ECU software mode switching and test verification method and device, equipment and storage medium

By designing diagnostic instructions to control the mode switching and test verification of the ECU, the problem that ECU software is difficult to maintain stably in Boot mode is solved, and an efficient test verification process is realized, which improves testing efficiency and reduces the risk of hardware damage.

CN120469918APending Publication Date: 2025-08-12VOYAH AUTOMOBILE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510539148.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-27
Publication Date
2025-08-12

AI Technical Summary

Technical Problem

In the prior art, ECU software is difficult to maintain stably after switching to Boot mode, resulting in interruption or failure of tests, and the mode switching is complex and there is a risk of hardware damage, reducing the testing efficiency.

Method used

By designing diagnostic instructions based on unified diagnostic service, the operation status of the ECU and the valid flag bit of the application software are detected, the ECU is controlled to switch or maintain the programming session mode under specific conditions, and test and verify in different modes.

Benefits of technology

It realizes stable Boot mode maintenance and mode switching of ECU software when the App software is effective, improves the efficiency of automotive software testing and verification, and avoids the risks of complex operations and hardware damage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120469918A_ABST
    Figure CN120469918A_ABST
Patent Text Reader

Abstract

The invention discloses an ECU software mode switching and test verification method and device, equipment and a storage medium, and relates to the technical field of automobile software, and the method comprises the steps: designing a diagnosis instruction based on a unified diagnosis service; controlling an electronic control unit to perform mode switching according to the diagnosis instruction or maintaining a programming session mode when the application software is valid; and testing and verifying the electronic control unit in different modes. According to the method and the device, the ECU software can be maintained in the Boot mode or perform mode switching under the condition that the App software is effective through the control of the specific diagnosis instruction, so that the efficiency of automobile software test verification can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of automotive software technology, and in particular to ECU software mode switching and test verification methods, devices, equipment, and storage media. Background Art

[0002] The electronic control unit (ECU) of a car plays a key role in controlling the vehicle's operation. Boot mode, also known as programming session mode, is a critical stage in the ECU's software lifecycle, primarily used for operations such as system initialization and software upgrades. In practical applications, ECU software sometimes needs to remain in Boot mode for specific debugging, diagnosis, or to address special operating conditions. For example, during the UDS protocol-based bootloader software testing process, engineers typically require the ECU to remain stably in Boot mode in order to execute various UDS diagnostic service-related tests in Boot mode. However, in actual testing, when the ECU is switched to Boot mode via a diagnostic instruction (such as 0x10 0x02 to enter a programming session), since the App software is always present and valid, the ECU will automatically return to App mode upon power-on, reset, or session timeout, and will be unable to effectively remain in Boot mode, resulting in test interruption or failure.

[0003] Currently, traditional ECU software struggles to maintain Boot mode after entering normal operating mode, creating significant inconvenience for debugging and diagnostics. Without effective maintenance of ECU software in Boot mode, re-entering Boot mode once the system enters normal operating mode often requires complex hardware manipulation or triggering with specialized external devices. This is not only inefficient but also carries the risk of hardware damage or system failure. Summary of the Invention

[0004] The main purpose of this application is to provide an ECU software mode switching and test verification method, device, equipment and storage medium, aiming to solve the technical problem of how to improve the efficiency of automobile software testing and verification.

[0005] To achieve the above objectives, the present application proposes an ECU software mode switching and test verification method, the method comprising:

[0006] Design diagnostic instructions based on unified diagnostic services;

[0007] controlling the electronic control unit to switch modes according to the diagnostic instructions or to maintain a programming session mode when the application software is valid;

[0008] The electronic control unit is tested and verified in different modes.

[0009] In one embodiment, the step of controlling the electronic control unit to switch modes according to the diagnostic instruction or to maintain the programming session mode when the application software is valid includes:

[0010] Detect the operating status of the electronic control unit and the valid flag of the application software;

[0011] When the running state and the valid flag of the application software meet a first preset condition, controlling the electronic control unit to enter a programming session mode according to the diagnostic instruction and maintaining the programming session mode when the application software is valid;

[0012] When the operating state and the application software valid flag meet a second preset condition, the electronic control unit is controlled to switch from the programming session mode to the application software mode according to the diagnostic instruction.

[0013] In one embodiment, when the operating state and the application software valid flag meet a first preset condition, the step of controlling the electronic control unit to enter a programming session mode according to the diagnostic instruction and maintaining the programming session mode when the application software is valid includes:

[0014] When the running state is that the application software is running normally and the application software valid flag is valid, determining that the running state and the application software valid flag meet a first preset condition, and controlling the electronic control unit to enter a programming session mode according to the diagnostic instruction;

[0015] When the application software is valid, security authentication is performed through a security access service, and a routine is started according to the diagnostic instruction;

[0016] When the routine is started, the application software valid flag is modified from valid to invalid, so that the electronic control unit maintains the programming session mode when the application software is valid.

[0017] In one embodiment, the step of modifying the application software valid flag from valid to invalid when the routine is started so that the electronic control unit maintains the programming session mode when the application software is valid includes:

[0018] When the routine is started, the valid flag of the application software is changed from valid to invalid;

[0019] The electronic control unit is controlled to continuously run a preset program so that the electronic control unit maintains the programming session mode when the application software is valid.

[0020] In one embodiment, when the operating state and the application software valid flag meet a second preset condition, the step of controlling the electronic control unit to switch from the programming session mode to the application software mode according to the diagnostic instruction includes:

[0021] When the running state is normal operation in programming session mode and the application software valid flag is invalid, determining that the running state and the application software valid flag meet a second preset condition, and performing security authentication through a security access service;

[0022] When the authentication is successful, the routine is closed according to the diagnostic instruction, and the valid flag of the application software is changed from invalid to valid;

[0023] When it is detected that the electronic control unit programming session times out or is powered on or reset, the electronic control unit is controlled to switch from the programming session mode to the application software mode.

[0024] In one embodiment, the step of testing and verifying the electronic control unit in different modes includes:

[0025] When the electronic control unit is in the programming session mode, testing and verifying the functionality of a preset program of the electronic control unit;

[0026] When the electronic control unit is in the application software mode, the actual control function of the electronic control unit is tested and verified.

[0027] In one embodiment, the step of designing a diagnostic instruction based on a unified diagnostic service includes:

[0028] Based on the unified diagnostic service, the routine control diagnostic service is used in conjunction with the sub-function definition to obtain the instructions for controlling the opening and closing of the routine;

[0029] Obtaining the control mode switching instruction through data identifier positioning;

[0030] The control on and off routine instructions and the control mode switching instructions are used as diagnosis instructions.

[0031] In addition, to achieve the above-mentioned purpose, the present application also proposes an ECU software mode switching and test verification device, which includes:

[0032] An instruction design module, used to design diagnostic instructions based on the unified diagnostic service;

[0033] a mode switching module, configured to control the electronic control unit to switch modes according to the diagnostic instruction or to maintain a programming session mode when the application software is valid;

[0034] The test and verification module is used to test and verify the electronic control unit in different modes.

[0035] In addition, to achieve the above-mentioned purpose, the present application also proposes an ECU software mode switching and test verification device, which includes: a memory, a processor, and a computer program stored on the memory and runnable on the processor, and the computer program is configured to implement the steps of the ECU software mode switching and test verification method as described above.

[0036] In addition, to achieve the above-mentioned purpose, the present application also proposes a storage medium, which is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by the processor, the steps of the ECU software mode switching and test verification method described above are implemented.

[0037] In addition, to achieve the above-mentioned purpose, the present application also provides a computer program product, which includes a computer program, and when the computer program is executed by a processor, it implements the steps of the ECU software mode switching and test verification method as described above.

[0038] One or more technical solutions proposed in this application have at least the following technical effects:

[0039] This application uses specific diagnostic instruction control to enable ECU software to maintain in Boot mode or switch modes when the App software is valid, solving the technical problems that erasing and re-downloading App software through flashing methods is often complicated and there is a risk of damage to ECU software / hardware, and because App mode and Boot mode cannot be switched conveniently and effectively, the test and verification in the two modes can only be performed separately, which greatly reduces the efficiency of the test. Compared with the existing technology, this application can improve the efficiency of automobile software testing and verification. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0041] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0042] Figure 1 A flowchart illustrating the first embodiment of the ECU software mode switching and test verification method of this application is provided;

[0043] Figure 2 A flowchart illustrating the second embodiment of the ECU software mode switching and test verification method of this application is provided;

[0044] Figure 3 Flowchart of maintaining the ECU software in Boot mode provided in Example 2 of this application;

[0045] Figure 4 This is a flowchart of the ECU software exiting Boot mode provided in Example 2 of this application;

[0046] Figure 5 A flowchart illustrating the third embodiment of the ECU software mode switching and test verification method of this application is provided;

[0047] Figure 6 A flowchart illustrating a fourth embodiment of the ECU software mode switching and test verification method of the present application is provided;

[0048] Figure 7 This is a schematic diagram of the module structure of the ECU software mode switching and test verification device according to an embodiment of the present application;

[0049] Figure 8 Schematic diagram of the device structure of the hardware operating environment involved in the ECU software mode switching and test verification method in the embodiment of the present application.

[0050] The purpose, features and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION

[0051] It should be understood that the specific embodiments described herein are merely used to explain the technical solutions of the present application and are not intended to limit the present application.

[0052] In order to better understand the technical solution of the present application, a detailed description will be given below in conjunction with the accompanying drawings and specific implementation methods.

[0053] The main solutions of the embodiments of the present application are: designing diagnostic instructions based on a unified diagnostic service; controlling the electronic control unit to switch modes or maintain the programming session mode when the application software is valid according to the diagnostic instructions; and testing and verifying the electronic control unit in different modes.

[0054] In this embodiment, for ease of description, the following description is made with the ECU software mode switching and the internal actuator of the test verification system as the execution subject.

[0055] Because the existing technology of erasing and re-downloading App software through flashing methods is often complicated and there is a risk of damage to the ECU software / hardware, and because App mode and Boot mode cannot be switched conveniently and effectively, test verification in the two modes can only be performed separately, which greatly reduces test efficiency.

[0056] This application provides a solution that, through specific diagnostic instruction control, enables ECU software to remain in Boot mode or switch modes when the App software is valid, thereby improving the efficiency of automotive software testing and verification.

[0057] It can be seen from the above embodiments that the present application uses specific diagnostic instruction control to enable the ECU software to maintain in Boot mode or switch modes when the App software is valid, thereby solving the problems that the operation of erasing and re-downloading the App software through the flashing method is often complicated and there is a risk of damage to the ECU software / hardware, and the technical problem that the App mode and Boot mode cannot be switched conveniently and effectively, so that the test verification in the two modes can only be performed separately, which greatly reduces the efficiency of the test. This can improve the efficiency of automobile software testing and verification.

[0058] It should be noted that the execution subject of this embodiment may be a computing service device with data processing, network communication, and program execution capabilities, such as a tablet computer, personal computer, mobile phone, or other electronic device capable of performing the aforementioned functions. This embodiment and the following embodiments will be described below using the internal actuator of an ECU software mode switching and test verification system as an example.

[0059] Based on this, the embodiment of the present application provides an ECU software mode switching and test verification method, referring to Figure 1 , Figure 1 This is a flow chart of the first embodiment of the ECU software mode switching and test verification method of this application.

[0060] In this embodiment, the ECU software mode switching and test verification method includes steps S10 to S30:

[0061] Step S10: designing a diagnostic instruction based on the unified diagnostic service.

[0062] It should be noted that Unified Diagnostic Services (UDS), also known as the UDS protocol, is a universal automotive diagnostic protocol defined by ISO 15765 and ISO 14229. Diagnostic tools connect to all UDS-enabled ECUs in the vehicle. The service ID (SID) and related parameters are contained in the eight data bytes of the CAN data frames sent by the diagnostic tool. It uses a request / response mechanism based on a client / server architecture. Diagnostic messages are event-triggered, with the client sending a diagnostic request and the server responding based on the request message. It uses both physical and functional addressing. Services include diagnostic session control, ECU reset, fault code reading and clearing, data identification reading, security access, and programming services.

[0063] Additionally, it should be noted that the diagnostic instruction is an instruction for dynamically controlling the opening and closing of the Boot mode of the ECU.

[0064] Step S20 : controlling the electronic control unit to switch modes according to the diagnostic instruction or maintaining the programming session mode when the application software is valid.

[0065] It should be noted that the Electronic Control Unit (ECU) is the core component of the automobile control system. It can collect automobile operating status information such as engine speed and vehicle speed through sensors, and then process and analyze this data according to preset programs and algorithms to determine the automobile's working status. It then sends control instructions to the actuators, such as controlling the injection timing of the injector and the ignition timing of the ignition coil, so as to accurately control various systems of the automobile.

[0066] Additionally, it's important to note that the automotive ECU's programming session mode, also known as Boot mode, is a special operating mode used for program updates, repairs, or low-level operations on the ECU. When the ECU enters Boot mode, it runs the Bootloader program, which is responsible for initializing the hardware, establishing communication interfaces, and operating the ECU's memory according to received instructions. Within the UDS diagnostic service, specific commands, such as the Diagnostic Session Control Service $10 02, can be used to enter programming session mode, or Boot mode, allowing firmware updates. In programming session mode, many diagnostic services, such as those associated with flashing, $11, $22, $2E, $31, $28, $34, $36, $37, and $85, can execute normally. Entering Boot mode typically requires specific conditions and methods. For example, the ECU enters this mode after receiving a specific trigger signal or meeting specific conditions, or by sending a command through a specific diagnostic tool. This mode plays a key role in software upgrades and fault repairs of automotive ECUs. It can achieve functional upgrades, performance optimization, or repair software vulnerabilities. At the same time, to ensure security, there are usually mechanisms such as secure access verification to prevent unauthorized modifications and potential security risks.

[0067] Additionally, it's important to note that mode switching involves switching the ECU between App mode and Boot mode. App mode, or application software mode, refers to a mode whereby applications on a mobile phone or in-vehicle terminal control and manage vehicle-related functions, as well as provide various services and information.

[0068] Step S30: testing and verifying the electronic control unit in different modes.

[0069] In App mode, the ECU can be remotely controlled and monitored using a mobile phone or in-vehicle terminal application. Its responsiveness can be tested by executing remote control commands such as starting the vehicle and unlocking the doors. The accuracy of vehicle status information such as battery level and tire pressure can be checked to verify communication between the ECU and the App and its actual control functions. This allows for early detection of potential faults and anomalies, ensuring a better user experience and avoiding safety hazards and inconveniences caused by functional anomalies. In Boot mode, specialized diagnostic equipment is used to communicate with the ECU, sending specific diagnostic commands to test the ECU's ability to enter the programming state, execute program updates, initialize hardware, establish communication interfaces, and perform memory read and write operations. This also verifies the effectiveness of the security access mechanism, ensuring accurate program updates and preventing unauthorized access and operation. This lays the foundation for functional upgrades, performance optimization, and troubleshooting of automotive electronic systems, maintaining the overall safety and reliability of the vehicle.

[0070] This embodiment provides an ECU software mode switching and test verification method. Through specific diagnostic instruction control, the ECU software can be maintained in Boot mode or switch modes when the App software is valid. This solves the technical problems that erasing and re-downloading the App software through the flashing method is often complicated and there is a risk of damage to the ECU software / hardware. In addition, since the App mode and Boot mode cannot be switched quickly and effectively, the test verification in the two modes can only be performed separately, which greatly reduces the test efficiency. This can improve the efficiency of automobile software testing and verification.

[0071] Based on the first embodiment of the present application, in the second embodiment of the present application, the same or similar contents as those in the above embodiment 1 can be referred to the above introduction and will not be described in detail later. Figure 2 , step S20 includes steps S21 to S23:

[0072] Step S21 , detecting the operating status of the electronic control unit and the valid flag of the application software.

[0073] It's important to note that the application software valid flag is a binary bit or set of bits used to identify whether the application software in the vehicle's ECU is valid. In automotive electronic systems, the ECU stores the application software code. Once the software has been correctly downloaded and burned into the ECU memory and passes integrity checks (such as checksum verification), this flag is set to a specific state (usually "valid"), indicating that the stored application software is complete and operational. When the ECU boots up, it first checks this flag. If the flag indicates valid, the ECU loads and runs the corresponding application software. If the flag indicates invalid, the ECU may adopt default program execution, report an error, or enter a specific repair mode to ensure the safety and stability of the vehicle system. Furthermore, this flag is updated during software updates. After the new software is successfully installed and verified, the flag is updated to indicate that the new software is valid.

[0074] Detecting the operating status of the electronic control unit means detecting whether the ECU is operating normally in App mode or Boot mode.

[0075] Step S22, when the operating state and the valid flag of the application software meet a first preset condition, controlling the electronic control unit to enter a programming session mode according to the diagnostic instruction and maintaining the programming session mode when the application software is valid.

[0076] It should be noted that the first pre-condition is that the ECU operates normally under the application software and the application software valid flag is valid.

[0077] In a feasible implementation, step S22 may include steps S221 to S223:

[0078] Step S221, when the running state is that the application software is running normally and the application software valid flag is valid, determine that the running state and the application software valid flag meet a first preset condition, and control the electronic control unit to enter a programming session mode according to the diagnostic instruction.

[0079] When it is detected that the ECU is running normally under the application software and the application software valid flag Flag_AppSoftwareValid=1 (valid), the ECU receives the 0x10 02 programming session diagnostic instruction in the extended session mode and enters the programming session mode, that is, the Boot mode.

[0080] Step S222: When the application software is valid, security authentication is performed through a security access service, and a routine is started according to the diagnostic instruction.

[0081] It should be noted that the Secure Access Service is the UDS Secure Access Service ($27), a key service in the Unified Diagnostic Services (UDS) protocol used to control access to restricted data and diagnostic services in automotive ECUs. Its primary purpose is to grant access rights to users before modifying ECU data stored in memory, thereby providing a method for accessing information and / or diagnostic services that are restricted for safety, emissions, or security reasons. For example, diagnostic services used to download / upload routines or information to a server and read specific memory locations from a server require secure access because improper programs or information could damage the ECU or jeopardize the vehicle's compliance with emissions, safety, or security standards.

[0082] When designing the ECU software to enable / disable the boot mode maintenance function, confidentiality and security factors must be considered. The $27 secure access service provides a method to facilitate access to restricted data or diagnostic services. Therefore, the operation of enabling / disabling this function must be considered under the condition that secure access (ECU unlocking) is passed before control is executed.

[0083] When the ECU is in Boot mode, it must complete Level FBL security authentication through the UDS secure access service ($27). Only after successful unlocking can the next step be performed.

[0084] Step S223, when the routine is started, the application software valid flag is modified from valid to invalid, so that the electronic control unit maintains the programming session mode when the application software is valid.

[0085] When the ECU receives the control diagnosis instruction start routine of 0x31 01C2 02 under the unlock condition, the application software valid flag in the memory will be changed to Flag_AppSoftwareValid=0 (invalid).

[0086] In a feasible implementation, step S223 may include steps S01 to S02:

[0087] Step S01, when the routine is started, the valid flag of the application software is changed from valid to invalid.

[0088] After the ECU starts the routine according to the instruction, it changes the application software validity flag in the memory from Flag_AppSoftwareValid=1 (valid) to Flag_AppSoftwareValid=0 (invalid).

[0089] Step S02 : controlling the electronic control unit to continuously run a preset program so that the electronic control unit maintains the programming session mode when the application software is valid.

[0090] After the application software valid flag is changed from valid to invalid, it is written to the Flash synchronously to ensure that the data is not lost during power failure. The ECU software will be locked in Boot mode and continue to run the Bootloader program, thus maintaining the Boot mode.

[0091] After changing the application software valid flag from valid to invalid, if the ECU programming session times out, the ECU will not exit Boot mode and enter App mode because the application software valid flag is set to 0 (i.e., the application software is invalid). When the ECU is powered on / reset again, it will detect that the application software is invalid and will continue to execute the Bootloader program, thus maintaining the ECU in Boot mode.

[0092] The ECU software is maintained in Boot mode as shown in the flowchart Figure 3 As shown, it includes: step 1, ECU runs application software, and the application software valid flag is valid; step 2, enters programming session mode according to the instruction; performs security authentication according to the instruction, if unsuccessful, the security access is not passed, and if successful, the security access Level FBL is unlocked; starts the routine according to the instruction, if unsuccessful, the boot mode maintenance fails, and if successful, the application software valid flag is invalid; step 4, the ECU remains in Boot mode and is not affected by power-on, reset, or programming session timeout.

[0093] By setting the valid flag of the application software to keep the ECU in Boot mode, it is possible to avoid the mode being switched during ECU test verification.

[0094] By changing the setting of the application software valid flag, the application software inside the ECU can disable / restore its self-start function, thereby improving the efficiency of automobile software testing and verification.

[0095] Step S23 , when the operating state and the application software valid flag meet a second preset condition, controlling the electronic control unit to switch from the programming session mode to the application software mode according to the diagnostic instruction.

[0096] It should be noted that the second precondition is that the ECU operates normally in Boot mode and the application software valid flag is invalid.

[0097] In a feasible implementation, step S23 may include steps S231 to S233:

[0098] Step S231, when the running state is normal running in programming session mode and the application software valid flag is invalid, determine that the running state and the application software valid flag meet a second preset condition, and perform security authentication through a security access service.

[0099] When it is detected that the ECU is operating normally in Boot mode and the application software valid flag Flag_AppSoftwareValid = 0 (invalid), the ECU completes the LevelFBL level security authentication through the UDS security access service ($27) in Boot mode, that is, it can proceed to the next step only after the unlocking is successful.

[0100] Step S232: When the authentication is successful, the routine is closed according to the diagnostic instruction, and the valid flag of the application software is changed from invalid to valid.

[0101] When the ECU receives the 0x31 03C2 02 shutdown routine control diagnostic instruction under unlocking conditions, it will modify the application software valid flag in the memory from Flag_AppSoftwareValid=0 (invalid) to Flag_AppSoftwareValid=1 (valid).

[0102] Step S233 : When it is detected that the electronic control unit programming session times out or is powered on or reset, the electronic control unit is controlled to switch from the programming session mode to the application software mode.

[0103] Because the application software valid flag is Flag_AppSoftwareValid=1 (valid), when power is recycled, reset, or the programming session times out, the ECU software will unlock and exit the Boot mode and run the application software, thereby returning to the App mode.

[0104] The flowchart of ECU software exiting Boot mode is as follows Figure 4 As shown, it includes: step 1, the ECU runs the Bootloader software, and the application software valid flag is invalid; security authentication is performed according to the instruction, if it fails, the security access is not passed, and if it succeeds, it enters step 2, the security access Level FBL is unlocked; according to the instruction, the routine is started, if it fails, the failure to maintain the Boot mode is closed, and if it succeeds, the application software valid flag is enabled; step 3, power is re-applied, reset, and the programming session times out, and the ECU returns to the App mode to run the application software.

[0105] By changing the setting of the application software valid flag, the application software inside the ECU can disable / restore its self-start function, thereby improving the efficiency of automobile software testing and verification.

[0106] This embodiment provides an ECU software mode switching and test verification method, which detects the operating status of an electronic control unit and the valid flag of the application software; when the operating status and the valid flag of the application software meet a first preset condition, the electronic control unit is controlled to enter a programming session mode according to the diagnostic instruction and maintain the programming session mode when the application software is valid; when the operating status and the valid flag of the application software meet a second preset condition, the electronic control unit is controlled to switch from the programming session mode to the application software mode according to the diagnostic instruction, which can improve the efficiency of automobile software testing and verification.

[0107] Based on the first embodiment of the present application, in the third embodiment of the present application, the same or similar contents as those in the above embodiment 1 can be referred to the above introduction and will not be described in detail later. Figure 5 , step S30 includes steps S31 to S32:

[0108] Step S31 : When the electronic control unit is in the programming session mode, the function of the preset program of the electronic control unit is tested and verified.

[0109] It should be noted that the preset program is the Bootloader program, which is a special software that runs first when the electronic control unit (ECU) is started. It mainly has the functions of initializing hardware, booting the operating system or application, providing basic communication functions, implementing software updates and upgrades, and performing security verification.

[0110] When the ECU is in the Boot mode, the function of the ECU's Bootloader program is tested and verified. The test and verification can ensure that the Bootloader program correctly initializes the ECU's hardware resources, so that each hardware module can work normally and provide a stable hardware environment for subsequent software operation. At the same time, it can also ensure that the various parameters and configurations of the software are correctly loaded during the startup process, ensuring the normal implementation of the software functions. Ensure the reliability of the communication function: Through test and verification, it can be confirmed whether the communication function of the Bootloader program and external devices is normal. This helps to ensure that the ECU can exchange data with diagnostic equipment, programming tools, etc. in a stable and accurate manner during the production, maintenance and upgrade of the vehicle, and realize effective control and management of the ECU. Testing and verifying the security mechanism of the Bootloader program can ensure that it has effective security protection capabilities. For example, by verifying the security access function, unauthorized devices can be prevented from illegally accessing and operating the ECU, protecting the security and stability of the vehicle's electronic system, and avoiding safety hazards caused by malicious attacks or misoperation.

[0111] Step S32 : When the electronic control unit is in the application software mode, the actual control function of the electronic control unit is tested and verified.

[0112] Testing and verifying the actual control functions of the ECU when it is in App mode can ensure that the ECU accurately controls the vehicle's systems and components in the actual operating environment according to design requirements, ensure the normal operation of key functions such as the vehicle's power system, braking system, and air-conditioning system, improve the vehicle's overall performance and reliability, and promptly discover potential problems such as control logic errors, response delays, and execution deviations for timely optimization and improvement. It can also verify the compatibility and collaborative working capabilities between the ECU and other electronic equipment in the vehicle, ensure the stability and consistency of the entire vehicle's electronic system, and provide strong protection for the vehicle's safety, comfort, and efficiency. It also helps to meet relevant industry standards and regulatory requirements and improve product quality and market competitiveness.

[0113] This embodiment provides an ECU software mode switching and test verification method, which tests and verifies the functions of the preset program of the electronic control unit when the electronic control unit is in the programming session mode; and tests and verifies the actual control function of the electronic control unit when the electronic control unit is in the application software mode, thereby improving the efficiency of automobile software testing and verification.

[0114] Based on the first embodiment of the present application, in the fourth embodiment of the present application, the same or similar contents as those in the above embodiment 1 can be referred to the above introduction and will not be described in detail later. Figure 6 , step S10 includes steps S11 to S13:

[0115] Step S11 : Based on the unified diagnostic service, the routine control diagnostic service is coordinated with the sub-function definition to obtain instructions for controlling the opening and closing of the routine.

[0116] It's important to note that sub-function definitions refer to the ability to implement diverse operations by assigning different sub-function codes to the routine control diagnostic service. Different sub-function codes correspond to different types of operations. For example, when the sub-function code is 0x01, it indicates a routine start. The diagnostic device uses this sub-function code to send a request to the ECU, instructing it to begin executing a specific routine.

[0117] Based on the UDS diagnostic service, a dedicated diagnostic instruction set is designed to achieve dynamic control of the opening and closing of the ECU Boot mode. For example, the $31 routine control diagnostic service is customized with sub-functions and DID. Corresponding to the routine control type, the sub-functions 0x01 and 0x03 are used to respectively realize the opening and closing of the ECU software's Boot mode maintenance function; 0x01: StartRoutine (opening the routine) and 0x03: StopRoutine (closing the routine) are defined.

[0118] Step S12: obtaining the control mode switching instruction through data identifier positioning.

[0119] It's important to note that the Data Identifier (DID) is a crucial component of the UDS (Unified Diagnostic Services) protocol, used to uniquely identify a specific data block or parameter within an ECU (Electronic Control Unit). It's typically a 16-bit (2-byte) hexadecimal value ranging from 0x0000 to 0xFFFF. Using the DID, a diagnostic tool can accurately read or write data from the ECU, such as sensor values, configuration parameters, and calibration values.

[0120] Define the Boot mode control routine through a custom routine DID (such as 0xC202) to achieve reliable switching of ECU software between Boot mode and App mode.

[0121] Step S13: Using the control start and stop routine instructions and the control mode switching instructions as diagnosis instructions.

[0122] After customizing the instructions for controlling the opening and closing routines and the instructions for controlling mode switching, these instructions are aggregated into a set and used as diagnostic instructions.

[0123] This embodiment provides an ECU software mode switching and test verification method, which is based on a unified diagnostic service, and obtains instructions for controlling the opening and closing of routines through routine control diagnostic services in conjunction with sub-function definitions; obtains instructions for controlling mode switching through data identifier positioning; and uses the instructions for controlling the opening and closing of routines and the instructions for controlling mode switching as diagnostic instructions to improve the efficiency of automobile software testing and verification.

[0124] It should be noted that the above examples are only used to understand this application and do not constitute a limitation on the ECU software mode switching and test verification method of this application. More forms of simple transformations based on this technical concept are all within the scope of protection of this application.

[0125] This application also provides an ECU software mode switching and test verification device, please refer to Figure 7 , the device comprises:

[0126] The instruction design module 10 is used to design diagnostic instructions based on the unified diagnostic service.

[0127] The mode switching module 20 is used to control the electronic control unit to switch modes according to the diagnostic instruction or to maintain the programming session mode when the application software is valid.

[0128] The test and verification module 30 is used to test and verify the electronic control unit in different modes.

[0129] In one embodiment, the mode switching module 20 is further used to detect the operating status of the electronic control unit and the valid flag of the application software; when the operating status and the valid flag of the application software meet a first preset condition, the electronic control unit is controlled to enter the programming session mode according to the diagnostic instruction and maintain the programming session mode when the application software is valid; when the operating status and the valid flag of the application software meet a second preset condition, the electronic control unit is controlled to switch from the programming session mode to the application software mode according to the diagnostic instruction.

[0130] In one embodiment, the mode switching module 20 is further used to determine that the operating state and the application software valid flag meet a first preset condition when the operating state is normal operation of the application software and the application software valid flag is valid, and control the electronic control unit to enter the programming session mode according to the diagnostic instruction; when the application software is valid, perform security authentication through the security access service, and start the routine according to the diagnostic instruction; when the routine is started, modify the application software valid flag from valid to invalid, so that the electronic control unit maintains the programming session mode when the application software is valid.

[0131] In one embodiment, the mode switching module 20 is further used to change the application software validity flag from valid to invalid when the routine is started; and control the electronic control unit to continuously run a preset program so that the electronic control unit maintains the programming session mode when the application software is valid.

[0132] In one embodiment, the mode switching module 20 is further used to determine that the operating state and the application software valid flag meet a second preset condition when the operating state is normal operation of the programming session mode and the application software valid flag is invalid, and perform security authentication through a security access service; when the authentication is successful, close the routine according to the diagnostic instruction, and change the application software valid flag from invalid to valid; when it is detected that the electronic control unit programming session has timed out or is powered on or reset, control the electronic control unit to switch from the programming session mode to the application software mode.

[0133] In one embodiment, the test verification module 30 is further used to test and verify the function of the preset program of the electronic control unit when the electronic control unit is in the programming session mode; and to test and verify the actual control function of the electronic control unit when the electronic control unit is in the application software mode.

[0134] In one embodiment, the instruction design module 10 is also used to obtain instructions for controlling the opening and closing of routines based on a unified diagnostic service through routine control diagnostic services in conjunction with sub-function definitions; obtain instructions for controlling mode switching through data identifier positioning; and use the instructions for controlling the opening and closing of routines and the instructions for controlling mode switching as diagnostic instructions.

[0135] The ECU software mode switching and test verification device provided in this application, which employs the ECU software mode switching and test verification method of the aforementioned embodiment, can solve the technical problem of improving the efficiency of automotive software testing and verification. Compared with the prior art, the beneficial effects of the ECU software mode switching and test verification device provided in this application are the same as those of the ECU software mode switching and test verification method provided in the aforementioned embodiment. Other technical features of the ECU software mode switching and test verification device are the same as those disclosed in the aforementioned embodiment method and are not further described here.

[0136] The present application provides an ECU software mode switching and test verification device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the ECU software mode switching and test verification method in the above-mentioned embodiment one.

[0137] Reference below Figure 8 , which shows a schematic diagram of the structure of an ECU software mode switching and test verification device suitable for implementing the embodiments of the present application. The ECU software mode switching and test verification device in the embodiments of the present application can include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions), PMPs (Portable Media Players), in-vehicle terminals (such as in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 8 The ECU software mode switching and test verification device shown is merely an example and should not impose any limitations on the functions and scope of use of the embodiments of the present application.

[0138] like Figure 8 As shown, the ECU software mode switching and test verification device may include a processing device 1001 (such as a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to the program stored in the ROM (Read Only Memory) 1002 or the program loaded from the storage device 1003 to the RAM (Random Access Memory) 1004. Various programs and data required for the operation of the automatic flashing overtaking lights and automatic horn equipment in the smart driving are also stored in RAM1004. The processing device 1001, ROM1002 and RAM1004 are connected to each other via a bus 1005. The input / output (I / O) interface 1006 is also connected to the bus. Typically, the following systems can be connected to I / O interface 1006: input device 1007 including, for example, a touch screen, touchpad, keyboard, mouse, image sensor, microphone, accelerometer, gyroscope, etc.; output device 1008 including, for example, an LCD (Liquid Crystal Display), speaker, vibrator, etc.; storage device 1003 including, for example, a magnetic tape, hard disk, etc.; and communication device 1009. Communication device 1009 can allow the ECU software mode switching and test verification device to communicate wirelessly or wired with other devices to exchange data. Although the figure shows an ECU software mode switching and test verification device with various systems, it should be understood that it is not required to implement or have all of the systems shown. More or fewer systems may be implemented or have instead.

[0139] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program comprising program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via a communication device, or installed from a storage device 1003, or installed from a ROM 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the method of the embodiment disclosed in the present application are executed.

[0140] The ECU software mode switching and test verification device provided in this application, which employs the ECU software mode switching and test verification method of the aforementioned embodiment, can solve the technical problem of improving the efficiency of automotive software testing and verification. Compared with the prior art, the beneficial effects of the ECU software mode switching and test verification device provided in this application are the same as those of the ECU software mode switching and test verification method provided in the aforementioned embodiment. Other technical features of the ECU software mode switching and test verification device are the same as those disclosed in the method of the aforementioned embodiment and are not further elaborated here.

[0141] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any one or more embodiments or examples in a suitable manner.

[0142] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

[0143] The present application provides a computer-readable storage medium having computer-readable program instructions (ie, a computer program) stored thereon, the computer-readable program instructions being used to execute the ECU software mode switching and test verification method in the above-mentioned embodiment.

[0144] The computer-readable storage medium provided in this application may be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, systems or devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, RAM (Random Access Memory), ROM (Read Only Memory), EPROM (Erasable Programmable Read Only Memory or flash memory), optical fiber, CD-ROM (CD-Read Only Memory), optical storage device, magnetic storage device, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, system or device. The program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.

[0145] The computer-readable storage medium may be included in the ECU software mode switching and test verification device; or it may exist independently without being assembled into the ECU software mode switching and test verification device.

[0146] The above-mentioned computer-readable storage medium carries one or more programs. When the above-mentioned one or more programs are executed by the ECU software mode switching and test verification device, the ECU software mode switching and test verification device: designs diagnostic instructions based on a unified diagnostic service; controls the electronic control unit to switch modes or maintain a programming session mode when the application software is valid according to the diagnostic instructions; and tests and verifies the electronic control unit in different modes.

[0147] The computer program code for performing the operations of the present application can be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer can be connected to the user's computer through any type of network, including a LAN (Local Area Network) or a WAN (Wide Area Network), or can be connected to an external computer (e.g., using an Internet service provider to connect via the Internet).

[0148] The flow charts and block diagrams in the accompanying drawings illustrate the possible architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present application. In this regard, each box in the flow chart or block diagram can represent a module, program segment or a part of code, and the module, program segment or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flow chart, and the combination of the boxes in the block diagram and / or flow chart can be implemented by a dedicated hardware-based system that performs the specified function or operation, or can be implemented by a combination of dedicated hardware and computer instructions.

[0149] The modules described in the embodiments of the present application may be implemented in software or hardware, wherein the name of a module does not necessarily limit the unit itself.

[0150] The computer-readable storage medium provided in this application stores computer-readable program instructions (i.e., a computer program) for executing the aforementioned ECU software mode switching and test verification method. This computer-readable storage medium can address the technical problem of improving the efficiency of automotive software testing and verification. Compared to the prior art, the beneficial effects of the computer-readable storage medium provided in this application are the same as those of the ECU software mode switching and test verification method provided in the aforementioned embodiments, and are not further elaborated here.

[0151] The present application also provides a computer program product, comprising a computer program, which, when executed by a processor, implements the steps of the above-mentioned ECU software mode switching and test verification method.

[0152] The computer program product provided in this application can solve the technical problem of improving the efficiency of automotive software testing and verification. Compared with the prior art, the beneficial effects of the computer program product provided in this application are the same as those of the ECU software mode switching and testing and verification methods provided in the above-mentioned embodiments, and will not be elaborated here.

[0153] The above description is only part of the embodiments of the present application and does not limit the patent scope of the present application. All equivalent structural transformations made by using the contents of the present application specification and drawings under the technical concept of the present application, or direct / indirect application in other related technical fields are included in the patent protection scope of the present application.

Claims

1. A method for switching and testing ECU software modes, characterized in that: The method comprises: Design diagnostic instructions based on unified diagnostic services; controlling the electronic control unit to switch modes according to the diagnostic instructions or to maintain a programming session mode when the application software is valid; The electronic control unit is tested and verified in different modes.

2. The method according to claim 1, wherein The step of controlling the electronic control unit to switch modes according to the diagnostic instruction or to maintain the programming session mode when the application software is valid includes: Detect the operating status of the electronic control unit and the valid flag of the application software; When the running state and the valid flag of the application software meet a first preset condition, controlling the electronic control unit to enter a programming session mode according to the diagnostic instruction and maintaining the programming session mode when the application software is valid; When the running state and the application software valid flag meet a second preset condition, the electronic control unit is controlled to switch from the programming session mode to the application software mode according to the diagnostic instruction.

3. The method according to claim 2, wherein The step of controlling the electronic control unit to enter a programming session mode according to the diagnostic instruction when the operating state and the application software valid flag meet a first preset condition and maintaining the programming session mode when the application software is valid includes: When the running state is that the application software is running normally and the application software valid flag is valid, determining that the running state and the application software valid flag meet a first preset condition, and controlling the electronic control unit to enter a programming session mode according to the diagnostic instruction; When the application software is valid, security authentication is performed through a security access service, and a routine is started according to the diagnostic instruction; When the routine is started, the application software valid flag is modified from valid to invalid, so that the electronic control unit maintains the programming session mode when the application software is valid.

4. The method according to claim 3, wherein The step of modifying the application software valid flag from valid to invalid when the routine is started so that the electronic control unit maintains the programming session mode when the application software is valid includes: When the routine is started, the valid flag of the application software is changed from valid to invalid; The electronic control unit is controlled to continuously run a preset program so that the electronic control unit maintains the programming session mode when the application software is valid.

5. The method according to claim 2, wherein The step of controlling the electronic control unit to switch from the programming session mode to the application software mode according to the diagnostic instruction when the operating state and the application software valid flag meet a second preset condition includes: When the running state is normal operation in programming session mode and the application software valid flag is invalid, determining that the running state and the application software valid flag meet a second preset condition, and performing security authentication through a security access service; When the authentication is successful, the routine is closed according to the diagnostic instruction, and the valid flag of the application software is changed from invalid to valid; When it is detected that the electronic control unit programming session times out or is powered on or reset, the electronic control unit is controlled to switch from the programming session mode to the application software mode.

6. The method according to claim 1, wherein The step of testing and verifying the electronic control unit in different modes includes: When the electronic control unit is in the programming session mode, testing and verifying the functionality of a preset program of the electronic control unit; When the electronic control unit is in the application software mode, the actual control function of the electronic control unit is tested and verified.

7. The method according to claim 1, wherein The step of designing a diagnostic instruction based on the unified diagnostic service includes: Based on the unified diagnostic service, the routine control diagnostic service is used in conjunction with the sub-function definition to obtain the instructions for controlling the opening and closing of the routine; Obtaining the control mode switching instruction through data identifier positioning; The control on and off routine instructions and the control mode switching instructions are used as diagnosis instructions.

8. An ECU software mode switching and test verification device, characterized in that: The device comprises: An instruction design module, used to design diagnostic instructions based on the unified diagnostic service; a mode switching module, configured to control the electronic control unit to switch modes according to the diagnostic instruction or to maintain a programming session mode when the application software is valid; The test and verification module is used to test and verify the electronic control unit in different modes.

9. An ECU software mode switching and test verification device, characterized in that: The device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the ECU software mode switching and test verification method according to any one of claims 1 to 7.

10. A storage medium, characterized in that: The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the ECU software mode switching and test verification method according to any one of claims 1 to 7 are implemented.