Safety control method and device for vehicle firmware upgrading, computer equipment and medium
By monitoring and matching the vehicle status with the preset conditions of the target electronic control unit, the vehicle is allowed to enter creep mode in parking mode, resolving the safety hazard caused by the failure of the electronic control unit upgrade and ensuring the safety and reliability of the vehicle during the firmware upgrade process.
Patent Information
- Application Number
- CN202511271667.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-08
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2045-09-08
AI Technical Summary
During the vehicle firmware upgrade process, when the electronic control unit upgrade fails, the existing technology fails to effectively prohibit the vehicle from driving autonomously, resulting in the user being unable to make necessary position adjustments, posing a safety hazard.
In parking mode, the system monitors target electronic control units that have failed to be upgraded, obtains vehicle status and detects whether it matches preset conditions. The system allows the vehicle to enter creep mode only when the entry conditions for creep mode are met, and ensures safe driving by adjusting the control parameters of the control system.
It allows the vehicle to travel in a restricted creep mode while ensuring safety, avoiding safety hazards caused by failed electronic control unit upgrades and improving the safety and reliability of vehicle firmware upgrades.
Smart Images

Figure CN120756485A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of firmware upgrades, and in particular to a security control method, device, computer equipment, and medium for vehicle firmware upgrades. Background Art
[0002] During an OTA firmware upgrade, the electronic control unit (ECU) may fail. When a software upgrade involving a safety-related system fails, the vehicle must be kept in a safe state (even if this restricts its functionality). This is especially true when ECUs such as the power control unit and braking system fail, often requiring the vehicle to disable autonomous driving.
[0003] Current firmware upgrade solutions have certain limitations when dealing with upgrade failures: after an upgrade fails, users are often only notified of the installation results and asked to contact after-sales service or use the vehicle with caution, without directly disabling the vehicle. As for the situation where driving is prohibited when the electronic control unit fails, the existing solution does not establish a mechanism to activate restricted mobility within the permitted range. If driving is completely prohibited, users will be unable to make necessary position adjustments (such as moving the vehicle out of a dangerous area) after the upgrade fails. Summary of the Invention
[0004] In view of this, embodiments of the present invention provide a security control method, apparatus, computer equipment, and medium for vehicle firmware upgrades to solve the problem of how to achieve necessary position adjustments by allowing the vehicle to travel in a restricted creep mode while ensuring safety after a vehicle firmware upgrade fails.
[0005] In a first aspect, an embodiment of the present invention provides a method for controlling security of vehicle firmware upgrades, the method comprising: When the vehicle is undergoing a firmware upgrade in parking mode, monitoring a target electronic control unit in the vehicle that has failed to be upgraded, wherein the target electronic control unit is any electronic control unit in the vehicle; Acquiring a vehicle state of the vehicle, and detecting whether the vehicle state and the target electronic control unit both meet corresponding preset conditions; If the target electronic control unit and the vehicle state both meet corresponding preset conditions, the vehicle is allowed to enter the creep mode.
[0006] Furthermore, the detecting whether the vehicle state and the target electronic control unit both meet corresponding preset conditions includes: detecting whether the vehicle state meets an entry condition associated with the creeping mode, and obtaining a first detection result; Obtaining an electronic control unit list, wherein the electronic control unit list includes multiple electronic control units and a driving strategy corresponding to each electronic control unit; Acquire the target driving strategy corresponding to the target electronic control unit from the electronic control unit list; detecting whether the target driving strategy meets an entry condition associated with the creeping mode, and obtaining a second detection result; It is determined whether the vehicle state and the target electronic control unit meet corresponding preset conditions according to the first detection result and the second detection result.
[0007] Furthermore, determining whether the vehicle state and the target electronic control unit meet corresponding preset conditions based on the first detection result and the second detection result includes: If the first detection result is that the vehicle state hits the entry condition associated with the creeping mode, and the second detection result is that the target driving strategy hits the entry condition associated with the creeping mode, then determining that the vehicle state and the target electronic control unit both meet corresponding preset conditions; If the first detection result is that the vehicle state does not hit the entry conditions associated with the creeping mode, or the second detection result is that the target driving strategy does not hit the entry conditions associated with the creeping mode, it is determined that the vehicle state and / or the target electronic control unit do not meet the corresponding preset conditions.
[0008] Furthermore, after allowing the vehicle to enter the creep mode, the method further includes: When the vehicle is in a creeping mode, obtaining driving state parameters of the vehicle in the creeping mode, wherein the driving state parameters include speed parameters, displacement parameters, and control parameters; Matching the driving state parameter with the creep parameter in the target driving strategy corresponding to the target electronic control unit to obtain a matching result; The control parameters of the control system in the vehicle are adjusted based on the matching result, so that the control system controls the vehicle to travel according to the adjusted control parameters.
[0009] Furthermore, adjusting the control parameters of the control system in the vehicle based on the matching result includes: If the matching result is that the speed parameter is greater than the speed threshold in the creep parameter, adjusting the traction parameter of the control system in the vehicle, and monitoring whether the speed parameter of the vehicle drops to the speed threshold within a preset time period; if it does not drop to the speed threshold, adjusting the braking parameter of the control system in the vehicle until the speed parameter of the vehicle is less than or equal to the speed threshold; Alternatively, if the matching result is that the displacement parameter is greater than the distance threshold in the creep parameter, and / or the control parameter does not meet the preset control parameter in the creep parameter, the vehicle is allowed to enter the parking mode.
[0010] Furthermore, after detecting whether the vehicle state and the target electronic control unit both meet corresponding preset conditions, the method further includes: Generate corresponding prompt information according to the vehicle status and / or the target electronic control unit; The vehicle is controlled to perform a corresponding prompt operation based on the prompt information.
[0011] Furthermore, the method further comprises: When the vehicle is in the creep mode, the vehicle is allowed to enter the normal driving mode in response to a creep exit command.
[0012] In a second aspect, an embodiment of the present invention provides a security control device for vehicle firmware upgrade, the device comprising: a monitoring module, configured to monitor a target electronic control unit in the vehicle that has failed to be upgraded when the vehicle is undergoing a firmware upgrade in the parking mode, wherein the target electronic control unit is any electronic control unit in the vehicle; a detection module, configured to obtain a vehicle state of the vehicle and detect whether the vehicle state and the target electronic control unit both meet corresponding preset conditions; The determination module is configured to allow the vehicle to enter a creep mode if both the target electronic control unit and the vehicle state meet corresponding preset conditions.
[0013] In a third aspect, an embodiment of the present invention provides a computer device comprising: a memory and a processor, the memory and the processor being communicatively connected to each other, computer instructions being stored in the memory, and the processor executing the method of the first aspect or any corresponding embodiment thereof by executing the computer instructions.
[0014] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium having computer instructions stored thereon, the computer instructions being used to enable a computer to execute the method of the first aspect or any corresponding embodiment thereof.
[0015] The method provided in the embodiments of the present application has the following beneficial effects: The method provided by the embodiment of the application can discover abnormal conditions in the firmware upgrading process in time by monitoring the target electronic control unit that fails to upgrade during the firmware upgrading process of the vehicle in the parking mode, avoids the security risks of the vehicle in the driving process caused by the failure of the electronic control unit upgrading, and effectively guarantees the safety of the vehicle during firmware upgrading; the vehicle is allowed to enter the inching mode only when the vehicle state and the target electronic control unit both meet the corresponding preset conditions, the vehicle is prevented from entering the driving state under the condition that the safety requirements are not met by strict condition judgment, the electronic control unit that fails to upgrade is prevented from causing adverse effects on the normal driving of the vehicle, and the safety and reliability of the vehicle in the driving process under abnormal conditions of firmware upgrading are improved. BRIEF DESCRIPTION OF DRAWINGS
[0016] In order to more clearly illustrate the technical solutions in the specific embodiments or the prior art, the following will briefly introduce the drawings needed to be used in the specific embodiments or the prior art description. Obviously, the drawings in the following description are some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0017] Figure 1 FIG. 1 is a flowchart of a safety control method for vehicle firmware upgrading according to an embodiment of the present application; Figure 2 FIG. 2 is a flowchart of another safety control method for vehicle firmware upgrading according to an embodiment of the present application; Figure 3 FIG. 3 is a structural block diagram of a safety control device for vehicle firmware upgrading according to an embodiment of the present application; Figure 4 FIG. 4 is a hardware structure schematic diagram of a computer device according to an embodiment of the present application. DETAILED DESCRIPTION
[0018] In order to make the purpose, technical solutions and advantages of the embodiments of the present application more clear, the technical solutions in the embodiments of the present application will be described clearly and completely in the following with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the protection scope of the present application.
[0019] According to the embodiment of the present application, a vehicle firmware upgrade security control method, device, computer equipment and medium are provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a group of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from here.
[0020] In the present embodiment, a vehicle firmware upgrade security control method is provided, Figure 1 is a flowchart of the vehicle firmware upgrade security control method according to the embodiment of the present application, as Figure 1 shown, the flow includes the following steps: Step 101, in the process of vehicle firmware upgrade in the parking mode, the target electronic control unit in the vehicle which fails to upgrade is monitored, and the target electronic control unit is any electronic control unit in the vehicle.
[0021] In the present embodiment, in the process of firmware upgrade (OTA installation process executed by FOTA master) when the vehicle is in the parking mode (i.e. the vehicle is stationary and the driving is prohibited), the target electronic control unit (target ECU) which fails to upgrade in the vehicle is monitored. The parking mode is the vehicle state triggered by FOTA master before OTA installation preparation stage, at this time the vehicle is prohibited to drive (driving mode is disabled). Firmware upgrade refers to the distribution, flashing and verification process of OTA installation package executed by FOTA master. The target electronic control unit refers to any one or more electronic control units (such as brake control unit, body control module, etc.) which fail in the firmware upgrade process. The monitoring method refers to that FOTA master actively detects the installation result state (such as verification signature, version number or function self-check) of each electronic control unit in the post-installation verification stage, and identifies the target electronic control unit which fails.
[0022] In the OTA installation package download and verification stage, the network connection stability can also be monitored in real time to ensure the integrity of the upgrade package. The specific process is as follows: before obtaining the upgrade package, FOTA master detects the network signal strength, transmission rate and packet loss rate through the vehicle communication module (such as 5G / 4G); if the network signal is lower than the preset threshold (such as -100dBm) or the packet loss rate exceeds 5%, try to switch to the standby network (such as Wi-Fi) or prompt the user to manually connect to a stable network; during the transmission of the upgrade package, the network state is continuously monitored, if the transmission is interrupted, the transmission is paused and the received data is cached, and after the network is restored, the transmission is continued to ensure the integrity of the upgrade package.
[0023] Step S102, obtaining the vehicle state of the vehicle, and detecting whether the vehicle state and the target electronic control unit meet the corresponding preset conditions.
[0024] It should be noted that the vehicle status refers to the functional status of the vehicle's core control system and the battery status. This is to comprehensively assess the vehicle's basic operating capabilities in the event of an abnormal firmware upgrade and provide a basis for determining whether to allow entry into creep mode. Specifically, it includes the following: On the one hand, the functional status of multiple key control systems in the vehicle, including but not limited to the powertrain, steering system, and drive system, is obtained. Relevant data is collected through internal vehicle sensors, diagnostic modules, and the self-check mechanisms of each system: the powertrain determines whether it is in normal working condition by detecting engine (or motor) operating parameters (such as speed, output power), fault codes, and other information; the steering system determines whether its function is normal by checking the validity of the wire control logic and the smooth operation of the mechanical steering structure; the drive system evaluates whether it is in normal condition by monitoring the command response of the control module and the operation status of the actuators (such as brakes and transmission components).
[0025] During the pre-installation phase, the vehicle's battery status can also be monitored. After triggering parking mode, FOTAmaster uses the Battery Management System (BMS) to collect key battery parameters in real time, including battery charge, voltage, and temperature. It then determines whether the charge level is above a preset threshold (e.g., 20%) and whether the voltage is stable within a normal range (e.g., 12V±0.5V), thereby confirming the battery's normal status.
[0026] In an embodiment of the present application, when detecting whether both the vehicle state and the target electronic control unit meet the corresponding preset conditions, it is specifically manifested as follows: when the target electronic control unit is an entertainment control unit or an air conditioning control unit (whose corresponding driving strategy is not affecting the core vehicle control and allowing creeping), and the vehicle's power system, steering system, and drive system functions are normal and the battery status meets the standard (the first detection result is met), its target driving strategy also meets the creeping mode access condition (the second detection result is met), so it is determined that both meet the preset conditions and the vehicle is allowed to enter the creeping mode; when the target electronic control unit is a braking control unit (whose corresponding driving strategy is affecting the core braking function and prohibiting creeping), even if the vehicle state meets the standard (the first detection result is met), but the target driving strategy does not hit the access condition (the second detection result is not met), it is determined that the preset conditions are not met at the same time, and entry into the creeping mode is prohibited; when the target electronic control unit is a body stability control unit (whose strategy requires allowing limited creeping when the core system is normal), but the vehicle state does not meet the standard (for example, the power system is abnormal, the first detection result is not met), even if the target driving strategy meets the access condition (the second detection result is met), it is still determined that the preset conditions are not met at the same time, and entry into the creeping mode is prohibited.
[0027] Step S103 : If the target electronic control unit and the vehicle state both meet corresponding preset conditions, the vehicle is allowed to enter the creep mode.
[0028] In an embodiment of the present application, when a vehicle is parked and an OTA upgrade is performed, if there is a failure to upgrade the target electronic control unit, and the target driving strategy corresponding to the target electronic control unit and the vehicle status meet the entry conditions for the creep mode: the system automatically determines that the preset conditions are met, actively controls the vehicle to enter the creep mode, removes the parking restrictions, and allows the driver to use normal operations (such as releasing the brake pedal) to make the vehicle travel at a speed threshold and distance threshold lower than the target driving strategy; or, in response to a user command (such as an activation button corresponding to the creep mode on the human-computer interaction interface), after verifying the legitimacy of the user command, the creep mode is passively activated: the drive system removes the traction restriction, the braking system maintains a normal response, and the human-computer interaction interface prompts that the creep mode has been entered. Whether actively triggered or in response to user operations, it is premised on the target electronic control unit strategy meeting the entry conditions and the vehicle status meeting the entry conditions, ensuring that the vehicle entering the creep mode can both meet basic mobility needs and avoid safety risks through preset restrictions.
[0029] In an embodiment of the present application, detecting whether the vehicle state and the target electronic control unit both meet corresponding preset conditions includes the following steps: Step A1, detecting whether the vehicle state meets the entry conditions associated with the creeping mode, and obtaining a first detection result.
[0030] Specifically, based on the acquired vehicle status (including but not limited to the functional status of the power system, steering system, and drive system, and the battery status), it is determined whether all the entry conditions for the creep mode are met, wherein the entry conditions may be: the functional status of the power system, steering system, and drive system are all normal, and the battery status meets the preset standards (such as the battery level is not lower than the preset threshold, the voltage is stable within the normal range, etc.). During the test, if all the above conditions are met, the vehicle status is determined to have met the entry conditions, and the first test result is met; if any system functional status is abnormal (such as power system failure, steering system wire control logic abnormality, etc.), or the battery status does not meet the standard (such as battery level is lower than the threshold, voltage is unstable, etc.), it is determined that the entry conditions are not met, and the first test result is met. The test result will determine whether the vehicle is allowed to enter the creep mode, ensuring that the creep mode is only allowed to enter under the premise that the core control capability and energy supply of the vehicle are reliable.
[0031] Step A2: Obtain an electronic control unit list, wherein the electronic control unit list includes multiple electronic control units and a driving strategy corresponding to each electronic control unit.
[0032] Specifically, the electronic control unit list refers to a set of structured data pre-stored in the vehicle system. The list covers all electronic control units of the vehicle (such as the brake control unit, body control module, on-board infotainment unit, etc.), and associates a corresponding driving strategy for each electronic control unit. The driving strategy of each electronic control unit is a pre-set rule based on its safety level and functional characteristics, which is used to clarify the driving authority and restriction logic of the vehicle in creep mode (for example, whether creep mode is allowed, whether specific restrictions need to be added, etc.) when the electronic control unit fails to be upgraded. The list is usually stored in the vehicle control system in the form of a database table, configuration file or mapping table, which facilitates rapid query and matching, and provides a data basis for subsequently locating the target driving strategy corresponding to the target electronic control unit from the list.
[0033] Step A3: Obtain the target driving strategy corresponding to the target electronic control unit from the electronic control unit list.
[0034] Specifically, based on the target electronic control unit (such as the brake control unit, in-vehicle infotainment unit, etc.) that has been determined to have failed to be upgraded, its type identification or unique identifier is used to accurately match it in the electronic control unit list. After locating the entry corresponding to the unit, the driving strategy associated with the entry is extracted.
[0035] As an example, each ECU in the ECU list is bound to a driving strategy through a unique identifier. For example, the brake control unit corresponds to a no-move strategy, the body control module corresponds to a restricted creep strategy (including speed and distance limits), and the in-vehicle infotainment unit corresponds to a full-function creep strategy. By matching the target ECU's identification information, its corresponding strategy content, i.e., the target driving strategy, can be directly retrieved from the list. This target driving strategy serves as the core basis for detecting whether creep mode entry conditions have been met, ensuring that adaptive driving control logic is implemented for ECUs that fail the upgrade.
[0036] Step A4: Detect whether the target driving strategy meets the entry conditions associated with the creeping mode, and obtain a second detection result.
[0037] Specifically, based on the access conditions associated with creep mode (i.e., the basic safety rules that allow the vehicle to enter creep mode), it is determined whether the target driving strategy corresponding to the target electronic control unit meets the conditions. The access conditions may be: the driving strategy is not a prohibited movement strategy, and the functional failure of the electronic control unit corresponding to the strategy does not affect the core control safety of the vehicle (such as the basic operation of power, steering, and braking). During the test, the target driving strategy needs to be matched with the above access conditions: If the target driving strategy is full-function creep (such as the strategy corresponding to the in-vehicle infotainment unit) or limited creep (such as the strategy corresponding to the body control module), the strategy does not prohibit movement and meets the basic safety requirements, and is determined to have met the entry conditions, and the second test result is compliance. If the target driving strategy is a no-movement strategy (such as the strategy corresponding to the brake control unit), this strategy directly conflicts with the entry conditions that allow creeping, and is determined to have missed the entry conditions, and the second test result is non-compliance. This test determines whether the fault of the target electronic control unit allows the vehicle to enter creep mode through its preset strategy, providing key basis for subsequent comprehensive judgment.
[0038] Step A5: determining whether the vehicle state and the target electronic control unit meet corresponding preset conditions according to the first detection result and the second detection result.
[0039] In an embodiment of the present application, if the first detection result is that the vehicle state hits the access conditions associated with the creeping mode, and the second detection result is that the target driving strategy hits the access conditions associated with the creeping mode, then it is determined that the vehicle state and the target electronic control unit both meet the corresponding preset conditions; if the first detection result is that the vehicle state does not hit the access conditions associated with the creeping mode, or the second detection result is that the target driving strategy does not hit the access conditions associated with the creeping mode, then it is determined that the vehicle state and / or the target electronic control unit do not meet the corresponding preset conditions.
[0040] As an example, when the target electronic control unit is an in-vehicle infotainment unit or a body control module, and the vehicle's power system, steering system, and drive system are normal, and the battery status meets the standard (the first detection result is in compliance), and its corresponding target driving strategy is to allow full-function creeping or limited creeping (the second detection result is in compliance), it is determined that the vehicle status and the target electronic control unit both meet the preset conditions; if the target electronic control unit is a braking control unit (its strategy prohibits movement, and the second detection result is not in compliance), even if the vehicle status is normal (the first detection result is in compliance), or the target electronic control unit is a body control module or air-conditioning system ECU but the vehicle's power system is faulty or the battery is insufficient (the first detection result is not in compliance), even if its strategy allows creeping (the second detection result is in compliance), it is determined that the vehicle status and / or the target electronic control unit do not meet the preset conditions, and entering the creep mode is prohibited. This reflects the core logic that both conditions must be met at the same time to determine compliance.
[0041] In the embodiment of the present application, after allowing the vehicle to enter the creep mode, the method further includes: Step B1, when the vehicle is in the creep mode, obtaining the driving state parameters of the vehicle in the creep mode, wherein the driving state parameters include speed parameters, displacement parameters and control parameters.
[0042] Specifically, when the vehicle enters creep mode, the sensors and data acquisition modules of various vehicle systems capture key information reflecting the vehicle's current driving status in real time, including speed parameters, displacement parameters, and control parameters. These three together form the real-time data basis for determining whether the vehicle meets the creep restriction conditions: Speed parameters can be collected in real time using a speed monitoring module or wheel speed sensors integrated into the braking system. For example, if the target ECU is a body control module (e.g., with a speed threshold of 10 km / h), while a vehicle is crawling on a residential road, the wheel speed sensors transmit wheel speed data every 50 milliseconds to a central control unit (e.g., FOTAmaster). This data is converted to the current driving speed (e.g., 6 km / h), ensuring real-time reflection of vehicle speed changes. Displacement parameters can be obtained in two ways: one is by integrating the speed data collected by the wheel speed sensors with the driving time (e.g., one wheel rotation corresponds to 0.8 meters of rolling distance, and 50 rotations in 10 seconds equals 40 meters of displacement); the other is by using a GPS positioning system to record longitude and latitude changes in real time and convert them into distance traveled. For example, if the target ECU is an in-vehicle infotainment unit (with no distance limit), while the vehicle is crawling in a parking lot, the GPS updates its position every 2 seconds, accurately recording a total displacement of 35 meters from the parking space to the exit. Control parameters can be obtained by continuously monitoring the driver's operating behavior using the brake pedal position sensor to determine whether it matches the preset control parameters. For example, when the target electronic control unit is a drive system auxiliary unit (requiring the driver to continuously depress the brake pedal), the sensor detects changes in pedal stroke in real time: if the pedal is continuously depressed (the stroke remains above 1 / 3), the control parameters are determined to comply with the preset control parameters; if the pedal is released (the stroke is 0), it is determined to be non-compliant, and the status data will be synchronously transmitted to the central control unit.
[0043] As an example, the target ECU is a body control module (with a speed threshold of 8 km / h and a distance threshold of 50 meters). While the vehicle is cruising on a congested road, the wheel speed sensor transmits real-time speed data (e.g., 7 km / h). The integrated wheel speed calculates a displacement of 30 meters, and the brake pedal position sensor indicates that the driver is continuously depressing the brake pedal (half the distance). These three data sets are aggregated and sent to FOTAmaster every 100 milliseconds to provide a basis for subsequent matching with constraint conditions. The target ECU is a steering assist unit (required speed ≤ 5 km / h). While the vehicle is cruising in a narrow alley, the bumpy road surface causes wheel speed fluctuations. The brake system speed module uses a filtering algorithm to correct the data, ultimately outputting a stable speed of 4 km / h. Simultaneously, the GPS records a displacement of 20 meters from the entrance to the corner, and the brake pedal sensor detects intermittent application of the brake pedal (meeting the rule of briefly releasing the brake pedal but requiring it to be depressed within 3 seconds), ensuring that control parameters reflect the driver's intent.
[0044] Step B2: Match the driving state parameters with the creep parameters in the target driving strategy corresponding to the target electronic control unit to obtain a matching result.
[0045] Specifically, a preset algorithm is used to compare the driving state parameters (speed parameters, displacement parameters, and control parameters) collected in real time by the vehicle with the creep parameters (speed threshold, distance threshold, and operation verification rules) set in the target driving strategy corresponding to the target electronic control unit to determine whether the two match.
[0046] As an example, let's assume the target ECU is a body control module (creep parameters are speed threshold ≤ 8 km / h, distance threshold ≤ 50 meters, and the driver must continuously depress the brake pedal). During creep, the vehicle's real-time driving state parameters are: speed 7 km / h (≤ 8 km / h), displacement 30 meters (≤ 50 meters), and the driver continuously depressing the brake pedal (compliant with regulations). After matching, all driving state parameters are within the creep parameter limits, resulting in a complete match.
[0047] Assume the target ECU is a drive system auxiliary unit (creep parameters include a speed threshold of ≤5 km / h, a distance threshold of ≤100 meters, and a brake pedal application every 5 seconds). Driving state parameters include: speed of 6 km / h (>5 km / h), displacement of 40 meters (≤100 meters), and the driver not applying the brake pedal for 10 seconds (not in compliance with the regulations). After matching, both the speed and control parameters do not meet the requirements, resulting in a multiple mismatch result.
[0048] Assuming the target electronic control unit is an in-vehicle infotainment unit (creep parameters are speed threshold ≤ 15 km / h, no distance limit, and no mandatory operating rules), the driving state parameters are: speed 12 km / h (≤ 15 km / h), displacement 150 meters (within the limit), and the driver not pressing the brake pedal (no rule violation). The match result is a perfect match.
[0049] Assume the target electronic control unit is a steering assist unit (creep parameters are speed threshold ≤ 10 km / h, distance threshold ≤ 80 meters, and brake pedal depressed and steering wheel angle ≤ 30°). Driving state parameters are: speed 9 km / h (≤ 10 km / h), displacement 90 meters (> 80 meters), and the driver is braking but the steering wheel angle is 45° (not in compliance with the rules). The matching result is displacement exceeded and the control rules do not match.
[0050] Step B3: adjusting the control parameters of the control system in the vehicle based on the matching result, so that the control system controls the vehicle driving according to the adjusted control parameters.
[0051] Specifically, if the matching result indicates that the driving state parameters successfully match the creep parameters, no control parameter adjustment is required. The drive system maintains the current traction output (e.g., 20% of rated power), the braking system remains in standby mode (brake pressure 0 MPa), the steering system responds normally to the driver's operation, and the vehicle continues to creep steadily at 7 km / h. If the matching result indicates that there are driving state parameters that fail to match the creep parameters, the corresponding control system is called to adjust the vehicle's driving state for the unmatched driving state parameters until all driving state parameters meet the creep parameter limits, or parking is triggered.
[0052] In an embodiment of the present application, adjusting the control parameters of the vehicle's control system based on the matching results includes: In step C1, if the matching result is that the speed parameter is greater than the speed threshold in the creep parameter, the traction parameter of the control system in the vehicle is adjusted, and the speed parameter of the vehicle is monitored to see whether it drops to the speed threshold within a preset time period. If it does not drop to the speed threshold, the braking parameter of the control system in the vehicle is adjusted until the speed parameter of the vehicle is less than or equal to the speed threshold.
[0053] Specifically, for the hierarchical control logic when the speed exceeds the limit, a step-by-step operation can be adopted, first adjusting the traction and then intervening in braking, to ensure that the vehicle speed quickly returns to a safe range. An example of the specific adjustment process is as follows: The target electronic control unit is the body control module (with a speed threshold of 8 km / h and a preset time period of 2 seconds). When the vehicle reaches 10 km / h (>8 km / h) during creeping, a command is first sent to the drive system to reduce the traction parameter from 30% of rated power to 10% (reducing power output). A 2-second timer is simultaneously started to monitor speed changes in real time. After 1.5 seconds, if the speed drops to 7 km / h (≤8 km / h), adjustments cease, maintaining the current traction parameter and allowing the vehicle to travel at a stable speed.
[0054] The target electronic control unit is the drive system auxiliary unit (speed threshold 5 km / h, preset time period 3 seconds). When the vehicle reaches 7 km / h (>5 km / h) during creeping, the traction parameter is first reduced from 25% to 5%. However, due to the 5° road gradient (uphill), the speed is only reduced to 6 km / h after 3 seconds (still exceeding the threshold). At this time, a command is sent to the braking system to adjust the braking parameters (applying 0.2 MPa brake pressure). After 1 second, the speed is reduced to 4 km / h (≤5 km / h), and braking intervention is stopped, maintaining the traction parameter unchanged.
[0055] The target electronic control unit is the in-vehicle infotainment unit (speed threshold 15km / h, preset time period 5 seconds). When the vehicle is creeping at a speed of 18km / h (>15km / h), the traction parameter is first reduced from 40% to 15%. After 4 seconds, the speed is reduced to 16km / h (not reaching the threshold); then the braking parameter is adjusted (0.1MPa pressure is applied), and monitoring is continued. After 2 seconds, the speed is reduced to 14km / h (≤15km / h), and the traction parameter is restored to 20% to maintain stable driving.
[0056] In special scenarios (such as slippery roads, the target electronic control unit is the steering assist unit, the speed threshold is 10km / h, and the preset time is 3 seconds), when the vehicle reaches 12km / h while creeping, the traction force is first reduced to 10%, but because the road is slippery, the wheels slip slightly, and the speed is still 11km / h after 3 seconds; immediately increase the braking parameters (apply 0.3MPa pressure), and adjust the wheel braking force distribution through the electronic stability control system. After 1.5 seconds, the speed drops to 9km / h to ensure that the speed can be quickly controlled even on low-adhesion roads.
[0057] Step C2: If the matching result is that the displacement parameter is greater than the distance threshold in the creep parameter, and / or the control parameter does not meet the preset control parameter in the creep parameter, the vehicle is allowed to enter the parking mode.
[0058] Specifically, mandatory safety measures for excessive displacement or illegal operation are implemented to avoid escalating risks by triggering parking mode. Examples of specific mandatory safety measures include: If only the displacement parameter exceeds the limit (the target electronic control unit is the body control module, the distance threshold is 50 meters, and the preset control parameter is to continuously step on the brake pedal), and the vehicle's displacement reaches 55 meters (>50 meters) while creeping, but the driver continues to step on the brake pedal (the control parameters are met), the system will determine that the displacement exceeds the limit and immediately send a command to the braking system (applying 0.5MPa braking pressure), while cutting off the drive system traction and decelerating the vehicle to 0 within 3 seconds; then the electronic parking brake is activated, entering the parking mode, and prompting that the maximum creep distance has been reached through the vehicle interactive terminal.
[0059] If only the control parameters are not met (the target electronic control unit is the drive system auxiliary unit, the distance threshold is 100 meters, and the preset control parameters are to step on the brake pedal once every 5 seconds), the displacement is 30 meters (≤100 meters), but the driver has not stepped on the brake pedal for 7 seconds (the control parameters are not met), the system will determine that the control is illegal, immediately start braking (0.4MPa pressure), and trigger the sound and light alarm; after the vehicle stops, the parking lock is activated and the vehicle enters parking mode, prompting the driver to re-operate to activate creep.
[0060] If the displacement exceeds the limit and the control is violated (the target electronic control unit is the steering assist unit, the distance threshold is 80 meters, and the preset control parameter is brake pedal travel ≥1 / 3), the displacement reaches 85 meters (>80 meters) and the driver's brake pedal travel is only 1 / 5 (<1 / 3, the control is not satisfied), the system will simultaneously trigger the double limit, quickly apply the brakes (0.6MPa pressure), cut off the power, and stop within 2 seconds; then activate the mechanical parking mechanism, enter the parking mode, and record the double violation information for subsequent diagnosis.
[0061] If it is a complex scenario (the target electronic control unit is the air conditioning control unit, the distance threshold is 120 meters, and the preset control parameter is a steering wheel angle ≤45°), the displacement is 110 meters (≤120 meters), but the driver suddenly turns the steering wheel (the angle reaches 60° and the control is not satisfactory), the system will determine that the control is illegal. Even if the displacement does not exceed the limit, it will immediately control the vehicle to slow down to 0 and park to avoid driving risks caused by excessive steering angles.
[0062] In the above embodiment, regardless of whether a single condition or a combination of conditions is triggered, forced parking is used to ensure that the vehicle stops moving when it exceeds the safety limit, further enhancing the safety redundancy in the creep mode.
[0063] In the embodiment of the present application, when the vehicle firmware upgrade fails, in addition to the basic creep mode control process, the failed electronic control unit and creep parameters are also managed: During the post-installation verification phase, if multiple ECU OTA upgrade failures are detected, they are first handled according to their security priority (high > medium > low). If a high-security ECU (e.g., brake control unit) fails, creep mode is disabled and a notification is displayed on the human-machine interface. If only medium- or low-security ECUs fail, creep parameters are dynamically adjusted based on the number of failed ECUs. The security level and number of failed ECUs are counted to obtain a statistical result. When the number of failed ECUs reaches a preset number, the first parameter adjustment rule is triggered. When the number of failed ECUs exceeds the preset number, the second parameter adjustment rule is triggered. Based on the matching adjustment rule, multiple creep parameters in the creep constraint conditions are adjusted accordingly. If the first rule is triggered, the creep parameter is reduced by a first percentage (e.g., 20%) from the original default value. If the second rule is triggered, the creep parameter is reduced by a second percentage (e.g., 50%) from the original default value. The adjusted creep parameters are then validated to ensure they are within a safe and reasonable range (e.g., the speed threshold is not less than a preset minimum value, and the distance threshold is not less than a preset minimum value). After verification, the FOTA master sends the adjusted creep parameters to the drive and braking systems to limit the vehicle's driving state. Finally, the human-machine interface displays the current creep parameter adjustment status due to the number of ECU OTA failures. The vehicle log records the number of failed ECUs, the adjusted parameter values, and the time of adjustment for subsequent query and analysis, ensuring that the risk level matches the restriction strength.
[0064] The creep parameter adjustment process also includes: FOTAmaster establishes a connection with the cloud server through a secure communication protocol (such as TLS), and regularly queries whether there are creep parameter update instructions (such as adjusting the speed threshold to 15km / h and the distance threshold to 200 meters); after receiving the update instruction, it analyzes the parameter legitimacy (such as the speed threshold must be ≥5km / h and ≤30km / h), and sends the new parameters to the drive system and braking system through the internal communication protocol; after the relevant system updates the parameters, it returns a confirmation message to FOTAmaster, and at the same time prompts on the human-computer interaction interface that the creep limit parameters have been updated to ensure that the local configuration is synchronized with the cloud.
[0065] The method provided in the embodiments of the present application achieves refined management of failed ECUs and creep parameters by hierarchically processing multiple ECU upgrade failures during the post-installation verification phase and dynamically adjusting creep parameters based on the number of failed ECUs. Through a hierarchical processing mechanism based on safety level priority, creep mode is directly disabled when a high-safety ECU fails, effectively avoiding safety risks caused by critical system failures. For medium- and low-safety ECU failures, creep parameters are dynamically adjusted based on the number of failures. This ensures that the creep limit strength matches the risk level while maintaining the vehicle's basic driving capability, thereby improving the vehicle's safety and adaptability in scenarios where multiple ECU upgrades fail.
[0066] A validation mechanism for adjusted parameters ensures that the adjusted creep parameters are within a safe and reasonable range, preventing new safety issues caused by over- or under-restriction and enhancing system robustness. By distributing the adjusted creep parameters to the drive and braking systems via FOTAmaster, precise control of the vehicle's driving state is achieved, ensuring effective enforcement of the restriction measures.
[0067] Prompting the creep parameter adjustment status on the HMI interface allows the driver to promptly understand the vehicle's current driving restrictions, improving driving safety. Recording the number of failed electronic control units, adjusted parameter values, and adjustment time in the on-board log not only facilitates subsequent tracing and analysis of upgrade failures, but also provides data support for system optimization, helping to improve the reliability and intelligence level of the entire vehicle firmware upgrade safety control system.
[0068] In an embodiment of the present application, after detecting whether the vehicle status and the target electronic control unit both meet the corresponding preset conditions, the method also includes: generating corresponding prompt information based on the vehicle status and / or the target electronic control unit; and controlling the vehicle to perform corresponding prompt operations based on the prompt information.
[0069] Specifically, the system combines the vehicle status (whether it meets the creep mode entry conditions) with the type and safety level of the target electronic control unit to generate a prompt reflecting the degree of abnormality. The system then performs a notification operation through the vehicle interaction system to ensure that the driver is aware of the vehicle status in a timely manner. The target electronic control unit is the brake control unit (high safety level). If the vehicle's status does not meet access requirements (e.g., powertrain abnormality), the system will generate a prompt message stating, "Vehicle OTA upgrade failed (brake control unit abnormality). Vehicle prohibited from driving. Contact maintenance personnel." The system will also control the vehicle's human-machine interface to display a red screen with a continuous beeping tone, lock the drive system, and maintain forced parking mode, preventing the driver from operating the vehicle.
[0070] The target electronic control unit is the in-vehicle infotainment unit (low security level). If the vehicle's status meets the access requirements, the system will generate a prompt message stating, "Vehicle OTA upgrade failed (in-vehicle entertainment system abnormality). The vehicle is allowed to enter creep mode, but some entertainment functions are unavailable." The human-machine interface displays a yellow pop-up window (not dominating the screen and not obscuring core driving information). A prompting voice message is played through the vehicle's speakers, allowing the vehicle to enter full-function creep mode without additional restrictions on basic driving operations.
[0071] The target electronic control unit is the body control module (medium safety level). If the vehicle's status meets the entry requirements, the system will generate a prompt message: "Vehicle OTA upgrade failed (body control module abnormality). Currently, creeping is restricted (speed ≤ 8 km / h, distance ≤ 50 meters)." This prompt is displayed in orange on the human-computer interface (for 10 seconds, then reduced to a status bar prompt). The instrument panel warning light is also illuminated, reminding the driver of driving restrictions. The vehicle enters creep mode according to the medium-level restrictions.
[0072] The target electronic control unit is the air conditioning control unit (low safety level). If the vehicle's status does not meet access requirements (e.g., low battery), the system will generate a prompt message stating, "Vehicle OTA upgrade failed (air conditioning system abnormality). Battery low, vehicle cannot be driven. Please charge and try again." A blue pop-up window appears on the control panel's human-machine interface, accompanied by a ding-dong tone, clearly informing the driver of the abnormality and the solution. The vehicle remains in the park lock position.
[0073] The target electronic control unit is a steering assist unit (medium safety level). If the vehicle meets the access requirements, the system will generate a prompt message stating, "Vehicle OTA upgrade failed (steering assist system abnormality). Creeping is currently restricted (steering angle ≤ 30°). Please drive with caution." This prompt is displayed scrollingly through the human-machine interface, coupled with steering wheel vibration feedback, reminding the driver of steering restrictions without interfering with the driver's primary field of view. The vehicle then enters creeping mode according to the specified steering conditions.
[0074] In the above embodiment, the severity of the prompt information (color, display mode, content) and the execution operation (lock, driving restriction, sound and light prompts) are strongly correlated with the safety level of the target electronic control unit and the vehicle status, achieving a match between the degree of abnormality and the intensity of notification, ensuring the driver's right to know the vehicle status and driving safety.
[0075] In an embodiment of the present application, the method further includes: when the vehicle is in the creep mode, in response to a creep exit instruction, allowing the vehicle to enter the normal driving mode.
[0076] Specifically, first, the creep exit command is sent to the FOTAmaster through the on-board diagnostic interface (such as OBD-II) or the internal communication protocol (such as IPCP). This command is used to instruct the system to exit the creep mode. After receiving the command, the FOTAmaster will send a control signal to the relevant module to release the driving strategy in the creep mode, such as canceling the speed limit on the vehicle speed by the speed threshold, clearing the monitoring of the distance threshold, and no longer requiring the driver to continuously step on the brake pedal to maintain the driving state. At the same time, the FOTAmaster will notify the drive system and the braking system to return to the normal working mode. The drive system no longer limits the traction output, and the braking system also returns to the normal braking control logic, so that the vehicle can enter the normal driving mode and is no longer restricted by the various conditions of the creep mode.
[0077] When exiting creep mode or executing a diagnostic command, the user authority authentication mechanism needs to be triggered. The process is as follows: When receiving a creep exit command or a diagnostic command, the on-board control unit starts the authority authentication module; the authentication module compares the input information with the authorization information in the on-board safety database to verify the authority level (such as maintenance technician); if the authentication is successful, the corresponding instruction is allowed to be executed; if the authentication fails, the operation is rejected and a prompt of insufficient authority is displayed on the human-computer interaction interface, and a log of unauthorized operations is recorded.
[0078] In the event of an OTA upgrade failure or creep mode anomaly, FOTAmaster adds hierarchical recording and storage of fault logs to facilitate subsequent fault analysis. The process is as follows: When an ECU upgrade failure or parameter matching anomaly in creep mode is detected, FOTAmaster classifies the fault level (fatal, warning, or prompt) based on the type of anomaly (e.g., high, medium, or low safety level). The fault code, occurrence time, relevant ECU type, driving status parameters (e.g., speed, displacement), and current system configuration information are recorded and stored in the on-board fault database. For serious faults (e.g., failure of a high-safety ECU), the fault log is synchronized to the T-BOX via the CAN bus and uploaded to the cloud server.
[0079] As an example, Figure 2 A flowchart of a security control method for vehicle firmware upgrades, such as Figure 2 As shown, the process includes: first entering the firmware upgrade process, the pre-installation stage allows the vehicle to enter the parking mode; then monitoring the target electronic control unit that failed to upgrade, and in the post-installation stage, matching the corresponding driving strategy in the electronic control unit list based on the target electronic control unit - prohibiting creeping strategy, prompting OTA upgrade failure and prohibiting driving; restricted creeping strategy and full-function creeping strategy, both of which prompt OTA upgrade failure and restricting driving; finally, responding to the creeping exit command to exit the creeping mode.
[0080] This embodiment also provides a vehicle firmware upgrade security control device, which is used to implement the above-mentioned embodiments and preferred embodiments. Details already described will not be repeated here. As used below, the term "module" may refer to a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation using hardware, or a combination of software and hardware, is also possible and contemplated.
[0081] This embodiment provides a security control device for vehicle firmware upgrade, such as Figure 3 Shown, including: A monitoring module 31 is configured to monitor a target electronic control unit in the vehicle that has failed to be upgraded when the vehicle is undergoing a firmware upgrade in the parking mode, wherein the target electronic control unit is any electronic control unit in the vehicle; The detection module 32 is used to obtain the vehicle state of the vehicle and detect whether the vehicle state and the target electronic control unit both meet corresponding preset conditions; The determination module 33 is configured to allow the vehicle to enter the creep mode if both the target electronic control unit and the vehicle state meet corresponding preset conditions.
[0082] Furthermore, the detection module 32 further includes: A first detection submodule is used to detect whether the vehicle state meets the entry conditions associated with the creeping mode and obtain a first detection result; A first acquisition submodule is configured to acquire an electronic control unit list, wherein the electronic control unit list includes a plurality of electronic control units and a driving strategy corresponding to each electronic control unit; A second acquisition submodule is used to acquire a target driving strategy corresponding to a target electronic control unit from the electronic control unit list; A second detection submodule is used to detect whether the target driving strategy meets the entry conditions associated with the creeping mode, and obtain a second detection result; The determination submodule is used to determine whether the vehicle state and the target electronic control unit meet corresponding preset conditions based on the first detection result and the second detection result.
[0083] Furthermore, a determination submodule is used to determine that the vehicle state and the target electronic control unit both meet the corresponding preset conditions if the first detection result is that the vehicle state hits the access conditions associated with the creeping mode, and the second detection result is that the target driving strategy hits the access conditions associated with the creeping mode; if the first detection result is that the vehicle state does not hit the access conditions associated with the creeping mode, or the second detection result is that the target driving strategy does not hit the access conditions associated with the creeping mode, then determine that the vehicle state and / or the target electronic control unit do not meet the corresponding preset conditions.
[0084] Furthermore, the device also includes: a control module, which is used to obtain the driving state parameters of the vehicle in the creep mode when the vehicle is in the creep mode, wherein the driving state parameters include speed parameters, displacement parameters and control parameters; matching the driving state parameters with the creep parameters in the target driving strategy corresponding to the target electronic control unit to obtain a matching result; adjusting the control parameters of the control system in the vehicle based on the matching result, so that the control system controls the vehicle driving according to the adjusted control parameters.
[0085] Furthermore, the control module further includes: a first adjustment submodule, configured to adjust a traction parameter of a control system in the vehicle if the matching result shows that the speed parameter is greater than a speed threshold in the creep parameter, and monitor whether the speed parameter of the vehicle drops to the speed threshold within a preset time period; if not, adjust a braking parameter of the control system in the vehicle until the speed parameter of the vehicle is less than or equal to the speed threshold; The second adjustment submodule is configured to allow the vehicle to enter the parking mode if the matching result is that the displacement parameter is greater than the distance threshold in the creep parameter and / or the control parameter does not meet the preset control parameter in the creep parameter.
[0086] Furthermore, the device also includes: a prompt module, which is used to generate corresponding prompt information according to the vehicle state and / or the target electronic control unit; and control the vehicle to perform corresponding prompt operations based on the prompt information.
[0087] Furthermore, the device also includes: an exit module, which is used to allow the vehicle to enter the normal driving mode in response to the creep exit instruction when the vehicle is in the creep mode.
[0088] See also Figure 4 , Figure 4 is a structural diagram of a computer device provided by an optional embodiment of the present invention, such as Figure 4 As shown, the computer device includes: one or more processors 10, memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. Various components utilize different buses to communicate with each other and can be installed on a common mainboard or installed in other ways as needed. The processor can process the instructions executed in the computer device, including instructions stored in the memory or on the memory to display the graphical information of the GUI on an external input / output device (such as, a display device coupled to the interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Equally, multiple computer devices can be connected, and each device provides part of the necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system).
[0089] The processor 10 can be a central processing unit, a network processing unit, or a combination thereof. The processor 10 can further include a hardware chip. The hardware chip can be an application specific integrated circuit, a programmable logic device, or a combination thereof. The programmable logic device can be a complex programmable logic device, a field programmable logic device, a generic array logic, or any combination thereof.
[0090] The memory 20 stores instructions executable by the at least one processor 10 for causing the at least one processor 10 to perform the methods illustrated in the above embodiments.
[0091] The memory 20 can include a program storage area and a data storage area. The program storage area can store an operating system and applications required by at least one function. The data storage area can store data created by the use of the computer device according to the presentation of a small program landing page, and the like. In addition, the memory 20 can include a high-speed random access memory, and can further include a non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state memory device. In some alternative embodiments, the memory 20 can optionally include a memory disposed remotely from the processor 10, and these remote memories can be connected to the computer device through a network. Examples of the network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.
[0092] The memory 20 can include a volatile memory, such as a random access memory, and can also include a non-volatile memory, such as a flash memory, a hard disk, or a solid state disk. The memory 20 can further include a combination of the above-mentioned types of memories.
[0093] The computer device further includes a communication interface 30 for communication of the computer device with other devices or communication networks.
[0094] The embodiment of the present invention also provides a computer-readable storage medium. The above-mentioned method according to the embodiment of the present invention can be implemented in hardware, firmware, or implemented as a computer code that can be recorded in a storage medium, or implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and downloaded through a network and will be stored in a local storage medium, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state drive, etc.; further, the storage medium can also include a combination of the above-mentioned types of memory. It can be understood that a computer, a processor, a microprocessor controller or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor or hardware, the method shown in the above embodiment is implemented.
[0095] Although the embodiments of the present invention have been described with reference to the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present invention. Such modifications and variations are all within the scope defined by the appended claims.
Claims
1. A security control method for vehicle firmware upgrade, characterized in that: The method comprises: When the vehicle is undergoing a firmware upgrade in parking mode, monitoring a target electronic control unit in the vehicle that has failed to be upgraded, wherein the target electronic control unit is any electronic control unit in the vehicle; Acquiring a vehicle state of the vehicle, and detecting whether the vehicle state and the target electronic control unit both meet corresponding preset conditions; If the target electronic control unit and the vehicle state both meet corresponding preset conditions, the vehicle is allowed to enter the creep mode.
2. The method according to claim 1, characterized in that The detecting whether the vehicle state and the target electronic control unit both meet corresponding preset conditions includes: detecting whether the vehicle state meets an entry condition associated with the creeping mode, and obtaining a first detection result; Obtaining an electronic control unit list, wherein the electronic control unit list includes multiple electronic control units and a driving strategy corresponding to each electronic control unit; Acquire the target driving strategy corresponding to the target electronic control unit from the electronic control unit list; detecting whether the target driving strategy meets an entry condition associated with the creeping mode, and obtaining a second detection result; It is determined whether the vehicle state and the target electronic control unit meet corresponding preset conditions according to the first detection result and the second detection result.
3. The method according to claim 2, characterized in that The determining, based on the first detection result and the second detection result, whether the vehicle state and the target electronic control unit meet corresponding preset conditions includes: If the first detection result is that the vehicle state hits the entry condition associated with the creeping mode, and the second detection result is that the target driving strategy hits the entry condition associated with the creeping mode, then determining that the vehicle state and the target electronic control unit both meet corresponding preset conditions; If the first detection result is that the vehicle state does not hit the entry conditions associated with the creeping mode, or the second detection result is that the target driving strategy does not hit the entry conditions associated with the creeping mode, it is determined that the vehicle state and / or the target electronic control unit do not meet the corresponding preset conditions.
4. The method according to claim 1, wherein After allowing the vehicle to enter creep mode, the method further includes: When the vehicle is in a creeping mode, obtaining driving state parameters of the vehicle in the creeping mode, wherein the driving state parameters include speed parameters, displacement parameters, and control parameters; Matching the driving state parameter with the creep parameter in the target driving strategy corresponding to the target electronic control unit to obtain a matching result; The control parameters of the control system in the vehicle are adjusted based on the matching result, so that the control system controls the vehicle to travel according to the adjusted control parameters.
5. The method according to claim 4, characterized in that The adjusting the control parameters of the control system in the vehicle based on the matching result includes: If the matching result is that the speed parameter is greater than the speed threshold in the creep parameter, adjusting the traction parameter of the control system in the vehicle, and monitoring whether the speed parameter of the vehicle drops to the speed threshold within a preset time period; if it does not drop to the speed threshold, adjusting the braking parameter of the control system in the vehicle until the speed parameter of the vehicle is less than or equal to the speed threshold; Alternatively, if the matching result is that the displacement parameter is greater than the distance threshold in the creep parameter, and / or the control parameter does not meet the preset control parameter in the creep parameter, the vehicle is allowed to enter the parking mode.
6. The method according to claim 1, characterized in that After detecting whether the vehicle state and the target electronic control unit both meet corresponding preset conditions, the method further includes: Generate corresponding prompt information according to the vehicle status and / or the target electronic control unit; The vehicle is controlled to perform a corresponding prompt operation based on the prompt information.
7. The method according to claim 1, characterized in that The method further comprises: When the vehicle is in the creep mode, the vehicle is allowed to enter the normal driving mode in response to a creep exit command.
8. A safety control device for vehicle firmware upgrade, characterized in that: The device comprises: a monitoring module, configured to monitor a target electronic control unit in the vehicle that has failed to be upgraded when the vehicle is undergoing a firmware upgrade in the parking mode, wherein the target electronic control unit is any electronic control unit in the vehicle; a detection module, configured to obtain a vehicle state of the vehicle and detect whether the vehicle state and the target electronic control unit both meet corresponding preset conditions; The determination module is configured to allow the vehicle to enter a creep mode if both the target electronic control unit and the vehicle state meet corresponding preset conditions.
9. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the method according to any one of claims 1 to 7 by executing the computer instructions.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Unmanned vehicle fault processing method and device, electronic equipment and storage medium
CN111123887A
Torque arbitration control method and system for new energy commercial vehicle
CN112644295A
Vehicle program update system and vehicle program update method
CN113553076A
Initialization method and system for air upgrade, electronic equipment and storage medium
CN116582833A
Vehicle OTA upgrade control method and related equipment
CN116643775A