Firmware upgrading method, control chip, electronic control unit and vehicle
By splitting and distributing the OTA upgrade data packets to multiple storage devices for verification and storage, the security risks in the vehicle parts upgrade process are solved, and high reliability and security upgrade of data packets are achieved.
Patent Information
- Application Number
- CN202311763417.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-19
- Publication Date
- 2025-06-20
AI Technical Summary
Vehicle parts have security risks during the OTA upgrade process, and the upgraded software may be tampered with, stolen or hijacked by attackers.
By receiving the target upgrade data packet and splitting it into multiple data blocks, it is allocated to at least two first storage devices for storage, and data verification is performed on the data blocks to ensure the integrity and legality of the data blocks before firmware upgrade.
It improves the reliability and security of the target upgrade data packets, reduces the risk of data blocks being stolen in the storage device, protects the confidentiality of the upgrade data, and reduces the cost and computing power requirements of the control chip.
Smart Images

Figure CN120180439A_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present disclosure relate to the technical field of firmware security upgrades, and more particularly, to a method for upgrading the firmware of a control chip, a control chip, an electronic control unit, and a vehicle. Background Art
[0002] Based on the recent development trend of the Internet of Vehicles, the OTA (Over-the-Air Technology) upgrade of vehicle components has become a common requirement for components.
[0003] However, in all links of the OTA upgrade of vehicle components, there are security risks, and the upgraded software may be tampered with, stolen, or hijacked by attackers. Summary of the Invention
[0004] An object of embodiments of the present disclosure is to provide a new technical solution for the secure upgrade of the firmware of a control chip.
[0005] According to a first aspect of embodiments of the present disclosure, there is provided a method for upgrading the firmware of a control chip, including:
[0006] Receiving a plurality of data blocks obtained by splitting a target upgrade data packet;
[0007] Allocating the plurality of data blocks to at least two first storage devices for storage;
[0008] Performing data verification on the received plurality of data blocks;
[0009] When the plurality of data blocks are successfully verified, storing the plurality of data blocks in a second storage device for firmware upgrade.
[0010] Optionally, the allocating the plurality of data blocks to at least two first storage devices for storage includes:
[0011] Analyzing the encoding of the plurality of data blocks to obtain a sorting value representing the arrangement order of the plurality of data blocks;
[0012] Determining the first storage device corresponding to each data block according to the sorting value;
[0013] Allocating each data block to the corresponding first storage device respectively.
[0014] Optionally, the method further includes:
[0015] Receiving the digital signature of the target upgrade data packet;
[0016] Parsing the digital signature to obtain a first hash value of the target upgrade data packet;
[0017] Performing data verification on the received multiple data blocks includes:
[0018] Calculating a second hash value of the multiple data blocks;
[0019] Comparing the first hash value and the second hash value;
[0020] When the first hash value is equal to the second hash value, determining that the verification of the multiple data blocks is successful; when the first hash value is not equal to the second hash value, determining that the verification of the multiple data blocks fails.
[0021] Optionally, the method further includes:
[0022] When the verification of the multiple data blocks fails, deleting the data blocks of the target upgrade data packet stored in the at least two first storage devices and sending an alarm.
[0023] Optionally, the method further includes:
[0024] When the data blocks of the target upgrade data packet stored in the second storage device are attacked, re-obtaining the multiple data blocks of the target upgrade data packet from the at least two first storage devices.
[0025] Optionally, the method further includes:
[0026] When a startup event occurs, detecting whether there is illegal data stored in the functional modules connected to the control chip;
[0027] When there is illegal data stored in the functional module, prohibiting the power supply from supplying power to the functional module.
[0028] According to a second aspect of the present disclosure, there is provided a control chip, including a processor and a memory, the memory is used for storing a computer program, and the computer program is used for controlling the processor to execute the method as described in the first aspect of the present disclosure.
[0029] According to a third aspect of the present disclosure, there is provided an electronic control unit, at least two first storage devices, and at least one control chip according to the second aspect of the present disclosure, and each control chip is connected to at least two first storage devices.
[0030] Optionally, the first storage device is a control chip with a hardware security module.
[0031] According to a fourth aspect of the present disclosure, there is provided a vehicle, including the electronic control unit according to the third aspect of the present disclosure.
[0032] According to a second aspect of the present disclosure, there is also provided a computer-readable storage medium, on which a computer program is stored, and the computer program, when executed by a processor, implements the method as described in the first aspect of the present disclosure.
[0033] Through this embodiment, by allocating the multiple data blocks obtained by splitting the target upgrade data packet to at least two first storage devices, the reliability of the target upgrade data packet can be improved, the difficulty of stealing the data blocks of the target upgrade data packet in the first storage device can be increased, and the confidentiality of the target upgrade data packet can be protected; in the case where multiple received data blocks are successfully verified, then storing the multiple data blocks in the second storage device for firmware upgrade can prevent the original data in the control chip from being affected in the case where the received data block is illegal or the data block is attacked during transmission, thereby improving the security of the control chip. In addition, through the method of this embodiment, there is no need to set a hardware security module in the control chip, which can reduce the cost of the control chip. In addition, through the method of this embodiment, there is no need for the data platform to encrypt each split data block in advance, nor does the control chip need to decrypt each received data block, which can shorten the time required for firmware upgrade of the control chip and reduce the computing power requirement of the control chip.
[0034] Other features and advantages of the present invention will become clear through the following detailed description of exemplary embodiments of the present invention with reference to the accompanying drawings. Description of the Drawings
[0035] The drawings incorporated in the specification and constituting a part of the specification illustrate embodiments of the present invention and, together with the description, are used to explain the principles of the present invention.
[0036] Figure 1 is a schematic connection structure diagram of a control chip and a first storage device according to an embodiment of the present disclosure;
[0037] Figure 2 is a flowchart of a firmware upgrade method for a control chip according to an embodiment of the present disclosure;
[0038] Figure 3 is a flowchart of an example of a firmware upgrade method for a control chip according to an embodiment of the present disclosure;
[0039] Figure 4 is a block diagram of a control chip according to an embodiment of the present disclosure;
[0040] Figure 5 is a block diagram of an electronic control unit according to an embodiment of the present disclosure. Detailed Embodiments
[0041] Various exemplary embodiments of the present invention will now be described in detail with reference to the accompanying drawings. It should be noted that: unless otherwise specifically stated, the relative arrangements of components and steps, numerical expressions, and numerical values set forth in these embodiments do not limit the scope of the present invention.
[0042] The following description of at least one exemplary embodiment is merely illustrative in nature and is in no way a limitation on the present invention, its applications, or uses.
[0043] Techniques, methods, and devices known to those of ordinary skill in the relevant art may not be discussed in detail, but where appropriate, the techniques, methods, and devices should be regarded as part of the specification.
[0044] In all examples shown and discussed herein, any specific values should be construed as merely exemplary and not as a limitation. Thus, other examples of the exemplary embodiments may have different values.
[0045] It should be noted that: like reference numerals and letters denote like items in the following drawings, and thus, once an item is defined in one drawing, further discussion thereof is not required in subsequent drawings.
[0046] <Vehicle Control Method>
[0047] The present disclosure provides a method for firmware upgrade of a control chip. This method can be implemented by the control chip.
[0048] In one embodiment, as Figure 1 shown, the control chip 1100 can be connected to at least two first storage devices 1200. The first storage devices 1200 can be arranged outside the control chip 1100.
[0049] In another embodiment, part or all of the first storage devices 1200 can also be arranged inside the control chip 1100.
[0050] The control chip 1100 can be a processor chip provided in an Electronic Control Unit (ECU) of a vehicle. The control chip 1100 can also include a storage device and a communication device inside, where the storage is used to store corresponding software data, and the communication device is used for external communication.
[0051] The first storage device 1200 can be provided by a memory such as a flash memory or an Electrically Erasable Programmable Read Only Memory (EEPROM), or can also be provided by a control chip with a Hardware Security Module (HSM).
[0052] Figure 2 It is a flowchart of a firmware upgrade method for a control chip according to an embodiment of the present disclosure.
[0053] As Figure 2 shown, the firmware upgrade method of the control chip may include steps S2100 to S2400 as follows:
[0054] Step S2100, receive multiple data blocks obtained by splitting a target upgrade data packet.
[0055] In this embodiment, the supplier of the target upgrade data uploads the target upgrade data packet to the data platform. The data platform can split the target upgrade data packet into multiple data blocks through a preset splitting algorithm, and transmit the multiple data blocks to the control chip through the vehicle's vehicle communication for the control chip to receive.
[0056] Specifically, the control chip can determine each received data block based on a preset splitting algorithm.
[0057] Step S2200, allocate the multiple data blocks to at least two first storage devices for storage.
[0058] Specifically, the control chip can allocate each received data block to the corresponding first memory for storage every time it receives a data block.
[0059] In an embodiment of the present disclosure, allocating the multiple data blocks to at least two first storage devices for storage may include: determining the corresponding first storage device according to the reception order of each data block; allocating each data block to the corresponding first storage device for storage.
[0060] Specifically, in the case where there are N (N is a positive integer greater than 1) first storage devices and M (M is a positive integer greater than 1) data blocks are received, the i-th received data block can be allocated to the (i % N + 1)-th first storage device for storage, where i is a positive integer less than or equal to M.
[0061] In another embodiment of the present disclosure, allocating a plurality of data blocks to at least two first storage devices for storage may include: randomly determining the first storage device corresponding to each data block; and respectively allocating each data block to the corresponding first storage device for storage.
[0062] In this embodiment, the number of data blocks corresponding to each first storage device may be the same or different, which is not limited herein.
[0063] In still another embodiment of the present disclosure, allocating a plurality of data blocks to at least two first storage devices for storage may further include: parsing the encoding of the plurality of data blocks to obtain a sorting value representing the arrangement order of the plurality of data blocks; determining the first storage device corresponding to each data block according to the sorting value; and allocating each data block to the corresponding first storage device for storage.
[0064] In this embodiment, when the data platform splits the target upgrade data packet into a plurality of data blocks through a preset splitting algorithm, generates an encoding representing the arrangement order of each data block based on a preset encoding algorithm, and transmits the plurality of data blocks and the encoding corresponding to each data block to the control chip through the vehicle's in-vehicle communication for the control chip to receive.
[0065] Further, the control chip may parse the encoding of the plurality of data blocks based on a decoding algorithm corresponding to the encoding algorithm to obtain a sorting value representing the arrangement order of the plurality of data blocks. For any value, based on the encoding obtained by the encoding algorithm, and then decoding the encoding based on the corresponding decoding algorithm, the result obtained is the same as the value before encoding.
[0066] Still further, in the case where N (N is a positive integer greater than 1) first storage devices are provided and M (M is a positive integer greater than 1) data blocks are received, the data block with the sorting value of j may be allocated to the (j % N + 1)-th first storage device for storage, where j is a positive integer less than or equal to M.
[0067] Through this embodiment, the plurality of data blocks obtained by splitting the target upgrade data packet are allocated to the corresponding first storage devices, which can ensure that the target upgrade data packet can be backed up to the first storage device, improve the reliability of the target upgrade data packet, and increase the difficulty of the data blocks of the target upgrade data packet being stolen in the first storage device. Moreover, when an abnormality occurs during the transmission of the target upgrade data packet, it will not affect the original data in the control chip. In addition, by allocating the plurality of data blocks obtained by splitting the target upgrade data packet to at least two first storage devices for storage, the confidentiality of the target upgrade data packet can be protected.
[0068] Step S2300, performing data verification on the received plurality of data blocks.
[0069] In one embodiment of the present disclosure, the method may further include: receiving a digital signature of a target upgrade data packet; parsing the digital signature to obtain a first hash value of the target upgrade data packet.
[0070] In this embodiment, the data platform may pre-calculate a first hash value of the target upgrade data packet based on a set hash algorithm, and then process the first hash value through a specific digital signature algorithm to obtain the digital signature of the target upgrade data packet. When the data platform splits the target upgrade data packet into multiple data blocks, it then transmits the digital signature and the multiple data blocks to the control chip through the vehicle's in-vehicle communication for the control chip to receive.
[0071] Further, before transmitting the digital signature to the control chip, the data platform may also encrypt the digital signature based on a set encryption algorithm. Then, the control chip may decrypt the received encrypted digital signature based on a decryption algorithm corresponding to the encryption algorithm to obtain the digital signature of the target upgrade data packet.
[0072] When the control chip obtains the digital signature of the target upgrade data packet, it may parse the digital signature of the target upgrade data packet based on the digital signature algorithm to obtain the first hash value of the target upgrade data packet.
[0073] On this basis, data verification of the received multiple data blocks may include: calculating a second hash value of the received multiple data blocks based on a set hash algorithm; comparing the received first hash value with the calculated second hash value; when the first hash value is equal to the second hash value, determining that the verification of the multiple data blocks is successful; when the first hash value is not equal to the second hash value, determining that the verification of the multiple data blocks fails.
[0074] In one example, the control chip may read the multiple data blocks from the first storage device when the reception of the multiple data blocks of the target upgrade data packet is completed, and then calculate the second hash value of the received multiple data blocks according to the arrangement order of the multiple data blocks and the set hash algorithm.
[0075] In another example, the control chip may also update the second hash value of all the data blocks of the target upgrade data packet that have been received once for each received data block according to the arrangement order of the multiple data blocks and the set hash algorithm.
[0076] Through this embodiment, data verification is performed on the integrity and legality of multiple received data blocks, so that subsequently, when multiple data blocks are successfully verified, the multiple data blocks can be stored in the second storage device. In the case where the received data block is illegal data or the data block is attacked during transmission, the original data in the control chip will not be affected.
[0077] Step S2400, when multiple data blocks are successfully verified, store the multiple data blocks in the second storage device for firmware upgrade.
[0078] Among them, the second storage device can be a storage device inside the control chip.
[0079] When multiple data blocks are successfully verified, it means that the multiple data blocks received by the control chip are complete and legal and can be used for firmware upgrade. Therefore, the multiple data blocks can be read from the first storage device and stored in the second storage device.
[0080] When storing the multiple data blocks in the second storage device, the control chip can be firmware-updated according to the received data blocks. Or, when all the data blocks obtained by splitting the target upgrade data packet are stored in the second storage device, the firmware upgrade of the control chip is completed.
[0081] Through this embodiment, the multiple data blocks obtained by splitting the target upgrade data packet are allocated to at least two first storage devices, which can improve the reliability of the target upgrade data packet, increase the difficulty of stealing the data blocks of the target upgrade data packet in the first storage device, and protect the confidentiality of the target upgrade data packet; when multiple received data blocks are successfully verified, the multiple data blocks are then stored in the second storage device for firmware upgrade, which can prevent the original data in the control chip from being affected in the case where the received data block is illegal data or the data block is attacked during transmission, and improve the security of the control chip. In addition, through the method of this embodiment, there is no need to set a hardware security module in the control chip, which can reduce the cost of the control chip. In addition, through the method of this embodiment, there is no need for the data platform to encrypt each split data block in advance, nor does the control chip need to decrypt each received data block, which can shorten the time required for the control chip firmware upgrade and reduce the computing power requirement of the control chip.
[0082] In an embodiment of the present disclosure, the method may further include: when multiple data blocks are verified to be failed, deleting the data blocks of the target upgrade data packet stored in the first storage device and sending out an alarm.
[0083] In the case where multiple received data blocks fail to be verified, it indicates that the multiple data blocks of the received target upgrade data packet are illegal data or incomplete, and cannot be used for firmware upgrade of the control chip. Therefore, the data blocks stored in the first storage device are not stored in the second storage device to avoid affecting the original data inside the control chip and prevent the control chip from being maliciously attacked.
[0084] On this basis, since the data blocks of the target upgrade data packet stored in the first storage device are illegal data or incomplete, the data blocks of the target upgrade data packet stored in the first storage device can be deleted to prevent useless data blocks from occupying the storage space of the first storage device.
[0085] Furthermore, when multiple data blocks fail to be verified, the control chip issues an alarm and notifies the user through other functional modules in the vehicle for the user to solve the problem in a timely manner.
[0086] Even further, when multiple data blocks fail to be verified, the control chip can also record this exception for the user to view.
[0087] In an embodiment of the present disclosure, the method may further include: when the data blocks of the target upgrade data packet stored in the second storage device are attacked, re-obtaining multiple data blocks of the target upgrade data packet from the first storage device.
[0088] In this embodiment, if the control chip is maliciously attacked, resulting in the loss or damage of the data blocks of the target upgrade data packet stored in the second storage device, multiple data blocks of the target upgrade data packet can be re-obtained from the first storage device to improve the reliability of the control chip.
[0089] In an embodiment of the present disclosure, the method may further include: when a startup event occurs, detecting whether there is illegal data stored in the functional modules connected to the control chip; when there is illegal data stored in the functional modules, prohibiting the power supply from supplying power to the functional modules.
[0090] In this embodiment, the functional modules connected to the control chip may include the first storage device directly connected to the control chip, or may also include other control chips connected to the first storage device connected to the control chip, that is, the first storage device connected to the control chip with a hardware security module is the same as the first storage device connected to other control chips.
[0091] Furthermore, the method may further include: when a startup event occurs, the control chip detects whether there is illegal data inside the control chip; when it is detected that there is illegal data inside the control chip, prohibiting the power supply from supplying power to the functional modules connected to the control chip.
[0092] Further, the method may further include: when it is detected that the control chip contains illegal data, clearing the illegal data inside the control chip.
[0093] When the illegal data inside the control chip is application layer data, if it is detected that the corresponding data block in the first storage device is legal data, the corresponding data block can be retrieved again from the first storage device. If it is detected that the application layer corresponding data block in the first storage device contains illegal data, an alarm may be issued and the user may be notified through other functional modules in the vehicle so that the user can solve the problem in time.
[0094] When there is a hardware security module in the control chip, if it is detected that the illegal data inside the control chip is not application layer data, the corresponding program code may not be executed, and an alarm may be issued and the user may be notified through other functional modules in the vehicle so that the user can solve the problem in time.
[0095] In this embodiment, when the control chip detects that the connected functional module stores illegal data, the power supply to the functional module is prohibited, which can prevent the functional module storing illegal data from affecting other functional modules that do not store illegal data and reduce the impact on the vehicle.
[0096] <Example>
[0097] Figure 3 It is a flowchart of an example of a firmware upgrade method for a control chip according to an embodiment of the present disclosure.
[0098] As Figure 3 shown, the method may include the following steps:
[0099] Step S3011, the supplier uploads the target upgrade data packet to the data platform.
[0100] Step S3021, the data platform calculates the first hash value of the target upgrade data packet based on the set hash algorithm.
[0101] Step S3022, the data platform processes the first hash value through a specific digital signature algorithm to obtain the digital signature of the target upgrade data packet.
[0102] Step S3023, the data platform encrypts the digital signature based on the set encryption algorithm to obtain the encrypted digital signature.
[0103] Step S3024, the data platform splits the target upgrade data packet into multiple data blocks through a preset splitting algorithm and generates a code representing the arrangement order of each data block based on a preset coding algorithm.
[0104] Step S3025: The data platform transmits multiple data blocks, the encoding corresponding to each data block, and the encrypted digital signature to the control chip through the vehicle's vehicle communication.
[0105] Step S3031: The control chip parses the encoding of the multiple received data blocks to obtain a sorting value representing the arrangement order of the multiple data blocks, and determines the first storage device corresponding to each data block according to the sorting value.
[0106] Step S3032: The control chip distributes each received data block to the corresponding first storage device for storage.
[0107] Step S3033: The control chip decrypts the received encrypted digital signature based on the decryption algorithm corresponding to the encryption algorithm to obtain the digital signature of the target upgrade data packet.
[0108] Step S3034: The control chip parses the digital signature of the target upgrade data packet based on the digital signature algorithm to obtain the first hash value of the target upgrade data packet.
[0109] Step S3035: The control chip calculates the second hash value of the multiple received data blocks.
[0110] Step S3036: The control chip performs data verification on the multiple received data blocks according to the first hash value and the second hash value.
[0111] Step S3037: When the verification of the multiple data blocks is successful, the control chip stores the multiple data blocks in the second storage device for firmware upgrade.
[0112] Step S3038: When the verification of the multiple data blocks fails, the control chip deletes the data blocks of the target upgrade data packet stored in the first storage device, records this exception, and issues an alarm.
[0113] <Control chip>
[0114] The present disclosure also provides a control chip, as Figure 4 shown. The control chip 4000 may include a processor 4100 and a memory 4200. The memory 4200 is used to store a computer program, and the computer program is used to control the processor 4100 to execute the method described in any embodiment of the present disclosure.
[0115] <Electronic control unit>
[0116] The present disclosure also provides an electronic control unit, as Figure 5As shown, the electronic control unit 5000 may include at least two first storage devices 5100 and at least one control chip 4000 as described in any embodiment of the present disclosure.
[0117] Specifically, each control chip 4000 may be connected to at least two first storage devices 5100. The first storage devices 5100 connected to different control chips 4000 may be the same or different, which is not limited herein.
[0118] In this embodiment, the first storage device 5100 may be provided outside the control chip 4000 or inside the control chip 4000, which is not limited herein.
[0119] In one embodiment of the present disclosure, the first storage device 5100 may be provided by a memory such as a flash memory or an Electrically Erasable Programmable Read Only Memory (EEPROM), or may be provided by a control chip with a Hardware Security Module (HSM).
[0120] <Vehicle>
[0121] The present disclosure also provides a vehicle, which may include the electronic control unit described in the foregoing embodiment.
[0122] The present disclosure may be a system, method, and / or computer program product. The computer program product may include a computer-readable storage medium having thereon computer-readable program instructions for causing a processor to implement various aspects of the present disclosure.
[0123] A computer-readable storage medium can be a tangible device that can hold and store instructions for use by an instruction execution device. A computer-readable storage medium may be, for example—but not limited to—an electrical storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of the computer-readable storage medium include: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), a digital versatile disc (DVD), a memory stick, a floppy disk, a mechanically encoded device, such as a punched card or raised structures in grooves having instructions stored thereon, and any suitable combination of the foregoing. The computer-readable storage medium as used herein is not construed as an instantaneous signal per se, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagated through a waveguide or other transmission medium (e.g., an optical pulse through an optical fiber cable), or an electrical signal transmitted through a wire.
[0124] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to respective computing / processing devices, or downloaded to an external computer or external storage device through a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network may include a copper transmission cable, an optical fiber transmission, a wireless transmission, a router, a firewall, a switch, a gateway computer, and / or an edge server. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in a computer-readable storage medium in each computing / processing device.
[0125] The computer program instructions for performing the operations of the present disclosure may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine - related instructions, microcode, firmware instructions, state - setting data, or source code or object code written in any combination of one or more programming languages, including object - oriented programming languages such as Smalltalk, C++, etc., and conventional procedural programming languages such as the "C" language or similar programming languages. The computer - readable program instructions may be executed entirely on the user's computer, partially on the user's computer, executed as a stand - alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or alternatively, may be connected to an external computer (e.g., via an Internet service provider through the Internet). In some embodiments, by using the state information of the computer - readable program instructions to customize an electronic circuit, such as a programmable logic circuit, a field - programmable gate array (FPGA), or a programmable logic array (PLA), the electronic circuit can execute the computer - readable program instructions to implement various aspects of the present disclosure.
[0126] Aspects of the present disclosure are described herein with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present disclosure. It should be understood that each block of the flowcharts and / or block diagrams, and combinations of blocks in the flowcharts and / or block diagrams, can be implemented by computer - readable program instructions.
[0127] These computer - readable program instructions can be provided to a processor of a general - purpose computer, a special - purpose computer, or other programmable data - processing apparatus to produce a machine such that when the instructions are executed by the processor of the computer or other programmable data - processing apparatus, a device is produced that implements the functions / acts specified in one or more blocks of the flowchart and / or block diagram. These computer - readable program instructions can also be stored in a computer - readable storage medium, which causes a computer, a programmable data - processing apparatus, and / or other devices to operate in a particular manner, so that the computer - readable medium storing the instructions includes a manufacture, which includes instructions for implementing various aspects of the functions / acts specified in one or more blocks of the flowchart and / or block diagram.
[0128] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other devices to cause a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other devices to produce a computer-implemented process such that the instructions executed on the computer, other programmable data processing apparatus, or other devices implement the functions / acts specified in one or more boxes of the flowchart and / or block diagram.
[0129] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a portion of an instruction, which contains one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions noted in the blocks may occur out of the order noted in the figures. For example, two consecutive blocks may in fact be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block of the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented by a dedicated hardware-based system that performs the specified functions or acts, or by a combination of dedicated hardware and computer instructions. It is well known to those skilled in the art that implementation by hardware, implementation by software, and implementation by a combination of software and hardware are equivalent.
[0130] The embodiments of the present disclosure have been described above. The above description is exemplary, not exhaustive, and is not limited to the disclosed embodiments. Many modifications and variations will be apparent to those of ordinary skill in the art in the field without departing from the scope and spirit of the described embodiments. The choice of terms used herein is intended to best explain the principles of the embodiments, the practical application, or improvements made to the technology in the market, or to enable other ordinary skilled people in the art in the field to understand the embodiments disclosed herein. The scope of the present disclosure is defined by the appended claims.
Claims
1. A method for firmware upgrade of a control chip, characterized in that, It includes: Receiving multiple data blocks obtained by splitting a target upgrade data packet; Allocating the multiple data blocks to at least two first storage devices for storage; Performing data verification on the received multiple data blocks; When the multiple data blocks are successfully verified, storing the multiple data blocks in a second storage device for firmware upgrade.
2. The method according to claim 1, characterized in that, The allocating the multiple data blocks to at least two first storage devices for storage includes: Parsing the encoding of the multiple data blocks to obtain a sorting value representing the arrangement order of the multiple data blocks; Determining the first storage device corresponding to each data block according to the sorting value; Allocating each data block to the corresponding first storage device respectively.
3. The method according to claim 1, characterized in that, The method further includes: Receiving the digital signature of the target upgrade data packet; Parsing the digital signature to obtain the first hash value of the target upgrade data packet; The performing data verification on the received multiple data blocks includes: Calculating the second hash value of the multiple data blocks; Comparing the first hash value and the second hash value; When the first hash value is equal to the second hash value, determining that the multiple data blocks are successfully verified; when the first hash value is not equal to the second hash value, determining that the multiple data blocks are verified failed.
4. The method according to claim 1, characterized in that, The method further includes: When the multiple data blocks are verified failed, deleting the data blocks of the target upgrade data packet stored in the at least two first storage devices and sending an alarm.
5. The method according to claim 1, characterized in that, The method further includes: When the data blocks of the target upgrade data packet stored in the second storage device are attacked, re-obtaining the multiple data blocks of the target upgrade data packet from the at least two first storage devices.
6. The method according to claim 1, characterized in that, The method further includes: When a startup event occurs, detecting whether there is illegal data stored in the functional modules connected to the control chip; When there is illegal data stored in the functional module, prohibiting the power supply from supplying power to the functional module.
7. A control chip, characterized in that, It includes a processor and a memory, the memory is used to store a computer program, and the computer program is used to control the processor to execute the method according to any one of claims 1 to 6.
8. An electronic control unit, characterized in that, At least two first storage devices, and at least one control chip according to claim 7, each control chip is connected to at least two first storage devices.
9. The electronic control unit according to claim 8, characterized in that, The first storage device is a control chip with a hardware security module.
10. A vehicle, characterized in that, It includes an electronic control unit according to claim 8 or 9.