Control system and method for preventing remote software upgrading abnormity, vehicle and medium

By designing a coordinated control system to monitor the vehicle network and its own status, avoiding the restart of the TBOX network module during the OTA upgrade process, the problems of upgrade interruptions and data loss are solved, and the continuity and security of the OTA upgrade process are ensured.

CN120075262APending Publication Date: 2025-05-30DEEPAL AUTOMOBILE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510226705.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-27
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

During the OTA upgrade of the vehicle, the restart of the TBOX network module may lead to upgrade interruption and data loss, especially in environments with poor network signals.

Method used

A control system is designed to monitor the vehicle network and its own status through the coordinated work of the TBOX network module, gateway, controller and OTA main control unit, determine whether it is in an OTA upgrade, and avoid restarting if necessary. In addition, the communication status between the OTA master control unit and the gateway is monitored in real time, and the exit mechanism is automatically triggered to ensure that the vehicle safely exits the OTA upgrade process.

Benefits of technology

It effectively prevents OTA upgrade interruption and data loss caused by TBOX network module restart, ensures the continuity of the upgrade process and data security, and reduces the inconvenience and risks caused to users due to the failure of the upgrade.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120075262A_ABST
    Figure CN120075262A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of vehicle control, in particular to a control system and method for preventing software remote upgrading abnormity, a vehicle and a medium, the control system comprises a TBOX network module, a gateway, a controller and an OTA main control unit, and the OTA main control unit is arranged in the TBOX network module; the TBOX network module is connected with the controller through the gateway; the control system is configured to send out a vehicle power-on instruction when the vehicle reaches the software appointment upgrading time, monitor a vehicle network and the state of the vehicle through the TBOX network module, judge whether the vehicle is in OTA upgrading or not when it is monitored that the vehicle network or the state of the vehicle is abnormal and the TBOX network module needs to be restarted, and send out the vehicle power-on instruction when the vehicle is in OTA upgrading. And if the OTA upgrading is carried out, restarting is not carried out, otherwise, restarting operation is carried out. According to the method and the device, OTA upgrading interruption and data loss caused by restarting of the TBOX network module in the upgrading process can be effectively prevented.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of vehicle control, and particularly relates to a control system, method, vehicle and medium for preventing abnormal remote software upgrade. Background Art

[0002] With the rapid development of automotive technology, especially the wide application of over-the-air (OTA) technology, intelligent vehicles have been able to configure upgrade tasks in the cloud and detect, download, and install software update packages through networking, thus completing the upgrade of the controller software version without on-site support from technicians. This technological innovation is particularly important in the development trend of electrified, connected, and intelligent vehicles, as it not only increases the vehicle's dependence on vehicle software but also becomes a key means for vehicles to achieve continuous updates of the vehicle system, problem repair, improvement of user experience, and reduction of enterprise recall risks and operating costs.

[0003] However, the OTA upgrade process is not always smooth. Since the upgrade process usually takes a long time, most users tend to choose the reservation upgrade method, that is, set a reservation upgrade task when the vehicle is parked in the garage or charging. Although this method can reduce the user's waiting time for the upgrade, it faces many challenges in actual operation. Especially when the vehicle is in an environment with poor network signals, such as underground garages, tunnels, etc., the working state of the TBOX network module is extremely vulnerable to the network condition. Once the TBOX network module detects abnormal network signals or abnormal working states of other internal modules after power-on, it may restart. If the vehicle is in the OTA upgrade process at this time, the restarted TBOX network module may continuously restart due to still abnormal signals, resulting in the loss of communication between the OTA master control unit and the controller, and the vehicle cannot normally exit the OTA upgrade process.

[0004] Vehicles in a long-term abnormal OTA upgrade state may have problems such as power depletion and inability to exit the OTA process, seriously affecting the normal use of users. Although some OTA upgrade control methods have been proposed currently, such as receiving the firmware over the air (FOTA) update package sent by the original equipment manufacturer (OEM) platform and determining whether the vehicle status meets the update conditions before updating, these methods often lack in-depth descriptions of specific control details, resulting in abnormal situations and OTA upgrade failures in some scenarios.

[0005] Another solution provides a control method for slicing the area after the controller upgrade fails, that is, setting a startup partition, a first running partition, and a second running partition in the controller, and using the dual-backup state to handle the situation of upgrade failure to shorten the OTA upgrade duration. However, this method still fails to comprehensively consider the OTA upgrade scenarios of vehicles in complex environments such as poor network signals, so there are still certain limitations in actual applications.

[0006] Therefore, it is necessary to develop a new control system, method, vehicle, and medium for preventing abnormal software remote upgrades. Summary of the Invention

[0007] The purpose of the present invention is to provide a control system, method, vehicle, and medium for preventing abnormal software remote upgrades, which can effectively prevent the OTA upgrade from being interrupted and data from being lost due to the restart of the TBOX network module during the upgrade process.

[0008] In a first aspect, a control system for preventing abnormal software remote upgrades according to the present invention includes a TBOX network module, a gateway, a controller, and an OTA main control unit. The TBOX network module is connected to the OTA main control unit; the TBOX network module is connected to the controller through the gateway; The control system is configured as follows: When the vehicle reaches the software reservation upgrade time, a vehicle power-on command is issued, the vehicle network and its own status are monitored through the TBOX network module, and when an abnormality in the vehicle network or its own status is detected and the TBOX network module needs to be restarted, it is judged whether the vehicle is in an OTA upgrade. If it is in an OTA upgrade, it is not restarted, otherwise a restart operation is performed.

[0009] Optionally, judging whether the vehicle is in an OTA upgrade specifically includes: Monitoring the working status of the OTA main control unit, and judging whether the vehicle is in an OTA upgrade according to the working status of the OTA main control unit. For example: when the vehicle is in the OTA upgrade process, the working status of the OTA main control unit is configured as 1, when the vehicle is in other states, the working status of the OTA main control unit is configured as 0, and it is judged whether the vehicle is in an OTA upgrade according to the status returned by the TA main control unit. If it is in an OTA upgrade, it is not restarted, and if it is not in the OTA upgrade state, it is restarted.

[0010] Optionally, it further includes a timing unit for monitoring the duration of no communication between the OTA main control unit and the gateway; The control system is further configured as follows: During the OTA upgrade process, it is monitored in real time whether there is communication between the OTA master control unit and the gateway. When the duration of no communication between the OTA master control unit and the gateway is greater than or equal to the preset time, the gateway sends a signal to exit the brush-writing power gear to the controller. After the controller controls the vehicle power supply to exit the brush-writing gear, the vehicle exits the OTA upgrade process. This can solve the problem that the vehicle cannot normally exit the OTA upgrade process due to the loss of communication between the OTA master control unit and the controller.

[0011] Optionally, the TBOX network module is further configured to: Record the restart times of the TBOX network module during the current power-on cycle after the vehicle is powered on, and judge whether the restart times are less than the preset times before each start of the TBOX network module. If the restart times of the TBOX network module are less than the preset times, the TBOX network module is restarted; otherwise, the TBOX network module is not restarted. By adding restart judgment logic and restricting the number of restarts, it is possible to effectively prevent the TBOX network module from entering a vicious cycle of continuous restart due to network signals and its own abnormal state.

[0012] In a second aspect, a control method for preventing software remote upgrade anomalies according to the present invention includes the following steps: Send a vehicle power-on command when the vehicle reaches the software reservation upgrade time; Monitor the vehicle network and its own state through the TBOX network module; When it is detected that the vehicle network or its own state is abnormal and the TBOX network module needs to be restarted, judge whether the vehicle is in the OTA upgrade; If the vehicle is in the OTA upgrade, the TBOX network module is not restarted; otherwise, the TBOX network module is restarted.

[0013] Optionally, judging whether the vehicle is in the OTA upgrade specifically includes: Monitor the working state of the OTA master control unit, and judge whether the vehicle is in the OTA upgrade according to the working state of the OTA master control unit. For example, when the vehicle is in the OTA upgrade process, the working state of the OTA master control unit is configured as 1; when the vehicle is in other states, the working state of the OTA master control unit is configured as 0. Judge whether the vehicle is in the OTA upgrade according to the state returned by the TA master control unit. Do not restart during the OTA upgrade, and restart when not in the OTA upgrade state.

[0014] Optionally, it further includes: During the OTA upgrade process, it is necessary to monitor in real time whether there is communication between the OTA master control unit and the gateway. When the duration of no communication between the OTA master control unit and the gateway is greater than or equal to the preset time, the gateway sends a signal to exit the brush power gear to the controller. After the controller controls the vehicle power supply to exit the brush gear, the vehicle exits the OTA upgrade process. This can solve the problem that the vehicle cannot normally exit the OTA upgrade process due to the loss of communication between the OTA master control unit and the controller.

[0015] Optionally, it further includes: Record the restart times of the TBOX network module during the current power-on cycle after the vehicle is powered on, and judge whether the restart times are less than the preset times before each start of the TBOX network module. If the restart times of the TBOX network module are less than the preset times, restart the TBOX network module; otherwise, do not restart the TBOX network module. This can solve the problem that the TBOX network module continuously restarts due to abnormal network signals after restart.

[0016] In a third aspect, a vehicle according to the present invention adopts the control system for preventing abnormal remote software upgrade as described in the present invention.

[0017] In a fourth aspect, a medium according to the present invention stores a computer-readable program, which can execute the steps of the control method for preventing abnormal remote software upgrade as described in the present invention when the computer-readable program is called.

[0018] Advantages of the present invention: (1) When it is detected that the status of the network or the TBOX network module is abnormal and the TBOX network module needs to be restarted, the control system can intelligently judge whether the vehicle is in the OTA upgrade process. If it is in the upgrade process, the restart is avoided to prevent upgrade interruption and data loss. This decision-making mechanism ensures the continuity of the upgrade process and the security of data.

[0019] (2) The present invention also has the ability to monitor the communication status between the OTA master control unit and the gateway in real time. Once the communication is abnormal and the interruption duration is too long, the system will automatically trigger the exit mechanism to ensure that the vehicle can safely and stably exit the OTA upgrade process. This design effectively solves the problem that the vehicle cannot normally exit the upgrade process due to communication loss.

[0020] (3) In order to prevent the TBOX network module from continuously restarting in complex environments such as abnormal network signals, the present invention records the restart times after the vehicle is powered on. Before each start, the system will judge whether the restart times reach the preset times. If they reach or exceed the preset times, the system will stop further restart operations, thus avoiding potential problems caused by continuous restart. This design further enhances the stability and reliability of the vehicle OTA upgrade process.

[0021] (4) By intelligently judging and avoiding restarting the TBOX network module during the OTA upgrade process, the present invention effectively reduces the risk of upgrade failure or interruption caused by restarting, which helps to improve the stability and success rate of the upgrade process.

[0022] In summary, the present invention has excellent environmental adaptability and fault response capabilities, and is designed to solve the OTA upgrade problem of vehicles in poor network signal or abnormal conditions. It ensures the smooth progress of the OTA upgrade process and greatly reduces the inconvenience and potential risks brought to users due to upgrade failure. Brief Description of the Drawings

[0023] Figure 1 It is a schematic block diagram of the control system for preventing abnormal software remote upgrade described in the embodiments of the present application; Figure 2 It is an architecture diagram of the software remote upgrade system described in the embodiments of the present application; Figure 3 It is a flowchart of the restart control of the TBOX network module in the control method for preventing abnormal software remote upgrade described in the embodiments of the present application; Figure 4 It is a flowchart of the power gear control in the control method for preventing abnormal software remote upgrade described in the embodiments of the present application; Figure 5 It is a flowchart of the restart times control in the control method for preventing abnormal software remote upgrade described in the embodiments of the present application; Figure 6 It is a flowchart of the software remote upgrade under normal requests; In the figure: 1 - TBOX network module, 11 - OTA main control unit, 2 - gateway, 21 - timing unit, 3 - controller, 4 - vehicle head unit, 5 - OTA vehicle-cloud platform. Specific Embodiments

[0024] The following will describe the embodiments of the present invention with reference to the accompanying drawings and preferred embodiments. Those skilled in the art can understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be understood that the preferred embodiments are only for illustrating the present invention and not for limiting the protection scope of the present invention.

[0025] Such as Figure 1 And Figure 3As shown in the figure, in the embodiment of the present application, a control system for preventing abnormal remote software upgrade includes a TBOX network module 1, a gateway 2, a controller 3, and an OTA main control unit 11. The TBOX network module 1 is connected to the OTA main control unit 11; the TBOX network module 1 is connected to the controller 3 through the gateway 2. The control system is configured to: issue a vehicle power-on command when the vehicle reaches the software reservation upgrade time, monitor the vehicle network and its own status through the TBOX network module 1, and when it is detected that the vehicle network or its own status is abnormal and the TBOX network module 1 needs to be restarted, determine whether the vehicle is in the OTA upgrade. If it is in the OTA upgrade, it will not be restarted; otherwise, the restart operation will be executed. When it is detected that the network or module status is abnormal and the TBOX network module 1 needs to be restarted, the control system can intelligently determine whether the vehicle is in the OTA upgrade process. If it is in the upgrade, the restart will be avoided to prevent upgrade interruption and data loss. This decision-making mechanism ensures the continuity of the upgrade process and the security of the data.

[0026] As Figure 1 shown, in a possible embodiment, the OTA main control unit 11 is integrated into the TBOX network module 1.

[0027] In a possible embodiment, determining whether the vehicle is in the OTA upgrade specifically includes: monitoring the working status of the OTA main control unit 11 and determining whether the vehicle is in the OTA upgrade according to the working status of the OTA main control unit 11. For example: when the vehicle is in the OTA upgrade process, the working status of the OTA main control unit 11 is configured as 1; when the vehicle is in other states, the working status of the OTA main control unit 11 is configured as 0. Determine whether the vehicle is in the OTA upgrade according to the status returned by the TA main control unit. Do not restart during the OTA upgrade, and restart when not in the OTA upgrade state.

[0028] As Figure 1 and Figure 4 shown, in a possible embodiment, it further includes a timing unit 21 for monitoring the duration of no communication between the OTA main control unit 11 and the gateway 2. The control system is further configured to: When the vehicle reaches the software reservation upgrade time and the vehicle is powered on, the OTA master control unit 11 sends a power brush writing gear request to the controller 3, and the vehicle enters the OTA upgrade process. During the OTA upgrade process, it is continuously monitored whether there is communication between the OTA master control unit 11 and the gateway 2. When the duration of no communication between the OTA master control unit 11 and the gateway 2 is greater than or equal to the preset time, the gateway 2 sends a signal to exit the brush writing power gear to the controller 3. After the controller 3 controls the vehicle power supply to exit the brush writing gear, the vehicle exits the OTA upgrade process. It can solve the problem that the vehicle cannot normally exit the OTA upgrade process due to the loss of communication between the OTA master control unit 11 and the controller 3.

[0029] As Figure 1 shown, in a possible embodiment, the timing unit 21 is integrated in the gateway 2.

[0030] As Figure 1 and Figure 5 shown, in a possible embodiment, the TBOX network module 1 is further configured to: After the vehicle is powered on, record the number of restarts of the TBOX network module 1 during this power-on cycle, and judge whether the number of restarts is less than the preset number before each start of the TBOX network module 1. If the number of restarts of the TBOX network module 1 is less than the preset number, restart the TBOX network module 1, otherwise do not restart the TBOX network module 1, and detect the status of the TBOX network module 1 after the vehicle is powered on next time. It can solve the problem that the TBOX network module 1 continuously restarts due to the abnormal network signal after restart.

[0031] As Figure 3 shown, in the embodiment of the present application, a control method for preventing software remote upgrade anomalies includes the following steps: Send a vehicle power-on instruction when the vehicle reaches the software reservation upgrade time; Monitor the vehicle network and its own status through the TBOX network module 1; When it is detected that the vehicle network or its own status is abnormal and the TBOX network module 1 needs to be restarted, judge whether the vehicle is in the OTA upgrade; If the vehicle is in the OTA upgrade, do not restart the TBOX network module 1, otherwise restart the TBOX network module 1.

[0032] In a possible embodiment, judging whether the vehicle is in the OTA upgrade specifically is: Monitor the working status of the OTA master unit 11, and determine whether the vehicle is in the OTA upgrade according to the working status of the OTA master unit 11. For example: when the vehicle is in the OTA upgrade process, configure the working status of the OTA master unit 11 to 1; when the vehicle is in other states, configure the working status of the OTA master unit 11 to 0. Determine whether the vehicle is in the OTA upgrade according to the status returned by the TA master unit. Do not perform a restart during the OTA upgrade, and perform a restart when not in the OTA upgrade state.

[0033] As Figure 4 shown, in a possible embodiment, a control method for preventing software remote upgrade anomalies further includes: After the vehicle reaches the software reservation upgrade time and is powered on, the OTA master unit 11 sends a power brush writing gear request to the controller 3, and the vehicle enters the OTA upgrade process. During the OTA upgrade process, continuously monitor whether there is communication between the OTA master unit 11 and the gateway 2. When the duration of no communication between the OTA master unit 11 and the gateway 2 is greater than or equal to a preset time (such as 10 minutes, which can also be appropriately adjusted according to the actual situation, such as: 8 minutes, 9 minutes, 11 minutes, etc.), the gateway 2 sends a signal to exit the brush writing power gear to the controller 3. After the controller 3 controls the vehicle power supply to exit the brush writing gear, the vehicle exits the OTA upgrade process. This can solve the problem that the vehicle cannot normally exit the OTA upgrade process due to the loss of communication between the OTA master unit 11 and the controller 3.

[0034] As Figure 5 shown, in a possible embodiment, a control method for preventing software remote upgrade anomalies further includes: After the vehicle is powered on, record the restart times of the TBOX network module 1 during this power-on cycle, and judge whether the restart times are less than the preset times before each start of the TBOX network module 1. If the restart times of the TBOX network module 1 are less than the preset times (such as: the preset times is 5 times, which can also be appropriately adjusted according to the actual situation, such as: 3 times, 4 times, or 6 times, etc.), then restart the TBOX network module 1, otherwise do not restart the TBOX network module 1. By adding a restart judgment logic and restricting the restart times, it is possible to effectively prevent the TBOX network module 1 from entering a vicious cycle of continuous restart due to network signals and its own abnormal states.

[0035] As Figure 2As shown, in a possible embodiment, a system architecture for software remote upgrade includes a TBOX network module 1, a gateway 2, a controller 3, a vehicle head unit 4, and an OTA vehicle-cloud platform 5. The TBOX network module 1 is connected to an OTA main control unit 11; the TBOX network module 1 is connected to the controller 3 through the gateway 2. The TBOX network module 1 can establish a communication connection with the OTA vehicle-cloud platform 5, and the vehicle head unit 4 is connected to the gateway 2. A timing unit 21 is provided in the gateway 2.

[0036] As Figure 6 shown, when the vehicle is in a normal network state and the self-state of the TBOX network module 1 is normal, the software remote upgrade process is as follows: S1: The user initiates an upgrade task detection. The OTA main control unit 11 on the vehicle side collects information of the controller 3, including software version number, software part number, hardware version number, and hardware part number, and uploads it to the OTA vehicle-cloud platform 5. The OTA vehicle-cloud platform 5 performs version comparison and sends the comparison result to the OTA main control unit 11.

[0037] S2: The OTA main control unit 11 receives and parses the comparison result, detects an upgrade task, downloads the upgrade package, and stores the installation package in the TBOX network module 1 or the controller 3.

[0038] S3: After the upgrade package is downloaded, the OTA main control unit 11 verifies the integrity and security of the upgrade package.

[0039] S4: The user sets a reserved upgrade task and locks the vehicle. After the vehicle is powered on at the reserved upgrade time, the OTA main control unit 11 sends a power brush writing gear request, and the vehicle enters the OTA upgrade process. After the OTA preconditions such as vehicle gear, vehicle speed, power gear, power battery power, and auxiliary battery power are prepared, the OTA main control unit 11 notifies the gateway 2, and the vehicle CAN network enters a silent state (only transmitting diagnostic messages) to erase and update the software of the controller 3.

[0040] S5: For the intelligent controller 3, after the OTA main control unit 11 sends a brush writing instruction, the controller 3 performs self-brush writing, and the controller 3 feeds back the brush writing progress and result to the OTA main control unit 11.

[0041] For the controller 3 with FBL brush writing, it is brushed according to the diagnostic standard process, and the OTA main control unit 11 controls the brush writing process to erase and update the software of the controller 3.

[0042] S6: After the OTA upgrade is completed, the OTA master control unit 11 feeds back the upgrade completion status to the TBOX network module 1. After receiving the feedback, the TBOX network module 1 sends a request to exit the OTA flashing gear to the controller 3. After the controller 3 sends the request to exit the flashing gear, it exits the OTA flashing gear, and the OTA upgrade process ends.

[0043] In the embodiments of the present application, based on the above software remote upgrade, after adding the method for preventing software remote upgrade anomalies in the embodiments of the present application, it is possible to cope with the upgrade challenges in complex environments such as poor network signals of the vehicle, ensure the smooth progress of the OTA upgrade process, and reduce the inconvenience and risks brought to users due to upgrade failures.

[0044] In the embodiments of the present application, a vehicle adopts a control system for preventing software remote upgrade anomalies as in the embodiments of the present application.

[0045] In the embodiments of the present application, a medium stores a computer-readable program, which when called, can execute the steps of the control method for preventing software remote upgrade anomalies as in the embodiments of the present application.

[0046] In the embodiments of the present application, the medium can be a tangible storage medium, which can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. The storage medium can be a machine-readable signal storage medium or a machine-readable storage medium. The storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatuses, or devices, or any suitable combination of the above. More specific examples of the storage medium will include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above.

[0047] The above embodiments are preferred embodiments of the present invention, but the embodiments of the present invention are not limited to the above embodiments. Any other changes, modifications, substitutions, combinations, and simplifications made without departing from the spirit and principle of the present invention shall be equivalent replacement methods and are all included in the protection scope of the present invention.

Claims

1. A control system for preventing abnormal software remote upgrade, characterized in that: The control system comprises a TBOX network module (1), a gateway (2), a controller (3) and an OTA main control unit (11), wherein the TBOX network module (1) is connected to the OTA main control unit (11); the TBOX network module (1) is connected to the controller (3) via the gateway (2); The control system is configured to: When the vehicle reaches the scheduled software upgrade time, a vehicle power-on command is issued, and the vehicle network and its own status are monitored through the TBOX network module (1). When it is detected that the vehicle network or its own status is abnormal and the TBOX network module (1) needs to be restarted, it is determined whether the vehicle is in the OTA upgrade process. If the vehicle is in the OTA upgrade process, the vehicle will not be restarted, otherwise a restart operation is performed.

2. The control system for preventing abnormal software remote upgrade according to claim 1, characterized in that: Determine whether the vehicle is in OTA upgrade, specifically: The working state of the OTA main control unit (11) is monitored, and whether the vehicle is in the process of OTA upgrading is determined according to the working state of the OTA main control unit (11).

3. The control system for preventing abnormal remote software upgrade according to claim 1, characterized in that: It also includes a timing unit (21) for monitoring the duration of no communication between the OTA main control unit (11) and the gateway (2); The control system is also configured to: During the OTA upgrade process, whether there is communication between the OTA main control unit (11) and the gateway (2) is monitored in real time. When the duration of no communication between the OTA main control unit (11) and the gateway (2) is greater than or equal to a preset time, the gateway (2) sends a flash power gear exit signal to the controller (3). After the controller (3) controls the power of the entire vehicle to exit the flash power gear, the entire vehicle exits the OTA upgrade process.

4. The control system for preventing abnormal remote software upgrade according to claim 1, characterized in that: The TBOX network module (1) is further configured to: After the vehicle is powered on, the number of restarts of the TBOX network module (1) in the current power-on cycle is recorded, and before each start of the TBOX network module (1), it is determined whether the number of restarts is less than a preset number. If the number of restarts of the TBOX network module (1) is less than the preset number, the TBOX network module (1) is restarted, otherwise the TBOX network module (1) is not restarted.

5. A control method for preventing abnormal software remote upgrade, characterized in that: The following steps are involved: When the vehicle reaches the scheduled software upgrade time, a vehicle power-on command is issued; The vehicle network and its own status are monitored through the TBOX network module (1); When the vehicle network or its own status is detected to be abnormal and the TBOX network module (1) needs to be restarted, determine whether the vehicle is in the process of OTA upgrade; If the vehicle is in the process of OTA upgrade, the TBOX network module (1) will not be restarted; otherwise, the TBOX network module (1) will be restarted.

6. The control method for preventing abnormal software remote upgrade according to claim 5, characterized in that: Determine whether the vehicle is in OTA upgrade, specifically: The working state of the OTA main control unit (11) is monitored, and whether the vehicle is in the process of OTA upgrading is determined according to the working state of the OTA main control unit (11).

7. The control method for preventing abnormal software remote upgrade according to claim 5, characterized in that: Also includes: During the OTA upgrade process, whether there is communication between the OTA main control unit (11) and the gateway (2) is monitored in real time. When the duration of no communication between the OTA main control unit (11) and the gateway (2) is greater than or equal to a preset time, the gateway (2) sends a flash power gear exit signal to the controller (3). After the controller (3) controls the power of the entire vehicle to exit the flash power gear, the entire vehicle exits the OTA upgrade process.

8. The control method for preventing abnormal software remote upgrade according to claim 5, characterized in that: Also includes: After the vehicle is powered on, the number of restarts of the TBOX network module (1) in the current power-on cycle is recorded, and before each start of the TBOX network module (1), it is determined whether the number of restarts is less than a preset number. If the number of restarts of the TBOX network module (1) is less than the preset number, the TBOX network module (1) is restarted, otherwise the TBOX network module (1) is not restarted.

9. A vehicle, characterized in that: A control system for preventing abnormal remote software upgrade as described in any one of claims 1 to 4 is adopted.

10. A medium, characterized in that A computer-readable program is stored therein, and when the computer-readable program is called, the steps of the control method for preventing abnormal remote software upgrade as described in any one of claims 5 to 8 can be executed.