ECU (Electronic Control Unit) upgrading method, device, equipment, medium and vehicle
By writing boot and application upgrade data in the ECU to an unrun partition and booting through a pre-boot program, the problem of failure of the existing ECU upgrade method caused by the failure of the APP function is solved, and convenient ECU upgrade and user experience improvement is achieved.
Patent Information
- Application Number
- CN202311528261.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-16
- Publication Date
- 2025-05-16
AI Technical Summary
The existing ECU upgrade method may cause the APP function to fail when the upgrade fails, seriously affecting the user's user experience.
By responding to the upgrade instruction, the boot upgrade data is written to the partitions that are not running in multiple boot partitions, and boots through the pre-boot program to achieve the upgrade of the boot program. When the new bootloader is running, the application upgrade data is written to partitions that are not run in multiple application partitions, and the application is booted from that partition to enable the application upgrade.
It has achieved successive upgrades of boot programs and applications, improved the convenience of ECU upgrades, and maintained APP functions when the upgrade failed, improving the user experience.
Smart Images

Figure CN120010874A_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the technical field of vehicle upgrade, and in particular, relates to an ECU upgrade method, device, equipment, medium and vehicle. Background Art
[0002] With the continuous development of the new energy vehicle field, the number of ECUs (Electronic Control Units) in cars is increasing, and the demand for OTA (Over-the-Air Technology) functions is also increasing. Therefore, the BOOT (Bootloader) function of ECU to achieve self-upgrade of software has become an essential function for vehicles.
[0003] Usually, the storage area in a single ECU is divided into a boot partition and an application partition. The boot partition stores the boot program BOOT, and the application partition stores the application program APP. As a boot program, BOOT can realize OTA of APP.
[0004] There are certain defects in the ECU upgrade method in the related art. In the ECU upgrade method, in order to realize the BOOT upgrade, PreBoot is usually added, and PreBoot can obtain the Boot upgrade program to realize the Boot upgrade. However, during the upgrade process, whether the BOOT upgrade fails or the APP upgrade fails, it will cause the APP function to fail, seriously affecting the user experience. Summary of the invention
[0005] The embodiments of the present application provide an ECU upgrade method, device, equipment, medium and vehicle, which can improve the problem that upgrade failure in the existing ECU upgrade method will cause APP function failure.
[0006] In a first aspect, an embodiment of the present application provides an ECU upgrade method, the ECU upgrade method comprising:
[0007] In response to the upgrade instruction, the boot program is run to write the acquired boot upgrade data into the idle boot partition; wherein the idle boot partition is a boot partition in which the boot program is not run among the multiple boot partitions, and the boot upgrade data is a new boot program;
[0008] When the ECU is restarted and the pre-boot program is running, the new boot program is booted and run from the free boot partition; wherein the pre-boot program is stored in the pre-boot partition;
[0009] Run the new boot program to obtain application upgrade data, and write the application upgrade data to the idle application partition; wherein the multiple application partitions include a running application partition and an idle application partition, the running application partition is an application partition storing the application program that was last run, and the application upgrade data is a new application program;
[0010] When the ECU is restarted again and the new boot program is run, the new application program is booted and run from the application partition storing the application upgrade data.
[0011] In some embodiments, after the boot program is run to write the acquired boot upgrade data into the idle boot partition, the method further includes:
[0012] Verify the written boot upgrade data;
[0013] When the verification result is successful, a first boot parameter is set based on the boot operation upgrade mode; wherein the first boot parameter is used to indicate that an idle boot partition among the multiple boot partitions is the first boot partition.
[0014] In some embodiments, when the ECU is restarted and the pre-boot program is running, the new boot program is booted and run from the idle boot partition, including:
[0015] Get the boot run upgrade mode;
[0016] When the boot operation upgrade mode is the first mode, a first boot partition is determined from the multiple boot partitions based on the first startup parameter, boot upgrade data is copied from the first boot partition to the second boot partition, and the boot program is booted and executed from the second boot partition;
[0017] When the boot-upgrade mode is the second mode, a first boot partition is determined from a plurality of boot partitions based on the first startup parameter, and the boot program is booted and run from the first boot partition.
[0018] In some embodiments, booting and running the new boot program from the idle boot partition further includes:
[0019] When the boot program is booted, the abnormal monitoring program is started and the first boot times of the boot program are counted; the abnormal monitoring program is used to restart the ECU when the boot program fails, and return to the execution step: obtaining the boot program upgrade mode;
[0020] After getting the boot to run the upgrade mode, it also includes:
[0021] When the first boot number reaches the first boot threshold and the boot operation upgrade mode is the second mode, the boot program is booted and executed from the second boot partition.
[0022] In some embodiments, running a new boot program to obtain application upgrade data and writing the application upgrade data to an idle application partition includes:
[0023] Responding to the application program flashing instruction, obtaining application upgrade data;
[0024] Identify an idle application partition from among the multiple application partitions, and write the application upgrade data into the idle application partition;
[0025] A second startup parameter is set based on the application upgrade mode; wherein the second startup parameter is used to indicate that the application partition storing the application upgrade data among the multiple application partitions is the first application partition.
[0026] In some embodiments, when the ECU is restarted again and a new boot program is run, the new application is booted and run from the application partition storing the application upgrade data, including:
[0027] Get the application upgrade mode;
[0028] When the application upgrade mode is the first mode, determining a first application partition from multiple application partitions based on the second startup parameter, copying application upgrade data from the first application partition to the second application partition, and booting and running the application from the second application partition;
[0029] When the application upgrade mode is the second mode, a first application partition is determined from the multiple application partitions based on the second startup parameter, and the application program is booted and run from the first application partition.
[0030] In some embodiments, booting and running the application from the application partition storing the application upgrade data further includes:
[0031] When the application is booted, the abnormal monitoring program is started and the number of second boots of the application is counted; the abnormal monitoring program is used to restart the ECU and return to the execution step of obtaining the application upgrade mode when the boot fails;
[0032] After obtaining the application upgrade mode, it also includes:
[0033] When the second boot number reaches the second boot threshold and the application upgrade mode is the second mode, the application program is booted and executed from the second application partition.
[0034] In some embodiments, the boot-upgrade mode and the application upgrade mode are both the first mode, or the boot-upgrade mode and the application upgrade mode are both the second mode.
[0035] In some embodiments, in response to the upgrade instruction, running the boot program to write the acquired boot upgrade data into the idle boot partition includes:
[0036] In response to the upgrade instruction, the boot program is run, and boot upgrade data is obtained through the boot program;
[0037] A free boot partition is identified from among the multiple boot partitions, and boot upgrade data is written into the free boot partition.
[0038] In a second aspect, an embodiment of the present application further provides an ECU upgrade device, the ECU upgrade device comprising:
[0039] A first writing module is used to respond to the upgrade instruction, run the boot program to write the acquired boot upgrade data into the idle boot partition; wherein the idle boot partition is a boot partition in which the boot program is not running among the multiple boot partitions, and the boot upgrade data is a new boot program;
[0040] A first boot module, used for booting and running a new boot program from an idle boot partition when the ECU is restarted and the pre-boot program is running; wherein the pre-boot program is stored in the pre-boot partition;
[0041] A second writing module is used to run a new boot program to obtain application upgrade data, and write the application upgrade data to an idle application partition; wherein the multiple application partitions include a running application partition and an idle application partition, the running application partition is an application partition storing the application program that was last run, and the application upgrade data is a new application program;
[0042] The second boot module is used to boot and run the new application program from the application partition storing the application upgrade data when the ECU is restarted again and runs the new boot program.
[0043] In a third aspect, an embodiment of the present application further provides an ECU upgrade device, the ECU upgrade device comprising: a processor and a memory storing computer program instructions;
[0044] When the processor executes the computer program instructions, the ECU upgrade method of the first aspect is implemented.
[0045] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium, on which computer program instructions are stored, and when the computer program instructions are executed by a processor, the ECU upgrade method of the first aspect is implemented.
[0046] In a fifth aspect, an embodiment of the present application further provides a vehicle, the vehicle comprising at least one of the ECU upgrade device of the second aspect, the ECU upgrade equipment of the third aspect, or the computer-readable storage medium of the fourth aspect.
[0047] The ECU upgrade method, device, equipment, medium and vehicle provided in the embodiments of the present application can write boot upgrade data to a partition in a non-running state among multiple boot partitions by responding to an upgrade instruction, and boot and run from the partition through a pre-boot program to achieve the upgrade of the boot program. When the new boot program is running, the application upgrade data can be written to a non-running partition among multiple application partitions, and the application can be booted and run from the partition to achieve the upgrade of the application. The boot program and the application can be upgraded successively through a single upgrade instruction, which improves the convenience of ECU upgrade, and because multiple boot partitions and application partitions are provided, when the new program fails to upgrade, the program in the original partition can be run to continue to maintain the APP function, and the APP function will not fail due to the upgrade failure, thereby improving the user experience. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments of the present application will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0049] Figure 1 It is a flowchart of an ECU upgrade method provided by an embodiment of the present application;
[0050] Figure 2 is a flowchart of an ECU upgrade method provided by another embodiment of the present application;
[0051] Figure 3 It is a flowchart of an ECU upgrade method provided by another embodiment of the present application;
[0052] Figure 4 is a flowchart of an ECU upgrade method provided in yet another embodiment of the present application;
[0053] Figure 5 is a flowchart of an ECU upgrade method provided in yet another embodiment of the present application;
[0054] Figure 6 is a flowchart of an ECU upgrade method provided in yet another embodiment of the present application;
[0055] Figure 7 A schematic diagram of the structure of an ECU upgrade device provided in one embodiment of the present application;
[0056] Figure 8 A schematic diagram of the structure of an ECU upgrade device provided in one embodiment of the present application. DETAILED DESCRIPTION
[0057] In order to more clearly understand the above-mentioned objectives, features and advantages of the present disclosure, the scheme of the present disclosure will be further described below. It should be noted that the embodiments of the present disclosure and the features in the embodiments can be combined with each other without conflict.
[0058] In the following description, many specific details are set forth to facilitate a full understanding of the present disclosure, but the present disclosure may also be implemented in other ways different from those described herein; it is obvious that the embodiments in the specification are only part of the embodiments of the present disclosure, rather than all of the embodiments.
[0059] It should be noted that, in this article, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the term "comprises" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.
[0060] With the continuous development of the new energy vehicle field, the number of ECUs (Electronic Control Units) in cars is increasing, and the demand for OTA (Over-the-Air Technology) functions is also increasing. Therefore, the BOOT (Bootloader) function of ECU to achieve self-upgrade of software has become an essential function for vehicles.
[0061] Usually, the storage area in a single ECU is divided into a boot partition and an application partition. The boot partition stores the boot program BOOT, and the application partition stores the application program APP. As a boot program, BOOT can realize OTA of APP.
[0062] However, there are certain defects in the ECU upgrade method in the related technology. Some ECU upgrade methods do not support BOOT upgrades, while other ECU upgrade methods support BOOT upgrades, but when the upgrade fails, it may cause the APP function to fail, seriously affecting the user experience.
[0063] In order to solve the above technical problems, the embodiments of the present application provide an ECU upgrade method, device, equipment, medium and vehicle. The ECU upgrade method provided by the embodiments of the present application is described in detail below through some embodiments and their application scenarios in conjunction with the accompanying drawings.
[0064] Figure 1 The following is a flow chart of an ECU upgrade method provided by an embodiment of the present application. The ECU upgrade method includes:
[0065] S110, in response to the upgrade instruction, the boot program is run to write the acquired boot upgrade data into the idle boot partition; wherein the idle boot partition is a boot partition in which the boot program is not run among the multiple boot partitions, and the boot upgrade data is a new boot program;
[0066] S120, when the ECU is restarted and the pre-boot program is running, booting and running the new boot program from the idle boot partition; wherein the pre-boot program is stored in the pre-boot partition;
[0067] S130, running a new boot program to obtain application upgrade data, and writing the application upgrade data to an idle application partition; wherein the multiple application partitions include a running application partition and an idle application partition, the running application partition is an application partition storing an application program that was last run, and the application upgrade data is a new application program;
[0068] S140, when the ECU is restarted again and the new boot program is run, the new application program is booted and run from the application partition storing the application upgrade data.
[0069] The ECU upgrade method provided in the embodiment of the present application is applied to an ECU upgrade device. The ECU upgrade device can realize the upgrade of the boot program BOOT and the application program APP in the ECU, and when an abnormality occurs during the upgrade process, it can avoid the function failure of the ECU and ensure the user experience. The following is an example of the ECU in the car.
[0070] In this embodiment, the device can write boot upgrade data to a partition in a non-running state among multiple boot partitions by responding to an upgrade instruction, and boot and run from the partition through a pre-boot program to achieve the upgrade of the boot program. When the new boot program is running, the application upgrade data can be written to a partition in a non-running state among multiple application partitions, and the application program can be booted and run from the partition to achieve the upgrade of the application. The boot program and the application program can be upgraded successively through a single upgrade instruction, which improves the convenience of ECU upgrades. Moreover, since multiple boot partitions and application partitions are provided, when the new program fails to upgrade, the program in the original partition can be run to continue to maintain the APP function, and the APP function will not fail due to the upgrade failure, thereby improving the user experience.
[0071] In S110, the device may respond to the upgrade instruction to upgrade the boot program and the application program respectively. The upgrade instruction may be triggered by a user, for example, by a user inside the vehicle, or by a user through a mobile device or other smart device that has a communication function with the vehicle, or by a car manufacturer through communication with the vehicle for directional triggering or range triggering. The user inside the vehicle may trigger the upgrade instruction by pressing an upgrade button inside the vehicle, by clicking on a related control on the display screen inside the vehicle, or by voice triggering inside the vehicle, and there is no limitation here.
[0072] After receiving the upgrade instruction, the device can communicate with the server and obtain the boot upgrade data. The boot upgrade data is the new boot program. After obtaining the boot upgrade data, the device can determine the boot partition running the boot program and the idle boot partition from multiple boot partitions.
[0073] The above-mentioned multiple boot partitions can be multiple independent storage partitions in the storage module of the ECU. The multiple boot partitions can all store relevant data of the boot program. When the ECU is started, a boot partition can be selected from the multiple boot partitions and the boot program stored in the boot partition can be run.
[0074] When the ECU is started, the partition where the boot program is selected to run is the boot partition for running the boot program, and the remaining partitions are the idle boot partitions.
[0075] Since one of the multiple boot partitions is in operation, the boot upgrade data can be written to one of the remaining idle boot partitions, thereby avoiding affecting the normal operation of the ECU.
[0076] Please refer to Figure 2 As an optional embodiment, the above S110 may include:
[0077] S210, in response to the upgrade instruction, running the boot program, and obtaining boot upgrade data through the boot program;
[0078] S220, identifying an idle boot partition from the multiple boot partitions, and writing the boot upgrade data into the idle boot partition.
[0079] In this embodiment, the device can run the boot program based on the upgrade instruction to obtain the boot upgrade data. The boot program can write the boot upgrade data into the idle boot partition, and the normal operation of the boot program will not be affected during the data writing process.
[0080] In S210, the device may select a boot partition from multiple boot partitions in response to the upgrade instruction and run a boot program stored in the boot partition. The boot program can communicate with a server or other device storing boot upgrade data to obtain the boot upgrade data.
[0081] In S220, based on the running boot program, the device can identify from multiple boot partitions that the partition corresponding to the running boot program is the boot partition running the boot program, and the remaining partitions not running the boot program are idle boot partitions.
[0082] In another embodiment, the device may also identify the running status identifiers of multiple boot partitions. For example, if the running status identifiers of the boot partition running the boot program are different from those of the idle boot partition, the idle boot partition may be determined by identifying the running status identifiers.
[0083] After determining the idle boot partition, the acquired boot upgrade data may be written into the idle boot partition.
[0084] Please refer to Figure 3 As an optional embodiment, after the above S110, the following may also be included:
[0085] S310, verifying the written boot upgrade data;
[0086] S320: If the verification result is successful, set a first boot parameter based on the boot operation upgrade mode; wherein the first boot parameter is used to indicate that an idle boot partition among the multiple boot partitions is the first boot partition.
[0087] In this embodiment, after writing the boot upgrade data, the device can verify it. After the verification is successful, the first startup parameter can be set based on the boot operation upgrade mode so that the pre-boot program can identify the free boot partition according to the first startup parameter.
[0088] In S310, after determining an idle boot partition and writing the boot upgrade data into the idle boot partition, the device may verify the boot upgrade data written into the boot partition and obtain a verification result.
[0089] As an optional implementation, the device can obtain verification and comparison data of the boot upgrade data when obtaining the boot upgrade data. Of course, the device can also obtain the verification and comparison data before obtaining the boot upgrade data, or obtain the verification and comparison data after obtaining the boot upgrade data.
[0090] After writing the boot upgrade data to the free boot partition, the device can process the boot upgrade data using a preset verification algorithm to obtain the data to be verified, and match the data to be verified with the verification comparison data. If the data to be verified matches the verification comparison data successfully, it means the verification is successful; if the data to be verified fails to match the verification comparison data, it means the verification result is verification failure.
[0091] When the verification fails, it means that there is an abnormality in the boot upgrade data obtained by the device. At this time, the ECU upgrade process can be stopped.
[0092] In S320, when the verification result is successful, the device may set the first startup parameter based on a preset boot operation upgrade mode.
[0093] After determining the boot operation upgrade mode, the device can set a first boot parameter based on the boot operation upgrade mode. The first boot parameter can indicate that the idle boot partition among the multiple boot partitions is the first boot partition. That is, when the ECU is restarted, the device can determine the first boot partition according to the first boot parameter, and the first boot partition is the idle boot partition among the multiple boot partitions.
[0094] In S120, after the device writes the boot upgrade data into the idle boot partition, the ECU can be restarted. The restarted ECU can run a pre-boot program, which can be stored in a pre-boot partition in the storage module of the ECU. It can be understood that the pre-boot partition is also independent of the above-mentioned multiple boot partitions.
[0095] When the boot program needs to be upgraded, the ECU will not directly run the boot program after restarting, but will run the pre-boot program. The pre-boot program can determine the free boot partition and boot the boot program from the boot partition. For example, before the ECU restarts, the ECU runs the original boot program, and the original boot program can obtain the boot upgrade data, which is the new boot program. After the ECU restarts, the ECU can boot the new boot program from the free boot partition to run the new boot program.
[0096] Please refer to Figure 4 As an optional embodiment, the above S120 may include:
[0097] S410, obtaining a boot operation upgrade mode;
[0098] S420, when the boot operation upgrade mode is the first mode, determining a first boot partition from multiple boot partitions based on the first startup parameter, copying the boot upgrade data from the first boot partition to the second boot partition, and booting the boot program from the second boot partition;
[0099] S430: When the boot-upgrade mode is the second mode, determine a first boot partition from a plurality of boot partitions based on the first startup parameter, and boot the boot program from the first boot partition.
[0100] In this embodiment, when the boot operation upgrade mode is the first mode, the device can determine the first boot partition from multiple boot partitions, and copy the boot upgrade data to the second boot partition through the pre-boot program. After the copy is completed, the pre-boot program can boot the boot program from the second boot partition, so that the ECU always uses the second boot partition as the partition where the boot program actually runs. When the boot operation upgrade mode is the second mode, the device can boot the boot program directly from the first boot partition after determining the first boot partition. At this time, the data in the second boot partition is not overwritten, and rollback after the upgrade fails can be achieved.
[0101] In S410, when the ECU is restarted, it can obtain a pre-set boot operation upgrade mode.
[0102] The above boot operation upgrade mode may include a first mode and a second mode. For example, multiple boot partitions are BootA partition and BootB partition. In the first mode, BootA partition is the partition where the boot program actually runs, and BootB partition is only used as a cache area for temporarily storing boot upgrade data. That is, among the multiple boot partitions, BootA partition is the boot partition that runs the boot program, and BootB partition is an idle boot partition.
[0103] In the second mode, both the BootA partition and the BootB partition can be used as the partitions where the boot program actually runs. That is, when the device chooses to run the boot program in the BootA partition, the BootA partition is the boot partition where the boot program runs, and the BootB partition is the idle boot partition; when the device chooses to run the boot program in the BootB partition, the BootB partition is the boot partition where the boot program runs, and the BootA partition is the idle boot partition.
[0104] In S420, when the boot operation upgrade mode is the first mode, the device can determine a first boot partition from multiple boot partitions based on the first startup parameter, and the first boot partition is the boot partition storing the boot upgrade data. Before the ECU is restarted, the first boot partition is an idle boot partition.
[0105] After determining the first boot partition, the device can copy the boot upgrade data from the first boot partition to the second boot partition by running the pre-boot program. After the copy is completed, the pre-boot program can boot the boot program from the second boot partition. At this time, the boot program is the new boot program.
[0106] In S430, when the boot operation upgrade mode is the second mode, the device can determine a first boot partition from multiple boot partitions based on the first startup parameter, and the first boot partition is the boot partition storing the boot upgrade data. Before the ECU is restarted, the first boot partition is an idle boot partition.
[0107] Since in the second mode, multiple boot partitions can be used as partitions for the boot program to actually run, the device can directly boot the boot program from the first boot partition by running the pre-boot program. At this time, the boot program is the new boot program.
[0108] As an optional embodiment, the above S120 may further include:
[0109] S510, when the boot program is being booted, start the abnormality monitoring program and count the first boot times of the boot program; the abnormality monitoring program is used to restart the ECU when the boot program fails, and return to execute S410;
[0110] After the above S410, the following steps may also be included:
[0111] S520: When the first booting number reaches the first booting threshold and the booting operation upgrade mode is the second mode, booting the boot program from the second boot partition.
[0112] In this embodiment, the device can start an abnormal monitoring program to restart the ECU when an abnormality or failure occurs in the boot operation each time the boot upgrade data is booted and run, so as to re-boot and run. When the number of boot operations reaches the preset requirement, the upgrade process can be stopped. If the boot operation upgrade mode is the second mode, the data in the second boot partition is not overwritten at this time, and the pre-boot program can boot the boot program from the second boot partition, so that when the upgrade boot program fails, the original boot program can continue to run.
[0113] In S510, when the device boots the idle boot partition by running the pre-boot program, it can also start an abnormal monitoring program, such as a watchdog or other monitoring control, and count the first boot times of the boot program. The initial value of the first boot times is 0. Each time the ECU restarts and boots the boot program through the pre-boot program, the first boot times can be added by 1 to count the boot times.
[0114] The above-mentioned abnormality monitoring program can perform abnormality monitoring during the process of booting the boot program, and restart the ECU when an abnormality occurs during the booting process or the booting process fails.
[0115] After the restart, the ECU can re-acquire the boot operation upgrade mode, and re-boot the boot program through the pre-boot program based on the boot operation upgrade mode.
[0116] In S520, when the boot program is booted and run through the pre-boot program, if an abnormality occurs in the boot process, the ECU can be restarted through the abnormality monitoring program and the boot process can be restarted. The reboot process can solve some abnormal problems, but when the boot upgrade data itself has an abnormality, the boot operation cannot be completed even if it is repeated many times. Therefore, the device can obtain a pre-set first boot threshold. When the boot process is continuously restarted, if the first boot number reaches or exceeds the first boot threshold, it means that restarting the boot process can no longer solve the abnormal problem, and the boot program upgrade process can be terminated at this time.
[0117] In an optional embodiment, the first boot threshold may be 3, and the device may be configured to terminate the boot process when the first boot number exceeds the first boot threshold. That is, when an abnormality occurs during the boot process of the new boot program and the ECU is repeatedly restarted for the fourth time, the boot process may be terminated.
[0118] After the upgrade process of the boot program is finished, if the boot operation upgrade mode is the second mode, then among the multiple boot partitions, the first boot partition stores the boot upgrade data, that is, the new boot program, and the second boot partition stores the original boot program. Since the boot upgrade data cannot be booted normally during multiple boot operations, the device can boot the original boot program from the second boot partition through the pre-boot program. That is, when an abnormality occurs in the upgraded boot program, the original boot program can be re-booted and run, so that even when the boot program upgrade fails, the ECU can still upgrade the application program through the original boot program.
[0119] When the original boot program can run normally, even if the boot program upgrade fails, the application can still be booted and run, and the application upgrade function can be realized by running the original boot program, that is, the normal use and upgrade of the application are not affected.
[0120] In S130 , after the pre-boot program boots and runs the new boot program from the free boot partition, the ECU runs the new boot program during this power-on process.
[0121] When the new boot program can run normally, the device can close the abnormal monitoring program. When the ECU runs the new boot program, the device can receive the application program flashing instruction. After receiving the application program flashing instruction, the device can communicate with the server and obtain the application upgrade data. The application upgrade data is the new application.
[0122] The above application flashing instruction may be automatically generated after the boot program is upgraded, or may be generated after a request or prompt to the user is made after the boot program is upgraded and triggered by the user, and there is no limitation here.
[0123] After acquiring the application upgrade data, the device can determine a running application partition and an idle application partition from multiple application partitions.
[0124] The above-mentioned multiple application partitions can be multiple independent storage partitions in the storage module of the ECU. The multiple application partitions can all store relevant data of the application program. When the ECU is started, an application partition can be selected from the multiple application partitions, and the application program stored in the application partition can be run to realize the corresponding function of the ECU.
[0125] The partition where the application program selected to run when the ECU is started is the running application partition, and the remaining partitions are the idle application partitions.
[0126] As an optional implementation, when setting multiple application partitions, since the minimum storage space of each application partition should be greater than or equal to the space occupied by the application, when setting application partitions, in order to reduce the total storage space of multiple application partitions, the number of application partitions can be set to 2.
[0127] Since one of the multiple application partitions is in a running state, the application upgrade data can be written to the idle application partition, thereby avoiding affecting the normal operation of the ECU.
[0128] Please refer to Figure 5 As an optional embodiment, the above S130 may include:
[0129] S610, in response to the application program flashing instruction, obtaining application upgrade data;
[0130] S620, identifying an idle application partition from the multiple application partitions, and writing the application upgrade data into the idle application partition;
[0131] S630, setting a second startup parameter based on the application upgrade mode; wherein the second startup parameter is used to indicate that the application partition storing the application upgrade data among the multiple application partitions is the first application partition.
[0132] In this embodiment, after the boot program upgrade is completed, the ECU runs the new boot program normally. At this time, the new boot program can obtain the application upgrade data, and after identifying the idle application partition from multiple application partitions, write the application upgrade data into the idle application partition. In the process of writing data, it will not affect the data stored in another application partition, that is, it will not affect the data of the original application program.
[0133] In S610, the device may respond to the application program flashing instruction and run a new boot program. The new boot program can communicate with a server or other device storing boot upgrade data to obtain application upgrade data. The application upgrade data is the new application program.
[0134] In S620 , the device may identify an idle application partition from a plurality of application partitions based on the running new boot program.
[0135] It should be noted that during this power-on process, the ECU stays in the new boot program and does not run the application program, that is, the application data in multiple application partitions are all in a non-booted state. At this time, the running application partition among the multiple application partitions refers to the application partition that was booted and run when the application program was run last time, and the other application partition is an application partition in a non-running state.
[0136] In another implementation, the device may also identify multiple application partitions through running status identifiers. For example, if there is a difference between the running status identifiers of the running application partition and the idle application partition, the idle application partition may be determined by identifying the running status identifier.
[0137] After the idle application partition is determined, the acquired application upgrade data may be written into the idle application partition.
[0138] In S630, the device may set a second startup parameter based on a preset application upgrade mode.
[0139] After determining the application upgrade mode, the device can set a second startup parameter based on the application upgrade mode. The second startup parameter can indicate that the application partition storing the application upgrade data in the multiple application partitions is the first application partition. That is, when the ECU is restarted, the device can determine the first application partition according to the second startup parameter, and the first application partition is the application partition storing the application upgrade data in the multiple application partitions.
[0140] In S140, after the device writes the application upgrade data into the idle application partition, the ECU may be restarted and the restarted ECU may run a new boot program.
[0141] When an application needs to be upgraded, the ECU will not directly run the application after restarting, but will run a new boot program. The new boot program can determine the application partition that stores the application upgrade data, and boot the application from the application partition. For example, before the ECU restarts, the ECU runs the original application. After the ECU restarts, the new boot program can boot the application from the application partition that stores the application upgrade data, thereby running the upgraded application.
[0142] It is understandable that in the related art, even after the boot program is updated, before the ECU is restarted, the original boot program is still used to upgrade the application. In the embodiment of the present application, after the boot program is upgraded and updated, the new boot program can be immediately run to upgrade the application, thereby timely avoiding the problems caused by the original boot program upgrading the application.
[0143] Please refer to Figure 6 As an optional embodiment, the above S140 may include:
[0144] S710, obtaining an application upgrade mode;
[0145] S720, when the application upgrade mode is the first mode, determine a first application partition from the multiple application partitions based on the second startup parameter, copy the application upgrade data from the first application partition to the second application partition, and boot and run the application from the second application partition;
[0146] S730, when the application upgrade mode is the second mode, determine a first application partition from the plurality of application partitions based on the second startup parameter, and boot and run the application program from the first application partition;
[0147] In this embodiment, when the application upgrade mode is the first mode, the device can determine the first application partition from multiple application partitions, and copy the boot upgrade data to the second application partition. After the copy is completed, the new boot program can boot the boot program from the second application partition, so that the ECU always uses the second application partition as the partition where the application program actually runs. When the application upgrade mode is the second mode, the device can boot the application program directly from the first application partition after determining the first application partition to achieve the upgrade of the application. At this time, the data in the second application partition is not overwritten, and rollback after the upgrade fails can be achieved.
[0148] In S710, when the ECU is restarted, it can obtain a preset application upgrade mode.
[0149] The above application upgrade mode may include a first mode and a second mode. For example, multiple application partitions are respectively AppA partition and AppB partition. In the first mode, AppA partition is the partition where the application is actually running, and AppB partition is only used as a cache area for temporarily storing application upgrade data. That is, among the multiple application partitions, AppA partition is a running application partition, and AppB partition is an idle application partition.
[0150] In the second mode, both the AppA partition and the AppB partition can be used as the partitions where the application is actually run. That is, when the device chooses to run the application in the AppA partition, the AppA partition is the running application partition and the AppB partition is the idle application partition; when the device chooses to run the application in the AppB partition, the AppB partition is the running application partition and the AppA partition is the idle application partition.
[0151] In S720, when the application upgrade mode is the first mode, the device can determine a first application partition from multiple application partitions based on the second startup parameter, and the first application partition is the application partition storing the application upgrade data. Before the ECU is restarted, the first application partition is an idle application partition.
[0152] After determining the first application partition, the device can copy the application upgrade data from the first application partition to the second application partition by running the new boot program. After the copy is completed, the new boot program can boot the application from the second application partition. At this time, the application that is booted and run is the upgraded application.
[0153] In S730, when the application upgrade mode is the second mode, the device can determine a first application partition from multiple application partitions based on the second startup parameter, and the first application partition is the application partition storing the application upgrade data. Before the ECU is restarted, the first application partition is an idle application partition.
[0154] Since in the second mode, multiple application partitions can be used as partitions for actually running the application program, the device can directly boot and run the application program from the first application partition by running the new boot program. At this time, the application program that is booted and run is the upgraded application program.
[0155] As an optional embodiment, the above S140 may further include:
[0156] S810, when the application is booted, start the abnormal monitoring program and count the number of second boots of the application; the abnormal monitoring program is used to restart the ECU and return to execute S710 when the boot fails;
[0157] After the above S710, the following steps may also be included:
[0158] S820: When the second booting number reaches the second booting threshold and the application upgrade mode is the second mode, boot and run the application program from the second application partition.
[0159] In this embodiment, the device can start an abnormal monitoring program to restart the ECU when an abnormality or failure occurs in the boot operation each time the application upgrade data is booted and run, so as to re-boot and run. When the number of boot operations reaches the preset requirement, the upgrade process can be stopped. If the application upgrade mode is the second mode, the data in the second application partition is not overwritten at this time, and the new boot program can boot and run the application from the second application partition, so that when the upgrade application fails, the original application can continue to run.
[0160] In S810, when the device boots the application partition storing the application upgrade data by running the new boot program, it can also start an abnormal monitoring program, such as a watchdog or other monitoring control, and count the second boot times of the application. The initial value of the second boot times is 0. Each time the ECU is restarted and the application is booted and run by the new boot program, the second boot times can be increased by 1 to count the boot times.
[0161] The above-mentioned abnormality monitoring program can perform abnormality monitoring during the process of booting and running the application program, and restart the ECU when an abnormality occurs during the booting and running process or the booting and running process fails.
[0162] After restarting, the ECU can re-acquire the application upgrade mode and re-boot and run the application based on the application upgrade mode.
[0163] In S820, when the application is booted and run, if an exception occurs in the boot process, the ECU can be restarted through the exception monitoring program and the boot process can be restarted. The reboot process can solve some abnormal problems, but when the application upgrade data itself has an abnormality, the boot operation cannot be completed even if it is repeated many times. Therefore, the device can obtain a pre-set second boot threshold. When the boot process is continuously restarted, if the second boot number reaches or exceeds the second boot threshold, it means that restarting the boot process can no longer solve the abnormal problem, and the application upgrade process can be terminated at this time.
[0164] In an optional embodiment, the second boot threshold may be 3, and the device may be configured to terminate the boot process when the second boot number exceeds the second boot threshold. That is, when an exception occurs during the boot process of the upgraded application and the ECU is repeatedly restarted for the fourth time, the boot process may be terminated.
[0165] After the application upgrade process is completed, if the application upgrade mode is the second mode, then among the multiple application partitions, the first application partition stores the application upgrade data, that is, the new application, and the second application partition stores the original application. Since the application upgrade data cannot be normally booted and run during multiple boot operations, the device can use the upgraded application to boot and run the original application from the second application partition. That is, when an abnormality occurs in the upgraded application, the original application can be rebooted to enable the ECU to maintain its original function even when the application upgrade fails.
[0166] As an optional embodiment, the booting operation upgrade mode and the application upgrade mode are both the first mode, or the booting operation upgrade mode and the application upgrade mode are both the second mode.
[0167] In this embodiment, the boot operation upgrade mode and the application upgrade mode can both be set to the first mode or both be set to the second mode.
[0168] When both the boot operation upgrade mode and the application upgrade mode are set to the second mode, no matter an exception occurs during the upgrade of the boot program or the upgrade of the application, it is possible to roll back to the original boot program or the original application, thereby avoiding ECU function failure.
[0169] It should be noted that, in the above embodiment, the storage module of the ECU can be divided into five independent storage partitions, namely a pre-boot partition, a plurality of boot partitions and a plurality of application partitions.
[0170] The present application also provides an ECU upgrade device, such as Figure 7 As shown, the ECU upgrade device includes:
[0171] The first writing module 701 is used to respond to the upgrade instruction, run the boot program to write the acquired boot upgrade data into the idle boot partition; wherein the idle boot partition is a boot partition in which the boot program is not running among the multiple boot partitions, and the boot upgrade data is a new boot program;
[0172] The first boot module 702 is used to boot and run the new boot program from the idle boot partition when the ECU is restarted and the pre-boot program is running; wherein the pre-boot program is stored in the pre-boot partition;
[0173] The second writing module 703 is used to run the new boot program to obtain application upgrade data, and write the application upgrade data to the idle application partition; wherein the multiple application partitions include a running application partition and an idle application partition, the running application partition is an application partition storing the application program that was last run, and the application upgrade data is a new application program;
[0174] The second boot module 704 is used to boot and run the new application program from the application partition storing the application upgrade data when the ECU is restarted again and runs the new boot program.
[0175] It should be noted that the ECU upgrade device is a device corresponding to the above-mentioned ECU upgrade method. All implementation methods in the above-mentioned method embodiment are applicable to the embodiment of the device and can achieve the same technical effect.
[0176] Figure 8 A schematic diagram of the hardware structure of the ECU upgrade device provided in an embodiment of the present application is shown.
[0177] The ECU upgrade device may include a processor 801 and a memory 802 storing computer program instructions.
[0178] Specifically, the processor 801 may include a central processing unit (CPU), or an application specific integrated circuit (ASIC), or may be configured to implement one or more integrated circuits of the embodiments of the present application.
[0179] The memory 802 may include a large capacity memory for data or instructions. By way of example and not limitation, the memory 802 may include a hard disk drive (HDD), a floppy disk drive, a flash memory, an optical disk, a magneto-optical disk, a tape, or a universal serial bus (USB) drive or a combination of two or more of these. Where appropriate, the memory 802 may include a removable or non-removable (or fixed) medium. Where appropriate, the memory 802 may be inside or outside the ECU upgrade device. In a particular embodiment, the memory 802 is a non-volatile solid-state memory.
[0180] In certain embodiments, the memory 802 may include a read-only memory (ROM), a random access memory (RAM), a magnetic disk storage media device, an optical storage media device, a flash memory device, an electrical, optical or other physical / tangible memory storage device. Thus, in general, the memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., a memory device) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the method according to an aspect of the present disclosure.
[0181] The processor 801 implements any one of the ECU upgrading methods in the above embodiments by reading and executing the computer program instructions stored in the memory 802 .
[0182] In one example, the ECU upgrade device may further include a communication interface 803 and a bus 810. Figure 8 As shown, the processor 801, the memory 802, and the communication interface 803 are connected via a bus 810 and communicate with each other.
[0183] The communication interface 803 is mainly used to implement communication between various modules, devices, units and / or equipment in the embodiments of the present application.
[0184] Bus 810 includes hardware, software or both, and couples the components of the ECU upgrade device to each other. For example, but not limitation, the bus may include an accelerated graphics port (AGP) or other graphics bus, an enhanced industrial standard architecture (EISA) bus, a front-end bus (FSB), a hypertransport (HT) interconnect, an industrial standard architecture (ISA) bus, an infinite bandwidth interconnect, a low pin count (LPC) bus, a memory bus, a microchannel architecture (MCA) bus, a peripheral component interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a serial advanced technology attachment (SATA) bus, a video electronics standard association local (VLB) bus or other suitable bus or a combination of two or more of these. Where appropriate, bus 810 may include one or more buses. Although the present application embodiment describes and shows a specific bus, the present application considers any suitable bus or interconnect.
[0185] In addition, in combination with the ECU upgrade method in the above embodiment, the embodiment of the present application can provide a computer storage medium for implementation. The computer storage medium stores computer program instructions; when the computer program instructions are executed by a processor, any one of the ECU upgrade methods in the above embodiment is implemented.
[0186] An embodiment of the present application also provides a vehicle, which may include at least one of the above-mentioned ECU upgrade device, ECU upgrade equipment or computer-readable storage medium.
[0187] It should be clear that the present application is not limited to the specific configuration and processing described above and shown in the figures. For the sake of simplicity, a detailed description of the known method is omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of the present application is not limited to the specific steps described and shown, and those skilled in the art can make various changes, modifications and additions, or change the order between the steps after understanding the spirit of the present application.
[0188] The functional blocks shown in the above block diagram can be implemented as hardware, software, firmware or a combination thereof. When implemented in hardware, it can be, for example, an electronic circuit, an application specific integrated circuit (ASIC), appropriate firmware, a plug-in, a function card, etc. When implemented in software, the elements of the present application are programs or code segments that are used to perform the required tasks. The program or code segment can be stored in a machine-readable medium, or transmitted on a transmission medium or a communication link by a data signal carried in a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, optical fiber media, radio frequency (RF) links, etc. The code segment can be downloaded via a computer network such as the Internet, an intranet, etc.
[0189] It should also be noted that the exemplary embodiments mentioned in this application describe some methods or systems based on a series of steps or devices. However, this application is not limited to the order of the above steps, that is, the steps can be performed in the order mentioned in the embodiment, or in a different order from the embodiment, or several steps can be performed simultaneously.
[0190] Aspects of the present disclosure are described above with reference to the flowchart and / or block diagram of the method, device (system) and computer program product according to the embodiment of the present disclosure. It should be understood that each box in the flowchart and / or block diagram and the combination of each box in the flowchart and / or block diagram can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device to produce a machine so that these instructions executed by the processor of the computer or other programmable data processing device enable the implementation of the function / action specified in one or more boxes of the flowchart and / or block diagram. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field programmable logic circuit. It can also be understood that each box in the block diagram and / or flowchart and the combination of boxes in the block diagram and / or flowchart can also be implemented by dedicated hardware that performs a specified function or action, or can be implemented by a combination of dedicated hardware and computer instructions.
[0191] The above are only specific implementation methods of the present application. Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working processes of the systems, modules and units described above can refer to the corresponding processes in the aforementioned method embodiments, and will not be repeated here. It should be understood that the protection scope of the present application is not limited to this. Any technician familiar with the technical field can easily think of various equivalent modifications or replacements within the technical scope disclosed in this application, and these modifications or replacements should be included in the protection scope of this application.
Claims
1. An ECU upgrade method, characterized in that: The ECU upgrade method comprises: In response to the upgrade instruction, the boot program is run to write the acquired boot upgrade data into the idle boot partition; wherein the idle boot partition is a boot partition in which the boot program is not run among the multiple boot partitions, and the boot upgrade data is a new boot program; When the ECU is restarted and the pre-boot program is running, the new boot program is booted and run from the idle boot partition; wherein the pre-boot program is stored in the pre-boot partition; Run the new boot program to obtain application upgrade data, and write the application upgrade data to the idle application partition; wherein the multiple application partitions include a running application partition and an idle application partition, the running application partition is an application partition storing the application program that was last run, and the application upgrade data is a new application program; When the ECU is restarted again and the new boot program is run, the new application program is booted and run from the application partition storing the application upgrade data.
2. The ECU upgrade method according to claim 1, characterized in that: After the boot program is run to write the acquired boot upgrade data into the idle boot partition, the method further includes: Verifying the written boot upgrade data; When the verification result is successful, a first boot parameter is set based on the boot operation upgrade mode; wherein the first boot parameter is used to indicate that the idle boot partition among the multiple boot partitions is the first boot partition.
3. The ECU upgrade method according to claim 2, characterized in that: When the ECU is restarted and the pre-boot program is run, booting and running the new boot program from the idle boot partition includes: Get the boot run upgrade mode; When the boot operation upgrade mode is the first mode, determining the first boot partition from the multiple boot partitions based on the first startup parameter, copying the boot upgrade data from the first boot partition to the second boot partition, and booting and running the boot program from the second boot partition; When the boot-upgrade mode is the second mode, the first boot partition is determined from the multiple boot partitions based on the first startup parameter, and the boot program is booted and run from the first boot partition.
4. The ECU upgrade method according to claim 3, characterized in that: The step of booting the new boot program from the idle boot partition further includes: When the boot program is booted, an abnormal monitoring program is started and the first boot times of the boot program are counted; the abnormal monitoring program is used to restart the ECU when the boot program fails, and return to the execution step: obtaining the boot program upgrade mode; After obtaining the boot operation upgrade mode, the method further includes: When the first boot number reaches a first boot threshold and the boot operation upgrade mode is a second mode, the boot program is booted and executed from the second boot partition.
5. The ECU upgrade method according to claim 3, characterized in that: The step of running the new boot program to obtain application upgrade data and writing the application upgrade data into the idle application partition includes: In response to an application program flashing instruction, obtaining the application upgrade data; Identify an idle application partition from the multiple application partitions, and write the application upgrade data into the idle application partition; A second startup parameter is set based on the application upgrade mode; wherein the second startup parameter is used to indicate that the application partition storing the application upgrade data among the multiple application partitions is the first application partition.
6. The ECU upgrade method according to claim 5, characterized in that: When the ECU is restarted again and the new boot program is run, the new application is booted and run from the application partition storing the application upgrade data, including: Get the application upgrade mode; When the application upgrade mode is the first mode, determining the first application partition from the multiple application partitions based on the second startup parameter, copying the application upgrade data from the first application partition to the second application partition, and booting and running the application from the second application partition; When the application upgrade mode is the second mode, the first application partition is determined from the multiple application partitions based on the second startup parameter, and the application program is booted and executed from the first application partition.
7. The ECU upgrade method according to claim 6, characterized in that: The step of guiding the application program to run from the application partition storing the application upgrade data further includes: When the application is booted, an abnormality monitoring program is started and the number of second boots of the application is counted; the abnormality monitoring program is used to restart the ECU and return to the execution step of obtaining the application upgrade mode when the boot fails. After obtaining the application upgrade mode, the method further includes: When the second booting number reaches a second booting threshold and the application upgrade mode is the second mode, the application is booted and executed from the second application partition.
8. The ECU upgrade method according to claim 6, characterized in that: The boot-upgrade mode and the application upgrade mode are both the first mode, or the boot-upgrade mode and the application upgrade mode are both the second mode.
9. The ECU upgrade method according to claim 1, characterized in that: In response to the upgrade instruction, the boot program is run to write the acquired boot upgrade data into the idle boot partition, including: In response to the upgrade instruction, running a boot program, and acquiring the boot upgrade data through the boot program; An idle boot partition is identified from the plurality of boot partitions, and the boot upgrade data is written into the idle boot partition.
10. An ECU upgrade device, characterized in that: The ECU upgrading device comprises: A first writing module is used to respond to the upgrade instruction, run the boot program to write the acquired boot upgrade data into the idle boot partition; wherein the idle boot partition is a boot partition in which the boot program is not running among the multiple boot partitions, and the boot upgrade data is a new boot program; A first boot module, used for booting and running the new boot program from the idle boot partition when the ECU is restarted and the pre-boot program is running; wherein the pre-boot program is stored in the pre-boot partition; A second writing module is used to run a new boot program to obtain application upgrade data, and write the application upgrade data to an idle application partition; wherein the multiple application partitions include a running application partition and an idle application partition, the running application partition is an application partition for storing the application program that was last run, and the application upgrade data is a new application program; The second boot module is used to boot and run the new application program from the application partition storing the application upgrade data when the ECU is restarted again and runs the new boot program.
11. An ECU upgrade device, characterized in that: The ECU upgrade device includes: a processor and a memory storing computer program instructions; When the processor executes the computer program instructions, the ECU upgrading method according to any one of claims 1 to 9 is implemented.
12. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer program instructions, and when the computer program instructions are executed by a processor, the ECU upgrading method according to any one of claims 1 to 9 is implemented.
13. A vehicle, characterized in that: The vehicle comprises at least one of the following: The ECU upgrading device as claimed in claim 10; The ECU upgrade device according to claim 11; The computer readable storage medium of claim 12.