Vehicle upgrading method and device, electronic equipment and vehicle

By storing the upgrade package in an online flash memory partition and executing relevant steps when an abnormality is detected in the embedded multimedia card chip, the upgrade failure problem caused by the failure of the EMMC chip was resolved, and the vehicle upgrade was successfully completed and the system stability was improved.

CN121193603APending Publication Date: 2025-12-23CHONGQING JINKANG NEW ENERGY VEHICLE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511230513.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-29
Publication Date
2025-12-23

AI Technical Summary

Technical Problem

During the over-the-air (OTA) upgrade process, the EMMC chip experienced a single-unit failure, leading to an increased read/write error rate and response latency, which triggered timeout protection and caused the upgrade to fail.

Method used

When an abnormal status is detected in the embedded multimedia card chip, the over-the-air (OTA) upgrade package is stored in the online flash memory partition and mounted to the specified directory to perform the upgrade task, which includes steps such as status monitoring, metadata detection, storage space determination, and upgrade package verification.

Benefits of technology

This avoids upgrade failures caused by EMMC unit failure, ensures a smooth upgrade process, simplifies the operation process, and improves system compatibility and stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121193603A_ABST
    Figure CN121193603A_ABST
Patent Text Reader

Abstract

The invention provides a vehicle upgrading method and device, electronic equipment and a vehicle, and the method comprises the steps: storing an over-the-air technology upgrade package to an online flash memory partition under the condition that the state of an embedded multimedia card chip is detected to be abnormal; mounting the online flash memory partition to a specified directory; an over-the-air downloading technology upgrade package is downloaded from the online flash memory partition by accessing a specified directory, and the over-the-air downloading technology upgrade package comprises a plurality of upgrade tasks; and vehicle upgrading is completed by executing the upgrading task so as to ensure that the vehicle is successfully upgraded.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of vehicles, in particular to a vehicle upgrading method and device, an electronic device and a vehicle. BACKGROUND

[0002] In the process of Over-The-Air Technology (OTA) upgrading of a Telematics BOX (T-BOX), large-capacity firmware data needs to be continuously written in an Embedded Multi MediaCard (EMMC) chip.

[0003] With long-term use of the EMMC chip, the programming / erasing times of the internal flash memory unit gradually approach the design limit. When the life is exhausted, the storage unit EMMC chip monomer will fail, thereby causing problems such as an increase in read / write error rate and an increase in response delay. At this time, if the T-BOX continues to perform the OTA upgrading operation, the EMMC is prone to trigger timeout protection due to the monomer failure, trigger an instruction to forcibly terminate data transmission, and cause upgrading failure. SUMMARY

[0004] Therefore, the present application aims to provide a vehicle upgrading method and device, an electronic device and a vehicle to solve the problem of upgrading failure caused by triggering of timeout protection and an instruction to forcibly terminate data transmission due to monomer failure of an EMMC chip when performing an OTA upgrading operation. The specific technical solutions are as follows: According to a first aspect of the present application, a vehicle upgrading method is provided, which comprises: storing an Over-The-Air Technology (OTA) upgrading package to an online flash memory partition when detecting that an Embedded Multi MediaCard (EMMC) chip state is abnormal; mounting the online flash memory partition to a specified directory; downloading the OTA upgrading package from the online flash memory partition by accessing the specified directory, the OTA upgrading package containing a plurality of upgrading tasks; completing vehicle upgrading by performing the upgrading tasks.

[0005] Optionally, the mounting of the online flash memory partition to the specified directory further comprises: identifying a storage location of the online flash memory partition; if the storage location is a NAND flash memory, reading physical data of the NAND flash memory by a memory technology device subsystem, and generating a block device, the physical data including data of the online flash memory partition; If the storage location is a NOR gate flash memory, then the NOR gate flash memory is abstracted into a block device through the memory technology device subsystem; Mount the block device to the specified directory.

[0006] Optionally, before storing the over-the-air (OTA) upgrade package to the online flash memory partition when an abnormality is detected in the embedded multimedia card chip, the following steps are included: Read metadata from the online flash partition according to a preset cycle; If the metadata reading fails, it is determined that a hardware error has occurred in the online flash partition; Add a fault marker to the online flash partition that has a hardware error and send an exception alert; If the metadata is read successfully, the remaining storage space of the online flash partition is determined using the metadata.

[0007] Optionally, storing the over-the-air (OTA) upgrade package to an online flash memory partition when an abnormality is detected in the embedded multimedia card chip includes: If an abnormality is detected in the embedded multimedia card chip, the required storage space for the over-the-air download technology upgrade package is obtained; If the required storage space is greater than or equal to the remaining storage space, a storage failure alert is sent. If the required storage space is less than the remaining storage space, then the space difference between the remaining storage space and the required storage space is obtained; If the space difference is greater than a preset space threshold, the over-the-air (OTA) upgrade package will be stored in the online flash memory partition.

[0008] Optionally, before completing the vehicle upgrade by executing the upgrade task, the process further includes: Obtain the hash value of the over-the-air (OTA) upgrade package; The hash value is compared with a preset security value; If they match, the over-the-air (OTA) upgrade package is decompressed to obtain the verification information of the OTA upgrade package. The verification information includes at least one of the following: version information, supported device models, and dependencies. The over-the-air (OTA) upgrade package is verified using the information to be verified.

[0009] Optionally, before storing the over-the-air (OTA) upgrade package to the online flash memory partition when an abnormality is detected in the embedded multimedia card chip state, the method further includes: Upon detecting an upgrade flag, a script is launched to monitor the status of the embedded multimedia card chip; Alternatively, upon receiving an upgrade command, a script can be started to monitor the status of the embedded multimedia card chip.

[0010] Optionally, after completing the vehicle upgrade by executing the upgrade task, the process further includes: Control the vehicle to exit upgrade mode; Obtain the vehicle's upgrade logs and report them to the vehicle cloud system; Remove the over-the-air (OTA) upgrade package from the online flash memory partition.

[0011] According to a second aspect of this application, a vehicle upgrade device is provided, the device comprising: The storage module is used to store the over-the-air (OTA) upgrade package to an online flash memory partition when an abnormality is detected in the embedded multimedia card chip. The mounting module is used to mount the online flash memory partition to a specified directory; The download module is used to download the over-the-air (OTA) upgrade package from the online flash memory partition by accessing a specified directory. The OTA upgrade package contains several upgrade tasks. The task execution module is used to complete the vehicle upgrade by executing the upgrade task.

[0012] According to another aspect of this application, an electronic device is also provided, comprising: processor; Memory used to store the processor's executable instructions; The processor is configured to execute the instructions to implement the vehicle upgrade method described above.

[0013] According to another aspect of this application, a vehicle is also provided, including the aforementioned vehicle upgrade device.

[0014] The vehicle upgrade method provided in this application, when an abnormality is detected in the embedded multimedia card chip, stores the over-the-air (OTA) upgrade package to an online flash memory partition. By detecting the status of the embedded multimedia card chip and storing the OTA upgrade package to the online flash memory partition when its status is abnormal, upgrade failure due to storage media failure is avoided. Mounting the online flash memory partition to a designated directory allows the upgrade package to be read and written directly, securely, and efficiently by the system and applications, thereby avoiding the complexity of the underlying storage media, simplifying the operation process, and ensuring compatibility. By accessing the designated directory, the OTA upgrade package, which contains several upgrade tasks, is downloaded from the online flash memory partition; the vehicle upgrade is completed by executing the upgrade tasks. This application, by detecting the status of the embedded multimedia card chip, can promptly detect its faults and, when an abnormality is detected, uses the online flash memory partition to perform the steps required for vehicle upgrade in place of the embedded multimedia card chip. This avoids the problem of timeout protection being triggered due to eMMC unit failure, which triggers the instruction to forcibly terminate data transmission and causes upgrade failure, thus ensuring a smooth vehicle upgrade.

[0015] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, specific embodiments of this application are given below. Attached Figure Description

[0016] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the scope of this application. Furthermore, the same reference numerals denote the same parts throughout the drawings. In the drawings: Figure 1 This is a flowchart of the steps of a vehicle upgrade method provided in this application; Figure 2 yes Figure 1 The flowchart shown is a process for step 102 in a vehicle upgrade method provided in this application; Figure 3 This is a flowchart of another vehicle upgrade method provided in this application; Figure 4 This is a structural schematic diagram of a vehicle upgrade device provided in this application; Figure 5 This is a schematic diagram of the structure of an electronic device provided in this application. Detailed Implementation

[0017] To make the objectives, technical solutions, and advantages of this application clearer, the various embodiments of this application will be described in detail below with reference to the accompanying drawings. However, those skilled in the art will understand that many technical details have been provided in the various embodiments of this application to facilitate a better understanding of the application. However, the technical solutions claimed in this application can be implemented even without these technical details and with various variations and modifications based on the following embodiments. The division of the various embodiments below is for ease of description and should not constitute any limitation on the specific implementation of this application. The various embodiments can be combined with and referenced by each other without contradiction.

[0018] During an Over-The-Air (OTA) upgrade of a Telematics Box (T-BOX), the embedded MultiMediaCard (EMMC) in the storage module reaches the end of its lifespan, causing the EMMC to fail. This results in a data write timeout, triggering the CMD12 STOP command (used to forcibly terminate the current data transmission process), leading to upgrade failure. Based on this problem, this application proposes a vehicle upgrade method. (Refer to...) Figure 1 The diagram illustrates a flowchart of a vehicle upgrade method provided in this application, the method comprising: Step 101: If an abnormality is detected in the embedded multimedia card chip, the over-the-air (OTA) upgrade package is stored in the online flash memory partition.

[0019] This application applies to scenarios involving over-the-air (OTA) technology upgrades of a telematics box (T-BOX). In this case, the T-BOX's status must first be checked to ensure it is functioning correctly, avoiding errors in the assessment results due to T-BOX malfunctions. During the upgrade process, the embedded multimedia card chip typically serves as a non-volatile storage medium for the vehicle's head unit, storing the OTA upgrade package. However, when it malfunctions (such as read / write errors, an increase in bad blocks, etc.), it can cause write data timeouts during the upgrade, leading to upgrade failure.

[0020] To avoid this problem, this application sets up a script to monitor the status of the embedded multimedia card chip. Before monitoring the embedded multimedia card chip status, the script needs to be triggered. In this application, the script is triggered to start when an upgrade flag is detected or an upgrade command is received. Specifically, the low-level flag of a specific general-purpose input / output (GPIO) pin can be set as the upgrade flag, or the reset flag of the watchdog timer after the vehicle is powered on can be set as the upgrade flag. Alternatively, a special flag can be set as the upgrade flag when new firmware is detected and a new over-the-air (OTA) upgrade package is generated; this application does not specify any particular limitation. The upgrade command can be generated based on the user manually clicking "Upgrade Now" on the vehicle's screen. After the script is started, the status of the embedded multimedia card chip can be monitored through the script. The steps involved include: Upon detecting an upgrade flag, a script is launched to monitor the status of the embedded multimedia card chip. Alternatively, upon receiving an upgrade command, a script can be started to monitor the status of the embedded multimedia card chip.

[0021] The above operations dynamically adapt to automatic or manual upgrade scenarios through a dual triggering mechanism (upgrade flag / command signal), and rely on scripts to monitor the EMMC in real time to ensure that the storage media status meets the upgrade requirements, thereby avoiding upgrade failures caused by EMMC anomalies and improving the robustness of the process and user experience.

[0022] In addition to real-time monitoring of the EMMC, the script can also detect system environment conditions (such as power supply voltage) to prevent power outages during upgrades; check the remaining storage capacity to determine if it is sufficient to store the new firmware; disable non-critical services (such as entertainment functions) to free up system resources; back up critical data (such as the current system image and configuration parameters) to reserve rollback paths; and compare the version number of the over-the-air (OTA) upgrade package to avoid duplicate upgrades or downgrades. These functions of the script can significantly reduce the risk of upgrade failures due to hardware or environmental issues.

[0023] When an abnormality is detected in the embedded multimedia card chip, this application stores the over-the-air (OTA) upgrade package to the online flash partition. However, before storing the OTA upgrade package, the online flash partition also needs to be checked to ensure that the OTA upgrade package can be successfully stored. Therefore, this application sets up a system to check the metadata of the online flash partition (e.g., a storage area of ​​a Solid State Drive (SSD)) at a preset period (e.g., hourly). The metadata records key information about the partition, such as file structure and storage block status. If the metadata cannot be read (e.g., verification fails or times out), it indicates that the storage medium may have a hardware error, i.e., physical damage (e.g., abnormal metadata verification value, possibly due to charge leakage in the flash chip causing data loss). In this case, a fault mark needs to be added to the faulty online flash partition, and the administrator needs to be notified via email / SMS to avoid continuing to use the damaged partition. If the metadata is normal, the storage block information (e.g., the number of used / unused blocks) is parsed to calculate the remaining storage space. The steps include: Read metadata from the online flash partition according to a preset cycle; If metadata reading fails, it is determined that there is a hardware error in the online flash partition; Add fault markers to online flash partitions that experience hardware errors and send exception alerts; If the metadata is read successfully, the remaining storage space of the online flash partition is determined using the metadata.

[0024] When determining the remaining storage space of an online flash partition, for example, if the total capacity of the online flash partition is determined to be 1TB and the used storage space is 800GB, then the remaining storage space is 200GB available for writing.

[0025] The above operations, through automated periodic detection and metadata analysis, enable real-time monitoring of the health status of online flash memory partitions. This allows for early detection and warning of hardware failures (such as flash memory damage) to avoid data loss risks, and also enables dynamic management of storage resources (such as remaining space statistics) to improve system reliability and operational efficiency.

[0026] The online flash partition in this application, also known as the FLASH online partition, refers to a pre-defined, independent, and addressable logical storage area within a FLASH (flash memory) chip. When an abnormality is detected in the embedded multimedia card chip, this application directs the over-the-air (OTA) upgrade package to this dedicated, readable and writable FLASHonline partition.

[0027] This application detects the remaining storage space of the online flash partition because, when the embedded multimedia card chip is in an abnormal state, the over-the-air (OTA) upgrade package needs to be stored in the online flash partition. Therefore, it is necessary to determine whether the remaining storage space of the online flash partition meets the storage requirements of the OTA upgrade package. If the required storage space for the OTA upgrade package exceeds the current remaining storage space, the system will send a failure alert to avoid upgrade interruption or data corruption due to insufficient space. If the remaining storage space is sufficient to store the upgrade package, the system will calculate the difference between the remaining storage space and the required storage space to determine whether the additional reserved space requirement is met. If the difference is large enough, exceeding a preset space threshold (e.g., a preset threshold of 10GB), it indicates that the storage space is sufficient, and the system allows the download and storage of the upgrade package. The steps involved include: In the event that an abnormal state is detected in the embedded multimedia card chip, the required storage space for obtaining the over-the-air (OTA) download technology upgrade package is obtained. If the required storage space is greater than or equal to the remaining storage space, a storage failure notification will be sent. If the required storage space is less than the remaining storage space, then obtain the space difference between the remaining storage space and the required storage space; If the space difference is greater than the preset space threshold, the over-the-air download technology upgrade package will be stored in the online flash memory partition.

[0028] For example, suppose the in-vehicle infotainment system needs to download a 5GB over-the-air (OTA) update package, but there is only 3GB of remaining storage space. In this case, the system will refuse the update and prompt the user to clear the space. If the remaining storage space is 10GB, the space difference is 10-5=5GB. The preset space threshold is 3GB. Since 5GB > 3GB, the OTA update package will be downloaded and stored in the online flash memory partition.

[0029] When an EMMC storage anomaly is detected, the above operations intelligently assess the storage feasibility of the over-the-air (OTA) upgrade package, preventing upgrade failure or system crashes due to insufficient space. Simultaneously, preset thresholds ensure sufficient buffer space during the upgrade process, improving system stability and upgrade success rate.

[0030] Step 102: Mount the online flash partition to the specified directory.

[0031] When mounting an online flash memory partition to a specified directory, this application first sends a query command to the flash memory chip via a Serial Peripheral Interface Controller (SPI) or a memory bus controller to read its ID number, thereby determining the physical storage medium type of the online flash memory partition [such as NAND gate flash memory (NAND Flash) and NOR gate flash memory (NOR Flash)]. If the storage medium is identified as NAND flash, the operating system of this application (usually an embedded Linux operating system) will directly read its underlying physical data (such as raw page / block data) through the memory technology device subsystem and create a virtual block device based on this data. Because a block device can only be mounted like a regular hard drive after its creation, subsequent operations are convenient. Furthermore, since NAND flash memory cannot be accessed directly byte-by-byte, but must be read in units of pages (typically 4KB~16KB) and erased in units of blocks (typically 128KB~4MB), directly manipulating the physical layer data avoids the additional overhead of the file system and ensures the accuracy of data reading. Furthermore, NAND flash memory can generate bad blocks during use. When directly reading physical data through the memory technology device subsystem, bad block detection (such as reading bad block marker bytes in the reserved area or maintaining a bad block table) and address remapping logic are required through the underlying driver to ensure that bad blocks are skipped, thereby avoiding data read failures caused by accessing marked bad blocks. Error checking and correcting (ECC) and block-level read / write control are also required to comply with the physical characteristics of NAND and ensure data integrity. If the storage medium is identified as NOR Flash (or NOT gate flash memory), reading its data is very simple and direct because NOR Flash can be directly addressed by bytes. It does not require the complex process of "reading physical data" to reconstruct the data. To adapt to the operating system's rule that a "block device" is required to mount the file system, the memory technology device subsystem needs to abstract it into a block device before mounting. After generating the block device, this application will also mount the block device to a specified directory of the file system (e.g., / mnt / upg / ota) through the EMMC component.

[0032] In step 102, such as Figure 2 As shown: Step 1021: Identify the storage location of the online flash partition.

[0033] Step 1022: If the storage location is a NAND flash memory, then the physical data of the NAND flash memory is read through the memory technology device subsystem, and a block device is generated. The physical data includes the data of the online flash memory partition.

[0034] Step 1023: If the storage location is a NOR gate flash memory, then the NOR gate flash memory is abstracted into a block device through the memory technology device subsystem.

[0035] Step 1024: Mount the block device to the specified directory.

[0036] In the NAND gate flash memory, when generating a block device, the physical addresses of bad blocks in the flash memory can be determined by reading its physical data. Then, through the address remapping logic of the memory technology device subsystem, a dynamic mapping table from logical addresses to physical addresses is established. This mapping table skips the physical addresses of all bad blocks during construction, thus providing a contiguous logical address space that masks bad blocks. This logical address space is then abstracted as the block device of the NAND gate flash memory. NOR gates do not have bad blocks, and their physical address space is inherently reliable. Therefore, their entire physical storage space can be directly linearly mapped to a block device, indicating that their entire storage space is usable. The memory technology device subsystem is an intermediate layer software framework of the embedded Linux operating system kernel. In this application, it is used to manage and abstract NAND gate flash memory chips and NOR gate flash memory chips. Of course, it can also manage and abstract other similar non-volatile storage devices, such as read-only memory (ROM), non-volatile random access memory (NVRAM), or electrically erasable programmable read-only memory (EEPROM), etc. This application does not make specific limitations here.

[0037] The above steps bypass potential file system corruption by directly manipulating the physical layer data of the NAND Flash and generating block devices, ensuring reliable access to critical data even in the event of storage media failure. This is suitable for firmware upgrade scenarios and improves the system's compatibility and robustness with flash hardware.

[0038] Step 103: Download the over-the-air (OTA) upgrade package from the online flash drive partition by accessing the specified directory. The OTA upgrade package contains several upgrade tasks.

[0039] Because once the NAND Flash block device is successfully mounted to the specified directory, the data in that directory will be presented in the form of a standard file system. Therefore, this application can access the over-the-air (OTA) upgrade package file using common Linux file operation commands (such as ls and cat). For example, the command `ls / mnt / upg / ota / ` can be used to check if the OTA upgrade package exists in the specified directory ( / mnt / upg / ota), and the command `cat / mnt / upg / ota / firmware.bin| head -n 1` can be used to check the header information of the OTA upgrade package. Accessing the OTA upgrade package in this way is compatible with existing toolchains and does not require the development of additional dedicated read / write interfaces. In addition, this application uses the UPG component to scan for qualified upgrade packages (such as files with specific filenames and matching checksums) in the mounted online flash partition, and then downloads the OTA upgrade package from them. An OTA upgrade package can contain multiple upgrade tasks.

[0040] It should be noted that upgrade tasks can be functional upgrades resulting from automakers releasing new features, such as adding automatic steering in urban roads, optimizing voice assistants, or updating entertainment systems. They can also be safety-critical upgrades resulting from discovering software defects or compliance risks that may affect driving safety, such as software algorithms causing abnormal braking distances, leading to over-the-air (OTA) updates to fix protocol vulnerabilities in vehicle communication modules (such as the CAN bus). Furthermore, they can be regulatory compliance upgrades resulting from new regulations taking effect or regional policy requirements, such as upgrades related to adjusting headlight standards for exported vehicles to adapt to left-hand drive / right-hand drive countries.

[0041] Step 104: Complete the vehicle upgrade by executing the upgrade task.

[0042] After downloading the over-the-air (OTA) upgrade package from an online flash memory partition, this application first verifies the integrity, authenticity, and compatibility of the OTA upgrade package. This includes comparing the hash value of the OTA upgrade package with a preset security value to determine if the upgrade package has been tampered with or corrupted. The hash value is a unique digital fingerprint of the upgrade package used to verify data integrity. If the hash value of the OTA upgrade package matches the preset security value, the OTA upgrade package can be decompressed for further verification. If the hash value of the OTA upgrade package does not match the preset security value, it may be due to malicious code injected by a hacker causing a change in the hash value of the OTA upgrade package. In this case, the upgrade needs to be terminated and an alert should be triggered.

[0043] For example, if the hash value of the upgrade package firmware_v2.1.bin released by a car manufacturer is a1b2c3..., and the default security value published on the car manufacturer's official website is a1b2c3..., then the hash value of the over-the-air (OTA) upgrade package is consistent with the default security value, indicating that the hash value verification has passed.

[0044] After unzipping the over-the-air (OTA) upgrade package, it is necessary to further verify key information such as version information, supported device models, and dependencies contained within the upgrade package to ensure that the upgrade package is fully compatible with the current device and to avoid upgrade failure due to version conflicts or missing dependencies. The steps involved include: Obtain the hash value of the over-the-air (OTA) upgrade package; Compare the hash value with the preset security value; If they match, the over-the-air (OTA) upgrade package is decompressed to obtain the verification information of the OTA upgrade package. The verification information includes at least one of the following: version information, supported device models, and dependencies. The over-the-air (OTA) upgrade package is verified using the information to be verified.

[0045] The above steps enable dual verification (hash value + metadata verification), ensuring the integrity, authenticity, and compatibility of over-the-air (OTA) upgrade packages and effectively preventing risks such as malicious tampering, version conflicts, and data corruption.

[0046] This application reads and tracks the upgrade process during the upgrade, ensuring that each step is executed as expected. It also acquires and uploads the upgrade results for subsequent analysis and processing. Upon completion of the upgrade, it exits the upgrade mode, uploads the upgrade log, and deletes the upgrade package to free up space. The steps involved include: Control the vehicle to exit upgrade mode; Obtain the vehicle's upgrade logs and report them to the vehicle cloud system; Remove the over-the-air (OTA) download technology upgrade package from the online flash memory partition.

[0047] The above operations prevent the system from being in an unstable state for a long time by forcibly exiting the upgrade mode, obtain upgrade logs to facilitate subsequent fault analysis and optimization of the upgrade process, and delete used over-the-air upgrade packages to free up storage space and prevent residual files from interfering with subsequent upgrades, thereby improving the system's security, reliability and storage management efficiency.

[0048] This application involves different systems and components during vehicle upgrades, for example, such as... Figure 3As shown, the process begins by monitoring the EMMC status via a startup script. When an abnormality is detected, the script stores the OTA upgrade package in the online flash partition. Simultaneously, the vehicle cloud system sends an anomaly notification and pushes an upgrade request to the diagnostic update center. The diagnostic update center, based on the upgrade request, sends an upgrade start notification to the OTA API. The EMMC / memory component then mounts the online flash partition to a specified directory. The OTA API then sends an upgrade start notification to the UPG component. The UPG component reads the OTA upgrade package from the EMMC / memory component and executes the upgrade task accordingly. The memory component typically works in conjunction with the EMMC. The memory component stores running applications and operating system data, while the EMMC provides long-term storage for the operating system, applications, and personal data. For the integrity of the upgrade task, system compatibility, and functional stability, the UPG component can perform operations such as reading the NAD partition, rebooting the entire system, and upgrading the MCU. During the upgrade process, the diagnostic update center needs to read the upgrade process, obtain the upgrade results, ensure each step is executed as expected, and report the upgrade results to the vehicle cloud system for subsequent analysis and processing. After the upgrade is complete, the diagnostic update center will exit the upgrade mode, report the upgrade log to the vehicle cloud system, and delete the OTA upgrade package.

[0049] The vehicle upgrade method provided in this application, when an abnormality is detected in the embedded multimedia card chip, stores the over-the-air (OTA) upgrade package to an online flash memory partition. By detecting the status of the embedded multimedia card chip and storing the OTA upgrade package to the online flash memory partition when its status is abnormal, upgrade failure due to storage media failure is avoided. Mounting the online flash memory partition to a designated directory allows the upgrade package to be read and written directly, securely, and efficiently by the system and applications, thereby avoiding the complexity of the underlying storage media, simplifying the operation process, and ensuring compatibility. By accessing the designated directory, the OTA upgrade package, which contains several upgrade tasks, is downloaded from the online flash memory partition; the vehicle upgrade is completed by executing the upgrade tasks. This application, by detecting the status of the embedded multimedia card chip, can promptly detect its faults and, when an abnormality is detected, uses the online flash memory partition to perform the steps required for vehicle upgrade in place of the embedded multimedia card chip. This avoids the problem of timeout protection being triggered due to eMMC unit failure, which triggers the instruction to forcibly terminate data transmission and causes upgrade failure, thus ensuring a smooth vehicle upgrade.

[0050] Reference Figure 4 The diagram shows a structural schematic of a vehicle upgrade device provided in this application, the device comprising: Storage module 201 is used to store over-the-air (OTA) upgrade packages to an online flash memory partition when an abnormality is detected in the embedded multimedia card chip.

[0051] Mount module 202 is used to mount online flash memory partitions to a specified directory.

[0052] Download module 203 is used to download an over-the-air (OTA) upgrade package from an online flash drive partition by accessing a specified directory. The OTA upgrade package contains several upgrade tasks.

[0053] Task execution module 204 is used to complete vehicle upgrades by executing upgrade tasks.

[0054] Optionally, the mounting module 202 includes: The identification submodule is used to identify the storage location of the online flash partition.

[0055] The read submodule is used to read the physical data of the NAND flash memory through the memory technology device subsystem if the storage location is NAND flash memory, and generate a block device. The physical data includes the data of the online flash partition.

[0056] The abstract submodule is used to abstract NOR gate flash memory as a block device through the memory technology device subsystem if the storage location is NOR gate flash memory.

[0057] The mount submodule is used to mount block devices to a specified directory.

[0058] Optionally, the vehicle upgrade device also includes: The read module is used to read the metadata of the online flash partition according to a preset cycle.

[0059] The anomaly detection module is used to determine that a hardware error has occurred in the online flash partition if metadata reading fails.

[0060] The anomaly alert module is used to add fault markers to online flash memory partitions that have hardware errors and send anomaly alerts.

[0061] The determination module is used to determine the remaining storage space of the online flash partition based on the metadata if the metadata is successfully read.

[0062] Optionally, storage module 201 includes: The first acquisition submodule is used to acquire the required storage space for the over-the-air (OTA) download technology upgrade package when an abnormality is detected in the embedded multimedia card chip.

[0063] The reminder submodule is used to send a storage failure reminder if the required storage space is greater than or equal to the remaining storage space.

[0064] The second acquisition submodule is used to obtain the space difference between the remaining storage space and the required storage space if the required storage space is less than the remaining storage space.

[0065] The storage submodule is used to store the over-the-air (OTA) upgrade package to the online flash memory partition if the space difference is greater than a preset space threshold.

[0066] Optionally, the vehicle upgrade device also includes: The hash value acquisition module is used to obtain the hash value of the over-the-air (OTA) download technology upgrade package.

[0067] The comparison module is used to compare the hash value with the preset security value.

[0068] The information acquisition module is used to decompress the over-the-air (OTA) upgrade package if the data matches, and to obtain the verification information of the OTA upgrade package. The verification information includes at least one of the following: version information, supported device models, and dependencies.

[0069] The verification module is used to verify the over-the-air (OTA) upgrade package using the information to be verified.

[0070] The monitoring module is used to start a script to monitor the status of the embedded multimedia card chip when an upgrade flag is detected.

[0071] Alternatively, upon receiving an upgrade command, a script can be started to monitor the status of the embedded multimedia card chip.

[0072] The mode control module is used to control the vehicle to exit the upgrade mode.

[0073] The log acquisition module is used to acquire the vehicle's upgrade logs and report them to the vehicle cloud system.

[0074] The deletion module is used to remove over-the-air (OTA) upgrade packages from online flash memory partitions.

[0075] The vehicle upgrade device provided in this application, upon detecting an abnormal state of the embedded multimedia card chip, stores the over-the-air (OTA) upgrade package to an online flash memory partition. By detecting the state of the embedded multimedia card chip and storing the OTA upgrade package to the online flash memory partition when its state is abnormal, upgrade failure due to storage media failure is avoided. Mounting the online flash memory partition to a designated directory allows the upgrade package to be read and written directly, securely, and efficiently by the system and applications, thereby avoiding the complexity of the underlying storage media, simplifying the operation process, and ensuring compatibility. By accessing the designated directory, the OTA upgrade package, which contains several upgrade tasks, is downloaded from the online flash memory partition; the vehicle upgrade is completed by executing the upgrade tasks. This application, by detecting the state of the embedded multimedia card chip, can promptly detect its faults and, upon detecting an abnormality, uses the online flash memory partition to perform the steps required for vehicle upgrades instead of the embedded multimedia card chip. This avoids the problem of timeout protection being triggered due to eMMC unit failure, which triggers a command to forcibly terminate data transmission and causes upgrade failure, thus ensuring a smooth vehicle upgrade.

[0076] Reference Figure 5 This application also provides an electronic device, such as Figure 5 As shown, it includes a processor 301, a communication interface 302, a memory 303, and a communication bus 304, wherein the processor 301, the communication interface 302, and the memory 303 communicate with each other through the communication bus 304. Processor 301, memory 303 for storing processor-executable instructions; The processor 301 is configured to execute the instructions to implement the vehicle upgrade method described above: If an abnormality is detected in the embedded multimedia card chip, the over-the-air (OTA) upgrade package will be stored in the online flash memory partition. Mount the online flash partition to the specified directory; By accessing a specified directory, the over-the-air (OTA) technology upgrade package is downloaded from the online flash memory partition. The OTA technology upgrade package contains several upgrade tasks. The vehicle upgrade is completed by executing the aforementioned upgrade task.

[0077] The communication bus mentioned above can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into address bus, data bus, control bus, etc. For ease of illustration, only one thick line is used to represent it in the diagram, but this does not mean that there is only one bus or one type of bus.

[0078] The communication interface is used for communication between the aforementioned terminal and other devices.

[0079] The memory may include random access memory (RAM) or non-volatile memory, such as at least one disk storage device. Optionally, the memory may also be at least one storage device located remotely from the aforementioned processor.

[0080] The processors mentioned above can be general-purpose processors, including central processing units (CPUs), network processors (NPs), etc.; they can also be digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.

[0081] In another embodiment provided in this application, a vehicle is also provided, which may specifically include the aforementioned vehicle upgrade device.

[0082] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., a solid-state drive (SSD)).

[0083] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0084] The various embodiments in this specification are described in a related manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the system embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions of the method embodiments.

[0085] The above description is merely a preferred embodiment of this application and is not intended to limit the scope of protection of this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application are included within the scope of protection of this application.

Claims

1. A vehicle upgrade method, characterized in that, The method includes: If an abnormality is detected in the embedded multimedia card chip, the over-the-air (OTA) upgrade package will be stored in the online flash memory partition. Mount the online flash partition to the specified directory; By accessing a specified directory, the over-the-air (OTA) technology upgrade package is downloaded from the online flash memory partition. The OTA technology upgrade package contains several upgrade tasks. The vehicle upgrade is completed by executing the aforementioned upgrade task.

2. The method according to claim 1, characterized in that, The step of mounting the online flash partition to the specified directory further includes: Identify the storage location of the online flash memory partition; If the storage location is a NAND flash memory, the physical data of the NAND flash memory is read through the memory technology device subsystem, and a block device is generated. The physical data includes the data of the online flash memory partition. If the storage location is a NOR gate flash memory, then the NOR gate flash memory is abstracted into a block device through the memory technology device subsystem; Mount the block device to the specified directory.

3. The method according to claim 1, characterized in that, Before storing the over-the-air (OTA) upgrade package to the online flash memory partition when an abnormality is detected in the embedded multimedia card chip, the following steps are included: Read metadata from the online flash partition according to a preset cycle; If the metadata reading fails, it is determined that a hardware error has occurred in the online flash partition; Add a fault marker to the online flash partition that has a hardware error and send an exception alert; If the metadata is read successfully, the remaining storage space of the online flash partition is determined using the metadata.

4. The method according to claim 3, characterized in that, The step of storing the over-the-air (OTA) upgrade package to an online flash memory partition when an abnormality is detected in the embedded multimedia card chip includes: If an abnormality is detected in the embedded multimedia card chip, the required storage space for the over-the-air download technology upgrade package is obtained; If the required storage space is greater than or equal to the remaining storage space, a storage failure alert is sent. If the required storage space is less than the remaining storage space, then the space difference between the remaining storage space and the required storage space is obtained; If the space difference is greater than a preset space threshold, the over-the-air (OTA) upgrade package will be stored in the online flash memory partition.

5. The method according to claim 1, characterized in that, Before completing the vehicle upgrade by executing the upgrade task, the process also includes: Obtain the hash value of the over-the-air (OTA) upgrade package; The hash value is compared with a preset security value; If they match, the over-the-air (OTA) upgrade package is decompressed to obtain the verification information of the OTA upgrade package. The verification information includes at least one of the following: version information, supported device models, and dependencies. The over-the-air (OTA) upgrade package is verified using the information to be verified.

6. The method according to claim 1, characterized in that, Before storing the over-the-air (OTA) upgrade package to the online flash memory partition when an abnormality is detected in the embedded multimedia card chip, the method further includes: Upon detecting an upgrade flag, a script is launched to monitor the status of the embedded multimedia card chip; Alternatively, upon receiving an upgrade command, a script can be started to monitor the status of the embedded multimedia card chip.

7. The method according to claim 1, characterized in that, After completing the vehicle upgrade by executing the upgrade task, the process further includes: Control the vehicle to exit upgrade mode; Obtain the vehicle's upgrade logs and report them to the vehicle cloud system; Remove the over-the-air (OTA) upgrade package from the online flash memory partition.

8. A vehicle upgrade device, characterized in that, The device includes: The storage module is used to store the over-the-air (OTA) upgrade package to an online flash memory partition when an abnormality is detected in the embedded multimedia card chip. The mounting module is used to mount the online flash memory partition to a specified directory; The download module is used to download the over-the-air (OTA) upgrade package from the online flash memory partition by accessing a specified directory. The OTA upgrade package contains several upgrade tasks. The task execution module is used to complete the vehicle upgrade by executing the upgrade task.

9. An electronic device, characterized in that, include: processor; Memory used to store processor-executable instructions; The processor is configured to execute the instructions to implement the vehicle upgrade method as described in any one of claims 1 to 7.

10. A vehicle, characterized in that, include: The vehicle upgrade device as described in claim 8.