Vehicle, program flashing method and device and storage medium

By deploying the security checksum packet processing module on the gateway of the domain controller, the secure and fast program flushing of multi-chip domain controllers is realized, and the problem of how to safely and quickly flushing of multi-chip domain controllers in the existing technology is solved.

CN120201017APending Publication Date: 2025-06-24ECARX (HUBEI) TECHCO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510335094.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-20
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

How to implement the program flushing of any chip safely and quickly when the domain controller contains multiple chips.

Method used

By deploying the security verification module and data packet processing module on the gateway of the domain controller, security verification between the chip and the host computer is carried out, target data packets are received and parsed, target chips of the program to be flashed, and data packets are sent to the target chip for flashing.

Benefits of technology

It realizes that when the domain controller contains multiple chips, the program flashing is quickly and safely after passing the security verification, improving the security and efficiency of program flashing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120201017A_ABST
    Figure CN120201017A_ABST
Patent Text Reader

Abstract

The invention discloses a vehicle, a program flashing method and device and a storage medium, the program flashing method is applied to a gateway of a domain controller, the domain controller comprises at least two chips and is configured with an extranet address, the gateway is deployed on a first chip in the at least two chips, and the gateway is deployed on a second chip in the at least two chips. The method comprises the following steps: performing security verification on each chip in at least two chips and an upper computer; receiving a target data packet sent by the upper computer under the condition that the security verification is passed, wherein the target data packet comprises a to-be-flashed target program; determining a target chip of the program to be flashed in the at least two chips according to an address space segment contained in the header of the target program; and sending the target data packet to the target chip so as to flash the target program on the target chip. By applying the technical scheme provided by the invention, program flashing can be carried out on any chip contained in the domain controller, the program flashing safety can be improved, and the data transmission processing efficiency can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer application technologies, and particularly to a vehicle, a program flashing method, a device, and a storage medium. Background Art

[0002] In a vehicle electronic system, a domain controller, as a core component of the vehicle's electronic architecture, is mainly used for centralized control, data processing, and network communication to improve the vehicle's intelligence level and safety.

[0003] Currently, only one external network address is allocated to a domain controller, and the host computer communicates with the domain controller through this external network address to flash the program of the chips included in the domain controller. For the case where the domain controller only includes one chip, the host computer can flash the program of this chip through the external network address of the domain controller. However, for the case where the domain controller includes multiple chips, how to achieve safe and fast flashing of the program of any chip included in the domain controller is a technical problem that those skilled in the art urgently need to solve at present. Summary of the Invention

[0004] The purpose of the present application is to provide a vehicle, a program flashing method, a device, and a storage medium to achieve safe and fast flashing of the program of any chip included in the domain controller.

[0005] To solve the above technical problem, the present application provides the following technical solutions:

[0006] In a first aspect, a program flashing method is provided, which is applied to a gateway of a domain controller. The domain controller includes at least two chips and is configured with one external network address. The gateway is deployed on a first chip among the at least two chips. The method includes:

[0007] Performing security verification on each of the at least two chips and the host computer;

[0008] Receiving a target data packet sent by the host computer when the security verification is passed. The target data packet contains a target program to be flashed;

[0009] Determining a target chip of the program to be flashed among the at least two chips according to an address space segment included in a header of the target program;

[0010] Sending the target data packet to the target chip to flash the target program on the target chip.

[0011] Optionally, the performing security verification on each of the at least two chips and the host computer includes:

[0012] Generating a seed when receiving a seed request from the host computer;

[0013] Generate a first secret key based on the target algorithm and the seed;

[0014] Perform a security check on each of the at least two chips based on the seed and the first secret key;

[0015] When the security check on each of the at least two chips passes, send the encrypted first secret key and the seed to the host computer, so that the host computer decrypts to obtain the first secret key and the seed, and generates a second secret key based on the target algorithm and the seed. When the second secret key is the same as the first secret key, determine that the security check on each of the at least two chips and the host computer passes.

[0016] Optionally, the performing a security check on each of the at least two chips based on the seed and the first secret key includes:

[0017] Send the encrypted seed to the second chip, so that the second chip decrypts to obtain the seed, and generates a third secret key based on the target algorithm and the seed, and returns the encrypted third secret key. The second chip includes other chips among the at least two chips except the first chip;

[0018] Decrypt the received encrypted third secret key to obtain the third secret key;

[0019] When the third secret key is the same as the first secret key, determine that the security check on each of the at least two chips passes.

[0020] Optionally, the determining the target chip of the program to be flashed among the at least two chips according to the address space segment included in the header of the target program includes:

[0021] Determine the actual address space corresponding to the address space segment included in the header of the target program according to the preset mapping relationship between the virtual address space and the actual address space;

[0022] Based on the actual address space, determine the target chip of the program to be flashed among the at least two chips.

[0023] Optionally, the sending the target data packet to the target chip includes:

[0024] When the target chip is not the first chip, after replacing the source address of the target data packet with the in-domain address of the first chip and replacing the target address of the target data packet with the in-domain address of the target chip, send the target data packet to the target chip.

[0025] Optionally, after sending the target data packet to the target chip, the method further includes:

[0026] Receiving a response data packet from the target chip;

[0027] Replacing the source address of the response data packet with the external network address, replacing the destination address of the response data packet with the address of the host computer, and sending the response data packet to the host computer.

[0028] Optionally, after sending the target data packet to the target chip, the method further includes:

[0029] Periodically sending heartbeat information to the target chip.

[0030] In a second aspect, a program flashing device is provided, which is applied to a gateway of a domain controller. The domain controller includes at least two chips and is configured with an external network address. The gateway is deployed on a first chip of the at least two chips. The device includes:

[0031] A verification module, configured to perform security verification on each of the at least two chips and the host computer;

[0032] A receiving module, configured to receive a target data packet sent by the host computer when the security verification is passed. The target data packet includes a target program to be flashed;

[0033] A determination module, configured to determine a target chip of the program to be flashed in the at least two chips according to an address space segment included in a header of the target program;

[0034] A sending module, configured to send the target data packet to the target chip to flash the target program on the target chip.

[0035] In a third aspect, a vehicle is provided. The vehicle includes a vehicle body and a domain controller deployed in the vehicle body. The domain controller is configured with at least two chips and an external network address. A gateway is deployed on a first chip of the at least two chips. The domain controller further includes:

[0036] A memory, configured to store a computer program;

[0037] A processor, configured to implement the steps of the program flashing method according to any one of claims 1 to 7 when executing the computer program.

[0038] In a fourth aspect, a computer-readable storage medium is provided. A computer program is stored on the computer-readable storage medium. When the computer program is executed by a processor, the steps of the program flashing method according to the first aspect are implemented.

[0039] In a fifth aspect, a computer program product is provided. The computer program product includes computer instructions stored in a computer-readable storage medium and adapted to be read and executed by a processor, so that a computer device having the processor executes the steps of the program flashing method as described in the first aspect.

[0040] By applying the technical solution provided in the embodiments of the present application, the gateway of the domain controller performs security verification on each chip included in the domain controller and the host computer, receives the target data packet sent by the host computer when the security verification is passed, determines the target chip of the program to be flashed according to the address space segment included in the header of the target program to be flashed included in the target data packet, and then sends the target data packet to the target chip to flash the target program on the target chip. By communicating between the gateway and the host computer, it is possible to flash the program for any chip included in the domain controller. Before performing the program flashing, security verification is first performed on each chip and the host computer. After the security verification is passed, the program flashing operation is executed, which helps to improve the security of the program flashing. Moreover, the data packet transmitted after the security verification is passed does not require encryption and decryption processing, which can improve the data transmission processing efficiency.

[0041] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the related art, the following will briefly introduce the drawings required for the description of the embodiments or the related art. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0043] Figure 1 It is a schematic structural diagram of a domain controller in an embodiment of the present application;

[0044] Figure 2 It is an implementation flowchart of a program flashing method in an embodiment of the present application;

[0045] Figure 3 It is a schematic structural diagram of a program flashing device in an embodiment of the present application;

[0046] Figure 4 It is a schematic structural diagram of a vehicle in an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0047] The following will clearly describe the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application belong to the scope of protection of the present application.

[0048] The terms "first", "second", etc. in the present application are used to distinguish similar objects, rather than to describe a specific order or sequence. It should be understood that such terms can be interchanged under appropriate circumstances so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first" and "second" are usually of the same type, and the number of objects is not limited. For example, the first object can be one or multiple.

[0049] The core of the present application is to provide a program flashing method, which can be applied to the gateway of a domain controller. The domain controller includes at least two chips and is configured with an external network address, which can be considered as an independent address assigned by the Original Equipment Manufacture (OEM) to the domain controller. The gateway is deployed on the first chip among the at least two chips. The host computer can communicate with the gateway through this external network address, and each chip included in the domain controller communicates through an intra-domain address.

[0050] As Figure 1 shown, the host computer is a diagnostic device, and the domain controller is an Autonomous Driving Control Unit (ADCU). The diagnostic device communicates with the ADCU based on the Ethernet protocol. The ADCU includes three chips: a System on Chip (SOC) A, a SOC B, and a Microcontroller Unit (MCU). The three chips communicate with each other based on the Ethernet protocol through a switch. The diagnostic device connects to the ADCU through the external network address of the ADCU, and this external network address is deployed on the SOC A. The SOC A has a Gateway (GW) function, that is, a gateway is deployed on the SOC A, and the gateway can determine which chip to send the data packet to according to the data packet received from the diagnostic device.

[0051] It should be noted that the addresses in the embodiments of the present application may include Internet Protocol (IP) addresses and / or Media Access Control (MAC) addresses.

[0052] See Figure 2As shown in the figure, it is the implementation flowchart of a program flashing method provided by an embodiment of the present application. The method includes the following steps:

[0053] S210: Perform security verification on each of at least two chips and the host computer.

[0054] In the embodiment of the present application, the host computer may include a diagnostic device and an Over-the-Air (OTA) server download device. The host computer can communicate with the gateway of the domain controller through the external network address of the domain controller.

[0055] When there is a need for program flashing, security verification can be performed first on each chip included in the domain controller and the host computer to verify the security of each chip included in the domain controller and the host computer.

[0056] After performing security verification on each of at least two chips and the host computer, if the security verification passes, it is considered that each chip included in the domain controller and the host computer is secure, and the program flashing operation can continue.

[0057] If the security verification fails, it is considered that there is at least one security risk in each chip included in the domain controller and the host computer. In this case, if the program flashing operation continues, it may cause the program flashing to fail or the program to be tampered with, bringing security risks to subsequent vehicle driving. Therefore, it is necessary to terminate the program flashing operation.

[0058] S220: Receive the target data packet sent by the host computer when the security verification passes. The target data packet contains the target program to be flashed.

[0059] When the host computer confirms that the security verification of each chip included in the domain controller and itself has passed, it can send a target data packet to the domain controller, and the gateway of the domain controller receives the target data packet. The target data packet contains the target program to be flashed. Optionally, the host computer can send the target data packet to the domain controller through the raw data transmission mode to improve the data transmission efficiency and the program flashing speed.

[0060] When the host computer sends the target data packet, the source address of the target data packet is the address of the host computer, and the destination address is the external network address of the domain controller.

[0061] After receiving the target data packet from the host computer, the gateway continues the operations of the subsequent steps.

[0062] S230: Determine the target chip of the program to be flashed among at least two chips according to the address space segment included in the header of the target program.

[0063] According to the agreement, the header of the target program contains address space segments, and different address space segments correspond to different chips.

[0064] After receiving the target data packet from the host computer, the gateway can parse the target data packet to obtain the target program to be flashed included in the target data packet, so as to obtain the address space segment included in the header of the target program. According to the obtained address space segment, the target chip can be determined from the chips included in the domain controller.

[0065] In the embodiment of the present application, the target program may be one or more target programs, the header of each target program contains the corresponding address space segment, and the determined target chip may also be one or more target chips. For each target program, according to the address space segment included in the header of the target program, the target chip to be flashed with the target program can be determined.

[0066] S240: Send the target data packet to the target chip to flash the target program on the target chip.

[0067] After determining the target chip of the program to be flashed according to the address space segment included in the header of the target program, the gateway can send the target data packet to the target chip, so that the target program can be flashed on the target chip.

[0068] If there are multiple target chips, the gateway can send the target data packet to each target chip respectively.

[0069] Applying the method provided in the embodiment of the present application, the gateway of the domain controller performs security verification on each chip included in the domain controller and the host computer, receives the target data packet sent by the host computer when the security verification is passed, determines the target chip of the program to be flashed according to the address space segment included in the header of the target program to be flashed included in the target data packet, and then sends the target data packet to the target chip to flash the target program on the target chip. By communicating between the gateway and the host computer, the program flashing of any chip included in the domain controller can be realized. Before the program flashing, the security verification of each chip and the host computer is performed first. After the security verification is passed, the program flashing operation is executed, which helps to improve the security of the program flashing. Moreover, the data packet transmitted after the security verification passes does not need to be encrypted and decrypted, which can improve the data transmission and processing efficiency.

[0070] In some embodiments of the present application, step S210 of performing security verification on each of at least two chips and the host computer may include the following steps:

[0071] Generate a seed when receiving a seed request from the host computer;

[0072] Generate a first secret key based on the target algorithm and the seed;

[0073] Perform a security check on each of at least two chips based on a seed and a first secret key;

[0074] In the case where the security check on each of at least two chips passes, send the encrypted first secret key and the seed to the host computer, so that the host computer decrypts to obtain the first secret key and the seed, and generates a second secret key based on a target algorithm and the seed. In the case where the second secret key is the same as the first secret key, determine that the security check on each of at least two chips and the host computer passes.

[0075] For the convenience of description, the above steps are combined for description.

[0076] In the embodiment of the present application, the gateway serves as the entry for program flashing and is a key node for docking outside the domain. To ensure security, for security services such as service 27, unlock gates for each chip are set, and security checks are performed on each chip and the host computer.

[0077] When there is a need for program flashing, the host computer can send a seed request to the gateway of the domain controller. For example, the host computer sends a seed request to the gateway of the domain controller through service 27 subfunction 05. After receiving the seed request, the gateway can generate a set of random numbers and determine the random numbers as the seed.

[0078] Each chip included in the domain controller and the host computer must save the same target algorithm. After the gateway determines the seed, it can generate a first secret key based on the target algorithm and the seed, and perform a security check on each chip included in the domain controller based on the seed and the first secret key.

[0079] In the case where the security check on each chip included in the domain controller passes, the gateway can encrypt the first secret key and the seed, send the encrypted first secret key and the seed to the host computer. After receiving the encrypted first secret key and the seed, the host computer can decrypt them to obtain the first secret key and the seed, then generate a second secret key based on the target algorithm and the seed, and then compare the second secret key with the first secret key to determine whether they are the same. If they are the same, it is determined that the security check on each chip included in the domain controller and the host computer passes. If they are not the same, it is considered that there may be a security risk.

[0080] From the above steps, it can be seen that the gateway generates a first secret key based on the target algorithm and the seed, and performs a security check on each of at least two chips based on the seed and the first secret key. If the security check on each chip passes, it is considered that each chip is secure. Furthermore, the encrypted first secret key and the seed are sent to the host computer, and the host computer decrypts to obtain the first secret key and the seed, and generates a second secret key based on the target algorithm and the seed.

[0081] Since the target algorithms stored in the host computer and each chip are the same, if both the host computer and the gateway are secure and the obtained seed has not been tampered with, the second secret key generated by the host computer based on the target algorithm and the seed will be consistent with the first secret key obtained from the gateway. If the second secret key generated by the host computer based on the target algorithm and the seed is inconsistent with the first secret key obtained from the gateway, it can be considered that there is a security risk in at least one of the host computer and the gateway.

[0082] Performing security verification on each chip included in the domain controller first and then on each chip and the host computer helps to improve security.

[0083] In some embodiments of the present application, performing security verification on each of at least two chips based on a seed and a first secret key may include the following steps:

[0084] Send the encrypted seed to the second chip so that the second chip decrypts to obtain the seed and generates a third secret key based on the target algorithm and the seed, and returns the encrypted third secret key. The second chip includes other chips except the first chip among at least two chips;

[0085] Decrypt the received encrypted third secret key to obtain the third secret key;

[0086] When the third secret key is the same as the first secret key, determine that the security verification of each of at least two chips passes.

[0087] For ease of description, the above steps are combined for description.

[0088] After the gateway generates a seed, it generates a first secret key based on the target algorithm and the seed, encrypts the seed, and sends the encrypted seed to the second chip. Optionally, the gateway can use a symmetric key to encrypt the seed and send the encrypted seed to the second chip. The second chip includes other chips except the first chip among at least two chips, that is, each of the other chips except the first chip among the at least two chips included in the domain controller can be called the second chip. Each chip can pre-store the symmetric key.

[0089] After the second chip receives the encrypted seed from the gateway, it can decrypt the encrypted seed to obtain the seed, obtain the third secret key through the operation of the target algorithm on the seed, and encrypt and return the third secret key to the gateway.

[0090] The gateway receives the encrypted third secret key returned by the second chip, decrypts the encrypted third secret key to obtain the third secret key, and compares the third secret key with the first secret key. If the two are the same, it can be considered that the unlocking is successful, each chip is secure and has not been tampered with, and it can be determined that the security check for each of at least two chips has passed and the first secret key is valid. If the two are different, it can be considered that there is a security risk, and it can be determined that the security check for each of at least two chips has not passed and the first secret key is invalid.

[0091] It can be understood that each chip included in the domain controller stores the same target algorithm. After the gateway sends the seed to the second chip, the second chip generates the third secret key based on the target algorithm and the seed, encrypts the third secret key and returns it to the gateway. The gateway decrypts the encrypted third secret key returned by the second chip to obtain the third secret key. If none of the chips have been tampered with, the third secret key must be the same as the first secret key. Therefore, if the third secret key is the same as the first secret key, it can be determined that the security check for each chip included in the domain controller has passed.

[0092] Through the seed and the secret key generated based on the seed, the security of each chip can be effectively verified.

[0093] For easy understanding, an example is given.

[0094] Suppose the domain controller includes three chips, namely SOC A, SOC B, and MCU. The gateway is deployed on SOC A, and each chip and the upper computer save the target algorithm.

[0095] A possible security verification process is as follows:

[0096] The upper computer sends a seed request to the gateway of the domain controller;

[0097] The gateway of the domain controller generates a random number, that is, the seed, according to the seed request;

[0098] The gateway of the domain controller operates on the seed through the target algorithm to obtain the first secret key, such as KEY A ;

[0099] The gateway of the domain controller encrypts the seed and sends it to SOC B and MCU respectively;

[0100] SOC B decrypts the received encrypted seed to obtain the seed, operates on the seed through the target algorithm to obtain the corresponding third secret key, such as KEY B ;

[0101] SOC B encrypts KEY B and returns it to the gateway;

[0102] Similarly, the MCU decrypts the received encrypted seed to obtain the seed, and performs an operation on the seed through a target algorithm to obtain the corresponding third key, such as KEY MCU ;

[0103] The MCU encrypts KEY MCU and returns it to the gateway;

[0104] The gateway receives the encrypted KEY sent by SOC B B , and the encrypted KEY sent by the MCU MCU , decrypts them respectively to obtain KEY B and KEY MCU ;

[0105] If KEY A , KEY B , and KEY MCU are the same, it is determined that the security verification of each chip passes, and KEY A is valid;

[0106] The gateway encrypts the seed and KEY A and sends them to the host computer;

[0107] The host computer receives the encrypted seed and KEY sent by the gateway A , decrypts them to obtain the seed and KEY A ;

[0108] The host computer performs an operation on the seed through a target algorithm to obtain KEY;

[0109] If KEY and KEY A are the same, it is determined that the security verification of each chip and the host computer passes.

[0110] It should be noted that in the security verification stage, symmetric encryption can be used for information transmission between chips and between the gateway and the host computer.

[0111] In some embodiments of the present application, step S230 may determine the target chip of the program to be flashed in at least two chips according to the address space segment included in the header of the target program, and may include the following steps:

[0112] According to the mapping relationship between the preset virtual address space and the actual address space, determine the actual address space corresponding to the address space segment included in the header of the target program;

[0113] Based on the actual address space, determine the target chip of the program to be flashed in at least two chips.

[0114] For the convenience of description, the above steps are combined for description.

[0115] In the embodiment of the present application, the mapping relationship between the virtual address space and the actual address space of each chip included in the domain controller can be preset. Optionally, this mapping relationship can be defined during program compilation.

[0116] After receiving the target data packet from the host computer, the gateway parses the target data packet, and can obtain the target program to be flashed included in the target data packet, and further obtain the address space segment included in the header of the target program.

[0117] According to the mapping relationship between the virtual address space and the actual address space, the gateway can determine the actual address space corresponding to the address space segment included in the header of the target program, and further, based on the actual address space, determine the target chip of the program to be flashed among at least two chips.

[0118] For example, the domain controller includes three chips, SOC A, SOC B, and MCU. Among them, SOC A and SOC B store programs through an Embedded Multi Media Card (EMMC), and MCU stores programs through its own memory. Assume that the addresses of these two EMMCs are both 0x000000 to 0x111111, and the memory address of MCU is 0x000000 to 0x111110, that is, the actual address spaces of SOC A and SOC B are both 0x000000 to 0x111111, and the actual address space of MCU is 0x000000 to 0x111110.

[0119] During program compilation, according to the mapping relationship between the virtual address space and the actual address space, the virtual address space corresponding to the actual address space of the target chip of the program to be flashed is determined and written into the header of the target program, that is, the address space segment included in the header of the target program is the virtual address space corresponding to the actual address space of the target chip. For example, if the target chip is SOC A and the actual address space of SOC A is 0x000000 to 0x111111, the address space segment included in the header of the target program during program compilation is 0x000000 to 0x111111. Or, if the target chip is SOC B and the actual address space of SOC B is 0x000000 to 0x111111, the address space segment included in the header of the target program during program compilation is 0x111112 to 0x22222. Or, if the target chip is MCU and the actual address space of MCU is 0x000000 to 0x111110, the address space segment included in the header of the target program during program compilation is 0x22223 to 0x333333.

[0120] If the address space segment included in the header of the target program obtained by the gateway is 0x000000 to 0x111111, then according to the mapping relationship between the virtual address space and the actual address space, it is determined that the corresponding actual address space of this address space segment is 0x000000 to 0x111111. Based on this actual address space, it can be determined that the target chip of the program to be flashed is SOC A;

[0121] If the address space segment included in the header of the target program obtained by the gateway is 0x111112 to 0x22222, then according to the mapping relationship between the virtual address space and the actual address space, it is determined that the corresponding actual address space of this address space segment is 0x000000 to 0x111111. Based on this actual address space, it can be determined that the target chip of the program to be flashed is SOC B;

[0122] If the address space segment included in the header of the target program obtained by the gateway is 0x22223 to 0x333333, then according to the mapping relationship between the virtual address space and the actual address space, it is determined that the corresponding actual address space of this address space segment is 0x000000 to 0x111110. Based on this actual address space, it can be determined that the target chip of the program to be flashed is MCU.

[0123] According to the mapping relationship between the virtual address space and the actual address space, the actual address space corresponding to the address space segment included in the header of the target program can be obtained. Based on this actual address space, the target chip of the program to be flashed can be accurately determined.

[0124] In some embodiments of the present application, step S240 of sending the target data packet to the target chip may include the following steps:

[0125] When the target chip is not the first chip, after replacing the source address of the target data packet with the in-domain address of the first chip and replacing the destination address of the target data packet with the in-domain address of the target chip, the target data packet is sent to the target chip.

[0126] In the embodiments of the present application, after determining the target chip of the program to be flashed, if the target chip is the first chip, since the gateway is deployed on the first chip, the gateway can directly deliver the target data packet to the first chip. If the target chip is not the first chip, the gateway can perform address replacement on the target data packet, replace the source address of the target data packet with the in-domain address of the first chip, replace the target address of the target data packet with the in-domain address of the target chip, and then send the target data packet after address replacement to the target chip, which helps to improve the forwarding success rate of the target data packet.

[0127] For example, assume that the address of the diagnostic device is 7FFF, the external network address of the domain controller is 1301, the internal network address of SOC B is 1311, and the internal network address of the MCU is 1322;

[0128] The diagnostic device sends a target data packet to the domain controller. The source address of the target data packet is the address 7FFF of the diagnostic device, and the destination address of the target data packet is the external network address 1301 of the domain controller. The target data packet carries a payload, that is, the target program to be flashed.

[0129] After the gateway of the domain controller receives the target data packet, if it determines that the target chip of the program to be flashed is SOC B, it performs address replacement, replaces the source address of the target data packet with the internal network address of SOC A, replaces the destination address of the target data packet with the internal network address of SOC B, and keeps the payload unchanged. The internal network address of SOC A can be determined based on the external network address of the domain controller;

[0130] If it determines that the target chip of the program to be flashed is the MCU, it performs address replacement, replaces the source address of the target data packet with the internal network address of SOC A, replaces the destination address of the target data packet with the internal network address of the MCU, and keeps the payload unchanged;

[0131] If it determines that the target chip of the program to be flashed is SOC A, it keeps the source address and destination address of the target data packet unchanged and keeps the payload unchanged.

[0132] In some embodiments of the present application, after sending the target data packet to the target chip, the method may further include the following steps:

[0133] Receive a response data packet from the target chip;

[0134] Replace the source address of the response data packet with the external network address, replace the destination address of the response data packet with the address of the host computer, and send the response data packet to the host computer.

[0135] In the embodiments of the present application, the gateway sends the target data packet to the target chip, the target chip can return a response data packet, and the gateway can forward the response data packet to the host computer to inform the host computer of the data transmission situation.

[0136] Optionally, if the target chip is the first chip, the gateway can directly obtain the response data packet from the target chip and send the response data packet to the host computer. The source address of the response data packet is the external network address of the domain controller, and the destination address of the response data packet is the address of the host computer.

[0137] If the target chip is not the first chip, the source address of the response data packet obtained by the gateway from the target chip is the in-domain address of the target chip, and the destination address is the in-domain address of the first chip. After the gateway replaces the source address of the response data packet with the external network address of the domain controller and replaces the destination address of the response data packet with the address of the host computer, the gateway sends the response data packet to the host computer.

[0138] Returning the response data packet to the host computer in a timely manner helps improve the reliability of data transmission.

[0139] In some embodiments of the present application, after sending the target data packet to the target chip, the method may further include the following steps:

[0140] Periodically send heartbeat information to the target chip.

[0141] In the embodiments of the present application, after the gateway sends the target data packet to the target chip, the target chip can perform the flashing of the target program. During the program flashing process, the target chip may switch from the flashing mode to other modes, such as the normal mode, due to timeout or other reasons, resulting in problems such as flashing interruption and flashing failure. To avoid this situation, the gateway can periodically send heartbeat information to the target chip for heartbeat verification. Optionally, the gateway can periodically send 0x3E80 to the target chip to maintain the heartbeat. This can effectively avoid the situation where the target chip automatically exits the flashing mode due to not receiving the heartbeat information, which helps improve the success rate of program flashing and reduce the vehicle maintenance cost.

[0142] It should be noted that in the embodiments of the present application, the chips included in the domain controller can perform data transmission through the Diagnostic communication over Internet Protocol (DoIP).

[0143] Corresponding to the above method embodiments, the embodiments of the present application further provide a program flashing device, which is applied to the gateway of the domain controller. The domain controller includes at least two chips and is configured with an external network address. The gateway is deployed on the first chip among the at least two chips. The program flashing device described below can be correspondingly referred to the program flashing method described above.

[0144] See Figure 3 As shown, the program flashing device 300 includes the following modules:

[0145] The verification module 310 is used to perform security verification on each of the at least two chips and the host computer;

[0146] A receiving module 320, configured to receive a target data packet sent by a host computer when the security verification is passed, where the target data packet contains a target program to be flashed.

[0147] A determining module 330, configured to determine target chips of the program to be flashed in at least two chips according to an address space segment included in the header of the target program.

[0148] A sending module 340, configured to send the target data packet to the target chips to flash the target program on the target chips.

[0149] Applying the device provided by the embodiments of the present application to perform security verification on each chip included in the domain controller and the host computer, receiving a target data packet sent by the host computer when the security verification is passed, determining the target chips of the program to be flashed according to the address space segment included in the header of the target program included in the target data packet, and then sending the target data packet to the target chips to flash the target program on the target chips. By communicating with the host computer through a gateway, program flashing can be realized for any chip included in the domain controller. Before program flashing, security verification is first performed on each chip and the host computer. After the security verification is passed, the program flashing operation is executed, which helps to improve the security of program flashing. Moreover, the data packet transmitted after the security verification is passed does not need to be encrypted and decrypted, which can improve the data transmission and processing efficiency.

[0150] In some embodiments of the present application, the verification module 310 is specifically configured to:

[0151] Generate a seed when receiving a seed request from the host computer;

[0152] Generate a first secret key based on a target algorithm and the seed;

[0153] Perform security verification on each of at least two chips based on the seed and the first secret key;

[0154] When the security verification of each of at least two chips is passed, send the encrypted first secret key and the seed to the host computer, so that the host computer decrypts to obtain the first secret key and the seed, and generates a second secret key based on the target algorithm and the seed. When the second secret key is the same as the first secret key, it is determined that the security verification of each of at least two chips and the host computer is passed.

[0155] In some embodiments of the present application, the verification module 310 is specifically configured to:

[0156] Send the encrypted seed to a second chip, so that the second chip decrypts to obtain the seed, generates a third secret key based on the target algorithm and the seed, and returns the encrypted third secret key. The second chip includes other chips except the first chip among at least two chips;

[0157] Decrypt the received encrypted third secret key to obtain the third secret key;

[0158] When the third secret key is the same as the first secret key, determine that the security check of each of the at least two chips passes.

[0159] In some embodiments of the present application, the determining module 330 is specifically configured to:

[0160] Determine the actual address space corresponding to the address space segment included in the header of the target program according to the preset mapping relationship between the virtual address space and the actual address space;

[0161] Based on the actual address space, determine the target chip of the program to be flashed in the at least two chips.

[0162] In some embodiments of the present application, the sending module 340 is specifically configured to:

[0163] When the target chip is not the first chip, after replacing the source address of the target data packet with the in-domain address of the first chip and replacing the target address of the target data packet with the in-domain address of the target chip, send the target data packet to the target chip.

[0164] In some embodiments of the present application, the receiving module 320 is further configured to:

[0165] After sending the target data packet to the target chip, receive a response data packet from the target chip;

[0166] The sending module 340 is further configured to:

[0167] Replace the source address of the response data packet with the external network address, replace the destination address of the response data packet with the address of the host computer, and send the response data packet to the host computer.

[0168] In some embodiments of the present application, the sending module 340 is further configured to:

[0169] After sending the target data packet to the target chip, periodically send heartbeat information to the target chip.

[0170] Regarding the device in the above embodiments, the specific manners in which each module performs operations have been described in detail in the embodiments related to the method, and will not be elaborated here.

[0171] Corresponding to the above method embodiments, an embodiment of the present application further provides a vehicle, as Figure 4 shown. The vehicle includes a vehicle body 410 and a domain controller deployed in the vehicle body 410. The domain controller is configured with at least two chips and an external network address. A gateway is deployed on the first chip of the at least two chips. The domain controller further includes:

[0172] A memory for storing a computer program;

[0173] A processor for implementing the steps of the above program flashing method when executing the computer program.

[0174] Corresponding to the above method embodiment, an embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the above program flashing method are implemented.

[0175] In addition, it should be noted that: an embodiment of the present application further provides a computer program product or a computer program. The computer program product or the computer program may include computer instructions, and the computer instructions may be stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor may execute the computer instructions, so that the computer device executes the description of the program flashing method in the corresponding embodiment described above. Therefore, it will not be elaborated here. In addition, the description of the beneficial effects of adopting the same method will not be elaborated either. For the technical details not disclosed in the computer program product or the computer program embodiment involved in the present application, please refer to the description of the method embodiment of the present application.

[0176] The various embodiments in this specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts among the various embodiments can be referred to each other.

[0177] It should be noted that in this article, the term "comprising", "including" or any other variant thereof is intended to cover a non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or device including the element. In addition, it should be pointed out that the scope of the method and device in the embodiment of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in a reverse order according to the functions involved. For example, the described method may be executed in an order different from that described, and various steps may be added, omitted or combined. In addition, the features described with reference to certain examples may be combined in other examples.

[0178] From the description of the above embodiments, those skilled in the art can also clearly understand that the units and algorithm steps of each example described in combination with the embodiments disclosed in this article can be implemented by electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0179] The steps of the methods or algorithms described in combination with the embodiments disclosed in this article can be directly implemented by hardware, software modules executed by a processor, or a combination of both. The software modules can be placed in a random access memory (Random Access Memory, RAM), memory, read-only memory (Read-Only Memory, ROM), programmable read-only memory (Programmable ROM, PROM), erasable programmable read-only memory (Erasable PROM, EPROM), electrically erasable programmable read-only memory (Electrically EPROM, EEPROM), registers, hard disks, removable disks, compact disc read-only memory (Compact Disc Read-Only Memory, CD-ROM), or any other form of storage medium known in the technical field, including several instructions for executing the methods described in various embodiments of this application.

[0180] The embodiments of this application have been described above in conjunction with the accompanying drawings. The description of the above embodiments is only used to help understand the technical solution and its core idea of this application. It should be noted that this application is not limited to the above specific embodiments. The above specific embodiments are merely illustrative and not restrictive. For those of ordinary skill in the art, without departing from the purpose of this application and the scope protected by the claims, many forms of embodiments can still be made, and several improvements and modifications can also be made to this application. These embodiments, improvements, and modifications are all within the protection scope of this application.

Claims

1. A program flashing method, characterized in that: A gateway applied to a domain controller, the domain controller comprising at least two chips and configured with an external network address, the gateway being deployed on a first chip of the at least two chips, the method comprising: Performing security verification on each of the at least two chips and the host computer; Receiving a target data packet sent by the host computer when the security check passes, the target data packet containing a target program to be flashed; Determining a target chip of the at least two chips to which the program is to be flashed according to the address space segment included in the header of the target program; The target data packet is sent to the target chip to flash the target program on the target chip.

2. The method according to claim 1, characterized in that The performing security verification on each chip of the at least two chips and the host computer includes: Upon receiving a seed request from the host computer, generating a seed; generating a first secret key based on a target algorithm and the seed; Based on the seed and the first secret key, performing security verification on each of the at least two chips; When the security verification of each of the at least two chips passes, the encrypted first key and the seed are sent to the host computer, so that the host computer decrypts the first key and the seed, and generates a second key based on the target algorithm and the seed. When the second key is the same as the first key, it is determined that the security verification of each of the at least two chips and the host computer has passed.

3. The method according to claim 2, characterized in that The performing security verification on each of the at least two chips based on the seed and the first secret key includes: Sending the encrypted seed to a second chip so that the second chip decrypts the seed, generates a third key based on a target algorithm and the seed, and returns the encrypted third key, wherein the second chip includes other chips among the at least two chips except the first chip; Decrypting the received encrypted third key to obtain the third key; When the third key is the same as the first key, it is determined that the security verification of each chip of the at least two chips passes.

4. The method according to claim 1, characterized in that: The step of determining the target chip of the at least two chips to be flashed with the program according to the address space segment included in the header of the target program comprises: Determine the actual address space corresponding to the address space segment included in the header of the target program according to the mapping relationship between the preset virtual address space and the actual address space; Based on the actual address space, a target chip to be flashed with a program in the at least two chips is determined.

5. The method according to claim 1, characterized in that The sending the target data packet to the target chip comprises: When the target chip is not the first chip, after replacing the source address of the target data packet with the domain address of the first chip and replacing the target address of the target data packet with the domain address of the target chip, the target data packet is sent to the target chip.

6. The method according to claim 1, characterized in that After sending the target data packet to the target chip, the method further includes: receiving a response data packet from the target chip; The source address of the response data packet is replaced with the external network address, the destination address of the response data packet is replaced with the address of the host computer, and the response data packet is sent to the host computer.

7. The method according to any one of claims 1 to 6, characterized in that After sending the target data packet to the target chip, the method further includes: Heartbeat information is periodically sent to the target chip.

8. A program flashing device, characterized in that: A gateway applied to a domain controller, the domain controller comprising at least two chips and configured with an external network address, the gateway being deployed on a first chip of the at least two chips, the device comprising: A verification module, used for performing security verification on each of the at least two chips and the host computer; A receiving module, used for receiving a target data packet sent by the host computer when the security check passes, wherein the target data packet contains a target program to be flashed; A determination module, used for determining a target chip of the at least two chips to which the program is to be flashed according to the address space segment included in the header of the target program; The sending module is used to send the target data packet to the target chip so as to flash the target program on the target chip.

9. A vehicle, characterized in that: The vehicle includes a vehicle body and a domain controller deployed in the vehicle body, the domain controller is configured with at least two chips and an external network address, a gateway is deployed on a first chip of the at least two chips, and the domain controller further includes: Memory for storing computer programs; A processor, configured to implement the steps of the program flashing method according to any one of claims 1 to 7 when executing the computer program.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the program flashing method according to any one of claims 1 to 7 are implemented.