Security control method and device for vehicle firmware upgrade, computer device and medium
By monitoring and detecting the target electronic control unit that fails to upgrade during the vehicle firmware upgrade process, the vehicle is allowed to enter crawl mode only when two conditions are met. This solves the problem of unsafe driving after a failed vehicle firmware upgrade and improves the safety and reliability of vehicle firmware upgrades.
Patent Information
- Application Number
- CN202511271667.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-08
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2045-09-08
AI Technical Summary
If the electronic control unit fails to upgrade during the vehicle firmware upgrade process, the existing technology cannot effectively prevent the vehicle from driving autonomously, which prevents the user from making necessary position adjustments and poses a safety hazard.
In parking mode, the system monitors the target electronic control unit that failed the upgrade, obtains the vehicle status and checks its compliance with preset conditions. The vehicle is allowed to enter crawl mode only when both conditions are met, and safe driving is ensured through strict condition judgment and parameter adjustment.
This enables the vehicle to make necessary position adjustments in a restricted crawl mode while ensuring safety, avoiding safety hazards caused by electronic control unit upgrade failures, and improving the safety and reliability of vehicle firmware upgrades.
Smart Images

Figure CN120756485B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of firmware upgrade technology, and specifically to a security control method, device, computer equipment, and medium for vehicle firmware upgrades. Background Technology
[0002] During OTA firmware upgrades, electronic control unit (ECU) upgrades may fail. When software upgrades involving safety-related systems fail, it is essential to ensure the vehicle is in a safe state (even if this state limits vehicle functionality). In particular, if ECUs such as the power control unit or braking system malfunction, autonomous driving is typically prohibited.
[0003] Current firmware upgrade solutions have certain limitations in handling upgrade failures: after an upgrade fails, they often only notify users to contact after-sales service or use the vehicle with caution based on the installation result, without directly disabling the vehicle; and for situations where driving is prohibited due to electronic control unit failure, existing solutions do not establish a mechanism to activate restricted mobility within an allowed range. If driving is completely prohibited, users will be unable to make necessary adjustments to their location (such as moving the vehicle out of a danger zone) after an upgrade failure. Summary of the Invention
[0004] In view of this, embodiments of the present invention provide a safety control method, apparatus, computer equipment and medium for vehicle firmware upgrades, in order to solve the problem of how to achieve necessary position adjustments by allowing the vehicle to drive in a restricted crawling mode while ensuring safety after a vehicle firmware upgrade fails.
[0005] In a first aspect, embodiments of the present invention provide a security control method for vehicle firmware upgrades, the method comprising:
[0006] When the vehicle is undergoing firmware upgrade in parking mode, the system monitors the target electronic control unit in the vehicle that failed to upgrade, wherein the target electronic control unit is any electronic control unit in the vehicle.
[0007] The vehicle status is obtained, and it is detected whether the vehicle status and the target electronic control unit both meet the corresponding preset conditions.
[0008] If both the target electronic control unit and the vehicle status meet the corresponding preset conditions, the vehicle is allowed to enter crawl mode.
[0009] Furthermore, the step of detecting whether the vehicle state and the target electronic control unit both meet the corresponding preset conditions includes:
[0010] Detect whether the vehicle status matches the admission criteria associated with the crawl mode to obtain a first detection result;
[0011] Obtain a list of electronic control units, wherein the list of electronic control units includes multiple electronic control units and a driving strategy corresponding to each electronic control unit;
[0012] Obtain the target driving strategy corresponding to the target electronic control unit from the list of electronic control units;
[0013] The second detection result is obtained by detecting whether the target driving strategy matches the admission conditions associated with the crawl mode.
[0014] Based on the first detection result and the second detection result, determine whether the vehicle state and the target electronic control unit meet the corresponding preset conditions.
[0015] Furthermore, determining whether the vehicle state and the target electronic control unit meet the corresponding preset conditions based on the first detection result and the second detection result includes:
[0016] If the first detection result is that the vehicle state meets the admission conditions associated with the crawl mode, and the second detection result is that the target driving strategy meets the admission conditions associated with the crawl mode, then it is determined that both the vehicle state and the target electronic control unit meet the corresponding preset conditions.
[0017] If the first detection result indicates that the vehicle state does not meet the access conditions associated with the crawl mode, or the second detection result indicates that the target driving strategy does not meet the access conditions associated with the crawl mode, then it is determined that the vehicle state and / or the target electronic control unit does not meet the corresponding preset conditions.
[0018] Furthermore, after allowing the vehicle to enter crawl mode, the method further includes:
[0019] When the vehicle is in crawl mode, the driving status parameters of the vehicle in crawl mode are acquired, wherein the driving status parameters include speed parameters, displacement parameters and control parameters.
[0020] The driving state parameters are matched with the creep parameters in the target driving strategy corresponding to the target electronic control unit to obtain the matching result;
[0021] Based on the matching result, the control parameters of the vehicle's control system are adjusted so that the control system controls the vehicle's movement according to the adjusted control parameters.
[0022] Furthermore, adjusting the control parameters of the vehicle's control system based on the matching result includes:
[0023] If the matching result is that the speed parameter is greater than the speed threshold in the creep parameter, then the traction parameter of the vehicle control system is adjusted, and the vehicle speed parameter is monitored within a preset time period to see if it drops to the speed threshold. If it does not drop to the speed threshold, then the braking parameter of the vehicle control system is adjusted until the vehicle speed parameter is less than or equal to the speed threshold.
[0024] Alternatively, if the matching result is that the displacement parameter is greater than the distance threshold in the creep parameter, and / or the control parameter does not meet the preset control parameter in the creep parameter, then the vehicle is allowed to enter the parking mode.
[0025] Furthermore, after detecting whether the vehicle status and the target electronic control unit both meet the corresponding preset conditions, the method further includes:
[0026] Generate corresponding prompt information based on the vehicle status and / or the target electronic control unit;
[0027] Based on the prompt information, the vehicle is controlled to perform the corresponding prompt operation.
[0028] Furthermore, the method also includes:
[0029] When the vehicle is in crawl mode, in response to a crawl exit command, the vehicle is allowed to enter normal driving mode.
[0030] Secondly, embodiments of the present invention provide a security control device for vehicle firmware upgrades, the device comprising:
[0031] The monitoring module is used to monitor the target electronic control unit in the vehicle that failed to upgrade when the vehicle is undergoing firmware upgrade in parking mode, wherein the target electronic control unit is any electronic control unit in the vehicle;
[0032] The detection module is used to acquire the vehicle status of the vehicle and detect whether the vehicle status and the target electronic control unit both meet the corresponding preset conditions.
[0033] The determination module is used to allow the vehicle to enter the crawl mode if both the target electronic control unit and the vehicle status meet the corresponding preset conditions.
[0034] Thirdly, embodiments of the present invention provide a computer device, including: a memory and a processor, the memory and the processor being communicatively connected to each other, the memory storing computer instructions, and the processor executing the computer instructions to perform the method described in the first aspect or any corresponding embodiment thereof.
[0035] Fourthly, embodiments of the present invention provide a computer-readable storage medium storing computer instructions that cause a computer to perform the method described in the first aspect or any of its corresponding embodiments.
[0036] The method provided in this application has the following beneficial effects:
[0037] The method provided in this application monitors the target electronic control unit (ECU) that fails to upgrade during the firmware upgrade process in parking mode. This allows for timely detection of anomalies during the firmware upgrade process, preventing safety hazards caused by ECU upgrade failures and effectively ensuring the safety of vehicle firmware upgrades. By acquiring the vehicle status and checking whether it and the target ECU both meet the corresponding preset conditions, the vehicle is allowed to enter crawl mode only when both conditions are met. This ensures that the vehicle still has a certain driving capability while strictly preventing the vehicle from entering a driving state if it does not meet safety requirements. This prevents the failed ECU from adversely affecting the normal driving of the vehicle and improves the safety and reliability of the vehicle when driving under abnormal firmware upgrade conditions. Attached Figure Description
[0038] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0039] Figure 1 This is a flowchart illustrating a security control method for vehicle firmware upgrades according to an embodiment of the present invention.
[0040] Figure 2 This is a flowchart illustrating another vehicle firmware upgrade security control method according to an embodiment of the present invention;
[0041] Figure 3 This is a structural block diagram of a vehicle firmware upgrade safety control device according to an embodiment of the present invention;
[0042] Figure 4 This is a schematic diagram of the hardware structure of a computer device according to an embodiment of the present invention. Detailed Implementation
[0043] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0044] According to embodiments of the present invention, a security control method, apparatus, computer device, and medium for vehicle firmware upgrades are provided. It should be noted that the steps shown in the flowcharts in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowcharts, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0045] This embodiment provides a security control method for vehicle firmware upgrades. Figure 1 This is a flowchart of a vehicle firmware upgrade security control method according to an embodiment of the present invention, such as... Figure 1 As shown, the process includes the following steps:
[0046] Step 101: During the firmware upgrade process of the vehicle in parking mode, monitor the target electronic control unit in the vehicle that failed the upgrade. The target electronic control unit can be any electronic control unit in the vehicle.
[0047] In this embodiment, during firmware upgrades (OTA installation via FOTAmaster) while the vehicle is in parking mode (i.e., the vehicle is stationary and prohibited from driving), the system monitors the target electronic control unit (ECU) that failed to upgrade. Parking mode is a vehicle state triggered by FOTAmaster during the pre-OTA installation preparation phase, during which driving is prohibited (driving mode is disabled). Firmware upgrade refers to FOTAmaster's execution of the OTA installation package distribution, flashing, and verification process. The target ECU refers to any one or more ECUs (such as brake control units, body control modules, etc.) that failed during the firmware upgrade process. The monitoring method involves FOTAmaster actively detecting the installation result status of each ECU (such as verifying signatures, version numbers, or functional self-tests) during the post-installation verification phase to identify the failed target ECU.
[0048] During the OTA installation package download and verification phase, network connection stability can be monitored in real time to ensure the integrity of the upgrade package transmission. The specific process is as follows: Before obtaining the upgrade package, FOTAmaster detects the network signal strength, transmission rate, and packet loss rate through the vehicle communication module (such as 5G / 4G); if the network signal is lower than a preset threshold (such as -100dBm) or the packet loss rate exceeds 5%, it attempts to switch to a backup network (such as Wi-Fi) or prompts the user to manually connect to a stable network; during the upgrade package transmission, the network status is continuously monitored, and if an interruption occurs, the transmission is paused and the received data is cached, continuing only after the network is restored to ensure the integrity of the upgrade package.
[0049] Step S102: Obtain the vehicle status and check whether the vehicle status and the target electronic control unit both meet the corresponding preset conditions.
[0050] It should be noted that vehicle status refers to the functional status of the vehicle's core control systems and battery status, in order to comprehensively assess the vehicle's basic operational capabilities in the event of a firmware upgrade anomaly, and to provide a basis for determining whether to allow entry into crawl mode. Specifically, it includes the following:
[0051] On the one hand, it acquires the functional status of multiple key control systems in the vehicle, including but not limited to the powertrain, steering, and drive systems. This is achieved through sensors, diagnostic modules, and the self-checking mechanisms of each system within the vehicle: the powertrain determines its normal operating status by detecting engine (or motor) operating parameters (such as speed and output power) and fault codes; the steering system determines its functionality by checking the effectiveness of the drive-by-wire logic and the smoothness of the mechanical steering mechanism; and the drive system assesses its normal operating status by monitoring the command response of the control module and the operational status of actuators (such as brakes and transmission components).
[0052] On the other hand, during the pre-installation preparation phase, the vehicle's battery status can also be acquired simultaneously. After triggering the parking mode, FOTAmaster collects key battery parameters in real time through the Battery Management System (BMS), including battery charge, voltage, and temperature; and determines whether the charge is higher than a preset threshold (e.g., 20%) and whether the voltage is stable within the normal range (e.g., 12V±0.5V), thereby determining whether the battery status is normal.
[0053] In this embodiment, when detecting whether the vehicle status and the target electronic control unit both meet the corresponding preset conditions, the specific implementation is as follows: When the target electronic control unit is an entertainment control unit or an air conditioning control unit (whose corresponding driving strategy is to not affect the core vehicle control and allow crawling), and the vehicle's power system, steering system, and drive system functions are all normal and the battery status is up to standard (the first detection result is compliant), its target driving strategy also meets the crawling mode access conditions (the second detection result is compliant), so it is determined that both meet the preset conditions, and the vehicle is allowed to enter the crawling mode; when the target electronic control unit is a braking control unit (whose corresponding driving strategy is to affect the core braking function and prohibit crawling), even if the vehicle status meets the standards (the first detection result is compliant), but the target driving strategy does not meet the access conditions (the second detection result is non-compliant), it is determined that the preset conditions are not met simultaneously, and entering the crawling mode is prohibited; when the target electronic control unit is a vehicle stability control unit (whose strategy requires that the core system is normal and allows limited crawling), but the vehicle status is not up to standard (such as an abnormal power system, the first detection result is non-compliant), even if the target driving strategy meets the access conditions (the second detection result is compliant), it is still determined that the preset conditions are not met simultaneously, and entering the crawling mode is prohibited.
[0054] Step S103: If the target electronic control unit and the vehicle status both meet the corresponding preset conditions, the vehicle is allowed to enter the crawl mode.
[0055] In this embodiment, during a vehicle parking OTA upgrade, if the target electronic control unit (ECU) upgrade fails, and the target driving strategy corresponding to the ECU and the vehicle status meet the entry conditions for crawl mode: the system automatically determines that the preset conditions are met, actively controls the vehicle to enter crawl mode, removes parking restrictions, and allows the driver to drive the vehicle at a speed and distance threshold lower than the threshold specified by the target driving strategy through normal operations (such as releasing the brake pedal); or, in response to a user command (such as the activation button corresponding to crawl mode on the human-machine interface), the system passively activates crawl mode after verifying the legality of the user command: the drive system removes traction restrictions, the braking system maintains normal response, and the human-machine interface indicates that crawl mode has been entered. Regardless of whether it is actively triggered or in response to user operation, it is based on the premise that the target ECU strategy meets the entry conditions and the vehicle status meets the entry conditions, ensuring that the vehicle entering crawl mode can both meet basic mobility needs and avoid safety risks through preset restrictions.
[0056] In this embodiment of the application, detecting whether the vehicle status and the target electronic control unit both meet the corresponding preset conditions includes the following steps:
[0057] Step A1: Detect whether the vehicle status matches the admission criteria associated with the crawl mode to obtain the first detection result.
[0058] Specifically, based on the acquired vehicle status (including but not limited to the functional status of the powertrain, steering system, drive system, and battery status), it is determined whether all the conditions for entering crawl mode are met. These conditions can be: the powertrain, steering system, and drive system are all in normal functional states, and the battery status meets preset standards (e.g., battery charge is not lower than a preset threshold, voltage is stable within the normal range, etc.). During detection, if all the above conditions are met, the vehicle status is considered to have met the entry conditions, and the first detection result is "compliant." If any system's functional status is abnormal (e.g., powertrain malfunction, steering system drive-by-wire logic malfunction, etc.), or the battery status is substandard (e.g., battery charge is lower than a threshold, voltage is unstable, etc.), the entry conditions are considered not met, and the first detection result is "incompatible." This detection result will determine whether the vehicle is allowed to enter crawl mode, ensuring that crawl mode is only permitted when the vehicle's core control capabilities and energy supply are reliable.
[0059] Step A2: Obtain the list of electronic control units, which includes multiple electronic control units and the driving strategy corresponding to each electronic control unit.
[0060] Specifically, the electronic control unit (ECU) list refers to a pre-stored structured data set in the vehicle system. This list covers all ECUs in the vehicle (such as brake control units, body control modules, and in-vehicle infotainment units), and associates each ECU with a corresponding driving strategy. The driving strategy for each ECU is a pre-defined rule based on its safety level and functional characteristics. This rule defines the vehicle's driving permissions and restrictions in crawl mode when an ECU upgrade fails (e.g., whether to allow entry into crawl mode, whether to apply specific restrictions). This list is typically stored in the vehicle control system as a database table, configuration file, or mapping table for quick lookup and matching, providing a data foundation for subsequently locating the target driving strategy corresponding to the target ECU from the list.
[0061] Step A3: Obtain the target driving strategy corresponding to the target electronic control unit from the list of electronic control units.
[0062] Specifically, based on the identified target electronic control units (such as brake control units, in-vehicle infotainment units, etc.) that have failed to be upgraded, a precise match is made in the list of electronic control units using their type identifier or unique identifier. After locating the entry corresponding to the unit, the driving strategy associated with that entry is extracted.
[0063] As an example, each electronic control unit (ECU) in the list is uniquely associated with a driving strategy. For instance, the brake control unit corresponds to a no-movement strategy, the body control module corresponds to a crawl restriction strategy (including speed and distance limits), and the in-vehicle infotainment unit corresponds to a full-function crawl strategy. By matching the identifier information of the target ECU, its corresponding strategy content, i.e., the target driving strategy, can be directly retrieved from the list. This target driving strategy serves as the core basis for detecting whether the crawl mode access conditions have been met, ensuring that appropriate driving control logic is applied to ECUs that fail to upgrade.
[0064] Step A4: Detect whether the target driving strategy meets the admission conditions associated with the crawl mode, and obtain the second detection result.
[0065] Specifically, based on the access conditions associated with crawl mode (i.e., the basic safety rules allowing vehicles to enter crawl mode), it is determined whether the target driving strategy corresponding to the target electronic control unit meets these conditions. The access conditions can be: the driving strategy is not a prohibited movement strategy, and the malfunction of the electronic control unit corresponding to the strategy does not affect the vehicle's core control safety (such as the basic operation of power, steering, and braking). During the test, the target driving strategy must be matched against the above access conditions.
[0066] If the target driving strategy is full-function crawl (such as the strategy corresponding to the in-vehicle infotainment unit) or a restricted crawl strategy (such as the strategy corresponding to the body control module), then the strategy does not prohibit movement and meets basic safety requirements, thus it is determined to meet the access conditions, and the second test result is compliant. If the target driving strategy is a no-movement strategy (such as the strategy corresponding to the brake control unit), then the strategy directly conflicts with the access conditions that allow entry into crawl mode, thus it is determined to not meet the access conditions, and the second test result is non-compliant. Through this test, it is determined whether a fault in the target electronic control unit allows the vehicle to enter crawl mode through its preset strategy, providing a key basis for subsequent comprehensive judgment.
[0067] Step A5: Determine whether the vehicle status and the target electronic control unit meet the corresponding preset conditions based on the first detection result and the second detection result.
[0068] In this embodiment of the application, if the first detection result is that the vehicle state meets the access conditions associated with the crawl mode, and the second detection result is that the target driving strategy meets the access conditions associated with the crawl mode, then it is determined that both the vehicle state and the target electronic control unit meet the corresponding preset conditions; if the first detection result is that the vehicle state does not meet the access conditions associated with the crawl mode, or the second detection result is that the target driving strategy does not meet the access conditions associated with the crawl mode, then it is determined that the vehicle state and / or the target electronic control unit does not meet the corresponding preset conditions.
[0069] As an example, when the target electronic control unit is an in-vehicle infotainment unit or a body control module, and the vehicle's powertrain, steering, and drive systems are normal, and the battery status is up to standard (the first detection result is met), and its corresponding target driving strategy allows full-function crawling or restricts crawling (the second detection result is met), it is determined that both the vehicle status and the target electronic control unit meet the preset conditions. However, if the target electronic control unit is a brake control unit (whose strategy prohibits movement, and the second detection result is not met), even if the vehicle status is normal (the first detection result is met), or if the target electronic control unit is a body control module or an air conditioning system ECU but the vehicle's powertrain is faulty or the battery is low (the first detection result is not met), even if its strategy allows crawling (the second detection result is met), it is determined that the vehicle status and / or the target electronic control unit do not meet the preset conditions, and entering the crawling mode is prohibited. This demonstrates the core logic that both conditions must be met simultaneously for a judgment to be valid.
[0070] In this embodiment of the application, after allowing the vehicle to enter crawl mode, the method further includes:
[0071] Step B1: When the vehicle is in crawl mode, acquire the vehicle's driving status parameters in crawl mode, including speed parameters, displacement parameters, and control parameters.
[0072] Specifically, once the vehicle enters crawl mode, sensors and data acquisition modules in various vehicle systems capture key information reflecting the vehicle's current driving status in real time. This includes speed parameters, displacement parameters, and control parameters, which together form the real-time data basis for determining whether the vehicle meets the crawl restriction conditions.
[0073] Speed parameters can be collected in real time through the speed monitoring module integrated into the braking system or wheel speed sensors. For example, when the target electronic control unit is the body control module (e.g., speed threshold 10 km / h), during vehicle crawling on residential roads, the wheel speed sensors transmit wheel speed data to the central control unit (e.g., FOTAmaster) every 50 ms, which is then converted to the current driving speed (e.g., 6 km / h) to ensure real-time reflection of vehicle speed changes. Displacement parameters can be obtained in two ways: one is based on the rotational speed data collected by the wheel speed sensors, combined with the driving time for integral calculation (e.g., one wheel revolution corresponds to a rolling distance of 0.8 meters, 50 revolutions in 10 seconds equals a displacement of 40 meters); the other is using a GPS positioning system to record latitude and longitude changes in real time and convert them into movement distance. For example, when the target electronic control unit is the in-vehicle infotainment unit (no distance limit), during vehicle crawling in a parking lot, the GPS updates the location information every 2 seconds, accurately recording the total displacement from the parking space to the exit as 35 meters. Control parameters can be continuously monitored by the brake pedal position sensor to determine whether they match the preset control parameters. For example, when the target electronic control unit is a drive system auxiliary unit (requiring the driver to continuously depress the brake pedal), the sensor detects the pedal travel changes in real time: if the pedal is continuously depressed (the travel is maintained above 1 / 3), it is determined that the control parameters meet the preset control parameters; if the pedal is released (the travel is 0), it is determined that it does not meet the preset control parameters, and this status data will be synchronously transmitted to the central control unit.
[0074] As an example, the target electronic control unit is the vehicle control module (speed threshold 8km / h, distance threshold 50m). When the vehicle is crawling in congested traffic, the wheel speed sensors transmit speed data in real time (e.g., 7km / h), the wheel speed integral calculates the displacement to be 30 meters, and the brake pedal position sensor shows that the driver has continuously pressed the pedal (half the travel). The data from these three sources are aggregated to FOTAmaster every 100ms to provide a basis for subsequent matching with the constraints. The target electronic control unit is the steering system assist unit (requires speed ≤5km / h). When the vehicle is crawling in narrow alleys, the wheel speed fluctuates due to road bumps. The braking system speed module corrects the data through a filtering algorithm, ultimately outputting a stable speed value of 4km / h. At the same time, GPS records the displacement from the entrance to the corner as 20 meters, and the brake pedal sensor detects intermittent pressing (conforming to the rule of short release but must be pressed again within 3 seconds), ensuring that the control parameters reflect the driver's intention.
[0075] Step B2: Match the driving status parameters with the creep parameters in the target driving strategy corresponding to the target electronic control unit to obtain the matching result.
[0076] Specifically, the vehicle's real-time driving status parameters (speed parameters, displacement parameters, and control parameters) are compared with the creep parameters (speed threshold, distance threshold, and operation verification rules) set in the target driving strategy corresponding to the target electronic control unit using a preset algorithm to determine whether the two match.
[0077] As an example, suppose the target electronic control unit is the vehicle body control module (creep parameters are speed threshold ≤ 8 km / h, distance threshold ≤ 50 meters, and continuous braking pedal application). During creep, the vehicle's real-time driving status parameters are: speed 7 km / h (≤ 8 km / h), displacement 30 meters (≤ 50 meters), and the driver continuously applying the brake pedal (compliant with the rules). After matching, all driving status parameters do not exceed the creep parameter limits, resulting in a perfect match.
[0078] Assuming the target electronic control unit is a drive system auxiliary unit (creep parameters: speed threshold ≤ 5 km / h, distance threshold ≤ 100 meters, brake pedal to be applied every 5 seconds), the driving status parameters are: speed 6 km / h (> 5 km / h), displacement 40 meters (≤ 100 meters), and the driver has not applied the brake pedal for 10 seconds (not in compliance with the rules). After matching, both speed and control parameters do not meet the restrictions, resulting in multiple mismatches.
[0079] Assuming the target electronic control unit is an in-vehicle infotainment unit (creep parameters: speed threshold ≤ 15 km / h, no distance limit, no mandatory operation rules), and the driving status parameters are: speed 12 km / h (≤ 15 km / h), displacement 150 meters (no exceedance), and the driver is not pressing the brake pedal (no rule violation). The matching result is a perfect match.
[0080] Assuming the target electronic control unit is a steering assist unit (creep parameters are speed threshold ≤ 10 km / h, distance threshold ≤ 80 meters, and simultaneous brake pedal depress + steering wheel angle ≤ 30°), the driving state parameters are: speed 9 km / h (≤ 10 km / h), displacement 90 meters (> 80 meters), driver depresses brake pedal but steering wheel angle reaches 45° (not in compliance with rules). The matching result is displacement exceeding limits and control rules mismatch.
[0081] Step B3: Adjust the control parameters of the vehicle's control system based on the matching results so that the control system controls the vehicle's movement according to the adjusted control parameters.
[0082] Specifically, if the matching result shows a successful match between the driving state parameters and the creep parameters, no adjustment of the control parameters is required. The drive system maintains the current traction output (e.g., 20% of rated power), the braking system remains in standby mode (brake pressure 0 MPa), the steering system responds normally according to the driver's operation, and the vehicle continues to creep steadily at 7 km / h. If the matching result shows that there are driving state parameters that fail to match the creep parameters, the corresponding control system is invoked to adjust the vehicle's driving state for the mismatched driving state parameters until all driving state parameters meet the creep parameter limits, or parking is triggered.
[0083] In this embodiment of the application, adjusting the control parameters of the vehicle's control system based on the matching result includes:
[0084] Step C1: If the matching result is that the speed parameter is greater than the speed threshold in the creep parameter, then adjust the traction parameter of the vehicle's control system and monitor whether the vehicle's speed parameter drops to the speed threshold within a preset time period. If it does not drop to the speed threshold, then adjust the braking parameter of the vehicle's control system until the vehicle's speed parameter is less than or equal to the speed threshold.
[0085] Specifically, the tiered control logic for speed exceeding limits can be implemented by first adjusting traction and then intervening in braking in a stepped manner to ensure that the vehicle speed quickly returns to a safe range. An example of the specific adjustment process is as follows:
[0086] The target electronic control unit is the vehicle control module (speed threshold 8 km / h, preset time period 2 seconds). When the vehicle's crawling speed reaches 10 km / h (>8 km / h), it first sends a command to the drive system to reduce the traction parameter from 30% of rated power to 10% (reducing power output); simultaneously, a 2-second timer is started to monitor speed changes in real time. After 1.5 seconds, when the speed drops to 7 km / h (≤8 km / h), the adjustment stops, the current traction parameter is maintained, and the vehicle travels at a stable speed.
[0087] The target electronic control unit is a drive system auxiliary unit (speed threshold 5 km / h, preset time period 3 seconds). When the vehicle creeps to a speed of 7 km / h (>5 km / h), the traction parameter is first reduced from 25% to 5%. However, due to the road slope of 5° (uphill), the speed only drops to 6 km / h after 3 seconds (still exceeding the threshold). At this point, a command is sent to the braking system to adjust the braking parameters (applying 0.2 MPa braking pressure). After 1 second, the speed drops to 4 km / h (≤5 km / h), braking intervention stops, and the traction parameter remains unchanged.
[0088] The target electronic control unit is the in-vehicle infotainment unit (speed threshold 15km / h, preset time period 5 seconds). When the vehicle crawls at a speed of 18km / h (>15km / h), the traction parameter is first reduced from 40% to 15%. After 4 seconds, the speed drops to 16km / h (below the threshold). Then the braking parameter is adjusted (applying 0.1MPa pressure), and monitoring continues. After 2 seconds, the speed drops to 14km / h (≤15km / h), and the traction parameter is restored to 20% to maintain stable driving.
[0089] In special scenarios (such as slippery roads, the target electronic control unit is the steering assist unit, the speed threshold is 10km / h, and the preset time is 3 seconds), when the vehicle creeps to a speed of 12km / h, the traction force is first reduced to 10%. However, due to the slippery road surface, the wheels slip slightly, and the speed is still 11km / h after 3 seconds. The braking parameters are immediately increased (applying 0.3MPa pressure), and the wheel braking force distribution is adjusted through the electronic stability control system. The speed drops to 9km / h after 1.5 seconds, ensuring rapid speed control even on low-traction roads.
[0090] Step C2: If the matching result is that the displacement parameter is greater than the distance threshold in the creep parameter, and / or the control parameter does not meet the preset control parameter in the creep parameter, then the vehicle is allowed to enter the parking mode.
[0091] Specifically, mandatory safety measures for exceeding displacement limits or violating control rules include triggering the parking mode to prevent the risk from escalating. Examples of specific mandatory safety measures include:
[0092] If only the displacement parameter exceeds the limit (the target electronic control unit is the body control module, the distance threshold is 50 meters, and the preset control parameter is continuous pressing of the brake pedal), and the vehicle displacement reaches 55 meters (>50 meters) while creeping, but the driver continues to press the brake pedal (the control parameter is met), the system determines that the displacement exceeds the limit, immediately sends a command to the braking system (applies 0.5MPa braking pressure), and simultaneously cuts off the traction of the drive system, decelerating the vehicle to 0 within 3 seconds; then the electronic parking brake is activated, entering parking mode, and a prompt is sent through the vehicle's interactive terminal indicating that the maximum creep distance has been reached.
[0093] If only the control parameters are not met (the target electronic control unit is the drive system auxiliary unit, the distance threshold is 100 meters, and the preset control parameters are to press the brake pedal once every 5 seconds), the displacement is 30 meters (≤100 meters), but the driver has not pressed the brake pedal for 7 seconds (control parameters are not met), then the system determines that the operation is in violation, immediately starts braking (0.4MPa pressure), and triggers an audible and visual alarm at the same time; after the vehicle comes to a complete stop, the parking lock is activated, the parking mode is entered, and a prompt is made to operate again to activate crawl mode.
[0094] If the displacement exceeds the limit and the operation is violated (the target electronic control unit is the steering assist unit, the distance threshold is 80 meters, and the preset control parameter is brake pedal travel ≥ 1 / 3), and the displacement reaches 85 meters (> 80 meters), and the driver's brake pedal travel is only 1 / 5 (< 1 / 3, the operation is not satisfied), then the system will simultaneously trigger the dual limits, quickly apply the brakes (0.6 MPa pressure), cut off the power, and stop within 2 seconds; then the mechanical parking mechanism will be activated, the parking mode will be entered, and the dual violation information will be recorded for subsequent diagnosis.
[0095] In complex scenarios (the target electronic control unit is the air conditioning control unit, the distance threshold is 120 meters, and the preset control parameters are steering wheel angle ≤ 45°), the displacement is 110 meters (≤ 120 meters), but the driver suddenly turns the steering wheel (the angle reaches 60°, and the control is not satisfied), the system will determine that the control is in violation of the rules. Even if the displacement does not exceed the limit, the system will immediately control the vehicle to decelerate to 0 and stop the vehicle to avoid driving risks caused by excessive steering angle.
[0096] In the above embodiments, regardless of whether a single condition or a combination of conditions are triggered, forced parking ensures that the vehicle stops moving when it exceeds safety limits, further enhancing the safety redundancy in crawl mode.
[0097] In this embodiment of the application, when the vehicle firmware upgrade fails, in addition to the basic crawl mode control process, the management of the failed electronic control unit and crawl parameters is also implemented:
[0098] During the post-installation verification phase, if multiple electronic control unit (ECU) OTA upgrade failures are detected, they are first processed according to safety level priority (high > medium > low): When a high-safety-level ECU (such as a brake control unit) fails, the creep mode is directly disabled and a prompt is displayed on the human-machine interface; if only medium / low-safety-level ECUs fail, the creep parameters are dynamically adjusted based on the number of failed ECUs: First, the safety level and number of multiple failed ECUs are statistically analyzed; when the number of failed ECUs is a preset number, the first-level parameter adjustment rule is triggered; when the number of failed ECUs exceeds the preset number, the second-level parameter adjustment rule is triggered; according to the matching adjustment rule, multiple creep parameters in the creep restriction conditions are adjusted accordingly: if the first-level rule is triggered, the creep parameters are reduced by a first percentage (e.g., 20%) from their original default values; if the second-level rule is triggered, the creep parameters are reduced by a second percentage (e.g., 50%) from their original default values. Subsequently, the adjusted creep parameters must undergo validity verification to ensure they are within a safe and reasonable range (e.g., the speed threshold is not lower than a preset minimum value, and the distance threshold is not less than a preset minimum value). After successful verification, the FOTA master sends the adjusted creep parameters to the drive and braking systems to limit the vehicle's driving status. Finally, the human-machine interface displays the current creep parameter adjustment status due to the number of failed OTA updates for electronic control units, and records the number of failed electronic control units, the adjusted parameter values, and the adjustment time in the vehicle log for subsequent querying and analysis, ensuring that the risk level matches the intensity of the restriction.
[0099] The creep parameter adjustment process also includes: FOTAmaster establishing a connection with the cloud server through a secure communication protocol (such as TLS) and periodically checking for creep parameter update instructions (such as adjusting the speed threshold to 15km / h and the distance threshold to 200 meters); upon receiving the update instruction, parsing the validity of the parameters (such as the speed threshold needing to be ≥5km / h and ≤30km / h), and sending the new parameters to the drive system and braking system through an internal communication protocol; after the relevant systems update the parameters, returning confirmation information to FOTAmaster, and simultaneously displaying a message on the human-machine interface indicating that the creep limit parameters have been updated, ensuring that the local configuration is synchronized with the cloud.
[0100] The method provided in this application achieves refined management of failed electronic control unit (ECU) upgrades and parameters by classifying and processing multiple ECU upgrade failures during the post-installation verification phase and dynamically adjusting creep parameters based on the number of failed ECUs. Through a safety-level priority-based classification mechanism, creep mode is directly prohibited when a high-safety-level ECU fails, effectively avoiding safety risks caused by critical system failures. For medium / low-safety-level ECU failures, creep parameters are dynamically adjusted based on the number of failures, ensuring basic vehicle driving capability while matching the creep restriction strength to the risk level, thus improving the vehicle's safety and adaptability in scenarios with multiple ECU upgrade failures.
[0101] The validity verification mechanism after parameter adjustment ensures that the adjusted creep parameters are within a safe and reasonable range, avoiding new safety issues caused by excessive or insufficient restrictions, and enhancing the robustness of the system. By distributing the adjusted creep parameters to the drive and braking systems through FOTAmaster, precise control of the vehicle's driving status is achieved, ensuring that the limiting measures are effectively implemented.
[0102] The HMI interface displays the status of creep parameter adjustments, allowing drivers to understand the vehicle's current driving restrictions and improving driving safety. The vehicle log records the number of failed electronic control units, the adjusted parameter values, and the adjustment time, which not only facilitates the tracing and analysis of upgrade failures but also provides data support for system optimization, helping to improve the reliability and intelligence of the entire vehicle firmware upgrade safety control system.
[0103] In this embodiment of the application, after detecting whether the vehicle status and the target electronic control unit both meet the corresponding preset conditions, the method further includes: generating corresponding prompt information based on the vehicle status and / or the target electronic control unit; and controlling the vehicle to perform corresponding prompt operations based on the prompt information.
[0104] Specifically, by combining the vehicle's status (whether it meets the crawl mode access criteria) with the type and safety level of the target electronic control unit, a prompt reflecting the degree of abnormality is generated and executed through the vehicle's interactive system to ensure that the driver is promptly aware of the vehicle's status.
[0105] The target electronic control unit is the brake control unit (high safety level). If the vehicle's condition does not meet the access requirements (such as powertrain malfunction), the system generates a message: "Vehicle OTA upgrade failed (brake control unit malfunction), vehicle prohibited from driving, please contact maintenance personnel." Simultaneously, the system controls the vehicle to display a red screen on the human-machine interface, accompanied by a continuous beeping sound, and locks the drive system, forcibly maintaining the parking mode to ensure the driver cannot operate the vehicle.
[0106] The target electronic control unit is the in-vehicle infotainment unit (low security level). The vehicle status meets the access requirements. The system generates a message: "Vehicle OTA upgrade failed (in-vehicle entertainment system malfunction), vehicle allowed to enter crawl mode, some entertainment functions unavailable." A yellow pop-up window is displayed on the human-machine interface (not a full-screen display, not obscuring core driving information), and a prompt voice is played once through the vehicle's audio system, allowing the vehicle to enter full-function crawl mode without additional restrictions on basic driving operations.
[0107] The target electronic control unit is the body control module (medium safety level). The vehicle status meets the access requirements, and the system generates a message: "Vehicle OTA upgrade failed (body control module malfunction), current crawling is restricted (speed ≤ 8km / h, distance ≤ 50 meters)". This message is displayed in orange on half-screen via the human-machine interface (reducing to a status bar indicator after 10 seconds) and the instrument panel warning lights illuminate simultaneously, alerting the driver to the driving restrictions. The vehicle then enters crawling mode under medium-level restrictions.
[0108] The target electronic control unit is the air conditioning control unit (low safety level). The vehicle's status does not meet the access requirements (e.g., insufficient battery power). The system generates a message: "Vehicle OTA upgrade failed (air conditioning system malfunction), insufficient battery power, vehicle cannot be driven, please charge and try again." A blue pop-up window appears on the human-machine interface, accompanied by a audible notification, clearly informing the driver of the cause of the malfunction and the solution, while the vehicle remains in the parking lock state.
[0109] The target electronic control unit is the steering assist unit (medium safety level). The vehicle status meets the access requirements, and the system generates a message: "Vehicle OTA upgrade failed (steering assist system malfunction), currently restricted to crawl (steering angle ≤30°), please drive with caution." The message is displayed scrolling through the human-machine interface, combined with steering wheel vibration feedback, to both remind the driver of the steering limitations and without interfering with the core driving view. The vehicle then enters crawl mode according to the restricted steering conditions.
[0110] In the above embodiments, the severity of the prompt information (color, display method, content) and the execution operation (locking, restricting driving, audio-visual prompts) are strongly correlated with the safety level of the target electronic control unit and the vehicle status, thereby achieving a match between the degree of abnormality and the intensity of notification, ensuring the driver's right to know the vehicle status and driving safety.
[0111] In this embodiment of the application, the method further includes: when the vehicle is in crawl mode, in response to a crawl exit command, allowing the vehicle to enter normal driving mode.
[0112] Specifically, the crawl exit command is first sent to the FOTAmaster via the on-board diagnostic interface (such as OBD-II) or internal communication protocol (such as IPCP). This command instructs the system to exit crawl mode. Upon receiving the command, the FOTAmaster sends control signals to relevant modules to remove the driving strategies in crawl mode. For example, it cancels the speed threshold limitation on vehicle speed, clears the monitoring of distance thresholds, and no longer requires the driver to continuously press the brake pedal to maintain driving status. At the same time, the FOTAmaster notifies the drive system and braking system to return to normal operating mode. The drive system no longer limits traction output, and the braking system also returns to normal braking control logic, thus enabling the vehicle to enter normal driving mode and no longer be subject to the various conditions of crawl mode.
[0113] When triggering the exit from crawl mode or executing diagnostic commands, a user authorization authentication mechanism needs to be triggered. The process is as follows: When a crawl exit command or diagnostic command is received, the vehicle control unit starts the authorization authentication module; the authentication module compares the input information with the authorization information in the vehicle safety database to verify the authorization level (such as a repair technician); if the authentication is successful, the corresponding command is allowed to be executed; if the authentication fails, the operation is rejected and an insufficient authorization message is displayed on the human-machine interface, while an unauthorized operation log is recorded.
[0114] When OTA upgrades fail or crawl mode malfunctions occur, a tiered recording and storage of fault logs is added to facilitate subsequent fault analysis. The process is as follows: When an electronic control unit upgrade failure or parameter matching anomaly in crawl mode is detected, FOTAmaster classifies the fault level (fatal, warning, alert) according to the anomaly type (e.g., high, medium, low safety level); records the fault code, occurrence time, relevant electronic control unit type, driving status parameters (e.g., speed, displacement), and current system configuration information, and stores it in the vehicle fault database; for serious faults (e.g., failure of a high-safety-level electronic control unit), the fault log is also synchronized to the T-BOX via the CAN bus and uploaded to the cloud server.
[0115] As an example, Figure 2 A flowchart of a security control method for vehicle firmware upgrades, such as Figure 2 As shown, the process includes: first, entering the firmware upgrade process, with the vehicle entering parking mode during the pre-installation phase; then, monitoring the target electronic control unit that failed to upgrade, and in the post-installation phase, matching the corresponding driving strategy in the electronic control unit list based on the target electronic control unit—the crawl prevention strategy, which prompts OTA upgrade failure and prohibits driving; the crawl restriction strategy and the full-function crawl strategy, both of which prompt OTA upgrade failure and restrict driving; finally, the crawl exit command can be responded to to exit the crawl mode.
[0116] This embodiment also provides a vehicle firmware upgrade security control device for implementing the above embodiments and preferred embodiments; details already described will not be repeated. As used below, the term "module" can refer to a combination of software and / or hardware that performs a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.
[0117] This embodiment provides a security control device for vehicle firmware upgrades, such as... Figure 3 As shown, it includes:
[0118] Monitoring module 31 is used to monitor the target electronic control unit in the vehicle that failed to upgrade when the vehicle is undergoing firmware upgrade in parking mode. The target electronic control unit can be any electronic control unit in the vehicle.
[0119] The detection module 32 is used to acquire the vehicle status and detect whether the vehicle status and the target electronic control unit both meet the corresponding preset conditions.
[0120] The determination module 33 is used to allow the vehicle to enter the crawl mode if both the target electronic control unit and the vehicle status meet the corresponding preset conditions.
[0121] Furthermore, the detection module 32 also includes:
[0122] The first detection submodule is used to detect whether the vehicle status meets the admission conditions associated with the crawl mode and obtain the first detection result;
[0123] The first acquisition submodule is used to acquire a list of electronic control units, wherein the list of electronic control units includes multiple electronic control units and the driving strategy corresponding to each electronic control unit;
[0124] The second acquisition submodule is used to obtain the target driving strategy corresponding to the target electronic control unit from the list of electronic control units;
[0125] The second detection submodule is used to detect whether the target driving strategy hits the admission conditions associated with the crawl mode, and obtain the second detection result;
[0126] The determination submodule is used to determine whether the vehicle status and the target electronic control unit meet the corresponding preset conditions based on the first detection result and the second detection result.
[0127] Furthermore, the determination submodule is used to determine that if the first detection result is that the vehicle state meets the access conditions associated with the crawl mode, and the second detection result is that the target driving strategy meets the access conditions associated with the crawl mode, then the vehicle state and the target electronic control unit both meet the corresponding preset conditions; if the first detection result is that the vehicle state does not meet the access conditions associated with the crawl mode, or the second detection result is that the target driving strategy does not meet the access conditions associated with the crawl mode, then the vehicle state and / or the target electronic control unit does not meet the corresponding preset conditions.
[0128] Furthermore, the device also includes: a control module, used to acquire the vehicle's driving state parameters in crawl mode when the vehicle is in crawl mode, wherein the driving state parameters include speed parameters, displacement parameters and control parameters; match the driving state parameters with the crawl parameters in the target driving strategy corresponding to the target electronic control unit to obtain a matching result; and adjust the control parameters of the vehicle's control system based on the matching result so that the control system controls the vehicle's driving according to the adjusted control parameters.
[0129] Furthermore, the control module also includes:
[0130] The first adjustment submodule is used to adjust the traction parameter of the vehicle's control system if the matching result is that the speed parameter is greater than the speed threshold in the creep parameter, and to monitor whether the vehicle's speed parameter drops to the speed threshold within a preset time period. If it does not drop to the speed threshold, the braking parameter of the vehicle's control system is adjusted until the vehicle's speed parameter is less than or equal to the speed threshold.
[0131] The second adjustment submodule is used to allow the vehicle to enter parking mode if the matching result is that the displacement parameter is greater than the distance threshold in the creep parameter, and / or the control parameter does not meet the preset control parameter in the creep parameter.
[0132] Furthermore, the device also includes: a prompting module, used to generate corresponding prompting information based on the vehicle status and / or the target electronic control unit; and to control the vehicle to perform corresponding prompting operations based on the prompting information.
[0133] Furthermore, the device also includes an exit module for allowing the vehicle to enter normal driving mode in response to a crawl exit command when the vehicle is in crawl mode.
[0134] Please see Figure 4 , Figure 4 This is a schematic diagram of the structure of a computer device provided in an optional embodiment of the present invention, such as... Figure 4As shown, the computer device includes one or more processors 10, memory 20, and interfaces for connecting the components, including high-speed interfaces and low-speed interfaces. The components communicate with each other via different buses and can be mounted on a common motherboard or otherwise installed as needed. The processors can process instructions executed within the computer device, including instructions stored in or on memory to display graphical information of a GUI on external input / output devices (such as display devices coupled to the interfaces). In some alternative implementations, multiple processors and / or multiple buses can be used with multiple memories and multiple memory modules, if desired. Similarly, multiple computer devices can be connected, each providing some of the necessary operations (e.g., as a server array, a group of blade servers, or a multiprocessor system).
[0135] Processor 10 may be a central processing unit, a network processor, or a combination thereof. Processor 10 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The programmable logic device may be a complex programmable logic device (CAMP), a field-programmable gate array (FPGA), a general-purpose array logic (GDA), or any combination thereof.
[0136] The memory 20 stores instructions executable by at least one processor 10 to cause at least one processor 10 to perform the method shown in the above embodiments.
[0137] The memory 20 may include a program storage area and a data storage area. The program storage area may store the operating system and applications required for at least one function; the data storage area may store data created based on the use of the computer device as shown by a landing page for an app. Furthermore, the memory 20 may include high-speed random access memory and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some alternative embodiments, the memory 20 may optionally include memory remotely located relative to the processor 10, which can be connected to the computer device via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.
[0138] The memory 20 may include volatile memory, such as random access memory; the memory may also include non-volatile memory, such as flash memory, hard disk or solid-state drive; the memory 20 may also include a combination of the above types of memory.
[0139] The computer device also includes a communication interface 30 for communicating with other devices or communication networks.
[0140] This invention also provides a computer-readable storage medium. The methods described above according to embodiments of the invention can be implemented in hardware or firmware, or implemented as computer code that can be recorded on a storage medium, or implemented as computer code downloaded via a network and originally stored on a remote storage medium or a non-transitory machine-readable storage medium and then stored on a local storage medium. Thus, the methods described herein can be processed by software stored on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. The storage medium can be a magnetic disk, optical disk, read-only memory, random access memory, flash memory, hard disk, or solid-state drive, etc.; further, the storage medium can also include combinations of the above types of memory. It is understood that computers, processors, microprocessor controllers, or programmable hardware include storage components capable of storing or receiving software or computer code, which, when accessed and executed by the computer, processor, or hardware, implements the methods shown in the above embodiments.
[0141] Although embodiments of the invention have been described in conjunction with the accompanying drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of the invention, and such modifications and variations all fall within the scope defined by the appended claims.
Claims
1. A security control method for vehicle firmware upgrades, characterized in that, The method includes: When the vehicle is undergoing firmware upgrade in parking mode, the system monitors the target electronic control unit in the vehicle that failed to upgrade, wherein the target electronic control unit is any electronic control unit in the vehicle. The vehicle status is obtained, and it is detected whether the vehicle status and the target electronic control unit both meet the corresponding preset conditions. If both the target electronic control unit and the vehicle status meet the corresponding preset conditions, the vehicle is allowed to enter crawl mode. The step of detecting whether the vehicle state and the target electronic control unit both meet the corresponding preset conditions includes: detecting whether the vehicle state matches the access conditions associated with the crawl mode to obtain a first detection result; obtaining an electronic control unit list, wherein the electronic control unit list includes multiple electronic control units and a driving strategy corresponding to each electronic control unit; obtaining the target driving strategy corresponding to the target electronic control unit from the electronic control unit list; detecting whether the target driving strategy matches the access conditions associated with the crawl mode to obtain a second detection result; and determining whether the vehicle state and the target electronic control unit meet the corresponding preset conditions based on the first detection result and the second detection result.
2. The method according to claim 1, characterized in that, The step of determining whether the vehicle state and the target electronic control unit meet the corresponding preset conditions based on the first detection result and the second detection result includes: If the first detection result is that the vehicle state meets the admission conditions associated with the crawl mode, and the second detection result is that the target driving strategy meets the admission conditions associated with the crawl mode, then it is determined that both the vehicle state and the target electronic control unit meet the corresponding preset conditions. If the first detection result indicates that the vehicle state does not meet the access conditions associated with the crawl mode, or the second detection result indicates that the target driving strategy does not meet the access conditions associated with the crawl mode, then it is determined that the vehicle state and / or the target electronic control unit does not meet the corresponding preset conditions.
3. The method according to claim 1, characterized in that, After allowing the vehicle to enter crawl mode, the method further includes: When the vehicle is in crawl mode, the driving status parameters of the vehicle in crawl mode are acquired, wherein the driving status parameters include speed parameters, displacement parameters and control parameters. The driving state parameters are matched with the creep parameters in the target driving strategy corresponding to the target electronic control unit to obtain the matching result; Based on the matching result, the control parameters of the vehicle's control system are adjusted so that the control system controls the vehicle's movement according to the adjusted control parameters.
4. The method according to claim 3, characterized in that, The adjustment of the control parameters of the vehicle's control system based on the matching result includes: If the matching result is that the speed parameter is greater than the speed threshold in the creep parameter, then the traction parameter of the vehicle control system is adjusted, and the vehicle speed parameter is monitored within a preset time period to see if it drops to the speed threshold. If it does not drop to the speed threshold, then the braking parameter of the vehicle control system is adjusted until the vehicle speed parameter is less than or equal to the speed threshold. Alternatively, if the matching result is that the displacement parameter is greater than the distance threshold in the creep parameter, and / or the control parameter does not meet the preset control parameter in the creep parameter, then the vehicle is allowed to enter the parking mode.
5. The method according to claim 1, characterized in that, After detecting whether the vehicle status and the target electronic control unit both meet the corresponding preset conditions, the method further includes: Generate corresponding prompt information based on the vehicle status and / or the target electronic control unit; Based on the prompt information, the vehicle is controlled to perform the corresponding prompt operation.
6. The method according to claim 1, characterized in that, The method further includes: When the vehicle is in crawl mode, in response to a crawl exit command, the vehicle is allowed to enter normal driving mode.
7. A safety control device for vehicle firmware upgrades, characterized in that, The device includes: The monitoring module is used to monitor the target electronic control unit in the vehicle that failed to upgrade when the vehicle is undergoing firmware upgrade in parking mode, wherein the target electronic control unit is any electronic control unit in the vehicle; The detection module is used to acquire the vehicle status of the vehicle and detect whether the vehicle status and the target electronic control unit both meet the corresponding preset conditions. The determination module is used to allow the vehicle to enter the crawl mode if both the target electronic control unit and the vehicle status meet the corresponding preset conditions. The detection module is used to detect whether the vehicle state matches the access conditions associated with the crawl mode, and obtain a first detection result; obtain an electronic control unit list, wherein the electronic control unit list includes multiple electronic control units and a driving strategy corresponding to each electronic control unit; obtain a target driving strategy corresponding to the target electronic control unit from the electronic control unit list; detect whether the target driving strategy matches the access conditions associated with the crawl mode, and obtain a second detection result; and determine whether the vehicle state and the target electronic control unit meet the corresponding preset conditions based on the first detection result and the second detection result.
8. A computer device, characterized in that, include: A memory and a processor, the memory and the processor being communicatively connected to each other, the memory storing computer instructions, the processor executing the computer instructions to perform the method of any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing a computer to perform the method of any one of claims 1 to 6.
Citation Information
Patent Citations
Unmanned vehicle fault processing method and device, electronic equipment and storage medium
CN111123887A
Vehicle program update system and vehicle program update method
CN113553076A