Vehicle-mounted software upgrading method and device

CN120803486APending Publication Date: 2025-10-17MERCEDES BENZ GRP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510727551.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-03
Publication Date
2025-10-17

Smart Images

  • Figure CN120803486A_ABST
    Figure CN120803486A_ABST
Patent Text Reader

Abstract

The invention discloses a vehicle-mounted software upgrading method and device, and belongs to the technical field of software upgrading. According to one specific embodiment, the method comprises the steps that after a bootstrap program needed by vehicle-mounted controller software upgrading is started, whether the function of the bootstrap program is abnormal or not is detected through a first verification strategy, and upgrading software data of the vehicle-mounted controller software are obtained and software upgrading operation is executed according to the situation that no abnormality exists; after the upgraded upgrading software is started, detecting whether the function of the upgrading software is abnormal or not by utilizing a second verification strategy; aiming at the abnormal condition, backup software with normal functions can be obtained from the backup storage area and is used for replacing the abnormal upgrading software; according to the embodiment of the invention, the problem that the vehicle-mounted controller cannot operate normally and cannot be repaired due to the existing method is solved, and the fine management degree and the upgrading reliability of the upgrading of the vehicle-mounted controller are improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of software upgrading, in particular to a vehicle-mounted software upgrading method and device. BACKGROUND

[0002] There are various controllers in an intelligent vehicle, and various intelligent user services are provided for the intelligent vehicle through software running on various vehicle-mounted controllers; with the functions of intelligent vehicle services becoming more and more rich, the frequency of performing software upgrading on the running software of the vehicle-mounted controller is also higher and higher.

[0003] The existing method usually directly uses the upgrading software to perform software upgrading on the vehicle-mounted controller after power-off, however, during the software upgrading, whether the function of the boot program is abnormal or the function of the upgraded software is abnormal will cause the vehicle-mounted controller to be unable to normally run, and in the case that the vehicle-mounted controller is unable to normally run, the vehicle-mounted controller cannot be repaired by re-flashing the upgrading software, which affects the vehicle experience of the passenger. SUMMARY

[0004] Therefore, the present application provides a vehicle-mounted software upgrading method and device, which can detect whether the function of the boot program is abnormal after starting the boot program required for vehicle-mounted controller software upgrading, acquire upgrading software data of the vehicle-mounted controller software and perform software upgrading operation for the case that there is no abnormality; start the upgrading software after the upgrading is completed, detect whether the function of the upgrading software is abnormal by using a second verification strategy; for the case that there is an abnormality, acquire backup software with normal function from a backup storage area and replace the upgrading software with abnormality; the embodiments of the present application overcome the problems of the existing method that the vehicle-mounted controller is unable to normally run and cannot be repaired, and improve the fine management degree and upgrading reliability of the vehicle-mounted controller upgrading.

[0005] In order to solve the above technical problems, the present application provides the following technical solutions:

[0006] In a first aspect, the present application provides a vehicle-mounted software upgrading method applied to a vehicle-mounted controller, including: in response to receiving an upgrading request for vehicle-mounted controller software, starting a boot program required for vehicle-mounted controller software upgrading; detecting whether the function of the boot program is abnormal by using a first verification strategy, acquiring upgrading software data of the vehicle-mounted controller software and performing software upgrading operation for the case that there is no abnormality; starting the upgrading software after the upgrading is completed, detecting whether the function of the upgrading software is abnormal by using a second verification strategy; for the case that there is an abnormality, acquiring backup software with normal function from a backup storage area and replacing the upgrading software with abnormality.

[0007] Optionally, the vehicle-mounted software upgrading method further comprises: in the case that the function of the boot program is abnormal, obtaining a backup boot program with normal function from the backup storage area, replacing the backup boot program with the boot program, further obtaining the upgrading software data of the vehicle-mounted controller software and performing the software upgrading operation.

[0008] Optionally, the function of the boot program is detected by using the first checking strategy, comprising: obtaining first checking data corresponding to the function of the boot program, calling a first checking program indicated by the first checking strategy to detect whether the first checking data is abnormal; wherein the first checking data comprises one or more of first flow data indicating a function flow of the boot program, first time interval data indicating a self-checking period of the boot program, and a first execution number of a key function of the boot program; and / or calling a second checking program indicated by the first checking strategy to perform communication with the boot program according to a first set time interval, and detecting whether the function of the boot program is abnormal according to the communication result.

[0009] Optionally, the function of the upgrading software is detected by using the second checking strategy, comprising: obtaining second checking data corresponding to the function of the upgrading software, calling a third checking program indicated by the second checking strategy to detect whether the second checking data is abnormal; wherein the second checking data comprises one or more of second flow data indicating a function flow of the upgrading software, second time interval data indicating a self-checking period of the upgrading software, and a second execution number of a key function of the upgrading software; and / or calling a second checking program indicated by the second checking strategy to perform communication with the upgrading software according to a second set time interval, and detecting whether the function of the upgrading software is abnormal according to the communication result.

[0010] Optionally, the vehicle-mounted controller comprises a plurality of core processors; the boot program and the upgrading software are run by using a first core processor in the plurality of core processors; and the second checking program is run by using a second core processor in the plurality of core processors.

[0011] Optionally, after obtaining the upgrading software data of the vehicle-mounted controller software, the method further comprises: obtaining an upgrading strategy from the upgrading request of the vehicle-mounted controller software, in the case that the upgrading strategy is a specific strategy related to firmware of the vehicle-mounted controller, obtaining firmware data related to the specific strategy for the firmware, and detecting whether the firmware data meets the specific strategy, and if so, performing the software upgrading operation based on the firmware.

[0012] Optionally, the vehicle-mounted controller is divided into a plurality of relatively independent storage partitions, and the two specific storage partitions include specific software in a mirror relationship and do not affect each other; the vehicle-mounted software method further includes: determining a first storage partition to which the currently running software of the vehicle-mounted controller belongs; after receiving an upgrade request for the vehicle-mounted controller software, downloading upgrade software data indicated by the upgrade request, and writing the upgrade software data into a second storage partition, wherein the second storage partition stores to-be-upgraded software in a mirror relationship with the currently running software, and performing a software upgrade operation on the to-be-upgraded software.

[0013] Optionally, starting the upgraded software after the upgrade is completed, including: in the case of detecting that the vehicle-mounted controller is restarted, starting the upgraded software in the second storage partition as the software currently running on the vehicle-mounted controller; and / or the vehicle-mounted software upgrade method further includes: after the currently running software of the vehicle-mounted controller is switched to the software belonging to the second storage partition, synchronously upgrading the software included in the first storage partition to the upgraded software.

[0014] In a second aspect, an embodiment of the present application provides a vehicle-mounted software upgrade device, including:

[0015] A starting module is configured to start a boot program required for vehicle-mounted controller software upgrade in response to receiving an upgrade request for the vehicle-mounted controller software;

[0016] A first detection module is configured to detect whether the function of the boot program is abnormal by using a first verification strategy, and for the case where the function is not abnormal, to acquire upgrade software data of the vehicle-mounted controller software and perform a software upgrade operation;

[0017] A second detection module is configured to start the upgraded software after the upgrade is completed, detect whether the function of the upgraded software is abnormal by using a second verification strategy, and for the case where the function is abnormal, to acquire backup software with a normal function from a backup storage area and replace the upgraded software with the abnormal function.

[0018] Optionally, the vehicle-mounted software upgrade device is configured to detect whether the function of the boot program is abnormal by using the first verification strategy, and further includes: for the case where the function of the boot program is abnormal, acquiring a backup boot program with a normal function from the backup storage area, replacing the backup boot program with the boot program, further acquiring the upgrade software data of the vehicle-mounted controller software, and performing the software upgrade operation.

[0019] Optionally, the vehicle-mounted software upgrading apparatus is configured to detect whether the function of the bootloader is abnormal by using a first checking strategy, and includes: obtaining first checking data corresponding to the function of the bootloader, and calling a first checking program indicated by the first checking strategy to detect whether the first checking data is abnormal; wherein the first checking data includes one or more of first flow data indicating a function flow of the bootloader, first time interval data indicating a self-checking period of the bootloader, and a first execution number of a key function of the bootloader; and / or calling a second checking program indicated by the first checking strategy to perform communication with the bootloader according to a first set time interval, and detecting whether the function of the bootloader is abnormal according to a communication result.

[0020] Optionally, the vehicle-mounted software upgrading apparatus is configured to detect whether the function of the upgrading software is abnormal by using a second checking strategy, and includes: obtaining second checking data corresponding to the function of the upgrading software, and calling a third checking program indicated by the second checking strategy to detect whether the second checking data is abnormal; wherein the second checking data includes one or more of second flow data indicating a function flow of the upgrading software, second time interval data indicating a self-checking period of the upgrading software, and a second execution number of a key function of the upgrading software; and / or calling a second checking program indicated by the second checking strategy to perform communication with the upgrading software according to a second set time interval, and detecting whether the function of the upgrading software is abnormal according to a communication result.

[0021] Optionally, the vehicle-mounted controller includes a plurality of core processors; and the vehicle-mounted software upgrading apparatus is configured to run the bootloader and the upgrading software by using a first core processor of the plurality of core processors, and run the second checking program by using a second core processor of the plurality of core processors.

[0022] Optionally, the vehicle-mounted software upgrading apparatus, after obtaining the upgrading software data of the vehicle-mounted controller software, further includes: obtaining an upgrading strategy from an upgrading request of the vehicle-mounted controller software, obtaining firmware data related to the specific strategy for the firmware in a case where the upgrading strategy is a specific strategy related to firmware of the vehicle-mounted controller, and performing the software upgrading operation step based on the firmware if the firmware data satisfies the specific strategy.

[0023] Optionally, the vehicle-mounted controller is divided into a plurality of relatively independent storage partitions, and the specific software included in two specific storage partitions is in a mirror relationship and does not affect each other; and the vehicle-mounted software upgrading apparatus is further configured to determine a first storage partition to which currently running software of the vehicle-mounted controller belongs, download upgrading software data indicated by an upgrading request after receiving the upgrading request for the vehicle-mounted controller software, and write the upgrading software data into a second storage partition, wherein the second storage partition stores to-be-upgraded software in a mirror relationship with the currently running software; and perform the software upgrading operation step for the to-be-upgraded software.

[0024] Optionally, the vehicle-mounted software upgrading device for starting the upgraded software after the upgrade is completed, comprising: in the case of detecting the restart of the vehicle-mounted controller, starting the upgraded software in the second storage partition as the software currently running on the vehicle-mounted controller; and / or, the vehicle-mounted software upgrading method further comprising: after the currently running software of the vehicle-mounted controller is switched to the software of the second storage partition, synchronously upgrading the software contained in the first storage partition to the upgraded software.

[0025] In a third aspect, an embodiment of the present application provides an electronic device, comprising:

[0026] one or more processors;

[0027] a storage device configured to store one or more programs,

[0028] When the one or more programs are executed by the one or more processors, the one or more processors implement the vehicle-mounted software upgrading method of the above-mentioned embodiments of the present application.

[0029] In a fourth aspect, an embodiment of the present application provides a computer readable storage medium having stored thereon a computer program for implementing a vehicle-mounted software upgrading method, which, when executed by a vehicle-mounted processor, implements the vehicle-mounted software upgrading method of the embodiments of the present application.

[0030] In a fifth aspect, an embodiment of the present application provides a vehicle capable of implementing the vehicle-mounted software upgrading method of the above-mentioned embodiments of the present application.

[0031] The technical solution of the above-mentioned application has the following advantages or beneficial effects: after starting the boot program required for upgrading the software of the vehicle-mounted controller, the first verification strategy is used to detect whether the function of the boot program is abnormal, for the case where the function is not abnormal, the upgrade software data of the vehicle-mounted controller software is obtained and the software upgrading operation is performed; after starting the upgraded software after the upgrade is completed, the second verification strategy is used to detect whether the function of the upgraded software is abnormal; for the case where the function is abnormal, the backup software with normal function is obtained from the backup storage area and replaces the upgraded software with abnormal function; the embodiments of the present application overcome the problems of the existing method that the vehicle-mounted controller cannot run normally and cannot be repaired, by respectively performing function detection on the boot program and the upgraded software, and replacing the abnormal software with the backup software for the abnormal case, thereby improving the fine management degree and the upgrade reliability of the vehicle-mounted controller. BRIEF DESCRIPTION OF DRAWINGS

[0032] Figure 1 is a flowchart of a vehicle-mounted software upgrading method according to an embodiment of the present application;

[0033] Figure 2 is a flowchart of another vehicle software upgrading method according to an embodiment of the present application;

[0034] Figure 3 is a structural diagram of a vehicle software upgrading method according to an embodiment of the present application;

[0035] Figure 4 is a structural diagram of a vehicle software upgrading device according to an embodiment of the present application;

[0036] Figure 5 is a structural diagram of a computer system suitable for implementing an embodiment of the present application. DETAILED DESCRIPTION

[0037] Exemplary embodiments of the present application are described herein with reference to the accompanying drawings, which are meant to be exemplary and not limiting in nature. Therefore, it should be understood that various changes and modifications to the embodiments described herein can be made without departing from the scope and spirit of the present application. Also, for the sake of brevity and clarity, descriptions of well-known functions and constructions are omitted herein.

[0038] It should be noted that the embodiments of the present application and the technical features in the embodiments can be combined with each other without conflict.

[0039] In addition, the terms "first", "second", "third", etc. contained in the embodiments of the present application are used to distinguish similar objects, and do not necessarily indicate a specific number or sequence. It should be understood that the terms used in this way can be interchanged under appropriate circumstances, which is only a way of distinguishing objects with the same properties in the description of the embodiments of the present application.

[0040] In addition, the vehicle involved in the embodiments of the present application can be an internal combustion engine vehicle using an engine as a power source, a hybrid vehicle using an engine and an electric motor as a power source, an electric vehicle using an electric motor as a power source, etc.

[0041] Figure 1 The main steps of the vehicle software upgrading method provided by the embodiments of the present application are shown in the following schematic diagram:

[0042] The vehicle software upgrading method provided by the embodiments of the present application is applied to one or more vehicle controllers in a vehicle.

[0043] Step S101: In response to receiving an upgrade request for the vehicle controller software, start the boot program required for the vehicle controller software upgrade.

[0044] Specifically, in the embodiment of the present application, the boot program in the vehicle-mounted controller is a bottom software running in the controller hardware, which has functions of initializing hardware, loading and starting the main application program, etc., and serves as the basic software required for software upgrade.

[0045] The upgrade request for the software of the vehicle-mounted controller can be triggered by the server or the vehicle-mounted client, for example, the server or the vehicle-mounted client sends the upgrade request for the software of the vehicle-mounted controller when detecting that any vehicle-mounted controller has a new software version.

[0046] Further, the boot program required for starting the software upgrade of the vehicle-mounted controller is started to perform the subsequent software upgrade operation after the boot program is started.

[0047] Step S102: The function of the boot program is detected by using the first check strategy, and for the case where no abnormality exists, the upgrade software data of the software of the vehicle-mounted controller is acquired and the software upgrade operation is performed.

[0048] Step S103: The upgrade software after the upgrade is started, and the function of the upgrade software is detected by using the second check strategy; for the case where abnormality exists, the backup software with normal function is acquired from the backup storage area and replaces the upgrade software with abnormality.

[0049] Specifically, in the existing method, in the case where the boot program has functional abnormality or the upgraded software has abnormality and cannot normally run, the vehicle-mounted controller can be caused to have problems such as "stuck" or "locked", and the vehicle-mounted controller with abnormality cannot be repaired again through the normal software upgrade (burning) process.

[0050] In the embodiment of the present application, the function of the boot program is detected by using the first check strategy, and the function of the upgrade software is detected by using the second check strategy.

[0051] 1) Detection of the function of the boot program.

[0052] Specifically, the first check strategy is called to detect the first check program and / or the second check program to perform the step of detecting whether the function of the boot program has abnormality.

[0053] Further, the first check data corresponding to the function of the boot program is acquired, and the first check program indicated by the first check strategy is called to detect whether the first check data has abnormality.

[0054] Specifically, a first check data is used to detect whether the function of the boot program is normal (i.e. the first flow data indicating the function flow of the boot program), the check data includes various specific mark points of the flow execution of the boot program, and the first check program is called to judge whether all the specific mark points are executed and the execution sequence is correct, so as to judge whether the function of the boot program is abnormal.

[0055] Another first check data is used to detect whether the self-check period of the boot program is normal (i.e. the first time interval data indicating the self-check period of the boot program), and a timing check period is set in the boot program, and the first check program is called to judge whether the execution period is within a specific threshold value, so as to judge the function of the boot program (for example, the specific threshold value of the timing check is 100 milliseconds, and in the case that the time interval of the two timing checks of the boot program exceeds the specific threshold value, it is determined that the function of the boot program is abnormal).

[0056] Still another first check data is used to detect whether the key function of the boot program is executed normally (i.e. the first execution times of the key function of the boot program), and the first check program is called to judge whether the function of the boot program is abnormal according to the counted execution times of the key function of the boot program; it can be understood that in the case that the boot program is normally running, the execution times of one or more key functions have specific values.

[0057] Further, in the embodiment of the present application, the first check strategy detection can further include calling the second check program (e.g. checker) to communicate with the upgrade software according to the first set time interval, and detecting whether the function of the boot program is abnormal according to the communication result. In the case that the communication result indicates that the communication is normal, it is determined that the function of the boot program is normal. The first set time interval can be set to 100 milliseconds, 1 second, 1 minute, etc., and the present application does not limit the value of the first set time interval.

[0058] That is, the first check strategy is used to detect whether the function of the boot program is abnormal, including: acquiring the first check data corresponding to the function of the boot program, and calling the first check program indicated by the first check strategy to detect whether the first check data is abnormal; wherein the first check data includes one or more of the first flow data indicating the function flow of the boot program, the first time interval data indicating the self-check period of the boot program, and the first execution times of the key function of the boot program; and / or calling the second check program indicated by the first check strategy to communicate with the boot program according to the first set time interval, and detecting whether the function of the boot program is abnormal according to the communication result.

[0059] Further, the first check strategy is used to detect whether the function of the boot program is abnormal, and for the case that the function is not abnormal, the upgrade software data of the vehicle controller software is acquired and the software upgrade operation is performed.

[0060] Further, for the case that the function of the boot program is abnormal, the backup boot program with normal function is acquired from the backup storage area, the backup boot program is replaced as the boot program, the upgrade software data of the vehicle controller software is acquired and the software upgrade operation is performed.

[0061] In the embodiment of the application, the backup storage area is arranged in the vehicle controller, and the backup boot program with normal function is stored in the backup storage area, for the case that the function of the boot program is abnormal, the backup boot program is directly used to replace the boot program with abnormal function, and the subsequent software upgrade operation is performed based on the replaced boot program (i.e. the backup boot program), the embodiment of the application overcomes the problem that the vehicle controller cannot perform the software upgrade due to the abnormal function of the boot program, and improves the refinement degree and reliability of the software upgrade of the vehicle controller.

[0062] 2) Detection of the function of the upgrade software.

[0063] Specifically, the second check strategy is used to detect whether the function of the boot program is abnormal.

[0064] Specifically, the second check data corresponding to the function of the upgrade software is acquired, and the third check program indicated by the second check strategy is used to detect whether the second check data is abnormal, specifically:

[0065] The second check data is used to detect whether the function of the upgrade software is normal (i.e. the second flow data indicating the function flow of the upgrade software), the check data includes each specific mark point of the flow execution of the upgrade software, and whether the upgrade software executes all the specific mark points and the execution order is correct is judged by calling the third check program, to judge whether the function of the upgrade software is abnormal.

[0066] Another second check data is used to detect whether the self-check period of the upgrade software is normal (i.e. the second time interval data indicating the self-check period of the upgrade software), the self-check period is arranged in the upgrade software, and whether the execution period is within the specific threshold value is checked by calling the third check program to judge whether the function of the upgrade software is abnormal (for example, the specific threshold value of the execution of the self-check is 200 milliseconds, and the case that the time interval of the two self-checks of the upgrade software exceeds the specific threshold value is judged as the case that the function of the upgrade software is abnormal).

[0067] The second check data is used to detect whether the key function of the upgraded software is executed normally (i.e., the second execution times of the key function of the upgraded software), and the third check program is called to determine whether the function of the upgraded software is abnormal according to the counted execution times of the key function of the upgraded software. It can be understood that, in the case that the upgraded software is normally running, the execution times of one or more key functions have a specific value.

[0068] Further, in the embodiment of the present application, the second check strategy detection can further include calling a second check program (e.g., checker) to communicate with the upgraded software according to a second set time interval, and detecting whether the function of the upgraded software is abnormal according to the communication result. In the case that the communication result indicates that the communication is normal, it is determined that the function of the upgraded software is normal. The second set time interval can be set to 100 milliseconds, 1 second, 1 minute, etc., and the present application does not limit the value of the second set time interval.

[0069] That is, the second check strategy is used to detect whether the function of the upgraded software is abnormal, which includes: obtaining the second check data corresponding to the function of the upgraded software, and calling the third check program indicated by the second check strategy to detect whether the second check data is abnormal; wherein the second check data includes one or more of the second flow data indicating the function flow of the upgraded software, the second time interval data indicating the self-checking period of the upgraded software, and the second execution times of the key function of the upgraded software; and / or calling the second check program indicated by the second check strategy to communicate with the upgraded software according to a second set time interval, and detecting whether the function of the upgraded software is abnormal according to the communication result.

[0070] Further, the second check strategy is used to detect whether the function of the upgraded software is abnormal, and in the case that the function is abnormal, the backup software with normal function is obtained from the backup storage area and replaces the upgraded software with abnormal function; if there is no abnormality, the multiple functions of the software are further executed.

[0071] In the embodiment of the present application, the backup storage area is arranged in the vehicle-mounted controller, and the backup software with normal function is stored in the backup storage area. In the case that the function of the upgraded software is abnormal, the backup software is directly used to replace the upgraded software with abnormal function, so that the software of the vehicle-mounted controller can continue to run. The embodiment of the present application overcomes the problem that the vehicle-mounted controller cannot run due to the abnormal function of the upgraded software, and improves the refinement degree and reliability of the software upgrade of the vehicle-mounted controller.

[0072] Figure 2 The main steps of another vehicle-mounted software upgrade method provided by the embodiment of the present application are shown in the following schematic diagram:

[0073] Step S201: Start software upgrade of the vehicle-mounted controller.

[0074] Step S202: Determine whether the boot program needs to be upgraded. If yes (Y), execute step S203, otherwise (N), execute step S205.

[0075] Step S203: Trigger the boot program to execute a self-upgrade step.

[0076] Step S204: Trigger the boot program to execute a data verification step.

[0077] Specifically, in the embodiment of the present application, before starting the boot program, it can be first determined whether the boot program has an updated version that needs to be upgraded. If yes, the boot program is triggered to execute a self-upgrade step and a data verification step. The degree of automatic control of the vehicle-mounted software upgrade is further improved.

[0078] Step S205: Start the boot program.

[0079] Step S206: Determine whether the function of the boot program has an abnormality. If yes (Y), execute step S207, otherwise (N), execute step S208.

[0080] Step S207: Obtain a backup boot program with normal function from a backup storage area, and replace the backup boot program with the boot program.

[0081] Specifically, in the embodiment of the present application, the boot program required for starting the software upgrade of the vehicle-mounted controller; the first verification strategy is used to detect whether the function of the boot program has an abnormality. In the case that the function of the boot program has an abnormality, a backup boot program with normal function is obtained from a backup storage area, and the backup boot program is replaced with the boot program. The upgrade software data of the vehicle-mounted controller software is obtained and the software upgrade operation is executed. In the case that the function of the boot program does not have an abnormality, the upgrade software data of the vehicle-mounted controller software is obtained and the software upgrade operation is executed.

[0082] Step S208: Determine whether to upgrade by using a specific strategy. If yes (Y), execute step S209, otherwise (N), execute step S210.

[0083] Step S209: Execute the software upgrade operation based on firmware.

[0084] Specifically, in an embodiment of the present invention, an upgrade strategy (i.e., a specific strategy) related to firmware (e.g., a chip) is provided, that is, after obtaining the upgrade software data of the vehicle-mounted controller software, it further includes: obtaining the upgrade strategy from the upgrade request of the vehicle-mounted controller software, and in the case where the upgrade strategy is a specific strategy related to the firmware of the vehicle-mounted controller, obtaining firmware data related to the specific strategy for the firmware, detecting whether the firmware data meets the specific strategy, and if so, performing the software upgrade operation based on the firmware.

[0085] In an embodiment of the present invention, when it is determined that the software is upgraded using a specific strategy related to the firmware (for example, a reserved channel upgrade strategy), one or more firmware data is detected to see whether they meet the specific strategy, for example: reading the level combination of 5 specific pins of the chip (i.e., firmware data) to see whether it meets the "high-low-high-low-high" standard; reading the absolute clock of the chip (i.e., firmware data) to see whether it is within a specific time period; reading chip-specific files (i.e., firmware data, such as fingerprint files, key files, etc.) to see whether they contain specific instructions; when it is detected that the firmware data meets the specific strategy, executing the software upgrade operation steps based on the firmware; otherwise, directly executing the software upgrade steps of step S210.

[0086] The embodiment of the present invention provides a reserved channel for software upgrades for professional authorized personnel by providing specific firmware-related policies and detecting firmware data, thereby further improving the reliability and refined management of software upgrades.

[0087] Step S210: executing a software upgrade step for the mirror partition.

[0088] Step S211: Data verification of the upgraded software.

[0089] Specifically, in an embodiment of the present invention, a mirrored partitioning software upgrade method is used to perform a vehicle controller software upgrade. This ensures that the software upgrade process does not affect the functionality of the current software (non-upgraded software) running in the vehicle controller, thereby improving the user experience. Specifically, the vehicle controller is divided into multiple relatively independent storage partitions, and the specific software contained in two specific storage partitions is mirrored and does not affect each other.

[0090] Furthermore, determine the first storage partition to which the currently running software of the vehicle controller belongs; after receiving an upgrade request for the vehicle controller software, download the upgrade software data indicated by the upgrade request, and write the upgrade software data into the second storage partition, wherein the second storage partition stores the software to be upgraded that is a mirror image of the currently running software, and perform the software upgrade operation on the software to be upgraded.

[0091] Further, before performing the software upgrade according to the upgrade software data, data verification (for example, data integrity, security, etc.) can be performed on the upgrade software data, and after the software upgrade, data verification (for example, data integrity, security, etc.) can be performed on the upgraded software data. The safety and reliability of the software of the vehicle-mounted controller are improved.

[0092] Step S212: Start the upgraded software of the mirror partition.

[0093] Specifically, in the embodiment of the present application, when the vehicle-mounted controller is restarted, the upgraded software in the mirror partition is started, that is, the upgraded software after the upgrade is started, which comprises: when the vehicle-mounted controller is restarted, the upgraded software in the second storage partition is started as the software currently running on the vehicle-mounted controller; and / or the vehicle-mounted software upgrade method further comprises: after the software currently running on the vehicle-mounted controller is switched to the software of the second storage partition, the software contained in the first storage partition is synchronously upgraded to the upgrade software. It can be understood that the vehicle-mounted controller software of the first storage partition and the second storage partition are mirror images of each other, when the software of the vehicle-mounted controller runs in one of the storage partitions (that is, the first storage partition), the software in the other storage partition (that is, the second storage partition) is upgraded, and after the restart, the upgraded software of the other storage partition (that is, the second storage partition) is automatically started, and the software in the storage partition (the first storage partition) that is not upgraded is synchronously upgraded; so that in the next software upgrade cycle, similar upgrade operations are correspondingly performed.

[0094] Step S213: Detect whether the function of the upgraded upgrade software is abnormal, if it is abnormal (Y), perform step S214, otherwise (N) perform step S215.

[0095] Step S214: Obtain the backup software with normal function from the backup storage area and replace the upgrade software with abnormal function.

[0096] Specifically, for the case that the function of the upgraded upgrade software is abnormal, the backup software with normal function is obtained from the backup storage area and replaces the upgrade software with abnormal function.

[0097] Step S215: Report the upgrade process details for the software upgrade.

[0098] Specifically, in the embodiment of the present application, the detailed information of the software upgrade process and related detection data can be recorded, and the detailed information is reported to the vehicle-mounted client or server, so as to further monitor the software upgrade situation of multiple vehicle-mounted controllers and analyze the software upgrade data of multiple vehicle-mounted controllers.

[0099] Step S216: End.

[0100] Figure 3 FIG. 1 is a structural diagram of a vehicle software upgrade method according to an embodiment of the present invention; FIG. Figure 3 As shown, it includes: a first core processor C1, a second core processor C2, and a backup storage area S; a boot program Boot, software to be upgraded APP-1, and upgrade software APP-2 running on the first core processor C1; and a check program Checker running on the second core processor C2. Specifically, the vehicle controller includes multiple core processors; the boot program and upgrade software are run on the first core processor among the multiple core processors; and the second check program is run on the second core processor among the multiple core processors. The various software (or programs) running on the first core processor C1 can be upgraded; the various backup software (or backup programs) stored in the backup storage area S cannot be changed.

[0101] Furthermore, the boot program Boot is stored in the boot area B, the software to be upgraded APP-1 is stored in the first storage partition A1, and the upgraded software APP-2 is stored in the second storage partition A2.

[0102] Furthermore, the backup boot program Boot-B is stored in the backup storage area S, and the backup software App-B is stored in the backup storage area S.

[0103] like Figure 3 As shown, the second check program (Checker) indicated by the first check strategy is called to communicate with the boot program (Boot) according to the first set time interval, and whether there is any abnormality in the function of the boot program is detected according to the communication result.

[0104] The second checker indicated by the second check strategy is called to communicate with the upgrade software (APP-2) at a second set time interval, and detects whether the upgrade software functions abnormally based on the communication results. The second checker can also be called to communicate with the software to be upgraded (APP-1) at a third set time interval, and detect whether the software functions abnormally based on the communication results. The values ​​of the first set time interval, the second set time interval, and the third set time interval can be the same or different depending on the actual scenario.

[0105] Further, in case that the function of the boot program is abnormal, the backup boot program (Boot-B) with normal function is obtained from the backup storage area S and is replaced with the boot program; in case that the upgraded software (APP-2) after the start of the upgrade is abnormal, the backup software (App-B) with normal function is obtained from the backup storage area S and is replaced with the abnormal upgraded software; in case that the software (APP-1) is abnormal, the backup software (App-B) with normal function can also be obtained from the backup storage area S and is replaced with the abnormal software.

[0106] The embodiment of the present application detects whether the function of the boot program and / or the upgraded software is abnormal through the communication between the checker and the boot program and / or the upgraded software, and improves the stability and reliability of the detection of the function of the boot program and / or the upgraded software; further, the backup software (backup boot program, backup software) with unchangeable normal function stored in the backup storage area is used to replace (restore) the abnormal program or software, which overcomes the problem in the prior art that the vehicle-mounted controller cannot be repaired by re-flashing the upgraded software in case that the vehicle-mounted controller cannot normally operate, and improves the experience of the passengers in using the vehicle.

[0107] Figure 4 A structure diagram of the vehicle-mounted software upgrade device 400 to which the embodiment of the present application can be applied is shown. It comprises:

[0108] The start module 401 is used to start the boot program required by the upgrade of the software of the vehicle-mounted controller in response to the reception of the upgrade request for the software of the vehicle-mounted controller.

[0109] The first detection module 402 is used to detect whether the function of the boot program is abnormal by using the first checking strategy, and in case that there is no abnormality, the upgraded software data of the software of the vehicle-mounted controller is obtained and the software upgrade operation is performed.

[0110] The second detection module 403 is used to start the upgraded software after the upgrade, detect whether the function of the upgraded software is abnormal by using the second checking strategy, and in case that there is abnormality, the backup software with normal function is obtained from the backup storage area and is replaced with the abnormal upgraded software.

[0111] The following refers to Figure 5 A structure diagram of the computer system 500 suitable for being used to implement the embodiment of the present application is shown. Figure 5 The shown computer system is only an example and should not bring any limitation to the function and use range of the embodiment of the present application.

[0112] As Figure 5As shown, the computer system 500 includes a central processing unit (CPU) 501 which can perform various appropriate actions and processes according to programs stored in a read only memory (ROM) 502 or loaded into a random access memory (RAM) 503 from a storage section 508. In the RAM 503, various programs and data required for the operation of the system 500 are also stored. The CPU 501, the ROM 502, and the RAM 503 are connected to each other through a bus 504. An input / output (I / O) interface 505 is also connected to the bus 504.

[0113] Connected to the I / O interface 505 are: an input section 506 including input devices such as a keyboard, a mouse, and a microphone; an output section 507 including output devices such as a cathode ray tube (CRT), a liquid crystal display (LCD), and a speaker; a storage section 508 including storage devices such as a hard disk; and a communication section 509 including communication devices such as a LAN card, a modem, and the like. The communication section 509 performs communication processing via a network such as the Internet. A drive 510 is also connected to the I / O interface 505 as necessary. A removable recording medium 511, such as a magnetic disk, an optical disc, a magneto-optical disc, a semiconductor memory, and the like, is attached to the drive 510 as necessary, so that a computer program read therefrom is installed into the storage section 508 as necessary.

[0114] In particular, the processes described above with reference to the flowcharts can be implemented as a computer software program according to embodiments of the present disclosure. For example, embodiments of the present disclosure include a computer program product comprising a computer program carried on a computer readable medium, the computer program comprising program code for performing the methods illustrated by the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via the communication section 509, and / or installed from the removable recording medium 511. When the computer program is executed by the central processing unit (CPU) 501, the above-described functions defined in the system of the present disclosure are performed.

[0115] It should be noted that the computer-readable medium shown in the present application can be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium may, for example, but is not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or component, or any combination of the above. More specific examples of computer-readable storage media can include, but are not limited to, an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, the computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device or component. In the present application, the computer-readable signal medium can include a data signal carried in a baseband or as a part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to an electromagnetic signal, an optical signal or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, which can send, propagate or transmit a program for use by or in conjunction with an instruction execution system, device or component. The program code contained on the computer-readable medium can be transmitted by any suitable medium, including but not limited to wireless, wire, optical cable, RF, etc., or any suitable combination of the above.

[0116] The flowcharts and block diagrams in the drawings illustrate the possible implementation architectures, functions and operations of the systems, methods and computer program products according to various embodiments of the present application. In this regard, each block in the flowcharts or block diagrams can represent a module, a program segment or a part of code containing one or more executable instructions for implementing the specified logical functions. It should also be noted that in some alternative implementations, the functions noted in the blocks can occur in different order than that shown in the drawings. For example, two blocks that are shown in succession can actually be executed substantially in parallel, and sometimes in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams or flowcharts, and the combination of blocks in the block diagrams or flowcharts, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0117] As another aspect, the application further provides a computer readable medium, which can be included in the device described in the above embodiments, or can exist independently without being assembled into the device. The computer readable medium carries one or more programs, which, when executed by the device, cause the device to include: in response to receiving an upgrade request for the vehicle-mounted controller software, starting a boot program required for the vehicle-mounted controller software upgrade; detecting whether the function of the boot program is abnormal by using a first verification strategy, and in the case of no abnormality, obtaining upgrade software data of the vehicle-mounted controller software and performing a software upgrade operation; starting the upgrade software after the upgrade is completed, detecting whether the function of the upgrade software is abnormal by using a second verification strategy; and in the case of abnormality, obtaining backup software with normal function from a backup storage area and replacing the abnormal upgrade software.

[0118] It should be understood by those skilled in the art that various modifications, combinations, sub-combinations, and substitutions can be made depending on design requirements and other factors. Any modification, equivalent replacement, and improvement within the spirit and principle of the application should be included in the protection scope of the application.

Claims

1. A vehicle software upgrade method, characterized in that: Applied to vehicle controllers, including: In response to receiving an upgrade request for the on-board controller software, starting a boot program required for upgrading the on-board controller software; Using a first verification strategy to detect whether there is an abnormality in the function of the boot program, if no abnormality exists, obtaining upgrade software data of the vehicle controller software and performing a software upgrade operation; The upgraded software is started after the upgrade is completed, and the second verification strategy is used to detect whether there is any abnormality in the function of the upgraded software; if there is an abnormality, the backup software with normal function is obtained from the backup storage area and replaced with the upgraded software with the abnormality.

2. The vehicle software upgrade method according to claim 1, characterized in that: Further including: In case that the function of the boot program is abnormal, a backup boot program with normal function is obtained from the backup storage area, the backup boot program is replaced with the boot program, and the upgrade software data of the vehicle controller software is further obtained and a software upgrade operation is performed.

3. The vehicle software upgrade method according to claim 1, characterized in that: The detecting whether there is an abnormality in the function of the boot program by using the first verification strategy includes: Obtaining first verification data corresponding to a function of the boot program, and calling a first verification program indicated by the first verification strategy to detect whether the first verification data has an abnormality; wherein the first verification data includes one or more of: first process data indicating a functional process of the boot program, first time interval data indicating a self-check period of the boot program, and a first execution count of a key function of the boot program; and / or, The second verification program indicated by the first verification strategy is called to communicate with the boot program at a first set time interval, and whether there is any abnormality in the function of the boot program is detected according to the communication result.

4. The vehicle software upgrade method according to claim 1, characterized in that: The detecting whether there is an abnormality in the function of the upgraded software by using the second verification strategy includes: Obtaining second verification data corresponding to the function of the upgrade software, and calling a third verification program indicated by the second verification strategy to detect whether the second verification data has an abnormality; wherein the second verification data includes: second process data indicating the functional process of the upgrade software, second time interval data indicating the self-check period of the upgrade software, and one or more of a second execution count of a key function of the upgrade software; and / or, The second verification program indicated by the second verification strategy is called to communicate with the upgrade software at a second set time interval, and whether there is any abnormality in the function of the upgrade software is detected based on the communication result.

5. The vehicle software upgrade method according to claim 3 or 4, characterized in that: The on-board controller includes multiple core processors; A first core processor among the plurality of core processors is used to run the boot program and the upgrade software; and a second core processor among the plurality of core processors is used to run the second verification program.

6. The vehicle software upgrade method according to claim 1 or 2, characterized in that: After obtaining the upgrade software data of the vehicle controller software, the method further includes: Obtaining an upgrade strategy from an upgrade request of the vehicle controller software; In the case where the upgrade strategy is a specific strategy related to the firmware of the vehicle controller, The steps of obtaining firmware data related to the specific policy for the firmware, detecting whether the firmware data satisfies the specific policy, and if so, performing a software upgrade operation based on the firmware.

7. The vehicle software upgrade method according to claim 1, characterized in that: The vehicle controller is divided into a plurality of relatively independent storage partitions, and the specific software included in two specific storage partitions are in a mirror relationship and do not affect each other; The vehicle software upgrade method further comprises: Determine the first storage partition to which the currently running software of the vehicle-mounted controller belongs; After receiving an upgrade request for the vehicle controller software, downloading the upgrade software data indicated by the upgrade request and writing the upgrade software data into a second storage partition, wherein the second storage partition stores the software to be upgraded that is a mirror image of the currently running software; The step of performing a software upgrade operation on the software to be upgraded.

8. The vehicle software upgrade method according to claim 7, characterized in that: The upgrade software after the startup upgrade is completed includes: When it is detected that the vehicle controller is restarted, starting the upgraded software in the second storage partition as the software currently running on the vehicle controller; and / or, The vehicle software upgrade method further includes: after the currently running software of the vehicle controller is switched to the software of the second storage partition, the software contained in the first storage partition is synchronously upgraded to the upgraded software.

9. A vehicle software upgrade device, characterized in that: Applied to vehicle controllers, including: a starting module, configured to start a boot program required for upgrading the on-board controller software in response to receiving an upgrade request for the on-board controller software; a first detection module, configured to detect whether there is an abnormality in the function of the boot program using a first verification strategy, and if no abnormality exists, obtain upgrade software data of the vehicle controller software and perform a software upgrade operation; The second detection module is used to start the upgrade software after the upgrade is completed, and use the second verification strategy to detect whether there is any abnormality in the function of the upgrade software; if there is an abnormality, obtain the backup software with normal function from the backup storage area and replace the upgrade software with the abnormality.

10. An electronic device for upgrading vehicle software, characterized in that: The electronic device comprises: one or more processors; a storage device for storing one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 8.