Remote upgrade optimization and exception recovery method for vehicle-mounted terminal

By obtaining and processing remote upgrade instructions in the on-board terminal, selecting the appropriate upgrade package and restoring the original program in abnormal situations, the flexibility and abnormal recovery problems of remote upgrade of the on-board terminal are solved, and a stable and reliable remote upgrade process is achieved.

CN120234024APending Publication Date: 2025-07-01BEILI XINYUAN (FOSHAN) INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510284196.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-11
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

The existing technology lacks flexibility when remote upgrade of vehicle terminals, and cannot perform targeted upgrades based on the actual situation of vehicle terminals, and lacks an effective abnormal recovery mechanism during the upgrade process, resulting in vehicle terminals being unable to work normally.

Method used

By obtaining the storage area where the currently running program is located, receiving remote upgrade instructions sent by the server, determining the version information of the upgrade program, selecting the appropriate target upgrade package, updating the historical running program to the upgrade program, and restoring the running of the original running program when the upgrade program is executed abnormally.

Benefits of technology

It realizes targeted upgrades based on actual conditions when the vehicle terminal is upgraded remotely, ensuring the stability and reliability of the vehicle terminal during the upgrade process, and avoiding the in-car terminal's inability to work normally due to the failure of the upgrade.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120234024A_ABST
    Figure CN120234024A_ABST
Patent Text Reader

Abstract

The embodiment of the invention relates to the technical field of Internet of Vehicles, and discloses a vehicle-mounted terminal remote upgrade optimization and exception recovery method, which comprises the following steps: acquiring a first storage area where a current running program is located, and receiving a remote upgrade instruction sent by a server through the current running program; determining upgrade version information of the upgrade program based on the remote upgrade instruction; determining one or more target upgrade packages for upgrading the vehicle-mounted terminal based on the upgrade version information, the current version information of the current running program and the historical version information of the historical running program stored in the second storage area; and updating the historical running program into an upgrading program based on the target upgrading package, and when the upgrading program is executed abnormally, recovering the running of the running program in the first storage area. By applying the technical scheme of the invention, the reliability of remote upgrading of the vehicle-mounted terminal can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the technical field of vehicle networking, and particularly to a method for remote upgrade optimization and exception recovery of an in-vehicle terminal. Background Art

[0002] When remotely upgrading an in-vehicle terminal in related technologies, a fixed upgrade package is usually pushed. This upgrade method lacks flexibility and cannot perform targeted upgrades according to the actual situation of the in-vehicle terminal. In addition, during the upgrade process, once an exception occurs in the program, related technologies often lack an effective exception recovery mechanism, resulting in the in-vehicle terminal being unable to work properly. This not only affects the normal use of users but also brings potential risks to the safe driving of vehicles. Summary of the Invention

[0003] In view of the above problems, the embodiments of the present invention provide a method for remote upgrade optimization and exception recovery of an in-vehicle terminal, which is used to solve the problems in related technologies that when remotely upgrading a program of an in-vehicle terminal, it cannot perform targeted upgrades according to the actual situation of the in-vehicle terminal, and once an exception occurs in the program, the entire in-vehicle terminal will be unable to work properly.

[0004] According to one aspect of the embodiments of the present invention, a method for remote upgrade optimization and exception recovery of an in-vehicle terminal is provided. The method includes: obtaining a first storage area where the currently running program is located, and receiving a remote upgrade instruction sent by a server through the currently running program; determining upgrade version information of an upgrade program based on the remote upgrade instruction; determining one or more target upgrade packages for upgrading the in-vehicle terminal based on the upgrade version information, the current version information of the currently running program, and the historical version information of the historical running program stored in a second storage area;

[0005] Updating the historical running program to the upgrade program based on the target upgrade package, and when an exception occurs during the execution of the upgrade program, restoring the operation of the program running in the first storage area.

[0006] In an optional embodiment, the above method further includes:

[0007] Downloading the upgrade program to the second storage area based on the upgrade version information and the current version information to obtain a program download result;

[0008] Performing an integrity check on the program download result to obtain an integrity check result;

[0009] Updating an upgrade flag based on the integrity check result, so that when the in-vehicle terminal loads and starts the bootloader program, it executes the upgrade program in the second storage area based on the updated upgrade flag, and when an exception occurs during the execution of the upgrade program, restores the operation of the program running in the first storage area.

[0010] In an alternative embodiment, the above method further includes:

[0011] Determining one or more target upgrade packages for upgrading the in-vehicle terminal based on the upgrade version information and the current version information;

[0012] Determining one or more replacement packages for upgrading the in-vehicle terminal based on the historical version information and the current version information;

[0013] Updating the historical running program to an upgrade program based on the target upgrade package and the replacement package, and when the upgrade program runs abnormally, restoring the operation of the running program in the first storage area.

[0014] In an alternative embodiment, when the upgrade program runs abnormally, after restoring the operation of the running program in the first storage area, the method further includes:

[0015] If the running program in the first storage area runs abnormally, then restoring the operation of the factory program in the third storage area;

[0016] Obtaining the upgrade status data of the in-vehicle terminal and the factory version information of the factory program;

[0017] Uploading the factory version information and the upgrade status data to the server based on the factory program, so that the server generates a target upgrade instruction based on the factory version information and the upgrade status data, and the target upgrade instruction includes the storage area corresponding to the target upgrade program.

[0018] In an alternative embodiment, determining one or more target upgrade packages for upgrading the in-vehicle terminal based on the upgrade version information, the current version information of the current running program, and the historical version information of the historical running program stored in the second storage area includes:

[0019] Comparing the upgrade version information with the current version information;

[0020] When the upgrade version information is different from the current version information, obtaining multiple upgrade packages corresponding to the upgrade program and multiple historical packages corresponding to the historical running program;

[0021] Taking the upgrade packages in the upgrade program that are different from the historical packages as one or more target upgrade packages for upgrading the in-vehicle terminal.

[0022] In an alternative embodiment, determining one or more target upgrade packages for upgrading the in-vehicle terminal based on the upgrade version information and the current version information includes:

[0023] Comparing the upgrade version information with the current version information;

[0024] When the upgrade version information is different from the current version information, obtain multiple upgrade packages corresponding to the upgrade program and multiple running packages corresponding to the currently running program;

[0025] Use the upgrade packages in the upgrade program that are different from the running packages as one or more target upgrade packages for upgrading the vehicle-mounted terminal.

[0026] In an alternative implementation manner, determine one or more modular replacement packages for upgrading the vehicle-mounted terminal based on historical version information and current version information, including:

[0027] Obtain multiple historical packages corresponding to the historical running program;

[0028] Obtain the running packages in the currently running program that are different from the historical packages;

[0029] Based on the intersection of the running packages and the upgrade packages, use the running packages in the currently running program that are different from the historical packages as one or more replacement packages for upgrading the vehicle-mounted terminal.

[0030] In an alternative implementation manner, update the historical running program to the upgrade program based on the target upgrade packages and the replacement packages, including:

[0031] Obtain the first historical package corresponding to the target upgrade package and the second historical package corresponding to the replacement package in the historical running program;

[0032] Replace the first historical package with the target upgrade package and the second historical package with the replacement package;

[0033] Perform integrity verification on the reorganized program obtained by reorganizing the target upgrade packages, the replacement packages, and the historical packages, and use the reorganized program that passes the integrity verification as the upgrade program.

[0034] In an alternative implementation manner, update the upgrade identifier based on the integrity verification result, including:

[0035] If the integrity verification result indicates that the program download result passes the integrity verification, update the upgrade identifier;

[0036] If the integrity verification result indicates that the program download result fails to pass the integrity verification, generate upgrade exception information for the remote upgrade instruction.

[0037] In an alternative implementation manner, determine that the upgrade program execution is abnormal, including:

[0038] Record the start timestamp of the upgrade program;

[0039] Based on the time difference between adjacent start timestamps, determine the running time of the upgrade program;

[0040] If there are consecutive target running times that are all less than the running threshold time, it is determined that the upgrade program execution is abnormal.

[0041] According to another aspect of the embodiments of the present invention, there is provided a vehicle-mounted terminal remote upgrade optimization and exception recovery device, including: an instruction acquisition module, configured to acquire a first storage area where the currently running program is located, and receive a remote upgrade instruction sent by a server through the currently running program; an information acquisition module, configured to determine upgrade version information of the upgrade program based on the remote upgrade instruction; a remote upgrade module, configured to determine one or more target upgrade packages for upgrading the vehicle-mounted terminal based on the upgrade version information, the current version information of the currently running program, and the historical version information of the historical running program stored in the second storage area; an exception recovery module, configured to update the historical running program to the upgrade program with the target upgrade package, and when the upgrade program execution is abnormal, resume the operation of the running program in the first storage area.

[0042] According to another aspect of the embodiments of the present invention, there is provided a vehicle, including: a processor, a memory, a communication interface, and a communication bus, where the processor, the memory, and the communication interface complete mutual communication through the communication bus; the memory is used to store at least one executable instruction, and the executable instruction causes the processor to execute the operations of the foregoing vehicle-mounted terminal remote upgrade optimization and exception recovery method.

[0043] According to still another aspect of the embodiments of the present invention, there is provided a computer-readable storage medium, where at least one executable instruction is stored in the storage medium, and the executable instruction causes the vehicle / device to execute the operations of the foregoing vehicle-mounted terminal remote upgrade optimization and exception recovery method.

[0044] According to an aspect of the embodiments of the present invention, there is provided a computer program product, including computer instructions, where the computer instructions are used to cause a computer to execute the vehicle-mounted terminal remote upgrade optimization and exception recovery method in the foregoing first aspect or any corresponding implementation manner thereof.

[0045] The technical solution provided by the embodiments of the present invention realizes targeted upgrade according to the actual situation of the vehicle-mounted terminal when remotely upgrading the program on the vehicle-mounted terminal by acquiring the first storage area where the currently running program is located, and receiving the remote upgrade instruction sent by the server through the currently running program; determining the upgrade version information of the upgrade program based on the remote upgrade instruction; determining one or more target upgrade packages for upgrading the vehicle-mounted terminal based on the upgrade version information, the current version information of the currently running program, and the historical version information of the historical running program stored in the second storage area; and updating the historical running program to the upgrade program with the target upgrade package; and by resuming the operation of the running program in the first storage area when the upgrade program execution is abnormal, the normal operation of the vehicle-mounted terminal is ensured.

[0046] The above description is only an overview of the technical solution of the embodiments of the present invention. In order to better understand the technical means of the embodiments of the present invention, it can be implemented according to the content of the description. And in order to make the above and other objects, features, and advantages of the embodiments of the present invention more obvious and understandable, the following specifically illustrates the specific embodiments of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] The drawings are only used to illustrate the embodiments and are not considered as a limitation to the present invention. And throughout the drawings, the same reference numerals are used to represent the same components. In the drawings:

[0048] Figure 1 A flowchart showing a method for remote upgrade optimization and exception recovery of an in-vehicle terminal provided by the present invention is shown;

[0049] Figure 2 Another flowchart showing a method for remote upgrade optimization and exception recovery of an in-vehicle terminal provided by the present invention is shown;

[0050] Figure 3 Still another flowchart showing a method for remote upgrade optimization and exception recovery of an in-vehicle terminal provided by the present invention is shown;

[0051] Figure 4 A structural diagram showing a device for remote upgrade optimization and exception recovery of an in-vehicle terminal provided by the present invention is shown;

[0052] Figure 5 A structural diagram showing a vehicle provided by the present invention is shown. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0053] The exemplary embodiments of the present invention will be described in more detail below with reference to the drawings. Although the exemplary embodiments of the present invention are shown in the drawings, it should be understood that the present invention can be implemented in various forms and should not be limited by the embodiments described herein.

[0054] Figure 1 A flowchart of the first embodiment of a method for remote upgrade optimization and exception recovery of an in-vehicle terminal according to the present invention is shown, and this method is executed by a vehicle. As Figure 1 shown, the method includes the following steps:

[0055] Step 110, obtain the first storage area where the currently running program is located, and receive a remote upgrade instruction sent by the server through the currently running program.

[0056] Among them, when obtaining the first storage area where the current running program is located and receiving the remote upgrade instruction sent by the server through the current running program, in order to ensure the smooth progress of the upgrade process, the vehicle will first verify the validity of the remote upgrade instruction. This verification process includes verifying the source of the instruction and checking the integrity of the instruction content to prevent upgrade failures caused by malicious attacks or data corruption. Once the remote upgrade instruction is confirmed to be valid, the vehicle will enter the preparatory upgrade state, and at this time, some non-critical functions will be suspended to reduce the impact on the normal operation of the vehicle during the upgrade process.

[0057] Step 120, determine the upgrade version information of the upgrade program based on the remote upgrade instruction.

[0058] Among them, when determining the upgrade version information of the upgrade program based on the remote upgrade instruction, it can be obtained by parsing the version information field included in the remote upgrade instruction. This field details the version of the program to be upgraded and the associated upgrade package information, such as the size and checksum of the upgrade package, and compares it with the running version information of the current running program to determine whether an upgrade is required. At the same time, it is also possible to first check the applicability and compatibility of the upgrade package to ensure that the upgraded program can run normally on the vehicle. In addition, after determining that the upgrade version information is correct, the corresponding upgrade resources will be prepared for the upgrade program, such as downloading the upgrade program to the specified second storage area to provide the necessary conditions for the subsequent upgrade operation of the in-vehicle terminal.

[0059] Step 130, determine one or more target upgrade packages for upgrading the in-vehicle terminal based on the upgrade version information, the current version information of the current running program, and the historical version information of the historical running program stored in the second storage area.

[0060] As above, by determining one or more target upgrade packages for upgrading the in-vehicle terminal based on the upgrade version information, the current version information of the current running program, and the historical version information of the historical running program stored in the second storage area, it is ensured that the selected upgrade packages not only meet the upgrade requirements but also match the historical running records of the in-vehicle terminal, reducing upgrade failures or system anomalies caused by version incompatibility.

[0061] In an alternative embodiment, when determining one or more target upgrade packages for upgrading the in-vehicle terminal based on the upgrade version information, the current version information of the current running program, and the historical version information of the historical running program stored in the second storage area, the upgrade version information can be compared with the current version information; when the upgrade version information is different from the current version information, obtain the multiple upgrade packages corresponding to the upgrade program and the multiple historical packages corresponding to the historical running program; and use the upgrade packages in the upgrade program that are different from the historical packages as one or more target upgrade packages for upgrading the in-vehicle terminal.

[0062] Further, when taking the upgrade packages in the upgrade program that are different from the historical packages as one or more target upgrade packages for upgrading the in-vehicle terminal, the multiple upgrade packages corresponding to the upgrade program can be compared with the corresponding multiple historical packages respectively to determine which upgrade packages are newly added or have changed. For the newly added upgrade packages, directly mark them as target upgrade packages because these upgrade packages contain new functions or fix new problems and are essential in the upgrade process. For the upgrade packages with changes, it is necessary to further analyze the differences between them and the historical packages to judge whether these differences will have a positive impact on the operation of the in-vehicle terminal. If the judgment result is affirmative, also mark them as target upgrade packages; if the judgment result is negative, or it is impossible to determine the impact, the upgrade package can be considered to be skipped to avoid potential upgrade risks. Through such a comparison and analysis process, it can be ensured that the selected target upgrade packages meet the upgrade requirements and minimize the upgrade failures or system anomalies caused by version incompatibility to the greatest extent.

[0063] In addition, during the process of determining the target upgrade packages, factors such as the release time, size of the upgrade packages, and whether they contain emergency fixes can also be considered. For example, if an upgrade package is different from the current version but has an early release time and has been replaced by subsequent versions, this upgrade package may not be the best choice. Similarly, if the upgrade package is too large, it may increase the data transmission time and storage space occupancy during the upgrade process, and the pros and cons need to be weighed. In addition, if the upgrade package contains an emergency fix and the fix is related to the problems encountered by the current in-vehicle terminal, this upgrade package should be given priority consideration.

[0064] Step 140, update the historical running program to the upgrade program based on the target upgrade packages, and when the upgrade program executes abnormally, resume the operation of the running program in the first storage area.

[0065] As above, by updating the historical running program to the upgrade program based on the target upgrade packages and resuming the operation of the running program in the first storage area when the upgrade program executes abnormally, the stability and reliability of the in-vehicle terminal during the remote upgrade process can be effectively guaranteed. If the upgrade program executes successfully, the in-vehicle terminal will normally run the new upgrade program and enjoy the functional and performance improvements brought by the upgrade. Once the upgrade program executes abnormally, such as causing problems like system crashes and function failures, this method can respond quickly and restore the in-vehicle terminal to the state before the upgrade, that is, continue to run the historical running program in the first storage area. This abnormal recovery mechanism ensures that the in-vehicle terminal can "advance and retreat freely" during the upgrade process, neither making the terminal unusable due to upgrade failures nor affecting the normal experience of users due to problems with the upgraded program. Therefore, while improving the remote upgrade efficiency and success rate of the in-vehicle terminal, this method also greatly enhances the system stability and user experience.

[0066] In an alternative embodiment, when the upgrade program runs abnormally, after restoring the operation of the running program in the first storage area, if the running program in the first storage area runs abnormally, then restore the operation of the factory program in the third storage area; obtain the upgrade status data of the vehicle-mounted terminal and the factory version information of the factory program; upload the factory version information and the upgrade status data to the server based on the factory program, so that the server generates a target upgrade instruction based on the factory version information and the upgrade status data. The target upgrade instruction includes the storage area corresponding to the target upgrade program. That is, after receiving these information, the server will perform analysis and processing. First, it will compare the factory version information of the current vehicle-mounted terminal with the latest upgrade program version on the server to determine whether there is an available upgrade. If there is an available upgrade, the server will generate a new target upgrade instruction according to the upgrade status data and prepare the corresponding target upgrade package. This new target upgrade instruction will specify which storage area the upgrade program should be stored in to ensure the smooth progress of the upgrade process. At the same time, the server will also send the new target upgrade instruction and related upgrade package information back to the vehicle-mounted terminal to notify it to perform the next upgrade attempt. In this way, even after the vehicle-mounted terminal encounters an upgrade failure, it can obtain a new upgrade opportunity by restoring the factory program and uploading relevant information to the server, thereby continuously improving the functions and performance of the system.

[0067] The method for optimizing remote upgrade and abnormal recovery of the vehicle-mounted terminal according to the embodiment of the present invention obtains the first storage area where the current running program is located and receives the remote upgrade instruction sent by the server through the current running program; determines the upgrade version information of the upgrade program based on the remote upgrade instruction; determines one or more target upgrade packages for upgrading the vehicle-mounted terminal based on the upgrade version information, the current version information of the current running program, and the historical version information of the historical running program stored in the second storage area; updates the historical running program to the upgrade program based on the target upgrade package, realizing targeted upgrade according to the actual situation of the vehicle-mounted terminal during remote program upgrade; by restoring the operation of the running program in the first storage area when the upgrade program executes abnormally, the normal operation of the vehicle-mounted terminal is ensured.

[0068] Figure 2 The flowchart of another embodiment of the method for optimizing remote upgrade and abnormal recovery of the vehicle-mounted terminal according to the present invention is shown, and this method is executed by the vehicle. As Figure 2 shown, the method includes the following steps:

[0069] Step 210, obtain the first storage area where the current running program is located, and receive the remote upgrade instruction sent by the server through the current running program.

[0070] For details, please refer toFigure 1 Step 110 of the illustrated embodiment will not be elaborated herein.

[0071] Step 220: Determine the upgrade version information of the upgrade program based on the remote upgrade instruction.

[0072] For details, please refer to Figure 1 Step 120 of the illustrated embodiment will not be elaborated herein.

[0073] Step 230: Download the upgrade program to the second storage area based on the upgrade version information and the current version information to obtain a program download result.

[0074] Among them, the above program download result includes successful download or failed download. If the download is successful, step 240 is executed; if the download fails, steps 220 to 230 are re-executed until the download is successful.

[0075] In an alternative embodiment, when downloading the upgrade program to the second storage area based on the upgrade version information and the current version information, the upgrade version information and the current version information can be compared first to confirm whether the upgrade version is the same as the current version and whether the upgrade version is applicable to the hardware configuration and software environment of the current vehicle terminal, so as to effectively avoid damage or abnormality to the vehicle terminal caused by an incompatible upgrade program. Only when the upgrade version information matches the current version information and it is confirmed that the upgrade version is applicable to the current vehicle terminal, will the download operation continue. This comparison process can increase the security and stability of the upgrade process and ensure the normal operation of the vehicle terminal after the upgrade.

[0076] Step 240: Perform an integrity check on the program download result to obtain an integrity check result.

[0077] Among them, when performing the integrity check on the program download result, a hash algorithm can be used to check the downloaded program file. By calculating the hash value of the downloaded file and comparing it with the hash value provided by the server, if the two are the same, it means that the downloaded program file is complete and not tampered with, and the subsequent upgrade process can continue; if they are different, it means that the downloaded program file may have problems, and at this time, the download operation needs to be re-executed until the downloaded program file passes the integrity check. This integrity check step can ensure the accuracy and reliability of the upgrade program and effectively avoid upgrade failure or vehicle terminal abnormality caused by program file damage or tampering.

[0078] Step 250: Update the upgrade flag based on the integrity check result, so that during the process of the in-vehicle terminal loading and starting the bootloader, the upgrade program in the second storage area is executed based on the updated upgrade flag, and when the upgrade program execution is abnormal, the operation of the program running in the first storage area is restored.

[0079] As described above, by updating the upgrade identifier, the correctness and security of the in-vehicle terminal during the execution of the upgrade program are ensured. Once the upgrade program starts to execute, the in-vehicle terminal will first check the upgrade identifier to determine whether the upgrade program in the second storage area should be executed. If the upgrade identifier indicates an upgrade, the in-vehicle terminal will load and execute the new program in the second storage area. During the execution process, if any abnormality is detected, such as program crash or unstable operation, the in-vehicle terminal will immediately stop executing the upgrade program and automatically resume running the program in the first storage area, thus ensuring the continuous availability and security of vehicle functions. This design not only improves the flexibility of the upgrade process but also greatly reduces the risk of vehicle function interruption caused by upgrade failure.

[0080] In an alternative embodiment, when updating the upgrade identifier based on the integrity check result, if the integrity check result indicates that the program download result passes the integrity check, the upgrade identifier is updated; if the integrity check result indicates that the program download result fails the integrity check, upgrade exception information for the remote upgrade instruction is generated. The generation of the upgrade exception information is a crucial feedback mechanism to notify the system administrator or relevant maintenance personnel that there are problems during the remote upgrade process and further inspection or correction is required. The upgrade exception information may include specific error codes, error descriptions, and the timestamp when the error occurred, which helps to quickly locate the cause of the problem. In addition, once the upgrade exception information is generated, the in-vehicle terminal will suspend further upgrade operations to avoid performing operations that may lead to more serious consequences under uncertain conditions. After receiving the upgrade exception information, the system administrator can manually intervene to check whether the downloaded program file is complete, whether data loss or corruption occurred during the network transmission process, or whether there is a problem with the program version on the server side, etc. Such a design ensures a high degree of controllability and reliability of the entire upgrade process.

[0081] In an alternative embodiment, when it is determined that the upgrade program execution is abnormal, the start timestamp of the upgrade program can be recorded; based on the time difference between adjacent start timestamps, the running time of the upgrade program is determined; if there are consecutive target running times that are all less than the running threshold time, it is determined that the upgrade program execution is abnormal, which helps to timely detect and handle potential problems during the upgrade process. The consecutive target running times being less than the running threshold time may indicate that the upgrade program encounters obstacles during execution, such as insufficient resources, program conflicts, or hardware failures. By recording the start timestamp and calculating the running time to monitor the running status of the upgrade program, once an abnormality is detected, corresponding measures can be taken. For example, the upgrade program can be restarted and the upgrade operation can be attempted again; or an upgrade exception report can be generated to notify the system administrator for manual intervention. Such a design not only improves the automation level of the upgrade process but also enhances the stability and reliability of the system, ensuring that the in-vehicle terminal can complete the remote upgrade in a timely and safe manner.

[0082] Its program status structure is as follows:

[0083] typedef struct APPStatus

[0084] {

[0085] uint32_t cur_App; / / The currently running program

[0086] uint32_t update_flag; / / Upgrade flag

[0087] uint32_t update_download; / / Upgrade file download address

[0088] uint32_t A_curbootTimeStamp; / / The current start timestamp of the program running in the first storage area A

[0089] uint32_t A_lastbootTimeStamp; / / The previous start timestamp of the program running in the first storage area A

[0090] uint32_t A_status; / / The status of the program running in the first storage area A

[0091] uint32_t A_errorCounts; / / The number of abnormal starts of the program running in the first storage area A uint32_t B_curbootTimeStamp; / / The current start timestamp of the program running in the second storage area B

[0092] uint32_t B_lastbootTimeStamp; / / Timestamp of the last startup of the program running in the second storage area B

[0093] uint32_t B_status; / / Status of the program running in the second storage area B

[0094] uint32_t B_errorCounts; / / Number of abnormal startups of the program running in the second storage area B

[0095] }

[0096] That is, by recording the startup timestamp and comparing it with the last startup timestamp, the running time of the last program is calculated. If the number of consecutive times exceeds the threshold and the running time is lower than the threshold time, it is determined that there is a phenomenon of abnormal rapid restart of the current program.

[0097] The method for remote upgrade optimization and exception recovery of the vehicle-mounted terminal according to the embodiment of the present invention obtains the first storage area where the current running program is located through the current running program, and receives a remote upgrade instruction sent by the server; determines the upgrade version information of the upgrade program based on the remote upgrade instruction; determines one or more target upgrade packages for upgrading the vehicle-mounted terminal based on the upgrade version information, the current version information of the current running program, and the historical version information of the historical running program stored in the second storage area; updates the historical running program to the upgrade program based on the target upgrade package, realizing targeted upgrade according to the actual situation of the vehicle-mounted terminal during remote program upgrade; when the execution of the upgrade program is abnormal, restores the operation of the program running in the first storage area, thereby ensuring the normal operation of the vehicle-mounted terminal.

[0098] Figure 3 The flowchart of another embodiment of the method for remote upgrade optimization and exception recovery of the vehicle-mounted terminal according to the present invention is shown, and this method is executed by the vehicle. As Figure 3 shown, this method includes the following steps:

[0099] Step 310, obtain the first storage area where the current running program is located, and receive a remote upgrade instruction sent by the server through the current running program.

[0100] For details, please refer to Figure 1 Step 110 of the embodiment shown, which will not be elaborated here.

[0101] Step 320, determine the upgrade version information of the upgrade program based on the remote upgrade instruction.

[0102] For details, please refer to Figure 1 Step 120 of the embodiment shown, which will not be elaborated here.

[0103] Step 330: Determine one or more target upgrade packages for upgrading the in-vehicle terminal based on the upgrade version information and the current version information.

[0104] As described above, by determining one or more target upgrade packages for upgrading the in-vehicle terminal based on the upgrade version information and the current version information, the currently running program is updated based on the obtained one or more target upgrade packages, so as to obtain the upgraded running program. In this embodiment, the specific process of determining the target upgrade packages based on the upgrade version information and the current version information can refer to Figure 1 Step 130 of the illustrated embodiment, which will not be elaborated here.

[0105] In an alternative embodiment, when determining one or more target upgrade packages for upgrading the in-vehicle terminal based on the upgrade version information and the current version information, the upgrade version information can be compared with the current version information; when the upgrade version information is different from the current version information, obtain multiple upgrade packages corresponding to the upgrade program and multiple running packages corresponding to the currently running program; and use the upgrade packages in the upgrade program that are different from the running packages as one or more target upgrade packages for upgrading the in-vehicle terminal. In addition, before implementing the upgrade, the target upgrade packages can also be verified to ensure their integrity and correctness, so as to avoid errors during the upgrade process or causing the in-vehicle terminal to malfunction.

[0106] Step 340: Determine one or more replacement packages for upgrading the in-vehicle terminal based on the historical version information and the current version information.

[0107] As described above, by determining one or more replacement packages for upgrading the in-vehicle terminal based on the historical version information and the current version information, the currently running program is updated based on the obtained one or more replacement packages, so as to obtain the upgraded running program.

[0108] In an alternative embodiment, when determining one or more modular replacement packages for upgrading the vehicle-mounted terminal based on historical version information and current version information, multiple historical packages corresponding to the historical running program may be obtained first; then the running packages in the current running program that are different from the historical packages may be obtained; finally, based on the intersection of the running packages and the upgrade packages, the running packages in the current running program that are different from the historical packages are used as one or more replacement packages for upgrading the vehicle-mounted terminal, so as to accurately identify which parts of the vehicle-mounted terminal program need to be updated, thereby avoiding unnecessary upgrade operations and improving the upgrade efficiency and accuracy. For example, if a certain module in the historical version has been replaced or deleted in the current version, then this module will not be included in the replacement package when determining the replacement package. Similarly, if some new modules or functions are added in the current version and do not exist in the historical version, then these new modules or functions will not be misidentified as parts that need to be replaced.

[0109] Step 350: Update the historical running program to the upgrade program based on the target upgrade package and the replacement package, and when the upgrade program runs abnormally, resume the running of the running program in the first storage area.

[0110] As described above, by updating the historical running program to the upgrade program based on the target upgrade package and the replacement package, and when the upgrade program runs abnormally, resuming the running of the running program in the first storage area, the stability and reliability of the vehicle-mounted terminal during the remote upgrade process can be effectively ensured. During the upgrade process, if any problem causes the upgrade program to fail to run properly, it can be quickly restored to the state before the upgrade, avoiding the situation where the vehicle-mounted terminal cannot work properly due to upgrade failure. This abnormal recovery mechanism greatly improves the security and user experience of the upgrade process. In addition, this method also reduces the time and bandwidth required for the upgrade by accurately identifying the parts of the program that need to be updated, making the entire upgrade process more efficient and convenient.

[0111] In an alternative implementation, when updating the historical running program to an upgraded program based on the target upgrade package and the replacement package, the first historical package corresponding to the target upgrade package and the second historical package corresponding to the replacement package in the historical running program can be obtained; the first historical package is replaced with the target upgrade package, and the second historical package is replaced with the replacement package; the integrity of the reorganized program obtained by reorganizing the target upgrade package, the replacement package, and the historical package is verified, and the reorganized program passing the integrity verification is used as the upgraded program, enhancing the controllability and accuracy of the upgrade process. By obtaining the historical packages corresponding to the target upgrade package and the replacement package and performing corresponding replacement operations, it can be ensured that all program packages involved in the upgrade process are correct and matched. The integrity verification of the reorganized program can effectively detect any damage or tampering that may occur during the transmission or processing of the program, thereby ensuring that the finally running upgraded program is complete and undamaged, further enhancing the security level of the upgrade process and providing users with a more stable and reliable in-vehicle terminal usage experience.

[0112] In an alternative implementation, verifying the integrity of the reorganized program obtained by reorganizing the target upgrade package, the replacement package, and the historical package and using the reorganized program passing the integrity verification as the upgraded program includes calculating the hash value of the reorganized program and comparing the calculated hash value with a preset hash value. If the two are the same, it is determined that the reorganized program passes the integrity verification, ensuring that the reorganized program has not been tampered with or damaged. In addition, digital signature technology can also be used to verify the signature of the reorganized program, further enhancing the integrity and security of the program. If the reorganized program fails to pass the integrity verification, the target upgrade package, the replacement package, and the historical package are retrieved again, and the replacement and reorganization operations are performed again until the reorganized program passes the integrity verification, minimizing upgrade failures or anomalies caused by program damage or tampering and providing users with a more stable and reliable in-vehicle terminal usage experience.

[0113] In another alternative implementation, the current running state of the in-vehicle terminal can also be evaluated before the upgrade. This step aims to ensure that the in-vehicle terminal remains stable during the upgrade process and avoid unnecessary failures or data loss caused by the upgrade operation. The evaluation content includes but is not limited to key indicators such as memory occupancy, CPU usage rate, and network connection status. If the evaluation result shows that the current state is not suitable for the upgrade, the user will be prompted to postpone the upgrade operation or the system will automatically find a suitable time for the upgrade to ensure the security and stability of the upgrade process. In addition, the in-vehicle terminal can be automatically restarted after the upgrade to ensure that the newly upgraded program can be started and run normally, further enhancing the user's usage experience.

[0114] In actual operation, taking the in-vehicle terminal with the STM32F40x series as the main chip as an example, the FLASH main memory block of this chip is divided into 4 sectors of 16KB, 1 sector of 64KB, and 7 sectors of 128KB. First, according to the functional division, the above sectors are divided into the following functional areas:

[0115] BOOT area: The starting position of the terminal software operation. According to the current operation status and exception flags of each storage area, the program operation area address is dynamically set to start the program, perform program upgrade, version rollback, and restore to factory settings, etc.

[0116] The first storage area: Can run the APP program to implement all functions of the terminal, or after receiving a remote upgrade instruction, download the program file from the server to this area.

[0117] The second storage area: Can run the APP program to implement all functions of the terminal, or after receiving a remote upgrade instruction, download the program file from the server to this area.

[0118] The third storage area: Burn and retain the factory program with basic functions such as network connection and remote upgrade at the factory. Among them, the factory program only retains the network connection and remote upgrade functions, and by default, sets the first storage area as the download area; source codes of other functions such as CAN message parsing, GPS positioning, file storage, etc. are shielded and deleted to ensure that the compiled program file is minimized; the factory program is burned together with BOOT and APP at the factory and stored in the third storage area.

[0119] Reserved area: Can be read and written at any time to store terminal parameters.

[0120] If the currently running program runs in the first storage area and receives a remote upgrade instruction, it will remotely download the upgrade file from the FTP server to the second storage area; after restarting, BOOT verifies the upgrade program in the second storage area. After the verification is completed, it jumps to the second storage area to run, and at the same time sets the first storage area as the upgrade area to be used as the area for storing the upgrade file for the next download. If the currently running program runs in the second storage area and receives a remote upgrade instruction, a similar upgrade process will be performed. At the same time, the in-vehicle terminal will also perform error judgment and status reporting during the upgrade process, such as:

[0121] typedef struct updateStatus

[0122] {

[0123] uint32_t hardVerErr; / / Hardware version error

[0124] uint32_t serverNetErr; / / Server network exception

[0125] uint32_t fileSizeErr; / / Upgrade file size exception

[0126] uint32_t fileCrcErr; / / Upgrade file integrity check error

[0127] uint32_t flashAddErr

[100] ; / / Read / write exception address (up to record 100 exception addresses)

[0128] uint32_t flashWriteCnt; / / FLASH read / write count threshold

[0129] }

[0130] Among them, the hardVerErr field is used to record the errors caused by the mismatch of the hardware version; the serverNetErr field is used to record the upgrade failure caused by the server network exception; the fileSizeErr field is used to record the error that the upgrade file size does not match the expectation; the fileCrcErr field is used to record the situation of the failure of the upgrade file CRC check; the flashAddErr array is used to record the specific addresses where exceptions occur during the read / write process of the FLASH chip, and up to 100 exception addresses can be recorded; the flashWriteCnt field is used to record the read / write times of the FLASH chip. When the preset threshold is reached, it may indicate that the FLASH is about to reach the end of its life, and early warning or processing is required. Through these error judgments and status reports, the reason for the upgrade failure can be more accurately located, providing strong support for subsequent problem solving and exception recovery.

[0131] When the vehicle-mounted terminal is powered on for the first time or the factory program, the first storage area is defaulted as the current program running area, and the second storage area is the download area. After the vehicle-mounted terminal is powered on, the program enters the BOOT startup program. If there is no upgrade flag, it is judged whether there is an exception flag in the first storage area. If not, the program enters the first storage area to execute the program. If there is an exception flag in the first storage area, it is judged whether there is an exception flag in the second storage area (an empty program is also an abnormal state). If not, the program enters the second storage area to execute the program, and at the same time, the second storage area is set as the current program running area, and the original program running area is set as the upgrade program download area. When there are exception flags in both areas, it jumps to the third storage area to execute the program. The factory program will upload the current vehicle-mounted terminal status and the factory program version to the server, wait for the server to send a remote upgrade instruction, and the server specifies the upgrade area (the first storage area / the second storage area). After the upgrade file is downloaded, it will be restarted and jump to the specified upgrade area to run the program.

[0132] Assume that the currently running program points to the first storage area. When a remote upgrade instruction is received, the program file is downloaded to the second storage area. After the download is complete, file size and integrity verification are performed (such as CRC32 cyclic redundancy check, which has extremely strong error detection ability and low overhead). If the verification passes, the upgrade flag is set, and at the same time, the vehicle-mounted terminal restarts and enters the BOOT startup program. If the verification fails, the program in the second storage area is set as abnormal, the upgrade flag is cleared, and an upgrade failure message is reported to the server, waiting for the server to create and execute the upgrade task again next time.

[0133] In summary, through a storage space allocation method with less hardware resource occupancy, the storage space expenditure is minimized to the greatest extent. Most of the occupied space in the backup area is cancelled, saving a large amount of storage space resources. By dividing the first storage area and the second storage area, the BOOT startup program determines based on the program running status of the two areas and jumps to one of the areas as the running area, and the other is automatically marked as the area for storing the upgrade program. After the upgrade program is downloaded, the program can be directly switched by switching the program jump pointer, and the upgraded program is run. The original running area is marked as the area for storing the upgrade program. There is no need to update the program file in the upgrade area to the program running area, saving the upgrade program and reducing the probability of upgrade failure. Through upgrade error judgment and status reporting, invalid upgrades are avoided and abnormal points can be quickly located, improving the fault handling rate. By recording the program running status, it is analyzed whether the program is abnormal, and the current program version status is saved. When the program is abnormal, it can quickly resume normal operation by switching back to the previous-level program. When both the first storage area and the second storage area have abnormal flags, the BOOT program will jump to the factory program area to execute the program. The factory program will upload the current terminal status and the factory program version to the management platform, wait for the platform to send an upgrade instruction, and the platform specifies the upgrade area. After the upgrade file is downloaded, the device will restart and jump to the specified upgrade area to run the program.

[0134] Figure 4 The structural schematic diagram of an embodiment of a vehicle-mounted terminal remote upgrade optimization and exception recovery device according to the present invention is shown. As Figure 4 shown, the device includes:

[0135] An instruction acquisition module 410, configured to acquire the first storage area where the currently running program is located, and receive a remote upgrade instruction sent by the server through the currently running program.

[0136] An information acquisition module 420, configured to determine the upgrade version information of the upgrade program based on the remote upgrade instruction.

[0137] The remote upgrade module 430 is used to determine one or more target upgrade packages for upgrading the vehicle terminal based on the upgrade version information, the current version information of the currently running program, and the historical version information of the historical running program stored in the second storage area.

[0138] The exception recovery module 440 is used to update the historical running program to the upgrade program with the target upgrade package, and when the execution of the upgrade program is abnormal, it restores the operation of the running program in the first storage area.

[0139] The further function descriptions of the above-mentioned various modules and units are the same as those in the corresponding method embodiments above, and will not be elaborated here.

[0140] Through the above device and its components, the technical solution provided by the embodiments of the present invention has the following advantages:

[0141] Figure 5 The structure diagram of an embodiment of a vehicle provided by the present invention is shown. The specific implementation of the vehicle in the specific embodiments of the present invention is not limited. The vehicle has the above-mentioned Figure 4 vehicle terminal remote upgrade optimization and exception recovery device shown. The vehicle may include: a processor 502, a communication interface 504, a memory 506, and a communication bus 508.

[0142] Among them: the processor 502, the communication interface 504, and the memory 506 complete mutual communication through the communication bus 508. The communication interface 504 is used for network communication with other devices such as clients or other servers. The processor 502 is used to execute the program 510, and specifically can execute the relevant steps in the above-mentioned method embodiments.

[0143] Specifically, the program 510 may include program code, and the program code includes computer-executable instructions.

[0144] The processor 502 may be a central processing unit CPU, or a specific integrated circuit ASIC (Application Specific Integrated Circuit), or one or more integrated circuits configured to implement the embodiments of the present invention. One or more processors included in the vehicle may be of the same type of processor, such as one or more CPUs; or they may be of different types of processors, such as one or more CPUs and one or more ASICs.

[0145] A memory 506 for storing a program 510. The memory 506 may include high-speed RAM memory and may also include non-volatile memory, such as at least one disk memory.

[0146] An embodiment of the present invention also provides a computer-readable storage medium storing at least one executable instruction, which, when running on a vehicle / vehicle-mounted terminal remote upgrade optimization and exception recovery device, causes the vehicle / vehicle-mounted terminal remote upgrade optimization and exception recovery device to execute the vehicle-mounted terminal remote upgrade optimization and exception recovery method in any of the above method embodiments.

[0147] An embodiment of the present invention also provides a computer program product including computer instructions for causing a computer to execute the vehicle-mounted terminal remote upgrade optimization and exception recovery method in the first aspect above or any corresponding embodiment thereof.

[0148] The algorithms or displays provided herein are not inherently related to any particular computer, virtual system, or other device. In addition, embodiments of the present invention are not directed to any particular programming language.

[0149] In the specification provided herein, a large number of specific details are set forth. However, it can be understood that embodiments of the present invention may be practiced without these specific details. Similarly, in order to streamline the present invention and assist in understanding one or more of the various inventive aspects, in the description of the exemplary embodiments of the present invention above, the various features of the embodiments of the present invention are sometimes grouped together into a single embodiment, figure, or description thereof. Among them, the claims following the specific implementation manners are hereby expressly incorporated into the specific implementation manners, where each claim itself serves as a separate embodiment of the present invention.

[0150] Those skilled in the art can understand that the modules in the devices in the embodiments can be adaptively changed and disposed in one or more devices different from the embodiments. The modules or units or components in the embodiments can be combined into one module or unit or component, and in addition, they can be divided into multiple sub-modules or sub-units or sub-components. Except that at least some of such features and / or processes or units are mutually exclusive.

[0151] It should be noted that the above embodiments illustrate the present invention rather than limit the present invention, and those skilled in the art can design alternative embodiments without departing from the scope of the appended claims. In the claims, any reference signs placed between parentheses shall not be construed as limiting the claim. The word "comprising" does not exclude the presence of elements or steps not listed in the claim. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. The present invention can be implemented by means of hardware including several different elements and by means of a suitably programmed computer. In a unit claim listing several devices, several of these devices can be embodied by the same item of hardware. The use of the words first, second, and third, etc. does not denote any order. These words can be interpreted as names. The steps in the above embodiments, unless otherwise specified, should not be construed as limiting the order of execution.

Claims

1. A method for remote upgrade optimization and abnormal recovery of a vehicle terminal, characterized in that: The method comprises: Acquire a first storage area where a currently running program is located, and receive a remote upgrade instruction sent by a server through the currently running program; Determine the upgrade version information of the upgrade program based on the remote upgrade instruction; Determine one or more target upgrade packages for upgrading the vehicle terminal based on the upgrade version information, the current version information of the currently running program, and the historical version information of the historical running program stored in the second storage area; The historical running program is updated to the upgraded program based on the target upgrade package, and when the upgraded program is executed abnormally, the running of the running program in the first storage area is restored.

2. The method according to claim 1, characterized in that The method further comprises: Based on the upgrade version information and the current version information, download the upgrade program to the second storage area to obtain a program download result; Performing integrity check on the program download result to obtain an integrity check result; The upgrade identifier is updated based on the integrity check result, so that the vehicle-mounted terminal executes the upgrade program in the second storage area based on the updated upgrade identifier during the process of loading the boot program, and resumes the operation of the running program in the first storage area when the upgrade program is executed abnormally.

3. The method according to claim 1, characterized in that The method further comprises: Based on the upgrade version information and the current version information, determining one or more target upgrade packages for upgrading the vehicle terminal; Determining one or more replacement packages for upgrading the vehicle-mounted terminal based on the historical version information and the current version information; The historical running program is updated to the upgraded program based on the target upgraded package and the replacement package, and when the upgraded program runs abnormally, the running program in the first storage area is restored.

4. The method according to any one of claims 1 to 3, characterized in that: When the upgrade program runs abnormally, after resuming the running of the program running in the first storage area, the method further includes: If the running program in the first storage area runs abnormally, the running of the factory program in the third storage area is restored; Acquire the upgrade status data of the vehicle-mounted terminal and the factory version information of the factory program; The factory version information and the upgrade status data are uploaded to the server based on the factory program, so that the server generates a target upgrade instruction based on the factory version information and the upgrade status data, and the target upgrade instruction includes a storage area corresponding to the target upgrade program.

5. The method according to claim 1, characterized in that: The determining one or more target upgrade packages for upgrading the vehicle terminal based on the upgrade version information, the current version information of the currently running program, and the historical version information of the historical running program stored in the second storage area includes: Comparing the upgraded version information with the current version information; When the upgraded version information is different from the current version information, obtaining multiple upgrade packages corresponding to the upgraded program and multiple historical packages corresponding to the historically running program; The upgrade package in the upgrade program that is different from the historical package is used as one or more target upgrade packages for upgrading the vehicle terminal.

6. The method according to claim 3, characterized in that The determining one or more target upgrade packages for upgrading the vehicle terminal based on the upgrade version information and the current version information includes: Comparing the upgraded version information with the current version information; When the upgrade version information is different from the current version information, obtaining multiple upgrade packages corresponding to the upgrade program and multiple running packages corresponding to the currently running program; The upgrade package in the upgrade program that is different from the running package is used as one or more target upgrade packages for upgrading the vehicle-mounted terminal.

7. The method according to claim 6, characterized in that The determining, based on the historical version information and the current version information, one or more modular replacement packages for upgrading the vehicle-mounted terminal includes: Acquire multiple historical packages corresponding to the historical running program; Acquire the running package in the current running program that is different from the historical package; Based on the intersection of the running package and the upgrade package, the running package in the current running program that is different from the historical package is used as one or more replacement packages for upgrading the vehicle terminal.

8. The method according to claim 7, characterized in that The updating of the historical running program to the upgraded program based on the target upgraded package and the replacement package includes: Acquire a first historical package corresponding to the target upgrade package and a second historical package corresponding to the replacement package in the historical running program; Replacing the first historical package with the target upgrade package, and replacing the second historical package with the replacement package; An integrity check is performed on the reorganized program of the target upgrade package, the replacement package and the historical package, and the reorganized program that passes the integrity check is used as the upgrade program.

9. The method according to claim 2, characterized in that: The updating of the upgrade mark based on the integrity check result includes: If the integrity check result indicates that the program download result passes the integrity check, updating the upgrade flag; If the integrity check result indicates that the program download result fails the integrity check, then upgrade exception information for the remote upgrade instruction is generated.

10. The method according to claim 9, characterized in that Determining that the upgrade program is executed abnormally includes: Recording the startup timestamp of the upgrade program; Determining the running time of the upgrade program based on the time difference between adjacent startup timestamps; If there are consecutive target running times that are all less than the running threshold time, it is determined that the upgrade program is executed abnormally.