Vehicle software upgrading method and device, equipment and storage medium

By continuously sending sub-data packets of the upgrade data packet and maintaining programming mode during the vehicle software upgrade process, the problem of electronic control unit flash timeout is solved, and a more efficient and stable upgrade process is achieved.

CN120729894APending Publication Date: 2025-09-30CHONGQING SELIS PHOENIX INTELLIGENT INNOVATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510808166.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-17
Publication Date
2025-09-30

AI Technical Summary

Technical Problem

In the prior art, the electronic control unit is prone to failure due to flashing timeout during the software upgrade process.

Method used

By continuously sending messages including sub-data packets of the upgrade data packet and the command to maintain the programming mode, it is ensured that the electronic control unit always remains in the programming mode during the upgrade process, and a command to exit the programming mode is sent when the upgrade is completed to avoid exiting midway.

Benefits of technology

It improves the success rate and efficiency of vehicle software upgrades, reduces waiting time, and ensures the stability of the upgrade process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120729894A_ABST
    Figure CN120729894A_ABST
Patent Text Reader

Abstract

The embodiment of the invention relates to the field of vehicle upgrading, in particular to a vehicle software upgrading method and device, equipment and a storage medium, and aims to guarantee stable flashing of an electronic control unit in the upgrading process. The method comprises the following steps: acquiring an upgrading data packet corresponding to software to be upgraded in a vehicle; switching an electronic control unit corresponding to the software to be upgraded to a programming mode; a first message is continuously sent to the electronic control unit through a corresponding data transmission protocol, and the first message comprises a plurality of sub-data packets of the upgrading data packet and a programming mode maintaining command; and under the condition of transmitting to the last sub-data packet of the upgrading data packet, a second message is sent to the electronic control unit, and the second message comprises the last sub-data packet of the upgrading data packet and a programming mode quitting command.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of vehicle upgrades, and specifically, to a vehicle software upgrade method, apparatus, device, and storage medium. Background Art

[0002] OTA (Over the Air Technology) is a technology that upgrades vehicle software by downloading software update packages from a remote server over the Internet. In the existing technology, when the OTA master controller flashes and upgrades the electronic control unit, it sends the upgrade data package to the corresponding electronic control unit for flashing.

[0003] In the prior art, during the flashing process of the electronic control unit, flashing timeout and flashing failure may easily occur. Summary of the Invention

[0004] The embodiments of the present application provide a vehicle software upgrade method, apparatus, device and storage medium, which aim to ensure stable flashing of the electronic control unit during the upgrade process.

[0005] A first aspect of an embodiment of the present application provides a vehicle software upgrade method, the method comprising: Obtain the upgrade data package corresponding to the software to be upgraded in the vehicle; Switching the electronic control unit corresponding to the software to be upgraded to a programming mode; continuously sending a first message to the electronic control unit through a corresponding data transmission protocol, wherein the first message includes a plurality of sub-data packets of the upgrade data packet and a maintain programming mode command; When the last sub-data packet of the upgrade data packet is transmitted, a second message is sent to the electronic control unit, where the second message includes the last sub-data packet of the upgrade data packet and a command to exit programming mode.

[0006] Optionally, obtaining an upgrade data package corresponding to the software to be upgraded in the vehicle includes: Obtaining a first version number of the software to be upgraded; Comparing the first version number with the second version number corresponding to the software to be upgraded in the server; When the first version number is lower than the second version number, the upgrade data package is downloaded from the server.

[0007] Optionally, switching the electronic control unit corresponding to the software to be upgraded to a programming mode includes: Sending a first command to the electronic control unit to enable the electronic control unit to enter an OTA mode; When the electronic control unit enters the OTA mode, sending a second command to the electronic control unit to enable the electronic control unit to enter the extended mode; When the electronic control unit enters the extended mode, a third command is sent to the electronic control unit to enable the electronic control unit to enter the programming mode.

[0008] Optionally, the continuously sending the first message to the electronic control unit through a corresponding data transmission protocol includes: When the electronic control unit communicates via Ethernet, continuously sending the first message to the electronic control unit via an Ethernet-based communication diagnostic protocol; In a case where the electronic control unit communicates via a controller area network bus, a first message is continuously sent to the electronic control unit via a unified diagnostic protocol.

[0009] Optionally, the method further includes: When the OTA upgrade master is connected to the electronic control unit through the OTA proxy layer, the first message is sent to the OTA proxy layer through the Ethernet-based communication diagnostic protocol, so that the OTA proxy layer sends the first message to the electronic control unit through the unified diagnostic protocol.

[0010] Optionally, before switching the electronic control unit corresponding to the software to be upgraded to a programming mode, the method further includes: Sending security authentication information to the electronic control unit corresponding to the software to be upgraded; If the safety certification fails, removing the electronic control unit from the upgrade sequence; Report the security authentication failure error code to the server.

[0011] Optionally, the method further includes: Upon receiving a timeout inquiry message sent by the electronic control unit, determining whether the upgrade data packet has been transmitted; If the upgrade data packet has not been completely transmitted, continue transmitting the first message; When the upgrade data packet is completely transmitted, a command to exit programming mode is sent to the electronic control unit.

[0012] A second aspect of an embodiment of the present application provides a vehicle software upgrade device, the device comprising: An upgrade data packet acquisition module is used to acquire the upgrade data packet corresponding to the software to be upgraded in the vehicle; A mode switching module, configured to switch the electronic control unit corresponding to the software to be upgraded to a programming mode; A first message sending module, configured to continuously send a first message to the electronic control unit through a corresponding data transmission protocol, wherein the first message includes a plurality of sub-data packets of the upgrade data packet and a maintain programming mode command; The second message sending module is used to send a second message to the electronic control unit when the last sub-data packet of the upgrade data packet is transmitted, and the second message includes the last sub-data packet of the upgrade data packet and a command to exit the programming mode.

[0013] Optionally, the upgrade data packet acquisition module includes: A first version number acquisition submodule, configured to acquire a first version number of the software to be upgraded; A version number comparison submodule, configured to compare the first version number with a second version number corresponding to the software to be upgraded in the server; The upgrade data package downloading submodule is used to download the upgrade data package from the server when the first version number is lower than the second version number.

[0014] Optionally, the mode switching module includes: A first mode switching submodule is configured to send a first command to the electronic control unit to enable the electronic control unit to enter the OTA mode; a second mode switching submodule, configured to send a second command to the electronic control unit to enable the electronic control unit to enter the extended mode when the electronic control unit enters the OTA mode; The third mode switching submodule is configured to send a third command to the electronic control unit when the electronic control unit enters the extended mode, so as to enable the electronic control unit to enter the programming mode.

[0015] Optionally, the first message sending module includes: a first sending submodule, configured to continuously send the first message to the electronic control unit through a communication diagnostic protocol based on Ethernet when the electronic control unit communicates through Ethernet; The second sending submodule is configured to continuously send a first message to the electronic control unit through a unified diagnostic protocol when the electronic control unit communicates through a controller area network bus.

[0016] Optionally, the first message sending module further includes: The third sending submodule is used to send the first message to the OTA proxy layer through the Ethernet-based communication diagnostic protocol when the OTA upgrade master is connected to the electronic control unit through the OTA proxy layer, so that the OTA proxy layer sends the first message to the electronic control unit through the unified diagnostic protocol.

[0017] Optionally, the device further comprises: A security authentication information sending module, configured to send security authentication information to the electronic control unit corresponding to the software to be upgraded; An upgrade stop module, configured to remove the electronic control unit from an upgrade sequence if the safety certification fails; The error code reporting module is used to report the security authentication failure error code to the server.

[0018] Optionally, the device further comprises: a timeout inquiry information receiving module, configured to determine whether the upgrade data packet has been transmitted after receiving the timeout inquiry information sent by the electronic control unit; a message sending module, configured to continue transmitting the first message when the upgrade data packet has not been completely transmitted; The exit command sending module is used to send an exit programming mode command to the electronic control unit when the transmission of the upgrade data packet is completed.

[0019] A third aspect of an embodiment of the present application provides a readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the method described in the first aspect of the present application is implemented.

[0020] A fourth aspect of an embodiment of the present application provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the method described in the first aspect of the present application are implemented.

[0021] The vehicle software upgrade method proposed in this application is adopted to obtain the upgrade data packet corresponding to the software to be upgraded in the vehicle; the electronic control unit corresponding to the software to be upgraded is switched to programming mode; a first message is continuously sent to the electronic control unit through the corresponding data transmission protocol, and the first message includes multiple sub-data packets of the upgrade data packet and a command to maintain the programming mode; when the last sub-data packet of the upgrade data packet is transmitted, a second message is sent to the electronic control unit, and the second message includes the last sub-data packet of the upgrade data packet and a command to exit the programming mode.

[0022] In this application, when flashing the electronic control unit corresponding to the software to be upgraded, a maintain programming mode command is added to the message transmitting the upgrade data, so that the electronic control unit always remains in programming mode during the flashing process and will not exit programming mode midway due to failure to receive the maintain programming mode command, thereby interrupting the software upgrade. When the flashing is completed, the last data transmission message carries the exit programming mode command, so that the electronic control unit can immediately exit programming mode when the flashing is completed, without waiting for a timeout, and can directly exit, effectively improving the upgrade efficiency of the vehicle software. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments of the present application. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0024] Figure 1 1 is a schematic diagram of OTA Ethernet-based data transmission proposed in one embodiment of the present application; Figure 2 This is a schematic diagram of OTA data transmission based on the CAN bus proposed in one embodiment of the present application; Figure 3 This is a schematic diagram of the connection relationship and structure between the master control, proxy layer, and slave control proposed in one embodiment of the present application; Figure 4 This is a flow chart of a vehicle software upgrade method proposed in one embodiment of the present application; Figure 5 This is a diagram of the message format based on Ethernet transmission; Figure 6 This is a schematic diagram of the CAN bus message format; Figure 7 This is a schematic diagram of communication between the OTA master control and the ECU component proposed in one embodiment of the present application; Figure 8 This is a schematic diagram of an Ethernet connection proposed in an embodiment of the present application; Figure 9 This is a schematic diagram of protocol format conversion proposed in one embodiment of the present application; Figure 10 is a schematic diagram of a vehicle software upgrade device proposed in one embodiment of the present application; Figure 11 FIG. 1 is a schematic diagram of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION

[0025] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0026] refer to Figure 1 and Figure 2 , Figure 1 This is a schematic diagram of OTA data transmission based on Ethernet proposed in one embodiment of the present application. Figure 2 This is a schematic diagram of OTA data transmission based on CAN bus proposed in one embodiment of the present application. Figure 1 as well as Figure 2 As shown in the figure, the vehicle upgrade process mainly involves OTA upgrade master (UMC, Universal Mobile Communications System), OTA upgrade agent (UA, User Area) OTA upgrade slave (US, UltraStation) and so on. Figure 1 For example, the OTA upgrade master, OTA upgrade agent, and OTA upgrade slave are implemented in the CDC (Smart Cockpit Domain Controller), VGW (Vehicle Gateway), and the ECU (Electronic Control Unit) being flashed. The CDC and VGW are connected via Ethernet (ETH) or CAN bus. The VGW is connected to each ECU component under it via Ethernet or CAN bus, and one or more ECU components are connected to it. Figure 3 , Figure 3 This is a schematic diagram of the connection relationship and structure between the master control, proxy layer, and slave control proposed in an embodiment of the present application. Figure 3 As shown in the figure, the OTA upgrade master can send data to the OTA slave through the CAN bus, or send data to the proxy layer through the DOIP (Diagnostic communication over Internet Protocol, Ethernet-based diagnostic communication) protocol, and then the proxy layer forwards the data to the OTA slave.

[0027] refer to Figure 4 , Figure 4 This is a flow chart of a vehicle software upgrade method proposed in one embodiment of the present application. Figure 4As shown, the method specifically includes the following steps: S11: Obtain an upgrade data package corresponding to the software to be upgraded in the vehicle.

[0028] In this embodiment, the software to be upgraded is the software in the vehicle that needs to be upgraded and runs in the corresponding electronic control unit. The upgrade data packet is the data packet of the latest version of the software to be upgraded in the server.

[0029] In this embodiment, the vehicle OTA upgrade master controller first compares the version number of the vehicle software with the latest version number of the vehicle software in the server. If the version number of the software in the vehicle is lower than the version number of the software in the server, the upgrade data packet corresponding to the software to be upgraded is obtained from the server.

[0030] For example, the version number of the software to be upgraded in the vehicle is 1.0.0.1, and the version number of the software in the server is 1.0.0.2, so the vehicle software needs to be upgraded.

[0031] S12: Switching the electronic control unit corresponding to the software to be upgraded to a programming mode.

[0032] In this embodiment, the ECU is essentially an embedded computer system. As the "central nervous system" of the vehicle's electronic architecture, it precisely controls various vehicle systems by receiving sensor signals, executing algorithms, and driving actuators. Modern vehicles typically have multiple ECUs, forming a distributed control network. The programming mode is the mode that the ECU must maintain during upgrades and refreshes.

[0033] In this embodiment, the OTA master first sends a preset command to make all the electronic control units of the vehicle enter the OTA mode, so that all the electronic control units of the vehicle are ready for OTA upgrade, and then sends a preset command to make each electronic control unit to be upgraded enter the extended mode. In the extended mode, the electronic control unit can open all receptions to better perform software upgrades, and then sends a preset command to make each electronic control unit to be upgraded enter the programming mode, waiting for OTA upgrade flashing.

[0034] S13: Continuously sending a first message to the electronic control unit through a corresponding data transmission protocol, where the first message includes a plurality of sub-data packets of the upgrade data packet and a maintain programming mode command.

[0035] In this embodiment, the first message includes multiple sub-data packets of the upgrade data packet and a maintain programming mode command, and the maintain programming mode command is used to notify the electronic control unit to remain in the programming mode and not exit.

[0036] In this embodiment, the upgrade data transmission process splits a large upgrade data packet into multiple smaller sub-packets, which are then transmitted via messages. A command to maintain programming mode is added to the first message and sent to the ECU simultaneously with the upgrade data packet. For ECUs supporting the Diagnostic Communication over Internet Protocol (DOIP), transmission is performed directly using DOIP messages. For ECUs supporting the CAN bus, transmission is performed using UDS messages. DOIP messages can also be converted to UDS messages by the master control agent layer and forwarded to the ECU.

[0037] For example, the upgrade data packet is divided into 10 sub-data packets, and 9 sub-data packets are continuously sent to the electronic control unit within a period of time, and the message carries a command to maintain the programming mode.

[0038] S14: When the transmission reaches the last sub-data packet of the upgrade data packet, a second message is sent to the electronic control unit, where the second message includes the last sub-data packet of the upgrade data packet and a command to exit programming mode.

[0039] In this embodiment, the second message includes the last sub-data packet of the upgrade data packet and an exit programming mode command. The exit programming mode command is used by the electronic control unit to exit programming mode and switch to application mode. All software in the vehicle is upgraded and can be used normally.

[0040] In this embodiment, when the OTA master is transmitting an upgrade data packet to the electronic control unit and is about to transmit the last sub-data packet, the electronic control unit only needs to complete the flashing of the last data packet, and a second message is sent to the electronic control unit to send the last sub-data packet of the upgrade data packet and the exit programming mode command to the electronic control unit. The electronic control unit immediately exits the programming mode after completing the flashing of the last sub-data packet.

[0041] For example, when the second message is in DOIP format, the message content is: 02, fd, 8001, N (data length: 8-4095 bytes), 0E80 ECUx (ECU address), 37, seqx, 3E, 92, XXXXXX (transmission data), where 02 is the protocol version number, fd is the inverted version value used to verify the correctness of the version number, 8001 indicates that the recipient has correctly received the diagnostic request and returned valid data, N is the byte length of the subsequent transmission data, 0E80 ECUx is the electronic control unit address, 37 is the exit programming mode service, seqx is the message sequence number used to track the communication process, and 3E, 92 is the exit programming mode command. When the second message is a UDS message, the message content is: ECUID, 37, seqx, 3E, 92, XXXXXX (transmission data), where ECUID is the electronic control unit ID, 37 is the exit programming mode service, seqx is the message sequence number, and 3E, 92 is the exit programming mode command.

[0042] In this embodiment, when the vehicle software is upgraded, the upgrade data and the command to maintain the programming mode are added to the message, which avoids the problem of timeout exit from the programming mode due to network congestion or long flashing time during data transmission, resulting in upgrade flashing interruption and failure. The success rate of the upgrade flashing is effectively improved. When the flashing is completed, the exit programming mode command is carried in the data transmission message, so that the programming mode can be exited in time without waiting for the delay of timeout exit. When multiple electronic control unit software need to be flashed, the waiting time for flashing is effectively saved.

[0043] In another embodiment of the present application, obtaining an upgrade data packet corresponding to the software to be upgraded in the vehicle includes: S21: Obtain the first version number of the software to be upgraded.

[0044] In this embodiment, the first version number is the version number of the vehicle-side software to be upgraded.

[0045] In this embodiment, the OTA upgrade master controller first obtains information of each software to be upgraded, where the software information includes the version number of the software to be upgraded.

[0046] For example, if the software to be upgraded is camera control software, the version number of the camera control software is obtained.

[0047] S22: Compare the first version number with the second version number corresponding to the software to be upgraded in the server.

[0048] In this embodiment, the second version number is the version number of the latest version of the software in the server.

[0049] In this embodiment, the first version number is compared with the second version number of the software corresponding to the software to be upgraded in the server.

[0050] For example, the software to be upgraded is camera control software, and the first version number of the software is compared with the version number of the latest version of the camera control software in the server.

[0051] S23: When the first version number is lower than the second version number, download the upgrade data package from the server.

[0052] In this embodiment, if the first version number of the vehicle software is lower than the second version number of the software in the server, it means that the version of the software to be upgraded in the vehicle is lower than the version in the server. At this time, the corresponding upgrade data packet is downloaded from the server, and the upgrade data packet is temporarily stored in the storage space corresponding to the OTA upgrade master. After the upgrade is completed, the temporarily stored data packet is cleared.

[0053] In this embodiment, when a new version of the software in the server is released, the OTA upgrade master promptly downloads the upgrade data package, ensuring real-time updating of the vehicle software.

[0054] In another embodiment of the present application, switching the electronic control unit corresponding to the software to be upgraded to a programming mode includes: S31: Sending a first command to the electronic control unit to enable the electronic control unit to enter an OTA mode.

[0055] In this embodiment, the OTA master first sends a first command to the electronic control unit. After receiving the first command, each electronic control unit of the vehicle enters the OTA mode.

[0056] For example, when activating vehicle OTA mode via command 31 01 02 04, the ECU performs global condition checks, including key hardware status checks (such as battery voltage and ignition status) and bus load monitoring. This centralized pre-check prevents flash interruptions or hardware damage caused by sudden system condition changes (such as an unexpected vehicle start) after a single ECU enters programming mode.

[0057] S32: Send a second command to the electronic control unit to enable the electronic control unit to enter an extended mode.

[0058] In this embodiment, after all electronic control units of the vehicle enter the OTA mode, the OTA master sends a second command to the electronic control unit, and the electronic control unit enters the extended mode to obtain higher authority, namely administrator authority.

[0059] In this embodiment, while the extended session (1003) provides higher operational permissions, its permissions are still limited to the current session type. Only when the vehicle is in OTA mode do some ECUs open special encrypted channels and memory erase and write interfaces. This layered authorization mechanism reduces the impact of unexpected operations on the vehicle's core functions.

[0060] S33: Send a third command to the electronic control unit to enable the electronic control unit to enter the programming mode.

[0061] In this embodiment, after the electronic control unit enters the extended mode, the OTA upgrade master sends a third command to the electronic control unit. After receiving the command, the electronic control unit enters the programming mode and waits for OTA upgrade flashing.

[0062] In this embodiment, OTA mode maintains the session and freezes non-essential communications via 3E 80, eliminating interference from regular CAN / LIN messages (such as instrument panel status updates and periodic body control module signals) during the flash process. Directly entering programming mode can cause packet conflicts or timing anomalies due to dynamic bus loads, impacting the stability of services 34 / 36 / 37.

[0063] In another embodiment of the present application, continuously sending the first message to the electronic control unit through the corresponding data transmission protocol includes: S41: When the electronic control unit communicates via Ethernet, continuously sending the first message to the electronic control unit via an Ethernet-based communication diagnostic protocol.

[0064] In this embodiment, when the electronic control unit communicates via Ethernet, the OTA master continuously sends the first message to the electronic control unit via an Ethernet-based communication diagnostic protocol.

[0065] refer to Figure 5 , Figure 5 This is a diagram of the message format based on Ethernet transmission, such as Figure 5 As shown in the figure, the DOIP protocol is used to communicate and upgrade with the VGW and the target ECU that supports the DOIP protocol. The upgrade diagnostic data communication message format is customized in the standard DOIP protocol data area. The message consists of fields such as the source logical address (0x0e80) for identifying the OTA master and the destination ECU logical address.

[0066] For example, the DOIP message format is: 02, fd, 8001, N (data length: 8 to 4095 bytes), 0E80 ECUx (ECU address), 36, seqx, 3E, 91, XXXXXX (transmitted data), where 36 is the hold programming mode service. 3E, 91 represents the hold programming mode command, which commands the electronic control unit to enter and remain in programming mode. Upgrade data can only be written to the ECU memory area while in programming mode.

[0067] S42: When the electronic control unit communicates via a controller area network bus, continuously sending a first message to the electronic control unit via a unified diagnostic protocol.

[0068] In this embodiment, when the electronic control unit communicates via the controller area network bus, the OTA upgrade master continuously sends the first message to the electronic control unit via the unified diagnostic protocol.

[0069] refer to Figure 6 , Figure 6 This is a diagram of the CAN bus message format, such as Figure 6 As shown in the figure, it includes an 11-bit destination address field, a 1-bit other content field, a 4-bit message length field, a 4-bit frame type field, a 4-bit data length field, an 11-bit source address field, a 4-bit priority field, a 1-bit broadcast flag field, and a 1-bit CRC check field. The CAN bus message is a UDS (Unified Diagnostic Services) message.

[0070] For example, the UDS message format is: ECUID, 36, seqx, 3E, 91, XXXXXX (transmission data), 36 is the hold programming mode service, and 3E, 91 is the hold programming mode command.

[0071] In this embodiment, after S42, the method further includes: S43: When the OTA upgrade master is connected to the electronic control unit through the OTA proxy layer, the first message is sent to the OTA proxy layer through the Ethernet-based communication diagnostic protocol, so that the OTA proxy layer sends the first message to the electronic control unit through the unified diagnostic protocol.

[0072] In this embodiment, some OTA upgrade master controls are connected to the OTA proxy layer, the OTA proxy layer is connected to the OTA slave control in the electronic control unit, the OTA upgrade master control and the proxy layer are connected via Ethernet, and the proxy layer and the slave control are connected via the controller LAN bus. The OTA upgrade master control sends a first message to the proxy layer via the DOIP protocol, and the proxy layer converts the first message into a second message and sends it to the slave control via the UDS protocol.

[0073] refer to Figure 7 , Figure 7 This is a schematic diagram of the communication between the OTA master control and the ECU device proposed in one embodiment of the present application, such as Figure 7 As shown in the figure, OTA communicates with the target ECU via Ethernet or CAN. DOIP is used for ECUs that support Ethernet, while UDS is used for ECUs that do not. CDC, VGW, and ECUs that do not support Ethernet communication convert DOIP messages to UDS messages to ensure compatibility between DOIP and UDS protocols.

[0074] refer to Figure 8 , Figure 8 This is a schematic diagram of an Ethernet connection proposed in an embodiment of the present application. Figure 8 As shown in the figure, the OTA master controller (UMC) is connected to the proxy layer through the CAN bus, and the proxy layer is also connected to the ECU through the CAN bus. At this time, data communication is directly carried out through the UDS message of the CAN bus.

[0075] refer to Figure 9 , Figure 9 This is a schematic diagram of the protocol format conversion proposed in one embodiment of the present application. Figure 9 As shown in the figure, when the OTA master controller transmits data to the ECU to be upgraded, if the OTA UMC and OTA UA / US are connected via Ethernet, the DOIP protocol format is used for data transmission. The OTA UMC needs to communicate with the OTA UA, and the OTA US and OTA UA use the CAN bus. The OTA UA converts the DOIP message into UDS for data transmission.

[0076] In this embodiment, a command including upgrade data and maintaining programming mode is sent to the electronic control unit through a corresponding protocol, thereby improving data transmission efficiency and reducing network congestion.

[0077] In another embodiment of the present application, before switching the electronic control unit corresponding to the software to be upgraded to a programming mode, the method further includes: S51: Sending security authentication information to the electronic control unit corresponding to the software to be upgraded.

[0078] In this embodiment, the security authentication information is used to verify whether the electronic control unit is in a normal operating state and can perform software upgrade and flashing normally.

[0079] In this embodiment, before switching modes, the OTA upgrade master first sends security authentication information to each electronic control unit corresponding to the software to be upgraded.

[0080] For example, the security authentication information is sent via a preset 27 01 instruction.

[0081] S52: If the safety certification fails, remove the electronic control unit from the upgrade sequence.

[0082] In this embodiment, if the security authentication fails, it means that the electronic control unit cannot be flashed and upgraded normally, and the electronic control unit is removed from the upgrade sequence.

[0083] S53: Report the security authentication failure error code to the server.

[0084] In this embodiment, the security authentication failure error code is a corresponding code generated when security authentication fails.

[0085] In this embodiment, when the OTA upgrade master fails in the security authentication of the electronic control unit, a security authentication failure error code is reported to the server.

[0086] In this embodiment, security authentication is performed on the electronic control unit to ensure that the upgrade and flashing process proceeds normally.

[0087] In another embodiment of the present application, the method further includes: S61: upon receiving the timeout inquiry information sent by the electronic control unit, determining whether the upgrade data packet has been completely transmitted.

[0088] In this embodiment, the timeout inquiry information is a message sent by the electronic control unit to the OTA upgrade main control when the electronic control unit does not receive the command to maintain the programming mode within a preset time, and is used to inquire whether to exit the programming mode.

[0089] In this embodiment, the OTA upgrade master may encounter problems such as network failure, and fail to send a message to the electronic control unit within the preset time. At this time, the electronic control unit sends a timeout query message to the OTA master. After receiving the message, the OTA master determines whether the upgrade data packet has been transmitted.

[0090] For example, if the electronic control unit does not receive a message within 5 seconds, it will actively send a message to the OTA master control to inquire whether to exit the programming mode. After receiving the inquiry information, the OTA master control checks whether the corresponding upgrade data has been transmitted. If the upgrade is completed, it sends an exit programming mode instruction to the electronic control unit. If the upgrade is not completed, it continues to send the first message.

[0091] S62: When the upgrade data packet has not been completely transmitted, continue to transmit the first message.

[0092] In this embodiment, the OTA master controller continues to transmit the first message to the electronic control unit when the upgrade data packet has not been completely transmitted.

[0093] S63: When the upgrade data package is completely transmitted, a command to exit programming mode is sent to the electronic control unit.

[0094] In this embodiment, when the upgrade data packet transmission is completed, the OTA upgrade master sends an exit programming mode command to the electronic control unit, so that the electronic control unit exits the programming mode.

[0095] In this embodiment, when the electronic control unit does not receive upgrade data for a long time, it will actively ask the OTA upgrade master whether to exit the programming mode. There is no need to wait, which increases the efficiency of vehicle software upgrades.

[0096] Based on the same inventive concept, an embodiment of the present application provides a vehicle software upgrade device. Figure 10 , Figure 10 FIG is a schematic diagram of a vehicle software upgrade device 1000 proposed in one embodiment of the present application. Figure 10 As shown, the device includes: The upgrade data packet acquisition module 1001 is used to acquire the upgrade data packet corresponding to the software to be upgraded in the vehicle; A mode switching module 1002 is configured to switch the electronic control unit corresponding to the software to be upgraded to a programming mode; A first message sending module 1003 is configured to continuously send a first message to the electronic control unit through a corresponding data transmission protocol, wherein the first message includes multiple sub-data packets of the upgrade data packet and a maintain programming mode command; The second message sending module 1004 is used to send a second message to the electronic control unit when the last sub-data packet of the upgrade data packet is transmitted, where the second message includes the last sub-data packet of the upgrade data packet and a command to exit programming mode.

[0097] Optionally, the upgrade data packet acquisition module includes: A first version number acquisition submodule, configured to acquire a first version number of the software to be upgraded; A version number comparison submodule, configured to compare the first version number with a second version number corresponding to the software to be upgraded in the server; The upgrade data package downloading submodule is used to download the upgrade data package from the server when the first version number is lower than the second version number.

[0098] Optionally, the mode switching module includes: A first mode switching submodule is configured to send a first command to the electronic control unit to enable the electronic control unit to enter the OTA mode; a second mode switching submodule, configured to send a second command to the electronic control unit to enable the electronic control unit to enter the extended mode when the electronic control unit enters the OTA mode; The third mode switching submodule is configured to send a third command to the electronic control unit when the electronic control unit enters the extended mode, so as to enable the electronic control unit to enter the programming mode.

[0099] Optionally, the first message sending module includes: a first sending submodule, configured to continuously send the first message to the electronic control unit through a communication diagnostic protocol based on Ethernet when the electronic control unit communicates through Ethernet; The second sending submodule is configured to continuously send a first message to the electronic control unit through a unified diagnostic protocol when the electronic control unit communicates through a controller area network bus.

[0100] Optionally, the first message sending module further includes: The third sending submodule is used to send the first message to the OTA proxy layer through the Ethernet-based communication diagnostic protocol when the OTA upgrade master is connected to the electronic control unit through the OTA proxy layer, so that the OTA proxy layer sends the first message to the electronic control unit through the unified diagnostic protocol.

[0101] Optionally, the device further comprises: A security authentication information sending module, configured to send security authentication information to the electronic control unit corresponding to the software to be upgraded; An upgrade stop module, configured to remove the electronic control unit from an upgrade sequence if the safety certification fails; The error code reporting module is used to report the security authentication failure error code to the server.

[0102] Optionally, the device further comprises: a timeout inquiry information receiving module, configured to determine whether the upgrade data packet has been transmitted after receiving the timeout inquiry information sent by the electronic control unit; a message sending module, configured to continue transmitting the first message when the upgrade data packet has not been completely transmitted; The exit command sending module is used to send an exit programming mode command to the electronic control unit when the transmission of the upgrade data packet is completed.

[0103] Based on the same inventive concept, another embodiment of the present application provides an electronic device, Figure 11 It is a schematic diagram of an electronic device 1100 proposed in one embodiment of the present application, including a memory 1102, a processor 1101 and a computer program stored in the memory and executable on the processor, wherein the processor, when executed, implements the vehicle software upgrade method described in any of the above embodiments of the present application.

[0104] As for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0105] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.

[0106] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, devices, or computer program products. Therefore, the embodiments of the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the embodiments of the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0107] The embodiments of the present application are described with reference to the flowcharts and / or block diagrams of the methods, terminal devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable in-vehicle safety terminal device to produce a machine, so that the instructions executed by the processor of the computer or other programmable in-vehicle safety terminal device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1A device that provides the functions specified in a block or multiple blocks.

[0108] These computer program instructions can also be stored in a computer readable memory that can guide a computer or other programmable in-vehicle security terminal device to work in a specific manner, so that the instructions stored in the computer readable memory produce a product including an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0109] These computer program instructions can also be loaded onto a computer or other programmable in-vehicle safety terminal device, so that a series of operation steps are executed on the computer or other programmable terminal device to produce a computer-implemented process, thereby providing instructions for implementing the process in the computer or other programmable terminal device. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0110] Although preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they become aware of the basic inventive concepts. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present invention.

[0111] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that includes a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or terminal device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or terminal device that includes the element.

[0112] The above is a detailed introduction to the vehicle software upgrade method, device, equipment and storage medium provided by this application. Specific examples are used in this article to illustrate the principles and implementation methods of this application. The description of the above embodiments is only used to help understand the method of this application and its core idea; at the same time, for general technical personnel in this field, based on the ideas of this application, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on this application.

Claims

1. A vehicle software upgrade method, characterized in that: The method comprises: Obtain the upgrade data package corresponding to the software to be upgraded in the vehicle; Switching the electronic control unit corresponding to the software to be upgraded to a programming mode; continuously sending a first message to the electronic control unit through a corresponding data transmission protocol, wherein the first message includes a plurality of sub-data packets of the upgrade data packet and a maintain programming mode command; When the last sub-data packet of the upgrade data packet is transmitted, a second message is sent to the electronic control unit, where the second message includes the last sub-data packet of the upgrade data packet and a command to exit programming mode.

2. The vehicle software upgrade method according to claim 1, characterized in that: The obtaining of an upgrade data packet corresponding to the software to be upgraded in the vehicle includes: Obtaining a first version number of the software to be upgraded; Comparing the first version number with the second version number corresponding to the software to be upgraded in the server; When the first version number is lower than the second version number, the upgrade data package is downloaded from the server.

3. The vehicle software upgrade method according to claim 1, characterized in that: Switching the electronic control unit corresponding to the software to be upgraded to a programming mode includes: Sending a first command to the electronic control unit to enable the electronic control unit to enter an OTA mode; When the electronic control unit enters the OTA mode, sending a second command to the electronic control unit to enable the electronic control unit to enter the extended mode; When the electronic control unit enters the extended mode, a third command is sent to the electronic control unit to enable the electronic control unit to enter the programming mode.

4. The vehicle software upgrade method according to claim 1, characterized in that: The continuously sending the first message to the electronic control unit through the corresponding data transmission protocol includes: When the electronic control unit communicates via Ethernet, continuously sending the first message to the electronic control unit via an Ethernet-based communication diagnostic protocol; In a case where the electronic control unit communicates via a controller area network bus, a first message is continuously sent to the electronic control unit via a unified diagnostic protocol.

5. The vehicle software upgrade method according to claim 4, characterized in that: The method further comprises: When the OTA upgrade master is connected to the electronic control unit through the OTA proxy layer, the first message is sent to the OTA proxy layer through the Ethernet-based communication diagnostic protocol, so that the OTA proxy layer sends the first message to the electronic control unit through the unified diagnostic protocol.

6. The vehicle software upgrade method according to claim 1, characterized in that: Before switching the electronic control unit corresponding to the software to be upgraded to a programming mode, the method further includes: Sending security authentication information to the electronic control unit corresponding to the software to be upgraded; If the safety certification fails, removing the electronic control unit from the upgrade sequence; Report the security authentication failure error code to the server.

7. The vehicle software upgrade method according to claim 1, characterized in that: The method further comprises: Upon receiving a timeout inquiry message sent by the electronic control unit, determining whether the upgrade data packet has been transmitted; If the upgrade data packet has not been completely transmitted, continue transmitting the first message; When the upgrade data packet is completely transmitted, a command to exit programming mode is sent to the electronic control unit.

8. A vehicle software upgrade device, characterized in that: The device comprises: An upgrade data packet acquisition module is used to acquire the upgrade data packet corresponding to the software to be upgraded in the vehicle; A mode switching module, configured to switch the electronic control unit corresponding to the software to be upgraded to a programming mode; A first message sending module, configured to continuously send a first message to the electronic control unit through a corresponding data transmission protocol, wherein the first message includes a plurality of sub-data packets of the upgrade data packet and a maintain programming mode command; The second message sending module is used to send a second message to the electronic control unit when the last sub-data packet of the upgrade data packet is transmitted, and the second message includes the last sub-data packet of the upgrade data packet and a command to exit the programming mode.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.

10. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the method according to any one of claims 1 to 7 is implemented.