Boot mutual refreshing method and device based on intelligent automobile trust chain
By adopting a boot mutual refresh method based on the trust chain of the smart car in smart cars, and using the backup and failure mechanism of the associated ECU, the problems of complex structure and high cost in the boot upgrade process in the existing technology are solved, and a safe and efficient boot upgrade is achieved, avoiding the situation of running and running.
Patent Information
- Application Number
- CN202510204522.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-24
- Publication Date
- 2025-06-13
AI Technical Summary
The existing technology has problems of complex structure and high development and maintenance costs in the upgrade process of smart car boots. Especially when the SB needs to be updated, the existing solution is difficult to effectively handle, which may lead to the situation where the associated ECU stores two boots and runs flying.
The boot mutual refresh method based on the smart car trust chain is adopted, and the CB backup of the original ECU is used to prevent power loss when the boot is updated. After the upgrade is successful, the boot stored in the associated ECU is set to invalid to avoid running and running.
It effectively avoids the possibility of self-refreshing and upgrade failure, thereby preventing APP from failing and saving development and maintenance costs.
Smart Images

Figure CN120144148A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of intelligent vehicle boot upgrade, and specifically relates to a boot mutual refresh method and device based on the trust chain of intelligent vehicles. Background Art
[0002] Currently, the upgrade of each manufacturer's boot is for the upgrade or update of its own electronic control unit (hereinafter referred to as ECU). Some software architectures are two-level Boot: SB (Startboot) + CB (Customerboot), and SB is maintained by the supplier itself. Since the program startup sequence is SB -> CB -> APP, adding refresh logic in SB can update CB. What if SB also needs to be updated? And the existing solutions have complex structures, high development and maintenance costs, and are a burden on controllers that do not require SB. Therefore, a technical solution that does not require the development of SB and prevents the associated ECU from storing two boots and running away is expected.
[0003] Based on this technical background, the present invention has studied a boot mutual refresh method and device based on the trust chain of intelligent vehicles. Summary of the Invention
[0004] Aiming at the deficiencies of the prior art, the present invention provides a boot mutual refresh method and device based on the trust chain of intelligent vehicles. This method uses the associated lower-level ECU to back up the CB of the original ECU to prevent power failure during boot update. After the upgrade is successful, the boot stored in the associated ECU is set to invalid to prevent the situation where the associated ECU stores two boots and runs away, avoiding the possibility of upgrade failure in self-refresh, which may lead to the invalidation of APP, and saving development and maintenance costs.
[0005] To achieve the above object, the first aspect of the present invention provides a boot mutual refresh method based on the trust chain of intelligent vehicles, including:
[0006] Using an associated node of an ECU to back up the boot CB of this ECU to obtain a backup boot CB;
[0007] Performing a boot upgrade on the original version of this ECU, and sending a successful upgrade flag to the said one associated node after the upgrade is completed;
[0008] After receiving the successful upgrade flag, the said one associated node sets the backup boot CB to an invalid mode;
[0009] Repeating the above process until the version upgrade of all ECUs is completed.
[0010] The second aspect of the present invention provides a boot mutual refresh device based on the trust chain of intelligent vehicles, including:
[0011] A backup module, configured to back up the boot CB of an ECU using an associated node of a certain ECU to obtain a backup boot CB;
[0012] An upgrade module, configured to perform a boot upgrade on the original version of the ECU, and send an upgrade success flag to the said associated node after the upgrade is completed;
[0013] An association failure module, after receiving the upgrade success flag, the said associated node sets the backup boot CB to an invalid mode;
[0014] A repeated call module, configured to repeat the above process until the version upgrade of all ECUs is completed.
[0015] The third aspect of the present invention provides an electronic device, the electronic device includes:
[0016] A memory, storing executable instructions;
[0017] A processor, the processor runs the executable instructions in the memory to implement the boot mutual refresh method based on the trust chain of intelligent vehicles described in the first aspect.
[0018] The fourth aspect of the present invention provides a computer-readable storage medium, the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the boot mutual refresh method based on the trust chain of intelligent vehicles described in the first aspect.
[0019] The beneficial effects of the present invention include:
[0020] The boot mutual refresh method based on the trust chain of intelligent vehicles proposed by the present invention uses the associated lower-level ECU to back up the CB of the original ECU to prevent power loss during boot update. After the upgrade is successful, the boot stored in the associated ECU is set to invalid to prevent the situation where two boots are stored in the associated ECU and the operation goes awry, avoiding the possibility of upgrade failure in self-refresh, which may lead to the invalidation of the APP, and saving development and maintenance costs.
[0021] Other features and advantages of the present invention will be described in detail in the subsequent specific implementation section. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] By describing the exemplary embodiments of the present invention in more detail in conjunction with the drawings, the above and other objects, features, and advantages of the present invention will become more obvious.
[0023] Figure 1Schematic flowchart of the boot mutual refresh method based on the trust chain of intelligent vehicles proposed by the present invention.
[0024] Figure 2 Schematic diagram of the boot mutual refresh structure in a specific embodiment of the boot mutual refresh method based on the trust chain of intelligent vehicles proposed by the present invention.
[0025] Figure 3 Schematic diagram of the trust chain loop in a specific embodiment of the boot mutual refresh method based on the trust chain of intelligent vehicles proposed by the present invention.
[0026] Figure 4 Schematic diagram of the boot mutual refresh principle based on the trust chain in a specific embodiment of the boot mutual refresh method based on the trust chain of intelligent vehicles proposed by the present invention. Specific Embodiment
[0027] The preferred embodiments of the present invention will be described in more detail below. Although the preferred embodiments of the present invention are described below, it should be understood that the present invention can be implemented in various forms and should not be limited by the embodiments set forth herein.
[0028] The present invention provides a boot mutual refresh method based on the trust chain of intelligent vehicles, as Figure 1 shown, including:
[0029] Use an associated node of a certain ECU to back up the boot CB of this ECU to obtain a backup boot CB;
[0030] Perform a boot upgrade on the original version of this ECU, and send a successful upgrade flag to an associated node after the upgrade is completed;
[0031] After an associated node receives the successful upgrade flag, set the backup boot CB to the invalid mode;
[0032] Repeat the above process until the version upgrades of all ECUs are completed.
[0033] In the present invention, the trust chain includes multiple ECUs, and each ECU has at least one other ECU as its associated node.
[0034] In the present invention, use the associated next-level ECU to back up the CB of the original ECU to prevent power loss during boot update. After the upgrade is successful, set the boot stored in the associated ECU to invalid to prevent the situation where two boots are stored in the associated ECU and the operation runs away, avoiding the possibility of upgrade failure in self-refresh, which may cause the APP to fail, and saving the development and maintenance costs.
[0035] According to the present invention, backing up the boot CB of an ECU using an associated node of the ECU to obtain a backup boot CB includes:
[0036] Using the extra flash space of the APP of the ECU associated with an associated node of the ECU to back up the boot CB of the ECU to obtain a backup boot CB.
[0037] According to the present invention, multiple ECUs include a central processing unit and multiple vehicle integration unit ECUs.
[0038] According to the present invention, the central processing unit ECU is associated with at least one vehicle integration unit ECU, and each vehicle integration unit ECU is associated with the central processing unit ECU, or is associated with some or several other vehicle integration unit ECUs.
[0039] Preferably, the central processing unit ECU and the multiple vehicle integration unit ECUs form a trust chain loop.
[0040] According to the present invention, backing up the boot CB of an ECU using an associated node of the ECU to obtain a backup boot CB includes:
[0041] Using a vehicle integration unit ECU associated with the central processing unit ECU to back up the boot CB of the central processing unit ECU to obtain a backup boot CB, or,
[0042] Using the central processing unit ECU or another vehicle integration unit ECU associated with a vehicle integration unit ECU to back up the boot CB of the vehicle integration unit ECU to obtain a backup boot CB;
[0043] Performing a boot upgrade on the original version of the ECU, and after the upgrade is completed, sending an upgrade success flag to an associated node includes:
[0044] Performing a boot upgrade on the original version of the central processing unit ECU, and after the upgrade is completed, sending an upgrade success flag to a vehicle integration unit ECU, or,
[0045] Performing a boot upgrade on the original version of a vehicle integration unit ECU, and after the upgrade is completed, sending an upgrade success flag to the central processing unit ECU or another vehicle integration unit ECU associated with it.
[0046] According to the present invention, after an associated node receives the upgrade success flag, setting the backup boot CB of the associated node to the invalid mode includes:
[0047] After receiving the upgrade success flag, a vehicle integrated unit ECU sets the backup boot CB to the invalid mode, or,
[0048] After receiving the upgrade success flag, the central processing unit ECU or another vehicle integrated unit ECU sets the backup boot CB to the invalid mode.
[0049] The present invention will be described in more detail by way of embodiments below.
[0050] Embodiment 1:
[0051] This embodiment proposes a boot mutual refresh method based on the trust chain of intelligent vehicles. The overall implementation process includes:
[0052] Utilize the additional flash space of the APP of the associated ECU to perform boot backup, then update the boot of the original ECU. After the upgrade is completed, send the flag to the associated node, and the associated node sets the backup boot to the invalid mode;
[0053] As Figures 2-4 shown, the specific implementation process includes:
[0054] First, the central processing unit ECU transfers the area boot CB0 to be upgraded to the area independent of the APP of the next-level associated vehicle integrated unit ECU1;
[0055] Secondly, the central processing unit upgrades its own boot. After the upgrade is successful, the central processing unit boot is updated to newCB0;
[0056] Finally, the central processing unit ECU sends the upgrade success flag flag01 to the vehicle integrated unit ECU1. At this time, after receiving flag01, the vehicle integrated unit ECU1 sets the previous version boot oldCB0 of the original central processing unit ECU stored in ECU1 to the invalid mode;
[0057] And so on, vehicle integrated unit ECU1 -> vehicle integrated unit ECU2, vehicle integrated unit ECU2 -> vehicle integrated unit ECU3, vehicle integrated unit ECU3 -> vehicle integrated unit ECU4, vehicle integrated unit ECU4 -> central processing unit ECU.
[0058] Embodiment 2:
[0059] This embodiment provides a boot mutual refresh method based on the trust chain of intelligent vehicles. As Figure 1 shown, among them, the trust chain includes multiple ECUs, and each ECU has at least one other ECU as its associated node, including:
[0060] Back up the boot CB of the ECU using an associated node of a certain ECU to obtain a backup boot CB;
[0061] Perform a boot upgrade on the original version of the ECU, and send a successful upgrade flag to an associated node after the upgrade is completed;
[0062] After an associated node receives the successful upgrade flag, set the backup boot CB to the invalidation mode;
[0063] Repeat the above process until the version upgrade of all ECUs is completed;
[0064] In this embodiment, backing up the boot CB of the ECU using an associated node of a certain ECU to obtain a backup boot CB includes:
[0065] Associate the extra flash space of the APP of the ECU with an associated node of a certain ECU, and back up the boot CB of the ECU to obtain a backup boot CB;
[0066] In this embodiment, multiple ECUs include a central processing unit and multiple vehicle integration unit ECUs;
[0067] In this embodiment, the central processing unit ECU is associated with at least one vehicle integration unit ECU, each vehicle integration unit ECU is associated with the central processing unit ECU, or is associated with some or several other vehicle integration unit ECUs;
[0068] In this embodiment, the central processing unit ECU and multiple vehicle integration unit ECUs form a trust chain loop;
[0069] In this embodiment, backing up the boot CB of the ECU using an associated node of a certain ECU to obtain a backup boot CB includes:
[0070] Back up the boot CB of the central processing unit ECU using a vehicle integration unit ECU associated with the central processing unit ECU to obtain a backup boot CB, or
[0071] Back up the boot CB of the vehicle integration unit ECU using the central processing unit ECU or another vehicle integration unit ECU associated with a vehicle integration unit ECU to obtain a backup boot CB;
[0072] Performing a boot upgrade on the original version of the ECU and sending a successful upgrade flag to an associated node after the upgrade is completed includes:
[0073] Perform a boot upgrade on the original version of the central processing unit ECU. After the upgrade is completed, send a successful upgrade flag to a vehicle integrated unit ECU. Or,
[0074] Perform a boot upgrade on the original version of a vehicle integrated unit ECU. After the upgrade is completed, send a successful upgrade flag to the associated central processing unit ECU or another vehicle integrated unit ECU;
[0075] In this embodiment, when an associated node receives the successful upgrade flag, setting the backup boot CB of the associated node to the invalid mode includes:
[0076] When a vehicle integrated unit ECU receives the successful upgrade flag, set the backup boot CB to the invalid mode. Or,
[0077] When the central processing unit ECU or another vehicle integrated unit ECU receives the successful upgrade flag, set the backup boot CB to the invalid mode.
[0078] Embodiment 3:
[0079] This embodiment provides a boot mutual refresh device based on the trust chain of intelligent vehicles. Among them, the trust chain includes multiple ECUs, and each ECU has at least one other ECU as its associated node, including:
[0080] A backup module, which is used to back up the boot CB of an ECU by using an associated node of a certain ECU to obtain a backup boot CB;
[0081] An upgrade module, which is used to perform a boot upgrade on the original version of the ECU. After the upgrade is completed, send a successful upgrade flag to an associated node;
[0082] An associated invalidation module. When an associated node receives the successful upgrade flag, set the backup boot CB of the associated node to the invalid mode;
[0083] A repeated call module, which is used to repeat the above process until the version upgrade of all ECUs is completed;
[0084] In this embodiment, backing up the boot CB of an ECU by using an associated node of a certain ECU to obtain a backup boot CB includes:
[0085] Using the extra flash space of the APP of the ECU associated with an associated node of a certain ECU to back up the boot CB of the ECU to obtain a backup boot CB;
[0086] In this embodiment, the multiple ECUs include a central processing unit and multiple vehicle integrated unit ECUs;
[0087] In this embodiment, a central processing unit ECU is associated with at least one vehicle integrated unit ECU, and each vehicle integrated unit ECU is associated with the central processing unit ECU, or is associated with some other vehicle integrated unit ECU(s).
[0088] In this embodiment, the central processing unit ECU and multiple vehicle integrated unit ECUs form a trust chain loop.
[0089] In this embodiment, backing up the boot CB of an ECU by using an associated node of a certain ECU to obtain a backup boot CB includes:
[0090] Backing up the boot CB of the central processing unit ECU by using a vehicle integrated unit ECU associated with the central processing unit ECU to obtain a backup boot CB, or
[0091] Backing up the boot CB of a vehicle integrated unit ECU by using the central processing unit ECU or another vehicle integrated unit ECU associated with the vehicle integrated unit ECU to obtain a backup boot CB;
[0092] Boot-upgrading the original version of the ECU and sending an upgrade success flag to an associated node after the upgrade is completed includes:
[0093] Boot-upgrading the original version of the central processing unit ECU and sending an upgrade success flag to a vehicle integrated unit ECU after the upgrade is completed, or
[0094] Boot-upgrading the original version of a vehicle integrated unit ECU and sending an upgrade success flag to the central processing unit ECU or another vehicle integrated unit ECU associated with it after the upgrade is completed;
[0095] In this embodiment, after an associated node receives the upgrade success flag, setting the backup boot CB of the associated node to the invalidation mode includes:
[0096] After a vehicle integrated unit ECU receives the upgrade success flag, setting the backup boot CB to the invalidation mode, or
[0097] After the central processing unit ECU or another vehicle integrated unit ECU receives the upgrade success flag, setting the backup boot CB to the invalidation mode.
[0098] Embodiment 4:
[0099] An embodiment of the present invention provides an electronic device including a memory and a processor.
[0100] The memory stores executable instructions.
[0101] A processor that runs executable instructions in a memory to implement a boot mutual refresh method based on the trust chain of an intelligent vehicle.
[0102] The memory is used to store non-transitory computer-readable instructions. Specifically, the memory may include one or more computer program products, and the computer program products may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may include, for example, random access memory (RAM) and / or cache memory, etc. The non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc.
[0103] The processor may be a central processing unit (CPU) or other forms of processing units with data processing capabilities and / or instruction execution capabilities, and may control other components in the electronic device to perform desired functions. In an embodiment of the present invention, the processor is used to run the computer-readable instructions stored in the memory.
[0104] Those skilled in the art should understand that, in order to solve the technical problem of how to obtain a good user experience effect, this embodiment may also include well-known structures such as communication buses, interfaces, etc., and these well-known structures should also be included in the protection scope of the present invention.
[0105] For a detailed description of this embodiment, reference may be made to the corresponding descriptions in the foregoing embodiments, and details will not be repeated here.
[0106] Embodiment Five:
[0107] An embodiment of the present invention provides a computer-readable storage medium that stores a computer program, and when the computer program is executed by a processor, it implements a boot mutual refresh method based on the trust chain of an intelligent vehicle.
[0108] According to the computer-readable storage medium of the embodiment of the present invention, non-transitory computer-readable instructions are stored thereon. When the non-transitory computer-readable instructions are run by a processor, all or part of the steps of the methods of the foregoing embodiments of the present invention are executed.
[0109] The above computer-readable storage medium includes but is not limited to: optical storage media (such as: CD-ROM and DVD), magneto-optical storage media (such as: MO), magnetic storage media (such as: magnetic tape or removable hard disk), media with built-in rewritable non-volatile memory (such as: memory card), and media with built-in ROM (such as: ROM cartridge).
[0110] The boot mutual refresh method based on the trust chain of intelligent vehicles proposed by the embodiments of the present invention utilizes the CB backup of the original ECU by the associated next-level ECU to prevent power failure during boot update. After the upgrade is successful, the boot stored in the associated ECU is set to invalid to prevent the associated ECU from storing two boots and avoid the occurrence of a runaway situation, thus avoiding the possibility of upgrade failure in self-refresh, which may lead to APP failure, and saving development and maintenance costs.
[0111] The embodiments of the present invention have been described above. The above description is exemplary, not exhaustive, and is not limited to the disclosed embodiments. Many modifications and variations are obvious to those of ordinary skill in the art without departing from the scope and spirit of the described embodiments.
Claims
1. A boot mutual refresh method based on a trust chain of an intelligent vehicle, wherein the trust chain includes multiple ECUs, each ECU has at least one other ECU as its associated node, characterized in that: include: Backing up the boot CB of a certain ECU by using a node associated with the ECU to obtain a backup boot CB; Performing boot upgrade on the original version of the ECU, and sending an upgrade success flag to the associated node after the upgrade is completed; After receiving the upgrade success flag, the one associated node sets the backup boot CB to failure mode; Repeat the above process until the version upgrade of all ECUs is completed.
2. The method according to claim 1, characterized in that The boot CB of a certain ECU is backed up by using a node associated with the ECU to obtain a backup boot CB including: The boot CB of a certain ECU is backed up by using the extra flash space of an APP associated with an associated node of the ECU to obtain a backup boot CB.
3. The method according to claim 1, characterized in that The multiple ECUs include a central processing unit and multiple vehicle integrated unit ECUs.
4. The method according to claim 3, characterized in that The central processing unit ECU is associated with at least one vehicle integrated unit ECU, and each vehicle integrated unit ECU is associated with the central processing unit ECU, or is associated with one or several other vehicle integrated unit ECUs.
5. The method according to claim 4, characterized in that The central processing unit ECU and multiple vehicle integrated unit ECUs form a trust chain loop.
6. The method according to claim 5, characterized in that The boot CB of a certain ECU is backed up by using a node associated with the ECU to obtain a backup boot CB including: Backing up the boot CB of the central processing unit ECU by using a vehicle integrated unit ECU associated with the central processing unit ECU to obtain a backup boot CB, or, Backing up the boot CB of a vehicle integrated unit ECU by using the central processing unit ECU or another vehicle integrated unit ECU associated with the vehicle integrated unit ECU to obtain a backup boot CB; The boot upgrade of the original version of the ECU and sending an upgrade success flag to the associated node after the upgrade is completed include: Boot upgrade the original version of the central processing unit ECU, and after the upgrade is completed, send an upgrade success mark to the vehicle integrated unit ECU, or, The original version of a vehicle integrated unit ECU is boot-upgraded, and after the upgrade is completed, an upgrade success mark is sent to the central processing unit ECU or another vehicle integrated unit ECU associated with it.
7. The method according to claim 6, characterized in that After receiving the upgrade success mark, the associated node sets the backup boot CB to failure mode, including: After receiving the upgrade success flag, the vehicle integrated unit ECU sets the backup boot CB to failure mode, or, The central processing unit ECU or another vehicle integrated unit ECU sets the backup boot CB to failure mode after receiving the upgrade success mark.
8. A boot mutual refresh device based on smart car trust chain, characterized in that: include: A backup module, used for backing up the boot CB of a certain ECU by using a node associated with the ECU to obtain a backup boot CB; An upgrade module, used for booting and upgrading the original version of the ECU, and sending an upgrade success flag to the associated node after the upgrade is completed; An associated failure module, wherein after receiving the upgrade success flag, the associated node sets the backup boot CB to failure mode; The module is called repeatedly to repeat the above process until the version upgrade of all ECUs is completed.
9. An electronic device, characterized in that: The electronic device comprises: A memory storing executable instructions; A processor, wherein the processor runs the executable instructions in the memory to implement the boot mutual refresh method based on the smart car trust chain according to any one of claims 1-7.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the boot mutual refresh method based on the smart car trust chain as described in any one of claims 1 to 7.