Vehicle OTA upgrade data processing method, device and equipment

By monitoring the OTA upgrade process and using deviation detection models to detect abnormal data and performing deviation correction measures, the security risks during the OTA upgrade process are solved and the stability and reliability are improved.

CN120353484APending Publication Date: 2025-07-22CHONGQING JINKANG NEW ENERGY VEHICLE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510434543.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-08
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

The existing OTA upgrade plan poses a risk of data leakage and security attacks in the automotive networking environment, resulting in unstable and unreliable OTA upgrade process, especially when data verification, decryption and installation are easily maliciously tampered with.

Method used

By monitoring the OTA upgrade process, the pre-trained deviation detection model is used to detect and monitor data abnormalities, and corresponding correction measures are performed, including stopping abnormal requests, adjusting computing resources, re-verifying data sources, re-compression algorithms, etc., to ensure the stability and security of the upgrade process.

Benefits of technology

It improves the stability and reliability of the OTA upgrade process, prevents software problems or malicious tampering, and ensures the normal operation and safety performance of the vehicle.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120353484A_ABST
    Figure CN120353484A_ABST
Patent Text Reader

Abstract

The invention provides a vehicle OTA upgrading data processing method, device and equipment, and relates to the technical field of vehicle safety, and the method comprises the steps: monitoring an OTA upgrading process, and obtaining current monitoring data in the OTA upgrading process; detecting the current monitoring data based on a pre-trained deviation detection model, and determining whether the current monitoring data is abnormal or not; and if the current monitoring data is abnormal, determining a target deviation correction measure corresponding to the current monitoring data, and executing the target deviation correction measure, thereby preventing the software from going wrong or being maliciously tampered in the OTA upgrading process, and preventing the normal operation and safety performance of the vehicle from being seriously dangerous, so as to improve the stability and reliability of the OTA upgrading process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of vehicle safety, and more particularly, to a method, device, and equipment for processing vehicle OTA upgrade data. Background Art

[0002] OTA (Over-The-Air) technology enables the update of automotive software without relying on physical connections, improving the efficiency and convenience of software updates. Automotive software involves multiple key areas such as vehicle operation control and safety monitoring. Once there are problems with the software during the OTA upgrade process or it is maliciously tampered with, it will pose a serious threat to the normal operation and safety performance of the vehicle.

[0003] Existing OTA upgrade solutions rely on external communication networks and servers, which to a certain extent increase the risk of data leakage and security attacks. Especially in the automotive networking environment, it may be possible to obtain control authority over the vehicle through network attack means, and then maliciously manipulate the vehicle or steal sensitive information. In particular, the complexity of data verification, decryption, installation, etc. during the OTA upgrade process increases, and thus the stability and reliability of the OTA upgrade process cannot be ensured. Summary of the Invention

[0004] In view of this, the purpose of the present invention is to provide a method, device, and equipment for processing vehicle OTA upgrade data to improve the stability and reliability of the OTA upgrade process.

[0005] In a first aspect, the present invention provides a method for processing vehicle OTA upgrade data, including:

[0006] Monitoring the OTA upgrade process to obtain current monitoring data during the OTA upgrade process;

[0007] Detecting the current monitoring data based on a pre-trained deviation detection model to determine whether the current monitoring data is abnormal;

[0008] If the current monitoring data is abnormal, determining the target rectification measure corresponding to the current monitoring data and executing the target rectification measure.

[0009] Optionally, the monitoring data includes monitoring data for one or more of the following behaviors during the OTA upgrade process:

[0010] Receiving an OTA upgrade request;

[0011] Verifying the legality and integrity of the OTA upgrade package;

[0012] Unpacking and installing the OTA upgrade package;

[0013] System restart after installing the OTA upgrade package and verification of functions after the upgrade.

[0014] Optionally, pre - determine the correspondence between abnormal monitoring data and corrective measures; when the current monitoring data is abnormal, determine the target corrective measures corresponding to the current monitoring data, including:

[0015] When the current monitoring data is abnormal, match the target corrective measures corresponding to the current monitoring data in the correspondence between abnormal monitoring data and corrective measures.

[0016] Optionally, when monitoring the behavior of receiving an OTA upgrade request, the monitoring data includes the statistics of the sending frequency of the source address corresponding to the OTA upgrade request;

[0017] The correspondence between abnormal monitoring data and corrective measures includes: the abnormal monitoring data is that the sending frequency of the source address sending requests is abnormal; the corresponding first corrective measure is to stop receiving abnormal OTA upgrade request data; the corresponding second corrective measure is to re - verify the source address corresponding to the abnormal OTA upgrade request data; the first corrective measure and the second corrective measure are executed synchronously.

[0018] Optionally, when monitoring the behavior of verifying the legality and integrity of the OTA upgrade package, the monitoring data includes the statistics of the hash value calculation duration during the verification process;

[0019] The correspondence between abnormal monitoring data and corrective measures includes: the abnormal monitoring data is that the hash value calculation duration is abnormal; the corresponding third corrective measure is to adjust the allocation parameters of computing resources; the corresponding fourth corrective measure is to confirm whether the OTA upgrade chip is normal; the third corrective measure and the fourth corrective measure are executed alternatively or synchronously;

[0020] When monitoring the behavior of verifying the legality and integrity of the OTA upgrade package, the monitoring data includes the hash value comparison result during the verification process;

[0021] The correspondence between abnormal monitoring data and corrective measures includes: the abnormal monitoring data is that the hash value comparison is inconsistent; the corresponding fifth corrective measure is to re - download the OTA upgrade package; the corresponding sixth corrective measure is to obtain the OTA upgrade package from the backup server; the fifth corrective measure and the sixth corrective measure are executed alternatively.

[0022] Optionally, when monitoring the behavior of decompressing and installing the OTA upgrade package, the monitoring data includes the decompression result, installation order, and installation result;

[0023] The corresponding relationship between the abnormal monitoring data and the rectification measures includes: the abnormal monitoring data is decompression failure; the corresponding seventh rectification measure is to replace the decompression algorithm and decompress the OTA upgrade package again; the corresponding eighth rectification measure is to restore some data from the backup; either the seventh rectification measure or the eighth rectification measure is executed.

[0024] The corresponding relationship between the abnormal monitoring data and the rectification measures includes: the abnormal monitoring data is installation failure and abnormal installation sequence; the corresponding ninth rectification measure is to pause the installation and reinstall it in the correct order.

[0025] Optionally, when monitoring the system restart after the installation of the OTA upgrade package and the behavior of verifying the upgraded functions, the monitoring data includes the system pre-check results.

[0026] The corresponding relationship between the abnormal monitoring data and the rectification measures includes: the abnormal monitoring data is that the proportion of deviations in the system pre-check results exceeds the preset threshold; the corresponding tenth rectification measure is to determine the file path and / or file type corresponding to the abnormal installation data, and determine whether the file path and / or file type is abnormal; if it is abnormal, stop the vehicle system restart operation and start the vehicle system repair program to repair the abnormal file path and / or file type.

[0027] Optionally, the deviation detection model is a linear binary classification model.

[0028] In a second aspect, the present invention provides a vehicle OTA upgrade data processing device, including:

[0029] A data acquisition module, configured to monitor the OTA upgrade process and acquire the current monitoring data during the OTA upgrade process.

[0030] A data detection module, configured to detect the current monitoring data based on a pre-trained deviation detection model to determine whether the current monitoring data is abnormal.

[0031] A rectification measure module, configured to, if the current monitoring data is abnormal, determine the target rectification measure corresponding to the current monitoring data and execute the target rectification measure.

[0032] In a third aspect, the present invention further provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the steps of the above vehicle OTA upgrade data processing method are implemented.

[0033] A method, device, and equipment for processing vehicle OTA upgrade data provided by an embodiment of the present invention monitor the OTA upgrade process to obtain current monitoring data during the OTA upgrade process; detect the current monitoring data based on a pre-trained deviation detection model to determine whether the current monitoring data is abnormal; if the current monitoring data is abnormal, determine the target rectification measure corresponding to the current monitoring data, and execute the target rectification measure, thereby preventing problems or malicious tampering of the software during the OTA upgrade process, which may pose a serious danger to the normal operation and safety performance of the vehicle, so as to improve the stability and reliability of the OTA upgrade process.

[0034] To make the above objects, features, and advantages of the present invention more obvious and understandable, the following specifically enumerates preferred embodiments and, in conjunction with the accompanying drawings, makes a detailed description as follows. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required in the embodiments. It should be understood that the following drawings only show some embodiments of the present invention, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.

[0036] Figure 1 Shows a schematic flowchart of a method for processing vehicle OTA upgrade data provided by an embodiment of the present invention;

[0037] Figure 2 Shows a schematic flowchart of the training process of the deviation detection model provided by an embodiment of the present invention;

[0038] Figure 3 Shows a schematic structural diagram of a vehicle OTA upgrade data processing system provided by an embodiment of the present invention;

[0039] Figure 4 Shows a schematic flowchart of another method for processing vehicle OTA upgrade data provided by an embodiment of the present invention;

[0040] Figure 5 Shows a schematic structural diagram of a vehicle OTA upgrade data processing device provided by an embodiment of the present invention;

[0041] Figure 6 Shows a schematic structural diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0042] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are only a part rather than all of the embodiments of the present invention. Components of the embodiments of the present invention described and illustrated herein generally may be arranged and designed in a variety of different configurations. Therefore, the detailed description of the embodiments of the present invention provided herein is not intended to limit the scope of the claimed invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0043] To facilitate better understanding of the present application by those skilled in the art, the technical terms related to the present application will be briefly introduced below.

[0044] A vehicle system is an electronic and software architecture in a vehicle, including multiple electronic control units interconnected through an in-vehicle network.

[0045] OTA upgrade is a technology for remotely updating software through wireless communication technology. In the present application, the software inside the vehicle is remotely updated through wireless communication technology.

[0046] An OTA upgrade chip is all the hardware and / or software required for performing OTA upgrade on a vehicle. In the present application, an OTA upgrade chip generally includes a wireless communication module, an ECU (electronic control unit), an encryption module, a verification module, a controller, and related firmware and software inside the vehicle, and the OTA upgrade chip is used to allow remote update of the vehicle software through a wireless network. Among them, the wireless communication module is used to receive a software update package from a server through a wireless network; the ECU is used to perform software update operations at the right time and monitor the status of the update process; the encryption module is used for data encryption and / or decryption operations to ensure the security of the transmitted data and prevent unauthorized access or tampering; the verification module is used to authenticate the received data and check its integrity to ensure the legitimacy of the update source and that the data has not been tampered with; the controller is used to coordinate each step in the entire OTA update process.

[0047] A security state is a specific configuration state of an OTA upgrade chip before accurately processing any OTA upgrade request. In this specific configuration state, it can ensure that the entire OTA upgrade process is safe and reliable, and can effectively prevent unauthorized access or malicious attacks.

[0048] Encryption algorithm: To encrypt the key information in the OTA upgrade request, in this application, the AES-128 encryption algorithm is adopted. During the OTA upgrade request process, 128-bit plaintext data and a 128-bit encryption key are used as inputs and subjected to several rounds of complex transformation operations. The resulting ciphertext is the encrypted result. Among them, the transformation operations include: In each round of transformation, first, a specific byte substitution operation is performed on each byte in the input data block to increase the complexity and security of the data; second, the rows of the data block after the substitution operation are shifted according to specific rules to disrupt the data arrangement order; then, the columns of the data block after the row shift operation are mixed through specific matrix operations to obtain an intermediate data block to enhance the diffusion of the data; finally, the round key of the current round is bitwise XORed with the intermediate data block to obtain the ciphertext. Among them, when the transformation operation is first executed, the input data block is the plaintext and the initial key, and when the transformation operation is not executed for the first time, the input data is the intermediate data block.

[0049] Hash algorithm: To calculate the hash value of the upgrade package. In this application, the hash algorithm specifically includes: Assume that the input upgrade package data is divided into several data blocks of fixed length, denoted as M i , where i = 1, 2,..., n, and n represents the number of data blocks. The initial hash value H0 is composed of 8 fixed 32-bit initial values. Its calculation process is as follows: First, message padding is performed to ensure that the input data length meets the algorithm requirements, and a sequence of padded data blocks is obtained; second, enter the iterative compression process. For each data block, the intermediate hash value H i is continuously updated through the action of a logical function. Among them, the expression of the logical function is:

[0050]

[0051] In the formula, Ch represents a function that selects from y and z according to the value of x. x, y, and z are all binary bit sequences, ∧ represents logical AND, represents XOR, represents logical NOT. Among them, the formula for updating the intermediate hash value is:

[0052]

[0053] H i = Hash(H i-1 , W i )

[0054] In the formula, W t represents the initial message block, σ0, σ1 represent bit operation functions, and Hash(H i-1 , W i ) represents the combination of the above logical functions to the previous round of hash value H i-1and the W after processing the current data block i perform an operation to obtain a new hash value; finally, after n rounds of iteration, the finally obtained hash value H n is the hash value calculated by the upgrade package and is used for subsequent comparison and verification with the legal hash value.

[0055] The communication module is used to check the legitimacy of the OTA upgrade request. In this application, it mainly examines the source address and protocol version of the OTA upgrade request. Among them, the examination of the source address is to ensure that it comes from a trusted channel and prevent requests from malicious attacks or illegal sources from entering the vehicle system; the examination of the protocol version is to ensure that the communication protocol used in the request is compatible with the vehicle system and can normally process OTA upgrades.

[0056] The monitoring module is used to detect and correct deviations in the data stream during the OTA upgrade process. In this application, the data stream during the OTA upgrade process is used as the input feature of the deviation detection model to obtain a prediction result, so as to accurately judge whether there is a deviation in the data stream during the OTA upgrade process and correct the error in a timely manner when a deviation occurs; among them, the deviation detection model receives the current monitoring data through the input layer and determines the linear classifier model of the category corresponding to the current monitoring data based on the current monitoring data through the decision layer; in this application, the deviation detection model is:

[0057] f(x) = sign(w T v + b)

[0058] In the formula, f(x) represents the prediction result, sign represents the function, w T v represents the inner product operation of the vector, that is w represents the weight vector, b represents the bias term; among them, when f(x) = +1, it is determined as a deviation situation, and when f(x) = -1, it is determined as a normal situation.

[0059] The "and / or" mentioned in this application describes the association relationship of associated objects and represents three possible relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the front and back associated objects.

[0060] After introducing the technical terms involved in this application, next, the technical solutions provided by this application will be described in detail.

[0061] This application embodiment provides a method for processing vehicle OTA upgrade data. Refer to Figure 1 As shown, the general process of the method for processing vehicle OTA upgrade data provided by this application embodiment is as follows:

[0062] Step 110: Monitor the OTA upgrade process and obtain the current monitoring data during the OTA upgrade process.

[0063] In the embodiments of the present application, when monitoring the OTA upgrade process, the received OTA upgrade request, verification of the legality and integrity of the OTA upgrade package, decompression and installation of the OTA upgrade package, system restart after the OTA upgrade package is installed, and verification of the functions after the upgrade can be obtained as the current monitoring data to ensure the smooth progress of the OTA upgrade process.

[0064] Further, when monitoring the behavior of receiving the OTA upgrade request, the monitoring data includes the statistics of the sending frequency of the source address corresponding to the OTA upgrade request;

[0065] When monitoring the behavior of verifying the legality and integrity of the OTA upgrade package, the monitoring data includes the statistics of the hash value calculation duration during the verification process and the hash value comparison result during the verification process;

[0066] When monitoring the behavior of decompressing and installing the OTA upgrade package, the monitoring data includes the decompression result, installation order, and installation result;

[0067] When monitoring the system restart after the OTA upgrade package is installed and the behavior of verifying the functions after the upgrade, the monitoring data includes the system pre-check result.

[0068] Step 120: Detect the current monitoring data based on a pre-trained deviation detection model to determine whether the current monitoring data is abnormal.

[0069] In the embodiments of the present application, the input data is the current monitoring data such as the received OTA upgrade request, verification of the legality and integrity of the OTA upgrade package, decompression and installation of the OTA upgrade package, system restart after the OTA upgrade package is installed, and verification of the functions after the upgrade; the output data is the category corresponding to the current monitoring data, where the category includes the deviation situation and the normal situation; after receiving the current monitoring data through the input layer, the deviation detection model processes the current monitoring data through the decision layer to obtain the category corresponding to the current monitoring data. In this way, by using a deviation detection model with the characteristics of a linear classifier, based on the current monitoring data, the category corresponding to the current monitoring data is determined, so as to accurately judge whether there is a deviation during the OTA upgrade process, that is, the current monitoring data is abnormal.

[0070] Step 130: If the current monitoring data is abnormal, determine the target rectification measure corresponding to the current monitoring data and execute the target rectification measure.

[0071] In the embodiments of the present application, the corresponding relationship between abnormal monitoring data and corrective measures is determined in advance; when the current monitoring data is abnormal, the target corrective measure corresponding to the current monitoring data is matched in the corresponding relationship between the abnormal monitoring data and the corrective measures.

[0072] Further, when the current monitoring data is abnormal, the process of matching the target corrective measure corresponding to the current monitoring data in the corresponding relationship between the abnormal monitoring data and the corrective measures is as follows:

[0073] When monitoring the behavior of receiving OTA upgrade requests, the monitoring data includes the statistics of the sending frequency of the source address corresponding to the OTA upgrade request; the corresponding relationship between the abnormal monitoring data and the corrective measures includes: the abnormal monitoring data is that the sending frequency of the source address sending requests is abnormal; the corresponding first corrective measure is to stop receiving abnormal OTA upgrade request data; the corresponding second corrective measure is to re-verify the source address corresponding to the abnormal OTA upgrade request data; the first corrective measure and the second corrective measure are executed synchronously;

[0074] When monitoring the behavior of verifying the legality and integrity of the OTA upgrade package, the monitoring data includes the statistics of the hash value calculation duration during the verification process; the corresponding relationship between the abnormal monitoring data and the corrective measures includes: the abnormal monitoring data is that the hash value calculation duration is abnormal; the corresponding third corrective measure is to adjust the allocation parameters of the computing resources; the corresponding fourth corrective measure is to confirm whether the OTA upgrade chip is normal; the third corrective measure and the fourth corrective measure are executed alternatively or synchronously; when monitoring the behavior of verifying the legality and integrity of the OTA upgrade package, the monitoring data includes the hash value comparison result during the verification process; the corresponding relationship between the abnormal monitoring data and the corrective measures includes: the abnormal monitoring data is that the hash values are inconsistent; the corresponding fifth corrective measure is to re-download the OTA upgrade package; the corresponding sixth corrective measure is to obtain the OTA upgrade package from the backup server; the fifth corrective measure and the sixth corrective measure are executed alternatively.

[0075] When monitoring the behavior of decompressing and installing the OTA upgrade package, the monitoring data includes the decompression result, the installation order, and the installation result; the corresponding relationship between the abnormal monitoring data and the corrective measures includes: the abnormal monitoring data is that the decompression fails; the corresponding seventh corrective measure is to change the decompression algorithm and re-decompress the OTA upgrade package; the corresponding eighth corrective measure is to restore some data from the backup; the seventh corrective measure and the eighth corrective measure are executed alternatively; the corresponding relationship between the abnormal monitoring data and the corrective measures includes: the abnormal monitoring data is that the installation fails and the installation order is abnormal; the corresponding ninth corrective measure is to suspend the installation and reinstall it in the correct order;

[0076] When monitoring the system restart after the installation of the OTA upgrade package and the behavior of verifying the functions after the upgrade, the monitoring data includes the system pre-check results; the correspondence between the abnormal monitoring data and the corrective measures is as follows: the abnormal monitoring data is that the proportion of deviations in the system pre-check results exceeds the preset threshold; the corresponding tenth corrective measure is to determine the file path and / or file type corresponding to the abnormal installation data, and determine whether the file path and / or file type is abnormal; if it is abnormal, the vehicle system restart operation is stopped, and the vehicle system repair program is started to repair the abnormal file path and / or file type.

[0077] A vehicle OTA upgrade data processing method provided by an embodiment of the present application continuously monitors various key monitoring data during the OTA upgrade process to ensure the smooth progress of the upgrade process; the monitoring data is received through the input layer of the pre-trained deviation detection model and its corresponding category is determined through the decision layer, thereby ensuring the stability of the OTA upgrade process and the accuracy of the data; when abnormal monitoring data is detected, the vehicle system will immediately identify and execute the corresponding corrective measures, so as to ensure that the upgrade process is not interfered by abnormal data and guarantee the reliability and security of software updates. Throughout the process, from the collection of monitoring data to the execution of abnormal detection and corrective actions, it is all implemented based on a linear classifier model that receives the current monitoring data through the input layer and determines its corresponding category, thereby ensuring the stability of the OTA upgrade process and the accuracy of the data.

[0078] The training process of the pre-trained deviation detection model provided by the embodiment of the present application will be described in detail below. Refer to Figure 2 As shown, the training process of the pre-trained deviation detection model provided by the embodiment of the present application is as follows:

[0079] Step 210: Obtain a training data set; where the training data set includes multiple training sample data; each training sample data includes monitoring data and the corresponding category standard data of the monitoring data.

[0080] In the embodiment of the present application, when obtaining the training data set, the following methods can be used but are not limited to:

[0081] First, obtain the monitoring data during the OTA upgrade process and the corresponding category data of the monitoring data, and obtain the deviation detection model.

[0082] Then, based on the deviation detection module, simulate the monitoring data and the corresponding category data of the monitoring data, and obtain the corresponding category standard data of the monitoring data during the simulation process.

[0083] Finally, monitor the monitoring data and the corresponding category standard data of the monitoring data to obtain the training data set.

[0084] Step 220: Select target training sample data from the training data set.

[0085] Step 230: Input the monitored sample data in the target training sample data into the initial deviation detection model, so that the initial deviation detection model receives the monitored sample data through the input layer and processes the monitored sample data through the decision layer to obtain class prediction data.

[0086] Step 240: Update each weight and each threshold of the initial deviation detection model based on the prediction error between the class prediction data and the class standard data in the target training sample data.

[0087] Step 250: Determine whether the iterative training termination condition is satisfied; if so, execute Step 260; if not, return to Step 220; wherein, the iterative training termination condition is that the number of iterations is not less than the number threshold, or the prediction error is not higher than the error threshold.

[0088] Step 260: Obtain a pre-trained deviation detection model based on each weight and each threshold of the initial deviation detection model updated when the iterative training operation is last executed.

[0089] Furthermore, the deviation detection model is a linear binary classification model.

[0090] The embodiments of the present application provide a detailed description of a vehicle OTA upgrade data processing system. Refer to Figure 3 As shown, the vehicle OTA upgrade data processing system provided by the embodiments of the present application includes:

[0091] A communication module, configured to receive and forward OTA upgrade request data;

[0092] An encryption module, connected to the communication module, configured to encrypt the OTA upgrade request data;

[0093] A cloud server, connected to the communication module, configured to receive the OTA upgrade request data sent by the communication module and send down the OTA upgrade package data;

[0094] A controller, connected to the cloud server, configured to receive the OTA upgrade package and decompress and install the OTA upgrade package;

[0095] A verification module, respectively connected to the communication module and the controller, configured to verify the legality of the OTA upgrade data, the OTA upgrade package, and the decompression and installation data;

[0096] The monitoring module, connected to the verification module, is used to monitor the OTA upgrade process, obtain the current monitoring data during the OTA upgrade process; detect the current monitoring data based on a pre-trained deviation detection model to determine whether the current monitoring data is abnormal; if the current monitoring data is abnormal, determine the target rectification measure corresponding to the current monitoring data, and execute the target rectification measure.

[0097] Based on the above embodiments, the vehicle OTA upgrade data processing method provided by the embodiments of the present application will be described in detail. Refer to Figure 4 As shown, the process of the vehicle OTA upgrade data processing method provided by the embodiments of the present application is as follows:

[0098] First, before the vehicle system responds to the OTA upgrade request, it is determined that the OTA upgrade chip is in a preset safe state to wait for receiving the OTA upgrade request, thereby ensuring the security and effectiveness of the vehicle system upgrade.

[0099] Furthermore, determining that the OTA upgrade chip is in a preset safe state specifically includes the following steps:

[0100] Hardware self-check: Obtain the parameter information of the hardware of the OTA upgrade chip, including but not limited to the encryption module, verification module, and controller, etc., to determine whether there are faults in the hardware involved in the OTA upgrade chip. If there are faults, stop the OTA upgrade process to prevent possible security risks and unstable vehicle system conditions;

[0101] Security configuration information: Obtain the security configuration information involved in the OTA upgrade chip. In the present application, the security configuration information includes but not limited to encryption algorithms, hash algorithms, and legitimate hash values, etc., and perform an initialization operation on the security configuration information to obtain the correct parameter values of each security configuration information, preparing for the subsequent OTA upgrade process;

[0102] Secure communication channel: After performing the initialization operation on the security configuration information, encryption technologies (such as AES for symmetric encryption, RSA or ECC for asymmetric encryption) and identity authentication technologies (such as digital certificates and public key infrastructure (PKI) mechanisms) can be used to establish a secure communication channel to ensure secure communication between the OTA upgrade chip and the vehicle system, ensuring that the data transmission during the OTA upgrade process will not be interfered with and attacked by the outside.

[0103] By setting the OTA upgrade chip in a preset safe state, the security of the vehicle system is improved, the confidentiality and integrity of the data are enhanced, the security and reliability of the communication are guaranteed, and the success rate of the OTA upgrade process is increased. The risk of upgrade failure caused by unexpected situations (such as network interruption, malicious attack, etc.) is reduced, and the stability and efficiency of the OTA upgrade process are improved.

[0104] Secondly, the communication module of the vehicle system is always in a listening state. When the communication module receives OTA upgrade request data, the verification module of the OTA upgrade chip checks the legality of the OTA upgrade request data. Specifically, it mainly checks the source address and protocol version in the OTA upgrade request data. By checking the source address of the OTA upgrade request, it is determined whether the OTA upgrade request comes from a trusted channel; by checking the protocol version of the OTA upgrade request, it is ensured that the communication protocol used in the OTA upgrade request is compatible with the communication protocol used by the vehicle system.

[0105] Furthermore, the specific steps for the verification module to detect the legality of the OTA upgrade request data include:

[0106] When the source address and / or protocol version of the OTA upgrade request data is / are illegal, the OTA upgrade request is rejected, and an alarm signal is sent to the vehicle system so that the vehicle system can take corresponding safety measures in a timely manner, such as starting an emergency plan and strengthening the monitoring of the vehicle system.

[0107] When the source address and protocol version of the OTA upgrade request data are legal, the communication module uses the encryption algorithm in the encryption module of the OTA upgrade chip to encrypt and transmit the OTA upgrade request data to ensure the security of the OTA upgrade request during the transmission process and prevent it from being stolen or tampered with. Among them, the OTA upgrade request is transmitted between the server and the vehicle system.

[0108] At the same time, the monitoring module monitors the behavior of receiving the OTA upgrade request. The monitoring data includes the statistics of the sending frequency of the source address corresponding to the OTA upgrade request. Based on the pre-trained deviation detection model, it is determined that the sending frequency of the source address sending the request is abnormal. If the same source address sends requests frequently, the monitoring module sends a signal to the communication module to stop receiving abnormal OTA upgrade request data, and re-verifies the source address corresponding to the abnormal OTA upgrade request data through the communication module to ensure the legality and security of the source of the OTA upgrade request data, which can effectively avoid interference to the OTA upgrade process caused by abnormal requests.

[0109] Furthermore, the communication module of the vehicle is also used to cache the received OTA upgrade requests for later processing. If it is necessary to re-detect or process the OTA upgrade requests, they can be obtained from the cache to improve the response speed and processing efficiency of the vehicle system.

[0110] Then, the controller obtains the OTA upgrade package data from the cloud server, and the verification module checks the legality of the OTA upgrade package data. In this application, the verification module calculates the hash value of the OTA upgrade package data using a preset hash algorithm and compares it with the legal hash value stored in the OTA upgrade chip. If the calculated hash value of the OTA upgrade package data is consistent with the legal hash value, it is determined that the OTA upgrade package data is legal data. By verifying the legality of the OTA upgrade package data, the legality and integrity of the OTA upgrade package data are determined;

[0111] Further, before calculating the hash value of the OTA upgrade package data using the preset hash algorithm, it also includes: verifying whether the OTA upgrade package data is legal using the verification formula of digital signature, and the specific process is as follows:

[0112] Before the controller receives the OTA upgrade package data, the cloud server uses the private key to digitally sign the OTA upgrade package data to ensure the authenticity and integrity of the issued OTA upgrade package data; after the controller receives the OTA upgrade package data sent by the cloud server, the verification module verifies the digital signature of the OTA upgrade package data through the public key sent by the cloud server to ensure that the OTA upgrade package data received by the controller is from a legal source address and has not been tampered with. This can effectively prevent malicious OTA upgrade package data from entering the controller. Among them, the verification formula of digital signature is:

[0113] Verify(Signature,Message,PublicKey)=True / False

[0114] In the formula, Verify represents the function, Signature represents the digital signature, Message represents the content of the upgrade package, and PublicKey represents the public key of the sender; if the verification result is False, the verification fails, and the verification module sends a rejection to install the upgrade package to the controller; if the verification result is True, the verification passes, and the verification module sends a command to install the upgrade package to the controller.

[0115] Meanwhile, the monitoring module monitors the behavior of verifying the legality and integrity of the OTA upgrade package. The monitoring data includes the statistics of the hash value calculation duration during the verification process. If the hash value calculation duration is abnormal, the allocation parameters of the computing resources are adjusted to allocate more computing resources for the abnormal hash value calculation or to confirm whether the OTA upgrade chip is normal. In this application, by increasing the allocation ratio of the computing resources of the OTA upgrade chip, the hash value calculation duration is shortened, thereby improving the efficiency of hash value calculation. If the calculated hash value is inconsistent with the hash threshold, the monitoring module sends an operation to the controller to re-obtain the OTA upgrade package data, or re-obtains the OTA upgrade package data from the backup server to ensure the integrity and correctness of the OTA upgrade package and guarantee the smooth progress of the OTA upgrade.

[0116] Next, after the controller obtains the legal OTA upgrade package data, it decompresses the OTA upgrade package data to obtain the decompressed data corresponding to the OTA upgrade package data.

[0117] Furthermore, decompressing the OTA upgrade package data specifically includes:

[0118] Obtain the compression format information in the OTA upgrade package data, determine the required decompression algorithm based on the compression format information to decompress the OTA upgrade package data. Among them, during the decompression process, the monitoring module verifies the decompressed data to ensure the integrity of the decompressed data. Transmit the decompressed data to the target system area and install the decompressed data in the target system area. The monitoring module verifies the decompressed data installed in the target system area to ensure the integrity and accuracy of the decompressed data.

[0119] Specifically, the monitoring module monitors the behavior of decompressing and installing the OTA upgrade package. The monitoring data includes the decompression result, installation order, and installation result. If the abnormal monitoring data is decompression failure, the monitoring module sends a replacement decompression algorithm to the controller, and the controller uses the replaced decompression algorithm to re-decompress the OTA upgrade package or recover some data from the backup. If the abnormal monitoring data is installation failure or installation order anomaly, the monitoring module sends a stop to install the decompressed data to the controller and reinstall the decompressed data to the target system area in the correct order.

[0120] Furthermore, detecting the compressed data during the decompression process can ensure the integrity and accuracy of the decompressed data. In this step, data corruption caused by transmission errors or other reasons can be detected in a timely manner, avoiding installing the damaged data into the target system area, thereby reducing the risk of system failures.

[0121] Determining the installation target system area of the upgrade package and transferring the decompressed upgrade package data to this area can ensure that the upgrade package is accurately installed at the specified location, which helps the orderly management and upgrade of the vehicle system, avoids incorrect installation in other inappropriate areas, and thus ensures the stability and security of the system.

[0122] Finally, install the decompressed data to the target system area to obtain installation data. The monitoring module monitors the system restart after the OTA upgrade package is installed and the behavior of verifying the functions after the upgrade. The monitoring data includes the results of the system pre-check; the abnormal monitoring data is that the proportion of deviations in the results of the system pre-check exceeds the preset threshold; then the monitoring module sends a stop operation for the vehicle system restart to the controller and starts the vehicle system repair program to repair the abnormal file path and / or file type. In this application, a file repair tool can be used to repair specific types of file errors. After the repair is completed, the detection is performed again until the detection passes before allowing the vehicle system to restart, which can effectively avoid system failures caused by deviations in the system detection stage and ensure the normal operation of the system after OTA upgrade.

[0123] After installing the decompressed data to the target system area, comprehensively verifying the installation data can further confirm the correctness and integrity of the installed decompressed data. Through this step, any problems during the installation process can be checked, such as missing files, incomplete installation, or compatibility problems with other system components, etc. Discovering and solving this problem in a timely manner can avoid unexpected failures after the system runs and improve the reliability and stability of the system.

[0124] The vehicle OTA upgrade data processing method provided by the embodiments of this application places the OTA upgrade chip in a preset safe state, and uses the encryption module, verification module, and monitoring module of the OTA upgrade chip to perform encryption processing and legality and integrity verification on the OTA upgrade request, upgrade package, and decompressed data, effectively preventing the intrusion of illegal upgrade packages and ensuring the security of the upgrade process. Calculate the hash value of the upgrade package using the preset hash algorithm and compare it with the legal hash value. Only when the calculated hash value is consistent with the legal hash value, perform subsequent decompression and installation operations, thus ensuring the legality and integrity of the upgrade package and enhancing the stability and reliability of the system.

[0125] Based on the above embodiments, the embodiments of this application provide a vehicle OTA upgrade data processing device. Refer to Figure 5 As shown, the vehicle OTA upgrade data processing device provided by the embodiments of this application at least includes:

[0126] The data acquisition module 510 is used to monitor the OTA upgrade process and acquire the current monitoring data during the OTA upgrade process;

[0127] The data detection module 520 is used to detect the current monitored data based on a pre-trained deviation detection model to determine whether the current monitored data is abnormal;

[0128] The rectification measure module 530 is used to determine the target rectification measure corresponding to the current monitored data and execute the target rectification measure if the current monitored data is abnormal.

[0129] In an optional embodiment, the monitored data includes the monitored data for one or more of the following behaviors during the OTA upgrade process:

[0130] Receiving an OTA upgrade request;

[0131] Verifying the legality and integrity of the OTA upgrade package;

[0132] Unpacking and installing the OTA upgrade package;

[0133] System restart after the OTA upgrade package is installed and verification of the functions after the upgrade.

[0134] In an optional embodiment, the rectification measure module 530 is further used for:

[0135] Pre-determining the correspondence between abnormal monitored data and rectification measures; if the current monitored data is abnormal, matching the target rectification measure corresponding to the current monitored data in the correspondence between abnormal monitored data and rectification measures.

[0136] In an optional embodiment, the rectification measure module 530 is further used for:

[0137] When monitoring the behavior of receiving an OTA upgrade request, the monitored data includes the statistics of the sending frequency of the source address corresponding to the OTA upgrade request;

[0138] The correspondence between abnormal monitored data and rectification measures includes: the abnormal monitored data is that the sending frequency of the source address sending requests is abnormal; the corresponding first rectification measure is to stop receiving abnormal OTA upgrade request data; the corresponding second rectification measure is to re-verify the source address corresponding to the abnormal OTA upgrade request data; the first rectification measure and the second rectification measure are executed synchronously.

[0139] In an optional embodiment, the rectification measure module 530 is further used for:

[0140] When monitoring the behavior of verifying the legality and integrity of the OTA upgrade package, the monitored data includes the statistics of the hash value calculation duration during the verification process;

[0141] The corresponding relationship between the anomaly monitoring data and the rectification measures includes: the anomaly monitoring data is the abnormal duration of hash value calculation; the corresponding third rectification measure is to adjust the allocation parameters of computing resources; the corresponding fourth rectification measure is to confirm whether the OTA upgrade chip is normal; either the third rectification measure or the fourth rectification measure is executed alternatively or synchronously;

[0142] When monitoring the behavior of verifying the legality and integrity of the OTA upgrade package, the monitoring data includes the hash value comparison result during the verification process;

[0143] The corresponding relationship between the anomaly monitoring data and the rectification measures includes: the anomaly monitoring data is the inconsistent hash value comparison; the corresponding fifth rectification measure is to re-download the OTA upgrade package; the corresponding sixth rectification measure is to obtain the OTA upgrade package from the backup server; either the fifth rectification measure or the sixth rectification measure is executed alternatively.

[0144] In an optional embodiment, the rectification measure module 530 is further configured to:

[0145] When monitoring the behavior of decompressing and installing the OTA upgrade package, the monitoring data includes the decompression result, the installation order, and the installation result;

[0146] The corresponding relationship between the anomaly monitoring data and the rectification measures includes: the anomaly monitoring data is the decompression failure; the corresponding seventh rectification measure is to replace the decompression algorithm and re-decompress the OTA upgrade package; the corresponding eighth rectification measure is to restore some data from the backup; either the seventh rectification measure or the eighth rectification measure is executed alternatively;

[0147] The corresponding relationship between the anomaly monitoring data and the rectification measures includes: the anomaly monitoring data is the abnormal installation failure and installation order; the corresponding ninth rectification measure is to suspend the installation and reinstall it in the correct order.

[0148] In an optional embodiment, the rectification measure module 530 is further configured to:

[0149] When monitoring the behavior of system restart after the OTA upgrade package is installed and verifying the functions after the upgrade, the monitoring data includes the system pre-check result;

[0150] The corresponding relationship between the anomaly monitoring data and the rectification measures includes: the anomaly monitoring data is that the proportion of deviations in the system pre-check result exceeds the preset threshold; the corresponding tenth rectification measure is to determine the file path and / or file type corresponding to the abnormal installation data, and determine whether the file path and / or file type is abnormal; if it is abnormal, stop the vehicle system restart operation and start the vehicle system repair program to repair the abnormal file path and / or file type.

[0151] In an optional embodiment, the deviation detection model is a linear binary classification model.

[0152] The device provided in the embodiments of the present application has the same implementation principle and the same technical effects as those in the foregoing method embodiments. For the sake of brief description, for the parts not mentioned in the device embodiments, reference may be made to the corresponding contents in the foregoing method embodiments.

[0153] As Figure 6 shown, an electronic device 600 provided in the embodiments of the present application includes: a processor 601, a memory 602, and a bus. The memory 602 stores machine-readable instructions executable by the processor 601. When the electronic device runs, the processor 601 communicates with the memory 602 through the bus, and the processor 601 executes the machine-readable instructions to perform the steps of the vehicle OTA upgrade data processing method as described above.

[0154] Specifically, the above-mentioned memory 602 and processor 601 can be general-purpose memory and processor, which are not specifically limited here. When the processor 601 runs the computer program stored in the memory 602, it can execute the above-mentioned vehicle OTA upgrade data processing method.

[0155] The processor 601 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit in the hardware of the processor 601 or by instructions in the form of software. The above-mentioned processor 601 may be a general-purpose processor, including a central processing unit (CPU for short), a network processor (NP for short), etc.; it may also be a digital signal processor (DSP for short), an application specific integrated circuit (ASIC for short), a field-programmable gate array (FPGA for short), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as being executed by the hardware decoding processor, or by a combination of the hardware and software modules in the decoding processor. The software module may be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory 602, and the processor 601 reads the information in the memory 602 and combines its hardware to complete the steps of the above method.

[0156] Corresponding to the above vehicle OTA upgrade data processing method, an embodiment of the present application further provides a computer-readable storage medium. The computer-readable storage medium stores machine-executable instructions. When the machine-executable instructions are called and run by a processor, the machine-executable instructions cause the processor to run the steps of the above vehicle OTA upgrade data processing method.

[0157] The vehicle OTA upgrade data processing device provided by the embodiments of the present application may be specific hardware on a device or software or firmware installed on the device, etc. For the device provided by the embodiments of the present application, the implementation principle and the technical effects produced are the same as those of the foregoing method embodiments. For the sake of brief description, for the parts not mentioned in the device embodiments, reference may be made to the corresponding content in the foregoing method embodiments. Those skilled in the art can clearly understand that, for the convenience and simplicity of description, the specific working processes of the foregoing described systems, devices, and units can all refer to the corresponding processes in the above method embodiments, and will not be repeated here.

[0158] In the embodiments provided by the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are only illustrative. For example, the division of units is only a logical function division, and there may be other division methods in actual implementation. For another example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed mutual coupling or direct coupling or communication connection may be through some communication interfaces, and the indirect coupling or communication connection of the devices or units may be in electrical, mechanical or other forms.

[0159] For another example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions, and operations of devices, methods, and computer program products according to multiple embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.

[0160] The unit described as a separation component may or may not be physically separated. The component shown as a unit may or may not be a physical unit, that is, it may be located in one place or may be distributed across multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0161] In addition, each functional unit in the embodiments provided in this application may be integrated in a processing unit, may exist physically separately for each unit, or two or more units may be integrated in one unit.

[0162] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable an electronic device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of each embodiment of this application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.

[0163] It should be noted that: similar reference numerals and letters represent similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. In addition, the terms "first", "second", "third", etc. are only used for descriptive distinction and cannot be understood as indicating or implying relative importance.

[0164] Finally, it should be noted that: the above embodiments are only specific implementation manners of this application, used to illustrate the technical solution of this application, and are not intended to limit it. The protection scope of this application is not limited thereto. Although this application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: any person skilled in the art within the technical scope disclosed in this application can still modify the technical solutions recorded in the foregoing embodiments or can easily think of changes, or perform equivalent replacements for some of the technical features; and these modifications, changes, or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application. All should be covered within the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.

Claims

1. A method for processing vehicle OTA upgrade data, characterized in that Including: Monitor the OTA upgrade process and obtain the current monitoring data during the OTA upgrade process; Detect the current monitoring data based on a pre-trained deviation detection model to determine whether the current monitoring data is abnormal; If the current monitoring data is abnormal, determine the target rectification measure corresponding to the current monitoring data and execute the target rectification measure.

2. The vehicle OTA upgrade data processing method according to claim 1, characterized in that The monitoring data includes monitoring data for one or more of the following behaviors during the OTA upgrade process: Receiving an OTA upgrade request; Verifying the legality and integrity of the OTA upgrade package; Unpacking and installing the OTA upgrade package; System restart after installing the OTA upgrade package and verifying the functions after the upgrade.

3. The vehicle OTA upgrade data processing method according to claim 2, wherein Pre-determine the correspondence between abnormal monitoring data and rectification measures; the step of determining the target rectification measure corresponding to the current monitoring data when the current monitoring data is abnormal includes: When the current monitoring data is abnormal, match the target rectification measure corresponding to the current monitoring data in the correspondence between abnormal monitoring data and rectification measures.

4. The vehicle OTA upgrade data processing method according to claim 3, wherein, When monitoring the behavior of receiving an OTA upgrade request, the monitoring data includes the statistics of the sending frequency of the source address corresponding to the OTA upgrade request; The correspondence between abnormal monitoring data and rectification measures includes: the abnormal monitoring data is that the sending frequency of requests from the source address is abnormal; the corresponding first rectification measure is to stop receiving the abnormal OTA upgrade request data; the corresponding second rectification measure is to re-verify the source address corresponding to the abnormal OTA upgrade request data; the first rectification measure and the second rectification measure are executed synchronously.

5. The vehicle OTA upgrade data processing method according to claim 3, wherein, When monitoring the behavior of verifying the legality and integrity of the OTA upgrade package, the monitoring data includes the statistics of the hash value calculation duration during the verification process; The correspondence between abnormal monitoring data and rectification measures includes: the abnormal monitoring data is that the hash value calculation duration is abnormal; the corresponding third rectification measure is to adjust the allocation parameters of computing resources; the corresponding fourth rectification measure is to confirm whether the OTA upgrade chip is normal; the third rectification measure and the fourth rectification measure are executed alternatively or synchronously; When monitoring the behavior of verifying the legality and integrity of the OTA upgrade package, the monitoring data includes the hash value comparison result during the verification process; The correspondence between abnormal monitoring data and rectification measures includes: the abnormal monitoring data is that the hash value comparison is inconsistent; the corresponding fifth rectification measure is to re-download the OTA upgrade package; the corresponding sixth rectification measure is to obtain the OTA upgrade package from the backup server; the fifth rectification measure and the sixth rectification measure are executed alternatively.

6. The vehicle OTA upgrade data processing method according to claim 3, wherein, When monitoring the behavior of unpacking and installing the OTA upgrade package, the monitoring data includes the unpacking result, the installation order, and the installation result; The corresponding relationship between the abnormal monitoring data and the corrective measures includes: the abnormal monitoring data is decompression failure; the corresponding seventh corrective measure is to replace the decompression algorithm and decompress the OTA upgrade package again; the corresponding eighth corrective measure is to restore some data from the backup; either the seventh corrective measure or the eighth corrective measure is executed. The corresponding relationship between the abnormal monitoring data and the corrective measures includes: the abnormal monitoring data is installation failure and abnormal installation sequence; the corresponding ninth corrective measure is to suspend the installation and reinstall it in the correct order.

7. The vehicle OTA upgrade data processing method according to claim 3, wherein When monitoring the system restart after the installation of the OTA upgrade package and the behavior of verifying the functions after the upgrade, the monitoring data includes the system pre-check result. The corresponding relationship between the abnormal monitoring data and the corrective measures includes: the abnormal monitoring data is that the proportion of deviations in the system pre-check result exceeds the preset threshold; the corresponding tenth corrective measure is to determine the file path and / or file type corresponding to the abnormal installation data, and determine whether the file path and / or the file type is abnormal; if it is abnormal, stop the vehicle system restart operation and start the vehicle system repair program to repair the abnormal file path and / or the file type.

8. The vehicle OTA upgrade data processing method according to any one of claims 1-7, characterized in that The deviation detection model is a linear binary classification model.

9. A vehicle OTA upgrade data processing device, characterized in that, It includes: A data acquisition module, which is used to monitor the OTA upgrade process and acquire the current monitoring data during the OTA upgrade process. A data detection module, which is used to detect the current monitoring data based on a pre-trained deviation detection model to determine whether the current monitoring data is abnormal. A corrective measure module, which is used to determine the target corrective measure corresponding to the current monitoring data and execute the target corrective measure if the current monitoring data is abnormal.

10. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein, When the processor executes the computer program, it implements the steps of the vehicle OTA upgrade data processing method described in any one of claims 1 to 8 above.