Updating method and device of vehicle-mounted controller, equipment, storage medium and vehicle
By encrypting and testing the upgrade package of the vehicle controller, generating a test package and verifying it, the information security problem of the vehicle controller during the software update process is solved, the authenticity and integrity of the upgrade package are verified, and the risk of malicious attacks is reduced.
Patent Information
- Application Number
- CN202511055584.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-30
- Publication Date
- 2025-11-11
AI Technical Summary
In the era of software-defined vehicles, frequent updates to the software system of vehicle controllers increase the risk of sensitive information leakage and malicious attacks. A method is needed to verify the authenticity and integrity of upgrade packages to ensure information security.
By encrypting the identity of the upgrade package, a test package is generated, and the vehicle controller is tested according to the expected feedback and the timing of the feedback, ensuring the reliability of the upgrade package's verification mechanism. Updates are only performed when the test is passed.
This enhances the information security of the vehicle controller during the update process, ensures the authenticity and integrity of the upgrade package, and reduces the risk of sensitive information leakage and malicious attacks.
Smart Images

Figure CN120930144A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of vehicle control technology, and in particular to a method, apparatus, device, storage medium, and vehicle for updating an on-board controller. Background Technology
[0002] In the era of software-defined vehicles, timely updates to the software system in the vehicle controller are crucial for fully realizing the vehicle's functions and value. However, frequent software updates also increase the risk of leakage of sensitive information in the vehicle controller and malicious attacks.
[0003] Against this backdrop, relevant regulations and industry standards require that when upgrading the software system of an on-board controller through a diagnostic tool or other terminal equipment, the on-board controller must have a certain verification capability to verify the authenticity and completeness of the upgrade package obtained during the upgrade process.
[0004] Therefore, there is an urgent need for a method to update vehicle controllers that can prevent malicious attacks during software system upgrades and ensure the information security of vehicle controllers. Summary of the Invention
[0005] This application provides a method, apparatus, device, storage medium, and vehicle for updating an on-board controller to solve the technical problems existing in the related art. Specifically, it includes the following technical solutions.
[0006] In a first aspect, this application provides a method for updating an in-vehicle controller, the method comprising: generating a test package based on an upgrade package of the in-vehicle controller and a verification file of the upgrade package, wherein the upgrade package is used to update the in-vehicle controller, and the verification file is an encrypted file obtained by encrypting a first identity identifier of the upgrade package; determining the expected feedback corresponding to the test package and a first feedback timing of the expected feedback; testing the in-vehicle controller based on the test package, the expected feedback, and the first feedback timing; and updating the in-vehicle controller based on the upgrade package and the verification file if the test result of the in-vehicle controller after testing is qualified.
[0007] In some possible implementations, generating a test package based on the upgrade package of the vehicle controller and the verification file of the upgrade package includes: tampering with the upgrade package or the verification file; generating the test package based on the tampered upgrade package and the verification file; or, generating the test package based on the tampered verification file and the upgrade package.
[0008] In some possible implementation manners, tampering with the upgrade package or the verification file includes: tampering with the upgrade package or the verification file through one tampering operation among data replacement, data deletion, and data addition.
[0009] In some possible implementation manners, testing the vehicle-mounted controller according to the test package, the expected feedback, and the expected feedback timing includes: obtaining the actual feedback of the vehicle-mounted controller on the test package and the second feedback timing of the actual feedback; if the actual feedback is the same as the expected feedback and the second feedback timing is the same as the first feedback timing, the test result is qualified.
[0010] In some possible implementation manners, testing the vehicle-mounted controller according to the test package, the expected feedback, and the expected feedback timing includes: obtaining the actual feedback of the vehicle-mounted controller on the test package and the second feedback timing of the actual feedback; if the actual feedback is not the same as the expected feedback, or the second feedback timing is not the same as the first feedback timing, the test result is unqualified; the method further includes: terminating the update operation of the vehicle-mounted controller when the test result is unqualified.
[0011] In some possible implementation manners, updating the vehicle-mounted controller according to the upgrade package and the verification file includes: decrypting the verification file and obtaining the first identity identifier according to the decrypted verification file; determining the second identity identifier of the upgrade package according to a preset calculation method; if the first identity identifier is the same as the second identity identifier, updating the vehicle-mounted controller according to the upgrade package.
[0012] In a second aspect, the present application provides an update device for a vehicle-mounted controller. The device includes a tampering module, a determination module, a testing module, and an update module; the tampering module is configured to generate a test package according to an upgrade package of the vehicle-mounted controller and a verification file of the upgrade package, the upgrade package is used to update the vehicle-mounted controller, and the verification file is an encrypted file obtained by encrypting the first identity identifier of the upgrade package; the determination module is configured to determine the first expected feedback corresponding to the test package and the first feedback timing of the expected feedback; the testing module is configured to test the vehicle-mounted controller according to the test package, the expected feedback, and the first feedback timing; the update module is configured to update the vehicle-mounted controller according to the upgrade package and the verification file when the test result after testing the vehicle-mounted controller is qualified.
[0013] In some possible implementations, when the tampering module generates a test package based on the upgrade package of the vehicle controller and the verification file of the upgrade package, it is configured to: tamper with the upgrade package or the verification file; generate the test package based on the tampered upgrade package and the verification file; or generate the test package based on the tampered verification file and the upgrade package.
[0014] In some possible implementations, when the tampering module tampers with the upgrade package or the verification file, it is configured to tamper with the upgrade package or the verification file by means of one of the following tampering operations: data replacement, data deletion, and data addition.
[0015] In some possible implementations, when the testing module tests the vehicle controller based on the test package, the expected feedback, and the expected feedback timing, it is configured to: obtain the actual feedback from the vehicle controller to the test package and the second feedback timing of the actual feedback; if the actual feedback and the expected feedback are the same, and the second feedback timing is the same as the first feedback timing, then the test result is a qualified test.
[0016] In some possible implementations, the testing module, when testing the vehicle controller according to the test package, the expected feedback, and the expected feedback timing, is configured to: obtain the actual feedback from the vehicle controller to the test package and the second feedback timing of the actual feedback; if the actual feedback and the expected feedback are different, or the second feedback timing is different from the first feedback timing, then the test result is a test failure; the updating module is further configured to: terminate the update operation of the vehicle controller if the test result is a test failure.
[0017] In some possible implementations, when the update module updates the vehicle controller according to the upgrade package and the verification file, it is configured to: decrypt the verification file and obtain the first identity identifier according to the decrypted verification file; determine the second identity identifier of the upgrade package according to a preset calculation method; and update the vehicle controller according to the upgrade package if the first identity identifier and the second identity identifier are the same.
[0018] Thirdly, this application provides an electronic device for updating an on-board controller, comprising: a memory storing at least one program instruction for updating the on-board controller; and a processor, wherein when the program instruction is executed by the processor, the vehicle implements the method of this application or any possible implementation thereof.
[0019] Fourthly, this application provides a computer program (product) including computer program / instructions, which are executed by a processor to cause a vehicle to implement the method in any possible implementation of this application.
[0020] Fifthly, this application provides a computer-readable storage medium having stored thereon program instructions for updating an onboard controller, which, when executed by one or more processors, cause the vehicle to implement the methods of any possible implementation of this application or any of its aspects.
[0021] In a sixth aspect, this application provides a vehicle that includes the apparatus described in the second aspect of this application or any possible embodiment of the second aspect.
[0022] The beneficial effects of the technical solution provided in this application include at least the following:
[0023] The technical solution provided in this application, on the one hand, encrypts the primary identifier of the upgrade package, enabling the vehicle controller to verify the upgrade package using a verification file after obtaining it, detecting whether the upgrade package has been tampered with, and ensuring the authenticity and integrity of the upgrade package. On the other hand, before verifying the upgrade package, a test package can be generated based on the upgrade package and the verification file to test the reliability of the vehicle controller's verification mechanism for the upgrade package. This ensures that the vehicle controller is updated only if its verification mechanism is secure and reliable, i.e., if the test result is satisfactory. This further enhances the information security of the vehicle controller during the update process. Attached Figure Description
[0024] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0025] Figure 1 This is a schematic diagram of an implementation scenario provided in the embodiments of this application;
[0026] Figure 2 This is a flowchart of the vehicle controller update method provided in the embodiments of this application;
[0027] Figure 3 This is a schematic diagram of the structure of the vehicle controller update device provided in the embodiments of this application;
[0028] Figure 4This is a schematic diagram of the structure of an electronic device for updating a vehicle controller provided in an embodiment of this application. Detailed Implementation
[0029] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0030] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0031] Figure 1 This is a schematic diagram of an implementation scenario provided in an embodiment of this application. (Reference) Figure 1 The implementation scenario provided in this application embodiment may include server 11 and vehicle 12.
[0032] Server 11 can be used, but is not limited to, generating, storing, distributing, and managing upgrade packages and verification files for software systems in the vehicle controller.
[0033] Vehicle 12 is equipped with an on-board controller. The on-board controller can obtain upgrade packages and verification files from server 11 through OTA (over-the-air) technology, and test the on-board controller based on the test package generated by the upgrade package and verification file to ensure the reliability of the verification mechanism of the upgrade package in the on-board controller. This ensures that the on-board controller can be updated through the upgrade package and verification file if the test result is qualified.
[0034] Optionally, server 11 can be a single server, a server cluster consisting of multiple servers, or a cloud computing service center. The on-board controller installed in vehicle 12 can be an EMS (engine management system), an MCU (motor control unit), or a CDC (cockpit domain controller), etc., and this application does not impose any restrictions in this regard.
[0035] Those skilled in the art should understand that the above-described server 11 and vehicle 12 are merely examples, and other existing or future servers and vehicles that are applicable to this application should also be included within the scope of protection of this application, and are hereby incorporated by reference.
[0036] Figure 2 This is a flowchart of an on-board controller update method provided in an embodiment of this application. This method can, for example, be... Figure 1 The application makes no restrictions on the execution of the on-board controller installed in the vehicles involved. See also Figure 2 The vehicle controller update method provided in this application embodiment may include steps S210-S240.
[0037] Step S210: Generate a test package based on the upgrade package and the verification file of the vehicle controller. The upgrade package is used to update the vehicle controller, and the verification file is an encrypted file obtained by encrypting the first identity of the upgrade package.
[0038] Optionally, the verification file for the upgrade package is an encrypted file obtained by encrypting the first identity identifier of the upgrade package. This can be used, but is not limited to, verifying the authenticity and integrity of the upgrade package. The first identity identifier of the upgrade package may be, for example, a hash value calculated based on the upgrade package. The verification file may be, for example, an encrypted file obtained by encrypting the first identity identifier using asymmetric algorithms such as RSA (Rivers-Shamir-Adleman), ECDSA (Elliptic Curve Digital Signature Algorithm), or DSA (Digital Signature Algorithm). The encryption method for the first identity identifier can also be any other type of encryption method; this application does not impose any restrictions in this regard.
[0039] In some embodiments, the upgrade package for the vehicle controller is centrally managed by the vehicle manufacturer and distributed to users who need to update their vehicle controllers. This reduces the risk of malicious tampering with the upgrade package and ensures its reliability. In this case, the transmission path of the vehicle controller upgrade package is, for example, as follows: the software vendor generates the upgrade package and sends it to the vehicle manufacturer; the vehicle manufacturer centrally manages the upgrade package, for example, by determining a first identifier for the upgrade package and encrypting the first identifier to generate a verification file. This allows the vehicle controller to verify the upgrade package upon receipt based on the verification file, confirming whether the upgrade package has been tampered with.
[0040] Vehicle manufacturers' methods for unified management of upgrade packages include, for example, encapsulating the upgrade packages to further reduce the risk of malicious tampering with the vehicle controller's upgrade packages and enhance the privacy and reliability of the upgrade packages. Encapsulation refers to the technique of packaging upgrade package-related data and operations to hide internal implementation details and provide a concise interface for external access to internal data.
[0041] The vehicle controller can be any type of controller installed in a vehicle, such as an EMS, MCU, or CDC. An upgrade package for the vehicle controller is, for example, a data package used to update the software system of the vehicle controller. The software system refers to a collection of programs and data that provide complete business capabilities for the vehicle or a specific functional domain of the vehicle, including but not limited to the application programs, firmware, operating system, and configuration files within the vehicle controller.
[0042] In some possible cases, the upgrade package for the vehicle controller may be a firmware upgrade package for upgrading the firmware in the vehicle controller, an operating system upgrade package for upgrading the operating system of the vehicle controller, an application upgrade package for upgrading the application of the vehicle controller, or a configuration file upgrade package for upgrading the configuration files such as system configuration, network configuration, calibration parameters, and security policies of the vehicle controller. This application does not impose any restrictions in this regard.
[0043] For example, the test package is any type of data packet generated based on the upgrade package and verification file, used to test the reliability of the vehicle controller's verification mechanism for the upgrade package. The vehicle controller's verification mechanism for the upgrade package is used to indicate a mechanism, implemented in software or hardware, within the vehicle controller to verify whether the upgrade package received by the vehicle controller has been tampered with.
[0044] For example, when the first identifier is the hash value of the upgrade package, the verification mechanism for the upgrade package by the vehicle controller can be: comparing the first hash value obtained after decrypting the verification file with the second hash value calculated from the hash value of the upgrade package received by the vehicle controller to determine whether the upgrade package received by the vehicle controller has been tampered with, or any other type of verification mechanism that can determine whether the upgrade package received by the vehicle controller has been tampered with. This application makes no restrictions in this regard. The first hash value, for example, is calculated by the vehicle manufacturer before the upgrade package is distributed.
[0045] In some embodiments, a method for generating a test package based on an upgrade package and a verification file of an onboard controller includes: tampering with the upgrade package or verification file; generating a test package based on the tampered upgrade package and verification file; or generating a test package based on the tampered verification file and upgrade package. The tampering operation of the upgrade package or verification file may include, for example, tampering with the upgrade package or verification file through one of the following tampering operations: data replacement, data deletion, and data addition. In this case, depending on the degree of tampering and the tampering operation performed on the upgrade package or verification file, the test package may include multiple packages.
[0046] For example, after the upgrade package is tampered with, a first test package is generated based on the verification file and the tampered upgrade package. The first test package further includes at least one of the following: a first replacement test package corresponding to data replacement of the upgrade package, a first deletion test package corresponding to data deletion of the upgrade package, or a first addition test package corresponding to data addition of the upgrade package.
[0047] Alternatively, after tampering with the verification file, a second test package is generated based on the upgrade package and the tampered verification file. The second test package further includes at least one of the following: a second replacement test package corresponding to data replacement in the verification file, a second deletion test package corresponding to data deletion in the verification file, or a second addition test package corresponding to data addition in the verification file.
[0048] Among them, data replacement is used to indicate the operation of replacing some or all of the data in the upgrade package or verification file with other data, data deletion is used to indicate the operation of deleting some or all of the data from the upgrade package or verification file, and data addition is used to indicate the operation of adding additional data to the upgrade package or verification file.
[0049] Step S220: Determine the expected feedback corresponding to the test package and the timing of the first feedback of the expected feedback.
[0050] For example, the expected feedback is, for instance, feedback information from the onboard controller to the test package predefined in the test package. This can be used, but is not limited to, verifying whether the onboard controller can correctly detect tampering in the upgrade package or verification file and respond correctly. The first feedback timing is, for instance, the moment or time period during which the onboard controller responds to the feedback information. This is used, but is not limited to, verifying whether the onboard controller's response to the test package is timely. For example, if the onboard controller can respond to the corresponding expected feedback within the moment or time period indicated by the first feedback timing after receiving the test package, it indicates that the onboard controller can detect tampering in the upgrade package or verification file in a timely manner, meaning that the onboard controller's verification mechanism for the upgrade package is highly reliable.
[0051] As mentioned earlier, test packages can include multiple packages depending on the degree of tampering and the type of tampering performed on the upgrade package or verification file. In this case, different expected feedbacks can be set for different test packages, and different first feedback times can be set for different expected feedbacks, so as to distinguish different tamperings in the upgrade package or verification file.
[0052] For example, if the test package includes a first replacement test package, a first deletion test package, and a first addition test package obtained by tampering with the upgrade package, and a second replacement test package, a second deletion test package, and a second addition test package obtained by tampering with the verification file, the expected feedback may include a first expected feedback corresponding to the first replacement test package, a second expected feedback corresponding to the first deletion test package, a third expected feedback corresponding to the first addition test package, a fourth expected feedback corresponding to the second replacement test package, a fifth expected feedback corresponding to the second deletion test package, and a sixth expected feedback corresponding to the second addition test package.
[0053] In some embodiments, the expected feedback timing is, for example, after the vehicle controller detects tampering in the upgrade package and before the vehicle controller is updated using the upgrade package, in order to reduce the risk of leakage of sensitive information in the vehicle controller or malicious attack on the vehicle controller caused by tampering in the upgrade package or verification file.
[0054] When the test package includes multiple different types of test packages, such as a first replacement test package, a first deletion test package, a first addition test package, a second replacement test package, a second deletion test package, and a second addition test package, a unique identifier can be assigned to each test package. This allows the vehicle controller or other devices communicating with and testing the vehicle controller to distinguish between the multiple different types of test packages based on the identifier. In this case, the expected feedback corresponding to the test package includes, for example, identification information indicating the identifier of the test package and feedback information predefined according to the test package. This allows the vehicle controller or other devices communicating with and testing the vehicle controller to associate the expected feedback with one of the multiple different types of test packages based on the identification information in the expected feedback.
[0055] Step S230: Test the vehicle controller according to the test package, expected feedback and the timing of the first feedback.
[0056] As described above, the expected feedback can be used to detect whether the vehicle-mounted controller can detect tampering in the upgrade package or verification file and respond correctly, and the first feedback timing can be used to verify the timeliness of the vehicle-mounted controller's response to the test package. In view of this, embodiments of the present application can test the reliability of the verification mechanism of the vehicle-mounted controller for the upgrade package according to the response of the vehicle-mounted controller to the test package and whether the timing of the response meets the expectation.
[0057] Exemplarily, testing the vehicle-mounted controller according to the test package, expected feedback, and expected feedback timing, for example, includes: obtaining the actual feedback of the vehicle-mounted controller to the test package and the second feedback timing of the actual feedback; if the actual feedback is the same as the expected feedback, and the second feedback timing is the same as the first feedback timing, the test result is qualified. Among them, the actual feedback of the vehicle-mounted controller to the test package is, for example, the feedback operation made by the vehicle-mounted controller after receiving the test package, such as any type of feedback information generated according to the test package, or no feedback to the test package, that is, no feedback information. When the actual feedback is the feedback information generated by the vehicle-mounted controller according to the test package, the second feedback timing is, for example, the generation timing of the feedback information; when the vehicle-mounted controller does not give feedback on the test, the second feedback timing is, for example, blank information.
[0058] In the above method, if the actual feedback of the vehicle-mounted controller to the test package is the same as the expected feedback, it means that the vehicle-mounted controller correctly responds to the tampering in the upgrade package or verification file, that is, it can detect the tampering in the upgrade package or verification file. If the second feedback timing of the actual feedback is the same as the first feedback timing of the expected feedback, it means that the response of the vehicle-mounted controller to the tampering in the upgrade package or verification file is timely. In this case, the test result of the vehicle-mounted controller is qualified, indicating that the verification mechanism of the vehicle-mounted controller for the upgrade package is safe and reliable.
[0059] If the actual feedback is different from the expected feedback, or the first feedback timing and the second feedback timing are different, it means that the vehicle-mounted controller may not be able to detect the tampering in the upgrade package or verification file, or the response to the tampering in the upgrade package or verification file is not timely, extending the risk window of sensitive information leakage in the vehicle-mounted controller and the risk of the vehicle-mounted controller being maliciously attacked. In this case, the test result of the vehicle-mounted controller is unqualified, indicating that there may be loopholes in the verification mechanism of the vehicle-mounted controller for the upgrade package.
[0060] Step S240, when the test result of testing the vehicle-mounted controller is qualified, update the vehicle-mounted controller according to the upgrade package and verification file.
[0061] As mentioned earlier, a passing test result for the on-board controller indicates that its verification mechanism for the upgrade package is secure and reliable, and can promptly and correctly respond to any tampering in the upgrade package or verification file. Therefore, provided the on-board controller's verification mechanism for the upgrade package is secure and reliable, the upgrade package and verification file can be obtained, allowing the on-board controller to be updated based on these documents.
[0062] In some embodiments, the method for updating the vehicle controller based on the upgrade package and the verification file includes, for example,: decrypting the verification file and obtaining a first identity identifier based on the decrypted verification file; determining a second identity identifier for the upgrade package; and updating the vehicle controller based on the upgrade package if the first identity identifier and the second identity identifier are the same. The first identity identifier is, for example, a first hash value calculated by the vehicle manufacturer before the upgrade package is distributed, and the second identity identifier is, for example, a second hash value calculated by the vehicle controller after receiving the upgrade package.
[0063] When the test result of the vehicle controller is unsuccessful, it indicates that there is a vulnerability in the vehicle controller's verification mechanism for the upgrade package. In this case, to reduce the risk of leakage of sensitive information in the vehicle controller or malicious attacks on the vehicle controller, the update operation can be terminated. For example, the vehicle controller update method provided in this application embodiment further includes: obtaining the actual feedback of the vehicle controller to the test package and the second feedback timing of the actual feedback; if the actual feedback is different from the expected feedback, or the second feedback timing is different from the first feedback timing, the test result is unsuccessful; in the case of a test result of unsuccessful, the update operation of the vehicle controller is terminated.
[0064] The technical solution provided in this application, on the one hand, encrypts the primary identifier of the upgrade package, enabling the vehicle controller to verify the upgrade package using a verification file after obtaining it, detecting whether the upgrade package has been tampered with, and ensuring the authenticity and integrity of the upgrade package. On the other hand, before verifying the upgrade package, a test package can be generated based on the upgrade package and the verification file to test the reliability of the vehicle controller's verification mechanism for the upgrade package. This ensures that the vehicle controller is updated only if its verification mechanism is secure and reliable, i.e., if the test result is satisfactory. This further enhances the information security of the vehicle controller during the update process.
[0065] In some other possible implementations, this application also provides an on-board controller update device. Figure 3 This is a schematic diagram of the structure of the vehicle controller update device provided in the embodiments of this application. See also... Figure 3The vehicle controller update device provided in this application embodiment includes a tampering module 310, a determination module 320, a testing module 330, and an update module 340.
[0066] The tampering module 310 is configured to generate a test package based on the upgrade package and the verification file of the vehicle controller. The upgrade package is used to update the vehicle controller, and the verification file is an encrypted file obtained by encrypting the first identity of the upgrade package.
[0067] The determination module 320 is configured to determine the first expected feedback corresponding to the test package and the timing of the first feedback of the expected feedback.
[0068] Test module 330 is configured to test the vehicle controller based on the test package, expected feedback, and the timing of the first feedback.
[0069] Update module 340 is configured to update the vehicle controller based on the upgrade package and verification file if the test result of the vehicle controller test is qualified.
[0070] In some embodiments, when generating a test package based on the upgrade package and the verification file of the vehicle controller, the tampering module 310 is configured to: tamper with the upgrade package or the verification file; generate a test package based on the tampered upgrade package and the verification file; or generate a test package based on the tampered verification file and the upgrade package.
[0071] In some embodiments, when tampering with the upgrade package or verification file, the tampering module 310 is configured to tamper with the upgrade package or verification file by means of one of the following tampering operations: data replacement, data deletion, and data addition.
[0072] In some embodiments, when the test module 330 tests the vehicle controller according to the test package, expected feedback, and expected feedback timing, it is configured to: obtain the actual feedback of the vehicle controller to the test package and the second feedback timing of the actual feedback; if the actual feedback and expected feedback are the same, and the second feedback timing is the same as the first feedback timing, then the test result of testing the vehicle controller is a qualified test.
[0073] In some embodiments, when the test module 330 tests the vehicle controller according to the test package, expected feedback, and expected feedback timing, it is configured to: obtain the actual feedback of the vehicle controller to the test package and the second feedback timing of the actual feedback; if the actual feedback and expected feedback are different, or the second feedback timing is different from the first feedback timing, the test result is a test failure; the update module 340 is further configured to terminate the update operation of the vehicle controller if the test result is a test failure.
[0074] In some embodiments, when updating the vehicle controller according to the upgrade package and the verification file, the update module 340 is configured to: decrypt the verification file and obtain a first identity identifier based on the decrypted verification file; determine a second identity identifier of the upgrade package according to a preset calculation method; and update the vehicle controller according to the upgrade package if the first identity identifier and the second identity identifier are the same.
[0075] It should be understood that the vehicle controller update device and the vehicle controller update method provided in the above embodiments belong to the same concept, and the specific implementation process can be found in the vehicle controller update method embodiment.
[0076] In some other possible implementations, this application also provides an electronic device for updating an onboard controller. Figure 4 This is a schematic diagram of the structure of an electronic device for updating an on-board controller provided in an embodiment of this application. See also... Figure 4 The electronic device for updating the vehicle controller provided in this application embodiment includes the following structure.
[0077] Memory 410 stores at least one program instruction for updating the vehicle controller. Processor 420 executes the aforementioned program instructions, causing the vehicle to achieve the above-mentioned combination. Figure 2 The steps of the described method and its various embodiments are described below. Depending on the implementation, the processor 420 may be one or more types of processors, including but not limited to DSP (digital signal processor), ASIC (application specific integrated circuit), FPGA (field-programmable gate array), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc., and the number of such devices can be determined according to actual needs.
[0078] In some other possible implementations, this application also provides a computer program (product) comprising computer program / instructions, which are executed by a processor to cause the vehicle to achieve the above-described combination. Figure 2 The steps of the described method and its various embodiments.
[0079] In some other possible implementations, this application also provides a computer-readable storage medium storing program instructions for updating an onboard controller, which, when executed by one or more processors, cause the vehicle to achieve the above-mentioned combination. Figure 2 The steps of the described method and its various embodiments are described. The computer-readable storage medium can be a readable signal medium or a readable storage medium. A readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of readable storage media (a non-exhaustive list) include: an electrical connection having one or more wires, a portable disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof.
[0080] In some other possible implementations, this application also provides a vehicle, the vehicle including Figure 3 The vehicle controller update device described in several embodiments thereof.
[0081] It should also be noted that the terms "first," "second," etc. (if applicable) in the specification and claims of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0082] The term "and / or" in the embodiments of this application is merely a description of the relationship between related objects, indicating that there can be three relationships. For example, A or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone.
[0083] The above description is only for the purpose of enabling those skilled in the art to understand the technical solution of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the principles of this application shall be included within the scope of protection of this application.
Claims
1. A method for updating an on-board controller, characterized in that, The method includes: Generating a test package based on an upgrade package of a vehicle-mounted controller and a verification file of the upgrade package, where the upgrade package is used to update the vehicle-mounted controller, and the verification file is an encrypted file obtained by encrypting a first identity identifier of the upgrade package; Determining an expected feedback corresponding to the test package and a first feedback timing of the expected feedback; Testing the vehicle-mounted controller according to the test package, the expected feedback, and the first feedback timing; When the test result after testing the vehicle-mounted controller is qualified, updating the vehicle-mounted controller according to the upgrade package and the verification file.
2. The method according to claim 1, characterized in that, The generating a test package based on an upgrade package of a vehicle-mounted controller and a verification file of the upgrade package includes: Tampering with the upgrade package or the verification file; Generating the test package according to the tampered upgrade package and the verification file; Or generating the test package according to the tampered verification file and the upgrade package.
3. The method according to claim 2, characterized in that, The tampering with the upgrade package or the verification file includes: Tampering with the upgrade package or the verification file through one of the tampering operations of data replacement, data deletion, and data addition.
4. The method according to claim 1, characterized in that, The testing the vehicle-mounted controller according to the test package, the expected feedback, and the first feedback timing includes: Obtaining an actual feedback of the vehicle-mounted controller on the test package and a second feedback timing of the actual feedback; If the actual feedback is the same as the expected feedback and the second feedback timing is the same as the first feedback timing, the test result is qualified.
5. The method according to claim 1, characterized in that, The testing the vehicle-mounted controller according to the test package, the expected feedback, and the first feedback timing includes: Obtaining an actual feedback of the vehicle-mounted controller on the test package and a second feedback timing of the actual feedback; If the actual feedback is different from the expected feedback or the second feedback timing is different from the first feedback timing, the test result is unqualified; The method further includes: When the test result is unqualified, terminating the update operation of the vehicle-mounted controller.
6. The method according to any one of claims 1-5, characterized in that, The updating the vehicle-mounted controller according to the upgrade package and the verification file includes: Decrypting the verification file and obtaining the first identity identifier according to the decrypted verification file; Determining a second identity identifier of the upgrade package; If the first identity identifier is the same as the second identity identifier, updating the vehicle-mounted controller according to the upgrade package.
7. A device for updating an on-board controller, characterized in that, The device includes a tampering module, a determining module, a testing module, and an updating module; The tampering module is configured to generate a test package based on an upgrade package of a vehicle-mounted controller and a verification file of the upgrade package, where the upgrade package is used to update the vehicle-mounted controller, and the verification file is an encrypted file obtained by encrypting a first identity identifier of the upgrade package; The determining module is configured to determine a first expected feedback corresponding to the test package and a first feedback timing of the expected feedback; The testing module is configured to test the vehicle controller based on the test package, the expected feedback, and the first feedback timing. The update module is configured to update the vehicle controller according to the upgrade package and the verification file if the test result after testing the vehicle controller is qualified.
8. An electronic device, characterized in that, include: A memory, wherein the memory stores program instructions for updating the vehicle controller; as well as, A processor, when the program instructions are executed by the processor, causes the vehicle to perform the method of any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores program instructions for updating the vehicle controller, which, when executed by one or more processors, cause the vehicle to perform the method of any one of claims 1-6.
10. A vehicle, characterized in that, The vehicle includes the vehicle controller update device as described in claim 7.