 170. Optionally, the vehicle 10 may include more or fewer subsystems, and each subsystem may include multiple elements (or vehicle-mounted components or components). In addition, each subsystem and element of the vehicle 10 may be interconnected by wire or wirelessly.

[0152] Optionally, Figure 3 The components in each subsystem shown in the figure are only examples. In practical applications, the components in the above subsystems may be added or deleted according to actual needs. Figure 3It should not be understood as limiting the embodiments of the present application.

[0153] It should be understood that the upgrade method involved in the present application scheme can be applied to Figure 3 Any vehicle-mounted component / element in the block diagram shown may also be applicable to components not included in the block diagram, or may also be applicable to some functional domain control components that manage the above components, such as the intelligent driving domain controller (multi domain controller, MDC) domain, the vehicle domain controller (vehicledomain controller, VDC) domain, the cockpit domain controller (cockpit domain controller, CDC) domain, etc. This application does not impose any restrictions on this.

[0154] The vehicle 10 may be a car, truck, motorcycle, bus, ship, airplane, helicopter, lawn mower, recreational vehicle, amusement park vehicle, construction equipment, tram, golf cart, train, and cart, etc., and the embodiments of the present application are not particularly limited.

[0155] In the existing OTA upgrade solution, if the core components of the vehicle fail to be upgraded, the core components will become "bricked". For example, see Figure 4 , Figure 4 This is a schematic diagram of a scenario in which the function of the core component provided by this application fails. Figure 4 As shown:

[0156] Scenario 1: During the process of upgrading core components (such as flashing the battery management system (BMS), microcontroller unit (MCU), and power distribution unit (PDU)), the vehicle battery fails. In this scenario, the OTA upgrade task cannot proceed due to the battery failure. After the battery failure is recovered, even if the T-box restarts the OTA upgrade task, the upper-layer application of the BMS, MCU, or PDU is damaged, so it cannot control the vehicle-related signals, resulting in the inability to continue the OTA upgrade task.

[0157] Scenario 2: During the process of upgrading core components (for example, flashing the passive entry and start system (PEPS), the T-box restarts. In this scenario 2, the restart of the T-box will cause the flashing of core components to be interrupted. After the T-box is restored / restarted, the T-box needs to re-enable the vehicle upgrade-related status (for example, the T-box re-enables the high-voltage signal). Since the upper-layer application of PEPS is damaged, PEPS cannot pull up the high-voltage signal, so the OTA upgrade task cannot be restored.

[0158] Scene 3 Figure 4 (not shown): software function failure of the core component (ie, non-hardware problem). In this scenario three, due to the software function failure of the core component, the OTA upgrade task cannot be issued, and thus the OTA upgrade task cannot be performed.

[0159] The above scenarios are all scenarios where the functions of core components fail during daily use or OTA upgrades. These scenarios may cause key problems such as the vehicle being unable to power on or wake up, resulting in the owner being unable to use the vehicle and unable to perform OTA upgrade tasks normally. In this case, operators are required to participate in rescue, such as using a tow truck or near-end flashing to restore the vehicle. This rescue method is inefficient and the user experience is poor.

[0160] Based on this, the present application proposes an upgrade method that can improve the efficiency of vehicle rescue and help improve user experience.

[0161] The following is a detailed description of the upgrade method and related devices provided by this application:

[0162] See also Figure 5 , Figure 5 Schematic diagram of the upgrade method provided in the embodiment of the present application. Figure 5 As shown, the upgrading method includes the following steps S501-S502. Figure 5 The method shown may be performed by a vehicle, or Figure 5 The execution subject of the method shown may also be a chip or vehicle-mounted component in which the upgrade master control software is deployed in the vehicle. For example, the upgrade master control software may be deployed in a vehicle-mounted component (or chip) such as a T-box, CDC, VDC, MDC, or gateway (GW) of the vehicle, and this application does not limit this. For the convenience of description, Figure 5 The method is mainly described by taking the vehicle-mounted component in which the upgrade master control software is deployed as an example of the execution subject. To simplify the description, it is referred to as the vehicle-mounted upgrade component in the following text. It should be noted that Figure 5is a schematic flow chart of a method embodiment of the present application, showing detailed communication steps or operations of the method, but these steps or operations are only examples, and the present application embodiment may also perform other operations or Figure 5 In addition, Figure 5 The steps in Figure 5 are executed in a different order than those presented, and may not be executed in the order Figure 5 All operations in . Among them:

[0163] S501: When a first component fails, the vehicle-mounted upgrade component upgrades the first component according to first strategy information.

[0164] The first policy information is used to indicate to ignore the results of N upgrade condition checks, or the first policy information is used to indicate to ignore the execution of N upgrade condition checks, or the first policy information is used to indicate to ignore the results of N1 upgrade condition checks and to indicate to ignore the execution of N2 upgrade condition checks, wherein N1+N2=N, N1 and N2 are non-negative integers, and N is an integer greater than 0.

[0165] It should be noted that "ignore the results of N / N1 upgrade condition checks" can be understood as executing N / N1 upgrade condition checks, but ignoring the results of the checks (that is, even if the checks are executed, the results of the checks are ignored, or described as not caring whether the results of the checks are passed). In this way, in some scenarios, the existing upgrade check process can be reused as much as possible, which has a relatively small impact on the existing upgrade check process, and thus the changes are relatively small, which can save development costs; "ignore the execution of N / N2 upgrade condition checks" can be understood as not executing N / N2 upgrade condition checks, or skipping the execution of N / N2 upgrade condition checks, which can improve the upgrade efficiency in some scenarios. In other words, in the case of a failure of the first component, the installation / flashing of the first component can be performed directly.

[0166] Exemplarily, the N upgrade condition checks involved in the present application include one or more of the following: pulling a high-voltage signal to check (or called an upgrade high-voltage signal), pulling a vehicle ignition signal (such as a KL15 signal) to check, checking the vehicle's power battery percentage, checking the vehicle's speed, checking the vehicle's gear position, checking the vehicle's ignition status, checking the vehicle's on-board diagnostic interface status, checking whether the vehicle allows whole-vehicle upgrades or whole-vehicle flashing, checking the vehicle's handbrake status, checking the vehicle's fast charging gun connection status, checking the vehicle's charging gun connection status, checking the vehicle's fuel filler cap status, checking the vehicle's battery percentage, or notifying the vehicle to enter upgrade mode, etc.

[0167] Optionally, in some feasible implementations, in addition to indicating to ignore the results of N upgrade condition checks or to ignore the execution of N upgrade condition checks, the first policy information may also indicate to execute K upgrade condition checks. Therefore, in the case of a failure of the first component, the first component may be installed / flashed when K upgrade condition checks are executed and the K upgrade condition checks pass, where K is an integer greater than or equal to 0. It should be understood that when K is equal to 0, it is equivalent to the first policy information only indicating to ignore the results of N upgrade condition checks or to ignore the execution of N upgrade condition checks (or the first policy information only indicating to ignore the results of N1 upgrade condition checks and to ignore the execution of N2 upgrade condition checks). Therefore, in the case of a failure of the first component, the installation / flashing of the first component may be directly executed. When K is an integer greater than 0, for example, N upgrade condition checks may include pulling a high-voltage signal check, pulling a vehicle ignition signal (such as a KL15 signal) check, checking the vehicle's power battery percentage, checking the vehicle's ignition status, checking the vehicle's on-board diagnostic interface status, checking whether the vehicle allows whole-vehicle upgrades or whole-vehicle flashing, checking the vehicle's handbrake status, checking the vehicle's fast charging gun connection status, checking the vehicle's charging gun connection status, checking the vehicle's fuel filler cap status, checking the vehicle's battery percentage, and notifying the vehicle to enter upgrade mode, etc.; K upgrade condition checks may include checking the vehicle's speed, checking the vehicle's gear position, etc.

[0168] It should be understood that the first policy information is the upgrade policy information corresponding to the failure of the first component (or the upgrade policy information corresponding to the emergency rescue task, or the upgrade policy information under the emergency rescue mode). Or it can be understood that the first policy information indicates the emergency rescue task. Here, the first policy information indicating the emergency rescue task can be understood as the specific binding / correspondence / association relationship between the emergency rescue task and the aforementioned specific upgrade policy information. Therefore, if the first policy information directly indicates a task with a special mark (i.e., an emergency rescue task), then based on the association between the emergency rescue task and the upgrade policy information, the corresponding upgrade policy information can be determined. In an embodiment of the present application, the first component may be a power-related component of the vehicle (or a core component / key component of the vehicle). Generally speaking, when a power-related component of the vehicle fails, it will affect the normal use of the entire vehicle, so emergency rescue is required. Accordingly, the corresponding upgrade strategy is the first policy information. Exemplarily, the power-related components of the vehicle may include BMS, MCU, PDU, PEPS, etc., and this application does not limit this.

[0169] It is understandable that the first policy information involved in the embodiment of the present application can be determined / generated by the vehicle (or the vehicle-mounted upgrade component in the vehicle), or the first policy information can also be pre-configured in the vehicle. That is to say, in the case of determining that the first component fails, the vehicle-mounted upgrade component in the vehicle can automatically generate the first policy information, or, in the case of determining that the first component fails, the vehicle-mounted upgrade component in the vehicle can also read the first policy information pre-configured in the vehicle, and then the vehicle-mounted upgrade component in the vehicle can upgrade the first component according to the first policy information. Optionally, in some possible implementations, the first policy information can also come from the server, that is, in the case of determining that the first component fails, the vehicle can report the fault information to the server, and then the server can send the first policy information to the vehicle according to the received fault information, and then the vehicle-mounted upgrade component in the vehicle can upgrade the first component according to the received first policy information. It should be noted that the present application is mainly understood as the first policy information being determined by the vehicle-mounted upgrade component in the vehicle or pre-configured in the vehicle.

[0170] In specific implementation, the vehicle-mounted upgrade component in the vehicle can obtain the abnormal state information of the vehicle (or other components in the vehicle), and determine the corresponding abnormal level based on the abnormal state information obtained, and then select the strategy information to perform the upgrade task based on the relationship between the abnormal level and the preset condition. Here, taking the abnormal state information of the first component as an example, when the abnormal state information of the first component is obtained, and based on the abnormal state information of the first component, it is determined that the corresponding first abnormal level meets the preset condition, the first component is upgraded according to the first strategy information. It should be understood that the first abnormal level belongs to one of multiple abnormal levels, and multiple abnormal levels are used to describe the severity of the fault.

[0171] In one possible implementation, multiple abnormality levels may be positively correlated with the severity of the fault, so the on-board upgrade component may upgrade the first component according to the first strategy information when the first abnormality level is not lower than the level threshold. In another possible implementation, multiple abnormality levels may be negatively correlated with the severity of the fault, so the on-board upgrade component may upgrade the first component according to the first strategy information when the first abnormality level is not higher than the level threshold. Here, "not lower than" may be understood as higher than or equal to, and "not higher than" may be understood as lower than or equal to.

[0172] For ease of understanding, the embodiments of the present application are mainly understood by taking the positive correlation between multiple abnormality levels and the severity of the fault as an example, that is, the higher the abnormality level, the more severe the fault. Exemplarily, as shown in Table 1 below, Table 1 shows a way of dividing the abnormality levels. Among them, when the abnormal status information of the vehicle is "1. The precondition check failed, and the formal flashing process was not started", or "2. The upgrade was successful, and the exit from OTA failed", the corresponding abnormality level is level 1; when the abnormal status information of the vehicle is "the upgrade failed, and the vehicle rollback was successful", the corresponding abnormality level is level 2; when the abnormal status information of the vehicle is "the upgrade failed, the rollback also failed, but the components can be started normally", the corresponding abnormality level is level 3; when the abnormal status information of the vehicle is "1. Non-power-related components are flashed to death and cannot be started (that is, the OTA upgrade process When the vehicle's abnormal status information is "1. Power-related components are dead / bricked (i.e., non-power-related components are dead / bricked during OTA upgrade)", or "2. Software function failure of non-power-related components and cannot be used", the corresponding abnormal level is level 4; when the vehicle's abnormal status information is "1. Power-related components are dead and cannot be started (i.e., power-related components are dead / bricked during OTA upgrade)", or "2. Software function alarm of power-related components affects driving use", the corresponding abnormal level is level 5; when the vehicle's abnormal status information is "upgrade stuck and does not exit, resulting in power supply and incomplete upgrade", the corresponding abnormal level is level 6. Taking the level threshold of level 5 as an example, when an error of level 5 or above occurs, the on-board upgrade component can upgrade the first component according to the first strategy information.

[0173] Table 1

[0174]

[0175] Optionally, before upgrading the first component according to the first strategy information, the vehicle upgrade component can also first determine whether there is a user in the current vehicle. When the user is in the car, the vehicle upgrade component can immediately upgrade the first component according to the first strategy information (i.e., immediately perform the rescue mission), so that the vehicle rescue can be completed as soon as possible, so that the user can use the car and improve the user experience; when the user is not in the car, the vehicle upgrade component upgrades the first component according to the first strategy information at the first moment. Here, the first moment is the rescue time scheduled by the vehicle upgrade component to the vehicle, that is, the vehicle upgrade component will send the rescue time to the vehicle, and the vehicle will automatically wake up after the scheduled rescue time arrives, so the vehicle upgrade component can upgrade the first component according to the first strategy information. It should be understood that when the user is not in the car and before the first moment arrives, the first vehicle control signal will be released, which is beneficial to vehicle energy saving. Here, the first vehicle control signal is a signal associated with the execution of M upgrade condition checks (or described as a signal that needs to be pulled up when the first vehicle control signal is a normal OTA upgrade / non-emergency rescue mission). In addition, when the user is not in the car and before the first moment arrives, the second vehicle control signal can be pulled, which is conducive to upgrading the first component directly according to the first strategy information after the first moment arrives, which is conducive to improving the rescue efficiency. Here, the second vehicle control signal is a signal associated with the first strategy information (or described as the second vehicle control signal is a signal that needs to be pulled when performing an emergency rescue mission, or a signal that needs to be pulled in an emergency rescue mode).

[0176] Generally speaking, the second vehicle control signal is included in the first vehicle control signal. Exemplarily, the first vehicle control signal can be one or more of the following signals: a vehicle sleep prohibition signal, a remote mode signal, a vehicle ignition signal (such as a KL15 signal), an upgrade high voltage signal, a mutual exclusion signal, a gear position flashing signal, a CAN network maintenance signal, etc. Exemplarily, the second vehicle control signal can be one or more of the following signals: a vehicle sleep prohibition signal, a remote mode signal, a KL15 signal (in emergency rescue mode, do not pull up or even if pulled up, ignore the result of pulling up (i.e., do not care whether it is pulled up successfully)), an upgrade high voltage signal (in emergency rescue mode, do not pull up or even if pulled up, ignore the result of pulling up (i.e., do not care whether it is pulled up successfully)), a mutual exclusion signal, a gear position flashing signal, a CAN network maintenance signal, etc.

[0177] Optionally, before upgrading the first component according to the first policy information, the vehicle-mounted upgrade component of the vehicle may also obtain a first user instruction input by the user, and the first user instruction is used to trigger the vehicle-mounted upgrade component to upgrade the first component according to the first policy information. Here, the first user instruction input by the user may be an operation instruction input / selected by the user on the user interface / visual interface.

[0178] It should be understood that when the vehicle-mounted upgrade component upgrades the first component according to the first strategy information, it can ignore the results of N upgrade condition checks, or directly install / flash the first component without performing N upgrade condition checks. In other words, the present application simplifies the pre-condition judgment and related processing procedures to complete the flashing of core components.

[0179] Optionally, after the first component is successfully upgraded, the vehicle status can be reset, that is, the vehicle can be restored to a normal and usable state, and support normal OTA upgrades and subsequent use of the vehicle by the owner.

[0180] S502: When the first component is not faulty, the vehicle-mounted upgrade component performs M upgrade condition checks according to the second policy information, and upgrades the first component when the M upgrade condition checks pass.

[0181] It should be understood that the second policy information is the upgrade policy information corresponding to the normal OTA upgrade (or the upgrade policy information corresponding to the non-emergency rescue task, or the upgrade policy information in normal mode). Or it is understood that the second policy information indicates a non-emergency rescue task or a normal OTA upgrade task, or the second policy information indicates the execution of M upgrade condition checks. The first policy information is associated with the second policy information. Here, the association of the first policy information with the second policy information can be understood as the first policy information being included in the second policy information (or the first policy information being a subset of the second policy information), or the association of the first policy information with the second policy information can also be understood as the upgrade condition check indicated by the first policy information being generated / determined based on the upgrade condition check indicated by the second policy information. Generally speaking, the second policy information comes from the server, that is, in the normal OTA upgrade process, the second policy information is generated by the server and sent to the vehicle. Among them, the second policy information can be associated with M upgrade condition checks, where the M upgrade condition checks are the upgrade condition checks corresponding to when the first component is not faulty, and M is an integer greater than 0. It should be understood that in the embodiment of the present application, when the first component is not faulty, the vehicle-mounted upgrade component needs to perform M upgrade condition checks, and the installation / flashing of the first component can be performed only when the results of the M upgrade condition checks are all successful / passed. Taking any one of the M upgrade condition checks, such as the first upgrade condition check, as an example, the passing of the first upgrade condition check can be understood as: the result of the first upgrade condition check is successful / passed.

[0182] In specific implementation, the vehicle-mounted upgrade component in the vehicle can obtain the abnormal state information of the vehicle (or each component in the vehicle), and determine the corresponding abnormal level according to the abnormal state information obtained. When the abnormal level does not meet the preset conditions, the first component is upgraded according to the second strategy information. Taking Table 1 as an example, assuming that the level threshold is level 5, when an error below level 5 (i.e. level 4 and below) occurs, the vehicle-mounted upgrade component can upgrade the first component according to the second strategy information.

[0183] It should be understood that the N upgrade condition checks involved in this application may be included in the M upgrade condition checks, or the N upgrade condition checks may be different from the M upgrade condition checks, or some of the N upgrade condition checks are included in the M upgrade condition checks, and the other part of the upgrade condition checks are different from the M upgrade condition checks. Among them, the M / N upgrade conditions may not be issued by the server, but pre-configured in the vehicle.

[0184] Exemplarily, the M upgrade condition checks involved in the present application include one or more of the following: pulling a high-voltage signal check, pulling a vehicle ignition signal (such as a KL15 signal check), checking the vehicle's power battery percentage, checking the vehicle's speed, checking the vehicle's gear position, checking the vehicle's ignition status, checking the vehicle's on-board diagnostic interface status, checking whether the vehicle allows whole-vehicle upgrades or whole-vehicle flashing, checking the vehicle's handbrake status, checking the vehicle's fast charging gun connection status, checking the vehicle's charging gun connection status, checking the vehicle's fuel filler cap status, checking the vehicle's battery percentage, or notifying the vehicle to enter upgrade mode, etc.

[0185] Generally speaking, 0<N≤M. For example, the M upgrade condition checks are respectively pulling the high voltage signal check, pulling the vehicle ignition signal (such as KL15 signal) check, checking the vehicle's power battery percentage, checking the vehicle's speed, and checking the vehicle's gear position (ie, M=5); the N upgrade condition checks are respectively pulling the high voltage signal check, pulling the vehicle ignition signal (such as KL15 signal) check, and checking the vehicle's power battery percentage (ie, N=3). For another example, the M upgrade condition checks are respectively pulling the high voltage signal check, pulling the vehicle ignition signal (such as KL15 signal) check, checking the vehicle's power battery percentage, checking the vehicle's speed, and checking the vehicle's gear position (ie, M=5); the N upgrade condition checks are respectively pulling the high voltage signal check, pulling the vehicle ignition signal (such as KL15 signal) check, checking the vehicle's power battery percentage, checking the vehicle's handbrake status, and checking the vehicle's fast charging gun connection status (ie, N=5).

[0186] Optionally, in some feasible implementations, when the first policy information, in addition to indicating to ignore the results of N upgrade condition checks or to ignore the execution of N upgrade condition checks, can also indicate to execute K upgrade condition checks, the K upgrade conditions can be included in the M upgrade conditions. In this case, N, K and M can satisfy: N+K=M. For example, N (where N=12) upgrade condition checks can include pulling a high-voltage signal check, pulling a vehicle ignition signal (such as a KL15 signal) check, checking the vehicle's power battery percentage, checking the vehicle's ignition status, checking the vehicle's on-board diagnostic interface status, checking whether the vehicle allows whole-vehicle upgrades or whole-vehicle flashing, checking the vehicle's handbrake status, checking the vehicle's fast charging gun connection status, checking the vehicle's charging gun connection status, checking the vehicle's fuel filler cap status, checking the vehicle's battery percentage, and notifying the vehicle to enter upgrade mode; K (where K=2) upgrade condition checks can include checking the vehicle The vehicle speed is checked, and the gear position of the vehicle is checked; M (where M=14) upgrade condition checks may include pulling a high-voltage signal to check, pulling a vehicle ignition signal (such as a KL15 signal) to check, checking the vehicle's power battery percentage, checking the vehicle's speed, checking the vehicle's gear position, checking the vehicle's ignition status, checking the vehicle's on-board diagnostic interface status, checking whether the vehicle allows whole-vehicle upgrades or whole-vehicle flashing, checking the vehicle's handbrake status, checking the vehicle's fast charging gun connection status, checking the vehicle's charging gun connection status, checking the vehicle's fuel filler cap status, checking the vehicle's battery percentage, and notifying the vehicle to enter upgrade mode.

[0187] In an embodiment of the present application, when an abnormality occurs in a core component of the vehicle, the vehicle side actively identifies the abnormal status information and generates a first strategy information to rescue the core component. This automatic rescue method that does not require human participation in rescue can reduce operating costs, and at the same time is conducive to improving rescue efficiency and enhancing user experience.

[0188] The above describes in detail the method of the embodiments of the present application. The following provides an apparatus for implementing any method in the embodiments of the present application. For example, an apparatus is provided including units (or means) for implementing each step performed by the device in any of the above methods.

[0189] See also Figure 6 , Figure 6 A schematic diagram of the structure of an upgrading device provided in an embodiment of the present application.

[0190] like Figure 6 As shown, the upgrade device 60 may include a transceiver unit 601 and a processing unit 602. The transceiver unit 601 and the processing unit 602 may be software, hardware, or a combination of software and hardware.

[0191] The transceiver unit 601 can implement a sending function and / or a receiving function, and the transceiver unit 601 can also be described as a transceiver unit. The transceiver unit 601 can also be a unit that integrates an acquisition unit (or receiving unit) and a sending unit, wherein the acquisition unit is used to implement a receiving function, and the sending unit is used to implement a sending function. Optionally, the transceiver unit 601 can be used to receive information sent by other devices, and can also be used to send information to other devices.

[0192] In a possible design, the upgrading device 60 may correspond to the above Figure 5 In the method embodiment shown, a vehicle-mounted device or chip for upgrading the main control software is deployed. The upgrading device 60 may include a device for executing the above Figure 5 In the method embodiment shown in the figure, the units of the operation performed by the upgrade main control software are respectively Figure 5 The operations performed by the upgrade master control software in the method embodiment shown are described as follows:

[0193] The processing unit 602 is configured to upgrade the first component according to first policy information when the first component fails, where the first policy information is used to indicate to ignore results of N upgrade condition checks, or the first policy information is used to indicate to ignore execution of the N upgrade condition checks, where N is an integer greater than 0;

[0194] The processing unit 602 is used to perform M upgrade condition checks according to the second policy information when the first component is not faulty, where M is an integer greater than 0; the processing unit 602 is used to upgrade the first component when the M upgrade condition checks pass, wherein passing the first upgrade condition check includes the result of the first upgrade condition check being successful, and the first upgrade condition check is any one of the M upgrade condition checks.

[0195] Optionally, the transceiver unit 601 is configured to receive second policy information from a server when the first component is not faulty.

[0196] In a possible implementation manner, the first policy information is associated with the second policy information, the second policy information comes from a server, and the first policy information is determined by the vehicle or preconfigured in the vehicle.

[0197] In a possible implementation, the processing unit 602 is further configured to:

[0198] Acquiring abnormal state information of the first component;

[0199] Determine a first abnormality level according to the abnormal state information, where the first abnormality level belongs to one of multiple abnormality levels, and the multiple abnormality levels are used to describe the severity of the fault;

[0200] When the first component fails, the processing unit 602 is used to upgrade the first component according to the first policy information:

[0201] When the first abnormality level meets a preset condition, the first component is upgraded according to the first policy information.

[0202] In a possible implementation manner, the multiple abnormality levels are positively correlated with the fault severity;

[0203] The first abnormality level meets the preset conditions, including:

[0204] The first abnormality level is not lower than a level threshold.

[0205] In a possible implementation, the multiple abnormality levels are negatively correlated with the fault severity;

[0206] The first abnormality level meets the preset conditions, including:

[0207] The first abnormality level is not higher than a level threshold.

[0208] In a possible implementation manner, the first component is a power-related component of the vehicle.

[0209] In a possible implementation manner, the power-related components include one or more of the following:

[0210] Battery management system BMS, microcontroller MCU, or power distribution unit PDU.

[0211] In a possible implementation manner, the N upgrade condition checks include one or more of the following:

[0212] Pull the high-voltage signal to check, pull the vehicle ignition signal to check, check the vehicle's power battery percentage, check the vehicle's speed, check the vehicle's gear position, check the vehicle's ignition status, check the vehicle's on-board diagnostic interface status, check whether the vehicle allows whole-vehicle upgrade or whole-vehicle flashing, check the vehicle's handbrake status, check the vehicle's fast charging gun connection status, check the vehicle's charging gun connection status, check the vehicle's fuel filler cap status, check the vehicle's battery percentage, or notify the vehicle to enter upgrade mode.

[0213] In a possible implementation manner, the step of upgrading the first component according to the first policy information includes:

[0214] The first component is upgraded at a first moment according to the first policy information.

[0215] In a possible implementation manner, the upgrading the first component according to the first policy information at the first moment includes:

[0216] When the user is not in the car, the first component is upgraded according to the first policy information at the first moment.

[0217] In a possible implementation manner, before upgrading the first component according to the first policy information at the first moment, the processing unit 602 is further configured to:

[0218] releasing a first vehicle control signal, where the first vehicle control signal is a signal associated with executing the M upgrade condition checks;

[0219] A second vehicle control signal is activated, where the second vehicle control signal is a signal associated with the first strategy information.

[0220] In a possible implementation manner, the second vehicle control signal is included in the first vehicle control signal.

[0221] In a possible implementation manner, when the first component is upgraded according to the first policy information, the processing unit 602 is configured to:

[0222] When the user is in the car, the first component is upgraded according to the first policy information.

[0223] In a possible implementation manner, before upgrading the first component according to the first policy information, the processing unit 602 is configured to:

[0224] Obtaining a first user instruction;

[0225] Based on the first user instruction, the first component is upgraded according to the first policy information.

[0226] For the technical effects of this design and any possible implementation method, please refer to the corresponding Figure 5 And an introduction to the technical effects of the corresponding implementation methods.

[0227] exist Figure 6 In another possible design of the upgrade device 60 shown, the upgrade device 60 may correspond to the above Figure 5The server in the method embodiment shown in the figure, such as the upgrade device 60, can be a server or a chip in the server. The upgrade device 60 can include a processor for executing the above Figure 5 The method embodiment shown in the figure is a unit for performing operations performed by the server, and each unit in the upgrade device 60 is respectively for implementing the above Figure 5 The operations performed by the server in the method embodiment shown are as follows:

[0228] The processing unit 602 is configured to generate second policy information;

[0229] The transceiver unit 601 is used to send the second strategy information to the vehicle;

[0230] The vehicle includes a first component, the second policy information is associated with M upgrade condition checks, the M upgrade condition checks are upgrade condition checks corresponding to when the first component is not faulty, the second policy information is associated with the first policy information, the first policy information is upgrade policy information corresponding to when the first component is faulty, the first policy information is used to indicate the result of ignoring the N upgrade condition checks, or the first policy information is used to indicate ignoring the execution of the N upgrade condition checks, M is an integer greater than 0, and N is an integer greater than 0.

[0231] In a possible implementation manner, the first strategy information is determined by the vehicle or preconfigured in the vehicle.

[0232] In a possible implementation manner, the first component is a power-related component of the vehicle.

[0233] In a possible implementation manner, the power-related components include one or more of the following:

[0234] Battery management system BMS, microcontroller MCU, or power distribution unit PDU.

[0235] In a possible implementation manner, the N upgrade condition checks include one or more of the following:

[0236] Pull the high-voltage signal to check, pull the vehicle ignition signal to check, check the vehicle's power battery percentage, check the vehicle's speed, check the vehicle's gear position, check the vehicle's ignition status, check the vehicle's on-board diagnostic interface status, check whether the vehicle allows whole-vehicle upgrade or whole-vehicle flashing, check the vehicle's handbrake status, check the vehicle's fast charging gun connection status, check the vehicle's charging gun connection status, check the vehicle's fuel filler cap status, check the vehicle's battery percentage, or notify the vehicle to enter upgrade mode.

[0237] For the technical effects of this design and any possible implementation method, please refer to the corresponding Figure 5 And an introduction to the technical effects of the corresponding implementation methods.

[0238] Optional, in the above Figure 6 In any possible design of the upgrade device 60 shown:

[0239] In one implementation, the upgrade device is a communication device. When the upgrade device is a communication device, the transceiver unit may be a transceiver, or an input / output interface; the processing unit may be at least one processor. Optionally, the transceiver may be a transceiver circuit. Optionally, the input / output interface may be an input / output circuit.

[0240] In another implementation, the upgrade device is a chip (system) or circuit used in a communication device. When the upgrade device is a chip (system) or circuit used in a communication device, the transceiver unit may be a communication interface (input / output interface), interface circuit, output circuit, input circuit, pin or related circuit on the chip (system) or circuit; the processing unit may be at least one processor, processing circuit or logic circuit.

[0241] According to the embodiment of the present application, Figure 6 The various units in the device shown can be separately or all combined into one or several other units to constitute, or some of the units (some) can also be split into multiple smaller units in function to constitute, which can achieve the same operation without affecting the realization of the technical effects of the embodiments of the present application. The above-mentioned units are divided based on logical functions. In practical applications, the functions of one unit can also be implemented by multiple units, or the functions of multiple units can be implemented by one unit. In other embodiments of the present application, other units can also be included based on the electronic device. In practical applications, these functions can also be implemented with the assistance of other units, and can be implemented by the collaboration of multiple units.

[0242] It should be noted that the implementation of each unit can also refer to the above Figure 5 The corresponding description of the method embodiment shown.

[0243] exist Figure 6 In the described upgrade device 60, when an abnormality occurs in a core component of the vehicle, the upgrade device 60 actively identifies abnormal status information and generates first strategy information to rescue the core component. This automatic rescue method that does not require human participation in rescue can reduce operating costs, and is beneficial to improving rescue efficiency and enhancing user experience.

[0244] See also Figure 7 , Figure 7A schematic diagram of the structure of an upgrading device provided in an embodiment of the present application.

[0245] It should be understood that Figure 7 The upgrade device 70 shown is only an example. The upgrade device of the embodiment of the present application may also include other components, or include Figure 7 components similar in function to the components in the Figure 7 All parts in.

[0246] The upgrading device 70 includes a communication interface 701 and at least one processor 702 .

[0247] The upgrade device 70 can correspond to any device in the vehicle-mounted device or server where the upgrade main control software is deployed. The communication interface 701 is used to send and receive signals, and at least one processor 702 executes program instructions, so that the upgrade device 70 implements the corresponding process of the method executed by the corresponding device in the above method embodiment.

[0248] In a possible design, the upgrading device 70 may correspond to the above Figure 7 In the method embodiment shown, a vehicle-mounted device or chip for upgrading the main control software is deployed. The upgrading device 70 may include components for executing the operations performed by the upgrading main control software in the above method embodiment, and each component in the upgrading device 70 is respectively for implementing the operations performed by the upgrading main control software in the above method embodiment. Specifically, it can be as follows:

[0249] In the case of a failure of the first component, upgrading the first component according to first policy information, wherein the first policy information is used to indicate to ignore results of N upgrade condition checks, or the first policy information is used to indicate to ignore execution of the N upgrade condition checks, where N is an integer greater than 0;

[0250] In the case that the first component is not faulty, M upgrade condition checks are performed according to the second policy information, where M is an integer greater than 0; in the case that the M upgrade condition checks are passed, the first component is upgraded, wherein passing the first upgrade condition check includes the result of the first upgrade condition check being successful, and the first upgrade condition check is any one of the M upgrade condition checks.

[0251] In a possible implementation manner, the first policy information is associated with the second policy information, the second policy information comes from a server, and the first policy information is determined by the vehicle or preconfigured in the vehicle.

[0252] In a possible implementation, the method further includes:

[0253] Acquiring abnormal state information of the first component;

[0254] Determine a first abnormality level according to the abnormal state information, where the first abnormality level belongs to one of multiple abnormality levels, and the multiple abnormality levels are used to describe the severity of the fault;

[0255] In the case where the first component fails, upgrading the first component according to the first policy information includes:

[0256] When the first abnormality level meets a preset condition, the first component is upgraded according to the first policy information.

[0257] In a possible implementation manner, the multiple abnormality levels are positively correlated with the fault severity;

[0258] The first abnormality level meets the preset conditions, including:

[0259] The first abnormality level is not lower than a level threshold.

[0260] In a possible implementation, the multiple abnormality levels are negatively correlated with the fault severity;

[0261] The first abnormality level meets the preset conditions, including:

[0262] The first abnormality level is not higher than a level threshold.

[0263] In a possible implementation manner, the first component is a power-related component of the vehicle.

[0264] In a possible implementation manner, the power-related components include one or more of the following:

[0265] Battery management system BMS, microcontroller MCU, or power distribution unit PDU.

[0266] In a possible implementation manner, the N upgrade condition checks include one or more of the following:

[0267] Pull the high-voltage signal to check, pull the vehicle ignition signal to check, check the vehicle's power battery percentage, check the vehicle's speed, check the vehicle's gear position, check the vehicle's ignition status, check the vehicle's on-board diagnostic interface status, check whether the vehicle allows whole-vehicle upgrade or whole-vehicle flashing, check the vehicle's handbrake status, check the vehicle's fast charging gun connection status, check the vehicle's charging gun connection status, check the vehicle's fuel filler cap status, check the vehicle's battery percentage, or notify the vehicle to enter upgrade mode.

[0268] In a possible implementation manner, the step of upgrading the first component according to the first policy information includes:

[0269] The first component is upgraded at a first moment according to the first policy information.

[0270] In a possible implementation manner, the upgrading the first component according to the first policy information at the first moment includes:

[0271] When the user is not in the car, the first component is upgraded according to the first policy information at the first moment.

[0272] In a possible implementation manner, before upgrading the first component according to the first policy information at the first moment, the method further includes:

[0273] releasing a first vehicle control signal, where the first vehicle control signal is a signal associated with executing the M upgrade condition checks;

[0274] A second vehicle control signal is activated, where the second vehicle control signal is a signal associated with the first strategy information.

[0275] In a possible implementation manner, the second vehicle control signal is included in the first vehicle control signal.

[0276] In a possible implementation manner, the step of upgrading the first component according to the first policy information includes:

[0277] When the user is in the car, the first component is upgraded according to the first policy information.

[0278] In a possible implementation manner, before upgrading the first component according to the first policy information, the method further includes:

[0279] Obtaining a first user instruction;

[0280] Based on the first user instruction, the first component is upgraded according to the first policy information.

[0281] For the technical effects of this design and any possible implementation method, please refer to the corresponding Figure 5 And an introduction to the technical effects of the corresponding implementation methods.

[0282] In another possible design, the upgrading device 70 may correspond to the above Figure 7The server in the method embodiment shown, such as the upgrade device 70, can be a server or a chip in the server. The upgrade device 70 can include components for executing the operations performed by the server in the above method embodiment, and the components in the upgrade device 70 are respectively for implementing the operations performed by the server in the above method embodiment. Specifically, it can be as follows:

[0283] generating second strategy information;

[0284] sending the second strategy information to the vehicle;

[0285] The vehicle includes a first component, the second policy information is associated with M upgrade condition checks, the M upgrade condition checks are upgrade condition checks corresponding to when the first component is not faulty, the second policy information is associated with the first policy information, the first policy information is upgrade policy information corresponding to when the first component is faulty, the first policy information is used to indicate the result of ignoring the N upgrade condition checks, or the first policy information is used to indicate ignoring the execution of the N upgrade condition checks, M is an integer greater than 0, and N is an integer greater than 0.

[0286] In a possible implementation manner, the first strategy information is determined by the vehicle or preconfigured in the vehicle.

[0287] In a possible implementation manner, the first component is a power-related component of the vehicle.

[0288] In a possible implementation manner, the power-related components include one or more of the following:

[0289] Battery management system BMS, microcontroller MCU, or power distribution unit PDU.

[0290] In a possible implementation manner, the N upgrade condition checks include one or more of the following:

[0291] Pull the high-voltage signal to check, pull the vehicle ignition signal to check, check the vehicle's power battery percentage, check the vehicle's speed, check the vehicle's gear position, check the vehicle's ignition status, check the vehicle's on-board diagnostic interface status, check whether the vehicle allows whole-vehicle upgrade or whole-vehicle flashing, check the vehicle's handbrake status, check the vehicle's fast charging gun connection status, check the vehicle's charging gun connection status, check the vehicle's fuel filler cap status, check the vehicle's battery percentage, or notify the vehicle to enter upgrade mode.

[0292] For the technical effects of this design and any possible implementation method, please refer to the corresponding Figure 5And an introduction to the technical effects of the corresponding implementation methods.

[0293] exist Figure 7 In the described upgrade device 70, when an abnormality occurs in a core component of the vehicle, the upgrade device 70 actively identifies abnormal status information and generates first strategy information to rescue the core component. This automatic rescue method that does not require human participation in rescue can reduce operating costs, and is beneficial to improving rescue efficiency and enhancing user experience.

[0294] For the case where the upgrade device can be a chip or a chip system, see Figure 8 Schematic diagram of the chip structure shown.

[0295] like Figure 8 As shown, the chip 80 includes a processor 801 and an interface 802. The number of the processors 801 may be one or more, and the number of the interfaces 802 may be multiple. It should be noted that the functions corresponding to the processor 801 and the interface 802 may be implemented by hardware design, software design, or a combination of hardware and software, which is not limited here.

[0296] Optionally, the chip 80 may further include a memory 803, and the memory 803 is used to store necessary program instructions and data.

[0297] In the present application, the processor 801 may be used to call the implementation program of the upgrade method provided by one or more embodiments of the present application in the vehicle-mounted device or one or more devices in the server where the upgrade master control software is deployed from the memory 803, and execute the instructions contained in the program. The interface 802 may be used to output the execution result of the processor 801. In the present application, the interface 802 may be specifically used to output various messages or information of the processor 801.

[0298] For the upgrade method provided by one or more embodiments of the present application, please refer to the aforementioned Figure 5 The various embodiments shown will not be described in detail here.

[0299] The processor in the embodiment of the present application may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0300] The memory in the embodiment of the present application is used to provide storage space, and the storage space can store data such as operating system and computer program. The memory includes but is not limited to random access memory (RAM), read-only memory (ROM), erasable programmable read only memory (EPROM), or portable read only memory (compact disc read-only memory, CD-ROM).

[0301] According to the method provided in the embodiment of the present application, the embodiment of the present application also provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed on one or more processors, the above-mentioned Figure 5 The method shown.

[0302] According to the method provided in the embodiment of the present application, the embodiment of the present application also provides a computer program product, the above-mentioned computer program product includes a computer program, when the above-mentioned computer program is run on a processor, it can implement the above-mentioned Figure 5 The method shown.

[0303] The embodiment of the present application also provides a system, which includes at least one upgrade device 60 or upgrade device 70 or chip 80 as described above, for executing the above Figure 5 The steps performed by the corresponding device in any embodiment.

[0304] The embodiment of the present application also provides a system, which includes a vehicle-mounted device deployed with an upgraded main control software and a server, wherein the vehicle-mounted device deployed with the upgraded main control software is used to execute the above Figure 5 In the embodiment shown, the server is used to perform the steps of upgrading the main control software. Figure 5 Steps performed by the server in the illustrated embodiment.

[0305] An embodiment of the present application also provides a processing device, including a processor and an interface; the processor is used to execute the method in any of the above method embodiments.

[0306] It should be understood that the above-mentioned processing device can be a chip. For example, the processing device can be a field programmable gate array (FPGA), a general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, a system on chip (SoC), a central processor unit (CPU), a network processor (NP), a digital signal processing circuit (DSP), a microcontroller unit (MCU), a programmable logic device (PLD) or other integrated chips. The methods, steps and logic block diagrams disclosed in the embodiments of the present application can be implemented or executed. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in the embodiments of the present application can be directly embodied as a hardware decoding processor to be executed, or the hardware and software modules in the decoding processor are combined to be executed. The software module can be located in a storage medium mature in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware.

[0307] It can be understood that the memory in the embodiments of the present application can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), and direct RAM (DR RAM). It should be noted that the memory of the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0308] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instructions may be transmitted from a website site, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (digital subscriber line, DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) mode to another website site, computer, server or data center. The computer-readable storage medium may be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrated. The available medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a high-density digital video disc (DVD)), or a semiconductor medium (eg, a solid state disc (SSD)).

[0309] The units in the above-mentioned various device embodiments completely correspond to the electronic devices in the method embodiments, and the corresponding modules or units perform the corresponding steps. For example, the transceiver unit (transceiver) performs the steps of receiving or sending in the method embodiment, and other steps except sending and receiving can be performed by the processing unit (processor). The functions of the specific units can refer to the corresponding method embodiments. Among them, the processor can be one or more.

[0310] It is understandable that in the embodiments of the present application, the electronic device can perform some or all of the steps in the embodiments of the present application, and these steps or operations are only examples. The embodiments of the present application can also perform other operations or variations of various operations. In addition, the various steps can be performed in different orders presented in the embodiments of the present application, and it is possible that not all operations in the embodiments of the present application need to be performed.

[0311] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0312] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0313] In the several embodiments provided in the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0314] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0315] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0316] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application can be essentially or the contributing part or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories ROM, random access memories RAM, magnetic disks or optical disks.

[0317] The above description is only a specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application.

Claims

1. An upgrading method, characterized in that: Applied to a vehicle, the vehicle comprising a first component, the method comprising: In the case of a failure of the first component, upgrading the first component according to first policy information, wherein the first policy information is used to indicate to ignore results of N upgrade condition checks, or the first policy information is used to indicate to ignore execution of the N upgrade condition checks, where N is an integer greater than 0; In the case that the first component is not faulty, M upgrade condition checks are performed according to the second policy information, where M is an integer greater than 0; in the case that the M upgrade condition checks are passed, the first component is upgraded, wherein passing the first upgrade condition check includes the result of the first upgrade condition check being successful, and the first upgrade condition check is any one of the M upgrade condition checks.

2. The method according to claim 1, characterized in that The first policy information is associated with the second policy information, the second policy information comes from a server, and the first policy information is determined by the vehicle or pre-configured in the vehicle.

3. The method according to claim 1 or 2, characterized in that: The method further comprises: Acquiring abnormal status information of the first component; Determine a first abnormality level according to the abnormal state information, where the first abnormality level belongs to one of multiple abnormality levels, and the multiple abnormality levels are used to describe the severity of the fault; In the case where the first component fails, upgrading the first component according to the first policy information includes: When the first abnormality level meets a preset condition, the first component is upgraded according to the first policy information.

4. The method according to any one of claims 1 to 3, characterized in that: The first component belongs to a power-related component of the vehicle.

5. The method according to claim 4, characterized in that The power-related components include one or more of the following: Battery management system BMS, microcontroller MCU, or power distribution unit PDU.

6. The method according to any one of claims 1 to 5, characterized in that: The N upgrade condition checks include one or more of the following: Pull the high-voltage signal to check, pull the vehicle ignition signal to check, check the vehicle's power battery percentage, check the vehicle's speed, check the vehicle's gear position, check the vehicle's ignition status, check the vehicle's on-board diagnostic interface status, check whether the vehicle allows whole-vehicle upgrade or whole-vehicle flashing, check the vehicle's handbrake status, check the vehicle's fast charging gun connection status, check the vehicle's charging gun connection status, check the vehicle's fuel filler cap status, check the vehicle's battery percentage, or notify the vehicle to enter upgrade mode.

7. The method according to any one of claims 1 to 6, characterized in that: The step of upgrading the first component according to the first policy information includes: The first component is upgraded at a first moment according to the first policy information.

8. The method according to claim 7, characterized in that The step of upgrading the first component according to the first policy information at the first moment includes: When the user is not in the car, the first component is upgraded according to the first policy information at the first moment.

9. The method according to claim 7 or 8, characterized in that: Before upgrading the first component according to the first policy information at the first moment, the method further includes: releasing a first vehicle control signal, where the first vehicle control signal is a signal associated with executing the M upgrade condition checks; A second vehicle control signal is activated, where the second vehicle control signal is a signal associated with the first strategy information.

10. The method according to claim 9, characterized in that The second vehicle control signal is included in the first vehicle control signal.

11. The method according to any one of claims 1 to 6, characterized in that: The step of upgrading the first component according to the first policy information includes: When the user is in the car, the first component is upgraded according to the first policy information.

12. The method according to any one of claims 1 to 11, characterized in that: Before upgrading the first component according to the first policy information, the method further includes: Obtaining a first user instruction; Based on the first user instruction, the first component is upgraded according to the first policy information.

13. An upgrading method, characterized in that: Applied to a server, the method comprises: generating second strategy information; sending the second strategy information to the vehicle; The vehicle includes a first component, the second policy information is associated with M upgrade condition checks, the M upgrade condition checks are upgrade condition checks corresponding to when the first component is not faulty, the second policy information is associated with the first policy information, the first policy information is upgrade policy information corresponding to when the first component is faulty, the first policy information is used to indicate the result of ignoring the N upgrade condition checks, or the first policy information is used to indicate ignoring the execution of the N upgrade condition checks, M is an integer greater than 0, and N is an integer greater than 0.

14. The method according to claim 13, characterized in that The first strategy information is determined by the vehicle or preconfigured in the vehicle.

15. The method according to claim 13 or 14, characterized in that The first component belongs to a power-related component of the vehicle.

16. The method according to claim 15, characterized in that The power-related components include one or more of the following: Battery management system BMS, microcontroller MCU, or power distribution unit PDU.

17. The method according to any one of claims 13 to 16, characterized in that: The N upgrade condition checks include one or more of the following: Pull the high-voltage signal to check, pull the vehicle ignition signal to check, check the vehicle's power battery percentage, check the vehicle's speed, check the vehicle's gear position, check the vehicle's ignition status, check the vehicle's on-board diagnostic interface status, check whether the vehicle allows whole-vehicle upgrade or whole-vehicle flashing, check the vehicle's handbrake status, check the vehicle's fast charging gun connection status, check the vehicle's charging gun connection status, check the vehicle's fuel filler cap status, check the vehicle's battery percentage, or notify the vehicle to enter upgrade mode.

18. An upgrading device, characterized in that: The method comprises a unit or a module for executing the method according to any one of claims 1 to 12.

19. An upgrading device, characterized in that: The method comprises a unit or a module for executing the method as claimed in any one of claims 13 to 17.

20. An upgrading device, characterized in that: include: A processor, when the processor calls the computer program or instruction in the memory, causes the method according to any one of claims 1 to 12 to be executed.

21. An upgrading device, characterized in that: include: A processor, when the processor calls the computer program or instruction in the memory, causes the method according to any one of claims 13 to 17 to be executed.

22. An upgrading device, characterized in that: comprising a logic circuit and an interface, wherein the logic circuit and the interface are coupled; The interface is used to input data to be processed, the logic circuit processes the data to be processed according to the method according to any one of claims 1 to 12 to obtain processed data, and the interface is used to output the processed data.

23. An upgrading device, characterized in that: comprising a logic circuit and an interface, wherein the logic circuit and the interface are coupled; The interface is used to input data to be processed, the logic circuit processes the data to be processed according to the method as described in any one of claims 13-17 to obtain processed data, and the interface is used to output the processed data.

24. A computer-readable storage medium, characterized in that: include: The computer-readable storage medium is used to store instructions or computer programs; when the instructions or the computer program are executed, the method according to any one of claims 1 to 12 is implemented.

25. A computer-readable storage medium, characterized in that: include: The computer-readable storage medium is used to store instructions or computer programs; when the instructions or the computer programs are executed, the method according to any one of claims 13 to 17 is implemented.

26. A computer program product, characterized in that include: instructions or computer programs; When the instructions or the computer program are executed, the method according to any one of claims 1 to 12 is performed.

27. A computer program product, characterized in that include: instructions or computer programs; When the instructions or the computer program are executed, the method according to any one of claims 13 to 17 is performed.

28. A vehicle, characterized in that: It comprises the upgrading device as claimed in claim 18, or the upgrading device as claimed in claim 20, or the upgrading device as claimed in claim 22.

29. A system, characterized in that: include: Vehicles and servers; The vehicle is used to execute the method according to any one of claims 1-18, and the server is used to execute the method according to any one of claims 13-17.

Citation Information

Patent Citations

  • Node hyper-fusion upgrading method and device, equipment and storage medium

    CN115643168A

  • Vehicle OTA upgrade control method and related equipment

    CN116643775A

  • Upgrade method and apparatus, and electronic device

    WO2023092382A1

Cited By

  • Upgrading method and related apparatus

    EP4722900A1

  • Upgrading method and related apparatus

    WO2025092715A1