Controller upgrading method and device and electronic equipment

By restarting and actively obtaining the session status after the controller is upgraded and re-upgrading to ensure that the target controller exits the programming mode correctly, the problem of the controller not working properly after the upgrade is solved, and the reliability of the entire vehicle operation is improved.

CN120491999APending Publication Date: 2025-08-15ZHEJIANG GEELY HLDG GRP CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510582500.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-07
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

During the controller upgrade process, the target controller may not be able to exit the programming mode, resulting in serious failures such as the vehicle being unable to start.

Method used

After the target controller is upgraded, restart the controller and actively obtain its session status. If it is programming mode, upgrade again. By obtaining the rescue controller list, operating environment information and fault prediction model, the upgrade process is ensured that the controller correctly exits the programming mode.

Benefits of technology

Reduces the risk that the controller does not exit the programming mode after upgrading, avoids interruption of the vehicle's power and ensures the normal operation of the vehicle.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120491999A_ABST
    Figure CN120491999A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of computers, in particular to a controller upgrading method and device and electronic equipment. According to the method and the device, after the target controller is upgraded, the target controller is restarted in a targeted manner and then the session state of the target controller is actively obtained, and the target controller is re-upgraded when the target controller does not correctly exit the programming state, so that the risk that the target controller does not exit the programming mode after the upgrade package is flashed is reduced, and the programming efficiency is improved. The situation that normal operation of the whole vehicle after upgrading is affected due to the fact that a single controller is in a programming mode is avoided, and particularly the problems that power of the whole vehicle is interrupted and the vehicle cannot be started due to the fact that the power controller cannot exit the programming mode are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of computer technology, and in particular to a controller upgrading method, device, and electronic device. Background Art

[0002] Over-the-Air (OTA) is a wireless software update technology that allows automakers to remotely push new firmware, software, or map data to vehicles. This technology can significantly reduce the workload of repair shops, improve efficiency, and reduce costs.

[0003] Typically, during an OTA upgrade, the OTA management module in the vehicle obtains the software upgrade package from the cloud server and writes the software upgrade package into the controller after the controller enters programming mode to upgrade the controller.

[0004] However, because the software upgrade package and the controller are not yet fully compatible, after the software upgrade package is written to the controller, the controller may not be able to exit programming mode and therefore not function properly. If the power controller has such problems, it may also cause serious faults such as the vehicle being unable to start. Summary of the Invention

[0005] In order to solve the above technical problems, the present disclosure provides a controller upgrade method, device and electronic device to reduce the risk that the target controller fails to exit the programming mode after the upgrade package is flashed.

[0006] In a first aspect, an embodiment of the present disclosure provides a controller upgrade method, the method comprising:

[0007] After the target controller upgrade is completed, restart the target controller;

[0008] Get the session mode of the target controller;

[0009] If the session mode of the target controller is the programming mode, the target controller is upgraded again.

[0010] In some embodiments, after the target controller upgrade is completed and before the target controller is restarted, the method further includes:

[0011] Upgrading the target controller using a target upgrade package, where the target upgrade package is the latest version upgrade package corresponding to the target controller in the current upgrade task;

[0012] The re-upgrading of the target controller includes:

[0013] The target controller is re-upgraded using the target upgrade package.

[0014] In some embodiments, after the target controller is upgraded and restarted, the method further includes:

[0015] After a preset waiting time, obtaining the restart status of the target controller;

[0016] If the target controller is successfully restarted, the session mode of the target controller is obtained; or

[0017] If the target controller fails to restart, it is determined that the upgrade of the target controller fails.

[0018] In some embodiments, the method further comprises:

[0019] After the target controller in the system to be upgraded has been re-upgraded, wait for the other controllers to be upgraded in the system to be upgraded to complete upgrading;

[0020] When the upgrade of the other controllers to be upgraded is completed, the system to be upgraded is restarted.

[0021] In some embodiments, after the target controller upgrade is completed, before restarting the target controller, the method further includes:

[0022] A rescue controller list is obtained, where the rescue controller list includes controller information of at least one power controller.

[0023] In some embodiments, obtaining a rescue controller list includes:

[0024] Based on historical system upgrade information and / or historical system maintenance information, calculating the probability of each controller being in programming mode after the upgrade is completed;

[0025] The rescue controller list is generated according to the controllers whose probabilities are greater than a preset probability threshold.

[0026] In some embodiments, after the target controller upgrade is completed, restarting the target controller includes:

[0027] After the target controller upgrade is completed, determining whether the target controller is a controller in the rescue controller list;

[0028] If the target controller is a controller in the rescue controller list, restart the target controller.

[0029] In some embodiments, if the session mode of the target controller is the programming mode, re-upgrading the target controller includes: if the session mode of the target controller is the programming mode, obtaining the operating environment information of the target controller;

[0030] If the operating environment information meets the upgrade condition of the target controller, the target controller is upgraded again.

[0031] In some embodiments, the target controller is located in a vehicle, and the operating environment information of the target controller includes one or more of the following:

[0032] Vehicle speed, gear position, high-voltage relay status;

[0033] If the operating environment information meets the upgrade condition of the target controller, re-upgrading the target controller includes:

[0034] If the vehicle speed is less than the preset speed threshold, the gear is in the parking gear, and the high-voltage relay is in the disconnected state, the target controller is upgraded again.

[0035] In some embodiments, after the target controller upgrade is completed and before the target controller is restarted, the method further includes:

[0036] When the target controller is upgraded, collecting upgrade event features of the target controller;

[0037] Inputting the upgrade event feature into a pre-trained fault prediction model to obtain the upgrade fault occurrence probability output by the fault prediction model;

[0038] If the upgrade failure occurrence probability is greater than a preset failure probability threshold, obtaining a backup upgrade package for the target controller;

[0039] The backup upgrade package is stored in a preset secure storage partition.

[0040] In some embodiments, if the session mode of the target controller is the programming mode, re-upgrading the target controller includes:

[0041] If the session mode of the target controller is the programming mode and the probability of an upgrade failure of the target controller is greater than a preset failure probability threshold, the target controller is re-upgraded using the backup upgrade package.

[0042] In a second aspect, an embodiment of the present disclosure provides a controller upgrade device, which is applied to a system to be upgraded, wherein the system to be upgraded includes multiple controllers to be upgraded, and the device includes:

[0043] A restart module, configured to restart the target controller after the upgrade of the target controller is completed;

[0044] A first acquisition module, configured to acquire a session mode of the target controller;

[0045] The re-upgrading module is used to re-upgrade the target controller if the session mode of the target controller is the programming mode.

[0046] In a third aspect, an embodiment of the present disclosure provides an electronic device, including:

[0047] Memory;

[0048] processor; and

[0049] computer programs;

[0050] The computer program is stored in the memory and is configured to be executed by the processor to implement the method as described in the first aspect.

[0051] In a fourth aspect, an embodiment of the present disclosure provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program is executed by a processor to implement the method described in the first aspect.

[0052] In a fifth aspect, an embodiment of the present disclosure further provides a computer program product, which includes a computer program or instructions, and when the computer program or instructions are executed by a processor, implements the controller upgrade method as described above.

[0053] The controller upgrade method, device and electronic device provided by the embodiments of the present disclosure actively obtain the session status of the target controller after the target controller upgrade is completed, and re-upgrade the target controller when the target controller does not correctly exit the programming state, thereby reducing the risk of the target controller not exiting the programming mode after the upgrade package is flashed, avoiding the normal operation of the entire vehicle after the upgrade being affected by a single controller being in programming mode, and especially solving the problem of vehicle power interruption and vehicle inability to start due to the power controller being unable to exit the programming mode. BRIEF DESCRIPTION OF THE DRAWINGS

[0054] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present disclosure and, together with the description, serve to explain the principles of the present disclosure.

[0055] In order to more clearly illustrate the embodiments of the present disclosure or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0056] Figure 1 A flow chart of a controller upgrade method provided in an embodiment of the present disclosure;

[0057] Figure 2A schematic diagram of an application scenario provided by an embodiment of the present disclosure;

[0058] Figure 3 A flowchart of a controller upgrade method provided by another embodiment of the present disclosure;

[0059] Figure 4 A schematic diagram of the structure of a controller upgrade device provided in an embodiment of the present disclosure;

[0060] Figure 5 A schematic diagram of the structure of an electronic device provided in an embodiment of the present disclosure. DETAILED DESCRIPTION

[0061] In order to more clearly understand the above-mentioned objectives, features and advantages of the present disclosure, the scheme of the present disclosure will be further described below. It should be noted that the embodiments of the present disclosure and the features therein can be combined with each other in the absence of conflict.

[0062] In the following description, many specific details are set forth to facilitate a full understanding of the present disclosure, but the present disclosure may also be implemented in other ways different from those described herein; it is obvious that the embodiments in the specification are only part of the embodiments of the present disclosure, rather than all of the embodiments.

[0063] An embodiment of the present disclosure provides a controller upgrade method, which is described below in conjunction with specific embodiments.

[0064] Figure 1 This is a flow chart of the controller upgrade method provided by the embodiment of the present disclosure. This method can be applied to Figure 2 The application scenario shown includes a server 21 and an upgrade management component 22. The server 21 can be an OTA server, which sets the rescue controller list through the OTA server and sends the set rescue controller list to the OTAMaster along with the task; the upgrade management component 22 can specifically be the vehicle's OTA Master. The upgrade management component 22 is used to manage the system to be upgraded, which includes multiple controllers to be upgraded. The OTA management module communicates with the vehicle control unit (VCU) through the Flexray (FR) bus, and is responsible for controlling the flashing timing and flashing status management of the vehicle during the upgrade. The VCU communicates with the controller (such as the vehicle power controller) through the CAN bus, for example Figure 2 The power controller 1, power controller 2, power controller 3 and power controller 4 are shown in FIG.

[0065] It is understandable that the controller upgrade method provided in the embodiments of the present disclosure can also be applied in other scenarios.

[0066] The following combination Figure 2 The application scenario shown is Figure 1 The controller upgrade method shown in the figure is introduced. The specific steps of this method are as follows:

[0067] S101 : After the target controller upgrade is completed, restart the target controller.

[0068] The target controller is one of multiple controllers to be upgraded.

[0069] Optionally, the target controller is a controller in the system to be upgraded that needs to be processed first or separately, such as a key functional module such as a VCU or a BMS, or a node that requires a special upgrade sequence.

[0070] Optionally, the target controller is at least one controller specified among multiple controllers to be upgraded.

[0071] Upgrade completed means that the upgrade package of the current target controller has been flashed.

[0072] After the target controller completes the upgrade, the upgrade management component 22 triggers the target controller to restart through software instructions or other means to ensure that the upgrade package written into the target controller can take effect.

[0073] S102: Acquire the session mode of the target controller.

[0074] The session mode refers to the communication status between the controller and external devices (such as the host computer and OTA management module). Common modes include the default session mode and programming mode.

[0075] The default session mode is the session mode in which the target controller is in normal working conditions.

[0076] Programming mode is a temporary state of the target controller during the upgrade process. If the target controller is still in programming mode after the upgrade is complete, it means that the target controller may not have exited the upgrade process correctly.

[0077] After the target controller is restarted, the upgrade management component 22 actively queries the current session mode of the target controller to determine whether the target controller upgrade correctly exits the programming mode.

[0078] Optionally, the upgrade management component 22 uses diagnostic instructions to confirm whether the target controller is currently in programming mode. The system includes a Unified Diagnostic Services Adapter (UDSAdapter), a middleware specifically designed for the UDS protocol. It converts non-UDS protocols (such as vendor-proprietary protocols) into a message format that complies with the UDS standard. Based on the UDS Adapter, the upgrade management component 22 uses diagnostic instructions to confirm whether the target controller is currently in programming mode.

[0079] S103: If the session mode of the target controller is the programming mode, re-upgrade the target controller.

[0080] When the upgrade management component 22 finds that the target controller is still in the programming mode after the restart, it triggers the second upgrade process for the target controller and re-writes the upgrade package of the target controller into the target controller.

[0081] Furthermore, after re-upgrading the target controller, the session mode of the target controller is again queried. If the target controller is not in programming mode, it indicates that the target controller has correctly exited programming mode after the re-upgrade, and the target controller upgrade is determined to be successful. Alternatively, if the target controller is still in programming mode after the re-upgrade, it indicates that the target controller has not correctly exited programming mode after the re-upgrade, and the target controller upgrade is determined to have failed.

[0082] Optionally, if the target controller is still in programming mode after the target controller is re-upgraded, this step is repeated until the target controller exits programming mode or the number of repetitions of this step exceeds a preset threshold.

[0083] Furthermore, after the target controller in the system to be upgraded is re-upgraded, the system to be upgraded waits for the other controllers to be upgraded in the system to be upgraded to complete upgrading; after the upgrading of the other controllers to be upgraded is completed, the system to be upgraded is restarted.

[0084] The target controller re-upgrade is completed, including the target controller re-upgrade is successful or the target controller re-upgrade fails.

[0085] In a single upgrade task, the upgrade management component 22 needs to upgrade multiple controllers to be upgraded in the system to be upgraded. After one or more target controllers are upgraded, it is still necessary to wait for the upgrade of other controllers to be upgraded to be completed.

[0086] If the target controller is re-upgraded successfully, it is determined that the target controller is upgraded successfully; or if the target controller is re-upgraded unsuccessfully, it is determined that the target controller is upgraded unsuccessfully.

[0087] Restarting the system to be upgraded is a global reset of the entire system. For example, powering off and then powering on the entire vehicle. After all controllers to be upgraded are upgraded, perform a system-wide reboot to ensure the new version of the program takes effect.

[0088] Optionally, a system-level restart may be performed on the system-level cache (such as the CAN communication matrix) to ensure that the new version functionality is fully loaded.

[0089] On this basis, when the target controller upgrade fails, the upgrade task is determined to have failed and the upgrade failure is reported to the user; or, when the target controller upgrade is successful and the upgrades of other controllers are completed, the upgrade task is determined to have succeeded and the upgrade success is reported to the user.

[0090] The embodiment of the present disclosure restarts the target controller after the target controller upgrade is completed; obtains the session mode of the target controller; and re-upgrades the target controller if the session mode of the target controller is the programming mode; actively obtains the session status of the target controller after the target controller upgrade is completed, and re-upgrades the target controller when the target controller does not correctly exit the programming status, thereby reducing the risk of the target controller not exiting the programming mode after the upgrade package is flashed, avoiding the normal operation of the entire vehicle after the upgrade due to a single controller being in programming mode, and especially solving the problem of vehicle power interruption and vehicle inability to start due to the power controller being unable to exit the programming mode.

[0091] Based on the above embodiment, after the target controller is upgraded and before the target controller is restarted, the method further includes: upgrading the target controller using a target upgrade package, where the target upgrade package is the latest version upgrade package corresponding to the target controller in the current upgrade task.

[0092] Correspondingly, re-upgrading the target controller includes: re-upgrading the target controller using the target upgrade package.

[0093] The target upgrade package refers to the latest version of the software package specified for the target controller in the current upgrade task, which is sent by the server 21 to the upgrade management component 22. That is, one of the original goals of this upgrade task is to upgrade the target controller using the target upgrade package.

[0094] After upgrading the target controller using the target upgrade package, the upgrade management component 22 does not immediately delete the target upgrade package, but instead retains it. For example, when the server 21 sends the target upgrade package to the upgrade management component 22, the upgrade management component 22 saves the target upgrade package to a secure storage area. After upgrading the target controller using the target upgrade package, the target upgrade package remains in the secure storage area.

[0095] Correspondingly, if the target controller is still in the programming mode after the restart, the target controller needs to be re-upgraded. The upgrade management component 22 still uses the latest target upgrade package to re-upgrade the target controller.

[0096] The embodiment of the present disclosure further improves the probability of successful upgrade of the target upgrade package by giving priority to retrying the latest target upgrade package when re-upgrading the target controller.

[0097] Based on the above embodiment, after the target controller is upgraded and restarted, the method further includes: obtaining the restart status of the target controller after a preset waiting time; if the target controller restarts successfully, obtaining the session mode of the target controller; or, if the target controller fails to restart, determining that the upgrade of the target controller has failed.

[0098] The preset waiting time is a preset delay time, which is used to reserve a buffer period required for the target controller to run stably from restart.

[0099] Optionally, the preset waiting time needs to cover the longest time from power failure to stable operation of the target controller, for example, it is set based on historical data statistics.

[0100] For example, in new energy vehicles, the battery management system (BMS) needs to calibrate the battery cell voltage when it restarts. If the detection is too early, it may mistakenly determine that the upgrade has failed.

[0101] The restart status is the operating status of the target controller after the restart, including a successful restart, such as normal entry into the working mode; or a restart failure, such as failure to respond, communication abnormality, etc.

[0102] Optionally, the upgrade control component determines whether the target controller is alive through a heartbeat signal, a status query instruction of a diagnostic service, or a hardware pin level detection.

[0103] After the target controller triggers a restart, the system delays for a preset time to avoid misjudgment caused by immediate detection, and then actively queries whether it has successfully started and entered a communicative state.

[0104] Furthermore, when the target controller is restarted successfully, it responds to the diagnostic request or actively sends a heartbeat packet within the preset waiting time, indicating that it has entered an operational state. At this time, the upgrade control component is informed of the successful restart status of the target controller, and reads the current session mode of the target controller through the diagnostic protocol to further determine whether the upgrade of the target controller is completely completed.

[0105] Alternatively, if the target controller responds to the diagnostic service instruction within the preset waiting time, or returns an error code, the upgrade of the target controller is marked as incomplete, and further determination is made as to whether a rollback, alarm, or other process needs to be triggered.

[0106] In the disclosed embodiment, after a target controller reboots, it must undergo multiple phases, including resetting, initialization, and program loading. This time consumption can fluctuate depending on factors such as ambient temperature and power quality. If the target controller's status is checked immediately after a reboot, it may be mistakenly identified as an upgrade failure because the target controller has not yet completed the reboot. By presetting a waiting time buffer, the target controller's misjudgment rate is reduced, improving the robustness of the system upgrade and providing a higher level of reliability for remote maintenance and upgrades of complex systems.

[0107] Based on any of the above embodiments, after the target controller is upgraded and before the target controller is restarted, the method further includes: obtaining a rescue controller list, wherein the rescue controller list includes controller information of at least one power controller.

[0108] The rescue controller list is a predefined list of controllers that records the power controller identifiers that need to be monitored during the upgrade process, such as controller type, hardware version, communication address, etc.

[0109] The power controller is the basis of vehicle power control. Whether the vehicle can start and drive is affected by the success of its upgrade. In this embodiment, the rescue controller list is used to focus on monitoring at least one power controller during the upgrade process.

[0110] Specifically, the upgrade management component 22 reads a pre-configured rescue controller list from a local storage (such as an onboard EEPROM) or a remote server (such as the server 21 ).

[0111] Before triggering the target controller to restart, the upgrade management component 22 actively loads a predefined rescue controller list to identify which controllers must perform session mode detection during the system upgrade process.

[0112] Correspondingly, after the target controller is upgraded, it is determined whether the target controller is a controller in the rescue controller list; if the target controller is a controller in the rescue controller list, the target controller is restarted.

[0113] Alternatively, if the target controller is not a controller in the rescue controller list, the target controller is not restarted.

[0114] Specifically, by comparing the identification information (such as controller ID, hardware version number) of the target controller with the entries in the rescue controller list, it is determined whether the target controller is a controller that needs to be managed in a key manner.

[0115] After the target controller is upgraded, the upgrade management component 22 queries the preset rescue controller list to check whether the target controller is marked as a key node that requires a forced restart. This determination process is triggered after the initial flash of the upgrade package to the target controller in the current upgrade task, providing a basis for subsequent restart decisions.

[0116] For a target controller that belongs to the rescue controller list, it means that the target controller is marked as a critical controller. The upgrade management component 22 forces it to restart immediately after the upgrade to increase the probability of it exiting the programming mode and ensure that the new version of the target controller can operate normally.

[0117] For a target controller that does not belong to the rescue controller list, it means that the target controller is marked as a non-critical controller, and the upgrade management component 22 allows it to continue running without restarting.

[0118] The disclosed embodiment implements differentiated upgrade strategies for critical and non-critical controllers through a dynamic screening mechanism of the rescue controller list. For critical controllers in the rescue controller list, forced restart and strict verification are used to ensure that power and safety-related controllers are in normal status after upgrade, thereby reducing the risk of systemic failure. For non-critical controllers that are not in the rescue controller list, seamless upgrades are achieved, reducing service interruption time and improving user experience and system availability.

[0119] At the same time, the embodiment of the present disclosure allocates restart resources according to the importance of the controller to avoid bus congestion and power overload, and is suitable for large-scale distributed system upgrade scenarios.

[0120] In some embodiments, obtaining the rescue controller list includes: counting the probability of each controller being in programming mode after the upgrade is completed based on historical system upgrade information and / or historical system maintenance information; and generating the rescue controller list based on controllers whose probability is greater than a preset probability threshold.

[0121] Historical system upgrade information refers to the record of upgrade tasks executed by the system to be upgraded at historical moments, including the controller to be upgraded, upgrade time, version number, upgrade result (success or failure), whether programming mode is triggered, and other fields for each upgrade task.

[0122] Historical system maintenance information records maintenance events caused by controller upgrade failures, such as hardware replacement, firmware rollback, and manual intervention repairs. This includes maintenance information for any controller that required manual intervention due to the inability to exit programming mode after an upgrade.

[0123] The preset probability threshold is a pre-set risk threshold used to distinguish high-risk and low-risk controllers. The preset probability threshold can be globally unified or dynamically adjusted by controller type, which is not limited in the present embodiment.

[0124] Collect historical upgrade and maintenance data for the system, count the frequency with which the same controller remains in programming mode after the upgrade package is flashed, resulting in failure to operate normally, and establish a probability model to quantify its risk level.

[0125] Specifically, controllers whose probability of being in programming mode after the upgrade is greater than the preset probability threshold are high-risk controllers and require close attention during the upgrade process. The controller information (such as serial number and communication address) should be added to the rescue controller list, and the forced restart and dialogue mode detection strategies should be associated.

[0126] Optionally, the preset probability threshold is optimized according to the fault tolerance capability of the system to be upgraded. For example, when the OTA bandwidth is insufficient, the preset probability threshold is lowered to narrow the detection range; in security-critical scenarios, the preset probability threshold is increased to improve detection coverage.

[0127] The disclosed embodiment obtains a rescue controller list based on real upgrade or maintenance data, accurately captures controllers in the system that have not exited programming mode normally, and automatically screens high-risk controllers through probability statistics, so that the rescue controller list has adaptive optimization capabilities.

[0128] In some embodiments, obtaining the rescue controller list includes: updating the rescue controller list according to the upgrade task of the current system to be upgraded to obtain an updated rescue controller list; and performing a system upgrade based on the updated rescue controller list and the upgrade package of the controller to be upgraded.

[0129] The upgrade task of the current system to be upgraded refers to the target scope and content of this upgrade operation, including the set of controllers to be upgraded, firmware version, upgrade package configuration (such as dependency description file), etc.

[0130] Updating the rescue controller list means dynamically adjusting the original list content based on the specific requirements of the upgrade task (such as the list of key controllers and dependency analysis). For example, if the upgrade includes a new autonomous driving domain controller, it will be added to the list to force session detection.

[0131] Before starting the upgrade process, the system parses the configuration file for the current upgrade task, identifies controllers that have a significant impact on system functionality or are dependencies, and dynamically adds them to the rescue controller list. It also removes old entries not relevant to the current upgrade, such as redundant controller information from previous upgrades, to ensure the list accurately matches current needs.

[0132] Based on the updated rescue controller list, differentiated management is performed on the controllers to be upgraded. The controllers in the rescue controller list are subjected to the post-upgrade restart and session mode verification process described in the above embodiment, while the controllers not in the rescue controller list are subjected to the lightweight process.

[0133] Optionally, the rescue controller list is updated in the server 21 to obtain an updated rescue controller list; the updated rescue controller list and the upgrade package of the controller to be upgraded are sent to the upgrade management component 22 to execute the upgrade task on the system to be upgraded.

[0134] The disclosed embodiment dynamically adjusts the rescue controller list in conjunction with the upgrade task, thereby avoiding the obsolescence or redundancy problem of the static list and balancing the efficiency and reliability of system upgrade and dialogue status detection.

[0135] In some embodiments, if the session mode of the target controller is a programming mode, the target controller is re-upgraded, including: if the session mode of the target controller is a programming mode, obtaining the operating environment information of the target controller; if the operating environment information meets the upgrade conditions of the target controller, the target controller is re-upgraded.

[0136] Specifically, the target controller is located in a vehicle, and the operating environment information of the target controller includes one or more of the following: vehicle speed, gear position, and high-voltage relay status.

[0137] Correspondingly, if the operating environment information meets the upgrade conditions of the target controller, the target controller is upgraded again, including: if the vehicle speed is less than the preset speed threshold, the gear is the parking gear, and the high-voltage relay is in the disconnected state, the target controller is upgraded again.

[0138] Alternatively, if any operating environment information does not meet the upgrade conditions of the target controller, the upgrade task is terminated and the upgrade is continued after the operating environment information meets the upgrade conditions of the target controller; or the user's operation instructions are continuously waited for and whether to continue the upgrade is determined according to the user's operation instructions.

[0139] The operating environment information does not meet the upgrade conditions of the target controller, including: the vehicle speed is greater than or equal to the preset threshold; or the gear is not the parking gear; or the high-voltage relay is in the connected state.

[0140] After the target controller is restarted, if the target controller is still in programming mode, that is, an abnormality occurs in the target controller upgrade process, first evaluate the operating environment information of the target controller to rule out the possibility that external factors may cause the target controller upgrade abnormality; after determining that the target controller upgrade abnormality is not caused by external factors, execute the steps of re-upgrading the target controller.

[0141] Among them, the target controller is a controller in the vehicle, specifically a power controller in the vehicle; the operating environment information of the target controller is evaluated, including: determining whether the vehicle speed is greater than or equal to a preset speed threshold; determining whether the vehicle gear is in the parking gear; and determining whether the state of the vehicle high-voltage relay is disconnected.

[0142] When the vehicle speed is greater than or equal to the preset speed threshold, it indicates that the vehicle may be in a non-stationary state, such as rolling down a slope or being pushed manually. At this time, if the controller is upgraded, the vibration may affect the integrity of the CAN bus signal, resulting in upgrade package transmission errors; or the memory write failure caused by the motor operation may cause the target controller upgrade to fail.

[0143] Optionally, the preset vehicle speed threshold is 3 km / h.

[0144] For example, when a vehicle is parked on a slope, if the electronic parking brake is not fully effective, the vehicle may slowly roll back due to gravity. The vehicle speed threshold detection can identify such risks in a timely manner.

[0145] When the vehicle is in the parking gear (P gear), if the motor controller accidentally outputs torque during the upgrade process, the parking gear can prevent the torque power from being transmitted to the wheels to avoid accidents.

[0146] The high-voltage relay is a safety element in the vehicle's high-voltage system, responsible for controlling the normal powering on and off of the high-voltage power system. During the controller upgrade process, ensure that the high-voltage relay is disconnected and the high-voltage power system is completely powered off to ensure safety during the upgrade and prevent interference with signals in the upgrade-related circuits caused by the high-voltage system's operation.

[0147] The embodiment of the present disclosure eliminates external factors that may cause upgrade abnormalities before re-upgrading the target controller, thereby avoiding upgrade abnormalities caused by external factors during re-upgrading and reducing meaningless re-upgrade processes.

[0148] In some embodiments, after the target controller is upgraded and before the target controller is restarted, the method further includes: when the target controller is upgraded, collecting upgrade event features of the target controller; inputting the upgrade event features into a pre-trained fault prediction model to obtain the upgrade failure probability output by the fault prediction model; if the upgrade failure probability is greater than a preset fault probability threshold, obtaining a backup upgrade package for the target controller; and storing the backup upgrade package in a preset secure storage partition.

[0149] Correspondingly, if the session mode of the target controller is the programming mode, the target controller is re-upgraded, including: if the session mode of the target controller is the programming mode, the target controller is re-upgraded using the backup upgrade package.

[0150] The upgrade event feature refers to a multi-dimensional data set generated by the target controller during the upgrade process and capable of reflecting the upgrade status of the target controller.

[0151] Upgrade event characteristics include, but are not limited to, timing characteristics, environmental characteristics, operational characteristics, and communication characteristics. Timing characteristics include the duration of the target controller upgrade phase; environmental characteristics include fluctuations in power supply voltage and ambient temperature during the target controller upgrade; operational characteristics include the model and type of the target controller, the difference between the current version of the target controller and the upgrade package version, and the number of abnormal data read and write operations during the upgrade process; and communication characteristics include peak vehicle CAN bus load rates and diagnostic command response delays.

[0152] A fault prediction model is a machine learning-trained model that can predict the probability of upgrade failure based on input features. This model is trained based on data such as success and failure cases in historical upgrade logs and maintenance records.

[0153] Optionally, after the fault prediction model is deployed online, the upgrade data of each vehicle controller is continuously collected to dynamically and continuously update the model parameters.

[0154] The backup upgrade package can be an upgrade package with the same functions as the upgrade package of the current upgrade task but with a different build configuration, or an upgrade package of the previous stable version, or a basic upgrade package that can maintain the basic functions of the target controller.

[0155] If the fault prediction model predicts that the target controller upgrade failure probability exceeds a preset fault probability threshold, it indicates that the target controller is likely to fail during the upgrade process, such as being unable to exit programming mode after the upgrade. At this time, a backup upgrade package is downloaded and stored in a preset secure storage partition in case the target controller is upgraded again without exiting programming mode.

[0156] Accordingly, when the target controller needs to be re-upgraded, the standby upgrade package is obtained from the preset secure storage partition to re-upgrade the target controller.

[0157] Optionally, when the target controller is re-upgraded for the first time without exiting the programming mode, the target controller is re-upgraded using the latest version of the target upgrade package corresponding to the target controller in the current upgrade task; when the target controller is re-upgraded using the target upgrade package, the target controller still does not exit the programming mode normally, and the fault prediction model predicts that the probability of target controller upgrade failure exceeds a preset fault probability threshold, a backup upgrade package is obtained from the preset secure storage partition to re-upgrade the target controller.

[0158] The disclosed embodiment predicts the probability of upgrade failure of the target controller, obtains a backup upgrade package as an alternative when the failure probability is high, performs risk warnings and pre-positions backup resources in advance, and improves the success rate of re-upgrade through a more stable backup upgrade package when the target controller needs to be re-upgraded, thereby improving the reliability and stability of the target controller upgrade.

[0159] Figure 3 A flow chart of a controller upgrade method provided by another embodiment of the present disclosure is shown as follows: Figure 3 As shown, the method includes the following steps:

[0160] S301. The OTA Master receives and saves the upgrade package of the controller to be upgraded and the rescue controller list to a local non-volatile register.

[0161] S302: The current target controller upgrade is completed without any failure information feedback.

[0162] S303: The OTA Master checks whether the current target controller is in the rescue controller list. If so, if the judgment result is "yes", execute S304; if the judgment result is "no", execute S308.

[0163] S304. The OTA Master immediately restarts the current target controller.

[0164] S305: The OTA Master checks whether the preset waiting time has expired. If the judgment result is "yes", execute S306; if the judgment result is "no", execute S308.

[0165] Optionally, the preset waiting time is 10 seconds.

[0166] S306. OTA Master uses UDS instruction 22F1 86 to confirm whether the current target controller is in programming mode. If the judgment result is "yes", execute S307; if the judgment result is "no", execute S308.

[0167] S307: Confirm that the vehicle conditions meet the upgrade requirements, and OTA Master re-upgrades the new software to the current target controller; if the upgrade is successful, execute S308; if the upgrade fails, execute S309.

[0168] S308: Wait for all target controllers to be upgraded, restart the vehicle controller, and report the upgrade success to the user.

[0169] S309: Wait for the upgrade of other target controllers to be completed, restart the vehicle controller, and report the upgrade failure to the user.

[0170] The disclosed embodiment proposes a method for diagnosing a session mode after the target controller (such as a power controller) is upgraded and restarted to confirm whether the target controller has exited the programming mode. When it is found that the diagnostic session mode of the target controller is not the default session mode, but a programming session, extended session, negative response, and no response mode, the software of such controller is re-upgraded and the software flag is rewritten, thereby solving the problem that the target controller cannot exit the programming mode and cannot work normally.

[0171] Among them, the rescue controller list is set up in the background and sent to the vehicle side along with the OTA task. The controllers that need to be rescued are flexibly set according to market sentiment without changing the vehicle software. The general UDS command is used to confirm whether the target controller is in programming mode. The target controller has implemented the corresponding diagnostic logic. No additional software logic is added to the target controller, and the upgrade strategy improvement cost is low.

[0172] In addition, compared with remote rescue, the embodiment of the present disclosure avoids the problem that rescue cannot be carried out due to network connection problems; the upgrade package of the rescue target controller will not be deleted, and there is no need to re-acquire the rescue upgrade package, and it is ensured that the target controller cannot exit the programming mode and the latest upgrade package is re-written; the rescue action performs a session mode check during the current task upgrade process, and no new tasks are generated, and no user confirmation is required, thus realizing non-perceptual detection and rescue.

[0173] Optionally, a rescue controller list can be set up using a cloud server. This list can be configured for each vehicle model's controllers that require rescue. Before each OTA begins, the rescue controller list is delivered to the vehicle along with the upgrade package and takes effect immediately during this OTA. Modifications are simple, grouping is flexible, and the list takes effect immediately.

[0174] Figure 4The controller upgrade device provided by the embodiment of the present disclosure can execute the processing flow provided by the controller upgrade method embodiment, such as Figure 4 As shown, the controller upgrade device 40 includes: a restart module 41, a first acquisition module 42, and a re-upgrade module 43; the restart module 41 is used to restart the target controller after the target controller upgrade is completed; the first acquisition module 42 is used to obtain the session mode of the target controller; the re-upgrade module 43 is used to re-upgrade the target controller if the session mode of the target controller is a programming mode.

[0175] Optionally, the controller upgrade device 40 also includes an upgrade module 44, which is used to upgrade the target controller using a target upgrade package, and the target upgrade package is the latest version upgrade package corresponding to the target controller in the current upgrade task; the re-upgrade module 43 is used to re-upgrade the target controller using the target upgrade package.

[0176] Optionally, the restart module 41 is further used to obtain the restart status of the target controller after a preset waiting time; if the target controller restarts successfully, obtain the session mode of the target controller; or, if the target controller fails to restart, determine that the target controller upgrade fails.

[0177] Optionally, the restart module 41 is further configured to wait for other controllers to be upgraded in the system to be upgraded to complete upgrading after the target controller in the system to be upgraded is upgraded; and restart the system to be upgraded after the upgrading of other controllers to be upgraded is completed.

[0178] Optionally, the controller upgrading device 40 further includes a second acquiring module 45 for acquiring a rescue controller list after the target controller is upgraded and before the target controller is restarted, wherein the rescue controller list includes controller information of at least one power controller.

[0179] Optionally, the second acquisition module 45 includes a statistical unit 451 and a first determination unit 452; the statistical unit 451 is used to count the probability of each controller being in programming mode after the upgrade is completed based on historical system upgrade information and / or historical system maintenance information; the first determination unit 452 is used to generate the rescue controller list based on the controllers whose probability is greater than a preset probability threshold.

[0180] Optionally, the restart module 41 includes a second determination unit 411 and a restart unit 412; the second determination unit 411 is used to determine whether the target controller is a controller in the rescue controller list after the target controller upgrade is completed; the restart unit 412 is used to restart the target controller if the target controller is a controller in the rescue controller list.

[0181] Optionally, the re-upgrade module 43 includes a first acquisition unit 431 and a re-upgrade unit 432; the first acquisition unit 431 is used to obtain the operating environment information of the target controller if the session mode of the target controller is a programming mode; the re-upgrade unit 432 is used to re-upgrade the target controller if the operating environment information meets the upgrade conditions of the target controller.

[0182] Optionally, the target controller is located in the vehicle, and the operating environment information of the target controller includes one or more of the following: vehicle speed, gear position, and high-voltage relay status; the re-upgrade unit 432 is used to re-upgrade the target controller if the vehicle speed is less than a preset speed threshold, the gear position is the parking gear, and the high-voltage relay is in the disconnected state.

[0183] Optionally, the controller upgrade device 40 also includes a prediction module 46, which includes a collection unit 461, a prediction unit 462, a second acquisition unit 463, and a storage unit 464; the collection unit 461 is used to collect upgrade event characteristics of the target controller when the target controller is upgraded; the prediction unit 462 is used to input the upgrade event characteristics into a pre-trained fault prediction model to obtain the upgrade fault occurrence probability output by the fault prediction model; the second acquisition unit 463 is used to obtain a backup upgrade package of the target controller if the upgrade fault occurrence probability is greater than a preset fault probability threshold; the storage unit 464 is used to store the backup upgrade package in a preset secure storage partition.

[0184] Optionally, the re-upgrade module 43 is further configured to re-upgrade the target controller using the backup upgrade package if the session mode of the target controller is a programming mode and the probability of an upgrade failure of the target controller is greater than a preset failure probability threshold.

[0185] Figure 4 The controller upgrading device of the illustrated embodiment can be used to execute the technical solution of the above-mentioned method embodiment. Its implementation principle and technical effects are similar and will not be described in detail here.

[0186] Figure 5 The electronic device provided by the embodiment of the present disclosure can execute the processing flow provided by the controller upgrade method embodiment, such as Figure 5As shown, the electronic device 50 includes: a memory 51, a processor 52, a computer program and a communication interface 53; wherein the computer program is stored in the memory 51 and is configured so that the processor 52 executes the controller upgrade method as described above.

[0187] In addition, an embodiment of the present disclosure further provides a computer-readable storage medium on which a computer program is stored. The computer program is executed by a processor to implement the controller upgrade method described in the above embodiment.

[0188] In addition, an embodiment of the present disclosure further provides a computer program product, which includes a computer program or instructions. When the computer program or instructions are executed by a processor, the controller upgrade method described above is implemented.

[0189] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device comprising the element.

[0190] The foregoing description is intended only to provide specific embodiments of the present disclosure, intended to enable those skilled in the art to understand and implement the present disclosure. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present disclosure. Therefore, the present disclosure is not intended to be limited to the embodiments described herein, but rather to be construed in the broadest manner consistent with the principles and novel features disclosed herein.

Claims

1. A controller upgrade method, characterized in that: The method comprises: After the target controller upgrade is completed, restart the target controller; Get the session mode of the target controller; If the session mode of the target controller is the programming mode, the target controller is upgraded again.

2. The method according to claim 1, characterized in that After the target controller upgrade is completed, before restarting the target controller, the method further includes: Upgrading the target controller using a target upgrade package, where the target upgrade package is the latest version upgrade package corresponding to the target controller in the current upgrade task; The re-upgrading of the target controller includes: The target controller is re-upgraded using the target upgrade package.

3. The method according to claim 1, characterized in that After the target controller is upgraded and restarted, the method further includes: After a preset waiting time, obtaining the restart status of the target controller; If the target controller is successfully restarted, the session mode of the target controller is obtained; or If the target controller fails to restart, it is determined that the upgrade of the target controller fails.

4. The method according to claim 1, wherein The method further comprises: After the target controller in the system to be upgraded has been re-upgraded, wait for the other controllers to be upgraded in the system to be upgraded to complete upgrading; When the upgrade of the other controllers to be upgraded is completed, the system to be upgraded is restarted.

5. The method according to claim 1, wherein After the target controller upgrade is completed, before restarting the target controller, the method further includes: A rescue controller list is obtained, where the rescue controller list includes controller information of at least one power controller.

6. The method according to claim 5, characterized in that The step of obtaining a rescue controller list includes: Based on historical system upgrade information and / or historical system maintenance information, calculate the probability of each power controller being in programming mode after the upgrade is completed; The rescue controller list is generated according to the power controllers whose probabilities are greater than a preset probability threshold.

7. The method according to claim 5, characterized in that After the target controller upgrade is completed, restarting the target controller includes: After the target controller upgrade is completed, determining whether the target controller is a controller in the rescue controller list; If the target controller is a controller in the rescue controller list, restart the target controller.

8. The method according to claim 1, characterized in that If the session mode of the target controller is the programming mode, re-upgrading the target controller includes: If the session mode of the target controller is programming mode, obtaining the operating environment information of the target controller; If the operating environment information meets the upgrade condition of the target controller, the target controller is upgraded again.

9. The method according to claim 8, characterized in that The target controller is located in a vehicle, and the operating environment information of the target controller includes one or more of the following: Vehicle speed, gear position, high-voltage relay status; If the operating environment information meets the upgrade condition of the target controller, re-upgrading the target controller includes: If the vehicle speed is less than the preset speed threshold, the gear is in the parking gear, and the high-voltage relay is in the disconnected state, the target controller is upgraded again.

10. The method according to claim 1, characterized in that After the target controller upgrade is completed, before restarting the target controller, the method further includes: When the target controller is upgraded, collecting upgrade event features of the target controller; Inputting the upgrade event feature into a pre-trained fault prediction model to obtain the upgrade fault occurrence probability output by the fault prediction model; If the upgrade failure occurrence probability is greater than a preset failure probability threshold, obtaining a backup upgrade package for the target controller; The backup upgrade package is stored in a preset secure storage partition.

11. The method according to claim 10, characterized in that If the session mode of the target controller is the programming mode, re-upgrading the target controller includes: If the session mode of the target controller is the programming mode and the probability of an upgrade failure of the target controller is greater than a preset failure probability threshold, the target controller is re-upgraded using the backup upgrade package.

12. A controller upgrade device, characterized in that: Applied to a system to be upgraded, the system to be upgraded includes multiple controllers to be upgraded, and the device includes: A restart module, configured to restart the target controller after the upgrade of the target controller is completed; A first acquisition module, configured to acquire a session mode of the target controller; The re-upgrading module is used to re-upgrade the target controller if the session mode of the target controller is the programming mode.

13. An electronic device, characterized in that: include: Memory; processor; as well as computer programs; The computer program is stored in the memory and configured to be executed by the processor to implement the method according to any one of claims 1 to 11.