ECU (Electronic Control Unit) upgrading method, device, equipment, medium and vehicle

By writing boot upgrade data in the ECU and using pre-boot programs to boot load, the problem of failure of BOOT function in the existing technology caused by failure of ECU upgrade in the prior art is solved, and convenient upgrades of boot loaders and applications are achieved, improving user experience.

CN120010876APending Publication Date: 2025-05-16BEIJING CO WHEELS TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311531741.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-16
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

The existing ECU upgrade method may cause the BOOT function to fail when the upgrade fails, seriously affecting the user's user experience.

Method used

By responding to the upgrade instructions, the boot upgrade data is obtained and written to the unrun partitions in multiple boot loading partitions. The pre-boot program is used to boot load from the partitions stored with the boot upgrade data to achieve the upgrade of the boot loader. When the upgraded version of the bootloader is running, the application upgrade data is written to the application partition where the original program data has been erased, and the application is booted from that partition to achieve the application upgrade.

Benefits of technology

The boot loader and application upgrades are achieved through a single upgrade instruction, which improves the convenience of ECU upgrades, and avoids the failure of Boot function when the upgrade fails, improving the user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120010876A_ABST
    Figure CN120010876A_ABST
Patent Text Reader

Abstract

The invention discloses an ECU upgrading method and device, equipment, a medium and a vehicle, and the ECU upgrading method comprises the steps: responding to an upgrading instruction, obtaining upgrading guiding data, and writing the upgrading guiding data into a loading guiding partition which does not run a loading guiding program; under the condition that the ECU is restarted and the pre-bootstrap program is booted and loaded, bootstrap loading is conducted on the bootstrap loading program of the upgraded version from a bootstrap loading partition where bootstrap upgrading data is stored; acquiring application upgrading data, and writing the application upgrading data into the application partition of which the original program data is erased; and under the condition that the ECU restarts and boots to load the bootstrap loader of the upgraded version, the application program of the upgraded version is booted to be loaded from the application partition. According to the embodiment of the invention, the sequential upgrade of the boot loader and the application program can be realized through the single upgrade instruction, the ECU upgrade convenience is improved, the original program can be returned when the upgrade fails, the Boot function failure cannot be caused, and the user experience is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the technical field of vehicle upgrade, and in particular, relates to an ECU upgrade method, device, equipment, medium and vehicle. Background Art

[0002] With the continuous development of the new energy vehicle field, the number of ECUs (Electronic Control Units) in cars is increasing, and the demand for OTA (Over-the-Air Technology) functions is also increasing. Therefore, the BOOT (Bootloader) function of ECU to achieve self-upgrade of software has become an essential function for vehicles.

[0003] Usually, the storage area in a single ECU is divided into a boot loader partition and an application partition. The boot loader partition stores BOOT, while the application partition stores APP (application program). BOOT, as a boot loader, can implement OTA of APP.

[0004] There are certain defects in the ECU upgrade method in the related technology. For example, some ECU upgrade methods do not support BOOT upgrade. In order to realize Boot upgrade, the ECU upgrade method has been improved and PreBoot has been added. PreBoot can obtain the Boot upgrade program to realize Boot upgrade. However, although this ECU upgrade method supports BOOT upgrade, the original Boot data will be deleted during the upgrade process, which may cause the BOOT function to fail when the upgrade fails, seriously affecting the user experience. Summary of the invention

[0005] The embodiments of the present application provide an ECU upgrade method, device, equipment, medium and vehicle, which can improve the problem that upgrade failure in the existing ECU upgrade method will cause the Boot function to fail.

[0006] In a first aspect, an embodiment of the present application provides an ECU upgrade method, the ECU upgrade method comprising:

[0007] In response to the upgrade instruction, boot upgrade data is obtained and written into a boot loading partition in which the boot loading program is not running among the plurality of boot loading partitions; wherein the boot upgrade data is an upgraded version of the boot loading program;

[0008] When the ECU is restarted and the pre-boot program is boot-loaded, the upgraded version of the boot loader is boot-loaded from the boot loading partition storing the boot upgrade data using the pre-boot program; wherein the pre-boot program is stored in the pre-boot partition;

[0009] Acquire application upgrade data, and write the application upgrade data to the application partition from which the original program data has been erased; wherein the application upgrade data is an upgraded version of the application program;

[0010] When the ECU is restarted again and the upgraded version of the boot loader is boot-loaded, the upgraded version of the application program is boot-loaded from the application partition using the upgraded version of the boot loader.

[0011] In some embodiments, after obtaining the boot upgrade data and writing it to the boot loading partition in the plurality of boot loading partitions that does not run the boot loading program, the method further includes:

[0012] Verify the written boot upgrade data to obtain the verification result;

[0013] When the verification result is successful, a first boot parameter is set based on the boot loading upgrade mode; wherein the first boot parameter is used to indicate that the boot loading partition storing the boot upgrade data among the multiple boot loading partitions is the first boot loading partition.

[0014] In some embodiments, when the ECU is restarted and the pre-boot program is boot-loaded, the upgraded version of the boot loader is boot-loaded from the boot loading partition storing the boot upgrade data using the pre-boot program, including:

[0015] Get bootloader upgrade mode;

[0016] When the boot loader upgrade mode is the first mode, a first boot loader partition is determined from the plurality of boot loader partitions based on the first startup parameter, boot upgrade data is copied from the first boot loader partition to the second boot loader partition using the pre-boot program, and the boot loader program is boot loaded from the second boot loader partition;

[0017] When the boot loader upgrade mode is the second mode, a first boot loader partition is determined from multiple boot loader partitions based on the first startup parameter, and the boot loader program is boot loaded from the first boot loader partition using the pre-boot program.

[0018] In some embodiments, boot loading the upgraded version of the boot loader from the boot loading partition storing the boot upgrade data using the pre-boot program further includes:

[0019] In the case of boot-loading the upgraded version of the boot loader by using the pre-boot program, the abnormality monitoring program is started and the first boot times of the upgraded version of the boot loader are counted; the abnormality monitoring program is used to restart the ECU in the case of boot-loading failure and return to the execution step: obtaining the boot-loading upgrade mode;

[0020] After getting the bootloader upgrade mode, it also includes:

[0021] When the first boot number reaches the first boot threshold and the boot loading upgrade mode is the second mode, the boot loading program is boot loaded from the second boot loading partition using the pre-boot program.

[0022] In some embodiments, obtaining application upgrade data and writing the application upgrade data to an application partition from which original program data has been erased includes:

[0023] In response to the application program flashing instruction, obtaining application upgrade data using the upgraded version of the boot loader;

[0024] Erase the original program data in the application partition;

[0025] Write application upgrade data to the application partition.

[0026] In some embodiments, when the boot loader upgrade mode is the first mode, the multiple boot loader partitions correspond to two memories respectively, and the two memories are different in at least one of function, capacity, read and write speed, setting location, and access method.

[0027] In some embodiments, in response to the upgrade instruction, obtaining the boot upgrade data and writing it to a boot loading partition in the plurality of boot loading partitions that is not running the boot loading program includes:

[0028] In response to the upgrade instruction, the boot loader is run, and boot upgrade data is acquired through the boot loader;

[0029] A boot load partition that is not running a boot loader is identified from among a plurality of boot load partitions, and boot upgrade data is written to the boot load partition that is not running a boot loader.

[0030] In a second aspect, an embodiment of the present application further provides an ECU upgrade device, the ECU upgrade device comprising:

[0031] A first writing module is used for obtaining boot upgrade data in response to an upgrade instruction and writing the boot upgrade data into a boot load partition in which a boot load program is not running among the multiple boot load partitions; wherein the boot upgrade data is an upgraded version of the boot load program;

[0032] A first boot module is used for boot loading the upgraded version of the boot loader program from the boot loading partition storing the boot upgrade data by using the pre-boot program when the ECU is restarted and the pre-boot program is boot loaded; wherein the pre-boot program is stored in the pre-boot partition;

[0033] A second writing module is used to obtain application upgrade data and write the application upgrade data to the application partition from which the original program data has been erased; wherein the application upgrade data is an upgraded version of the application program;

[0034] The second boot module is used to boot load the upgraded version of the application program from the application partition using the upgraded version of the boot loader when the ECU is restarted again and boot loads the upgraded version of the boot loader.

[0035] In a third aspect, an embodiment of the present application further provides an ECU upgrade device, the ECU upgrade device comprising: a processor and a memory storing computer program instructions;

[0036] When the processor executes the computer program instructions, the ECU upgrade method of the first aspect is implemented.

[0037] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium, on which computer program instructions are stored, and when the computer program instructions are executed by a processor, the ECU upgrade method of the first aspect is implemented.

[0038] In a fifth aspect, an embodiment of the present application further provides a vehicle, the vehicle comprising at least one of the ECU upgrade device of the second aspect, the ECU upgrade equipment of the third aspect, or the computer-readable storage medium of the fourth aspect.

[0039] The ECU upgrade method, device, equipment, medium and vehicle provided in the embodiments of the present application can write boot upgrade data to a partition in a non-running state among multiple boot loading partitions by responding to an upgrade instruction, and boot load from the partition through a pre-boot program to achieve the upgrade of the boot loader. When the upgraded version of the boot loader is running, the application upgrade data can be written to the application partition from which the original program data has been erased, and the application can be boot loaded from the partition to achieve the upgrade of the application. The boot loader and the application can be upgraded successively through a single upgrade instruction, which improves the convenience of ECU upgrades, and because there are multiple boot partitions, when the upgrade fails, the program of the original boot loading partition can be run, and the Boot function will not fail due to the upgrade failure, thereby improving the user experience. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments of the present application will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0041] Figure 1 It is a flowchart of an ECU upgrade method provided by an embodiment of the present application;

[0042] Figure 2 is a flowchart of an ECU upgrade method provided by another embodiment of the present application;

[0043] Figure 3 It is a flowchart of an ECU upgrade method provided by another embodiment of the present application;

[0044] Figure 4 is a flowchart of an ECU upgrade method provided in yet another embodiment of the present application;

[0045] Figure 5 is a flowchart of an ECU upgrade method provided in yet another embodiment of the present application;

[0046] Figure 6 A schematic diagram of the structure of an ECU upgrade device provided in one embodiment of the present application;

[0047] Figure 7 A schematic diagram of the structure of an ECU upgrade device provided in one embodiment of the present application. DETAILED DESCRIPTION

[0048] In order to more clearly understand the above-mentioned objectives, features and advantages of the present disclosure, the scheme of the present disclosure will be further described below. It should be noted that the embodiments of the present disclosure and the features in the embodiments can be combined with each other without conflict.

[0049] In the following description, many specific details are set forth to facilitate a full understanding of the present disclosure, but the present disclosure may also be implemented in other ways different from those described herein; it is obvious that the embodiments in the specification are only part of the embodiments of the present disclosure, rather than all of the embodiments.

[0050] It should be noted that, in this article, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the term "comprises" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.

[0051] With the continuous development of the new energy vehicle field, the number of ECUs (Electronic Control Units) in cars is increasing, and the demand for OTA (Over-the-Air Technology) functions is also increasing. Therefore, the BOOT (Bootloader) function of ECU to achieve self-upgrade of software has become an essential function for vehicles.

[0052] Usually, the storage area in a single ECU is divided into a boot loader partition and an application partition. The boot loader partition stores the boot loader BOOT, and the application partition stores the application APP. As a boot loader, BOOT can implement OTA of APP.

[0053] However, there are certain defects in the ECU upgrade method in the related technology. Some ECU upgrade methods do not support BOOT upgrades, while other ECU upgrade methods support BOOT upgrades, but when the upgrade fails, the BOOT function may fail, seriously affecting the user experience.

[0054] In order to solve the above technical problems, the embodiments of the present application provide an ECU upgrade method, device, equipment, medium and vehicle. The ECU upgrade method provided by the embodiments of the present application is described in detail below through some embodiments and their application scenarios in conjunction with the accompanying drawings.

[0055] Figure 1 The following is a flow chart of an ECU upgrade method provided by an embodiment of the present application. The ECU upgrade method includes:

[0056] S110, in response to the upgrade instruction, obtaining boot upgrade data and writing the boot upgrade data into a boot load partition in which the boot load program is not running among the multiple boot load partitions; wherein the boot upgrade data is an upgraded version of the boot load program;

[0057] S120, when the ECU is restarted and the pre-boot program is boot-loaded, boot-load the upgraded version of the boot loader program from the boot loading partition storing the boot upgrade data using the pre-boot program; wherein the pre-boot program is stored in the pre-boot partition;

[0058] S130, obtaining application upgrade data, and writing the application upgrade data into the application partition from which the original program data has been erased; wherein the application upgrade data is an upgraded version of the application program;

[0059] S140, when the ECU is restarted again and the upgraded version of the boot loader is boot-loaded, the upgraded version of the application program is boot-loaded from the application partition using the upgraded version of the boot loader.

[0060] The ECU upgrade method provided in the embodiment of the present application is applied to an ECU upgrade device. The ECU upgrade device can realize the upgrade of the boot loader BOOT and the application APP in the ECU, and when an abnormality occurs during the upgrade process, it can avoid the function failure of the ECU and ensure the user experience. The following is an example of the ECU in the car.

[0061] In this embodiment, the device can write the boot upgrade data to a partition in a non-running state among multiple boot loading partitions by responding to the upgrade instruction, and boot load from the partition through the pre-boot program to achieve the upgrade of the boot loader. When the upgraded version of the boot loader is running, the application upgrade data can be written to the application partition from which the original program data has been erased, and the application program can be boot loaded from the partition to achieve the upgrade of the application. The boot loader and the application program can be upgraded successively through a single upgrade instruction, which improves the convenience of ECU upgrade. When an abnormality occurs during the boot loader upgrade process, the boot loading partition storing the original program data can also be boot loaded again to fall back to the original boot loader, and the Boot function will not fail due to upgrade failure, thereby improving the user experience.

[0062] In S110, the device may respond to the upgrade instruction to upgrade the boot loader and the application respectively. The upgrade instruction may be triggered by a user, for example, by a user inside the vehicle, or by a user through a mobile device or other smart device that has a communication function with the vehicle, or by a car manufacturer through communication with the vehicle for directional triggering or range triggering. The user inside the vehicle may trigger the upgrade instruction by pressing an upgrade button inside the vehicle, by clicking on a related control on the display screen inside the vehicle, or by using voice inside the vehicle, and there is no limitation here.

[0063] After receiving the upgrade instruction, the device can communicate with the server and obtain the boot upgrade data. The boot upgrade data is the upgraded version of the boot loader. After obtaining the boot upgrade data, the device can determine the boot load partition in operation and the boot load partition that does not run the boot loader from multiple boot load partitions.

[0064] The above-mentioned multiple boot loading partitions can be multiple independent storage partitions in the storage module of the ECU. The multiple boot loading partitions can all store relevant data of the boot loading program. When the ECU is started, a boot loading partition can be selected from the multiple boot loading partitions, and the boot loading program stored in the boot loading partition can be run.

[0065] As an optional implementation, when setting multiple boot loading partitions, since the minimum storage space of each boot loading partition should be greater than or equal to the space occupied by the boot loader program, when setting the boot loading partitions, in order to reduce the total storage space of multiple boot loading partitions, the number of boot loading partitions can be set to 2.

[0066] Taking the case where the number of boot loader partitions is 2 as an example, the partition where the boot loader program selected to run when the ECU is started is the boot loader partition in the running state, and the other partition is the boot loader partition where the boot loader program is not running.

[0067] Since one of the multiple boot loading partitions is in a running state, the boot upgrade data can be written to the remaining boot loading partitions that are not running the boot loader, thereby avoiding affecting the normal operation of the ECU.

[0068] Please refer to Figure 2 As an optional embodiment, the above S110 may include:

[0069] S210, in response to the upgrade instruction, running a boot loader program, and obtaining boot upgrade data through the boot loader program;

[0070] S220, identifying a boot loading partition that does not run a boot loading program from a plurality of boot loading partitions, and writing boot upgrade data into the boot loading partition that does not run a boot loading program.

[0071] In this embodiment, the device can run the boot loader based on the upgrade instruction to obtain the boot upgrade data. The boot loader can write the boot upgrade data to the boot loading partition that does not run the boot loader, and the normal operation of the boot loader will not be affected during the data writing process.

[0072] In S210, the device may select a boot loading partition from multiple boot loading partitions in response to the upgrade instruction and run the boot loading program stored in the boot loading partition. The boot loading program can communicate with a server or other device storing boot upgrade data to obtain the boot upgrade data.

[0073] In S220, the device can identify, based on the running boot loader, from multiple boot loader partitions, that the partition corresponding to the running boot loader is a boot loader partition in a running state, and the remaining partitions are boot loader partitions where the boot loader is not running.

[0074] When the number of boot loading partitions is greater than 2, all boot loading partitions except the boot loading partition running the boot loading program are boot loading partitions that do not run the boot loading program. At this time, one boot loading partition can be selected from the multiple boot loading partitions that do not run the boot loading program as a partition for storing boot upgrade data.

[0075] In another embodiment, the device may also identify through the running status identifiers of multiple boot loading partitions. For example, if there is a difference in the running status identifier between a boot loading partition in a running state and a boot loading partition that is not running the boot loader, the boot loading partition that is not running the boot loader can be determined by identifying the running status identifier.

[0076] After determining the boot loading partition in which the boot loading program is not running, the acquired boot upgrade data may be written to the boot loading partition in which the boot loading program is not running.

[0077] Please refer to Figure 3 As an optional embodiment, after the above S110, the following may also be included:

[0078] S310, verifying the written boot upgrade data to obtain a verification result;

[0079] S320, when the verification result is successful, setting a first boot parameter based on the boot loading upgrade mode; wherein the first boot parameter is used to indicate that the boot loading partition storing the boot upgrade data among the multiple boot loading partitions is the first boot loading partition.

[0080] In this embodiment, after writing the boot upgrade data, the device can verify it. After the verification is successful, the first startup parameter can be set based on the boot loading upgrade mode so that the pre-boot program can identify the boot loading partition storing the boot upgrade data according to the first startup parameter.

[0081] In S310, after determining the boot loading partition where the boot loading program is not running and writing the boot upgrade data into the boot loading partition where the boot loading program is not running, the device may verify the boot upgrade data written into the boot loading partition and obtain a verification result.

[0082] As an optional implementation, the device can obtain verification and comparison data of the boot upgrade data when obtaining the boot upgrade data. Of course, the device can also obtain the verification and comparison data before obtaining the boot upgrade data, or obtain the verification and comparison data after obtaining the boot upgrade data.

[0083] After the device writes the boot upgrade data to the boot loading partition that does not run the boot loader, it can use the preset verification algorithm to process the boot upgrade data to obtain the data to be verified, and match the data to be verified with the verification comparison data. If the data to be verified matches the verification comparison data successfully, it means that the verification is successful; if the data to be verified fails to match the verification comparison data, it means that the verification result is verification failure.

[0084] When the verification fails, it means that there is an abnormality in the boot upgrade data obtained by the device. At this time, the ECU upgrade process can be stopped.

[0085] In S320, when the verification result is successful, the device may set the first startup parameter based on a preset boot loader upgrade mode.

[0086] After determining the boot load upgrade mode, the device can set a first boot parameter based on the boot load upgrade mode. The first boot parameter can indicate that the boot load partition storing the boot upgrade data among the multiple boot load partitions is the first boot load partition. That is, when the ECU is restarted, the device can determine the first boot load partition according to the first boot parameter, and the first boot load partition is the boot load partition storing the boot upgrade data among the multiple boot load partitions.

[0087] In S120, after the device writes the boot upgrade data into the boot loading partition that is not running the boot loader, the ECU can be restarted. The restarted ECU can run the pre-boot program, which can be stored in the pre-boot partition in the storage module of the ECU. It can be understood that the pre-boot partition is also independent of the above-mentioned multiple boot loading partitions.

[0088] When the boot loader needs to be upgraded, the ECU will not directly run the boot loader after restarting, but will run the pre-boot program. The pre-boot program can determine the boot loading partition that stores the boot upgrade data, and boot load the boot loader from the boot loading partition. For example, before the ECU is restarted, the ECU runs the original boot loader, and the original boot loader can obtain the boot upgrade data, which is the upgraded version of the boot loader. After the ECU is restarted, the ECU can boot load the boot loader from the boot loading partition that stores the boot upgrade data, thereby running the upgraded version of the boot loader.

[0089] Please refer to Figure 4 As an optional embodiment, the above S120 may include:

[0090] S410, obtaining a boot loading upgrade mode;

[0091] S420, when the boot loader upgrade mode is the first mode, determine a first boot loader partition from multiple boot loader partitions based on the first startup parameter, copy boot upgrade data from the first boot loader partition to a second boot loader partition using a pre-boot program, and boot load the boot loader program from the second boot loader partition;

[0092] S430: When the boot loader upgrade mode is the second mode, determine a first boot loader partition from multiple boot loader partitions based on the first startup parameter, and boot load the boot loader program from the first boot loader partition using the pre-boot program.

[0093] In this embodiment, when the boot load upgrade mode is the first mode, the device can determine the first boot load partition from multiple boot load partitions, and use the pre-boot program to copy the boot upgrade data to the second boot load partition. After the copy is completed, the pre-boot program can boot load the boot loader from the second boot load partition, so that the ECU always uses the second boot load partition as the partition where the boot loader actually runs. When the boot load upgrade mode is the second mode, the device can boot load the boot loader directly from the first boot load partition after determining the first boot load partition. At this time, the data in the second boot load partition is not overwritten, and fallback after the upgrade fails can be achieved.

[0094] In S410, when the ECU is restarted, it can obtain the pre-set boot loader upgrade mode.

[0095] The above boot loading upgrade mode may include a first mode and a second mode. For example, multiple boot loading partitions are BootA partition and BootB partition. In the first mode, BootA partition is the partition where the boot loading program actually runs, and BootB partition is only used as a cache area for temporarily storing boot upgrade data. That is, among the multiple boot loading partitions, BootA partition is a boot loading partition in a running state, and BootB partition is a boot loading partition where the boot loading program is not running.

[0096] In the second mode, both the BootA partition and the BootB partition can be used as the partitions where the boot loader actually runs. That is, when the device chooses to run the boot loader in the BootA partition, the BootA partition is the boot loader partition in the running state, and the BootB partition is the boot loader partition where the boot loader is not running; when the device chooses to run the boot loader in the BootB partition, the BootB partition is the boot loader partition in the running state, and the BootA partition is the boot loader partition where the boot loader is not running.

[0097] In S420, when the boot loader upgrade mode is the first mode, the device can determine a first boot loader partition from multiple boot loader partitions based on the first startup parameter, and the first boot loader partition is a boot loader partition storing boot upgrade data. Before the ECU is restarted, the first boot loader partition is a boot loader partition that does not run the boot loader program.

[0098] After determining the first boot loading partition, the device can copy the boot upgrade data from the first boot loading partition to the second boot loading partition by running the pre-boot program. After the copy is completed, the pre-boot program can boot load the boot loader from the second boot loading partition. At this time, the boot loader running is the upgraded version of the boot loader.

[0099] In S430, when the boot loader upgrade mode is the second mode, the device can determine a first boot loader partition from multiple boot loader partitions based on the first startup parameter, and the first boot loader partition is a boot loader partition storing boot upgrade data. Before the ECU is restarted, the first boot loader partition is a boot loader partition that does not run the boot loader program.

[0100] Since in the second mode, multiple boot loading partitions can be used as partitions for the boot loading program to actually run, the device can directly boot load the boot loading program from the first boot loading partition by running the pre-boot program. At this time, the boot loading program that runs is the upgraded version of the boot loading program.

[0101] As an optional embodiment, the above S120 may further include:

[0102] S510, when the upgraded version of the boot loader is boot-loaded by using the pre-boot program, the abnormality monitoring program is started, and the first boot times of the upgraded version of the boot loader are counted; the abnormality monitoring program is used to restart the ECU when the boot loading fails, and return to execute S410;

[0103] After the above S410, the following steps may also be included:

[0104] S520: When the first boot count reaches a first boot threshold and the boot loader upgrade mode is the second mode, boot load the boot loader program from the second boot loader partition using the pre-boot program.

[0105] In this embodiment, the device can start an abnormal monitoring program to restart the ECU when an abnormality or failure occurs in the boot loading each time the boot upgrade data is boot loaded, so as to re-boot load. When the number of boot loading reaches the preset requirement, the upgrade process can be stopped. If the boot loading upgrade mode is the second mode, the data in the second boot loading partition is not overwritten at this time, and the pre-boot program can boot load the boot loader from the second boot loading partition, so that when the upgrade boot loader fails, the original boot loader can continue to run.

[0106] In S510, when the device boots and loads the boot loading partition storing the boot upgrade data by running the pre-boot program, it can also start an abnormal monitoring program, such as a watchdog or other monitoring control, and count the first boot times of the upgraded version of the boot loader. The initial value of the first boot times is 0. Each time the ECU is restarted and the boot loader is boot loaded through the pre-boot program, the first boot times can be increased by 1 to count the boot times.

[0107] The above-mentioned abnormality monitoring program can perform abnormality monitoring during the process of boot loading the boot loader, and restart the ECU when an abnormality occurs in the boot loading process or the boot loading process fails.

[0108] After restarting, the ECU can reacquire the bootloader upgrade mode and re-boot the bootloader using the pre-boot program based on the bootloader upgrade mode.

[0109] In S520, when the bootloader is bootloaded using the pre-bootloader, if an exception occurs in the bootloading process, the ECU can be restarted through the exception monitoring program and the bootloading process can be restarted. The rebooting process can solve some abnormal problems, but when the boot upgrade data itself has an abnormality, the bootloading cannot be completed even if it is repeated many times. Therefore, the device can obtain a pre-set first boot threshold, and when the bootloading process is continuously restarted, if the first boot number reaches or exceeds the first boot threshold, it means that restarting the bootloading process can no longer solve the abnormal problem, and the upgrade process of the bootloader can be terminated at this time.

[0110] In an optional embodiment, the first boot threshold may be 3, and the device may be configured to terminate the boot loading process when the first boot number exceeds the first boot threshold. That is, when an exception occurs during the boot loading process of the upgraded version of the boot loader and the ECU is repeatedly restarted for the fourth time, the boot loading process may be terminated.

[0111] After the upgrade process of the boot loader is finished, if the boot loader upgrade mode is the second mode, then among the multiple boot loader partitions, the first boot loader partition stores the boot upgrade data, that is, the upgraded version of the boot loader, and the second boot loader partition stores the original boot loader. Since the boot upgrade data cannot be normally boot loaded during multiple boot loading processes, the device can use the pre-boot program to boot load the original boot loader from the second boot loading partition. That is, when an abnormality occurs in the upgraded boot loader, the original boot loader can be re-booted and loaded, so that even when the boot loader upgrade fails, the ECU can still upgrade the application through the original boot loader.

[0112] When the original boot loader can run normally, even if the boot loader upgrade fails, the application can still be booted and loaded and the application upgrade function can be realized by running the original boot loader, that is, the normal use and upgrade of the application are not affected.

[0113] In S130 , after the pre-boot program boot-loads the boot loader program from the boot loading partition storing the boot upgrade data, the ECU runs the upgraded version of the boot loader program during this power-on process.

[0114] When the upgraded version of the boot loader can run normally, the device can close the abnormal monitoring program. When the ECU runs the upgraded version of the boot loader, the device can receive the application program flashing instruction. After receiving the application program flashing instruction, the device can communicate with the server and obtain the application upgrade data. The application upgrade data is the upgraded version of the application program.

[0115] The above application flashing instruction may be automatically generated after the boot loader is upgraded, or may be generated after the boot loader is upgraded and a request or prompt is made to the user and the instruction is triggered by the user, and there is no limitation here.

[0116] After obtaining the application upgrade data, the device can write the application upgrade data to the application partition from which the original program data has been erased.

[0117] The application partition may be an independent storage partition in the storage module of the ECU, and the application partition may be independent of the pre-boot partition and the plurality of boot-loading partitions. When the ECU is started, the application stored in the application partition may be run to implement the corresponding function of the ECU.

[0118] Please refer to Figure 5 As an optional embodiment, the above S130 may include:

[0119] S610, in response to the application program flashing instruction, obtaining application upgrade data using the upgraded version of the boot loader;

[0120] S620, erasing the original program data in the application partition;

[0121] S630, writing the application upgrade data into the application partition.

[0122] In this embodiment, after the boot loader is upgraded, the ECU normally runs the upgraded boot loader, which can obtain the application upgrade data and write the application upgrade data into the application partition where the original program data has been erased.

[0123] In S610, the device may respond to the application program flashing instruction and run the upgraded version of the boot loader. The upgraded version of the boot loader can communicate with the server or other devices storing boot upgrade data to obtain application upgrade data. The application upgrade data is the upgraded version of the application program.

[0124] In S620, before writing the application upgrade data into the application partition, the device may erase the original program data in the application partition.

[0125] In S630, after erasing the original program data in the application partition, the device may write the application upgrade data into the application partition.

[0126] In S140, after the device writes the application upgrade data into the application partition, the ECU may be restarted. The restarted ECU may run the upgraded version of the boot loader.

[0127] When the application needs to be upgraded, the ECU will not directly run the application after restarting, but will run the upgraded version of the boot loader. The upgraded version of the boot loader can boot and load the application from the application partition. For example, before the ECU is restarted, the ECU runs the original application. After the ECU is restarted, the upgraded version of the boot loader can boot and load the application from the application partition, thereby running the upgraded application.

[0128] It is understandable that in the related art, even after the boot loader is updated, before the ECU is restarted, the original boot loader is still used to upgrade the application. In the embodiment of the present application, after the boot loader is upgraded and updated, the upgraded version of the boot loader can be immediately run to upgrade the application, thereby timely avoiding the problems caused by the original boot loader upgrading the application.

[0129] As an optional embodiment, when the boot loading upgrade mode is the first mode, the multiple boot loading partitions may correspond to two memories respectively.

[0130] It is understandable that if the multiple boot-loading partitions are two independent partitions of the same memory, the parameters of the multiple boot-loading partitions can be substantially the same. At this time, the multiple boot-loading partitions should all be able to be used as partitions where the boot loader actually runs. That is, when the multiple boot-loading partitions are two independent partitions of the same memory, the boot-loading upgrade mode should be set to the second mode, so that when an abnormality occurs in the boot-upgrade data, the boot-loading of the boot-upgrade data can no longer be performed, but the original boot loader can be directly boot-loaded to achieve fallback after the upgrade fails.

[0131] In this embodiment, when multiple boot loader partitions can correspond to two memories respectively, the boot loader upgrade mode can be set to the first mode. There is at least one parameter difference in the parameters of the two memories, for example, at least one of the functions, capacities, read / write speeds, setting locations, and access methods of the two memories is different.

[0132] According to the storage parameters corresponding to the two memories respectively, a memory more suitable for actual operation of the boot loader is selected from the two memories, and the boot loading partition corresponding to the memory is set as the second boot loading partition, and the other boot loading partition is set as the first boot loading partition.

[0133] It should be noted that in the above embodiment, the storage module of the ECU can be divided into four independent storage partitions, namely a pre-boot partition, multiple boot loading partitions and an application partition. The above four storage partitions can be obtained by dividing the same memory, or can be composed of two or more memories, which is not limited here.

[0134] The present application also provides an ECU upgrade device, such as Figure 6 As shown, the ECU upgrade device includes:

[0135] The first writing module 601 is used to obtain boot upgrade data in response to the upgrade instruction and write the boot upgrade data into the boot load partition that does not run the boot load program among the multiple boot load partitions; wherein the boot upgrade data is the boot load program of the upgraded version;

[0136] The first boot module 602 is used to boot load the upgraded version of the boot loader from the boot loading partition storing the boot upgrade data by using the pre-boot program when the ECU is restarted and the pre-boot program is boot loaded; wherein the pre-boot program is stored in the pre-boot partition;

[0137] The second writing module 603 is used to obtain application upgrade data and write the application upgrade data into the application partition from which the original program data has been erased; wherein the application upgrade data is an upgraded version of the application program;

[0138] The second boot module 604 is used to boot load the upgraded version of the application program from the application partition using the upgraded version of the boot loader when the ECU is restarted again and boot loads the upgraded version of the boot loader.

[0139] It should be noted that the ECU upgrade device is a device corresponding to the above-mentioned ECU upgrade method. All implementation methods in the above-mentioned method embodiment are applicable to the embodiment of the device and can achieve the same technical effect.

[0140] Figure 7 A schematic diagram of the hardware structure of the ECU upgrade device provided in an embodiment of the present application is shown.

[0141] The ECU upgrade device may include a processor 701 and a memory 702 storing computer program instructions.

[0142] Specifically, the processor 701 may include a central processing unit (CPU), or an application specific integrated circuit (ASIC), or may be configured to implement one or more integrated circuits of the embodiments of the present application.

[0143] The memory 702 may include a large capacity memory for data or instructions. By way of example and not limitation, the memory 702 may include a hard disk drive (HDD), a floppy disk drive, a flash memory, an optical disk, a magneto-optical disk, a tape, or a universal serial bus (USB) drive or a combination of two or more of these. Where appropriate, the memory 702 may include a removable or non-removable (or fixed) medium. Where appropriate, the memory 702 may be inside or outside the ECU upgrade device. In a particular embodiment, the memory 702 is a non-volatile solid-state memory.

[0144] In certain embodiments, the memory 702 may include a read-only memory (ROM), a random access memory (RAM), a magnetic disk storage media device, an optical storage media device, a flash memory device, an electrical, optical or other physical / tangible memory storage device. Thus, in general, the memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., a memory device) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the method according to an aspect of the present disclosure.

[0145] The processor 701 implements any one of the ECU upgrading methods in the above embodiments by reading and executing the computer program instructions stored in the memory 702 .

[0146] In one example, the ECU upgrade device may further include a communication interface 703 and a bus 710. Figure 7 As shown, the processor 701, the memory 702, and the communication interface 703 are connected via a bus 710 and communicate with each other.

[0147] The communication interface 703 is mainly used to implement communication between various modules, devices, units and / or equipment in the embodiments of the present application.

[0148] Bus 710 includes hardware, software or both, and couples the components of the ECU upgrade device to each other. For example, but not limitation, the bus may include an accelerated graphics port (AGP) or other graphics bus, an enhanced industrial standard architecture (EISA) bus, a front-end bus (FSB), a hypertransport (HT) interconnect, an industrial standard architecture (ISA) bus, an infinite bandwidth interconnect, a low pin count (LPC) bus, a memory bus, a microchannel architecture (MCA) bus, a peripheral component interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a serial advanced technology attachment (SATA) bus, a video electronics standard association local (VLB) bus or other suitable bus or a combination of two or more of these. Where appropriate, bus 710 may include one or more buses. Although the present application embodiment describes and illustrates a specific bus, the present application considers any suitable bus or interconnect.

[0149] In addition, in combination with the ECU upgrade method in the above embodiment, the embodiment of the present application can provide a computer storage medium for implementation. The computer storage medium stores computer program instructions; when the computer program instructions are executed by a processor, any one of the ECU upgrade methods in the above embodiment is implemented.

[0150] An embodiment of the present application also provides a vehicle, which may include at least one of the above-mentioned ECU upgrade device, ECU upgrade equipment or computer-readable storage medium.

[0151] It should be clear that the present application is not limited to the specific configuration and processing described above and shown in the figures. For the sake of simplicity, a detailed description of the known method is omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of the present application is not limited to the specific steps described and shown, and those skilled in the art can make various changes, modifications and additions, or change the order between the steps after understanding the spirit of the present application.

[0152] The functional blocks shown in the above block diagram can be implemented as hardware, software, firmware or a combination thereof. When implemented in hardware, it can be, for example, an electronic circuit, an application specific integrated circuit (ASIC), appropriate firmware, a plug-in, a function card, etc. When implemented in software, the elements of the present application are programs or code segments that are used to perform the required tasks. The program or code segment can be stored in a machine-readable medium, or transmitted on a transmission medium or a communication link by a data signal carried in a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, optical fiber media, radio frequency (RF) links, etc. The code segment can be downloaded via a computer network such as the Internet, an intranet, etc.

[0153] It should also be noted that the exemplary embodiments mentioned in this application describe some methods or systems based on a series of steps or devices. However, this application is not limited to the order of the above steps, that is, the steps can be performed in the order mentioned in the embodiment, or in a different order from the embodiment, or several steps can be performed simultaneously.

[0154] Aspects of the present disclosure are described above with reference to the flowchart and / or block diagram of the method, device (system) and computer program product according to the embodiment of the present disclosure. It should be understood that each box in the flowchart and / or block diagram and the combination of each box in the flowchart and / or block diagram can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device to produce a machine so that these instructions executed by the processor of the computer or other programmable data processing device enable the implementation of the function / action specified in one or more boxes of the flowchart and / or block diagram. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field programmable logic circuit. It can also be understood that each box in the block diagram and / or flowchart and the combination of boxes in the block diagram and / or flowchart can also be implemented by dedicated hardware that performs a specified function or action, or can be implemented by a combination of dedicated hardware and computer instructions.

[0155] The above are only specific implementation methods of the present application. Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working processes of the systems, modules and units described above can refer to the corresponding processes in the aforementioned method embodiments, and will not be repeated here. It should be understood that the protection scope of the present application is not limited to this. Any technician familiar with the technical field can easily think of various equivalent modifications or replacements within the technical scope disclosed in this application, and these modifications or replacements should be included in the protection scope of this application.

Claims

1. An ECU upgrade method, characterized in that: The ECU upgrade method comprises: In response to the upgrade instruction, boot upgrade data is obtained and written into a boot loading partition in which the boot loading program is not running among the multiple boot loading partitions; wherein the boot upgrade data is an upgraded version of the boot loading program; When the ECU is restarted and the pre-boot program is boot-loaded, the upgraded version of the boot loader program is boot-loaded from the boot loading partition storing the boot upgrade data using the pre-boot program; wherein the pre-boot program is stored in the pre-boot partition; Acquire application upgrade data, and write the application upgrade data into the application partition from which the original program data has been erased; wherein the application upgrade data is an upgraded version of the application program; When the ECU is restarted again and the upgraded version of the boot loader is boot-loaded, the upgraded version of the application program is boot-loaded from the application partition using the upgraded version of the boot loader.

2. The ECU upgrade method according to claim 1, characterized in that: After obtaining the boot upgrade data and writing it into the boot loading partition in which the boot loading program is not running among the multiple boot loading partitions, the method further includes: Verifying the written boot upgrade data to obtain a verification result; If the verification result is successful, a first boot parameter is set based on the boot loading upgrade mode; wherein the first boot parameter is used to indicate that the boot loading partition storing the boot upgrade data among the multiple boot loading partitions is the first boot loading partition.

3. The ECU upgrade method according to claim 2, characterized in that: In the case where the ECU is restarted and the pre-boot program is boot-loaded, boot-loading the upgraded version of the boot loader program from the boot loading partition storing the boot upgrade data by using the pre-boot program includes: Get bootloader upgrade mode; When the boot loading upgrade mode is the first mode, determining the first boot loading partition from the multiple boot loading partitions based on the first startup parameter, copying the boot upgrade data from the first boot loading partition to the second boot loading partition by using the pre-boot program, and boot loading the boot loading program from the second boot loading partition; When the boot loader upgrade mode is the second mode, the first boot loader partition is determined from the multiple boot loader partitions based on the first startup parameter, and the boot loader program is boot loaded from the first boot loader partition using the pre-boot program.

4. The ECU upgrade method according to claim 3, characterized in that: The method of boot-loading the upgraded version of the boot loader program from the boot loading partition storing the boot upgrade data by using the pre-boot program also includes: In the case where the upgraded version of the boot loader is boot-loaded by using the pre-boot program, an abnormality monitoring program is started and the first boot times of the upgraded version of the boot loader are counted; the abnormality monitoring program is used to restart the ECU in the case of boot loading failure and return to the execution step: obtaining the boot loading upgrade mode; After obtaining the boot loading upgrade mode, the method further includes: When the first boot number reaches a first boot threshold and the boot loading upgrade mode is a second mode, the boot loading program is boot loaded from the second boot loading partition using the pre-boot program.

5. The ECU upgrade method according to claim 3, characterized in that: The obtaining of application upgrade data and writing the application upgrade data into the application partition from which the original program data has been erased includes: In response to the application program flashing instruction, obtaining the application upgrade data using the upgraded version of the boot loader; Erasing original program data in the application partition; The application upgrade data is written into the application partition.

6. The ECU upgrade method according to claim 3, characterized in that: When the boot loading upgrade mode is the first mode, the multiple boot loading partitions correspond to two memories respectively, and the two memories are different in at least one of function, capacity, read and write speed, setting location, and access method.

7. The ECU upgrade method according to claim 1, characterized in that: The method of obtaining the boot upgrade data in response to the upgrade instruction and writing the boot upgrade data into the boot loading partition in which the boot loading program is not running among the plurality of boot loading partitions comprises: In response to the upgrade instruction, running a boot loader program, and acquiring the boot upgrade data through the boot loader program; A boot loading partition that does not run a boot loading program is identified from the plurality of boot loading partitions, and the boot upgrade data is written into the boot loading partition that does not run a boot loading program.

8. An ECU upgrade device, characterized in that: The ECU upgrading device comprises: A first writing module is used for obtaining boot upgrade data in response to an upgrade instruction and writing the boot upgrade data into a boot load partition in which a boot load program is not running among the multiple boot load partitions; wherein the boot upgrade data is an upgraded version of the boot load program; A first boot module, configured to boot load the upgraded version of the boot loader program from the boot loading partition storing the boot upgrade data by using the pre-boot program when the ECU is restarted and the pre-boot program is boot loaded; wherein the pre-boot program is stored in the pre-boot partition; A second writing module is used to obtain application upgrade data and write the application upgrade data into the application partition from which the original program data has been erased; wherein the application upgrade data is an upgraded version of the application program; The second boot module is used to boot load the upgraded version of the application program from the application partition using the upgraded version of the boot loader when the ECU is restarted again and boot loads the upgraded version of the boot loader.

9. An ECU upgrade device, characterized in that: The ECU upgrade device includes: a processor and a memory storing computer program instructions; When the processor executes the computer program instructions, the ECU upgrading method according to any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer program instructions, and when the computer program instructions are executed by a processor, the ECU upgrading method according to any one of claims 1 to 7 is implemented.

11. A vehicle, characterized in that: The vehicle comprises at least one of the following: The ECU upgrading device as claimed in claim 8; The ECU upgrade device as claimed in claim 9; The computer readable storage medium of claim 10.